
Case Study · Retail & E-commerce
Ransomware Response for an Omnichannel Retailer
- ~14 daysFrom activation to critical-systems recovery
- 3 phasesRecovery ordered by business priority
- 1Evidence chain preserved for investigation
The challenge
A mid-size omnichannel retailer found its warehouse management systems and part of its in-store point-of-sale estate encrypted overnight. Shipping operations were halted and the internal team was weighing whether to shut everything down or pay.
The first decisions, taken under pressure, risked destroying the evidence needed to understand the scope of the attack and restoring un-remediated systems back into production.
My approach
I took coordination of the response alongside the internal team: targeted isolation of the affected segments, blocking of lateral-movement paths, and preservation of evidence — forensic images and logs — before any remediation.
In parallel I reconstructed the attack timeline, identified the point of entry and verified backup integrity, so recovery could start from clean sources rather than reintroducing the compromise.
Recovery was ordered by business priority — logistics and payments first, supporting systems next — and closed with a board debrief on root cause, residual exposure and the few measures that would materially reduce the risk of recurrence.
Related
You might also like
Incident ResponseThe first 60 minutes of an incident: what to do (and what not to do)
Containing the attack without destroying the evidence you will need later.14 Dec 2025 · 4 min read
RansomwareRansomware: pay or don’t pay is the wrong question
The decision is prepared months earlier, while you are not yet on fire.22 Nov 2025 · 4 min read
Incident ResponseThe incident response retainer: why preparation changes the outcome
A contract already signed, a plan already rehearsed, roles already assigned.18 Oct 2025 · 4 min read