An illustrative case explaining the route
Production halted when the office systems were encrypted, not the controllers
A building materials plant with a single line running two shifts. The machines and controllers sit on a relatively separate network, but work orders, quality records and raw material balances all originate in an ERP on the office network. When ERP, quality and warehouse were encrypted, production stopped even though nothing had touched the machines.
Manufacturing & industry
What was affected
- The ERP server and its database.
- The quality system and batch records.
- The warehouse system and raw material balances.
- A file share holding production recipes and line calibrations.
What had been tried before it reached us
- Trying to run the line manually from old printed work orders.
- Restoring an ERP copy onto the same server before the environment was known to be clean.
- Opening an encrypted file in the warehouse application to test whether it still worked.
The route
- 01
Separating office from production network
Every trust path between the two networks was stopped before any examination, because the first risk was encryption reaching the control stations.
- 02
Protecting what was untouched
The weekly offline copy was isolated immediately, before anyone connected it looking for a single file.
- 03
Ordering by impact on downtime
Systems were ordered by what prevents the line from running rather than by size: work orders first, then quality, then warehouse balances.
- 04
The database before the files
The ERP database file was examined: fully or partially encrypted, and whether the transaction log was intact enough to roll state back.
- 05
Handover in stages
What restarts production was delivered first into a clean environment, and the rest followed.
The outcome
What came back
- The ERP database from the weekly offline copy, with a gap of several days.
- Quality records from report exports that had been written to a different folder.
- Warehouse balances, rebuilt from movements documented in the recovered ERP.
What did not
- Custom production recipes edited after the last weekly copy.
- Line calibrations reset days before the incident and never written down.
- Attachments on quality records for the final week's batches.
What would have changed the outcome
- Frequent copies of configuration and calibration files, not only of the large databases.
- A monitored buffer zone between the office and production networks.
- A written and tested manual operating plan that allows hours of running without systems.
Next step
Start free assessmentIsolate the device and keep the ransom note.
Send the file extension, the ransom note and a description of the affected devices. We assess the case without inaccurate promises.