Rebuilding after a ransomware attack

2025 · Waste management · Bavaria

The on-premise Windows server was encrypted and operations had stopped. What made the difference between recovery and an existential question was a decision taken long before: a backup at a second location, out of the attacker’s reach. Without it, none of what followed would have been possible.

We did not restore the server in its old location but moved it straight into a cloud environment hosted in Germany – recovery and migration in one go, so the downtime was not paid for twice. At the same time we replaced the network architecture that had failed to stop the attack: pfSense at the site and in the cloud, an OpenVPN link between them, and the same solution for home office access.

A case like this is also the most honest test of a backup strategy. It shows whether recovery was rehearsed or merely planned, and whether anyone knows in which order systems have to come back. What stands afterwards is more resilient than what stood before – but it is not a route anyone should have to take.

Technologies used

Microsoft Windows / Microsoft Windows Server, Netgate pfSense, OpenVPN

Every tool we work with is listed in the tech stack.

Scope

Facing a similar task? Let’s talk about it – or see how we work in IT security and compliance.

Arrange a conversation All projects