Netwrix > Case Studies > Rapid Ransomware Recovery: A Case Study of 4sinfosec and Netwrix

Rapid Ransomware Recovery: A Case Study of 4sinfosec and Netwrix

Netwrix Logo
Technology Category
  • Cybersecurity & Privacy - Malware Protection
  • Infrastructure as a Service (IaaS) - Backup & Recovery
Applicable Industries
  • Finance & Insurance
Use Cases
  • Security Claims Evaluation
  • Structural Health Monitoring
About The Customer
4sinfosec is a managed service provider (MSP) based in Florida, US. It provides IT services to healthcare, finance, and government organizations. Customers can opt for full-time support if they don’t have internal IT staff, or engage the MSP for complex projects where advanced expertise is needed. 4sinfosec has a team of 17 engineers and 11 support professionals. In this case, their client was a US-based insurance company with 500 employees, which had suffered a severe ransomware infection.
The Challenge
4sinfosec, a managed service provider (MSP), was tasked with assisting a US-based insurance company with 500 employees in recovering from a ransomware infection. The infection had spread from the insurance company's parent company, which had 50,000 employees, due to domain trusts and network integration. The ransomware had encrypted 80% of the insurance company’s servers, rendering all services completely down. The parent company was even more severely affected, with 100% of its servers infected. The challenge was to assess the damage and restore the client's operations as quickly as possible.
The Solution
The solution came in the form of Netwrix Auditor, a tool that 4sinfosec was familiar with. The tool provided detailed reports on unusual behavior, enabling the team to identify all compromised accounts and track the ransomware’s actions almost step-by-step. This allowed them to identify the root cause within 30 minutes, a process that could have taken a week without Netwrix Auditor. The tool also provided a clear picture of the damage, from a holistic view of which servers were encrypted down to exactly which files were affected. This actionable intelligence enabled the team to prioritize recovery efforts to minimize downtime for the client. The quick recovery demonstrated the true value of Netwrix Auditor to the customer, building trust in the MSP. The customer was so impressed by how the 4sinfosec team handled the ransomware that they decided to engage them full time to manage their whole ecosystem.
Operational Impact
  • The use of Netwrix Auditor not only expedited the recovery process but also demonstrated its value as a forensics tool to the customer. The customer, who had previously used the solution only to report on the number of users and files, was astonished to learn that it could also be used as a forensics tool. The impressive handling of the ransomware attack by the 4sinfosec team led the customer to engage them full time to manage their whole ecosystem. This has opened up new opportunities for 4sinfosec to enhance the customer's security by using Netwrix solutions to classify their data, implement a least-privileged model, and perform regular risk assessment and mitigation.
Quantitative Benefit
  • Reduced incident investigation time from potentially a week to just 30 minutes
  • Minimized downtime by prioritizing recovery efforts based on actionable intelligence
  • Secured a new permanent customer for 4sinfosec

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.