A Friday night call no IT director wants
At 2:14 AM on a Saturday, the on-call administrator at a 250-bed regional hospital opened a ticket: every Windows endpoint across two campuses was displaying a ransom note. The EHR was down. Imaging was offline. Pharmacy was on paper.
Triage, contain, recover - by the playbook
Within 22 minutes of the call, our IR team was on a bridge with the CIO, CFO, and General Counsel. We isolated the domain, preserved key evidence, engaged the hospital's cyber insurance breach coach, and started parallel restoration of clinical priority systems from immutable backups.
- Domain controllers isolated and rebuilt from clean baselines
- Immutable backups validated and clinical systems restored first
- Threat actor evicted from environment within 36 hours
- Coordinated communications with HHS, state agencies, and patients
- No ransom paid; no PHI confirmed exfiltrated
Back online by Monday morning
Clinical operations returned to full electronic charting within 72 hours of detonation. Insurance covered the engagement. The hospital adopted our managed SOC, EDR, and immutable backup program - and has not had a security incident since.
"Within an hour we knew exactly what was happening, what we needed to do, and who was doing it. I have never been so glad to have a vendor on retainer."

