We Recovered This Law Firm From Ransomware in 2 Hours
Saturday 2am: crypto-locker hit a 15-user law firm in Pretoria. Monday 9am: back online, zero ransom paid, full audit trail for insurers.
2:13am Saturday: Our monitoring flagged 847 file changes in 4 minutes on their file server. Automated containment isolated the server.
What happened: An associate opened a fake “Sheriff summons” attachment. It bypassed basic antivirus and started encrypting their conveyancing files.
Why they recovered:
- 3-2-1 backups: local NAS + immutable cloud copy in South Africa
- Endpoint protection with ransomware rollback - we rolled back 22 workstations
- M365 Safe Attachments would have blocked it - we enabled it after
Result: 2 hours to restore 1.2TB, Monday staff worked normally. Insurer accepted our incident report for POPIA compliance. No ransom, no data leak notification needed.
Lesson for 5-50 staff firms: OneDrive is not a backup. You need versioned, tested restores. Our R950 Health Check tests a real file restore.
Want this as a checklist?
Download the free PDF and share with your team. No email required.
Secure Your Microsoft 365 Before Hackers Do
Book the R950 POPIA Health Check — 2hr on-site, plain-English report.
