Containing an active ransomware attack across 2,400 assets in two weeks.

The Trigger

An active ransomware incident. 2,400 assets encrypted, a ransom demand issued, and data exfiltrated. Business operations completely crippled. The organisation called Theos.

The Environment

A major Philippine real estate and commercial group operating across a large on-premises and hybrid environment. No prior relationship with Theos. The call came during an active incident.

The Theos Approach

Incident Response

Theos activated incident response immediately. Forensic investigation identified patient zero within two weeks. The threat was contained, eradicated, and the full environment stabilised. Coverage continued through the Christmas period and into the New Year until the environment was confirmed clean.

Transition to Managed Security

In early January, the organisation engaged Theos on a long-term managed security contract. The programme covers TDR across assets, identity, cloud, and business applications; dark web monitoring; annual penetration testing; DFIR retainer; tabletop exercises and board briefings; and significant infrastructure hardening across collaboration and workspace environments.

"

We called Theos during an active ransomware incident. Two weeks later the threat was contained. We have not used another security provider since.

Major Commercial and Real Estate Group, Philippines

The Outcomes

2 weeks
Patient zero identified and threat contained within two weeks of engagement
2,400 assets
Full environment stabilised and confirmed clean before end of year
Multi-year
Long-term managed security contract signed covering every Theos service line
0 recurrence
No repeat incident following full environment hardening and TDR deployment
DICT / BSP
Security programme aligned to Philippine regulatory obligations

LET US HELP YOU!

LET US HELP YOU!