A Friday, 11:40 p.m., the call comes in: the billing server’s files have a strange extension and there’s a ransom note on the desktop. The organization was not a CROC client and had no retainer. What follows is the reconstruction of the first four hours, with the affected party’s permission and no identifying data.
Hour 0 to 1: the decisions already made
Before calling us, the IT team did what instinct dictates and forensics laments: powered off the affected servers. Volatile memory, running processes, connections, encryption keys in some cases, was lost. The first instruction of the call was to touch nothing else: isolate from the network yes, power off no.
FIRST HOUR · ACTUAL SEQUENCE
23:40 incoming call · initial triage
23:55 preliminary scope: 1 server + 12 workstations
00:10 network isolation of the affected segment
00:25 variant identified from the note
00:40 initial-access hypothesis: VPN without MFA
00:55 emergency credentials rotated
Hour 1 to 4: containing without evidence
Without prior telemetry, every basic question, since when are they inside? what did they take?, required hours of reconstruction from the logs that survived. The VPN without a second factor turned out to be the access; it had been exposed for months. Encryption was contained to the isolated segment and restoration started from verified backups that same night.
The retainer doesn’t do magic. It makes the 11:40 p.m. call not start from zero.
WHAT A RETAINER WOULD HAVE CHANGED
Agreed runbook (nobody powers off servers), telemetry already connected (scope answered in minutes, not hours), pre-authorized remote access (containment within the first hour) and agreed rates (nobody negotiates prices during a crisis). This case’s four hours would have shrunk to under one.
The organization is today a CROC client with a retainer. Its annual tabletop reproduces, with its own team, exactly this sequence.