Legal York, North Yorkshire 52 employees, 2 offices Detection to containment: 11 minutes

York law firm contains an out-of-hours ransomware attempt in 11 minutes

A 52-staff York law firm contained an out-of-hours ransomware attempt in 11 minutes using 24/7 managed detection and response, with zero files encrypted, zero client data exfiltrated and no business downtime.

A partner's credentials were harvested through a lookalike Microsoft login page. At 22:47 on a Sunday, the attacker attempted lateral movement toward the document management server. The SOC isolated the affected devices before encryption began.

Client: 52-staff commercial law firm. Name withheld under our confidentiality terms.

At a glance

Client
52-staff commercial law firm
Sector
Legal
Location
York, North Yorkshire
Size
52 employees, 2 offices
Services
24/7 SOC (MDR), EDR, Incident Response
Timeline
Detection to containment: 11 minutes
Headline result
11 minutes — From first alert to full containment

Measured results

From first alert to full containment
11 minutesFrom first alert to full containment
Files encrypted
0Files encrypted
Client data exfiltrated
0Client data exfiltrated
Business downtime on Monday morning
0 hoursBusiness downtime on Monday morning

The challenge

  • Client confidentiality obligations meant any data exfiltration would be a reportable and reputational event.
  • Previous protection was signature-based antivirus with no out-of-hours monitoring.
  • The firm's IT support was business-hours only, Monday to Friday.
  • Lexcel and client due-diligence questionnaires increasingly asked about 24/7 monitoring.

What we did

  1. 1

    Deployed EDR agents across all laptops, desktops and servers, with behavioural detection rather than signatures alone.

  2. 2

    Onboarded the estate to the 24/7 UK SOC, including Microsoft 365 sign-in and identity telemetry.

  3. 3

    Agreed containment authority in advance so the SOC could isolate a device out of hours without waiting for approval.

  4. 4

    On the night: SOC analysts saw impossible-travel sign-in, credential reuse and suspicious process execution, isolated two endpoints and disabled the compromised account.

  5. 5

    Forced password reset and MFA re-registration, then verified no data had been exfiltrated.

  6. 6

    Delivered a written post-incident report and closed the phishing route with conditional access policies.

The outcome

  • The firm opened as normal on Monday with no client-facing impact and no notifiable breach.
  • Conditional access now blocks sign-in from outside approved countries and unmanaged devices.
  • 24/7 monitoring evidence is supplied directly in client due-diligence questionnaires.
  • The post-incident report satisfied the firm's insurer without a claim being made.
It happened at eleven o'clock on a Sunday night. Nobody here would have seen it until Monday, and by then it would have been a very different conversation with our clients.
Practice Manager, commercial law firm, York

The concepts behind this engagement

Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.

FAQ

Questions about this engagement

The questions businesses in a similar position ask most often before starting.

What does MDR do that antivirus and EDR alone do not?

+

EDR provides the telemetry and the ability to isolate a device; MDR provides the humans who watch it around the clock and act. In this incident the technical detection fired at 22:47 on a Sunday. An unmonitored EDR console would have queued that alert until Monday morning, by which point encryption and exfiltration would have completed. The SOC analyst validated the alert against sign-in telemetry, confirmed it was not a false positive, and used pre-agreed containment authority to isolate two endpoints and disable the account. The technology found it; the staffed service is what stopped it.

Why agree containment authority in advance?

+

Because the time lost seeking approval at night is the time an attacker uses to move laterally and reach a file server. Pre-agreed authority defines exactly what the SOC may do without calling you: typically isolate an endpoint from the network, disable a compromised user account, and kill a malicious process. It does not extend to deleting data, rebuilding machines or changing configuration. The trade-off is that a false positive can briefly isolate a working laptop, which is an inconvenience measured in minutes and reversible with one click. Weighed against a firm-wide encryption event, the trade is straightforward.

Does a law firm of 52 staff really need 24/7 monitoring?

+

Attackers deliberately act outside business hours, and most SME ransomware detonates at night or over a weekend precisely because nobody is watching. For a law firm the calculation is sharper than headcount suggests: the value at risk is client confidentiality, professional obligations and the ability to keep working, not the replacement cost of hardware. Client due-diligence questionnaires and Lexcel assessments increasingly ask directly whether monitoring is continuous. At SME scale a shared, UK-staffed SOC costs a fraction of hiring even one in-house analyst, which is why it is now the normal answer rather than an enterprise one.

Related case studies

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way