York law firm contains an out-of-hours ransomware attempt in 11 minutes
A 52-staff York law firm contained an out-of-hours ransomware attempt in 11 minutes using 24/7 managed detection and response, with zero files encrypted, zero client data exfiltrated and no business downtime.
A partner's credentials were harvested through a lookalike Microsoft login page. At 22:47 on a Sunday, the attacker attempted lateral movement toward the document management server. The SOC isolated the affected devices before encryption began.
Client: 52-staff commercial law firm. Name withheld under our confidentiality terms.
At a glance
- Client
- 52-staff commercial law firm
- Sector
- Legal
- Location
- York, North Yorkshire
- Size
- 52 employees, 2 offices
- Services
- 24/7 SOC (MDR), EDR, Incident Response
- Timeline
- Detection to containment: 11 minutes
- Headline result
- 11 minutes — From first alert to full containment
Measured results
- From first alert to full containment
- 11 minutesFrom first alert to full containment
- Files encrypted
- 0Files encrypted
- Client data exfiltrated
- 0Client data exfiltrated
- Business downtime on Monday morning
- 0 hoursBusiness downtime on Monday morning
The challenge
- Client confidentiality obligations meant any data exfiltration would be a reportable and reputational event.
- Previous protection was signature-based antivirus with no out-of-hours monitoring.
- The firm's IT support was business-hours only, Monday to Friday.
- Lexcel and client due-diligence questionnaires increasingly asked about 24/7 monitoring.
What we did
- 1
Deployed EDR agents across all laptops, desktops and servers, with behavioural detection rather than signatures alone.
- 2
Onboarded the estate to the 24/7 UK SOC, including Microsoft 365 sign-in and identity telemetry.
- 3
Agreed containment authority in advance so the SOC could isolate a device out of hours without waiting for approval.
- 4
On the night: SOC analysts saw impossible-travel sign-in, credential reuse and suspicious process execution, isolated two endpoints and disabled the compromised account.
- 5
Forced password reset and MFA re-registration, then verified no data had been exfiltrated.
- 6
Delivered a written post-incident report and closed the phishing route with conditional access policies.
The outcome
- The firm opened as normal on Monday with no client-facing impact and no notifiable breach.
- Conditional access now blocks sign-in from outside approved countries and unmanaged devices.
- 24/7 monitoring evidence is supplied directly in client due-diligence questionnaires.
- The post-incident report satisfied the firm's insurer without a claim being made.
“It happened at eleven o'clock on a Sunday night. Nobody here would have seen it until Monday, and by then it would have been a very different conversation with our clients.”
The concepts behind this engagement
Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.
Where this fits in what Complete Cyber Security does
FAQ
Questions about this engagement
The questions businesses in a similar position ask most often before starting.
What does MDR do that antivirus and EDR alone do not?
+
EDR provides the telemetry and the ability to isolate a device; MDR provides the humans who watch it around the clock and act. In this incident the technical detection fired at 22:47 on a Sunday. An unmonitored EDR console would have queued that alert until Monday morning, by which point encryption and exfiltration would have completed. The SOC analyst validated the alert against sign-in telemetry, confirmed it was not a false positive, and used pre-agreed containment authority to isolate two endpoints and disable the account. The technology found it; the staffed service is what stopped it.
Why agree containment authority in advance?
+
Because the time lost seeking approval at night is the time an attacker uses to move laterally and reach a file server. Pre-agreed authority defines exactly what the SOC may do without calling you: typically isolate an endpoint from the network, disable a compromised user account, and kill a malicious process. It does not extend to deleting data, rebuilding machines or changing configuration. The trade-off is that a false positive can briefly isolate a working laptop, which is an inconvenience measured in minutes and reversible with one click. Weighed against a firm-wide encryption event, the trade is straightforward.
Does a law firm of 52 staff really need 24/7 monitoring?
+
Attackers deliberately act outside business hours, and most SME ransomware detonates at night or over a weekend precisely because nobody is watching. For a law firm the calculation is sharper than headcount suggests: the value at risk is client confidentiality, professional obligations and the ability to keep working, not the replacement cost of hardware. Client due-diligence questionnaires and Lexcel assessments increasingly ask directly whether monitoring is continuous. At SME scale a shared, UK-staffed SOC costs a fraction of hiring even one in-house analyst, which is why it is now the normal answer rather than an enterprise one.
Related case studies
Manufacturing
Leeds manufacturer passes Cyber Essentials Plus first time to win a supply-chain contract
Read moreConstruction
Northallerton construction firm recovers from a server failure in under four hours
Read moreEducation

