A commercial builder blocks a ransomware attempt after security uplift
01The challenge
95 staff, sites everywhere, laptops that lived in utes and a lot of subcontractor email. The builder had antivirus, a firewall and a strong belief that it was too small to be a target.
Its insurer disagreed and the renewal questionnaire was due in six weeks.
02The approach
Endpoint detection and response on every device, email filtering, enforced MFA and a 24/7 security operations centre. Awareness training and phishing simulation for all staff, because in the ASD Annual Cyber Threat Report 2024-25 business email compromise fraud resulting in financial loss made up 15% of cybercrime reported by Australian businesses, with email compromise without financial loss accounting for a further 19%.
Documented evidence produced alongside the controls, so the insurer questionnaire became a retrieval exercise.
03The results
Four months later the SOC flagged anomalous encryption activity on a site laptop at 11pm on a Saturday. The device was isolated within minutes, the account disabled, and the attempt went no further.
No ransom demand, no data loss, no notifiable data breach, and a renewal that completed without a scramble.
By the numbers
The outcomes that mattered.
The service behind this
Cyber Security
More proof
Related case studies.
Start here
Want results like these?
A no-obligation conversation about your infrastructure, security posture and operational risk. No lock-in, and a response within one business day.