The Construction Company That Was One Ransomware Email Away From Losing Everything

No email filtering. No phishing training. No endpoint protection. Here's what that looked like and what we did about it.

A commercial construction company in the Inland Empire about 25 employees, mostly field crews with a small office staff reached out to us after hearing about another construction company in their network that got hit by ransomware. That company lost access to every file on their server for two weeks and ended up paying a five figure ransom to get their data back.

Our client's reaction was honest: "We have no idea if that could happen to us. Can you just tell us where we stand?"

So we did an assessment. And what we found was a textbook example of how small businesses end up vulnerable not through negligence, but through never having anyone look at the full picture.

What the assessment revealed

Their email had no filtering beyond what comes standard with their basic email plan. No advanced threat protection. No scanning of attachments for malicious content. Every phishing email that was well crafted enough to avoid the default spam filter landed directly in their employees' inboxes.

Nobody on the team had ever received phishing awareness training. They didn't know what to look for. They didn't know that the email that looks like it's from their bank might not be from their bank. They didn't know that clicking a link in a fake invoice could silently install software that encrypts every file on the network.

Their computers had the antivirus that came with Windows and nothing else. No endpoint detection. No monitoring. No alerts. If something malicious did get installed, nobody would know until the damage was already done.

And their backups? They had one. An external hard drive plugged into the server. Connected to the same network. Which means if ransomware hit, it would encrypt the backup too. They'd lose everything the original files and the only copy.

The gap between "we're probably fine" and "we're completely exposed"

The owner wasn't careless. He'd just never been told any of this. Previous IT support a freelancer who came in as needed had set up the basics and moved on. Nobody had ever sat down with him and said, "Here are the five specific things that could take your business offline, and here's what we need to do about each one."

That's the gap. Not technical sophistication. Communication. Someone who explains the risk in plain English and then actually fixes it.

What we put in place

We started with email. We upgraded their email plan to include advanced threat protection real time scanning of attachments and links, impersonation detection and quarantine for anything suspicious. This alone blocks the vast majority of phishing attempts before anyone ever sees them.

We deployed endpoint protection on every computer. Not just antivirus behavioral monitoring that watches for suspicious activity and alerts our team in real time. If something does get through email filtering, this is the second line of defense.

We ran a phishing simulation. Two weeks after the training, we sent a simulated phishing email to the entire company. Forty percent of the staff clicked. That number sounds scary, and it is but it's also completely normal for a first test. Three months later, after ongoing training and periodic simulations, the click rate dropped to under eight percent.

We rebuilt their backup. Cloud based, encrypted, stored offsite, disconnected from the local network so ransomware can't reach it. Tested quarterly to confirm we can actually restore from it.

Where they are now

Six months after the initial assessment, this company went from being completely exposed to having a layered security posture that would stop the vast majority of attacks targeting businesses their size.

The owner told us the thing he appreciated most wasn't any specific tool it was the fact that someone finally explained all of this to him in a way that made sense and then actually handled it.

That's the job. Not selling fear. Not drowning people in jargon. Just protecting businesses that don't have a full time security team because they shouldn't need one to be safe.

Next
Next

Why Your Office WiFi Is Terrible (And What to Actually Do About It)