How a preventable ransomware attack ended a pharmaceutical distributor. Based on a real Cyber Armed Security engagement.
We gave a mid-sized UK pharmaceutical distributor a complimentary Open-Source Intelligence (OSINT) review, the same passive, non-intrusive assessment we use to show organisations their real exposure.
The findings were significant. Exposed credentials, unsecured infrastructure, and a public digital footprint that would give a real attacker more than enough to plan an intrusion. We shared this openly: this organisation had the profile of an active, realistic ransomware target.
We proposed a full penetration test and remediation programme to close the gaps we had found, and briefed the executive team on why it mattered. After consideration, the decision was made not to proceed.
Part of that briefing included a detail specific to the time of year: attackers often target the Christmas period deliberately, knowing that reduced staffing and slower monitoring give them more room to operate undetected. We raised this as a realistic possibility worth planning around.
"We shared what we'd found, what it would take to fix, and why timing mattered. The business chose to hold off."
We deliver a free OSINT review, identify serious exposure, and brief leadership directly on the risk.
We propose a full penetration test and remediation plan, including a note on the added risk around the Christmas period. The organisation decides not to proceed at that time.
The organisation is hit by a ransomware attack while staffing and monitoring are at their lowest. Systems are encrypted and operations grind to a halt.
They come back to us to help contain and respond. Alongside the ransom demand itself, regulatory penalties for the resulting data exposure add significantly to the financial impact.
The combined weight of the ransom, recovery costs, and regulatory fines proves unrecoverable. The business ceases to operate.
This wasn't a story about being caught out by the unknown. The exposure had been identified, the fix had been costed, and the timing risk had been discussed.
Ransomware groups deliberately target the periods when defenders are stretched thinnest. Industry-wide data shows just how consistent that pattern is.
of ransomware attacks in the past year struck on a weekend or holiday, when offices are running skeleton crews.
of organisations cut security operations staffing by half or more during these exact windows.
eliminate security monitoring entirely over holidays and weekends, no one watching at all.
of attacks follow a period of organisational disruption, a merger, acquisition, or round of layoffs, where focus is already elsewhere.
Most organisations that suffer a serious incident are not oblivious. Somewhere in the business, the risk was known. What separates outcomes is whether the gap between knowing and closing was ever actually crossed.
An attacker can profile your organisation from public data alone, without touching a single system. That work costs them almost nothing.
Holidays and shutdown periods are chosen on purpose, because reduced staffing means longer dwell time before anyone notices.
The ransom is rarely the whole bill. Recovery, downtime and regulatory penalties for exposed data stack on top of it.
An OSINT review is passive, needs no access to your systems, and turns around in seven days. It's the simplest place to start.
Tell us your domain, and we'll show you what's already public.