All articles

Ransomware

Friday 18:47 to Monday 08:00: Anatomy of a Ransomware Attack on a 50-Person Company

An hour-by-hour reconstruction of a ransomware attack on a 50-person company: from the Friday click to the Monday ransom note, and where it is really decided.

Sylvio Sorel··5 min read
A brass padlock and a rolled-up banknote resting on a computer keyboard.

The ransom note is the last thing that happens, not the first. By the time it lands on a screen on Monday morning, the attackers have been inside for the best part of three days — moving, copying, deleting — and the decisive moments are already behind you. A ransomware attack on a small company is not an event; it is a weekend.

We reconstruct one here, hour by hour, on a composite 50-person business drawn from real incident patterns. None of the numbers are invented: they come from the 2025 threat reporting of ENISA, Sophos and CrowdStrike. The point is not the technology. It is the timing — and the uncomfortable fact that almost everything that determined the outcome was decided weeks before anyone clicked anything.

The firm

The company is a 50-person industrial-components supplier in eastern France — a profitable, unglamorous business that machines parts for larger manufacturers. It runs a remote-access portal so engineers can reach drawings from the workshop floor and from home. IT is one capable generalist who also handles the phones and the printers. There is a backup; nobody has restored from it in two years. There is no security monitoring after 18:00, because there is no one there after 18:00. This is not negligence. It is the ordinary shape of a 50-person company — and attackers know the shape better than most boards do.

The 61-hour attack timeline The 61-hour timeline — from the Friday-evening click to the Monday-morning ransom note, with the two regulatory clocks that start the moment you become aware.

Friday, 18:47 — the click

The finance assistant is clearing her inbox before the weekend. An email that looks like a supplier invoice asks her to log in to view a “revised payment schedule.” The page is a perfect clone. She enters her credentials. Phishing remains the way in for roughly 60% of intrusions across the EU, according to ENISA’s 2025 Threat Landscape, precisely because it works on a tired person at 18:47 on a Friday. This is the kind of lapse our training and awareness programmes are built to make survivable — because no firewall forgives a valid login.

Friday, 19:16 — breakout

Twenty-nine minutes. That is the average time, per CrowdStrike’s 2026 Global Threat Report, between an intruder’s first foothold and their first lateral move to a second machine. The stolen credentials are sold and handed to a ransomware crew in a median of 22 seconds. By the time the assistant has driven home, someone else is logged in as her, mapping the network, and quietly creating a new administrator account that belongs to no one.

Saturday, 02:00 — reconnaissance

While the workshop sleeps, the intruder reads the company. Where are the file servers. Who has domain-admin rights. Where the accounting system lives. Where the backups are — and, critically, whether those backups are reachable from inside the network. They are. The single most expensive decision this company never made was to keep its backups online, in the same domain, behind the same password as everything else.

Saturday, 23:00 — the backups go first

Modern crews destroy your recovery before they touch your data — it is what turns an incident into a ransom. They delete the backup volumes and the shadow copies. Sophos’s 2025 State of Ransomware found backup availability has fallen to a four-year low, with only 53% of victims able to use backups to recover. The firm has just joined the other 47%, and no one will know until Monday.

Sunday — the quiet theft

No encryption yet. Instead, gigabytes leave the building: drawings, contracts, the HR folder, the customer list. Three in four ransomware attacks now exfiltrate data before encrypting it, because stolen data is leverage even if you restore perfectly. This is double extortion — pay to decrypt, and pay again to stop us publishing. A clean backup no longer buys your silence.

Monday, 04:30 — encryption

In the hours before the early shift, the payload runs across every reachable machine. Encryption itself takes well under an hour; the fastest crews go from first access to full encryption in under four hours, though this one took its time over the weekend for a bigger haul. Files become unreadable. The remote portal goes dark. The phone system, which runs over the same network, goes silent.

Monday, 08:00 — the note

The early shift cannot log in. A text file sits on every desktop with a countdown and a payment address. Only now — 61 hours after the click — does the company “have an incident.” This is the moment most boards imagine the story begins. It is, in truth, the moment the story ends.

The clocks you didn’t know were running

Two regulatory clocks start the instant the firm becomes aware, not the instant it is ready. If the company is in scope of NIS2 — and as a supplier to larger manufacturers it may well be — Article 23 requires an early warning to the national authority within 24 hours, a fuller notification within 72 hours, and a final report within one month. Because personal data left the building, GDPR Article 33 adds its own 72-hour notification to the data protection authority. Both deadlines now fall on a leadership team that cannot open its own email, has no rehearsed plan, and has never spoken to a breach lawyer. Knowing how these obligations interlock is the quiet half of NIS2 readiness — the half nobody practises until the Monday it is too late.

What would have stopped it Each stage of the attack maps to a control that breaks the chain. None of them can be bought on the Monday.

What actually decided the outcome

Walk the timeline backwards and every stage has a control that breaks it — and not one of them could have been bought on the Monday. Multi-factor authentication on the remote portal stops a stolen password cold. Endpoint detection that someone actually watches turns a 29-minute breakout into a 3 a.m. alert. Backups kept offline and immutable — and tested — survive the Saturday deletion. Network segmentation keeps the phones working while the file server burns. A rehearsed incident-response plan, with the 24- and 72-hour clocks already mapped to named owners, turns Monday from panic into procedure. As we argued in 5 Signs Your Business Has Already Been Compromised, the dangerous gap is rarely the tooling — it is that no one is accountable for noticing. That accountability is exactly what a Virtual CISO exists to hold: not to run the night shift, but to make sure the decisions that decide a weekend like this one are taken in the calm months before it.

The attack was won or lost weeks before the click. The only leverage a 50-person company ever has over a ransomware crew is the set of decisions it made while nothing was wrong.

Sylvio Sorel

CISSP, PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor — founder, Cyber-Management.

Take the next step

Talk to a security practitioner, not a salesperson.

Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.