Sector: Multi-channel retail | Stores: 46 | Peak share of annual revenue: 31%
The situation
At 02:40 on a Thursday, encryption began across the client’s warehouse management and e-commerce fulfilment systems. Eight days remained before the trading week that accounts for almost a third of annual revenue.
Hour 0 to 6: containment
The on-call manager declared an incident within eleven minutes using the one-page trigger card issued after the previous year’s simulation. Affected segments were isolated, the insurer’s breach hotline was called before any internal escalation, and appointed forensic responders were engaged under the policy rather than sourced under pressure.
Hour 6 to 18: parallel recovery
Rather than waiting for forensics to complete, the team began rebuilding fulfilment on clean infrastructure from offline backups tested four months earlier. Stores were moved to a documented manual process that had been rehearsed once and never used in anger.
Hour 18 to 36: restoration
- E-commerce order capture restored at hour 21 on segregated infrastructure.
- Warehouse dispatch resumed at hour 29 at roughly 60% throughput.
- Full throughput reached at hour 36, six days before peak trading began.
The result
- No ransom paid. Recovery achieved entirely from backups.
- Stores remained open throughout on manual processes.
- Business interruption loss quantified and settled within the policy, with forensic and legal costs covered from hour one.
- Peak trading week delivered ahead of the prior year.
Why it worked
Nothing about the response was improvised. The trigger card, the tested backups, the pre-agreed responder panel and the manual store process all existed before the attack. The single most valuable decision — calling the insurer before anyone else — had been rehearsed in a ninety-minute desktop exercise the previous autumn.