Étude de cas MiliSec — Virtual CISO
How a Virtual CISO contained ransomware, preserved business continuity, and turned the incident into a NIS2/DORA compliance roadmap.
Contexte
A mid-market services firm (400 staff, £50M turnover) discovers mass encryption on Monday morning. The BCP is activated but IT lacks documented runbooks.
Intervention
The Virtual CISO leads the war room: segmentation, forensics, cyber-insurance activation, documented negotiations with the ransomware gang.
Résultat
72-hour recovery, £0 ransom paid, evidence preserved for ICO/NCSC notifications within NIS2/DORA timelines.
Leçon clé
A tested incident plan and an on-call Virtual CISO cut resolution time by 80 %.
<!-- TODO editor: review, add metrics/stats if available, then set status: published -->