CRITICAL INFRA
Loading critical CVEs…
ALL EXPLOITED
Loading…

Case study: an accounting firm back on its feet after a ransomware attack

📅 2026-09-19 · Cyber Immunity

An accounting firm called us after a ransomware attack had encrypted their files and stopped their work. We rebuilt everything securely, with ransomware-resistant backup and continuous monitoring. Here is exactly what we did — explained both technically and in plain terms.

The situation: work stopped overnight

A ransomware attack encrypted the firm's files and locked their SAGA accounting application. They simply could not work — no access to data, with tax deadlines approaching. The causes were classic: no real protection at the network edge, a fragile backup (easy to encrypt too), and nobody watching the attack as it happened.

What we built

We designed a simple infrastructure, but with layered defense: filtering at the internet edge, the accounting app isolated, backup that an attack cannot delete, and round-the-clock monitoring.

Internetatacuri MikroTikGeoIP + Q-Feeds server Hyper-V VM 1 — SAGAcontabilitate VM 2 — Linuxloguri + OpenVPN 2FA server vechibackup + replicare VM + monitorizare 24/7 cu Checkmk pe serverele Cymmunity (Hetzner)

1. A "doorman" at the network entrance

Technical: a MikroTik router with GeoIP filtering, Q-Feeds reputation feeds and dynamic lists that automatically block, for 60 minutes, any internet address attempting an attack (scanning, password brute-force, exploit).

What it means for you: any break-in attempt from the internet is stopped automatically at the door, no matter which country it comes from. It never reaches your computers and server.

2. The SAGA app, isolated and protected

Technical: a Hyper-V server with two separate virtual machines — one dedicated solely to the SAGA accounting app, the other a Linux server for log monitoring and remote access via OpenVPN with two-factor authentication (Google OTP code on the phone).

What it means for you: SAGA runs isolated, shielded from the rest of the network. You can work from home safely: besides the password, you need a code that appears on your phone — so nobody gets in as you, even if they learn the password.

3. Backup and copies that start immediately

Technical: the old physical server was turned into a backup and replication target for the virtual machines — recent copies, kept separate from the main system.

What it means for you: if the new server fails or a new attack gets through, we have recent copies that start in minutes. You do not lose data and are not stuck for days.

4. Someone watching 24/7

Technical: the firm's entire infrastructure is now monitored with Checkmk, installed on Cymmunity's own servers in Hetzner — availability, disk space, services, backup status and security events, with alerting.

What it means for you: we see the problem before you feel it. If something is wrong (a full disk, a down service, an attack attempt), we get an alert and act — we do not wait for work to stop.

The result

Work resumed securely. Data is protected, internet attacks are blocked automatically, remote access is safe, and everything is under continuous monitoring. The firm works calmly, with tax deadlines met — and a clear plan if anything happens again.

Why it matters for an accounting firm

An accounting firm holds the data of dozens or hundreds of clients, has fixed tax deadlines and legal data-protection duties. A single attack can stop you at the worst moment — and cost you clients and trust. Protection is no longer a luxury, but part of operating. The solution above is affordable even for a small firm, and we adapt it to your size.

Let's discuss your project →