Leading Ransomware Recovery
On a Saturday morning in September 2023, a Play ransomware variant encrypted virtually every Windows system across the company in about two hours. More than 500 endpoints and over 125 virtual servers were down before 8 a.m. I was the Service Desk Supervisor on paper. Within the first hour I was directing the technical response, and I ran it through recovery and the hardening that followed. We paid no ransom, lost no critical production data, and had roughly 80% of operations back within 24 hours. The work during and after the incident is what moved me into an infrastructure leadership role the following year.
Building Resilient Backups
The backup redesign was finished about a year before the ransomware incident that tested it. At the time it looked like a sensible refresh tied to a Veeam version upgrade. In hindsight it was the single decision that made recovery possible, and the difference between a hard week and a company-ending loss.