a

Client Success Story

Powernode Computer Inc.

Incident to Infrastructure: A Full-Scope Recovery

Facts at a Glance

Manufacturing and Distribution Services / 2024 / Ontario
\

Project Scope

  • Incident Response
  • Infrastructure Rebuild
  • Cloud Enablement
  • Microsoft 365
  • Data Recovery
Ransomware attack, all on-prem services, workstations affected, 100% of production systems offline

Within 96 hours, Synchroworks transformed a total operational shutdown into a secure, functioning network – restoring core systems, rebuilding infrastructure, and elevating cyber maturity.

The Challenge

Powernode Computer Inc (PNC) experienced a full-scale ransomware attack that encrypted all on-premise servers and workstations, bringing production to a standstill. The legacy environment lacked antivirus, endpoint protection, and had an end-of-life firewall, leaving the network exposed. Initial assessments confirmed that 34 systems were encrypted, including core infrastructure such as Sage ERP and SQL databases.

PNC needed more than containment. It required a full rebuild that would not replicate legacy weaknesses.

Business Impact

The attack brought PNC’s operations to a standstill:

  • 100% production downtime
    No access to ERP, accounting, or order systems
  • Data integrity compromised
    One backup fully encrypted; another partially usable
  • Customer and partner disruption
    Inability to fulfill orders or communicate securely
  • Insurance and legal exposure
    Urgent need for forensic preservation and documentation

Without immediate intervention, PNC risked prolonged downtime, reputational damage, and significant financial loss.

Opportunities
and Solutions

Synchroworks mobilized immediately after the initial alert to assess the situation and contain the threat. Our team’s dual objective was to halt the active attack and establish a secure foundation for rebuilding PNC’s infrastructure without reintroducing the vulnerabilities that led to the breach.

Immediate Containment and Triage

Within hours of the initial alert, Synchroworks advised PNC to disconnect internet access, shut down all endpoints, and isolate compromised systems. On-site analysts quickly confirmed that the Trinity Locker Group had deployed ransomware across the environment, verifying full encryption of critical infrastructure including Sage ERP and custom MySQL applications. To support insurance and legal proceedings, Synchroworks preserved the forensic trail by physically isolating systems and collecting digital evidence. Secure, out-of-band communication channels were established using Microsoft 365, enabling coordinated incident response while maintaining business continuity.

Infrastructure Rebuild and Network Hardening

Recognizing the opportunity to rebuild from a clean slate, Synchroworks deployed a modern, security-first infrastructure. A Sophos XGS 2100 firewall and Cisco Layer 3 switches were installed to establish a segmented, zero-trust network architecture – limiting lateral movement and reducing exposure. Simultaneously, endpoint protection and endpoint detection and response (EDR) solutions were deployed across all clean workstations and servers. This replaced the previously absent antivirus and malware defenses, creating a unified and proactive security layer throughout the environment.

Microsoft 365 Security Review and Recovery

Although the ransomware did not compromise PNC’s Microsoft 365 tenant, our team conducted a full security audit to eliminate any risk of lateral compromise. This included tenant-wide password resets, enforcement of multi-factor authentication, conditional access policy reviews, and a comprehensive audit of risky sign-ins. To maintain business operations during the rebuild, Synchroworks provisioned a secure SharePoint environment for file collaboration. Cloud-based backups were also implemented to ensure redundancy and support future recovery needs.

Data Recovery and Application Restoration

PNC’s on-site backups were partially affected. Synchroworks wiped the compromised server and reinstalled a clean operating system, then restored essential business systems using fresh virtual machines. In collaboration with PNC’s Sage partner, the team rebuilt the ERP environment and imported the most recent uncorrupted SQL backups, restoring core functions such as accounting and order management with minimal data loss.

Post-Incident Security Improvements

In the weeks that followed, our team implemented a series of long-term security enhancements to strengthen PNC’s cyber resilience:

  • A structured patch management plan
  • Monthly security reviews
  • Endpoint monitoring and alerting
  • Security awareness training for staff
  • Development of a formal incident response plan and disaster recovery strategy

Results

Within 96 hours of first contact, Synchroworks transitioned PNC from a state of total operational paralysis to a secure, functioning core network. By the end of the first week, full ERP and file services were restored, enabling order fulfillment to resume ahead of the insurer’s mandated deadline.

PNC didn’t just recover – it rebuilt its systems on a foundation aligned with modern cybersecurity best practices. What started as a major disruption became a catalyst to strengthen operations and modernize IT for the long term.

Key benefits delivered by Synchroworks:

Zero Reinfection

No malicious callbacks or residual threats were detected following the cutover to the new firewall and EDR systems. The rebuilt environment remained clean and stable throughout post-incident monitoring.

Operational Recovery

Core business systems, including Sage ERP, SQL databases, and file services, were fully restored within one week. This rapid turnaround minimized disruption to customers and partners and preserved business continuity.

Improved Resilience

Transparent communication, milestone-driven execution, and clear documentation enabled PNC’s leadership to make timely, informed decisions throughout the crisis.

Executive Confidence

The new infrastructure featured segmented network architecture, automated cloud backups, and documented incident response playbooks. These upgrades significantly reduced the likelihood and potential impact of future attacks.

Empower your business for success with Synchroworks’ comprehensive IT consulting services.
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.