Key Takeaways
- A 45-employee Ontario industrial supplier was encrypted on a Friday evening. The CEO called Fusion Computing at 9pm. Staff were working again Monday morning.
- A six-figure Bitcoin ransom demand was never paid, and every in-scope server, file share and ERP record came back from air-gapped recovery points.
- The way in was a phished credential with no multi-factor authentication (MFA) behind it, the most common ransomware root cause in the 100 to 250 employee band (Sophos, 2025).
- What made Monday possible happened months earlier, when we rebuilt a backup set that was untested and partly corrupt when we inherited it.
Mike Pearlstein is CEO of Fusion Computing and holds the CISSP. He has led Fusion’s managed IT and cybersecurity practice since 2012, serving Canadian businesses across Toronto, Hamilton, and Metro Vancouver.
Ransomware recovery is the work of restoring encrypted systems after an attack without paying the attacker. This ransomware recovery case study follows one Canadian engagement hour by hour, from a Friday 9pm phone call to Monday morning. I have worked this weekend more than once, and this is the version that went right.
Introduction
A 45-employee industrial supply company in Ontario was hit with ransomware on a Friday evening. Every workstation and server displayed a ransom demand. File shares, the enterprise resource planning (ERP) system, the customer database, and 15 years of operational data were encrypted. The Canadian Centre for Cyber Security calls ransomware one of the most disruptive forms of cybercrime facing Canada, and this is what that looks like at 45 seats.

The call reached our on-call line at 9pm. Fusion Computing runs weekend incident response as a standing capability, so isolation started that same evening. My rule on a Friday night is to bound the damage before diagnosing it. This is the anonymized account of that engagement, published with the client’s permission.
The challenge
According to the Canadian Centre for Cyber Security (2025), ransomware is the top cybercrime threat facing Canada’s critical infrastructure. The Centre judges it will almost certainly remain the most impactful cyber threat to Canadian organizations. Industrial distribution sits inside that supply chain.
This company came to us months earlier with a backup that existed mostly on paper. Jobs ran inconsistently, restores were never tested, and part of the set was corrupt when Fusion inherited it. Fusion Computing manages that backup platform now, rebuilt around immutable, air-gapped recovery points with a monthly restore drill booked.
That decision is the whole case study. In our experience the restore drill is the first control a business cuts, because nothing visibly breaks when you skip it. It breaks once, on a Friday night. I have yet to meet an owner in Mississauga or anywhere else who felt the saving was worth it.
“I got the call no business owner wants. Our systems were locked and there was a ransom demand on every screen. Fusion had someone working on it within the hour, and by Monday morning our team walked in, sat down, and got back to work like nothing happened.”
CISSP-led, Canadian-owned, and running weekend incident response since 2012. Get in touch or call 416-566-2845.
Fusion Computing’s ransomware incident response
According to the Canadian Centre for Cyber Security ransomware playbook (ITSM.00.099), segmentation is what lets a defender stop malware spreading between zones of a network. We worked that order on the night. Isolate, map the blast radius, investigate, and only then restore.
Friday 9pm: containment first
The CEO called at 9pm. That same evening every affected system was isolated, network segments were cut, and the compromised account was disabled. We measured that containment window from the first phone call rather than from a first alert, because the company had no endpoint detection running that night. Closing that gap became step two of the rebuild.

Saturday: finding the way in
Our engineers found the entry point on Saturday. A phished credential with no multi-factor authentication behind it. Sophos ranked compromised credentials the most common ransomware root cause in the 100 to 250 employee band in 2025, at 30% of attacks. This client sat just under that band. The detail I keep returning to is that, on the attack path we identified, phishing-resistant MFA would have blocked the password-only credential.
Sunday: restore, then validate
Servers, file shares, and the ERP came back from the air-gapped copies. Each system was validated against a known-clean baseline and checked for persistence before it rejoined the network. I treat restoring fast and restoring clean as two separate jobs, because the second one is what stops a reinfection on Tuesday.
Monday morning: the office opens
Staff walked in at 7am and worked. We measured the outcome at every in-scope server, file share and ERP record restored, and nothing paid against a six-figure Bitcoin demand. In my experience that Monday is the only metric an owner remembers, and the recovery ran across a closed weekend, with staff back at work Monday morning.
Prepared vs unprepared: what would have happened without preparation
According to Sophos’ State of Ransomware 2025, the average cost of recovering from a ransomware attack, excluding any ransom paid, was US$1.53 million. Only 16% of victims were fully recovered inside a day. Backups restored the data in just 54% of incidents, the lowest rate Sophos had recorded in six years.
- The backups would have been the story. Sophos found 38% of organizations whose ransom demand climbed blamed backups that had failed. That is the branch this company was on before the rebuild.
- Recovery would have run in weeks. Only 53% of 2025 victims were fully recovered inside a week. Bare-metal rebuilds fill the difference.
- The payment decision would have been real. The Canadian Centre for Cyber Security states there is no guarantee threat actors will unlock systems or return stolen data after payment, and that they can revictimize you later with the same data.
The Cyber Centre’s guidance on preventing and recovering from ransomware says an incident response plan should be available offline. The systems holding the digital copy are the ones an attacker encrypts first. Ours was on paper that night.
Results and business impact: the 4-step hardening checklist
The business reopened Monday with in-scope systems restored and nothing paid. Forensic review found no evidence of client data exfiltration. Whether a PIPEDA report is required depends on a separate real risk of significant harm assessment, including the sensitivity of the personal information involved and the probability of misuse. Sophos found exfiltration in 28% of 2025 encryption incidents.
Recovery was half the job. What I care about more is the four controls the incident finally unlocked in the weeks after the Ontario restore.
- MFA enforced on every account. On the attack path Fusion identified, phishing-resistant MFA would have blocked the password-only credential path.
- Managed endpoint detection and response on every workstation and server. No endpoint telemetry existed on the night of the attack, which is why the clock started with a phone call.
- A documented monthly restore test on the immutable offsite backups. The recovery points existed before the incident; the recurring test cadence is now documented and proven rather than assumed.
- Quarterly phishing simulations and awareness training. The way in was a person, so the control has to keep meeting people.
Fusion Computing runs those four inside the company’s ongoing managed IT service alongside its cybersecurity services, rather than letting them fade once the crisis passed. The same sequence sits inside our incident response plan template, and you can talk to our team about running it on your environment.
Fusion Computing has protected Canadian SMBs since 2012, under CISSP-led governance, with managed IT and security run as one service.
Why this ransomware recovery mattered
According to the Cyber Centre’s Ransomware Threat Outlook 2025 to 2027, all Canadian organizations are at risk regardless of size or sector. Downtime and recovery cost can decide whether a small business stays commercially viable. My read is simple: this one stayed viable because the restore drill happened first.
Ransomware recovery FAQ: how long it takes and what recovery requires
These are the four questions Canadian owners ask us in the week after an incident. The Cyber Centre’s baseline controls for small and medium organizations open at control 3.1, develop an incident response plan, and reach backup and encryption at 3.7. Every answer below sits inside that frame, and reporting duties sit under PIPEDA.
How quickly can a business recover from ransomware?
Recovery time varies widely with preparation. This engagement was back at work Monday morning after a Friday 9pm call. Sophos found only 16% of 2025 victims fully recovered inside a day and 53% inside a week.
What should you do first when ransomware hits?
Isolate affected systems to stop the spread, and leave them powered on, because some forensic evidence lives only in memory. Call your provider or incident response team before you call anyone else. In this case immediate containment bounded the damage. Do not negotiate with the attackers yourself.
What does ransomware recovery cost a Canadian small business?
Sophos put the 2025 average recovery cost at US$1.53 million excluding any ransom, down from US$2.73 million a year earlier. That figure is a global survey average across organizations of 100 to 5,000 employees, not a Canadian-SMB benchmark; actual recovery cost varies with incident scope, downtime, and restoration work. We break the Canadian numbers down in our ransomware recovery cost benchmark.
Should you pay the ransom?
The Cyber Centre states there is no guarantee threat actors will unlock systems or return stolen data after payment, and that they can copy the data and revictimize you later. This client paid nothing against a six-figure demand because verified air-gapped recovery points existed. Verified recovery points can remove the need to pay for decryption; they do not remove extortion risk if data was stolen.
Reading further: our Toronto marketing agency cyber crisis recovery, the co-managed IT build for a growing construction firm, and the rest of the Fusion Computing case study library. You can also download this case study as a PDF.
If a Friday night would leave you guessing about your own restore points, book a consultation and I will walk your recovery posture with you personally. Fusion Computing has run CISSP-led security for Canadian businesses across Toronto and the GTA since 2012, and a cybersecurity assessment is where most engagements start.

