

NTT DATA mobilised specialist incident-response and infrastructure-recovery capabilities to analyse the attack, execute emergency containment and recover affected systems. Activities were coordinated around the need to restore operational control while maintaining a reliable investigation trail




NTT DATA combined rapid incident triage, identity and access analysis, secure system recovery and a structured path to stronger monitoring to contain the attack, restore operational control and improve readiness for future incidents
Assessed the attack, prioritised affected systems and applied emergency containment measures to limit further compromise and coordinate technical recovery
Reviewed compromised accounts, backdoors and communication channels to identify unauthorised access and potential persistence mechanisms
Supported recovery of affected workstations and servers while reviewing security controls to enable safer restoration of the environment
Defined a path to strengthen monitoring, escalation, executive reporting and coordination with security operations capabilities for future incidents
The engagement helped contain the incident, restore control of critical systems and support secure recovery of affected workstations and servers, while improving visibility into compromised identities, access paths and security-tool performance and establishing a stronger foundation for monitoring, incident governance and business-continuity readiness