{"id":3378,"date":"2022-05-31T12:38:25","date_gmt":"2022-05-31T10:38:25","guid":{"rendered":"https:\/\/www.advens.com\/cas-client\/intervention-du-cert-pour-gerer-une-attaque-par-ransomware\/"},"modified":"2022-10-24T12:21:49","modified_gmt":"2022-10-24T10:21:49","slug":"cert-intervention-to-manage-a-ransomware-attack","status":"publish","type":"cas-client","link":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/","title":{"rendered":"CERT intervention to manage a ransomware attack\u00a0"},"content":{"rendered":"\n<p>After being attacked by ransomware, the services of a French local authority called on Advens to control the attack, limit its impact, recover data loss, and protect them from any future attacks.\u00a0<\/p>\n\n\n\n<p><br>It\u2019s Thursday, January 21, 2021. All computers are down and the telephone network is severely disrupted. The signs of a computer hack are evident. Time is running out for the county council of the French Department of Vienne: little by little, a CryptoLocker malware has encrypted the authority&#8217;s various files! With corrupt backups, HR systems affected, and road management systems infected, ANSSI is called to the rescue.\u00a0<\/p>\n\n\n\n<p><br>Advens then intervenes via videoconference, during the weekend, and two experts come on-site to manage the cyberattack.\u00a0<\/p>\n\n\n\n<figure id=\"block-citation-1730948005\" class=\"acf-block-citation aligncenter mb-4\">\n  <blockquote class=\"blockquote\">\n    <p class=\"fs-3\">\u201cI would like to emphasise the responsiveness of the Advens teams. I was able to contact the teams in a few hours. After an initial video call during the weekend, the CERT Advens teams arrived on-site on Monday. It all got underway very quickly and smoothly.\u201d <\/p>\n  <\/blockquote>\n  <div class=\"d-flex align-items-center justify-content-start gap-3 gap-xl-4\">\n        <figcaption class=\"blockquote-footer text-end d-flex flex-wrap align-items-center justify-content-end m-0\">\n      <strong>Luis Manuel Da Silva<\/strong>\n      <span class=\"mx-1\">\u2022<\/span>\n      <span>Director of Digital Transition of the French Department of Vienne <\/span>\n    <\/figcaption>\n  <\/div>\n<\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Ransomware attack: challenges and issues <\/h2>\n\n\n\n<p>The local authority needed quick and effective assistance to deal with this attack, to control it and then <strong>to<\/strong> <strong>rebuild a sound information system<\/strong> so they could resume their work.\u00a0<\/p>\n\n\n\n<p><br>CryptoLocker malware is ransomware, a type of virus that mainly infects the computer systems of local authorities and ministries, but also private companies. To stop the encryption and return the data, hackers demand a ransom.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Our teams&#8217; intervention<\/h2>\n\n\n\n<p>Systems compromised by ransomware require a high level of responsiveness from incident response specialists. The three strengths of Advens&#8217; support, according to Luis Manuel Da Silva, Director of Digital Transition for the French Department of Vienne?\u00a0<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Quality of management, assistance and incident response operations <\/li><li>Meticulous, rigorous work <\/li><li>Team availability <\/li><\/ul>\n\n\n\n<figure id=\"block-citation-786626716\" class=\"acf-block-citation aligncenter mb-4\">\n  <blockquote class=\"blockquote\">\n    <p class=\"fs-3\">\u201cA lot of work has been done, both face-to-face and remotely. Even when they weren&#8217;t on site, there was always a communication channel through which you could talk to the experts and get quick answers.\u201d <\/p>\n  <\/blockquote>\n  <div class=\"d-flex align-items-center justify-content-start gap-3 gap-xl-4\">\n        <figcaption class=\"blockquote-footer text-end d-flex flex-wrap align-items-center justify-content-end m-0\">\n      <strong>Luis Manuel Da Silva<\/strong>\n      <span class=\"mx-1\">\u2022<\/span>\n      <span>Director of Digital Transition for the French Department of Vienne <\/span>\n    <\/figcaption>\n  <\/div>\n<\/figure>\n\n\n\n\n<div id=\"block-colonnes-542843394\" class=\"acf-block-colonnes colonnes alignwide\">\n  <div class=\"container\">\n    <div class=\"row mb-4\">\n      <div class=\"col-12\">\n        <h3>The Advens advantage  <\/h3>\n                      <\/div>\n    <\/div>\n\n                  \n    <div class=\"row row-colonnes row-cols-1 row-cols-md-2 row-cols-xl-3 gy-4 mb-4 mb-xl-5\">\n              <div class=\"col -img\">\n          <div class=\"card h-100 bg-grey-white border-0\">\n            <div class=\"card-body\">\n                                          <h4><\/h4>\n              <p><span class=\"TextRun SCXW193407563 BCX8\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW193407563 BCX8\">Does more than technical operations to contain the virus infection and repair the information system<\/span><\/span><span class=\"EOP SCXW193407563 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:720,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:360}\">\u00a0<\/span><\/p>\n\n                          <\/div>\n          <\/div>\n        <\/div>\n              <div class=\"col -img\">\n          <div class=\"card h-100 bg-grey-white border-0\">\n            <div class=\"card-body\">\n                                          <h4><\/h4>\n              <p><span class=\"TextRun SCXW169623098 BCX8\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW169623098 BCX8\">Brings reassurance to teams in crisis<\/span><\/span><span class=\"EOP SCXW169623098 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:720,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:360}\">\u00a0<\/span><\/p>\n\n                          <\/div>\n          <\/div>\n        <\/div>\n              <div class=\"col -img\">\n          <div class=\"card h-100 bg-grey-white border-0\">\n            <div class=\"card-body\">\n                                          <h4><\/h4>\n              <p><span class=\"TextRun SCXW122273693 BCX8\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW122273693 BCX8\">Provides the opportunity to rebuild on healthier and more solid foundations<\/span><\/span><span class=\"EOP SCXW122273693 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:720,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:360}\">\u00a0<\/span><\/p>\n\n                          <\/div>\n          <\/div>\n        <\/div>\n          <\/div>\n  <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">After the attack and intervention: the results <\/h2>\n\n\n\n<p>Following the intervention of the Advens CERT, the departmental council was able to rebuild its systems and start again on a healthier basis.<\/p>\n\n\n\n<p><br>Beyond the technical aspects, the support in this kind of intervention has a very important <strong>human dimension<\/strong>. This kind of ransomware attack paralyses a whole community and all the services that depend on it. The teams\u2019 stress level is therefore quite substantial. It is the role of our experts to support and reassure them, both professionally and empathetically.<\/p>\n\n\n\n<figure id=\"block-citation-1314585224\" class=\"acf-block-citation aligncenter mb-4\">\n  <blockquote class=\"blockquote\">\n    <p class=\"fs-3\">\u201cQuite paradoxically, I have fond memories of this time of high adrenaline.\u201d <\/p>\n  <\/blockquote>\n  <div class=\"d-flex align-items-center justify-content-start gap-3 gap-xl-4\">\n        <figcaption class=\"blockquote-footer text-end d-flex flex-wrap align-items-center justify-content-end m-0\">\n      <strong>Luis Manuel Da Silva<\/strong>\n      <span class=\"mx-1\">\u2022<\/span>\n      <span>Director of Digital Transition for the French Department of Vienne <\/span>\n    <\/figcaption>\n  <\/div>\n<\/figure>\n\n\n\n<p>Advens first-responders bring a lot of reassurance and control, and thorough knowledge of what actions to take in order to get back on track in the most secure way possible, all within reasonable deadlines that are universally agreed on.\u201d<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Ransomware attack: how to avoid it next time? <\/h2>\n\n\n\n<p>After extinguishing the fire and recovering the systems and data, the most important thing is to document the attack and its operational response. With an assessment, formal feedback, and short and medium-term action plans, the local authority is able to project itself towards an even <strong>more secure situation<\/strong> than that left by the CERT at the end of the mission.\u00a0<\/p>\n\n\n\n<p><br>This is where Advens consultants and experts bring real added value. By documenting their feedback, they make it possible to understand the attack, highlight vulnerabilities and analyse the quality of the response provided.\u00a0<\/p>\n\n\n\n<p><br><strong>And if another crisis occurs despite all efforts,it will be more manageable and the attack will have less impact.<\/strong>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After being attacked by ransomware, the services of a French local authority called on Advens to control the attack, limit its impact, recover data loss, and protect them from any future attacks.\u00a0 It\u2019s Thursday, January 21, 2021. All computers are down and the telephone network is severely disrupted. The signs of a computer hack are [&hellip;]<\/p>\n","protected":false},"featured_media":2569,"template":"","taxo_secteur":[39],"taxo_expertise":[70],"class_list":["post-3378","cas-client","type-cas-client","status-publish","has-post-thumbnail","hentry","taxo_secteur-public-services","taxo_expertise-incident-response"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CERT intervention to manage a ransomware attack\u00a0 - Advens<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CERT intervention to manage a ransomware attack\u00a0 - Advens\" \/>\n<meta property=\"og:description\" content=\"After being attacked by ransomware, the services of a French local authority called on Advens to control the attack, limit its impact, recover data loss, and protect them from any future attacks.\u00a0 It\u2019s Thursday, January 21, 2021. All computers are down and the telephone network is severely disrupted. The signs of a computer hack are [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"Advens\" \/>\n<meta property=\"article:modified_time\" content=\"2022-10-24T10:21:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.advens.com\/app\/uploads\/2022\/05\/poitiers.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1350\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/\",\"url\":\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/\",\"name\":\"CERT intervention to manage a ransomware attack\u00a0 - Advens\",\"isPartOf\":{\"@id\":\"https:\/\/www.advens.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.advens.com\/app\/uploads\/2022\/05\/poitiers.png\",\"datePublished\":\"2022-05-31T10:38:25+00:00\",\"dateModified\":\"2022-10-24T10:21:49+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#primaryimage\",\"url\":\"https:\/\/www.advens.com\/app\/uploads\/2022\/05\/poitiers.png\",\"contentUrl\":\"https:\/\/www.advens.com\/app\/uploads\/2022\/05\/poitiers.png\",\"width\":1350,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.advens.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Case studies\",\"item\":\"https:\/\/www.advens.com\/en\/cas-clients\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"CERT intervention to manage a ransomware attack\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.advens.com\/#website\",\"url\":\"https:\/\/www.advens.com\/\",\"name\":\"Advens\",\"description\":\"For Cyber, People &amp; Planet\",\"publisher\":{\"@id\":\"https:\/\/www.advens.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.advens.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.advens.com\/#organization\",\"name\":\"Advens\",\"url\":\"https:\/\/www.advens.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.advens.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.advens.com\/app\/uploads\/2025\/07\/Logotype-aDvens-Cybersecurity.png\",\"contentUrl\":\"https:\/\/www.advens.com\/app\/uploads\/2025\/07\/Logotype-aDvens-Cybersecurity.png\",\"width\":1501,\"height\":1501,\"caption\":\"Advens\"},\"image\":{\"@id\":\"https:\/\/www.advens.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/advens\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CERT intervention to manage a ransomware attack\u00a0 - Advens","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/","og_locale":"en_US","og_type":"article","og_title":"CERT intervention to manage a ransomware attack\u00a0 - Advens","og_description":"After being attacked by ransomware, the services of a French local authority called on Advens to control the attack, limit its impact, recover data loss, and protect them from any future attacks.\u00a0 It\u2019s Thursday, January 21, 2021. All computers are down and the telephone network is severely disrupted. The signs of a computer hack are [&hellip;]","og_url":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/","og_site_name":"Advens","article_modified_time":"2022-10-24T10:21:49+00:00","og_image":[{"width":1350,"height":450,"url":"https:\/\/www.advens.com\/app\/uploads\/2022\/05\/poitiers.png","type":"image\/png"}],"twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/","url":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/","name":"CERT intervention to manage a ransomware attack\u00a0 - Advens","isPartOf":{"@id":"https:\/\/www.advens.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#primaryimage"},"image":{"@id":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.advens.com\/app\/uploads\/2022\/05\/poitiers.png","datePublished":"2022-05-31T10:38:25+00:00","dateModified":"2022-10-24T10:21:49+00:00","breadcrumb":{"@id":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#primaryimage","url":"https:\/\/www.advens.com\/app\/uploads\/2022\/05\/poitiers.png","contentUrl":"https:\/\/www.advens.com\/app\/uploads\/2022\/05\/poitiers.png","width":1350,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/www.advens.com\/en\/business-case\/cert-intervention-to-manage-a-ransomware-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.advens.com\/en\/"},{"@type":"ListItem","position":2,"name":"Case studies","item":"https:\/\/www.advens.com\/en\/cas-clients\/"},{"@type":"ListItem","position":3,"name":"CERT intervention to manage a ransomware attack\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/www.advens.com\/#website","url":"https:\/\/www.advens.com\/","name":"Advens","description":"For Cyber, People &amp; Planet","publisher":{"@id":"https:\/\/www.advens.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.advens.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.advens.com\/#organization","name":"Advens","url":"https:\/\/www.advens.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.advens.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.advens.com\/app\/uploads\/2025\/07\/Logotype-aDvens-Cybersecurity.png","contentUrl":"https:\/\/www.advens.com\/app\/uploads\/2025\/07\/Logotype-aDvens-Cybersecurity.png","width":1501,"height":1501,"caption":"Advens"},"image":{"@id":"https:\/\/www.advens.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/advens\/"]}]}},"_links":{"self":[{"href":"https:\/\/www.advens.com\/en\/wp-json\/wp\/v2\/cas-client\/3378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.advens.com\/en\/wp-json\/wp\/v2\/cas-client"}],"about":[{"href":"https:\/\/www.advens.com\/en\/wp-json\/wp\/v2\/types\/cas-client"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.advens.com\/en\/wp-json\/wp\/v2\/media\/2569"}],"wp:attachment":[{"href":"https:\/\/www.advens.com\/en\/wp-json\/wp\/v2\/media?parent=3378"}],"wp:term":[{"taxonomy":"taxo_secteur","embeddable":true,"href":"https:\/\/www.advens.com\/en\/wp-json\/wp\/v2\/taxo_secteur?post=3378"},{"taxonomy":"taxo_expertise","embeddable":true,"href":"https:\/\/www.advens.com\/en\/wp-json\/wp\/v2\/taxo_expertise?post=3378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}