Case Study

Ransomware Recovery for a Private Hospital Group

A private hospital group in Gauteng was hit by ransomware that encrypted file servers and administrative workstations overnight. OAS contained the attack within minutes, recovered clean data from immutable cloud backups, and restored 140 endpoints inside one business day. No ransom was paid and no patient data was lost.

Note: This case study is illustrative. Client details are anonymised and figures are representative of typical OAS engagements.

The challenge

A private hospital group in Gauteng, operating three facilities and roughly 800 staff, suffered a ransomware attack that began on a Friday evening. The attackers gained entry through a phishing email opened on an administrative workstation. Within hours, file servers and shared drives at two facilities were encrypted.

The group faced an impossible weekend. Patient billing, scheduling, and administrative systems were offline. POPIA obligations demanded a clear answer on whether patient data had been exfiltrated. The attackers demanded payment in cryptocurrency, with a deadline.

Critically, the group's legacy backup appliance sat on the same network as production systems. It had been encrypted alongside everything else.

The approach

The group engaged OAS under an emergency incident response arrangement. Our team followed the same Protect, Detect, Recover discipline that underpins the Three Pillar Managed Security framework.

First, containment. SentinelOne agents were deployed across the estate within hours. Behavioural AI identified the ransomware lineage, killed active processes, and isolated 23 compromised machines from the network.

Second, assessment. Forensic analysis through the SentinelOne Storyline reconstructed the attack path from initial phishing email to lateral movement. The evidence showed encryption but no large-scale data exfiltration — a finding the group could present to the Information Regulator.

Third, recovery. The group had recently migrated its most critical data to Cove Data Protection as part of an earlier OAS pilot. Because Cove stores backups in immutable cloud storage, off the production network, those copies were untouched. OAS restored servers from clean recovery points and rebuilt affected workstations in parallel.

The outcome

  • 140 endpoints restored inside one business day, with the remaining estate completed over the weekend
  • No ransom paid and no negotiation with the attackers
  • No patient clinical data lost; billing records recovered to within four hours of the attack
  • A documented incident report supporting the group's POPIA notification obligations

The group subsequently moved its full estate onto the Three Pillar Managed Security service. SentinelOne now protects every endpoint, N-able N-central provides 24/7 monitoring, and Cove backup jobs are verified daily. Eighteen months on, two further intrusion attempts have been neutralised autonomously — before staff ever noticed.

Ready to strengthen your defences?

Book a no-obligation security assessment. We'll map your gaps across Protect, Detect and Recover — and show you exactly where you stand.