| Quick summary: A 24/7 alarm monitoring and dispatch company in the Los Angeles area called DCG mid-ransomware attack. DCG had an engineer onsite within two hours, kept the dispatch center running throughout, discovered the client’s own backups were also compromised, coordinated recovery with the client’s cyber insurance carrier, and fully restored the main office and two remote locations in 30 days, on a stronger security baseline than before. |

The Call
It started on a Friday morning, the kind of call every business owner dreads. A 24/7 alarm monitoring and dispatch company in the Los Angeles area was in the middle of an active ransomware attack when they called DCG Technical Solutions for help.
Within two hours of that call, terms were agreed, paperwork was signed, and a DCG engineer was onsite. That is what “We do it now” looks like when it matters most.
Stopping the Bleeding First
The client’s business is built on being available around the clock. Their dispatch and call center operations cannot go down, lives and property depend on it. So the first priority was not the servers, it was making sure that critical function stayed online while everything else was evaluated.
DCG’s team moved immediately to contain the threat, stopping all lateral movement across the network, then worked side by side with onsite staff to confirm the call center could keep functioning while the rest of the infrastructure was assessed. By the end of day one, the client’s core operation was stable and secure.
Facing the Hard Truth: The Backups Were Compromised Too
Here is where this case gets serious. When DCG’s engineers checked the client’s onsite backups, expecting them to be the safety net, they found the backups had also been compromised and were not restorable. This is one of the most damaging outcomes a ransomware attack can produce, and it meant recovery would require a different path.
DCG immediately brought the client’s leadership team into the loop and helped them engage their cyber insurance carrier. Working hand in hand with the insurance team, DCG guided the client through the process of rebuilding servers, Active Directory, and their local Exchange environment, all while carefully preserving forensic data the insurance investigators needed. Once the insurance forensic team signed off on the recovery approach, rebuilding began.
Through the negotiation process, the client was able to work with their insurance company and the threat actor to obtain a recovery key for the encrypted data. But the story did not end there. Because the SQL and Exchange databases had been encrypted while actively running, both had significant corruption. DCG’s engineers manually repaired the database files to bring the systems back to a usable, trustworthy state, not a shortcut, a real fix.
Protecting the Brand While the Work Happened
One detail that made a real difference for this client: nobody outside the company needed to know anything was wrong.
Using DCG’s email security platform, the team stood up an Emergency Inbox so the client could continue reading and responding to inbound email throughout the recovery. Customers, partners, and vendors kept getting responses like normal. This is Effortless Experience thinking in practice: the client’s brand reputation stayed fully intact while a serious recovery effort happened behind the scenes.
Rebuilding Stronger, Not Just Rebuilding
Rebuilding a compromised network is an opportunity, not just a repair job. DCG treated it that way.
While recovering the environment, DCG deployed rental servers onsite as a temporary bridge so business could continue while the permanent systems were rebuilt. A brand new Active Directory domain controller was built from the ground up, allowing DCG to bring the client’s configuration and security settings up to DCG’s current security baseline rather than simply restoring what existed before.
DCG’s team reviewed every available log for signs of compromise, patched the perimeter firewall, and made a strategic shift: retiring the old firewall-based VPN in favor of a Zero Trust Network Access solution for all remote users. DCG’s 24/7 SOC team was placed on high alert throughout the rebuild, watching closely for any sign the threat actor was attempting to regain access.
Once the primary site was stable, DCG worked with the client’s leadership team to extend recovery to two remote office locations. Rather than sinking time and money into rebuilding aging four- to five-year-old workstations and laptops, DCG recommended replacing them outright, protecting the client from investing in equipment that was already near the end of its useful life.
The Timeline
A full-scale ransomware recovery, from initial compromise to complete restoration, in 30 days.
What Protection Looks Like Now
Today, this client operates with a security posture far beyond where they started:
In Their Own Words
The Bottom Line
Ransomware does not wait for a convenient time, and neither do we. This client learned the hard way that even businesses who believe they are prepared can have gaps, compromised backups being one of the most dangerous. What made the difference was not luck, it was a partner who showed up in two hours, protected what mattered most first, communicated every step of the way, and used the crisis as an opportunity to build something stronger than what existed before.
That is what it means to be a true outsourced IT partner: not just fixing what broke, but making sure it cannot break the same way again.
| Worried about your own backup strategy or wondering if your business could recover from a ransomware attack? Contact DCG Technical Solutions today for a free security assessment. |
Published by DCG Technical Solutions, LLC







































