A pharmaceutical company detected a ransomware attack on May 4, with confirmed exfiltration, and reported on May 13 that the activity had been contained with external support, with core systems restored.
Nine days between detection and announced containment is a good result for an incident with exfiltration, and usually indicates prior preparation: a plan written beforehand, a response contract already signed, and backups that worked.
The most expensive part of these cases is rarely technical. It's deciding under pressure what to switch off and when to switch it back on, with operations halted and without knowing exactly how far the attacker got.
Pharmaceutical manufacturing carries a regulatory aggravator that shortens the clock. A production system under quality regulation doesn't come back online on a technology decision: it requires documented verification, and every day halted costs batches and supply commitments.
For smaller operations, the applicable version needs no expensive contract: knowing in advance who calls whom, having backups tested with a full restore, and having written down which system can be switched off without stopping everything.
