Skip to content
StrikeCyberStrikeCyber
Retail & eCommerce

Assumed Breach and Incident Response Readiness for a Logistics Operator

A national logistics operator had backups and a plan on paper, but had never tested whether it could actually respond to a live intrusion.

Retail & eCommerce sector
Industry
Retail & eCommerce
Services
Incident Response, Red Teaming
Engagement
Assumed breach and incident response readiness exercise
Region
National

The Challenge

The client is a national logistics operator underpinning a large retail and eCommerce supply chain. Its warehouse management, order fulfilment and transport systems run continuously, and even a few hours of disruption ripples out to retailers and customers. Ransomware and extortion against logistics and distribution had been rising, and the leadership team knew that downtime, not just data loss, was the existential threat to the business.

They had the usual artefacts: an incident response plan, backups and cyber insurance. What they had never done was pressure-test any of it. Nobody could say with confidence whether the response team could contain an active intruder, whether backups would actually restore the systems that mattered, or whether the business could communicate and make decisions under the stress of a live crisis.

Our Approach

StrikeCyber designed a combined assumed breach and incident response readiness exercise. Instead of spending weeks proving that an attacker could get in, the engagement started from the realistic assumption that one already had, then tested everything that happens next.

  • Expert operators were given a controlled foothold inside the environment and behaved like a ransomware affiliate preparing for impact: escalating privileges, moving laterally and locating high-value systems and backups, with techniques mapped to MITRE ATT&CK.
  • As the operators progressed, the client's own team responded to the activity in real time, exercising their detection, containment and escalation processes against a live adversary rather than a tabletop scenario.
  • A facilitated crisis session ran in parallel, putting technical responders, IT leadership and business decision-makers in the room together to test communications, authority and decision-making under time pressure.

The exercise deliberately blended offensive tradecraft with response, so the client saw both how an attacker would operate and how their own people, processes and technology held up.

What We Found

  • Containment was slower and messier than assumed. Responders could see suspicious activity but lacked a rehearsed way to isolate affected systems quickly, so the simulated attacker had time to reach backup infrastructure.
  • Backups were reachable from the same credentials used elsewhere. Because backup systems were not sufficiently segmented, the same access that compromised production could have encrypted or deleted the recovery point, the exact failure that turns an incident into a catastrophe.
  • Communications defaulted to compromised channels. The plan assumed email and internal chat would be available, with no rehearsed out-of-band alternative for a scenario where those systems are down or untrusted.
  • Decision-making stalled on authority. When the group faced choices such as taking core systems offline or engaging external help, it was unclear who held the authority to decide, and hesitation cost time that a real incident would not forgive.

The Outcome

The client came away with a clear, prioritised picture of where its response would have broken. Backup infrastructure was segmented and given separate credentials so recovery could survive a domain-wide compromise, and restore procedures for the most critical fulfilment systems were documented and tested rather than assumed. A rehearsed containment runbook gave responders a fast, agreed way to isolate systems, and an out-of-band communications channel was established for use when primary systems cannot be trusted. The incident response plan was updated with explicit decision authority and escalation thresholds, so the next crisis begins with clarity rather than debate.

Crucially, the team had now practised. The muscle memory built during a controlled exercise is what shortens response time when a real intrusion happens.

Why It Matters

For a logistics business, resilience is measured in hours of downtime avoided, not just records protected. A plan and a backup mean little until they have survived contact with a realistic attacker. An assumed breach readiness exercise reveals whether containment, recovery and crisis decision-making actually work while the stakes are still simulated. To rehearse your own response before an attacker forces the issue, get in touch.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation