Skip to main content

Ransomware in Berlin: managing the crisis once data has been exfiltrated

A ransomware attack involving data theft in Berlin demonstrates once again that extortion no longer relies solely on encryption. When information leaves the organisation, the ransomware response becomes as much legal and communicative as it is technical.

CybersecuritySeintec team2-3 min read
Ransomware in Berlin: managing the crisis once data has been exfiltrated

News summary

The Berlin case reported by Reuters fits the dominant pattern of recent years: attackers encrypt systems, but first they exfiltrate the information. Extortion is no longer just about restoring access to data, but about not publishing it. This completely changes the nature of the response.

A company with impeccable backups can restore its servers in hours and still face a serious problem: contracts, payroll, histories, or customer data in the hands of third parties. Backups solve availability; they do not solve confidentiality.

At Seintec, we insist on a point that is often discovered too late: the most costly phase of modern ransomware is not restoration, but determining exactly what was taken. Without sufficient logs —of access, outbound traffic, or file server activity— that question remains unanswered, and without an answer, it is impossible to notify correctly or negotiate with sound judgment.

Within the European framework, moreover, the clock is ticking. Notification to the supervisory authority and, where appropriate, to the affected individuals, has demanding deadlines. An organisation that discovers the incident on Friday afternoon and has not decided who leads, who speaks to the regulator, and who speaks to the customers, loses its first useful hours.

The practical recommendation is to prepare for the crisis in advance: a technical response contact available out of hours, an identified legal advisor, a single spokesperson, and baseline messaging for customers and employees. It does not eliminate the damage, but it prevents improvisation from multiplying it.

In terms of prevention, three controls continue to account for most of the value: multi-factor authentication for all remote access, segmentation to prevent lateral movement across the network, and immutable copies outside the domain, verified through actual restoration tests.

Source: Reuters 5 September 2026

Why this matters to a company operating in Spain

The threat landscape affecting Spanish companies no longer distinguishes by size. Attacks are automated, sold as a service, and seek the shortest path: a reused credential, an unpatched server, or a provider with poorly controlled remote access. For an SME, the difference between a minor scare and a multi-day shutdown almost always depends on decisions made before the incident.

That is why every industry update should be read in operational terms: which specific controls would have prevented the problem, what evidence must be preserved, and who makes the decision when the clock is ticking. This is the approach we apply to managed cybersecurity projects at Seintec.

Real business impact

Before deciding on an investment, it is advisable to identify what is at stake. In cybersecurity projects, we typically review these four areas with management and the IT manager:

  • Operational disruption: orders, invoicing, or production halted while systems are restored.
  • Loss or exposure of personal data, with a mandatory 72-hour notification requirement to the AEPD.
  • Hidden cost of recovery: overtime, external hiring, and loss of client trust.
  • Contractual and compliance requirements (ENS, NIS2, ISO 27001) that demand evidence, not intentions.

Five-step action plan

A useful plan fits on one page. This is the roadmap we apply with our clients to move from news to measurable improvement, without disrupting daily operations:

  • Confirm the scope with evidence: which machines, which accounts, and what volume of data left the organisation.
  • Isolate without destroying: contain the affected systems while preserving logs and memory for subsequent analysis.
  • Activate the crisis committee comprising management, technical, legal, and communication teams, and appoint a single spokesperson.
  • Restore from verified immutable copies and only onto rebuilt systems, never onto compromised ones.
  • Notify the supervisory authority and affected parties within the deadline where appropriate, and document every decision.

Key indicators you should be measuring

What is not measured is not managed. These indicators allow you to verify if the technological investment is yielding results and serve as the basis for the periodic reports we deliver to our clients:

  • Mean time to detection and mean time to containment of an incident (MTTD and MTTC).
  • Percentage of remote and privileged access with MFA active.
  • Age of the last tested restoration from an immutable copy.
  • Activity log coverage: retention days and systems included.

How we approach it at Seintec: Cybersecurity

We shield your business so it never stops. We operate from our own datacenter in Spain, with a certified technical team and a single point of contact who knows your infrastructure, so you do not have to explain your environment every time an incident arises.

These are the capabilities we bring to the table in a cybersecurity project:

  • EDR / XDR: Advanced detection and response across endpoints and network.
  • UTM perimeter security: Managed firewall and segmentation.
  • Email filtering: Blocking of phishing, spam, and impersonation.
  • WAF: Protection of published applications and services.
  • Immutable backup: Backups that ransomware cannot alter.
  • MFA and identity: Conditional access by user and device.

What you gain by working with a technology partner

Outsourcing does not mean losing control: it means gaining predictability, coverage, and independent technical insight. These are the benefits our clients highlight:

  • Total prevent–detect–respond coverage: Immutable backup, email filtering, WAF, EDR/XDR and UTM perimeter security in a single managed contract.
  • Assured continuity: Regain control of your infrastructure following a cyber incident with a recovery objective agreed with you in the continuity plan.
  • Zero Trust by design: Identity-based access control and MFA for every user and device.
  • AI-powered defence: Machine learning engines that monitor endpoints and networks in real time, reducing the mean time to detection.

Frequently Asked Questions

Should a ransomware ransom be paid?
Paying does not guarantee that data will not be published or that decryption tools will work, and it funds future attacks. The decision rests with management following legal advice, but the priority should be recovery from verified backups and fulfilling notification obligations.
How do we know which data has been stolen?
Only through logs. If traces of access, outbound traffic, and file server activity are not preserved for long enough, the investigation cannot narrow down the scope, and the company is forced to assume the worst-case scenario.
How do I know if my company is truly protected?
With evidence: EDR coverage, two-factor authentication on all remote access, immutable copies, and a recently tested restoration. If any of these four points are not confirmed, there is a real risk of prolonged downtime.
Where should a company wanting to address cybersecurity begin?
With an audit of the current environment. At Seintec, we perform an initial no-cost review that identifies risks, dependencies, and priorities, resulting in a phased plan with fixed deadlines and budgets.
Is it necessary to halt business operations during the project?
No. We plan migrations and changes within agreed windows, with prior pilot tests and rollback options, ensuring disruption is minimal or non-existent for users.
What type of companies do you serve?
SMEs and mid-market companies in sectors such as industry, automotive, logistics, retail, legal, and healthcare, with both on-premises and hybrid cloud infrastructure.
What coverage and response times (SLA) do you offer?
Support from Monday to Friday, 09:00 to 18:00, and 24x7 emergencies 365 days a year, with a committed response SLA and a 99.98% service SLA in 2025.

Concepts mentioned in this article: Backup · Ransomware

The response to ransomware is prepared before the incident. At Seintec we review your exposure level, your backups, and your detection capacity, and we document the crisis procedure in writing. Request a cybersecurity review.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.