Case Studies

Locked Out of the Site Office: Rebuilding IT for a Construction JV After a Ransomware Attack

Engineers Couldn’t Log In, Drawings Were Gone, and Payroll Was Frozen

A joint venture between two established construction firms in Singapore, operating from a shared site office in Jurong, faced a complete operational standstill when engineers arrived one Monday morning to find they could no longer access project drawings, contract documents, or timesheet systems. The shared IT environment, hosted on a single on-premise server, had been encrypted overnight by ransomware. For six days, field supervisors could not retrieve updated blueprints, procurement teams were unable to process purchase orders, and payroll processing for over 120 site workers was delayed. The financial exposure from stalled progress, contractual penalties, and reputational risk to both parent companies grew with each hour the systems remained offline. With no recent backups and no dedicated IT support, the joint venture’s leadership had no path to recovery and no way to verify whether data had already been exfiltrated.

Initial Assessment Revealed a Single Point of Failure and Zero Cyber Resilience

When we were called in on day three of the outage, the environment showed clear signs of a targeted ransomware intrusion. The attackers had exploited an unpatched remote desktop protocol (RDP) service exposed to the internet, gaining access weeks earlier and moving laterally across the network. The joint venture had been relying on a single HPE ProLiant server running Windows Server with locally stored project files and no offsite backup. Antivirus software was present but outdated, and no endpoint detection or firewall logging was in place. We confirmed that all data on the primary server and connected drives had been encrypted, including AutoCAD drawings, BIM models, and HR records. Worse, the absence of immutable backups meant there was no way to restore clean data without paying the ransom or rebuilding from scratch. The lack of network segmentation allowed the malware to spread unchecked, and no incident response plan existed to guide containment.

We Rebuilt the Environment Using Zero Trust Principles and Automated Recovery

Our first action was to isolate the compromised network and begin forensic analysis using tools from Palo Alto Networks’ Cortex XDR platform to trace the attack vector and confirm no persistent access remained. We then deployed a temporary cloud-based workspace on Microsoft Azure, allowing project managers and engineers to resume work using cached files and manual logs while the permanent solution was built. The new architecture was designed around redundancy and resilience: two virtualized domain controllers hosted in separate availability zones on Azure, joined with a site-to-site VPN to a newly installed FortiGate firewall at the site office. All user data was migrated to Microsoft 365 with advanced threat protection enabled, and project files were synchronized to SharePoint with version history and access controls. We implemented Veeam Backup & Replication with immutable storage in AWS S3, ensuring that backups could not be altered or deleted by ransomware. Critical systems were restored within 72 hours of starting the rebuild, and full services—including access to AutoCAD, Procore integration, and payroll processing via Humanic—were online within nine days of the initial incident.

Operations Resumed with 99.98% Uptime and No Further Security Incidents

The joint venture resumed full operations without paying the ransom. Since the rebuild, the new environment has maintained 99.98% uptime across a 14-month period, with automated backups verified daily and successful recovery drills conducted every quarter. Engineers now access drawings through a secure, role-based portal with multi-factor authentication, reducing unauthorized access risks. Payroll delays dropped to zero, and contractual milestones have been met consistently. The client avoided an estimated SGD 256,000 in potential liquidated damages from project delays. More importantly, both parent companies now have audit-ready compliance documentation for PDPC requirements, including data access logs and encryption policies. The site office has since become a model for other joint ventures in the group, with standardized IT deployment now rolled out across three additional projects.

Shared IT Environments in Joint Ventures Are High-Risk Without Independent Oversight

When two companies share IT infrastructure without a neutral, third-party operator, accountability for patching, backups, and access controls often falls through the cracks. One party assumes the other is managing security, while neither conducts regular audits. In this case, the absence of a dedicated IT steward created a blind spot that attackers exploited. Singapore-based construction JVs should treat shared IT not as a cost-saving measure but as a joint liability—requiring independent monitoring, segregated responsibilities, and predefined incident protocols before ground is broken. Ownership of data, access rights, and recovery roles must be contractually defined at the outset, not after an attack occurs.

When your project timeline depends on uninterrupted access to documents and systems, a single compromised server can cascade into delays, penalties, and lost trust. See how TYPENT designs resilient IT for construction teams.

Uncover your hidden systems risk in 5 minutes.

Stop reading about risk and start measuring yours. Our free interactive assessment generates a custom IT vulnerability score — specific to your setup, your sector, and your staff count.