Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
A small U.S. construction firm contacted Intrust IT for a cybersecurity proposal, rejected it over cost, and three weeks later was hit by ransomware that encrypted its server and connected backup. The organization, active for years, shut down within months. The episode, reconstructed by consultant Dave Hatter in testimony published Oct. 8, 2026, has not received independent confirmation but documents a recurring pattern in the construction sector: underestimating cyber risk as a business-continuity factor.
- A CFO contacted Intrust IT; the owner rejected the proposal, deeming the company "too small" to be a target
- Three weeks later, an unpatched Windows server and its attached backup drive were encrypted by ransomware
- The firm lost the ability to pay employees and track receivables from clients and vendors
- The case rests solely on a consultant's testimony; no public records verify the name, location, or details of the failure
The Refusal: "Too Expensive, Too Small"
The firm's new CFO had initiated contact with Intrust IT, a U.S.-based cybersecurity and compliance consulting firm. The owner blocked the deal. Dave Hatter, an Intrust consultant, reported that the response included two arguments common in his experience with small businesses: perceived excessive cost and the belief that the company's size guaranteed invisibility to attackers.
The owner cited an informal IT arrangement. According to Hatter's testimony, the words were: "We got a guy, my brother's uncle's cousin does my IT, don't need you guys." The phrase, reported by Hatter, illustrates a widespread practice: relying on a single non-specialist to contain spend, without assessing residual risk.
Hatter also reported a standard response he regularly receives: "Thanks for shopping. You're too expensive." The refusal was unexceptional in the consultant's portfolio, but the consequences were not.
The Attack: Old Server, Exposed Backup
Three weeks after the refusal, Hatter received a call from the same firm's accountant. He recognized the number. The company was under ransomware attack. The server was an outdated, unpatched Windows system containing the most critical operational data. The backup resided on an external drive physically connected to the same machine.
Both devices had been encrypted. Hatter described the configuration with a precision that highlights its structural fragility: "Their entire backup is this external drive, which, of course, is now encrypted." The physical link between production and backup nullified the second's recovery function, turning redundancy into a single point of failure.
The operational impact was immediate and total. Hatter reported: "So, literally, they can't pay their employees. They don't know who owes them money." The company had no offline or isolated copies of its information assets. The brief does not specify whether the owner attempted to negotiate the ransom, nor the amount demanded.
"Their entire backup is this external drive, which, of course, is now encrypted"
The Collapse: From Years of Operation to Closure Within Months
The organization, active for years, ceased operations within months of the attack. The dossier does not document the exact liquidation path: no closure date, no cited legal documents, no statements from employees or clients. The source is exclusively Hatter, who noted he could not help the company after the incident and was unaware of any outcome from a potential ransom payment.
This is the case's main limitation. There is no company name, precise location, year of the event beyond "several years ago," nor independent sources confirming the sequence. The story remains a significant but unverifiable anecdote. Its utility lies in the pattern it illustrates, not in statistical validation.
What to Do Now
The construction firm's case offers three specific operational lessons, derived directly from the configuration documented in the brief.
First: physically separate backups from the production network. The external drive connected to the same Windows server rendered the backup useless when needed. A disconnected copy, updated on a regular cadence, would have preserved essential operational data.
Second: keep servers updated. The unpatched Windows system constituted the attack's entry point. The brief does not specify which vulnerability was exploited, but the lack of security updates is documented as a pre-existing condition.
Third: assess cyber risk in terms of business continuity, not just immediate cost. The owner calculated the consulting expense without quantifying the risk of total operational shutdown. Three weeks later, the cost of inaction materialized as operational paralysis and business closure.
Reading: The Cost of Inaction as a Missing Metric
The Hatter case is not a statistical datum but a structural narrative. Its narrative force lies in temporal compression: three weeks between refusal and attack, months between attack and closure. This timescale makes explicit what traditional business metrics often obscure: cyber risk as a low-perceived-probability, high-real-impact event.
The construction sector, cited by Hatter as the context of his experience, presents characteristics that amplify vulnerability. Small construction firms operate with thin margins, non-specialized IT staff, and a risk culture oriented toward physical safety rather than information security. The combination produces exactly the profile described: a single person for informal IT, dated servers, connected backups, no incident-response plan.
The brief does not document whether the firm reassessed its position after the attack, nor whether other firms in the same network modified their security approach. The story remains isolated, a single data point that does not permit generalization but mechanically illustrates the cause-effect relationship between risk underestimation and operational consequences.
For business decision-makers, the case suggests a concrete question: is the immediate savings on cybersecurity consulting commensurate with the risk of total business interruption? In the experience documented by Hatter, the answer arrived in three weeks, and it was definitive.
Information is based on the cited source and current as of publication.
Sources
- https://www.theregister.com/security/2026/10/08/cheapskates-wouldnt-pay-for-security-help-got-hit-by-ransomware-and-went-bust-months-later/5301757
- https://news.lavx.hu/article/cheapskates-wouldn-t-pay-for-security-help-got-hit-by-ransomware-and-went-bust-months-later
- https://nvd.nist.gov/vuln/detail/cve-2026-88772
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772
- https://www.cisa.gov/binding-operational-directive-22-01
- https://cisa.gov/known-exploited-vulnerabilities-catalog
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.