Signature Foods
When you supply household names, a single halted production line doesn't just cost a shift's output; it puts shelves at risk and trust on the line.
Move Intermodal
Intermodal logistics
300+
Belgium
CIO Tomas Tempelaars was five minutes into his commute when his phone rang. "There are a few numbers where, if they call before half past eight, you know something is wrong," he recalls.
His managed service provider had already taken first containment steps, isolating the affected systems. But by ten o'clock, the MSP concluded the situation was beyond its remit and called in Eye Security, a team it already trusted from earlier work.
"The MSP acted fast, immediately isolating the first affected systems," Tomas Tempelaars says. "Still, they recognised this was not just another alert. Within ninety minutes we were in a joint intake call with all the right people, which gave us the reassurance that the incident was being managed."
The trigger had appeared the night before. Endpoint detection had flagged credential harvesting, files being packaged for exfiltration, and unusual administrative connections. The MSP's quick isolation limited the immediate damage but the deeper entry point was still open. The pattern fit the classic double-extortion playbook: data theft already under way, ransomware likely to follow.
Move Intermodal's experience reflects a wider pattern across European transport and logistics:
"One full day of disruption is dramatic from a planning perspective. Transport would start to stall and restoring visibility becomes exponentially harder. That costs revenue and can trigger contractual exposure."
Tomas Tempelaars
CIO
The response was guided by a single principle: assume breach. The threat actors had already explored the backup estate. If unchecked, their next moves would have been to disable backups and detonate ransomware.
"Continuity comes first," Tomas emphasises. "We knew quickly that core operational servers were not down, but we switched to maximum containment to keep the problem as small as possible."
Bas van den Berg, Principal Cyber Security Expert at Eye Security, led the response and recalls the pressure of those first hours. "When we entered the environment, the attackers were only hours away from deploying ransomware. Our first task was to eradicate persistence and find the root cause before they had a chance to return. We removed backdoors, collected forensic evidence and worked with the MSP to reset all credentials and take the vulnerable VPN offline. From there, we connected the environment to our SOC so every move could be monitored in real time."
Thanks to those measures, business continuity held. "People could not use the file server for a few days, and printing was unavailable," Tomas Tempelaars says, "but the core processes continued."
The speed of recovery was not luck. Cybersecurity was already a priority at Move Intermodal. EDR was in place, a dedicated taskforce met regularly to improve security posture, and patch management and access control were on the agenda long before this incident.
"Preparation makes the difference," Bas underlines. "Because Move Intermodal already had EDR and a security program running, we could build on that instead of starting from scratch. From there, our role was to contain, eradicate, and monitor so attackers could not return. Without EDR in place, it is very likely this would have escalated into a large-scale ransomware attack. That combination, preparedness inside the company and immediate external support, is what stopped this from turning into a shutdown."
For Tomas Tempelaars, the way the two teams worked together mattered as much as the outcome.
"The updates were short and clear, we never sat with open questions. The way Eye Security worked with our team gave us peace of mind. They brought structure in the middle of the incident and helped us make the right decisions quickly."
Tomas Tempelaars
CIO
The attack was stopped in time but the threat was not going away. That is why Move Intermodal chose to continue with Eye Security as a Managed Detection and Response (MDR) customer.
"MDR means constant vigilance," Bas explains. "We do not just react when something happens. We continuously watch, hunt, and respond. For a sector where every hour of downtime has direct financial and contractual impact, this level of monitoring and response is mandatory."
"Now our systems are monitored around the clock, and if something happens again, we know it will be spotted and contained before it spirals out of control. That allows us to focus on what matters: keeping goods moving."
Tomas Tempelaars
CIO
Built on the NIST Cybersecurity Framework, this 5-minute assessment shows you exactly where the gaps are across detection, response, recovery and risk transfer and where Eye Security would close them. No sales call required.
Start the assessment
When you supply household names, a single halted production line doesn't just cost a shift's output; it puts shelves at risk and trust on the line.
Goed Belgium has found the complete package: technical strength, expert guidance, and the added safety of cyber insurance.
The construction company chose Eye Security to gain continuous detection and response, integrated cyber insurance, and awareness.