Case Studies

The situation was clear. The organization was not.

What began as a temporary administration turned into a restructuring effort. Then came the attack. And with it, a task for which there was no mandate.

Restructuring Environment · IT Turnaround · Crisis Intervention · Restoring Control

Contents

Background

A publicly traded manufacturing company with five production sites and a history marked by structural challenges. Two business segments with different cultures and operational approaches had been brought together under one roof without a coordinated integration process. In 2020 and 2021, this tension was overshadowed by strong growth. In the second half of 2022, the tide turned: downwardly revised forecasts, the CEO’s departure effective immediately, and the appointment of the company’s first-ever CIO. Leadership changes continued over the next two years—four CFOs, two CEOs, and a Chief Restructuring Officer installed as the de facto representative of creditors. The CTO remained the sole constant at the C-suite level.

Mandate

At the end of 2022, an external IT leadership team was brought in to provide interim management of the core IT organization—infrastructure, workplace, and service management—until a permanent successor could be found. They began in mid-January 2023. The role was clearly defined and independent of existing program structures. The mandate was clearly limited: restoring control over the IT base organization. IT security and cyber defense were not part of this mandate. Within the first two weeks, the scope changed. The framework conditions did not.

Initial Assessment and Restructuring Mandate

The initial situation report was compiled immediately after taking office—a structured assessment of the existing reality, with a strict separation of facts, assumptions, and opinions. The situation report was prepared independently of existing programs and their reporting frameworks. It was this separation that provided a solid basis for decision-making—not the report itself.

The result made a transitional administration impossible. An external auditor’s report had assessed the IT organization as being significantly deficient just a few months earlier. The report existed. It had not triggered any operational consequences. The infrastructure was in a state that did not allow for management but required a turnaround. And IT security would not withstand a targeted attack—a finding that fell outside the scope of the mandate but was documented in the situation report.

With the first status report, the administrative assignment was transformed into a restructuring mandate in consultation with the company.

Renovation in 2023

Over the course of 2023, the IT foundation was established within the contracted scope. Infrastructure, workplace, and service management were once again under control—with clear responsibilities, effective processes, and robust reporting.

The plan was to complete the engagement by the end of the first quarter of 2024. The basis for this was included in the scope of the engagement.

What was missing: a cyber defense. That was outside the scope of the contract. This distinction becomes relevant.

An attack as a reality check

In February 2024, a ransomware attack affected all five production sites. The attack targeted an organization whose critical security infrastructure had not been included in the scope of the project.

The initial assessment had documented the threat and clearly identified the likelihood of an attack. Anything that had not been specifically requested was not included.

Second Situation Report

By the morning after the attack, the extent of the damage was clear: a major ransomware attack. No effective action had been taken overnight.

On Day 1, the second situation report was compiled—remotely, within a few hours. It was not a continuation of the first report, but a separate assessment based on new conditions: what had not happened overnight; what immediate measures were lacking; and why existing structures had failed to enable an operational response. Based on this, initial crisis measures were defined and implemented. The IT systems were disconnected from the internet that same afternoon.

The second assessment served as the basis for the decision to proceed with the procedure.

Escalation of the situation

On Day 2, external forensic experts were on site. By Day 3, the evidence was clear: the existing organizational structure and decision-making framework were not equipped to respond to this situation. Even effective forensic work was hampered under these conditions.

As the situation escalated, further intervention became necessary. Just as the renovation itself had gone beyond the scope of the original contract.

On-site intervention

On Day 3, the missing crisis management structure was established within a single day. Direct links to the board, including the CFO and CTO. A steering committee with defined decision-making authority. Technical crisis teams with clear chains of command. Secure zones with explicit access protocols. A briefing for the executive board with a clear focus: getting production back up and running as quickly as possible.

The intervention was aimed at restoring decision-making capacity where it had been lost. Decisions were not merely prepared; they were made and implemented. The intervention was carried out in close coordination with the on-site forensic team and within the existing management structure, with a focus on decision-making capacity and a clear allocation of responsibilities.

From that point on, forensic work could take hold. Not because of new technology, but because of the ability to control the process.

Restoring controllability

The recovery followed a clear phased approach: containment and safeguarding of data integrity, prioritized restart of business-critical systems, stabilization, and a controlled return to normal operations. The restart did not follow the original operational sequence, but rather a prioritized, controllable sequence.

Core systems were restored within twelve days. Key production processes were back up and running about three weeks after the attack. Both of these achievements were made while the company was simultaneously undergoing a restructuring process.

A structural pattern complicated the process: The crisis management team at the executive level was organized according to hierarchy, not according to operational expertise relevant to this situation. Business needs—such as resuming production, managing supply chains, and addressing customer requirements—were incorporated into the IT recovery plan too late, even though prioritization had been prepared and planned. As a result, the executive team’s assessment of the situation and the operational reality inevitably began to diverge too early.

Handover and Completion

In June 2024, Phase 3—stabilization, optimization, and modernization—was formally handed over to the CIO. The mandate came to an end.

What was handed over was a revitalized grassroots organization and a crisis management structure built under real pressure. Both are holding up. Operations were not handed over until these structures were functioning independently.

All details have been anonymized. The incident was reported by WirtschaftsWoche, ZEIT/dpa, and heise online, among others. The internal perspective is based on documented work progress from the client engagement.

Recurring service modules

Independent Assessment of the Situation

Distinguishing between facts, assumptions, and opinions. A basis for decision-making that emerges outside existing reporting frameworks—and is therefore reliable

Developing Operational Decision-Making Capabilities

Intervening in systems that are no longer capable of responding on their own. Responsibility is assumed and maintained until results are visible.

Structured restart

Prioritize based on value creation, not on existing infrastructure. Do not hand over until the structures built can stand on their own.

Lorem Ipsum

Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata sanctus est Lorem ipsum dolor sit amet. Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata sanctus est Lorem ipsum dolor sit amet.

Are there any situations that remind you of this case?

The initial consultation is confidential and is intended to help us clearly assess your situation.

Fast. Focused. Effective.

After one or two meetings, we’ll know where you stand and what matters most next. You’ll get a clear picture and initial ideas—not in weeks, but in days.

Your next step:

Privacy Overview

We use cookies and similar technologies to ensure the secure and reliable operation of this website. Some cookies are technically necessary, while others are used to optimize content and features and to analyze website usage. For more information about the processing of personal data and your rights, please see our Privacy Policy. You may modify or withdraw your consent at any time, effective for the future.