What a Contained Cyber Attack Looks Like for a Dallas or Plano Business
Three real client containments with the timelines intact, including a Plano device beaconing to China for 17 hours and a Microsoft 365 account locked in under 15 minutes.
Every cybersecurity company in North Texas will tell you that it stops attacks. Very few of them will show you a clock.
That gap is what this article is meant to close. What follows are three real engagements from our own client work, with the timelines left intact. One involves a wireless device inside a Plano medical practice that had been quietly sending data to China for seventeen hours before anyone looked at the right logs. One involves a software company whose Microsoft 365 environment absorbed 1,520 login attempts from 1,510 different addresses across 44 countries. The third is a healthcare software company that arrived with 467 unresolved vulnerabilities and no security program at all.
None of these stories ends in a breach notification letter. That is the entire point. What separates a bad afternoon from a reportable incident is almost never how clever the attacker was. It is how many minutes passed between the moment something became visible and the moment somebody acted on it.
If you run a business in Dallas, Plano or Frisco, the useful question to put to a security vendor is not whether they will stop an attack. It is what their most recent containment actually looked like, measured in minutes, and whether they will show you the numbers.
Containment Is the Only Security Word That Comes With a Number Attached
Containment means cutting an attacker off from what they are trying to reach, before they reach it. Prevention is the wall. Detection is the alarm. Containment is the moment somebody pulls the plug on the intruder. It is the only one of the three that produces a hard number you can hold a vendor to, because it runs on a stopwatch that starts when the alert fires and stops when the threat can no longer move.
Almost every security product sells prevention and detection. Both are necessary and neither is sufficient, because both are silent about what happens next. A firewall that blocks 36,231 sessions has done real work. If a device on your network is still leaking data through a channel that firewall cannot inspect, the block count is not a result. It is a statistic.
The business translation is straightforward. Downtime, legal exposure, insurance claims and lost revenue all scale with dwell time, which is the industry term for how long an attacker sits inside your environment before anyone removes them. A compromise contained in two minutes costs you the two minutes. The same compromise contained in two weeks costs you a forensic investigation, a legal review of your notification obligations, an uncomfortable conversation with your insurance carrier, and whatever your customers decide to do afterward. Our published case studies exist so clients can check those timelines rather than take our word for them.
Seventeen Hours Undetected and Two Minutes to Contain, in Plano
A multi provider medical practice in Plano came to us with a reasonable question and no way to answer it. They had invested in a capable next generation firewall, which is a firewall that inspects the contents of traffic rather than just the addresses on it. On paper the configuration looked serious, with 66 firewall rules and 26 alert rules. Nobody could say whether any of it worked, because the security email inbox had become unreadable and the staff had stopped opening it.
They are a HIPAA covered entity, meaning federal healthcare privacy law obligates them to maintain documented, functioning safeguards over patient information. The distance between what their firewall claimed to do and what it actually did was unknown, and unknown is not a defensible position in front of a regulator. Full findings are in the Plano medical practice case study.
We deployed a log collector and captured twenty four hours of full fidelity traffic, 2.7 million log lines across 690,955 sessions. Within four hours we had found three systemic failures. Twenty one rules labeled as recording attack attempts had never once fired, so 1,062 genuine attack sessions in a single day were invisible. Twenty rules meant to catch data leaving the network were matching inbound scans instead, so all 137 alerts in that category represented exactly zero data leaving. And one misconfigured rule generated 220,890 events in twenty four hours, which was 98 percent of the entire alert volume. That single rule was why nobody read the security mailbox. The real signal lived in the remaining two percent, and no human being was going to find it there.
At hour eight, the analysis surfaced the thing that mattered. A wireless device had been beaconing to Chinese infrastructure for at least seventeen hours. It was a small USB over network adapter made in Shenzhen running firmware from 2020, the kind of forty dollar convenience device somebody buys to share a printer and never thinks about again. The firewall had already quarantined it, and that quarantine blocked 36,231 inspected sessions with zero bytes leaving. The device had found the seam. It was tunneling data out through a low level protocol that never reaches the layer where the quarantine rules live, pushing 408 kilobytes through 5,171 of those sessions to a Chinese domain provider.
Containment was applied one layer down, at the network hardware itself, with a lease denial and a block at the wireless controller. Beaconing stopped within two minutes.
Seventeen hours undetected followed by two minutes to contain is not a story about a brilliant response. It is a story about what visibility buys you. Everything expensive in that engagement happened during the seventeen hours when nobody could see.
Fifteen Hundred Login Attempts From Forty Four Countries and Nobody Got In
The second engagement involves a Plano based company that builds electronic health records software used by hospitals and clinics. Their position in the supply chain makes them a target worth real patience, because a compromise there does not stop at their own data. It extends downstream into every clinical operation running their platform.
They had 58 user identities in Microsoft 365 and no monitoring at the cloud application layer, which means nobody was watching who logged in, from where, or what got shared outside the company. They also had a complication that rules out the easy answer. The company legitimately operates in the United States and Colombia, with staff in Plano, Richardson, Bogota and Medellin. A blunt policy blocking all foreign access would have shut down a third of the workforce on day one.
Across roughly nine months and 43,865 monitored events, one pattern emerged that no native Microsoft tool would ever have assembled. A single user account absorbed 1,520 failed login attempts from 1,510 unique addresses in 44 countries, and 1,500 of those addresses were used exactly one time each. That is not a brute force attack, which hammers repeatedly from one place and trips a lockout. That is a distributed credential campaign engineered to stay underneath every per address lockout threshold Microsoft enforces. Each address contributes one attempt and vanishes. To the built in tooling it looks like 1,520 unrelated typos spread across a year and a planet. Only aggregation across the full event history reveals one adversary.
The campaign escalated deliberately, opening with two attempts in month one and reaching 725 attempts across 24 countries by month eight. That is the signature of an attacker who probed, confirmed nothing was pushing back, and increased pressure accordingly. The outcome after nine months was zero successful logins from any hostile address, with every confirmed login tracing back to approved geography and multi factor authentication enforced throughout. The record is in the Plano EHR monitoring case study.
That result deserves a plain statement of what it is worth. Nothing happened. No incident, no notification, no insurance claim, no phone call to a hospital customer. Nine months of escalating pressure produced no business consequence whatsoever. That is what a working security program looks like, and it is hard to sell, because the deliverable is an absence.
Under Fifteen Minutes From Alert to Locked Account
The same engagement produced the containment number that matters most, because in this case data actually moved.
The account the campaign had been grinding against had at some point created anonymous sharing links in SharePoint, which are links that work for anyone holding them with no login required. Those links were redeemed from Seoul, South Korea. Six access events occurred inside a twenty nine second window and two documents were downloaded.
The analyst response followed a protocol worth stealing. Lock first, investigate second. The account was locked before anybody had determined whether the access was malicious, whether the documents were sensitive, or who was on the other end. Alert to locked account took under fifteen minutes.
The investigation afterward confirmed both documents were sales and marketing collateral containing no client data and no patient information. That outcome was luck. The response was not. Had those two files been a patient list, the fifteen minute lock would have been the difference between an internal note and a federally mandated breach notification with a legal bill attached. This is the habit most in house teams get backwards. Waiting to confirm that access is hostile hands the attacker exactly the window they need.
Making that speed possible required a geographic model with three tiers rather than a switch with two settings. Access from the United States and Colombia generates no alert. Access from thirty sanctioned countries triggers automatic lockdown with no human in the loop. Everything else, which is where Seoul landed, gets flagged and held for review. Across nine months, 52 countries touched that tenant, so without the tiered model the Seoul event would have been one flag among hundreds and the fifteen minutes would have been fifteen days. If your own Microsoft 365 environment has never been examined this way, our guide on the first forty eight hours after a compromised mailbox is the place to start, and email security is where most of these campaigns begin.
What the Three Timelines Have in Common
Our third case involves a 45 employee healthcare software company where we came in as the primary technology provider rather than a security add on. We built the program from nothing, remediated 467 vulnerabilities, migrated their infrastructure to the cloud with identity controls established during the move rather than bolted on afterward, and delivered a documented HIPAA posture they could hand an auditor. That work is the healthcare EHR company case study, and it is why we treat managed technology services and security as one discipline rather than two vendors pointing at each other.
Look at all three together and the same factors appear every time.
Visibility comes before speed. The Plano practice contained a live compromise in two minutes, and the seventeen hours before it were the expensive part, because nobody could see. This is why continuous vulnerability management and honest external scanning are not optional line items. You cannot respond to what you have never looked at.
Aggregation beats alerting. The credential campaign was invisible to every individual alert and obvious across the whole dataset. The 220,890 event rule proves it from the other direction, where more alerts produced less awareness. If your provider reports how many alerts it generated last month rather than what it concluded, you are buying volume, not analysis.
Protocol beats judgment under time pressure. Lock first, investigate second is a decision made in advance so nobody has to make it at eleven at night with incomplete information. The same logic governs whether anyone has actually restored from your backups recently, which is the difference between tested recovery and a hopeful assumption, and whether your compliance obligations are documented before a regulator asks rather than reconstructed afterward.
What to Ask Before You Hire Anyone in Dallas, Plano or Frisco
Take these questions into your next vendor conversation, whether you are talking to us or to somebody else.
Ask what their most recent containment was and how long it took from alert to action. If the answer is a product name rather than a number of minutes, you have learned something. Ask whether they are watching your Microsoft 365 or Google environment at the identity layer, because your firewall cannot see a login from Seoul that used a valid password. Ask who is on the other end of an alert at two in the morning on a Sunday, and whether that person can act or only forward an email.
The businesses we work with across McKinney, Collin County and the wider Dallas Fort Worth area are not asking for a product catalog. They are asking whether somebody is actually watching, and how fast that somebody moves. If you already have an internal technology team and want security layered alongside it rather than replacing it, that is a co-managed arrangement and it is a common shape for a first engagement. For a narrative version of a live response, see our walkthrough of the first sixty minutes of a ransomware attack.
Talk to Someone Who Will Show You the Clock
Innovation Network Design is headquartered in McKinney and works with businesses throughout Collin County, Dallas, Plano, Frisco and the rest of North Texas. Every engagement above began the same way, with somebody deciding they were tired of not knowing.
If you want to find out what is actually happening on your network before an attacker tells you, start with a security assessment or reach us through our contact page. You can also call 512-518-4408 and talk to someone who will answer the questions above about our own work, with numbers.
Frequently Asked Questions
What does containment mean in cybersecurity?
Containment is the step where an attacker is cut off from the systems or data they are trying to reach, after they have already gotten in somewhere. It differs from prevention, which keeps them out, and from detection, which only tells you something is wrong. Containment is measured in elapsed time from alert to action, which makes it the one part of a security program you can hold a vendor to with a number.
How long does it take to contain a cyber attack on a small business?
That depends almost entirely on whether anyone can see the activity, not on how sophisticated the attack is. In the Plano engagement above, containment took two minutes once the traffic was visible, but the device had been active for seventeen hours before that. In the Microsoft 365 case, an account was locked in under fifteen minutes from the initial alert. Averages for businesses without monitoring are measured in weeks, which is where the real cost sits.
Should we lock an account before we know whether the access was malicious?
Yes, in almost every case. Locking an account is reversible and takes seconds, while waiting to confirm intent gives an attacker time to move deeper or take data. The protocol our analysts follow is lock first, investigate second, and it is why a suspicious download from Seoul stayed a fifteen minute incident instead of a breach notification.
Can a firewall alone stop these kinds of attacks?
No, and the Plano medical practice is a direct example of why. Their firewall correctly quarantined a compromised device across more than 36,000 sessions, but the device tunneled data out through a low level protocol the firewall could not inspect. A firewall is one layer. It cannot see logins to cloud services, anonymous file sharing links, or traffic that never reaches the layer where its rules are written.
Need Help With This?
Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.
Mark Sullivan
Innovation Network Design
With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.
Ready to Secure Your Business?
Get a free security assessment and find out where your organization stands.