Skip to main content

FLUX IT

All Case Studies

From Repeated Cyber Incidents to Eight Years of Cyber Resilience

Industry Transport & Heavy Logistics
Environment Hybrid Enterprise & Logistics Dispatch
Tenure 8+ Consecutive Years
Engagement Zero Trust, Network & Cloud

Executive Summary

Following multiple severe cyber security incidents, including a ransomware attack that encrypted critical operational servers, a leading Australian transport and logistics provider engaged FLUX IT to overhaul its technical architecture, implement enterprise cyber security, and eliminate business continuity risk.

What followed was a comprehensive two-year modernisation program across network segmentation, server platforms, Microsoft 365 cloud infrastructure, secure remote communications, and Zero Trust security controls. More than eight years later, the organisation continues to operate with zero reported cyber security incidents.

By replacing legacy single-server architectures with enterprise-grade redundant infrastructure, establishing deterministic network micro-segmentation, and enforcing rigid identity controls, FLUX IT helped transform an exposed operational environment into a hardened, high-availability platform that continues to scale without downtime.

8+ Yrs Zero Incidents Over eight consecutive years without a single ransomware or security breach.
96% Technical Debt Reduction Decommissioned fragile legacy single-points-of-failure and flat networks.
0 hrs Dispatch Interruption Two-year phased overhaul completed with zero operational transport downtime.

Confronting Ransomware Vulnerabilities

Prior to FLUX IT's engagement, the transport enterprise operated on an outdated, fragile infrastructure that left critical transport logistics exposed. The organisation had suffered two major cyber security incidents in consecutive years, culminating in a catastrophic ransomware compromise that encrypted mission-critical servers and paralysed dispatch operations.

A comprehensive technical audit revealed compounding architectural risks that left the business severely exposed to lateral movement propagation:

  • Lateral Movement Exposure: A single flat unsecured subnet enabled malware and threat actors to propagate freely between endpoints, storage units, and core servers.
  • Legacy Single Points of Failure: Outdated Small Business Server (SBS) multi-role platforms created fatal dependencies across file, identity, and email services.
  • Broad Attack Surface: Widespread use of local administrator rights, unchecked privilege creep, and little to no vulnerability or patch management drastically broadened exposure vectors.
  • Governance & Infrastructure Gaps: Undocumented processes, procedures, and infrastructure with no clear responsibility, ambiguous hardware ownership, and an absence of system accountability.

The FLUX IT Engineering Framework

FLUX IT structured and executed a multi-phased engineering roadmap designed to replace single points of failure with redundant, segmented, and cloud-managed infrastructure:

[01]

Network Core & Micro-Segmentation

Dismantled the legacy flat broadcast topology into isolated, security-hardened enterprise segments. Deployed a redundant Cisco core switching fabric, migrated to dedicated VLAN routing, and implemented Sophos Next-Gen Firewalls with deep stateful packet inspection, achieving a significantly improved perimeter defence and robust lateral movement risk mitigation.

[02]

Server Overhaul, Rack Consolidation & Physical Hardening

Replaced fragile SBS architecture with high-reliability dedicated server platforms. Deployed dual Active Directory Domain Controllers, isolated file clusters, and consolidated a congested server room into a structured single-rack system with centralised UPS power protection, overcoming physical limitations and mitigating physical denial-of-service risks.

[03]

Microsoft 365 Cloud & Unified Telephony

Transitioned legacy on-premises email to Microsoft 365 with advanced anti-phishing safeguards, reducing attack surface and mitigating risks of social engineering. Deployed Microsoft Teams for scalable cloud telephony / VoIP and engineered managed enterprise Wi-Fi across office and warehouse dispatch zones.

[04]

Zero Trust Governance & ERP Modernisation

Enforced strict Zero Trust administrative controls, mandatory Multi-Factor Authentication (MFA), centralised patch automation, and ongoing staff security education while modernising the core transport ERP environment for continuous dispatch availability.

Transformation Matrix

Domain Legacy Vulnerable State FLUX IT Hardened Architecture
Network Topology Single flat /24 broadcast domain with zero internal isolation or stateful inspection. Enterprise Cisco Fabric & Sophos NGFW: Micro-segmentation and East-West traffic inspection via isolated VLANs, host-based firewalls, and deep perimeter inspection to block lateral propagation.
Server & Endpoint Architecture Legacy Small Business Server (SBS) combining all core roles; single-node failure points with unmonitored endpoints. Dedicated Redundant Nodes & EDR: Dual Domain Controllers, Active Directory Tiered Admin Model (Tier 0/1/2) to stop credential harvesting, and Sophos for Endpoint with Attack Surface Reduction (ASR) rules.
Email & Productivity On-premises Exchange server exposed to unpatched vulnerabilities and lacking authentication hygiene. Microsoft 365 & Defender Hygiene: Full enforcement of SPF, DKIM, and DMARC (p=reject) paired with Safe Links, Safe Attachments, Zero-Hour Auto Purge (ZAP), and automated anti-phishing safeguards.
Identity & Access Unrestricted local administrative rights, privilege creep, single-factor passwords, and legacy protocol exposures. Zero Trust & Privileged Access: Entra ID Conditional Access, mandatory MFA, Windows LAPS to eliminate Pass-the-Hash, and complete disablement of insecure legacy protocols (SMBv1, NTLM).
Physical & Operational Security Tangled cabling, uncoordinated independent UPS units, lack of physical port controls, and zero centralised visibility. Consolidated Rack & Infrastructure Governance: Single-rack architecture with centralised UPS power protection, structured patch management cadences, fully documented standard operating procedures, and clearly defined system and hardware ownership.

Verified Business Impact

The two-year overhaul delivered immediate stability, followed by more than eight years of uninterrupted operational uptime for the enterprise:

  • 8+ Years of Incident-Free Operations: Completely eliminated recurring ransomware infections, malicious payloads, and cybersecurity-driven downtime.
  • Lateral Movement Risk Mitigation: VLAN segmentation and isolated boundaries effectively mitigate lateral movement risks across endpoints, core databases, and file servers, significantly reducing exposure from unresolved host vulnerabilities.
  • High-Availability Resilience: Server and power redundancy guarantee that hardware component failures fail over without interrupting round-the-clock transport dispatch.
  • Operational Dispatch Agility: Cloud telephony via Microsoft Teams and modernised ERP throughput improved operational tracking across fleet depots and mobile workers.
  • Vulnerability Management & Essential Eight Alignment: Sustained patch cadences, structured vulnerability management, and continuous identity verification ensure ongoing alignment with ACSC Essential Eight cybersecurity baselines.

Security Controls & Technologies

Security Controls Implemented by FLUX IT

  • Network Segmentation
  • Perimeter Defence
  • Identity & Access Management
  • Phishing Resistance
  • Attack Surface Reduction
  • Device Hardening
  • Delegation of Duty

Security Technologies Deployed

  • Sophos
  • Sophos Next Gen Firewalls
  • Cisco Enterprise Switching
  • Microsoft 365 & Entra ID
  • Multi-Factor Authentication (MFA)
  • Microsoft Teams (Cloud Telephony / VoIP)
  • Centralised UPS Power Systems