Key Takeaways

  • BullWall now monitors cloud and on-premises storage for malicious encryption around the clock.
  • Agentless deployment reduced endpoint installation work and enabled automated isolation of suspicious users or devices.
  • The project reflects a wider move toward data-centric ransomware controls that complement EDR and XDR.

The Ministry of Digital Governance of the Hellenic Republic has deployed BullWall Ransomware Containment across critical cloud and on-premises storage, adding automated detection and isolation at the data layer to its existing cyber defenses.

The deployment addresses two gaps identified by the Ministry of Digital Governance of the Hellenic Republic. Manual storage monitoring was not practical outside normal working hours, and the ministry lacked a dedicated containment mechanism for ransomware that evaded perimeter, endpoint detection and response, or extended detection and response controls.

While EDR and XDR identify suspicious activity across endpoints and connected systems, ransomware that reaches shared storage may encrypt large volumes of operational data before a human analyst can intervene. Public-sector systems bring an additional complication: extended disruption can affect services used by citizens and businesses, not merely internal workflows.

“While EDR and XDR solutions are valuable to protect endpoints and detect threats, we recognized that ransomware could still evade these measures and target our on-premises and cloud storage repositories,” said the director general of the Ministry of Digital Governance of the Hellenic Republic. “BullWall Ransomware Containment offered a unique, agentless approach and would provide real-time ransomware containment at the storage layer.”

Working with longstanding Ricoh partner Doxiadis Graphotechniki S.A., the Ministry of Digital Governance of the Hellenic Republic integrated the containment solution across both storage environments. The teams configured customized detection thresholds and developed incident-response playbooks governing what should happen when the system identifies behavior associated with malicious encryption.

Rather than waiting for an analyst to investigate an alert, the platform immediately isolates the relevant endpoint or user, restricting how far encryption spreads through connected file repositories. Its agentless architecture also means that software does not have to be installed separately on individual endpoints, reducing deployment time.

During the initial rollout, the platform provided information about data-access patterns and flagged several instances of potentially malicious activity. The source did not characterize those events as confirmed ransomware attacks. Still, the early warnings enabled the Ministry of Digital Governance of the Hellenic Republic to investigate and remediate potential vulnerabilities before attackers could exploit them.

Ransomware remains a persistent public-sector threat. The European Union Agency for Cybersecurity identified ransomware as Europe’s leading cyber threat in its Threat Landscape 2023 and listed public administration among the most targeted sectors.

Government exposure is also visible beyond Europe. Sophos reported in its State of Ransomware in State and Local Government 2024 that 69% of surveyed government organizations experienced ransomware attacks, while 90% of successful attacks resulted in data encryption (source). Those figures help explain why storage monitoring is increasingly treated as a separate control rather than an incidental feature of endpoint security.

Containment, however, is only one part of cyber resilience. NIST emphasizes protection and recovery of critical data stores, including the use of resilient storage and recovery practices. Immutable backups, tested restoration procedures, identity controls and incident playbooks remain relevant even when real-time containment is present. A system can limit damage, but recovery readiness still determines how quickly essential services return.

The approach also fits the detect, respond and recover functions of the NIST Cybersecurity Framework and the resilience expectations associated with the EU NIS2 Directive. Other vendors, including Rubrik and Cohesity, address parts of the storage-layer containment and cyber-recovery market, suggesting that data-centric protection is developing into a broader enterprise category.

For the Ministry of Digital Governance of the Hellenic Republic, automation has reduced the need for staff to monitor storage manually and allowed security personnel to concentrate on higher-value work. While endpoint defenses remain valuable, securing the data itself provides another opportunity to stop ransomware before an isolated compromise becomes a government service outage.