The Ministry of Digital Governance of the Hellenic Republic runs Greece's national digital transformation strategy, delivering fast, reliable online government services to citizens and businesses. Ransomware is a particular concern for public-sector organisations: a single undetected breach could mean catastrophic loss of sensitive data, prolonged downtime for essential services, and eroded public trust.
The Ministry had robust defences in place but identified two gaps. Manual security monitoring was impossible during out-of-office hours, leaving a window of vulnerability. And there was no dedicated containment solution to stop a ransomware attack if it slipped past the network perimeter. The goal was clear: real-time automated detection and containment across its critical cloud and on-premises storage, stopping sophisticated attacks at the earliest point.
While EDR and XDR solutions are valuable to protect endpoints and detect threats, we recognized that ransomware could still evade these measures and target our on-premises and cloud storage repositories. BullWall Ransomware Containment offered a unique, agentless approach and would provide real-time ransomware containment at the storage layer.
After assessing various EDR and XDR solutions, the Ministry selected BullWall, working with longstanding Ricoh partner Doxiadis Graphotechniki S.A. Together, the teams integrated the solution across both storage environments, set customised detection thresholds, and built incident response playbooks. Because the architecture is agentless, there was no need to deploy software on individual endpoints, drastically reducing complexity and deployment time.
Today the solution monitors the Ministry's storage landscape around the clock and immediately isolates an endpoint or user when malicious encryption is detected, stopping threats from spreading. Within days of deployment, Ransomware Containment
was delivering actionable insight into data access patterns and had already flagged several instances of potentially malicious activity. The automated detection and containment has also reduced the burden on the IT and security team, who now focus on strategic, higher-value work rather than manually monitoring storage.
We would recommend Ransomware Containment to any organisation seeking to strengthen its ransomware defences. The ease of deployment, responsive support, and proven effectiveness make it a smart choice for public sector entities committed to safeguarding their digital assets and maintaining public trust.
With Ransomware Containment, the Ministry has strengthened its cybersecurity posture and gained peace of mind that it is well-protected against future threats. The BullWall solution provides an extra layer of protection that complements existing perimeter defences and ensures the Ministry can identify and recover quickly in the event of a ransomware incident. Feedback from the IT and security teams has been overwhelmingly positive, centring on the intuitive dashboard, granular monitoring and alerting, and the confidence that a ransomware attack can be contained automatically.



