National industrial engineering, construction, and maintenance services specialist confirmed a cyber security incident after being listed by the RansomHub group. Enterprise networks were hardened post-incident; no physical site closures were required.