Cyber Services
Ransomware Recovery
Decryption using an array of over 100 tools, with on-site assessment of the entry point that let it in.
What is included
Decryption Attempt
Over 100 tools applied against the identified strain, with realistic assessment of what is recoverable.
Entry-Point Assessment
On-site work to establish how the attacker got in, how long they were present, and what else was reached.
Incident Response
Incidents identified, investigated, contained, remediated and recovered from, with forensics in-house when needed.
Hardening Before Return
The gap closed and the environment strengthened before systems are brought back into service.
Who this is for
- Small business
- Corporate IT
- Law firms
- Healthcare
- Municipalities
- Manufacturing
- Anyone currently encrypted
The first hour, in order
If this is happening now, the sequence matters more than the speed.
Isolate, do not wipe. Disconnect affected systems from the network — pull the cable, disable the port, isolate through your endpoint tool. Do not reimage anything yet, and think carefully before powering machines off: memory can hold the key material, the process history and the account artefacts that tell you what happened. A well-meant rebuild in hour two destroys the evidence that determines your notification obligations in week three.
Assume identity is compromised. If the attacker deployed across your estate, they almost certainly hold domain-level credentials. Password resets and privileged account containment come early, and they need to be done in an order that does not tip the attacker off before you can execute it.
Call counsel, then your insurer, then responders. Counsel first, because engaging forensics through counsel can preserve privilege over the investigation. Your cyber policy almost certainly requires notice within a short window and may require you to use panel counsel and a panel forensics firm — using your own vendor first can jeopardise coverage. Read the policy now, not in hour six.
Preserve before you fix. Ransom notes, encrypted file samples, logs, firewall and VPN records, and the affected systems themselves. Logs roll. Cloud tenants have retention limits. Preservation is a first-hour task.
Do not communicate with the attacker yet. Not from a company account, not at all, until you have advice. Early contact sets expectations and forecloses options.
Whether to pay: the part that is not a business decision alone
We do not advise clients to pay or not pay — that is a decision for the organisation with its counsel and its insurer. What we do is make sure it is an informed one.
The sanctions problem is real. The U.S. Treasury’s Office of Foreign Assets Control has made clear that facilitating a ransom payment to a sanctioned entity or jurisdiction can itself violate sanctions regulations, with liability applying even where the payer did not know. Several ransomware groups and the individuals behind them are designated. Any payment decision requires sanctions screening, and this is exactly why counsel is involved before anything moves.
Decryptors are slower than people expect. Where a payment is made, the tool provided is frequently slow, partially effective, and requires substantial engineering to run at scale. Restoring from good backups is usually faster than decrypting, which is why the state of your backups is the single most decisive factor in how this ends.
Payment does not delete data. There is no enforceable assurance that exfiltrated data is destroyed, and re-extortion is common. A payment may buy silence for a period; it does not restore the position.
Recovery, in the order it has to happen
Scope before rebuild. How they got in, how long they were there, what they touched and whether they still have access. Rebuilding into an environment the attacker still holds access to is the most expensive mistake in this field, and it is common.
Rebuild trust, not just servers. Where domain-level compromise is established, credentials, service accounts and trust relationships need systematic treatment. Restoring a domain controller from a backup taken during the intrusion restores the intrusion with it.
Restore in business priority order. Agreed with the business rather than by IT alone, and verified as clean before reconnection. Backups themselves are validated — attackers target backup infrastructure first and specifically, and organisations regularly discover their restore point is inside the attacker’s dwell time.
Monitor heavily afterwards. Re-intrusion in the weeks following recovery is a known pattern, particularly where the initial access route was never conclusively identified. Enhanced monitoring through that period is not optional.
Then close the route. The unpatched edge device, the exposed remote access, the missing multi-factor authentication, the flat network. Recovery without remediation buys you a repeat.
Before it happens: the readiness that actually matters
Three things decide how bad a ransomware incident is, and all three are cheap compared with the incident.
Backups you have actually restored from. Offline or immutable, segregated from production credentials, and tested with a real restore rather than a successful job log. An untested backup is a hypothesis.
An incident response plan with names and numbers. Counsel, insurer, responders, leadership, communications — printed, because it will be needed when the network is down and the intranet is encrypted.
A tabletop exercise. The first time your leadership team makes a payment decision, a notification decision and a communications decision should not be at 2am during the real thing.
Readiness assessment, backup review, tabletop facilitation and a pre-negotiated response retainer are all quoted separately — and a retainer matters, because the worst moment to negotiate rates and terms is while the business is stopped.
Frequently asked questions
It is happening right now. What do I do first?
Isolate affected systems from the network but do not reimage or wipe. Assume credentials are compromised. Call counsel, then your insurer, then responders — the order matters for privilege and for coverage. Preserve logs and ransom notes. Do not communicate with the attacker yet.
Should we pay?
That is your decision with counsel and your insurer, and it must include sanctions screening — paying a designated entity can itself be a violation. Understand too that decryptors are often slow and partial, and that payment does not reliably delete stolen data.
They say they stole our data. Did they?
Their claims are not evidence in either direction. Forensics answers it — staging activity, archive creation, outbound volumes and the tooling left behind. That analysis determines your notification obligations, so restoring without it leaves an unquantified legal exposure.
Our backups are encrypted too. Now what?
Common, because attackers target backup infrastructure first. Options narrow but are not zero: older offline media, cloud snapshots outside the compromised credential scope, provider-side retention, and partial recovery of critical data. The honest range gets narrower the longer they were inside.
How long until we are running again?
Anywhere from days to weeks, driven mostly by backup quality and the extent of domain compromise. Anyone quoting a firm number before scoping is guessing. What we will give you early is a realistic range and the specific factors that would move it.
Can we just rebuild everything and move on?
Not safely. Rebuilding before scoping means you may rebuild into an environment the attacker still holds, and it destroys the evidence that establishes what was taken — which is what your regulators and your customers will eventually ask about.
In detail
Should you become a target of a ransomware attack, we provide decryption services utilizing a wide array of over 100 tools and software solutions. Our team will conduct an on-site assessment to identify the entry point utilized by the attacker and initiate the decryption process.
In the event that decryption proves unsuccessful, we engage in negotiations with the attacker to mitigate the impact of the attack, although this option is considered a last resort.
Scope your requirement
If you are encrypted right now, call 602-725-2818 rather than booking. Time matters, and the first hours shape what is recoverable. Do not power down or wipe anything until we have spoken.
Background reading: Ransomware: the two problems most vendors only half-solve