Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Cyber Services

Ransomware Recovery

Decryption using an array of over 100 tools, with on-site assessment of the entry point that let it in.

SDVOSBCertified
9FNE2CAGE Code
24 / 7 / 365SOC Monitoring
In-HouseForensic Capability

What is included

Decryption Attempt

Over 100 tools applied against the identified strain, with realistic assessment of what is recoverable.

Entry-Point Assessment

On-site work to establish how the attacker got in, how long they were present, and what else was reached.

Incident Response

Incidents identified, investigated, contained, remediated and recovered from, with forensics in-house when needed.

Hardening Before Return

The gap closed and the environment strengthened before systems are brought back into service.

Who this is for

  • Small business
  • Corporate IT
  • Law firms
  • Healthcare
  • Municipalities
  • Manufacturing
  • Anyone currently encrypted

The first hour, in order

If this is happening now, the sequence matters more than the speed.

Isolate, do not wipe. Disconnect affected systems from the network — pull the cable, disable the port, isolate through your endpoint tool. Do not reimage anything yet, and think carefully before powering machines off: memory can hold the key material, the process history and the account artefacts that tell you what happened. A well-meant rebuild in hour two destroys the evidence that determines your notification obligations in week three.

Assume identity is compromised. If the attacker deployed across your estate, they almost certainly hold domain-level credentials. Password resets and privileged account containment come early, and they need to be done in an order that does not tip the attacker off before you can execute it.

Call counsel, then your insurer, then responders. Counsel first, because engaging forensics through counsel can preserve privilege over the investigation. Your cyber policy almost certainly requires notice within a short window and may require you to use panel counsel and a panel forensics firm — using your own vendor first can jeopardise coverage. Read the policy now, not in hour six.

Preserve before you fix. Ransom notes, encrypted file samples, logs, firewall and VPN records, and the affected systems themselves. Logs roll. Cloud tenants have retention limits. Preservation is a first-hour task.

Do not communicate with the attacker yet. Not from a company account, not at all, until you have advice. Early contact sets expectations and forecloses options.

Whether to pay: the part that is not a business decision alone

We do not advise clients to pay or not pay — that is a decision for the organisation with its counsel and its insurer. What we do is make sure it is an informed one.

The sanctions problem is real. The U.S. Treasury’s Office of Foreign Assets Control has made clear that facilitating a ransom payment to a sanctioned entity or jurisdiction can itself violate sanctions regulations, with liability applying even where the payer did not know. Several ransomware groups and the individuals behind them are designated. Any payment decision requires sanctions screening, and this is exactly why counsel is involved before anything moves.

Decryptors are slower than people expect. Where a payment is made, the tool provided is frequently slow, partially effective, and requires substantial engineering to run at scale. Restoring from good backups is usually faster than decrypting, which is why the state of your backups is the single most decisive factor in how this ends.

Payment does not delete data. There is no enforceable assurance that exfiltrated data is destroyed, and re-extortion is common. A payment may buy silence for a period; it does not restore the position.

Recovery, in the order it has to happen

Scope before rebuild. How they got in, how long they were there, what they touched and whether they still have access. Rebuilding into an environment the attacker still holds access to is the most expensive mistake in this field, and it is common.

Rebuild trust, not just servers. Where domain-level compromise is established, credentials, service accounts and trust relationships need systematic treatment. Restoring a domain controller from a backup taken during the intrusion restores the intrusion with it.

Restore in business priority order. Agreed with the business rather than by IT alone, and verified as clean before reconnection. Backups themselves are validated — attackers target backup infrastructure first and specifically, and organisations regularly discover their restore point is inside the attacker’s dwell time.

Monitor heavily afterwards. Re-intrusion in the weeks following recovery is a known pattern, particularly where the initial access route was never conclusively identified. Enhanced monitoring through that period is not optional.

Then close the route. The unpatched edge device, the exposed remote access, the missing multi-factor authentication, the flat network. Recovery without remediation buys you a repeat.

Before it happens: the readiness that actually matters

Three things decide how bad a ransomware incident is, and all three are cheap compared with the incident.

Backups you have actually restored from. Offline or immutable, segregated from production credentials, and tested with a real restore rather than a successful job log. An untested backup is a hypothesis.

An incident response plan with names and numbers. Counsel, insurer, responders, leadership, communications — printed, because it will be needed when the network is down and the intranet is encrypted.

A tabletop exercise. The first time your leadership team makes a payment decision, a notification decision and a communications decision should not be at 2am during the real thing.

Readiness assessment, backup review, tabletop facilitation and a pre-negotiated response retainer are all quoted separately — and a retainer matters, because the worst moment to negotiate rates and terms is while the business is stopped.

Frequently asked questions

It is happening right now. What do I do first?

Isolate affected systems from the network but do not reimage or wipe. Assume credentials are compromised. Call counsel, then your insurer, then responders — the order matters for privilege and for coverage. Preserve logs and ransom notes. Do not communicate with the attacker yet.

Should we pay?

That is your decision with counsel and your insurer, and it must include sanctions screening — paying a designated entity can itself be a violation. Understand too that decryptors are often slow and partial, and that payment does not reliably delete stolen data.

They say they stole our data. Did they?

Their claims are not evidence in either direction. Forensics answers it — staging activity, archive creation, outbound volumes and the tooling left behind. That analysis determines your notification obligations, so restoring without it leaves an unquantified legal exposure.

Our backups are encrypted too. Now what?

Common, because attackers target backup infrastructure first. Options narrow but are not zero: older offline media, cloud snapshots outside the compromised credential scope, provider-side retention, and partial recovery of critical data. The honest range gets narrower the longer they were inside.

How long until we are running again?

Anywhere from days to weeks, driven mostly by backup quality and the extent of domain compromise. Anyone quoting a firm number before scoping is guessing. What we will give you early is a realistic range and the specific factors that would move it.

Can we just rebuild everything and move on?

Not safely. Rebuilding before scoping means you may rebuild into an environment the attacker still holds, and it destroys the evidence that establishes what was taken — which is what your regulators and your customers will eventually ask about.

In detail

Should you become a target of a ransomware attack, we provide decryption services utilizing a wide array of over 100 tools and software solutions. Our team will conduct an on-site assessment to identify the entry point utilized by the attacker and initiate the decryption process. 

In the event that decryption proves unsuccessful, we engage in negotiations with the attacker to mitigate the impact of the attack, although this option is considered a last resort.

Guides on this topic

Scope your requirement

If you are encrypted right now, use the urgent intake form rather than booking. Time matters, and the first hours shape what is recoverable. Do not power down or wipe anything until we have spoken.

Background reading: Ransomware: the two problems most vendors only half-solve

When you call

Information responders will ask for first

The first call is faster and more useful if someone has these answers ready. Partial answers are fine; guessing is not.

  • The text or a photo of the ransom note, and the file extension added to encrypted files
  • When the encryption was noticed and what first looked wrong
  • Roughly how many servers and workstations are affected, and whether cloud services or email are involved
  • The state of your backups: where they live, when the last good one ran, and whether they appear touched
  • Endpoint protection, firewall, and remote access tools in use, and who administers them
  • Your cyber insurance carrier and policy number, and whether the insurer has been notified
  • Who in the organization can authorize decisions, and who is the day-to-day contact

Write everything down with times as you go. A running log of who did what and when becomes part of the record later.

Deliverables

What the investigation should produce

Beyond getting systems running, a ransomware engagement should leave you with a written record that counsel, insurers, and leadership can rely on.

Timeline

A reconstructed sequence from initial access through encryption, with the evidence supporting each step.

Entry vector

How the attacker got in, stated with the confidence the evidence supports, and whether that route is now closed.

Scope of impact

Systems, accounts, and data stores reached, and findings on whether data was staged or sent out.

Preserved evidence

Images, logs, and artifacts collected with documented chain of custody, so findings can be defended later.

Remediation list

Prioritized fixes, from credential resets to configuration changes, so the same route is not used twice.

Carriers often have specific documentation needs. Our article on the forensic evidence cyber insurers need explains what is typically requested.

Obligations after an incident

Notification questions to raise with counsel

Whether an incident triggers notice to individuals, regulators, or business partners depends on what data was affected and where those people live. Forensic findings feed that decision; counsel makes it. This is general information, not legal advice.

  • State breach laws. Most states, including Arizona, have breach notification laws with their own definitions and timelines. Affected people in several states can mean several sets of requirements.
  • Sector rules. Healthcare organizations have separate federal obligations, covered in our overview of HIPAA breach forensic requirements. Financial and government contractors may have their own.
  • Contracts. Customer and vendor agreements often require prompt notice of a security incident, sometimes faster than any statute.
  • Law enforcement. Reporting to federal authorities is generally encouraged and can be coordinated through counsel.

Having a responder already in place shortens every one of these steps. Our comparison of an incident response retainer versus on-demand response sets out the tradeoffs. To discuss readiness, request a consultation.