Cut the infected machines off from the network — pull the Ethernet, drop the Wi-Fi — and then slow down. The two most damaging moves in any attack's first hour are both cleanups: wiping machines to reinstall, and tidying away encrypted files. Leave servers and NAS units exactly as they are until a plan exists; photograph the ransom note, and copy down the strange new extension the files carry. Above all, suspend every scheduled backup right now: the next automatic run can push encrypted copies over the clean ones you'll want later.
One admin task belongs in hour one as well. Where personal data is involved, UK GDPR may treat the attack as a reportable breach — so whoever owns compliance in your business should hear about it today, not at the end of the week.
Copies the malware never touched. Off-site and offline backups. Version history in the big cloud platforms — SharePoint, OneDrive, Dropbox and Google Drive can all step files back to the day before. Snapshots on the NAS; shadow copies on Windows. Current strains hunt snapshots and shadow copies to destroy them, but their aim is imperfect, and partial survivors turn up in case after case.
A decryptor someone has already written. Security researchers and the No More Ransom initiative publish free tools for every family that gets cracked. Pin down which family hit you — the note's wording and the renamed files' suffix identify it — then check whether yours has been broken. What you must never do is wire money to an anonymous 'guaranteed decryption' site: the honest ones are middlemen paying the criminals with a markup, and the rest are simply thieves.
Whatever the encryption never got to. Encrypting a company's storage takes hours, and plenty of attacks die early — cut short by a reboot, an alert admin, or their own bugs. Bench work on real incidents turns up secondary volumes never visited, older versions of files sitting in unallocated space, VM snapshots the malware treated as opaque blobs, database dumps it didn't understand, and files damaged only in their opening blocks. Finding it all is methodical rather than magical: image every disk, then audit the images file by file.
We don't pay ransoms, we don't negotiate with the people behind the attack, and we won't do either on a client's behalf. The position is practical as much as principled: plenty of payers receive broken decryptors or silence; payment flags your firm as willing for the next crew; the UK's official advice is against paying; and where a sanctioned group wrote the strain, the payment itself can be unlawful. Every hour and pound is better spent on the three routes above — which, in most incidents we see, return more than the victim believed possible on day one.
Log the crime with Action Fraud, and don't scrap the encrypted disks. Ransomware families do get cracked long after their attacks, and a preserved drive costs shelf space while a discarded one closes the door for good.
Courier or post in the affected storage — label multi-drive systems by bay — and every disk is imaged before analysis touches anything, so no original is ever worked on. You'll receive a written statement of what's recoverable via all three routes, plus one fixed quote. Ransomware is treated as forensic work on our tariff, which means the agreed figure is payable before bench work begins rather than after it. If the attack is still unfolding, ring 0800 689 0668 and say so — live incidents go to the head of the queue.
The service page for ransomware data recovery carries the full detail, and the hardware most business data sits on has pages of its own: RAID recovery, NAS recovery and SAN and virtual machine recovery.
The costliest thing in most attacks isn't the encryption — it's the backup job that ran afterwards. Suspend every schedule the moment ransomware is confirmed, before automation replaces your clean copies with locked ones.
The diagnostic is free, the quote is fixed, and logical faults run no fix no fee. Start online or ring the freephone.