By the time a ransom note is on screen the attacker has finished. What has not finished is your own automation, and the difference between a bad week and a ruinous one is usually decided by what your systems do to themselves over the next few hours.
The attacker's clock stopped when the encryption run completed. Your own is still going, and it is attached to everything that copies data on a schedule: the nightly backup job, the hourly snapshot, the replication link to the second site, the folder sync running quietly on every desktop. None of those can tell a legitimate change from a malicious one. They see files that have been modified and they do exactly what they were configured to do, which is push the modified version over the last good one and retire the copy underneath.
So the first action is not isolation, tempting though that is. Stop every scheduled backup, snapshot, replication task and sync client you own, including the ones you had forgotten about. This is the single most expensive mistake that reaches this bench and it is almost never anybody's fault — the job ran as designed, on time, and traded the last clean copies for encrypted ones. Freeze the lot, and work out afterwards what survived.
Then contain it. Pull network cables and disable the wireless on affected machines, but leave the power on where you reasonably can, because volatile memory sometimes still holds process and key material that disappears the instant it is cut. Photograph the note. Keep one encrypted file and, if you can find one anywhere, an untouched copy of the same file from before the attack — that pair is often what identifies the strain. And write down when it was noticed, because the interval between the run starting and somebody spotting it turns out to matter to almost every question asked later.
Before any plan gets built, spend two minutes on the No More Ransom project. Law enforcement agencies and security researchers have broken a considerable number of strains over the years, either by finding flaws in the implementation or by seizing key material during a takedown, and the resulting decryptors are published free. Upload the ransom note and one locked file and the identification service will tell you whether yours is among them. Now and again it closes an incident inside an afternoon for nothing.
What nobody can offer is a way through the encryption itself when it has been done competently. Modern strains use standard, well-tested algorithms with per-file keys wrapped in a public key held only by the attacker, and no laboratory on earth breaks that. Any firm implying otherwise is describing a sales process rather than mathematics. Everything useful that follows comes from somewhere else entirely.
The first is whatever the run never finished. Encrypting an estate is slow, noisy and easily interrupted — somebody notices, a laptop sleeps, a share disconnects, a service crashes partway through. Partial encryption is extremely common: large files with a scrambled header and a body that reads perfectly, whole directories skipped over, a server that was powered down that evening and never touched. Which is why the first genuinely useful document produced on one of these jobs is an inventory that separates the files which really have been encrypted from the far larger number that merely look as though they were.
The second is the deleted originals, and this is where most of the good news comes from. A great many strains do not overwrite a file in place. They read it, write an encrypted copy alongside it under a new name, and delete the source. Deletion clears the pointer and leaves the content sitting in unallocated space until something needs the room. Read the disks properly at sector level and a substantial share of the pre-attack files often comes back intact. None of that involves cryptography — it is ordinary recovery work applied to an unusual cause, which is precisely why it is priced like ordinary recovery work.
The third is anything the attack could not reach. A disk rotated into a safe, an archive tape, the external drive somebody unplugged in March and never reconnected — whatever was disconnected during the run is normally clean, and that is the entire argument for keeping one copy that does not live permanently attached to the network. Cloud services frequently hold versioned copies as well, though only for a fixed retention window, so establish that window before building a plan on it. Windows shadow copies are worth checking for the same reason, with the caveat that many strains delete them on the way through — and even then, a deleted shadow copy leaves its blocks on the disk in the same way a deleted file does.
Some laboratories will settle the ransom for you, put the decrypted files on a disk and invoice the whole thing as data recovery. That does happen in this trade and it is not on offer here. The reasons are practical well before they are ethical. Decryptors handed over after payment are frequently defective, frequently incomplete, and sometimes never turn up. Payment marks an organisation as one that pays, and repeat attacks on the same victim are a well-documented pattern. Several of the groups involved sit under sanctions regimes, which turns a commercial decision into a legal one for you rather than for them. And every payment underwrites the next set of attacks.
It is worth being equally plain about what this bench is. It is not an incident response retainer and it is not a negotiator. It reads storage. What it adds for commercial work is documentation: custody of every disk recorded from the moment it arrives, so an insurer, a regulator or a solicitor can be given a clean account of where the media has been, and a non-disclosure agreement whenever you want one. Should you also need to establish how the attacker got in or what was taken out, that is a forensic investigation with a full written report at £800 + VAT — a service you ask for on purpose. It is never bolted onto a recovery quietly, and most firms getting back on their feet after an attack have no use for it.
The price follows the hardware, exactly as it does for every other job on this site. A single encrypted drive is £300 + VAT. A server, NAS or array is from £500 + VAT, rising with the number of member disks and the state they arrive in. Ransomware is not classed as forensic work here and is not priced as though it were, whatever you may have been quoted elsewhere — the fact that the cause was criminal does not change what the bench physically has to do to the disks.
Send storage, not furniture. The disks themselves, each labelled with the bay it came out of, packed so nothing can shift in transit, tracked and insured to Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford, GU2 8XH. From the estates off the A329(M) or anywhere along the M4 that is close enough to be a lunchtime run if somebody wants to drive it — about forty minutes and eighteen miles from Bracknell via the A322 and the A3 — and reception takes hand deliveries Mon–Fri 9:00am–5:30pm. There is no collection service anywhere on this network, so nothing in the job waits on a driver being free.
Ring 0800 689 0668 before the parcel leaves and describe what the attack has stopped the business doing, and the job is flagged ahead of its arrival. The assessment is free and closes 2 working days after booking in. It comes back with four things: an inventory of what has actually been encrypted, an estimate of how much is retrievable from the deleted originals, a yes or no on whether a published decryptor exists for your strain, and a single fixed price.
In the hour after an attack, nothing you own is more dangerous than your own schedule. Backups, snapshots, replication and sync clients cannot tell malicious changes from legitimate ones, and left running they will faithfully replace the last clean copies with encrypted ones. Freeze every one of them before you touch anything else.
Free diagnostic closing 2 working days after your device is booked in, one fixed written quote, and no fix, no fee on logical faults. Cards and USB sticks £250 + VAT, any single drive or SSD £300 + VAT.