Cybersecurity

Ransomware: containment, recovery, and never again

Ransomware is the visible end of an intrusion that usually started weeks earlier. By the time files encrypt, the attacker has already had access, moved laterally, found your backups, and in most cases taken a copy of your data.

Recovery therefore is not just decryption. It is containment, establishing what was taken, restoring cleanly without reinfecting, and closing the original route in.

What the engagement includes

  • Emergency containment to stop encryption spreading further
  • Scope assessment: which systems, which accounts, what data
  • Data exfiltration analysis — most modern ransomware steals before it encrypts
  • Guided recovery from backup with verification that restores are clean
  • Decryption support where a viable key or tool exists
  • Root-cause analysis of the initial access vector
  • Rebuild of backup architecture with immutable and offline copies
  • Hardening programme so the same path is not available again

Who this is for

Any organisation currently encrypted, and any organisation that would like not to be. Prevention work is dramatically cheaper than recovery work.

How it runs

Every engagement follows the same five stages — discover, architect, implement, validate, defend. See how we work →

How the engagement runs

Five stages, with indicative timing. Exact dates are confirmed at scoping.

  1. 01
    Contain

    Stop the spread. Isolate affected segments and disable compromised accounts, preserving evidence throughout.

    Hours 0–4
  2. 02
    Assess scope

    Which systems, which accounts, which data — and critically, whether data left before encryption.

    Days 1–2
  3. 03
    Recover

    Clean rebuild and restore from verified backups, sequenced so recovered systems are not reinfected.

    Days 2–10
  4. 04
    Root-cause

    The initial access vector identified and closed. Ransomware is the end of an intrusion, not the start.

    In parallel
  5. 05
    Harden

    Immutable backups, phishing-resistant MFA, segmentation and monitoring so the path cannot be reused.

    Weeks 2–8

Questions we get asked

That is a business and legal decision, not a technical one, and we do not make it for you. We will give you the facts you need: whether backups are viable, whether data was taken, and what paying does and does not resolve. Payment does not undo exfiltration and does not guarantee usable decryption.
Use the incident number on our site for anything active. Containment guidance starts on the first call — the priority is stopping the spread before anything else.
Phishing-resistant MFA, endpoint detection that is actually monitored, aggressive patching of internet-facing systems, network segmentation, and immutable offline backups you have restored from in a test. That combination stops the overwhelming majority of ransomware before encryption.

Every engagement starts free.

We assess your environment first, then scope. No commitment until you have seen how we work.