Ransomware: containment, recovery, and never again
Ransomware is the visible end of an intrusion that usually started weeks earlier. By the time files encrypt, the attacker has already had access, moved laterally, found your backups, and in most cases taken a copy of your data.
Recovery therefore is not just decryption. It is containment, establishing what was taken, restoring cleanly without reinfecting, and closing the original route in.
What the engagement includes
- Emergency containment to stop encryption spreading further
- Scope assessment: which systems, which accounts, what data
- Data exfiltration analysis — most modern ransomware steals before it encrypts
- Guided recovery from backup with verification that restores are clean
- Decryption support where a viable key or tool exists
- Root-cause analysis of the initial access vector
- Rebuild of backup architecture with immutable and offline copies
- Hardening programme so the same path is not available again
Who this is for
Any organisation currently encrypted, and any organisation that would like not to be. Prevention work is dramatically cheaper than recovery work.
How it runs
Every engagement follows the same five stages — discover, architect, implement, validate, defend. See how we work →
How the engagement runs
Five stages, with indicative timing. Exact dates are confirmed at scoping.
-
01
Contain
Stop the spread. Isolate affected segments and disable compromised accounts, preserving evidence throughout.
Hours 0–4 -
02
Assess scope
Which systems, which accounts, which data — and critically, whether data left before encryption.
Days 1–2 -
03
Recover
Clean rebuild and restore from verified backups, sequenced so recovered systems are not reinfected.
Days 2–10 -
04
Root-cause
The initial access vector identified and closed. Ransomware is the end of an intrusion, not the start.
In parallel -
05
Harden
Immutable backups, phishing-resistant MFA, segmentation and monitoring so the path cannot be reused.
Weeks 2–8