The instinct after finding the ransom note is to start putting things right, and it is almost always the wrong instinct. Disconnect affected machines from the network — pull the cable, drop the wi-fi — but leave them switched on if you reasonably can, because volatile memory occasionally still holds keys or process detail that is gone the moment the power is. Photograph the note. Keep one sample of an encrypted file and, if you can find it, an untouched original of the same file; a matched pair like that is often what identifies the strain and tells you whether a published decryptor exists.
Then suspend every automated backup job before anything else. This is the single costliest mistake we see, and it is nobody's fault in particular: the backup ran overnight, exactly as designed, and faithfully replaced the last good copies with encrypted ones. Snapshots, replication, cloud sync and the rest all behave the same way, because none of them can tell the difference between a legitimate change and a malicious one. Pause them, then start working out what you actually still have.
First place: whatever the attack did not reach. Offline media is the obvious candidate — a rotated drive in a safe, an archive tape, the disk somebody unplugged in March and forgot about. Anything not connected at the time is usually untouched, which is the entire argument for keeping one copy that is not permanently attached to anything. Cloud sync services often keep versioned copies too, though only for a limited window, so check the retention period before you assume.
Second place: the deleted originals. Plenty of ransomware families encrypt a copy of each file and delete the original rather than overwriting it in place. Deleting removes the reference and leaves the content sitting on the disk until something else needs the space, so a forensic pass across the raw disk frequently recovers a substantial proportion of the pre-attack files intact. This is ordinary recovery work rather than cryptography, and it is the route that most often produces the good news.
Third place: what the attacker missed. Encrypting an entire estate takes time and makes noise, so attacks are commonly interrupted — by someone noticing, by a machine going to sleep, by the process falling over on a large share. Partial encryption is extremely common: file headers scrambled while the bulk of a large file remains readable, whole directories skipped, one server left alone because it was off that night. An itemised assessment of what is genuinely encrypted, rather than what appears to be, is the first useful thing anyone can give you.
We will not help you pay, and we will not quietly pay on your behalf and present it as a recovery — a practice that exists in this industry and should not. The reasons are practical rather than moral. A meaningful share of victims who pay receive a decryptor that is broken, partial or simply never arrives. Payment marks you as a payer, and repeat targeting is a documented pattern. There may be sanctions exposure attached to the group you would be paying. And every payment funds the next attack, quite possibly on somebody you know.
There is one honest exception to the pessimism, and it is worth ten minutes of anybody's time: some strains have been broken, and free decryptors are published for them by law enforcement and security researchers through the No More Ransom project. Take your note and a sample encrypted file, check there first, and check before you do anything else. It costs nothing and it occasionally ends the whole problem in an afternoon.
Practicalities. Ransomware recovery is forensic-classed work here, which means the fee is settled in advance rather than on the usual no fix, no fee basis, and it means the job is handled with a documented chain of custody in case an insurer, a regulator or a solicitor wants to see one later. What you send is the storage — the disks themselves, labelled by bay if they came out of a server or a NAS — rather than the whole rack, and you send it tracked and insured, or bring it to the Cambridge desk yourself. There is no collection service, so nothing waits on a van.
The assessment is free and complete inside 2 working days of arrival. It tells you what is actually encrypted, what is recoverable from deleted originals, whether a published decryptor applies, and what a full recovery would cost as one fixed figure. Norfolk's larger employers — the food processors and packers, the agricultural co-operatives, the offshore supply-chain firms out of Great Yarmouth — all run systems where a week of lost records is a great deal more expensive than the assessment, and all of them are welcome to ring 0800 689 0668 before they decide anything at all.
In most attacks the expensive loss is not the encryption itself — it is the backup that ran on schedule a few hours later. Pause every automatic backup, snapshot and sync as soon as an infection is confirmed, before your own automation trades the last clean copies for locked ones.
Free diagnostic inside 2 working days of arrival, one fixed quote, no fix no fee on logical faults. Start online or ring the freephone.