Ransomware Recovery & Incident Response
Ransomware can stop critical business operations in minutes. AS helps organizations assess encrypted environments, identify affected systems, examine available backups and recovery sources, and develop a safe recovery strategy. Where technically feasible, we investigate available recovery and decryption options.
When you need this
- Servers, shares or VMs encrypted and a ransom note left
- Backups encrypted, deleted or found to be incomplete
- Hypervisor hosts (ESXi, Hyper-V) targeted directly
- Databases partially encrypted and applications down
- Uncertainty about what was affected and whether it's safe to restore
- Need to preserve evidence for insurers, regulators or law enforcement
What we do
Ransomware incident assessment
We establish scope: which systems, which data, which variant, and whether the attacker still has access.
Encrypted file analysis
Samples are analysed to understand how the variant encrypts files — fully, partially or intermittently — which drives what is recoverable.
Recovery feasibility assessment
Before any commitment, we set out realistic options: backups, snapshots, storage-level recovery, partial-file recovery and, where they exist, decryption options.
Backup analysis
Backups and snapshots are checked for integrity, completeness and safety to restore without reintroducing the threat.
Server, virtual machine and database recovery
Storage-level and file-level recovery of encrypted systems where technically feasible.
Recovery planning
A sequenced plan that restores the most critical services first, on clean infrastructure.
Evidence preservation
Images and logs are preserved in a forensically sound way for later investigation or claims.
Post-incident recovery support
Help with hardening, backup redesign and monitoring so the same entry point isn't left open.
How it works
- Step 1
Contain
Isolate affected systems and preserve their current state — no reboots, no re-imaging, no restores yet.
- Step 2
Assess
Identify the variant, the affected systems and every potential recovery source.
- Step 3
Preserve
Image affected storage and backups so recovery never works on originals.
- Step 4
Recover
Recover data from the safest, most complete sources first; investigate partial-file and decryption options where feasible.
- Step 5
Restore
Rebuild services on clean infrastructure in business-priority order.
- Step 6
Validate and improve
Verify recovered data, confirm the threat is removed, and address the gaps that allowed the incident.
What affects the outcome
Outcomes are never guaranteed. Every case is assessed on its own condition, and we tell you what is realistic before you commit.
- The ransomware variant and how it encrypts (full, partial or intermittent)
- Whether backups or snapshots survived and are clean
- What was done after discovery (reboots, restores, rebuilds, paying)
- The condition of the underlying storage and whether it was overwritten
- For large files such as databases and virtual disks, how much content remains unencrypted
AS ransomware analysis tools
Tools for analysing encrypted files and assessing recoverable content in database and virtual disk files.
Frequently asked questions
Can you decrypt our files?
It depends on the variant. Some families have known weaknesses or published keys; most do not. Where technically feasible, we investigate available recovery and decryption options and tell you clearly what is realistic before any chargeable work.
Should we pay the ransom?
We advise against it as a first option. Payment doesn't guarantee working decryption, may be restricted in your jurisdiction, and funds further attacks. Recovery options should be assessed first.
Our backups were encrypted too. Is there anything left?
Often, yes. Partially encrypted backups, storage-level remnants and snapshots frequently contain recoverable data. This is exactly what the assessment determines.
Do you need the ransom note or contact with the attackers?
No contact with attackers is needed. A copy of the ransom note and a few encrypted samples help identify the variant.
Can you help with evidence for our insurer?
Yes. We preserve images and logs in a forensically sound manner and can provide documentation of what was affected and recovered.
Related services
Not sure what you're dealing with?
Describe the situation and we'll tell you what's realistic.