For individuals and businesses

Data recovery after ransomware attacks

When your files or business systems stop because of encryption, you need to understand the available options before taking the next step. We assess the damaged data and its alternative sources, then explain the possible scope of recovery and the work plan that suits your case.

The examination result is the basis of the estimate. Recovery chances differ from one case to another.

A lit digital padlock on a computer screen above a stream of data

Is the infection still active?

Disconnect the affected device from the network if possible, and get in touch from a clean device. In a business environment, inform the IT lead immediately, and do not connect healthy backups to the infected environment.

Read the first steps

What was affected?

Choose what is closest to your case. If more than one system was affected, you can explain that in the assessment request.

Received only a threat to leak data? Tell us in the request, and involve the relevant security team; assessing a leak is different from recovering files.

An assessment that helps you make a clear decision

Before expanding the work, we set out the questions that affect your decision: which data has priority? What is available for examination? And how do we verify the result?

  • Identifying what needs examination

    The files, the systems and the alternative sources linked to them.

  • A limited test

    We start with a scope that shows the possibilities before processing all of the data.

  • Clarifying the limits of the result

    We distinguish between data that came back usable, data that needs further work, and what could not be recovered.

  • Agreement before execution

    The recovery scope, cost and time estimate are set before the agreed work begins.

Data recovery may need more than one route

The right route may be decryption when a compatible solution exists, recovery from a healthy backup, or examining other sources of the data. That is why we start by assessing the case instead of assuming that one tool will handle every file.

  • Decryption

    Making encrypted data readable again when a valid method exists for the specific case.

  • Data recovery

    Reaching usable data from the sources the state of the case allows us to examine.

  • Security response

    Handling the breach and its extent in coordination with the relevant team. Recovering a file does not by itself prove the network is safe.

From describing the problem to verifying the result

  1. 01

    Describe the case

    Tell us what stopped, when you noticed it, and which data you need first.

  2. 02

    We define what the examination needs

    We explain the information, samples or media required and how they are handled.

  3. 03

    We assess the options

    We review the available scope and show what needs testing and what can be estimated.

  4. 04

    You approve the scope of work

    We agree on priorities, cost and the time estimate.

  5. 05

    We verify before handover

    The result is reviewed against the usability standard agreed with you.

Start with the data your business depends on

Many files may be damaged, but the priority for getting them back differs. Tell us whether the first need is accounting, orders, customer data or project files. This order helps define the scope of examination and handover in stages when the case allows.

Send a business case

Examples that help you understand the scenarios

See illustrative cases that show how priorities and decisions differ between sectors. These examples are not a promise of a similar result in your case.

  • Composite illustrative example

    Construction & contracting

    Engineering project files

    How does an organisation order its need for work files when central access fails?

    Read the example
  • Composite illustrative example

    Manufacturing & industry

    Production stopped without one controller being encrypted

    A building materials plant: ERP, quality and warehouse systems were encrypted, and production halted although the machines themselves were untouched.

    Read the example
  • Composite illustrative example

    Health & care

    Patient records and imaging on one storage unit

    A clinic group: the records system and the imaging archive were encrypted together, halting both booking and consultation.

    Read the example

Other illustrative examples

Questions to help you before sending your case

No. You can start the request by describing what happened and the type of device. The team will identify any additional information needed later.

That cannot be determined before examination. We explain what the assessment supports, what needs testing, and the limits of the expected result.

Start with a short description. If we need files for examination, we will explain what is required and how to share it. Do not put passwords or customer data in the form.

After understanding the number of systems, the type of data, its condition, and the scope of work required. We explain the estimate before execution is approved.

Contact can begin and the case description can be gathered remotely. The requirements of the actual examination are set after the initial information is reviewed.

Removing the malware and dealing with the encrypted files are two different matters. The state of the data needs its own assessment.

Say so when you get in touch. Assessing access to or leakage of data requires involving the relevant security team, even if there are no encrypted files.

The examination result and what could not be verified are explained within the agreed scope, without turning uncertainty into a promise of recovery.

Start a case assessment

The first request does not require uploading files.

Let's start with a description of your case

Identify the affected systems and the data that matters most to you. We will use this information to decide the next step in the assessment.