For individuals and businesses
Data recovery after ransomware attacks
When your files or business systems stop because of encryption, you need to understand the available options before taking the next step. We assess the damaged data and its alternative sources, then explain the possible scope of recovery and the work plan that suits your case.
The examination result is the basis of the estimate. Recovery chances differ from one case to another.
Is the infection still active?
Disconnect the affected device from the network if possible, and get in touch from a clean device. In a business environment, inform the IT lead immediately, and do not connect healthy backups to the infected environment.
What was affected?
Choose what is closest to your case. If more than one system was affected, you can explain that in the assessment request.
-
Encrypted files
Documents, photos or work files that no longer open, or that now carry unusual extensions.
Explore file recovery -
Servers and central storage
File shares or company data on a server, a NAS or a RAID array.
Explore server recovery -
Databases
An accounting, sales or operations application that stopped after its database was damaged.
Explore database recovery -
Virtual environments
Virtual machines or their disks that are no longer available after the incident.
Explore environment recovery -
Backups
Backups that will not open, or restore points that are no longer available when needed.
Explore backup assessment -
Not sure
Describe what you see, and we will start by identifying the information needed to understand the case.
Start a case assessment
Received only a threat to leak data? Tell us in the request, and involve the relevant security team; assessing a leak is different from recovering files.
An assessment that helps you make a clear decision
Before expanding the work, we set out the questions that affect your decision: which data has priority? What is available for examination? And how do we verify the result?
Identifying what needs examination
The files, the systems and the alternative sources linked to them.
A limited test
We start with a scope that shows the possibilities before processing all of the data.
Clarifying the limits of the result
We distinguish between data that came back usable, data that needs further work, and what could not be recovered.
Agreement before execution
The recovery scope, cost and time estimate are set before the agreed work begins.
Data recovery may need more than one route
The right route may be decryption when a compatible solution exists, recovery from a healthy backup, or examining other sources of the data. That is why we start by assessing the case instead of assuming that one tool will handle every file.
Decryption
Making encrypted data readable again when a valid method exists for the specific case.
Data recovery
Reaching usable data from the sources the state of the case allows us to examine.
Security response
Handling the breach and its extent in coordination with the relevant team. Recovering a file does not by itself prove the network is safe.
From describing the problem to verifying the result
- 01
Describe the case
Tell us what stopped, when you noticed it, and which data you need first.
- 02
We define what the examination needs
We explain the information, samples or media required and how they are handled.
- 03
We assess the options
We review the available scope and show what needs testing and what can be estimated.
- 04
You approve the scope of work
We agree on priorities, cost and the time estimate.
- 05
We verify before handover
The result is reviewed against the usability standard agreed with you.
Start with the data your business depends on
Many files may be damaged, but the priority for getting them back differs. Tell us whether the first need is accounting, orders, customer data or project files. This order helps define the scope of examination and handover in stages when the case allows.
Examples that help you understand the scenarios
See illustrative cases that show how priorities and decisions differ between sectors. These examples are not a promise of a similar result in your case.
-
Composite illustrative example
Construction & contracting
Engineering project files
How does an organisation order its need for work files when central access fails?
Read the example -
Composite illustrative example
Manufacturing & industry
Production stopped without one controller being encrypted
A building materials plant: ERP, quality and warehouse systems were encrypted, and production halted although the machines themselves were untouched.
Read the example -
Composite illustrative example
Health & care
Patient records and imaging on one storage unit
A clinic group: the records system and the imaging archive were encrypted together, halting both booking and consultation.
Read the example
Other illustrative examples
- One admin credential opened several client environments Composite illustrative example
- Tills still selling while stock had no idea what left Composite illustrative example
- Shipments on the road and a tracking system that will not answer Composite illustrative example
Questions to help you before sending your case
No. You can start the request by describing what happened and the type of device. The team will identify any additional information needed later.
That cannot be determined before examination. We explain what the assessment supports, what needs testing, and the limits of the expected result.
Start with a short description. If we need files for examination, we will explain what is required and how to share it. Do not put passwords or customer data in the form.
After understanding the number of systems, the type of data, its condition, and the scope of work required. We explain the estimate before execution is approved.
Contact can begin and the case description can be gathered remotely. The requirements of the actual examination are set after the initial information is reviewed.
Removing the malware and dealing with the encrypted files are two different matters. The state of the data needs its own assessment.
Say so when you get in touch. Assessing access to or leakage of data requires involving the relevant security team, even if there are no encrypted files.
The examination result and what could not be verified are explained within the agreed scope, without turning uncertainty into a promise of recovery.
The first request does not require uploading files.
Let's start with a description of your case
Identify the affected systems and the data that matters most to you. We will use this information to decide the next step in the assessment.