Modern ransomware cannot be decrypted by anyone but the attacker, so the useful question is what survived it. Shadow copies the run failed to clear, unencrypted originals still sitting in free space, files it never reached, and backups it could not touch. We establish exactly what is recoverable, free, before you decide anything about paying.
$ mdr triage /dev/sdb → Device: Dell PowerEdge (RAID 5) → Status: RANSOMWARE — files encrypted (.locked) → Strain: identified · known variant $ mdr engineer-working → Read-only image: taken · source preserved → Shadow copies: located + extracted → Decryptor: applied · known flaw $ mdr verify → ✓ databases — restored → ✓ documents — 142,800 files → ✓ data recovered — attacker unpaid
Pull the network cable but leave running machines powered — shadow copies and material held only in memory can be lost on restart. Keep the encrypted files; they cost nothing to retain and are occasionally needed later.
Ordered by how much difference each makes, and none of it costs anything.
Isolation stops it spreading to shares and NAS units. Powering down loses volatile evidence and can discard shadow copies that survived the attack.
The instinct to wipe and reinstall is strong and it destroys the artefacts that establish what left the network — which you may need for the ICO and almost certainly for your insurer.
Not whether it exists. When it last ran, whether it was reachable from the infected network, and whether anyone has restored from it recently. Backups that sat on a mapped drive are usually encrypted too.
The strain name and contact details identify the family, which determines whether a free decryptor exists and how the attack behaves.
The negotiation clock is designed to pressure you. Knowing what is recoverable without paying is the only thing that changes your position.
Worth stating plainly, because a good deal of this industry is vague about it.
Current ransomware encrypts each file under its own random symmetric key, then seals those keys with the attacker’s public key. Breaking one file gains you nothing toward the next, and the master key exists only on the attacker’s side. That is not a gap a specialist closes — it is correctly implemented cryptography doing exactly what it was designed to do.
Where a free decryptor exists it is usually published through the No More Ransom project and applies to a specific family with a specific implementation flaw. We check that first because it costs nothing. Where none applies, any firm still offering decryption is either describing an old broken strain or quietly proposing to pay the ransom on your behalf with a fee attached.
In practice most of what is retrieved after an attack was never successfully encrypted in the first place.
Both are happening while you deal with the technical side, and both are shaped by decisions made in the first day.
Your insurer. Cyber policies almost always require the affected systems preserved for assessment. Wiping and rebuilding before the insurer’s appointed responder has looked is a common way a valid claim gets argued over — not because anyone acted in bad faith, but because the evidence of what happened went with the reinstall. Check the policy wording before touching anything, and if there is an incident hotline on it, use that first.
The regulator. Where personal data may have been accessed, UK GDPR gives you 72 hours to assess and potentially notify. The question the ICO asks is not whether files were encrypted but whether data left the network — and that is answered by logs, connection records and artefacts that a rebuild removes. Imaging the systems read-only before anything else preserves the ability to answer it, and costs nothing extra.
Worth setting side by side, because that is the decision actually being made.
Recovery on servers, NAS units and RAID systems starts from £500 +VAT; a single workstation is from £300 +VAT. Both are fixed in writing after a free 48-hour assessment that tells you what survived before you commit to anything.
Ransom demands against UK SMEs typically run into the tens of thousands, and paying buys a decryptor — not the deletion of anything already copied out, and not a guarantee the decryptor works on every file. Recovery around the attack costs a fraction of that and carries no dependence on the attacker keeping their word. We take no percentage of anything and no part in negotiation, which means we have no reason to overstate what we can retrieve.
Get the device to us with a short note on what happened. The diagnostic that follows costs nothing, and the figure that follows it is fixed in writing before any work begins.
Nothing can begin until the device is on the bench, which makes this the only step that needs anything from you. Pack it properly, put your details in with it, and send it over. What follows is a free diagnostic and a written figure, in that order.
Posting it? Use something tracked and insured — whatever is on the drive is worth considerably more than the postage. Bringing it in? Weekdays, 9am to 5:30pm, and it still wants packing as above for the journey.
Tell us what the device is, what it is doing, and anything already tried — an engineer will come back with a realistic view of the odds and a price band, before you commit to posting anything.
We’ll be in touch shortly. If it’s urgent, call 0161 871 0788.
What people most often ask us after a ransomware attack.
No, and nor can anyone else for a current strain. Each file is encrypted under its own key, sealed with the attacker’s public key, and the master exists only on their side. Where an older family has a known flaw, a free decryptor may exist through No More Ransom and we check that first at no cost.
That is exactly what the free assessment answers, and it varies enormously — from almost everything to very little, depending on what shadow copies survived, whether originals remain in free space, and what the run never reached. You get a figure before you commit to anything.
Disconnect them from the network, but leave running machines powered. Isolation stops the spread; a restart can discard shadow copies and memory-resident material that would otherwise have been recoverable.
Very likely encrypted alongside everything else, because modern families follow mapped drives and network shares deliberately. What tends to survive is anything that was offline, immutable, or on a system the attack could not authenticate to.
If personal data may have been accessed or exfiltrated, you have 72 hours to assess and potentially notify. The question is whether data left the network, and answering it depends on artefacts that a rebuild destroys — which is why we image before anything else.
No. We do not handle negotiation or payment and take no percentage of anything recovered. That also means we have no incentive to overstate what can be retrieved — the assessment says what it says.
We name the family, put the numbers in writing, and recover from workstations, NAS and servers alike — with the evidence kept safe for your insurer. Get in touch today.