Modern ransomware cannot be decrypted by anyone but the attacker — so the useful question is what survived. Shadow copies, unencrypted originals still sitting in free space, files the run never reached, and backups it could not reach. We assess exactly what is recoverable, free, before you decide anything about paying.
$ bdr triage /dev/sdb → Device: Dell PowerEdge (RAID 5) → Status: RANSOMWARE — files encrypted (.locked) → Strain: identified · known variant $ bdr engineer-working → Read-only image: taken · source preserved → Shadow copies: located + extracted → Decryptor: applied · known flaw $ bdr verify → ✓ databases — restored → ✓ documents — 142,800 files → ✓ data recovered — attacker unpaid
Isolate the affected systems from the network but leave them powered if they are already running — shadow copies and material held only in memory can be lost on reboot. Don’t reformat, don’t reinstall, and keep the encrypted files themselves; they are sometimes needed later, and they cost nothing to retain.
It is no longer a matter of a few scrambled documents. Current families move laterally, hunt backups deliberately, and take copies before encrypting anything — which changes what recovery means.
It matters that this is said plainly, because a good deal of the industry is vague about it.
For current, properly implemented ransomware families, the encryption is sound and the keys are held by the attacker. Nobody decrypts those — not us, not a specialist firm, not law enforcement. Any company implying otherwise is either describing old strains with known flaws, or selling you a ransom payment with a service charge attached.
Where a genuine free decryptor exists, it is usually published through the No More Ransom project, and it applies to a specific family with a specific implementation error. We check for that first because it costs nothing. When one applies, excellent. When one does not, the honest answer is that decryption is off the table and recovery means working around the encryption instead.
In practice, most of what comes back after ransomware was never successfully encrypted in the first place.
Ransomware tries to delete them, and frequently fails to remove every one — particularly on servers with generous shadow storage, or where deletion ran with insufficient privilege.
Many families encrypt to a new file and delete the original rather than overwriting in place. Those originals often remain in unallocated space and can be carved out intact.
Attacks get interrupted, hit permission errors, skip file types, or are stopped partway. Whole directories are commonly untouched.
Offline copies, immutable snapshots, cloud versioning and NAS snapshots that were not reachable from the infected network.
Establishing what did and did not leave matters for your notification obligations, and the artefacts that answer it are often still on the system.
A ransomware incident is rarely only a technical event, and the technical response can damage the other parts.
Insurers generally require the affected systems preserved rather than rebuilt, and a rebuild before assessment can compromise a claim. Where personal data may have been taken, UK GDPR obliges you to assess and potentially notify the ICO within 72 hours — and answering the question of what left the network depends on logs and artefacts that a reinstall destroys.
So we image affected systems read-only before doing anything else. That preserves the evidential position, keeps the encrypted files available in case a decryptor is published later, and means every recovery attempt runs against a copy. It costs nothing extra and it protects options you may not yet know you need.
Assessed free, priced in writing, and you decide with the numbers in front of you.
Ransomware work on servers, NAS units and RAID systems starts from £500 +VAT; a single affected workstation or drive is from £300 +VAT. The free 48-hour assessment establishes the strain, what shadow copies and unencrypted material survive, and what is realistically recoverable — before you commit to anything.
We do not handle ransom negotiation or payment, and we do not take a percentage of anything. Where the assessment finds little to recover, we tell you that instead of billing you to discover it. Full write-ups: Ransomware Recovery: LockBit, and No Backup.
Send the device in for its free diagnostic and tell us briefly what happened; an engineer reviews it and confirms your exact quote in writing before anything starts.
Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.
Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.
Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.
We’ll be in touch shortly. If it’s urgent, call 01865 593000.
What people most often ask us after a ransomware attack.
Not for current families. The encryption is properly implemented and the keys sit with the attacker, so nobody decrypts them — us included. Older strains with implementation flaws sometimes have free decryptors published through No More Ransom, and we check for that first because it costs nothing.
Isolate affected machines from the network but leave them powered if they are already on, because shadow copies and memory-resident material can be lost on reboot. Don’t reformat or reinstall, and keep the encrypted files — they may be useful later.
That is your decision and we take no part in it, but two things are worth knowing: payment buys a decryptor, not deletion of anything already stolen, and recovery around the attack frequently returns most of what matters without paying. Assess what is recoverable before deciding.
Usually more than people expect — surviving shadow copies, unencrypted originals still present in free space, files the attack never reached, and any backup or snapshot outside the infected network. The assessment tells you which of those apply to your case.
If personal data may have been accessed or taken, UK GDPR requires you to assess and potentially notify the ICO within 72 hours. Establishing what left the network relies on logs and artefacts that a rebuild destroys, which is one reason to image systems before restoring.
From £500 plus VAT for servers, NAS and RAID systems, and from £300 plus VAT for a single workstation or drive — quoted in writing after a free 48-hour assessment. We don’t handle ransom payment and don’t take a percentage.
We name the family, put the numbers in writing, and recover from workstations, NAS and servers alike — with the evidence kept safe for your insurer. Get in touch today.