Get the affected machines off the network and off the internet — unplug cables, kill Wi-Fi — but resist the urge to wipe anything, and leave the NAS or server powered on until you have had a proper think. Rushing to reinstall Windows and start fresh destroys the very artefacts that make recovery possible. Photograph the ransom note, write down the new extension the encrypted files have taken on, and halt every backup job at once so freshly encrypted files can't overwrite your last good backup.
If your business is covered by UK GDPR and personal data is caught up in the attack, remember it may count as a reportable breach — bring in whoever handles your compliance sooner rather than later.
Route one: the copies the ransomware overlooked. Offline and off-site backups, cloud version history (OneDrive, SharePoint, Google Drive and Dropbox can all roll files back to their pre-attack state), NAS snapshots and Windows shadow copies. Modern strains do try to wipe shadow copies and NAS snapshots — but 'try' is the operative word, and we routinely find them partly intact.
Route two: a free decryptor. A number of ransomware families have been cracked, with free decryption tools released by researchers and by the No More Ransom project. Pinning down the exact strain — from the note and the file extension — tells you whether you are in luck. Never hand money to a 'decryption service' advertised on some unknown website; most simply pay the criminals for you, or take your cash and vanish.
Route three: lab recovery of whatever the encryption missed. Encrypting a whole estate takes time, and attacks are often cut short partway through. On real jobs we turn up untouched files on secondary drives, older versions lurking in unallocated space, entire virtual-machine snapshots, database backups the malware never parsed, and half-encrypted files where only the opening blocks are damaged. It is ordinary data-recovery craft applied to an unusual crime scene — imaged drives, forensic tooling and a file-by-file audit of what pulled through.
Paying is the last resort, and not only on principle: study after study finds that a sizeable share of those who pay get nothing usable back, and a payment marks you as a soft target for the next crew. UK authorities advise against it, and where sanctioned groups are involved, paying can create legal exposure of its own. Work through the three routes above first — most businesses who arrive assuming they will 'have to pay' turn out to have far more surviving data than they feared.
Report the incident through Action Fraud and preserve the evidence — it costs nothing, and every so often the strain that hit you is one that gets broken months later, at which point those preserved encrypted drives suddenly become recoverable.
Send or courier over the affected drives, NAS or server (labelled by bay) and we image the lot before any analysis begins — the originals are never worked on directly. You will get a report on what is recoverable across all three routes plus one fixed quote; no fix, no fee applies to the recovery work here as on any other job. Active incidents jump the queue on arrival — call 0800 689 0668 and tell us it is live.
Related reading: NAS recovery, RAID recovery and SAN & virtual machine recovery — the three places business data tends to sit when ransomware strikes.
Stop every backup job the moment you're attacked. A scheduled backup that fires after encryption can overwrite your last clean copies with encrypted ones — turning a bad day into a genuine disaster.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.