Ransomware seals up your files and demands payment — yet paying is seldom the only way out, and frequently the worst. We identify the strain, recover whatever can be recovered — decryptable variants, shadow copies, backups, data that was never encrypted — and keep the whole of it intact for your insurer and investigators. It opens with a free assessment of exactly what can be brought back, before paying so much as crosses your mind.
$ bdr triage /dev/sdb → Device: Dell PowerEdge (RAID 5) → Status: RANSOMWARE — files encrypted (.locked) → Strain: identified · known variant $ bdr engineer-working → Read-only image: taken · source preserved → Shadow copies: located + extracted → Decryptor: applied · known flaw $ bdr verify → ✓ databases — restored → ✓ documents — 142,800 files → ✓ data recovered — attacker unpaid
As soon as ransomware shows itself, cut the affected machines off — off the network, away from any backups — so it can’t spread. Reformat nothing, rebuild nothing, delete nothing, and don’t hurry to pay: a payment buys no guarantee of a working decryptor, and it bankrolls more crime. Keep the ransom note and a few encrypted sample files, and come to us — the strain is identified first, and a few can be decrypted for nothing.
Today’s ransomware goes well beyond scrambling a handful of files — it moves across drives, seeks out your backups, and aims at the systems your business runs on. These are the cases we meet most.
Before anything else is touched, we fix the exact family and variant from the ransom note and a few encrypted samples. Some strains have a free or known decryptor; for the current big families the encryption simply can’t be broken — so recovery comes instead from shadow copies, backups and data that escaped encryption.
Identifying the strain always comes first — we check the No More Ransom project, run by Europol and police forces to publish free decryptors, alongside our own tooling. Whatever the family, you’re told honestly what’s recoverable before any work starts.
Ransomware-hit data comes back across every major operating system, server and NAS platform — Windows, macOS and Linux, and the virtual environments running on them. If ransomware reached it, chances are we can help.
Desktops, laptops and workstations; physical and virtual servers; NAS and SAN systems; current and older Windows, macOS and Linux releases.
One principle drives everything here: your files come back without a penny reaching the criminals. Before anyone touches a byte we name the family behind the attack, and we refuse to gamble on a blind payment. From there the job is deliberately methodical — originals are frozen as evidence, every operation happens on cloned copies, and we chase recovery down each avenue in turn: unencrypted leftovers, offline and versioned backups, Windows shadow copies, and any decryptor that genuinely exists.
Walk us through the incident. Using the ransom note plus a handful of scrambled sample files, our engineers pin down which family is responsible — then confirm whether a functioning decryptor is already in circulation for it.
Every affected disk is captured as a write-blocked forensic image. Your original media is sealed away untouched as evidence, while all the subsequent work happens only against the clones.
We rank each avenue by how much it is likely to return, then work down the list: deleted originals carved straight from unallocated space; temporary and half-scrambled files; transaction logs sitting inside your databases; cloud and offline backup sets; shadow copies the malware never managed to wipe; and, last of all, any legitimate published decryptor.
Where a strain is old or flawed enough to have a working decryptor, we run it. Modern families are a different story. BlackCat, Akira, LockBit and their peers wrap each file in AES-256 sealed behind an RSA or ECC key — a lock that no one, this lab included, can pick, and we will not claim otherwise. So we go around the encryption rather than through it: originals the malware duplicated and then overlooked, shadow copies, and the plentiful partly-scrambled files that fast strains leave behind (many bother only with the opening few megabytes, or strike every Nth block), plus whatever else on the platter is still legible.
Files, databases and virtual machines are pulled out and reassembled — and we sequence the work so that whatever you most need running again is handled first.
A full inventory of what came back goes to you for review; once you have confirmed it, everything is written out to a clean external drive.
The recovered set returns to you on new media — or, for lighter volumes, over an encrypted transfer — all set for you to rebuild your systems from.
From workstations up through virtual machines, RAID arrays, NAS boxes and servers, we bring encrypted data back — naming the family first, safeguarding the evidence throughout, and pursuing every open recovery route to the end.
Tell us what happened and we’ll get back to you, usually within a working day.
A reply is on its way to you soon. Anything urgent, our line is 01483 901310.
A written quote lands before any work starts — no buried fees, no pressure.
A few recent ransomware recoveries across servers, NAS and workstations. Identifying details stripped, specifics kept deliberately vague.
This particular family had a documented flaw. Working from read-only images of every disk, we deployed a decryptor and brought the databases and file shares back whole.
What the malware never reached was the NAS’s internal snapshots. Those protected versions, together with everything left unencrypted, came back in full.
With direct decryption off the table, recovery came instead from shadow copies, a dated offline backup, and the unencrypted fragments left on the disk.
Send the device in for its free diagnostic and tell us briefly what happened; an engineer reviews it and confirms your exact quote in writing before anything starts.
Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.
Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.
Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.
We’ll be in touch shortly. If it’s urgent, call 01483 901310.
What people most often ask us after a ransomware attack.
More often than people expect, though the strain sets the ceiling. A few can be decrypted outright; for the rest we lean on other routes — leftover unencrypted data on the drive, offline and cloud backup sets, and Windows shadow copies. Where exactly you land is what the assessment establishes.
Have it assessed before you decide, every time. Handing over money buys no guarantee the decryptor even works, marks you out as an easy repeat target, and bankrolls the next victim’s attack. In a good many jobs we return the data without a single payment changing hands.
On occasion, yes. Older strains sometimes carry published keys or known weaknesses, and the No More Ransom project — a free initiative run by Europol alongside police forces — can crack a number of them. But for today’s major families the cipher is intact and unbreakable by anyone at all; rather than pretend, we simply route around it and recover your data another way.
Usually more than you would think. Off-site and offline copies, NAS snapshots, and shadow copies the malware attempted but failed to purge tend to slip past it; add database transaction logs and half-encrypted files and there is a real amount to rebuild from. We line all of those up against whatever you need restored first.
It is not really about a list. We start by working out the family from the note and a couple of encrypted samples, then check whether a decryptor is available — including the free No More Ransom tools. Whichever strain it turns out to be, we weigh every recovery avenue, not decryption on its own.
That is a core part of what we do. Servers, RAID sets, NAS units and virtual machines that have been locked are all familiar ground: we image each disk, reconstruct the array if it needs it, and pull back file shares, mailboxes and databases.
Completely. We handle these cases quietly and are glad to sign an NDA. Both your data and the fact you were breached at all go no further than us.
For a one-disk machine it is typically a flat per-drive charge from £300 + VAT. Anything bigger is priced case by case, because the strain, how much data is involved and which systems are affected all move the figure. Either way a written quote reaches you before work starts — no surprises.
You can either bring them to our Guildford premises, open 9am to 5:30pm Monday to Friday, or post them under full insurance. From servers and NAS units, pull the drives first and mark each one with its bay or order number. Pop your contact details in so we can log the job, and we will assess it before any work starts.
The defences are dull but effective — versioned or offline backups the malware cannot touch, systems kept patched, and caution around attachments. Already been hit? Take the machine off the network, resist wiping and reinstalling over your only copies, and do not be rushed into paying. Send the drives to us: shadow copies, unencrypted remnants and a dig through old backups frequently turn up more than the ransom note admits, and the free diagnostic gives you an honest read before you commit to anything.
Routinely, yes. Our engineers slot in beside your insurer and whatever incident-response or breach specialists they appoint, rather than cutting across them. Since everything runs on read-only forensic images and copies alone, none of our work disturbs the evidence investigators or insurers rely on — and for your claim we can set down the strain, which systems were affected, and precisely what was retrieved. Do flag any cyber cover early: certain policies insist on an approved provider or particular procedures, and we will work within them.
We name the family, put the numbers in writing, and recover from workstations, NAS and servers alike — with the evidence kept safe for your insurer. Get in touch today.