Containment
Infected systems isolated, remote access cut, suspicious accounts disabled, and encryption stopped from reaching healthy servers.
Start here
Free Audits 5Urgent help
Emergency 4Ongoing support
Managed IT 5Projects
Servers & Hosting 6 Network & Virtualization 9 DevOps 5 Security & Recovery 5 Hardware & Licensing 2Find out where your servers, security, backups and performance stand, at no cost.
Server down, network out, site hacked or data lost? Call us now.
Monthly network and server support with response times written into the contract.
Setup, configuration, management and migration of Linux and Windows servers, panels and mail.
Network design and cabling, MikroTik, VoIP, branch links, virtualization and private cloud.
Networking & communications
Virtualization & cloud
Containers, Kubernetes, automated delivery, infrastructure as code and observability.
Server hardening, firewalls, backup and DR, ransomware recovery and incident forensics.
Advice, supply and installation of servers and network gear, plus genuine enterprise licenses.
Start here
Urgent help
Ongoing support
Projects
Files have strange extensions and every folder has a ransom note. Don't power systems off or delete anything; unplug infected machines from the network and call us. Our job is to contain the attack, work out how far it spread, and bring services back from clean backups.
Ransomware recovery is the work of containing a ransomware attack, establishing how far it spread, cleaning the infected network and bringing services back from clean backups. It is needed when server files carry an unknown extension, the accounting database won't open, or even the backups on a NAS are encrypted. PikoSystem isolates infected systems and disables suspicious accounts, preserves evidence before anything changes, identifies the strain with ID Ransomware and checks No More Ransom for a legitimate decryptor, locates the last clean backup or Shadow Copy, resets passwords and closes the entry point, such as exposed RDP. Decryption is never promised, and you hear plainly what can and can't be recovered. You receive an incident report with timeline and likely entry point, a list of restored systems and lost data, and preserved evidence for legal or insurance follow-up.
Infected systems isolated, remote access cut, suspicious accounts disabled, and encryption stopped from reaching healthy servers.
The ransom note, sample encrypted files, Windows event logs and, where possible, memory and disk images captured before anything changes.
The ransomware family identified from the note and file extensions using ID Ransomware, and a check for a legitimate public decryptor in sources such as No More Ransom.
Backups and Shadow Copies checked, the last pre-infection copy located, and that copy verified clean before restoring.
Systems cleaned or reinstalled, every password reset including service and domain admin accounts, and the initial entry point closed, such as exposed RDP or a vulnerable VPN.
Servers and data restored in order of business priority, with monitoring for signs the attacker is coming back.
A few simple facts speed up the assessment when you call. Note the time the first sign appeared, which systems have encrypted files and which still look healthy, and keep a photo or copy of the ransom note, which usually names the group or a contact channel.
We also need to know where backups live and when the last good one ran, which domain and server admin accounts exist, and how the network is laid out, even as a sketch on paper. Write down everything done so far, with times. Name one person who can make fast calls, such as cutting the company off the internet.
Restore order matters as much as the backups. Identity comes first: a compromised domain controller is either restored from a pre-intrusion backup in an isolated network or the domain is rebuilt, and the krbtgt account password is reset twice with a gap between resets. Then DNS, DHCP and the backup infrastructure, then databases and core business applications, and finally file servers and user machines.
Each restored system is powered on and scanned in a separate VLAN before it rejoins the main network. This order is best written down before any incident.
The most common is restoring before the entry point is closed. If exposed RDP or a leaked VPN account is still active, the attacker encrypts everything again the same night. Next is restoring from a backup taken while the attacker was already inside, which brings their backdoor back with the data.
Resetting passwords from a machine that is itself infected, missing service accounts and the scheduled tasks an attacker pushed out through Group Policy, and reconnecting the backup NAS before cleanup is finished all send recovery back to square one.
WannaCry spread in 2017 as a worm, using the EternalBlue exploit against SMBv1 and jumping between machines automatically. Installing the MS17-010 patch and blocking port 445 from the internet stopped most infections.
Current ransomware is mostly human-operated. Attackers log in with stolen VPN or RDP credentials, spend days or weeks moving around the network, take over a domain admin account, delete backups, copy data out, and then launch encryption on every server at once. That is why recovery today also has to cover compromised accounts, attacker persistence and possible data theft.
On the first call we guide you through isolating systems and arrange the access we need.
We identify the strain, the affected systems and the state of your backups, then explain your real recovery options.
We close the entry point, clean or rebuild systems and restore data in priority order.
We deliver the incident report and implement or recommend changes to backups, access and the network.
For most current ransomware, decryption without the attacker's key isn't possible, and we won't promise it. If a legitimate decryptor exists for your strain, we test it on copies of your files. The main recovery path is clean backups and any surviving Shadow Copies.
That decision is yours, but paying doesn't guarantee a working key and may carry legal consequences. Before deciding anything, check the state of your backups and your recovery options.
Many ransomware groups copy data out before encrypting. By reviewing firewall logs, outbound traffic and tools the attacker left behind, we assess whether data left the network and state it in the report.
We then look at Shadow Copies, older backups on separate media, file versions in cloud services, and database files that were only partly encrypted. Results depend on each incident, and we tell you plainly what is and isn't recoverable.
Related searches
Quote
A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.