Hit by Ransomware? Here's what to do.
You're looking at encrypted files, a ransom wallpaper, or a chat from someone telling you 'your files have been encrypted'. Don't pay. Don't restart. Don't guess. Here's the costed, evidence-first path UK firms take to recover.
We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.
YOU MAY HAVE SEARCHED
Do these 4 things in the next 10 minutes
- 1
Take a photo of the ransom note with your phone — don't click any links or paste any text from it. The ransom note tells us which group we're dealing with, and identifies the decryption trail and indicator patterns.
- 2
Disconnect the infected device(s) from the network — pull the cable or disable Wi-Fi. Do NOT power them off (see below).
- 3
Identify what's encrypted — file shares, SharePoint, OneDrive, the Exchange mailbox, the backup server. This tells us the blast radius and how good your recovery options are.
- 4
Stop a spread: disable any sync tools (OneDrive, Google Drive sync) that might be silently propagating encrypted files to the cloud, where they'd overwrite clean versions.
What we do — the Gridisys incident timeline
From the moment you engage, within fixed-price limits.
Identification
- ▸Identify the ransomware family — variant, leak site, known decryption tools available (NoMoreRansom has free tools for 160+ variants).
- ▸Stop the spread: block known malicious infrastructure at your firewall/Defender, isolate additional hosts showing infection indicators.
- ▸Preserve evidence: the ransom note, encrypted file samples, any attacker communications — these inform ICO reasoning and insurer notification.
Containment
- ▸Hunt for attacker persistence — backdoor accounts, malicious OAuth grants, scheduled tasks, RDP enablement, new admin accounts in Entra / AD.
- ▸Validate backup availability: do you have clean backups? Where? Are they reachable from the compromised network? Cloud immutable backups are usually the answer.
- ▸Decide on ransom — gather facts (recovery difficulty, decryption feasibility, data exposure) so leadership can decide rationally, not under threat.
- ▸Begin ICO risk assessment — ransomware involving personal data is overwhelmingly an Article 33 case.
Eradication & recovery
- ▸Wipe or rebuild infected systems from gold images — never attempt to clean ransomware in place.
- ▸Restore from clean backups, validating version integrity as you go.
- ▸Reset all credentials — not only those clearly compromised. Reset M365, AD, service accounts, RDP, admin accounts.
- ▸Close the entry vector: MFA enforcement, conditional access baselines, RDP exposure, email security, EDR/Defender coverage, app consent policy.
Regulatory & resilience
- ▸ICO notification submitted if required (within 72 hours of awareness — see our ICO breach notification service).
- ▸Cyber-insurer close-out — evidence, timeline, claim filing.
- ▸Post-incident review — what we learned, what controls to add, how to prevent a recurrence. Optional: weeks 4-8 months of free Gridisys managed SOC support.
What it costs
A Gridisys ransomware triage + containment engagement is fixed-price. Full incident response (containment, eradication, recovery coordination, ICO decision, insurer coordination) is scoped to your environment size, multi-site spread, and regulatory reporting needs. The initial 15-minute triage call is free — we'll tell you up front what an engagement would cost in your situation. Contact us for a tailored quote.
Full pricing breakdownWhat we cover
RELATED INCIDENT RESPONSE GUIDES
Frequently asked questions
Talk to us now
The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.