ACTIVE INCIDENT RIGHT NOW? Gridisys 24/7 emergency triage — £0 first 15 minutes.
24/7 EMERGENCY INCIDENT RESPONSE · UK

Hit by Ransomware? Here's what to do.

You're looking at encrypted files, a ransom wallpaper, or a chat from someone telling you 'your files have been encrypted'. Don't pay. Don't restart. Don't guess. Here's the costed, evidence-first path UK firms take to recover.

We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.

YOU MAY HAVE SEARCHED

"my files are encrypted what do I do""we have ransomware what do I do UK""ransomware recovery UK""how do I recover from ransomware""should I pay the ransom""lockbit has encrypted our servers""cl0p ransom note""akira ransomware UK"

Do these 4 things in the next 10 minutes

  1. 1

    Take a photo of the ransom note with your phone — don't click any links or paste any text from it. The ransom note tells us which group we're dealing with, and identifies the decryption trail and indicator patterns.

  2. 2

    Disconnect the infected device(s) from the network — pull the cable or disable Wi-Fi. Do NOT power them off (see below).

  3. 3

    Identify what's encrypted — file shares, SharePoint, OneDrive, the Exchange mailbox, the backup server. This tells us the blast radius and how good your recovery options are.

  4. 4

    Stop a spread: disable any sync tools (OneDrive, Google Drive sync) that might be silently propagating encrypted files to the cloud, where they'd overwrite clean versions.

Ransomware hit over 60% of UK businesses in the last 12 months — most cases never reach the news. Recovery is usually possible without paying. The cost is measured in downtime, not ransoms.

What we do — the Gridisys incident timeline

From the moment you engage, within fixed-price limits.

Hours 0-4

Identification

  • Identify the ransomware family — variant, leak site, known decryption tools available (NoMoreRansom has free tools for 160+ variants).
  • Stop the spread: block known malicious infrastructure at your firewall/Defender, isolate additional hosts showing infection indicators.
  • Preserve evidence: the ransom note, encrypted file samples, any attacker communications — these inform ICO reasoning and insurer notification.
Hours 4-24

Containment

  • Hunt for attacker persistence — backdoor accounts, malicious OAuth grants, scheduled tasks, RDP enablement, new admin accounts in Entra / AD.
  • Validate backup availability: do you have clean backups? Where? Are they reachable from the compromised network? Cloud immutable backups are usually the answer.
  • Decide on ransom — gather facts (recovery difficulty, decryption feasibility, data exposure) so leadership can decide rationally, not under threat.
  • Begin ICO risk assessment — ransomware involving personal data is overwhelmingly an Article 33 case.
Days 2-14

Eradication & recovery

  • Wipe or rebuild infected systems from gold images — never attempt to clean ransomware in place.
  • Restore from clean backups, validating version integrity as you go.
  • Reset all credentials — not only those clearly compromised. Reset M365, AD, service accounts, RDP, admin accounts.
  • Close the entry vector: MFA enforcement, conditional access baselines, RDP exposure, email security, EDR/Defender coverage, app consent policy.
Weeks 2-6

Regulatory & resilience

  • ICO notification submitted if required (within 72 hours of awareness — see our ICO breach notification service).
  • Cyber-insurer close-out — evidence, timeline, claim filing.
  • Post-incident review — what we learned, what controls to add, how to prevent a recurrence. Optional: weeks 4-8 months of free Gridisys managed SOC support.

What it costs

A Gridisys ransomware triage + containment engagement is fixed-price. Full incident response (containment, eradication, recovery coordination, ICO decision, insurer coordination) is scoped to your environment size, multi-site spread, and regulatory reporting needs. The initial 15-minute triage call is free — we'll tell you up front what an engagement would cost in your situation. Contact us for a tailored quote.

Full pricing breakdown

What we cover

LockBit, Cl0p, Akira, Black Basta, Rhysida, Royal, Play, BianLian, 8Base and other active variants
Microsoft 365 / Entra ID ransomware + mailbox-side compromise (BEC layered with encryption)
Windows server & endpoint ransomware (file servers,hyper-V hosts, domain controllers, RDS farms)
VMware ESXi and Linux hypervisor ransomware (Akira, Royal, Play variants)
Backup-targeted ransomware — Veeam, Commvault, Backup Exec compromise
ICO Article 33 decision + drafting — see our ICO breach notification consulting
Cyber insurance coordination — panel-vendor coordination, evidence preservation for the insurer
Decryption feasibility assessment — NoMoreRansom tool availability, key recovery, structure analysis

Frequently asked questions

Talk to us now

The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.