If your files have been encrypted and you are looking at a ransom note, the next hour matters. We help London businesses and home users find out what can be recovered without paying, recover it, and get systems back up safely.
What to do right now
- Disconnect affected computers, servers and NAS boxes from the network, including Wi-Fi. Leave them powered on if they already are, and do not restart them.
- Disconnect backups. Unplug backup drives and pause cloud sync so that encrypted files do not overwrite good copies.
- Keep the evidence. Do not delete the ransom note or the encrypted files, and do not run clean-up tools yet.
- Do not contact the attacker or pay before you know what can be recovered.
- Call us on 020 7237 6805.
What we do
Identify the strain
The ransom note, the file extension and a sample of encrypted files tell us which ransomware family was used, and whether a free decryption tool has been published for it.
Look for what survived
We check for volume shadow copies, NAS snapshots, cloud version history, offline backups and old drives. Attackers try to delete these and often miss some.
Recover partly encrypted files
To work quickly, many strains encrypt only part of each large file. Databases, virtual machine disks, mail stores and archives can often be repaired or have most of their contents extracted.
Recover deleted originals
Some ransomware writes an encrypted copy and deletes the original. On hard drives those deleted originals can sometimes be recovered from an image of the disk.
Rebuild cleanly
Recovered data goes onto clean systems. We reinstall, patch and restore, so the route the attacker used is closed before anything goes back online.
What nobody can honestly promise
Modern ransomware uses encryption that cannot be broken without the key. Any company that guarantees decryption for every strain is either paying the ransom on your behalf or misleading you. Our commitment is to tell you what is recoverable and what is not, and to confirm the price before recovery work starts.
Cost
Ransomware recovery is quoted case by case, because the cost depends on how many drives are involved and what can be recovered by each route. The initial consultation is free. Our fixed prices for other recoveries are on the data recovery calculator.
Questions
Can you decrypt my files without paying the ransom?
Sometimes. Free decryption tools exist for some ransomware strains, and many attacks leave backups, snapshots or partly encrypted files that can be recovered. Where the encryption is sound and nothing else survives, no one can decrypt the files without the attacker's key, and we will tell you if that is the case.
Should I pay the ransom?
UK law enforcement and the National Cyber Security Centre advise against paying. Payment does not guarantee you get your files back and marks you as someone who pays. It is your decision, and it should be made after you know what can be recovered without paying.
Do I have to report a ransomware attack?
If personal data was affected, organisations must assess whether to report it to the Information Commissioner's Office, normally within 72 hours of becoming aware. Attacks should also be reported to the police through the national fraud and cyber crime reporting service.
Should I wipe the infected computers?
Not yet. Disconnect them from the network and leave them as they are. The encrypted files, the ransom note and the system logs are what we use to identify the strain and find out what is recoverable.

