Disconnect the affected machines from the network and the internet — pull cables, kill Wi-Fi — but don't wipe anything and don't switch off the NAS or server until you've thought it through. The instinct to reinstall Windows and move on destroys exactly the artefacts that make recovery possible. Photograph the ransom note, note the file extension the encrypted files now carry, and stop all backup jobs immediately so encrypted files don't overwrite your last good backup versions.
If the business falls under UK GDPR and personal data is involved, remember an attack may be a reportable breach — loop in whoever handles your compliance early.
Route one: copies the ransomware missed. Offline and off-site backups, cloud version history (OneDrive, SharePoint, Google Drive and Dropbox can roll files back to pre-attack versions), NAS snapshots, and Windows shadow copies. Modern ransomware tries to delete shadow copies and NAS snapshots — but 'tries' is the operative word, and we regularly find them partly intact.
Route two: a free decryptor. Some ransomware families have been broken and have free decryption tools published by researchers and the No More Ransom project. Identifying the exact strain (from the note and file extension) tells you if you're lucky. Never buy a 'decryption service' from an unknown website — most simply pay the criminals or take your money.
Route three: lab recovery of what encryption didn't reach. Encryption takes time, and attacks get interrupted. On real jobs we find untouched files on secondary drives, older file versions in unallocated space, whole virtual machine snapshots, database backups the malware didn't parse, and partially encrypted files where only the first blocks are damaged. This is standard data recovery craft applied to an unusual crime scene — imaged drives, forensic tools, and a file-by-file audit of what survived.
Payment is a last resort, and not just ethically: industry studies year after year find a meaningful share of payers get nothing usable back, and payment marks you as a payer for the next crew. UK authorities advise against paying, and for some sanctioned groups paying can itself create legal exposure. Exhaust the three routes above first — most businesses that come to us assuming they'll 'have to pay' turn out to have more surviving data than they thought.
Report the attack via Action Fraud and preserve the evidence — it costs nothing and occasionally the strain you're hit with is one that gets broken months later, at which point preserved encrypted drives become recoverable.
Send or courier the affected drives, the NAS or the server (labelled by bay), and we image everything before any analysis — originals are never worked on. You get a report of what's recoverable across all three routes and one fixed quote; no fix, no fee applies to ransomware like everything else. Business-critical cases are prioritised on arrival — call 0800 689 0668 and say it's an active incident.
Related reading: NAS recovery, RAID recovery and SAN & virtual machine recovery — the three places business data usually lives when ransomware hits.
Stop backup jobs immediately after an attack. A scheduled backup that runs post-encryption can overwrite your last clean copies with encrypted ones — turning a bad day into a disaster.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.