Take the affected machines off the network and the internet — cables out, Wi-Fi off — then resist the two instincts that destroy evidence: wiping and reinstalling. Leave the NAS or server exactly as it stands until there's a plan. Photograph the ransom note, record the extension the encrypted files now end in, and pause every scheduled backup job at once, because a backup that runs now can replace your last clean copies with encrypted ones.
One more early call: if the affected systems held personal data and UK GDPR applies to your business, the incident may need reporting as a breach — bring your compliance person or provider in at the start rather than the end.
First: copies the malware never reached. Offline and off-site backups, version history in OneDrive, SharePoint, Google Drive and Dropbox (all of which can wind files back to before the attack), NAS snapshots, and Windows shadow copies. Current strains attempt to destroy snapshots and shadow copies — attempt being the key word; partial survivals are something we find again and again.
Second: a published decryptor. Researchers and the No More Ransom project have broken a number of families and released free tools. Identify the strain precisely — the note plus the new file extension usually does it — and you'll know whether yours is one of them. Steer well clear of paid 'decryption services' on unknown websites: the usual business model is paying the criminals with your money, or simply keeping it.
Third: whatever the encryption never finished. Encrypting terabytes takes hours, and attacks get interrupted — by staff, by reboots, by the malware's own bugs. Real jobs turn up clean files on secondary volumes, earlier versions in unallocated space, whole virtual machine snapshots, database backups the malware didn't parse, and files where only the opening blocks were touched. Recovering those is conventional lab craft pointed at an unconventional crime scene: image every drive, then audit, file by file, what survived.
Our answer is flat: no — and we never pay ransoms or negotiate with attackers on a client's behalf. The practical case against paying is as strong as the ethical one: a consistent share of those who pay receive nothing usable, paying advertises your organisation as a payer to the next crew, official UK guidance says don't, and if the group behind the strain is sanctioned the payment may itself carry legal risk. Put the three routes above to work instead — businesses that arrive certain they'll 'have no choice' usually leave with far more recovered than they expected.
Report the incident through Action Fraud, and keep the encrypted drives. Preserving them costs nothing, and ransomware families do get broken months later — at which point a shelf of preserved drives goes from worthless to recoverable overnight.
Ship or courier in the affected drives, NAS or server — drives labelled by bay — and everything is imaged before analysis begins, so no original is ever worked on. You receive a written account of what's recoverable across all three routes and a single fixed quote; ransomware sits in our forensic category, which means the agreed price is payable upfront rather than on completion. A live incident is pulled to the front the moment it's booked in — ring 0800 689 0668 and say the attack is still running.
Full details are on the ransomware data recovery page, with related reading on NAS recovery, RAID recovery and SAN & virtual machine recovery — between them, the storage where business data usually lives when an attack lands.
Pause every backup job the moment ransomware is found. One scheduled run after encryption can replace your only clean copies with encrypted ones — the most expensive automation failure there is.
Free diagnostic on arrival, one fixed quote, no fix no fee on logical faults — start online or pick up the freephone.