Ransomware response & recovery
Contain impact, preserve evidence, eradicate the compromise and validate restoration – with realistic limitations stated up front.
When this fits
- You are currently experiencing a ransomware or extortion incident.
- You need evidence preserved correctly while you recover.
- You need a post-incident review to prevent recurrence.
Decisions and outcomes
This service answers: how do we stop the bleeding, preserve what matters, and get back to safe operations.
Scope
Typically included
- Containment guidance
- Evidence preservation
- Eradication support
- Recovery validation and post-incident review
Not included unless agreed
- Any guarantee of decryption or full recovery
- Encouragement to pay a ransom
Deliverables
- Incident timeline
- Indicators of compromise
- Recovery plan
- Post-incident review
Process
1. Contain
Stop further spread safely.
2. Preserve
Protect evidence before it is lost.
3. Eradicate
Remove the compromise, not just the symptom.
4. Restore and verify
Bring systems back and confirm they are clean.
Methods and standards
Guidance aligns with current official ASD ransomware guidance. See cyber.gov.au.
Security and evidence
No public evidence upload
This page never accepts malware, source code or evidence. Secure transfer is agreed only after authorisation and scoping, outside this website.
Limitations
What this engagement cannot promise
We do not guarantee decryption or complete recovery, and we do not encourage paying a ransom.
Proof
No approved proof for this service yet
Case studies, sample reports and named experts will appear here once approved for publication.
Ready to talk about your situation?
Tell us the high-level scope. No malware, source code or evidence – just enough for us to route you safely.