Skip to main content

Do not send malware, source code, credentials or evidence through this website. Responding to an active incident? Get incident help.

Ransomware Response & Recovery

Ransomware response & recovery

Contain impact, preserve evidence, eradicate the compromise and validate restoration – with realistic limitations stated up front.

When this fits

  • You are currently experiencing a ransomware or extortion incident.
  • You need evidence preserved correctly while you recover.
  • You need a post-incident review to prevent recurrence.

Decisions and outcomes

This service answers: how do we stop the bleeding, preserve what matters, and get back to safe operations.

Scope

Typically included

  • Containment guidance
  • Evidence preservation
  • Eradication support
  • Recovery validation and post-incident review

Not included unless agreed

  • Any guarantee of decryption or full recovery
  • Encouragement to pay a ransom

Deliverables

  • Incident timeline
  • Indicators of compromise
  • Recovery plan
  • Post-incident review

Process

1. Contain

Stop further spread safely.

2. Preserve

Protect evidence before it is lost.

3. Eradicate

Remove the compromise, not just the symptom.

4. Restore and verify

Bring systems back and confirm they are clean.

Methods and standards

Guidance aligns with current official ASD ransomware guidance. See cyber.gov.au.

Security and evidence

No public evidence upload

This page never accepts malware, source code or evidence. Secure transfer is agreed only after authorisation and scoping, outside this website.

Limitations

What this engagement cannot promise

We do not guarantee decryption or complete recovery, and we do not encourage paying a ransom.

Proof

No approved proof for this service yet

Case studies, sample reports and named experts will appear here once approved for publication.

Ready to talk about your situation?

Tell us the high-level scope. No malware, source code or evidence – just enough for us to route you safely.