Anyone, at the worst possible moment
“Everything is encrypted and there is a ransom note on the screen”
Does this sound familiar?
- Files renamed with an unfamiliar extension and will not open
- A ransom note on desktops or printed from network printers
- Shared drives and the server inaccessible
- Backup software reporting failures or the backup drive is encrypted too
- Staff unable to work and nobody certain what to touch
What it costs to ignore
Every hour of delay costs money and destroys evidence. Powering machines off wipes encryption keys that sometimes sit in memory. Restoring into a network the attacker still controls gets you encrypted again within days. And if personal information was accessed, Quebec's Law 25 imposes notification obligations that depend on scoping the breach properly.
How the engagement runs
- 1
Contain without destroying evidence
Isolate affected machines at the network layer. Do not power them off — volatile memory frequently holds encryption keys and forensic evidence that shutdown erases permanently.
- 2
Establish scope
How they got in, how long they were inside, what moved laterally, and what data was actually accessed rather than theoretically reachable. Insurers and regulators will require this.
- 3
Eradicate
Remove persistence mechanisms, rotate every credential in the blast radius, and close the original entry vector before anything is restored.
- 4
Restore from verified-clean backups
Into a rebuilt environment, in dependency order. Our objective is always recovery without funding the attacker.
- 5
Document and harden
The written timeline your insurer, lawyer and board will ask for, plus the fixes that stop a repeat. Attackers revisit organisations that paid or that never closed the door.
If this is happening right now
Email info@digitalsecurityconsulting.com with URGENT in the subject line. We prioritise active incidents ahead of scheduled work and aim to begin remote triage the same business day.
Before you do anything else:
- Disconnect, do not shut down. Pull the network cable. Leave the machine running.
- Delete nothing. The ransom note, the strange scheduled task, the unfamiliar admin account — all of it is evidence.
- Do not restore yet. Restoring into a network the attacker still holds means re-encryption within days.
- Check your insurance policy before engaging any responder.
Why the order matters
The instinct is to get back up immediately. That instinct is what turns a recoverable incident into a repeat one.
Contain, scope, eradicate, then restore. In that order. Skipping the scoping step means you never learn how they got in — so you rebuild the same environment with the same door open.
What happens afterwards
Recovery is not the end of the engagement. Attackers return to organisations that paid, and to organisations that never closed the entry vector. The hardening plan, the backup work and the credential hygiene are what make this a one-time event rather than an annual one.
What you get
- Containment and eradication of the active incident
- Restoration from clean backups where they exist
- Forensic timeline and scope-of-access findings
- Documentation suitable for insurers, counsel and Law 25 obligations
- A prioritised hardening plan so it does not happen twice
Frequently asked questions
What should we do in the first ten minutes?
Disconnect affected machines from the network but do not power them off. Do not delete anything, including the ransom note. Do not restore yet. Then email us with URGENT in the subject line. Powering off destroys encryption keys that are sometimes recoverable from memory, and restoring into a compromised network simply gets you encrypted again.
Should we pay the ransom?
Almost never as a first move. Payment funds the attacker, does not guarantee a working decryptor, and marks you as an organisation that pays — a real factor in repeat targeting. Decryptors supplied by attackers are frequently slow, buggy or partial. It is a decision for leadership with legal and insurance advice, only after recovery options are genuinely exhausted. We do not broker payments.
How long does recovery take?
With tested offline backups, usually days. Without them, weeks — or never. That difference was decided months before the attack, by whether anyone tested a restore.
Do we have to report it?
If personal information was compromised, Quebec's Law 25 imposes obligations including notifying the Commission d'accès à l'information and affected individuals where there is a risk of serious injury. Establishing scope accurately is what determines your obligations, which is another reason not to destroy evidence in the first hour.
Will our cyber insurance cover this?
Often, but most policies require prompt notification and many will not cover responders engaged without prior approval. Check the policy before hiring anyone, including us. We produce the timeline and remediation documentation insurers require and keep evidence handling clean so your claim is not compromised.
Services involved
Cybersecurity
Incident response, ransomware recovery, and hardening that holds up under audit.
Learn moreInfrastructure & Backup
Servers, clusters and backups designed so that failure is survivable and boring.
Learn moreWireless & Networks
Wi-Fi and network infrastructure designed, deployed, then attacked to prove it holds.
Learn moreTell us what is breaking — or what you are trying to build.
You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.
Active incident? Write “URGENT” in your message and we prioritise it.