# Ransomware Recovery and Response

Source: https://dijitulsupport.co.uk/ransomware-recovery/
Updated: 2026-10-10

> dijitul support helps UK small businesses recover from ransomware: isolating infected devices, finding how the attacker got in, checking which backups are clean, restoring data and rebuilding affected PCs and servers. We also close the gap so it does not happen again. Emergency work is £45 an hour + VAT, and larger recoveries are quoted.

## Common symptoms

- Files have strange extensions and will not open
- A ransom note text file has appeared in every folder
- Your desktop wallpaper has been replaced with a demand for payment
- The server or NAS is unreachable or its shares are empty
- OneDrive is showing thousands of files changed at once
- Your antivirus has been switched off and you did not do it

## Key facts

- First step: disconnect affected devices from the network, but do not switch them off
- The Cyber Security Breaches Survey 2025/2026 found only 25% of UK businesses have a formal incident response plan
- Cloud-synced folders such as OneDrive can sync encrypted files, but version history can often roll them back
- The NCSC advises against paying ransoms; payment does not guarantee data back
- Personal data breaches may need reporting to the ICO within 72 hours
- Recovery work: £45 an hour + VAT; whole-office rebuilds are quoted

## The first 30 minutes

What you do straight away decides how much you lose. Call dijitul on 01623 650333 or 07425 323333, and while you wait:

- **Unplug the network cable and turn off Wi-Fi** on any device showing ransom notes or encrypted files. Do not shut it down; memory can hold useful evidence and sometimes encryption keys.
- **Disconnect backup drives** that are plugged in, and do not plug any in.
- **Do not reply** to the attackers or visit their payment site.
- **Write down what you see**: the ransom note name, the file extension, the time you noticed.
- **Check other devices**, especially the server, NAS and any PC with mapped drives.

## How we recover your business

Our recovery work follows a clear order:

- **Contain:** isolate infected machines, disable compromised accounts, revoke Microsoft 365 sessions and block remote access (RDP, VPN) until we know how they got in.
- **Identify:** work out the ransomware family from the note and file extension. The No More Ransom project lists free decryptors for some older strains; we check before anything else.
- **Check backups:** confirm which backups predate the infection and are untouched. Cloud backups with immutability or versioning are usually the safest source.
- **Rebuild, do not clean:** we wipe and reinstall infected PCs and servers rather than trying to remove malware in place. It is quicker to trust a fresh build.
- **Restore:** bring data back from clean backups, oldest-risk first, and check it opens.
- **Close the door:** fix the entry point, which is most often a phished password, an exposed RDP port, an unpatched VPN or a reused admin account.

## OneDrive, SharePoint and cloud files

If a PC syncing OneDrive gets encrypted, the encrypted files sync up to the cloud. The good news: Microsoft 365 keeps version history, and OneDrive has a *Restore your OneDrive* feature that rolls a whole library back to a point in time within the last 30 days. SharePoint libraries have the same option. We use these to restore cloud files quickly once the infected device is offline. This is also why version history and retention settings matter before anything happens. See [SharePoint and OneDrive support](https://dijitulsupport.co.uk/sharepoint-onedrive-support/).

## How ransomware usually gets in

In small businesses we see the same few entry points again and again:

- **Remote Desktop exposed to the internet**, often port-forwarded years ago so someone could work from home, protected by a weak or reused password.
- **Phished Microsoft 365 or VPN credentials** with no MFA, giving the attacker a normal-looking login.
- **Unpatched firewalls and VPN appliances** with known vulnerabilities that criminals scan for automatically.
- **Malicious email attachments** or fake software updates that install a loader, which later brings in the ransomware.

Finding the actual entry point matters. Restoring data without closing it invites a second attack, sometimes within days.

## Should you pay?

That is your decision, and we will not make it for you, but the NCSC advises against paying. Payment does not guarantee you get a working decryptor, many groups also steal data and threaten to publish it regardless, and paying marks you as a business that pays. If you have cyber insurance, call your insurer's incident line early, as many policies require you to use their response process.

Report the attack to Report Fraud, which replaced Action Fraud on 4 December 2025, at reportfraud.police.uk or 0300 123 2040. If personal data was accessed or made unavailable, you may need to report to the ICO within 72 hours. We will help you gather the technical facts for both.

## Make sure it is the last time

According to the UK Government's Cyber Security Breaches Survey 2025/2026, only 25% of businesses have a formal incident response plan. After a recovery we help you put the basics in place: 3-2-1 backups with at least one copy offline or immutable, MFA everywhere, no exposed RDP, patching within 14 days and separate admin accounts. See [data backup and recovery](https://dijitulsupport.co.uk/data-backup-recovery/) and [endpoint protection](https://dijitulsupport.co.uk/antivirus-endpoint-protection/).

Emergency recovery is charged at £45 an hour + VAT. Where a whole office or server needs rebuilding, we give you a quote once we have seen the damage. For ongoing protection, the [Complete plan](https://dijitulsupport.co.uk/pricing/) is £99 a month + VAT.

## FAQs

### What should I do first if we are hit by ransomware?

Disconnect affected devices from the network by unplugging the cable and turning off Wi-Fi, but leave them switched on. Unplug any backup drives. Do not contact the attackers. Then call dijitul on 01623 650333 so we can contain the spread and check which backups are safe.

### Can you decrypt our files without paying?

Sometimes. Free decryptors exist for some older ransomware families, listed by the No More Ransom project, and dijitul checks that first. For most modern strains, recovery depends on clean backups or Microsoft 365 version history. That is why tested, offline or immutable backups matter so much.

### How long does ransomware recovery take?

It depends on how many devices were hit and the state of your backups. A single infected laptop with OneDrive version history can be recovered the same day. A server and several PCs needing rebuilds take longer. dijitul quotes larger recoveries once we have assessed the damage.

### Do I have to report a ransomware attack?

If personal data was accessed, lost or made unavailable and the breach poses a risk to people, UK GDPR requires reporting to the ICO within 72 hours. Reporting the crime to Report Fraud is strongly recommended. dijitul helps you gather the technical details both reports need.

### How much does ransomware recovery cost?

dijitul charges £45 an hour + VAT for emergency response and recovery work. Whole-office rebuilds or server restores are quoted once we know the scope. That cost is usually far smaller than the downtime, which is why we focus on getting you working again first.

## Pricing and contact

Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Plans: Essential £25/month + VAT (Website software updates (core, plugins, themes) applied and checked, Daily backups, Uptime monitoring, Security monitoring); Business £50/month + VAT (Everything in Essential, 1 hour of fixes or changes every month, Priority support); Complete £99/month + VAT (Everything in Business, 3 hours of fixes or changes every month, IT and Microsoft 365 helpdesk for your team). Ad-hoc support is £45 an hour + VAT. The first 30 minutes are the minimum charge, then we bill in 15-minute blocks. Contact: 01623 650333, support@dijitul.uk, https://dijitulsupport.co.uk/contact/
