---
title: 'Ransomware attack recovery'
url: 'https://triplepoint.org.uk/security/incident-response/ransomware-recovery'
markdown: 'https://triplepoint.org.uk/security/incident-response/ransomware-recovery.md'
date: '2026-10-08'
description: 'Help with a ransomware attack for UK businesses. Specialist responders contain it, find out how the attackers got in and what they took, and help you recover safely.'
---

# Ransomware attack recovery

If it's happening now1. **Disconnect, don't switch off.** Unplug affected machines from the network or turn off their Wi-Fi, but leave them powered on if you can: some evidence is lost when a computer shuts down.
2. **Don't contact the attackers or pay anything yet.** Leave the ransom note where it is and take a photo of it.
3. **Call for help.** Contact us, or if you can't reach us, Sophos's UK emergency line on **+44 1235 635329**.
4. **Tell your cyber insurer early.** Many policies require it, and some name the responders you have to use.
5. **Write down what you have seen**: when it started, which systems are affected, and anything unusual beforehand.

 The riskMost ransomware groups now steal data before they encrypt it, then threaten to publish it. Getting your systems back doesn't end that threat, and paying doesn't guarantee the decryption tool works or that the stolen data is deleted.

The encryption is usually the last step. Attackers have often been inside for some time beforehand, and if the way they got in isn't found and closed, a business that has recovered can be hit again.

 What it does- Contains the attack and stops it spreading to systems that are still working
- Identifies the ransomware group and what they are known to do, including whether they publish stolen data
- Works out how the attackers got in and what they touched, so the way in is closed before you recover
- Investigates what data was taken, to help you decide who needs to be told
- Support with ransom negotiation, if it comes to that
- A report on what happened, for your insurer, your board and the regulator

Ransomware usually starts with something else: a phishing email, a stolen password or an unpatched system facing the internet. Once you've recovered, [24/7 managed detection and response](https://triplepoint.org.uk/security/detect-and-respond/mdr) watches for the early signs, and [incident readiness](https://triplepoint.org.uk/security/incident-response/incident-readiness) means you know what to do if it happens again.

 Who it's forAny business hit by ransomware, whether or not you're already a customer. MDR Plus customers already have full incident response included.

 How we supply itRansomware response is carried out by Sophos's incident response team and arranged through us. Contact us and we'll get it started. If you can't reach us, you can call Sophos's UK emergency line directly on **+44 1235 635329**.

 What's under the hood**Sophos Incident Response Services** — Sophos's digital forensics and incident response team, which gained NCSC-assured Cyber Incident Response (Level 2) status in 2024.

 Questions Should we pay the ransom?+That's your decision, usually made with your insurer and legal advisers. Paying doesn't guarantee the decryption tool works or that stolen data is deleted, and paying a group that is under sanctions can be illegal. The responders can help you understand the options.

 Can we get our files back without paying?+Sometimes. Free decryption tools exist for some older ransomware, and the responders will check whether one applies. For most current attacks, though, recovery means rebuilding from clean systems rather than decrypting.

 Do we have to report it?+If personal data may have been taken or made unavailable, UK GDPR usually requires you to report it to the ICO within 72 hours of finding out, unless it's unlikely to put anyone at risk. You can also report the crime through Report Fraud (reportfraud.police.uk) in England, Wales and Northern Ireland, or to Police Scotland on 101.

 How quickly can someone help?+Onboarding starts within hours of getting in touch, and most cases are triaged within 48 hours. How long full recovery takes depends on how far the attack reached.

 How much does it cost?+It depends on the size of the incident, and the cost is agreed with you before work starts.

[← Back to Recover from an attack](https://triplepoint.org.uk/security/incident-response)

## Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

[Talk to us →](https://triplepoint.org.uk/contact?about=Ransomware%20recovery) or [see every security area →](https://triplepoint.org.uk/security)

---

## Navigation

- Parent: [Cyber incident response and recovery](https://triplepoint.org.uk/security/incident-response.md)
- Previous: [Emergency incident response](https://triplepoint.org.uk/security/incident-response/emergency-response.md)
- Next: [Business email compromise (BEC) response](https://triplepoint.org.uk/security/incident-response/business-email-compromise.md)
