IT emergency · ransomware

Your data has been encrypted? Take a breath. We'll help you out of this.

A ransomware attack feels like the whole company has ground to a halt. We guide you through the crisis — from the first hour and checking whether your data can be saved despite encryption, to securely rebuilding your IT and ERP landscape. With a German team that speaks your language and knows your systems.

Affected right now?

Call us directly:

+49 431 128 371 33

Or describe the situation in writing — please from an account that is not affected by the attack.

The first minutes

What to do right now — and what not to do.

  1. 1

    Disconnect — don't power off

    Pull network cables and disable Wi-Fi on affected systems. But leave the devices switched on: memory often holds traces that are valuable for analysis and decryption.

  2. 2

    Isolate backups immediately

    Disconnect backup servers, NAS and external drives from the network before the attackers reach them too. Restore nothing until the cause is clear.

  3. 3

    Document everything

    Photograph the ransom note, write down times, affected systems and first anomalies. Insurers, authorities and forensics will need this information.

  4. 4

    Notify insurer & get help

    Report the incident to your cyber insurer (if you have one) and get experienced support immediately — every hour counts.

Please don't

  • Don't reinstall systems or “quickly clean up” — this destroys evidence and recovery chances.
  • Don't contact or pay the attackers on your own.
  • Don't run unknown “decryption tools” from the internet.
  • Don't communicate about the incident via potentially compromised email accounts.

How we guide you

From the first hour to a hardened IT.

A crisis needs structure. We guide you through six phases — with clear responsibilities, traceable decisions and one fixed point of contact.

  1. Phase 01

    First response & containment

    We stop the spread, secure affected systems and evidence and get a first picture of the situation — remotely right away, on-site by arrangement.

  2. Phase 02

    Assess recoverability

    Before anyone thinks about ransom, we systematically check every route back to your data — backups, snapshots, shadow copies, known decryptors, weaknesses in the encryption.

  3. Phase 03

    Crisis team & communication

    Together with you we form a crisis team, structure decisions and tasks and support communication with employees, customers, suppliers, insurers and authorities.

  4. Phase 04

    Negotiation support

    If there is no other way, we handle communication with the attackers — level-headed, documented and coordinated with you, your insurer and the investigating authorities.

  5. Phase 05

    Rebuilding the IT landscape

    We rebuild your infrastructure cleanly — prioritised by what your business needs first: identities, servers, workplaces, ERP. Never restore what was compromised.

  6. Phase 06

    Hardening & follow-up

    We close the entry points, set up immutable backups and monitoring and create an emergency plan with you — so it doesn't happen a second time.

Recovery

Encrypted doesn't mean lost.

Before anyone talks about ransom, we check every route back to your data. Experience shows there are more of them than it seems in the initial panic. There's no guarantee — but there is an honest assessment, quickly.

  • Backups & snapshots

    We check all backup states for integrity and infection — including those forgotten or believed to be unusable.

  • Shadow copies & version history

    Windows shadow copies, hypervisor snapshots and Microsoft 365/OneDrive versioning survive an attack more often than you'd think.

  • Known decryptors

    Publicly available decryption tools exist for a number of ransomware families, e.g. via the “No More Ransom” project. We identify the variant and check this safely.

  • Incomplete encryption

    Many variants only partially encrypt large files for speed. Databases and archives can then often be largely recovered.

  • Rescuing ERP databases

    Our speciality: SQL Server databases of Navision and Business Central. We know the data structures and can reconstruct accounting, inventory and orders even from damaged data.

  • Cloud & third-party data

    What's held in SaaS services, at your tax advisor, at banks or in mailboxes helps rebuild master data and open items.

Negotiation

If it comes to contact with the attackers, you won't stand alone.

Extortionists rely on time pressure and fear. We handle communication calmly and professionally, buy time for recovery and clarify what data was actually exfiltrated. You make every decision — informed and coordinated with your insurer, legal counsel and the authorities.

  • Identification of the threat actor and its known behaviour
  • Proof that the attackers can actually decrypt
  • Clarification of scope and type of stolen data
  • Sanctions and legal check before any payment decision
  • Complete documentation for insurers and investigators

Before it happens

Ransomware readiness check

The best crisis is the one that never happens — or is over in hours rather than weeks. We check how well prepared you are today.

  • Backup concept with a real restore test
  • Immutable and separated backups
  • Review of admin access, MFA and remote access
  • Emergency plan with phone list and restart order
  • Crisis exercise (tabletop) with management and IT
  • Restart plan for ERP and core processes

FAQ

Frequently asked questions.

In an emergency: better to call once too early.

+49 431 128 371 33
Should we pay the ransom?
In principle we advise against it — as do Germany's BSI and the police: payment finances further attacks, does not guarantee working decryption and does not protect against publication of stolen data. Our first goal is always to get you operational again without paying. If the company's existence is at stake, the decision is yours alone — we then make sure it is taken informed, legally reviewed and coordinated with your insurer and the authorities.
Why negotiate with attackers if you don't want to pay?
Professional communication buys time for recovery, provides information about the scope and nature of data exfiltration and can be used to verify whether a decryptor works. Whether anything is paid in the end is a separate decision.
What reporting obligations do we have?
If personal data is affected, notification to the competent data protection authority is usually required within 72 hours (Art. 33 GDPR). Companies covered by NIS2 also have short reporting deadlines towards the BSI. We also recommend filing a report with the cybercrime contact point (ZAC) of your state criminal police office. We help with the preparation — the legal assessment is made by your legal counsel or data protection officer.
Will cyber insurance cover the costs?
Many cyber policies cover the costs of crisis management, recovery and business interruption — but often only with prior agreement. So inform your insurer immediately. We work transparently with your insurer and its service providers and document our services so they can be claimed.
Do you also do IT forensics?
Our focus is on crisis management, recovery and rebuilding. Where a court-proof forensic investigation is required, we secure evidence properly and work hand in hand with specialised forensic experts, your legal counsel and the investigating authorities.
We're not (yet) affected. Can you prepare us?
Absolutely — that's the cheapest route. With a ransomware readiness check we review backups (including a restore test), access and emergency plans and rehearse the emergency with you before it happens.

Note: this page does not replace legal advice. Decisions about notifications, communication with attackers or payments should always be coordinated with legal counsel, insurers and the competent authorities.

IT emergency · ransomware

You don't have to go through this alone.

Call us or report the incident in writing — we'll get back to you as soon as possible and discuss the next steps with you.

+49 431 128 371 33