Ransomware Remediation & Recovery.

You're not alone — and the next hours matter. Containment, recovery, and compliance support from a skilled partner.

Call +27 87 55 00 555 Quick Support

The First Hour.

What to do — and what not to do — when you discover ransomware.

Every action in the first hour affects whether you can recover, claim insurance, and satisfy POPIA. A skilled partner helps you make the best of a bad situation — starting with preserving evidence, not destroying it.

Do

  • Isolate affected systems from the network immediately
  • Leave systems powered on where safe — memory may hold critical evidence
  • Preserve firewall, email, and cloud audit logs
  • Document when the incident was discovered and by whom
  • Call AOLC on +27 87 55 00 555
  • Follow our POPIA Breach Playbook

Don't

  • Reboot or shut down servers unless instructed
  • Wipe, reformat, or reinstall affected systems
  • Pay the ransom before assessing backups and insurance
  • Delete ransom notes or suspicious files
  • Attempt DIY recovery that overwrites evidence
  • Delay notification if personal information was accessed

Remediation Phases.

Six phases from containment to hardening — so you recover once, properly.

1. Contain

Isolate infected endpoints and servers. Stop active encryption, block lateral movement, and protect clean systems from spread.

2. Preserve

Forensic imaging before remediation. See Digital Forensics for evidence collection that supports insurance and POPIA reporting.

3. Eradicate

Remove malware, close entry points, reset compromised credentials, and patch vulnerabilities the attacker exploited.

4. Recover

Restore from verified clean backups. Validate data integrity before reconnecting to production. Rebuild compromised systems from scratch where needed.

5. Report

POPIA breach notification support, insurer documentation, and board-ready incident summary.

6. Harden

Post-incident review, IR plan update, and preventive controls — Managed Security and Cyber Awareness Training.

What We Restore.

🖥

Servers & VMs

Windows and Linux file servers, domain controllers, and hypervisor-hosted workloads.

Microsoft 365

Exchange, OneDrive, SharePoint, and Teams data from backup or tenant recovery tools.

📁

File Shares

On-premise and cloud-hosted shared drives — the data most ransomware targets first.

💻

Line-of-Business Apps

Accounting, ERP, CRM, and industry-specific applications restored to a clean baseline.

How We Engage.

Two paths — emergency response when you're under attack, or a retainer so you're ready before it happens.

Active Incident

P1 — respond now

Project engagement when ransomware is already affecting your business. AOLC logs confirmed incidents as P1 with immediate escalation to our security lead and 24/7 after-hours response through our Managed Security runbook.

Call Now

IR Retainer

Pre-signed — faster SLA

Reserved forensic and remediation hours with a guaranteed response SLA. Basic (10 hrs/year, 1 business day) or Standard (20 hrs/year, 4 business hours). Unused hours convert to proactive security work.

View Retainer Options

Make the Best of a Bad Situation.

Ransomware is one of the most stressful events a business can face. Many of our clients tell us they felt alone and judged when it happened. AOLC's role is the opposite — experienced, calm, and focused on recovery.

We have supported South African law firms, schools, manufacturers, and professional services firms through active incidents. We coordinate with your insurer, legal counsel, and existing IT team. No blame — just a clear path back to operations, with the documentation POPIA and your board require.

Get Help Now
Ransomware remediation and recovery support

Frequently Asked Questions.

Direct answers to the questions that come up most often. Encoded as FAQPage structured data so AI search engines can quote them accurately.

What should I do in the first hour after discovering ransomware?

Isolate affected systems from the network immediately — unplug Ethernet or disable Wi-Fi. Do not reboot or shut down unless instructed. Do not pay the ransom yet. Preserve firewall and cloud logs. Call AOLC on +27 87 55 00 555 and follow our POPIA Breach Playbook at aolc.tech/resources/popia-breach-playbook.html.

Should we pay the ransom?

AOLC does not recommend paying as a first response. Over 60% of South African businesses that pay still do not recover all their data. We first attempt recovery from clean backups, assess whether decryption is viable, and coordinate with your insurer and legal counsel before any payment decision.

Can AOLC recover our data without paying?

Often yes — if you have offline or immutable backups that were not encrypted. AOLC validates backup integrity, restores to clean infrastructure, and verifies data before reconnecting to production. Where backups are unavailable, we assess decryption options and coordinate with insurers.

How quickly can AOLC respond to an active ransomware incident?

Confirmed ransomware is logged as P1 with immediate escalation to AOLC's security lead and 24/7 after-hours response. Clients with an Incident Response Retainer receive a faster guaranteed SLA — 4 business hours for Standard, 1 business day for Basic.

Will you help with POPIA breach notification?

Yes. AOLC documents scope of impact, supports your notification to the Information Regulator under POPIA section 22, and helps prepare communications to affected data subjects. See our POPIA Breach Playbook for the full process.

What is the difference between emergency response and an IR retainer?

Emergency response is a project engagement scoped when an incident is already happening — we respond as fast as possible but contracts and scope are agreed under pressure. An IR Retainer is pre-signed with reserved hours and a guaranteed SLA, so response starts within hours instead of days.

Can you work with our existing IT provider or insurer?

Yes. AOLC regularly coordinates with internal IT teams, external MSPs, legal counsel, and cyber insurers. We can take the lead on containment and forensics while keeping your existing provider informed, or work entirely alongside them.

Ransomware Help Enquiry.

Active incident or planning ahead — tell us your situation and we'll respond urgently.