Ransomware Post-mortem Service

Ransomware post-mortem

It already happened. Now you need to know how, and make sure it does not repeat

Restoring the systems does not close the incident. If you do not establish the entry vector, how long they were inside and what they took before encrypting, the organisation goes back into production with the door still open and no idea whether it has a data breach to notify. Reinfection within weeks is a common pattern.

Your obligations are on a clock

  • NIS2: early warning within 24 hours, notification within 72 hours and a final report within one month.
  • DORA: initial notification within 4 hours and never later than 24 from detection.
  • GDPR: 72 hours to notify the supervisory authority if personal data was accessed.

Answering those questions requires forensic analysis, not an educated guess.

What we do

Evidence preservation. First, before it is lost: forensic images, memory dumps and logs, with chain of custody from minute one.

Incident reconstruction. Entry vector, lateral movement, privilege escalation, persistence and a full timeline from first access.

Exfiltration assessment. Which data left and which did not. That is the difference between notifying a breach and being able to evidence that there was none.

Adversary identification. Ransomware family, TTPs and attribution where the evidence supports it.

Hardening plan. The specific measures that stop the same path from working again.

What you get

  • Executive report for the board and your insurer.
  • Technical report with timeline, evidence and indicators of compromise.
  • Reasoned opinion on data exfiltration.
  • Expert report with chain of custody, admissible in court if there is litigation or an insurance claim.
  • Prioritised remediation plan.

Frequently asked questions

Do you recover the encrypted files? Honestly: with most modern ransomware families, no. It is only possible where there is a known flaw in the cryptographic implementation or recoverable keys. Our job is to establish what happened and close the way in, not to promise a decryption that is almost never possible.

Should we pay the ransom? We do not advise on payment. We do give you the technical information you need to decide, and it may carry legal implications you should discuss with your lawyer.

We have already restored the systems. Is it still worth it? Less than before, but yes. Evidence usually remains in logs, backups and systems that were not restored.

Incident in progress?

Call +34 686 250 244 directly. In an active incident, every hour that passes destroys evidence.

Let us talk about your case

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)
Email: info@jaymonsecurity.com

Spain