Practical, short-form briefings written for the people who have to make decisions during an incident: owners, IT managers, consultants and engineers.
What to do, what not to do, and what to preserve. A checklist that protects both the evidence and your recovery options.
Repeat attacks, broken decryptors, leaked data anyway, and legal exposure. What the evidence says about paying.
Veeam VBK chains, Hyper-V VHDX files and SQL dumps are attacked first. Why they are often repairable and what to send us.
Why hypervisors are targeted first, how the encryptors work, and how virtual disks are reconstructed in the laboratory.
Data theft before encryption changed the economics of ransomware. What it means for backups, disclosure and recovery priorities.
Attack volumes, sectors under pressure, the role of AI, and what regulators expect from organisations after an incident.
Service scope, environments, pricing model and incident response.
Eighteen families with extensions, targets and the laboratory recovery view.
The eight stages from stolen password to ransom note.