UK cyber incident response
Ransomware? Don’t pay, don’t wipe - call first.
- stop it spreading to what’s still clean
- what your realistic recovery options are (backups, decryptors, negotiation support)
- evidence preserved for insurers and, if needed, the ICO
Call now. I'll take it live during UK business hours - out of hours you'll get a callback within 2 hours. Triage starts the moment we speak, and hands-on remote response within the hour.
What happens when you call
- 1
Triage (first call, free). In plain English: what’s happening, what’s at risk, what to do in the next 30 minutes - including the things NOT to do (don’t wipe machines, don’t pay anything, don’t tip off the attacker).
- 2
Contain. Remote access agreed, the bleeding stopped: attacker locked out, spread halted, evidence preserved.
- 3
Recover & report. Systems restored, entry point closed, and the paperwork handled - board summary, insurer evidence, and ICO notification support if personal data is involved.
CISSP · OSCE · OSCP · CISM · Chartered Engineer · 20+ years
Security assessment and incident work for organisations from startups to Camelot (the UK National Lottery operator).
“Adam provided a first class security penetration engagement for Extreme Networks Professional Services and provided our customer with the relevant information and recommendations to secure their network.”
I handle incidents for SMEs and startups - ransomware, hijacked email accounts and invoice fraud, hacked websites, and data breaches with the GDPR clock running. One senior responder, remote-first, UK-based. If your incident needs a large forensics team or law-enforcement liaison beyond my scope, I'll tell you on the first call and point you to the right people - that call is still free.
Can't talk right now?
In a meeting, phones down, mid-crisis - send this and I'll call you back.
