Skip to main content
Home/Services/Ransomware Response
Security Testing

Ransomware Response

Contain the blast radius, recover the business, avoid paying

HIPAA PCI-DSS SOC 2 NIST CSF GDPR
engagement log Ransomware Response testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingRDP or VPN initial accesscritical
day 03findingCredential abuse for lateral movementhigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
2-6 weeks per incidenttypical duration $35,000 emergency engagementfixed scope, from 7deliverables 7methodology stages
Scope

What this engagement covers

The service

Dedicated ransomware response - containment, forensics, decryption support, negotiation guidance, and recovery. We have seen every variant; we know what works and what makes it worse.

What we test

Full ransomware engagement lifecycle: intrusion vector identification, lateral movement reconstruction, payload analysis, data exfil scoping, decryptor validation, and recovery verification.

Method

How we run it

Parallel workstreams - one team contains, another investigates, a third supports recovery. We coordinate with your insurer, counsel, and executive team. We do not handle payment; we partner with specialist negotiators when one is needed.

01

Emergency containment

02

Forensic triage and evidence preservation

03

Intrusion timeline reconstruction

04

Data exfil assessment

05

Eradication and hardening

06

Recovery validation

07

Post-incident reporting

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Rapid containment of active encryption
  • Intrusion vector and scope determination
  • Data exfiltration assessment
  • Coordinated recovery plan
  • Decryptor validation (when available)
  • Full post-incident report
  • Hardening recommendations to prevent recurrence
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

RDP or VPN initial access Credential abuse for lateral movement Cobalt Strike / similar C2 Shadow copy destruction Data staging in cloud storage Persistence in domain controllers
Fit

Who this is for

Active ransomware incidents
Post-incident forensic engagements
Insurance-mandated response
Pre-incident tabletop participants
Standards this supports

Findings are mapped to HIPAA, PCI-DSS, SOC 2, NIST CSF, GDPR, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!