Skip to content
PCLaw emergency?Call
PCLaw emergency

Talk to a specialist now

Call +1 (647) 696-9066

Fastest route. We respond in under 15 minutes.

Your information is kept strictly confidential.

Data Recovery

PCLaw Ransomware Recovery: What to Do in the First 24 Hours

Ransomware has encrypted the server that holds PCLaw. The steps taken in the first hours decide how much can be recovered. This is the order to do them in.

By Saimoon Bhuiyan

If you are reading this during an attack: disconnect the affected server from the network now, leave it switched on, and call your IT provider and your cyber insurer. Then read on.

Ransomware is the most damaging thing that can happen to a firm's PCLaw data, and it is also one where the right first steps make a very large difference to the outcome.

The first hour

  1. Disconnect, do not shut down. Unplug the network cable and turn off Wi-Fi on every affected machine. Leave them powered on. Shutting down can destroy information held in memory that helps with recovery and investigation.
  2. Disconnect your backups. Unplug external backup drives and disable cloud sync immediately. Attackers go after backups first, and sync tools will happily replace good files with encrypted ones.
  3. Do not delete anything. Not the encrypted files, not the ransom note, not the strange new files. All of it is evidence, and some of it may be needed to recover.
  4. Do not reinstall Windows or PCLaw, and do not run clean-up tools.
  5. Photograph the ransom note and note the extension added to the encrypted files. They identify which ransomware it is.
  6. Call your cyber insurer before engaging anyone else. Many policies require you to use their response team, and a wrong first step can affect cover.

The first day

  • Find out what is affected. Is it only the server, or workstations too? Is the PCLaw data folder or SQL database encrypted, or only other files?
  • List every backup that exists, including old ones: external drives in a drawer, the previous server, a year-end copy sent to your accountant, a laptop that had PCLaw data copied to it, your IT provider's own copies.
  • Check each backup from a clean computer that has never been on the affected network. Do not plug a backup drive into an infected machine to see if it works.
  • Record the date of each backup. The gap between the newest clean backup and today is what must be recovered or re-entered.
  • Change passwords for email, remote access and administrator accounts, from a clean device.

Recovery routes that do not involve paying

A clean backup. This is the outcome a good backup routine exists for. The backup is restored to a rebuilt, clean server, never back onto the infected one.

Shadow copies and snapshots. Windows, virtual machine platforms and storage devices often keep earlier versions of files. Attackers try to delete them and do not always succeed.

Partially encrypted database files. To work fast, many ransomware strains encrypt only part of a large file. Database files are large, and a substantial share of the records inside can often be extracted from what was left untouched. This is specialist work and it is where we are most often able to help when no backup survives.

Data held elsewhere. Old backups, exported reports, printed month-end reports and your accountant's files can be used to rebuild what cannot be recovered directly.

A published decryptor. For some older ransomware families, free decryption tools exist. It is worth checking, but do not count on it.

Should the firm pay?

That decision belongs to the firm, its insurer and its legal advisers, and we do not make it for anyone. Know these facts before deciding:

  • Payment does not guarantee a working decryption key, and decrypted databases are frequently damaged.
  • Paying may be restricted by sanctions law, depending on who the attackers are.
  • Your insurer and law enforcement should be involved before any contact with the attackers.

Your professional obligations

A law firm holds confidential client information, so an attack is more than an IT problem. Depending on where you practise, you may have duties to notify your law society or state bar, a privacy regulator, your clients, and your insurer, sometimes within a short time. Take advice on this on the first day.

Getting PCLaw running again

  1. Recover the data by the best route available, working on copies.
  2. Build a clean server. Never reuse the infected system without wiping it.
  3. Install the same PCLaw version the data came from.
  4. Restore the recovered data and run Verify Data Integrity.
  5. Check the figures: trust bank balance, client trust listing, receivables and general bank balance, against the last reports you trust.
  6. Re-enter the work done between the recovered data and the attack, from paper, email and bank records.
  7. Reconcile every bank and trust account before normal work resumes.

Making sure it cannot happen twice

  • At least one backup copy kept offline or immutable, where the server cannot reach it. See our PCLaw backup guide.
  • Restores tested every quarter.
  • Multi-factor authentication on email and all remote access.
  • Remote desktop never exposed directly to the internet.
  • Windows, PCLaw and security software kept up to date.
  • Staff trained to recognise phishing, which is how most attacks begin.

How we help

We work alongside your IT provider and your insurer's response team on the part they do not specialise in: getting the PCLaw data back and proving it is correct. Our PCLaw data recovery service is available 24 hours a day, every day. We work only on copies, and there is no charge if nothing can be recovered. Contact us now and a specialist will respond within 15 minutes.

Available 24/7

PCLaw Emergency? We're On It.

Don't let a PCLaw failure cost another hour of billable time. Our emergency response team is standing by.