Your files are locked, a ransom note is sitting on the screen, and everyone in the building wants the same thing. Get back to work. So the affected machines get wiped and rebuilt, and with a backup that actually restores, you’re usually running again in days rather than weeks.

Here’s the part that’s easy to miss. Five U.S. agencies and South Korea’s national police published a joint ransomware advisory on August 10, 2026, and it tells victims to preserve the encrypted files before anything gets erased. Doing that adds hours, not days. What it costs comes down to storage space and how much of your environment has to be rebuilt by hand.

The First Hours Are for Containment, Not Cleanup

Pull the affected machines off the network and leave them alone. Don’t power them down if you can avoid it, and don’t start deleting things. That’s the whole job in hour one.

Whether you end up negotiating is a separate question, and the decision about whether to pay deserves its own careful look once you know what you’ve lost. Right now the only goal is making sure nobody destroys something while trying to feel useful. Panic cleanup is how businesses give up options they never knew they had.

Before Anyone Reformats a Machine

The advisory is specific about what to keep. When a compromise is found, it tells responders to preserve encrypted files, file timestamps, ransom notes, and relevant system logs.

Three of those four are obvious enough. The fourth is the one people destroy by accident.

File timestamps don’t survive a casual copy. Drag a folder onto a USB drive and the destination often stamps everything with today’s date. The original created and modified times are gone, and they go quietly. What preserves them is a full disk image made with a tool built for the job, or a copy made with a utility that carries timestamps across on purpose. Ask your provider for an image, not a copy.

Ransom notes matter too. They identify which family hit you, which is what determines whether a decryption tool exists. Logs are the other half of the picture, and where those records live decides how much of the story you can still reconstruct a week later.

Then label what you kept. Write down the date, the machine the image came from, and which ransom note was on it. A year from now, when a tool gets published for a family nobody in your office remembers by name, that label is the difference between a usable archive and an anonymous drive in a closet.

A Locked File Is Not a Worthless File

Encryption looks permanent on the day it happens. It isn’t always.

The advisory documents a real example. Researchers found that one ransomware family’s Linux builds generated their encryption keys with a weak random number generator seeded by the system clock. Because of that flaw, defenders may be able to rebuild the keys mathematically from file timestamps and recover the data without paying. That finding was published in March 2026, months after victims were first hit. Anyone who had already reformatted got nothing from it.

This isn’t a lottery ticket to plan around. The flaw applies to one family’s Linux builds, and most office desktops run Windows. But small offices run more Linux than they realize. The network storage box in the closet, the backup appliance, the virtualization host sitting under the line-of-business server. Free decryption tools also keep arriving late: law enforcement agencies maintain a public repository built to help victims of ransomware retrieve their encrypted data without having to pay the criminals, and new tools get added as families are cracked.

So the question isn’t whether your odds are good. It’s what being wrong costs you. Keeping an encrypted image costs disk space. Deleting it closes every future option, permanently.

What You Handle and What Your IT Team Handles

Most of this isn’t the owner’s job. Two parts are, though, and they’re the two that get skipped.

You handle this.Your IT team handles this.
Say out loud that nothing gets wiped until the images exist.Take full disk images of every affected machine.
Decide which systems have to come back online first.Rebuild from clean media and restore verified backups.
Collect the ransom notes and screenshots before anyone tidies up.Pull and preserve logs from servers, firewalls, and cloud accounts.
Call your insurance carrier and your attorney early.Check the ransom note against published decryption tools.
Approve the storage the preserved images will sit on.Confirm each image is readable before the originals are erased.

A team that already keeps your network documentation and system inventory has a real advantage in that right-hand column, because they know what lived on each machine before it was wiped. Without it, you’re rebuilding from memory and guesswork. For the businesses we support in Port St. Lucie, Florida and across the Treasure Coast, that inventory is part of the managed service, not something assembled in the middle of an emergency.

How Much Time This Adds and What Drives the Cost

Imaging runs alongside the rebuild. It doesn’t hold up recovery the way people fear it will.

A disk image takes about as long as reading the whole drive, so plan on hours per machine and longer for a large file server. Those images then need somewhere to sit. External drives are fine. So is a segregated share, as long as it isn’t the same place your live backups live.

There’s a reason the backup question decides everything downstream. The same advisory describes crews deleting volume shadow copies before they encrypt anything, and in one case erasing backup and archived data at both the primary data center and the disaster recovery site. So the copy that saves you is the copy they couldn’t reach from inside your network.

The real cost driver isn’t the imaging. It’s whether your backups were tested before the attack. A restore that works turns this into a bad week. A restore that fails turns it into a rebuild from scratch, and that’s where the hours and the invoices pile up. Keeping a backup copy that lives outside the network, layered across local, cloud, and offsite storage, is what separates those two weeks.

If you don’t know which of the two you’d land in, that’s worth finding out before an incident answers it for you. O&O Systems runs a free domain security risk assessment that shows where your exposure sits across email, cloud, web, and infrastructure.

Frequently Asked Questions

How long should we keep the encrypted files?

Keep them at least until a full restore is confirmed and your insurance and legal matters are closed out. After that, a year on inexpensive storage is a reasonable default. Decryption tools have been published that long after the attacks they unlock, and the storage costs far less than the data would.

Does keeping the encrypted data leave us more exposed?

Not if it stays offline. Encrypted files are inert; they can’t run on their own. The risk comes from leaving the image on a drive that’s mounted and reachable every day. Store it on media you disconnect, label it clearly, and keep it out of the same location as your working backups.

Can we keep one folder instead of imaging the whole disk?

You can, and it’s better than nothing. You’ll probably lose the timestamps and the logs, though, which are the two things that make later recovery and later investigation possible. If the machine can be spared for a few hours, image it.

Our attack hit Windows machines. Does any of this apply?

Yes, with one honest caveat. The key-reconstruction finding described above is specific to one family’s Linux builds. The instruction to preserve encrypted files, timestamps, notes, and logs isn’t tied to any single family, and free decryption tools have been released for Windows ransomware too.

What if our IT provider says the images aren’t necessary?

Ask what happens if a decryption tool appears in six months. If the answer is that the data will already be gone, the images are cheap insurance against that answer. It’s a reasonable call to skip them when every affected file restored cleanly from backup and nothing is missing, but that should be a decision someone made on purpose.

Would You Know What to Preserve Tomorrow?

Probably not yet, and that’s normal. These decisions take minutes when someone has already settled who images the drives and where the images go. They take hours of argument when nobody has. Writing that down is the entire exercise, and it costs you nothing today.

Start with what you’re exposed to right now. O&O Systems will run a free domain security risk assessment and hand back a plain-language snapshot of where the gaps are across email, cloud, web, and infrastructure.