Emergency Incident Response (Available in Taiwan Only)
What to do in the first hour, how incident response works, whether decryption is realistic for your case, expected timelines and costs, and how to close the gaps that let it happen. Available in Taiwan only.

Why Arrosoft
One team handling containment and recovery at the same time
Which ransomware can be decrypted?
Whether a given ransomware can be decrypted varies by family, variant and version. LockBit — depends on version; usable decryption tools exist for some. Phobos — also version-dependent; the infecting variant must be confirmed first. Akira — common among SMEs and healthcare organizations; currently only some earlier versions have a realistic chance of decryption, with newer versions considerably harder. Qilin — difficult to decrypt; a highly active group, with no public decryption tool. Medusa — also difficult, with no public decryption tool. Because ransomware is continuously updated and evolving, whether decryption is actually possible still depends on the infecting version, the variant, and the condition of the encrypted files.

How long does decryption take, and how is cost calculated?
Decryption time varies with the ransomware family, the difficulty of decryption, the scope of infection, the volume of data, and the state of your backups. Cost is assessed against the scale of the incident, the difficulty of data recovery, and factors such as whether on-site support or incident investigation is required.

How should organizations strengthen protection after a ransomware incident?
Organizations should review their security gaps to reduce the risk of being attacked again. Complete ransomware protection can be approached in four stages: Prevent — patch vulnerabilities; enforce least privilege. Detect — continuous monitoring for anomalous behaviour and threats. Respond — rapidly isolate infected devices and control the damage. Recover — restore through backup, data recovery and integrity verification, returning the organization to normal operation.
