Our Team | Akira Ransomware Recovery

The Architects of Enterprise Resilience

We are a highly specialized, globally distributed tactical unit dedicated exclusively to defeating complex ransomware operations. When critical infrastructure falls to advanced threat actors, our operators execute precise, data-preserving recovery missions.

Ransomware response is not a standard IT support function. An attack by sophisticated threat actors like the Akira syndicate requires an immediate, clinical, and multi-disciplinary intervention. Standard sysadmin practices often inadvertently destroy forensic evidence or trigger secondary destructive payloads. We built our roster differently.

Our team is strictly composed of elite practitioners who specialize in the exact disciplines required to dismantle a cyber attack: malware reverse engineering, digital forensics, Active Directory hardening, cloud security architecture, and enterprise data recovery. By isolating these highly specialized roles, we ensure that every phase of the incident response—from the initial binary decompilation to the final secure network rebuild—is handled by an absolute master of that specific domain.

Meet the leaders engineering your recovery.

Core Technical Leadership

Sergey Ignatov

Principal Security Architect & Cloud Infrastructure Specialist

Sergey is the architectural mastermind behind our secure recovery environments. Possessing some of the most rigorous leadership certifications in the cybersecurity industry (CISSP and CISM), Sergey’s role is critical during the initial containment phase. You cannot restore encrypted data into a compromised network. Sergey designs the zero-trust, sterile cloud enclaves where safe decryption and data validation occur.

With deep expertise in Microsoft Azure and AWS security topologies, he ensures that the newly rebuilt enterprise infrastructure is hermetically sealed against re-infection. Furthermore, as a certified Claude Architect, Sergey integrates cutting-edge, multi-agent AI workflows to rapidly ingest and analyze millions of firewall and endpoint logs during active incidents, drastically reducing the time required to identify the threat actor’s initial access vector.

Operational Focus:

  • Designing and provisioning sterile cloud recovery environments (AWS/Azure).
  • Integrating AI-driven log analysis for rapid threat hunting.
  • Establishing zero-trust perimeters for post-incident enterprise operations.
CISSP CISM Claude Certified Architect AWS Security Specialty (SCS-C01) MS-500 & AZ-500 Security Admin

Armen Tiraturyan

Director of Enterprise Data Recovery & Incident Management

Armen serves as the primary Incident Commander during active recovery operations. With an extensive background in enterprise-grade data recovery systems, Armen’s expertise bridges the gap between raw decryption and actual business continuity. A successful decryption is useless if the underlying database structure is corrupted in the process. Armen ensures that does not happen.

He orchestrates the intricate process of bare-metal recovery, backup integrity validation, and secure data migration. While the reverse engineers focus on breaking the encryption algorithm, Armen works directly with client stakeholders to prioritize the restoration of business-critical assets, ensuring that downtime is minimized. His mastery of cloud management and information systems ensures that recovered data is reintegrated smoothly and securely into the client’s production environment.

Operational Focus:

  • Directing the Incident Command pipeline from triage to full restoration.
  • Validating and repairing corrupted backup repositories.
  • Orchestrating complex, multi-terabyte data reintegration projects.
Enterprise Data Recovery Incident Management Cloud Architecture

dr. Vladimir Avdejenkov

Chief of Security Governance & Threat Detection Systems

Ransomware is as much a legal and compliance crisis as it is a technical one. Dr. Avdejenkov leads our forensic evidence preservation and regulatory governance efforts. Holding a Ph.D. and bringing a profound understanding of advanced event logging architecture, he ensures that the incident is tracked, logged, and analyzed with absolute cryptographic precision.

Threat actors often attempt to cover their tracks by wiping Windows Event Logs and clearing SIEM data. Dr. Avdejenkov specializes in extracting fragmented log data, piecing together the timeline of the attack, and determining the exact scope of data exfiltration. His work provides the irrefutable forensic evidence required by cyber insurance providers, legal counsel, and regulatory bodies (such as GDPR compliance authorities) in the aftermath of a massive data breach.

Operational Focus:

  • Advanced forensic event logging and SIEM reconstruction.
  • Determining precise timelines of data exfiltration and lateral movement.
  • Ensuring post-incident regulatory compliance and audit readiness.
Ph.D. Security Auditing Threat Detection Architecture

Forensics, Analysis & Blue Team Operations

Artem Dolgikh

Lead Security Engineer & Blue Team Operations Specialist

Artem is our frontline defender, tasked with evicting the threat actor and sealing the breach. His profound expertise lies in Active Directory (AD) hardening, specifically through advanced Group Policy Management (GPMC) and ADMX infrastructure control. Many organizations fall victim to ransomware because their internal security policies have “blind spots” due to outdated Central Stores. Artem identifies and eliminates these vulnerabilities.

A highly decorated Blue Team operator with verified lab credentials in ransomware investigations, phishing forensics, and malicious browser extension analysis, Artem conducts active threat hunting within the compromised network. He strips attackers of their persistent backdoors, terminates rogue RMM (Remote Monitoring and Management) sessions, and enforces devastatingly strict Windows hardening protocols to ensure the network is a fortress before any decrypted data is returned to it.

Operational Focus:

  • Active Directory (AD) restructuring and ADMX policy enforcement.
  • Hunting and eradicating persistent attacker footholds (RMM tools, backdoors).
  • Endpoint and server hardening to CIS Benchmark standards.
Active Directory Hardening Blue Team Operations SOC Engineering

Alex Perotti

Senior Malware Reverse Engineer & Threat Intelligence Analyst

Alex operates at the absolute bleeding edge of digital forensics. When an Akira payload (or any advanced ransomware variant) drops, Alex is the operator who takes the binary apart. As our Senior Malware Reverse Engineer, he decompiles the malicious executables, analyzing the exact cryptographic implementation used by the threat actor.

Ransomware developers are human, and they make mistakes. Alex hunts for flaws in the malware’s encryption routines, occasionally uncovering logic errors that allow for partial or full data recovery without the need for a threat actor’s key. Furthermore, if a decryptor is acquired, Alex tests it in an isolated sandbox, reverse-engineering the tool to ensure it does not contain secondary backdoors or data-wiping triggers before we ever run it on client data. He also maps the specific TTPs (Tactics, Techniques, and Procedures) to our Cyber Threat Intelligence (CTI) databases to attribute the attack to specific affiliate groups.

Operational Focus:

  • Decompilation and dynamic analysis of ransomware binaries.
  • Validating and securing threat actor decryption utilities.
  • Mapping TTPs for deep cyber threat intelligence attribution.
Malware Reverse Engineering Cyber Threat Intelligence (CTI) Binary Analysis

Vladimir Martynov

Cybersecurity Advisory & Security Operations Professional

Vladimir bridges the technical execution of the recovery with long-term strategic resilience. As a specialist in Security Systems Controls and SSCP Architecture, his role is to evaluate the systemic failures that allowed the initial intrusion to occur and to engineer a roadmap to ensure it never happens again.

During the recovery phase, Vladimir works alongside the internal IT teams of our clients to implement rigorous information security administration protocols. He defines the risk mitigation strategy, advising on the deployment of robust identity and access management (IAM) solutions, strict network segmentation, and the operationalizing of internal Security Operations Centers (SOC). He doesn’t just help you recover; he helps you transform your security posture.

Operational Focus:

  • Systemic vulnerability assessments and root cause mitigation.
  • Designing and implementing robust security operations controls (SSCP).
  • Long-term strategic security advisory for post-breach environments.
SSCP Architecture Risk Mitigation Information Security Admin

Our Collaborative Engagement Model

Our team’s true strength lies in our synchronized operational cadence. A ransomware event is chaotic; our response is systemic. While Alex Perotti is actively dissecting the ransomware payload in a sandboxed environment to map the encryption parameters, Artem Dolgikh is simultaneously securing the Active Directory infrastructure to cut off the attacker’s oxygen.

Concurrently, Sergey Ignatov stands up a hardened, zero-trust cloud environment where Armen Tiraturyan begins the painstaking process of staging and validating surviving backups. Above all this, dr. Vladimir Avdejenkov ensures that every action taken preserves the chain of custody for legal and insurance purposes, while Vladimir Martynov interfaces with executive leadership to communicate risk mitigation strategies.

This parallel processing allows us to drastically reduce the traditional timeline of ransomware recovery. By eliminating silos and deploying dedicated specialists to every front of the digital battlefield, we turn catastrophic breaches into manageable, measurable recovery operations.