Ransomware : Your Crippling Information Technology Catastrophe
Ransomware  Remediation ExpertsCrypto-Ransomware has become an escalating cyber pandemic that represents an enterprise-level threat for businesses of all sizes unprepared for an assault. Multiple generations of ransomware such as CrySIS, CryptoWall, Bad Rabbit, SamSam and MongoLock cryptoworms have been replicating for many years and still cause destruction. Newer versions of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, as well as daily unnamed newcomers, not only perform encryption of online data files but also infiltrate all accessible system backup. Data synchronized to cloud environments can also be rendered useless. In a poorly designed system, it can render any restoration useless and effectively sets the network back to zero.

Getting back online programs and data following a ransomware outage becomes a sprint against the clock as the victim struggles to stop the spread, eradicate the crypto-ransomware, and restore enterprise-critical activity. Due to the fact that crypto-ransomware needs time to move laterally across a network, penetrations are frequently launched on weekends and holidays, when penetrations may take longer to discover. This compounds the difficulty of quickly assembling and coordinating a knowledgeable mitigation team.

Progent has a range of solutions for protecting Adelaide businesses from ransomware penetrations. These include team member education to help identify and not fall victim to phishing attempts, ProSight Active Security Monitoring for endpoint detection and response using SentinelOne's AI-based threat defense to identify and quarantine day-zero malware attacks. Progent also provides the services of veteran ransomware recovery professionals with the track record and perseverance to restore a breached network as quickly as possible.

Progent's Ransomware Restoration Help
Soon after a crypto-ransomware penetration, paying the ransom in cryptocurrency does not provide any assurance that cyber criminals will provide the keys to unencrypt all your data. Kaspersky estimated that 17% of ransomware victims never recovered their information after having paid the ransom, resulting in more losses. The risk is also very costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger organizations, the ransom demand can be in the millions. The other path is to re-install the essential components of your IT environment. Without the availability of full system backups, this calls for a wide complement of skills, top notch team management, and the capability to work non-stop until the task is done.

For two decades, Progent has offered certified expert Information Technology services for businesses throughout the US and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes engineers who have earned top industry certifications in important technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity experts have garnered internationally-recognized industry certifications including CISM, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has experience with financial systems and ERP application software. This breadth of experience gives Progent the skills to knowledgably determine necessary systems and integrate the remaining components of your network system after a ransomware attack and rebuild them into a functioning system.

Progent's security team uses best of breed project management applications to orchestrate the complex recovery process. Progent appreciates the urgency of working quickly and in unison with a customer's management and IT staff to prioritize tasks and to put critical services back online as soon as humanly possible.

Client Case Study: A Successful Ransomware Intrusion Restoration
A client sought out Progent after their organization was taken over by Ryuk ransomware virus. Ryuk is thought to have been deployed by North Korean state criminal gangs, suspected of using techniques leaked from America's NSA organization. Ryuk attacks specific organizations with little or no tolerance for operational disruption and is among the most lucrative incarnations of ransomware malware. Well Known victims include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a regional manufacturing company based in Chicago and has about 500 workers. The Ryuk intrusion had brought down all business operations and manufacturing processes. The majority of the client's system backups had been directly accessible at the time of the attack and were eventually encrypted. The client was evaluating paying the ransom (exceeding $200,000) and praying for the best, but ultimately reached out to Progent.


"I cannot thank you enough in regards to the support Progent provided us during the most fearful time of (our) company's life. We would have paid the cybercriminals except for the confidence the Progent experts afforded us. The fact that you could get our e-mail and production servers back on-line sooner than five days was amazing. Every single person I talked with or texted at Progent was totally committed on getting us working again and was working 24 by 7 on our behalf."

Progent worked together with the client to rapidly assess and assign priority to the key systems that needed to be restored to make it possible to restart departmental operations:

  • Windows Active Directory
  • Microsoft Exchange Server
  • MRP System
To get going, Progent adhered to ransomware incident response industry best practices by halting lateral movement and cleaning systems of viruses. Progent then started the steps of bringing back online Active Directory, the key technology of enterprise environments built on Microsoft technology. Microsoft Exchange Server email will not work without AD, and the customer's MRP software used Microsoft SQL Server, which needs Active Directory services for access to the information.

In less than 48 hours, Progent was able to restore Windows Active Directory to its pre-intrusion state. Progent then helped perform rebuilding and storage recovery of needed systems. All Exchange Server ties and attributes were usable, which greatly helped the restore of Exchange. Progent was also able to collect non-encrypted OST files (Microsoft Outlook Offline Folder Files) on staff desktop computers in order to recover email information. A not too old off-line backup of the customer's manufacturing systems made it possible to recover these essential services back online for users. Although major work still had to be done to recover totally from the Ryuk event, essential systems were recovered rapidly:


"For the most part, the production manufacturing operation did not miss a beat and we made all customer sales."

Throughout the next few weeks important milestones in the restoration project were accomplished in tight collaboration between Progent engineers and the customer:

  • In-house web sites were restored with no loss of data.
  • The MailStore Exchange Server containing more than 4 million archived messages was brought on-line and available for users.
  • CRM/Product Ordering/Invoicing/AP/Accounts Receivables (AR)/Inventory Control capabilities were completely operational.
  • A new Palo Alto 850 security appliance was installed and configured.
  • 90% of the user workstations were back into operation.

"So much of what transpired in the initial days is mostly a haze for me, but our team will not forget the care all of the team accomplished to help get our business back. I have been working with Progent for the past ten years, possibly more, and every time Progent has impressed me and delivered. This time was a Herculean accomplishment."

Conclusion
A possible business-killing disaster was avoided with results-oriented professionals, a wide range of subject matter expertise, and close teamwork. Although in analyzing the event afterwards the crypto-ransomware virus attack detailed here should have been identified and disabled with up-to-date security technology solutions and NIST Cybersecurity Framework best practices, staff training, and well thought out incident response procedures for information backup and proper patching controls, the reality remains that state-sponsored criminal cyber gangs from China, Russia, North Korea and elsewhere are tireless and are not going away. If you do get hit by a crypto-ransomware penetration, feel confident that Progent's roster of professionals has extensive experience in ransomware virus blocking, mitigation, and data restoration.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others that were involved), thank you for making it so I could get rested after we got over the most critical parts. All of you did an impressive effort, and if anyone is visiting the Chicago area, a great meal is my treat!"

Download the Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this customer case study, please click:
Progent's Ryuk Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting Services in Adelaide
For ransomware system restoration consulting in the Adelaide metro area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.