Progent's Ransomware Forensics Investigation and Reporting Services in Allentown
Progent's ransomware forensics experts can capture the system state after a ransomware attack and perform a detailed forensics investigation without interfering with activity related to business resumption and data recovery. Your Allentown business can utilize Progent's ransomware forensics report to counter subsequent ransomware assaults, assist in the recovery of lost data, and comply with insurance carrier and regulatory mandates.
Ransomware forensics analysis involves determining and documenting the ransomware attack's progress throughout the targeted network from start to finish. This audit trail of how a ransomware attack progressed within the network helps you to assess the impact and highlights weaknesses in rules or work habits that should be corrected to avoid future breaches. Forensics is usually given a high priority by the cyber insurance carrier and is often required by government and industry regulations. Since forensic analysis can be time consuming, it is essential that other key activities such as business continuity are pursued in parallel. Progent has an extensive team of IT and security professionals with the knowledge and experience needed to perform the work of containment, business continuity, and data recovery without interfering with forensics.
Ransomware forensics is complex and requires close cooperation with the groups assigned to data recovery and, if necessary, payment negotiation with the ransomware attacker. Ransomware forensics can involve the examination of all logs, registry, GPO, Active Directory (AD), DNS, routers, firewalls, scheduled tasks, and basic Windows systems to detect anomalies.
Services involved with forensics investigation include:
- Disconnect but avoid shutting off all potentially suspect devices from the network. This may require closing all RDP ports and Internet connected network-attached storage, modifying admin credentials and user passwords, and configuring two-factor authentication to secure backups.
- Capture forensically sound digital images of all exposed devices so the data recovery group can proceed
- Save firewall, VPN, and additional key logs as soon as possible
- Determine the kind of ransomware used in the assault
- Survey every machine and storage device on the system including cloud-hosted storage for indications of compromise
- Catalog all compromised devices
- Determine the kind of ransomware used in the attack
- Study log activity and user sessions to determine the time frame of the ransomware attack and to identify any potential lateral movement from the originally infected machine
- Understand the security gaps used to carry out the ransomware attack
- Search for the creation of executables surrounding the original encrypted files or system compromise
- Parse Outlook PST files
- Analyze attachments
- Separate any URLs embedded in messages and determine whether they are malicious
- Provide detailed attack documentation to meet your insurance carrier and compliance mandates
- Document recommendations to close security gaps and improve processes that reduce the risk of a future ransomware breach
Progent's Qualifications
Progent has delivered online and on-premises network services throughout the United States for over two decades and has earned Microsoft's Partner designation in the Datacenter and Cloud Productivity competencies. Progent's team of SMEs includes consultants who have earned high-level certifications in foundation technology platforms such as Cisco networking, VMware virtualization, and popular Linux distros. Progent's data security consultants have earned internationally recognized certifications such as CISA, CISSP, and CRISC. (See certifications earned by Progent consultants). Progent also offers top-tier support in financial and ERP applications. This scope of expertise gives Progent the ability to salvage and consolidate the undamaged parts of your IT environment after a ransomware assault and reconstruct them quickly into a functioning network. Progent has worked with leading cyber insurance carriers including Chubb to help businesses recover from ransomware assaults.
Contact Progent about Ransomware Forensics Analysis Expertise in Allentown
To find out more information about ways Progent can help your Allentown business with ransomware forensics, call 1-800-462-8800 or see Contact Progent.