Overview of Progent's Ransomware Forensics and Reporting Services in Birmingham
Progent's ransomware forensics experts can save the evidence of a ransomware attack and carry out a comprehensive forensics investigation without disrupting activity related to business continuity and data recovery. Your Birmingham organization can utilize Progent's post-attack ransomware forensics documentation to counter subsequent ransomware attacks, assist in the cleanup of encrypted data, and meet insurance carrier and governmental mandates.
Ransomware forensics is aimed at determining and documenting the ransomware assault's storyline across the targeted network from start to finish. This history of how a ransomware attack travelled through the network assists your IT staff to assess the impact and highlights shortcomings in security policies or processes that should be corrected to avoid future breaches. Forensics is typically assigned a high priority by the insurance carrier and is typically mandated by government and industry regulations. Because forensics can take time, it is essential that other important recovery processes such as operational resumption are pursued in parallel. Progent maintains a large team of IT and data security experts with the knowledge and experience needed to carry out activities for containment, operational continuity, and data restoration without disrupting forensics.
Ransomware forensics analysis is arduous and requires intimate cooperation with the groups focused on data restoration and, if needed, settlement talks with the ransomware adversary. forensics typically require the examination of all logs, registry, GPO, Active Directory (AD), DNS, routers, firewalls, scheduled tasks, and core Windows systems to detect variations.
Activities associated with forensics investigation include:
- Disconnect without shutting off all possibly affected devices from the network. This can require closing all RDP ports and Internet connected NAS storage, changing admin credentials and user PWs, and setting up 2FA to secure backups.
- Capture forensically sound duplicates of all suspect devices so your data recovery group can proceed
- Save firewall, virtual private network, and other critical logs as soon as feasible
- Determine the kind of ransomware involved in the attack
- Survey each computer and data store on the network as well as cloud-hosted storage for signs of encryption
- Catalog all compromised devices
- Establish the kind of ransomware used in the assault
- Study log activity and sessions in order to establish the timeline of the attack and to spot any potential sideways migration from the first infected system
- Identify the attack vectors used to perpetrate the ransomware assault
- Search for new executables surrounding the first encrypted files or system compromise
- Parse Outlook PST files
- Analyze attachments
- Separate any URLs embedded in messages and determine whether they are malicious
- Produce comprehensive attack documentation to meet your insurance carrier and compliance requirements
- List recommendations to close cybersecurity gaps and improve processes that reduce the exposure to a future ransomware breach
Progent's Background
Progent has delivered online and onsite IT services throughout the U.S. for over two decades and has earned Microsoft's Partner certification in the Datacenter and Cloud Productivity practice areas. Progent's team of subject matter experts includes professionals who have earned high-level certifications in foundation technologies including Cisco networking, VMware, and major Linux distros. Progent's cybersecurity experts have earned prestigious certifications such as CISM, CISSP-ISSAP, and CRISC. (Refer to certifications earned by Progent consultants). Progent also offers top-tier support in financial management and ERP applications. This scope of skills allows Progent to identify and consolidate the undamaged parts of your IT environment following a ransomware assault and reconstruct them quickly into a functioning system. Progent has worked with leading cyber insurance carriers like Chubb to help businesses recover from ransomware attacks.
Contact Progent about Ransomware Forensics Expertise in Birmingham
To learn more about how Progent can assist your Birmingham business with ransomware forensics analysis, call 1-800-462-8800 or visit Contact Progent.