Ransomware : Your Worst Information Technology Disaster
Crypto-Ransomware has become an escalating cyberplague that poses an existential threat for businesses vulnerable to an assault. Multiple generations of ransomware such as Dharma, CryptoWall, Locky, NotPetya and MongoLock cryptoworms have been circulating for a long time and continue to inflict damage. Modern strains of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Nephilim, plus frequent unnamed newcomers, not only encrypt on-line information but also infiltrate many available system backups. Data synched to off-premises disaster recovery sites can also be ransomed. In a poorly architected system, it can make automated recovery hopeless and effectively sets the entire system back to square one.
Getting back programs and information following a ransomware attack becomes a sprint against time as the targeted organization fights to contain the damage, clear the virus, and resume mission-critical operations. Since ransomware takes time to move laterally throughout a network, penetrations are frequently sprung during nights and weekends, when attacks may take more time to identify. This compounds the difficulty of quickly assembling and orchestrating an experienced mitigation team.
Progent provides an assortment of services for securing Bristol businesses from crypto-ransomware penetrations. These include user training to help recognize and avoid phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based threat protection to discover and quarantine day-zero modern malware assaults. Progent in addition offers the assistance of expert ransomware recovery consultants with the skills and perseverance to rebuild a compromised environment as urgently as possible.
Progent's Ransomware Restoration Help
After a crypto-ransomware event, even paying the ransom in cryptocurrency does not guarantee that cyber hackers will respond with the keys to decipher any or all of your data. Kaspersky Labs estimated that seventeen percent of crypto-ransomware victims never recovered their data even after having sent off the ransom, resulting in additional losses. The risk is also costly. Ryuk ransoms are commonly several hundred thousand dollars. For larger organizations, the ransom can be in the millions of dollars. The fallback is to re-install the critical parts of your Information Technology environment. Absent access to essential system backups, this calls for a broad range of IT skills, professional project management, and the capability to work 24x7 until the task is over.
For decades, Progent has made available expert IT services for companies across the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes professionals who have attained high-level industry certifications in leading technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security specialists have earned internationally-renowned certifications including CISM, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent also has experience in accounting and ERP applications. This breadth of experience affords Progent the skills to knowledgably ascertain important systems and integrate the remaining components of your network system following a crypto-ransomware attack and rebuild them into an operational system.
Progent's recovery team has state-of-the-art project management systems to orchestrate the sophisticated recovery process. Progent understands the importance of working swiftly and in concert with a customer's management and Information Technology resources to prioritize tasks and to get critical applications back on line as fast as humanly possible.
Client Story: A Successful Ransomware Penetration Recovery
A business engaged Progent after their organization was crashed by Ryuk ransomware. Ryuk is believed to have been created by North Korean state sponsored criminal gangs, suspected of adopting approaches exposed from America's NSA organization. Ryuk targets specific companies with little or no tolerance for disruption and is one of the most profitable examples of crypto-ransomware. High publicized victims include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a regional manufacturer located in Chicago with around 500 staff members. The Ryuk attack had disabled all business operations and manufacturing processes. The majority of the client's backups had been online at the time of the intrusion and were destroyed. The client was taking steps for paying the ransom demand (exceeding $200,000) and praying for the best, but in the end brought in Progent.
Progent worked hand in hand the customer to rapidly determine and prioritize the most important areas that had to be addressed to make it possible to continue departmental operations:
Within two days, Progent was able to re-build Active Directory services to its pre-penetration state. Progent then completed rebuilding and storage recovery of mission critical servers. All Exchange Server ties and configuration information were intact, which facilitated the rebuild of Exchange. Progent was able to collect intact OST files (Outlook Off-Line Folder Files) on staff workstations to recover mail messages. A recent offline backup of the businesses accounting/MRP software made them able to return these essential programs back on-line. Although major work remained to recover fully from the Ryuk damage, essential systems were restored rapidly:
Throughout the following few weeks key milestones in the recovery process were accomplished in close cooperation between Progent engineers and the customer:
Conclusion
A likely business catastrophe was averted due to dedicated professionals, a broad spectrum of IT skills, and tight teamwork. Although in retrospect the ransomware virus incident detailed here could have been stopped with modern cyber security solutions and recognized best practices, user training, and well designed security procedures for data backup and applying software patches, the reality is that government-sponsored criminal cyber gangs from China, Russia, North Korea and elsewhere are relentless and will continue. If you do fall victim to a ransomware incident, feel confident that Progent's team of professionals has a proven track record in crypto-ransomware virus blocking, removal, and data disaster recovery.
Download the Ransomware Remediation Case Study Datasheet
To read or download a PDF version of this customer case study, click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware System Recovery Services in Bristol
For ransomware system restoration expertise in the Bristol metro area, call Progent at