Overview of Progent's Ransomware Forensics Analysis and Reporting in Ontario
Progent's ransomware forensics experts can capture the system state after a ransomware attack and carry out a detailed forensics investigation without interfering with the processes related to operational continuity and data recovery. Your Ontario business can use Progent's post-attack forensics documentation to counter future ransomware attacks, assist in the cleanup of lost data, and meet insurance and governmental mandates.
Ransomware forensics analysis involves discovering and documenting the ransomware assault's storyline throughout the targeted network from start to finish. This history of the way a ransomware assault travelled within the network assists your IT staff to assess the impact and uncovers shortcomings in security policies or work habits that need to be rectified to prevent future break-ins. Forensics is commonly given a top priority by the insurance provider and is typically required by state and industry regulations. Since forensic analysis can be time consuming, it is essential that other key activities like operational resumption are pursued concurrently. Progent has an extensive roster of IT and data security experts with the skills needed to perform the work of containment, business continuity, and data recovery without disrupting forensics.
Ransomware forensics analysis is complicated and requires close interaction with the groups focused on file recovery and, if needed, payment talks with the ransomware hacker. Ransomware forensics can require the examination of logs, registry, Group Policy Object (GPO), Active Directory, DNS servers, routers, firewalls, scheduled tasks, and core Windows systems to check for variations.
Services associated with forensics include:
- Detach without shutting off all possibly affected devices from the system. This can involve closing all RDP ports and Internet facing network-attached storage, changing admin credentials and user passwords, and implementing 2FA to secure backups.
- Copy forensically sound duplicates of all exposed devices so the data restoration group can proceed
- Preserve firewall, VPN, and other critical logs as soon as feasible
- Establish the type of ransomware involved in the assault
- Inspect each computer and data store on the system as well as cloud storage for signs of compromise
- Catalog all encrypted devices
- Establish the type of ransomware used in the assault
- Study log activity and sessions to determine the timeline of the assault and to identify any possible sideways movement from the first infected system
- Identify the security gaps exploited to perpetrate the ransomware assault
- Search for the creation of executables associated with the original encrypted files or system compromise
- Parse Outlook web archives
- Examine email attachments
- Separate any URLs from messages and check to see whether they are malware
- Provide detailed incident documentation to meet your insurance and compliance requirements
- List recommended improvements to close cybersecurity gaps and enforce processes that lower the exposure to a future ransomware breach
Progent's Background
Progent has delivered online and onsite network services across the United States for over 20 years and has been awarded Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's roster of subject matter experts (SMEs) includes consultants who have earned high-level certifications in foundation technologies including Cisco infrastructure, VMware, and popular distributions of Linux. Progent's cybersecurity experts have earned internationally recognized certifications such as CISA, CISSP-ISSAP, and CRISC. (Refer to certifications earned by Progent consultants). Progent also offers top-tier support in financial and ERP applications. This scope of skills allows Progent to identify and consolidate the surviving parts of your information system following a ransomware attack and reconstruct them rapidly into a functioning network. Progent has worked with top insurance providers including Chubb to assist organizations clean up after ransomware attacks.
Contact Progent about Ransomware Forensics Services in Ontario
To find out more about ways Progent can assist your Ontario business with ransomware forensics, call 1-800-462-8800 or see Contact Progent.