Progent's Ransomware Forensics Investigation and Reporting in Reading
Progent's ransomware forensics consultants can save the evidence of a ransomware assault and perform a detailed forensics analysis without disrupting the processes required for business continuity and data restoration. Your Reading organization can utilize Progent's ransomware forensics report to combat subsequent ransomware attacks, validate the cleanup of lost data, and meet insurance and governmental reporting requirements.
Ransomware forensics is aimed at determining and documenting the ransomware attack's progress across the targeted network from beginning to end. This audit trail of the way a ransomware assault progressed through the network helps you to evaluate the impact and uncovers vulnerabilities in policies or work habits that need to be corrected to prevent later break-ins. Forensic analysis is commonly given a top priority by the insurance carrier and is often required by state and industry regulations. Since forensics can take time, it is essential that other key activities such as business continuity are performed concurrently. Progent maintains a large team of information technology and cybersecurity experts with the knowledge and experience required to carry out activities for containment, operational continuity, and data recovery without disrupting forensic analysis.
Ransomware forensics investigation is complex and calls for intimate interaction with the teams assigned to data recovery and, if necessary, settlement talks with the ransomware adversary. Ransomware forensics typically require the examination of logs, registry, GPO, Active Directory (AD), DNS, routers, firewalls, scheduled tasks, and basic Windows systems to check for variations.
Activities involved with forensics investigation include:
- Isolate but avoid shutting off all potentially suspect devices from the network. This can require closing all RDP ports and Internet facing NAS storage, changing admin credentials and user passwords, and implementing two-factor authentication to guard your backups.
- Capture forensically sound digital images of all suspect devices so your data recovery team can get started
- Preserve firewall, virtual private network, and additional key logs as soon as feasible
- Establish the variety of ransomware involved in the attack
- Examine every computer and storage device on the network as well as cloud-hosted storage for indications of compromise
- Catalog all encrypted devices
- Establish the type of ransomware used in the assault
- Review logs and user sessions in order to determine the time frame of the ransomware assault and to spot any possible sideways migration from the originally infected machine
- Understand the attack vectors used to perpetrate the ransomware assault
- Search for the creation of executables surrounding the original encrypted files or network breach
- Parse Outlook web archives
- Analyze email attachments
- Extract URLs embedded in email messages and check to see whether they are malware
- Produce detailed incident documentation to satisfy your insurance and compliance regulations
- Suggest recommendations to close security gaps and improve workflows that reduce the risk of a future ransomware breach
Progent's Background
Progent has delivered remote and onsite IT services across the United States for over two decades and has been awarded Microsoft's Partner designation in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes professionals who have earned advanced certifications in core technology platforms such as Cisco infrastructure, VMware virtualization, and popular Linux distros. Progent's data security consultants have earned prestigious certifications such as CISM, CISSP, and GIAC. (See certifications earned by Progent consultants). Progent also has top-tier support in financial management and Enterprise Resource Planning applications. This breadth of expertise allows Progent to salvage and integrate the surviving pieces of your IT environment after a ransomware intrusion and reconstruct them quickly into a functioning network. Progent has worked with top cyber insurance providers including Chubb to help organizations recover from ransomware assaults.
Contact Progent about Ransomware Forensics Services in Reading
To find out more information about how Progent can assist your Reading business with ransomware forensics, call 1-800-462-8800 or visit Contact Progent.