Overview of Progent's Ransomware Forensics Analysis and Reporting in Columbus
Progent's ransomware forensics consultants can preserve the system state after a ransomware attack and perform a comprehensive forensics analysis without impeding activity required for operational continuity and data restoration. Your Columbus organization can use Progent's ransomware forensics report to block future ransomware attacks, validate the recovery of lost data, and meet insurance carrier and regulatory mandates.
Ransomware forensics analysis is aimed at determining and documenting the ransomware assault's storyline throughout the network from start to finish. This history of the way a ransomware attack travelled through the network helps your IT staff to assess the impact and brings to light shortcomings in policies or work habits that need to be corrected to prevent future break-ins. Forensics is usually assigned a high priority by the cyber insurance provider and is often required by state and industry regulations. Since forensics can be time consuming, it is critical that other important recovery processes such as operational resumption are executed concurrently. Progent maintains an extensive team of information technology and cybersecurity professionals with the knowledge and experience needed to carry out activities for containment, operational continuity, and data recovery without disrupting forensics.
Ransomware forensics is complex and calls for intimate cooperation with the groups responsible for data recovery and, if needed, settlement discussions with the ransomware attacker. Ransomware forensics can require the review of all logs, registry, Group Policy Object, AD, DNS, routers, firewalls, schedulers, and core Windows systems to detect changes.
Activities associated with forensics include:
- Disconnect but avoid shutting down all possibly affected devices from the system. This can require closing all Remote Desktop Protocol (RDP) ports and Internet connected network-attached storage, modifying admin credentials and user PWs, and setting up two-factor authentication to protect backups.
- Preserve forensically sound duplicates of all exposed devices so your data restoration group can proceed
- Save firewall, VPN, and additional critical logs as quickly as possible
- Determine the version of ransomware involved in the assault
- Survey every computer and data store on the system as well as cloud-hosted storage for indications of compromise
- Inventory all encrypted devices
- Determine the type of ransomware involved in the assault
- Review logs and user sessions in order to determine the time frame of the assault and to spot any potential lateral movement from the first infected system
- Identify the attack vectors used to carry out the ransomware attack
- Look for new executables surrounding the original encrypted files or system compromise
- Parse Outlook web archives
- Examine attachments
- Separate URLs from messages and check to see if they are malicious
- Produce comprehensive attack documentation to satisfy your insurance and compliance mandates
- List recommendations to shore up security gaps and improve processes that lower the exposure to a future ransomware breach
Progent's Qualifications
Progent has provided online and on-premises IT services throughout the United States for over two decades and has earned Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's roster of subject matter experts includes consultants who have been awarded advanced certifications in core technologies including Cisco networking, VMware, and major Linux distros. Progent's cybersecurity experts have earned prestigious certifications including CISA, CISSP-ISSAP, and GIAC. (Refer to certifications earned by Progent consultants). Progent also offers top-tier support in financial and ERP software. This breadth of expertise gives Progent the ability to identify and integrate the surviving parts of your information system following a ransomware assault and rebuild them rapidly into a viable network. Progent has worked with top cyber insurance carriers like Chubb to help organizations recover from ransomware assaults.
Contact Progent about Ransomware Forensics Expertise in Columbus
To learn more about ways Progent can assist your Columbus organization with ransomware forensics analysis, call 1-800-462-8800 or visit Contact Progent.