Ransomware : Your Feared Information Technology Nightmare
Ransomware  Recovery ConsultantsRansomware has become a modern cyberplague that represents an extinction-level danger for organizations unprepared for an assault. Versions of ransomware like the Dharma, WannaCry, Bad Rabbit, NotPetya and MongoLock cryptoworms have been running rampant for many years and still inflict harm. Newer versions of ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Egregor, plus daily as yet unnamed newcomers, not only perform encryption of on-line data but also infiltrate any accessible system backups. Data replicated to cloud environments can also be ransomed. In a poorly designed system, this can render any recovery useless and effectively knocks the network back to square one.

Getting back online services and information following a ransomware attack becomes a race against time as the targeted organization tries its best to stop the spread, clear the ransomware, and resume business-critical activity. Due to the fact that ransomware requires time to move laterally across a targeted network, attacks are usually sprung during nights and weekends, when successful attacks in many cases take longer to identify. This multiplies the difficulty of rapidly assembling and orchestrating a knowledgeable response team.

Progent makes available a range of support services for protecting Sorocaba enterprises from ransomware events. These include staff training to help recognize and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based threat defense to detect and disable day-zero modern malware attacks. Progent in addition can provide the assistance of expert ransomware recovery professionals with the talent and commitment to reconstruct a compromised environment as quickly as possible.

Progent's Ransomware Recovery Support Services
Following a crypto-ransomware penetration, sending the ransom in cryptocurrency does not ensure that merciless criminals will respond with the needed keys to decipher any or all of your data. Kaspersky Labs determined that 17% of ransomware victims never restored their data after having sent off the ransom, resulting in increased losses. The risk is also very costly. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom demand can be in the millions of dollars. The fallback is to piece back together the critical elements of your IT environment. Without the availability of complete system backups, this calls for a broad complement of skill sets, well-coordinated team management, and the ability to work non-stop until the recovery project is finished.

For twenty years, Progent has offered professional Information Technology services for companies throughout the United States and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes professionals who have earned top certifications in leading technologies including Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security consultants have earned internationally-renowned certifications including CISA, CISSP, CRISC, SANS GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has expertise with financial management and ERP application software. This breadth of experience affords Progent the ability to quickly identify critical systems and consolidate the remaining parts of your IT environment after a ransomware penetration and configure them into an operational system.

Progent's ransomware group has best of breed project management applications to orchestrate the complicated restoration process. Progent knows the urgency of working quickly and together with a customer's management and IT staff to prioritize tasks and to put the most important services back online as fast as possible.

Client Story: A Successful Ransomware Attack Recovery
A small business escalated to Progent after their company was crashed by the Ryuk crypto-ransomware. Ryuk is believed to have been deployed by North Korean government sponsored cybercriminals, suspected of using strategies leaked from the U.S. NSA organization. Ryuk seeks specific companies with limited ability to sustain disruption and is among the most lucrative incarnations of crypto-ransomware. Headline organizations include Data Resolution, a California-based information warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a single-location manufacturer based in Chicago with around 500 employees. The Ryuk intrusion had shut down all essential operations and manufacturing processes. The majority of the client's backups had been online at the time of the intrusion and were destroyed. The client was taking steps for paying the ransom (in excess of $200K) and praying for good luck, but ultimately reached out to Progent.


"I can't tell you enough in regards to the help Progent gave us during the most fearful time of (our) businesses existence. We had little choice but to pay the criminal gangs if it wasn't for the confidence the Progent group provided us. That you could get our e-mail and essential applications back quicker than five days was something I thought impossible. Every single expert I spoke to or communicated with at Progent was urgently focused on getting our company operational and was working 24 by 7 to bail us out."

Progent worked with the customer to rapidly assess and assign priority to the most important areas that had to be restored to make it possible to resume departmental operations:

  • Windows Active Directory
  • E-Mail
  • Accounting/MRP
To begin, Progent followed Anti-virus event response industry best practices by halting the spread and performing virus removal steps. Progent then began the task of rebuilding Windows Active Directory, the foundation of enterprise environments built on Microsoft Windows technology. Microsoft Exchange Server messaging will not operate without AD, and the customer's MRP applications used Microsoft SQL, which depends on Windows AD for access to the databases.

In less than two days, Progent was able to recover Active Directory services to its pre-attack state. Progent then charged ahead with setup and storage recovery on needed applications. All Exchange Server schema and configuration information were usable, which greatly helped the restore of Exchange. Progent was also able to find intact OST data files (Microsoft Outlook Off-Line Data Files) on team PCs to recover mail data. A recent off-line backup of the client's manufacturing software made them able to restore these vital services back available to users. Although a large amount of work remained to recover totally from the Ryuk event, critical services were restored quickly:


"For the most part, the manufacturing operation showed little impact and we delivered all customer sales."

During the following few weeks key milestones in the restoration project were accomplished in tight cooperation between Progent engineers and the customer:

  • In-house web applications were brought back up without losing any information.
  • The MailStore Server containing more than 4 million archived messages was spun up and accessible to users.
  • CRM/Customer Orders/Invoices/Accounts Payable/Accounts Receivables/Inventory capabilities were 100% restored.
  • A new Palo Alto 850 firewall was installed.
  • Most of the desktops and laptops were being used by staff.

"A huge amount of what was accomplished that first week is mostly a haze for me, but my team will not forget the care all of the team put in to give us our business back. I have been working together with Progent for the past 10 years, maybe more, and every time I needed help Progent has outperformed my expectations and delivered. This situation was a testament to your capabilities."

Conclusion
A probable enterprise-killing catastrophe was avoided with hard-working experts, a wide spectrum of subject matter expertise, and tight teamwork. Although in retrospect the ransomware incident detailed here could have been shut down with advanced security technology and recognized best practices, staff education, and appropriate incident response procedures for data backup and keeping systems up to date with security patches, the reality remains that government-sponsored cyber criminals from China, North Korea and elsewhere are tireless and will continue. If you do fall victim to a ransomware penetration, feel confident that Progent's roster of experts has a proven track record in ransomware virus blocking, cleanup, and data restoration.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Tony (along with others who were involved), I'm grateful for letting me get rested after we got past the initial fire. Everyone did an fabulous effort, and if anyone is around the Chicago area, a great meal is my treat!"

Download the Ransomware Recovery Case Study Datasheet
To review or download a PDF version of this customer story, please click:
Progent's Ryuk Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Consulting Services in Sorocaba
For ransomware cleanup consulting services in the Sorocaba metro area, call Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.