Ransomware : Your Worst IT Catastrophe
Crypto-Ransomware  Remediation ExpertsRansomware has become an escalating cyber pandemic that represents an enterprise-level danger for businesses vulnerable to an attack. Multiple generations of ransomware like the Dharma, Fusob, Bad Rabbit, SamSam and MongoLock cryptoworms have been around for many years and still inflict harm. More recent strains of ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, as well as daily unnamed viruses, not only encrypt online critical data but also infect many available system backups. Information synchronized to the cloud can also be ransomed. In a vulnerable data protection solution, it can render automated restore operations useless and effectively knocks the datacenter back to square one.

Getting back on-line applications and data after a ransomware event becomes a race against the clock as the targeted business tries its best to stop lateral movement, cleanup the virus, and restore mission-critical operations. Since ransomware requires time to move laterally throughout a targeted network, penetrations are often sprung during weekends and nights, when attacks typically take longer to detect. This compounds the difficulty of promptly marshalling and orchestrating a capable mitigation team.

Progent has a variety of services for securing Liverpool enterprises from ransomware attacks. Among these are team training to help identify and not fall victim to phishing attempts, ProSight Active Security Monitoring for endpoint detection and response (EDR) using SentinelOne's behavior-based cyberthreat protection to identify and extinguish day-zero malware attacks. Progent in addition offers the services of seasoned ransomware recovery engineers with the skills and commitment to reconstruct a compromised network as rapidly as possible.

Progent's Crypto-Ransomware Recovery Support Services
After a ransomware invasion, even paying the ransom in cryptocurrency does not guarantee that criminal gangs will respond with the keys to decipher all your data. Kaspersky Labs determined that 17% of ransomware victims never recovered their files even after having sent off the ransom, resulting in more losses. The gamble is also very costly. Ryuk ransoms are commonly several hundred thousand dollars. For larger enterprises, the ransom demand can reach millions of dollars. The other path is to piece back together the key elements of your Information Technology environment. Without access to essential system backups, this calls for a wide complement of skill sets, well-coordinated team management, and the ability to work 24x7 until the job is finished.

For two decades, Progent has provided professional IT services for companies across the US and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes professionals who have attained advanced industry certifications in foundation technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security specialists have garnered internationally-renowned industry certifications including CISA, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent also has expertise in financial systems and ERP software solutions. This breadth of experience affords Progent the capability to rapidly understand necessary systems and consolidate the remaining parts of your network environment after a ransomware event and assemble them into a functioning network.

Progent's recovery team has state-of-the-art project management tools to coordinate the complex restoration process. Progent appreciates the importance of acting rapidly and in unison with a client's management and IT resources to assign priority to tasks and to put the most important services back online as fast as humanly possible.

Client Case Study: A Successful Ransomware Attack Restoration
A client contacted Progent after their company was brought down by Ryuk crypto-ransomware. Ryuk is believed to have been created by North Korean government sponsored cybercriminals, possibly adopting approaches leaked from America's National Security Agency. Ryuk goes after specific companies with limited ability to sustain disruption and is among the most profitable iterations of ransomware. Well Known targets include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a small manufacturer located in Chicago with about 500 workers. The Ryuk penetration had disabled all business operations and manufacturing processes. The majority of the client's data backups had been online at the time of the attack and were eventually encrypted. The client was pursuing financing for paying the ransom demand (more than $200,000) and praying for good luck, but ultimately engaged Progent.


"I can't speak enough about the care Progent provided us during the most critical time of (our) company's existence. We would have paid the Hackers if it wasn't for the confidence the Progent team afforded us. That you could get our e-mail and important servers back on-line faster than a week was incredible. Each expert I talked with or messaged at Progent was urgently focused on getting us operational and was working day and night on our behalf."

Progent worked together with the client to quickly assess and assign priority to the key areas that had to be restored in order to resume departmental functions:

  • Active Directory (AD)
  • E-Mail
  • Financials/MRP
To get going, Progent adhered to Anti-virus incident mitigation industry best practices by stopping the spread and clearing infected systems. Progent then started the process of recovering Microsoft AD, the heart of enterprise networks built on Microsoft Windows technology. Microsoft Exchange messaging will not operate without Active Directory, and the businesses' MRP system leveraged Microsoft SQL Server, which needs Active Directory for security authorization to the databases.

In less than two days, Progent was able to recover Windows Active Directory to its pre-penetration state. Progent then initiated rebuilding and hard drive recovery of critical servers. All Exchange Server data and attributes were intact, which greatly helped the restore of Exchange. Progent was able to find local OST files (Microsoft Outlook Offline Folder Files) on user desktop computers in order to recover mail messages. A not too old offline backup of the customer's financials/ERP software made them able to return these vital services back online. Although a large amount of work remained to recover fully from the Ryuk virus, the most important systems were recovered quickly:


"For the most part, the production manufacturing operation was never shut down and we produced all customer sales."

Throughout the following few weeks important milestones in the recovery process were made through close cooperation between Progent engineers and the client:

  • Self-hosted web applications were brought back up without losing any information.
  • The MailStore Server with over 4 million archived emails was brought on-line and accessible to users.
  • CRM/Product Ordering/Invoices/Accounts Payable/Accounts Receivables/Inventory functions were fully functional.
  • A new Palo Alto 850 security appliance was installed and configured.
  • Ninety percent of the user workstations were fully operational.

"Much of what transpired those first few days is nearly entirely a fog for me, but I will not forget the countless hours each of you accomplished to give us our business back. I have been working together with Progent for the past ten years, possibly more, and each time I needed help Progent has impressed me and delivered. This event was the most impressive ever."

Conclusion
A likely business disaster was averted by results-oriented experts, a wide array of technical expertise, and tight collaboration. Although in analyzing the event afterwards the ransomware penetration detailed here could have been disabled with advanced cyber security technology solutions and NIST Cybersecurity Framework best practices, staff education, and properly executed security procedures for data backup and applying software patches, the reality remains that government-sponsored cybercriminals from China, North Korea and elsewhere are relentless and are not going away. If you do get hit by a ransomware penetration, remember that Progent's team of professionals has a proven track record in ransomware virus blocking, remediation, and information systems recovery.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others who were helping), I'm grateful for allowing me to get some sleep after we got over the first week. Everyone did an amazing job, and if anyone that helped is around the Chicago area, a great meal is my treat!"

Download the Ransomware Recovery Case Study Datasheet
To review or download a PDF version of this customer case study, click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting in Liverpool
For ransomware cleanup services in the Liverpool metro area, phone Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.