Ransomware : Your Crippling IT Catastrophe
Ransomware  Remediation ConsultantsRansomware has become a too-frequent cyber pandemic that poses an existential danger for businesses of all sizes vulnerable to an assault. Multiple generations of ransomware such as CrySIS, WannaCry, Bad Rabbit, SamSam and MongoLock cryptoworms have been around for years and continue to cause destruction. Modern versions of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, plus frequent as yet unnamed viruses, not only perform encryption of on-line files but also infect all accessible system backup. Files synched to off-premises disaster recovery sites can also be rendered useless. In a poorly architected environment, it can render automated recovery useless and basically sets the entire system back to zero.

Recovering services and information following a ransomware event becomes a sprint against the clock as the victim struggles to stop lateral movement, clear the crypto-ransomware, and resume mission-critical activity. Since ransomware needs time to spread across a network, attacks are usually launched on weekends, when successful penetrations in many cases take longer to discover. This compounds the difficulty of rapidly mobilizing and coordinating an experienced mitigation team.

Progent provides a range of services for protecting Waltham enterprises from crypto-ransomware penetrations. These include user training to help identify and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's AI-based cyberthreat protection to discover and suppress day-zero malware assaults. Progent in addition can provide the assistance of veteran ransomware recovery consultants with the track record and perseverance to restore a breached network as urgently as possible.

Progent's Ransomware Recovery Help
Following a crypto-ransomware invasion, even paying the ransom in cryptocurrency does not ensure that merciless criminals will provide the keys to unencrypt any of your data. Kaspersky determined that seventeen percent of ransomware victims never recovered their files even after having sent off the ransom, resulting in additional losses. The risk is also costly. Ryuk ransoms are typically several hundred thousand dollars. For larger organizations, the ransom can reach millions of dollars. The alternative is to setup from scratch the critical components of your Information Technology environment. Absent access to full information backups, this requires a broad range of skill sets, professional team management, and the capability to work non-stop until the task is over.

For decades, Progent has provided expert IT services for companies throughout the US and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes consultants who have attained top industry certifications in leading technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security engineers have garnered internationally-recognized industry certifications including CISA, CISSP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has expertise in accounting and ERP software solutions. This breadth of expertise affords Progent the capability to rapidly identify necessary systems and organize the surviving components of your IT system after a ransomware event and assemble them into a functioning network.

Progent's ransomware group uses powerful project management tools to orchestrate the complicated recovery process. Progent appreciates the urgency of working swiftly and in unison with a customer's management and IT team members to assign priority to tasks and to get key services back online as fast as possible.

Client Story: A Successful Crypto-Ransomware Penetration Restoration
A small business hired Progent after their network system was taken over by the Ryuk ransomware. Ryuk is generally considered to have been deployed by North Korean state sponsored criminal gangs, possibly using technology exposed from the United States National Security Agency. Ryuk seeks specific businesses with limited room for operational disruption and is one of the most profitable iterations of crypto-ransomware. Headline victims include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a small manufacturer based in the Chicago metro area and has around 500 workers. The Ryuk event had disabled all company operations and manufacturing capabilities. Most of the client's backups had been on-line at the time of the intrusion and were damaged. The client was taking steps for paying the ransom demand (exceeding $200,000) and hoping for good luck, but in the end made the decision to use Progent.


"I cannot tell you enough about the help Progent gave us during the most critical period of (our) company's life. We most likely would have paid the hackers behind this attack if it wasn't for the confidence the Progent group provided us. The fact that you could get our e-mail and production applications back into operation in less than 1 week was incredible. Each expert I talked with or communicated with at Progent was amazingly focused on getting us operational and was working at all hours to bail us out."

Progent worked with the client to rapidly assess and prioritize the most important systems that needed to be addressed in order to continue company functions:

  • Windows Active Directory
  • Microsoft Exchange
  • MRP System
To get going, Progent adhered to ransomware incident mitigation best practices by halting the spread and clearing up compromised systems. Progent then started the process of rebuilding Windows Active Directory, the key technology of enterprise systems built on Microsoft technology. Exchange email will not work without AD, and the businesses' financials and MRP software leveraged Microsoft SQL, which needs Active Directory services for security authorization to the data.

Within 48 hours, Progent was able to rebuild Windows Active Directory to its pre-intrusion state. Progent then charged ahead with rebuilding and storage recovery on critical applications. All Exchange Server data and attributes were usable, which facilitated the rebuild of Exchange. Progent was also able to find local OST data files (Outlook Email Offline Folder Files) on team desktop computers and laptops to recover mail data. A recent off-line backup of the businesses financials/MRP systems made them able to return these essential programs back servicing users. Although a large amount of work was left to recover completely from the Ryuk event, critical systems were returned to operations quickly:


"For the most part, the production operation did not miss a beat and we produced all customer deliverables."

Throughout the next couple of weeks key milestones in the recovery project were accomplished in tight collaboration between Progent consultants and the customer:

  • Self-hosted web sites were restored without losing any information.
  • The MailStore Exchange Server containing more than four million archived emails was brought online and available for users.
  • CRM/Product Ordering/Invoicing/Accounts Payable (AP)/AR/Inventory functions were 100 percent functional.
  • A new Palo Alto 850 security appliance was installed.
  • 90% of the desktop computers were being used by staff.

"A lot of what was accomplished that first week is nearly entirely a blur for me, but our team will not soon forget the countless hours each and every one of your team put in to help get our company back. I have utilized Progent for the past ten years, maybe more, and each time I needed help Progent has outperformed my expectations and delivered. This time was a testament to your capabilities."

Conclusion
A likely enterprise-killing catastrophe was averted due to top-tier professionals, a wide range of IT skills, and tight collaboration. Although upon completion of forensics the ransomware virus penetration described here could have been blocked with modern security technology and ISO/IEC 27001 best practices, user training, and appropriate incident response procedures for data backup and proper patching controls, the reality is that state-sponsored cybercriminals from China, Russia, North Korea and elsewhere are relentless and are an ongoing threat. If you do get hit by a crypto-ransomware attack, feel confident that Progent's roster of professionals has substantial experience in crypto-ransomware virus blocking, cleanup, and file disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Jesse, Arnaud, Allen, Tony and Chris (and any others that were helping), thank you for making it so I could get some sleep after we got past the initial push. Everyone did an fabulous job, and if any of your team is around the Chicago area, dinner is on me!"

Download the Crypto-Ransomware Remediation Case Study Datasheet
To read or download a PDF version of this case study, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware System Recovery Expertise in Waltham
For ransomware cleanup services in the Waltham metro area, phone Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.