Ransomware : Your Crippling Information Technology Nightmare
Crypto-Ransomware  Remediation ConsultantsRansomware has become a modern cyberplague that presents an extinction-level danger for businesses of all sizes poorly prepared for an attack. Different versions of crypto-ransomware such as Dharma, CryptoWall, Locky, Syskey and MongoLock cryptoworms have been running rampant for many years and still inflict havoc. Modern versions of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Conti and Egregor, plus frequent unnamed malware, not only encrypt online information but also infiltrate all accessible system backups. Data replicated to cloud environments can also be rendered useless. In a vulnerable system, this can render automatic recovery useless and basically sets the datacenter back to square one.

Getting back services and data following a ransomware event becomes a sprint against time as the victim fights to contain, cleanup the ransomware, and restore business-critical operations. Due to the fact that crypto-ransomware needs time to move laterally across a targeted network, assaults are usually launched during weekends and nights, when attacks may take longer to discover. This compounds the difficulty of rapidly assembling and orchestrating a qualified response team.

Progent has an assortment of help services for securing Naples enterprises from crypto-ransomware attacks. These include team education to help identify and avoid phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based cyberthreat protection to detect and extinguish day-zero malware assaults. Progent also provides the services of veteran ransomware recovery engineers with the track record and perseverance to rebuild a breached network as urgently as possible.

Progent's Crypto-Ransomware Recovery Support Services
After a crypto-ransomware event, paying the ransom demands in cryptocurrency does not guarantee that cyber criminals will provide the needed codes to unencrypt any or all of your data. Kaspersky ascertained that 17% of ransomware victims never restored their files even after having sent off the ransom, resulting in additional losses. The risk is also very costly. Ryuk ransoms are typically several hundred thousand dollars. For larger organizations, the ransom demand can reach millions. The fallback is to setup from scratch the critical elements of your IT environment. Without access to essential information backups, this requires a broad range of skill sets, professional team management, and the ability to work continuously until the task is complete.

For twenty years, Progent has offered certified expert IT services for businesses throughout the United States and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes consultants who have attained top certifications in important technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security experts have garnered internationally-recognized certifications including CISA, CISSP-ISSAP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has expertise in financial management and ERP application software. This breadth of expertise provides Progent the skills to efficiently understand necessary systems and integrate the surviving components of your computer network environment after a crypto-ransomware penetration and configure them into an operational network.

Progent's recovery group has best of breed project management applications to orchestrate the complex recovery process. Progent understands the urgency of acting swiftly and together with a client's management and IT team members to prioritize tasks and to put essential services back on-line as soon as possible.

Case Study: A Successful Ransomware Intrusion Recovery
A client escalated to Progent after their company was crashed by Ryuk crypto-ransomware. Ryuk is thought to have been created by North Korean state cybercriminals, possibly adopting approaches exposed from the United States NSA organization. Ryuk seeks specific businesses with little tolerance for operational disruption and is among the most lucrative instances of ransomware. Headline organizations include Data Resolution, a California-based information warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a regional manufacturing business headquartered in the Chicago metro area with around 500 employees. The Ryuk event had brought down all company operations and manufacturing capabilities. The majority of the client's data backups had been directly accessible at the start of the intrusion and were damaged. The client was taking steps for paying the ransom demand (in excess of two hundred thousand dollars) and wishfully thinking for the best, but in the end brought in Progent.


"I cannot tell you enough in regards to the care Progent provided us during the most fearful period of (our) businesses survival. We may have had to pay the cyber criminals except for the confidence the Progent experts afforded us. That you could get our e-mail system and critical servers back on-line faster than five days was amazing. Every single expert I talked with or e-mailed at Progent was hell bent on getting my company operational and was working all day and night to bail us out."

Progent worked with the client to quickly assess and prioritize the key services that had to be recovered in order to restart departmental functions:

  • Windows Active Directory
  • Microsoft Exchange Email
  • Accounting and Manufacturing Software
To get going, Progent followed Anti-virus event mitigation best practices by stopping the spread and cleaning up infected systems. Progent then started the work of rebuilding Microsoft AD, the heart of enterprise systems built on Microsoft Windows technology. Microsoft Exchange Server messaging will not function without Active Directory, and the client's financials and MRP system utilized Microsoft SQL, which needs Active Directory for security authorization to the database.

In less than two days, Progent was able to restore Active Directory to its pre-penetration state. Progent then charged ahead with reinstallations and hard drive recovery on critical servers. All Exchange Server schema and attributes were usable, which facilitated the rebuild of Exchange. Progent was also able to collect intact OST files (Outlook Off-Line Folder Files) on user workstations in order to recover mail messages. A recent offline backup of the customer's accounting/MRP software made them able to return these essential programs back available to users. Although a large amount of work needed to be completed to recover fully from the Ryuk damage, the most important systems were returned to operations rapidly:


"For the most part, the production manufacturing operation survived unscathed and we delivered all customer orders."

During the next few weeks important milestones in the restoration project were made through close cooperation between Progent consultants and the client:

  • Self-hosted web sites were restored with no loss of data.
  • The MailStore Server containing more than 4 million archived emails was brought on-line and accessible to users.
  • CRM/Customer Orders/Invoicing/AP/Accounts Receivables (AR)/Inventory functions were 100% functional.
  • A new Palo Alto 850 security appliance was deployed.
  • 90% of the user desktops were back into operation.

"A huge amount of what was accomplished that first week is mostly a fog for me, but our team will not soon forget the dedication all of the team accomplished to give us our company back. I've trusted Progent for the past ten years, maybe more, and each time Progent has come through and delivered. This situation was a life saver."

Conclusion
A possible business disaster was avoided by results-oriented experts, a broad spectrum of knowledge, and close teamwork. Although in hindsight the ransomware attack described here should have been identified and prevented with modern cyber security systems and recognized best practices, user training, and properly executed security procedures for data backup and proper patching controls, the reality is that state-sponsored hackers from Russia, North Korea and elsewhere are relentless and are not going away. If you do fall victim to a ransomware virus, remember that Progent's roster of experts has a proven track record in crypto-ransomware virus defense, mitigation, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Chris (and any others that were contributing), thanks very much for allowing me to get rested after we made it over the most critical parts. Everyone did an amazing job, and if anyone is visiting the Chicago area, dinner is on me!"

Download the Crypto-Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this case study, please click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware System Restoration Consulting in Naples
For ransomware system recovery consulting services in the Naples metro area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.