Ransomware : Your Crippling Information Technology Catastrophe
Crypto-Ransomware  Recovery ExpertsCrypto-Ransomware has become a too-frequent cyberplague that poses an enterprise-level threat for businesses vulnerable to an assault. Multiple generations of ransomware such as Reveton, WannaCry, Locky, SamSam and MongoLock cryptoworms have been around for years and still inflict harm. More recent versions of ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Nephilim, as well as more unnamed newcomers, not only perform encryption of online critical data but also infect most configured system protection mechanisms. Files synched to off-premises disaster recovery sites can also be rendered useless. In a vulnerable system, it can make automated restoration hopeless and basically sets the network back to zero.

Restoring applications and data after a ransomware intrusion becomes a sprint against the clock as the targeted organization struggles to contain, clear the ransomware, and restore mission-critical operations. Since ransomware needs time to replicate across a network, penetrations are usually launched during weekends and nights, when penetrations in many cases take longer to uncover. This multiplies the difficulty of promptly marshalling and coordinating a capable mitigation team.

Progent provides a variety of support services for securing Sandy Springs businesses from ransomware events. Among these are team training to help identify and not fall victim to phishing scams, ProSight Active Security Monitoring for endpoint detection and response utilizing SentinelOne's behavior-based threat defense to discover and extinguish zero-day modern malware attacks. Progent also offers the services of veteran ransomware recovery engineers with the track record and commitment to reconstruct a breached environment as urgently as possible.

Progent's Ransomware Restoration Services
After a crypto-ransomware penetration, even paying the ransom demands in cryptocurrency does not ensure that cyber hackers will respond with the needed codes to unencrypt any or all of your data. Kaspersky estimated that seventeen percent of ransomware victims never recovered their data even after having sent off the ransom, resulting in more losses. The gamble is also expensive. Ryuk ransoms are often several hundred thousand dollars. For larger organizations, the ransom can be in the millions. The alternative is to re-install the key elements of your Information Technology environment. Absent the availability of essential system backups, this requires a broad complement of skills, professional team management, and the willingness to work non-stop until the recovery project is over.

For twenty years, Progent has made available professional IT services for companies across the U.S. and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes professionals who have attained advanced certifications in leading technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cybersecurity experts have garnered internationally-recognized industry certifications including CISM, CISSP, CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent in addition has expertise with financial systems and ERP applications. This breadth of experience gives Progent the ability to quickly identify necessary systems and integrate the surviving components of your Information Technology environment after a crypto-ransomware event and rebuild them into a functioning network.

Progent's security team deploys top notch project management applications to coordinate the complex recovery process. Progent appreciates the importance of working rapidly and in unison with a client's management and Information Technology resources to assign priority to tasks and to get the most important applications back on line as soon as possible.

Customer Story: A Successful Ransomware Intrusion Response
A business sought out Progent after their company was attacked by the Ryuk ransomware. Ryuk is thought to have been created by North Korean state criminal gangs, possibly adopting technology leaked from the United States National Security Agency. Ryuk seeks specific organizations with little or no room for disruption and is one of the most lucrative iterations of ransomware. High publicized targets include Data Resolution, a California-based data warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a small manufacturer located in the Chicago metro area and has about 500 employees. The Ryuk attack had disabled all company operations and manufacturing capabilities. Most of the client's information backups had been on-line at the beginning of the attack and were encrypted. The client considered paying the ransom (more than two hundred thousand dollars) and praying for good luck, but ultimately reached out to Progent.


"I cannot tell you enough in regards to the support Progent gave us during the most stressful period of (our) businesses survival. We had little choice but to pay the cyber criminals behind the attack if it wasn't for the confidence the Progent experts gave us. The fact that you could get our e-mail system and key applications back online in less than seven days was beyond my wildest dreams. Each consultant I spoke to or texted at Progent was hell bent on getting our system up and was working at all hours on our behalf."

Progent worked hand in hand the client to quickly get our arms around and assign priority to the critical elements that needed to be addressed to make it possible to restart company operations:

  • Active Directory (AD)
  • Microsoft Exchange
  • Accounting/MRP
To start, Progent followed AV/Malware Processes penetration response industry best practices by stopping lateral movement and performing virus removal steps. Progent then started the task of bringing back online Windows Active Directory, the foundation of enterprise systems built upon Microsoft Windows Server technology. Exchange messaging will not function without AD, and the customer's financials and MRP system leveraged SQL Server, which needs Active Directory for security authorization to the information.

In less than two days, Progent was able to restore Active Directory to its pre-virus state. Progent then helped perform setup and storage recovery of critical servers. All Microsoft Exchange Server ties and configuration information were intact, which facilitated the restore of Exchange. Progent was also able to collect local OST data files (Outlook Offline Folder Files) on staff desktop computers in order to recover email data. A not too old off-line backup of the businesses accounting software made them able to restore these required services back servicing users. Although a large amount of work was left to recover completely from the Ryuk virus, critical services were restored rapidly:


"For the most part, the production manufacturing operation did not miss a beat and we produced all customer deliverables."

Throughout the following couple of weeks important milestones in the restoration project were completed in tight collaboration between Progent consultants and the customer:

  • Self-hosted web applications were returned to operation without losing any data.
  • The MailStore Exchange Server with over 4 million historical emails was restored to operations and available for users.
  • CRM/Orders/Invoicing/AP/Accounts Receivables/Inventory Control functions were completely restored.
  • A new Palo Alto 850 firewall was set up.
  • 90% of the user desktops were back into operation.

"A lot of what happened in the early hours is nearly entirely a blur for me, but my management will not soon forget the countless hours each of your team put in to give us our company back. I have been working together with Progent for the past 10 years, possibly more, and each time Progent has shined and delivered. This situation was a Herculean accomplishment."

Conclusion
A possible business catastrophe was evaded due to top-tier experts, a broad array of knowledge, and close collaboration. Although in post mortem the ransomware incident detailed here could have been identified and blocked with advanced cyber security technology solutions and NIST Cybersecurity Framework best practices, user and IT administrator education, and well thought out security procedures for data protection and proper patching controls, the fact is that state-sponsored cyber criminals from Russia, North Korea and elsewhere are tireless and are an ongoing threat. If you do fall victim to a ransomware attack, feel confident that Progent's team of professionals has extensive experience in ransomware virus defense, mitigation, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Tony (and any others that were helping), thank you for allowing me to get some sleep after we got over the initial push. All of you did an incredible effort, and if anyone that helped is visiting the Chicago area, a great meal is my treat!"

Download the Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this case study, click:
Progent's Ryuk Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting Services in Sandy Springs
For ransomware cleanup expertise in the Sandy Springs metro area, phone Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.