Overview of Progent's Ransomware Forensics and Reporting Services in Edmonton
Progent's ransomware forensics experts can save the system state after a ransomware assault and carry out a detailed forensics analysis without impeding activity required for operational resumption and data recovery. Your Edmonton business can use Progent's post-attack forensics documentation to counter subsequent ransomware assaults, validate the recovery of encrypted data, and comply with insurance and regulatory reporting requirements.
Ransomware forensics analysis involves determining and documenting the ransomware attack's storyline across the network from beginning to end. This history of the way a ransomware attack travelled within the network assists you to evaluate the impact and brings to light gaps in security policies or work habits that should be rectified to prevent later break-ins. Forensic analysis is usually assigned a top priority by the insurance provider and is typically mandated by government and industry regulations. Because forensics can take time, it is critical that other important activities like business resumption are pursued concurrently. Progent maintains a large roster of IT and security experts with the skills required to carry out the work of containment, business continuity, and data recovery without disrupting forensics.
Ransomware forensics analysis is complex and calls for intimate interaction with the teams focused on file cleanup and, if needed, settlement discussions with the ransomware attacker. Ransomware forensics typically require the examination of logs, registry, Group Policy Object, Active Directory, DNS servers, routers, firewalls, schedulers, and basic Windows systems to look for changes.
Activities involved with forensics investigation include:
- Isolate but avoid shutting off all potentially affected devices from the network. This can require closing all RDP ports and Internet facing NAS storage, changing admin credentials and user PWs, and setting up two-factor authentication to guard backups.
- Create forensically sound digital images of all exposed devices so the data recovery group can proceed
- Preserve firewall, VPN, and other critical logs as soon as possible
- Establish the version of ransomware used in the attack
- Survey every machine and data store on the system including cloud storage for indications of encryption
- Inventory all compromised devices
- Establish the kind of ransomware used in the attack
- Review log activity and user sessions to determine the time frame of the assault and to identify any potential sideways migration from the originally compromised machine
- Identify the attack vectors exploited to carry out the ransomware attack
- Look for the creation of executables surrounding the first encrypted files or system breach
- Parse Outlook web archives
- Examine email attachments
- Extract URLs from messages and check to see whether they are malicious
- Provide comprehensive attack reporting to satisfy your insurance carrier and compliance mandates
- Suggest recommendations to close security gaps and improve workflows that reduce the risk of a future ransomware exploit
Progent's Background
Progent has provided remote and onsite network services across the United States for more than 20 years and has been awarded Microsoft's Partner certification in the Datacenter and Cloud Productivity competencies. Progent's roster of subject matter experts includes professionals who have been awarded high-level certifications in core technology platforms such as Cisco networking, VMware, and popular distributions of Linux. Progent's cybersecurity consultants have earned industry-recognized certifications including CISA, CISSP-ISSAP, and CRISC. (See certifications earned by Progent consultants). Progent also offers top-tier support in financial management and ERP applications. This scope of expertise allows Progent to salvage and integrate the undamaged pieces of your IT environment after a ransomware attack and rebuild them rapidly into a viable network. Progent has collaborated with top cyber insurance providers including Chubb to help organizations clean up after ransomware attacks.
Contact Progent about Ransomware Forensics Services in Edmonton
To find out more information about ways Progent can help your Edmonton business with ransomware forensics analysis, call 1-800-462-8800 or see Contact Progent.