Ransomware : Your Feared IT Catastrophe
Crypto-Ransomware  Recovery ConsultantsRansomware has become an escalating cyber pandemic that represents an extinction-level danger for businesses vulnerable to an attack. Multiple generations of ransomware such as CryptoLocker, CryptoWall, Locky, Syskey and MongoLock cryptoworms have been circulating for many years and continue to cause havoc. Modern strains of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Nephilim, plus daily unnamed newcomers, not only encrypt on-line data files but also infect most configured system backups. Information synchronized to off-premises disaster recovery sites can also be encrypted. In a poorly designed data protection solution, it can make automatic restoration impossible and effectively knocks the entire system back to zero.

Getting back on-line applications and information following a ransomware event becomes a race against time as the victim fights to stop the spread, eradicate the virus, and resume mission-critical activity. Because crypto-ransomware takes time to move laterally throughout a network, penetrations are often sprung during weekends and nights, when penetrations in many cases take more time to uncover. This multiplies the difficulty of quickly assembling and coordinating a qualified response team.

Progent makes available a range of help services for securing Yonkers enterprises from ransomware penetrations. Among these are staff training to help identify and not fall victim to phishing exploits, ProSight Active Security Monitoring for endpoint detection and response (EDR) using SentinelOne's behavior-based cyberthreat defense to discover and suppress day-zero modern malware assaults. Progent also offers the services of experienced ransomware recovery professionals with the track record and commitment to rebuild a compromised environment as rapidly as possible.

Progent's Crypto-Ransomware Restoration Services
Following a crypto-ransomware event, paying the ransom demands in cryptocurrency does not ensure that criminal gangs will respond with the needed keys to unencrypt any of your information. Kaspersky ascertained that 17% of ransomware victims never recovered their files after having sent off the ransom, resulting in additional losses. The risk is also costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger organizations, the ransom demand can be in the millions. The other path is to piece back together the critical parts of your Information Technology environment. Absent access to complete system backups, this calls for a broad range of skill sets, well-coordinated team management, and the ability to work 24x7 until the job is done.

For two decades, Progent has offered certified expert Information Technology services for companies throughout the United States and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes professionals who have been awarded high-level certifications in leading technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security specialists have garnered internationally-recognized industry certifications including CISA, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has experience with accounting and ERP software solutions. This breadth of expertise gives Progent the capability to efficiently ascertain important systems and integrate the remaining parts of your network environment after a ransomware penetration and rebuild them into a functioning network.

Progent's security team has best of breed project management applications to orchestrate the complex recovery process. Progent knows the urgency of working swiftly and together with a client's management and Information Technology resources to prioritize tasks and to get essential services back on line as soon as possible.

Case Study: A Successful Crypto-Ransomware Incident Restoration
A client escalated to Progent after their network system was taken over by Ryuk ransomware. Ryuk is thought to have been developed by North Korean state sponsored cybercriminals, suspected of using algorithms exposed from the U.S. National Security Agency. Ryuk goes after specific companies with little or no ability to sustain disruption and is among the most profitable iterations of crypto-ransomware. Major organizations include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a regional manufacturing company headquartered in the Chicago metro area with about 500 employees. The Ryuk attack had frozen all business operations and manufacturing capabilities. Most of the client's data backups had been online at the beginning of the intrusion and were encrypted. The client considered paying the ransom (in excess of $200,000) and hoping for good luck, but in the end engaged Progent.


"I cannot thank you enough in regards to the support Progent provided us during the most fearful period of (our) company's life. We most likely would have paid the cyber criminals behind the attack except for the confidence the Progent team gave us. The fact that you could get our e-mail and important applications back on-line sooner than one week was amazing. Every single expert I spoke to or messaged at Progent was laser focused on getting our company operational and was working at all hours on our behalf."

Progent worked hand in hand the client to quickly identify and prioritize the essential systems that needed to be addressed in order to resume business operations:

  • Microsoft Active Directory
  • Microsoft Exchange
  • Accounting/MRP
To start, Progent followed ransomware event mitigation industry best practices by halting the spread and clearing infected systems. Progent then started the work of bringing back online Microsoft Active Directory, the heart of enterprise environments built on Microsoft Windows Server technology. Exchange email will not work without Windows AD, and the customer's MRP system leveraged Microsoft SQL, which needs Windows AD for access to the data.

Within 48 hours, Progent was able to recover Windows Active Directory to its pre-penetration state. Progent then performed rebuilding and storage recovery of critical servers. All Exchange schema and configuration information were intact, which accelerated the restore of Exchange. Progent was able to assemble local OST files (Outlook Off-Line Data Files) on various workstations to recover email information. A not too old offline backup of the businesses accounting/ERP software made them able to recover these required applications back on-line. Although a large amount of work remained to recover fully from the Ryuk damage, critical systems were recovered quickly:


"For the most part, the assembly line operation did not miss a beat and we produced all customer deliverables."

Throughout the following month key milestones in the recovery process were completed in close collaboration between Progent consultants and the client:

  • Self-hosted web sites were restored without losing any data.
  • The MailStore Microsoft Exchange Server containing more than 4 million historical messages was brought on-line and accessible to users.
  • CRM/Product Ordering/Invoices/Accounts Payable/Accounts Receivables (AR)/Inventory capabilities were completely operational.
  • A new Palo Alto 850 security appliance was deployed.
  • Nearly all of the desktops and laptops were fully operational.

"So much of what went on those first few days is nearly entirely a haze for me, but our team will not soon forget the commitment each of your team put in to give us our company back. I have entrusted Progent for at least 10 years, possibly more, and each time Progent has shined and delivered. This situation was a testament to your capabilities."

Conclusion
A probable business-ending catastrophe was avoided by top-tier professionals, a wide spectrum of IT skills, and tight teamwork. Although upon completion of forensics the ransomware penetration described here should have been identified and stopped with advanced security systems and best practices, staff education, and well designed security procedures for data protection and keeping systems up to date with security patches, the reality remains that state-sponsored cyber criminals from China, Russia, North Korea and elsewhere are relentless and are an ongoing threat. If you do get hit by a ransomware incursion, remember that Progent's team of professionals has proven experience in ransomware virus defense, remediation, and file disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others who were involved), thank you for allowing me to get some sleep after we made it through the first week. Everyone did an fabulous effort, and if any of your guys is around the Chicago area, dinner is on me!"

Download the Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this customer case study, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Services in Yonkers
For ransomware cleanup consulting in the Yonkers area, phone Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.