Ransomware : Your Crippling IT Catastrophe
Ransomware has become a too-frequent cyberplague that poses an enterprise-level danger for businesses of all sizes vulnerable to an assault. Versions of crypto-ransomware like the CrySIS, Fusob, Locky, NotPetya and MongoLock cryptoworms have been circulating for many years and still inflict damage. Modern versions of crypto-ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Nephilim, along with frequent as yet unnamed viruses, not only encrypt online information but also infiltrate all available system protection. Files replicated to off-premises disaster recovery sites can also be corrupted. In a poorly architected system, this can make automatic recovery useless and basically knocks the datacenter back to square one.
Getting back online applications and data following a ransomware intrusion becomes a sprint against time as the targeted organization struggles to stop the spread, clear the virus, and restore business-critical activity. Due to the fact that ransomware needs time to replicate across a network, penetrations are frequently sprung during weekends and nights, when attacks are likely to take more time to recognize. This multiplies the difficulty of promptly mobilizing and organizing an experienced mitigation team.
Progent provides an assortment of solutions for securing Alexandria businesses from ransomware attacks. These include team training to help identify and not fall victim to phishing exploits, ProSight Active Security Monitoring for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based threat defense to detect and extinguish day-zero modern malware attacks. Progent in addition offers the assistance of seasoned ransomware recovery professionals with the track record and commitment to restore a compromised environment as urgently as possible.
Progent's Crypto-Ransomware Recovery Help
Following a ransomware penetration, paying the ransom demands in cryptocurrency does not ensure that distant criminals will provide the keys to unencrypt all your data. Kaspersky estimated that seventeen percent of ransomware victims never restored their data even after having sent off the ransom, resulting in increased losses. The risk is also very costly. Ryuk ransoms are commonly several hundred thousand dollars. For larger organizations, the ransom demand can be in the millions. The other path is to setup from scratch the vital parts of your IT environment. Without the availability of essential information backups, this calls for a wide range of IT skills, professional team management, and the willingness to work 24x7 until the job is over.
For decades, Progent has provided professional IT services for businesses throughout the United States and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes engineers who have earned advanced industry certifications in leading technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security engineers have garnered internationally-recognized certifications including CISA, CISSP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has expertise with accounting and ERP application software. This breadth of expertise gives Progent the ability to knowledgably determine necessary systems and organize the surviving parts of your Information Technology system after a ransomware attack and rebuild them into an operational system.
Progent's security team utilizes state-of-the-art project management systems to orchestrate the complex recovery process. Progent knows the urgency of acting rapidly and in unison with a client's management and IT resources to prioritize tasks and to get key systems back online as fast as humanly possible.
Customer Story: A Successful Crypto-Ransomware Incident Recovery
A small business engaged Progent after their network was crashed by Ryuk ransomware. Ryuk is thought to have been launched by North Korean state sponsored criminal gangs, suspected of adopting approaches exposed from America's National Security Agency. Ryuk attacks specific organizations with little or no ability to sustain operational disruption and is one of the most profitable incarnations of ransomware viruses. High publicized organizations include Data Resolution, a California-based info warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a small manufacturing company based in the Chicago metro area and has about 500 employees. The Ryuk event had shut down all essential operations and manufacturing capabilities. Most of the client's backups had been directly accessible at the start of the intrusion and were damaged. The client was taking steps for paying the ransom (in excess of $200K) and hoping for good luck, but ultimately made the decision to use Progent.
Progent worked together with the customer to quickly assess and assign priority to the key areas that had to be recovered to make it possible to resume business operations:
In less than two days, Progent was able to recover Windows Active Directory to its pre-attack state. Progent then performed reinstallations and storage recovery of critical servers. All Exchange Server ties and attributes were intact, which accelerated the rebuild of Exchange. Progent was able to collect local OST files (Outlook Off-Line Data Files) on staff PCs and laptops to recover mail information. A recent off-line backup of the businesses accounting/MRP software made it possible to recover these essential services back on-line. Although significant work needed to be completed to recover fully from the Ryuk attack, essential systems were recovered quickly:
Throughout the next month key milestones in the restoration project were made in tight cooperation between Progent consultants and the client:
Conclusion
A possible business disaster was averted due to hard-working experts, a broad array of subject matter expertise, and tight collaboration. Although in hindsight the crypto-ransomware incident detailed here would have been blocked with advanced cyber security systems and best practices, staff training, and properly executed security procedures for data protection and applying software patches, the reality remains that government-sponsored hackers from China, North Korea and elsewhere are tireless and are not going away. If you do get hit by a ransomware virus, remember that Progent's roster of experts has extensive experience in crypto-ransomware virus blocking, cleanup, and file disaster recovery.
Download the Crypto-Ransomware Removal Case Study Datasheet
To read or download a PDF version of this case study, please click:
Progent's Crypto-Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware System Recovery Consulting Services in Alexandria
For ransomware cleanup services in the Alexandria metro area, call Progent at