Ransomware : Your Crippling IT Nightmare
Ransomware  Recovery ConsultantsRansomware has become a too-frequent cyberplague that poses an extinction-level danger for organizations poorly prepared for an assault. Multiple generations of crypto-ransomware like the CryptoLocker, CryptoWall, Bad Rabbit, Syskey and MongoLock cryptoworms have been circulating for many years and continue to inflict harm. More recent versions of ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti and Egregor, plus more unnamed malware, not only perform encryption of online data but also infect many available system protection mechanisms. Information synchronized to off-premises disaster recovery sites can also be ransomed. In a poorly architected environment, this can make automatic restoration hopeless and effectively knocks the entire system back to square one.

Getting back online services and data after a crypto-ransomware outage becomes a race against the clock as the targeted business struggles to contain the damage, remove the crypto-ransomware, and restore mission-critical activity. Since ransomware takes time to replicate throughout a targeted network, penetrations are often sprung at night, when attacks in many cases take longer to notice. This multiplies the difficulty of rapidly marshalling and orchestrating a knowledgeable mitigation team.

Progent has a variety of help services for protecting Hayward organizations from ransomware events. These include team member education to become familiar with and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response using SentinelOne's behavior-based threat defense to detect and extinguish day-zero malware attacks. Progent in addition can provide the services of veteran ransomware recovery professionals with the track record and commitment to re-deploy a compromised system as rapidly as possible.

Progent's Ransomware Restoration Support Services
Following a ransomware attack, paying the ransom demands in cryptocurrency does not provide any assurance that cyber hackers will return the keys to decrypt any of your information. Kaspersky Labs determined that 17% of ransomware victims never recovered their information even after having sent off the ransom, resulting in additional losses. The gamble is also very costly. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom demand can reach millions. The other path is to re-install the mission-critical parts of your IT environment. Without access to full information backups, this calls for a wide complement of IT skills, professional project management, and the capability to work 24x7 until the recovery project is finished.

For twenty years, Progent has provided expert Information Technology services for companies throughout the US and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes professionals who have earned advanced certifications in leading technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity engineers have garnered internationally-recognized industry certifications including CISA, CISSP, CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has experience with financial management and ERP application software. This breadth of expertise affords Progent the capability to quickly ascertain necessary systems and consolidate the surviving components of your Information Technology environment following a crypto-ransomware attack and rebuild them into a functioning network.

Progent's security group uses best of breed project management applications to orchestrate the complex recovery process. Progent understands the importance of working swiftly and together with a client's management and Information Technology team members to prioritize tasks and to get key services back online as soon as humanly possible.

Case Study: A Successful Ransomware Incident Response
A business engaged Progent after their network was crashed by Ryuk ransomware. Ryuk is generally considered to have been created by North Korean state hackers, suspected of adopting techniques exposed from the United States NSA organization. Ryuk attacks specific businesses with little or no tolerance for disruption and is among the most profitable iterations of ransomware malware. Major organizations include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a regional manufacturing company located in Chicago with around 500 workers. The Ryuk intrusion had shut down all essential operations and manufacturing capabilities. The majority of the client's system backups had been directly accessible at the beginning of the intrusion and were encrypted. The client was pursuing financing for paying the ransom (exceeding two hundred thousand dollars) and praying for good luck, but ultimately brought in Progent.


"I can't thank you enough in regards to the expertise Progent gave us throughout the most fearful time of (our) company's life. We would have paid the hackers behind this attack if not for the confidence the Progent group provided us. That you could get our messaging and essential servers back into operation faster than one week was earth shattering. Each expert I got help from or communicated with at Progent was hell bent on getting us back online and was working 24 by 7 to bail us out."

Progent worked hand in hand the customer to rapidly identify and assign priority to the mission critical areas that had to be addressed to make it possible to resume business functions:

  • Active Directory
  • Email
  • Financials/MRP
To begin, Progent adhered to Anti-virus event response best practices by stopping the spread and cleaning systems of viruses. Progent then started the steps of restoring Microsoft Active Directory, the heart of enterprise systems built on Microsoft technology. Exchange messaging will not function without AD, and the client's financials and MRP system used Microsoft SQL, which needs Active Directory services for access to the data.

In less than 2 days, Progent was able to restore Active Directory services to its pre-penetration state. Progent then completed reinstallations and storage recovery on critical applications. All Exchange data and configuration information were intact, which facilitated the rebuild of Exchange. Progent was also able to locate intact OST files (Outlook Email Offline Folder Files) on user PCs to recover email data. A recent offline backup of the client's accounting systems made them able to recover these essential services back on-line. Although a lot of work remained to recover totally from the Ryuk attack, critical systems were recovered rapidly:


"For the most part, the production line operation was never shut down and we made all customer sales."

Throughout the following few weeks important milestones in the recovery project were completed through close collaboration between Progent team members and the customer:

  • Self-hosted web applications were restored with no loss of information.
  • The MailStore Server exceeding 4 million historical messages was brought online and accessible to users.
  • CRM/Orders/Invoicing/Accounts Payable (AP)/Accounts Receivables (AR)/Inventory Control functions were fully recovered.
  • A new Palo Alto 850 firewall was brought on-line.
  • Nearly all of the user PCs were operational.

"Much of what went on that first week is mostly a blur for me, but my management will not soon forget the care all of the team accomplished to help get our company back. I've been working together with Progent for the past 10 years, maybe more, and every time Progent has outperformed my expectations and delivered as promised. This event was a Herculean accomplishment."

Conclusion
A possible business disaster was evaded with dedicated professionals, a wide range of technical expertise, and tight collaboration. Although upon completion of forensics the ransomware incident described here should have been blocked with advanced security technology solutions and NIST Cybersecurity Framework or ISO/IEC 27001 best practices, user and IT administrator education, and well thought out security procedures for information backup and proper patching controls, the fact is that state-sponsored criminal cyber gangs from Russia, North Korea and elsewhere are tireless and are an ongoing threat. If you do fall victim to a ransomware incursion, remember that Progent's roster of experts has extensive experience in crypto-ransomware virus defense, mitigation, and information systems restoration.


"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others that were helping), thank you for letting me get some sleep after we got past the initial fire. Everyone did an fabulous effort, and if anyone that helped is in the Chicago area, a great meal is the least I can do!"

Download the Ransomware Remediation Case Study Datasheet
To review or download a PDF version of this customer case study, click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware System Restoration Services in Hayward
For ransomware system recovery services in the Hayward metro area, phone Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.