Ransomware : Your Worst Information Technology Catastrophe
Ransomware  Remediation ExpertsRansomware has become a modern cyber pandemic that presents an extinction-level threat for organizations vulnerable to an assault. Different versions of ransomware such as CrySIS, Fusob, Bad Rabbit, SamSam and MongoLock cryptoworms have been out in the wild for years and continue to inflict destruction. More recent versions of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, LockBit and Nephilim, as well as frequent unnamed viruses, not only perform encryption of online data but also infect any accessible system backup. Information replicated to cloud environments can also be rendered useless. In a vulnerable environment, this can render any restore operations hopeless and basically knocks the datacenter back to square one.

Getting back online applications and data after a ransomware intrusion becomes a race against time as the targeted organization fights to contain, cleanup the virus, and restore mission-critical activity. Since ransomware needs time to replicate throughout a network, assaults are often launched on weekends and holidays, when attacks are likely to take more time to uncover. This multiplies the difficulty of quickly mobilizing and coordinating a qualified mitigation team.

Progent makes available a range of solutions for protecting Hialeah enterprises from crypto-ransomware events. These include user training to become familiar with and avoid phishing exploits, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based cyberthreat defense to identify and disable day-zero malware assaults. Progent in addition provides the services of veteran ransomware recovery consultants with the talent and perseverance to re-deploy a breached environment as rapidly as possible.

Progent's Ransomware Recovery Support Services
After a ransomware event, paying the ransom demands in cryptocurrency does not provide any assurance that distant criminals will return the needed codes to decrypt any or all of your data. Kaspersky Labs ascertained that 17% of ransomware victims never recovered their files even after having paid the ransom, resulting in more losses. The risk is also very costly. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom demand can be in the millions. The fallback is to re-install the vital components of your IT environment. Absent the availability of complete system backups, this requires a broad complement of skills, top notch team management, and the capability to work 24x7 until the job is over.

For two decades, Progent has provided professional IT services for businesses throughout the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes professionals who have earned advanced industry certifications in key technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity specialists have earned internationally-recognized certifications including CISM, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has experience in financial management and ERP application software. This breadth of experience affords Progent the skills to rapidly understand necessary systems and re-organize the surviving pieces of your network environment following a ransomware attack and rebuild them into a functioning system.

Progent's security team of experts utilizes state-of-the-art project management tools to orchestrate the complicated restoration process. Progent understands the urgency of working swiftly and in concert with a customer's management and IT team members to prioritize tasks and to get essential systems back on-line as fast as humanly possible.

Case Study: A Successful Ransomware Virus Recovery
A customer contacted Progent after their network system was brought down by Ryuk ransomware. Ryuk is generally considered to have been developed by North Korean state sponsored hackers, possibly using technology leaked from the United States National Security Agency. Ryuk attacks specific organizations with limited tolerance for operational disruption and is one of the most profitable examples of ransomware malware. Headline victims include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a regional manufacturing business located in Chicago with around 500 staff members. The Ryuk penetration had shut down all essential operations and manufacturing capabilities. Most of the client's data protection had been directly accessible at the time of the intrusion and were damaged. The client was pursuing financing for paying the ransom demand (more than $200,000) and hoping for good luck, but ultimately utilized Progent.


"I can't tell you enough about the care Progent gave us throughout the most fearful period of (our) businesses existence. We would have paid the cyber criminals behind the attack if not for the confidence the Progent group gave us. The fact that you were able to get our messaging and production servers back online in less than a week was something I thought impossible. Each consultant I worked with or e-mailed at Progent was laser focused on getting my company operational and was working at all hours to bail us out."

Progent worked with the client to rapidly determine and prioritize the most important applications that had to be recovered to make it possible to resume departmental operations:

  • Active Directory
  • Microsoft Exchange
  • Accounting and Manufacturing Software
To get going, Progent followed AV/Malware Processes event mitigation best practices by halting the spread and clearing infected systems. Progent then started the steps of bringing back online Microsoft AD, the foundation of enterprise networks built on Microsoft Windows Server technology. Exchange email will not operate without Active Directory, and the customer's accounting and MRP system utilized Microsoft SQL Server, which requires Active Directory for access to the information.

In less than 2 days, Progent was able to re-build Active Directory to its pre-penetration state. Progent then assisted with setup and hard drive recovery of the most important servers. All Exchange Server ties and attributes were intact, which accelerated the rebuild of Exchange. Progent was able to collect intact OST files (Outlook Email Offline Data Files) on user workstations to recover email information. A not too old offline backup of the businesses accounting/ERP software made them able to restore these essential programs back available to users. Although significant work was left to recover totally from the Ryuk virus, the most important services were recovered quickly:


"For the most part, the manufacturing operation showed little impact and we delivered all customer shipments."

Throughout the next month critical milestones in the restoration process were accomplished through tight cooperation between Progent consultants and the client:

  • In-house web sites were returned to operation with no loss of data.
  • The MailStore Microsoft Exchange Server containing more than four million historical emails was restored to operations and accessible to users.
  • CRM/Customer Orders/Invoices/Accounts Payable (AP)/AR/Inventory Control modules were completely restored.
  • A new Palo Alto 850 security appliance was installed and configured.
  • Nearly all of the user workstations were operational.

"Much of what occurred during the initial response is nearly entirely a blur for me, but we will not forget the urgency each and every one of you accomplished to give us our business back. I have been working together with Progent for at least 10 years, maybe more, and every time Progent has outperformed my expectations and delivered as promised. This time was a stunning achievement."

Conclusion
A probable enterprise-killing disaster was averted through the efforts of hard-working experts, a wide spectrum of technical expertise, and tight teamwork. Although upon completion of forensics the ransomware penetration detailed here could have been disabled with modern cyber security solutions and security best practices, team training, and well designed security procedures for data protection and proper patching controls, the reality is that government-sponsored cyber criminals from China, Russia, North Korea and elsewhere are tireless and are an ongoing threat. If you do get hit by a ransomware penetration, remember that Progent's roster of professionals has proven experience in ransomware virus blocking, cleanup, and file disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Jesse, Arnaud, Allen, Tony and Chris (along with others who were contributing), I'm grateful for making it so I could get some sleep after we made it over the initial push. Everyone did an amazing effort, and if anyone that helped is around the Chicago area, a great meal is on me!"

Download the Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this customer story, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Expertise in Hialeah
For ransomware cleanup consulting services in the Hialeah area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.