Ransomware : Your Crippling Information Technology Nightmare
Ransomware  Recovery ConsultantsRansomware has become an escalating cyber pandemic that poses an enterprise-level danger for businesses poorly prepared for an assault. Different versions of crypto-ransomware such as CryptoLocker, Fusob, Bad Rabbit, Syskey and MongoLock cryptoworms have been running rampant for years and continue to inflict destruction. More recent variants of ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Nephilim, as well as more as yet unnamed viruses, not only perform encryption of online information but also infect most configured system protection. Data synchronized to off-premises disaster recovery sites can also be rendered useless. In a vulnerable environment, it can render any restore operations impossible and basically knocks the entire system back to square one.

Getting back online applications and data following a ransomware intrusion becomes a sprint against time as the victim tries its best to contain the damage, eradicate the ransomware, and resume enterprise-critical operations. Since ransomware needs time to spread across a network, assaults are usually sprung during weekends and nights, when penetrations may take longer to recognize. This compounds the difficulty of quickly mobilizing and orchestrating a capable response team.

Progent makes available an assortment of help services for securing Manhattan Beach organizations from ransomware attacks. These include user education to help recognize and not fall victim to phishing exploits, ProSight Active Security Monitoring for endpoint detection and response utilizing SentinelOne's AI-based threat defense to identify and suppress zero-day malware attacks. Progent in addition provides the services of experienced ransomware recovery professionals with the skills and commitment to re-deploy a breached network as soon as possible.

Progent's Crypto-Ransomware Recovery Support Services
After a ransomware event, paying the ransom in cryptocurrency does not ensure that merciless criminals will return the keys to decrypt any or all of your information. Kaspersky Labs estimated that 17% of ransomware victims never recovered their data even after having sent off the ransom, resulting in additional losses. The gamble is also expensive. Ryuk ransoms are typically several hundred thousand dollars. For larger organizations, the ransom can be in the millions. The alternative is to piece back together the critical components of your IT environment. Without access to complete system backups, this requires a broad complement of skill sets, top notch project management, and the willingness to work non-stop until the task is complete.

For twenty years, Progent has offered certified expert IT services for companies throughout the United States and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes consultants who have attained top industry certifications in leading technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity consultants have earned internationally-renowned industry certifications including CISM, CISSP-ISSAP, ISACA CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has expertise in accounting and ERP applications. This breadth of experience provides Progent the ability to knowledgably understand important systems and organize the surviving components of your Information Technology system following a ransomware attack and configure them into an operational system.

Progent's recovery team deploys best of breed project management systems to orchestrate the complicated restoration process. Progent understands the importance of working swiftly and in concert with a client's management and IT team members to prioritize tasks and to get key applications back on-line as soon as humanly possible.

Client Story: A Successful Crypto-Ransomware Intrusion Response
A business escalated to Progent after their organization was crashed by the Ryuk ransomware. Ryuk is thought to have been created by North Korean government sponsored cybercriminals, suspected of using techniques leaked from America's National Security Agency. Ryuk attacks specific organizations with little tolerance for operational disruption and is among the most lucrative incarnations of crypto-ransomware. Well Known victims include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a single-location manufacturer based in the Chicago metro area with around 500 employees. The Ryuk event had shut down all essential operations and manufacturing processes. Most of the client's system backups had been directly accessible at the time of the intrusion and were eventually encrypted. The client was evaluating paying the ransom demand (more than $200K) and wishfully thinking for the best, but ultimately engaged Progent.


"I cannot thank you enough about the care Progent provided us throughout the most stressful time of (our) company's survival. We may have had to pay the cybercriminals if it wasn't for the confidence the Progent team provided us. The fact that you could get our messaging and critical applications back into operation quicker than five days was incredible. Every single expert I spoke to or texted at Progent was amazingly focused on getting our system up and was working at all hours to bail us out."

Progent worked together with the client to rapidly understand and prioritize the critical areas that had to be recovered in order to resume business operations:

  • Active Directory
  • Email
  • Accounting and Manufacturing Software
To begin, Progent adhered to Anti-virus penetration mitigation industry best practices by halting lateral movement and cleaning systems of viruses. Progent then started the task of bringing back online Microsoft AD, the heart of enterprise environments built upon Microsoft Windows Server technology. Microsoft Exchange Server email will not work without Active Directory, and the client's financials and MRP system utilized SQL Server, which depends on Active Directory for security authorization to the information.

In less than 2 days, Progent was able to restore Windows Active Directory to its pre-attack state. Progent then charged ahead with setup and hard drive recovery on mission critical servers. All Exchange ties and attributes were intact, which accelerated the rebuild of Exchange. Progent was able to assemble intact OST data files (Microsoft Outlook Off-Line Folder Files) on team PCs to recover mail messages. A recent offline backup of the businesses accounting/MRP software made them able to restore these required programs back available to users. Although significant work was left to recover completely from the Ryuk virus, core services were restored quickly:


"For the most part, the manufacturing operation ran fairly normal throughout and we delivered all customer deliverables."

During the following month important milestones in the restoration process were made in close collaboration between Progent engineers and the client:

  • Self-hosted web applications were brought back up without losing any information.
  • The MailStore Exchange Server with over four million historical emails was brought on-line and accessible to users.
  • CRM/Customer Orders/Invoices/AP/Accounts Receivables/Inventory Control functions were completely operational.
  • A new Palo Alto Networks 850 firewall was brought online.
  • Nearly all of the user desktops and notebooks were functioning as before the incident.

"So much of what occurred in the initial days is mostly a haze for me, but our team will not forget the care each of your team put in to give us our business back. I have trusted Progent for at least 10 years, maybe more, and every time I needed help Progent has outperformed my expectations and delivered as promised. This event was a testament to your capabilities."

Conclusion
A possible business catastrophe was averted with top-tier experts, a broad range of IT skills, and tight teamwork. Although in retrospect the ransomware virus attack detailed here should have been disabled with advanced cyber security technology and recognized best practices, user and IT administrator training, and well designed incident response procedures for information backup and keeping systems up to date with security patches, the fact is that government-sponsored cyber criminals from China, North Korea and elsewhere are tireless and represent an ongoing threat. If you do get hit by a ransomware incursion, feel confident that Progent's roster of experts has substantial experience in crypto-ransomware virus defense, mitigation, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others that were involved), thanks very much for letting me get rested after we got through the initial push. Everyone did an fabulous effort, and if any of your team is visiting the Chicago area, a great meal is on me!"

Download the Crypto-Ransomware Cleanup Case Study Datasheet
To read or download a PDF version of this customer story, please click:
Progent's Crypto-Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting in Manhattan Beach
For ransomware system recovery consulting services in the Manhattan Beach area, phone Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.