Ransomware : Your Crippling Information Technology Nightmare
Ransomware has become an escalating cyber pandemic that poses an enterprise-level danger for businesses poorly prepared for an assault. Different versions of crypto-ransomware such as CryptoLocker, Fusob, Bad Rabbit, Syskey and MongoLock cryptoworms have been running rampant for years and continue to inflict destruction. More recent variants of ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Nephilim, as well as more as yet unnamed viruses, not only perform encryption of online information but also infect most configured system protection. Data synchronized to off-premises disaster recovery sites can also be rendered useless. In a vulnerable environment, it can render any restore operations impossible and basically knocks the entire system back to square one.
Getting back online applications and data following a ransomware intrusion becomes a sprint against time as the victim tries its best to contain the damage, eradicate the ransomware, and resume enterprise-critical operations. Since ransomware needs time to spread across a network, assaults are usually sprung during weekends and nights, when penetrations may take longer to recognize. This compounds the difficulty of quickly mobilizing and orchestrating a capable response team.
Progent makes available an assortment of help services for securing Manhattan Beach organizations from ransomware attacks. These include user education to help recognize and not fall victim to phishing exploits, ProSight Active Security Monitoring for endpoint detection and response utilizing SentinelOne's AI-based threat defense to identify and suppress zero-day malware attacks. Progent in addition provides the services of experienced ransomware recovery professionals with the skills and commitment to re-deploy a breached network as soon as possible.
Progent's Crypto-Ransomware Recovery Support Services
After a ransomware event, paying the ransom in cryptocurrency does not ensure that merciless criminals will return the keys to decrypt any or all of your information. Kaspersky Labs estimated that 17% of ransomware victims never recovered their data even after having sent off the ransom, resulting in additional losses. The gamble is also expensive. Ryuk ransoms are typically several hundred thousand dollars. For larger organizations, the ransom can be in the millions. The alternative is to piece back together the critical components of your IT environment. Without access to complete system backups, this requires a broad complement of skill sets, top notch project management, and the willingness to work non-stop until the task is complete.
For twenty years, Progent has offered certified expert IT services for companies throughout the United States and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes consultants who have attained top industry certifications in leading technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity consultants have earned internationally-renowned industry certifications including CISM, CISSP-ISSAP, ISACA CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has expertise in accounting and ERP applications. This breadth of experience provides Progent the ability to knowledgably understand important systems and organize the surviving components of your Information Technology system following a ransomware attack and configure them into an operational system.
Progent's recovery team deploys best of breed project management systems to orchestrate the complicated restoration process. Progent understands the importance of working swiftly and in concert with a client's management and IT team members to prioritize tasks and to get key applications back on-line as soon as humanly possible.
Client Story: A Successful Crypto-Ransomware Intrusion Response
A business escalated to Progent after their organization was crashed by the Ryuk ransomware. Ryuk is thought to have been created by North Korean government sponsored cybercriminals, suspected of using techniques leaked from America's National Security Agency. Ryuk attacks specific organizations with little tolerance for operational disruption and is among the most lucrative incarnations of crypto-ransomware. Well Known victims include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a single-location manufacturer based in the Chicago metro area with around 500 employees. The Ryuk event had shut down all essential operations and manufacturing processes. Most of the client's system backups had been directly accessible at the time of the intrusion and were eventually encrypted. The client was evaluating paying the ransom demand (more than $200K) and wishfully thinking for the best, but ultimately engaged Progent.
Progent worked together with the client to rapidly understand and prioritize the critical areas that had to be recovered in order to resume business operations:
In less than 2 days, Progent was able to restore Windows Active Directory to its pre-attack state. Progent then charged ahead with setup and hard drive recovery on mission critical servers. All Exchange ties and attributes were intact, which accelerated the rebuild of Exchange. Progent was able to assemble intact OST data files (Microsoft Outlook Off-Line Folder Files) on team PCs to recover mail messages. A recent offline backup of the businesses accounting/MRP software made them able to restore these required programs back available to users. Although significant work was left to recover completely from the Ryuk virus, core services were restored quickly:
During the following month important milestones in the restoration process were made in close collaboration between Progent engineers and the client:
Conclusion
A possible business catastrophe was averted with top-tier experts, a broad range of IT skills, and tight teamwork. Although in retrospect the ransomware virus attack detailed here should have been disabled with advanced cyber security technology and recognized best practices, user and IT administrator training, and well designed incident response procedures for information backup and keeping systems up to date with security patches, the fact is that government-sponsored cyber criminals from China, North Korea and elsewhere are tireless and represent an ongoing threat. If you do get hit by a ransomware incursion, feel confident that Progent's roster of experts has substantial experience in crypto-ransomware virus defense, mitigation, and information systems disaster recovery.
Download the Crypto-Ransomware Cleanup Case Study Datasheet
To read or download a PDF version of this customer story, please click:
Progent's Crypto-Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Cleanup Consulting in Manhattan Beach
For ransomware system recovery consulting services in the Manhattan Beach area, phone Progent at