Ransomware : Your Crippling Information Technology Catastrophe
Ransomware  Recovery ConsultantsRansomware has become an escalating cyberplague that represents an existential threat for businesses of all sizes poorly prepared for an attack. Versions of ransomware such as CrySIS, CryptoWall, Locky, SamSam and MongoLock cryptoworms have been out in the wild for years and continue to cause havoc. Newer variants of crypto-ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, LockBit and Nephilim, plus more as yet unnamed malware, not only perform encryption of on-line information but also infiltrate most configured system protection. Data synchronized to cloud environments can also be encrypted. In a poorly designed data protection solution, this can render automated restoration impossible and basically sets the entire system back to zero.

Restoring applications and information after a crypto-ransomware intrusion becomes a sprint against time as the targeted organization fights to contain, eradicate the virus, and resume mission-critical operations. Due to the fact that ransomware requires time to replicate across a network, assaults are often sprung at night, when successful attacks are likely to take more time to recognize. This compounds the difficulty of quickly mobilizing and orchestrating a capable response team.

Progent makes available a variety of solutions for securing Knoxville enterprises from ransomware penetrations. Among these are team member training to help recognize and avoid phishing exploits, ProSight Active Security Monitoring for endpoint detection and response (EDR) using SentinelOne's behavior-based cyberthreat protection to identify and extinguish zero-day malware attacks. Progent also can provide the assistance of expert ransomware recovery consultants with the talent and commitment to restore a compromised network as rapidly as possible.

Progent's Ransomware Recovery Support Services
Soon after a crypto-ransomware attack, sending the ransom demands in cryptocurrency does not ensure that criminal gangs will return the needed codes to unencrypt any or all of your files. Kaspersky determined that seventeen percent of ransomware victims never restored their information even after having paid the ransom, resulting in increased losses. The risk is also costly. Ryuk ransoms are often several hundred thousand dollars. For larger enterprises, the ransom demand can be in the millions of dollars. The other path is to setup from scratch the critical parts of your IT environment. Without the availability of full data backups, this requires a broad complement of skill sets, professional project management, and the ability to work 24x7 until the task is done.

For two decades, Progent has offered certified expert Information Technology services for companies across the US and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes engineers who have been awarded high-level industry certifications in important technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity specialists have garnered internationally-renowned industry certifications including CISA, CISSP-ISSAP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent in addition has expertise in financial systems and ERP applications. This breadth of expertise provides Progent the capability to quickly identify important systems and organize the remaining parts of your Information Technology environment following a ransomware penetration and rebuild them into a functioning network.

Progent's ransomware team of experts deploys best of breed project management systems to orchestrate the complicated restoration process. Progent appreciates the importance of acting swiftly and in concert with a customer's management and Information Technology staff to assign priority to tasks and to get essential systems back on-line as soon as humanly possible.

Business Case Study: A Successful Crypto-Ransomware Penetration Recovery
A customer engaged Progent after their network was penetrated by Ryuk crypto-ransomware. Ryuk is thought to have been developed by North Korean state cybercriminals, suspected of using techniques exposed from the United States National Security Agency. Ryuk seeks specific organizations with limited room for operational disruption and is one of the most profitable instances of ransomware viruses. Major targets include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's customer is a small manufacturing business located in the Chicago metro area with about 500 staff members. The Ryuk intrusion had frozen all essential operations and manufacturing capabilities. The majority of the client's information backups had been on-line at the beginning of the attack and were eventually encrypted. The client was pursuing financing for paying the ransom demand (in excess of $200,000) and hoping for the best, but in the end engaged Progent.


"I can't speak enough about the help Progent gave us during the most stressful period of (our) businesses existence. We most likely would have paid the cybercriminals except for the confidence the Progent experts provided us. The fact that you could get our e-mail system and production applications back online sooner than one week was incredible. Every single expert I got help from or e-mailed at Progent was absolutely committed on getting us working again and was working at all hours on our behalf."

Progent worked hand in hand the client to rapidly identify and prioritize the most important systems that needed to be addressed in order to restart company functions:

  • Active Directory
  • Exchange Server
  • Financials/MRP
To begin, Progent followed AV/Malware Processes incident response best practices by stopping the spread and cleaning up infected systems. Progent then initiated the process of restoring Windows Active Directory, the core of enterprise systems built on Microsoft Windows Server technology. Microsoft Exchange Server messaging will not function without Windows AD, and the client's financials and MRP applications leveraged SQL Server, which requires Active Directory services for authentication to the database.

Within two days, Progent was able to restore Active Directory to its pre-virus state. Progent then helped perform setup and hard drive recovery of the most important servers. All Exchange Server ties and attributes were intact, which facilitated the rebuild of Exchange. Progent was able to locate local OST data files (Microsoft Outlook Off-Line Folder Files) on various desktop computers and laptops in order to recover mail data. A recent off-line backup of the customer's accounting/MRP systems made them able to return these essential programs back online for users. Although significant work needed to be completed to recover totally from the Ryuk virus, core systems were recovered rapidly:


"For the most part, the manufacturing operation did not miss a beat and we made all customer orders."

Over the following couple of weeks key milestones in the recovery project were made in close cooperation between Progent engineers and the customer:

  • Internal web sites were restored without losing any information.
  • The MailStore Microsoft Exchange Server with over 4 million archived emails was brought online and available for users.
  • CRM/Orders/Invoices/Accounts Payable (AP)/AR/Inventory capabilities were 100 percent restored.
  • A new Palo Alto Networks 850 security appliance was installed.
  • Nearly all of the user desktops were being used by staff.

"Much of what transpired during the initial response is mostly a haze for me, but we will not soon forget the care each of your team accomplished to help get our company back. I have been working together with Progent for the past 10 years, possibly more, and each time I needed help Progent has impressed me and delivered. This time was a life saver."

Conclusion
A potential business extinction disaster was evaded due to dedicated experts, a wide range of subject matter expertise, and close teamwork. Although in hindsight the ransomware attack described here should have been identified and stopped with current cyber security solutions and best practices, team training, and appropriate security procedures for data backup and keeping systems up to date with security patches, the fact is that state-sponsored criminal cyber gangs from Russia, North Korea and elsewhere are relentless and are not going away. If you do get hit by a crypto-ransomware incident, remember that Progent's roster of professionals has a proven track record in crypto-ransomware virus blocking, mitigation, and file recovery.


"So, to Darrin, Aaron, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others who were involved), I'm grateful for letting me get some sleep after we got over the initial fire. Everyone did an impressive job, and if any of your guys is around the Chicago area, dinner is the least I can do!"

Download the Ransomware Removal Case Study Datasheet
To review or download a PDF version of this customer case study, please click:
Progent's Crypto-Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware System Restoration Consulting in Knoxville
For ransomware system restoration services in the Knoxville area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.