Progent's Ransomware Forensics Investigation and Reporting in Petaluma
Progent's ransomware forensics consultants can save the system state after a ransomware assault and carry out a detailed forensics analysis without disrupting activity required for business resumption and data restoration. Your Petaluma business can utilize Progent's post-attack forensics documentation to combat subsequent ransomware assaults, assist in the restoration of lost data, and meet insurance and regulatory reporting requirements.
Ransomware forensics analysis involves tracking and documenting the ransomware attack's storyline throughout the network from start to finish. This history of how a ransomware attack travelled through the network helps you to assess the impact and brings to light vulnerabilities in security policies or processes that should be rectified to avoid later breaches. Forensic analysis is typically assigned a high priority by the cyber insurance carrier and is typically required by government and industry regulations. Since forensic analysis can be time consuming, it is vital that other key recovery processes such as operational resumption are pursued in parallel. Progent maintains an extensive roster of IT and data security professionals with the knowledge and experience required to carry out activities for containment, operational continuity, and data restoration without interfering with forensics.
Ransomware forensics analysis is time consuming and calls for close interaction with the teams responsible for file cleanup and, if necessary, settlement negotiation with the ransomware threat actor. Ransomware forensics typically involve the review of all logs, registry, Group Policy Object (GPO), AD, DNS servers, routers, firewalls, scheduled tasks, and basic Windows systems to look for changes.
Services involved with forensics investigation include:
- Disconnect without shutting down all potentially impacted devices from the network. This may require closing all Remote Desktop Protocol (RDP) ports and Internet connected network-attached storage, changing admin credentials and user PWs, and setting up two-factor authentication to protect backups.
- Copy forensically complete duplicates of all suspect devices so the data recovery team can proceed
- Preserve firewall, VPN, and other critical logs as quickly as possible
- Determine the strain of ransomware used in the attack
- Examine each computer and storage device on the network as well as cloud storage for indications of compromise
- Catalog all encrypted devices
- Establish the kind of ransomware involved in the assault
- Review log activity and user sessions in order to establish the time frame of the attack and to identify any potential lateral migration from the originally infected machine
- Identify the security gaps used to carry out the ransomware attack
- Search for new executables associated with the first encrypted files or system breach
- Parse Outlook web archives
- Analyze attachments
- Extract any URLs embedded in messages and determine whether they are malware
- Provide extensive incident reporting to meet your insurance carrier and compliance requirements
- Document recommended improvements to close cybersecurity vulnerabilities and improve workflows that reduce the exposure to a future ransomware exploit
Progent's Qualifications
Progent has delivered online and onsite IT services across the U.S. for more than 20 years and has earned Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's team of subject matter experts includes professionals who have been awarded advanced certifications in core technologies including Cisco networking, VMware, and popular distributions of Linux. Progent's cybersecurity consultants have earned prestigious certifications such as CISA, CISSP, and GIAC. (See Progent's certifications). Progent also offers top-tier support in financial management and Enterprise Resource Planning applications. This breadth of expertise gives Progent the ability to identify and consolidate the undamaged pieces of your information system following a ransomware intrusion and reconstruct them quickly into a functioning network. Progent has collaborated with leading cyber insurance carriers like Chubb to help businesses recover from ransomware attacks.
Contact Progent about Ransomware Forensics Investigation Services in Petaluma
To learn more about ways Progent can help your Petaluma organization with ransomware forensics, call 1-800-462-8800 or visit Contact Progent.