Ransomware : Your Worst Information Technology Catastrophe
Ransomware  Recovery ExpertsCrypto-Ransomware has become an escalating cyberplague that represents an extinction-level threat for businesses of all sizes unprepared for an attack. Different versions of crypto-ransomware like the Reveton, WannaCry, Locky, Syskey and MongoLock cryptoworms have been running rampant for a long time and continue to inflict havoc. Modern versions of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Nephilim, along with additional unnamed newcomers, not only encrypt on-line data but also infect many accessible system restores and backups. Information replicated to cloud environments can also be encrypted. In a poorly architected data protection solution, it can render any restore operations hopeless and basically knocks the entire system back to square one.

Getting back programs and information after a crypto-ransomware intrusion becomes a sprint against time as the targeted business struggles to contain, remove the ransomware, and resume mission-critical activity. Since ransomware requires time to move laterally across a network, assaults are often launched on weekends and holidays, when penetrations typically take longer to uncover. This multiplies the difficulty of quickly assembling and orchestrating an experienced response team.

Progent has a range of support services for protecting Webster enterprises from crypto-ransomware attacks. These include team member training to help identify and not fall victim to phishing scams, ProSight Active Security Monitoring for endpoint detection and response using SentinelOne's AI-based threat protection to identify and extinguish zero-day malware attacks. Progent in addition provides the assistance of experienced ransomware recovery engineers with the talent and commitment to rebuild a breached environment as urgently as possible.

Progent's Ransomware Restoration Support Services
Following a ransomware penetration, paying the ransom demands in cryptocurrency does not ensure that criminal gangs will provide the keys to decrypt any of your files. Kaspersky Labs determined that 17% of ransomware victims never recovered their information after having sent off the ransom, resulting in additional losses. The risk is also costly. Ryuk ransoms are typically a few hundred thousand dollars. For larger enterprises, the ransom demand can reach millions of dollars. The alternative is to re-install the key parts of your Information Technology environment. Without the availability of full information backups, this calls for a wide range of skills, top notch team management, and the willingness to work non-stop until the task is over.

For two decades, Progent has made available professional Information Technology services for companies throughout the United States and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes consultants who have been awarded advanced certifications in important technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cybersecurity consultants have garnered internationally-recognized industry certifications including CISA, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has expertise in financial management and ERP applications. This breadth of expertise affords Progent the skills to knowledgably determine important systems and consolidate the remaining parts of your network environment after a ransomware penetration and rebuild them into a functioning system.

Progent's security team utilizes powerful project management systems to coordinate the sophisticated recovery process. Progent understands the importance of working swiftly and in unison with a customer's management and Information Technology team members to assign priority to tasks and to put essential services back on line as fast as humanly possible.

Case Study: A Successful Ransomware Penetration Recovery
A client escalated to Progent after their organization was brought down by Ryuk crypto-ransomware. Ryuk is generally considered to have been launched by North Korean state criminal gangs, possibly adopting technology leaked from the U.S. NSA organization. Ryuk attacks specific organizations with limited room for operational disruption and is one of the most lucrative iterations of crypto-ransomware. High publicized targets include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a regional manufacturing business based in the Chicago metro area and has about 500 employees. The Ryuk attack had paralyzed all business operations and manufacturing capabilities. Most of the client's backups had been online at the beginning of the intrusion and were encrypted. The client was actively seeking loans for paying the ransom (more than two hundred thousand dollars) and praying for good luck, but in the end made the decision to use Progent.


"I can't thank you enough about the expertise Progent provided us during the most fearful time of (our) company's survival. We had little choice but to pay the cyber criminals behind the attack if it wasn't for the confidence the Progent experts afforded us. That you were able to get our e-mail and production servers back in less than 1 week was something I thought impossible. Every single expert I spoke to or texted at Progent was hell bent on getting us working again and was working all day and night to bail us out."

Progent worked hand in hand the client to rapidly assess and prioritize the mission critical services that needed to be addressed in order to continue departmental operations:

  • Active Directory
  • E-Mail
  • Financials/MRP
To get going, Progent adhered to Anti-virus incident response best practices by halting lateral movement and removing active viruses. Progent then began the process of restoring Microsoft AD, the key technology of enterprise networks built on Microsoft Windows technology. Microsoft Exchange Server email will not work without AD, and the customer's MRP software used Microsoft SQL, which needs Active Directory services for security authorization to the databases.

Within 48 hours, Progent was able to restore Active Directory to its pre-penetration state. Progent then assisted with reinstallations and storage recovery on mission critical servers. All Exchange schema and attributes were intact, which accelerated the restore of Exchange. Progent was also able to find local OST data files (Outlook Email Offline Folder Files) on team desktop computers and laptops in order to recover email data. A not too old off-line backup of the customer's manufacturing software made them able to recover these essential programs back online. Although major work remained to recover completely from the Ryuk virus, essential services were recovered quickly:


"For the most part, the production operation ran fairly normal throughout and we produced all customer sales."

Throughout the next month critical milestones in the restoration project were achieved in close collaboration between Progent team members and the customer:

  • In-house web applications were brought back up with no loss of data.
  • The MailStore Microsoft Exchange Server exceeding 4 million historical messages was brought on-line and available for users.
  • CRM/Orders/Invoicing/AP/Accounts Receivables/Inventory Control modules were 100% restored.
  • A new Palo Alto Networks 850 security appliance was brought online.
  • Most of the user PCs were functioning as before the incident.

"A huge amount of what was accomplished those first few days is nearly entirely a blur for me, but my team will not soon forget the commitment each of your team accomplished to help get our business back. I have utilized Progent for the past ten years, possibly more, and every time I needed help Progent has outperformed my expectations and delivered. This time was a stunning achievement."

Conclusion
A likely business-ending catastrophe was evaded through the efforts of top-tier experts, a broad range of technical expertise, and tight teamwork. Although in post mortem the ransomware virus penetration detailed here would have been identified and disabled with modern cyber security technology and ISO/IEC 27001 best practices, staff training, and appropriate security procedures for information backup and applying software patches, the fact is that government-sponsored hackers from Russia, North Korea and elsewhere are relentless and will continue. If you do get hit by a ransomware virus, feel confident that Progent's team of experts has proven experience in crypto-ransomware virus defense, removal, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others that were contributing), thanks very much for making it so I could get rested after we made it past the most critical parts. Everyone did an fabulous effort, and if any of your guys is around the Chicago area, dinner is the least I can do!"

Download the Ransomware Remediation Case Study Datasheet
To read or download a PDF version of this case study, click:
Progent's Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Services in Webster
For ransomware cleanup expertise in the Webster area, call Progent at 800-462-8800 or see Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.