Ransomware : Your Worst Information Technology Nightmare
Ransomware  Recovery ExpertsRansomware has become an escalating cyber pandemic that poses an extinction-level danger for businesses of all sizes vulnerable to an attack. Multiple generations of ransomware such as Dharma, CryptoWall, Locky, Syskey and MongoLock cryptoworms have been out in the wild for many years and continue to cause damage. Modern variants of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Nephilim, as well as frequent as yet unnamed newcomers, not only perform encryption of on-line data but also infiltrate all configured system backups. Files synchronized to the cloud can also be rendered useless. In a vulnerable system, this can make automatic restoration useless and basically sets the datacenter back to square one.

Restoring programs and data after a ransomware intrusion becomes a race against time as the targeted business struggles to stop lateral movement, eradicate the crypto-ransomware, and restore business-critical operations. Due to the fact that crypto-ransomware requires time to move laterally across a network, assaults are frequently launched during weekends and nights, when successful penetrations may take longer to recognize. This compounds the difficulty of rapidly assembling and orchestrating an experienced mitigation team.

Progent makes available a variety of help services for protecting Vitória enterprises from ransomware attacks. These include team member training to become familiar with and not fall victim to phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response utilizing SentinelOne's behavior-based cyberthreat protection to detect and extinguish day-zero modern malware attacks. Progent in addition provides the assistance of seasoned crypto-ransomware recovery engineers with the talent and perseverance to re-deploy a breached network as soon as possible.

Progent's Ransomware Recovery Services
Subsequent to a crypto-ransomware invasion, sending the ransom demands in cryptocurrency does not ensure that cyber hackers will return the needed keys to decipher any of your information. Kaspersky Labs estimated that 17% of crypto-ransomware victims never restored their information after having sent off the ransom, resulting in more losses. The gamble is also costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger enterprises, the ransom can be in the millions. The other path is to piece back together the critical elements of your IT environment. Without the availability of full data backups, this calls for a wide complement of IT skills, top notch team management, and the ability to work non-stop until the task is over.

For twenty years, Progent has made available certified expert IT services for businesses throughout the US and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes consultants who have attained high-level certifications in important technologies including Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security consultants have earned internationally-renowned certifications including CISA, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has experience in financial management and ERP applications. This breadth of experience provides Progent the skills to quickly determine critical systems and consolidate the remaining pieces of your Information Technology system after a ransomware event and configure them into an operational system.

Progent's recovery team of experts utilizes state-of-the-art project management tools to coordinate the sophisticated restoration process. Progent appreciates the urgency of working rapidly and in unison with a customer's management and Information Technology staff to assign priority to tasks and to put critical applications back online as fast as possible.

Customer Case Study: A Successful Crypto-Ransomware Attack Restoration
A small business contacted Progent after their network system was crashed by Ryuk ransomware virus. Ryuk is thought to have been launched by North Korean state criminal gangs, suspected of adopting algorithms leaked from America's NSA organization. Ryuk targets specific organizations with little tolerance for disruption and is one of the most lucrative incarnations of ransomware. Major victims include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a small manufacturer based in Chicago with around 500 employees. The Ryuk event had brought down all essential operations and manufacturing capabilities. The majority of the client's information backups had been on-line at the beginning of the attack and were destroyed. The client was pursuing financing for paying the ransom (more than $200K) and praying for good luck, but in the end utilized Progent.


"I cannot thank you enough in regards to the expertise Progent provided us throughout the most critical period of (our) company's existence. We would have paid the criminal gangs if not for the confidence the Progent experts afforded us. The fact that you could get our messaging and critical applications back online in less than one week was beyond my wildest dreams. Every single consultant I spoke to or e-mailed at Progent was hell bent on getting us operational and was working all day and night on our behalf."

Progent worked with the customer to quickly understand and assign priority to the mission critical services that had to be restored in order to restart business functions:

  • Microsoft Active Directory
  • Exchange Server
  • Financials/MRP
To get going, Progent followed ransomware event response industry best practices by stopping lateral movement and disinfecting systems. Progent then started the work of recovering Microsoft AD, the heart of enterprise networks built upon Microsoft Windows technology. Exchange messaging will not function without Windows AD, and the customer's financials and MRP software utilized SQL Server, which depends on Windows AD for security authorization to the data.

Within two days, Progent was able to rebuild Active Directory to its pre-penetration state. Progent then charged ahead with reinstallations and storage recovery on key servers. All Exchange Server ties and attributes were usable, which greatly helped the restore of Exchange. Progent was able to assemble intact OST files (Outlook Offline Data Files) on staff PCs and laptops to recover mail data. A recent off-line backup of the businesses accounting/ERP systems made them able to restore these required applications back online for users. Although a large amount of work needed to be completed to recover totally from the Ryuk event, core systems were restored rapidly:


"For the most part, the manufacturing operation showed little impact and we did not miss any customer sales."

Throughout the next couple of weeks critical milestones in the recovery project were completed in close collaboration between Progent consultants and the client:

  • Internal web applications were restored without losing any data.
  • The MailStore Server with over 4 million archived emails was brought online and available for users.
  • CRM/Customer Orders/Invoices/Accounts Payable/AR/Inventory capabilities were fully functional.
  • A new Palo Alto Networks 850 security appliance was installed.
  • Most of the user desktops were operational.

"A lot of what was accomplished those first few days is mostly a fog for me, but we will not forget the dedication all of you accomplished to give us our company back. I've entrusted Progent for the past ten years, possibly more, and each time I needed help Progent has come through and delivered as promised. This situation was a stunning achievement."

Conclusion
A potential business extinction disaster was avoided due to dedicated experts, a wide range of technical expertise, and tight teamwork. Although upon completion of forensics the ransomware penetration described here could have been identified and prevented with up-to-date cyber security technology and NIST Cybersecurity Framework best practices, staff training, and well designed incident response procedures for information protection and applying software patches, the reality remains that government-sponsored cyber criminals from Russia, North Korea and elsewhere are relentless and represent an ongoing threat. If you do fall victim to a crypto-ransomware incident, remember that Progent's team of professionals has substantial experience in ransomware virus defense, removal, and data recovery.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others that were contributing), thank you for allowing me to get rested after we got over the first week. All of you did an impressive job, and if any of your team is around the Chicago area, a great meal is on me!"

Download the Ransomware Remediation Case Study Datasheet
To review or download a PDF version of this customer case study, click:
Progent's Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Consulting in Vitória
For ransomware system recovery services in the Vitória metro area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.