Overview of Progent's Ransomware Forensics and Reporting Services in Lower Manhattan
Progent's ransomware forensics consultants can preserve the evidence of a ransomware attack and perform a comprehensive forensics investigation without interfering with activity related to operational continuity and data restoration. Your Lower Manhattan business can use Progent's post-attack forensics report to counter future ransomware attacks, assist in the recovery of lost data, and comply with insurance carrier and regulatory requirements.
Ransomware forensics investigation is aimed at tracking and describing the ransomware assault's storyline across the targeted network from start to finish. This history of the way a ransomware attack progressed through the network helps you to evaluate the damage and highlights gaps in security policies or processes that need to be corrected to avoid future break-ins. Forensic analysis is typically assigned a high priority by the insurance carrier and is typically mandated by state and industry regulations. Since forensic analysis can take time, it is critical that other key recovery processes such as business continuity are executed concurrently. Progent has a large team of information technology and data security professionals with the knowledge and experience required to carry out the work of containment, operational resumption, and data recovery without disrupting forensic analysis.
Ransomware forensics analysis is arduous and requires intimate cooperation with the groups responsible for file restoration and, if necessary, settlement discussions with the ransomware attacker. Ransomware forensics typically involve the review of logs, registry, GPO, Active Directory (AD), DNS servers, routers, firewalls, schedulers, and basic Windows systems to check for changes.
Services involved with forensics analysis include:
- Detach but avoid shutting down all possibly suspect devices from the system. This may involve closing all RDP ports and Internet connected network-attached storage, changing admin credentials and user passwords, and implementing 2FA to protect your backups.
- Capture forensically valid digital images of all suspect devices so your data restoration team can proceed
- Save firewall, VPN, and other critical logs as soon as possible
- Identify the variety of ransomware used in the assault
- Examine each computer and data store on the system including cloud storage for indications of encryption
- Catalog all compromised devices
- Establish the type of ransomware involved in the attack
- Review log activity and user sessions to establish the time frame of the ransomware attack and to identify any possible lateral movement from the originally infected machine
- Identify the security gaps exploited to perpetrate the ransomware assault
- Search for new executables surrounding the original encrypted files or network breach
- Parse Outlook PST files
- Examine email attachments
- Separate any URLs from messages and determine if they are malicious
- Produce detailed attack documentation to satisfy your insurance and compliance regulations
- List recommended improvements to close cybersecurity gaps and enforce processes that lower the risk of a future ransomware breach
Progent's Qualifications
Progent has delivered online and onsite network services throughout the U.S. for over 20 years and has earned Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's roster of subject matter experts includes professionals who have been awarded advanced certifications in foundation technology platforms including Cisco infrastructure, VMware, and major Linux distros. Progent's data security experts have earned internationally recognized certifications including CISA, CISSP-ISSAP, and CRISC. (Refer to certifications earned by Progent consultants). Progent also offers guidance in financial management and ERP software. This breadth of skills gives Progent the ability to salvage and consolidate the undamaged pieces of your information system after a ransomware assault and reconstruct them rapidly into a viable system. Progent has worked with leading insurance carriers like Chubb to help organizations clean up after ransomware assaults.
Contact Progent about Ransomware Forensics Expertise in Lower Manhattan
To find out more about how Progent can help your Lower Manhattan organization with ransomware forensics analysis, call 1-800-462-8800 or visit Contact Progent.