Ransomware : Your Crippling IT Disaster
Crypto-Ransomware  Recovery ExpertsRansomware has become an escalating cyberplague that represents an existential danger for businesses of all sizes poorly prepared for an assault. Different iterations of crypto-ransomware like the CryptoLocker, CryptoWall, Bad Rabbit, NotPetya and MongoLock cryptoworms have been circulating for many years and still inflict damage. Newer versions of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Nephilim, as well as additional as yet unnamed viruses, not only perform encryption of on-line data files but also infiltrate any accessible system restores and backups. Data synched to the cloud can also be ransomed. In a vulnerable environment, this can render any restore operations hopeless and basically knocks the entire system back to square one.

Getting back online applications and information after a crypto-ransomware attack becomes a race against time as the victim fights to stop lateral movement, eradicate the ransomware, and resume enterprise-critical operations. Since ransomware takes time to replicate across a network, assaults are frequently sprung on weekends, when penetrations tend to take longer to identify. This compounds the difficulty of rapidly assembling and orchestrating an experienced response team.

Progent provides a variety of support services for protecting Brisbane organizations from ransomware attacks. These include user training to help identify and not fall victim to phishing exploits, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) using SentinelOne's behavior-based cyberthreat defense to identify and quarantine day-zero modern malware attacks. Progent also provides the assistance of veteran crypto-ransomware recovery professionals with the talent and commitment to reconstruct a breached environment as quickly as possible.

Progent's Ransomware Recovery Services
After a ransomware penetration, sending the ransom in cryptocurrency does not provide any assurance that merciless criminals will respond with the needed codes to decrypt any or all of your files. Kaspersky determined that 17% of ransomware victims never restored their data even after having paid the ransom, resulting in additional losses. The risk is also very costly. Ryuk ransoms are often a few hundred thousand dollars. For larger enterprises, the ransom can reach millions. The other path is to re-install the vital elements of your IT environment. Absent access to complete data backups, this requires a broad range of skill sets, professional team management, and the willingness to work 24x7 until the job is completed.

For two decades, Progent has made available certified expert Information Technology services for companies across the United States and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes engineers who have earned high-level industry certifications in important technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security experts have garnered internationally-recognized certifications including CISA, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has expertise with financial management and ERP applications. This breadth of experience provides Progent the skills to rapidly identify important systems and integrate the remaining components of your computer network system following a ransomware penetration and rebuild them into a functioning system.

Progent's recovery team of experts utilizes state-of-the-art project management applications to orchestrate the sophisticated restoration process. Progent understands the urgency of working swiftly and in concert with a customer's management and IT resources to prioritize tasks and to put essential services back on-line as soon as possible.

Client Case Study: A Successful Ransomware Virus Recovery
A customer sought out Progent after their company was crashed by the Ryuk ransomware. Ryuk is thought to have been deployed by North Korean state sponsored cybercriminals, possibly adopting techniques exposed from America's NSA organization. Ryuk targets specific companies with limited ability to sustain operational disruption and is among the most lucrative incarnations of ransomware. Headline targets include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a single-location manufacturing business located in the Chicago metro area with around 500 employees. The Ryuk event had frozen all essential operations and manufacturing processes. The majority of the client's data backups had been on-line at the start of the attack and were eventually encrypted. The client considered paying the ransom (in excess of $200,000) and praying for the best, but in the end engaged Progent.


"I cannot say enough about the care Progent gave us during the most stressful period of (our) company's survival. We had little choice but to pay the cyber criminals behind the attack if not for the confidence the Progent experts afforded us. That you were able to get our e-mail system and important servers back on-line sooner than a week was earth shattering. Each expert I worked with or texted at Progent was urgently focused on getting my company operational and was working non-stop on our behalf."

Progent worked hand in hand the client to quickly get our arms around and prioritize the mission critical applications that had to be recovered in order to resume company operations:

  • Windows Active Directory
  • Email
  • Financials/MRP
To start, Progent followed Anti-virus event mitigation industry best practices by stopping lateral movement and removing active viruses. Progent then started the task of bringing back online Microsoft AD, the core of enterprise networks built on Microsoft Windows Server technology. Exchange email will not operate without Active Directory, and the client's accounting and MRP system leveraged Microsoft SQL Server, which requires Active Directory for access to the database.

In less than 48 hours, Progent was able to re-build Windows Active Directory to its pre-penetration state. Progent then performed reinstallations and hard drive recovery on key systems. All Microsoft Exchange Server data and attributes were usable, which accelerated the rebuild of Exchange. Progent was also able to find local OST files (Outlook Email Offline Folder Files) on staff PCs and laptops to recover mail messages. A not too old off-line backup of the customer's accounting/ERP software made them able to recover these required programs back servicing users. Although major work was left to recover fully from the Ryuk damage, the most important services were returned to operations quickly:


"For the most part, the assembly line operation showed little impact and we made all customer deliverables."

Over the next few weeks critical milestones in the restoration process were achieved in close collaboration between Progent engineers and the customer:

  • Self-hosted web sites were brought back up with no loss of information.
  • The MailStore Server exceeding four million archived messages was spun up and available for users.
  • CRM/Customer Orders/Invoicing/AP/AR/Inventory functions were 100% operational.
  • A new Palo Alto 850 firewall was installed.
  • Ninety percent of the desktops and laptops were fully operational.

"So much of what transpired that first week is mostly a fog for me, but I will not soon forget the care all of you put in to give us our business back. I've been working together with Progent for at least 10 years, possibly more, and each time Progent has outperformed my expectations and delivered. This time was a Herculean accomplishment."

Conclusion
A likely business disaster was evaded with top-tier experts, a broad spectrum of knowledge, and tight teamwork. Although upon completion of forensics the ransomware incident detailed here would have been identified and blocked with modern security solutions and security best practices, team training, and well designed security procedures for backup and keeping systems up to date with security patches, the reality is that state-sponsored criminal cyber gangs from China, North Korea and elsewhere are relentless and are an ongoing threat. If you do get hit by a ransomware penetration, feel confident that Progent's roster of professionals has substantial experience in crypto-ransomware virus defense, mitigation, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Jesse, Arnaud, Allen, Tony and Chris (along with others who were helping), I'm grateful for allowing me to get some sleep after we got over the initial push. Everyone did an impressive job, and if any of your team is visiting the Chicago area, a great meal is on me!"

Download the Crypto-Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this customer story, please click:
Progent's Ryuk Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware System Recovery Expertise in Brisbane
For ransomware system recovery services in the Brisbane metro area, phone Progent at 800-462-8800 or see Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.