Ransomware : Your Feared Information Technology Nightmare
Ransomware  Recovery ConsultantsRansomware has become a modern cyberplague that represents an enterprise-level threat for organizations unprepared for an attack. Multiple generations of ransomware such as Reveton, Fusob, Locky, NotPetya and MongoLock cryptoworms have been around for a long time and still inflict harm. More recent versions of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, as well as frequent as yet unnamed viruses, not only perform encryption of on-line data but also infiltrate any accessible system protection mechanisms. Information replicated to the cloud can also be encrypted. In a vulnerable environment, this can make automatic restoration useless and basically sets the entire system back to zero.

Recovering applications and information following a crypto-ransomware event becomes a race against the clock as the targeted business struggles to contain, cleanup the ransomware, and restore enterprise-critical activity. Due to the fact that ransomware needs time to move laterally throughout a network, assaults are usually launched on weekends and holidays, when successful attacks tend to take longer to notice. This compounds the difficulty of quickly mobilizing and organizing a capable response team.

Progent offers a variety of solutions for protecting Guadalajara organizations from ransomware attacks. These include staff training to help identify and not fall victim to phishing exploits, ProSight Active Security Monitoring for endpoint detection and response (EDR) using SentinelOne's behavior-based threat protection to discover and quarantine zero-day modern malware assaults. Progent also provides the services of seasoned ransomware recovery engineers with the track record and perseverance to rebuild a compromised network as quickly as possible.

Progent's Ransomware Restoration Support Services
Following a crypto-ransomware invasion, even paying the ransom in cryptocurrency does not ensure that cyber criminals will provide the keys to unencrypt any of your files. Kaspersky estimated that seventeen percent of ransomware victims never recovered their data even after having paid the ransom, resulting in increased losses. The risk is also very costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger organizations, the ransom can reach millions of dollars. The alternative is to re-install the key components of your IT environment. Absent access to complete data backups, this calls for a wide complement of skills, professional team management, and the ability to work non-stop until the task is complete.

For decades, Progent has offered certified expert Information Technology services for businesses throughout the United States and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts includes engineers who have attained top industry certifications in foundation technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity consultants have garnered internationally-renowned certifications including CISA, CISSP-ISSAP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has expertise with accounting and ERP applications. This breadth of expertise provides Progent the capability to knowledgably determine necessary systems and integrate the remaining pieces of your computer network environment following a ransomware attack and configure them into a functioning network.

Progent's security team has state-of-the-art project management systems to orchestrate the complicated restoration process. Progent knows the urgency of acting quickly and in concert with a client's management and IT staff to assign priority to tasks and to put key services back on-line as soon as possible.

Client Story: A Successful Ransomware Intrusion Restoration
A client escalated to Progent after their network system was brought down by the Ryuk ransomware virus. Ryuk is thought to have been created by North Korean state sponsored hackers, possibly using strategies leaked from the United States National Security Agency. Ryuk goes after specific companies with little or no room for disruption and is among the most lucrative incarnations of ransomware. Major targets include Data Resolution, a California-based info warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a regional manufacturer located in the Chicago metro area and has about 500 workers. The Ryuk intrusion had frozen all business operations and manufacturing capabilities. The majority of the client's data protection had been on-line at the start of the attack and were encrypted. The client was pursuing financing for paying the ransom demand (exceeding $200,000) and wishfully thinking for good luck, but in the end brought in Progent.


"I can't thank you enough about the expertise Progent gave us during the most fearful time of (our) businesses existence. We most likely would have paid the criminal gangs if not for the confidence the Progent group gave us. That you could get our e-mail and key servers back into operation quicker than one week was something I thought impossible. Each consultant I interacted with or e-mailed at Progent was laser focused on getting us operational and was working 24 by 7 to bail us out."

Progent worked with the customer to rapidly understand and assign priority to the most important services that needed to be restored in order to restart business functions:

  • Microsoft Active Directory
  • Microsoft Exchange
  • Accounting and Manufacturing Software
To start, Progent adhered to ransomware penetration response best practices by stopping the spread and cleaning up infected systems. Progent then began the work of bringing back online Active Directory, the key technology of enterprise networks built on Microsoft Windows technology. Microsoft Exchange messaging will not work without AD, and the client's MRP system leveraged Microsoft SQL Server, which needs Active Directory services for security authorization to the data.

In less than 2 days, Progent was able to recover Active Directory services to its pre-attack state. Progent then helped perform reinstallations and storage recovery of needed systems. All Exchange Server schema and configuration information were usable, which greatly helped the restore of Exchange. Progent was also able to locate non-encrypted OST data files (Microsoft Outlook Offline Folder Files) on various workstations and laptops in order to recover email information. A not too old off-line backup of the customer's financials/ERP software made them able to return these required services back online. Although a large amount of work was left to recover fully from the Ryuk event, the most important systems were restored rapidly:


"For the most part, the production operation survived unscathed and we did not miss any customer sales."

During the following couple of weeks important milestones in the recovery project were completed through tight cooperation between Progent engineers and the customer:

  • Self-hosted web applications were restored without losing any information.
  • The MailStore Exchange Server with over four million archived messages was brought on-line and accessible to users.
  • CRM/Product Ordering/Invoices/Accounts Payable/Accounts Receivables (AR)/Inventory functions were 100 percent restored.
  • A new Palo Alto 850 firewall was brought online.
  • Most of the user PCs were back into operation.

"Much of what occurred in the initial days is nearly entirely a fog for me, but my management will not forget the urgency each of the team put in to help get our business back. I've trusted Progent for the past ten years, possibly more, and every time I needed help Progent has come through and delivered as promised. This event was a stunning achievement."

Conclusion
A possible enterprise-killing disaster was avoided with dedicated professionals, a broad array of IT skills, and close collaboration. Although in retrospect the ransomware attack detailed here should have been identified and stopped with modern cyber security technology and recognized best practices, user and IT administrator education, and well thought out security procedures for backup and applying software patches, the fact remains that state-sponsored cybercriminals from Russia, China and elsewhere are relentless and will continue. If you do get hit by a ransomware penetration, feel confident that Progent's roster of experts has substantial experience in ransomware virus blocking, remediation, and information systems disaster recovery.


"So, to Darrin, Aaron, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others that were involved), I'm grateful for letting me get some sleep after we got past the first week. All of you did an amazing job, and if any of your guys is in the Chicago area, a great meal is the least I can do!"

Download the Crypto-Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this case study, please click:
Progent's Crypto-Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting Services in Guadalajara
For ransomware system restoration services in the Guadalajara metro area, call Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.