Ransomware : Your Feared Information Technology Catastrophe
Ransomware  Recovery ConsultantsRansomware has become a too-frequent cyber pandemic that poses an existential danger for businesses unprepared for an attack. Different versions of ransomware like the Dharma, WannaCry, Bad Rabbit, NotPetya and MongoLock cryptoworms have been circulating for a long time and continue to inflict harm. Modern strains of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Nephilim, along with frequent unnamed viruses, not only encrypt online data files but also infect many configured system backups. Data replicated to off-premises disaster recovery sites can also be rendered useless. In a poorly designed environment, it can render automated recovery useless and effectively sets the datacenter back to square one.

Getting back applications and data following a crypto-ransomware attack becomes a sprint against the clock as the victim fights to stop lateral movement, eradicate the crypto-ransomware, and resume enterprise-critical operations. Since crypto-ransomware takes time to replicate throughout a targeted network, penetrations are often launched on weekends and holidays, when successful attacks in many cases take longer to recognize. This multiplies the difficulty of promptly mobilizing and orchestrating a knowledgeable response team.

Progent has a variety of services for protecting El Paso enterprises from ransomware penetrations. Among these are team education to become familiar with and avoid phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response utilizing SentinelOne's behavior-based threat defense to identify and disable day-zero malware attacks. Progent also provides the services of veteran ransomware recovery engineers with the talent and perseverance to reconstruct a breached network as rapidly as possible.

Progent's Ransomware Recovery Support Services
Soon after a ransomware invasion, even paying the ransom demands in cryptocurrency does not guarantee that cyber criminals will return the needed codes to unencrypt all your files. Kaspersky ascertained that 17% of crypto-ransomware victims never recovered their information after having paid the ransom, resulting in additional losses. The gamble is also very costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger organizations, the ransom demand can be in the millions of dollars. The fallback is to setup from scratch the essential elements of your Information Technology environment. Absent the availability of essential information backups, this calls for a wide range of skills, top notch project management, and the capability to work non-stop until the recovery project is completed.

For twenty years, Progent has offered professional IT services for companies throughout the United States and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes consultants who have attained high-level industry certifications in key technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity consultants have earned internationally-renowned industry certifications including CISA, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has expertise in financial systems and ERP applications. This breadth of experience provides Progent the ability to knowledgably ascertain important systems and consolidate the surviving components of your network system after a crypto-ransomware attack and assemble them into a functioning network.

Progent's security team deploys powerful project management tools to orchestrate the complex recovery process. Progent understands the urgency of acting swiftly and in unison with a customer's management and IT resources to prioritize tasks and to put key services back on line as fast as possible.

Client Case Study: A Successful Crypto-Ransomware Attack Response
A customer engaged Progent after their network was attacked by Ryuk crypto-ransomware. Ryuk is generally considered to have been created by North Korean state sponsored hackers, suspected of adopting approaches leaked from America's National Security Agency. Ryuk seeks specific organizations with little or no ability to sustain disruption and is among the most lucrative versions of ransomware. High publicized victims include Data Resolution, a California-based data warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a small manufacturing business located in the Chicago metro area and has about 500 workers. The Ryuk penetration had shut down all essential operations and manufacturing capabilities. The majority of the client's data protection had been directly accessible at the start of the attack and were destroyed. The client was taking steps for paying the ransom (more than $200K) and praying for the best, but ultimately utilized Progent.


"I can't say enough in regards to the help Progent provided us throughout the most fearful time of (our) company's life. We most likely would have paid the cyber criminals if not for the confidence the Progent group gave us. The fact that you were able to get our e-mail and key servers back quicker than one week was earth shattering. Each expert I talked with or texted at Progent was hell bent on getting us operational and was working day and night on our behalf."

Progent worked hand in hand the client to quickly understand and prioritize the critical elements that had to be addressed in order to continue business operations:

  • Windows Active Directory
  • Email
  • Financials/MRP
To get going, Progent followed AV/Malware Processes incident response best practices by stopping the spread and cleaning systems of viruses. Progent then began the work of bringing back online Active Directory, the key technology of enterprise systems built upon Microsoft Windows technology. Microsoft Exchange messaging will not work without Active Directory, and the client's financials and MRP applications utilized SQL Server, which needs Windows AD for access to the database.

In less than two days, Progent was able to rebuild Windows Active Directory to its pre-penetration state. Progent then charged ahead with setup and storage recovery of essential servers. All Exchange Server data and attributes were intact, which facilitated the restore of Exchange. Progent was also able to locate non-encrypted OST files (Outlook Offline Data Files) on staff PCs and laptops in order to recover email information. A not too old offline backup of the customer's financials/ERP software made it possible to restore these essential services back online. Although significant work was left to recover totally from the Ryuk damage, essential systems were restored quickly:


"For the most part, the assembly line operation showed little impact and we made all customer orders."

Over the next few weeks key milestones in the restoration process were made through close cooperation between Progent consultants and the client:

  • In-house web applications were restored without losing any data.
  • The MailStore Server with over 4 million historical emails was restored to operations and accessible to users.
  • CRM/Product Ordering/Invoices/Accounts Payable/AR/Inventory Control capabilities were 100 percent operational.
  • A new Palo Alto 850 security appliance was installed and configured.
  • Most of the user workstations were operational.

"Much of what was accomplished that first week is mostly a blur for me, but our team will not forget the urgency each of your team put in to give us our company back. I've entrusted Progent for at least 10 years, possibly more, and every time Progent has come through and delivered as promised. This time was a stunning achievement."

Conclusion
A potential enterprise-killing catastrophe was dodged due to results-oriented professionals, a wide range of IT skills, and close teamwork. Although upon completion of forensics the ransomware penetration detailed here could have been blocked with up-to-date cyber security solutions and security best practices, user and IT administrator training, and properly executed security procedures for information backup and keeping systems up to date with security patches, the fact remains that government-sponsored criminal cyber gangs from Russia, North Korea and elsewhere are tireless and represent an ongoing threat. If you do fall victim to a ransomware penetration, remember that Progent's roster of experts has substantial experience in ransomware virus defense, remediation, and data recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Tony (and any others that were contributing), I'm grateful for letting me get rested after we made it past the first week. Everyone did an impressive job, and if any of your team is in the Chicago area, dinner is my treat!"

Download the Ransomware Removal Case Study Datasheet
To review or download a PDF version of this case study, please click:
Progent's Crypto-Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting Services in El Paso
For ransomware cleanup consulting services in the El Paso area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.