Ransomware : Your Feared IT Nightmare
Crypto-Ransomware  Remediation ExpertsCrypto-Ransomware has become a modern cyber pandemic that presents an enterprise-level threat for businesses of all sizes unprepared for an assault. Different iterations of ransomware such as Reveton, Fusob, Bad Rabbit, NotPetya and MongoLock cryptoworms have been replicating for years and still cause damage. More recent variants of crypto-ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, along with additional unnamed viruses, not only encrypt on-line information but also infiltrate many accessible system backups. Information replicated to cloud environments can also be encrypted. In a poorly designed system, this can make automated restore operations useless and effectively sets the entire system back to square one.

Recovering services and data after a ransomware outage becomes a sprint against time as the targeted organization fights to stop the spread, remove the crypto-ransomware, and restore enterprise-critical operations. Because ransomware requires time to replicate across a targeted network, attacks are often sprung during nights and weekends, when attacks may take longer to notice. This compounds the difficulty of rapidly assembling and coordinating a qualified response team.

Progent provides an assortment of services for protecting Sarasota enterprises from crypto-ransomware events. These include team training to help identify and avoid phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response utilizing SentinelOne's AI-based threat protection to identify and extinguish zero-day modern malware attacks. Progent in addition offers the assistance of experienced ransomware recovery professionals with the talent and commitment to restore a breached network as quickly as possible.

Progent's Ransomware Restoration Services
Soon after a crypto-ransomware invasion, paying the ransom in cryptocurrency does not guarantee that cyber hackers will respond with the keys to decipher any of your information. Kaspersky Labs ascertained that 17% of crypto-ransomware victims never recovered their information after having sent off the ransom, resulting in more losses. The risk is also expensive. Ryuk ransoms are commonly several hundred thousand dollars. For larger organizations, the ransom demand can reach millions. The alternative is to piece back together the essential elements of your Information Technology environment. Absent the availability of full system backups, this requires a wide range of IT skills, professional project management, and the capability to work 24x7 until the job is complete.

For decades, Progent has offered certified expert Information Technology services for companies across the US and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes consultants who have earned high-level certifications in leading technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security specialists have garnered internationally-recognized certifications including CISM, CISSP-ISSAP, ISACA CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent in addition has expertise with financial systems and ERP application software. This breadth of experience affords Progent the capability to knowledgably understand necessary systems and re-organize the surviving components of your Information Technology environment following a crypto-ransomware event and rebuild them into an operational system.

Progent's recovery team of experts has best of breed project management tools to coordinate the complicated restoration process. Progent knows the importance of acting rapidly and together with a customer's management and Information Technology resources to assign priority to tasks and to put the most important applications back on line as soon as humanly possible.

Case Study: A Successful Crypto-Ransomware Attack Recovery
A business engaged Progent after their network was crashed by the Ryuk ransomware. Ryuk is generally considered to have been launched by North Korean state sponsored cybercriminals, possibly using strategies exposed from America's National Security Agency. Ryuk targets specific companies with little or no room for operational disruption and is among the most lucrative examples of ransomware viruses. High publicized organizations include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a regional manufacturer based in the Chicago metro area and has around 500 staff members. The Ryuk attack had shut down all company operations and manufacturing processes. The majority of the client's system backups had been directly accessible at the start of the intrusion and were encrypted. The client was taking steps for paying the ransom demand (exceeding two hundred thousand dollars) and praying for good luck, but ultimately called Progent.


"I cannot tell you enough about the care Progent provided us during the most stressful period of (our) businesses survival. We may have had to pay the cyber criminals behind the attack if not for the confidence the Progent group afforded us. The fact that you were able to get our e-mail and important servers back in less than seven days was amazing. Each consultant I worked with or messaged at Progent was laser focused on getting our system up and was working all day and night to bail us out."

Progent worked with the client to rapidly get our arms around and assign priority to the mission critical applications that needed to be restored in order to restart departmental operations:

  • Active Directory
  • Email
  • Accounting/MRP
To begin, Progent followed AV/Malware Processes event response best practices by stopping the spread and removing active viruses. Progent then began the process of bringing back online Windows Active Directory, the key technology of enterprise environments built upon Microsoft technology. Microsoft Exchange Server email will not operate without AD, and the customer's financials and MRP software used Microsoft SQL, which depends on Active Directory services for authentication to the databases.

Within 2 days, Progent was able to restore Active Directory to its pre-intrusion state. Progent then performed reinstallations and hard drive recovery on mission critical servers. All Exchange schema and attributes were usable, which accelerated the rebuild of Exchange. Progent was able to collect intact OST files (Microsoft Outlook Offline Data Files) on user PCs and laptops to recover email information. A recent off-line backup of the businesses manufacturing systems made it possible to restore these vital applications back online for users. Although a lot of work was left to recover completely from the Ryuk damage, core systems were returned to operations quickly:


"For the most part, the manufacturing operation ran fairly normal throughout and we did not miss any customer deliverables."

Throughout the following month key milestones in the recovery process were made through close cooperation between Progent consultants and the customer:

  • In-house web sites were returned to operation with no loss of information.
  • The MailStore Exchange Server exceeding four million historical messages was brought on-line and available for users.
  • CRM/Product Ordering/Invoicing/Accounts Payable (AP)/AR/Inventory capabilities were completely operational.
  • A new Palo Alto Networks 850 firewall was deployed.
  • Most of the desktop computers were fully operational.

"So much of what occurred that first week is nearly entirely a haze for me, but our team will not forget the urgency all of your team accomplished to help get our company back. I've been working together with Progent for the past ten years, maybe more, and every time Progent has shined and delivered as promised. This event was a life saver."

Conclusion
A potential business-ending disaster was averted due to results-oriented experts, a broad spectrum of subject matter expertise, and close teamwork. Although in post mortem the crypto-ransomware attack described here could have been shut down with advanced cyber security solutions and recognized best practices, user training, and well designed security procedures for backup and proper patching controls, the reality remains that state-sponsored cyber criminals from China, North Korea and elsewhere are tireless and will continue. If you do get hit by a crypto-ransomware penetration, remember that Progent's roster of professionals has a proven track record in crypto-ransomware virus blocking, mitigation, and data restoration.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others who were contributing), thanks very much for allowing me to get some sleep after we got past the initial push. Everyone did an fabulous job, and if any of your guys is in the Chicago area, dinner is on me!"

Download the Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this customer story, please click:
Progent's Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Consulting in Sarasota
For ransomware recovery consulting in the Sarasota metro area, phone Progent at 800-462-8800 or see Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.