Ransomware : Your Feared IT Nightmare
Ransomware has become an escalating cyberplague that presents an enterprise-level threat for businesses vulnerable to an attack. Versions of ransomware such as Reveton, Fusob, Locky, SamSam and MongoLock cryptoworms have been out in the wild for many years and continue to inflict damage. Modern strains of ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Nephilim, as well as additional unnamed malware, not only perform encryption of on-line information but also infect any accessible system backup. Information synched to the cloud can also be rendered useless. In a poorly designed data protection solution, it can render any recovery hopeless and effectively knocks the entire system back to square one.
Getting back online programs and information after a ransomware event becomes a sprint against the clock as the targeted business tries its best to stop lateral movement, remove the ransomware, and restore business-critical operations. Since ransomware takes time to move laterally across a targeted network, assaults are often sprung during weekends and nights, when attacks are likely to take longer to notice. This multiplies the difficulty of promptly assembling and organizing a qualified mitigation team.
Progent has a range of support services for securing Irving businesses from ransomware penetrations. Among these are team member training to become familiar with and avoid phishing attempts, ProSight Active Security Monitoring for endpoint detection and response (EDR) using SentinelOne's AI-based threat protection to detect and suppress day-zero malware attacks. Progent also can provide the services of veteran ransomware recovery professionals with the track record and commitment to reconstruct a compromised environment as quickly as possible.
Progent's Ransomware Restoration Support Services
After a crypto-ransomware invasion, paying the ransom in cryptocurrency does not guarantee that cyber criminals will respond with the needed keys to unencrypt any of your data. Kaspersky ascertained that 17% of ransomware victims never recovered their data after having sent off the ransom, resulting in increased losses. The risk is also expensive. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom can be in the millions. The other path is to piece back together the essential components of your IT environment. Without access to full data backups, this requires a broad complement of skill sets, top notch project management, and the willingness to work continuously until the task is finished.
For twenty years, Progent has provided professional Information Technology services for businesses throughout the U.S. and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes professionals who have attained top industry certifications in important technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security experts have garnered internationally-renowned industry certifications including CISM, CISSP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has expertise with accounting and ERP software solutions. This breadth of expertise provides Progent the capability to knowledgably ascertain critical systems and integrate the surviving parts of your IT environment after a ransomware attack and assemble them into a functioning network.
Progent's recovery team of experts deploys powerful project management tools to coordinate the complex recovery process. Progent appreciates the urgency of acting rapidly and in unison with a client's management and IT staff to assign priority to tasks and to put critical systems back on-line as soon as possible.
Client Case Study: A Successful Ransomware Incident Restoration
A customer contacted Progent after their network system was taken over by the Ryuk ransomware. Ryuk is thought to have been developed by North Korean state sponsored hackers, suspected of adopting techniques exposed from America's National Security Agency. Ryuk goes after specific organizations with little room for operational disruption and is among the most lucrative iterations of ransomware malware. Major organizations include Data Resolution, a California-based information warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a regional manufacturing business based in Chicago with around 500 workers. The Ryuk penetration had brought down all company operations and manufacturing processes. The majority of the client's data backups had been directly accessible at the beginning of the intrusion and were encrypted. The client was pursuing financing for paying the ransom (more than $200,000) and hoping for the best, but in the end brought in Progent.
Progent worked hand in hand the customer to quickly identify and assign priority to the critical areas that had to be restored to make it possible to resume departmental functions:
Within 2 days, Progent was able to re-build Windows Active Directory to its pre-intrusion state. Progent then completed setup and storage recovery of key servers. All Exchange schema and configuration information were usable, which facilitated the rebuild of Exchange. Progent was also able to find non-encrypted OST data files (Microsoft Outlook Offline Data Files) on staff PCs and laptops in order to recover mail information. A recent offline backup of the customer's financials/MRP systems made it possible to restore these vital applications back on-line. Although major work needed to be completed to recover fully from the Ryuk virus, essential services were restored rapidly:
During the next month important milestones in the recovery process were accomplished in tight cooperation between Progent consultants and the customer:
Conclusion
A probable business-ending disaster was averted with dedicated professionals, a broad array of IT skills, and tight collaboration. Although in hindsight the crypto-ransomware incident described here could have been prevented with current security systems and security best practices, staff education, and well thought out security procedures for data protection and keeping systems up to date with security patches, the reality remains that government-sponsored cyber criminals from China, Russia, North Korea and elsewhere are relentless and are not going away. If you do get hit by a ransomware penetration, feel confident that Progent's roster of professionals has a proven track record in ransomware virus defense, cleanup, and information systems recovery.
Download the Crypto-Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this customer case study, please click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware System Restoration Consulting in Irving
For ransomware recovery consulting services in the Irving area, call Progent at