Crypto-Ransomware : Your Feared Information Technology Nightmare
Crypto-Ransomware  Remediation ConsultantsRansomware has become a modern cyberplague that poses an existential danger for businesses of all sizes poorly prepared for an assault. Multiple generations of crypto-ransomware like the CrySIS, WannaCry, Bad Rabbit, NotPetya and MongoLock cryptoworms have been running rampant for a long time and continue to inflict harm. Modern variants of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, LockBit and Nephilim, along with frequent unnamed newcomers, not only encrypt on-line data files but also infect all available system restores and backups. Information synched to cloud environments can also be corrupted. In a vulnerable system, this can make any recovery useless and basically sets the network back to square one.

Restoring applications and data following a ransomware intrusion becomes a sprint against the clock as the targeted business fights to stop the spread, cleanup the ransomware, and restore enterprise-critical operations. Due to the fact that ransomware takes time to move laterally throughout a targeted network, penetrations are usually sprung at night, when successful penetrations tend to take more time to discover. This multiplies the difficulty of quickly marshalling and organizing a capable mitigation team.

Progent provides a range of services for securing Calgary enterprises from crypto-ransomware events. These include team training to become familiar with and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) using SentinelOne's AI-based threat defense to discover and quarantine zero-day malware assaults. Progent in addition can provide the services of expert crypto-ransomware recovery professionals with the track record and perseverance to re-deploy a compromised system as soon as possible.

Progent's Crypto-Ransomware Restoration Help
After a ransomware event, sending the ransom in cryptocurrency does not provide any assurance that criminal gangs will provide the needed codes to decrypt all your files. Kaspersky determined that 17% of ransomware victims never restored their information after having paid the ransom, resulting in increased losses. The gamble is also costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger organizations, the ransom demand can reach millions. The other path is to piece back together the vital parts of your IT environment. Without the availability of complete information backups, this requires a wide range of IT skills, professional team management, and the willingness to work continuously until the task is finished.

For decades, Progent has made available certified expert IT services for companies throughout the US and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes consultants who have been awarded high-level certifications in leading technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security specialists have garnered internationally-renowned certifications including CISM, CISSP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has expertise in financial systems and ERP application software. This breadth of expertise gives Progent the ability to knowledgably determine important systems and consolidate the remaining components of your IT system following a ransomware event and rebuild them into a functioning system.

Progent's security group has powerful project management tools to coordinate the sophisticated recovery process. Progent knows the importance of working quickly and in unison with a customer's management and IT staff to assign priority to tasks and to get essential applications back online as fast as humanly possible.

Case Study: A Successful Ransomware Virus Restoration
A small business hired Progent after their company was brought down by Ryuk ransomware virus. Ryuk is thought to have been developed by North Korean government sponsored criminal gangs, suspected of adopting technology leaked from the U.S. NSA organization. Ryuk attacks specific organizations with limited ability to sustain disruption and is among the most profitable examples of ransomware. Well Known victims include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a single-location manufacturing company based in Chicago and has about 500 workers. The Ryuk intrusion had disabled all company operations and manufacturing capabilities. Most of the client's information backups had been directly accessible at the time of the attack and were damaged. The client was actively seeking loans for paying the ransom (exceeding $200K) and hoping for the best, but in the end made the decision to use Progent.


"I can't speak enough in regards to the help Progent provided us throughout the most fearful time of (our) businesses existence. We may have had to pay the Hackers if not for the confidence the Progent experts gave us. The fact that you could get our messaging and key applications back on-line in less than seven days was amazing. Every single staff member I got help from or e-mailed at Progent was absolutely committed on getting us working again and was working 24 by 7 to bail us out."

Progent worked with the client to rapidly get our arms around and assign priority to the most important elements that needed to be recovered to make it possible to continue business functions:

  • Active Directory (AD)
  • Microsoft Exchange
  • Financials/MRP
To get going, Progent adhered to ransomware incident mitigation best practices by stopping lateral movement and performing virus removal steps. Progent then started the process of recovering Active Directory, the key technology of enterprise networks built on Microsoft Windows technology. Microsoft Exchange Server messaging will not work without Windows AD, and the businesses' accounting and MRP applications utilized Microsoft SQL Server, which requires Active Directory for authentication to the databases.

Within two days, Progent was able to rebuild Windows Active Directory to its pre-attack state. Progent then completed reinstallations and storage recovery of critical applications. All Exchange Server schema and configuration information were usable, which accelerated the rebuild of Exchange. Progent was also able to locate non-encrypted OST data files (Microsoft Outlook Offline Data Files) on user PCs and laptops to recover mail messages. A recent off-line backup of the customer's accounting systems made them able to recover these required services back on-line. Although significant work was left to recover completely from the Ryuk virus, essential services were returned to operations rapidly:


"For the most part, the production manufacturing operation never missed a beat and we produced all customer shipments."

During the next month important milestones in the recovery process were completed in tight collaboration between Progent consultants and the customer:

  • Self-hosted web applications were brought back up with no loss of information.
  • The MailStore Server containing more than four million historical messages was restored to operations and available for users.
  • CRM/Orders/Invoicing/AP/AR/Inventory capabilities were fully restored.
  • A new Palo Alto Networks 850 firewall was set up and programmed.
  • Ninety percent of the desktops and laptops were functioning as before the incident.

"A huge amount of what transpired those first few days is nearly entirely a blur for me, but my management will not forget the dedication each of your team accomplished to give us our business back. I've utilized Progent for the past ten years, maybe more, and each time Progent has impressed me and delivered. This time was a testament to your capabilities."

Conclusion
A likely company-ending catastrophe was avoided due to results-oriented experts, a broad array of IT skills, and tight teamwork. Although in retrospect the ransomware penetration described here should have been identified and disabled with advanced cyber security technology and recognized best practices, user education, and appropriate incident response procedures for data protection and keeping systems up to date with security patches, the fact is that government-sponsored criminal cyber gangs from China, North Korea and elsewhere are relentless and are not going away. If you do get hit by a ransomware attack, remember that Progent's team of professionals has substantial experience in ransomware virus blocking, cleanup, and data recovery.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others who were contributing), I'm grateful for making it so I could get some sleep after we made it through the initial fire. Everyone did an impressive effort, and if any of your guys is around the Chicago area, dinner is on me!"

Download the Crypto-Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this case study, click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Expertise in Calgary
For ransomware recovery services in the Calgary area, phone Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.