Ransomware : Your Worst Information Technology Catastrophe
Crypto-Ransomware has become a too-frequent cyberplague that presents an extinction-level threat for organizations unprepared for an assault. Multiple generations of ransomware such as Reveton, WannaCry, Locky, SamSam and MongoLock cryptoworms have been around for many years and continue to inflict destruction. Modern versions of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Conti and Egregor, along with daily as yet unnamed newcomers, not only encrypt on-line information but also infect most available system restores and backups. Data synchronized to cloud environments can also be ransomed. In a poorly designed data protection solution, it can render any restoration useless and basically sets the network back to zero.
Getting back on-line applications and data after a ransomware attack becomes a race against time as the targeted organization struggles to contain, clear the ransomware, and restore business-critical operations. Because ransomware requires time to spread across a targeted network, penetrations are frequently sprung at night, when attacks are likely to take longer to detect. This compounds the difficulty of rapidly mobilizing and organizing a qualified mitigation team.
Progent has a variety of solutions for securing Wichita businesses from crypto-ransomware events. Among these are user training to help recognize and avoid phishing exploits, ProSight Active Security Monitoring (ASM) for endpoint detection and response utilizing SentinelOne's behavior-based cyberthreat protection to identify and quarantine zero-day modern malware assaults. Progent also offers the assistance of experienced ransomware recovery professionals with the skills and commitment to restore a compromised system as urgently as possible.
Progent's Ransomware Restoration Help
Following a crypto-ransomware event, paying the ransom demands in cryptocurrency does not ensure that cyber criminals will respond with the codes to unencrypt any or all of your files. Kaspersky Labs determined that 17% of ransomware victims never recovered their data even after having sent off the ransom, resulting in more losses. The risk is also very costly. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom demand can reach millions of dollars. The alternative is to setup from scratch the vital elements of your IT environment. Absent the availability of full data backups, this calls for a broad range of skills, well-coordinated project management, and the capability to work non-stop until the task is finished.
For decades, Progent has offered professional Information Technology services for businesses across the United States and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes professionals who have attained high-level industry certifications in important technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security specialists have garnered internationally-recognized industry certifications including CISA, CISSP-ISSAP, ISACA CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has experience in financial management and ERP application software. This breadth of expertise provides Progent the ability to knowledgably identify important systems and re-organize the remaining components of your Information Technology environment following a crypto-ransomware event and assemble them into a functioning system.
Progent's recovery team uses state-of-the-art project management systems to coordinate the complicated recovery process. Progent understands the urgency of working quickly and in concert with a client's management and IT team members to assign priority to tasks and to get essential services back on line as soon as humanly possible.
Case Study: A Successful Ransomware Attack Response
A business sought out Progent after their organization was taken over by the Ryuk ransomware. Ryuk is believed to have been launched by North Korean state sponsored criminal gangs, possibly adopting approaches leaked from America's NSA organization. Ryuk seeks specific companies with limited room for operational disruption and is one of the most profitable versions of ransomware viruses. High publicized organizations include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a regional manufacturing business headquartered in Chicago with around 500 staff members. The Ryuk attack had disabled all business operations and manufacturing capabilities. The majority of the client's backups had been on-line at the time of the attack and were encrypted. The client was evaluating paying the ransom (exceeding $200K) and hoping for good luck, but ultimately utilized Progent.
Progent worked together with the client to quickly get our arms around and prioritize the most important systems that had to be addressed to make it possible to resume business functions:
In less than 2 days, Progent was able to re-build Active Directory services to its pre-virus state. Progent then helped perform reinstallations and storage recovery of critical applications. All Microsoft Exchange Server data and configuration information were intact, which facilitated the rebuild of Exchange. Progent was able to find non-encrypted OST files (Microsoft Outlook Offline Folder Files) on staff desktop computers in order to recover email information. A not too old off-line backup of the businesses manufacturing systems made them able to recover these required programs back online. Although significant work needed to be completed to recover totally from the Ryuk attack, the most important services were restored quickly:
Over the next month important milestones in the restoration project were made through close collaboration between Progent engineers and the customer:
Conclusion
A probable business extinction disaster was dodged through the efforts of dedicated professionals, a broad spectrum of IT skills, and tight collaboration. Although in retrospect the crypto-ransomware virus incident described here would have been identified and stopped with current cyber security technology solutions and NIST Cybersecurity Framework or ISO/IEC 27001 best practices, staff training, and appropriate security procedures for data backup and proper patching controls, the fact is that state-sponsored cyber criminals from Russia, North Korea and elsewhere are tireless and will continue. If you do fall victim to a ransomware virus, feel confident that Progent's team of experts has a proven track record in ransomware virus blocking, remediation, and information systems disaster recovery.
Download the Crypto-Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this case study, click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)
Contact Progent for Ransomware Cleanup Consulting Services in Wichita
For ransomware cleanup consulting in the Wichita area, phone Progent at