Ransomware : Your Crippling Information Technology Catastrophe
Ransomware  Recovery ConsultantsRansomware has become a too-frequent cyber pandemic that represents an existential danger for businesses unprepared for an attack. Different versions of ransomware such as Dharma, WannaCry, Locky, Syskey and MongoLock cryptoworms have been replicating for years and still cause havoc. Newer variants of crypto-ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Egregor, as well as more unnamed malware, not only encrypt on-line information but also infiltrate many configured system restores and backups. Information synchronized to the cloud can also be encrypted. In a vulnerable data protection solution, it can make automatic restoration useless and effectively sets the datacenter back to square one.

Recovering applications and data after a crypto-ransomware event becomes a race against the clock as the targeted organization tries its best to contain, eradicate the crypto-ransomware, and restore enterprise-critical operations. Because ransomware takes time to replicate across a targeted network, penetrations are usually launched during nights and weekends, when successful penetrations may take more time to recognize. This multiplies the difficulty of rapidly marshalling and organizing a capable response team.

Progent provides an assortment of services for securing Atlanta enterprises from ransomware attacks. These include staff education to help recognize and not fall victim to phishing exploits, ProSight Active Security Monitoring (ASM) for endpoint detection and response using SentinelOne's behavior-based threat protection to identify and disable day-zero malware attacks. Progent also can provide the assistance of seasoned ransomware recovery engineers with the talent and commitment to reconstruct a compromised environment as rapidly as possible.

Progent's Ransomware Restoration Help
Following a ransomware penetration, paying the ransom demands in cryptocurrency does not provide any assurance that distant criminals will return the needed keys to unencrypt any or all of your files. Kaspersky ascertained that 17% of ransomware victims never recovered their files after having sent off the ransom, resulting in increased losses. The gamble is also expensive. Ryuk ransoms are commonly a few hundred thousand dollars. For larger enterprises, the ransom can reach millions of dollars. The other path is to re-install the mission-critical components of your Information Technology environment. Without the availability of full information backups, this calls for a broad range of skill sets, top notch team management, and the capability to work non-stop until the job is over.

For two decades, Progent has made available expert Information Technology services for companies across the US and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes engineers who have earned high-level certifications in leading technologies including Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security engineers have garnered internationally-renowned certifications including CISA, CISSP-ISSAP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (See Progent's certifications). Progent also has expertise in financial systems and ERP application software. This breadth of expertise provides Progent the skills to rapidly ascertain important systems and organize the remaining parts of your computer network environment following a ransomware penetration and rebuild them into an operational network.

Progent's recovery group uses powerful project management tools to coordinate the complicated restoration process. Progent knows the importance of acting swiftly and in concert with a customer's management and Information Technology team members to assign priority to tasks and to get critical systems back on line as fast as humanly possible.

Customer Story: A Successful Crypto-Ransomware Virus Restoration
A client contacted Progent after their organization was taken over by the Ryuk ransomware. Ryuk is thought to have been created by North Korean state sponsored hackers, suspected of using techniques exposed from America's NSA organization. Ryuk goes after specific businesses with little tolerance for operational disruption and is among the most lucrative incarnations of crypto-ransomware. Major targets include Data Resolution, a California-based information warehousing and cloud computing firm, and the Chicago Tribune. Progent's customer is a single-location manufacturing business headquartered in the Chicago metro area and has about 500 workers. The Ryuk intrusion had shut down all essential operations and manufacturing capabilities. The majority of the client's data backups had been directly accessible at the beginning of the attack and were damaged. The client was pursuing financing for paying the ransom demand (exceeding two hundred thousand dollars) and hoping for the best, but in the end made the decision to use Progent.


"I cannot tell you enough in regards to the care Progent gave us during the most stressful time of (our) company's life. We may have had to pay the cybercriminals if it wasn't for the confidence the Progent experts afforded us. That you could get our messaging and production servers back online quicker than a week was something I thought impossible. Every single person I worked with or e-mailed at Progent was totally committed on getting us back on-line and was working breakneck pace to bail us out."

Progent worked hand in hand the client to rapidly determine and assign priority to the essential systems that had to be restored to make it possible to restart business functions:

  • Active Directory
  • Microsoft Exchange
  • Accounting/MRP
To begin, Progent followed AV/Malware Processes incident response industry best practices by isolating and clearing infected systems. Progent then started the work of recovering Active Directory, the foundation of enterprise environments built on Microsoft Windows technology. Microsoft Exchange Server messaging will not work without Windows AD, and the customer's accounting and MRP system leveraged Microsoft SQL Server, which needs Active Directory services for authentication to the database.

Within 2 days, Progent was able to restore Active Directory services to its pre-intrusion state. Progent then assisted with rebuilding and hard drive recovery of needed applications. All Exchange Server data and configuration information were usable, which greatly helped the restore of Exchange. Progent was also able to locate local OST files (Microsoft Outlook Offline Data Files) on staff workstations and laptops to recover email information. A recent off-line backup of the customer's manufacturing software made them able to recover these essential programs back on-line. Although major work remained to recover fully from the Ryuk event, the most important systems were restored rapidly:


"For the most part, the production operation never missed a beat and we produced all customer shipments."

Over the next month critical milestones in the recovery process were completed through close collaboration between Progent consultants and the client:

  • In-house web sites were brought back up without losing any data.
  • The MailStore Exchange Server with over 4 million archived emails was brought on-line and available for users.
  • CRM/Orders/Invoices/Accounts Payable (AP)/Accounts Receivables/Inventory functions were fully functional.
  • A new Palo Alto 850 firewall was set up.
  • Most of the user desktops were functioning as before the incident.

"So much of what was accomplished in the initial days is nearly entirely a fog for me, but my team will not soon forget the urgency all of your team accomplished to give us our business back. I have been working with Progent for the past ten years, maybe more, and each time I needed help Progent has outperformed my expectations and delivered. This situation was a life saver."

Conclusion
A potential business extinction disaster was dodged through the efforts of dedicated experts, a wide array of knowledge, and close collaboration. Although in hindsight the ransomware virus incident detailed here would have been identified and stopped with modern security technology solutions and recognized best practices, user and IT administrator education, and properly executed incident response procedures for data backup and keeping systems up to date with security patches, the reality is that government-sponsored criminal cyber gangs from Russia, China and elsewhere are relentless and will continue. If you do get hit by a crypto-ransomware incident, remember that Progent's team of professionals has a proven track record in crypto-ransomware virus blocking, cleanup, and file recovery.


"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others that were contributing), I'm grateful for allowing me to get some sleep after we made it past the first week. All of you did an incredible job, and if any of your guys is visiting the Chicago area, dinner is my treat!"

Download the Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this ransomware incident report, please click:
Progent's Crypto-Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Expertise in Atlanta
For ransomware system recovery expertise in the Atlanta metro area, phone Progent at 800-462-8800 or visit Contact Progent.



An index of content::

  • 24 Hour Short-Term Staffing Support Services Consulting Expertise Supplemental IT Staffing Support Services Consultants
  • 24-Hour Microsoft MCITP Consulting Career Marietta - Alpharetta Security Consulting Contract Job Opportunities Atlanta, GA
  • 24/7 Consulting Services for Atlanta IT Support Providers Atlanta Georgia Atlanta Consultants for IT Service Providers

  • Contract Job Compensation for Cisco Consultant
    Home Based Microsoft Consultants Jobs

    Our compensation model is based on revenue sharing, so just like being an independent consultant, your income is entirely driven by your generated revenue. Some Progent consultants focus on quality of life and elect to work at an easy pace, using our self-determined schedule to pursue individual enthusiasms like mountain biking, motorcycle racing, snow boarding, surfing, travel, or spending private time with family and friends. Other consultants use the chance to make major bucks through hard effort and extended days. Progent fully supports both sides of the spectrum and any point in between.

  • 24x7 ProSight Virtual Machine Hosting Consulting Services ProSight Virtual Hosting Professionals

  • Emergency MSP360 Server Backup Integration
    MSP360 Exchange Mailbox Backup Online Support Services

    Progent can help you to create, install and manage a backup/restore solution based on MSP360 Backup software to protect your IT assets hosted on any major public cloud. Progent offers monitoring and remote management to prevent data loss resulting from user miscues, software flaws, malicious insiders, and malware assaults such as ransomware.

  • Altaro VM Backup Troubleshooting Network Consultant After Hours Altaro VM Backup Boot from Backup Online Support Services

  • 24x7 ransomware business recovery Engineers
    ransomware virus recovery Technology Professional

    Progent's Ransomware Hot Line provides 24x7 access to a proven ransomware recovery consultant who can help your business to contain the spread of an ongoing ransomware attack. Call 800-462-8800

  • At Home Workers Consulting and Support Services near Atlanta - Collaboration Technology Consultants Atlanta Hartsfield-Jackson Airport ATL, USA At Home Workforce Guidance in Atlanta - Collaboration Systems Consulting and Support Services Decatur - Buckhead - Norcross
  • At Home Workers Guidance - Atlanta - Endpoint Management Solutions Expertise Remote Workforce Atlanta Consulting - Endpoint Management Tools Consulting Experts

  • ProSight Email Security Gateway Consultant Services
    ProSight Email Zero Hour Protection Consultants

    Progent's ProSight Email Guard uses the technology of top information security companies to provide web-based management and comprehensive protection for all your inbound and outbound email. The hybrid architecture of Progent's Email Guard integrates a Cloud Protection Layer with a local gateway device to offer complete protection against spam, viruses, Dos Attacks, Directory Harvest Attacks, and other email-borne malware. Email Guard's Cloud Protection Layer serves as a preliminary barricade and keeps most threats from making it to your network firewall. This decreases your exposure to inbound threats and conserves network bandwidth and storage space. Email Guard's on-premises gateway appliance provides a further level of analysis for inbound email. For outbound email, the on-premises gateway offers anti-virus and anti-spam protection, DLP, and encryption. The onsite security gateway can also assist Microsoft Exchange Server to track and protect internal email traffic that originates and ends inside your corporate firewall.

  • Atlanta At Home Workers IP Voice Solutions Assistance Marietta - Alpharetta Atlanta At Home Workforce IP Voice Technology Guidance Atlanta Hartsfield-Jackson Airport ATL
  • Atlanta Crypto-Ransomware Hermes Vulnerability Audit Marietta - Alpharetta Atlanta Ransomware Ryuk Readiness Checkup Atlanta
  • Atlanta Crypto-Ransomware Removal Experts ATL, U.S.A. Atlanta Urgent Crypto Remediation ATL
  • Atlanta Dharma Crypto-Ransomware Operational Recovery Atlanta Georgia Atlanta Ransomware Virus Remediation Decatur - Buckhead - Norcross

  • Urgent ransomware hot line Consultants
    Top Ranked ransomware system rebuild Consultant

    Progent's Ransomware Hot Line provides 24x7 access to a experienced ransomware recovery consultant who can assist you to contain the spread of an active ransomware breach. Call 800-462-8800

  • Atlanta DopplePaymer Crypto-Ransomware Business Recovery Atlanta, GA Atlanta Nephilim Ransomware Recovery Fulton County Georgia
  • Atlanta IT Outsourcing Group Atlanta Information Technology Consulting
  • Atlanta MongoLock Ransomware Data-Recovery Atlanta Top Ranked Atlanta Nephilim Crypto-Ransomware Restoration Decatur - Buckhead - Norcross
  • Atlanta Remote Workers Cloud Solutions Consulting Experts Atlanta Hartsfield-Jackson Airport ATL ATL Remote Workforce Consulting - Atlanta - Cloud Solutions Consulting and Support Services
  • Atlanta Ryuk Ransomware Forensics Atlanta Hartsfield-Jackson Airport ATL, United States Atlanta Dharma Ransomware Forensics Investigation ATL

  • Microsoft Teams PBX integration Consultant Services
    Microsoft Teams Integration

    File summary_Microsoft-Teams-Consulting-Experts.asp does not exist



  • Atlanta Sodinokibi Ransomware Negotiation Services Atlanta Marietta - Alpharetta Atlanta Avaddon Crypto-Ransomware Negotiation Consultants
  • Atlanta Telecommuters Video Conferencing Technology Assistance Work at Home Employees Atlanta Consulting Services - Video Conferencing Systems Consulting Atlanta Georgia
  • Atlanta, GA Small Business IT Support Firms Atlanta, Georgia IT Consulting
  • Cisco Meraki Dashboard Cloud Management Small Business Networking Cisco Network Management Solutions Tech Support Outsource

  • Cisco Firewall Systems Consultant
    System Repair Cisco Architecture

    Progent can assist your organization to deploy Cisco's networking technology to create a robust foundation for your onsite, private cloud, or hybrid-cloud data center and improve operations in vital areas including resource utilization, security and compliance, versatility, availability, and disaster recovery.

  • Atlanta Lockbit Ransomware Business-Recovery Marietta - Alpharetta
  • Cisco System Recovery Atlanta, Fulton County Cisco Technical Consultant Atlanta Georgia
  • Atlanta Spora Crypto-Ransomware Mitigation Atlanta, Fulton County
  • Co-Location Specialists Data Center Colocation Support Services
  • Conti Ransomware Hot Line Atlanta, America Ransomware Removal and Data Restore Atlanta, Fulton County
  • Decatur - Buckhead - Norcross Server Troubleshoot Expert Co-Location Facility Computer Support Companies Colocation Decatur - Buckhead - Norcross
  • Dharma ransomware hot line Consultants DopplePaymer ransomware hot line Consultant
  • Emergency Exchange Server 2010 Computer Consulting Group Atlanta Georgia Migrations Exchange Server 2019 ATL, U.S.A.
  • Georgia Computer System Consultant BlackBerry Redirector 24 Hour Integration Services BlackBerry Enterprise Server Atlanta Georgia
  • Microsoft Dynamics GP (Great Plains) Atlanta Reseller - Setup Expert Georgia Atlanta Georgia Dynamics GP Atlanta Premier Partner - Migration Consultants
  • Microsoft SharePoint Server 2007 Support and Help Atlanta Hartsfield-Jackson Airport ATL Microsoft SharePoint Server 2013 Specialist
  • Microsoft Video Conferencing Consultant Services Consulting MS Office Communications Server 2007
  • Online Help Identity Authentication 24/7 Zero Trust Cybersecurity Technical Support Services
  • Redhat Linux, Sun Solaris, UNIX Network Consultant Atlanta Hartsfield-Jackson Airport ATL Remote Support Services CentOS Linux, Sun Solaris, UNIX Atlanta Georgia
  • Remote Workers Consulting nearby Atlanta - Connectivity Solutions Consultants ATL Atlanta Hartsfield-Jackson Airport ATL Urgent Atlanta Remote Workers Solutions Consulting Services
  • SQL Server 2012 Outsourcing Top Microsoft SQL Server 2017 Networking Help Atlanta Hartsfield-Jackson Airport ATL
  • SQL Server 2014 Monitoring Specialist SQL Server 2014 In-memory ColumnStore Integration Services

  • Computer Consultants Microsoft Operations Manager
    Operations Manager Consulting Services

    Even if your company has a minimal computer services staff and a modest technology budget, your information network can still have the same high availability and responsiveness that once needed a substantial in-house service organization. Progent's 24x7 Network Support Services for small businesses combine the expertise of world-class Microsoft-expert and Cisco-premier IT consultants, the latest system management software for 24x7 monitoring and alerts, and cost-effective support packages such as a help desk service to keep your vital business applications and servers operating.

  • Security Consultant Firewall Georgia CISSP Consulting Services
  • Teleworkers Atlanta Guidance - Security Systems Guidance Atlanta Hartsfield-Jackson Airport ATL Atlanta Telecommuters Endpoint Security Solutions Consulting Services Fulton County Georgia
  • Teleworkers Consulting nearby Atlanta - Help Desk Augmentation Consulting and Support Services Atlanta Georgia Top Quality Remote Workforce Consultants near Atlanta - Help Desk Outsourcing Guidance Atlanta, Fulton County

  • Microsoft ISA 2004 Server Setup and Support
    ISA Server IT Consulting

    Progent's Microsoft certified consultants offer small and midsize businesses consulting services for Microsoft Forefront TMG and ISA Servers. Microsoft's Forefront TMG and ISA Servers include an advanced application-layer aware firewall that can secure your business network from attack by outside and inside threats. Forefront Threat Management Gateway and ISA Server perform thorough examination of Internet protocols such as HTTP, which allows these security platforms to detect many threats that can elude ordinary firewalls. The combined firewall and VPN structure of Forefront TMG and ISA Server permit stateful filtering and monitoring of all VPN streams. ISA Servers are the centerpiece of Microsoft's system security initiative, and Progent's Microsoft-certified engineers and CISSP, CISA and CISM certified security consultants can help you enhance your network protection through experienced design and integration of Forefront TMG and Microsoft ISA Servers. Progent's Microsoft-certified engineers can help your company to configure Microsoft Forefront Threat Management Gateway 2010, manage and troubleshoot all versions of ISA Server, or migrate from ISA Server to Microsoft Forefront TMG.

  • Top At Home Workforce Expertise near Atlanta - Setup Expertise Atlanta, Fulton County At Home Workers Atlanta Expertise - Setup Assistance Atlanta
  • Windows Server 2012 R2 Computer Outsourcing Consultant Windows Server 2016 Migration
  • Windows, UNIX, Solaris Support and Help Solaris with Windows Consultancy
  • Work at Home Employees Expertise in Atlanta - Backup/Recovery Technology Consultants Decatur - Buckhead - Norcross Atlanta At Home Workforce Data Protection Systems Consulting Services

  • © 2002-2025 Progent Corporation. All rights reserved.