Crypto-Ransomware : Your Worst Information Technology Catastrophe
Crypto-Ransomware  Remediation ConsultantsRansomware has become an escalating cyber pandemic that poses an extinction-level threat for businesses poorly prepared for an assault. Multiple generations of ransomware such as CrySIS, WannaCry, Bad Rabbit, Syskey and MongoLock cryptoworms have been replicating for years and still inflict damage. Modern versions of ransomware like Ryuk, Maze, Sodinokibi, DopplePaymer, Conti and Nephilim, plus daily unnamed newcomers, not only perform encryption of online files but also infiltrate any accessible system restores and backups. Files replicated to the cloud can also be rendered useless. In a vulnerable environment, it can render automatic restoration hopeless and basically sets the entire system back to square one.

Getting back applications and information following a ransomware outage becomes a race against time as the targeted business fights to stop lateral movement, remove the ransomware, and restore business-critical activity. Due to the fact that ransomware requires time to spread throughout a network, assaults are often launched during nights and weekends, when attacks tend to take more time to identify. This compounds the difficulty of rapidly assembling and organizing an experienced mitigation team.

Progent offers a range of support services for protecting Beverly Hills businesses from ransomware events. These include staff education to help recognize and avoid phishing attempts, ProSight Active Security Monitoring for endpoint detection and response (EDR) utilizing SentinelOne's AI-based cyberthreat protection to discover and suppress day-zero modern malware assaults. Progent in addition can provide the assistance of seasoned crypto-ransomware recovery engineers with the skills and commitment to re-deploy a compromised environment as urgently as possible.

Progent's Ransomware Restoration Help
Following a ransomware attack, even paying the ransom demands in cryptocurrency does not ensure that merciless criminals will provide the codes to decipher any of your information. Kaspersky Labs ascertained that 17% of crypto-ransomware victims never recovered their data after having paid the ransom, resulting in increased losses. The risk is also very costly. Ryuk ransoms are commonly several hundred thousand dollars. For larger organizations, the ransom can be in the millions of dollars. The other path is to piece back together the critical components of your Information Technology environment. Without the availability of full information backups, this requires a broad range of skill sets, professional team management, and the capability to work non-stop until the task is completed.

For two decades, Progent has provided expert Information Technology services for businesses throughout the US and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes consultants who have been awarded high-level certifications in leading technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cybersecurity experts have garnered internationally-recognized certifications including CISA, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has expertise with accounting and ERP application software. This breadth of experience provides Progent the ability to quickly understand important systems and integrate the remaining pieces of your network environment following a ransomware penetration and assemble them into a functioning network.

Progent's security team deploys state-of-the-art project management tools to orchestrate the complicated recovery process. Progent appreciates the urgency of working rapidly and together with a client's management and Information Technology staff to prioritize tasks and to put critical applications back on-line as fast as humanly possible.

Client Case Study: A Successful Ransomware Incident Recovery
A customer contacted Progent after their organization was crashed by the Ryuk ransomware. Ryuk is thought to have been deployed by North Korean state criminal gangs, possibly adopting techniques exposed from America's National Security Agency. Ryuk attacks specific businesses with little or no room for operational disruption and is one of the most profitable versions of crypto-ransomware. Well Known targets include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's customer is a regional manufacturer based in Chicago with about 500 staff members. The Ryuk intrusion had brought down all business operations and manufacturing capabilities. Most of the client's information backups had been directly accessible at the start of the intrusion and were eventually encrypted. The client considered paying the ransom (exceeding $200K) and wishfully thinking for good luck, but ultimately brought in Progent.


"I can't speak enough in regards to the expertise Progent provided us throughout the most critical period of (our) businesses survival. We most likely would have paid the cyber criminals behind the attack if not for the confidence the Progent experts afforded us. That you could get our messaging and essential applications back into operation faster than five days was amazing. Each person I talked with or communicated with at Progent was urgently focused on getting us operational and was working at all hours to bail us out."

Progent worked together with the client to quickly understand and prioritize the mission critical services that had to be addressed to make it possible to resume company functions:

  • Windows Active Directory
  • Email
  • MRP System
To start, Progent followed Anti-virus incident mitigation best practices by halting the spread and performing virus removal steps. Progent then initiated the task of bringing back online Microsoft Active Directory, the core of enterprise systems built on Microsoft Windows Server technology. Exchange email will not function without AD, and the client's accounting and MRP system utilized SQL Server, which requires Windows AD for authentication to the databases.

Within 48 hours, Progent was able to re-build Active Directory to its pre-attack state. Progent then completed setup and storage recovery of key applications. All Microsoft Exchange Server ties and attributes were intact, which facilitated the rebuild of Exchange. Progent was also able to locate local OST data files (Microsoft Outlook Offline Folder Files) on various PCs in order to recover mail messages. A recent off-line backup of the client's financials/ERP systems made them able to restore these essential services back available to users. Although a large amount of work still had to be done to recover completely from the Ryuk damage, critical services were restored quickly:


"For the most part, the production manufacturing operation showed little impact and we did not miss any customer shipments."

Over the following few weeks key milestones in the restoration process were made through tight cooperation between Progent consultants and the customer:

  • Self-hosted web applications were restored without losing any data.
  • The MailStore Microsoft Exchange Server exceeding four million historical messages was spun up and accessible to users.
  • CRM/Orders/Invoicing/Accounts Payable (AP)/Accounts Receivables/Inventory functions were 100 percent functional.
  • A new Palo Alto 850 security appliance was deployed.
  • Nearly all of the desktop computers were functioning as before the incident.

"A huge amount of what was accomplished that first week is mostly a haze for me, but my team will not forget the urgency each of the team put in to help get our business back. I have been working together with Progent for the past ten years, possibly more, and each time I needed help Progent has shined and delivered. This situation was a life saver."

Conclusion
A possible enterprise-killing disaster was avoided by hard-working professionals, a broad spectrum of knowledge, and tight collaboration. Although in analyzing the event afterwards the ransomware virus penetration detailed here would have been identified and blocked with modern security systems and NIST Cybersecurity Framework or ISO/IEC 27001 best practices, team training, and well designed security procedures for information protection and proper patching controls, the fact remains that state-sponsored hackers from China, North Korea and elsewhere are tireless and will continue. If you do get hit by a ransomware incident, remember that Progent's team of professionals has substantial experience in ransomware virus blocking, cleanup, and file disaster recovery.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others who were contributing), thanks very much for allowing me to get rested after we got past the most critical parts. Everyone did an impressive job, and if anyone is in the Chicago area, dinner is the least I can do!"

Download the Crypto-Ransomware Removal Case Study Datasheet
To review or download a PDF version of this ransomware incident report, please click:
Progent's Crypto-Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Consulting Services in Beverly Hills
For ransomware system recovery services in the Beverly Hills metro area, phone Progent at 800-462-8800 or go to Contact Progent.



An index of content::

  • 24 Hour Beverly Hills Netwalker Ransomware Settlement Guidance Beverly Hills-West Hollywood, CA Beverly Hills Snatch Ransomware Settlement Support Beverly Hills
  • 24-Hour Beverly Hills Locky Crypto-Ransomware Operational Recovery Beverly Hills Beverly Hills Egregor Ransomware Cleanup Beverly Hills-West Hollywood
  • Beverly Hills Nephilim Ransomware Cleanup Beverly Hills-West Hollywood, California
  • At Home Workers Beverly Hills Consulting Services - Infrastructure Consulting Beverly Hills Offsite Workforce Integration Consultants
  • Beverly Hills Dharma Ransomware Removal Beverly Hills, United States Beverly Hills 24/7 CryptoLocker Repair Consultants Beverly Hills-West Hollywood, California, U.S.A.
  • Beverly Hills Ransomware Egregor Vulnerability Review Beverly Hills Beverly Hills-West Hollywood, USA Beverly Hills Ransomware Readiness Evaluation
  • Beverly Hills Remote Workforce Collaboration Technology Consultants Beverly Hills-Westwood, California, America Beverly Hills Remote Workers Collaboration Systems Expertise Beverly Hills
  • Beverly Hills Ryuk Crypto-Ransomware Forensics Beverly Hills, CA Beverly Hills Dharma Ransomware Forensics Beverly Hills-Bel Air, CA
  • Beverly Hills Small Business IT Consultant Beverly Hills, California Network Consulting Company
  • Beverly Hills Telecommuters Data Protection Solutions Consulting Experts Beverly Hills Beverly Hills-Century City Beverly Hills Work at Home Employees Backup/Restore Technology Guidance

  • Juniper Firewalls Security Consultancy
    Security Firms Juniper NetScreen VPN

    Progent's Juniper-certified NetScreen engineer can help you to configure and optimize NetScreen 5000 series routers, migrate from previous NetScreen products to the latest Juniper products, and repair network infrastructure problems in all-Juniper or mixed-vendor systems.

  • Beverly Hills Work at Home Employees Security Systems Assistance Beverly Hills-Bel Air, California, United States Beverly Hills-Bel Air At Home Workforce Consulting and Support Services near Beverly Hills - Security Systems Assistance
  • Beverly Hills, CA Computer Network Support Group Cisco and Microsoft Certified Beverly Hills Small Business IT Outsourcing
  • Beverly Hills Avaddon Ransomware System-Restore Beverly Hills-Century City, CA, United States
  • Beverly Hills-Bel Air After Hours Work from Home Employees Beverly Hills Guidance - Integration Solutions Expertise Telecommuters Beverly Hills Consulting Services - Connectivity Consulting Experts Beverly Hills, CA
  • Beverly Hills-Bel Air, CA At Home Workforce Consulting in Beverly Hills - Help Desk Call Center Augmentation Guidance Work at Home Employees Beverly Hills Consulting Experts - Call Desk Solutions Consulting Beverly Hills-Bel Air, California
  • Beverly Hills-Century City, CA Computer Consulting Firm BlackBerry Desktop Manager BlackBerry Wireless Engineer Beverly Hills
  • Beverly Hills-Century City, California Consulting Support for Beverly Hills IT Support Firms Beverly Hills, CA Specialists for Computer Support Organizations nearby Beverly Hills - Temporary Support Staff Expansion
  • Beverly Hills-Century City, California Security Auditor CISSP Urgent Security Computer Security Specialist Beverly Hills-West Hollywood, CA
  • Beverly Hills-West Hollywood, CA Network Engineer Mandrake Linux, Solaris, UNIX Gentoo Linux, Solaris, UNIX Online Technical Support
  • Beverly Hills-Westwood, California Offsite Workforce Consulting Experts - Beverly Hills - VoIP Systems Consulting Emergency Teleworkers Beverly Hills Expertise - VoIP Systems Consulting Experts Beverly Hills-Bel Air, United States

  • Urgent Offsite BDR Services IT Consultant
    ProSight DPS ECHO Cloud Backup Services Remote Support

    ProSight Data Protection Services ECHO from Progent offer small and mid-sized businesses an affordable end-to-end service for secure backup/disaster recovery. For a fixed monthly cost, ProSight DPS automates and monitors your backup processes and enables rapid recovery of critical files, applications and virtual machines that have become unavailable or corrupted due to component failures, software glitches, natural disasters, human mistakes, or malicious attacks such as ransomware. ProSight Data Protection Services can help you back up, recover and restore files, folders, applications, system images, plus Microsoft Hyper-V and VMware images/. Critical data can be backed up on the cloud, to an on-promises device, or mirrored to both. Progent's disaster recovery consultants can deliver advanced expertise to configure ProSight DPS to be compliant with regulatory standards like HIPAA, FINRA, and PCI and, whenever needed, can help you to recover your critical data.

  • Beverly Hills-Westwood, California, US Beverly Hills Nephilim Crypto-Ransomware System-Rebuild 24-7 Beverly Hills Sodinokibi Ransomware System-Restoration

  • Juniper SRX100 Router Computer Security
    After Hours Security Consultancy Juniper SRX5400 Firewall

    Progent's Juniper-certified network engineers can help you evaluate the business case for adopting Juniper's SRX Series gateways, plan and execute cost-effective deployments, configure equipment to reflect your security strategy, and provide ongoing consulting services to help you monitor, manage, update, and troubleshoot your environment in order to maximize the business value of your SRX gateway solution.

  • Biggest Beverly Hills Snatch Crypto-Ransomware Removal Beverly Hills-West Hollywood Beverly Hills Conti Crypto-Ransomware Restoration
  • Consultant CISSP Certified Network Security Architect CISSP Certified Network Security Architect Technology Professional
  • Dynamics Class Designer Great Plains Software
  • Dynamics GP Beverly Hills Gold Partner - Implementation Expert Beverly Hills California Dynamics GP (Great Plains) Partner near me in Beverly Hills - Customization Consultants

  • SentinelOne Endpoint Protection and Response Consultants
    Open Now Engineers SentinelOne Behavior-based Antivirus

    Progent is a reseller and integrator for SentinelOne's Singularity product family, a subscription-based, cloud-first cyberthreat management platform that incorporates machine learning technology and advanced services to deliver cutting-edge endpoint detection and response (EDR).

  • Exchange Server 2013 Technicians Beverly Hills Top Rated Exchange Server 2010 IT Manager Beverly Hills-West Hollywood, California
  • Immediate Small and Midsize Office Information Technology Outsourcing Group 24/7 Small and Midsize Office Security Consulting Services

  • SQL Server 2014 Disaster Recovery Technical Support Services
    SQL Server 2014 and Hyper-V Support

    Microsoft SQL Server 2014 incorporates significant enhancements in key areas including performance, availability, security, and cloud readiness. Microsoft SQL Server 2014 is the first version of Microsoft SQL Server that includes in-memory technology that operates transparently with all types of applications including Online Transaction Processing, data warehousing (DWH), and business analytics. Progent's Microsoft-certified SQL Server 2014 consulting team can deliver efficient remote and onsite consulting services such as planning, deployment, management, remediation, and software development services to enable businesses of all sizes to achieve fast return from their SQL Server 2014 deployment.

  • Information Technology Consulting Firm Windows 2019 Server Beverly Hills-Century City, California Windows Server 2019 Computer Consulting Firm Beverly Hills-Century City, CA

  • Microsoft Small Business Server Professional
    SBS 2008 Configuration

    Microsoft Small Business Server is an affordable collection of server products that provides the foundation for a powerful but easy-to-manage IT network. The technical sophistication of the Microsoft .NET components bundled with Microsoft Small Business Server requires a computer consultant with hands-on experience planning and building cohesive, comprehensive business technology solutions. Progent's SBS Server consultants have an average of over 10 years of experience supporting computer systems powered by Microsoft platforms. This experience ensures you success in installing, managing, and maintaining network solutions that include the Small Business Server package of servers and productivity software.

  • Network Support Group Cisco Beverly Hills-Bel Air Cisco Specialist Beverly Hills-Bel Air

  • 24-Hour Computer Support Help Desk Services Online Support
    Desktop Help Desk Outsourcing Services Support

    Progent's Network Contact Center Outsourcing Support Services for desktop technical support are intended specifically for small businesses who need immediate availability of a Help Desk Service Center with expert telephone support and full escalation options but who have to work within a restricted information technology budget. Key components of Progent's Help Desk Outsourcing Services are Help Desk Support, Optional Remote Access Support, System Evaluation, Expert Prioritization, Virtual Help Desk Call Center Services, By-the-Minute Billing, and Help Desk Call Center Software Recommendation and Deployment.

  • Online Consulting Microsoft SharePoint Server Beverly Hills-West Hollywood, CA Beverly Hills-West Hollywood, US Microsoft SharePoint 2010 Integration Services
  • Ransomware Cryptoworm Recovery Beverly Hills-Westwood, US Beverly Hills Locky Ransomware Hot Line
  • Remote Workers Guidance nearby Beverly Hills - Endpoint Management Solutions Guidance Beverly Hills-West Hollywood Beverly Hills-Westwood, California Beverly Hills At Home Workforce Endpoint Management Tools Expertise

  • Online Help Microsoft LCS Server 2007
    Microsoft Live Communications Server Specialists

    Microsoft Office Communications Server delivers Instant Messaging and presence as part of a scalable, world-class solution offering enhanced security, seamless compatibility with popular Microsoft software, an expandable, industry-standard development platform, and support for regulatory mandates such as HIPAA, Sarbanes-Oxley, and Gramm-Leach-Bliley. Your enterprise can realize cost savings and elevated business efficiencies, increased individual productivity, and better IP security with this easy-to-manage, highly available solution. Successful implementations of Microsoft Office Communications Server call for careful planning and consideration prior to roll out. Progent's Microsoft-authorized professionals can provide the skill necessary to realize all the advantages of Microsoft Office Communications Server throughout your entire organization.

  • Remote Workforce Beverly Hills Consulting - Voice/Video Conferencing Systems Assistance Beverly Hills-Westwood, CA Beverly Hills Offsite Workforce Voice/Video Conferencing Systems Guidance Beverly Hills-Century City, CA
  • SQL Server 2012 IT Technical Support Company Microsoft SQL Server Small Business Specialist Beverly Hills-Westwood
  • Server and Desktop Monitoring and Reporting Integration Services Server Monitoring Professional
  • Beverly Hills Snatch Crypto-Ransomware Remediation Beverly Hills-Westwood, CA
  • Supplemental Staffing Support Consulting Expertise Beverly Hills-Century City, CA Temporary Network Support Staffing Support Consulting Specialist Beverly Hills, CA
  • Support and Setup SCOM 2016 Consulting System Center 2016 Business Continuity
  • Telecommuters Expertise nearby Beverly Hills - Cloud Integration Systems Consultants Teleworkers Consulting and Support Services in Beverly Hills - Cloud Integration Technology Guidance Beverly Hills-Bel Air, CA
  • VBA for Mac Support Word for Mac Onsite Technical Support

  • © 2002-2025 Progent Corporation. All rights reserved.