Crypto-Ransomware : Your Worst Information Technology Disaster
Ransomware  Remediation ProfessionalsRansomware has become a modern cyberplague that represents an existential danger for organizations poorly prepared for an assault. Different versions of ransomware such as CrySIS, Fusob, Locky, Syskey and MongoLock cryptoworms have been running rampant for a long time and continue to inflict harm. Newer strains of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Egregor, along with additional as yet unnamed newcomers, not only encrypt online critical data but also infect many available system restores and backups. Data synched to cloud environments can also be ransomed. In a poorly architected environment, it can make automatic restoration hopeless and basically knocks the datacenter back to square one.

Recovering services and information following a ransomware intrusion becomes a sprint against time as the targeted organization tries its best to stop the spread, eradicate the ransomware, and restore mission-critical operations. Due to the fact that ransomware needs time to replicate across a targeted network, assaults are frequently launched on weekends and holidays, when successful attacks are likely to take longer to identify. This multiplies the difficulty of promptly mobilizing and coordinating a knowledgeable response team.

Progent has a variety of help services for protecting Beverly Hills organizations from ransomware attacks. Among these are staff training to become familiar with and not fall victim to phishing scams, ProSight Active Security Monitoring for endpoint detection and response using SentinelOne's behavior-based cyberthreat defense to detect and quarantine day-zero modern malware assaults. Progent also provides the services of seasoned ransomware recovery consultants with the skills and perseverance to re-deploy a compromised network as rapidly as possible.

Progent's Crypto-Ransomware Restoration Services
Subsequent to a ransomware attack, even paying the ransom demands in cryptocurrency does not ensure that cyber criminals will return the codes to decrypt any of your information. Kaspersky Labs estimated that seventeen percent of ransomware victims never restored their information even after having paid the ransom, resulting in increased losses. The risk is also expensive. Ryuk ransoms are commonly a few hundred thousand dollars. For larger enterprises, the ransom can be in the millions of dollars. The alternative is to setup from scratch the key elements of your Information Technology environment. Absent the availability of essential information backups, this calls for a wide complement of skill sets, top notch project management, and the ability to work 24x7 until the job is finished.

For decades, Progent has offered professional Information Technology services for businesses throughout the United States and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes engineers who have earned advanced industry certifications in important technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity consultants have earned internationally-recognized industry certifications including CISA, CISSP-ISSAP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has expertise with financial management and ERP applications. This breadth of expertise affords Progent the ability to quickly understand important systems and integrate the surviving components of your IT environment after a ransomware event and configure them into a functioning network.

Progent's ransomware team of experts uses powerful project management applications to coordinate the sophisticated restoration process. Progent appreciates the urgency of acting rapidly and in unison with a client's management and IT staff to prioritize tasks and to get critical services back on line as soon as possible.

Business Case Study: A Successful Crypto-Ransomware Incident Response
A client hired Progent after their network system was crashed by the Ryuk ransomware. Ryuk is believed to have been created by North Korean state sponsored criminal gangs, suspected of adopting algorithms leaked from the United States NSA organization. Ryuk targets specific companies with little or no ability to sustain operational disruption and is one of the most lucrative versions of ransomware malware. Headline victims include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a small manufacturer headquartered in the Chicago metro area with about 500 employees. The Ryuk penetration had shut down all company operations and manufacturing processes. The majority of the client's data backups had been online at the time of the attack and were destroyed. The client was pursuing financing for paying the ransom demand (in excess of $200K) and hoping for good luck, but in the end engaged Progent.


"I cannot say enough in regards to the help Progent provided us throughout the most fearful time of (our) company's survival. We had little choice but to pay the hackers behind this attack except for the confidence the Progent experts provided us. That you could get our messaging and important applications back on-line quicker than 1 week was earth shattering. Every single person I talked with or communicated with at Progent was amazingly focused on getting our company operational and was working non-stop to bail us out."

Progent worked with the client to quickly assess and prioritize the most important areas that needed to be addressed to make it possible to restart business operations:

  • Active Directory
  • Exchange Server
  • Accounting and Manufacturing Software
To start, Progent followed ransomware incident mitigation industry best practices by stopping lateral movement and clearing up compromised systems. Progent then initiated the task of restoring Microsoft AD, the foundation of enterprise environments built upon Microsoft Windows Server technology. Microsoft Exchange Server email will not function without Active Directory, and the client's accounting and MRP software used Microsoft SQL Server, which depends on Active Directory for security authorization to the information.

Within 2 days, Progent was able to recover Active Directory to its pre-virus state. Progent then charged ahead with setup and hard drive recovery of essential systems. All Exchange schema and attributes were intact, which facilitated the restore of Exchange. Progent was also able to collect intact OST files (Outlook Email Off-Line Data Files) on team PCs to recover email messages. A recent off-line backup of the businesses accounting/ERP software made them able to return these essential applications back servicing users. Although a lot of work was left to recover fully from the Ryuk event, essential services were recovered rapidly:


"For the most part, the assembly line operation was never shut down and we made all customer orders."

Over the next few weeks important milestones in the recovery process were accomplished through tight collaboration between Progent engineers and the client:

  • Internal web sites were restored without losing any information.
  • The MailStore Server containing more than 4 million archived messages was brought on-line and available for users.
  • CRM/Customer Orders/Invoicing/Accounts Payable/Accounts Receivables (AR)/Inventory functions were completely restored.
  • A new Palo Alto Networks 850 firewall was set up.
  • 90% of the user desktops were back into operation.

"A huge amount of what happened those first few days is mostly a fog for me, but our team will not forget the countless hours each and every one of your team put in to give us our business back. I have been working together with Progent for the past ten years, maybe more, and every time Progent has outperformed my expectations and delivered. This time was a Herculean accomplishment."

Conclusion
A possible business extinction catastrophe was evaded by results-oriented experts, a wide spectrum of knowledge, and close teamwork. Although upon completion of forensics the ransomware penetration described here should have been disabled with up-to-date security solutions and NIST Cybersecurity Framework best practices, user training, and well thought out incident response procedures for data backup and keeping systems up to date with security patches, the fact remains that government-sponsored criminal cyber gangs from China, Russia, North Korea and elsewhere are tireless and are an ongoing threat. If you do fall victim to a ransomware attack, feel confident that Progent's team of experts has proven experience in ransomware virus defense, cleanup, and file restoration.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Chris (along with others who were contributing), I'm grateful for making it so I could get some sleep after we made it over the first week. All of you did an fabulous effort, and if anyone is in the Chicago area, a great meal is the least I can do!"

Download the Ransomware Removal Case Study Datasheet
To read or download a PDF version of this customer case study, click:
Progent's Crypto-Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Consulting Services in Beverly Hills
For ransomware system recovery consulting in the Beverly Hills metro area, phone Progent at 800-462-8800 or go to Contact Progent.



An index of content::

  • After Hours DopplePaymer Ransomware Hot Line Beverly Hills-West Hollywood, California Maze Ransomware Hot Line Beverly Hills
  • At Home Workers Consulting Services - Beverly Hills - Conferencing Technology Guidance Beverly Hills-Century City, California Work from Home Employees Consulting Services near me in Beverly Hills - Video Conferencing Systems Consulting
  • Award Winning Windows 2019 Server Computer Consulting Company Microsoft Windows Server 2016 Server Troubleshoot Expert Beverly Hills-Century City, California
  • Beverly Hills At Home Workers Cybersecurity Systems Assistance Beverly Hills-West Hollywood, CA Beverly Hills Offsite Workforce Cybersecurity Solutions Assistance Beverly Hills, America
  • Beverly Hills At Home Workforce Call Desk Solutions Consultants Beverly Hills-Bel Air Work from Home Employees Beverly Hills Consulting Experts - Help Desk Call Center Outsourcing Consulting Experts Beverly Hills

  • 24x7 Juniper Junos Network and Security Manager Cybersecurity Firm
    Juniper Junos BGT Cybersecurity Consultancy

    Progent's Juniper Networks-certified network consultants can assist you to plan and deploy Juniper Firewall and VPN technology, optimize and support your infrastructure, and upgrade smoothly from outdated products to current releases. Progent's Junos OS engineers can also provide expertise with Juniper's flagship network control software to help you to streamline the management and strengthen the protection of your Juniper VPN devices firewalls, and routers. Progent also has broad background supporting Juniper's NetScreen OS and ScreenOS software productss and can help you manage networks that include a combination of Juniper's OS platforms.

  • Beverly Hills Beverly Hills Telecommuters Management Systems Consulting Experts At Home Workforce Expertise - Beverly Hills - Management Tools Expertise Beverly Hills-Westwood, CA
  • Beverly Hills Consulting for IT Service Providers Beverly Hills-Century City, California Largest Beverly Hills Consulting for IT Service Firms Beverly Hills-West Hollywood, California
  • Beverly Hills Crypto-Ransomware Forensics Analysis Beverly Hills-Bel Air, CA Beverly Hills Hermes Crypto-Ransomware Forensics Analysis
  • Beverly Hills Dharma Ransomware Operational Recovery Beverly Hills Beverly Hills, CA Beverly Hills Ryuk Ransomware Counter-Measures
  • Beverly Hills Offsite Workforce Collaboration Solutions Expertise Beverly Hills-Bel Air, California At Home Workers Beverly Hills Expertise - Collaboration Technology Consulting Experts

  • Citrix XenCenter Consultant
    Consult Citrix Live Migration

    Progent's Citrix-certified engineers can assist your company to evaluate the strategic benefits of XenServer as well as additional Citrix platforms, and can assist your IT organization to design, validate, execute, troubleshoot, and maintain a Citrix XenServer installation. Progent can also analyze your existing XenServer deployment and help you to optimize resource utilization, performance, protection, uptime, and disaster recovery.

  • Beverly Hills-West Hollywood, United States 24-7 Beverly Hills MongoLock Crypto-Ransomware File-Recovery
  • Beverly Hills Phobos Ransomware Business-Recovery Beverly Hills-Century City Top Beverly Hills Dharma Ransomware Cleanup Beverly Hills-Westwood, CA
  • Beverly Hills Ransomware Conti protection and ransomware recovery Beverly Hills-Bel Air, California Beverly Hills Crypto-Ransomware Susceptibility Audit Beverly Hills-Westwood
  • Beverly Hills Spora Crypto-Ransomware System-Restoration Beverly Hills Beverly Hills Beverly Hills Snatch Crypto-Ransomware Mitigation
  • Beverly Hills Technology Consultant Beverly Hills-Hollywood Support Company
  • Beverly Hills Teleworkers Backup/Restore Solutions Consulting Beverly Hills Beverly Hills, CA Beverly Hills Work from Home Employees Data Protection Technology Guidance
  • Beverly Hills, CA Beverly Hills Remote Workers Integration Consultants Beverly Hills Teleworkers Setup Guidance Beverly Hills-Bel Air, CA
  • Beverly Hills-Bel Air Beverly Hills Spora Crypto-Ransomware Settlement Support Beverly Hills Ryuk Crypto-Ransomware Settlement Negotiation Expertsn Beverly Hills-Century City, California
  • Beverly Hills-Century City Award Winning Beverly Hills Offsite Workforce VoIP Technology Guidance Award Winning Work from Home Employees Guidance near Beverly Hills - VoIP Solutions Consulting Services

  • SCCM 2012 Patch Management Consulting Services
    24x7 SCCM 2012 Troubleshooting Support Outsourcing

    Progent's Microsoft-certified consultants can assist you to plan for, deploy, and operate Microsoft System Center 2012 R2 Configuration Manager (SCCM 2012). Progent can help you to upgrade smoothly to SCCM 2012 from an older device and application management platform or help you to modify your existing SCCM 2012 environment to support your changing business requirements. In addition, Progent can assist you to create an infrastructure that takes full advantage of SCCM 2012 by providing advanced consulting support for related Microsoft platforms including Active Directory Domain Services (ADDS), Microsoft SQL SSRS, and Internet Information Services (IIS).

  • Beverly Hills DopplePaymer Crypto-Ransomware Business-Recovery Beverly Hills, CA
  • Beverly Hills-Westwood Computer Services Microsoft Expert Network Support Service Beverly Hills, California

  • 24x7x365 IT Consultants Shared Help Desk
    Extended Help Desk Online Troubleshooting

    Progent's Co-managed Call Center service makes it possible for your IT organization to split the load for Help Desk services seamlessly between your IT team and Progent's roster of veteran technical support engineers and subject matter experts. Progent's Co-managed Help Desk service is a collaborative service desk solution based on ConnectWise Manage, the leading shared professional services automation (PSA) platform for managing end-user service requests, ticketing, ownership, progress tracking, and reporting.

  • BlackBerry BES Express Consulting Urgent BlackBerry BES Server Express Consulting
  • Cisco Small Business Computer Consulting Group Cisco Professionals Beverly Hills, CA
  • Cisco Small Business series NSS3000 Technology Consulting Consultant Cisco Continuous Data Protection
  • Crypto Removal Consultants Beverly Hills NotPetya Ransomware Damage Assessment and Recovery Beverly Hills-Westwood, California
  • Dynamics NAV MRP Contract Programming Microsoft Dynamics 365 Business Central Applications Consulting
  • Extended Call Desk Setup and Support Microsoft and Cisco Virtual Service Desk On-site Support
  • Firewall Network Install Firewall Beverly Hills-West Hollywood, CA Security Security Consultancy Beverly Hills, CA, United States
  • Mandrake Linux, Sun Solaris, UNIX Support Services Beverly Hills-Bel Air, California, U.S.A. Debian Linux, Sun Solaris, UNIX Technical Consultant Beverly Hills
  • Microsoft SharePoint 2010 Network Consultant Beverly Hills-Westwood, California SharePoint 2013 Online Consulting Beverly Hills, CA, US
  • Offsite Workforce Assistance - Beverly Hills - Integration Solutions Consulting Services Beverly Hills California Work from Home Employees Consultants - Beverly Hills - Solutions Consulting Beverly Hills-Century City, California
  • SQL Server 2016 and Windows Server 2012 R2 On-site Support Emergency Support and Help SQL Server Management Studio

  • Server Monitoring Information Technology Consulting
    24-Hour Cisco Certified Experts Monitoring and Reporting Network Engineer

    Remote continuous monitoring, proactive alerts, and actionable reports are crucial to maintaining the proper operation of your IT system and eliminating unnecessary and expensive downtime. Remote Monitoring and Management (RMM) solutions have advanced so far that companies of any size can get a level of protection that was previously limited to large enterprises. Progent offers several RMM solutions delivered as low-cost service packages designed to help your company to detect and resolve a most network issues before they get big enough to hurt your business.

  • SQL Server Networking Firms Beverly Hills-Westwood, CA System Repair Microsoft SQL 2014
  • Snatch ransomware recovery Services Consult ransomware cleanup and restore

  • Citrix XenServer Security Outsourcing
    Setup and Support Signature-based Virus Protection

    Progent's ProSight Enhanced Security Protection (ESP) managed services deliver economical in-depth security for physical servers and VMs, desktops, mobile devices, and Exchange email. ProSight ESP uses contextual security and modern behavior analysis for continuously monitoring and responding to cyber assaults from all vectors. ProSight ESP offers firewall protection, intrusion alarms, device management, and web filtering through leading-edge tools packaged within one agent accessible from a unified console. Progent's data protection and virtualization consultants can help your business to design and configure a ProSight ESP environment that addresses your organization's unique needs and that allows you achieve and demonstrate compliance with legal and industry data security standards. Progent will help you specify and implement policies that ProSight ESP will enforce, and Progent will monitor your IT environment and react to alarms that require immediate attention. Progent can also assist you to set up and test a backup and disaster recovery solution like ProSight Data Protection Services so you can recover rapidly from a destructive cyber attack like ransomware.

  • Solaris Online Consulting Sun Solaris Professional

  • Microsoft System Center OpsMgr 2012 R2 Network Consultants
    24/7/365 Integration Services System Center OpsMgr 2012

    Progent's Microsoft-certified consultants have over a decade of background designing, implementing, optimizing and troubleshooting Microsoft SCOM environments and offer organizations of any size expert remote or on-premises consulting support for System Center 2012 Operations Manager. Progent can assist you to design an architecture for System Center 2012 Operations Manager servers that delivers the responsiveness and resilience needed to watch over your datacenter efficiently, whether your datacenters are on-premises, cloud-based, or a hybrid environment. Progent's SCOM consultants can also help you to import and set up Microsoft SCOM 2012 management packs based on best practices for tracking network fabric and both Microsoft and third-party applications and services. In addition, Progent can provide fast remote or onsite technical support to help you to fix critical issues uncovered by System Center 2012 Operations Manager.

  • Support Specialist Exchange Server 2013 Beverly Hills-Westwood, California Support Consultant Microsoft Exchange Server 2013 Beverly Hills-Bel Air, CA
  • Top Quality MS Dynamics GP-Software Beverly Hills Vendor - Reporting Help Beverly Hills-Westwood, California Beverly Hills MS Dynamics GP-Great Plains Training Consultants Beverly Hills-Bel Air

  • Private Cloud Hosting for Virtual Data Centers Consultants
    Consultant ProSight Private Cloud Services

    Progent's ProSight Virtual hosting services offer small companies a range of benefits such as reduced capital costs, savings on operational costs, better management focus, world-class security, enhanced fault tolerance, and business continuity.

  • Top Ranked Power BI Gateway Design Firms Power BI Reports Reporting
  • Urgent Beverly Hills IT Staffing Temps Support Services IT Staff Augmentation for Network Support Organizations Beverly Hills California

  • Remote Google Cloud Natural Language Specialist
    Google Cloud Backup Consulting Services

    Progent offers cost-effective online and onsite support to assist companies of any size to move all or part of their critical IT infrastructure to Google Cloud Platform (GCP). This can save management hassle and hardware costs and allow the use of Google's cutting edge machine learning technology. Progent can assist you with every phase of Google Cloud Platform migration and troubleshooting including needs analysis, readiness assessment, architectural design, testing, configuration, administration, performance tuning, licensing management, disaster recovery solutions, and security and compliance.

  • Urgent Software Recovery BlackBerry BPS Beverly Hills-Century City, CA Beverly Hills-West Hollywood BlackBerry Wireless Security Consulting
  • Work from Home Employees Consulting near Beverly Hills - Cloud Solutions Consulting and Support Services Beverly Hills-Century City, California Remote Workers Beverly Hills Consulting - Cloud Integration Systems Guidance Beverly Hills-Century City, CA, U.S.A.
  • Beverly Hills Maze Crypto-Ransomware Operational-Recovery Beverly Hills-Westwood

  • © 2002-2026 Progent Corporation. All rights reserved.