Progent's Ransomware Forensics and Reporting in Calgary
Progent's ransomware forensics experts can capture the system state after a ransomware assault and perform a detailed forensics investigation without slowing down activity required for business resumption and data recovery. Your Calgary business can utilize Progent's post-attack ransomware forensics report to counter future ransomware assaults, validate the recovery of encrypted data, and meet insurance carrier and governmental reporting requirements.
Ransomware forensics is aimed at discovering and documenting the ransomware attack's progress across the targeted network from start to finish. This audit trail of the way a ransomware assault progressed within the network assists you to assess the damage and uncovers vulnerabilities in rules or processes that should be corrected to prevent future break-ins. Forensics is commonly assigned a high priority by the cyber insurance provider and is often mandated by state and industry regulations. Because forensic analysis can take time, it is critical that other key activities such as business resumption are executed in parallel. Progent maintains an extensive roster of IT and security professionals with the skills needed to perform the work of containment, operational continuity, and data recovery without interfering with forensics.
Ransomware forensics investigation is arduous and calls for close interaction with the teams responsible for data recovery and, if necessary, settlement discussions with the ransomware hacker. Ransomware forensics typically involve the examination of all logs, registry, Group Policy Object (GPO), Active Directory (AD), DNS servers, routers, firewalls, schedulers, and basic Windows systems to detect anomalies.
Services involved with forensics analysis include:
- Isolate but avoid shutting down all possibly impacted devices from the system. This can require closing all Remote Desktop Protocol (RDP) ports and Internet connected NAS storage, changing admin credentials and user passwords, and setting up two-factor authentication to protect your backups.
- Preserve forensically valid duplicates of all exposed devices so the file recovery team can proceed
- Preserve firewall, VPN, and additional key logs as quickly as possible
- Determine the type of ransomware used in the assault
- Inspect each computer and data store on the system as well as cloud-hosted storage for indications of compromise
- Inventory all compromised devices
- Determine the kind of ransomware used in the assault
- Study logs and sessions to establish the timeline of the ransomware attack and to identify any possible sideways migration from the first compromised machine
- Understand the attack vectors exploited to carry out the ransomware assault
- Search for new executables associated with the first encrypted files or system compromise
- Parse Outlook PST files
- Examine attachments
- Extract any URLs embedded in messages and check to see whether they are malicious
- Provide detailed incident reporting to meet your insurance and compliance mandates
- List recommendations to shore up cybersecurity gaps and enforce workflows that reduce the exposure to a future ransomware exploit
Progent's Qualifications
Progent has delivered remote and onsite IT services across the U.S. for more than 20 years and has been awarded Microsoft's Partner designation in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes professionals who have earned high-level certifications in core technology platforms including Cisco infrastructure, VMware virtualization, and major distributions of Linux. Progent's cybersecurity consultants have earned internationally recognized certifications including CISA, CISSP, and CRISC. (Refer to Progent's certifications). Progent also has guidance in financial and Enterprise Resource Planning applications. This breadth of skills allows Progent to salvage and consolidate the undamaged parts of your information system following a ransomware assault and rebuild them quickly into a functioning system. Progent has worked with top insurance carriers including Chubb to assist businesses recover from ransomware assaults.
Contact Progent about Ransomware Forensics Expertise in Calgary
To learn more about how Progent can assist your Calgary organization with ransomware forensics investigation, call 1-800-462-8800 or visit Contact Progent.