Ransomware : Your Worst IT Catastrophe
Ransomware has become a modern cyberplague that presents an enterprise-level threat for organizations poorly prepared for an assault. Multiple generations of ransomware like the CryptoLocker, WannaCry, Locky, SamSam and MongoLock cryptoworms have been circulating for years and continue to inflict destruction. More recent variants of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Snatch or Nephilim, along with additional as yet unnamed malware, not only do encryption of on-line data but also infect many available system backups. Information synchronized to off-site disaster recovery sites can also be encrypted. In a vulnerable environment, this can render automated recovery useless and effectively knocks the entire system back to square one.
Getting back services and information following a crypto-ransomware intrusion becomes a race against the clock as the victim fights to stop lateral movement and clear the ransomware and to restore enterprise-critical operations. Due to the fact that ransomware requires time to move laterally, penetrations are frequently sprung on weekends, when penetrations tend to take more time to notice. This multiplies the difficulty of promptly assembling and orchestrating a knowledgeable mitigation team.
Progent offers a range of solutions for protecting organizations from ransomware attacks. These include staff education to help identify and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for remote monitoring and management, in addition to installation of modern security appliances with machine learning technology from SentinelOne to detect and suppress new threats rapidly. Progent also offers the assistance of veteran crypto-ransomware recovery professionals with the talent and commitment to rebuild a breached environment as rapidly as possible.
Progent's Ransomware Recovery Help
Following a crypto-ransomware event, even paying the ransom in cryptocurrency does not ensure that merciless criminals will provide the codes to decipher any or all of your information. Kaspersky Labs ascertained that 17% of ransomware victims never restored their information even after having paid the ransom, resulting in more losses. The risk is also very costly. Ryuk ransoms frequently range from fifteen to forty BTC ($120,000 and $400,000). This is greatly above the usual ransomware demands, which ZDNET determined to be in the range of $13,000. The other path is to piece back together the vital parts of your Information Technology environment. Without the availability of complete information backups, this calls for a wide range of skill sets, well-coordinated team management, and the willingness to work 24x7 until the recovery project is complete.
For two decades, Progent has provided professional Information Technology services for companies in Recife and throughout the United States and has achieved Microsoft's Gold Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes consultants who have earned high-level certifications in important technologies including Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security experts have garnered internationally-renowned certifications including CISA, CISSP, CRISC, and SANS GIAC. (Visit Progent's certifications). Progent in addition has expertise in accounting and ERP application software. This breadth of experience affords Progent the skills to efficiently ascertain important systems and organize the surviving components of your network system after a ransomware penetration and assemble them into an operational network.
Progent's security team utilizes state-of-the-art project management applications to orchestrate the complex restoration process. Progent knows the urgency of working swiftly and in unison with a client's management and Information Technology resources to assign priority to tasks and to put the most important applications back on line as fast as possible.
Client Case Study: A Successful Ransomware Incident Response
A client hired Progent after their network was crashed by the Ryuk ransomware virus. Ryuk is believed to have been deployed by Northern Korean government sponsored criminal gangs, suspected of using strategies exposed from the United States NSA organization. Ryuk targets specific organizations with little ability to sustain operational disruption and is one of the most profitable examples of ransomware. Headline victims include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's customer is a single-location manufacturing business located in the Chicago metro area with around 500 employees. The Ryuk penetration had shut down all company operations and manufacturing processes. Most of the client's backups had been online at the beginning of the attack and were damaged. The client was evaluating paying the ransom demand (in excess of $200,000) and hoping for good luck, but ultimately reached out to Progent.
"I can't thank you enough about the care Progent gave us during the most fearful period of (our) businesses life. We most likely would have paid the hackers behind this attack if not for the confidence the Progent team provided us. That you were able to get our e-mail and important servers back in less than five days was incredible. Every single person I worked with or e-mailed at Progent was urgently focused on getting our company operational and was working breakneck pace on our behalf."
Progent worked together with the client to quickly identify and assign priority to the mission critical services that needed to be restored to make it possible to resume business functions:
To start, Progent adhered to Anti-virus incident response industry best practices by halting the spread and clearing up compromised systems. Progent then began the work of bringing back online Active Directory, the key technology of enterprise environments built upon Microsoft Windows Server technology. Exchange email will not function without AD, and the client's MRP applications leveraged SQL Server, which depends on Windows AD for security authorization to the information.
- Windows Active Directory
- Microsoft Exchange Email
- MRP System
In less than 48 hours, Progent was able to recover Active Directory to its pre-virus state. Progent then accomplished reinstallations and hard drive recovery of essential systems. All Exchange Server data and attributes were usable, which greatly helped the rebuild of Exchange. Progent was able to locate non-encrypted OST data files (Outlook Email Off-Line Data Files) on staff workstations to recover mail data. A recent off-line backup of the client's accounting/MRP software made them able to return these required programs back on-line. Although major work was left to recover fully from the Ryuk virus, critical systems were recovered rapidly:
"For the most part, the production manufacturing operation showed little impact and we made all customer deliverables."
During the next month key milestones in the restoration process were achieved through tight collaboration between Progent consultants and the client:
- In-house web sites were returned to operation with no loss of information.
- The MailStore Server containing more than 4 million historical messages was brought online and available for users.
- CRM/Customer Orders/Invoicing/Accounts Payable (AP)/AR/Inventory functions were 100 percent restored.
- A new Palo Alto Networks 850 firewall was deployed.
- 90% of the user workstations were being used by staff.
"A lot of what went on that first week is nearly entirely a fog for me, but my management will not forget the care each of you put in to give us our business back. I have been working together with Progent for at least 10 years, maybe more, and each time I needed help Progent has come through and delivered as promised. This event was a testament to your capabilities."
A probable business extinction disaster was dodged through the efforts of top-tier professionals, a broad spectrum of technical expertise, and tight collaboration. Although upon completion of forensics the crypto-ransomware virus penetration described here would have been prevented with modern security solutions and recognized best practices, user and IT administrator education, and well designed security procedures for information backup and applying software patches, the reality is that government-sponsored criminal cyber gangs from China, Russia, North Korea and elsewhere are tireless and are not going away. If you do fall victim to a ransomware penetration, feel confident that Progent's team of experts has proven experience in ransomware virus defense, removal, and file restoration.
"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Chris (and any others that were contributing), thank you for making it so I could get rested after we made it past the initial fire. All of you did an fabulous job, and if anyone that helped is around the Chicago area, a great meal is on me!"
To read or download a PDF version of this ransomware incident report, please click:
Progent's Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)
Additional Ransomware Protection Services Available from Progent
Progent can provide companies in Recife a range of remote monitoring and security evaluation services designed to help you to minimize the threat from ransomware. These services utilize modern artificial intelligence technology to detect zero-day variants of ransomware that can evade traditional signature-based anti-virus solutions.
For 24-Hour Recife Ransomware Remediation Services, call Progent at 800-462-8800 or go to Contact Progent.
- ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
Progent's ProSight Active Security Monitoring is an endpoint protection (EPP) solution that incorporates SentinelOne's cutting edge behavior-based machine learning technology to defend physical and virtual endpoint devices against new malware assaults like ransomware and email phishing, which easily evade legacy signature-based AV tools. ProSight ASM protects local and cloud-based resources and provides a single platform to manage the complete malware attack lifecycle including blocking, infiltration detection, mitigation, remediation, and post-attack forensics. Top features include single-click rollback with Windows Volume Shadow Copy Service (VSS) and automatic system-wide immunization against new attacks. Progent is a SentinelOne Partner, dealer, and integrator. Find out more about Progent's ProSight Active Security Monitoring endpoint protection and ransomware recovery.
- ProSight Enhanced Security Protection: Endpoint Protection and Microsoft Exchange Email Filtering
Progent's ProSight Enhanced Security Protection (ESP) managed services deliver affordable multi-layer protection for physical servers and virtual machines, desktops, mobile devices, and Exchange Server. ProSight ESP utilizes contextual security and advanced machine learning for round-the-clock monitoring and reacting to security threats from all attack vectors. ProSight ESP offers firewall protection, intrusion alerts, device control, and web filtering via leading-edge tools incorporated within a single agent managed from a single control. Progent's data protection and virtualization experts can help your business to design and configure a ProSight ESP environment that meets your organization's specific requirements and that helps you demonstrate compliance with government and industry information security standards. Progent will assist you define and implement security policies that ProSight ESP will manage, and Progent will monitor your network and respond to alarms that call for urgent attention. Progent can also help you to set up and test a backup and restore solution such as ProSight Data Protection Services so you can get back in business rapidly from a potentially disastrous security attack like ransomware. Read more about Progent's ProSight Enhanced Security Protection (ESP) unified endpoint security and Exchange filtering.
- ProSight Data Protection Services (DPS): Managed Backup and Recovery Services
Progent has worked with advanced backup/restore software providers to create ProSight Data Protection Services, a portfolio of subscription-based management offerings that provide backup-as-a-service (BaaS). ProSight DPS products manage and monitor your backup processes and allow non-disruptive backup and fast recovery of vital files, applications, system images, plus VMs. ProSight DPS lets you recover from data loss resulting from equipment failures, natural disasters, fire, malware such as ransomware, user mistakes, malicious insiders, or application bugs. Managed services available in the ProSight Data Protection Services product line include ProSight Altaro VM Backup, ProSight 365 Total Backup (formerly Altaro 365 Backup), ProSight ECHO Backup using Barracuda purpose-built hardware, and ProSight DPS MSP360 Cloud and On-prem Backup. Your Progent service representative can assist you to determine which of these managed backup services are best suited for your IT environment.
- ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
ProSight Email Guard is Progent's spam and virus filtering service that uses the infrastructure of leading data security companies to provide web-based management and comprehensive security for your email traffic. The powerful structure of Email Guard combines a Cloud Protection Layer with a local security gateway appliance to offer complete defense against spam, viruses, Denial of Service Attacks, Directory Harvest Attacks (DHAs), and other email-borne malware. The Cloud Protection Layer serves as a first line of defense and blocks the vast majority of unwanted email from making it to your security perimeter. This reduces your exposure to inbound attacks and saves network bandwidth and storage space. Email Guard's on-premises security gateway appliance adds a further level of inspection for incoming email. For outgoing email, the on-premises gateway provides anti-virus and anti-spam protection, protection against data leaks, and email encryption. The onsite gateway can also help Exchange Server to track and safeguard internal email traffic that stays inside your corporate firewall. For more details, visit Email Guard spam and content filtering.
- ProSight WAN Watch: Network Infrastructure Management
ProSight WAN Watch is a network infrastructure monitoring and management service that makes it simple and inexpensive for small and mid-sized organizations to diagram, track, reconfigure and troubleshoot their connectivity hardware like routers and switches, firewalls, and load balancers plus servers, printers, client computers and other networked devices. Incorporating state-of-the-art RMM technology, ProSight WAN Watch makes sure that infrastructure topology maps are always current, copies and displays the configuration of almost all devices connected to your network, tracks performance, and generates notices when problems are discovered. By automating complex management and troubleshooting activities, WAN Watch can knock hours off ordinary chores like network mapping, expanding your network, finding devices that need important updates, or identifying the cause of performance issues. Learn more about ProSight WAN Watch network infrastructure monitoring and management services.
- ProSight LAN Watch: Server and Desktop Remote Monitoring
ProSight LAN Watch is Progent's server and desktop monitoring service that incorporates advanced remote monitoring and management (RMM) technology to help keep your network operating efficiently by tracking the health of vital assets that power your information system. When ProSight LAN Watch uncovers an issue, an alert is transmitted automatically to your designated IT personnel and your assigned Progent engineering consultant so that all potential issues can be addressed before they have a chance to impact productivity. Find out more about ProSight LAN Watch server and desktop remote monitoring consulting.
- ProSight Virtual Hosting: Hosted Virtual Machines at Progent's World-class Data Center
With Progent's ProSight Virtual Hosting service, a small organization can have its key servers and applications hosted in a secure Tier III data center on a fast virtual host configured and managed by Progent's IT support experts. Under the ProSight Virtual Hosting service model, the client owns the data, the operating system software, and the apps. Since the system is virtualized, it can be moved immediately to a different hardware environment without requiring a lengthy and difficult configuration procedure. With ProSight Virtual Hosting, your business is not tied a single hosting provider. Find out more details about ProSight Virtual Hosting services.
- ProSight IT Asset Management: Network Documentation Management
ProSight IT Asset Management service is a cloud-based IT documentation management service that makes it easy to capture, maintain, find and protect data about your IT infrastructure, procedures, applications, and services. You can quickly find passwords or serial numbers and be alerted about upcoming expirations of SSL certificates ,domains or warranties. By updating and managing your IT infrastructure documentation, you can eliminate as much as 50% of time spent looking for critical information about your IT network. ProSight IT Asset Management includes a centralized location for storing and collaborating on all documents required for managing your business network such as standard operating procedures and self-service instructions. ProSight IT Asset Management also offers advanced automation for gathering and relating IT information. Whether you're making enhancements, doing maintenance, or responding to an emergency, ProSight IT Asset Management delivers the knowledge you need when you need it. Read more about ProSight IT Asset Management service.
- Progent Active Defense Against Ransomware: Machine Learning-based Ransomware Detection and Remediation
Progent's Active Defense Against Ransomware is an endpoint protection service that utilizes cutting edge behavior-based analysis tools to guard endpoints as well as physical and virtual servers against modern malware attacks such as ransomware and file-less exploits, which easily escape traditional signature-matching anti-virus tools. Progent ASM services safeguard local and cloud resources and offers a single platform to automate the entire threat progression including protection, detection, mitigation, remediation, and post-attack forensics. Top capabilities include one-click rollback with Windows Volume Shadow Copy Service and automatic network-wide immunization against new threats. Learn more about Progent's ransomware protection and cleanup services.
- Progent's Outsourced/Shared Call Desk: Help Desk Managed Services
Progent's Support Desk managed services permit your information technology staff to offload Support Desk services to Progent or split activity for Help Desk services seamlessly between your in-house support group and Progent's nationwide pool of IT service engineers and subject matter experts. Progent's Shared Help Desk Service provides a seamless extension of your core support resources. User access to the Service Desk, provision of support, escalation, ticket creation and updates, performance metrics, and management of the service database are consistent whether incidents are taken care of by your in-house support organization, by Progent, or a mix of the two. Read more about Progent's outsourced/shared Help Desk services.
- Progent's Patch Management: Patch Management Services
Progent's managed services for patch management offer organizations of all sizes a flexible and cost-effective solution for assessing, validating, scheduling, implementing, and documenting software and firmware updates to your dynamic information system. In addition to optimizing the protection and functionality of your computer environment, Progent's software/firmware update management services free up time for your IT team to concentrate on line-of-business initiatives and activities that derive maximum business value from your network. Read more about Progent's patch management support services.
- ProSight Duo Multi-Factor Authentication: Access Security, Endpoint Remediation, and Protected Single Sign-on
Progent's Duo authentication managed services incorporate Cisco's Duo cloud technology to protect against compromised passwords by using two-factor authentication (2FA). Duo supports one-tap identity verification with iOS, Google Android, and other personal devices. Using 2FA, whenever you sign into a protected online account and enter your password you are asked to verify your identity via a device that only you have and that uses a separate network channel. A broad selection of out-of-band devices can be utilized as this second form of ID validation such as a smartphone or wearable, a hardware/software token, a landline phone, etc. You can register several verification devices. To find out more about ProSight Duo identity authentication services, see Duo MFA two-factor authentication (2FA) services.
- ProSight Reporting: Real-time Reporting for Ticketing and Network Monitoring Platforms
ProSight Reporting is an expanding suite of in-depth reporting tools designed to integrate with the industry's leading ticketing and network monitoring platforms such as ConnectWise Manage, ConnectWise Automate, Customer Thermometer, Auvik, and SentinelOne. ProSight Reporting uses Microsoft Graph and utilizes color coding to surface and contextualize critical issues like spotty support follow-through or endpoints with out-of-date AVs. By exposing ticketing or network health concerns concisely and in near-real time, ProSight Reporting improves productivity, lowers management overhead, and saves money. For details, see ProSight Reporting for ticketing and network monitoring applications.