Ransomware : Your Feared Information Technology Nightmare
Crypto-Ransomware has become a too-frequent cyberplague that presents an extinction-level threat for businesses unprepared for an attack. Versions of crypto-ransomware such as Reveton, Fusob, Locky, NotPetya and MongoLock cryptoworms have been circulating for a long time and still cause damage. Modern strains of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Snatch or Nephilim, as well as frequent unnamed malware, not only encrypt on-line data but also infiltrate all accessible system restores and backups. Information synched to cloud environments can also be corrupted. In a poorly designed environment, it can render automatic recovery useless and basically sets the entire system back to square one.
Getting back services and information following a crypto-ransomware event becomes a sprint against time as the targeted organization tries its best to contain the damage, cleanup the virus, and resume mission-critical activity. Due to the fact that crypto-ransomware requires time to spread, penetrations are usually sprung at night, when penetrations tend to take more time to identify. This multiplies the difficulty of rapidly mobilizing and coordinating a knowledgeable response team.
Progent offers a variety of services for protecting organizations from ransomware penetrations. These include staff education to become familiar with and avoid phishing attempts, ProSight Active Security Monitoring for remote monitoring and management, plus installation of the latest generation security appliances with artificial intelligence technology from SentinelOne to discover and suppress new threats intelligently. Progent in addition provides the assistance of expert ransomware recovery professionals with the talent and commitment to rebuild a breached network as rapidly as possible.
Progent's Ransomware Recovery Services
Soon after a crypto-ransomware penetration, sending the ransom in cryptocurrency does not ensure that distant criminals will provide the codes to decrypt any or all of your data. Kaspersky determined that 17% of ransomware victims never restored their files even after having sent off the ransom, resulting in increased losses. The gamble is also very costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger enterprises, the ransom can be in the millions. The alternative is to re-install the vital parts of your Information Technology environment. Absent access to essential information backups, this requires a wide complement of skills, well-coordinated team management, and the capability to work continuously until the job is done.
For two decades, Progent has provided expert IT services for businesses across the United States and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes consultants who have attained top industry certifications in foundation technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security engineers have earned internationally-recognized industry certifications including CISM, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has experience in financial systems and ERP software solutions. This breadth of experience provides Progent the skills to efficiently understand important systems and consolidate the remaining parts of your Information Technology system after a crypto-ransomware attack and configure them into an operational system.
Progent's security team of experts deploys powerful project management tools to orchestrate the complex recovery process. Progent appreciates the importance of working rapidly and together with a client's management and IT staff to assign priority to tasks and to put the most important applications back online as fast as humanly possible.
Customer Case Study: A Successful Crypto-Ransomware Virus Response
A client contacted Progent after their organization was crashed by the Ryuk ransomware. Ryuk is believed to have been launched by Northern Korean state criminal gangs, possibly using technology exposed from the United States NSA organization. Ryuk goes after specific businesses with limited ability to sustain disruption and is among the most profitable iterations of ransomware malware. Well Known victims include Data Resolution, a California-based info warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a single-location manufacturer based in the Chicago metro area and has about 500 employees. The Ryuk event had disabled all company operations and manufacturing processes. The majority of the client's system backups had been online at the start of the intrusion and were destroyed. The client was pursuing financing for paying the ransom demand (more than two hundred thousand dollars) and hoping for the best, but in the end made the decision to use Progent.
"I cannot thank you enough in regards to the expertise Progent gave us throughout the most fearful time of (our) company's survival. We had little choice but to pay the hackers behind this attack if it wasn't for the confidence the Progent team afforded us. The fact that you could get our e-mail system and essential servers back into operation quicker than seven days was something I thought impossible. Each staff member I worked with or e-mailed at Progent was hell bent on getting us back online and was working 24 by 7 on our behalf."
Progent worked hand in hand the customer to rapidly understand and assign priority to the essential areas that needed to be restored in order to restart company operations:
- Active Directory (AD)
- E-Mail
- Accounting/MRP
To start, Progent followed AV/Malware Processes incident mitigation best practices by halting the spread and performing virus removal steps. Progent then initiated the steps of bringing back online Microsoft Active Directory, the key technology of enterprise systems built on Microsoft Windows Server technology. Microsoft Exchange messaging will not operate without AD, and the businesses' financials and MRP system utilized SQL Server, which depends on Active Directory for access to the databases.
Within two days, Progent was able to re-build Active Directory to its pre-intrusion state. Progent then completed rebuilding and hard drive recovery of needed servers. All Exchange Server ties and attributes were usable, which accelerated the restore of Exchange. Progent was also able to find non-encrypted OST data files (Outlook Email Off-Line Folder Files) on staff workstations and laptops in order to recover mail data. A recent off-line backup of the businesses accounting/ERP systems made them able to restore these required applications back available to users. Although a large amount of work was left to recover totally from the Ryuk attack, the most important systems were restored quickly:
"For the most part, the production line operation was never shut down and we produced all customer sales."
During the following few weeks critical milestones in the restoration process were achieved through close collaboration between Progent engineers and the client:
- In-house web applications were brought back up without losing any information.
- The MailStore Exchange Server with over four million archived emails was brought online and available for users.
- CRM/Orders/Invoices/Accounts Payable/Accounts Receivables (AR)/Inventory Control capabilities were completely restored.
- A new Palo Alto 850 firewall was installed.
- Nearly all of the user desktops and notebooks were being used by staff.
"A lot of what happened in the initial days is nearly entirely a fog for me, but I will not forget the dedication each of you put in to give us our company back. I've been working together with Progent for the past 10 years, maybe more, and each time Progent has outperformed my expectations and delivered as promised. This time was no exception but maybe more Herculean."
Conclusion
A probable enterprise-killing catastrophe was avoided through the efforts of dedicated experts, a wide array of technical expertise, and close teamwork. Although upon completion of forensics the ransomware incident described here should have been identified and stopped with up-to-date cyber security technology solutions and security best practices, team education, and well thought out security procedures for data protection and proper patching controls, the reality is that state-sponsored cyber criminals from Russia, North Korea and elsewhere are tireless and are not going away. If you do get hit by a ransomware virus, feel confident that Progent's roster of experts has substantial experience in ransomware virus blocking, remediation, and file restoration.
"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others who were contributing), thanks very much for making it so I could get some sleep after we made it past the initial fire. All of you did an incredible job, and if anyone is in the Chicago area, dinner is on me!"
To review or download a PDF version of this customer case study, please click:
Progent's Crypto-Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Additional Ransomware Protection Services Offered by Progent
Progent can provide businesses in Grand Rapids a range of online monitoring and security evaluation services to help you to reduce the threat from ransomware. These services utilize next-generation machine learning technology to uncover zero-day strains of ransomware that can escape detection by legacy signature-based security solutions.
- ProSight LAN Watch: Server and Desktop Monitoring and Management
ProSight LAN Watch is Progent's server and desktop remote monitoring service that incorporates state-of-the-art remote monitoring and management (RMM) technology to help keep your network operating at peak levels by tracking the state of critical computers that drive your information system. When ProSight LAN Watch uncovers a problem, an alert is transmitted immediately to your specified IT staff and your assigned Progent consultant so all looming problems can be addressed before they can impact productivity. Learn more details about ProSight LAN Watch server and desktop monitoring services.
- ProSight LAN Watch with NinjaOne RMM: Unified RMM Solution for Networks, Servers, and Workstations
ProSight LAN Watch with NinjaOne RMM software delivers a centralized, cloud-driven platform for monitoring and managing your client-server infrastructure by offering an environment for performing common time-consuming jobs. These can include health checking, patch management, automated repairs, endpoint deployment, backup and restore, A/V response, remote access, built-in and custom scripts, asset inventory, endpoint status reporting, and troubleshooting help. If ProSight LAN Watch with NinjaOne RMM identifies a serious issue, it transmits an alarm to your specified IT staff and your assigned Progent technical consultant so that potential issues can be fixed before they impact your network. Find out more details about ProSight LAN Watch with NinjaOne RMM server and desktop remote monitoring consulting.
- ProSight WAN Watch: Infrastructure Remote Monitoring and Management
Progent's ProSight WAN Watch is a network infrastructure management service that makes it easy and inexpensive for smaller organizations to map out, monitor, enhance and debug their connectivity appliances such as routers and switches, firewalls, and access points plus servers, printers, client computers and other devices. Using cutting-edge Remote Monitoring and Management (RMM) technology, ProSight WAN Watch makes sure that network diagrams are kept current, captures and manages the configuration of almost all devices connected to your network, tracks performance, and generates alerts when issues are discovered. By automating complex management and troubleshooting activities, ProSight WAN Watch can cut hours off ordinary chores like network mapping, expanding your network, finding appliances that require important software patches, or isolating performance issues. Learn more details about ProSight WAN Watch network infrastructure management services.
- ProSight Reporting: In-depth Reporting for Ticketing and Network Monitoring Applications
ProSight Reporting is a growing family of real-time and in-depth reporting tools created to work with the industry's leading ticketing and remote network monitoring platforms such as ConnectWise Manage, ConnectWise Automate, Customer Thermometer, Auvik, and SentinelOne. ProSight Reporting incorporates Microsoft Graph and utilizes color coding to highlight and contextualize key issues like inconsistent support follow-up or machines with missing patches. By exposing ticketing or network health concerns clearly and in near-real time, ProSight Reporting enhances productivity, reduces management overhead, and saves money. For more information, visit ProSight Reporting for ticketing and network monitoring platforms.
- ProSight Data Protection Services: Backup and Disaster Recovery Services
Progent has partnered with advanced backup technology providers to produce ProSight Data Protection Services, a family of offerings that deliver backup-as-a-service (BaaS). ProSight DPS services automate and monitor your data backup processes and allow non-disruptive backup and rapid recovery of critical files, apps, system images, and VMs. ProSight DPS helps you recover from data loss caused by equipment failures, natural calamities, fire, malware like ransomware, user error, ill-intentioned employees, or software bugs. Managed backup services available in the ProSight Data Protection Services portfolio include ProSight DPS Altaro VM Backup, ProSight 365 Total Backup (formerly Altaro 365 Backup), ProSight DPS ECHO Backup based on Barracuda dedicated storage, and ProSight MSP360 Hybrid Backup. Your Progent consultant can help you to determine which of these fully managed backup services are best suited for your IT environment.
- ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
ProSight Email Guard is Progent's spam filtering service that uses the technology of top data security vendors to provide web-based management and comprehensive security for all your email traffic. The powerful architecture of Progent's Email Guard integrates a Cloud Protection Layer with a local security gateway appliance to offer advanced protection against spam, viruses, Dos Attacks, Directory Harvest Attacks, and other email-borne threats. The cloud filter serves as a first line of defense and keeps the vast majority of unwanted email from making it to your network firewall. This decreases your vulnerability to external threats and conserves system bandwidth and storage. Email Guard's on-premises gateway device adds a further layer of analysis for inbound email. For outbound email, the on-premises gateway offers anti-virus and anti-spam protection, policy-based Data Loss Prevention, and email encryption. The on-premises gateway can also help Microsoft Exchange Server to track and safeguard internal email that originates and ends within your security perimeter. For more details, see ProSight Email Guard spam and content filtering.
- ProSight Duo Two-Factor Authentication: Identity Validation, Endpoint Remediation, and Secure Single Sign-on
Progent's Duo authentication service plans utilize Cisco's Duo cloud technology to protect against stolen passwords by using two-factor authentication. Duo enables single-tap identity verification on iOS, Android, and other out-of-band devices. Using 2FA, when you sign into a protected online account and enter your password you are requested to confirm who you are via a device that only you have and that uses a different ("out-of-band") network channel. A broad range of out-of-band devices can be utilized for this second means of ID validation such as a smartphone or watch, a hardware token, a landline phone, etc. You may register multiple verification devices. For details about Duo two-factor identity validation services, go to Duo MFA two-factor authentication (2FA) services.
- Outsourced/Co-managed Call Desk: Help Desk Managed Services
Progent's Support Center managed services permit your information technology staff to outsource Help Desk services to Progent or split activity for support services transparently between your in-house network support group and Progent's extensive pool of IT support engineers and subject matter experts. Progent's Co-managed Help Desk Service offers a seamless supplement to your core IT support resources. User interaction with the Help Desk, provision of technical assistance, issue escalation, ticket generation and tracking, efficiency measurement, and management of the support database are consistent regardless of whether issues are resolved by your corporate IT support organization, by Progent, or a mix of the two. Find out more about Progent's outsourced/shared Service Center services.
- Active Defense Against Ransomware: Machine Learning-based Ransomware Identification and Remediation
Progent's Active Protection Against Ransomware is an endpoint protection (EPP) managed service that utilizes next generation behavior analysis technology to guard endpoint devices as well as servers and VMs against modern malware attacks such as ransomware and file-less exploits, which easily escape traditional signature-matching AV tools. Progent Active Security Monitoring services protect local and cloud resources and provides a unified platform to automate the complete malware attack progression including protection, identification, containment, remediation, and forensics. Key features include one-click rollback using Windows Volume Shadow Copy Service (VSS) and real-time system-wide immunization against new threats. Learn more about Progent's ransomware defense and cleanup services.
- ProSight IT Asset Management: Network Documentation Management
ProSight IT Asset Management service is an IT infrastructure documentation management service that makes it easy to create, maintain, find and protect information related to your IT infrastructure, processes, applications, and services. You can quickly find passwords or IP addresses and be warned automatically about upcoming expirations of SSL certificates or warranties. By cleaning up and organizing your IT infrastructure documentation, you can save up to half of time thrown away trying to find critical information about your IT network. ProSight IT Asset Management features a common location for holding and sharing all documents related to managing your network infrastructure such as recommended procedures and How-To's. ProSight IT Asset Management also supports advanced automation for gathering and associating IT data. Whether you're planning improvements, performing maintenance, or reacting to a crisis, ProSight IT Asset Management gets you the information you require when you need it. Learn more about ProSight IT Asset Management service.
- Progent's Patch Management: Software/Firmware Update Management Services
Progent's support services for software and firmware patch management offer businesses of all sizes a versatile and affordable solution for assessing, testing, scheduling, implementing, and tracking updates to your ever-evolving IT system. In addition to maximizing the security and reliability of your computer environment, Progent's software/firmware update management services allow your IT team to focus on line-of-business initiatives and tasks that deliver the highest business value from your information network. Find out more about Progent's software/firmware update management services.
- ProSight Virtual Hosting: Hosted Virtual Machines at Progent's Tier III Data Center
With Progent's ProSight Virtual Hosting service, a small business can have its critical servers and apps hosted in a protected fault tolerant data center on a fast virtual machine host set up and managed by Progent's network support experts. With Progent's ProSight Virtual Hosting model, the client retains ownership of the data, the OS software, and the apps. Because the environment is virtualized, it can be ported easily to a different hardware solution without a time-consuming and technically risky reinstallation process. With ProSight Virtual Hosting, your business is not locked into a single hosting provider. Learn more details about ProSight Virtual Hosting services.
- ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
ProSight Active Security Monitoring (ASM) is an endpoint protection (EPP) service that incorporates SentinelOne's next generation behavior-based machine learning technology to guard physical and virtual endpoint devices against modern malware attacks like ransomware and email phishing, which easily get by traditional signature-matching AV tools. ProSight Active Security Monitoring protects on-premises and cloud-based resources and offers a single platform to automate the complete malware attack progression including blocking, identification, mitigation, remediation, and forensics. Key features include single-click rollback using Windows Volume Shadow Copy Service and automatic system-wide immunization against new threats. Progent is a SentinelOne Partner, reseller, and integrator. Learn more about Progent's ProSight Active Security Monitoring next-generation endpoint protection and ransomware defense.
- ProSight Enhanced Security Protection (ESP): Endpoint Security and Exchange Email Filtering
ProSight Enhanced Security Protection services offer affordable multi-layer protection for physical and virtual servers, desktops, mobile devices, and Exchange email. ProSight ESP uses adaptive security and advanced heuristics for continuously monitoring and responding to security assaults from all attack vectors. ProSight ESP provides firewall protection, intrusion alarms, endpoint management, and web filtering via cutting-edge technologies packaged within one agent managed from a single console. Progent's security and virtualization consultants can assist you to design and configure a ProSight ESP deployment that meets your organization's unique requirements and that allows you demonstrate compliance with legal and industry information protection regulations. Progent will assist you specify and configure policies that ProSight ESP will enforce, and Progent will monitor your network and react to alarms that call for immediate attention. Progent's consultants can also help your company to install and verify a backup and restore system such as ProSight Data Protection Services so you can get back in business quickly from a potentially disastrous cyber attack such as ransomware. Learn more about Progent's ProSight Enhanced Security Protection (ESP) unified endpoint security and Exchange email filtering.
For 24/7/365 Grand Rapids Ransomware Cleanup Consulting, call Progent at 800-462-8800 or go to Contact Progent.