Overview of Progent's Ransomware Forensics and Reporting Services in Calgary
Progent's ransomware forensics experts can preserve the system state after a ransomware assault and perform a detailed forensics investigation without interfering with the processes required for business resumption and data restoration. Your Calgary organization can utilize Progent's ransomware forensics documentation to combat subsequent ransomware assaults, assist in the restoration of encrypted data, and comply with insurance and regulatory reporting requirements.
Ransomware forensics investigation involves determining and describing the ransomware assault's storyline across the network from beginning to end. This history of the way a ransomware assault progressed through the network helps you to evaluate the damage and uncovers weaknesses in policies or processes that should be rectified to prevent future break-ins. Forensics is typically assigned a high priority by the cyber insurance provider and is typically mandated by government and industry regulations. Because forensics can be time consuming, it is critical that other important activities like operational resumption are performed concurrently. Progent maintains an extensive team of IT and data security experts with the knowledge and experience required to perform the work of containment, operational continuity, and data recovery without disrupting forensic analysis.
Ransomware forensics investigation is time consuming and calls for close cooperation with the groups focused on data restoration and, if needed, payment discussions with the ransomware attacker. forensics typically involve the examination of all logs, registry, Group Policy Object, AD, DNS servers, routers, firewalls, schedulers, and core Windows systems to check for changes.
Services associated with forensics investigation include:
- Detach but avoid shutting off all possibly suspect devices from the system. This can require closing all RDP ports and Internet connected network-attached storage, modifying admin credentials and user passwords, and implementing 2FA to guard your backups.
- Create forensically sound duplicates of all exposed devices so the data restoration team can get started
- Save firewall, virtual private network, and other critical logs as soon as possible
- Establish the type of ransomware involved in the attack
- Inspect each machine and data store on the network including cloud storage for signs of compromise
- Catalog all encrypted devices
- Establish the type of ransomware involved in the assault
- Study log activity and user sessions to establish the time frame of the ransomware assault and to identify any possible sideways migration from the first compromised machine
- Identify the attack vectors used to carry out the ransomware attack
- Search for new executables surrounding the original encrypted files or network compromise
- Parse Outlook web archives
- Analyze email attachments
- Separate URLs from email messages and check to see whether they are malicious
- Provide detailed attack documentation to meet your insurance carrier and compliance regulations
- Document recommended improvements to close security vulnerabilities and enforce workflows that lower the risk of a future ransomware breach
Progent's Qualifications
Progent has provided remote and on-premises IT services across the U.S. for over two decades and has been awarded Microsoft's Partner designation in the Datacenter and Cloud Productivity practice areas. Progent's roster of SMEs includes consultants who have earned advanced certifications in core technology platforms such as Cisco networking, VMware, and popular Linux distros. Progent's cybersecurity consultants have earned internationally recognized certifications such as CISM, CISSP, and CRISC. (See Progent's certifications). Progent also has guidance in financial and ERP software. This broad array of expertise allows Progent to salvage and integrate the undamaged parts of your information system following a ransomware intrusion and reconstruct them rapidly into a viable network. Progent has worked with top cyber insurance providers like Chubb to assist organizations clean up after ransomware assaults.
Contact Progent about Ransomware Forensics Expertise in Calgary
To learn more information about ways Progent can assist your Calgary business with ransomware forensics, call 1-800-462-8800 or see Contact Progent.