Ransomware : Your Feared IT Catastrophe
Ransomware has become an escalating cyber pandemic that presents an enterprise-level danger for businesses unprepared for an assault. Versions of ransomware such as CrySIS, WannaCry, Locky, NotPetya and MongoLock cryptoworms have been out in the wild for years and still inflict destruction. More recent strains of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit or Nephilim, as well as more unnamed viruses, not only do encryption of online files but also infiltrate any configured system protection. Data replicated to the cloud can also be ransomed. In a poorly designed data protection solution, this can make automated recovery impossible and basically knocks the datacenter back to square one.
Restoring services and data following a crypto-ransomware attack becomes a race against time as the victim struggles to contain the damage, eradicate the ransomware, and restore business-critical activity. Due to the fact that crypto-ransomware needs time to spread, attacks are frequently launched on weekends, when successful penetrations in many cases take longer to detect. This multiplies the difficulty of rapidly mobilizing and orchestrating a qualified mitigation team.
Progent makes available an assortment of support services for securing organizations from ransomware penetrations. These include team training to help recognize and avoid phishing exploits, ProSight Active Security Monitoring for remote monitoring and management, in addition to deployment of modern security appliances with artificial intelligence technology from SentinelOne to identify and disable zero-day cyber threats quickly. Progent in addition can provide the services of expert ransomware recovery consultants with the talent and commitment to rebuild a breached environment as rapidly as possible.
Progent's Crypto-Ransomware Restoration Services
Subsequent to a ransomware invasion, paying the ransom demands in cryptocurrency does not guarantee that merciless criminals will provide the keys to decrypt any of your data. Kaspersky determined that 17% of ransomware victims never restored their files even after having sent off the ransom, resulting in more losses. The gamble is also expensive. Ryuk ransoms are commonly several hundred thousand dollars. For larger organizations, the ransom demand can reach millions of dollars. The other path is to setup from scratch the key parts of your Information Technology environment. Absent the availability of essential system backups, this calls for a wide range of skills, well-coordinated project management, and the capability to work continuously until the recovery project is completed.
For decades, Progent has offered expert Information Technology services for businesses throughout the United States and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes consultants who have earned high-level certifications in key technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security specialists have garnered internationally-recognized industry certifications including CISA, CISSP-ISSAP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has experience with accounting and ERP applications. This breadth of expertise gives Progent the ability to quickly identify important systems and re-organize the remaining components of your Information Technology system following a ransomware penetration and configure them into an operational network.
Progent's ransomware team utilizes powerful project management applications to coordinate the sophisticated restoration process. Progent appreciates the urgency of acting quickly and in concert with a customer's management and Information Technology staff to assign priority to tasks and to get critical services back online as fast as humanly possible.
Client Story: A Successful Crypto-Ransomware Incident Restoration
A client engaged Progent after their organization was brought down by the Ryuk ransomware. Ryuk is thought to have been developed by Northern Korean state cybercriminals, possibly using technology exposed from the U.S. National Security Agency. Ryuk seeks specific companies with little tolerance for operational disruption and is among the most profitable examples of ransomware viruses. Major victims include Data Resolution, a California-based information warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a small manufacturing company headquartered in the Chicago metro area with about 500 employees. The Ryuk attack had disabled all business operations and manufacturing capabilities. The majority of the client's data backups had been directly accessible at the start of the intrusion and were destroyed. The client was actively seeking loans for paying the ransom (in excess of $200K) and wishfully thinking for good luck, but ultimately reached out to Progent.
"I cannot thank you enough in regards to the care Progent provided us during the most critical time of (our) company's survival. We may have had to pay the cyber criminals behind the attack if not for the confidence the Progent experts gave us. The fact that you were able to get our e-mail and important applications back into operation in less than seven days was incredible. Each expert I talked with or communicated with at Progent was amazingly focused on getting us back online and was working at all hours on our behalf."
Progent worked hand in hand the customer to quickly determine and assign priority to the critical elements that had to be addressed to make it possible to restart company operations:
- Windows Active Directory
- Electronic Mail
- Financials/MRP
To get going, Progent adhered to Anti-virus penetration mitigation industry best practices by halting lateral movement and performing virus removal steps. Progent then initiated the process of rebuilding Windows Active Directory, the foundation of enterprise systems built on Microsoft Windows technology. Exchange email will not function without AD, and the customer's accounting and MRP software utilized Microsoft SQL Server, which needs Active Directory services for security authorization to the databases.
Within two days, Progent was able to restore Active Directory to its pre-attack state. Progent then charged ahead with reinstallations and hard drive recovery of key applications. All Microsoft Exchange Server data and attributes were intact, which accelerated the rebuild of Exchange. Progent was also able to locate intact OST files (Outlook Off-Line Folder Files) on team PCs and laptops in order to recover email messages. A not too old offline backup of the customer's accounting/ERP software made them able to recover these vital services back online. Although a lot of work remained to recover totally from the Ryuk damage, core services were restored quickly:
"For the most part, the production manufacturing operation was never shut down and we made all customer sales."
Throughout the next few weeks important milestones in the recovery project were completed through tight collaboration between Progent engineers and the client:
- Internal web applications were returned to operation with no loss of data.
- The MailStore Server with over 4 million historical messages was brought on-line and available for users.
- CRM/Orders/Invoicing/Accounts Payable (AP)/AR/Inventory Control functions were fully operational.
- A new Palo Alto Networks 850 security appliance was brought online.
- Nearly all of the desktops and laptops were back into operation.
"Much of what transpired that first week is mostly a fog for me, but we will not soon forget the dedication each of your team put in to help get our company back. I've entrusted Progent for at least 10 years, possibly more, and each time Progent has outperformed my expectations and delivered as promised. This event was a life saver."
Conclusion
A potential business disaster was averted with dedicated professionals, a wide range of IT skills, and tight teamwork. Although upon completion of forensics the ransomware penetration described here should have been identified and stopped with modern cyber security technology solutions and NIST Cybersecurity Framework or ISO/IEC 27001 best practices, user and IT administrator education, and properly executed security procedures for data protection and keeping systems up to date with security patches, the fact is that government-sponsored hackers from China, North Korea and elsewhere are relentless and are not going away. If you do get hit by a ransomware incident, remember that Progent's team of experts has substantial experience in ransomware virus blocking, remediation, and data restoration.
"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Tony (along with others who were involved), I'm grateful for allowing me to get rested after we got past the most critical parts. Everyone did an impressive effort, and if any of your team is in the Chicago area, dinner is on me!"
To read or download a PDF version of this case study, click:
Progent's Crypto-Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)
Additional Ransomware Protection Services Offered by Progent
Progent offers businesses in San Diego a portfolio of remote monitoring and security assessment services designed to assist you to minimize the threat from ransomware. These services include next-generation AI capability to detect new strains of ransomware that can evade traditional signature-based security products.
- ProSight LAN Watch: Server and Desktop Monitoring
ProSight LAN Watch is Progent's server and desktop monitoring service that incorporates advanced remote monitoring and management (RMM) techniques to help keep your network operating efficiently by checking the health of critical computers that power your information system. When ProSight LAN Watch detects a problem, an alert is transmitted automatically to your specified IT staff and your Progent engineering consultant so that any potential issues can be resolved before they can impact your network. Find out more about ProSight LAN Watch server and desktop monitoring services.
- ProSight LAN Watch with NinjaOne RMM: Centralized RMM Solution for Networks, Servers, and Desktops
ProSight LAN Watch with NinjaOne RMM software delivers a unified, cloud-driven platform for monitoring and managing your client-server infrastructure by providing tools for streamlining common tedious jobs. These include health checking, patch management, automated remediation, endpoint configuration, backup and recovery, A/V protection, secure remote access, built-in and custom scripts, resource inventory, endpoint profile reporting, and troubleshooting assistance. If ProSight LAN Watch with NinjaOne RMM uncovers a serious incident, it sends an alert to your specified IT staff and your assigned Progent technical consultant so potential issues can be fixed before they impact productivity. Learn more details about ProSight LAN Watch with NinjaOne RMM server and desktop monitoring consulting.
- ProSight WAN Watch: Network Infrastructure Remote Monitoring and Management
ProSight WAN Watch is a network infrastructure management service that makes it easy and affordable for small and mid-sized organizations to map, monitor, reconfigure and debug their networking hardware like routers, firewalls, and wireless controllers as well as servers, printers, client computers and other networked devices. Using state-of-the-art Remote Monitoring and Management technology, ProSight WAN Watch makes sure that network maps are always current, copies and displays the configuration of almost all devices connected to your network, tracks performance, and sends alerts when issues are discovered. By automating complex network management processes, ProSight WAN Watch can cut hours off common tasks such as network mapping, expanding your network, finding appliances that need important software patches, or isolating performance issues. Learn more details about ProSight WAN Watch network infrastructure monitoring and management services.
- ProSight Reporting: Real-time Reporting for Ticketing and Network Monitoring Platforms
ProSight Reporting is an expanding suite of real-time and in-depth management reporting plug-ins created to work with the top ticketing and network monitoring programs such as ConnectWise Manage, ConnectWise Automate, Customer Thermometer, Auvik, and SentinelOne. ProSight Reporting incorporates Microsoft Graph and utilizes color coding to surface and contextualize key issues like spotty support follow-through or machines with out-of-date AVs. By exposing ticketing or network health concerns clearly and in near-real time, ProSight Reporting enhances productivity, reduces management overhead, and saves money. For more information, visit ProSight Reporting for ticketing and network monitoring applications.
- ProSight Data Protection Services (DPS): Backup and Recovery Services
Progent has worked with advanced backup/restore technology providers to produce ProSight Data Protection Services, a portfolio of subscription-based management offerings that provide backup-as-a-service (BaaS). ProSight DPS services automate and track your data backup processes and enable non-disruptive backup and rapid recovery of important files, apps, system images, and VMs. ProSight DPS helps you protect against data loss resulting from equipment breakdown, natural disasters, fire, cyber attacks like ransomware, human mistakes, malicious insiders, or software glitches. Managed backup services available in the ProSight Data Protection Services product family include ProSight Altaro VM Backup, ProSight 365 Total Backup (formerly Altaro 365 Backup), ProSight ECHO Backup based on Barracuda purpose-built storage, and ProSight MSP360 Hybrid Backup. Your Progent service representative can help you to identify which of these fully managed services are best suited for your network.
- ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
ProSight Email Guard is Progent's spam and virus filtering service that uses the technology of leading data security vendors to provide centralized control and comprehensive security for your email traffic. The hybrid structure of Email Guard integrates cloud-based filtering with an on-premises security gateway device to offer complete protection against spam, viruses, Denial of Service (DoS) Attacks, Directory Harvest Attacks (DHAs), and other email-based threats. Email Guard's Cloud Protection Layer acts as a first line of defense and keeps the vast majority of threats from making it to your network firewall. This decreases your exposure to inbound threats and conserves system bandwidth and storage. Email Guard's on-premises gateway appliance adds a deeper layer of analysis for inbound email. For outbound email, the local gateway offers anti-virus and anti-spam protection, protection against data leaks, and email encryption. The local gateway can also help Microsoft Exchange Server to monitor and protect internal email traffic that originates and ends within your corporate firewall. For more details, visit Email Guard spam and content filtering.
- ProSight Duo Two-Factor Authentication: Identity Validation, Endpoint Policy Enforcement, and Protected Single Sign-on (SSO)
Progent's Duo authentication managed services incorporate Cisco's Duo cloud technology to protect against stolen passwords by using two-factor authentication (2FA). Duo enables one-tap identity verification with Apple iOS, Google Android, and other personal devices. With Duo 2FA, whenever you log into a secured application and give your password you are requested to verify your identity on a unit that only you possess and that uses a separate network channel. A broad range of devices can be used for this added means of ID validation including an iPhone or Android or watch, a hardware token, a landline phone, etc. You can designate several validation devices. For more information about Duo identity authentication services, go to Cisco Duo MFA two-factor authentication services.
- Progent's Outsourced/Shared Call Center: Support Desk Managed Services
Progent's Call Desk managed services permit your IT staff to offload Support Desk services to Progent or split activity for Service Desk support seamlessly between your in-house network support team and Progent's nationwide pool of IT support technicians, engineers and subject matter experts. Progent's Shared Service Desk provides a transparent extension of your in-house support staff. User interaction with the Service Desk, delivery of technical assistance, issue escalation, ticket generation and updates, performance metrics, and maintenance of the service database are consistent regardless of whether incidents are taken care of by your internal network support organization, by Progent, or both. Learn more about Progent's outsourced/shared Call Center services.
- Active Protection Against Ransomware: Machine Learning-based Ransomware Detection and Remediation
Progent's Active Protection Against Ransomware is an endpoint protection (EPP) solution that incorporates cutting edge behavior-based machine learning tools to defend endpoint devices as well as servers and VMs against new malware attacks such as ransomware and email phishing, which routinely escape traditional signature-based AV tools. Progent ASM services safeguard on-premises and cloud resources and offers a single platform to manage the complete threat lifecycle including blocking, identification, mitigation, remediation, and post-attack forensics. Top capabilities include single-click rollback using Windows Volume Shadow Copy Service (VSS) and automatic network-wide immunization against newly discovered threats. Find out more about Progent's ransomware defense and recovery services.
- ProSight IT Asset Management: Network Documentation Management
ProSight IT Asset Management service is a cloud-based IT documentation management service that allows you to capture, maintain, retrieve and safeguard data about your IT infrastructure, processes, applications, and services. You can quickly find passwords or IP addresses and be alerted automatically about impending expirations of SSLs ,domains or warranties. By updating and managing your IT documentation, you can eliminate up to 50% of time spent trying to find critical information about your network. ProSight IT Asset Management features a common location for holding and sharing all documents related to managing your business network such as standard operating procedures (SOPs) and self-service instructions. ProSight IT Asset Management also supports a high level of automation for collecting and relating IT data. Whether you're making improvements, doing maintenance, or responding to a crisis, ProSight IT Asset Management delivers the data you need the instant you need it. Learn more about ProSight IT Asset Management service.
- Patch Management: Software/Firmware Update Management Services
Progent's support services for software and firmware patch management offer organizations of all sizes a versatile and cost-effective solution for evaluating, testing, scheduling, implementing, and tracking software and firmware updates to your dynamic information system. Besides maximizing the protection and reliability of your IT network, Progent's software/firmware update management services permit your in-house IT team to concentrate on line-of-business projects and tasks that derive the highest business value from your information network. Learn more about Progent's patch management services.
- ProSight Virtual Hosting: Hosted Virtual Machines at Progent's World-class Data Center
With Progent's ProSight Virtual Hosting service, a small business can have its key servers and apps hosted in a secure Tier III data center on a high-performance virtual machine host configured and managed by Progent's network support experts. Under the ProSight Virtual Hosting model, the client retains ownership of the data, the operating system software, and the apps. Since the environment is virtualized, it can be ported immediately to an alternate hardware environment without a time-consuming and technically risky reinstallation procedure. With ProSight Virtual Hosting, your business is not tied one hosting provider. Learn more about ProSight Virtual Hosting services.
- ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
ProSight Active Security Monitoring (ASM) is an endpoint protection solution that utilizes SentinelOne's cutting edge behavior-based analysis tools to defend physical and virtual endpoint devices against modern malware assaults like ransomware and email phishing, which easily escape legacy signature-matching anti-virus products. ProSight Active Security Monitoring safeguards on-premises and cloud resources and offers a unified platform to manage the complete threat lifecycle including protection, infiltration detection, containment, cleanup, and post-attack forensics. Key features include single-click rollback using Windows Volume Shadow Copy Service and real-time network-wide immunization against new threats. Progent is a SentinelOne Partner, dealer, and integrator. Learn more about Progent's ProSight Active Security Monitoring (ASM) next-generation endpoint protection and ransomware defense.
- ProSight Enhanced Security Protection (ESP): Endpoint Protection and Microsoft Exchange Filtering
Progent's ProSight Enhanced Security Protection managed services offer economical multi-layer security for physical and virtual servers, desktops, smartphones, and Exchange Server. ProSight ESP utilizes adaptive security and advanced machine learning for continuously monitoring and reacting to security threats from all attack vectors. ProSight ESP delivers two-way firewall protection, intrusion alarms, endpoint management, and web filtering via cutting-edge tools incorporated within a single agent managed from a single control. Progent's security and virtualization experts can assist you to plan and configure a ProSight ESP environment that addresses your company's specific needs and that allows you achieve and demonstrate compliance with government and industry data security regulations. Progent will help you specify and configure security policies that ProSight ESP will manage, and Progent will monitor your IT environment and react to alerts that require urgent attention. Progent can also help your company to install and verify a backup and restore system such as ProSight Data Protection Services (DPS) so you can recover rapidly from a destructive cyber attack like ransomware. Find out more about Progent's ProSight Enhanced Security Protection (ESP) unified endpoint security and Microsoft Exchange email filtering.
For San Diego 24x7 Crypto-Ransomware Cleanup Consulting, reach out to Progent at 800-462-8800 or go to Contact Progent.