Ransomware : Your Feared Information Technology Disaster
Ransomware  Recovery ProfessionalsRansomware has become a modern cyberplague that represents an extinction-level danger for businesses of all sizes vulnerable to an assault. Different iterations of crypto-ransomware like the CryptoLocker, WannaCry, Locky, NotPetya and MongoLock cryptoworms have been replicating for a long time and continue to inflict destruction. Newer variants of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, as well as more as yet unnamed malware, not only perform encryption of on-line files but also infiltrate many accessible system protection. Files synchronized to off-premises disaster recovery sites can also be rendered useless. In a poorly architected environment, this can render automatic restore operations hopeless and effectively knocks the datacenter back to square one.

Getting back programs and information following a ransomware attack becomes a race against time as the targeted business struggles to contain, clear the ransomware, and resume enterprise-critical operations. Since ransomware requires time to replicate across a targeted network, attacks are often sprung during nights and weekends, when successful penetrations typically take longer to discover. This multiplies the difficulty of rapidly mobilizing and organizing a capable mitigation team.

Progent makes available an assortment of support services for protecting Philadelphia businesses from ransomware events. These include team member training to become familiar with and avoid phishing attempts, ProSight Active Security Monitoring for endpoint detection and response (EDR) using SentinelOne's behavior-based threat defense to detect and suppress zero-day malware assaults. Progent in addition offers the assistance of veteran crypto-ransomware recovery professionals with the skills and perseverance to rebuild a compromised network as quickly as possible.

Progent's Ransomware Restoration Support Services
After a ransomware event, even paying the ransom in cryptocurrency does not guarantee that merciless criminals will provide the needed codes to decrypt any or all of your information. Kaspersky Labs estimated that seventeen percent of ransomware victims never restored their files after having sent off the ransom, resulting in more losses. The risk is also expensive. Ryuk ransoms are commonly a few hundred thousand dollars. For larger enterprises, the ransom demand can reach millions. The fallback is to piece back together the critical components of your IT environment. Without access to full information backups, this requires a wide complement of skill sets, top notch project management, and the ability to work 24x7 until the job is over.

For decades, Progent has provided certified expert IT services for businesses throughout the US and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes professionals who have been awarded top certifications in leading technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security experts have earned internationally-recognized certifications including CISA, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has expertise in financial systems and ERP applications. This breadth of experience affords Progent the skills to knowledgably understand necessary systems and integrate the surviving pieces of your IT environment after a ransomware penetration and rebuild them into an operational system.

Progent's recovery team deploys top notch project management applications to orchestrate the complex recovery process. Progent knows the urgency of acting swiftly and in concert with a client's management and IT resources to prioritize tasks and to put key applications back on-line as fast as humanly possible.

Customer Case Study: A Successful Ransomware Incident Response
A customer contacted Progent after their company was taken over by the Ryuk ransomware virus. Ryuk is thought to have been developed by North Korean state cybercriminals, suspected of using technology exposed from America's NSA organization. Ryuk seeks specific organizations with little or no room for disruption and is among the most lucrative instances of ransomware viruses. Major targets include Data Resolution, a California-based information warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a regional manufacturing company headquartered in Chicago with around 500 staff members. The Ryuk penetration had shut down all business operations and manufacturing capabilities. The majority of the client's information backups had been online at the time of the attack and were encrypted. The client was taking steps for paying the ransom demand (exceeding $200,000) and praying for good luck, but ultimately made the decision to use Progent.


"I cannot thank you enough in regards to the care Progent provided us throughout the most critical period of (our) company's survival. We most likely would have paid the cybercriminals if it wasn't for the confidence the Progent group afforded us. That you could get our messaging and essential servers back online quicker than 1 week was incredible. Every single expert I got help from or communicated with at Progent was urgently focused on getting us back online and was working day and night on our behalf."

Progent worked with the customer to quickly determine and assign priority to the mission critical areas that needed to be restored to make it possible to restart departmental functions:

  • Microsoft Active Directory
  • Microsoft Exchange
  • Accounting and Manufacturing Software
To start, Progent followed AV/Malware Processes incident mitigation best practices by halting lateral movement and clearing up compromised systems. Progent then started the work of bringing back online Microsoft Active Directory, the foundation of enterprise environments built upon Microsoft Windows technology. Microsoft Exchange messaging will not function without AD, and the client's MRP software used Microsoft SQL Server, which requires Windows AD for authentication to the data.

In less than 48 hours, Progent was able to re-build Windows Active Directory to its pre-attack state. Progent then accomplished reinstallations and hard drive recovery on essential systems. All Exchange Server schema and configuration information were usable, which greatly helped the restore of Exchange. Progent was also able to find local OST files (Outlook Email Offline Folder Files) on staff desktop computers in order to recover mail information. A recent offline backup of the customer's financials/ERP systems made it possible to restore these required programs back available to users. Although major work needed to be completed to recover fully from the Ryuk virus, essential services were restored rapidly:


"For the most part, the assembly line operation never missed a beat and we produced all customer sales."

Throughout the next few weeks critical milestones in the restoration project were accomplished in close collaboration between Progent consultants and the client:

  • Internal web applications were restored without losing any data.
  • The MailStore Exchange Server containing more than four million archived messages was brought on-line and accessible to users.
  • CRM/Customer Orders/Invoicing/AP/Accounts Receivables (AR)/Inventory functions were 100 percent operational.
  • A new Palo Alto 850 security appliance was set up.
  • Most of the user desktops and notebooks were functioning as before the incident.

"A huge amount of what transpired during the initial response is nearly entirely a blur for me, but my management will not forget the care each and every one of the team put in to help get our company back. I have utilized Progent for the past ten years, maybe more, and every time Progent has impressed me and delivered as promised. This event was a Herculean accomplishment."

Conclusion
A potential company-ending disaster was dodged due to top-tier professionals, a wide range of technical expertise, and tight teamwork. Although in hindsight the ransomware penetration described here would have been identified and stopped with modern cyber security technology and best practices, user and IT administrator education, and well designed incident response procedures for data protection and proper patching controls, the fact remains that state-sponsored criminal cyber gangs from Russia, North Korea and elsewhere are relentless and are not going away. If you do fall victim to a ransomware penetration, remember that Progent's team of professionals has a proven track record in crypto-ransomware virus defense, remediation, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Tony and Chris (and any others who were helping), thanks very much for letting me get some sleep after we got over the initial push. Everyone did an impressive effort, and if anyone that helped is in the Chicago area, dinner is my treat!"

Download the Ransomware Cleanup Case Study Datasheet
To read or download a PDF version of this customer story, click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting Services in Philadelphia
For ransomware system restoration consulting services in the Philadelphia area, phone Progent at 800-462-8800 or go to Contact Progent.



An index of content::

  • 24-7 2500 Wireless Controller Outsourcing wireless controller On-site Technical Support
  • 24/7 Specialist Dynamics GP Great Plains Software Dynamics GP Software Consultant Services

  • Professionals Virtual Server Technology
    Server Virtualization Integration

    By using virtual servers, companies are able to operate multiple virtual servers on one physical server. Virtual server technology allows IT organizations to gain all the advantages of server isolation, but without the costs that goes with purchasing additional server hardware. Virtualization is also the enabling technology for private clouds, which provide major benefits including lowering the costs of hardware, facilities, and management while improving information security, system reliability, and recoverability. Other useful server management options are network monitoring utilities, Microsoft WSUS, and remote system management cards. Progent's professional server management experts can help you with all aspects of server consolidation and management to allow your business to cut expenses and conserve time.

  • At Home Workers Philadelphia Guidance - Collaboration Technology Assistance Top At Home Workers Consulting near Philadelphia - Collaboration Systems Expertise Philadelphia

  • Engineers SentinelOne Active Security Monitoring
    SentinelOne Singularity Complete Reseller Computer Engineer

    Progent is a dealer and integrator for SentinelOne's Singularity product line, a subscription-based, cloud-centric threat management solution that incorporates machine learning technology and advanced services to provide cutting-edge endpoint detection and response (EDR).

  • At Home Workforce Philadelphia Consultants - Network Security Systems Consulting Philadelphia International Airport PHL Work from Home Employees Consultants nearby Philadelphia - Cybersecurity Solutions Consultants Philadelphia, PA

  • Citrix Xen Hypervisor Consultants
    XenServer Virtualization Engineers

    Progent's Citrix-certified engineers can help you to evaluate the strategic advantages of XenServer and other Citrix products, and can assist your IT organization to design, validate, execute, troubleshoot, and maintain a XenServer solution. Progent can in addition analyze your current Citrix technology deployment and help you to optimize resource utilization, responsiveness, security and compliance, availability, and recoverability.

  • At Home Workforce Philadelphia Consulting Experts - Cloud Integration Solutions Consulting and Support Services Philly Philadelphia Work from Home Employees Cloud Technology Assistance Philadelphia
  • Award Winning Philadelphia Conti Crypto-Ransomware Settlement Help Philadelphia, PA 24-Hour Philadelphia Ryuk Ransomware Negotiation Consultants Philadelphia International Airport PHL
  • Computer Network Support Group Microsoft Exchange Philadelphia Harrisburg Computer Network Support Microsoft Exchange 2010 Philadelphia Harrisburg

  • IT Consultants Offsite BDR Services
    Best ProSight Data Protection Services ECHO Specialist

    ProSight ECHO Data Protection Services from Progent offer small and mid-sized businesses a low-cost end-to-end service for cloud backup/disaster recovery. ProSight Data Protection Services automates your backup processes and allows rapid restoration of vital files, apps and VMs that have become unavailable or corrupted as a result of component failures, software glitches, disasters, human mistakes, or malware attacks such as ransomware. ProSight DPS can help you back up, retrieve and restore files, folders, applications, system images, as well as Microsoft Hyper-V and VMware images/. Critical data can be backed up on the cloud, to an on-premises device, or to both. Progent's BDR consultants can provide advanced expertise to set up ProSight DPS to to comply with government and industry regulatory requirements like HIPAA, FIRPA, PCI and Safe Harbor and, whenever needed, can assist you to recover your business-critical data.

  • Dharma Ransomware Hot Line Philadelphia Harrisburg Conti Ransomware Hot Line Philadelphia International Airport PHL
  • Exchange Server 2010 Migration Consultancy Consult Exchange 2003 to Exchange 2010 Upgrade

  • UNIX Specialist
    Sun Solaris Setup and Support

    Progent's Sun Solaris platform support services offer small and mid-size companies and software developers support for managing and maintaining Sun Solaris systems that operate with Microsoft-based networks. Progent offers your business contact with Solaris consultants, support professionals premier by Microsoft and Cisco, and security experts with CISA credentials. This broad range of expertise provides you with a convenient one-stop consulting firm to show you how to create and maintain a protected and robust cross-platform network and communications environment that allows Solaris and Microsoft interoperability by integrating Microsoft Windows with popular versions of UNIX such as Apple Mac OS X, Solaris, IBM AIX, Hewlett Packard HP-UX, Berkeley UNIX (BSD), SCO, and SGI/Irix or leading Linux variations including RedHat, SUSE, CentOS, Ubuntu, PCLOS, fedora, Gentoo Linux, Mandrake/Mandriva, Debian GNU/Linux, and Slackware.

  • Hosting IT Manager Philadelphia Small Business Network Consulting Companies Data Center Colo

  • 24-Hour Troubleshooting Microsoft 365
    IT Consultants Microsoft 365 Teams Integration

    Progent can help you to understand the many subscription plans available with Microsoft 365, previously called Office 365, and configure your network with Microsoft 365 so you derive maximum business value. Progent supports multi-vendor networks that include Windows, macOS or OS X, and Linux technology. Progent can also assist your business to build and maintain hybrid networks that transparently integrate local and cloud products and services.

  • Mandrake Linux, Sun Solaris, UNIX Remote Support Philadelphia Pennsylvania Philly Ubuntu Linux, Solaris, UNIX Support
  • Microsoft Philadelphia Computer Consultancy Firm System Consultant Philadelphia
  • Network Consulting Signature-based Virus Protection ProSight Ransomware Rollback Support Services
  • Network Installation Philadelphia Philadelphia, PA Technology Consultants
  • Online Support Services MS CRM Consultants CRM
  • Philadelphia At Home Workers Solutions Guidance Philadelphia Harrisburg Offsite Workforce Philadelphia Consulting and Support Services - Integration Solutions Guidance Philadelphia Pennsylvania
  • Philadelphia Consulting Experts for IT Support Organizations Philadelphia Harrisburg Consultants for Network Support Companies nearby Philadelphia - Transparent Short-Term IT Support Help Philadelphia Harrisburg

  • Immediate Wireless Integration Example Application
    Proxim Tsunami Wireless Case Studies

    Progent delivered a wireless networking environment that allowed a school to increase productivity and avoid the recurring expense of a dedicated link. Progent recommended a Proxim Tsunami high-speed wireless bridge. The low-cost building-to-building Proxim bridge is intended for connecting remote sites as far as 2.5 miles apart and can reach even longer ranges. This wireless alternative offered improved bandwidth and reliability than simply amplifying the 802.11b network, and since it uses the 5.8Ghz spectrum it provided protection against local interference.

  • Philadelphia Spora Ransomware System-Rebuild Philadelphia, PA
  • Philadelphia Conti Ransomware Repair Philadelphia Philadelphia Conti Ransomware Business-Recovery Philadelphia Harrisburg
  • Philadelphia Crypto-Ransomware Malware Removal Philadelphia, PA Philadelphia Spora Crypto-Ransomware Cleanup
  • Philadelphia DopplePaymer Crypto-Ransomware Forensics Philadelphia Pennsylvania Top Quality Philadelphia DopplePaymer Crypto-Ransomware Forensics Philadelphia Pennsylvania
  • Philadelphia Egregor Crypto-Ransomware Repair Philadelphia International Airport PHL Philadelphia Sodinokibi Crypto-Ransomware Remediation Philly
  • Philadelphia Harrisburg Cisco Security Consulting Firms Cisco Computer Network Consultant Philly, United States
  • Philadelphia Harrisburg Microsoft Dynamics GP-Great Plains Philadelphia Vender - Setup Consultants Philadelphia Microsoft Dynamics GP Reporting Experts Philly
  • Philadelphia Offsite Workforce Setup Consulting and Support Services Philadelphia, PA, U.S.A. Work from Home Employees Philadelphia Assistance - Infrastructure Consulting and Support Services Philadelphia International Airport PHL, United States
  • Philadelphia Pennsylvania CISSP Cybersecurity Group 24x7 Security Security Consulting Philadelphia
  • Philadelphia Remote Workers Endpoint Management Solutions Assistance Philadelphia Harrisburg Remote Workforce Consulting Experts in Philadelphia - Management Systems Consulting Services Philadelphia Harrisburg
  • Philadelphia Remote Workers VoIP Technology Consultants Philly Philly At Home Workforce Consultants near Philadelphia - VoIP Solutions Consulting Services
  • Philadelphia Remote Workforce Video Conferencing Solutions Consulting and Support Services Philadelphia International Airport PHL Work at Home Employees Consulting Services near me in Philadelphia - Voice/Video Conferencing Systems Consultants Philadelphia Harrisburg
  • Philadelphia Pennsylvania Philadelphia WannaCry Crypto-Ransomware System-Restore
  • Philadelphia Telecommuters Help Desk Call Center Augmentation Assistance Philadelphia Pennsylvania Telecommuters Consulting and Support Services near Philadelphia - Call Desk Outsourcing Consultants Philly
  • Philadelphia, PA Emergency Philadelphia Crypto-Ransomware Repair Philadelphia Crypto-Ransomware Removal Services Philadelphia Harrisburg
  • Philadelphia, PA Philadelphia Ransomware Sodinokibi Readiness Checkup After Hours Philadelphia Ransomware Nephilim Preparedness Review Philadelphia, PA, USA
  • Philly Information Technology Consulting Microsoft SQL Server SQL Server 2014 Technology Consulting Philly
  • RIM BlackBerry Maintenance Philly Emergency BlackBerry Professional Software Onsite and Remote Support
  • SharePoint Server 2007 Remote Support Philly Philadelphia, PA Microsoft SharePoint Server 2007 On-site Support
  • Short-Term Network Support Staffing Support Services Expertise Philadelphia, PA IT Staffing for Computer Support Groups Philadelphia Harrisburg, United States
  • Teleworkers Consulting Services in Philadelphia - Backup/Recovery Solutions Consulting Experts Philly Philadelphia, PA, United States Teleworkers Consulting in Philadelphia - Data Protection Solutions Consulting Services
  • Top Computer Consultant Telecommuter Job Philadelphia Pennsylvania Award Winning Microsoft MCP Remote Consultant Contract Job Opportunities Philly, United States
  • Windows Cluster Remote Troubleshooting On-site Technical Support Windows 2008 Cluster
  • Windows Server 2019 On-Call Services Philly Technical Firms Windows 2008 Server Philadelphia, PA, United States

  • © 2002-2025 Progent Corporation. All rights reserved.