Ransomware : Your Worst IT Catastrophe
Ransomware has become a too-frequent cyber pandemic that represents an extinction-level threat for businesses of all sizes unprepared for an attack. Different iterations of crypto-ransomware like the CryptoLocker, WannaCry, Bad Rabbit, Syskey and MongoLock cryptoworms have been circulating for a long time and still inflict destruction. Recent variants of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti or Egregor, as well as additional unnamed viruses, not only encrypt on-line information but also infiltrate most accessible system protection mechanisms. Information synched to off-site disaster recovery sites can also be ransomed. In a poorly designed system, it can render automated recovery hopeless and basically knocks the network back to square one.
Getting back online services and data after a crypto-ransomware intrusion becomes a sprint against the clock as the victim fights to contain, clear the crypto-ransomware, and resume business-critical activity. Due to the fact that ransomware requires time to move laterally, assaults are usually sprung on weekends and holidays, when penetrations tend to take more time to notice. This compounds the difficulty of promptly assembling and orchestrating an experienced response team.
Progent offers a range of help services for securing businesses from crypto-ransomware events. Among these are user training to become familiar with and not fall victim to phishing exploits, ProSight Active Security Monitoring (ASM) for remote monitoring and management, along with deployment of the latest generation security appliances with AI capabilities from SentinelOne to discover and quarantine zero-day cyber threats intelligently. Progent also offers the assistance of seasoned ransomware recovery professionals with the track record and commitment to rebuild a compromised environment as urgently as possible.
Progent's Ransomware Restoration Support Services
Following a ransomware penetration, even paying the ransom in cryptocurrency does not ensure that cyber criminals will respond with the needed keys to decipher any of your files. Kaspersky Labs estimated that 17% of ransomware victims never recovered their information after having sent off the ransom, resulting in more losses. The risk is also very costly. Ryuk ransoms are typically several hundred thousand dollars. For larger organizations, the ransom demand can reach millions of dollars. The fallback is to setup from scratch the mission-critical components of your IT environment. Without access to essential system backups, this requires a broad complement of skills, professional project management, and the capability to work 24x7 until the job is done.
For two decades, Progent has provided expert Information Technology services for companies throughout the United States and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes professionals who have been awarded advanced industry certifications in foundation technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security engineers have garnered internationally-renowned certifications including CISA, CISSP, CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has experience in financial management and ERP application software. This breadth of experience affords Progent the skills to quickly ascertain necessary systems and organize the surviving pieces of your computer network system following a crypto-ransomware attack and assemble them into an operational network.
Progent's security group utilizes powerful project management applications to orchestrate the complicated recovery process. Progent understands the urgency of acting rapidly and in unison with a customer's management and IT team members to assign priority to tasks and to put critical systems back on-line as soon as humanly possible.
Business Case Study: A Successful Ransomware Intrusion Recovery
A business engaged Progent after their network system was brought down by the Ryuk ransomware. Ryuk is generally considered to have been deployed by North Korean government sponsored hackers, possibly adopting techniques exposed from America's NSA organization. Ryuk goes after specific businesses with limited room for operational disruption and is among the most profitable incarnations of crypto-ransomware. Headline organizations include Data Resolution, a California-based information warehousing and cloud computing firm, and the Chicago Tribune. Progent's customer is a single-location manufacturing business based in the Chicago metro area with about 500 staff members. The Ryuk attack had paralyzed all essential operations and manufacturing capabilities. Most of the client's data protection had been on-line at the time of the intrusion and were damaged. The client was pursuing financing for paying the ransom (more than $200,000) and hoping for good luck, but in the end utilized Progent.
"I can't say enough about the help Progent gave us during the most stressful period of (our) businesses survival. We most likely would have paid the cybercriminals if not for the confidence the Progent group afforded us. The fact that you could get our e-mail system and key applications back online sooner than seven days was incredible. Each consultant I spoke to or texted at Progent was hell bent on getting our system up and was working 24 by 7 to bail us out."
Progent worked with the client to rapidly identify and assign priority to the critical systems that needed to be addressed in order to continue business functions:
- Active Directory (AD)
- E-Mail
- Accounting/MRP
To get going, Progent adhered to AV/Malware Processes event mitigation best practices by stopping lateral movement and clearing up compromised systems. Progent then started the process of rebuilding Microsoft Active Directory, the foundation of enterprise systems built upon Microsoft Windows technology. Microsoft Exchange email will not operate without Active Directory, and the businesses' MRP system leveraged Microsoft SQL, which depends on Active Directory for authentication to the databases.
Within two days, Progent was able to re-build Windows Active Directory to its pre-attack state. Progent then completed setup and hard drive recovery of the most important systems. All Microsoft Exchange Server ties and configuration information were usable, which facilitated the rebuild of Exchange. Progent was also able to locate non-encrypted OST data files (Outlook Email Off-Line Data Files) on user workstations to recover email messages. A recent offline backup of the businesses accounting systems made it possible to restore these vital applications back online. Although a large amount of work needed to be completed to recover totally from the Ryuk attack, critical systems were restored quickly:
"For the most part, the assembly line operation survived unscathed and we made all customer sales."
Over the next couple of weeks key milestones in the recovery project were made in close collaboration between Progent team members and the client:
- In-house web applications were returned to operation with no loss of information.
- The MailStore Server exceeding 4 million archived emails was brought on-line and available for users.
- CRM/Customer Orders/Invoices/Accounts Payable/AR/Inventory capabilities were completely operational.
- A new Palo Alto Networks 850 firewall was installed and configured.
- 90% of the user desktops were functioning as before the incident.
"A lot of what occurred that first week is mostly a haze for me, but I will not soon forget the countless hours each and every one of the team put in to give us our company back. I've utilized Progent for the past ten years, possibly more, and every time I needed help Progent has impressed me and delivered. This time was a Herculean accomplishment."
Conclusion
A possible business disaster was evaded by hard-working professionals, a wide range of subject matter expertise, and tight collaboration. Although in analyzing the event afterwards the crypto-ransomware virus attack described here could have been shut down with advanced security systems and ISO/IEC 27001 best practices, user training, and appropriate security procedures for data backup and proper patching controls, the reality remains that government-sponsored cyber criminals from China, North Korea and elsewhere are tireless and represent an ongoing threat. If you do fall victim to a ransomware incursion, remember that Progent's team of professionals has extensive experience in ransomware virus blocking, mitigation, and data recovery.
"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others that were contributing), thank you for making it so I could get some sleep after we got past the initial fire. All of you did an amazing effort, and if any of your team is around the Chicago area, dinner is my treat!"
To read or download a PDF version of this case study, please click:
Progent's Crypto-Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)
Additional Ransomware Protection Services Offered by Progent
Progent offers companies in Chandler a range of online monitoring and security assessment services to help you to reduce the threat from ransomware. These services utilize modern artificial intelligence capability to detect zero-day variants of ransomware that are able to get past traditional signature-based security solutions.
- ProSight LAN Watch: Server and Desktop Remote Monitoring and Management
ProSight LAN Watch is Progent's server and desktop monitoring service that incorporates state-of-the-art remote monitoring and management technology to help keep your IT system running efficiently by checking the health of vital assets that power your business network. When ProSight LAN Watch detects an issue, an alert is transmitted automatically to your specified IT management staff and your assigned Progent consultant so any potential problems can be resolved before they have a chance to impact your network. Find out more details about ProSight LAN Watch server and desktop remote monitoring services.
- ProSight LAN Watch with NinjaOne RMM: Unified RMM for Networks, Servers, and Workstations
ProSight LAN Watch with NinjaOne RMM software delivers a unified, cloud-driven platform for monitoring and managing your network, server, and desktop devices by offering an environment for streamlining common tedious jobs. These can include health monitoring, update management, automated repairs, endpoint deployment, backup and restore, anti-virus response, remote access, built-in and custom scripts, asset inventory, endpoint status reports, and debugging support. If ProSight LAN Watch with NinjaOne RMM uncovers a serious incident, it sends an alarm to your specified IT staff and your Progent consultant so that potential problems can be fixed before they interfere with productivity. Find out more about ProSight LAN Watch with NinjaOne RMM server and desktop remote monitoring services.
- ProSight WAN Watch: Infrastructure Management
ProSight WAN Watch is an infrastructure management service that makes it simple and inexpensive for smaller businesses to map out, monitor, optimize and debug their connectivity appliances such as switches, firewalls, and access points as well as servers, printers, endpoints and other devices. Using cutting-edge RMM technology, WAN Watch ensures that network diagrams are always updated, copies and displays the configuration of almost all devices on your network, monitors performance, and generates notices when issues are detected. By automating time-consuming management activities, ProSight WAN Watch can cut hours off common chores such as network mapping, reconfiguring your network, locating devices that need important software patches, or isolating performance bottlenecks. Learn more about ProSight WAN Watch network infrastructure management services.
- ProSight Reporting: In-depth Reporting for Ticketing and Network Monitoring Applications
ProSight Reporting is a growing line of real-time reporting plug-ins designed to integrate with the industry's top ticketing and network monitoring applications including ConnectWise Manage, ConnectWise Automate, Customer Thermometer, Auvik, and SentinelOne. ProSight Reporting uses Microsoft Graph and features color coding to surface and contextualize critical issues like inconsistent support follow-through or machines with out-of-date AVs. By identifying ticketing or network health concerns concisely and in near-real time, ProSight Reporting enhances network value, lowers management hassle, and saves money. For more information, see ProSight Reporting for ticketing and network monitoring platforms.
- ProSight Data Protection Services (DPS): Managed Backup and Recovery Services
Progent has partnered with leading backup software companies to create ProSight Data Protection Services, a family of offerings that provide backup-as-a-service. ProSight DPS services automate and monitor your backup processes and enable non-disruptive backup and rapid restoration of critical files/folders, apps, images, and virtual machines. ProSight DPS helps you avoid data loss resulting from equipment breakdown, natural disasters, fire, cyber attacks like ransomware, user error, malicious insiders, or application glitches. Managed services in the ProSight DPS product line include ProSight Altaro VM Backup, ProSight 365 Total Backup (formerly Altaro 365 Backup), ProSight DPS ECHO Backup using Barracuda purpose-built storage, and ProSight DPS MSP360 Hybrid Backup. Your Progent service representative can assist you to identify which of these fully managed services are best suited for your IT environment.
- ProSight Email Guard: Inbound and Outbound Spam Filtering and Data Leakage Protection
ProSight Email Guard is Progent's spam and virus filtering service that incorporates the technology of top information security companies to provide web-based management and comprehensive protection for your inbound and outbound email. The powerful structure of Progent's Email Guard managed service combines a Cloud Protection Layer with an on-premises gateway appliance to offer complete protection against spam, viruses, Denial of Service (DoS) Attacks, Directory Harvest Attacks, and other email-borne threats. The cloud filter acts as a first line of defense and blocks most unwanted email from making it to your network firewall. This decreases your exposure to external attacks and conserves system bandwidth and storage. Email Guard's onsite security gateway appliance adds a deeper level of inspection for incoming email. For outgoing email, the on-premises security gateway provides anti-virus and anti-spam protection, DLP, and email encryption. The on-premises gateway can also assist Microsoft Exchange Server to monitor and protect internal email traffic that originates and ends inside your security perimeter. For more information, see Email Guard spam filtering and data leakage protection.
- ProSight Duo Two-Factor Authentication: Identity Validation, Endpoint Policy Enforcement, and Secure Single Sign-on
Progent's Duo MFA services utilize Cisco's Duo technology to defend against password theft by using two-factor authentication (2FA). Duo enables one-tap identity verification with Apple iOS, Android, and other out-of-band devices. Using 2FA, whenever you sign into a protected online account and enter your password you are asked to verify your identity via a unit that only you have and that uses a different network channel. A wide range of out-of-band devices can be used as this added means of ID validation including an iPhone or Android or watch, a hardware token, a landline telephone, etc. You may designate multiple verification devices. For more information about ProSight Duo identity authentication services, go to Cisco Duo MFA two-factor authentication services for access security.
- Progent's Outsourced/Shared Service Center: Help Desk Managed Services
Progent's Call Center services allow your IT group to offload Help Desk services to Progent or divide responsibilities for support services transparently between your in-house network support staff and Progent's extensive roster of IT support engineers and subject matter experts. Progent's Shared Service Desk offers a smooth supplement to your corporate IT support organization. End user access to the Help Desk, delivery of support, problem escalation, trouble ticket creation and updates, efficiency metrics, and management of the service database are cohesive regardless of whether issues are resolved by your in-house IT support staff, by Progent's team, or by a combination. Find out more about Progent's outsourced/shared Service Desk services.
- Active Defense Against Ransomware: AI-based Ransomware Identification and Remediation
Progent's Active Protection Against Ransomware is an endpoint protection solution that incorporates next generation behavior-based analysis tools to guard endpoints and servers and VMs against modern malware assaults like ransomware and email phishing, which easily get by legacy signature-based anti-virus products. Progent ASM services protect on-premises and cloud resources and provides a unified platform to automate the complete malware attack lifecycle including filtering, detection, mitigation, remediation, and forensics. Key capabilities include single-click rollback using Windows Volume Shadow Copy Service (VSS) and automatic system-wide immunization against newly discovered attacks. Learn more about Progent's ransomware protection and cleanup services.
- ProSight IT Asset Management: Network Documentation Management
ProSight IT Asset Management service is a cloud-based IT documentation management service that allows you to capture, update, retrieve and safeguard data related to your network infrastructure, processes, applications, and services. You can quickly find passwords or IP addresses and be warned about upcoming expirations of SSL certificates or domains. By updating and organizing your network documentation, you can save as much as half of time wasted trying to find vital information about your network. ProSight IT Asset Management features a common repository for holding and collaborating on all documents related to managing your network infrastructure such as recommended procedures and self-service instructions. ProSight IT Asset Management also supports a high level of automation for collecting and associating IT data. Whether you're making improvements, doing regular maintenance, or responding to an emergency, ProSight IT Asset Management delivers the data you need when you need it. Read more about ProSight IT Asset Management service.
- Patch Management: Patch Management Services
Progent's managed services for software and firmware patch management offer organizations of any size a versatile and cost-effective alternative for assessing, testing, scheduling, applying, and tracking updates to your ever-evolving information system. In addition to optimizing the security and functionality of your computer environment, Progent's software/firmware update management services allow your IT team to focus on more strategic initiatives and activities that derive maximum business value from your network. Find out more about Progent's patch management support services.
- ProSight Virtual Hosting: Hosted Virtual Machines at Progent's Tier III Data Center
With ProSight Virtual Hosting service, a small organization can have its key servers and applications hosted in a secure Tier III data center on a fast virtual machine host set up and managed by Progent's IT support professionals. With the ProSight Virtual Hosting model, the client retains ownership of the data, the operating system platforms, and the applications. Because the system is virtualized, it can be moved easily to a different hosting environment without requiring a time-consuming and technically risky reinstallation process. With ProSight Virtual Hosting, you are not locked into a single hosting provider. Learn more details about ProSight Virtual Hosting services.
- ProSight Active Security Monitoring: Endpoint Protection and Ransomware Defense
Progent's ProSight Active Security Monitoring (ASM) is an endpoint protection service that utilizes SentinelOne's cutting edge behavior machine learning tools to guard physical and virtual endpoint devices against modern malware assaults such as ransomware and file-less exploits, which easily escape legacy signature-based anti-virus tools. ProSight ASM safeguards on-premises and cloud resources and offers a unified platform to automate the complete malware attack lifecycle including blocking, identification, mitigation, remediation, and forensics. Key capabilities include single-click rollback with Windows Volume Shadow Copy Service and real-time system-wide immunization against newly discovered attacks. Progent is a SentinelOne Partner, reseller, and integrator. Learn more about Progent's ProSight Active Security Monitoring endpoint protection and ransomware defense.
- ProSight Enhanced Security Protection (ESP): Endpoint Security and Exchange Email Filtering
ProSight Enhanced Security Protection (ESP) managed services deliver economical multi-layer protection for physical servers and VMs, desktops, mobile devices, and Exchange email. ProSight ESP utilizes contextual security and modern behavior analysis for round-the-clock monitoring and responding to security assaults from all attack vectors. ProSight ESP offers two-way firewall protection, intrusion alerts, device control, and web filtering via leading-edge tools incorporated within one agent accessible from a unified control. Progent's security and virtualization consultants can assist you to plan and configure a ProSight ESP deployment that meets your company's specific requirements and that allows you demonstrate compliance with legal and industry data protection regulations. Progent will help you define and configure security policies that ProSight ESP will enforce, and Progent will monitor your network and react to alerts that call for urgent attention. Progent's consultants can also assist you to install and test a backup and disaster recovery solution such as ProSight Data Protection Services (DPS) so you can get back in business rapidly from a destructive cyber attack like ransomware. Find out more about Progent's ProSight Enhanced Security Protection (ESP) unified physical and virtual endpoint protection and Microsoft Exchange email filtering.
For Chandler 24/7 Ransomware Cleanup Help, call Progent at 800-462-8800 or go to Contact Progent.