About Proven Data

Cybersecurity experts since 2011.

Proven Data is a specialized cybersecurity firm focused on incident response, ransomware recovery, and post-breach remediation. Since 2011, our team has resolved more than 3,000 cyber incidents.

14+

Years in Cybersecurity

3,000+

Cyber Incidents Resolved

80%

Resolved Without Ransom

Our Focus

When cyber threats hit, we're already responding.

Proven Data started in 2011 as a data recovery lab. Over the following decade, the business evolved into a full-spectrum cybersecurity firm, and today we operate exclusively as a cybersecurity incident response firm. What we do:

24/7 Incident Response (DFIR)

Active threat containment, forensic triage, and breach scoping during live cyber incidents.

Ransomware Recovery

Cryptographic recovery and decryption R&D that restores encrypted data without paying threat actors whenever possible.

Data Breach Response

Exfiltration scoping, regulatory notification support, and evidence preservation.

Cyber Extortion Defense & Settlement

OFAC-compliant negotiation and settlement management.

Post-Breach Remediation

Malware eradication, persistence removal, and hardened restoration.

If you need something outside cybersecurity, Proven Data no longer offers data recovery or litigation-related digital forensics, but we're happy to point you in the right direction:

  • For consumer and business data recovery — recovering data from failed drives, damaged storage media, deleted files, RAID rebuilds, mobile device extraction, and similar hardware-related recovery work — we recommend our trusted partner SalvageData, with over 20 years of experience in the data recovery industry.
  • For digital forensics supporting litigation, eDiscovery, and expert-witness work, we recommend our trusted partner LitigationForensics.

If your matter is a live cyber incident, ransomware attack, or data breach, you're in the right place.

Our Journey

Over a decade of building trust and expertise.

2011

Founded as a Data Recovery Lab

Proven Data was founded in 2011 as a specialized data recovery firm, developing proprietary techniques to recover data from damaged storage media and, later, from the earliest ransomware variants targeting SMBs.

2017

Ransomware Recovery Pioneer

Became one of the first firms in the U.S. to systematically reverse-engineer ransomware encryption schemes, achieving data recovery without ransom payments in the majority of cases — a capability that remains the core of our ransomware practice today.

2020

Full Incident Response Capability

Expanded into full-spectrum cyber incident response, launching 24/7 emergency operations, forensic triage for active breaches, and OFAC-compliant cyber extortion settlement. This is the point at which Proven Data became an incident response firm first, and a recovery lab second.

2023

Cybersecurity Specialization & Lynx Platform

Formally consolidated Proven Data's focus around cybersecurity incident response, ransomware recovery, and post-breach remediation — the areas where our team has the deepest technical expertise. In the same year, we launched the Lynx platform, an integrated cybersecurity SaaS that unifies case management, threat intelligence, and forensic triage tooling to support our IR engagements end-to-end.

What Drives Us

Our core values.

Team Excellence

Our people are our greatest asset. We invest in continuous training and certifications to maintain an elite team of cybersecurity professionals.

Recovery-First Approach

We exhaust every technical avenue to restore encrypted data without paying ransoms. Our R&D lab continuously develops new decryption techniques against active ransomware variants.

Rapid Response

When an incident strikes, minutes matter. Our 24/7 team mobilizes immediately with a proven process honed across thousands of engagements.

Forensic Rigor

Every investigation follows forensically sound methodologies. Our findings are court-admissible and meet the standards of insurance carriers and regulators.

Client Partnership

We treat every engagement as a partnership. Transparent communication, clear timelines, and no surprises — from first call to final report.

Leadership

Meet the team leading the charge.

Bogdan Glushko

Bogdan Glushko

CEO

Bogdan founded Proven Data in 2011 with a mission to help organizations recover from data loss and cyber incidents. Under his leadership, the company has grown from a data recovery lab into a nationally recognized cybersecurity firm handling thousands of incident response cases.

George Gershen

George Gershen

Director of Operations

George oversees the day-to-day operations of Proven Data, ensuring that every client engagement runs smoothly from intake to resolution. He has built and scaled the operational processes that allow the team to handle a high volume of concurrent cases without compromising quality.

Magdy Abdelaziz

Magdy Abdelaziz

Head of DFIR

GSTRTGIAC Strategic Planning, Policy, and LeadershipGEIRGIAC Enterprise Incident ResponseGCFEGIAC Certified Forensic ExaminerGCIHGIAC Certified Incident HandlerGCFAGIAC Certified Forensic AnalystGREMGIAC Reverse Engineering Malware

6+ years leading digital forensics and incident response. Manages a multinational DFIR team, developing IR strategies and overseeing global-scale incident investigations.

The Team

The people behind every response.

Mohamed Abdelghani

Mohamed Abdelghani

Principal DFIR Engineer

9+ years in SOC operations, incident response, and digital forensics. Former DFIR team lead at the Egyptian Computer Emergency Readiness Team (EG-CERT).

GCFAGIAC Certified Forensic AnalystGDATGIAC Defending Advanced ThreatsCFCECertified Forensic Computer ExaminerENCEEnCase Certified ExaminerACEAccessData Certified ExaminereCREeLearnSecurity Certified Reverse EngineereCTHPCertified Threat Hunting Professional (INE Security)
Andrew Leshkevich

Andrew Leshkevich

Principal Systems Administrator

15+ years in system administration, network management, and IT infrastructure. Deep expertise in Linux/Unix, virtualization, and containerization.

RHCERed Hat Certified EngineerMTCNAMikroTik Certified Network AssociateMCSAMicrosoft Certified Solutions AssociateMCSEMicrosoft Certified Solutions Expert
Mostafa Elnaggar

Mostafa Elnaggar

Senior DFIR Engineer

6+ years in DFIR, penetration testing, and security operations. Leads ransomware investigations (Akira, RansomHub) with prior offensive security experience.

GCFEGIAC Certified Forensic ExaminerGCIHGIAC Certified Incident HandlerOSWEOffensive Security Web ExperteCPPTeLearnSecurity Certified Professional Penetration Tester
AF

Amr Fathy

Senior DFIR Engineer

7+ years in DFIR, reverse engineering, and threat intelligence. Previously Threat Intelligence Analyst at SOCRadar with deep malware analysis expertise.

GCFEGIAC Certified Forensic ExaminerGCIHGIAC Certified Incident HandlerPCNSAPalo Alto Networks Certified Network Security AdministratorCCDCertified Cyber Defender (CyberDefenders)
Kenji Minei

Kenji Minei

Cybersecurity R&D Engineer

4+ years in reverse engineering, focusing on ransomware recovery R&D. Former malware reverse engineer at a global oil company and penetration tester.

GREMGIAC Reverse Engineering Malware
PJ

Park Jong-Hwi

Cybersecurity R&D Engineer

3 years in cybersecurity specializing in malware analysis, Windows internals, digital forensics, and reverse engineering.

Abdullah Yasin

Abdullah Yasin

DFIR Analyst and Responder

3+ years in digital forensics, incident response, and threat hunting. Also develops defensive security training content at HackTheBox.

CCDCertified Cyber Defender (CyberDefenders)BTL1Blue Team Level 1 (Security Blue Team)eCTHPCertified Threat Hunting Professional (INE Security)eCDFPCertified Digital Forensics Professional (INE Security)eJPTeLearnSecurity Junior Penetration Tester (INE Security)
Cole Popkin

Cole Popkin

DFIR Analyst

Specializes in forensic evidence collection, cryptocurrency analysis, and OSINT for incident response investigations. Hands-on experience with backup and recovery systems, Python development, and network security.

Dmitriy Lif

Dmitriy Lif

Senior Recovery Engineer

Specializes in data reconstruction and carving for ransomware recovery and forensic investigations. Deep technical expertise in storage systems, RAID arrays, and drive-level diagnostics applied to incident response casework.

George Pavel

George Pavel

Engagement Manager

Specializes in enterprise client engagement, strategic partnerships, and business development across ransomware recovery, incident response, and complex data recovery engagements. Oversees partner network expansion, GSA government contracting, and client compliance alignment (HIPAA/NIST).

Chris Morrissey

Chris Morrissey

Engagement Manager

Specializes in client communication, crisis management, and bridging complex technical issues for executive stakeholders during active incidents. Serves as the primary liaison between technical response teams and client leadership, legal, insurance, and compliance partners to align incident recovery strategies with core business objectives.

Michael Galloway

Michael Galloway

Mobile Recovery Engineer

10+ years in hardware diagnostics and mobile device extraction supporting DFIR engagements. Expertise in mobile acquisition, mechanical HDD failure analysis, and RAID reconstruction for incident response cases.

Adrian Wunderle

Adrian Wunderle

File System & File Type Engineer

7+ years in complex hardware diagnostics and storage analysis supporting ransomware recovery and DFIR investigations. Hands-on expertise in damaged media analysis, board-level repairs, custom SATA adaptations, and hardware-level decryption support using PC3000 tooling.

24/7 Team Available

Ready to talk? Reach out today.

Whether you need incident response, want to strengthen your security posture, or are evaluating partners — our team is here to help.

1 (877) 364-5161