Balance Between Cybersecurity and Resilience – Rob Emsley, Dell Technologies
Rob Emsley, Director of Data Protection Solutions at Dell Technologies, explains why there needs to be a better balance struck between cybersecurity and resilience.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Rob emsley who's director of data protection solutions for Dell Technologies. And we're talking about the relationship between data protection and cybersecurity these days and there's a recent controversial report from the folks at Gartner Maverick talking about maybe we're out of balance on the two rob. Welcome the show.
Hey, hey, Mike. Love you to be here. Yeah, it certainly it certainly interesting.
You know, I think you've been covering the news daily weekly monthly for a long time the cyber security and cyber attacks seem to be occurring on a daily hourly basis. And certainly the the prevailing wisdom has been hey, you have to protect yourself from keeping the bad guys out. But as you mentioned the the team over at Gardner and a specifically the the team that does this Mavericks research You know, they tend to take the the contrary view, you know, that is held by most people that you can keep the bad guys out of your environment and really what they say is you need to accept that you will be hacked and you have to embrace the breach.
And so that means becoming more resilient which means finding ways to recover faster from the attack and the limit the attack. What is your sense of how much organizations actually doing that I mean, we've been talking about data protection for decades now and it always seems to be something we don't quite get right. So where are we right now in terms of maturity for the whole process?
Yeah, I think. Christian I think that the reality is this the old customers have a backup and Recovery discipline within their environment. I mean back up is is old as you and I might you know, as long as people have been creating data.
They've realized that creating a backup of that data is the the best way of giving you something that you can use for Recovery. One of the things that's changed. It's the Cyber criminals have realized that as well as going after your production data if they can infiltrate your backup data, then really all of the Leverage is on the Cyber criminal because your production data is infected and you're back up data is infected and they hold often the keys to unlock both of those.
So one of the things that's really changed is how do I actually give myself a copy of my environment? That really can't be infected by the Cyber criminals. And that's really where here at Delta Technologies.
We've been very focused at providing a solution within the context of backup and Recovery that gives you a truly cyber resilient starting point in order to bring your environment back up and running and I can go into details about how we do that. The gardener report makes it seem though that the spending on Cybersecurities coming at the expense of data protection and in my experience those two things tend to be separate budgets and organizations. So what is your sense of?
What is the right balance between these two things? And and where should we be focusing our efforts? Yeah.
And yeah, I think the wood balance is is very key that Mike. I think that That what we've seen is that a lot of it budget dollars is spent in the discipline of prevention and securing the perimeter and securing the elements inside of the perimeter. And I think the the point that Gartner is conveying is that That's money.
Well spent but you need to get a balance between spending money on keeping the bad guys out and also spending money on if they do get in and the assumption is that they will get in through, you know, some way somehow to give you. Budget dollars to spend on allowing you to react to that situation. So that's the that's the money on Cyber resilience.
So prevention is good, but you need to get the balance and they really, you know, in the in the the Mavericks report, you know that, you know, hopefully, you know, you can share that link with our you know with your readers. You'll see the actually show a seesaw, you know to actually get that that budget spent balanced. You know, I read the report and I laughed so I went back in time and I looked up.
When was the first time we started talking about the need to converge cybersecurity and data protection and I got as far back as 2007. So what is it or what prevents us from achieving that goal? Because here we are, you know two decades later essentially and we're still talking about the same issues.
So what has been the problem well, I think I think what's changed is the the I think the the backup environment, you know, maybe certainly years ago, you know was was very much based around, you know back up to tape. You know, if you remember, you know, that was the prevailing medium that backup copies were stored on you know, one of the the advantages that the tape had you know was that it was often disconnected from the network now now but even when the medium is disconnected the backup servers have always been on the network and the challenge is is that that network is part of the the same attack surface as the production environment. So the the credentials and the the fishing attacks that take place to engineer socially engineer away into a customers it environment not only gives the bad Actors Access to production environment.
But it also gives the bad Actors Access to backup environments and that's really what's changed over the last probably half a decade is how many situations occur the the backup environment where you know for many years before people have relied on being available for them to use for Recovery are often compromised themselves. And that's where I think it becomes really concerning to many clients is if that's happening. What do I need to do to my backup environment to make it not susceptible to Bad actors infiltrating it and that's where many of our customers, you know, we talk about three three important capabilities we talk about isolation.
We talk about and utility and we talk about intelligence and the Isolation element is really predicated on we work with customers to deliver what we call a cyber Vault and a cyber vault as the name suggests is a volt for you to keep a good known copy of your data away from the traditional attack services so that when you need to go to the Vault, you have the confidence that what is in the vault is actually going to allow you to bring your business back into production and the way we do that is if you think about a volts normally the vaults that you and I use whether or not it's in a hotel or whether or not it's a bank vault the ability to open the vault is actually controlled from outside of the Vault, you know, a keypad on the outside, etc. Etc. But a cyber Vol that we deliver from our data protection solution the Mechanisms to control it are actually controlled independent of everything that's outside.
It's actually controlled from inside the volt itself, you know, so the management of it is controlled and automated. Is also isolated from the attack surface and that is is why you know over the last few years. We have over 1,000 customers that have invested in the Dell Technologies cyber resiliency technology as a additional solution to their investment in our data protection capabilities.
Do you think we need to narrow the time between when the ransomware attack is detected and we start backing up the latest version of our data because it seems like the game is really just to protect as much data as we can as quickly as we can and then limit the damage because it doesn't seem like we're able to eliminate the thread altogether. yeah, I mean, I mean certainly, you know, one of the things you'll see your tended to see is quite often the concept of creating a backup copy is a daily, you know as a daily activity, you know, but you know with with storage and backup Technologies now the ability to create more frequent copies of your data is is much more readily available, you know, either through more frequent backups or the use of snapshot technology within the storage EK systems, you know, because a lot of what we're talking about with regards to vaulting data and and keeping copies good copies of data away from the traditional attack Services, you know are things that are not only available within the context of data protection and back up and recovery, but also, Technologies storage systems whether or not it be, you know, high-end primary storage solutions or unstructured storage solutions for file and object storage, you know, we have technology within both of those environments that also you know gives you the ability to to isolate and secure the copies of data on a more frequent basis, you know, and certainly you make a good point is that in today's economy time is everything so it isn't just how quickly can you restore but it's how how much exposure to corruption are you able to accept and the the smaller amount of time is driven by more frequent creation of copies within the environment. Do you think there's a lot more Focus these days on recovery time objectives because time is money and the longer that things are not recovered.
The more damage there is to the business or are we more focused on that than we have been historically. Now I I think I think that time, you know, the the old adage that time is money is is still very very true Mike, you know, one of the things that that as well as having a good known copy of data that is is kind of the the first thing that we that we advise our customers to do many clients are actually investing in what's known as a an isolated recovery environment because if you think about it when you get attacked by a cyber criminal and invariably that attack is something you have to report to the authorities, you know within the United States you would report that invariably to the FBI. You have to realize and some of our customers unfortunately have to deal with this your data center that's been infected now becomes a crime scene.
And your ability to recover into that environment may not be your choice to perform because the authorities are investigating a crime so many customers use the isolation of our cyber vault in order to build a recovery environment that they can stand up the critical applications in the critical systems that they need to run their business as quickly as they possibly can and they use that in parallel while the authorities are investigating the cybercrime. We've been telling people about the need for a 3-2-1 approach to data protection for years. And we've also kind of seen people not their head and then nobody ever tested the capability.
So are we getting better at the best practices for data protection are people really thinking through the testing to make sure they can get to the data because as you and I well known many people have invested in backup and Recovery only to discover that the data was corrupted for one reason or another. Yeah. No, you make it very good point certainly when it comes to cyber resiliency.
It's it's people process and Technology working together, you know, one of the things that that were that we're very fortunate to be able to do is the big part of Dell Technologies is is our our Global Services organization. So a lot of of what we do is very consultative in in its natur. Yeah, you know as far as it's it's really working out with customers kind of the the processes that they need to follow, you know, not only to create their cyber Vault.
But also if you correctly point out to regularly test their cyber is in itsy and their ability to bring the business back online, you know, a lot of a lot of the Consulting is to really work with customers to understand. You know, how much of your it real estate is Mission critical insofar as in order to continue to do what you do as a business. These are the systems in the applications that you need to bring up and you need to have available, you know, and and then to really concentrate on those initially as the the focus of your cyber resiliency investment, you know, but certainly, you know, testing recovery is is just as important.
For preparing yourself for Disaster Recovery, then put, you know recovery from sort of natural disasters that you know are things that we you know in the past were kind of the the big area of focus, you know, protecting yourself from from an outage caused by, you know, hurricane flooding fire Etc, but make no mistake cyber cyber attacks are are probably more prevalent than any form of naturally occurring disaster. All right, so to bring It full circle, do you think that the cybersecurity people are having more conversations with the data protection people or they still operating in isolation from each other and who's in control the budget and how much influence does that either party really have? Yeah, you know, we definitely seen a a change over the years Mike certainly, you know, the the debt Protection Team, you know was was very much, you know part of the the it operations organization, you know, they were offering a service, you know to the you know through it to protect data, you know and create copies of data for operational recovery Disaster Recovery over the last several years many of our of our discussions are with the the corporate information security office, you know, the the seaso's you know when and One of the things that that many customers find is that the budget for cyber resiliency is greenlighted much more quickly than you know regular IT projects.
In fact, you know, you know one of the times where you know, we find that the Cyber resilient infrastructure is invested in is is on customers to unfortunately. have been affected by a cyber crime, you know when you know, one of the the the best customer stories that we had is, you know, one of our United States school districts that that were infected by a ransomware attack and had to use whatever mechanisms and processes that they could to bring themselves back into production and it took them multiple weeks in order to get to a state that they could continue to operate in the way that they needed to so after that instance that incident they they worked with us and one of our partners to invest in a cyber recovery Vault and then Unfortunately, they were infected Again by a ransomware attack, but this time their ability to restore operations was measured in hours and not weeks so that was a real opportunity for us to sort of see the before and after and for them, you know, that was a kind of a game-changer that you know, being out of business and out of production for multiple weeks, you know means that they can Sort of off the classes to their students. They can't you know administer the school district.
So be able to do that in a matter of hours is really sort of the night and day and and many investments in cyber resiliency are not driven by the IT director. They're really driven and greenlighted by the the office of of the security officer. You also think that the board of directors is paying more attention.
It's easier to get these projects funded because they're starting to realize that ransomware is such a threat. Absolutely. Yeah, I mean, you know, we often say that cyber resiliency and cyber security in general, you know is a board level a board level decision, you know, and it's interesting one of the things that that the advice to many boards when they think about hiring cisos and one of the things that the the Gartner report talks about and they talk about as an organization the board should be thinking about, you know, green lighting.
How do we become a cyber resilient organization? One of the things that they say is hey one of the best sea saves that you want to hire. It's not somebody that has never been impacted by a cyber crime, but somebody that has been impacted and is actually had to deal with the repercussions of bringing the business up online.
So they actually talk about hiring for failure, you know, which is kind of like sometimes cancer. But it's kind of like the you know, the the belief is that people that have gone through something, you know have more understanding of what is needed than people that haven't had to deal with with conflict, you know, and that is is, you know, very, you know, you know, very true in this world of cyber resiliency. All right, no matter what the topic this School of Hard Knocks is still the best teacher.
Hey Rob. Thanks for being on the show. Thanks a lot, Mike.
All right back to you guys in the studio.