2. Cyber Resiliency is Just Data Protection – Tech Field Day Podcast
Cyber Resiliency is a term that encompasses much more than simply protecting data. This episode features Tom Hollingsworth joined by Krista Macomber and Max Mortillaro discussing the additional features in a cyber resiliency solution and the need to understand how data needs to be safeguarded from destruction or exploitation. The episode highlights the shift from reactive to proactive measures as well as the additional integrations that are needed between development, deployment, and operations teams to ensure success.
Transcript
Cyber resiliency is a very complicated subject, and sometimes in order to make people understand it a little bit better, you boil it down to something simpler like data protection. But is it really that simple or is there more to it than that? In this episode of the Tech Field Day podcast, we explore that cyber resiliency is just data protection.
Welcome to the Tech Field Day podcast. Each time we meet, we bring together a group of independent IT experts to discuss a single topic or a premise. This podcast is brought to you by the Tech Field Day event series where we bring these folks in person or on premises to discuss key concepts with companies in the industry.
My name is Tom Hollingsworth and I'm an event lead for the Tech Field Day event series, which is a part of the Futurum group. Before we get into today's discussion, let's meet our panelists, starting with Krista. Hi Tom.
It's, um, great to be here. Thanks so much for having me. Um, Krista Maycumber, I'm a research director and a senior analyst with the Futurum Group.
I cover, um, anything and everything, data protection, but also data security, and as we'll ultimately get into, um, trends around cyber resiliency as well. Hey, Dom, uh, max Morro. I'm, uh, an analyst at Tech and Plugs.
Uh, I cover primarily data infrastructure, so anything which is related to storage, data management, data protection, cyber resiliency, and so on. And it's great to be here. Alright, well, now that we've met you, let's jump into today's episode by introducing our premise.
Now I remember it as backup or maybe backup and restore, but it's gotten a little bit fancier since I was involved with it. You know, now we're talking about things like data protection and business continuity or cyber resilience, but let's be real about this. That doesn't matter what I call it, cyber resilience is really just data protection.
And now that you're thoroughly upset at me for that, I'm sure that somebody out there is about to leave a very nasty comment on this video telling me that I'm full of it, but luckily I'm not. I'm just trying to get you to leave a comment. I'm gonna open the floor up to my guests here.
What is it about the fact that people want to boil this down to like, you know, something that they're familiar with? Because I feel like that's a lot of what this kind of discussion is, is like cyber resilience sounds big and scary. Oh, you mean it's just backup.
Oh, okay. That's easy. Sorry.
Data protection is what we're calling it now, but we all know that there's a little bit more to it than that. Right? There really is Tom, and I think, um, you bring a, a great point about wanting to kind of boil things down to functionalities in terms that we're familiar with.
I think number one, when we think about the world of security, the network or kind of set of tools that we have available is just so vast and so complex that it's, um, important to kind of, you know, identify when we're talking about security in general, what really are we referring to? Um, and then I think as well when we think about, um, just kind of the new requirements that are emerging for, um, the ability to kind of recover data and ensure data privacy, um, that's where I think it becomes important to remain rooted in those fundamental capabilities to be able to then understand what's being added. Um, but certainly I would agree that it, you know, cyber resiliency goes well beyond strictly backing up in recovering data.
Um, and we can certainly get into that. Yeah, I, I would also agree to that, to that because when we talk about backup and restore, we're purely the functional scenario of I've lost some operational data and I need to recover it because I made a mistake or whatever. While here, when we're looking at cyber resiliency, we're looking way beyond that.
We're looking even beyond, uh, I think as, uh, Krista was saying, even beyond regular operational disaster recovery or even we are born in the, in fact, in the rim of business continuity, in the case of a catastrophic event. Uh, and, and it's not the regular case of, uh, there was a, a flood or there is something happening here. Here, the, the challenge is really ensuring that the company can recover and even survive because you have a real targeted attack against some critical asset corn, jewells and and so on.
Yeah, max, those are all great points. And even when we think about, um, double clicking down into those recovery requirements themselves, recovering from a cyber attack is very different from recovering from a traditional disaster that we're used to. Um, you know, it's not always clear when exactly the attacker penetrated the environment, um, and things of that nature.
Um, also there's the requirement to really understand how critical and sensitive, um, you know, is the various data that may have been impacted, so that from there, um, it's possible to, to prioritize what is recovered first. Yeah. I wanted to also say that you also have a kind of a, a difference between, you know, the immediateness kind of operation recovery where we want to be as close as possible to your, uh, recovery point.
Um, and here you need to, as you say, to probably have a gap between what you want to recover because you may have data which is very close to let's say the latest backup you have that may be compromised. So there are other factors that you take there into account and also the, the necessity to verify and probably clean the data eventually before you can restore it, uh, in production. And I think that's a very important point because historically backup and disaster recovery and data protection have always been focused around what happens when some kind of an external factor causes a complete outage.
Like I live in the state of Oklahoma, I've seen what happens when a building gets wiped out by a tornado. And that is, you know, the, the, the restoration part is, well, we need to go get the data and we need to go put it somewhere where we can find out how to pay the teacher's payroll or something like that. And that's when business continuity came around and said, well, what if we had like a, a, a vaulted site somewhere that we could get everything back up and running quickly.
But cyber attacks often, like we've seen with the, you know, the xz U utils attack that recently happened as of the recording of this podcast, that was two years in the making. We don't know where the bad data is. We have to be able to have additional tooling that will allow us to detect that.
And I think that's one of the things that the data protection vendors really kind of kicked off when they started talking about things like entropy detection in your, in your backups or in your offline storage, where it's like, we can tell when things are suddenly hard to compress because they're being encrypted. That's our usually one of our first markers that something is going on and you need to be aware of it and you need to fix it. So is this kind of like a software augmentation of what is considered traditionally to be, you know, pretty simplistic software and hardware?
Like we write this to tape, or maybe we back it up to the cloud. Are we starting to add intelligence in there that allow, that give us better capabilities to not only recover from disasters, but even maybe to prevent them before they happen? Sure, it's a great point, Tom.
And we're definitely seeing more sophisticated capabilities are being, um, you know, built in or otherwise added to data protection software. And you bring up the great example of, um, the ability to detect that an attack is in progress based on things like, as you mentioned, um, you know, PY changes within the backup environment, anomalous user activity and things of that nature. So, um, that insight and that intelligence can be used to, um, you know, prevent the attack from fretting from spreading further into the environment.
Um, and it also can be used to identify what Max is alluding to in his comments, what we refer to as the last known good recovery point. So really kind of identifying, um, what is the point that we can roll back to and minimize the amount of data loss. Yeah.
In addition to that, you, I mean, several resiliency is, is data protection is part of that, but it goes way beyond that. So in any case, you need to implement kind of controls at multiple layers, right? So data protection is ultimately kind of your last result point where you want to go to when you've lost any hope of recovering anywhere else.
But there are variety of controls. So it's not just the ability to detect, but it's also the kind of prevention controls that you want to implement. It can be, you know, your, um, immutability policies, how you secure your retention policies, or you avoid, you know, people from making unauthorized changes or rather how you make that harder and more difficult for the intruder.
And that's going to happen at different levels. You can do that at the primary storage level. Of course, you need to also think about doing that on the data protection system.
Yeah, I think it's important to point that out, max, that, that it's more than just being able to get the data back. It's being able to prevent the data from being destroyed in the first place. Because one of the things that we've seen quite frequently with new attackers that are coming out is once they get into the system, the first thing they do other than, you know, try to remove the log files that prove that they got in, is they go after the backup systems.
They are trying to take away your ability to restore the data. Now, that is generally true of people who are doing this kind of as an extortion kind of play, where they're gonna ransom your data back to you, whether it's decrypting it with an encryption key or flat out stealing it. Um, they don't want you to be able to get that data back because one of the things that, uh, a lot of these third party, uh, services that are trying to help broker these things, uh, say first thing is don't pay.
Like if you pay it, they're just never gonna go away. Um, you've got to find a way to get that data back from a certain recovery point or something like that. So what ha usually happens is the attackers infiltrate and then they disable the backup systems, they delete the accounts, they remove the ability for you to get that back.
So should companies that are looking into a, what maybe more considered a traditional data protection system be asking about these cyber resiliency pieces, what can you offer me above and beyond just a simple data recovery from point of failure? It's critical. I mean, so we work, um, closely on a regular basis with, um, IT practitioners and absolutely it's become a table stakes capability.
Um, you know, for sure. And that's because as a whole, when we think about cybersecurity and cyber resiliency, um, there really has become the need to be as, um, preventative and as proactive as possible. And that's because the attackers are getting smarter and smarter every day.
Um, as you mentioned, Tom, they've been targeting the backup environments for some time now. They're now armed with artificial intelligence, um, to just kind of up the ante, if you will, for their attacks, right? So, um, the more capabilities that are built in to be able to prevent the attacker from gaining access and to be able to detect as quickly as possible if they have gained access, those are gonna be critical to minimizing the amount of data loss, minimizing the amount of downtime as well.
If an attack does occur. Yeah, probably as a site, as a site comment as well. And in most of the cases we're facing, you know, uh, ransomware attacks where they want to, you know, extract a ransom out of you.
But we also have cases where it's more cyber warfare between, you know, uh, nation state actors and there the intent is not to kind of get a ransom out of you. It's pro primarily either to, uh, you know, completely destroy your data or your system, you know, regardless, you know, there is not even any kind of regard for the ability of recovering anything, but it's just a, a side note. But, you know, uh, as Krista was saying, uh, the, these, these capabilities are, are becoming table stake in the sense that most, more and more organizations are looking after that, uh, especially clean rooms, which are starting to get, you know, productized.
So moving away from kind of, and how would I say that? Reference architectures where you need to add a lot of elements here, this and there, and you need to, to compose with multiple elements. And it's becoming more and more, I mean, or gradually at least we see some companies releasing products which kind of simplify the workflow.
Now, it's not that easy in the sense that there is still a lot of things that you need to integrate manually, especially all of your tests, you know, to recover the data, to do the cleaning. This is not going to be, uh, automated probably any soon, I would say. I would agree.
And I think that that's valuable for people to understand that, that, you know, the complexity of these attacks has grown significantly even in the last, just three or four years. And part of that expansion comes from the fact that it, there's a valuable funding ramp for this. And when you look at, you know, things that are evolutionary, we always go back to things like the emote, um, a series of malwares and things like that.
It's not just that these people are writing a tool to be able to get into your systems, it's that they're taking what they've learned and they are improving upon it with every step of the way. So the next strain of this virulent system will be more hardened against your, your countermeasures, and you can't just hope that, oh, hey, this, uh, this program that uses like, you know, uh, vaulting copies or creates, you know, a certain kind of immutable snapshot is gonna be enough to prevent this from happening in the future. You know, should we be encouraging our vendors to begin kind of exploring these ideas a little deeper so that we are legitimately trying to avoid this problem where the attackers have more technological sophistication than the defenders?
Absolutely. So I was, um, last month I was at an event for Microsoft for their copilot for security launch, and that was, um, kind of a big topic of conversation was, um, you know, enabling the defenders, if you will, to be, um, you know, a step ahead of the attackers, um, in how can you know technology vendors, what kind of tools can they provide to do so, so in Microsoft case, it is, you know, this artificial intelligence assistant that not only makes your, um, you know, SecOps team makes their job that much easier, um, but it also can help them to do things like, you know, begin to automatically apply data privacy policies as content is being created, or, um, do things like maybe uncover some vulnerabilities in the environment. Yeah.
And, and that's one of the important things that people have to understand is it's not just that there's a way to detect it, it's a way to kind of contain the damage, because we all have heard that, you know, doesn't matter how the attackers get in the front door of your system, whether they're, you know, crashing through the gates or they're slipping in through a, an unused service account, the behavior of the attackers almost always looks the same. They want to do lateral movement to unprotected systems. They want to try to find ways to escalate privileges.
You know, uh, if we think back to the, uh, the Seminole work, Jurassic Park pray distinguishes itself through movement, that kind of thing, where we're looking for them to try to jump to another, to another system. We're looking for them to try to find ways to keep moving. And if we have guardrails in place from a data protection or cyber resiliency solution that says, no, no, no, no, the backup operators group should never be trying to jump onto these servers with login attempts at these times.
Like that's a way for you to not only contain the damage, but to send a secondary alert to your operations teams to go, wait a minute, something isn't right here and you need to figure this out. A hundred percent. And, um, one thing I know we were talking a little bit about internally before we went on, um, I hear here that I think is relevant to this conversation, especially as we look at data protection and data security, is, um, what the industry is calling data security, posture management.
So that's kind of the ability to not only, um, you know, have some data classification, but really take that a step further and be able to do things like uncover if there are vulnerabilities in the environment like misconfigurations or maybe access to data, um, that shouldn't be provided to a particular user, um, to be able to kind of uncover those, um, so that the security and the IT teams together can take action. So it's, you know, really kind of along those themes as well of being very preventative upfront. Yeah, if I can can jump on.
So on, on one topic, it's really also going with cyber resilience. It's really a, a kind of a shift also in the mindset, which usually was like, yeah, there is a probability that something may happen to us when we are talking already about cyber resiliency. We are already taking for granted that we are going to be breached at some point in time, and that we have to think more about what are critical assets, how we protect them, how we can bring them back, how we can, you know, enable the organization to recover from this kind of attack rather than be in a kind of a denial saying that, Hey, it's not gonna happen to us because we're smarter than the other guys.
You know, it's not really the case. Uh, everybody can get hit at any time. So it's really about kind of completely changing the way we think about it.
Okay. We're never gonna get hacked says, uh, the company that gets hacked like within the next month that they say that. Because if you're not making yourself a target, you're not paying enough attention to be able to figure out how to prevent this from happening.
And, and I think you're, you know, you're spot on with that max, that companies, even if they think there's a low likelihood that they're going to be breached, they need to know what's important. Because, you know, if you think back in data protection and, and business continuity, we always had things like recovery time objectives, recovery point objectives. Now obviously they haven't gone away, but it's important for people to understand that you can't immediately restore all of the data you have to triage.
What, what's important to get back? Is it important to get back transaction data from five years ago? Or is it important to get the operating, um, systems of the, the company back up?
I mean, look at when something like the Apple App store going down happens, what's the most important system to get back up? Is it the one that allows you to add a description to an app, or is it the system for buying the app from the app store? Well, if you ask Apple, they'll tell you exactly what it is.
So they have to do that prioritization, and unfortunately we do too, and we have to reclassify that information as we move along, which is why I think that things like data security, posture management are so important is because it gives you a framework to be able to go out and say, this is important. This needs to be restored, this needs to be protected. We need to find ways to keep this moving so that we don't find ourselves getting caught out with, oh, well, you know, we just lost all of our customer data.
Well now we actually found it, but it was on an unprotected server, so it may have been exposed to people, and we need to figure out what we do need to do to triage that A hundred percent. It's about getting that insights so you can have that plan, right, and kind of react accordingly. That's, you know, really what is the, the really unique part about these cyber attacks.
Yeah, we definitely need to understand what kind of applications you have, the priority, the importance. Triaging is key also in the context of how you are going to implement, uh, you know, your, your kind of recovery environment as well, because you might have that on-prem in a colo, you may want to recover in the cloud. And there, there's an entire, uh, different set of, you know, requirements, constraints that come into play based on what is your strategy where you want to recover.
You may need to think about, you know, connectivity from to the cloud. You may need to think about, uh, the cost aspect because then building an environment, you know, or during the recovery in the cloud is going to be fairly easy to do, but then comes the cost, you know, of doing that there, procuring the infra and so on. So, uh, you know, there, there's no easy, you know, answer, but, um, there's this aspect which is to be taken into account during the design stage.
I would say Max, did I hear you right, that just backing things up to the cloud isn't, isn't a strategy like there, there needs to be something more involved because I, I was told by this other guy that all I gotta do is just copy my data to this S3 bucket on, on Amazon's servers and, and know, get taken care of it's Magic. No, no, no. This is, I I would say it's a bit too advanced.
I would recommend that you just stick with VMware snapshots, which is a proven method. You know What I love? Oh man, we are gonna get planned For that.
What I love too is, oh, the recycle bin in Microsoft 365 is a backup policy. Nope, you're right. Nope, it's not.
It, it has a retention policy and you can guarantee that it's gonna be the first thing dropped whenever something happens. And I think that it's, it's a shift in the way that people think about these policies. You know, backup and disaster recovery.
We're always reactive. We don't have to do this until something bad happens. And I mean, how many times have we told people you need to test your backup so that they don't fail?
Right? Well then we get into this idea of data protection. You need to be more proactive about it.
You need to make sure that you have things in place to stop the problems before they happen. And now that we've turned this corner to cyber resiliency, it's, it feels like it's a more holistic outlook on things. It's creating policies that prevent these disasters from happening in the first place.
So you don't have to be proactive. That then leads you to not having to be reactive, but you can be reactive when you need to be because you've created something that is more survivable than just somebody go dig that old backup tape out of the back of your car so that we can get the operating system for the server back online. Exactly.
Exactly. It's, um, it's pretty fascinating what these, you know, vendors are developing. I'm even seeing, um, you know, the ability to, um, you know, take a snapshot or take it back up based on this anomalous activity that's being detected that we were talking about a few minutes ago.
Um, and to me that's truly kind of the, the reactive end of things. And then as you mentioned, Tom, kind of the ability to also upfront build in capabilities so that hopefully we're at least minimizing, you know, the potential attacks that get through, um, you know, through capabilities like data security, posture management, um, and things of that nature. Yeah, I would say that it's also, it's also has, um, a positive aspect overall in, you know, how I would say assertive.
The organization is in, you know, properly configuring and protecting the assets. Uh, we've tended to be pretty much lenient in a way in the past because the probability of that happening was very low. We had to deal with other stuff, everything we need to take a very tar approach at all levels, you know, um, implementing proper security everywhere.
So I think it goes to what Krista was saying before about this, uh, you know, uh, posture management, uh, aspect. Man, you guys are telling me that I'm gonna have to integrate with my operations teams and understand how things work so that I can address their needs as they, man, this is becoming a lot more involved than just popping the backup tape in and taking it out and taking it home with me once a week. It's, oh, man.
Yep. Yeah, we, um, it was interesting. We actually filled us some research, um, late last year that was talking to, um, you know, kind of the executive level.
And what we found was, um, security and IT teams are starting to work together and it's largely, you know, kind of driven by these cybersecurity and cyber resiliency requirements. You know, I think when it comes down to tactical things like, you know, having the proper systems in place and things of that nature, we're still getting there, but I think we're certainly making strides in terms of both teams are getting on the same page about the, you know, business objectives and the vision. Um, and they're starting to really begin to do things like start to create some joint incident response plans and things like that.
So it's, we're, uh, we're making progress, I think for sure. So I'm gonna put you on the spot. If somebody walks into my organization and says that I need to buy their new cyber resiliency widget, what is the one question that I need to ask to find out how fully featured it really is?
It's good question. I think the way that I would approach it is covering both ends of the spectrum that we've been talking about. So asking what are the number one capabilities for, you know, ideally preventing attackers from getting in, and then what are the capabilities for, um, remediation, assuming that at some point there is unfortunately going to be a breach.
Well, I, I, I would like to probably see, um, the, the full scale of, you know, features which are available in the solution. So, um, probably, uh, what happens if I was to lose everything, you know, what, what kind of architecture or element I have to go beyond just, uh, what's on-prem? I mean, it's not probably a satisfactory answer, but, uh, I, I want, I want to hear more than just, uh, we can protect you against ransomware.
Show me how, show me what that means. You know, what, what's, what happens? Because what happens if I lose your primary infrastructure?
That will be probably the question I would be asking. Yeah, because it's great that you have data protection solution that you have immutability, you have this, you have that. If I go there, if I wipe the underlying storage, how do I recover from that?
Well, as you can see, this is a complicated topic, just like any other things related to security. And unfortunately, anyone who tells you that it's a very cut and dried answer is probably trying to put one over on you. There are a lot of nuances that you need to understand in order to see why data protection is not cyber resiliency and cyber resiliency is more than that, that there's more to it than that.
So yeah. Yes, the premise of the episode was obviously designed to kind of put you in a, in a spot where you're thinking, well, why aren't those two things equivalent? And as you can hear from our experts, there's more to it than that.
It's that the proactive nature of it, it's the uh, way that it integrates into systems and operations teams and helps you understand all of the policies that need to be put in place so that you never even find yourself in one of these kinds of situations. Because let's be fair, the best backup solution out there, whether it's data protection or cyber resiliency, is the one that you never have to use in the first place. I want to thank you both for joining us today on the Tech Field Day podcast.
Where before we go, where can people connect with you to learn more about this conversation? Sure. Um, so I am on LinkedIn, um, and I'm on Twitter.
Um, we can make sure that those things are included in any show notes here. Um, and I also do, I publish regularly on the Future Arm Group website. I also co-host a weekly podcast of my own called Infrastructure Matters, um, through the RUM group as well.
You can find me also on LinkedIn, Elia and RO on X at max ro probably the seven on masteron. Um, I am blogging on a regular basis at Tech Unplug io slash blog, and otherwise, you know, YouTube, whatever, everything is on LinkedIn usually. All right.
Well, thank you very much for listening to this episode of the Tech Field Day podcast. It is available in your favorite pod catcher or on YouTube. If you enjoyed this discussion, please remember that you subscribe so you don't miss an episode and leave a rating and a review for people so they know what they're getting themselves into.
com slash podcast. Thanks for listening in, and we will see you next week.