99. Data Protection Needs To Do More – Tech Field Day Podcast
Data Protection is a critical component of security but it needs more features to meet the challenges of today’s attack environments. In this episode, Tom Hollingsworth and Jack Poller discuss how data protection companies like Veeam, Commvault, and Object First offer solutions like immutability and identity protection as solutions to modern problems. They talk about the importance of having a holistic business strategy that directs restoration efforts such as realistic RPO and RTO objectives. Lastly they discuss how data protection companies can use events like RSAC to get the word out about their latest features.
Transcript
The world of cybersecurity is heating up, and you need to make sure that everything you have is protected, and that is the basis of data protection. But is the bare minimum of data protection enough? In this episode of the Tech Field Day podcast, basic data protection isn't enough.
Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community and is often as-- recorded in association with one of our events. Tech Field Day is a part of the Futurum Group, and this podcast is published on our sister company's website, Techstrong TV.
On this episode, which we're recording prior to the RSAC conference, we're gonna be discussing data protection. But before we get to that, I'd like to introduce my co-host for this episode. Hi, I'm Jack Poller, founder and principal analyst with Paradigm Technica, focused on all things security.
And I'm Tom Hollingsworth, event lead for Security Field Day, as well as the event lead for Tech Field Day Extra at RSAC twenty twenty-six. Let's jump into the premise for today's episode. No doubt you've seen that, the hacking community has been rather spicy as of late, and there's been a lot of attacks that are backed by both criminal organizations, but also nation-states, and they've been pretty destructive.
And we know that security has been pivoting quite a bit over the last few months to incorporate lots of new solutions. One of those is data protection. And we're excited to hear from some data protection companies during Tech Field Day Extra at RSAC.
But the premise for this episode is that basic data protection is not enough. I know that a lot of people out there are probably thinking, "Well, you know, I've got backups. " But at the time of recording, we've seen a recent spate of attacks that are, quite honestly, kind of eye-opening.
It's not just locking up your files and demanding Bitcoin and ransom. We're talking about organizations that have had every server wiped and locked out, every mobile device, whether it's a laptop or a phone, completely annihilated, and it happened in a matter of hours instead of days or even weeks. And so that's what led us to kinda come up with this idea of data protection is not enough.
Data protection's important, don't get me wrong, but there's more aspects of data protection that you need to think about. So Jack, I, I wanna toss this over to you. What's one thing in data protection that you feel like needs to be a critical component above and beyond what we would consider to be traditional backup recovery da-- disaster recovery, business continuity?
Right. Well, I think part of it starts with, looking at the history of where we started from. And, you know, data protection, backup, and recovery was really based on the premise that we were dealing with physical components that failed, hard drives that failed, right?
And how do we recover from a failure? And throughout all of that and, and almost all of backup and recovery was premised on the fact that you were losing a part of your environment, but not the entire environment. What we're seeing today is the total scorched earth destruction.
And so the question is, h-uh, both how do you recover from that and how do you prevent that from happening in one way or the other? And looking at it and saying, "Well, it doesn't matter what they do because I have a backup," or, "I have an immutable backup," or, "I have an air-gapped backup," the, you know, there's this huge amount of business continuity interruption, and we have to think about things not as recovering from a portion of our environment that gets lost, but how do we think about the totality of our environment and the totality of our business? And so I want the-- From a data perspec-per-- data protection perspective, I think the vendors need to look at not solving so much a security problem, but a business problem, which is how do we keep our business up and running in the face of both mechanical disasters, network disasters, s-physical attacks, network-based attacks, insiders coming in and doing stuff, people who have nefarious, you know...
The, the, the nefarious goals here are changing, and the tactics are changing, and the tactics are happening, and I'm gonna use the word that we-- everybody hates to use, but we have to use, which is AI is changing the game again. And so I think we need to start thinking about looking at the big picture, not just at data as data. So let's start there, because one of the presenters that we're gonna have at Tech Field Day Extra is Object First, which was recently acquired by Veeam, and immutability is kind of their, their key f- platform feature.
Uh, they have something they called OOTBI, O-O-T-B-I. Uh, it is an on-premises, storage appliance that is, capable of backing up at least four hundred and thirty-two terabytes at its, its highest capacity, and you can actually cluster those things together to get even higher than that. But one of the things that I think is important for people to understand is the days of just, like, taking the tape out of the LTO drive and, and shuffling it off to a vault somewhere, that's gone, because the amount of time that it takes to get that, hardware out of the building to kind of a, a safe site, like, that could be the end of your entire data set.
Uh, like I, I remember doing this back when I actually did it for a living twenty years ago, and the concept of, you know, well, having an off-site storage thing, that was the hard part for me to get people to, to think about. " Um, you know, i-nothing can destroy the vault, because as we've seen, one of the first things that attackers go for now is the backup data, because they know that if someone has a good backup copy, they're not gonna get paid. They're just gonna restore from that.
SoIs immutability in and of itself enough for people to say, "Yeah, we're good. Uh, don't pay the ransom. We'll just get all of our data back"?
In that particular case, it may be. And I think immutability is a necessary component of a data protection security strategy, but it's not sufficient. So let's just look at what happens when they wipe your four hundred terabytes of data.
How much effort does it take to restore that? What's the time involved, and what's the loss of business during that time? How many...
You know, for some, for some organizations, they deal with a lot of data, but not a lot of business volume, so maybe that, that, you know, day downtime or whatever it actually turns out to be is not. Other businesses measure their revenue in millions of dollars per minute, so, you know, minute downtime is, is, is crucial. So yes, you definitely need immutable backups to prevent the, the attackers from destroying your backup.
But what happens when they get in your environment? They-- maybe they can't destroy your backup, but they can still destroy your primary environment, and then what do you do? And so I think we need to look at, what's the business continuity plans?
What are we going to do while we're in the process of dealing with an event? Both identifying the event when it happens, in process, "Oh, we've been attacked. Now what do we do?
How do we prevent it? How do we mitigate it? " Right?
And I just think that the data protection is just one piece of the story. I think we need to look at, you know, how does, the a- user access come into play, right? And a lot of people say, "Okay, I've backed up my important data," right?
But a lot of, organizations are still based on-- even cloud-based organizations are still dependent on Active Directory. Now, do you back up Active Directory or not? If you...
Right? If you don't have your Active Directory up and running, nothing... You know, it's, it's the, it's the very st- first step in recovering your environment.
If Active Directory goes down, everything else is down. Doesn't matter. Your users have no identity.
They can't get to what they need, even if the data's there, right? So we do have to think about all of the-- Again, I'm going back to sort of this concept of what's totality of system. What are you protecting?
How are you protecting it? And, and I think that it's important to note that all of the presenters that we're dealing with at Tech Field Day Extra, both Veeam, Object First, and Commvault, have ways of protecting your identity store- Yes ... which is Active Directory or Entra ID if you're using Microsoft Azure, and I'm gonna call it Active Directory 'cause that's how old I am.
But, but that's something that people have to understand is, like, if, if the identity store is corrupted, it doesn't matter how much data that you restore because they're just gonna be able to get back in, and a lot of people just kinda forget that after a while. A-and I think that it's important that the, the, the, data protection people have hooks into the identity store. They're able to monitor it.
They're able to ensure that it is consistent because otherwise you're, you're just leaving the door open. You know, it's like if you paint a fresh coat of paint over the hole that they s- knocked in the wall, well, the hole's still there. They can just go right on through.
And it's becoming more and more apparent that a lot of the identity problems that we're running into are also from insider threats. Yep. Where it's like, if I can corrupt somebody or if I can create an attack that's specially crafted to nail somebody, I, I can get lots of access inside that I shouldn't.
And, and I think the companies are finally starting to realize that we can't trust everyone. We have to kinda look at everything as we're keeping an eye on what to keep safe. Well, and there's, there's, there's two aspects of, insider threats that we have to think about.
When we talk about inside versus outside, we typically mean, you know, an employee or a contractor who's part of our organization versus an attacker who's not part of our organization. But when an attacker gets somebody's identity, and they've corrup-- right, they've compromised an identity, and now I go into, you know, Tech Field Day and I've managed to con Tom out of his password of password123, then I'm now Tom, and I'm doing activities inside, so I'm actually now an insider even though I'm an outsider, right? I've assumed his identity, and I'm running around the environment as if I'm an insider.
And so we still have to think about that inside threat as still an outside threat, potentially. The other thing to think about is, you know, from a data protection point of view, is are you actually protecting data, or are you protecting systems, right? So one of the things that we talked about at the intro is this, a nation state attacker who, right, went after a US-based company and wiped not just the systems in their, IT environment, but also their mobile devices.
So what effort are you doing to protect your corporate enterprise level data on your employees' mobile devices? What do they have access to? And how important is that data, right, to your organization?
And so the, you know, and can you recover that data that's residing on their mobile device or not? I think that's another piece of the pie that's missing. A-and exactly.
" Well, what happens if your mobile gets wiped? " But will iCloud allow you to restore if the MDM server is down? Like, like, there's a lot of challenge there in, in the correct order of restoration.
And, like, that was -- that's one of the things that I remember from back in the day doing a restoration on a failed server, was I actually had to get Novell Directory Services back up and running to have authentication to restore the data. Sometimes that was more challenging than getting the data restored. And, and that's kind of an old school way of thinking about it w- that you brought up.
Like, am I protecting data? Am I protecting transaction data, databases, or am I looking at holistic, server architecture? Am I able to do a bare metal restore to get my recovery time objectiveUh, as slow as possible because, you know, going back to something you said, all companies have an RPO and an RTO.
If, if you don't know what that is, you should find out because it's important, because they're two very important numbers. RTO is how quickly can we get this thing back online so we're not losing money? But RPO, recovery point objectives, are how far back do I need to go to get the right data?
Because this is one of the things that you and I heard at, Commvault Shift last year. Uh, sometimes you, you may have to roll back weeks to, to find uncorrupted copies of the data that you are know are good enough that you're not gonna continually reinfect yourself, but does that mean that you have to do an atomic restore to three months ago? That's a problem if you've got a lot of transaction data.
If you know that it's a problem in, say, the operating system files of the server, you'd rather d- restore the transaction data up to, like, yesterday, but maybe restore the OS back to a couple of months ago. And, and at least in my career, that's something that's not easy to do because the backup was the backup at this time, and you, you can't restore in piecemeal. And, and, you know, we've talked about, you know, and I brought up mobile devices, and we talked about those being separately and, you know, companies think about backing up their data as, you know, their systems level data, their database, their transaction system, their email system.
How much of our business today exists and it works on Slack or Microsoft Teams, right? And how much would we lose? I mean, there's a whole...
I-in the DevOps world, there's an entire CI/CD, continuous integration, continuous development pipeline that's based on integrating with Slack and with, ServiceNow and all of these external environments, and we need to protect ourselves from when those systems go down, when an attacker gets in and destroys the data, or when somebody goes and tries to steal the data and exfiltrate it. And there are three different use cases there, but all of these things, these systems are now tightly integrated, and now that we throw agentic AI into the mix, it gets even more tightly integrated and with more pieces moving faster. And from a, a, a CIO and a cybersecurity CISO perspective, you know, you can't protect what you don't know about.
So when we talk about data protection, what data are we protecting, right? And so it's great that we have, when we've protected the data, that we have an immutable backup of it. We have immutable, right-- Nobody can change the storage so that when we go to recover it, we have something that we're-- we feel very confident that we're recovering good stuff.
But are we s- is it suffi-- Are we protecting all of the stuff we need to protect? Oh, the solution, Jack, of course, is just back up everything, right? Storage is unlimited, effectively.
It, it can't cost any more to back up an extra forty-eight terabytes, can it? Uh, please, I hope somebody is laughing at that, because that is exactly the problem, is that we, we need to be strategic in what we are, are, trying to protect. And just like in the old days of having an IDS sensor on every server, that's expensive and creates a lot of extra noise.
Well, if you're literally backing up every bit that is written to disk or cloud or what have you, the amount of time that it takes for that, data to be, you know, put in a immutable copy or, or stored somewhere, like, physics is still physics. Like, I can't transmit a terabyte file any faster than physics would allow, no matter what kind of thing, and that's just thinking about the data transfer over the wire. If the system has to process that and catalog it into a, a format that is easily recoverable, you're adding overhead onto that.
And what happens when you run into the problem of, well, you know, it takes an entire eight-hour span overnight for me to back up all these files, and now it's time to start the backup again, or it's time for operations to start, and, and I can't deal with latency at that point. So yeah, we have to be strategic, and, and I think that that's one thing that data protection companies really need to make sure that they're upfront about, is do you have a method to help identify certain things that are critical that need to be backed up? " Uh, 'cause, you know, for, for everyone that says, "Oh yeah, well, it's, it's stored in a database somewhere, and we back that database up.
That's not a problem," is an Excel spreadsheet living on someone's laptop that is critical to the business that nobody knows about because that one person is like, "Oh, you know, I just... " More, more importantly, is their backup strategy in an Excel file somewhere? Which when you, when you, when you talk to and, and you know, I'm being facetious, but I'm not, because when you talk to people who say, "Oh, it's all backed up," a lot of times it's all backed up because I have a, a spreadsheet that tells me what tape number I'm using or what disk drive it's on or whatever it is, right?
And, you know, and I laugh at that, but I also laugh at something else you said, which was the old days, we used to talk about, well, storage is cheap, storage is essentially free. Funny enough, AI has changed that equation again, and now storage is suddenly in very high demand, memory and storage, and so now storage is getting to be expensive again. And so we can't necessarily think about it, and so again, we do have to think about the business side of this.
And, you know, and a-any cybersecurity leader who isn't thinking about... is-- who is only thinking about attack and defend and not thinking about how do I protect and enable the business to do better, go faster, be more secure while it does its business, right, is not really a security leader. They're just part of the machinery, right?
They're not really helping and enabling the company. " "Well, no. " Right.
" "Well, no. " Like, oh, okay. Like, like that's the reason why you field test generators in a hospital is to make sure that they're actually gonna kick over when they're supposed to.
And, and that's more important for people now because, again, like even with the best like entropy detection systems that a lot of these vendors have implemented in their solutions now, you may only have a matter of an hour before everything in your system is crypto locked, and that's like using automation to do it. Could you imagine if someone was maliciously trying to avoid triggering those kinds of things under a certain threshold? It's like, "Hey, wait.
" "Oh. " It's like the people who deposit nine thousand dollars into a series of bank accounts. It's just under the reporting threshold, so I can get away with a lot before someone's like, "Wait a minute.
" And, and you, you bring up, something else which is, I think, becoming important, which is the speed of operations, and I was about to say the speed of attacks, but it's more fundamental than that because AI is working much faster than humans do. " And so that was the instruction they gave to an AI agent, and unfortunately, the AI agent lost track of the don't delete instruction and went rogue and started deleting everything. So this person's only recourse was to literally run over to their laptop and unplug it from the network and turn it off was the only way they could stop bad things from happening, right?
So when we think about data protection, right? So now sh- this person just deleted years of email archives. What's the level of effort?
Some of which are very, very important, some of which may be subject to legal holds to discovery, right, and lawsuits, and so how do you go and protect from that type of event, from AI agents doing things they shouldn't? They're not an attacker. They are not doing something wrong necessarily, but they are operating very quickly.
And the other part of that too is if you have something that's looking at data exfiltration and looks at it as at volume, is that volume now gonna -- those, those volume calculations gonna change based on an AI agent doing stuff at machine speed that we didn't think about before? Yeah. D-DLP is gonna have a nightmare if it sees a whole bunch of stuff flying out of the system to be analyzed by a model somewhere.
That's right. But that, that's the, the problem we have to think about because security has changed radically in the last two or three years from when we started debating all of this stuff. Like you remember when, we were talking about having like, you know, big Hadoop clusters that needed to stay on site and egress and ingress costs were astronomical, and no, it's gotta stay over there, and we need to optimize east-west traffic, and now it's like, just kidding.
Uh, you know, we, we need these things and these clusters and these special arrays and, you know, then we need to make sure that it's all protected, but not this stuff over here because we really don't care about that. We can regenerate it. And, and we're kind of -- the, the landscape is shifting so quickly that it's hard to keep up, and I think that that's why it's important that people have a holistic strategy.
Yeah, don't get me wrong, data protection is a critical part of it, and I'm very glad to see that companies like Veeam and Commvault are keeping up with what the, the cutting edge is. But it can't just stop. We can't say, "Okay.
" We need to continue. We need to build on that. We need to see how the attackers are coming after us, and I think that the AI agent conversation is one that's very important to have because we're starting to see more and more, threat actors leveraging AI.
Maybe it's not, oh, well, AI is hacking this for me, but they're dispatching it almost like workers, where it's like, "Okay. " Because, you know, they don't get tired. They don't need to go have a Cheeto break.
Like, they literally can just keep going and then tell you, "Hey, guess what? " A-and then it's up to the, the human in the loop to say, "Okay. " And the good thing about Commvault and Veeam showing up at RSA is they are now participating in the security community and learning what it means to think about the business world, the, the business of security as opposed to the business of data protection, and I think that's a key component that I, you know, is very important is that through participating and being a part of the community, they're going to, only get better at helping us secure our environments, right?
Uh, you know, but, you know, and you're right that AI is accelerating things on the attacker side. There was another, incident that just, hit on my radar right before this show where, luckily it was a white hat hacker who found, a misconfigured database, and that was now exposed to the world. And I can't believe in this day and age I'm saying that people are now misconfiguring their databases and exposing them to world, but they still are, despite the presence of many cybersecurity tools aimed directly at that particular problem.
And this white hat hacker used an AI agent and twenty dollars worth of tokens to go find a vulnerability, get in, and, theoretically could have exfiltrated, you know, terabytes of data, right? And it's, you know, so we stillWe still are missing on a lot of the, the fundamental basics of cybersecurity and basic cybersecurity hygiene. And, you know, and data protection is, of course, one of those very important components.
Yeah, we, we have to have whole-- we have to have a, a business case policy for this. We can't throw tools at the problem and hope that they're gonna fix that. And that goes back to, you know, easy definitions.
Do you have a BCDR plan? Do you have an RPO? Do you have an RTO?
What is the budget to hit those things? Because the worst thing in the world is to think that you've got one thing and find out you don't. And, and I, I'm in a unique position because I live in a part of the wor-- country where disasters usually take the form of, like, huge weather events, right?
Like, I've seen what's happened when people have had to dig through the wreckage of a tornado to grab hard drives out of a server to, like, run payroll for teachers, and that's a different kind of disaster than a nation-state hacked my hospital and wiped every device. But they both have the same end result, which is we need to get this thing back up and running, and we need clear direction on how to do it. Yeah, the tools are gonna make that a lot easier.
Like, you know, thinking back, 'cause that, that particular example that I gave was literally something that happened about a day before I started working for Tech Field Day as an event support person. And now, thirteen years after the fact, that conversation is a lot easier to have, right? "Oh, well, let's go out to the cloud, and we'll restore it.
" But then what happens if someone gets in and is able to completely wipe all of the, the stored payroll information in the cloud because we're protesting something? Who knows? Like, like, you, you-- your business has to know how to handle that.
And, and yeah, your business... I'm not talking about Boeing and Walmart. I'm talking about anybody that has anything stored in Amazon, anybody that has anything stored on a computer on their, their desk that they use for checking out, crafts from an Etsy store or whatever.
Like, y-y-you've got to have an idea of what's gonna happen if everything goes dark tonight. One of the things that Commvault u-d-did a couple years ago, and I'm-- I hope they're still doing it, is when they, they moved into ransomware protection, they would run a, a thought exercise, a little tabletop exercise with executives in a company, not the security folks. The C- CISO would be there, but it would also be your CFO and your CIO and the CEO, and they would basically say, "Okay, let's do an exercise.
Let's simulate what happens when you get hit by a, a ransomware attack, and the CISO's gonna come to you and explain what happened. Now run through the decision-making process of how are we gonna maintain our-- do our business continuity. Let's go through that process and have you understand the panic you get, the-- what happens, what decisions you have to make, what do you bring up first, what's most critical, what's not most critical," all of those types of things, and do that actual tabletop exercise.
And I think it would be great if we brought that in and said, "Let's update that," and say, "What happens if you get hit by a nation-state attacker," right? And the-- and they are-- the, the, the tactic isn't ransomware, and the decision-making isn't do I pay, and how much do I pay, and, and if, you know, and if I pay, how much of my secrets are still getting exposed? It's, ah, my-- I'm starting from scratch on bare metal with absolutely nothing running.
How-- What's my decision-making process for doing that, right? When the CISO comes to me and says, "I'm sorry," you know, gives me a call on my cell phone and says, "I'm sorry. I've been...
You know, w-we're dead," right? " What's dec-- How do you announce that to your stockholders, right? What happens, right?
We've learned about this recent event from the news. I have no idea what they've said to the SEC or to the stockholders, to the board of directors, all right? That's-- This is, you know, massive panic attack for people, and, you know, it's all part and parcel of the cybersecurity story.
I mean, honestly, I've, I've only ever had to deal with the whole hit-by-a-bus thing a couple of times in my career. I'm very glad that I've only had to deal with it a couple of times, but you have to be prepared for it no matter what. And now we know that there are new reporting rules aga-- for security incidents where the SEC has to be notified within, I believe it's fifteen days now, of, of what's going on to prevent companies from basically holding that information as long as possible before releasing it because, you know, we, we wouldn't want the stock price to dip.
Uh, although, let's be fair, the stock price has probably already dipped on the rumors that something might have happened. Uh, but I will-- I'll close it out by saying this. One of the nice things about having events like RSAC is that we get to talk to the companies that are doing it, and we get to ask them those kinds of questions from the practitioner's perspective of how are you ad-- accommodating for these things?
What, what does it look like when you need to do this? Because we need to make sure that the voice of the people on this side of the keyboard is heard, and that's one of the reasons why Tech Field Day is so important is because we get people like Jack and many others who get to walk into a room with companies like Veeam and ObjectFirst and Commvault and ask those tough questions and say, "Okay, if something were to happen, walk me through how it would occur. " Jack, if people wanna check out some of the stuff that you're doing, where can they go to learn more?
com. You can also find me on LinkedIn and all of the typical socials as well as I write columns all the time for Security Boulevard. And as we mentioned, we are gonna be at RSAC this year, Tech Field Day Extra at RSAC.
com, you can click on the link for all of our, event, coverage from RSAC, including, live presentations on the 23rd and the 24th from Veeam, ObjectFirst, and Commvault. Uh, you'll also be able to check out recorded videos if you're listening to this after the fact, as well as any coverage from any of our wonderful group of delegates, including Jack Palmer and many more. We also wanna thank you for listening to this episode of the Tech Field Day podcast.
If you enjoyed this discussion, do us a favor and subscribe on YouTube or in your favorite podcast application. We don't want you to miss any episodes. We'd also love it if you'd leave us a rating and a review and, and maybe a nice comment or even a mean one.
I don't care. This podcast is brought to you by Tech Field Day, which is a home for IT experts from across the enterprise. Tech Field Day is a part of the Futurum Group.
com/podcast or check us out on Techstrong TV. Thank you very much for listening in. We'll see you all next week.