Data Recovery Readiness in the Modern IT Environment – Techstrong Con 2023
As organizations modernize and move to the cloud with cutting edge IT solutions, attack surfaces continue to widen. How do you stay “recovery ready” if defenses fail? As attackers become smarter, staying one step ahead is paramount to ensure that new threats don’t take down backups that are often the last line of defense. Kaitlin Carrollo talks about best practices in data protection with our informative demo.
Transcript
Hi, my name is Caitlin carollo, and I'm a sales engineer at metallic with CommVault. Today we're going to be talking about recovery Readiness in the modern it environment and how security plays a role in your backup and Recovery efforts of your it environment. Now metallic and CommVault is a backup and Recovery Solution and organization that has focused on protecting our customers data for the last 26 years.
Now over that period of time we've seen a lot of change in the landscape of it environments and digital transformation has started accelerating very quickly, but has also been a phase change over many years. Now we see right the changes that have been in place during these different waves of Technology whether we think back to traditional database environments and physical servers how that transition through to things like virtual environments. Then changes like things like kubernetes and container orchestration along with the development of hybrid Cloud adoption and SAS applications.
Now over that period of time CommVault has helped our customers protect all kinds of workloads part of all of these different environments, but one thing that we're really seeing with our customers is that with digital transformation accelerating so is ransomware. So we're seeing that SAS application adoption is starting to outpace traditional applications along with that managing these older platforms or Legacy technology is a challenge when we have very very components within our environments. Because of these different components we're starting to see a lot of fragmentation and data silos within customer environments.
And with this complexity it leads to risk. So when we have you know, all these different components in a given environment as well as Cutting Edge Technologies older technologies, that may be fewer people know how to manage. We're also seeing that increase in Risk.
There's a larger attack surface. There's way more points of entry for attackers. And there's a lot more expertise required to manage these environments as the complexity increases.
Now we think about with this acceleration of digital transformation as we add these different components into our environments to make our lives easier be more cost-effective while still maintaining components of environments that are business critical. We have to think about not only how we're going to protect our environments. But also how we're going to be ready to respond.
If something were to happen within those environments. Now, this is where CommVault. Being industry leader in backup and Recovery.
We really take a industry standard approach to ransomware protection and ransomware Recovery. So the ransomware recovery framework that we follow is that of the nist cybersecurity framework. So the National Institute of Standards and technology has this framework in place to identify security risks as well as protect find them and then respond and recover when an attack occurs.
Now this framework is critical across. All components of your environment. So if you're looking at protecting production data, all of these Concepts do apply in terms of protecting those environments, but we also specifically apply this framework to our backups because we're also seeing that backup environments are becoming a big Target for ransomware attacks.
Because when you have your backups, of course, that's what you would go to if something were to happen to production. And so of course attackers are starting to see that and are even exploiting that and going directly to the backups first. So we'll talk through this framework and how it applies to our environments as a whole but especially to our data protection so that you can be armed with information to understand how to ensure that even with backups in place.
They are fully protected so that you're able to perform that recovery in the event of cyber event. The first element of this framework is the identify phase. This is where you're going to get a lay of the land and see what risks might be out there in terms of the environment that you're analyzing.
now in case of your backup environment You might want to get some insights into what could be a risk as well as what could be additional tools that you need to put in place in order to protect your environment. So in the case of our Solutions with metallic, which is a software as a service solution, we have What's called the security IQ dashboard and really what this is for is to provide you insights into what's actually happening within your environment. And what areas could be exposed to risk.
Now an example of this could be there might be examples of additional government governance layers that you can put into place such as two-step authorization approval workflows or in decreasing the amount of times. You can log into an environment before you're locked out. But the idea here is to really get a look at what all the possibilities are again, whether it's in your backup environment or in your production environment.
Now when we look at security IQ again, this is a dashboard to give you a high look at a high-level. Look at what is out there so that you can start getting an idea of where you might want to Target your efforts from a security perspective. So we'll see things like the latest audit events as well as that security posture score which has recommendations like I mentioned for two step authorization encryption.
Auditing and other components like that lockout duration that I've mentioned. In general you'll approach this phase with an open mind and try to think about all of the different ways that your environment could be at risk with the understanding that this information is what's going to arm you with the ability to start protecting that environment. That leads us to the next phase which would be the protect phase.
This is really where you need to ensure that your data and your systems are protected from attacks. Now in the case of a environment, this is ensuring that not only your data itself. Your backup sets are protected but also the service that's interacting with that storage.
So the service that runs the backup operations as well as the service that runs the restore operations that also needs to be protected. When we think about protecting backup data, usually we're thinking about immutable storage and air gap for those data copies so that they can't be modified or tampered with but similarly too. We need to also isolate our backup service so that in the event that our production environment is affected that backup service will still be separate isolated and able to perform recoveries without having been negatively impacted by something like ransomware.
This involves having multiple controls in place such as zero trust access multi-factor authentication to access that service as well as strong levels of encryption following things like fips 140-2 and having as 256 bit encryption increase. Then on the other side of it right with the storage so that would be for your service primarily, but we want to make sure that we apply the same controls to our storage itself. So it's good to have your backup environment that's running those operations decoupled from the storage itself, but we still need really strong security around that storage Target, of course because that's where your data is residing.
So in the event of an attack, that's where you're going to go to get that data back. And so it's really important to have that air gap in place for your backup storage. Now back in the older days of backup and Recovery Solution that a lot of customers used was tape backups.
And this is something that's still used in many environments today where you take a backup to a tape, you take the tape out of the drive and then you send that tape to some offsite location like an Iron Mountain. Or some other secured off-site destination. Now with customers that are moving to the cloud or more commonly adopting a hybrid Cloud strategy where you're going to have workloads on-prem workloads in the cloud.
We're seeing a move away from tape to more flexible cloud-based Solutions when it comes to that airgat storage. Now there's a couple ways that you can secure your cloud-based storage some of which being putting in protections like that zero trust concept and multi-factor authentication for those tenants. You can also turn on object blocks on that storage Target to prevent any changes to the underlying storage once data has been written.
Or in the case of a lot of our customers. We also saw a need for full separation between storage Target and customer environment. And that's where we introduced our metallic recovery Reserve storage service which provides that full air gap between production and Storage by ensuring that customers don't actually have any underlying access to the Azure tenant where the storage resides Now this is protection against both ransomware from external Bad actors, but also internal Bad actors people who might have access to the internal Network or to credentials to Azure tenants things like that having this off-site copy in the cloud while also completely decoupling the storage from the production environment is providing our customers with a really strong security solution for their backup data so that it's fully isolated but still in that off-site location and available for quick recovery.
The next stage here is going to be the detect stage. Now. This is where we're going to be looking for threats and identifying what those threats might be suspicious activities activities that are outside of the norm.
So this is where we're really looking for something that's going on before an event has actually occurred. this is where we want to look for things like unauthorized changes again anomalies, so Every environment will have some kind of Baseline where there's usual activity and then there's unusual activity and sometimes unusual activity is completely acceptable. It might be a one-time upgrade of a system or a data migration, but we really want to be checked checking for what those changes might be so that we can pinpoint them and then be prepared to respond to those events.
now in the case of a backup environment we can do that through anomaly detection as well as Honeypot files on the file systems that were protecting so we can monitor for things like files being created files being modified piles being deleted that's outside of the norm but these tools although extremely helpful to help detect something that is out of the ordinary and potentially a threat. They're also happening after the backup has been taken. So this would be happening in that stage where an attack maybe has already occurred or data has already been modified.
So it's really important to be able to track these changes and then identify them so that a response can be implemented. But we may also want to look at detecting threats before an event sexually occurred. Now this is where especially in the backup and Recovery space.
We're starting to see the need for cyber deception. Now cyber deception is again a little different from backups in that it's happening earlier in the life cycle of a ransomware attack. So when we think of backups, we think we have our production data, you know, of course, we're following the nist framework to protect that data.
In production by you know, having our firewalls in place having zero trust access and MFA on all of those important admin accounts, but then we're also going to have our backup environment so that if something does happen, we're able to recover from our secure backup copy. Now we're cyber Deception comes into play is that space in between of protecting your production environment and having to recover from your backups. So I talked about honey pots how we can put honey pots on the file systems and use the backup jobs to monitor for these changes.
But when we think of cyber deception, this is where we're going to create fake assets and actually put them in production as opposed to looking at them on the back end from the backups. Now these fake assets are lightweight. They're easily configurable and they look just like production assets.
However, they hold no production value in your environment. This could be something like an active directory user that looks like an administrator, but it's not it could be a virtual machine. Anything that has an IP address a router a switch within your on-prem network can be a good candidate for a cyber deception sensor and really these sensors are used to not only distract attackers so that when attackers come into the network and they start to sit and collect information, but also to give your teams a chance to identify where those attackers are sitting in the environment so that they can then make changes and lock down the environment and increase the protections that you haven't place.
So we think about modern ransomware attacks. A lot of attackers aren't just gaining access to a customer's Network and then immediately encrypting their data attackers will come in and they'll sit and they'll collect information. So you might have a wide range of devices and components within your network.
And an attacker isn't going to come in and just immediately do something they're gonna sit and move laterally through the network. The first place they land is probably not going to be that Crown Jewel that they're looking to attack or to gather information from but they might be in a place where it's not super valuable information, but it has a path to something that's more valuable. Now this is really where threat sensors come into play because we can use these fake sensors to distract as well as identify that someone is doing something that they shouldn't be because these sensors have no production value.
Attackers who are touching them. We know that they shouldn't be there because no one in our organization would be using this asset since it has no production value. So when an attacker engages with one of these sensors, it will send that data to an external tool.
So that could be the dashboard for the Cyber deception tool or it could be an external tool like a CM that you have in place to monitor log events across your whole environment. And this event notification will allow users to identify that threat before something has actually occurred in an effort to get further back in that life cycle of a security event so that we can identify that threat and lock things down before we even need to get to that stage of recovering from a backup. After we've done some of that detection, right?
So, of course we're looking for threats in advance of an attack through cyber-deception, but we may also be using those helpful insights from our backup environment to detect those threats as well. And once we detect that something has occurred if there has been an impact to the environment, that's where we want to respond Now respond might sound a lot like recover or restore and sometimes it's a step that gets skipped in the framework. But the important thing here is that response is about limiting the negative impact as well as determining what you're going to do with the information that you gathered in the detective phase.
When we look at something like an unusual file activity dashboard where we're looking at those anomaly alerts. We'll get information like what file system what folder was affected during that analysis that triggered the anomaly alert. This can help you determine, you know what systems are infected what systems need to be locked down because they either have been infected or they may be at risk of being infected.
This is really where you use these tools to not only just gather information, but determine what you're going to do with that information before you recover your data. The same is true. When you're using cyber deception, you'll get these alerts and depending on the nature of the alert or what activity has been performed.
You'll want to then make decisions about how you're going to respond to that event before you go into recovery. Again, having those intelligent alerts are really critical to determine how you're going to respond. And so the ability to integrate with those external tools are really going to help with that response process, whether it's through syslog webhooks direct integration with a cm and sore platform having those audit events alerts and logs pushed out there is going to assist in your ability to respond as well as automate processes as part of that response.
And then the last phase here is going to be the recover phase. Now. This is what we all think of when we think of backup and Recovery right backup end recovery.
We're going to pull our data back so that we can start operations after an event has occurred. Now when you're looking at recurring data, there's a couple things to consider one, of course that you're able to recover in the first place. So your backup environment is secured.
You have the tools you need to recover the specific data that you need that was maybe impacted by the security event. But also that you have flexibility in terms of where you're going to recover that data. For example, if you're backing up data that's on-prem and you have a copy locally so that you can do restores between your local copy and your production environment in the event of something like accidental deletion or things like that needing to revert back to an earlier version.
That's really really useful and even in the event of security event like a ransomware attack. You may still be able to leverage your local copy. Once you're on prep environment has been secured depending on how broad the attack was.
And what systems were affected. on the other hand, you may need to take more time to secure your on-prem environment, but it may not be enough time to continue operations of your organization. So you may need to for example recover data to a different location so that you can do both securing of your on-prem environment and continuing your business operations in tandem.
This is why it's really important to have a solution that is going to give you flexibility in terms of where your backup copies reside both on-prem and the cloud as well as where you can recover that data, too. So having a solution that is highly flexible. And even if your whole on-prem environment was no longer available.
You can still restore that data elsewhere is going to give you the full flexibility to respond to that ransomware attack in the way. That is most Is the best fit for that particular event? Similarly, you'll want to have granular recovery options.
So when you're looking to recover data, there might be certain components that are top priority. And so when you're looking at backup and Recovery tools, you want them to be built in such a way that you can have those flexible destinations. So say you have that off-site cloud copy.
You can recover that data to the cloud instead of having to recover it back on Prem. So for your VMware VMS instead of doing a VMware to VMware restore and having those VMS back on friend. Maybe you're on-prem environment is not ready for that property yet and you need to restore those VMS to Azure as Azure PMS.
With the tool that has flexible, but robust restore options, you'll have the ability to choose the granularity. So in this case here, we can see we can choose guest files virtual machine files or the full virtual machine restore including live recovery and live Mount options. We can also choose that flexible destination for that recovery.
So we'd be able to restore these VMware VMS out into Azure and the software itself will go through the process of converting that VM over to the cloud VM so that we can then start using it in the cloud while our security team is still responding to the on-prem event. Now that covers what the different components of the nist framework would be for cybersecurity identify protect detect respond and recover. There's a lot of different facets to this.
And again, we really focused on how this applies to your backup environment. But as we know all of these principles do apply across all components of our environments, so we'd be looking at applying this concept in production or our production systems and this very tightly relates to how we treat our backup environment. So really our backup Empire is often that recover phase of the nist framework if we were to apply this to our whole production environment.
But again, since we know that our backup environment can be a target for these attacks. We also want to make sure that each one of these components of the framework are applied to that environment. Now coming from CommVault and metallic.
We have Solutions in place with our customers that cover this whole framework and really give them peace of mind that they'll be able to recover their data when they need it. If we look at something like the metallic software as a service solution, we're offering a data protection as service solution where the services itself is hosted in Azure, but we're able to protect a wide range of workloads within our customers environments again in this digital transformation landscape where we have workloads on-prem in the cloud in software as a service applications as well as customers who have endpoint devices that are out in the field. We want to be able to protect all of those workloads while still providing a really secure solution.
So that in the event of a ransomware attack, the backup environment is safe and able to be restored. This includes things like metallic threatwise, which would be that cyber deception tool to help you identify those threats earlier in the life cycle through things like those fake assets that can be put within your production environment to help detect those potential attackers before an event has actually occurred. Again, when we're looking at protecting data within the modern data landscape, we need to make sure that we're covering all components of a customer environment while keeping things as simple as possible and easy to scale.
With the solution like metallic with CommVault we're able to protect all components of customers environment regardless of where they are in their hybrid Cloud Journey. This could be their SAS applications like Office 365 Dynamics 365 and Salesforce. It could also be traditional workloads on-prem like virtual machines physical databases physical servers or even Cloud workloads.
So infrastructure is a service in services like Azure AWS or Oracle. With a software as a service backup Solutions such as metallic, you'll really benefit from reduced infrastructure automatic updates and simple management while still getting that Enterprise grade security that follows the best practices as outlined by the nist organization. Thank you so much for attending and we hope to speak with you soon.
And we look forward to all of the other sessions that are scheduled for the conference.





