This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Practical Tips for Data Security and Data Protection Alignment

Download resources

About this session

Rick Vanover, who has spent thirteen years on Veeam's product team talking to security professionals, presents practical ways to align data protection and cybersecurity teams. Drawing on Veeam's own market research, he notes that most organizations say they need significant improvement in that alignment, and tells of a healthcare provider that nearly lost everything in a ransomware incident because the backup and security teams never talked. He argues security teams need visibility into restore activity (who accessed what data, from where, using which account) since a quiet 'redirected restore' is one of the easiest ways to exfiltrate data undetected. He relays six pieces of advice from Veeam's ransomware support team: keep an offline, air-gapped or immutable copy of data; carefully manage encryption passwords; avoid shared or domain-admin backup accounts; follow an updated 3-2-1 rule with a verified-recoverable copy; enable MFA at both the application and operating-system layers; and maintain a documented, tested recovery plan with a clear decision owner. A colleague closes in French on aligning backups with Law 25 obligations, and a short Q&A follows.

Key takeaways

  • Give the security team automated visibility into restore/recovery activity logs; no visibility into who touched backup data is an immediate red flag.
  • Keep at least one ultra-resilient backup copy that is offline, air-gapped or immutable, on top of an otherwise standard 3-2-1 backup strategy.
  • Manage backup encryption passwords as carefully as the backups themselves; losing the password after an incident can make an intact backup unusable.
  • Replace shared or domain-administrator backup accounts with individual, role-scoped accounts, and layer MFA at both the application and operating-system level for backup infrastructure.
  • Document and regularly test the recovery plan, including who is authorized to declare a disaster and initiate restores, before an incident forces the question.

Speakers

Rick Vanover
Rick Vanover
Senior Director of Product Strategy · Veeam

Resources

Tags

More from GoSec 2023

Also from Rick Vanover

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.