Industry executives and experts share their predictions for 2023. Read them in this 15th annual VMblog.com series exclusive.
In 2023, Data Backup Must Prioritize Security and Immutability
By Adrian Moir, Technology Strategist & Principal Engineer, Quest Software
Cybersecurity attacks have become more prominent in recent years, and threat actors are smarter than ever before. As a result, backup and replication have become more security-focused in order to better protect an organization’s data and important information. Adding to this challenge, the distributed nature of the current workforce increases threats even more, as it becomes more challenging to keep track of who has access to data. This makes it increasingly difficult for organizations to monitor, track and protect their data, which puts everyday data and workflows at risk. So how can backup and replication further mature to better support business operations?
Why data security and immutability matter
The key is increasing the focus on data security and immutability. Cybersecurity must become a key component of business operations in order to keep valuable data within organizations safe. Without improving cybersecurity measures, enterprise data may fall to attackers that are seeking out easy ways to profit. Immutability ensures that data, and certain types of data, cannot be deleted or modified even in the event of a business disruption. This protects organizations in the event of a breach, as they’ll more easily be able to get back any information that was stolen.
Meanwhile, data immutability has the power to protect data in an organization’s time of need. In 2021, 44% of organizations impacted by ransomware did not have immutable backups and thus had weaker security operations. This is a huge vulnerability that attackers will go after, and organizations must adapt their systems to be better protected.
This becomes even more important to businesses, which increasingly need to keep up with the relentless growth of data created and consumed by their organizations. As that quantity increases, so does the size of the attack surface and the potential for operational damage and legal liability. Businesses, and their customers, not only want their data restored after it is compromised; they want the process to be effective and efficient, and to be assured that they can recover. The cost of implementing such systems may be high initially, but it’s cheaper to set something up proactively than to potentially damage or shut down business operations entirely.
To succeed, businesses must create proactive data backup and education plans
Business leaders need to create proactive playbooks for data backup, immutability, replicability and recovery. This includes not only everyday plans for backup but also plans for recovery in the case of a cyberattack, outage or another business disruptor. This includes everything from the tools IT teams will use, to the tactics engineers can use to pressure-test the system (from chaos engineering to cloud-based backup protocols), to how to maintain accurate reporting in order to understand the business’s exposure to threats.
This is not just a matter of dollars and cents; this effort must be supported by the CEO, CIO, CISO and senior management. Their endorsement will make it easier for the organization to be accountable for the successes, and failures, of its plans for resilience. They have the ability and opportunity to create a culture of data security from the top-down that can trickle to the rest of the organization.
These leaders also have a crucial role to play in helping employees understand the new proactive plan, the reason for its existence, and how to carry it out. Education is also a must-have for success. It’s not just about creating the solution; everyone within the business must know their role during an attack and have a roadmap of what to do next in a variety of different situations. Employees must also be prepared via testing the backup process, making sure it – and human-centric procedures – run as smoothly as possible.
On the horizon: immutability and data security must protect data in motion
Backup and replication are always evolving, and data security and immutability must evolve with it. Currently, immutability primarily protects data being stored, or data at rest. To improve protection, the concept of protecting data in motion needs to be more broadly tied to backup and not just data security. Encryption as part of the backup process is also popular with organizations as it makes it more difficult for bad actors to use the data, and its record-keeping makes it easier to restore. By doing this, companies don’t have to worry that the data is compromised while it’s going from one place to another.
Because data is the most valuable digital asset for any organization, it remains an overall goldmine for attackers. Backup and replication strategies will always be needed, but they need to adapt to the ever-changing threat landscape – both technologically, via immutability and an increased focus on data security, as well as culturally and strategically. It’s imperative in 2023 for leaders to invest in creating a proactive plan that works for their environment, and their employees, to protect business-critical operations across the data ecosystem.
##
ABOUT THE AUTHOR
Adrian Moir is a Technology Strategist and Principal Engineer at Quest Software. A data protection specialist with 30 years’ experience in IT, he specializes in delivering sustainable data protection solutions for enterprises of any size. He has worked for small and large companies, vendors and channel partners alike, using his background in electronic and electrical engineering, hardware platforms, networking, operating systems and virtual infrastructures. Adrian previously worked with Quest’s field-based pre-sales technical teams across EMEA.






