Navigating The Complexities Of Data Backups In A Hybrid World

With hybrid IT infrastructures and growing data volumes, data today is scattered across more locations than ever before, often moving between on-premises systems and the cloud. This shift has brought about complex and costly challenges for both the management and protection of an organisation’s data.

Not only is it exposed to growing cyber threats; employees, despite their best intentions, can also accidentally delete or alter it, adding to the risk.

Research from Forrester highlights the magnitude of the issue. Currently, over half of workloads in small and medium-sizes businesses (SMB) run in the public cloud. Despite this reliance on cloud services, nearly three-quarters of these businesses admit they lack the capability or capacity to train their employees on the growing complexities of cloud environments.

This skills gap leaves them vulnerable to a range of security threats. Ransomware is a significant concern: According to Statista, there were over 317 million ransomware attempts globally in 2023 alone. These attempts often target data backups, forcing organisations to pay ransoms or face severe consequences, such as data loss, reputational damage and financial losses.

The Importance Of Reliable Backups

Backups are essential in defending against ransomware and other attacks. Global compliance standards frequently mandate regular backups, and these requirements are becoming increasingly stringent. However, creating and maintaining effective backups is challenging, particularly for businesses relying on hybrid IT systems.

A robust data protection and disaster recovery strategy is crucial but can be difficult to maintain in a complex and fast changing environment. Businesses must safeguard their data wherever it resides, including physical servers, mobile devices, remote users, collaboration tools and the cloud. Backing up this multifaceted landscape often requires tools from numerous vendors, complicating the process and increasing costs.

The rapid implementation of new cloud services can exacerbate these issues. Often, performance is prioritised over security. Additionally, businesses may choose cheaper, less comprehensive backup solutions to cover each data environment. While this approach might seem cost-effective initially, it can lead to higher costs and complexity in the long run.

Many businesses mistakenly believe that cloud providers handle all backup needs, but this is usually not the case.

Cloud providers typically do not offer historical data storage or full data protection and recovery; instead, these responsibilities fall on the customer. Moreover, when cloud data is compromised, backups hosted in the same place as the original data will also be affected. Cloud customers must therefore implement additional data protection measures that meet their requirements in terms of recovery times and recovery points.

Effective Backup Strategies

To streamline backup processes and reduce the administrative burden, organisations should seek a single solution that allows for multiple backups across all data environments. The first step is to conduct a careful audit to understand where data resides and how it is currently backed up. Ideally, a comprehensive, one-stop backup platform should cover on-premises servers, end devices, SaaS solutions and the public cloud. This integrated approach makes backup processes more efficient and manageable, while providing better transparency across the entire organisation.

A solid backup and recovery strategy should address a range of possible scenarios, from file loss to system outages to ransomware attacks. This includes the ability to quickly set up a new production environment in case of a disaster to avoid costly downtime. Backups must be immutable, verified for integrity and tested for usability – and stored in separate locations to prevent infection with malware or ransomware.

Cost considerations are also crucial. Backup solutions which offer data protection no matter where the data lives can be more cost-effective and the spend more predictable. These solutions offer the flexibility to evolve with changing requirements as data moves from on-premises, to the cloud, SaaS and endpoints.

Ultimately, all businesses, regardless of size or industry, are at risk of ransomware and infected backups. Hackers do not discriminate, so organisations must assume they are at risk and prepare accordingly. With the constant threat of cyberattacks looming, a single backup strategy is no longer sufficient.

Only a flexible, multi-backup approach covering the entire IT environment can reliably protect businesses against the myriad risks they face.

Brent Torre is Product Executive, Backup & Disaster Recovery at Kaseya

Image: mesh cube

You Might Also Read:

What Is CloudSecOps?:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Breach Exposes Millions Of Mobile Numbers To Phishing Attacks
Webinar: Generative AI and Security »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

QA Systems

QA Systems

QA Systems provides software testing solutions for safety and business critical sectors and software safety and security standards.

NextLabs

NextLabs

NextLabs provides data-centric security software to protect business-critical data and applications.

Global Learning Systems (GLS)

Global Learning Systems (GLS)

Global Learning Systems provides security awareness and compliance training programs for employees that effectively promote behavior change and protect your organization.

CERT-UA

CERT-UA

CERT-UA is the national Computer Emergency Response Team for Ukraine.

2Secure

2Secure

2Secure is one of Sweden's largest private security companies. Service inlcude personal security, corporate security, information and cyber security.

Zanasi & Partners

Zanasi & Partners

Zanasi & Partners is a security research and advisory company active in the EU and MENA areas. Services focus on technology solutions.

Crosscheck Networks

Crosscheck Networks

Crosscheck products allow you to test your APIs across different protocols and message formats with functional automation, performance, and security testing capabilities.

Accel

Accel

Accel is a leading venture capital firm that invests in people and their companies from the earliest days through all phases of private company growth. Areas of focus include cybersecurity.

Beyond Identity

Beyond Identity

Beyond Identity employs an elegantly simple concept, the personal certificate authority and self signed certificates, to replace passwords.

Deepnet Security

Deepnet Security

Deepnet Security is a leading security software developer and hardware provider in Multi-Factor Authentication (MFA), Single Sign-On (SSO) and Identity & Access Management (IAM).

Scrut Automation

Scrut Automation

Scrut Automation's mission is to make compliance less painful and time consuming, so that businesses can focus on running their business.

NACVIEW

NACVIEW

NACVIEW is a Network Access Control solution. It allows to control endpoints and identities that try to access the network - wired and wireless, including VPN connections.

Europol - European Cybercrime Centre (EC3)

Europol - European Cybercrime Centre (EC3)

The European Cybercrime Centre (EC3) was set up by Europol to strengthen the law enforcement response to cybercrime in the EU.

Vector Choice Technologies

Vector Choice Technologies

Vector Choice Technology Solutions has a long standing reputation in cyber security consulting since 2008.

Q-Bird

Q-Bird

Q*Bird's mission is to provide equipment for the current, and future European quantum internet.

Cyber Security Unity (CSU)

Cyber Security Unity (CSU)

Cyber Security Unity (formerly the UK Cyber Security Association) is a new global community which has been set up to help unite the industry and combat the growing cyber threat.