Navigating The Complexities Of Data Backups In A Hybrid World

With hybrid IT infrastructures and growing data volumes, data today is scattered across more locations than ever before, often moving between on-premises systems and the cloud. This shift has brought about complex and costly challenges for both the management and protection of an organisation’s data.

Not only is it exposed to growing cyber threats; employees, despite their best intentions, can also accidentally delete or alter it, adding to the risk.

Research from Forrester highlights the magnitude of the issue. Currently, over half of workloads in small and medium-sizes businesses (SMB) run in the public cloud. Despite this reliance on cloud services, nearly three-quarters of these businesses admit they lack the capability or capacity to train their employees on the growing complexities of cloud environments.

This skills gap leaves them vulnerable to a range of security threats. Ransomware is a significant concern: According to Statista, there were over 317 million ransomware attempts globally in 2023 alone. These attempts often target data backups, forcing organisations to pay ransoms or face severe consequences, such as data loss, reputational damage and financial losses.

The Importance Of Reliable Backups

Backups are essential in defending against ransomware and other attacks. Global compliance standards frequently mandate regular backups, and these requirements are becoming increasingly stringent. However, creating and maintaining effective backups is challenging, particularly for businesses relying on hybrid IT systems.

A robust data protection and disaster recovery strategy is crucial but can be difficult to maintain in a complex and fast changing environment. Businesses must safeguard their data wherever it resides, including physical servers, mobile devices, remote users, collaboration tools and the cloud. Backing up this multifaceted landscape often requires tools from numerous vendors, complicating the process and increasing costs.

The rapid implementation of new cloud services can exacerbate these issues. Often, performance is prioritised over security. Additionally, businesses may choose cheaper, less comprehensive backup solutions to cover each data environment. While this approach might seem cost-effective initially, it can lead to higher costs and complexity in the long run.

Many businesses mistakenly believe that cloud providers handle all backup needs, but this is usually not the case.

Cloud providers typically do not offer historical data storage or full data protection and recovery; instead, these responsibilities fall on the customer. Moreover, when cloud data is compromised, backups hosted in the same place as the original data will also be affected. Cloud customers must therefore implement additional data protection measures that meet their requirements in terms of recovery times and recovery points.

Effective Backup Strategies

To streamline backup processes and reduce the administrative burden, organisations should seek a single solution that allows for multiple backups across all data environments. The first step is to conduct a careful audit to understand where data resides and how it is currently backed up. Ideally, a comprehensive, one-stop backup platform should cover on-premises servers, end devices, SaaS solutions and the public cloud. This integrated approach makes backup processes more efficient and manageable, while providing better transparency across the entire organisation.

A solid backup and recovery strategy should address a range of possible scenarios, from file loss to system outages to ransomware attacks. This includes the ability to quickly set up a new production environment in case of a disaster to avoid costly downtime. Backups must be immutable, verified for integrity and tested for usability – and stored in separate locations to prevent infection with malware or ransomware.

Cost considerations are also crucial. Backup solutions which offer data protection no matter where the data lives can be more cost-effective and the spend more predictable. These solutions offer the flexibility to evolve with changing requirements as data moves from on-premises, to the cloud, SaaS and endpoints.

Ultimately, all businesses, regardless of size or industry, are at risk of ransomware and infected backups. Hackers do not discriminate, so organisations must assume they are at risk and prepare accordingly. With the constant threat of cyberattacks looming, a single backup strategy is no longer sufficient.

Only a flexible, multi-backup approach covering the entire IT environment can reliably protect businesses against the myriad risks they face.

Brent Torre is Product Executive, Backup & Disaster Recovery at Kaseya

Image: mesh cube

You Might Also Read:

What Is CloudSecOps?:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Breach Exposes Millions Of Mobile Numbers To Phishing Attacks
Webinar: Generative AI and Security »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Optimum Insurance

Optimum Insurance

Optimum's Cyber Risk & Data Protection Insurance policies are designed to protect against cyber exposures that arise when a company’s data and customer information is breached or stolen.

Security Audit Systems

Security Audit Systems

Security Audit Systems is a website security specialist providing website security audits and managed web security services.

Intertek Group

Intertek Group

Intertek Group provides Assurance, Testing, Inspection and Certification services. Activities include cybersecurity testing and certification.

Grimm Cyber

Grimm Cyber

GRIMM makes the world a more secure place by increasing the cyber resiliency of our client’s systems, networks, and products.

Tempered Networks

Tempered Networks

Tempered Networks delivers the first purpose-built platform for IIoT cybersecurity that allows customers to connect and secure devices in minutes without the need for specialized skills.

IronNet Cybersecurity

IronNet Cybersecurity

IronNet’s product and services provide enterprise-wide security management and visibility of your network, users and assets.

PreEmptive Solutions

PreEmptive Solutions

PreEmptive Protection hit the sweet spot between cost, convenience and functionality by helping you protect and secure your apps in a smarter way.

Bechtle

Bechtle

Bechtle is one of Europe’s leading IT service providers offering a blend of direct IT product sales and extensive systems integration services.

KSOC Labs

KSOC Labs

KSOC is an event-driven SaaS platform built to automatically remediate Kubernetes security risks.

NorthRow

NorthRow

NorthRow provides digital transformation compliance solutions to help businesses manage regulatory and financial crime risks.

LastPass

LastPass

LastPass provides award-winning password and identity management solutions that are convenient, effortless, and easy to manage.

Boecore

Boecore

Boecore is an aerospace and defense engineering company that specializes in software solutions, systems engineering, cybersecurity, enterprise networks, and mission operations.

Agile Defense

Agile Defense

Agile Defense is an Information Technology services provider, delivering leading-edge Digital Transformation solutions to the Federal Government.

LegalByte

LegalByte

LegalByte is a leading provider of comprehensive legal and forensic services dedicated to addressing the complex challenges of the digital age.

Runecast Solutions

Runecast Solutions

Runecast Solutions is a global leader in AI-powered risk mitigation, security, continuous compliance and more efficient IT operations management.

Baidam Solutions

Baidam Solutions

Baidam Solutions is a 100% Australian owned and operated First Nations information technology business.