The Role of Backup in Corporate Security

No single security measure works for every problem or at all times. To solve this never-ending issue, data center administrators rely on the "deep defense" paradigm. Deep defense uses a layered security approach where multiple elements collectively bear the burden of protecting your systems and data. Backup plays a vital role in this model.

15 Dec 2023 SintelSedat Akfidan 5 min read
The Role of Backup in Corporate Security

The Role of Backup in Organizational Security

A single security measure will not solve this endless problem for every situation or always. Data center managers rely on the "deep defense" paradigm to solve this problem. Deep defense uses a layered security approach where multiple elements collectively bear the burden of protecting your systems and data. Backup plays a vital role in this model.

This article discusses how to effectively use it.

Last Line of Defense

Let's conduct a thought experiment: ransomware has scrambled all your data or a virus has spread throughout your systems. What applicable options do you have? Sometimes, ransomware authors provide a decryption key after receiving payment. Most of the time they don't; they take the money and leave the organization with nothing.

No matter what the virus writers' motivations are, there is usually no way to reverse the damage. Even if you get a decryption key or find a tool that cleans the virus, can you be completely sure that you've removed all traces from your systems?

When we talk about "deep defense," backup represents the last layer. First, accept the proposition that no system is unhackable. You and your security teams and vendors can take every possible precaution, yet you may still be a victim. You may have the best tools available, but someone will find a way around them.

The backup industry and its evangelists initially pushed for offsite and offline backups to protect against natural and physical disasters. Malicious software added another strong reason. Taking data offline makes it inaccessible for an active attack. Removing data from the workplace adds barriers against malicious actors like rogue employees.

The uncontrolled spread of ransomware led to innovation in backup storage technology: immutability. Thanks to this feature, data is not subject to change for the intended period. This allows you to maintain an active connection without making your backed-up data vulnerable to malicious software. However, consider this a convenience feature. The saying "no system is unhackable" still holds true.

The Role of Backup in Organizational Security

Defensive Backup Strategies

Including backup in your security response doesn't require major changes. Any security incident that leaves your environment unusable or uncertain requires a clean wipe and reload. Essentially, you treat it like a natural disaster that destroys all your equipment. However, since you haven't purchased spare hardware, you'll need to take an extra step to completely wipe your systems.

Make sure you understand what "wiping" means. Formatting a hard drive doesn't erase it. Contrary to the long-held belief, even a "full" format performs the same logical steps as a quick format and then verifies that it can manipulate every sector. Use built-in tools or software utilities that effectively zero out storage.

Another persistent myth claims you need multiple passes to truly zero out magnetic storage. No one has shown this to be true, and even if it were possible, it would require analog equipment. Your goal is to ensure that any remaining malicious software traces cannot re-infect the system. A single wipe pass will accomplish this.

Most modern hypervisors write zeros to the thick provisioned area when you create a virtual hard disk. They also typically zero out the thin provisioned area, adding extra value. However, this only protects the virtual machine.

The management operating system may continue to read hidden data independent of the hypervisor. Therefore, you could choose to skip the manual wiping process for storage that only holds virtual hard disks, but this carries some risks.

Wiping every fixed drive in your organization involves significant time and effort. However, modern malicious software, especially ransomware, can be highly prevalent. Missing even a single example could waste all that effort. Clarify all of this in your recovery planning.

Your organization can consider alternatives such as replacing every drive and replacing them all with new ones. This would still be a heavy workload, but it would save time and eliminate some of the effort. Take an additional step forward by consulting your insurance company.

You can view a malicious software attack as a complete loss and allow you to replace all your equipment. Do not assume you have coverage for this. Even if your operator offers it, it may require an additional purchase beyond your current policy.

The only place the attackers can continue is your drives. In recent years, different types of UEFI/firmware malicious software have been found, although they are not yet routinely used by ransomware attackers, experiments are being conducted with them.

If you discover that the attackers have hidden there, the only way to be sure is to replace the hardware. If there is persistent malicious software in your UEFI, wiping your drive will not stop the attacker's access.

After learning about clean systems, you can expose your backup environment. Before doing anything else, create a copy of your last known good backup on an isolated system. Since you've already done a lot of work, making multiple copies won't add much. These copies act as additional insurance. You'll need to bring the original back online to restore, which could expose it to missed malicious software.

Unless you've encountered such a situation, your disaster recovery procedure will follow this point through to the last restore.

For some organizations, size or time constraints will make such a clean procedure impossible. In such cases, you'll need to bring in identity-authenticated security professionals before any design issues arise. Use these to define measurements you can use to assess whether your system is "clean enough" to move into recovery mode and protect against threats.

Carefully consider the risks of partial wiping before deciding that the time or effort saved is worth it. Imagine having to perform a full wipe after a failed partial wipe, which can be daunting.

*To properly protect your virtualization environment and all the data, use Hornetsecurity VM Backup to securely back up and replicate your virtual machine.

*For complete guidance, get our comprehensive Backup Bible, which serves as your indispensable resource containing invaluable information on backup and disaster recovery.

To keep up to date with the latest articles and practices, pay a visit to our Hornetsecurity blog now.*

Wrap-Up

Backup not only provides a foundation for your security response, but it also depends on your security applications. The recommended current techniques for capturing, transporting, and storing backup data have already covered a long way in protecting these data from security breaches.

Source: The Role of Backup in Organizational Security - Hornetsecurity