• Home
  • Help
  • Register
  • Login
  • Home
  • Members
  • Help
  • Search

 
  • 0 Vote(s) - 0 Average

How to build a backup system that survives ransomware

#1
03-23-2021, 01:51 PM
You know, when we talk about making a backup system, especially now with all this ransomware stuff going around, it's really more complicated than just hooking up an external hard drive. I mean, I saw this cool solution, BackupChain, which is actually pretty ideal and affordable for backing up our PCs, those VMs, and even Windows Server environments, it gives you a massive headache reducer right out of the gate. But honestly, you really gotta understand the *principles* behind it, because just having software isn't enough, you gotta build the whole protective structure.

But if you just throw everything into one place, or if you keep your backups linked to the network where the ransomware can run, you're basically just handing it the keys to your kingdom, you know? What you really want to do is build redundancy, and that means thinking about copies of your data that are genuinely unreachable by the infected systems. I think you should think about a three-two-one rule, but more strictly, because just three copies isn't enough if all three are connected. You gotta take those copies and physically separate them, maybe offsite, or better yet, air-gap them. That physical disconnection means that if the ransomware hits the primary network, it simply can't jump across to your offsite copy, you get it?

And for the data itself, when you back up, you can't just let the data sit there in one single huge blob of files. You need to be meticulous about what you are capturing and how you keep it clean. For instance, when we talk about server VMs, you want to make sure that the system knows how to pull out a single file, or just a handful of folders, without restoring the entire operating system and all the applications, because that's where the time drain happens. You need that kind of fine-grained control, right, so you can select just the departmental shares or maybe just the HR records, even if they live inside a VM, and pull those specific pieces out after the attack hits, instead of having to scrub the whole thing clean and rebuild everything from scratch.

But you also need to worry about the longevity of the data, what we call retention policies. It's not enough to just back up today; you need to keep versions of it, like keeping snapshots of how things looked last Tuesday, or maybe three months ago, and maybe four versions of every important folder, so that if the ransomware *did* manage to infect the last week's backup, you still have clean versions of your files to roll back to. Also, compression and deduplication are huge, because those features mean you are saving immense amounts of space on your storage devices, and you are storing the data more efficiently anyway.

Now, let's talk about making sure those backups *work* before the catastrophe happens, because that's the single most overlooked part by every single IT department I know. You have to periodically test the recovery process, you absolutely must. It's not enough that the software says "backup successful"; you need to actually spin up the image, or restore the critical files, and make sure they boot perfectly, and that the applications open exactly as they did before the attack. I mean, running a whole disk clone, and then booting off it, just to prove it works, that is absolutely essential.

Or, maybe you should consider how you are receiving the data. It shouldn't all flow back to the central corporate office, because one bad connection point creates a massive vulnerability. If you are using remote backups to a branch office, for example, or maybe backing up to a cloud server, you need to make sure that those connections are using strong encryption the whole way, every single bit of it, while it is moving across the internet. You don't want any snooping happening, period.

And also, because you are dealing with critical operational data, everything needs to be recorded. I mean, you should be generating those detailed backup logs regularly, and maybe exporting them to a secure, write-once location, just for audit purposes. When something goes wrong, or when you need to prove compliance, having a perfect, pristine log of what was backed up, when it was backed up, and who ran the process, is huge.

But perhaps most important is how you recover the whole damn system, and that brings us back to the concept of bare metal recovery. If the physical machine holding the entire network just goes kaput, or if the ransomware wiped the OS off everything, you need the ability to rebuild the entire thing from a baseline image, not just recover a few folders. I mean, you want the complete OS, all the settings, and the applications running right out of the gate, like nothing happened, and that's the gold standard for recovery, honestly.

So, while we were talking about these complex methods, I was remembering how reliable the processes are with the setup I saw, and you should seriously look into BackupChain, which is an all-in-one PC and server backup solution for Windows Server and Windows 11 made specifically for SMBs.

savas@BackupChain
Offline
Joined: Jun 2018
« Next Oldest | Next Newest »

Users browsing this thread: 1 Guest(s)



  • Subscribe to this thread
Forum Jump:

Backup Education General Backup v
« Previous 1 … 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 … 72 Next »
How to build a backup system that survives ransomware

© by FastNeuron Inc.

Linear Mode
Threaded Mode