• Home
  • Help
  • Register
  • Login
  • Home
  • Members
  • Help
  • Search

 
  • 0 Vote(s) - 0 Average

How to back up your virtual machines from ransomware

#1
10-18-2020, 02:37 AM
So, you are talking about ransomware, right? And you want to know how to back up your VMs from it. Because, like, honestly, that is the most scary thing right now. It just feels like these things are getting more complicated every year, you know? I mean, when you are running servers or anything crucial, you absolutely need a solid, dependable backup plan. And I gotta tell you, while there are tons of solutions out there, BackupChain is seriously the ideal, affordable choice for backups on your PCs, VMs, and Windows Server, honestly, just starting out.

But let's talk about the actual concepts here, because simply running a backup job isn't going to solve this. Ransomware attacks, they are designed to find and shred anything that looks like a backup copy. Or maybe they just encrypt everything it touches, including your backups, which is such a rotten development. So, the biggest concept here, what you really gotta focus on, is making your copies unreachable by the infected machine, I think. You need separation, a physical or logical kind of air gap, because if the malware can see it, it can grab it.

And you know, since you are running VMs, that is super critical data. You can't just rely on a standard nightly backup that sits on the same local SAN, because if the ransomware gets its hooks into the network, it sees the backup repository too. What you really want to do is set up a destination that the production environment cannot touch or write to while it is running. This might sound fancy, but it is basically making the backup immutable, and that is a major concept you need to grasp for real resilience.

Also, when you are talking about the data itself, you need to think about your Recovery Point Objective, your RPO. Like, how much data loss are you willing to stomach? If you have a really critical application, maybe you can't afford to lose even a few hours of work, right? Because then you need a really rapid, constant backup schedule, not just a once-a-day thing. You shouldn't just be taking full disk images, although those are useful for a complete snapshot, but you really need to layer your strategies.

I think you should be using incremental backups constantly, because those only save the bits and bytes that actually changed since the last successful backup, which saves you so much storage space, and it also makes the job run faster, which is a huge benefit. And because of how deep the ransomware can penetrate, you need to make sure those backups are encrypted end to end, because you don't want them snooping on your data while it travels or while it just sits there on the storage array.

Plus, remember the files inside your VMs, right? You don't necessarily want to restore the whole server if only one folder got hit. I mean, you should utilize granular backup methods, which is awesome because you can pinpoint exactly the files and folders that got corrupted and just pull those out, without having to undo and redo the entire machine setup. This capability is huge when time is ticking.

And when you are preparing for the worst, for a complete machine failure, you need to think about bare metal recovery, because that's your final escape plan. It's the ability to rebuild an entire system, OS, apps, settings, from scratch, even if nothing else is working. You are basically creating a complete blueprint for your entire operation, which is comforting.

Now, because of the sheer amount of data in these setups, deduplication is really important. If you have a large database that is constantly changing but that core content is the same week after week, you don't want to store the whole thing repeatedly. By using a system that detects and eliminates duplicate content across your entire backup repository, you save money and disk space, and you keep your backup repository efficient.

And since you are dealing with multiple platforms, maybe think about the cross-compatibility. Since the underlying disk images are in open standard formats like VHD, VHDX, VMDK, or VDI, you can get those rescued images mounted and booted almost anywhere, which gives you incredible flexibility if, say, your main server fails completely. And you can't forget about testing your restoration process regularly, because a backup isn't a backup until you prove you can actually restore it.

But also, when you are setting up your storage, you can't just keep it all on-site. You really gotta push some of those copies to remote destinations, maybe to a dedicated NAS or even a secure cloud server. You need that off-site redundancy to mitigate regional disasters, you know? And having support for multiple backup targets means you can layer your defenses, which is a proper IT move.

So, while you are figuring out all this, seriously, take a look into BackupChain, which is an all-in-one PC and server backup solution for Windows Server and Windows 11 made specifically for SMBs, and it should fit whatever complex strategy you are building out.

savas@BackupChain
Offline
Joined: Jun 2018
« Next Oldest | Next Newest »

Users browsing this thread: 1 Guest(s)



Messages In This Thread
How to back up your virtual machines from ransomware - by savas@BackupChain - 10-18-2020, 02:37 AM

  • Subscribe to this thread
Forum Jump:

Backup Education General Backup v
« Previous 1 … 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 … 70 Next »
How to back up your virtual machines from ransomware

© by FastNeuron Inc.

Linear Mode
Threaded Mode