Commvault’s long time partnership with Microsoft has once again given us the opportunity to offer our customers cutting edge features and functionality. We are excited to have had the opportunity to develop this feature in lockstep with Microsoft allowing us to release our enhanced capabilities on Commvault Complete and Metallic® DMaaS simultaneously when Azure Restore Points became publicly available on July 19th 2022.
Commvault Protection for Azure Virtual Machines
Figure 1
Commvault has always offered options for protecting Azure Virtual Machines (VM) by using snapshots or even installing software on the VM to provide Application Awareness. Each disk resource is individually snapped and protected. The process is serial by nature as each resource request needed to be made in series.
In Figure 1, a backup request would need to protect the OS disk, then Data 1 disk and then Data 2. All 3 create the virtual machine and would be protected together, but their snaps may not complete at exactly the same time and additional coordination with the application layer may be needed to ensure consistency at an application level.
New Restore Point Functionality
Figure 2
With Restore Points, Commvault will now have the ability to create collections of restore points across all volumes on a VM. When doing so, the restore process is simplified, and the collection points are stored on cost efficient storage. This is a major architectural change in data protection for Microsoft that Commvault Complete and Metallic enable with a click.
In the example in Figure 2, once a Restore Point Collection is created, the same VM would be protected as a single API call to create a Restore Point. Every Restore Point is incremental and should complete in seconds. All disks within the VM are consistent with the restore point automatically. Every Restore Point will contain a Disk Restore Point for all managed disks. The Disk Restore Point consists of a snapshot of that disk. This reduces the restore process in this example from 3 steps to 1.
How is it simplified?
Leveraging the Commvault platform to orchestrate VM protection and more importantly, the recovery of VMs at enterprise scale is a critical need. Getting away from point solutions and homebrew scripting naturally promotes growth and reduces downtime. Being able to recover dozens or hundreds of instances with a few clicks keeps end user time from being sacrificed.
Improve resiliency while reducing tech waste
Commvault supports creating snapshots in cost audited resource groups already and automatically tags resources as they are created so that cost reporting is accurate. Adding VM Restore Points to our portfolio now allows us to create the restore points in cost efficient and less redundant storage tiers. It might be a minor cost difference, but at cloud scale, the billing is in the details and every improvement brings value to the solution. There’s no tradeoff in taking advantage of Restore Points. It simplifies and reduces cost while improving resiliency. Azure Restore Points ensures that the applications and the operating system are consistent when creating these collections at the native instance level.
A quick recap
Better cost efficiency, better performance, better resiliency, and a simplified design. A resounding win! We are excited to have had the opportunity to develop this feature in lockstep with Microsoft and prove yet again our commitment to making the latest enhancements in Azure readily available within the Commvault Intelligent Data Services portfolio of solutions.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Until very recently, many enterprises were limited by on-prem infrastructure, requiring huge data centers that had to be maintained, cooled, and secured. On top of that, the enterprise-owned server utilization rate is a measly 18%, with the majority of data centers operating at energy efficiency levels below 80%. This underutilization made on-prem ripe for disruption when the cloud came about. The cloud’s on-demand scalability provided companies the ability to optimize utilization rates without the hassle of managing, powering or cooling infrastructure. Considering the benefits, it’s not surprising that the average enterprise on-prem to cloud migration led to a 65% energy reduction and 84% carbon reduction (Accenture, The Green Behind the Cloud). Moreover, AWS is set to power all operations with 100% renewable energy by 2025, with a commitment to achieve net-zero carbon emissions by 2040. They use reclaimed or recycled water for cooling and have embodied carbon in the construction of newer data centers across the globe. And as an AWS recommended partner, Clumio is pushing the boundaries of environmentally sustainable computing with its on-demand hyper-scalable architecture.
Cloud-Native Solutions are Key to Maximize Sustainability
whether you need help protecticting your data against ransomware, meeting compliance requirements, or recovering from data loss; data backups can take up a significant amount of storage space, and increase your infrastructure footprint if done on-prem. Companies must choose carefully if they are conscious of reducing their carbon footprint from their data. Some best practices include going with a cloud-native / SaaS data protection vendor if possible, implementing incremental backups vs full system snapshots, categorizing and auto-archiving data based on criticality and usage, and most importantly, investing in a platform that is architected to scale on demand. If these concerns sound like yours, Clumio can help.
How Clumio Can Help
Clumio is a cloud-native backup solution, architected with a container-based stateless data processing pipeline that leverages efficient Lambda functions. This allows adaptability and efficient scaling to optimize usage based on your exact policies. Having this scalable compute and increased utilization rates can ultimately lead to significant carbon reduction from your data estate, in addition to significantly lower TCO (save your wallet while saving the planet).
See for yourself how the industry’s first cloud-native backup and rapid recovery solution can optimize your business’s sustainability metrics. Schedule a demo and learn how your business can be up and running with Clumio in as few as 10 minutes — no need to wait for and install new infrastructure and software.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
In this blog, you’ll learn how Commvault Grid makes implementing an immutable architecture easy as an integrated appliance or reference design for an all-in-one solution. With cyber-attacks increasing it delivers comprehensive data management across workloads to protect your data through 5 security layers. Commvault offers a hybrid of controls that work together to harden data against ransomware, cyber threats, and bad actors.
What is an Immutable Architecture and how do organization benefit?
Immutability is defined as the ability of any data to be maintained in a non-fungible state for a specific duration of time. Data immutability can be attained via various methods working in conjunction with each other. An immutable architecture is a model in which no updates, security patches, or configuration changes happen “in-place” on production systems. If any change is needed, a new version of the architecture is built and deployed into production.
Organizations need an immutable architecture to ensure their data is safe and secure and more importantly, ready whenever they need to restore it. Immutability is a proven technique used to reduce cyber-attacks on backup data and ensure that backup copies aren’t changed in any way.
Commvault Grid for Greater Immutability
Commvault Grid makes it easier to implement an immutable architecture as an integrated appliance or reference design for an all-in-one solution. It delivers comprehensive data management for all workloads from a single, extensible platform. Commvault employs a multi-layered approach to protect against various threat vectors and ensure data is safe. Commvault’s immutable architecture consists of 5 layers which are:
Storage I/O Controls
Zero Trust AAA Controls
Infrastructure Hardening
Zero trust isolation and air gap
Data Validation
Commvault Grid leverages the entire Commvault software portfolio providing access to all the features, functions, and industry-leading integrations with applications, databases, public cloud environments, hypervisors, operating systems, containers and NextGen workloads. Wherever your data resides, you have the ability to view it, use it, and confidently protect it. Commvault Grid accelerates hybrid cloud adoption with an integrated solution built on a deeply layered system of controls that work together to harden data against ransomware, cyber threats, and bad actors.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Examples of hidden and fluctuating cloud backup costs
Egress Fees
The majority of cloud providers will allow their users to place data into the cloud without any fees. However, this does not apply when their data is retrieved from the cloud. Cloud providers typically charge what’s known as egress fees any time data is retrieved.
If your enterprise is constantly pulling its data out of the cloud—such as migrating or recovering data— you can see how the fees can add up quickly and lead to inflated costs that are nearly impossible to predict. Egress fees are considered a hidden fee since they fluctuate based on usage and are tied to a common action (data retrieval).
Licenses
There may be a variety of licenses that are required, each with their own fee. These can snowball when cloud backup vendors require licenses for each of the data sources you back up or multiple licenses per user—something you may not realize until the bill comes.
Snapshots and Storage Costs
It is common for enterprises to create long-term storage for their production data if they need to recover it after an attack—such as ransomware. This could involve creating massive amounts of snapshots for each account in high-tier storage. Furthermore, each time a block or file is changed, a new snapshot is automatically created. These snapshots are replicated across accounts, effectively doubling backup storage costs that continue to pile up over time. Costs are further compounded when considering industry retention requirements that go beyond 35 days.
Adding to all the complexity is the fact that it’s difficult to gauge just how many of the backup snapshots in your AWS accounts are even needed. Sure, your bill can display how much you are spending in a particular region, but it doesn’t show the level of granularity regarding the age of the snapshots or assets they are associated with.
Achieve Predictable Costs and Lower TCO with the Industry’s Leading Cloud-Native Backup Solution
You can avoid excessive cloud spending and gain control over backup costs by choosing a cloud backup solution with a simple, straightforward pricing model that clearly spells out the ongoing charges.
Built natively in AWS, Clumio’s backup solution offers the scalability, performance, data protection, and faster access to innovation made possible by the cloud while avoiding the hidden costs, complexity, and limited flexibility of snapshot-based backup solutions.
Simplified Pricing
Clumio’s Pay-As-You-Go consumption model with rollover credits provides enterprises with a simplified and clear backup-as-a-service solution that ensures cost predictability while lowering TCO:
Transparency – No hidden costs, no license fees, and no egress charges—plus full visibility into data consumption.
No Friction – Choose from on-demand or commitment contracts with no setup required.
100% SaaS – No complex cloud infrastructure or software to install or manage.
An integrated cost analyzer tool that provides insights to help reduce unnecessary cloud spend
Reduced Storage Spending
Rather than retain Amazon EBS snapshots, Clumio further reduces spending by storing data in a compressed, de-duplicated format in Amazon S3, effectively cutting the cost of long-term EBS data retention. This allows enterprises to meet compliance and develop retention strategies based on business and regulatory requirements instead of costs.
Get Started with Clumio
Clumio offers more than just cost savings. In under 15 minutes, your enterprise can:
Instantly backup AWS data across your entire organization with Clumio
Gain data protection from ransomware attacks and other malicious threats via air-gapped storage with Clumio
Meet varying and complex data compliance objectives with global policies with Clumio
Lower RTO (Recovery Time Objective) and ensure business continuity in the event of downtime with Clumio
Experience firsthand why Clumio is the industry’s leading innovator for AWS cloud backup. Start your free trial, all without any pre-planning or the need to install new infrastructure or software.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
We are immensely proud of this achievement. Why not? We have been in this quadrant longer than some of our competitors have even been in business.
As an innovation-driven company, we have always prided ourselves on building elegant solutions to your hard problems, which let’s face it, have only gotten harder over the last few years.
Living between legacy and hybrid cloud applications and systems, today’s CIOs and IT professionals grapple with more applications and workloads than ever. All while bolstering their security posture to protect their data from ransomware and advance transformational business projects with the resources they have at hand.
Now is not the time to take chances on unproven technologies in today’s increasingly uncertain macroenvironment. It is the time to invest for the future, so you and your organization come out stronger on the other side.
I’ve had a lot of these conversations with customers lately, many of whom are weighing these concerns with the need for a trusted, intelligent, and reliable cloud data management vendor. One that not only provides proven technology, but the flexibility and scalability needed to continue to evolve to meet tomorrow’s needs. And one with the demonstrated its ability to execute on a vision over and over.
In its latest report, Gartner highlighted a few of Commvault’s strengths in this area:
First, we provide comprehensive workload support on premises and in the cloud. This enables you to add new backup and recovery capabilities for your business regardless of the applications creating and using your mission critical data. And you can manage your data through a single pane of glass.
Next, based on your unique business needs, you may want to leverage backup software, an appliance, or software as a service. Commvault enables you to choose any or all these approaches – to balance your capital and operating expenses based on your business needs, staffing concerns, or even in response to supply chain delays.
Last, our solutions and our extensive partner ecosystem span multiple geographies extending the reach and capabilities for global enterprises. We will protect your data wherever it is or has to be.
Thank you, Gartner, for the rigorous analysis and for sharing your findings. And more importantly, thank you to all our customers and partners globally who continue to entrust Commvault to protect and manage their critical data. We owe this honor to you.
Download a copy of the 2022 Gartner® Magic Quadrant™ for Enterprise Backup and Recovery Solutions
Ron Miller recently wrote an article on TechCrunch titled “It Really Does Take a Village to Keep you Secure in the Cloud” that struck a chord with me. In his article, Ron discussed the cloud shared responsibility model and the importance of us all taking steps to ensure the security and persistence of our data. I appreciate his view of the cloud computing community as a village and the opportunity to consider everyone’s part in it. How can we help each other? How can we make this village better?
Thinking about the cloud computing community as a village; an interdependent network of individuals within a given space. Individual members have their own specializations but many have overlapping needs for which it may not be feasible to be self-sufficient. You might have a farmer, a blacksmith and a shoemaker. The farmer doesn’t make his own tools and shoes, because it would cause him to neglect the farm. Instead he gets them from the blacksmith and the shoemaker. As members of the cloud computing village, we also want to focus on our specializations, making them the best they can be, and relying on other members of the village for the other things we need.
Ron paraphrases AWS Chief Security Officer Steve Schmidt saying “AWS is a target. It has to deal with millions of events every month, most of which we (cloud consumers) never hear about.” With AWS’s security team monitoring their services and Security Guardians embedded in each service development team, it’s safe to say that AWS is doing their part. But as Steve Schmidt states, AWS data is targeted by bad actors. So what about the rest of us in the shared responsibility model? What is our responsibility and what do we need from each other? As Ron states, “Security is such a complex undertaking that no one entity can be responsible for keeping a system safe, especially when user error at any level can leave a system vulnerable to clever hackers. There have to be communication channels across every level of the organization, with customers and with concerned third parties.”
Preventative security measures are an important part of everyone’s responsibility, and there are other village members who can help with that part of your security stance. But experts agree that when it comes to data breaches, ransomware and insider threats, it’s not a matter of if, but when. This makes it imperative to back up your data outside your account and control access domain. Clumio provides an important part of keeping the village safe by offering its members turnkey, air gapped, immutable data protection. We use the power of the cloud to power incredible scale and speed within a secure, simple, intuitive backup and recovery solution that frees up your time for creating your own innovations. We know how important security is, so we’ve built in security features like SSO, MFA, end-to-end encryption with BYOK, access controls and more.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Here at Commvault, we’re continuing to live our values and celebrate why it’s OUR TIME as we connect, inspire, care, and deliver… together!
Last week, we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work!
I’m so proud to announce the inspiring Vaulters who just won our FY’23 Q1 CEO Living Our Values Awards:
Analyst Submissions Team
Microsoft & Oracle Teams
CEO Living Our Values Awards
If you are interested in joining our team and becoming a Vaulter, visit our Careers site for more information.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
In a microservices-based architecture for an enterprise-level system like Clumio, it is impractical to have a public endpoint per microservice. One of the major problems is the tight coupling this introduces between the client and the server. In addition, each microservice needs to implement and maintain the common pieces like logging, tracing, security (authentication, authorization, rate-limiting).
An API Gateway dwells between a client and a server to proxy requests and responses between the two.
Having an API Gateway provides a unified entry-point for all the external clients and a framework that takes care of all the common pieces mentioned above. This also enables each microservice to implement its own communication protocol that best fits its requirements, independent of the Gateway.
AWS API Gateway
In addition to the above goodness provided by API Gateways, we also had additional requirements that went into choosing one:
Having a mechanism to integrate with the API Gateway in a manner that has no/minimal friction for introducing new APIs and maintaining existing APIs, so as to enable developers to focus primarily on their business logic
Given an API Gateway could potentially be a single point of failure, it should be a fully managed offering that is resilient and highly scalable
Support for Websockets
AWS API Gateway ticks all these requirements and offers good integration with other AWS services for building on top of it.
Leveraging AWS API Gateway
Swagger specification
Swagger provides a powerful representation for RESTful APIs.
We have employed the go-swagger tool which is capable of generating a Swagger specification from annotated Go code.
As a result, developers only need to annotate their REST API as per the above specification and let our framework (mentioned later) take care of integrating the same with AWS API Gateway.
Integrating with AWS API Gateway
At Clumio, all our AWS infrastructure is managed as code via Terraform. AWS API Gateway can be configured using the Terraform resources that it offers.
We use the aws_api_gateway_rest_api resource that allows us to feed the entire Swagger specification into the AWS API Gateway. The AWS API Gateway, however, cannot process a raw Swagger specification. It expects various extensions (like x-amazon-apigateway-integration) to be part of the Swagger specification so that it could configure an API seamlessly. This is where we have implemented a framework that injects the required extensions into a raw Swagger specification to make it work with the AWS API Gateway!
VPC Link Integration type
AWS API Gateway offers various integrations with your backend servers for proxying the incoming API requests.
As all our microservices are bound to a VPC for tighter security, we use the VPC Link integration. This enables the AWS API Gateway to access private API endpoints within the VPC securely.
Custom Domain Names and API Mappings
By default, AWS API Gateway generates a unique domain name for the API, something like aabbccdd12.execute-api.us-west-2.amazonaws.com. For an enterprise company, we would obviously like to customize the public domain name of the APIs for our consumers. AWS API Gateway allows us to do so via Custom Domain Names.
In addition, we also create separate APIs in API Gateway corresponding to some of our most dense API base paths. All these APIs are then glued together via API Mappings as below. This allows us to scale out our APIs and yet have a single public-facing domain name for them.
Lambda Authorizer, Usage Plans and API Keys
As mentioned earlier, one of the primary use-cases for an API Gateway is to enforce authentication and authorization right at the beginning of the API request lifecycle, so that only the relevant traffic hits the backend servers.
We have implemented a Token-based Lambda Authorizer which expects the following input: The authorizationToken (in the form of a JWT) can be used to implement the required authentication/authorization logic within the Lambda Authorizer to return the output as below:
The authentication/authorization decision is governed by the value of Effect (Allow|Deny) and the throttling decision is governed by the API key identifier in usageIdentifierKey. The API Key has to be associated with a Usage Plan which dictates the request quote to enforce (in terms of requests per second). We issue an API key for each client and hence are able to enforce throttling per client.
Another interesting thing in the output is context which can have any key-value pairs as required by the application. We use this heavily to capture the client information which we then pass throughout the API request lifecycle. This eliminates the need to lookup client details, while the request navigates through multiple microservices at the backend.
Conclusion
We hope you gained insight into how we leverage AWS API Gateway at Clumio and also a sneak-peek into the broader Engineering efforts that we carry out. We give utmost attention to security, scalability and most importantly adopting developer-friendly processes. This makes it easier to maintain products as we mature and scale, while being extensible enough to cater to new functionalities.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Welcome to the live stream celebrations as Commvault’s CEO, Sanjay Mirchandani rings the closing bell at NASDAQ’s headquarters in New York City.
The stream is due to start at 4pm ET on July 28th and a replay will be available shortly after. Post and follow the reaction by following #Commvault on social media.
That sense of accomplishment accompanies an added sense of relief, regardless of how long it took to achieve. But…what does this have to do with Bring Your Own Key (BYOK)? Read on.
Along similar lines, Clumio’s Backup as a Service Cloud promised to support the BYOK feature more than 2 years ago! This feature allowed customers to encrypt their backup data using their own encryption key using the Amazon Web Service (AWS) native Key Management Service (KMS) feature.
AWS KMS makes it easy for customers to create and manage cryptographic keys and control their use across a wide range of AWS services and in their applications.
When Clumio added the BYOK feature, it supported VMWare, Microsoft 365 (M365) and AWS EC2/EBS data sources as these were the data sources Clumio supported at that time. However, between then and now, Clumio added additional critical data sources like S3, RDS and DynamoDB.
Now with the most recent release, Clumio has brought BYOK capabilities to all of our critical data sources, and in doing so has achieved the resolution we started long ago. And it doesn’t stop here, as we will continue to invest efforts to bring BYOK to future data sources also.
Why do customers care about BYOK:
Doesn’t Clumio encrypt all backups already, and if yes, why is BYOK needed? It’s true that Clumio does encrypt all the backup data in its cloud with a customer-dedicated key, and that key is also rotated every 30 days. However, in some cases, certain customers have additional stringent security requirements:
How encryption works:
AWS S3 bucket keys have reduced the cost of server side encryption by more than 99% and don’t need to lookup the key for every single transaction. Since Clumio backs up data with millions of transactions, having to look up the key for every single transaction was a no-go. With AWS’S S3 bucket keys feature, Clumio can use the customers BYOK key as the Amazon S3 Bucket Key and encrypts all the data landing in the S3 bucket using the customers BYOK key.
How To Enable the BYOK feature:
Go to Settings and Security Features – Encryption Key. When you go to the page, Clumio provides details about the feature, along with its requirements and limitations. Customers can proceed by deploying the AWS CloudFormation StackSets inside any one of their AWS accounts where they want to use the BYOK key.
The reason StackSets is needed is because Clumio will need to create a multi-region (global) key and use that for encrypting backups in all regions where the data sources are present. Once successfully deployed, customers can verify the connection in the Clumio UI by visiting the page at any time.
The green check at the top of the page indicates that everything is working as expected. For whatever reason, if the key is not accessible, it changes to a red X and allows you to Check Access again to see if things are resolved and working again.
How to verify and audit Clumio’s Access
One of the advantages of the BYOK feature is that customers can verify and audit any time Clumio has accessed their key. Customers can go to the CloudTrail logs and see all the details of each time Clumio accesses their key, including the reason for access. Customers can go to the CloudTrail Logs section in their AWS account where the AWS CloudFormation StackSet was deployed.
For S3 bucket keys, since the keys are cached by the AWS S3 bucket keys, access might not be present for every single transaction. However, keys are accessed for every single transaction for EC2/EBS, VMWare and M365 backups.
What happens when key is no longer accessible:
Remember this: BYOK gives you the power of encrypting all backup data, but on the flip side, if the key is lost, then you’re in big trouble! Luckily, keys in AWS aren’t like physical keys and even if someone deletes them, customers still get 30 days to recover them. For whatever reason, if the keys are not recovered, then backup data would be rendered useless. It is meant to be used as a fail safe mechanism but great care should be taken to use this feature.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
I joined Commvault fresh out of school and at the height of the dot.com boom in 1998. While I had other offers in hand, I liked the people I met during the rigorous interview process and was drawn to an opportunity to cut my teeth on something that would move the needle and bring real value for our customers.
Opportunities like this don’t come around often. For me, it was the right decision.
Jump ahead twenty years to when our new CEO Sanjay Mirchandani saw the opportunity to transform Commvault into a software and SaaS data management company. I couldn’t miss this once-in-a-lifetime opportunity. After all, how many times do you get to start with a clean sheet of paper and launch something that would transform both your company and your career?
No matter how it turned out, not taking this chance would have been a huge regret.
No regrets were necessary. Sanjay gave me and a small, stealth startup team a big goal, a little funding, and permission to break the mold to develop the best backup-as-a-service offering available. We had to be agile – make decisions, see it through, fail fast, and readjust. Together, we launched our Metallic software-as-a-service offering on-time later that year. And just six quarters later, it became a $50M business for Commvault.
For my career, this was the push I was looking for. It wasn’t engineering for engineering’s sake. We were designing a product that was tailored to the end-to-end customer experience – from trial to onboarding to purchase to support to renewal. We had to look at it from the outside in, working cross-functionally, and with customers and partners to plan for the entire user journey.
It was an amazing and incredibly rewarding challenge. However, opportunities like this are rare and can be a little risky because you’re stepping into the unknown. So I thought I’d share my advice to help you seize your next career opportunity:
Get uncomfortable. Look outside your role and even your chosen function for new opportunities. And know, a little bit of “imposter syndrome” is good – It means you are expanding, growing, and pushing your boundaries.
Look from the outside in. Take time to understand your stakeholders’ perspective and expectations. Not just about the product itself, but the broader customer experience – how it is priced, where can it be purchased, and how they will pay for it.
Don’t fall in love with your ideas. Great ideas can come from anywhere and anyone, especially working cross-functionally. And when you are moving fast, your ideas often have a shelf life. So be open, flexible, and agile.
Overcommunicate. Time is not a luxury in technology. Communications is critical to align people, functions, and the field to work better and faster. Don’t skip this step.
Bend it – don’t break it. In a role like this, it is common to ask why something it done a certain way. Look for opportunities to make a product or process better, but don’t break it (or the person behind it).
I’m fortunate. I joined a company that inspired me to look for new opportunities and empowered me to pursue them. And, in many respects, I am just getting started as CTO of our Metallic business – a ride I’m more than ready for. If you haven’t already found that once-in-a-lifetime opportunity, my advice to you in your career is to leave no room for regrets.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
It’s time to get in on the Metallic Data Management as a Service (DMaaS) offering that’s gone from zero to $50M in record time
At Microsoft’s Inspire partner event this week (July19-21), there’ll be a significant focus on data management. Data is the lifeblood of any organization, and the threats to data loom larger today than ever before.
Today’s customers face significant data challenges. They’re looking for trusted experts—partners they can rely on to solve these issues with innovative, proven solutions. Customers are also suffering from point solution fatigue: needing one solution to protect some data, another to protect other data—on and on and on. They’re also looking for solutions that are proven to deliver results—solutions that deliver the results they promise.
Tired of managing so many solutions to meet your customers’ data challenges? (They are, too!)
Now, you can help end this madness. With Metallic, you get industry-leading Commvault technology, in a lightweight SaaS-delivery model. Enterprise data management that’s proven to safeguard entire customer data estates from deletion, corruption, and attack. It empowers businesses to protect and manage any workload—no matter where it lives and where it may need to live in the future—across on-prem, cloud, hybrid cloud, multi-cloud, SaaS, and the edge. It’s something no other solution can deliver on—and it’s exactly what your customers need.
If you want to be the partner of choice and win big as data protection transforms, it’s time to take a serious look at Metallic. If you don’t have a data protection practice and you need to start one, Metallic can be the cornerstone of your new practice. Here’s why:
The world of data protection and data management is moving to SaaS: All the experts agree that data protection is swiftly moving to SaaS. If you’re not offering solutions that meet your customers’ needs, you risk losing your customer base to someone who is. With Metallic, Commvault gives you a solution in your portfolio that is the best in class, best in DMaaS—and so much more. Plus, no infrastructure or operational support needed—Metallic provides it all for your customers.
Metallic is built on proven technology and a shared vision with Microsoft: Metallic is built on Azure and born out of 25+ years of joint engineering with Microsoft. Metallic is proven technology—it’s feature rich, supporting the widest range of workloads.
Ransomware recovery starts before you’re compromised: As the ONLY DMaaS provider to achieve FedRAMP High In Process – In PMO Review, Metallic offers a hardened, multi-layered approach to preserving and recovering data in the face of attack. But we take it one step further. Withfully integrated cyber deception, Metallic ThreatWise™ enables you to actively defend your data the moment an attack begins (not just recover from them). These unique and differentiated capabilities drive bad actors away from real data, and immediately surface zero-day and unknown threats before encryption, leakage, exfiltration, or theft. It’s unparalleled protection you can offer with Metallic.
Are you ready to win in the rapidly transforming data management market? If so, you’re ready for Metallic.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
CSR is all about showing the human side of us. It’s about showing how we truly care about our business, our planet, and most importantly, our people! We all know that over the past few years, the importance of care, support, and creating a better world have never been more top of mind. Making a difference and having an impact is core to Commvault’s culture, and we are stronger than ever…together!
Our values – we connect, we inspire, we care, and we deliver – are at the root of everything we do. These guiding principles shape our daily interactions with each other and our communities, power our passion for technical excellence and outstanding customer service, and support our overarching commitment to responsible, sustainable, and ethical business. Whether we’re helping our customers manage their data more sustainably, supporting the development and inclusion of our global workforce, or giving back to our communities, we continue to prioritize our stakeholders and treat long-term sustainability as a non-negotiable requirement of doing business.
Building both a better today, and a better tomorrow, is at the heart of who we are. And with innovation at the core of everything we do, we continue to drive new sustainability initiatives to advance our progress in 2022 and beyond.
I’m so proud to see all the incredible efforts of our Vaulters represented in this year’s report. More to come on our CSR efforts, so stay tuned!
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Ransomware threats continue to dominate headlines — and for good reason.
The good news is that you can strengthen your organization’s resiliency and security posture and stay one step ahead of ransomware with proactive data security best practices.
After all, the steps you take today to protect and defend against threats can determine how quickly your organization can resume normal business operations if you get hit with ransomware. For comprehensive coverage of cyber threats, you must proactively invest in preventative security measures to keep data safe and recoverable from attacks.
Follow these five best practices to implement a solid ransomware readiness strategy.
Have a Multilayered Security Plan
With ransomware threats becoming increasingly sophisticated, a multilayered approach to securing your data dramatically helps reduce your organization’s risk. Commvault believes a multilayered security framework that can protect, detect and recover is the best approach to protecting and recovering from ransomware attacks. While the average is 21 days of downtime, we have seen organizations resume operations as quickly as two days when leveraging a multilayered security approach.
Learn about Commvault’s multilayered approach to protect, detect, and recover from cyber threats. Learn more >
Control Who Has Access
Effective data protection starts with a strong foundation. Hardened security protocols, such as multifactor authentication, advanced data encryption, and zero-trust user access controls prevent unwarranted access to systems and data. With Commvault, you can identify risk exposure and coverage status from a single management console across your entire environment.
Watch this video to see how Commvault provides data security controls.
https://play.vidyard.com/xqQA12tnxA4dNEmSAgDj9P
Isolate and Air Gap
Data isolation using air gap techniques can reduce the exposure of backup data to malware and other vulnerabilities. Commvault suggests implementing a 3-2-1 back strategy for greater ransomware protection: 3 copies of your data, on 2 different media types, with 1 copy offsite. Utilize your cloud first initiatives for not just primary data but to secure your backups as well. Commvault provides a modernized approach to air gapping that is not only simple but also provides the maximum level of security needed to protect against lateral moving threats.
https://play.vidyard.com/i7Y7ACrZYzaSXEXkyBzibq
Segment Your Networks
If a cyberattack is successful, don’t give outside threats unlimited access to your entire network. Divide your network into smaller segments to prevent lateral movement and compromise of your business-critical data. Commvault augments your security strategy by providing the flexibility to quickly add cloud storage using Metallic® Recovery Reserve™. Using Metallic® Recovery Reserve™, you can easily implement an offsite cloud storage location, providing a virtual air-gapped, immutable copy of your data to satisfy the 3-2-1 backup storage rule and safeguard your data from cyberattacks.
Improve Security Posture
You need the ability to catch threats before they impact your business. Commvault provides centralized visibility and management through a single, unified platform with security dashboards and alerts to quickly identify risk exposure, detect suspicious activity, and resume business operations. The Commvault Security Health Assessment Dashboard offers a single place for IT Admins to bolster security posture quickly, identify risks in real-time, take corrective action, and rapidly recover data.
Commvault ransomware protection solutions are built on responsiveness, innovation, and rapid execution to help you stay one step ahead of ransomware. With Commvault, you have the most robust data management features at your fingertips to ensure your data remains secure and resilient, keeping your business ransomware ready.
Want to gain more insight into securing your enterprise data to avoid becoming headline news? Read how five organizations were attacked, how they recovered, and their lessons learned. Read Now >
Fred is the VP of Technology at BioPlus Specialty Pharmacy, the nation’s largest non-payer specialty pharmacy. They have physical locations in six states and are licensed to fill prescriptions in all 50, with over 500 employees. BioPlus innovated a 2 hour acceptance guarantee, 2 day ready to ship guarantee, and 2 click online refills.
The Pain Before the Cloud
Computing in an on-premises environment, BioPlus’s IT team was always playing catchup. They felt they were chronically behind, as the company was growing faster than the team could add servers, technologies and solutions. They knew they needed to move to the cloud to better enable their growth. BioPlus operates in a highly regulated space, subject to HIPAA, Medicare and PCI compliance standards, and of course the medical field is known to be a prime target of ransomware attacks. Given those realities, they knew data protection was of the utmost importance, and selected Clumio to help fufill that need.
Unlimited Scalability for Unlimited Business Growth
Once BioPlus decided to move their environment from on premises to the cloud, their journey took about 11 months. After considering all the options, they selected AWS because they felt those services would best support BioPlus’s brand promise and speed to service. They needed virtually unlimited resources to enable growth and scale as they expanded into new markets. The other very important factor was AWS’s security and compliance. Given BioPlus’s decision criteria for their cloud environment, it’s no surprise that they selected Clumio as their data protection provider. Fred loved that Clumio’s infinite scalability meant he wouldn’t have to worry about backup keeping up with growth. Especially considering that patient data like records and lab work tend to expand exponentially. Clumio’s elasticity was and is key to enabling BioPlus’s growth and success.
Data Protection Challenges
If one thing is a given, Fred knew their data had to be secure, and liked that Clumio is built with security at the forefront of thought, from front to back. Additionally, he had to consider the long-term retention requirements for patient records. HIPAA requires 6 years, and CMS requires 10 years for medicare providers. HIPAA also requires backed up data to be air-gapped. Because BioPlus processes payments, they are also subject to PCI, which requires end-to-end encryption. Clumio delivers on all of these needs.
Finding Even More Benefits in Clumio
Fred and his colleagues at BioPlus were already thrilled with everything Clumio delivered, but there were a few additional wow factors that really sealed the deal. First was the speed to implementation. BioPlus was able to have their Clumio backups fully up and running in less than a week from signing up. They also needed fast recovery times, and the ability to restore individual files. Finally, the fact that Clumio did all of this with SaaS simplicity meant Fred’s team could focus on their many other tasks. Then there’s the fact that Clumio saved Fred about 20% vs the other solutions he considered. This was naturally a welcome benefit.
More Details in the On-Demand Webinar
In the recording, Fred and Jeff go into much more detail on all of the points above, and they answer the audience’s questions about encryption key rotation, the future of healthcare and pharmacy technology, moving core legacy applications to the cloud, and more. If all this sounds interesting.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
We’ve all heard of the adage, “The only constant in life is change.” These words ring especially true for our customers today, as they navigate rising tides of shifting IT hybrid and multi-cloud environments, while battling cyberthreats all along the way.
At Commvault, we see those customers’ needs clearly – which is why we evolve not only our solutions, but also our partnerships to help bring those customers safely through that sea of change. Today’s news of our expanded Oracle partnership is a perfect example of how Commvault helps customers navigate changing trends and markets, with a steadfast commitment to the same peace of mind we have always afforded them.
Commvault and Oracle: a 25-year history of integration
Commvault has long supported Oracle customers protecting the crown jewels of their enterprises – their Oracle data. We have more than 3,000 joint customers, which is increasing every year, and the amount of Oracle data we are protecting has grown by more than 30% year over year.
More than 400,000 customers rely on Oracle today to run their businesses. As many of those companies are accelerating their own cloud adoption and migrating to OCI – they have a natural need for agile cloud solutions to protect along that journey.
As Oracle accelerated its own cloud business, bringing the power of OCI to its customer base, Commvault kept pace. In 2017, Commvault underscored our support for Oracle customers moving to OCI, through our Commvault Complete software. Two years later, we introduced Metallic SaaS – which has quickly grown to become the gold standard in data management as a service. With today’s news, Oracle customers who need all the benefits of a SaaS-delivered solution, can now harness the power of Metallic with OCI to protect their data on premises and in the cloud. We’re excited for this natural evolution of our partnership to meet customers where they are with the most innovative and flexible SaaS solutions in our industry.
In fact, Metallic is the only DMaaS solution to protect across Azure, AWS, and OCI.
A shared commitment to cloud innovation and enterprise support
Oracle boasts the broadest and deepest suite of cloud applications, while OCI continues to scale. At the same time, Metallic SaaS has reached an inflection point of hypergrowth, having grown to 50M ARR in just 6 quarters. As both of our companies come alongside customers to help them through their cloud journeys, we deliver unique opportunity to the Oracle installed base, to protect traditional workloads as they adopt the cloud.
Today, our Metallic SaaS portfolio expands to include support for new Oracle Cloud workloads – with OCI VMs and Oracle Container Engine (OKE) – in addition to existing support for Oracle databases running on premises or in cloud VMs, while Oracle customers can choose to send air-gapped backup copies to OCI leveraging Metallic Recovery Reserve.
Maybe change isn’t the only constant – what also stays the same is our promise to customers that they can depend upon Commvault to always keep their data safe and recoverable, no matter what lies under the deep. With today’s news, we are happy to continue to pay off on these promises for Oracle customers everywhere.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Ransomware breaches have increased by 13% – more than the last five years combined.1 Sixty percent of InfoSec leaders agree that ransomware threats should be prioritized to the same level as terrorism.2 A cybersecurity attack will impact your organization. It all comes down to how well you have prepared for your cyber recovery.
Are your organization and employees prepared for a cyberattack?
Do your teams know their roles, and will they work together?
Who has the authority/decision-making power to make time-sensitive decisions such as shutting down servers or networks?
As an executive, are your business leaders in sync, and how will you keep them informed?
Zero Loss Strategy
Consider if a ransomware attack hit you today. Would you have a job or company tomorrow? You need a solution that expands beyond zero trust principles to better plan, manage and reduce the impact of a ransomware attack—introducing Zero Loss Strategy, built on Zero Trust Principles and implemented through a multilayered security framework for consistent and automated data protection and recovery. With Commvault, protect what matters most through the broadest workload coverage for greater data protection and rapid recovery across cloud and storage platforms all through a unified customer experience helping you to remain vigilant against cyber threats. Zero Loss Strategy delivers:
End-to-end data visibility
Catch threats before they fully impact your data. With a single management platform, identify business-critical and sensitive data, reduce your attack surface, and minimize risk exposure.
Broadest workload protection
Protect what matters most. Commvault covers the broadest of workloads, from traditional on-premises to hybrid cloud and SaaS applications; we also support native cloud integration, so as your organization and data grow, we can easily help you scale.
Faster business response
Speed and accuracy are essential to responding to a ransomware attack. Consolidating your data protection to a single dashboard, the Commvault Command Center™ gives your organization greater production and efficiency.
Zero Trust Principles
Trust but verify. Organizations need to follow zero trust principles to ensure cyber threats do not have unlimited access within their networks. It is core to every organization’s proper cyber hygiene.
A Zero Loss Strategy is built on Zero Trust Principles and implemented through a multi-layered security framework. Commvault uses these as the foundation for a Zero Loss Strategy. We provide multiple layers of authentication controls to stop malicious actors, insider threats, and even unintentional accidents from deleting backup data.
Commvault Multilayered Security Protection
Many experts recommend having a layered anti-malware and ransomware strategy. Commvault has built these security capabilities into our data protection software and policies without the incremental management overhead. Commvault data protection and management platform include five security layers:
Identify and mitigate risks to backup data within a single interface
Protect by applying security controls based on industry-leading standards
Monitor for ransomware, insider threats, and other threats
Respond and take action on threats and continuously validate backup data
Recover data quickly across multiple on-premises, cloud, and hybrid environments
Implement an Action Plan
To help you better protect and manage your data, maintain healthy business operations, and manage risk, you need an approach that brings together your data management teams, security teams, and stakeholders. You need a strategy to help you be better prepared and have the ability to recover quickly if a cyberattack does occur.
Create an incident response plan and test, test, test
Ensure you have the right staff, vendors, process and technology in place
Follow the NIST multilayered security framework: identify, protect, monitor, respond and recover to cover security gaps that may exist in your infrastructure
Follow Zero Trust Principles to verify those users already in your perimeter
Use a centralized management system, not multiple product points, for easy visibility across your data
Eliminate gaps in your environment through air gap, honeypots and isolate networks
Ensure your data protection provider can easily scale with your evolving needs and that you have flexible restore options to rapidly recover. You want a comprehensive approach, not a complex one. Learn more about a Zero Loss Strategy and ransomware protection and recovery.
References
1. InfoSecuity, Benjamin David, Ransomware Attacks Increasing at “Alarmin” Rate, May 2022 – 2. TechRadarPro, Anthony Spadafora, IT Workers Believe Ransomware is as Serious as Terrorism, January 2022.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
How are you protecting your data from a ransomware attack or natural disaster? What is your recovery plan? Is your disaster recovery plan the same as your cyber recovery plan? The steps you take to protect your data might be the same, but your recovery efforts may vary. Both types of disasters could be devastating to your business, but what’s critical is recovery. The average cost of downtime for large enterprises is more than $11,600 per minute,1 and 40-60% of small businesses won’t reopen after data loss.2 So, the way you think about recovery matters.
Gartner defines a ransomware attack as “cyber extortion that occurs when malicious software infiltrates computer systems and encrypts data, holding it hostage until the victim pays a ransom.”3 A cyberattack is very different from a natural disaster attack. In this instance, your data is intentionally infiltrated. Bad actors have proactively gained access and placed malware into your environment, locking up your systems, hijacking critical data, and seeking ransom. It is estimated that a ransomware attack occurs every 11 seconds.4
What Is a Natural Disaster?
When a disaster strikes, such as a flood, earthquake, fire, or storm, your data environments are inadvertently shut down or even destroyed. In this instance, your data is not intentionally infiltrated. In 2021, there were 401 natural disaster events worldwide.5
What Is Disaster Recovery?
Disaster recovery is the ability to regain access and functionality of critical data systems and IT infrastructure as soon as possible after a natural disaster occurs. It relies upon the replication of data from an off-premises location or cloud environment, where the data is backed up and not impacted by the natural disaster. In a disaster recovery situation, the goal is to restore business operations efficiently with minimal downtime and zero data loss, as the business readiness of the data is considered pre-qualified for recovery. In a disaster recovery situation, your efforts are centered on the efficiency of restoring operations.
What Is Cyber Recovery?
Cyber Recovery aims to provide the ability to regain access and functionality of critical data systems and IT infrastructure as soon as possible after a cyberattack such as ransomware occurs. In a cyber recovery situation, your objectives are to get your business backup and running from an air-gapped and immutable copy of data, which assures you of data integrity. Data protection solutions with the implementation of zero trust architecture assure you a layered approach to defense even for your backup environment. However, “seeing is believing” and this is where it is important to ensure you are frequently validating the business-readiness of the data as part of the cyber recovery tabletop exercises. This can be achieved by performing application validation of the data using custom scripts in a network-quarantined sandbox environment. By doing so, you can prevent any potential re-infection of the environment and thereby contain the “blast radius” after an attack.
How do Cyber Recovery and Disaster Recovery Differ?
Cyber recovery and disaster recovery differ. With disaster recovery, the focus is on the Mean Time to Recovery (MTTR) of operations and the smooth functioning of business. In a best-case disaster recovery scenario, data is not compromised. As for cyber recovery, it is all about your business survival, focusing on data, applications, infrastructure and more.
Characteristics of Disaster Recovery vs. Cyber Recovery
Disaster Recovery
Cyber Recovery
Principle requirement
Rapid means to recovery of business operations with minimal downtime. It is typically assumed that there is zero data loss.
Rapid recovery of business and its data, with zero data loss, and the assurance that data has not been manipulated or tampered with.
Recovery objective expected
Recovery to the closest point in time.
Recovery to the closest point in time from an air-gapped immutable copy.
Tools used
Typically requires replication tools to aid data replication between sites and locations, complete with orchestration to aid seamless failover and failback operations
Requires a host of tools and processes to confirm data has not been manipulated for the protection of applications, networks, use of SIEM/SOAR ecosystem solutions for forensics & analytics, and network monitoring tools.
Frequency of testing recovery runbook
Typically, once every six months to a year.
As frequently as possible to validate the business readiness of data. Exercises include processes that engage incident response teams (IRT), legal, corporate, public relations, communications, third-party insurance, and IT teams. These tabletop exercises help minimize downtime during times of crisis so that it becomes collective muscle memory when it comes to recovery.
What Is an Incident Response Plan?
Do you have an incident response plan? Is your organization and its employees prepared for a ransomware attack or natural disaster?
All the teams involved must be able to play their part in the cyber recovery process effectively
They must be capable of exercising plans and have permission to execute those plans if something happens. During an actual attack, you don’t want teams pointing fingers at each other regarding who is responsible for what. This is often referred to as “IT Collision,” which can significantly impact an organization’s ability to respond to a cyber-crisis efficiently. Ensuring that all the key stakeholders and teams are enabled with the right permissions ensures that they can make swift decisions with authority – and this can be achieved by teams typically being given pre-authorization to perform prescribed actions. Process-induced latency to the recovery exercise can be eliminated without having to get people out of bed and onto a Zoom call to receive authorization.
As for C-Level executives, are your business leaders in sync? How many different business units and partners need to be involved in an incident response plan? Are you concerned about consequences to shareholders in the event of a ransomware attack?
It is important that executives drive a business impact analysis of the entire estate that includes PPT (People, Process, and Technology) to measure the overall impact of downtime after a cyber event.
Identify what needs to be part of the cyber recovery plan .
Identify teams that need to be engaged with as security teams, IRT’s (incident response teams), cyber insurance partners, and data protection teams, as all need to work in close concert for the cyber recovery exercise to be effective.
Detailed processes need to be chalked out that need to be followed during a ransomware attack.
Finally, practice, practice, practice until it becomes collective muscle memory to be able to respond with minimal friction points during actual crisis response.
What Are the Types of Cyberattacks?
It is easy to assume that all ransomware is similar, and it is not uncommon to think that one size fits all in terms of prevention and preparation. However, because each type of ransomware is usually developed to attack different, targeted networks, they can be very different in the way they operate. It is essential to understand the different types currently being used (keeping in mind that attackers are capable of combining multiple types of ransomware).
The strength of protection against any ransomware attack is in your defense strategy, especially given the rise in zero-day vectors with no known tactics, techniques or procedures (TTP).
Six types of Ransomware:
CryptoWall – is responsible for a high percentage of ransomware attacks. Typically, CryptoWall is used to attack targets through phishing emails. The WannaCry ransomware virus is a derivative of the Crypto family and was at the core of the largest cyberattacks ever perpetrated. Unfortunately, the creators of CryptoWall continue to release new versions designed to get around security protections.
Locky – as the name implies, Locky is what it does (locks you out of files and replaces the files with the extension .lockey). However, its name misses the most damaging part of this type of ransomware – its speed. Locky has the distinction of spreading to other files throughout the network faster than other ransomware strains.
Crysis – takes data attacks to a new level, actually kidnapping your data and moving it to a new virtual location. The significance of this aspect of the attack is that it qualifies as a breach if your company works with personal data; organizations must contact anyone who may have information on your network to stay in compliance with local, state, and federal guidelines.
SamSam – attacks unpatched WildFly application servers in the internet-facing portion of their network. Once inside the network, the ransomware looks for other systems to attack.
Cerber – attacks the database server processes to gain access instead of going straight after the files. Its creators sell the ransomware software to criminals for a portion of the ransom collected, i.e., Ransomware-as-a-Service.
Maze – is a variant of ransomware representing the trend in what is called “leakware.” After data is encrypted, bad actors threaten to leak ransomed private data on the dark web unless the ransom is paid.
Safeguarding against ransomware must be at the forefront of organizations’ security efforts.
How Does Ransomware Spread?
Social Engineering is a key tactic used by cybercriminals to encourage unsuspecting users to download/click a spurious link/website. Ransomware is often spread through email phishing messages containing malicious links or by drive-by downloading, which occurs when a user unintentionally visits a contaminated site, and malware is downloaded onto the user’s computer or mobile device. Once within the IT environment, threat vectors move laterally within the network until detected. The anatomy of a ransomware attack is typically to move through unstructured data to remain undetected for as long as possible. Until recently, malware and threat vectors have been known to gestate within an environment for up to 300 days while gradually encrypting data sets and wreaking widespread havoc.
However, with more recent attacks, we find threat vectors being able to sweep in and achieve instantaneous, large-scale destruction by performing mass deletes or encryption. The speed of these attacks does not allow teams to respond fast enough. Therefore, ensuring that the data protection environment is safeguarded from day one against any pace of attack is key. Security professionals must rely on “air-gapped and immutable” backup copies as their insurance policy.
How Commvault Fights Ransomware
Commvault data protection and recovery can be a valuable part of your anti-ransomware strategy. Commvault multi-layered security is built on zero trust principles and based on the National Institute of Standards and Technology (NIST) cybersecurity framework to protect data and enable quick recovery in the event of a ransomware attack. Commvault helps protect and isolate your data, provides proactive monitoring and alerts, and enables fast restores. Advanced technologies powered by artificial intelligence and machine learning, including honeypots, make it possible to detect and provide alerts on potential attacks as they happen so you can respond quickly. By keeping your backups out of danger and making it possible to restore them within your Service Level Agreements, you can minimize the impact of a ransomware attack so you can get back to business right away (and avoid paying expensive ransoms).
Protecting and isolating your backup copies is critical for data integrity and security. Therefore, Commvault has taken an agnostic approach to immutability. With Commvault, you do not need special hardware or cloud storage accounts to lock backup data against ransomware threats. If you happen to have Write-Once, Read Many (WORM)-, object lock- or snapshot-supported hardware (which Commvault fully supports), you can still use Commvault’s built-in locking capabilities to complement and layer on top of existing security controls. Commvault’s ability to support layered defense for securing data sets against ransomware ensures that our customers benefit from a sound cyber recovery-ready architecture. Here are some elements to include in your immutability architecture:
Access locks to isolate copy store against ransomware
Immutability with lifecycle locks to reduce risks, balanced with consumption impact
Air-gap isolation network and controls
Configuration governance to protect against intentional or accidental changes
Concurrent Recovery performance – reduce latency with due importance to speed and cost impact
Automatic patching to stay current, simplifying management and maintenance of data protection infrastructure
Alignment with the 3-2-1 data protection philosophy (3 copies of data, 2 different media, 1 vaulted copy)
Learn more about Commvault’s immutable infrastructure architecture here.
Commvault Multilayered Security Protection
With every environment having a mix of different infrastructures, securing backup data against random unauthorized changes can seem challenging. Just like securing your house, you need to identify the risks and enable the protection and monitoring capabilities to match your needs.
Many experts recommend having a layered anti-malware and ransomware strategy. Commvault has built these security capabilities into our data protection software and policies without the incremental management overhead. The Commvault data protection and management platform include five security layers:
Identify and mitigate risks to backup data within a single interface
Protect by applying security controls based on industry-leading standards
Monitor for ransomware, insider threats, and other threats
Respond and take action on threats and continuously validate backup data
Recover data quickly across multiple on-premises, cloud, and hybrid environments
Commvault multi-layered security consists of feature sets, guidelines, and best practices to manage cybersecurity risk and ensure data is readily available. It is essential to understand that these capabilities are part of Commvault’s core platform experience, Commvault Complete™ Data Protection. There is no special licensing, no additional costs, and no required hardware or software. The layered security depth is enhanced through greater integration with Metallic™ and Commvault Grid for those customers seeking the simplicity of Backup as a Service or a data protection appliance, respectively.
Ransomware Security Measures
Air gap: Traditionally, air-gapped networks have absolutely no connectivity to public networks. Tape is a traditional medium for air-gapped backups because tape can be removed from the tape library and stored offsite. To air gap secondary backup targets on disk or cloud, some access is needed, but communication is severed when it is not required. When the isolated data does not need to be accessed, communication is severed either by turning communication ports off, disabling VLAN switching, enabling next-gen firewall controls, or turning systems off.
Multi-factor Authentication (MFA)6: This is a layered approach to securing data and applications where a system requires a user to present two or more credentials to verify a user’s identity for login. MFA increases security because even if one credential becomes compromised, unauthorized users will be unable to meet the second authentication requirement and will not be able to access the targeted physical space, computing device, network, or database.
Least Privilege Access: This standard security practice provides access to users and/or accounts with the bare minimum capabilities to do their job and nothing more. You decide who has access to what. This minimizes exposure if the account is compromised and limits data access leaks.
Perform Regular Backups with Immutability: Consider increasing the frequency of backups and expanding your data protection to a 3-2-1 backup strategy; 3 copies of your data, on 2 different media types, with a copy offsite and preferably air-gapped. Other essential data protection tools include encryption, write once, read many (WORM), and strict access controls.
Data immutability: Data that cannot be altered. To better protect against ransomware, ensure backup copies are immutable by using layered security controls, write once read many (WORM) capabilities, and immutable storage, as well as built-in ransomware protection for backup data.
Data encryption and key management: A technology in which data is translated into an unreadable form or code, and only users with access to a secret key or password can read it. Encryption at rest and in-flight ensures the backup data, even if exfiltrated, is rendered useless to bad actors without the decryption keys or password.
Anomaly Alerts: These indicate deviation from the expected pattern of data or events. Anomaly detection helps provide behavioral insight, giving your organization the ability to learn about identification patterns to understand your environment and recognize unusual behavior before a threat impacts your environment and business.
Honeypots7: A network-attached system set up as a decoy to lure cyberattackers and detect, deflect and study hacking attempts to gain unauthorized access to information systems. The function of a honeypot is to represent itself on the internet as a potential target for attackers — usually, a server or other high-value asset – and to gather information and notify defenders of any attempts to access the honeypot by unauthorized users.
Application hardening8: A catchall term for protecting an app against intrusions by eliminating vulnerabilities and increasing layers of security. Data security involves multiple layers of defense that are not limited to the app itself: the host level, the operating system level, the user level, the administrator level, and even the physical level of the device all have vulnerabilities that a good security system must address. For this reason, application hardening might be called system hardening or OS hardening as well.
Whether you are hit with a cyberattack or face a natural disaster — the reality is your organization needs to be prepared and take steps to protect your data and work with a provider who offers rapid cyber and disaster recovery solutions. So how prepared are you? Read our eBook on Understanding Team Roles and Responsibilities in Fighting Ransomware.
References
1.,2. Branko K: Web tribunal: 15+ scary data loss statistics to Keep in Mind in 2022, March 2022. – 3. Gartner, 6 Ways to Defend Against a Ransomware Attack, by Manasi Sakpal, November 2020 – 4. Safe at Last, 22 Ransomware Statistics to Help Fortify Your Cybersecurity Models: Jan 2022 – 5 Statistica, Madhumitha Jaganmohan, Global Number of Natural Disasters Events 2007-2021, February 2022 – 6. CISA – 7. TechTarget, Ben Lutkevich, Casey Clark, Michael Cobb, honeypot (computing) – 8. Thales, Application Hardening
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection