{"id":5049,"date":"2022-11-01T15:35:23","date_gmt":"2022-11-01T19:35:23","guid":{"rendered":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/?p=5049"},"modified":"2022-11-04T11:58:36","modified_gmt":"2022-11-04T15:58:36","slug":"data-storage-and-backup-security-how-to-defend-against-ransomware","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/","title":{"rendered":"Data Storage and Backup Security: How to Defend Against Ransomware"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5050\" src=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2.jpg\" alt=\"Data Storage and Backup Security: How to Defend Against Ransomware\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2.jpg 800w, https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2-300x150.jpg 300w, https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2-768x384.jpg 768w, https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2-540x270.jpg 540w, https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2-162x81.jpg 162w, https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify;\"><strong><em>This is part of Solutions Review\u2019s Premium Content Series, a collection of contributed columns written by industry experts in maturing software categories. In this submission, <a href=\"https:\/\/www.continuitysoftware.com\/\" target=\"_blank\" rel=\"noopener\">Continuity Software<\/a> CTO Doron Pinhas offers advice on how to defend against ransomware with data storage and backup security.<\/em><\/strong><\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4686 alignleft\" src=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2021\/12\/SR-Premium-Content.gif\" alt=\"\" width=\"105\" height=\"110\" srcset=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2021\/12\/SR-Premium-Content.gif 105w, https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2021\/12\/SR-Premium-Content-77x81.gif 77w\" sizes=\"(max-width: 105px) 100vw, 105px\" \/>The cost of a single storage system breach could overwhelmingly exceed the investment in a storage security framework and controls.<\/p>\n<p style=\"text-align: justify;\">Ransomware attacks are growing more frequent and intense for obvious reasons. CISOs and security teams, therefore, expand their framework to encompass <span style=\"text-decoration: underline;\"><strong><a href=\"https:\/\/solutionsreview.com\/data-storage\/data-storage-buyers-guide\/\" target=\"_blank\" rel=\"noopener\">storage<\/a><\/strong><\/span> and <span style=\"text-decoration: underline;\"><strong><a href=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/get-a-free-backup-and-disaster-recovery-buyers-guide\/\" target=\"_blank\" rel=\"noopener\">backup systems<\/a><\/strong><\/span> and add controls specific to their unique needs. They do it as the more they define and enforce detailed security policies, the more they reduce their risk.<\/p>\n<p style=\"text-align: justify;\">If you\u2019re taking your first storage-security steps, we urgently recommend getting to know prominent storage &amp; backup security guidelines and frameworks. Examples include the <a href=\"https:\/\/www.continuitysoftware.com\/resources\/nist-guide-for-storage-security-2\/\" target=\"_blank\" rel=\"noopener\"><em>NIST Security Guidelines for Storage Infrastructure<\/em><\/a> (published in 2020), ISO 27040 (published in 2015), and SNIA\u2019s storage security publications.<\/p>\n<p style=\"text-align: justify;\">Here are six strategies that infrastructure &amp; security leaders must take to safeguard their data in storage and backup systems:<\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"speedbump-1\" href=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/get-free-disaster-recovery-service-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"DRaaS Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2020\/02\/DRaaS_SB_BG_800.gif\" alt=\"Download Link to DRaaS Buyer's Guide\" width=\"800\" height=\"100\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n<h2><strong>Data Storage and Backup Security<\/strong><\/h2>\n<hr \/>\n<h3 style=\"text-align: justify;\"><strong>1. Steer a Culture that Breaks the Silos Between Security and Storage Teams<\/strong><\/h3>\n<p style=\"text-align: justify;\">Security teams often lack a good understanding of <span style=\"text-decoration: underline;\"><strong><a href=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-protection-vendor-map\/\" target=\"_blank\" rel=\"noopener\">storage &amp; backup capabilities<\/a><\/strong><\/span>, protocols, and the attack surface. Storage teams often adopt a na\u00efve approach to security. They assume it complicates storage management (somewhat true) and that security and performance are contradictory (valid years ago, much less so today). A good first step could be to perform a one-time audit for storage security.<\/p>\n<h3><strong>2. Build Safeguards into Storage &amp; Backup Security Processes and Practices<\/strong><\/h3>\n<p style=\"text-align: justify;\">Start by creating secure storage designs, implementations, and management procedures. Walk yourselves through the storage lifecycle from technology inception through security updates and patches to retiring storage devices.<\/p>\n<h3><strong>3. Raise Your Security Baseline<\/strong><\/h3>\n<p style=\"text-align: justify;\">To include <span style=\"text-decoration: underline;\"><strong><a href=\"https:\/\/solutionsreview.com\/identity-management\/get-a-free-identity-and-access-management-software-solutions-buyers-guide\/\" target=\"_blank\" rel=\"noopener\">identity and access management<\/a><\/strong><\/span> controls that separate administration within and between different data-planes (such as primary storage, backup, and <span style=\"text-decoration: underline;\"><strong><a href=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/get-free-disaster-recovery-service-buyers-guide\/\" target=\"_blank\" rel=\"noopener\">disaster recovery<\/a><\/strong><\/span>), business functions, and environments (such as production, development, and testing). You can bake security baselines, guidelines, and quality controls into your IT management DNA and apply them with every new storage initiative.<\/p>\n<h3><strong>4. Deploy and Inventory Storage &amp; Backup in Adherence with Baseline Security<\/strong><\/h3>\n<h3><strong>5. Monitor and Measure Change Against Baselines 24\/7<\/strong><\/h3>\n<p>To make sure you never deviate from them.<\/p>\n<h3><strong>5. Expand your Incident Response and Recovery Plan<\/strong><\/h3>\n<p style=\"text-align: justify;\">Expand it to cover the storage, using metrics on the likelihood and severity of incidents as they apply to your business. (Use available data to benchmark your environment against other organizations for reference.) Run tabletop exercises to decide how to recover from scenarios such as these:<\/p>\n<ul>\n<li style=\"text-align: justify;\">An attack wipes out a large storage array supporting thousands of servers, VMs, and operating system instances. The onslaught has erased your data and storage configurations. You must rebuild the array, create the LUNs, and remap them to those servers and data stores.<\/li>\n<li style=\"text-align: justify;\">A criminal hacker deletes your SAN settings, including zoning and masking. It took years to design and roll out those configurations. Now you must fall back on your documentation and backups. Do you have automation in place to recover quickly?<\/li>\n<li style=\"text-align: justify;\">An unidentified strain of ransomware targeting a zero-day vulnerability in SAN storage software has hit your storage plane. The ransomware targets primary storage and backups. You need to keep secure backups so you can recover once you stop the attack. You must defuse the malicious software as soon as possible.<\/li>\n<\/ul>\n<h4><strong>Getting On the Storage Security Fast Track<\/strong><\/h4>\n<p style=\"text-align: justify;\">If you ask us what\u2019s the best thing to do as a starting point, we\u2019d say \u201ceasy!\u201d. Obviously, it\u2019s to reach out to experts who can identify the \u201cgaps\u201d. They can map your infrastructure and conduct a one-time audit to get you on your way.<\/p>\n<p style=\"text-align: justify;\">Then, understand that automation will be your new best friend for curtailing errors, costs, and person-hours. It\u2019s best to bake automation into storage &amp; backup security provisioning, validation, and auditing. Consider automation that validates your configurations against your security baselines.<\/p>\n<div class=\"hr hr\"><\/div>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"speedbump-3\" href=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-protection-vendor-map\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"Data Protection Vendor Map\" src=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2020\/02\/DP_VM_SB_800.jpg\" alt=\"Download Link to Data Protection Vendor Map\" width=\"800\" height=\"100\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>This is part of Solutions Review\u2019s Premium Content Series, a collection of contributed columns written by industry experts in maturing software categories. In this submission, Continuity Software CTO Doron Pinhas offers advice on how to defend against ransomware with data storage and backup security. The cost of a single storage system breach could overwhelmingly exceed [&hellip;]<\/p>\n","protected":false},"author":385,"featured_media":5050,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[1257,1256],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Data Storage and Backup Security: How to Defend Against Ransomware<\/title>\n<meta name=\"description\" content=\"Continuity Software CTO Doron Pinhas offers advice on how to defend against ransomware with data storage and backup security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Doron Pinhas\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/\",\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/\",\"name\":\"Data Storage and Backup Security: How to Defend Against Ransomware\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2.jpg\",\"datePublished\":\"2022-11-01T19:35:23+00:00\",\"dateModified\":\"2022-11-04T15:58:36+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/2ab2c030695abeb7a0ed3270b017b021\"},\"description\":\"Continuity Software CTO Doron Pinhas offers advice on how to defend against ransomware with data storage and backup security.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2.jpg\",\"width\":800,\"height\":400,\"caption\":\"Data Storage and Backup Security: How to Defend Against Ransomware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data Storage and Backup Security: How to Defend Against Ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#website\",\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/\",\"name\":\"Best Backup and Disaster Recovery Tools, Software, Solutions &amp; Vendors\",\"description\":\"Solutions Review\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/2ab2c030695abeb7a0ed3270b017b021\",\"name\":\"Doron Pinhas\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/99ff13ad77dbeda186f610e46f06dba9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/99ff13ad77dbeda186f610e46f06dba9?s=96&d=mm&r=g\",\"caption\":\"Doron Pinhas\"},\"description\":\"Doron is an avid Storage and Backup security advocate, and one of the two authors of the recently published NIST special publication titled: \u201cSecurity Guidelines for Storage Infrastructure\u201d. Alongside continuous research of storage security, threat landscape, and market maturity analysis, he is also engaged in writing, public speaking and information exchanged with leading organizations.\",\"url\":\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/author\/dpinhas\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data Storage and Backup Security: How to Defend Against Ransomware","description":"Continuity Software CTO Doron Pinhas offers advice on how to defend against ransomware with data storage and backup security.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/","twitter_misc":{"Written by":"Doron Pinhas","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/","url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/","name":"Data Storage and Backup Security: How to Defend Against Ransomware","isPartOf":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2.jpg","datePublished":"2022-11-01T19:35:23+00:00","dateModified":"2022-11-04T15:58:36+00:00","author":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/2ab2c030695abeb7a0ed3270b017b021"},"description":"Continuity Software CTO Doron Pinhas offers advice on how to defend against ransomware with data storage and backup security.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#primaryimage","url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2.jpg","contentUrl":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/files\/2022\/11\/MicrosoftTeams-image-2.jpg","width":800,"height":400,"caption":"Data Storage and Backup Security: How to Defend Against Ransomware"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/data-storage-and-backup-security-how-to-defend-against-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/"},{"@type":"ListItem","position":2,"name":"Data Storage and Backup Security: How to Defend Against Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#website","url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/","name":"Best Backup and Disaster Recovery Tools, Software, Solutions &amp; Vendors","description":"Solutions Review","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/2ab2c030695abeb7a0ed3270b017b021","name":"Doron Pinhas","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/99ff13ad77dbeda186f610e46f06dba9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/99ff13ad77dbeda186f610e46f06dba9?s=96&d=mm&r=g","caption":"Doron Pinhas"},"description":"Doron is an avid Storage and Backup security advocate, and one of the two authors of the recently published NIST special publication titled: \u201cSecurity Guidelines for Storage Infrastructure\u201d. Alongside continuous research of storage security, threat landscape, and market maturity analysis, he is also engaged in writing, public speaking and information exchanged with leading organizations.","url":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/author\/dpinhas\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/posts\/5049"}],"collection":[{"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/users\/385"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/comments?post=5049"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/posts\/5049\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/media\/5050"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/media?parent=5049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/categories?post=5049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/backup-disaster-recovery\/wp-json\/wp\/v2\/tags?post=5049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}