Wednesday, February 16, 2022

Data Protection - 3-2-1 Backup Rules must evolve

 

Let’s back up a moment . The 3-2-1 backup strategy simply states that you should have 3 copies of your data (your production data and 2 backup copies) on two different media (disk and tape) with one copy off-site for disaster recovery.  This is depicted in the figure that follows.

The 3-2-1 backup strategy depicted above was an advancement on the tape-based strategy where you had only one media copy and you took it offsite.  So it was an advancement in its time.  It was inherently limited, however, due to the technology of the time.  With older continuity and backup protection, 3-2-1 was about the best you could do.  The second media type was typically tape and depending upon the size of the company using the 3-2-1 backup strategy the options for getting it offsite ranged from hiring a service such as Iron Mountain to putting it in the back of your car.  As cloud-based backup companies evolved, they offered 3-2-1 backup via the cloud (and for the most part ignored the second media type in favor of the cloud.)


This backup strategy enables you to perform disaster recovery in two different ways – with the cloud and then with physically moving data offsite.  In this approach, the cloud does not receive all backup copies – they are split between the first and second media type locally.   Typical IT administrators who use this backup strategy are trading increased labor (physically moving data offsite) for lowered spend on WAN bandwidth.



3-2-2 backup strategy

In this backup strategy, you achieve continuity through the use of both the cloud and a local second media type.  The cloud affords you both continuity and extended retention.  The local second media affords you another copy of what you have in the cloud in a 3-2-2 backup strategy.  


3-2-3 backup strategy

A variation of the 3-2-2 backup strategy


So what will happen in 2022 ?

In 2022, the 3-2-1 backup rule will continue to be the golden rule of complete data protection. This means that organizations will keep three copies of data saved across at least two media types, with one more copy saved offsite. In 2022, ROI will also remain the name of the game, so organizations will seek a proven solution that makes this easy and affordable to implement. The ideal backup solution will enable a backup script to a local destination and a backup transfer script to an offsite target. Using a transfer script to copy backups to a second location enables the administrator to perform the operation offline, without the original source needing to be used. 

In 2022, there will be various options available for implementing 3-2-1 workflows. The first possibility will be disk and cloud. Combining local disks and cloud storage locations is a common pattern for a backup strategy. An available backup on a local disk translates into very fast recovery time, as the local network allows for much higher bandwidth. A remote backup on a cloud storage location insulates the organization’s data from disaster, malware, and other problems that arise. The second option will be network-attached storage (NAS) and cloud. NAS devices are an affordable on-site storage location for backups. Leveraging an on-site NAS ensures a large, dedicated storage pool and high bandwidth for backups. Transferring those backups to the cloud as an offline process allows administrators to avoid touching the original source multiple times. The third option will be disk and tape. Disk remains the most common storage media, and tape continues to make strides in speed and storage capacity. With a local disk, the administrator can quickly back up their environment and have the backups available for fast restore. Using a tape library for offsite storage enables the administrator to store their backups in a safe location (like a security deposit box or a third-party storage locker) that – unlike the cloud – the administrator has physical access to. 

Of course, in 2022, going beyond the 3-2-1 backup rule will provide organizations with extra insurance to protect their digital transformation initiatives. Organizations can choose to utilize a second cloud storage location (i.e., 3-2-2 strategy) or NAS, tape and/or cloud (i.e., 3-3-2 strategy) for added redundancy. 

Finally, in 2022, utilizing WORM storage in the cloud with Immutable Backups will provide the best protection against ransomware attacks. With a locked backup, malware cannot delete your critical data, enabling the administrator to recover if the worst does happen. By combining the 3-2-1 backup with immutable backups in the cloud, administrators can ensure their organization’s data is protected against the latest threat landscape.


https://www.cisa.gov/uscert/sites/default/files/publications/data_backup_options.pdf


Saturday, January 8, 2022

2022 Data Protection Predications

 It shouldn’t be news to anyone that ransomware is the cybersecurity challenge of the moment. As we head into a new year, it’s important everyone gains a clear understanding of how attackers are evolving and how best to strategically protect organizations from attacks and the impact they have on business.

Attackers are getting smarter, and the payouts are getting larger and more widespread. As a CEO or CIO of an organization, it’s irresponsible at this point not to have a proven ransomware response plan. Any organization can fit the target characteristics for today’s cybercriminals, and it’s become simply a matter of time until your organization’s number is up.

The ability to recover should be a focal point of any security plan. This will be defined by how quickly you can stand up your systems and get them running again. However, in our accelerated digital age, too much can happen overnight or in three to five days for the traditional back up model to be good enough. Recovery solutions need to modernize to fit what the world has become. They need to be continuous and able to keep applications running 24/7 even in the face of disruption or threat





Here are a few predictions being made for data protection in 2022

Businesses will reconsider on-premises data centers in favor of cloud

Many companies that moved applications into the public cloud are now considering a reverse migration – back to their on-premises data centers / centres for three main reasons:  cost creep, data sovereignty requirements, and IT management control. Cloud fees can be unpredictable, and many businesses struggle to control the insidious growth of workloads and instances. Many also want to avoid ‘egress’ fees charged for removing data from the cloud.

In addition to cost, some organizations are subject to GDPR and other regulations that require them to ensure their customers’ data stays within the borders of the company home office country. If the cloud vendor does not have a data center in their geographic location, these so-called data sovereignty regulations may require them to move their workload and data back on premises.

A third common reason for moving back on premise is to regain some of the IT control that is given up to cloud vendors. While cloud vendors assume the IT burden and responsibility for system maintenance, they also take control of when and how that maintenance is performed. For critical applications with high availability SLAs, excess or inconveniently timed downtime can cost tens of thousands of dollars and more than justify moving workloads back on prem.

More investment in disaster recovery

Climate change and social unrest have moved the need for disaster recovery to the forefront of IT focus. DR planning is no longer a matter of factoring in the rare ‘once in 100 years storm’ or ‘once in a lifetime earthquake’. Natural disasters have become an increasingly common threat to business operations. Companies will spend more on DR in 2022 and look for more flexible deployment options for protection, such as replicating on-premises workloads to the cloud, or use of multi-node failover clustering across cloud availability zones and regions.

High availability protection for storage will become standard

Climate change and natural disaster threats have also shown IT teams that simple backup of data storage is no longer sufficient. Regardless of whether the storage is NFS, SAN, cloud-native shared storage, or replicated local storage, companies will need to implement a more sophisticated way to handle DR. They will increase protection levels for their data storage – both on premises and in the cloud – to include high availability and disaster protection.

Container complexity will limit adoption for production workloads

Containers are continuing to make the headlines and are destined to be applied in more use cases throughout the IT infrastructure. The benefits of containers are proven in DevOps environments but their complexity, coupled with constraints on IT resources and the complex architecture of many applications, databases, and ERP systems will limit their adoption in production environments. Companies will continue to run complicated applications, databases, and ERPs in traditional on-premises and cloud environments. They will use application-aware HA/DR clustering to reduce complexity of these environments while ensuring they are protected from downtime.



The Resurgence of Tape as a Critical Component of Cyber-Resilient Infrastructure

According to a recent study by ESG Research of more than 300 IT and line of business executives, two out of five respondents reported that their organizations had experienced successful ransomware attacks. Even more startling is the fact that more than 80% had paid ransoms to retrieve their data.

And the data landscape is changing, with exponential growth in unstructured data that is at the core of digital transformation, AI and machine learning initiatives. This “new” data is what is driving businesses forward. It has unique requirements, must be kept for many years and decades, layering on new challenges around cyber-security and protection of this valuable data.

In 2022 and beyond, enterprises will shift more focus and investment toward building cyber-resilient infrastructure for this type of data – in other words building infrastructure with cyber-security in mind. Tape storage systems are a critical part of these cyber-resilient infrastructures, particularly for long term data storage. The world’s largest cloud providers now use tape at massive scale in their data centers, and enterprises are quickly adopting a similar approach. This is a new way to use tape, not the old paradigm – with both the use cases and architectures looking fundamentally different. Over the next few years, every enterprise and every organization that is generating large amounts of data will need to leverage these same architectures and practices.



The Priority Gap: When Patchability Does Not Equal Protection

Vulnerability management often fails at the point where security mandates collide with IT operations, creating a Priority Gap between vulne...