• Nougat@fedia.io
    link
    fedilink
    arrow-up
    28
    ·
    3 days ago

    Tell me you don’t have a viable backup strategy without saying you don’t have a viable backup strategy.

    • LongLive@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 days ago

      What does a viable backup strategy look like in the modern day? How difficult is it to build and maintain it?

      • Nougat@fedia.io
        link
        fedilink
        arrow-up
        10
        ·
        3 days ago

        Depends on the needs of the business, of course, but –

        There are lots of different ways to make data rollback robust, and as many methods as possible will offer different avenues to recovery. VM snapshots (with or without live mounting), shadow copies, incremental forever, cloud storage for backups, multiple appliances in different physical locations.

        None of these are terribly “difficult.” What tends to make these kinds of efforts less effective is a failure to regularly test them. Can I recover a VM snapshot? Can I live mount it somewhere? Sure, the product I’m using says I can, but have I proved it, and do I still remember how to do it quickly and correctly in the middle of a crisis?

        • IHawkMike@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          3 days ago

          Nothing you said is wrong, in fact it’s all good advice. But none of what you listed implicitly provides protection against ransomware either.

          For that you need backups that are immutable. That is, even you as the admin cannot alter, encrypt, or delete them because your threat model should assume full admin account compromise. There are several onprem solutions for it and most of the cloud providers offer immutable storage now too.

          And at the very least, remove AD SSO from your backup software admin portals (and hypervisors); make your admins use a password safe.

          • Nougat@fedia.io
            link
            fedilink
            arrow-up
            4
            ·
            3 days ago

            You’re right, I forgot about that. Our backups require three people’s signoff to delete. Alter and encrypt I’m sure are the same, we’ve just never needed to do that as far as I’m aware.

  • HappyStarDiaz@real.lemmy.fan
    link
    fedilink
    English
    arrow-up
    5
    ·
    3 days ago

    I worked for Lee Enterprises pre bankruptcy and there was near zero viable anything then; can’t imagine near twenty years later how bad it is now.

  • Coolbeanschilly@lemmy.ca
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    3 days ago

    What I’m more concerned about is who the people performing the attacks are, and why the press itself isn’t attempting to expose them, and are instead sanitizing the attacks.