Cloud complexities and the cyber resilience conundrum

    By Ian Wood, Senior Director Systems Engineering at Commvault

    The cloud vs on-prem debate has been won and there is a clear winner. Today’s enterprises are cloud-first – as many as 85% of applications used by businesses are expected to be SaaS-based by the end of this year.

    Driving this is the phenomenal increase in data generated by IoT and, more recently, AI. Uptake of AI has arguably been faster than initially anticipated, currently growing at an exponential rate, and requiring massive bandwidth to accommodate its processing and storage requirements.

    Plus, increasing AI governance is likely to require data retention on a larger scale. Organisations will need to demonstrate how decisions were made using AI and keep relevant data securely for transparency. This will create yet more data storage, for longer timescales, as the outputs from AI models are likely to be scrutinised for many years to come.

    These escalating demands require huge scalability and computational power; resources that hyperscalers like AWS and Azure are ready to deliver in abundance. However, while offering compelling cost efficiencies, scalability, and quick deployment, the administration and security concerns associated with public clouds can be difficult to manage.

    Security gaps across multiple clouds

    Navigating cloud-native environments, understanding where sensitive data resides, and ensuring robust security measures are in place across hundreds of technology stacks, has proven challenging.

    Managing constantly changing and expanding workloads across multiple cloud providers requires in depth expertise, not readily available in every IT team. As hyperscalers operate security differently, each with their own set of proprietary tools and multiple layering of protection, reliable and consistent security enforcement is highly complex.

    A recent survey sums up the widespread concern, with 86% of global CIOs saying that the explosion of data due to cloud-native stacks is impossible for humans to manage. Ultimately, the responsibility lies with the customer to properly configure, monitor, secure, and back up their cloud workloads. It is possible to leverage the deep domain expertise of security platform providers who offer reliable, consolidated monitoring and protection designed for multiple cloud technologies, hybrid, and on-premises environments. However, with so much critical data at risk, organisations must ensure they set out comprehensive and well-established recovery procedures themselves to ensure continuous business.

    Planning for reliable cyber resilience

     

    As a first step, it’s vital organisations acknowledge that preparing for cyberattacks and recovery is not the same as traditional disaster recovery planning for accidental deletion, or failures caused by hardware problems, power outages, or natural disasters. In these scenarios, restoration of clean backup copies is relatively straightforward.

    Recovery from a cyberattack is typically more onerous and potentially dangerous, especially in the case of ransomware which, if not isolated effectively, may re-infect restored copies and backups.

    A comprehensive cyber recovery plan covering the following points will help ensure recovery of both clean data and applications, and minimise downtime:

    • A cyber resilience plan. Have a specific plan for cyber recovery that’s supported by business leaders.
    • Definition of the MVC. Understand what constitutes the minimum viable company (MVC) which must be operational after an incident. Accept that everything cannot be rebuilt immediately and define essentials.
    • Tools at the ready. Ensure the right remediation tools and backup processes are already in place, including air-gapped and immutable copies for recovery. 
    • Test rigorously. Not just tabletop testing, but regular real-world testing and red teaming. If there are only minutes to meltdown, teams need to be able to respond effectively under pressure.
    • A cleanroom. Ensure this capability is part of your chosen security platform for clean and stress-free restoration of data and applications in a new uncontaminated, on-demand cloud environment, eliminating the bane of malware/ransomware re-infection.

       

      Recovering cloud applications

       

      Remember data recovery is only part of the conundrum and rebuilding applications is often the most time-consuming and complex element, especially if done manually. Typically, organisations tend to be practiced at restoring data quickly, but longer downtime occurs if applications need repairing.

       

      Fortunately, advanced security platforms now have automated and AI-powered options that can facilitate this reconstruction process. Vital cloud applications can be up and running quickly as part of an automated cleanroom recovery process in hours or minutes, instead of days or weeks. The ability to recover directly from cloud environments also streamlines recovery and keeps costs low as cleanrooms can be launched on demand, then closed as soon as recovery or testing is completed. In this way, organisations only pay for what they use.  

       

      With rapidly increasing volumes of AI and IoT data and applications to manage, having the capability to recover what matters quickly should be a tried-and-tested component of every cloud-first strategy. Being confident in the efficacy of the cyber resilience plan relies on sufficient investment in time, tools, and training; none of which organisations should neglect, unless they have complete immunity from cyberattacks and impenetrable cyber defences – almost impossible in today’s volatile and unpredictable threat landscape.