The Backup Wrap-Up

Disk Backup Security - Disk Make Things Worse?


Listen Later

Disk backup security is the weak link that ransomware attackers exploit every day—and most backup admins don't even realize it. In this episode, Curtis and Prasanna examine how the move from tape to disk-based backups created an unintended security gap that threat actors now target as their first priority.

The transition to disk brought real benefits: deduplication made storage affordable, replication eliminated the "man in a van" for offsite copies, and backup verification became practical. But disk backup security wasn't part of the original architecture. When backups lived on tape, physical access was required to destroy them. Disk backups sitting in E:\backups can be wiped out with a single command.

Threat actors figured this out fast. After gaining initial access, the first thing they do is identify and eliminate your backups. No backups means no recovery—which means you pay the ransom.

Curtis and Prasanna discuss the history of how we got here, why backups are now the number one target, and practical solutions including obfuscation, getting backups out of user space, and implementing truly immutable storage. The standard is simple: if you can't delete the backups, they can't delete the backups.

TIMESTAMPS:

0:00 - Episode intro

1:24 - Welcome & introductions

4:04 - Tape explained for the modern audience

9:07 - Why tape got faster (and problematic)

10:54 - The shoe-shining problem

12:27 - Deduplication changes everything

15:35 - Benefits of disk-based backup

20:29 - THE PROBLEM: RM -r / DEL .

23:43 - Backups are the #1 ransomware target

26:26 - Immutability as the solution

27:32 - Book: Learning Ransomware Response & Recovery

...more
View all episodesView all episodes
Download on the App Store

The Backup Wrap-UpBy W. Curtis Preston (Mr. Backup)

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

26 ratings


More shows like The Backup Wrap-Up

View all
The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

289 Listeners

Risky Business by Patrick Gray

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

649 Listeners

Tech Talks Daily by Neil C. Hughes

Tech Talks Daily

201 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,031 Listeners

Smashing Security by Graham Cluley

Smashing Security

322 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,109 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

177 Listeners

Hacking Humans by N2K Networks

Hacking Humans

316 Listeners

Random but Memorable by 1Password

Random but Memorable

71 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

207 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners

The Rest Is Classified by Goalhanger

The Rest Is Classified

1,289 Listeners