๐ Cyber-resilience Insights: Prework & Recovery are the linchpin. Organizations are ramping up their cyber-resilience efforts by investing in automation, to help facilitate their modern backup infrastructure. I’ve seen firsthand that prioritized recovery planning and understanding application architecture are game-changers. Verification and analysis of recovered data are critical; collaboration between IT ops and security is non-negotiable.
Here’s what I’ve learned: Automation when utilized and not mired with maintenance, or mismanagement is a game-changer. Automating core systems for recovery, selecting the right destination, restoring services, and even verification can assist or at times fully mitigate risks.
๐ช Recovering critical business functions to designated locations is a rising trend.๐
๐จโ๐ป Paying ransoms isn’t the answer, so let’s be prepared! Let’s embrace a structured approach for a cyber-resilient future!๐
Gartner has a fantastic write-up on this minus the Automation perspective that will talk you through their Ransomware Recovery Guidance Framework.
๐ง๐ต๐ฒ ๐ด๐๐ถ๐ฑ๐ฎ๐ป๐ฐ๐ฒ ๐ณ๐ฟ๐ฎ๐บ๐ฒ๐๐ผ๐ฟ๐ธ ๐๐๐ฎ๐ด๐ฒ๐ ๐ฎ๐ฟ๐ฒ ๐ฎ๐ ๐ณ๐ผ๐น๐น๐ผ๐๐:
Prework.ย This stage includes everything necessary to begin recovery. Prework consists of two separate phases. The first is a planning phase that takes place before an attack. In this phase, you develop and establish the plan for ransomware recovery. The second phase starts when an attack is underway and continues until it has been contained. Recovery cannot begin until the attack has been contained.
๐ฆ๐๐ฎ๐ด๐ฒ 1: Recovery type and destination.ย Analyze backupย data to determine the type of recovery method that will be used and where data will be restoredย to.
๐ฆ๐๐ฎ๐ด๐ฒ 2: Recovery of data and services.ย Prioritize mission-critical applications and dependencies while using all available advanced options and adhering to the best practices of the backup platform.
๐ฆ๐๐ฎ๐ด๐ฒ 3: Recovery verification.ย Confirm that recovery of data and services has been completed and ensure the environment is ready to be brought back online.
๐ฆ๐๐ฎ๐ด๐ฒ 4:ย Productionย integration.ย Outline the process of reintegrating recovered data and services into production environments, so that business as usual can resume.
#Cyberresilience #Ransomware #Automation #ITInsights
๐ก๐ผ๐๐ถ๐ฐ๐ฒ: The views expressed in this post are my own. The views within any of my posts, or articles are not those of my employer or the employers of any contributing experts. ๐๐ถ๐ธ๐ฒ ๐ this post? Click ๐๐ต๐ฒ ๐ฏ๐ฒ๐น๐น icon ๐ for more!