Why cyber resilience now depends on recovery

cyber resilience and recovery

From the moment GenAI burst onto the scene fewer than four years ago, the cybersecurity industry was placed in a very challenging position. Indeed, few other sectors were required to consider how the same technology could simultaneously offer such significant pros and cons.

Many of the subsequent predictions have since come to pass, with vendors and government authorities alike first responding to the opportunities and risks presented by highly capable LLMs before having to turn their attention to the new and unprecedented challenges posed by agentic AI.

If the tactics used by threat actors were plotted on a maturity curve, that ecosystem has moved from AI experimentation to industrial-scale implementation and highly nuanced strategies. For example, attacks increasingly incorporate measures designed to compromise systems and frustrate recovery. This is all about leverage and creating a criminal version of competitive advantage, where every element of an attack is designed to maximise pressure on the victim and improve the chances of achieving the desired outcome.

Novel problems need novel solutions

This situation has raised the stakes for those responsible for data protection and backup. Safeguarding data so it remains available and recoverable has become equally important as stopping threat actors from breaching defences in the first place. As a result, storage and backup strategies are increasingly being designed to withstand deliberate attempts to compromise or deny access to critical data.

To put this in context, traditional backup strategies were designed to protect against unintentional data loss rather than deliberate attempts to deny access to critical data. But now, connected backup environments can be compromised alongside production systems if they remain accessible to attackers. Cyber resilience, therefore, depends on creating backup copies and ensuring that at least one remains available for recovery after a successful attack.

Until recently, a 3-2-1 backup strategy – based on maintaining three copies of data across two different types of storage media, with one copy stored off-site to reduce the risk of a single point of failure – was seen as a tried-and-trusted approach. Today, of course, organisations have implemented highly connected IT environments, meaning in theory, immutable copies can still be accessible if they remain connected to compromised infrastructure.

In response, the 3-2-1-1-0 framework has emerged, which maintains one copy of data completely offline and physically separated from the network. It also introduces the principle of zero backup errors, recognising that recovery depends on the integrity of the data being restored. Modern backup strategy therefore considers both the number of copies held and the confidence that at least one will remain available when every other layer of defence has failed.

Matching storage technologies to recovery needs

Physically separating storage from the network, or air-gapping, works on the basis that it cannot be reached by attackers, even if they have compromised the wider IT environment. This provides an additional layer of protection against ransomware campaigns, for example, that deliberately target backup environments. By definition, this helps preserve a known-good copy that can be relied upon during recovery.

One of the key questions to ask when designing these environments is which storage technologies are best suited to delivering a genuine physical air gap. As with any storage use case, different technologies offer different advantages, making it important to understand the role each is expected to perform.

For the 3-2-1-1-0 framework, tape storage is inherently well-suited to creating a physical air gap because data stored on tape is not directly accessible over the network. Yes, other storage technologies can also support offline strategies, but they typically require additional controls to achieve equivalent isolation.

Tape complements disk and cloud storage, with each technology serving a different purpose within the overall backup strategy. For many organisations, it has become a practical component of a broader cyber resilience strategy, reflecting the value of maintaining an offline recovery capability.

This also represents the need for a mindset shift, in which cyber resilience is viewed as an ongoing capability rather than a point-in-time technology decision. Backup strategies should be reviewed against today’s threat landscape rather than the assumptions on which they were originally designed. As part of this approach, recovery testing is just as important as creating backup copies because organisations need confidence that data can be restored when required.

Ultimately, the effectiveness of any backup strategy depends on whether it enables recovery under real attack conditions. As long as recovery remains possible, even after a successful cyber attack, organisations can strike an effective balance between protection and resilience.

Andrew Dodd, HPE Storage Tape Worldwide Marketing Communications Manager, the LTO Program

Andrew Dodd

Andrew Dodd is HPE Storage Tape Worldwide Marketing Communications Manager, the LTO Program.

Author

Scroll to Top

SUBSCRIBE

SUBSCRIBE