
In our previous episode, we took a look at number nine on our #TOPcyber21 cybersecurity best practices matrix: Email and Phishing Protection. With the help of our cast of cyber experts from Inky, IronScales, Red Sift, and TBI, we discussed the many aspects of this critical risk vector, prevention tools, and best practices to further protect from devastating compromises like ransomware.
As we reach the halfway point of our “Who’s In Your Cloud?” series today, we will be focusing on Cloud SaaS Backup. Losing business data stored on online tools results in costly and timely delays that ultimately devastate your business- and this can all be avoided with the help of Cloud SaaS Backup. Find out how this solution helps guard your SaaS applications’ data from threats such as accidental deletion or ransomware here in episode 10. We’ll also hear from our partners as they discuss their available solutions to ensure protection, regulate compliance and improve data visibility for your cloud application data. We’re thankful to our cyber expert cast joining us today from ConnectWise and Datto as they help us educate our clients and prospects on the road to #secure, reliable, trusted technology!
As a reminder, we began releasing a new episode every Tuesday, starting 10/20/21, and will continue to do so through late spring of 2022, with brief time off for holidays with family and friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational, and enjoyable experience. So how do you tune in?
To easily follow the journey ahead, we’ve diversified your access options to all (23) of our coming episodes. You can follow along here on our blog or by any of the following methods:
- Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
- LinkedIn: follow here
- YouTube: follow here
- Facebook: follow here
- Podcast: follow here
Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!
Read Transcript
Hello, hello and welcome back to “Who’s In Your Cloud?” 21 steps to Secure, Reliable, Trusted Technology and thank you for joining us today. I’m Lauren Lev, Marketing Manager for TechOnPurpose and the most entertaining host of our blog series. Today, we’ll be discussing cloud SaaS backup and how this solution helps guard your SaaS applications’ data from threats such as ransomware or accidental deletion, and what solutions are available to you to avoid a devastating data loss. Last week, we had one of our best episodes yet focusing on email and phishing protection. View all of our episodes of this series on LinkedIn, Facebook, YouTube, or Spotify. And sign up for our blog at TechOnPurpose.net/blog to get all episodes delivered straight to your inbox. Today’s episode brings us halfway through our series and through our Cybersecurity Best Practices Matrix. Matt, can you believe it, like halfway it’s been crazy.
Matt Tankersley
Man, it’s been quite a journey. And hopefully the next half will be even better for everybody.
Lauren Lev
Absolutely. All right, well on deck for today is TOPcyber21 practice number 10, cloud SaaS backup. We’ll be discussing its importance, associated risks and solutions. Datto is joining us today and we’ll hear about how their solutions ensure protection, regulatory compliance and improve data visibility for your cloud application data. If you’re like me back in the day, you know what the sheer core and regret feels like when you realize that you just injected that floppy disk before saving the final copy of your term paper hours before it was due. I’m very guilty. There were a lot of tears that day. Fast forward to a few years and having my iPhone stolen and not having a recent backup. You’ve never seen a meltdown until you’ve witnessed a 16 year old at the Geek Squad counter being told there’s nothing they can do since your latest device backup was from over a year ago. I was so guilty and I paid the price. So apparently I’m a really slow learner, but I finally got it, mostly thanks to automated backups. But myself and backup technology has caught up with the times. Today we’re going to discuss how SaaS backup solutions help guard your SaaS applications data from threats such as ransomware or accidental deletion. Before we get into all of that, let’s meet our cast for today. We have a VIP cast member joining us, which is Vice President of Global Security Sales from ConnectWise Jay Ryerse. It’s been so long since you’ve joined us on the blog, but we’re happy to have you back.
Jay Ryerse
Oh, thanks, Lauren. I’m very excited to be here and to spend some time with Jason and Matt as well. But you are the hostess with the mostest so-
Lauren Lev
I like to think so.
Jay Ryerse
Really glad to be here today.
Lauren Lev
Thanks, Jay. All right. We have another cast member joining us today from Datto, it is their Channel Development Manager, Jason Pryce. Jason, thanks for coming. We’re happy to have you.
Jason Pryce
I’m happy to be here. Thanks for having me. I’m happy to be on a panel with such esteemed people. You definitely took my- what I had planned to say with the hostess with the mostest. So, I’m sure I’ll come up with something better than that. You know, before the end of this blog happens so-
Lauren Lev
Good, I look forward to it. I like all this, you know, positive affirmation. It’s great for my ego. All right. And we have of course TechOnPurpose’s Founder and CEO, Matt Tankersley. Alright, Matt, take it away. What does our audience need to know right out the gate about cloud SaaS backup?
Matt Tankersley
Well, welcome back, everybody. And again, Happy New Year, if you haven’t heard that enough times from enough people. But, we’re a smaller cast today, a lot of people are traveling this week and we’re honored to have everybody here from ConnectWise and Datto as well. Two of our more strategic partners and all of what we do, in particular cybersecurity related to cloud SaaS backup, so I think it’ll be a quick episode today. For those listeners who are used to the 2x speed playback of our 40 and 50 minute episodes, maybe this will move a little quicker for you. Let’s set the stage with you know a few statistics I think that hit home on this best practice. And then Lauren, let’s in usual fashion, let’s pass it around the room and learn more about our two guests, at least for the audience that don’t know them and the companies that they represent. And then we’ll jump into our usual round of conversation about what’s the issue that dictates or warrants a need for SaaS cloud backup. And then we’ll kick it back and hear about some specific solutions, particularly from our friends at Datto today. So, thanks for being here, guys. Alright, so some stats: 47% of users reported that data in their SaaS applications is somewhat important, but 42% say it’s critical to their day-to-day operations. So I’m not sure where our viewing audience is on that front, but I know that we can’t do anything without our cloud today. And my guess is a vast majority of our data is certainly critical to us and probably to most of our clients. Looks like 30% of people have never backed up files to a separate location other than their computer, which is an interesting problem. So what happens if that computer is lost, stolen, damaged or compromised? That’s a problem, right? I see that we actually now have a day dedicated to this. World Backup Day is March 31st. And that’s the global marketplace, basically saying this is so important, we need to at least make sure that folks are hearing about it from all of us at least one day a year, why this is needed, why it’s so important, and how to easily get underway. So listen, losing your personal data- Lauren, you talked about that early on, that’s bad enough. Losing your business data stored and your online tools can result in costly and timely delays that ultimately devastate your business. Right? This is bad stuff. So, all of it can be prevented by simply utilizing the many cloud SaaS backup solutions that are in the marketplace. And so, let’s not take my word for that and let’s hear from our cast today. Lauren, let’s get everybody introduced and learn a little bit more about them.
Lauren Lev
Perfect, happy to. Alright, so we’ll have both of you introduce yourself and tell us more about your background and your company before moving on to round table question number one. We’ll get more into it. Okay, so Jay, as our VIP cast member, you’re up first. Tell us about yourself and your role at ConnectWise?
Jay Ryerse
Sure, thanks, Lauren. So, I am VP of Global Security Sales. So, I match our teams that work with our partners in the community on solving for cybersecurity issues, of which you know, backups, ability to respond and recover are part of them. ConnectWise is the world’s leading software company dedicated to the success of IT solution providers. And we provide solutions that Matt and Lauren and their team use to help deliver services efficiently and effectively, you know, to their clients, because there’s not enough of us to go around humans, we’ve got to throw some technology at it. My background comes from working with small businesses on cybersecurity related issues. I have worked my way up into this global role I have today, really just helping solve the challenges that our partners and their clients are facing when it comes to all things cybersecurity. I am a CISSP, Certified Information Systems Security Professional, which you don’t usually find on the sales side of the conversation. So, I tend to bring a certain amount of levity to the conversation to help make sure we’re thinking about the right things and not just throwing out products and problems when there are better solutions than just technology. Which, you know, we’ve sort of seen with backups in this world. Now, we talked about SaaS and let’s make sure we all know what that is. Right? That’s software as a service. And in this case, it’s how you deliver backups to the cloud and as a service. Now, that you guys get. Not everybody knows what that means and where it fits in the conversation. I guess I’m gonna rather than open up with a fun conversation, I’m gonna do what I like to do, which is I’m gonna go dark for a moment. I’ll tell you guys about a law firm in the Atlanta area that was hit by a cyber attack on the Friday night before Christmas back in 2016. So I’m going back a little bit, but the story is relevant. The attackers we found out afterwards had been in the network for over 300 days. When they finally decided it was time to launch their ransomware attack, this law firm didn’t have the right protections in place and they’re on-site backups had been compromised. Meaning, the attackers got the admin password for the network and they were able to log into the backup systems. And if you’re all technical, this is going to make you cringe. They literally went into the backup routines. They unchecked all the data folders. So they’re only backing up the routine Windows files. The ones you get on CD when you buy a new computer, right, now nothing more than that. And nobody noticed. You know, no triggers, no alarms, no Hey, someone checking these? Nobody was testing the backups for restore capability on a regular basis. Just a lot of things went wrong in their processes that allowed the attackers to literally wait 91 days from when they made that change because they only had a 90 day retention period on the backups. So they’re only keeping 90 days, so on day 91, they knew that the IT team had not figured out there was a problem. They were able to launch their attack, and they encrypted 89 of the 140 workstations and 43 servers.
Matt Tankersley
Wow.
Jay Ryerse
There was no cloud backup. Nothing that was backed up previously ever went to the cloud. And basically, this law firm was forced, in order to stay in business, we’ll go ahead and pay the ransom payments. Now, it wasn’t a pretty sight. Even once they got the key, it took weeks to get them back up and online because the decryption process and then that cleaning process and rebuilding their network, it just takes so much more than you ever imagined. I’m sure you can picture if you’re a lawyer, if you’re an attorney, you can think about your office. What would happen if you had no computers and no data for weeks on end at the end of the year? You know, what would that mean to your business? And look, it’s not always that bad, right? You can say, well, Jay, I’m a five user, you know, accounting firm, and we backup our QuickBooks to a USB drive. Well, there’s so much more that needs to go on in that conversation, which I think is why we’re here today. And ultimately, from the CISSP side of me, look, your ability to recover is your ability to survive an attack. An attack could be a cyber attack, it could be hardware failure, it could be your cloud provider. Some solutions out there- there was one in Texas that happened a few years ago, they were hosting QuickBooks for 126,000 businesses and they got hit by a cyber attack and they never recovered. So 126,000 businesses lost their QuickBooks files like that, and had no idea why or how that could possibly happen. So backups are a critical part of all things we do in technology. But it really does start with you having that plan and that approach in place. I think today’s conversation might actually be the most important one of the 21 that we’re going to talk about, when you’re thinking about 2022 and how you’re going to really run your business going forward.
Lauren Lev
That’s certainly more devastating than my floppy disk paper term paper fiasco.
Matt Tankersley
Little bit different. Alright, so before we pass it over to Jason, let me say a couple of things. First off, I am afraid you told that story and I cringed about the lost QuickBooks data. I actually think one of our clients was one of the people that was using that company. And they lost three years of QuickBooks data and spent the next 18 months rebuilding from receipts and hand copies of invoices their entire accounting system. It was an absolute nightmare. I can’t imagine what the cost of the expense of that was.
Jay Ryerse
Yeah, you know, Matt, it’s funny. We’ll cover this, I’m sure, but I’m jumping into it now. Knowing where your assets are, are one of the first things you have to assess when it comes to determining your backup system. Like, you know, hey, I got my computers, but you know, those cloud providers and where are they backing up? How often? How will I recover? What’s that going to look like to me? It’s part of that risk assessment that every business needs to be doing on a regular basis, you know, trying to understand what the impact would be to their business.
Matt Tankersley
I agree. And let me give you guys two plugs real quickly and then I want to hear from our friends at Datto because we love this product as well. And so, we actually use your Identify platform to do cyber risk assessments for our clients. We love that platform. And we encourage everybody from the beginning of this campaign to the end, visit WhosInYour.Cloud and get your free risk assessment from TechOnPurpose. And it’s the ConnectWise platform we use that enables us to do that. And we also use- we’ve obviously talked about a lot of things, but we’re in Episode 10 or 11 now I think it is, we’re going to talk about 10 or 11 more. A lot of the things on our portfolio come from your team, one of those is Perch SIEM, right. And we actually got a call, I think it was New Year’s Eve that we had a device that had been compromised by this log4J thing. And here’s the good news, all of our cyber portfolio stack that we have implemented did nothing- it did everything it could to protect that and nothing was affected other than that device got compromised, but it couldn’t get to anything, it couldn’t do anything, it couldn’t execute anything. But based on that great product from your team, we were able to quickly identify that, isolate that, recreate that server in a more secure and safe manner. And the interesting- Yeah, we had that. We had just done an update to solve that based on the vendor solution. So it’s ironic that we still had that exploit occur, but zero impact, knocking on wood obviously for that. Well, I guess one final thought before we go over just rehashing some of our data because you said it right. You said that the malicious actor was present in the environment for 300 days before that happened. Well, we know, right, based on industry data that the average malicious actor is present in an environment 287 days before they’re identified, so that one went on a little bit longer. And it’s all of those things that compel us to create this structured approach to cybersecurity 1-21 to make sure that that sort of thing is not happening. And if you look at Episode Two as an example of Dark Web Monitoring, right? If we know credentials are compromised, the moment that they’re showing up on the dark web we can be doing things to reset those passwords. So, they can try to be in there for 387 days, but it’s gonna be pointless because the passwords changed. So there’s a method to all this crazy madness. And we thank you all for listening. And Jay, great contributions and great partnership, thank you. Lauren, let’s hear from Jason about Datto. What is, you know, who is Datto and what does he do at Datto? And then we’ll jump into round two of talking about, you know, what we’re doing specifically to solve this problem for clients.
Jason Pryce
Yes, awesome. So once again, Jason Pryce, Channel Development Manager at Datto. My job, my role is to not educate, not only educate our partners, such as you guys over TechOnPurpose, but also educate their clients and their prospects and their end users. Because we need everybody to be on board with what’s happening in terms of this technology, landscape, right? It’s always changing, it’s always evolving. And you know, our job is just to make sure that everybody’s making good decisions on a daily basis, that’s going to make sure that their, you know, their cybersecurity integrity is good. I’ve been at Datto for about eight years now. I came here actually from Geek Squad. So you were probably talking to one of my agents back in the day, and they’re the ones that gave you the bad news back in the day.
Lauren Lev
Yeah, y’all made me cry.
Jason Pryce
So, I’m sorry, I do apologize about that.
Lauren Lev
Well I made myself cry.
Jason Pryce
But hopefully we gave you a shoulder to cry on. Right. So that’s all that matters, right, at the end of the day that we were there to support you in that moment. And I went from there to join the support organization at Datto. I was in a support organization for a couple of years and then moved into more of a facilitating role and then more into the role I’m in now where it’s more so education, more so just letting people know what’s out there. Unfortunately, Jay he’s one upping me because I do not have a CISSP, whatever it’s called, you know. So you know, I’ve been working with Nelson Nixon on this call, I can, I can hopefully show him up. But you know, I’m just happy to be here. In terms of Datto, what we do is, we are a company that really provides tons of different tools for our service providers, to be able to not only protect their clients, networks, and infrastructure, but also be able to help with efficiencies within those organizations as well. We are a company that was founded in 2007, in Norwalk, Connecticut, so one of the most, you know, inconspicuous places for a big tech startup to start. And, you know, fast forward a couple of years later, we have over 2000 employees worldwide, we have over 24 offices around the world, we have US base support. So anytime that there’s any sort of issue or anything of that nature, we want to make sure that we’re able to communicate with you. And there’s no sort of barriers that are in the way of making us take care or helping us to take care of you. But yeah, that’s who I am and that’s who Datto is.
Matt Tankersley
Awesome. Well, Lauren, where do you want to go from here? Do we want to talk about the issue? Or have we already done that? You tell me.
Lauren Lev
Does anybody feel like they have any more to add about the issue?
Jason Pryce
I’ll talk a little bit more about the issue quickly. Yeah, so one of the- I mean, when it comes to protecting your data, more people are getting more on board with, okay, yes, I need to make sure that all my data on the servers are good, that their data in the workstation is good, even my data on my iPhone is being backed up. One of the things that people are just now kind of realizing is that they need to make sure that their SaaS data, as it pertains to Microsoft Office or Google Workspace, that data is also being backed up in a secure environment, you know, in the need that something is compromised. Whether it be, as you stated before, ransomware or something like accidental deletion or intentional deletion, that data is there for you to retrieve and be utilized in a quick fashion. So I think it’s really important to understand that when you look at Microsoft, and you look at Google, right, we think that these companies are just, you know, impenetrable, right? They are- they have iron gates, right. But these companies operate on what’s called a shared responsibility model. So, as it pertains to the data that you have in your Outlook or your OneDrive and things of that nature, they’re going to make sure that their infrastructure is up to par, right? They’re gonna make sure that they have enough servers, that the workload is distributed evenly, they’re going to make sure that they have levels of redundancy. From a power standpoint, they’re going to make sure that the facilities are cooled correctly. All of those things are things that they are going to make sure that happens. The thing that you have to make sure that is good is that you have to make sure that the data that’s in there is secure, right? So if something happens, where you get ransomware, unfortunately, that’s a “you” problem. That’s not a Microsoft problem. If something happened, where there is a connectivity issue, right, that’s a Microsoft problem, but it does impact you, right, because you can’t get access to your data, right? And so, you have to just keep that in mind that these companies aren’t bulletproof. These companies, they actually recommend that you have a third party backup solution to make sure that you are taking care of your data and have it securely in another location.
Jay Ryerse
I’m gonna add to that because Jason is absolutely right. That shared responsibility is a challenge that when business owners, small business owners, medium business owners in enterprise, buy something from Microsoft, doesn’t Microsoft back it up? Isn’t that their job? And they don’t realize it till it’s too late that that wasn’t the case. But now, let me pivot a little bit, let’s make sure we frame this conversation well. So when we think of backups, there’s actually three areas that we have to talk about in the conversation. The first one is a philosophy and it’s called 321: at least three copies of my data in at least two locations, plus I want one offline. Okay, so a local copy where you can run locally, you know, using Datto products and Acronis products, other products that are out there are fantastic. And then they’ve got a cloud option where you can run it in the cloud and you can backup the cloud. But the security guy in me is like you remember when, maybe I’m dating myself here now too Lauren, remember when we used to have tape drives. And okay, now, you might know this, we would have this process in place where the client would take a tape home every Friday. Now, sometimes they put- they went to the bank and put them in a safety deposit box, which was good. Most of the time they got left in a box in the trunk of a car and hopefully never got stolen. But that offline copy helps you prevent a cyber intruder getting to your backups and encrypting them, like half of that law firm I mentioned. It also helps you in the event of a fire, flood or some sort of other natural disaster, where you’ve always got one more option to bring data back. Maybe it’s not every single day or every 15 minutes where you’re backing up, maybe it’s once a month you take that off site. So 321 has to become part of our terminology in the way that we work with our conversations. The next thing we look at in backups, and Jason probably could speak better to this than I will, but the concept is simple. It’s RTO and RPO. So RTO is: recovery time objective. How long will it take and how long is the business willing to wait to have their data restored? Obviously, a local copy you can probably restore back faster than a cloud copy, probably faster than an offline copy. There’s things that have to happen to make all those functions, the people and the processes have to execute well. But understanding, Hey, you know, look, if we’re down for four hours, my business will be okay. I don’t want to be out for four hours, but I can live with that. Some businesses will tell you, Hey, if I only have to go back a week, that’s fine. And your cost for managing recovery time is baked into those pricing and in a SaaS solution. The other side of the coin is what we call RPO. The recovery point objective. How old can the data be? See, it might be that I can wait two days to get my data as long as when you bring it back, it’s within 15 minutes of that outage. Or it might be, Hey, I need you to get it back faster, but if it’s six hours old that’s going to be okay. Yeah, I can reload some invoices and process that data. And every business is different and they have to measure and assess that risk. And really kind of sit back in that chair and think about how many users in our company wouldn’t be able to function. And we always know sales can still jump on calls and their cell phones, they’ll be okay, but everybody else we have to worry about. And is that production line going to be an issue? Can I deliver food orders in the restaurant? Right? If I’m a bank, you know, how am I going to process transactions? Am I going to close the branch until they’re back online and what do these things look like for you? So 321 philosophy, recovery point objective and recovery time objectives are relevant when you’re looking at any type of backup planning.
Jason Pryce
I would add one thing to that, right. So when you talk about RTO and RPO, I like to think about it as a measure of your threshold for pain, right? And so, if you have a good, you know, if you have a good threshold for pain, you can be further away from, you know, having the immediate result, right, having a 15 minute old backup and having the ability to be up and running, you know, within 15 minutes. If you have a, you know, a low threshold of pain, man, you’re typically going to have to invest more into the solution to make sure that you can get back in a reasonable amount of time, essentially.
Matt Tankersley
This is awesome. This is why we have a diverse cast, guys. And if you come back to it, there’s your CISSP answer, right, RTO and RPO. I’m gonna throw some acronyms at you. And the reality is the diversity of our team. You nailed it, what’s your pain threshold? Because that’s what those two things basically tell you. I love that.
Jay Ryerse
And in addition, Matt, because you talk about assessments. You know, during the assessment process is really to help establish what the risk tolerance is, right? And every business is different. I mean, look, I might be willing to forego a few days of the data. But you know, it doesn’t hurt me as a CEO, right. But your team might be like, that’d be horrible, right? So you’re gonna go find those things out in the process. And when you can establish risk tolerance for data loss, everything else in building out a SaaS plan is easy.
Matt Tankersley
Well, and if you think about it, we haven’t even begun to scratch the surface on the considerations that that can of worms just opened that you have to go through. And the reality is, if you’re that small tax office or some other company, you don’t want to learn these new acronyms, you don’t have it. And that’s what TechOnPurpose is here for guys, because we’re gonna guide you and get you simply to where your data is protected, it’s recoverable. I want us for when we come back around in round two, I want to talk about the importance of retention periods, because that was an important part of what you did, right? When you were talking about your compromise, they didn’t have more than 90 days. One of the things I love about our friends at Datto is they have an infinite cloud retention plan. And they are doing multiple backups multiple times a day of this cloud data. And we have nice acronyms for all of those things as well. But what that translates to is we can mitigate your pain threshold by making sure that we have multiple copies available for an infinite period of time so that we can get you back to that point. So man, what a great conversation. A smaller group works well, Lauren.
Lauren Lev
I know, this is great.
Matt Tankersley
It’s good stuff. Well, so we’ve talked a little bit about the issue. Let’s talk about some very specific solutions. And I say, you know, let’s talk about the Datto solution and your approach to providing this level of security that we’re talking about this level of recoverability. What’s Datto doing about that?
Jason Pryce
Yeah, so we’re doing so many things. So just to give a little backstory, right, so the first product that we ever launched was a continuity solution, right? The ability to backup your on-premise data to a Datto, a device or an appliance that lives on premise, and then be able to take that data and actually send it to the cloud. And that goes to what Jay was talking about and having data in multiple locations, one part of the 321 rule. We’ve evolved to not only be able to do that and do it very well, but to also be able to offer a backup of like Microsoft and Google SaaS data. It’s important to know that the number one attack vector, right, is Microsoft- I’m sorry, they just changed the name to Microsoft, it’s not 365 anymore, but it’s Microsoft.
Matt Tankersley
Yeah it is actually. Actually, they went from Office 365 to Microsoft 365.
Jason Pryce
Microsoft, yes. All right. There we go. All right. Yeah, so it’s like the number one, you know, attack vector, right. So if you look at the amount of phishing attempts, the scams, things of that nature, like 89% come through like your email. So it’s something that you want to make sure that not only you are securing, we do have products that help secure that environment, but more importantly, to be able to back it up, right? So security is always going to be first, right, you always want to do that first, right? Backup is always a thing you don’t want to have to go to, but you know you have it if you need it, right. So there’s different layers of protection that you need to make sure that you’re going to be safe and protected. But I think what we do well is not only the security side, but in terms of being able to backup that data, right? We’re backing it up multiple times a day, it’s going to our own private data center. So that’s always going to be a plus right? Something happened to Microsoft’s data center. Guess what, you’re in luck. We still have all your data, it’s still accessible, it’s still recoverable. You can still do exports or imports into other data centers, there’s so many things that you can do with it. And, you know, I think it’s important because you know, you think about how much business interactions on projects, things of that nature happen through Microsoft 365 or Google Workspace, right? A tremendous amount. And if you take a look at where we were prior to COVID versus post COVID, or I shouldn’t say post COVID, because it’s like I jinx it every single time I say that, right? So when we take a look at, like when COVID first started there was like a 700% increase in the amount of people that were going to Microsoft 365, right. 700%, right, because everybody now had to work remotely, they had to work, you know, from home. There’s different ways that they needed to figure out how to communicate with one another, whether it be utilizing like teams, or you know, something of that nature, different SharePoint, the connections that are happening, I mean, all these different things came into play. And all of a sudden, you have everybody really just filling into this room, that had that growth potential and that was supposed to grow over the next five years, but that seemed to have happened in six months, right? And so, it’s more important now than ever, to really make sure that that data is being protected in those environments. I remember when we first launched this product through an acquisition, this was about five years ago, we acquired a company named Backupify. And, you know, the CEO at the time must have been so forward thinking because inside, you know, we were like, Oh, this is stupid, like who’s gonna- Who needs to backup Microsoft data? Who needs to backup that? Like, it just seemed like a stupid thing. We didn’t say that publicly, we didn’t say that out loud and the CEO never heard us say that, right? But as we’ve seen over the last five years, the need for that has increased significantly, right. And so, you know, it’s awesome that we’re able to offer this product and give people that peace of mind to know that their data is safe and protected and can easily be accessed in the event of an emergency.
Matt Tankersley
So we’ve kicked this around the room a couple of times and we haven’t really drawn the lines of delineation. And I’m going to provide a little bit of focus for our conversation and perspective to a coming episode, right? We’ve kind of broken down our TOPcyber21 into two areas, right. And today, we’re talking about cloud SaaS backup primarily. And what’s awesome is you’re getting a little bit of a teaser on what’s coming down the pipe as we start talking about server backups and BCDR. Because that’s a critical component. Right? So let’s continue to feed that conversation to come and let’s try to focus on the cloud side of things today. What’s awesome about this is I don’t know that we have a client today that doesn’t use Google or Office 365, as a rule, right. And I’ll tell you that for all the right reasons, we don’t sell that service without a backup, like the ones we’re talking about here today, for all the right reasons. I literally just came from a lunch appointment with a tax accounting firm that wants to- they’re using a website hosted email to pop. I think that’s a scary word- pop. And they were wanting to talk to me about Cloud Storage. And that was my first question: what do you use for email? And this is the answer. And I go, Well, we’ve got a quick fix for you. And you know what I love too, encryptions. It’s worth saying things about encryption. One thing to keep in mind about these cloud backups, is they’re able to be encrypted in such a manner that Datto can’t see that data, that information, I as your manager service provider, I can’t see that information, and only you can. And hopefully, you have that decryption key someplace real safe where it doesn’t get lost. And that’s important, right? I had this guy ask me today, he says, Hey, can someone come to me? Can a court come to me and subpoena Microsoft and get copies of my data? Because apparently he’s seen where that happened at Google. Great question, so I think, you know, I actually don’t know the answer to that. I do know that my backup data they couldn’t do that with, but I’ll go get you an answer. So yeah, cloud backup, guys. It’s got to happen. Everybody’s using Google. Everybody’s using Microsoft. I’m sure there are some other forms of backup that we should potentially talk about as well from the cloud, right, guys. But those are the two key ones.
Jay Ryerse
Yeah, Matt, I’ll kind of pile on what Jason was saying, again. Another war story from just a few weeks ago, a partner had gotten an email from a client on a Saturday afternoon. And the attachment in the email said, it was a tech stock that opened up on his desktop. That basically was one of the attack groups telling him exactly what they did, and they didn’t encrypt anything, there was no ransomware. They basically said though, we’ve been in your network now for weeks and we’ve stolen 350 gigs of data from your Microsoft Cloud. And they did it using last week’s content. They phished a user who gave them their credentials and didn’t have multi-factor authentication turned on. And literally, the partner was looking at the firewalls in their business, there was no stealing 350 gigs of data, you’d see it in the firewall. Well, when we looked at the logs, it’s because they logged into Microsoft’s portal directly and downloaded it right from Microsoft to themselves. And they presented copies of files. I mean, they could have just said delete all and killed it all.
Lauren Lev
So, what was the point of them doing that? Like, oh, make sure you do better next time?
Jay Ryerse
Extortion. They literally said, we’re going to share all of these files out to the world, unless you pay us.
Lauren Lev
Oh okay. That’s what I thought, but then you skip that part. And I was like, friendly reminder?
Jay Ryerse
In this letter, there were frequently asked questions, so that the person receiving this would know exactly, you know, they’re like, they’re having a conversation. You know, why would you do this? Money. No, how did you do it? Well, we’ll tell you, but not until you pay us. And in fact, once you pay us, we will show you the risk assessment that we ran to show you where all of your vulnerabilities were, so that we can help you close those down. So future threat actors won’t be able to leverage that same hole that we came in from.
Jason Pryce
So basically, they’re doing the same thing that TechOnPurpose does, but they charge you like 100 times more.
Jay Ryerse
Yeah, and it’s- I’ve got the whole email and it makes you sick. At times you almost have to laugh because these guys have heard all the objections. Well, what if I don’t pay? Well, then we’re going to do this. And that’s what we’re dealing with in this world today is some people that do not care about your data, but they know that you care about it. Whether you’re trying to secure this space, or implement your SaaS backups, right, you have to get this right, you can no longer put it behind you and we can kind of wrap this up with legislation. You know this log4J, you know, vulnerability that’s existed. You’re now seeing governments saying that businesses that now fall victim to an attack from this attack that should have already known to fix it and didn’t, should be held accountable. That’s a whole new level of risk management for a business owner that you can solve for with the right SaaS platform. And of course, here at ConnectWise, we have our own platform that some of our partners use, but, you know, we’ve partnered with some of the best in the industry, you know, to allow partners like Matt to be able to use those. I know you guys are using Acronis and we’re big fans of what Acronis has done in the backup world and how they’ve solved these challenges. They’re all good. The issue is, when you do your assessments, you know, everybody who’s listening today and reads this later on, you’ve got to look at this again from all the different angles, and we’ve only covered a few. I mean, Jason and I could probably go on for another hour just calling out all the things to think about. But Matt, they’re on your checklist. There are things you do with your clients every day of the week. And so, why don’t you tell us about that?
Matt Tankersley
Wow, which part? That’s such a can of worms, right?
Jay Ryerse
SaaS backups? How are you solving it for your clients?
Matt Tankersley
How do- which products are we using, which technology?
Jay Ryerse
No, how do you look at it? You’ve heard how we look at it, how Jay and Jason are looking at it today. What’s your view on this?
Matt Tankersley
You know, it’s pretty simple. And I’ve implied it once and hopefully I’ll do a better job this time around. Right. So the reality is, everything starts with the risk assessment. And unfortunately, here we are offering this invaluable free thing to people and more often than not, they’re coming to us asking us to solve a single single problem. In this case, like the story, I told a minute ago when the guy just wanted cloud storage. Well, it turns out, he’s got all kinds of issues. He doesn’t use complex passwords. He doesn’t use MFA. And he’s using web pop mail hosted stuff, right. But as you heard me say earlier, we don’t provide- I mean, I think, easily 99% of our clients use Google or Microsoft, right? Anybody that’s not using one of those two things is probably not the right kind of client for us, because there’s so many other issues related to that. And as I said, we don’t sell those products without the backup, cloud backup, it’s just not an option. And so, what it is, I don’t know that, Jason, you’ve heard this, and this might help facilitate the closure of the conversation and a little bit of the origins of this whole campaign that we’ve created, “Who’s In Your Cloud?” But we had a number of clients that consistently refused to adopt best security practices. We cared about these folks deeply. We see the writing on the wall, and they’re heading toward devastating disaster. And we have to ask ourselves, do we want to be on that ship when it sinks? And so, in a last foray of attempt to educate and motivate, we created this campaign called “Who’s In Your Cloud?” for 21 steps, right? And we created what we call a security awareness declaration matrix. And so, we’re actually requiring all of our clients to sign this declaration that basically says, of the 21 security steps. Which of these have you adopted? Do you refuse to adopt? Would you like to adopt effectively, or you’re in the process of adopting it? Right, and then there’s some fine print. It’s just one of our standard terms and conditions. And it basically says, if you consistently refused to adopt best practices, guess what? Cloud SaaS backup is one of those, then we can fire you as a client at any time, because we’re gonna get off the ship. We don’t want to be there when it goes down. We’re telling you, you know, your kids don’t touch the hot oven, don’t touch the hot oven, don’t touch the hot oven, and the kid walks up there. And Jason, you got a young one, you’ll find that out some time soon, hopefully not. And they still want to touch that up. And you’re like, you don’t want to see that pain. So the other side of that, by the way, is we tell our clients, if they consistently refuse to adopt best security practices, they experience a compromise and want us to remediate our rates go up exponentially.
Jason Pryce
So I think what you’re saying is awesome. Because I speak to a ton of different people in your position, different MSPs and people who provide these services across the country. And more and more people are saying, you know what, if they’re not willing to take a multi-layered approach to protecting their environment, we don’t want them as a customer, right? It’s not about the money at this point. But I want to be able to sleep at night, and I want my techs to be able to sleep at night. And I, you know, I don’t want to work with you. You’re supposed to be partners, right? So when I make certain recommendations, right? They really need to be truly considered, right? And if there’s questions, there’s always gonna be questions, right? Well, why do I need this or can I get away with this? And that’s normal, but at the end of the day, you guys are the professionals. I see you guys at different events, learning about the new solutions, learning about the new processes and procedures out there and new legislation coming down. So you guys are the most educated people in the room. So hopefully they take heed to like these, you know, these pieces of advice that you’re giving them because they’re not saying it from a standpoint of just wanting to sell you more, but really how to really protect you and have everybody have a good night’s sleep.
Matt Tankersley
And we said from the beginning, we wish you didn’t have to do any of this. We’d love to do something more for you from an IT perspective, and it’s no longer an option. And Jay, I think you’ll appreciate this, right? So we use your Identify platform to create these risk assessments. So they make these beautiful reports, which by the way, are invaluable to your insurance company who’s going to be coming back and asking you all of those same questions, and you’ll already have those questions answered and it didn’t cost you 1000s of dollars. What’s interesting is that report, what we find is the typical business owner gets it and now they have intelligence, but they don’t know how to decipher that intelligence. Like we’re telling them what their most critical and high and medium risk things are. And here’s the recommended remediation steps. It’s full of acronyms that they don’t understand, and RTO and RPO. And, you know, where do you go with that? Well, that’s where our TOPcyber21 matrix comes in. We literally hand this thing to them very intentionally built, how do I get started in securing my environment? What’s the simplest thing you can do? TOPcyber step 21. Get your people trained. It’s inexpensive, right? Let’s monitor the dark web to make sure that we don’t have compromised credentials. Let’s make sure that we’re using complex passwords and password managers everywhere, including MFA and identity access management. And we’re going to get there and hopefully they’re starting with Cloud SaaS backup on the front end.
Jay Ryerse
You know, Matt, we talked about this a lot, is that the business community automatically assumes that security is going to be expensive. And what I tell them is that look, it can be. And for some businesses it needs to be, but the first impact on your business is not going to be money, it’s going to be sacrificing convenience. Right? And having to get a code from a phone gets my phone so there it is. Now, back to authentication. Not being able to reuse the same password over and over again, can’t store my passwords in the browser, I got to use a password manager. All these things have nominal costs associated with them. They do require you to sacrifice convenience. And so, when you’re willing to say, Okay, I’ll have that conversation with you. And you really assess, then that’s where you start to understand what this roadmap looks like, you know, we talked about action plans, right? You know, we don’t have to do everything tomorrow. But let’s put the next 90-180 days onto a roadmap. And let’s roll these things out that you should have, based on what we learned from your assessment, so that you’re not the slowest kid in the woods when the bear is chasing you. That’s what it boils down to, right? Get rid of the easy stuff because even the White House can get attacked. We want to make sure that we’ve got the right controls in place, including those SaaS backups, so that you can survive an attack, or an outage, or fire or flood, or whatever that might look like in your business.
Jason Pryce
Or an employee who just clicks on anything.
Jay Ryerse
Don’t even get me started there, Jason. I got stories there, click-happy colleagues.
Matt Tankersley
You reminded me of something, Jay. I’ll have to tell my story sometime about MicrosoftMail1.o and how I figured out how to actually hack email addresses to send an email from anybody to anybody. And to prove it, I sent something . And my phone rang a little bit later, by the way. And it turns out, I actually had a buddy that worked at the White House that cleared me real quickly. This guy was just doing a test, you know, but it’s a funny story. And it tells you how far the vulnerabilities have actually, and how the security has actually evolved. Because theoretically, we can’t do that very well anymore. We’re, you know, spoofing email in that way, if you will. Cloud SaaS backup, guys, it’s not an option. Like most of the security things out there, if you’re willing to say I’m not going to compromise and use password managers and I’m not gonna back these things up, you’re saying you’re okay being out of business. How long can you be out of business? That’s the RTO, the RPO conversation. If any of this didn’t make sense, and you have questions, you know, please reach back to a member of our team. I think Lauren’s going to give you some instructions on our way out here, how to get some free trials of all of these technologies that we’re talking about. So any final thoughts, guys, on how we can motivate the team about the urgency of this issue and how to get started, Jay?
Jay Ryerse
Just start the assessments. Again, what we don’t know can hurt us. The assessment will help you start to get visibility into what you need to consider. Doesn’t mean you’re going to do everything in the world, but you’re going to align really well towards, you know, the TOP21 because they actually make sense. They’re practical, they’re implementable, and they’re reasonably affordable when you start looking at the cost of outage.
Jason Pryce
I think I’m right on board and today it seems like I’m copying everything Jay says, but he is smart. He’s just saying some valuable stuff, but definitely making sure that you go through like a checklist, or you know, that you guys do to, you know, pretty much highlight the risk, and then just take action off of that. Right? And, you know, it’s your job to, you know, to educate them. Because once again, there’s gonna be tons of questions like, I’ve never seen that much red on a paper before. Right? And it’s, you know, it’s your job to be like, okay, you know, we see it all the time. But, you know, these are the steps that we can take to get you to a better place, right? At the end of the day, it’s all about just getting to a better place and always striving to continue to go there. Because guess what, when you think that you’re at that final destination, right? The criminals come out with something even better and heinous and crazier, and you’re going to have to keep moving. Right? So it’s a journey. That doesn’t stop, right. But you always want to be, you know, ahead of the class, right, for lack of a better term.
Matt Tankersley
Yeah. So Lauren, I’m gonna let you close us out. I’m gonna put a fine point on this whole thing with some facts that might be useful to our listening audience. As Jay said, this stuff is not that expensive. I want to tell you how simple it is and how quick it is. I don’t care if you have five mailboxes, or you have 500 mailboxes, I don’t care if it’s Google, I don’t care if it’s Microsoft 365. It’s important to point out that these SaaS backup solutions that we’re working with don’t just backup your email, they backup your SharePoint sites, they backup your Google Drive, they backup your OneDrive. So it’s a comprehensive backup, and it literally takes less than 24 hours from the time that you decide I’m going to be smart enough to backup my data, for us to be backing up all that data three times a day and keep infinite copies of it online. We’re looking forward to seeing your request to learn more and get you signed up for this level of security. Lauren, if you don’t mind, close us out and let folks know how they can plug in more.
Lauren Lev
Alright, and with that, ladies and gentlemen, we have reached the halfway point in our series. As we round out topic number 10 of our 21 steps to secure, reliable, trusted technology, I wanted to remind our audience that losing critical data affects organizations of all sizes. I think that Jason touched on it earlier with Microsoft, but in 2009, Microsoft and T-Mobile nearly lost all of their customers’ data due to a failure of the Microsoft Server computer. And even Pixar accidentally lost 90% of Toy Story 2 to inherit computer demand. It happens to everybody, but don’t let it happen to you. So next week, we’ll be discussing how the demand for encrypted email grows daily and why encryption tools are vital to business sustainability. And we talked about it a little bit today, but next week we will dive deeper. So catch up on all episodes on LinkedIn, YouTube, Facebook, and Spotify. And get direct delivery to your inbox by signing up at TechOnPurpose.net/blog. And if you would like to start a free trial from any of our partners here today, send an email to . And we’ve said it over and over again today, but to get your free cybersecurity risk assessment visit WhosInYour.Cloud today. Alright, that is all for us today. Goodbye, everyone.
Matt Tankersley
Thanks, everyone. Thank you, gentlemen.



















