TechOnPurpose Logo

Episode 16: Server Backups & BCDR

by | May 17, 2022

Who's In Your Cloud?
Who's In Your Cloud?
Episode 16: Server Backups & BCDR
Loading
/

Welcome back to “Who’s In Your Cloud?” 21 Steps to Secure, Reliable, Trusted Technology. Brought to you by TechOnPurpose, this is Episode 16: Server Backups & BCDR.

In our last episode, we focused on the importance of Remote Access Security in today’s growing remote-workforce world. With the help of our cast of cyber experts, we discussed how to safely work from anywhere – from any device. View Episode 15 to learn how to achieve secure remote access for your company without the burden of complexity. 

Now today’s episode is all about Server Backups and BCDR (Business Continuity & Disaster Recovery). Did you know, businesses lose around $8,500 per hour due to ransomware-induced downtime? (Palo Alto). Employing the right Business Continuity & Disaster Recovery strategy and tools will help to speed up the recovery time from days or weeks to just minutes or hours in the event of data loss or system outages.

Stick around to learn from our cast of cyber experts about the critical need for Servers Backups and BCDR and their available solutions that ensure your business remains operational and secure. We’re very thankful to our cyber expert cast joining us today from Datto, Intelisys, and Opti9, as they help us educate our clients and prospects on the road to #secure, reliable, trusted technology!

As a reminder, we began releasing a new episode every Tuesday, starting 10/20/21, and will continue to do so through late spring of 2022, with brief time off for holidays with family and friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational, and enjoyable experience. So how do you tune in?

To easily follow the journey ahead, we’ve diversified your access options to all (23) of our coming episodes. You can follow along here on our blog or by any of the following methods:

  • Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
  • LinkedIn:  follow here
  • YouTube:  follow here
  • Facebook:  follow here
  • Podcast:  follow here

Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!

Read Transcript
Lauren Lev
Hi, I’m Lauren Lev, Marketing Manager for TechOnPurpose and the host of this series: “Who’s In Your Cloud?” 21 steps to secure reliable, trusted technology, and this is Episode 16: Server Backups and BCDR. To see more of me and my cybercrime fighting partner, Matt Tankersley, check out all of our previous episodes on LinkedIn, Facebook, YouTube, or Spotify. And if you’re not already getting episodes delivered straight to your inbox, what are you waiting for? Sign up at TechOnPurpose.net/blog and sign up for our free cybersecurity risk assessment at WhosInYour.Cloud. Server backups and BCDR, let’s get into it. If you’re no cyber expert like me, the first question you’re probably asking yourself is what the heck is BCDR and why does this girl keep saying it like she knows what we’re talking about? Well, BCDR stands for business continuity and disaster recovery. See Matt, I’m capable of learning a thing or two around here. So it turns out server backups and BCDR tools and processes are operational imperatives to ensure simple, rapid, secure data and system restorations. There are countless ways to approach and discuss these topics. Starting with questions like, how long could your company afford to operate without access to critical data or systems should set the appropriate foundation for all that follows. Selecting and employing the right BCDR strategy, tools and processes are core to operational recovery in the event of data loss or system outages, and will help to speed up recovery time for days or weeks to even just minutes or hours. In today’s episode, our cast of cyber experts will shed a light on a thing or two about server backups and BCDR and what solutions are out there in the marketplace. So let’s meet our cast of sassy and savvy characters for today. Back with us again is VIP cast member Patrick Chen, Solutions Engineer for Intelisys. It’s been a while since we’ve seen you, Patrick, but glad to see you’re up and at them again.

Patrick Chen
Thank you. Thanks for having me. It’s always a pleasure. And it’s a lot of fun with these videos. So I really appreciate you guys inviting me back.

Lauren Lev
Of course. Explain to the audience a little bit more about who you are and what you do at Intelisys.

Patrick Chen
Yeah, so Intelisys, for those that maybe haven’t watched some of the awesome previous episodes, we are a managed services distributor. So you know, we sell a variety of different things. BCDR happens to be one of those solutions. You know, my role at Intelisys is to be an agnostic engineer where we can help consult, you know, help identify the requirements for the customers, what their use cases are, maybe the challenges they’re trying to face. And then we align the right suppliers of technology solutions alongside Matt and Lauren, to make sure that the customer gets what they need.

Lauren Lev
Fresh off paternity leave back again on the blog is Jason Pryce, Channel Development Manager from Datto. Jason once again, congratulations on your little one.

Jason Pryce
Oh, thank you. You’re far too kind. I miss paternity leave, but this is like an awesome way to be turned to do this video and show. So thanks for having me.

Lauren Lev
Well tell the audience a little bit more about who you are and what you do at Datto.

Jason Pryce
Oh, yeah. So Jason Pryce, I’ve been at Datto for about eight years, what’s called a channel development manager. So essentially, I do two things, right? I help my MSP partners, better educate and position BCDR amongst a whole other host of tools to the end users. So that’s one thing I do. The other thing I do is I actually talk to end users, right? And by end users, it’s the small and medium sized businesses out there, the everyday people, and I want to share what ransomware is I want to share, you know, the different ways that people are accessing systems and things of that nature, right? Because knowledge is power, the more you know, the better you can protect against those things. So my job essentially is just educating people.

Lauren Lev
Introducing a totally new partner to TechOnPurpose and obviously a new cast member, we have Sagi Brody from Opti9. So introduce yourself and tell us what you do for Opti9.

Sagi Brody
Thanks for having me. This looks like a fun group. A lot of positive fun and energy, much better than the boring other podcasts that I’ve done. Yeah, I can already tell it’s gonna be fun, especially for a topic like disaster recovery. But so I’m the CTO at Opti9. I’ve been really kind of in this role or a similar role for over 20 years and half embarrassed to admit that, but for a very long time. And what I do is really, I just sort of shaped the product roadmap and where our services are going. Opti9 is a managed cloud provider. And so we really provide bespoke and customized solutions, be it private cloud, public cloud, or BCDR. And that’s really our bread and butter. And we really take ownership and accountability of those solutions for our customers. And we kind of guide them through the strategy. It’s not just here’s your login and password, good luck. It’s really about taking ownership of that strategy and ensuring they have what they need.

Lauren Lev
Well, I’m excited to start working with you guys. I know this is my first interaction, but I’ve heard very good things from the team. So welcome aboard. It’s a little bit of baptism by fire. You’re new to the company and now we’re throwing you into the vlog, but we promise it’s fun. And you probably already know him. My partner in crime. My boss, the head honcho, Matt Tankersley, Founder and CEO of TechOnPurpose, Matt, thanks for being here. Not like you have a choice, but thank you anyways. I appreciate it.

Matt Tankersley
Lauren, thank you. Thanks for making it feel like it’s a choice, that means a lot. Yeah, listen, I want to welcome all of our cyber expert cast today, and you guys are a powerful team. I love as I was listening to introductions, the 360 degree perspective that you guys are bringing to the conversation today. You know, you got people that are actually developing products that do the things that we’re talking about today. You have people that strategize and help to develop those products, and then people that have to actually deliver that as a managed service in partnership with TechOnPurpose. So really excited for the cast that you pulled together for a great job. And also, Lauren, you’ve had a challenging week, and I want to take a moment to recognize your impressive resilience and survival skills. And say, thanks for doing all you do to pull this program together and keep all those cats herded on time and on top. So thank you, you’re a rockstar. So obviously, you’ve not heard about the bee incident, so we’ll talk more about that in the B-roll.. Listen, Episode 16. Can you believe we made it this far? It’s amazing. I feel like we haven’t discussed enough the critical need for risk assessment as a priority. I just want to throw this on the front end right, and how this helps us and you and our listeners to clearly identify the critical and high risk areas that need to be addressed promptly, right. And as you mentioned, our listeners can sign up for that free risk assessment, by visiting WhosInYour.Cloud, that’s a landing page we have out there for you to learn more and get signed up. And so today’s topic- server backups and BCDR. And, you know, for me, this is an all too common missing component I see in a lot of organizations. It stacks, which is intriguing. You know, we just trust and believe that our servers are always going to stay up and our data is not going to go anywhere. And unfortunately, that’s not everybody, but I do see it more than I’d like to see. And so what does this even have to do with cybersecurity? Right? This is a cybersecurity story and we’re talking about data, recovery and backup. Well, most folks probably know that those are pretty well entwined. But let’s, I say we turn it over to our real cyber experts. So let’s learn some more.

Lauren Lev
Patrick, we’re gonna go to you first. So in your experience, why are server backups and BCDR important? Feel free to share any statistics or stories, probably horror stories if you have anything that comes to mind.

Patrick Chen
There’s a lot of statistics, you know, and I think the one that comes to mind that I think is probably the scariest, is the fact that I remember reading that 90% of all companies that don’t have a BCDR solution in place, they typically go out of business within four months after a major impact. I think that speaks for itself. Right? And you know, these days with how much ransomware is proliferating- How much data you know, with all the digital transformation that’s been happening across all the organizations, SMB all the way to enterprise, the digital data itself, that’s the lifeblood of any organization. And if all of a sudden you’re unable to access it, your company is effectively crippled right? Here’s what I’ll also say-I know today is primarily about server backups and BCRD, but what I want us all to keep in mind is there’s also a difference between business continuity and disaster recovery. And I’m hoping we’ll be able to get into that because they’re actually very, very different things. And they both come together very well, to help keep a company afloat.

Lauren Lev
Perfect. Thanks, Patrick. Jason, we’ll go over to you next. What are your thoughts?

Jason Pryce
So first and foremost, I think server backups are the most important thing you can do, right? However, it’s typically the last thing you want to have to actually utilize, right? There’s so many other steps, right? You want to make sure you have the right firewalls, you want to make sure people are educated. And I click on random things, right, you want to make sure that this is gonna stay up to date. But the thing is, at the end of the day, if one of those things fail, if something is able to get through, you need to rely on having a robust backup system that can also be able to get you up and running in a timely manner, right? So it is two different points, right, you want to have the backup, you want to have the information saved. But you also want to be able to access and utilize that information as quickly as possible to get back up and running it to minimize your amount of downtime. In terms of stories that I’ve heard recently, just last week, there’s a college in Chicago called Lincoln College, it was founded in 1863. So it’s been around forever. Last November, they got a ransomware attack. So that means that somebody sent somebody in the school, something malicious, they opened it up, and it pretty much encrypted everything. So at that point, the school can no longer hold classes, the school can no longer do anything in terms of their admission process, they still couldn’t pin up grades, they had to suspend classes. It took them about five months to get their systems back online. Right, but because we’re off, so for such a long period of time, they’re actually closing the school next week for good. A school that’s been around for hundreds of years, one cyber incident where they didn’t have a backup system that was able to be spun up in a quick manner, they now are out of business. And the kids who are in school now have to transfer to other schools and it’s just a snowball effect of different things that have happened because of this one ransomware situation. So you know, that showed up last week on my feed, and I was just devastated for those kids. Right? I’m devastated for the alumni. Because that one incident happened, they lost all that data.

Patrick Chen
If I was a student there, I would just tell them I already completed all my credits. How would they know, right?

Matt Tankersley
Right. Well, you know, what I love about what Jason did is A, you validated the point that Patrick made about the significance of losing your everything to the point of closure, which you had brought up. And the other thing is, how does this merge with cybersecurity? Right? I think you clearly pointed that out, right? If you’re a victim of ransomware, and you don’t have a data backup, right, how are you going to restore? So two great points. I’m interested to see, Lauren, what Sagi’s going to bring to the conversation next.

Sagi Brody
Absolutely. Yeah, I mean, I would agree with what Jason and Patrick said. And, you know, I think one thing that I would just caution people about is to just not make assumptions. You know, we’ve seen too many people making assumptions that they don’t need certain things. And it just really comes down to just a lack of understanding. And this is really a habitual issue that just, you know, is ongoing. And as things get more complex, I’m using the cloud, I don’t need backup, because I’m on the cloud now. Or I moved all my email to Microsoft, therefore, you know, I have built in backups, and so on and so forth. And so, in the realm of really backups, and DR. We see a lot of this, we see people saying, you know, I’m protected from ransomware, because I have a security company. Or there’s also a very big misunderstanding. And I think that Patrick alluded to this, there’s a misunderstanding between backups and disaster recovery. These are really two, two separate sorts of strategies that are there to achieve two separate end goals. And so I think the best thing to do is kind of demystify, and make sure people don’t don’t have the wrong assumptions around what they have. Because as Jason pointed out, I mean that could be life or death, you know, for businesses. And, you know, talking about stories and not to sell any more fear, but, you know, we had a customer who had local backups, and they had offsite backups, and you know, you would assume, hey, we’re in pretty good shape. But what’s happening is the attackers are getting more sophisticated as well. They’re actually attacking the backup servers. And, you know, if you’re an attacker, it makes sense. Let me go and delete all my backups first, and then on ransomware, we’re actually seeing that. And so, we had a customer who had that situation happen to them all the documents were deleted, they were ransomware. And part of our services, we actually air-gap a copy of their backups on our side. And we were able to use that and restore their entire business. And, you know, it’s funny, like you hear about these interesting statistics, but for me, you know, being on the other end of that phone call, and being able to help them I mean, you know, it was awesome because they probably would have ended up like that school otherwise.

Jason Pryce
Absolutely, and just to jump in, because some people were saying, Well, I’m never gonna get ransomware this, that, the other, but people have been placing the value of backups before ransomware was a thing, right? When you can go to your computer and have a blue screen, right? When there was the blue screen of death, right, or your computer doesn’t boot up, or you had a power surge, right. So it’s not just the cybersecurity aspect that we think about when we think about needing to have a backup. You should always just need or want to see them or see the value in having a backup of any data because anything can happen. Even if somebody walked into your place of business, put their hands on the server and walked out, you need to make sure that you have a copy of that data.

Sagi Brody
Yeah, and to Matt’s question, you know, in the realm of cybersecurity, the way I’ve always thought of it is, you know, you have proactive security monitoring, you have threat detection and threat prevention, threat hunting all of the managed security providers. I know, that’s the proactive component. You know, think of it as almost like umbrella insurance for cybersecurity, you need proactive, you need detection. But none of these security solutions guarantee 100% that they’re going to catch everything. So you must have the reactive component to what you do if something gets by and you cannot have a complete cybersecurity strategy without both sides of that fence.

Matt Tankersley
One of the things I think they’ll point out is, Jason implied this and I want to say it too, when it comes to recovery, it’s one thing to be able to have a copy of your data and recover that data. But if that device has failed, right, there’s a continuity now you’ve got to go either get a new device, reconfigure a device and customize the operating system. And one of the things I love about the products that Datto equips us with is the ability to take operational snapshots of these critical servers as well. So we can have a hardware failure. And not only do we have a backup of our data, but within seconds and minutes, we can be operational from the stored hardware, literally operating off of the same IP address and the same host name. And Sagi, I know that your team is a big bean shop. And we’re being partners as well. And so we’re glad to have you here. And we’re gonna have, I think, our second round of questions and talk about the specific solutions that you guys are equipping TechOnPurpose and our clients with and probably seeing the tools and tactics, Patrick, that your team is recommending for partners like TechOnPurpose. So all good stuff. Great introduction. Great start.

Patrick Chen
I was going to add on to what Sagi had kind of mentioned about, you know, where DR fits into the overall cybersecurity scheme of things. And I wanted to elaborate on that a little bit more, I believe in one of the previous episodes, we talked about the CIA triad in the cybersecurity world. In my mind imagining things everything’s well. Okay. So when you’re looking at from a cybersecurity specialists perspective, right, they’re typically looking at three of those components. And the CIA stands for confidentiality, integrity and availability.The confidentiality side is exactly what Sagi was mentioning, and how we have to be proactive and make sure that we have the ability to keep that data encrypted and hidden from eyes that shouldn’t be seeing it. The integrity side is for us to make sure that the data we are accessing, right is, is the data that’s supposed to be there. It hasn’t been, you know, adulterated in any sort of way. Right changes were made without our permissions. And then the last part is the availability, which is really the integrity and the availability is kind of where this data beat business continuity and disaster recovery solution really comes into play, especially on the availability side, because the availability is pretty self explanatory. How do we ensure that the data that we need to access is always going to be right? And so when you look at it from that perspective, this is really where the BCDR conversation comes in, in cybersecurity.

Lauren Lev
Okay, so we’re gonna start out talking about solutions. And I’m gonna have Jason- You can go first, what are Datto’s solutions for server backups and BCDR? I know Matt mentioned something briefly a second ago, but can you go into a little bit more detail?

Jason Pryce
So yeah, so in terms of data, we have a bunch of different solutions that will accommodate server backup. So whether you have servers that are virtual or physical on premise, or you’re utilizing Azure, for free your workloads, we have different levels of backups that can accommodate all of those different places where data is, is used. So regardless of which one of those places your data is kept, we have solutions, which are able to accommodate that. What we do is what’s called a full image based backup, that means we’re taking a backup of everything on that server that is going to be the operating system, your settings, all the different data, every single block level piece of information, we are backing up. We’re not only keeping it on site, but we’re actually sending it off site to our private data center, that private data center is utilizing the latest and greatest encryption, military grade at that, to make sure that nobody has access to that data. We then also send that data to a secondary site just to make sure that we have your data located in at least three different locations. And this adheres to the three to one rule. The three to one rule is to say that, hey, we want to make sure that anytime you’re doing a backup, it’s located in three locations, right to those locations, or different physical locations, and one of them is off site. So we adhere to that 100%. But the beauty of our solution is that from that, that is on the backup side. But on the disaster recovery side, the side where you have to get back on and running, we’re able to actually virtualize or take that data and turn it into a live working computer. So you can continue working in a quick manner, right? So we’re talking about you being down for, you know, 20 minutes, or 30 minutes or 40 minutes, and you’ll be able to get back up and running and not have that downtime, right. So I think the current cost of downtime is $8,000 per hour is the average, right? So if you’re down for an hour, that’s going to cost you $8,000 down for a day, we’re going to extrapolate that 24 times eight, and whatever that number is. So get back up and running as quickly as possible. And with our solution, we allow that to be done. You know, we’ve been around for a while. And we’ve helped 1000s of 1000s of small to medium sized businesses actually overcome any sort of attacks that they’ve had, and be able to get back up and running and to save their business. You know, as Peter mentioned earlier, when it’s talking about people who don’t have backup, you know, and they get into an incident where they get ransom, or whatever the case may be, 90% don’t exist within 12 months. So that is a true stat. And I’ve unfortunately seen the flip side that does bring true.

Matt Tankersley
And Jason, I’m curious, you know, if I refer back to what Patrick said a minute ago, and we focus on the integrity side of the conversation, what is Datto doing to ensure that the integrity of that data is present? From the moment it’s being backed up to the moment it’s being distributed from your appliances into your various models?

Jason Pryce
Okay, yeah, so a couple things are happening, right. So the first thing that is happening is that when a backup is taken, we actually have a couple of processes which run on the backup, right, and that’s going to check to see if there’s any sort of ransomware that may exist within that data set. If there is, we’re going to actually alert you because we want you to know as quickly as possible, so that they can be measured to actually remove that. The other thing that we’re doing is we want to make sure that in the event of a disaster, that data is in a good position to be able to be booted up. So what we do is we do a screenshot verification, right? A screenshot verification is where we take that data, we boot it up, we wait to actually allow us to log in to that data. And then we take a snapshot of that. We then just send a snapshot to you, so you note that on this day at this time, this point is 100% good. You don’t have the fear of wondering whether it’s going to work in the time of a disaster. I mentioned that, you know, we also made sure that we use AES 256 military grade encryption to make sure that the data is not accessible. We save our data in a read only format, which is also very important. As Sagi said earlier, one of the things that you have to worry about is people actually attacking the actual backup systems. And because we save everything in a read only format. ransomware and things of that nature don’t have the ability to rewrite any of the information, so they can’t get ransomware and things of that nature. So that’s some of the big things that we do to prevent any sort of, you know, integrity issues locally, but also we have different things that we do in terms of multi-factor identification to make sure the right people have access to your data that’s in the cloud as well. So tons of things that you can do here at Datto.

Sagi Brody
That screenshot feature that Datto has is awesome. It’s been around for so many years, and I’m just surprised that others haven’t picked up on it. You know, and what’s great about it is, this is all very emotional, right? Like this, you know, as I said before, this is people’s livelihood. This is, you know, their business and being able to see that and to actually see that booted up, you know, in your inbox every day. I mean, it’s got to put a lot of people’s minds at ease. So that’s so cool that you guys have that.

Matt Tankersley
Absolutely, but Jason, we’re grateful for you and your products and, and grateful for your contributions, as always in the show. So, Lauren, are we turning it over to Sagi?

Lauren Lev
Yeah, we are. Let’s dote on some Opti9 for a second.The floor’s all yours.

Sagi Brody
Oh, boy. So you know, what I will say so we’re a managed provider? Right. And, you know, I think just like we were talking about before, as I kind of break it down, you know, the different offerings, really, you have technology that’s out there, you have vendors who are creating amazing technologies. And then you have folks like Opti9, who are providing services. And people are using both to solve these challenges around business continuity and disaster recovery. And it really comes down to, you know, what is it, as an IT organization, or as a company, what is your appetite to take ownership and accountability of setting up these technologies, configuring them, monitoring them, managing and securing them. And again, there’s no right or wrong answer. There’s huge IT shops who have an appetite to manage that. And there’s folks who would rather outsource that. And so Opti9 does the latter. And, you know, really I think the first thing you gotta do is sit down and say, what do we want to actually be responsible for as an IT organization and what do we want to outsource? And so we provide disaster recovery and offsite backups completely as a service. And what that means is that our customers are holding us accountable to an SLA to a service level, that these things are working the way that they should. You know, they’re not holding us accountable to so many terabytes of storage or gigabytes. When in regards to disaster recovery, we’re going to promise that their data is not going to be any older than 15 minutes and their entire environment will be back up and running within the hour of when they declare a disaster. And those are the primary deliverables, honestly, everything else is just details. I would also say that in the realm of service providers, again, there’s no right or wrong, you have very transactional providers, who are probably a mid tier from what I was describing. And then you have ones that are very, you know, very customized, and we tend to lean more towards customized, and we tend to work with larger enterprises, who have big environments who have, you know, messy environments. So that’s skeletons in the closet and, and legacy IT and you know, that’s just the reality if you need to replicate and preserve your critical production systems. We have to cover all that, we can’t ignore the old IBM server in the corner of your server, and we can’t ignore your physical servers. So when it comes to business continuity, backups, and disaster recovery, we cover the gamut. We cover all those platforms, you know, bring us your old legacy systems, your messy things, we’ll find a way to protect it, because DR is all or nothing. And I think the other thing that we do is we help our customers with the strategy, right? Replicating data is the easy part when it comes to disaster recovery. That’s easy and tools like, obviously, Datto and Veem and other amazing technologies that will replicate all the data. I think the bigger question is, during an event, how are you going to consume it? How are you going to access it? How are your users gonna access it? And honestly, that’s more of a networking challenge. That’s more of an integration challenge. How are they going to access it? Where it’s, it’s not an exception to the security and network framework that you’ve already built? You know, and in general cloud shouldn’t be an exception. And so we work with that and we do a ton of network integration. And we, like I said before, deliver it as a service.

Matt Tankersley
Sagi, that’s a great overview. And we love the early stage of the partnership that we’re talking with you guys about. And, you know, this isn’t just the only thing you do, by the way. And so I think it’s probably important for folks to know that if you don’t know much about that, or Opti9 and obviously, we’re here to help you. Intelisys has a fantastic and the team and Patrick had fantastic alternatives to all of these products, as well as the experience with these products. And so, Lauren, are we in this in the last stage of our questions, we’re gonna let Patrick close this out. I’ll save any thoughts I have till the end. And Patrick, I know that you were passionately wanting to make sure and connect dots between the differences in business continuity and DR backup. And so now might be a good time for that, or anything that you have to bolt onto what’s near Jason and share those.

Patrick Chen
Yeah. I mean, when Sagi started to talk, and immediately it was like I was chomping on the bit to try to flesh that out a little bit more, because he actually provided a fantastic segue. And he’s absolutely right, the strategy side is huge. Right? And, you know, on the intelligence side, you know, alongside, you know, Matt and Lauren’s team, when we’re working with the customers we have access to all these different technologies, Datto, included, right, Veem, included, everything that we’ve been talking about today is accessible. But one of the different things that you know, collectively, what our team and Matt’s team brings together is we are looking at a top down, from that side of the strategic conversation. Because going back to the whole business continuity versus disaster recovery conversation, disaster recovery to me is more of, hey, how do we restore our services, right? But the whole business continuity side is a much grander scheme of things. Because when you’re planning it out, ideally, you want to sit down with your customer and say, you know, hey, I know we have these technologies in place that we want to sell you, but let’s actually talk through it, let’s understand a business impact, right, do what’s called a business impact analysis, how much impact? You know, how much are you impacted as a customer, if x y things happen, right, and then identify the critical areas of the business and the real potential high risk areas. Okay. And then from there, you develop your DR plan. And it’s not just the technology, like Sagi said, it’s also what are the policies and procedures that we need to follow? If a disaster happens, right. And it can also go beyond just servers, and also technology, right? I used to work at a hospital a long time ago helping out and some of the things that we were looking at were not just our applications, it’s also where are our people? Right, a disaster could be a, what I guess what they call a god type event. If there’s a hurricane, right? Are we only worried about the applications? Or are we worried about where our people are located? And then when that disaster happens, how do we know they’re okay? Right. So it can also encompass other areas, it can encompass communications. It can also encompass, you know, the endpoint solution and the network, like Sagi said. Even if our servers can come back up really quickly, how do we get our employees and our users the ability to access the data that we’re bringing back up? Right, so those are all very important questions. And, you know, it’s layered for sure. But as we know, security is all about layers, right? And sometimes it’s all about talking with the customer and understanding, not just their appetite for risk, per se, but how much risk they’re willing to take. But often, and unfortunately, it all comes down to what does their budget look like? Right? They are the ones that are going to have to tell us or tell you pay, this is a big deal for us. So ransomware is a big deal. But maybe it’s not that big of a deal if we can’t call our employees right. So they’re willing to allocate and spend more money in certain areas than others. In the perfect world, we can get everything all you know, layer down, we can sell everything we can implement everything. But that’s typically not the case. And that’s where the strategic conversation really comes in handy. That’s at least my opinion.

Lauren Lev
Yeah. And I liked the way that Sagi said it earlier. He said what’s your appetite for being able to handle things like this on your own and what do you feel like is important to outsource to other people. So very well said.

Matt Tankersley
Yeah, what I love about that entire conversation guys, and you only have to tip of the iceberg because you’re talking about systems and safety teams, availability of data and availability of tools, right? And then what you didn’t talk about yet is, you know, we know we have some health care clients that are there as well. And when their systems are not operational, and they’ve got a patient sitting there waiting to receive services, how are you going to serve them if you can’t look up that file? And all you have is the paper in front of you, you can see that last test, and they’re giving blood or taking blood or whatever it is that they’re doing, right? How do you continue to do that? Because guess what, you’re not right back to that hurricane just yet. I’m gonna focus on the blood folks for just a minute, right? They need a lot of blood, there’s been a lot of people that have hurt, how can they continue to get blood with people that need it if their systems are down, right? And so this whole conversation about strategy and BC in particular, business continuity is absolutely more than an IT conversation. And the beautiful thing is, we’re here to help and Patrick and his team and Sagi and Jason’s got tools to help us with those kinds of things. And we can help you do that. So it’s, whether you’re having that conversation with us or someone else, make sure you’re having those conversations. Don’t just backup your servers and think that you’ve got business continuity, right. I think that was one of the points that you were making.

Patrick Chen
Absolutely. You kind of summarized it a lot better than I did. Mine was probably a little bit verbose.

Matt Tankersley
No, man. I’ll tell you, it takes a team and each of us spark and feed off of each other. And hopefully, for our viewers and listeners, you guys are perceiving the importance and the critical component of why this is in our stack of 21 best security practices at TechOnPurpose, and it goes just beyond it. We’ve had that conversation. So Lauren, I know you probably want to wrap us up and let everybody give a final word or two. I know that I’m going to say I’m exceptionally impressed. In an industry that is overrun with acronyms that we didn’t introduce any of the 1000 DR acronyms that are out there like meantime to recovery, you know, all of those things, ITO and I can’t even remember them all. There are so many just in the backup space. So guys, great way to keep it understandable for the viewing audience out there. All right, Lauren, you got the wheel? Where are we going?

Lauren Lev
Yeah, anybody have anything else they want to say before I close this out?

Jason Pryce
I will say one thing, and this is for the people who may be listening and are like, but I’m small, you know, nobody’s thinking about me in terms of sending me ransomware or making me click on a link. And what I would say is nobody, they don’t care about your data. They care about how important your data is to you. Right? It could be photos, it could be, you know, all your transactions, whatever the case may be, it’s all about how important it is to you. Right? So just just think of it in that way. And don’t think of it as somebody saying, you know, let me go get this person with a dry cleaners and nobody cares about whatever, dry cleaners still love it. They care about what that data means to you.

Matt Tankersley
Yep. And how they’re gonna get money from it. They’re gonna basically extort storage for your data. And listen, the statistics are clear. SMBs are clear targets. So ransomware guys, it’s not just the big guys.

Sagi Brody
And it’s usually automatic. You know, these are attacks that are happening automatically and they don’t know you. It’s a transaction business. In fact, a lot of these ransomware firms have a live chat because they don’t want to get a bad reputation that they’re not ransomware-ing you fast enough. Yeah, sad but true. But I would say you know, sometimes, I guess at the beginning there’s a lot of assumptions out there. We got to break through that. And if you think you have a DR strategy or business continuity strategy, that’s great, but really ask yourself, if you were hit with ransomware next week, and you had two choices, pay $100,000 Ransom or hit the button on your DR strategy, what’s less risky for you? And I think a lot of people you know, they have something but they’ve never tested it. They’ve never used it and so it’s less risky to pay the money and so obviously you want the DR strategy to be that less risky option and if it’s not, then you don’t have a good enough strategy.

Matt Tankersley
That’s a very good point. I’ll put my business hat on in closing and say if your strategy is in your head, if your business continuity DR strategy is in your head, what happens if something happens to you? Guys, write down these processes, share them with other people, make sure folks know how to respond. All right, Patrick, any final words?

Patrick Chen
I mean, you know, I don’t know if you guys remember one of the Batman movies where Michael Kane comes out and just says some people just want to watch the world burn. Right? It’s very appropriate here. You know, a lot of times it is about money, and sometimes people just want to cause problems and sometimes the disasters aren’t even self-inflicted and you don’t even know, right? Sometimes it is hardware and that’s where these DR solutions come in. You know, we’ve been talking a lot about ransomware. But having a proper DR solution, it’s there to address any type of disaster, not just security. And I think that’s, you know, we’ve got to remember that.

Matt Tankersley
Good point, guys. Thanks for your partnership. Thanks for all you do to help us and our clients keep our information CIA (confidential, integrity, availability).

Lauren Lev
Awesome. All right, well, Patrick, Sagi, Jason, thanks for joining Matt and I for Episode 16 of our “Who’s In Your Cloud?” vlog series, where we’re covering the 21 steps to secure, reliable and trusted technology. As a reminder, you can and should check out all of our episodes on LinkedIn, Facebook, YouTube, and Spotify, or get them delivered straight to your inbox by signing up at TechOnPurpose.net/blog. To start a free trial from these solution partners you see here today, send us an email to . And like Matt mentioned earlier in the video, sign up for that very important free cybersecurity risk assessment at WhosInYour.Cloud. Next week, we’re switching gears to manage detection and response. We’ll be joined by some new TOP partners and some new cast members. So join us right back here next week. We will be meeting the game and discussing all things MDR. Thank you guys!

Ready for your free cybersecurity survey?

Discover potential vulnerabilities for your business and get a copy of our #TOPcyber21 Best Security Practices to help get you started on the road to #secure, reliable, trusted technology! Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.

Claim Your Free Cybersecurity Sruvey

View Next

Diagram showing how Texas cybersecurity law applies to every business, with two outcome paths — documented before a breach leads to safe harbor, documented after leads to full legal exposure

Texas Cybersecurity Law: What Every Business Must Know

⏱ 6 min readKey Takeaways Texas cybersecurity law already requires every business, regardless of size, to protect sensitive personal information and report breaches within 60 days of discovery. SB 2610 offers a safe harbor from punitive damages — but only if you can...
CVE dashboard showing NIST's "Not Scheduled" status replacing CVSS scores — patch prioritization without a score

NIST Just Derailed Patch Prioritization — Here’s Your Fix

⏱ 3 min readKey Takeaways NIST stopped automatic CVSS scoring for most CVEs on April 15 — the patch prioritization signal most organizations relied on just changed permanently. Only CVEs on CISA's KEV list, federal software, and EO 14028 critical software receive...
AI-Enabled Device Code Phishing — TechOnPurpose Identity & Access Management MFA Bypass Prevention

AI-Enabled Device Code Phishing Is Bypassing MFA — What Your Microsoft 365 Users Are Up Against

⏱ 4 min readKey Takeaways Device code phishing abuses a legitimate Microsoft OAuth flow — no passwords stolen, no MFA prompt triggered, full M365 access granted. AI-generated lures are now role-specific and hyper-personalized — standard phishing training won't catch...
Chrome Zero-Day Patch — TechOnPurpose TC21-05 Endpoint Patch Management Urgency

Chrome Zero Day Patch: Update Now

⏱ 4 min readKey Takeaways This chrome zero day patch isn’t routine maintenance — it covers two vulnerabilities already being weaponized. CVE-2026-5289 scored a 9.6 CVSS — a full sandbox escape. If exploited, an attacker owns the endpoint. CISA added CVE-2026-5281 to...
Russian CTRL Toolkit remote desktop hijacking — TechOnPurpose TC21-15 secure remote access defense

Russian Malware CTRL: Remote Desktop Hijacking Undetected

⏱ 4 min readKey Takeaways Newly disclosed Russian remote access toolkit called CTRL is enabling remote desktop hijacking attacks that bypass all known threat intelligence platforms — including VirusTotal CTRL is a newly disclosed Russian-origin remote access toolkit...
Old vulnerabilities cyber risk — TechOnPurpose patch management defense-in-depth

#CYBERinsanity: The Vulnerabilities Attacking You Today Were Published a Decade Ago

⏱ 5 min readKey Takeaways 32% of the most active exploits are old vulnerabilities, more than ten years old — patches exist, they're just not being applied. Attackers start with the low-hanging fruit: automated scans for known, unpatched flaws before deploying anything...
Defense in depth strategy — TechOnPurpose TOPCYBER21 cybersecurity framework protects your organization from vulnerability exploits

Why Patching Alone Won’t Stop 40% of Cyberattacks

⏱ 4 min readKey Takeaways A defense in depth strategy is no longer optional — it's the only architecture that holds when patching alone fails. Nearly 40% of all intrusions in Q4 2025 were caused by exploited vulnerabilities — not phishing, not credential theft. Some...
2026 National Cyber Strategy Blog Post image

2026 National Cybersecurity Strategy: What It Means for You

⏱ 5 min readKey Takeaways The White House's 2026 national cybersecurity strategy introduces six strategic pillars — the clearest federal signal yet that passive cyber defense is no longer acceptable. All six pillars align directly to the TOPCYBER21™ framework — if...
TechOnPurpose achieves MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally—a significant jump of 32 positions from last year's #191.

TechOnPurpose Named to MSSP Alert’s 2025 List of Top 250 MSSPs – Climbs 32 Spots Year-Over-Year

TechOnPurpose is proud to announce its inclusion in MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally - a significant jump of 32 positions from last year's #191. This marks the second consecutive year...
#STOPtheCYBERinsanity image - Is Pen Testing a Dollars-Before-Defense Mistake

#CYBERinsanity: When Pen Testing Becomes a Dollars-Before-Defense Mistake

The Fallacy of Pen Testing as a Priority in Cybersecurity If you’ve been following our STOP the #CYBERinsanity series, you already know this uncomfortable truth: Most cybersecurity failures aren’t caused by brilliant hackers or exotic zero-day exploits. They’re caused...
en_US