As a response to the increasing skill of cyber intruders targeting organisations of all sizes, it’s become common for security teams to adopt ‘zero-trust’ methods to protect their companies’ people and intellectual property.
The basis of zero-trust is a default position of refusal by security systems to access information, by users, machines, and services at every stage of interaction with IT systems. Unless an entity (a user, or a remote system, or internal application, etc.) can safely prove their veracity and identity, the default refusal of access stands.
The zero-trust paradigm extends logically to immutability, a “write once, read-many” data structure that doesn’t allow any change to stored information, be that editing, encryption by bad actors, or deletion. Immutable data is the impenetrable core of important information in the modern organisation, kept separate from typical IT systems that, to function, have to allow changes to be made. For companies that truly value their intellectual property, immutable storage (often called immutable backups) are the guarantee that data remains safe in the event of cyber incursion or natural disaster.
The go-to company in the immutable storage space is Object First, a company founded in 2022 by the co-founders of Veeam to provide on-premise immutable object storage for Veeam backups. We spoke recently to Anthony Cusimano, the Chief Evangelist and Director of Solutions Marketing at the company, about immutability, air-gapped data, hardware backup appliances, and security layering.
“Our Object First appliance was built with immutability and zero-trust baked in—it’s secure by default straight out of the box,” he said. “Immutability in backups means you have a copy of your data that can’t be changed, deleted or overwritten—it’s the old ‘write once, read many’ principle.
“A lot of people tick a box and assume their snapshot is ‘immutable’, but that’s not the same as true immutability.”
In today’s ransomware attacks, among bad actors’ first acts is to disable or encrypt backup repositories, thus removing recovery options. Effectively air-gapping data repositories with immutable storage is the final layer of a security posture that ensures a business can get back up and running in the event of the worst happening. In combination with role-based security policies in zero-trust frameworks and multi-factor authentication, organisations have the very best chances of business continuity.
“If a bad actor with admin rights can just delete your backup, it was never truly immutable in the first place,” Anthony told us. “Unplugging a network cable and calling it an air-gap misses the point—if you can plug that cable back in, the data was never really isolated.”
The concept of air-gapping data is as old as backups. But where previously, data might be written to tape or external drives and sneakerware-d off-site (carried away and in a remote physical location), today’s immutable backup solutions are crated by network-isolated, S3-compatible storage buckets. Unlike tape, it’s a faster way to restore data, and much simpler to recover. There’s also no need for large-scale changes to IT teams’ workflows – immutable snapshots can be automated with just a few clicks in existing Veeam backup dashboards. Companies using virtual images will already likely be doing something similar, and the Object First appliances plug straight in, are modular for expanded needs, and are ready to go, right out of the box.
Anthony said that it’s important to plan capacity, tiering short-term hat tier data for instant restore, mid-term immutable object store, and optional cold or archive tiers for regulatory retention.
“We always advocate the ‘three-two-one’ rule: three copies of your data, on two different media, with at least one copy off-site—and make as many of those immutable as you can.”
The Object First UBI appliances offer a solution on each of those tiers, and can be chained together or expanded to handle increasing data amounts (20TB to 7PB) as the organisation grows. That means companies can reduce the patchwork approach many have taken as backup facilities have grown organically, often a mixture of NVMe, Flash drives, spinning rust, offsite backups, tape, cloud storage, and cold-storage archives.
In recent years, many companies heeded the call to the cloud, and have found that the costs of cloud storage for backups at many levels to not be cost-efficient. The S3-compatible Object First storage devices, therefore, offer a real cost-saving alternative to cloud storage, without having to invest in new workflows and tooling.
As appliances slot in, teams get one interface to manage all devices, which are effectively self-sufficient: there’s no RAID tuning or balancing needed, and updates to software and drive firmware is automatic. Anthony did point out that even the most paranoid systems administrator gets access to a deep level of metrics and attenuation methods, but for the vast majority of storage professionals, setup, maintenance and oversight defaults are more than adequate.
What the organisation gets complements their layered approach to cybersecurity, with highly-compliant immutable backups inaccessible by even internal staff, adding a massive degree of reliability in data restore, plus incredibly quick restore times. The mantra of backup (three copies, on two different media, one off-site) can be expanded for the ransomware age. There can now be a further layer of air-gapped and immutable data, one that has zero recoverability errors.
There is still need, of course to practise regular recovery drills, and maintain existing cybersecurity measures. Object First offers an additional layer of surety, important as bad actors become more conversant with new techniques of infiltration, data corruption, and IP exfiltration. Separated from the rest of the stack, the true-immutable backup solutions are available to step in and get a company back on track in the event of a disastrous incident, whatever its cause.
To find out more about Object First, head to the company’s website, and check out a podcast we recorded with Anthony recently, for more on the same subjects.
Author
- View all posts
Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.