All about backup
Topics at a glance
What is a backup?
General answer: A backup is a copy of the data in case of an emergency. Correct! BUT, is one copy enough? As learned with the backup rule, it always requires multiple copies.
This answers 90% of the question. Unfortunately, however, the devil is in the detail here too. For example, with the sheer volume of data, how can I determine that a user has deleted something? This deletion was, of course, also correctly mapped on my copy during the last backup, so this file is gone forever.
How about if we work with versions? So we make one (or two) copies of our data every day from scratch and never overwrite anything.
Sure, it’s a good idea, and it would work if the cost of the storage capacity didn’t increase immeasurably at some point. Ergo, it would be clever to only record the changes daily, but not to change anything in the original backups.
In addition there are other, very important, questions that need to be considered: What data are we talking about at all? Where is my data actually stored? Can I download it there automatically? Where should I then store my backups to cover all eventualities? Who has access to my backups and how? Should I manage this myself? Who has insight into my data? If someone else does this for me, can I prosecute them if my data is suddenly offered for sale on the Darknet? What is actually the case with the immutability of the backups in the event of a virus attack (ransomware) and why can I trust which service provider?
As you can see, this is only a small part of the decision-making factors that need to be taken into account, and the subject of backups is unfortunately a little more complicated than we thought. That’s why we want to advise you as best we can in the decision-making process – we know the details and the pitfalls, it’s the one thing we do every day and have been doing for over 20 years!
What is a Cloud Backup?
Cloud backup is the service whereby a company’s data is stored on a remote server. This internet-based computer technology allows users to access their data – whenever and wherever they need it. Thanks to cloud backup services, copies of your data are automatically and continuously sent to the cloud. This ensures an up-to-date backup of your data and your data can be restored easily and quickly.
What are the advantages of the cloud?
- Accessibility – data can be accessed from anywhere in the world and any device with an online connection.
- Disaster Recovery – SMEs as well as large companies can quickly and securely access and restore all their backed-up data in case of an emergency.
- Security – Cloud providers, especially private cloud services, offer the best possible security standards and procedures to protect customers’ data stored in the cloud.
- Data consolidation – Thanks to the huge storage capacities provided, users can consolidate their storage resources from multiple locations locally and globally.
Do you have a new cloud backup project in the pipeline? Put your trust in MOUNT10 – winner of the BILANZ Wirtschaftsmagazin Telekom Rating 2022 in the area of cloud services for business customers. We offer a variety of backup solutions tailored to your needs.
Why does Microsoft 365 require a backup?
Many companies assume that their data in Microsoft 365 is automatically fully protected.
That is not the case.
Although Microsoft provides the infrastructure, customers are responsible for protecting and restoring their own data.
Want to find out more? Read the full article on our blog.
The golden backup rule
With the 3-2-1-1-0 backup rule, you cannot prevent an attack, but attacked systems are back online within minutes – and with the latest data.
3 – Keep at least 3 copies of your data.
Protect your data sufficiently. The probability of something going wrong on 3 devices at the same time is much lower than with two.
2 – Store backups on 2 different media
It is recommended that copies of backed up data are kept on 2 separate types of storage (tape, external hard drive, cloud storage) to minimise the chance of damage from a total failure in an emergency.
1 – Keep at least one backup copy off-site.
What if a state of emergency occurs and things you don’t want to imagine happen anyway; water in the data centre or fire in your own premises?
This also applies to cloud services. Microsoft has addressed this in the SLAs: “We recommend that you regularly back up your content and data stored in the Services or store it using third-party apps and services.” (Link: https://lnkd.in/g9zRuPRU 6. Availability of the services).
Supplement your backup concept with a backup solution from an external company to have certainty that no matter what, your data is kept safe and you can access it at any time in case of emergency.
1 – Create at least one backup copy offline
Keep at least one backup copy separate from the network and any IT infrastructure. This can be rotating external USB hard drives, analogue tapes or storage with immutability function. Then, if a hacker gains access to your data, everything on your network is vulnerable.
0 – Make sure your backups are error-free
In an emergency, faulty backups could cost you your business. Did you know that our support team checks your backup process daily and will contact you immediately in case of irregularities or a failed backup?
Don’t sit back and be without data and complement your backup strategy with the Swiss market leader MOUNT10!
How do I make a backup?
You have important documents that need to be protected from hacker attacks and other dangers, but you have never made a backup?
The basics are pretty simple:
- Take a storage medium (external hard drive, NAS or a cloud storage)
- decide which data is really important and close to your heart
- Then copy it to the chosen medium so that you can still have it “under your pillow” in case of an emergency.
This guide is a perfectly valid approach for home use, but it is not practical in a business environment.
In business, one should eliminate the possible sources of error. This can be ensured with an automated process. However, it is crucial for an error-free backup to ensure that this automation is monitored to see whether it really always works reliably. In addition, this process should also be tested regularly so that in an emergency all data can be accessed again within minutes and operations can continue “normally”.
Furthermore, one must ensure that no backdoors are created for industrial espionage and unwanted readers of one’s own data.
The next important question to ask is whether it makes sense to have the backups under one’s own control. Wouldn’t it be better to leave this to a professional organisation, which could also be important for compliance?
And because one does not want to buy a pig in a poke, it would still be important to find out what references the service provider can show in its portfolio.
In addition, you should find out whether competent staff can help immediately and at any time of day in the event of an emergency – ideally in your own national language.
There is a wide range of reasons why you should work with us. Let us know where you still have questions or what you are missing, and we will make sure you are prepared for an emergency.
Be aware, backing up or restoring are two different things. Don’t just sit back and be without data!
Which backup strategy is appropriate?
What do I have to consider, what is pragmatically implementable and good enough?
A good backup strategy starts with answering the following questions: Which data is really important for me and which less? Which systems do I need to be able to restore quickly in order to keep my business running?
For data backup, a good guideline is certainly the well-known 3-2-1 backup rule, 3 copies on 2 media, 1 of which is external. As long as the immutability of these backup stocks can be ensured, you have already done a lot right.
This backup philosophy also applies to your data that is stored with a provider such as Microsoft or Google. You will be made aware of this, your responsibility, by the cloud providers in the small print.
We recommend a combination of short-term immutable storage of all your systems and long-term immutable storage of your data.
If you are able to restore your entire systems within a useful period of time, this forms the basis for high and continuous availability of your entire IT infrastructure. Experience shows, however, that this function only really makes sense with reasonably up-to-date systems, i.e. it brings you no additional benefit if you keep copies of entire systems for a long time, because the up-to-dateness of the systems contributes significantly to their usefulness.
With data, on the other hand, the situation is somewhat different. Whether you are legally obliged to keep your important data, business transactions or intellectual property for a year, ten years or even longer, or you simply want to make sure that if an employee leaves your company, he or she can damage you by deleting data that is not immediately noticed.
But what is the really important data? Everyone knows which data is REALLY important and which data is REALLY unimportant – unfortunately the grey area in between is very large.
In the end, the most sensible thing to do is to back up everything except the really unimportant data.
A successful backup strategy also includes a recovery plan. In this way you ensure that all parties understand their role and can perform it in an emergency. The whole thing should not be a purely technical exercise and should be run as a simulation from time to time. This allows you to have a clear, “simple” path to recovery in an emergency. Because in an emergency you cannot think freely, you have to be able to stick to a simple emergency plan with simple structures.
Conclusion: The right backup strategy must be well thought out, automated, tested and yet as simple as possible so that it really works reliably in an emergency.
How often should a backup be tested?
Simply having a backup is not enough. What matters is whether it works when it really counts.
Many companies invest in backup solutions – but then blindly rely on everything running smoothly. However, without regular testing, it remains unclear whether data is complete, systems can be restored properly, and the defined recovery times are actually met.
In an emergency, there is no time for that. Within minutes, it becomes clear whether the backup is a genuine safeguard – or merely a false hope.
The crucial question is therefore: When was the last time you successfully tested your backup?
Read more on the blog.
What risks do I need to be able to cover for my backup?
When it comes to backups, people often talk about the risks, but it is actually the benefits that should be highlighted.
The benefit is that in the event of a data loss, the necessary parts or the entire data stock can be recreated from the backup.
To make this possible, the data must be well protected and immutable. Like this no virus can alter these backups and make them unusable. In addition to such a virus, the backup must of course also not be able to be changed negligently or even wantonly.
The benefit of a good backup, such as that of MOUNT10, is therefore a “silver bullet” for the worst case scenario, which is very likely to occur.
Can your company be blackmailed?
Unfortunately, attacks by cyber criminals continue to increase steadily in 2023, so that no company is safe from cyber attacks any more.
With the free guide from the Swiss Cyber Defence DNA (SCD-DNA), you can easily and efficiently set the hurdle for hackers high enough to prevent your company from being blackmailed.
Learn more about the non-profit initiative here: scd-dna.ch
What happens during a ransomware attack?
Your business is just one click away from a total shutdown.
No sophisticated hacker attack, no Hollywood scenario – a single moment of carelessness is all it takes. And suddenly your data is encrypted, your systems are shut down and your business is paralysed.
The uncomfortable truth: in many cases, it is not the attackers who fail – but the preparation. Backups are in place, but unusable. Contingency plans exist, but have never been tested.
When the worst happens, only one question matters:
Can you get your business up and running again tomorrow – or not?
Read more on our blog.
What measures can I take to protect my SME from a ransomware attack?
According to a recent study by Mobiliar, almost every third Swiss SME has already been the victim of a hacker attack. With a few simple preventive steps, you can protect your company from the worst and be back online within minutes despite the attack – and without data loss!
- Make regular data backups & create write-protected backups
- Install malware protection, internet & spam filters
- Secure networks & remote accesses
- Regularly update hardware & software
- Password policy & defined roles for employees
- Clear emergency processes & use of independent technology
What to do if a cyberattack does occur?
The National Cyber Security Centre NCSC advises the following steps:
- Put emergency plan in place, disconnect all systems from the network, change login credentials and turn off Wi-Fi.
- Be sure to report the cyber incident to the National Cyber Security Centre (NCSC) – regardless of whether damage has been done or not: NCSC web form
- Report criminally relevant incidents (intrusion into data processing system / theft / extortion) to the police: Dial 112 or contact your local police station: www.suisse-epolice.ch
- The NCSC helps to assess which malware has affected you and whether other companies have been affected.
- The police advise and support further action, e.g. whether a ransom should be paid
- Specialised private companies help to repair and, if necessary, restore your infrastructure
How do I know that I have been the victim of a ransomware attack?
You will probably not notice the attack immediately.
Many attacks take place before the weekend, i.e. you only notice it on Monday. Usually, your data is encrypted and a text file or screenshot with instructions is shown.
You can find out what to do after an attack in our blog.
Will cyber insurance help me in the event of a ransomware attack?
Conditional.
A cyber insurance policy can compensate you for the financial effort in the aftermath of a cyberattack.
Therefore, it may make sense to look into it.
However, it will never get you your data back or cover the damage if you have lost your data.
Read more about this in our blog.
What are the benefits of securing my data with MOUNT10?
MOUNT10 does nothing but protect your most important asset, your data – and has been doing so since 2005.
Whether backing up individual local files, virtual machines or the entire Microsoft 365 environment, we offer solutions that meet your exact needs and let you sleep easy.
- Your data is encrypted and read-only
- Your data is kept in duplicate
- Your data history cannot be deleted
- Your backups are checked daily
- We thank you for your trust in us with free and competent support
External auditing firms are increasingly pointing out the necessity of external data storage and independent operating personnel!
Trust the more than 3’500 satisfied MOUNT10 customers.