News in the Channel - issue #42

AI SECURITY

CONTINUED

Backup With threats on the increase, backup is crucial in case there is a breach. But this too is becoming more complex. Paul says geographically separated immutable copies remain best practice (3-2-1 style). “Immutability should increasingly be regarded as a baseline requirement regardless of customer size because ransomware and AI-driven attacks don't distinguish between organisations,” he adds. “However, resilience is about more than maintaining multiple copies. Partners should be thinking about end-to-end cyber resilience, ensuring storage itself is designed to resist tampering while also considering architectural separation, recovery objectives and long-term operational resilience.” Alex says every customer, regardless of size, needs an immutable recovery point. “But resilience is about more than storing multiple copies,” he notes. “The more important question is whether recovery remains operationally independent. If backup and production share the same hyperscaler, infrastructure and operational dependencies, organisations may simply be duplicating the same risk. True resilience comes from separating production and protection.” Geert says the principle should be resilience by design. “Immutable backups and geographically separate copies provide an important safeguard against ransomware, operational failures and human error,” he adds. “The exact approach will vary by organisation, but it’s increasingly difficult to argue that any business can rely solely on prevention. “A strong backup and recovery strategy remains one of the most effective ways to reduce business impact when something goes wrong. However, backups are only part of the answer. Modern ransomware attacks increasingly involve data theft as well as encryption, so organisations also need controls that help prevent sensitive

information from being stolen and misused in the first place.” Scott agrees that MSPs/resellers should ensure there are immutable backups and copies held on different sites. “But this can’t be a governance/compliance tick-box exercise,” he warns. “Immutable, isolated, offline/off-site and multi-site backups would be strongly recommended as ransomware resilience controls and part of a tested recovery strategy. This stops attackers being able to target backups and gives MSPs an effective way to recover from a breach.” Trusted advice With such a complex and fast-moving cybersecurity picture, it means resellers must be careful in their conversations with customers on this topic. “The conversation should move beyond ‘Is my data backed up?’ to ‘Can I recover it independently?’” says Alex. “Customers increasingly want to understand recovery times, operational dependencies, testing, identity protection, jurisdiction and who ultimately controls access to their data. AI has accelerated that shift because organisations recognise they may not always have time to prevent an attack, but they still need confidence they can recover from one.” Paul says that rather than leading with cyberthreats, partners should help customers understand that successful AI depends on trusted data. “Conversations should focus on how data is organised, governed and made available to different AI workloads, ensuring organisations can scale AI initiatives without creating new operational bottlenecks or unnecessary complexity,” he says. Geert adds that governance, identity and accountability should be at the heart of the discussion. “As organisations introduce AI into business processes, they need to focus not just on the models themselves but on what those systems can access and do,” he says. “AI agents, service accounts,

Contributors

Scott Rogers

uk.tdsynnex.com

Paul Speciale

scality.com

Alex Walsh

keepit.com

Geert Busse

westconcomstor.com

44

Powered by