3 ms·
I'd recommend a few things. 1. File history preservation. We use Dropbox Paper, which preserves file history - if someone were to delete all of our documents w
by staticassertion 5y ago
I'd recommend a few things.
1. File history preservation. We use Dropbox Paper, which preserves file history - if someone were to delete all of our documents we could recover them.
This is harder to do for production data, which may take up petabytes of space. Archiving out the data in big chunks can help here (we back up our kafka data to S3, for example, and the exporter will do that in batches).
You can also enable object versioning on those S3 buckets or prevent deletion/ mutation of objects. Another good idea is to use a uuid in the key name so that they can't be guessed.
2. Remove all forms of lateral movement. Move to a 'zero trust' system. Ransoming one machine is not worthwhile, attackers need to own a lot of your network if they want to monetize. They usually do this by traversing over as many machines as possible.
None of our systems can communicate with each other in corporate environments, and there's no remote execution protocols like SSH in our production environment (between servers). All access is explicitly authenticated and authorized.
There's lots of other good defenses but IMO if you do these two things you're in a very good place.
I wouldn't recommend "backups" generically. It's hard to do backups well and safely. (1) is technically a backup, but it's how the system works normally, it isn't some separate backup system that never gets tested. Backups are also very expensive, whereas zero trust is cheap.
- chopin 5y ago> Backups are also very expensive, whereas zero trust is cheap. Could you elaborate on this? I would have thought that they are at least in the same ball-park. I work at a large software company and we have a lot of internal systems one has access to. You have to harden your AD, you have to be very careful with single-sign on, etc. I'd bet, if I could compromise the machine of one of our employees I could do a lot of lateral movement. You must not only harden the production machine, you need to harden everything in the supply chain for those machines.
- staticassertion 5y agoI'm making a big assumption, which is that the company is young and starting to think about security. I'm not sure what you want me to elaborate on though. Backups have a very literal cost - storage, maintenance, etc. Zero trust is just a paradigm, it's no more expensive than any other approach, it's just an architectural choice. I don't think compromising our machines would be easy, nor do I Think lateral movement would be easy, but there's still more that we can do.
- syshum 5y ago>>> Backups are also very expensive, whereas zero trust is cheap. In reality the inverse is almost always true unless you are setting up a company from the start to be Zero Trust Implantation of Zero Trust on an existing network and existing company with establish business processes that depend on a non-zero trust network well that can be very expensive to implement. Also as we move forward in time with better and better immutable backup technologies the cost of the doing proper backups comes done. Finally with modern Ransomware it is not just about the encrypted data, it is about data exfiltration as well. This is where the Zero Trust model come in, to prevent exfiltration. At the end of the day Zero Trust and Backup are 2 different things, used for different purposes, Having Zero Trust does not mean you can forego backup. Having proper backups immutable does not mean can forego Zero Trust.
- staticassertion 5y agoTrue, I'm making an assumption that a company is young. For older companies it'll be years to move to zero trust - although, once you do, it's "free". Backups are pretty costly and that cost never goes away. I didn't say it was one or the other, I recommended both.