Agent-Based Data Protection – Bret Piatt, CyberFortress
CyberFortress CEO Bret Piatt explains why agent-based approaches to data protection in the age of remote work are back in vogue.
Transcript
This is texturing TV. Hey guys. Thanks to the throw.
We're here with Brett Piet whose CEO for cyber Fortress and we're talking about endpoints and agents and data protections and lines and bears and tigers. Oh my Brett welcome the show. Thank you.
Michael happy to be on we've been having this debate about agent versus Agent list forever in a day and it seems though that with more people working from home that maybe the argument is Shifting more back towards an agent because we need to do more things or what do you think is going on with this whole agent agent list debate at the moment. Yeah, so bit of about me. So I've been in the internet for 20 years and we've gone back and forth between client server on applications Thin Client thick client agent lens versus agent on backup as CEO of cyber Fortress global data backup and Recovery company.
We talked with customers about this on a regular basis. So what we're seeing and what we we've seen in some data from Gallup recently is now more than three quarters of workers are spending at least some time at home and a larger much larger amount of them are never coming back into an office. So the the agent versus Agent list if you have valuable data on employee computers, if you're unsure if these employee home networks are as secure as your office Network, you may need to back up more frequently there maybe a higher risk of accidental spills or other things pet related at home.
You don't seem to have happen at the office which leads me to believe that many organizations with this change over. Bit need to look at their endpoint backup strategy and think about agents for those workers that are either predominantly from home or much more frequently from home. Is it more challenging now to because the situation is a little more fluent people are working from home a couple of days and then they're going back in the office because the boss wants to have everybody together at least a couple of days during the week.
It seems like the whole situation is a lot more fluid. So do I need agents in both locations or do people want to mix and match or can I even do that or should I just go with agent straight up because I just don't know where anybody's gonna be in any given time. Yeah, and with the agent-based solutions, you can have agents connecting into a centralized system at the office.
You could have an agent list system polling the devices and pulling data from inside the office. You can also elect for agent-based solutions that securely encrypt the data and store it to a cloud directly. So it'll go directly from wherever that employee is checking in at up to a secure company controlled cloud data repository.
We're seeing them with that Gallup data nearly one in four workers are not coming into the office at all anymore. So the even if this idea that folks are gonna be back in two or three days a week the data right now does not show that that's true for I mean potentially as many as 20 million American workers There's a lot of frustration with data protection and light of all the ransomware attacks that are out there. What do you see that people need to do better or they're not just doing and it seems like a lot of people are pointing fingers these days that data protection, but I just wonder if it's a matter of process rather than platform.
Yeah, I mean the ransomware and and any kind of accident or attack that's going to cause data loss is one where we recommend that you have training programs for your employees and the data protection solution in place. It's even if you have a great data protection solution. It's still not a lot of fun to restore from a backup.
Are the bad guys getting better at figuring out our work patterns and have a targeting a specifically it seems like early on we sent a lot of people home. We said here's your VPN and hopefully everything will work out but it seems to me that maybe that's not robust enough or people are targeting the VPN. So do we need to close the gap between cybersecurity and data protection more than we have thus far.
Yeah, I think many companies have seen with the the VPN and the amount of video that we're all doing today as we're recording this interview over the internet. If you've got thousands of employees going through a VPN then going back out to the internet to engage in video level applications that led most Enterprises to open up or perform split tunneling or set it in a way. We're not all the traffic is secured through that VPN.
So the attackers are taking advantage of this and looking at the type of applications that may not be through the VPN. Is there a way that they can reach those users and bypass maybe some of the security devices that were in place on the corporate Network and then secondarily hackers are using artificial intelligence and they're using all of the information that's publicly available about all of us to craft much more. Well written fishing emails.
It used to be that spearfishing was just something that happened to senior Executives where someone would do research and then try to Tend to be someone like me emailing my employees, but with the rise of artificial intelligence. Now everyone can be targeted in that individualized way. Yeah.
Right. Do you think that there's a greater emphasis on recovery these days because it used to be we would back things up and more or less hope that we can recover them. And if we didn't it was kind of annoying but it wasn't critical.
It's in the degree that it is today. So is there more emphasis on the amount of time it takes and recovery time objectives in general? This is one that ransomware has brought to light with just the increasing frequency of recoveries.
The data backup used to be that kind of last line of defense and it was something that you didn't a very often have to restore from but with the increasing frequency due to ransomware and other accidents that are happening more often the amount of time it takes to get your data back online has become much more Paramount and people are reevaluating all across the Enterprise's over the years as they've been kind of reducing budget to allow for a longer recovery time objective. Let's say if you're a big pipeline operator and these pipelines float a gas stations that run out of gas in a week, but it'll take you two weeks to restore and get your systems back online in the event of a failure that recovery time objective is really from a tech perspective out of sync with your business needs and with the needs of the market. So I think some of these situations where businesses Have had to pay large Ransom because their recovery time objective didn't match their business needs as they thought it did.
This is is one that's being reevaluated across the board now. We have cited three two. One is a best practice forever and a day now is that still the best practice is for the people need local copies and then a copy in the cloud and then a copy this offline or has that evolved as we've kind of moved along the path here in the fight against ransomware.
So with a endpoint set of data, I think you can have a copy that's on the local computer. You can have a copy that's in the cloud somewhere and then a copy that is stored in a read-only manner as well. So you don't want to necessarily just have a file sync and share Solution that's backing up the data off of your endpoint.
So if you spilled stuff on your keyboard, you could get the data out of that cloud if that cloud is not creating timestamp to read only copies of the data and marking it offline. Then it is vulnerable to ransomware or these other hacker threats that are out there today on the server level of data. This is one where we're not catching attacks for it used to be kind of up to 90 days.
I'm seeing much more now saying that hackers are getting in and waiting six months or more before they actually affect an attack. So if you're offline copies of your data, and you're those read only ones only go back 93 days, so you've got the full coverage for one business quarter. Not necessarily going to put you in a safe spot and if you've got to lose 90 days worth of that.
How do you think through the the ways to get yourself caught back up what level of work that is? So some of these threat scenarios now are causing folks to reevaluate three to one reevaluate ways to determine if attackers have compromised their systems much more quickly because it becomes very complicated to do a far back recovery and then a lot of manual data update. There's a lot of data protection platforms out there what differentiates one from the other these days?
So as you look at data protection platforms today, there's some that specialize in endpoint. There's some that specialize in bare metal servers. There's some that specialize in virtualized you have other specializing in Cloud applications that are running on infrastructure the service you have some that that focus on individual software as a service applications.
So as you go into all those different places businesses are running data backup today so that they can run a recovery in the event that they lose data off those platforms. There's specific features. You could drill down into each of those areas that what we're seeing across the market is you have this heterogeneous mixed environment and almost every business now, it's not that there's very few companies that have everything on premise or everything in their own data center or everything on a public Cloud at this point.
So they're either having to select multiple data backup and Recovery vendors or look for some of the vend. Out in the market that have the ability to cover and to end from endpoint through to software as a service. What is that one thing that you see organizations doing when it comes to data protection?
That just makes you shake your head and go. How come we're still doing this in the year 2022. So I mean with the email is the kind of first big SAS application that really went cloud cloud native for almost every business hardly anyone's running their own mail server at this point and everyone's not backing up that cloud email server.
So the cloud mail providers run highly reliable redundant systems, but they don't necessarily provide that safe second separated control and separated access read-only copy of that mail data. So we see folks that have their information out there on their mail server. Someone's account gets hacked all of their email gets deleted the data gets deleted out of the archive as well.
If they even have the archive set up with that vendor because it's under the same set of permissions and then that mail is lost and If for anybody to think about losing their whole mailbox, it's pretty terrifying and I think if you look at the number of companies that have a separated segregated controlled archive and backup of their email in the especially in the mid market and down into SMB. It's not very high from a coverage percentage perspective. And then the Enterprise it's probably only covered when and where required by regulation.
All right. It's amazing. They're worse things don't happen.
Hey, Brett. Thanks for being on the show. Absolutely.
Thank you, Michael. All right back to you guys in the studio.