Veritas Technologies’ Matt Waxman on Thwarting Ransomware Attacks
Matt Waxman, senior vice president and global general manager for data protection for Veritas Technologies, explains why thwarting ransomware attacks requires a different approach to backup and recovery than other types of disasters.
Transcript
This is Textron tv. Hey guys, thanks. We're here with Matt Waxman, who's senior Vice President and General Manager for Data Protection for Veritas.
And we're talking about the subtle differences between trying to protect data in the context of a disaster versus ransomware because, well, one size does not fit all. Hey, Matt, welcome to the show. Hey, Mike, thanks for having me.
So, most folks I think are just basically, you know, we're doing data protection. It's same everywhere, no issues, and we'll just execute until, you know, the moment arrives when they need it, and suddenly they realize there's a whole host of things they should be considering. So walk us through the differences here.
Yeah. You know, um, I wish it were as simple as just saying, once you have a backup, you're, you're all good. Right?
But the reality is, um, you know, there's a pretty big difference between dealing with things like a natural disaster or a power failure or those types of things versus a cyber, uh, incident. And, um, you know, have this conversation very frequently with customers. And I think it's, it's simple when you start to think about what would you do in those cases?
Let's take an example. A power failure, right? A power failure, uh, could be something that is, uh, gonna last for an hour.
It could be something that last for a day. So you have a decision to make, right? As an organization, do you want to, um, wait it out, or do you wanna continue your operations in some other location, a secondary site cloud, so on and so forth.
It's a pretty straightforward set of decisions to be made. Uh, most organizations these days have a disaster recovery plan. They've executed that, they've rehearsed it, they've practiced, and, uh, so you push a button and, and you just go.
But the difference in the cyber world is now you're dealing with, uh, an advanced adversary. They're, they're trying to make it as difficult as possible for you to be able to continue your business. Um, and they're going to, uh, do that in an adaptive way.
They've hit you in one way, and then they see that you're starting to bring systems up, they're gonna hit you in another way, or they're gonna take out your messaging system when you're trying to communicate amongst your teams, uh, to be able to coordinate what you're gonna do to recover. So it becomes far, far more complex to deal with a cyber event than any of those other types of events that are largely temporal. The cyber event too, sometimes, you know, it feels like they're targeting the backup systems first because they wanna knock those offline and then they launch the primary attack.
But, um, you know, are they adjusting their tactics and techniques as people get savvier about backup, but maybe not about protecting the backup? Yes, it's, it's, uh, definitely the case that, you know, the, the backup infrastructure has become a prime target for obvious reasons, right? If you take out the backup infrastructure, that is your last line of defense for, for most organizations.
So it means that the data protection infrastructure has to become much, much more resilient unto itself. All the things that you would expect at your network layer, at your application, layer zero trust architectures, all those sorts of things you need to apply to your data protection environment as well. But it also means that, uh, you need to have other safeguards in place.
There are more advanced ways to protect that data, making sure you have multiple copies of it, making sure you're putting, um, analytics and monitoring in place to be able to, uh, look for anomalous behavior that may be happening, uh, not just on your network, but within your data itself. So the, the backups have, have to become much smarter than just what we thought of as tape for decades and decades just sitting there off on the shelf. They need to be actively used to protect the data themselves.
When we have some sort of outage, we're generally happy to have a copy of our data that we can restore it from, and there was some sense of urgency, but I feel like with cyber attacks and ransomware, the recovery time urgency is a lot higher. So, you know, does that factor into our thinking? Yeah.
You know, there's, um, uh, for those that have been in this space for a long time, either on the vendor side or on the, the customer side of things, we've talked about recovery time objectives and recovery point objectives, RTO and RPO for a very, very long time. How quickly can you get the data back? And this, the, the, uh, goal was always, how do you do that in minutes, right?
How quickly could you fail over and get your data back in your applications online? And there are absolutely systems today that allow you to do that in minutes. Um, but in a cyber event, uh, you know, you look at the typical event that's happening out there, there's been some very public ones over the past couple of years, of course, where, you know, it's, uh, weeks of downtime.
Um, you know, you look at some of the attacks that happened in the Vegas casinos, uh, last fall, right? And, and they were weeks of time where, you know, they couldn't necessarily process bills the same way they have in the past. Uh, customers couldn't even get into their hotel room, uh, without a manual key.
And so, you know, the, the outage impact is far, far greater. So what we like to talk to customers about, and you hear this sort of language starting to formulate a lot more, is the notion of a minimal viable business, right? Because when you have, if you're a bank or you're a casino, or you're a retailer or so forth, there are a set of business functions that are absolutely the most critical to get operational to just keep your lights on, right?
It could be your payment system, it could be your customer support system, so on and so forth. You gotta first start by identifying those and then working backwards from that to figure out, okay, what are the safeguards you're gonna put in place? How do you ensure that data is protected as much as possible?
Uh, what are the tools that you're using? How have you actually rehearsed a plan and practiced that to be able to recover in those cases, so on and so forth. But that minimal viable business that MVB right, is, is the thing to really hone in on because you can't bring, it's just not practical to bring an entire global business back online in, in minutes after a cyber attack.
We used to have, along with, uh, RTO and RPO, the notion of 1, 2, 3 in terms of our copies of our data. Do we still do that? I feel like a lot of folks are like, well, it's up in the cloud, I'll just get it.
Yeah, it, it, uh, we still do that. Yeah, it's still pretty important. And, you know, it's one of those, I know I find myself reminding people that it still applies whether your data is in the cloud, whether your data is in a hyper-converged infrastructure, uh, whether it's in a traditional multi-tiered app, it, it, it really doesn't matter.
The foundation of that was, you know, it's important to keep at least three copies of your data, keep them in two locations. If you're in the cloud, that means, uh, think about getting at least to another availability zone, another region, if not to another cloud, uh, to, to segregate that out and make sure that one of those copies is truly, um, tamper resistant, right? Is really immutable at, at its core.
Um, SaaS-based applications, I think really hold, uh, the same case. And, and they're just too easily overlooked, right? Because the data is the same.
If you're, I'm not gonna name any particular vendors, but any of the major SaaS applications that most organizations use, they're critical to your business function. Why wouldn't you be applying the same best practice around that data that you would any of your traditional on premises, you know, large database applications. So, 3, 2, 1 still holds true today.
Do you think at some point we might be applying various forms of AI to this process? 'cause it seems like there's a, a ripe opportunity here to automate something. Yeah.
Uh, you know, we have been, um, certainly at Veritas, we have, uh, implemented AI and machine learning in multiple ways. And, you know, like most things, it's not a silver bullet because, you know, there's, uh, AI that you can use to detect anomalous behavior. Uh, but that's different than what you would do to, uh, say generate an insight into how data is being used or to detect, uh, user behaviors.
So, you know, these things are constantly evolving and certainly things like generative AI have led to new opportunities, uh, to do those things. But the, the way I, um, like to think about it is the number of attacks, cyber events and attacks that are going on these days, uh, you can't keep up with just as humans, uh, because the adversary is now using AI themselves, whether that's to generate the phishing campaign, uh, or that's to just automatically, uh, go out and, and try, uh, to breach the volume, the sophistication of those things has continued to grow, uh, in a non-linear fashion, right? And so how do you combat that?
You can't combat it with just adding more humans to monitor the systems and so forth. You have to use AI to do that. And so, you know, those are some of the ways that we've been investing is, you know, putting the, um, the human centric threats, uh, in the forefront and looking at how we can apply things like AI to solve for some of those things in a more efficient, more scalable, uh, manner Is the way this process, uh, is managed changing.
And I'm asking the question. 'cause, you know, back in the day, if I wanted to find out who was in charge of data protection, I would just go find the person who's lowest on the totem pole and go from there. But, um, you know, is that love all and elevate it?
Yeah. You know, you bring up a really fascinating point because, um, you know, certainly as roles have evolved, you look at things like, uh, cloud native application development. You know, there's a different set of, uh, personas who are building those applications who are responsible for building and running them than traditionally would've been, you know, your IT staff, your app development, or your line of business, so on and so forth.
Um, cloud architects, platform engineers, um, all sorts of personas that now are part of the responsibility of ensuring that your data is resilient. Not all of them are steeped experts in data protection, nor should they necessarily be. And so, uh, one of the ways that we are applying AI is to take the knowledge, the depth and breadth of what those backup administrators, um, have been doing for decades, and make that more easily accessible to those who aren't the backup experts and don't have the time to become the backup experts.
And that's a great way to leverage generative ai, right? Is to be able to take what was a very complex task with deep amounts of knowledge and turn it into a natural language, uh, interaction, right? That, that you can have.
So, um, but that's constantly evolving. There are SaaS app admins now, right? That, that manage large SaaS implementations.
How are they thinking about data protection? Um, that will continue to evolve over time. So what do you see people doing that just makes you shake your head and go, folks, we gotta be a little bit smarter than that.
Um, well, you know, I'll say that you, you brought up the 3, 2, 1 rule before. I think if I put that sort of into a category, the basics matter, right? It's, it's like hygiene in a way.
So, um, there are so many good tools that are baked into, uh, you know, these products and these offerings and these services that, uh, people just need to take advantage of. You know, the classical one that, uh, it, it feels very redundant to talk about it, but it's so important is multifactor authentication. If you don't have that turned on, it's literally the biggest, simplest way to prevent most, uh, attacks.
Uh, and it's right at your fingertips to be able to turn it on. We all turn it on our consumer devices. Why wouldn't you be doing that on your infrastructure?
So, uh, it sounds a little boring, but like getting those basics right, making sure you've got three copies of data in two locations, um, those types of things really matter. They make me shake my head when I sometimes encounter someone who is operating a very, very large business yet, um, you know, hasn't, hasn't turned those things on. Is the volume of data that we're dealing with also much larger than it used to be.
And of course, it seems like it's just getting bigger all the time. It is, it is. And, and this is why I think that, um, rehearsals, drills, however you wanna think about them, are so important because it's one thing to have the theory written down on paper, have done a tabletop exercise to figure out, okay, this is what we're gonna do when we have an incident like this.
Um, maybe it's pretty straightforward to try that out on a demo application and demo environment, so on and so forth. But when you have to do it at scale, um, it's a whole different ball of wax, right? And one of the things that you saw in the early two thousands was disaster recovery testing started to become a normal function in a lot of organizations.
And now you see regulation actually coming around that, uh, especially in the eu, it's, it's evolving a little bit more rapidly to ensure that, um, customers are validating that they can respond, that they can recover, and they can do it in a timely fashion. And it's like anything practice makes perfect. So if you're not practicing this stuff, how do you know when the time comes are you're gonna be able to, to execute on it.
All right, folks. Well, you heard it. Here is an old joke about it.
You know, how do you get to Carnegie Hall? Practice, practice, practice. Same thing goes on with data protection and everywhere else we are.
Matt, thanks for being on the show. Thanks, Mike. All right.
And back to you guys. And Steve.