Indonesian government datacenter locked down in $8M ransomware rumble
theregister.com
theregister.com
but first, offline full backups that get tested.... why doesn't anyone do this any more?
Many people and organizations decide it's cheaper to not spend money against a potential threat or risk, and to their credit it is in fact cheaper.
That is, of course, until the threat or risk becomes real rather than potential. Suddenly you have Lady Luck staring you down at your front door, invoice in hand demanding immediate payment of principal and all interest accrued.
Incidentally, this is why (at least at the consumer level) cloud storage and backups have become so prominent and in many cases forcefed by hardware, software, and service providers: Because it's hands-free and cheap data security for most consumers. Unfortunately, this doesn't always scale to large enterprise organizations.
The proposition then becomes "Our last non-compromised (as far as we know) backup is half a year old, can we afford to lose months of progress, or should we just pay the ransom?".
Or perhaps the attacker doesn't have a persistent foothold, but can make a credible claim that they do - do you take the risk? Keeping in mind that every moment you burn investigating and trying to discover the extent of the compromise is another moment you're down and burning money.
Every business-critical system and service, including every user account used, first needs to be inventoried and then inventoried on an ongoing basis.
With that, data can be roughly sized and classified with a business impact analysis - "How much money do we lose if X?".
From that, backup jobs/agents, retention schedules, and other forms of mitigation investments can be made.
PS: It's heartening to see CommVault is still in business.
EDIT: I once bought a FireKing smaller 3-hour data safe and implemented a barcoded LTO GFS policy using Iron Mountain as the offsite vaulting vendor. Sadly, FK no longer make safes for tape media anymore. It looks like IBM/HPE/Quantum LTO-9 tapes and drives are about the only games in town, and around $80 for 18 TB making them half the gross cost of circular spinning rust. Amazon's Glacier uses low-speed circular spinning rust like Facebook does for colder storage.
You set up 2 servers on either side of it, and you mirror the data across the link, repeating the state of the buffer with forward error correction.
A typical use would be to allow remote monitoring an industrial control system, collecting logs, etc. The data diode assures data can egress, but control can never ingress.
!?
That ain't no backup
Also, Amazon Glacier is a pretty cool service, and it's incredibly cheap.