BlueXP is now NetApp Console
Monitor and run hybrid cloud data services
Hi, my name is Jason Blossel. I'm a principal marketing strategist at NetApp. And today I'd like to talk to you a little bit about cyber resilience and what that means to NetApp and what that really means to you as we partner with Google Cloud to deliver value added services to help you along your journey to protect and secure your data. It really shouldn't be a surprise to you that one of the top concerns among executives is cyber threats. And according to a research study by Aliance, they found that the top concerns of executives were that cyber resilience or cyber security with ransomware and data breaches being at the top of that list. Now, why would that be the case? Well, according to Sofos in the most recent report, they found that the average cost to recover from a ransomware attack was $1.4 million. That's a lot of money. Now most of that is the downtime associated with any type of data breach or ransomware or attack not so much the specific recovery time or even the cost of the ransom. Now it this becomes more important to consider as according to some NetApp research the most popular form of protecting data from a ransomware attack is data backup and recovery. And with the massive amount of data growth at 40 to 50% per year this backup challenge becomes more and more difficult. according to a study by veh which found that about a third of backups and a third of restoers fail. So relying exclusively upon data backup to recover from data uh from data um breaches or ransomware attacks really probably isn't the best strategy alone but others should be considered as part of the overall strategy. Now Netup has a lot of um credentials associated with data security. NetUP is the only enterprise storage vendor that's validated to store topsecret data. And what we mean by that is that NetUP is the only storage vendor listed on the commercial solutions for classified component list, which is a list of available um products and services for use with the NSA. Now, Netup is also certified with FIPS 140-2. We're on the data department of defense approved product list as well as being um involved with and supported and certified for common criteria. Our customers benefit from this and these are a few customers that are associated with our partnership with Google cloud. Carfor is a French retailer in the middle of a major digital transformation with really aggressive growth goals over the next several years. And they rely on netup cloud volume service and cloud volumes on tap on Google cloud for their cloud storage to support their existing applications as well as new containerized applications. Mailor light delivers an online platform for their customers to support email marketing campaigns. They send over 30 million emails per day with their digital service and they chose NetApp Cloud Volume Service on Google Cloud to deliver the performance and 247 uptime required by their customers. Dexcom is a leader in diabetes care technology and as a result of rapid growth they discovered their development environments were spread across multiple locations making collaboration and efficiency much more difficult. They turned to Google Cloud, Jrog and NetApp to consolidate their development environment and standardize on a common solution with NetApp Cloud Volume Service as their shared storage environment.Now, NetApp is addressing the challenges of cyber attacks with a datacentric approach based on the principles of zero trust which suggests an inside out approach to data protection and security. NetApp is a strong position to enhance protection and security solutions because the data sits on our storage to begin with. We can manage data copies, data access, and threat detection where the data actually sits. And we recognize thatdata protection and data security conversations are becoming much more crucial and much more important. In fact, thebarrier between them or the line between protection and security really is blurring quite a bit. And we call that cyber resilience. It's areas like ransomware that are driving some of thisneed to have not only the detection of the threat but also the remediation and recovery of data because at the end of the day most of the hacks that are out there in the market tend to focus on the data particularly file data and so the need to have both adequate protection availability as well as detection and threat remediation are critical to any strategy to protect against cyber threats.Now most of the attention around ransomware is on the recovery of data or ransomware recovery and you'll see that a lot with a number of different software vendors who deliver value in that space but it's limited to the backup or the secondary copies typically.Now from as I mentioned from NetApp's own research this is the leading approach by those whohave been surveyed that backup is their number one response to ransomware attacks followed closely by user behavior analytics but few storage vendors are designing solutions into the primary storage to prevent attack to begin with. Netup is a leader in integrated data protection and security and we're focused on not only the recovery of data but also the detection and prevention of attacks in the first place. Now, NetApp has a number of capabilities that deliver value for cyber security and cyber resilience and we've mapped them here to the um the NIST cyber security framework around identify, protect, detect, respond and recover. And we've simplified that a little bit with protect, detect, and recover. But we deliver value such as data discovery. I mean, it's critical to understand what kind of data you have in the first place before you start developing a strategy or implementation plan around the protection of data because not all data is of equal value. You may not want to protect cat videos and someone's music library. So, you want to know where the important data is and the less important data is as well before you decide how you're going to protect and secure it. We offer uh tremendous capabilities around protection and um data security to prevent the manipulation or the deletion of data. We have capabilities that allow you to detect threats rapidly and in real time both at the user level as well as detecting threats and how they impact your storage. And then we're able to respond in an automated fashion by either creating recovery points or by preventing user access. And then finally, we offer forensic analysis and the ability to rapidly recover data in order to get your business and organization back online quickly. And we'll walk through some of these. So, we deliver this value through a layered approach. Um, and we start off with the storage layer. So, Ontar is our flagship storage software that has built into it a number of tremendous features that we'll talk about in a moment to help establish the groundwork for your data security and data protection capabilities. We layer on top of that uh data services that are managed through the cloud across any environment uh to support your ONAP uh data protection needs by backing up to object storage. We also have capabilities to look at and discover what kind of data you have, permission optimization, and be able tomake plans on how to better protect that data. And finally, we have the ability to manage and look in your total infrastructure to see what kind of uh performance you have as well as user behavior analytics. All of these are managed through a single pane of glass or through single management platform called cloud manager which delivers simplistic uh capabilities to be able to uh monitor, protect and secure and manage your infrastructure across a hybrid multicloud.Now, we recognize that ransomware protection isn't just a single thing, right? There's lots of different concerns that you may have and lots of different issues that may come about that you need toplan for and prepare for things such as insider threats, data encryption, data deletion, malware, and even data theft. And I like to walk through these uh briefly with you and how NetApp can help address these challenges.So, starting with data or insider threats rather. Here we're talking about rogue administrators or maybe even compromised user accounts. It could also be disgruntled employees. Now, some of the challenges that we may be facing include identifying user account behavior anomalies or maybe requiring multiple admins to perform critical tasks, autotriggering snapshot recovery points, and even blocking compromised user access. These are some of the responses that NetApp can offer to protect against insider threats. And we do that through a number of products. One is as I mentioned the foundation of NetUP ontap which is delivered in the cloud or on premises as well as cloud insights which is an infrastructure monitoring and reporting tool that has capabilities built into it to look at the security of your data by monitoring user behavior. The next suation or the next user um issue could be data encryption. We're talking about the encryption of primary or secondary data. The response here would be through immutable snapshot copies. Also replicating and worm locked data copies. So being able to take those snapshots and replicating them to a sec secondary location, whether that's another ONAP device or whether that's in s um object storage and then being able to lock that data through intelligent and secure worm file locking and then also being able to provide storage performance metric alerts. So what often happens is that as data is being encrypted, it becomes less dduplicatable.It becomes less able to be dduplicated. And so as we start to see changes within the storage behavior then such as uh snapshot reserve or maybe efficiency changes that might be an indication of an encryption attack. The products that we're looking at once again would be ONAP as well as cloud insights. on tap providing a lot of the foundational capabilities at the data layer and insights with the monitoring. Data deletion is another problem. One of the challenges that organizations often face is that a hacker will get into their environment and start to delete their backup copies in order to prevent the ability to recover data. This is not the only threat. Other threats could be mass deletions by even an inside user who wants to do espionage.The response here would be automated AIdriven data discovery as well as secure worm file locking once again to prevent the deletion of data not just um the manipulation of data as well as anomalous user activity detection. The solutions that we incorporate here would be a version of ONAP as well as cloud insights cloud backup to provide the backup and file locking necessary as well as cloud data sense to understand who is touching what file and where as it relates to malware. This is predominantly an ONAP um deliver value, but we're talking about the malware saved to a storage system as well as the threat of malware activity within the file system. The response here would be known malware blocked from storage. Uh NetApp ontap has uh the capability to look at known malware extensions and be able to block those from the file system before they've even been written to disk. We also integrate with leading anti virus software systems so that anytime a file is accessed then we act uh we're actively comparing that against the database of known malware. files compared against malware prior to being opened is also another um value that we offer through that integration of anti virus software. And then file system anomaly detection to detect malware is a new capability that we've added to ONAP. And what this does is it starts to look at things like data entropy to see if there's an indication of possible ransomware attack or malware. And finally, data theft. Data theft is becoming one of the more uh concerning threats for many organizations. We're talking about the malicious exfiltration of data. And so Netup's response to this is to be doing more user behavior anomaly detection to see who's accessing what data. Should someone in HR be accessing engineering files as an example? And so we can detect who's accessing what and where and what they're doing with that data. And then as a response to that we can automatically block the suspected user account from the storage not through active directory but direct directly at the storage layer and we do that through a combination and integration of an ontap storage system combined with cloud insights which provides that capability to look through f policy to see the user behavior and the file access patterns. Anet's built a portfolio of solutions available in partnership with Google cloud and they're built on the foundation of ONAP. As I mentioned before, we offer two different versions of ONAP in the cloud on Google. One is cloud volumes on tap which is a virtual instance of ONAP available in the Google marketplace that delivers a high availability and reach rich features available from the leading storage operating system. This runs in a virtual infrastructure that you can set up and delivers all the efficiency and capabilities of ONAP running in a virtual environment. Cloudfind service is a fully managed storage service through the Google console offering flexible performance, elastic capacity and advanced data management features such as immutable snapshots, clones and efficient backup to object. This service is supported through Google and is a f um is available as a fully managed service.Netup cloud backup delivers simple efficient integrated backup for cloud volumes on tap or on promises uh ontap storage to object storage such as Google cloud storage or even onrem storage grid by NetApp and cloud insights offers powerful infrastructure monitoring and reporting across your hybrid cloud with advanced features to detect and protect against ransomware attacks when combined with ONTAP storage such as cloud volumes on tap and cloud data can look across your storage resources including file enhanced object storage, NetApp and non-Netapp file and object storage to identify and categorize your data for improved data governance. Another new feature available in cloud manager is a ransomware protection dashboard. This new feature aggregates data from a variety of sources to provide a broad view of your storage environment as well as provide the ability to alert to potential risks. The new dashboard pulls data from active IQ, which is NetApp's autosupport database, as well as events from ONAP storage, whether it be on premises or in the cloud,backup, cloud insights, and more to give the user insights and recommended actions to better defend against ransomware attacks. It also promises to be a central window into data security and preparedness across your IT infrastructure. With this dashboard, a user can do things like map and secure your data from any data source or audit users and receive alerts on anomalies or set up and execute a backup and recovery strategy and much more. So stay tuned for more information on this new Dashboard as it's currently in beta but soon to be available in the market. Cyber resilience integrates data protection and data security into one unified holistic approach and NetUP solutions help to deliver the tools needed for IT and security teams to better protect data stored in Google Cloud or wherever your data is located. If you'd like to speak with a specialist, follow the link listed here. Or if you'd like to learn more about NetApp solutions available on Google Cloud, go to netapp.com/googlecloud. You may also try Cloud Volumes on Tap with a free 30-day trial. The link is available here as well. Thank you for watching. Have a great day.
NetApp and Google Cloud take a data-centric approach to addressing the challenges of ransomware and cyber attacks using an operating model called cyber resilience.