Softline IT

Immutable data storage for critical systems: Protecting your business from cyberattacks and physical threats

Ransomware has evolved, now frequently targeting the destruction or encryption of backups to prevent recovery without ransom payment. This creates a critical vulnerability, as even the presence of backups does not guarantee successful recovery after an attack. If attackers gain access to the backup system, they can modify or delete data, rendering it unusable. Furthermore, physical threats, such as natural disasters or targeted attacks on data centers, can lead to complete loss of infrastructure and data if backups are not adequately protected, underscoring the need to ensure data integrity and availability.

Why traditional backup strategies are not always effective against modern threats

The modern cyber threat landscape demands that Ukrainian enterprises rethink traditional approaches to data protection. There is a growing number of targeted cyberattacks, particularly ransomware, which not only encrypt operational data but also actively seek out and compromise backups, making recovery virtually impossible 1. In such conditions, standard backup strategies relying on ordinary snapshots or copies may prove insufficient. Attackers can gain access to backup systems, delete or alter archives, leaving businesses without a last line of defense. Moreover, in the context of physical threats that can lead to complete or partial destruction of infrastructure, it is critical to have mechanisms that guarantee data integrity regardless of the state of primary systems.

What are immutable storage and cyber recovery vaults?

To counter these threats, companies are increasingly turning to the concepts of immutable storage and cyber recovery vaults. Immutable storage is a data storage system that guarantees that once data is written, it cannot be changed, overwritten, or deleted for a defined period 2. This principle is known as WORM (Write Once, Read Many) 3. It ensures that even an administrator with the highest privileges cannot modify or delete data until its immutability period expires. This creates robust protection against internal and external threats, including ransomware and accidental errors.

A cyber recovery vault is a more comprehensive architecture that goes beyond simple immutability. It combines immutable storage with a high level of isolation and security 4. Key features of cyber recovery vaults include: logical or physical isolation (air-gapping) from the primary network, preventing direct attacker access; strict access policies and multi-factor authentication; regular data integrity checks; and the ability to rapidly recover in an isolated environment. This allows not only for data preservation but also for verifying its integrity and readiness for recovery, minimizing business downtime after an incident.

Key benefits of immutable storage for critical data protection

Implementing immutable data storage provides several critically important benefits for business protection:
  • Guaranteed data integrity. The primary benefit is that data written to immutable storage remains unchanged and protected from any modifications or deletions for the specified period. This provides reliable protection against ransomware that attempts to destroy backups, as well as against accidental errors or malicious insider actions.
  • Fast and reliable recovery. In the event of a cyberattack or other disaster, the enterprise can be confident that it has a clean, uncompromised copy of its critical data for recovery. This significantly reduces recovery time objective (RTO) and minimizes data loss (RPO).
  • Regulatory compliance. Many industries, especially financial and healthcare, have strict requirements for data storage and integrity. Immutable storage helps meet compliance standards such as GDPR 5, PCI DSS [6], and NBU requirements [7], providing evidence of data immutability and preservation for the necessary term.
  • Protection against logical errors. In addition to external threats, immutability protects against internal logical errors that can lead to data corruption or deletion.

Architectural models: On-premise, cloud, and hybrid immutable storage solutions

The choice of immutable storage architecture depends on specific business needs, existing infrastructure, and budget. There are three main deployment models:

On-premise solutions

These solutions involve deploying specialized data storage systems or software solutions directly within the enterprise's infrastructure. These can be storage systems that support WORM functionality or software-defined storage that ensures data immutability. Advantages include full control over data and infrastructure, and potentially lower long-term operational costs for large data volumes. Disadvantages include high initial capital expenditures, the need for hardware management and maintenance, and potentially less flexibility in scaling compared to cloud solutions.

Cloud solutions

Many cloud providers offer immutable storage services, for example, through object lock policies or special storage tiers. Examples include AWS S3 Object Lock [8], Azure Blob Immutable Storage [9], and Google Cloud Storage Retention Policies [10]. These solutions provide high scalability, flexibility, and reduce capital expenditures by converting them into operational costs. Data is stored in geographically distributed data centers, increasing resilience to physical threats. However, infrastructure control is reduced, and costs can increase with larger data volumes and access intensity.

Hybrid models

A hybrid approach combines the advantages of on-premise and cloud solutions. For example, critically important data can be stored in an on-premise immutable repository for maximum control and low latency, while less critical or archival data is replicated to a cloud-based immutable repository. This allows for cost optimization, increased flexibility, and an additional layer of protection through geographical distribution.

Implementation challenges and how to overcome them

Implementing immutable storage, especially cyber recovery vaults, can be associated with certain challenges:
  • Cost. Specialized immutable storage solutions, especially those providing isolation (air-gapping) and additional security features, can have significant upfront costs. It is important to conduct a thorough total cost of ownership (TCO) calculation, considering not only capital expenditures but also operational costs, licensing, and support [11].
  • Integration complexity. Integrating new immutable storage with existing backup systems (e.g., Veeam, Commvault, Rubrik) and the overall IT infrastructure requires careful planning and expertise [12]. Compatibility and seamless operation of all components must be ensured.
  • Management and processes. Implementing immutability requires reviewing existing data management and security policies. It is necessary to clearly define immutability periods for different data types, access procedures, and recovery processes.
  • Testing. Regular testing of recovery processes from immutable storage is critical to confirm their effectiveness and readiness for real incidents.

To overcome these challenges, it is recommended to engage experienced system integrators who can assist with architecture design, optimal solution selection, integration, and configuration. Softline IT helps plan and implement cybersecurity solutions: from current state audit to an agreed-upon change plan.

Pros and cons of immutable storage

On-premise solutions

  • Pros: Full control over data and infrastructure, potentially lower long-term operational costs for large data volumes.
  • Cons: High initial capital expenditures, need for hardware management and maintenance, less flexibility in scaling.

Cloud solutions

  • Pros: High scalability, flexibility, reduced capital expenditures (converted to operational costs), geographical distribution for increased resilience.
  • Cons: Less control over infrastructure, costs can increase with larger data volumes and access intensity.

Hybrid models

  • Pros: Cost optimization, increased flexibility, additional layer of protection through geographical distribution, combination of control and scalability.
  • Cons: Complexity of management and integration across different environments.

Checklist for evaluating immutable storage solutions

  • Support for WORM and immutable storage at the storage/service level
  • Integration capabilities with existing backup systems (Veeam, Commvault, Rubrik, etc.)
  • Level of isolation and air-gapping (for cyber recovery vaults)
  • Scalability and flexibility of the solution (on-premise, cloud, hybrid)
  • Compliance with regulatory requirements (GDPR, PCI DSS, NBU)
  • Cost of implementation and operation (TCO)
  • Ease of management and monitoring
  • Vendor support and solution ecosystem
  • Capabilities for recovery testing and DR plans

Softline IT helps teams plan and implement cybersecurity, from an assessment of the current environment to an agreed change plan.

Sources used

  1. 01cisa.govCISA guidance
  2. 02ibm.comSource: ibm.com
  3. 03snia.orgSource: snia.org
  4. 04dell.comSource: dell.com
  5. 05gdpr-info.euSource: gdpr-info.eu

Tags