Thank you for the good explanation and for sharing!
@LoftBits Жыл бұрын
But it still sounds a bit like "letting the horse bolt, then bringing it safely back and fixing the gate"... If the AI behind the Vault can so brilliantly detect even dormant malware in the data, why not apply its logic to the production as well and get a clean bill of health? Or, even better, why not employ it in preventative controls (like a good old 'antivirus') to make sure that the ransomware, alongside any other malware for that matter, does NOT enter the production environment in the first place?
@damianerangey Жыл бұрын
Ture, but you also need to consider a scenario where a bad actor has access to the network and encrypts all data in prod. You would need a logical (or physical air gapped vault) to recover from. You want to try and prevent a bad actor getting access to all parts of your infra (i.e. the vault) for this scenario. That being said, I also agree that prod side scanning should also be included for (which could lead to future back door attacks). Why wait for the backup to hit the fault before seeing if its bad or not and then having to roll back after the fact.