1 00:00:00,439 --> 00:00:02,670 W. Curtis Preston (2): Very few people like their backup system. 2 00:00:02,849 --> 00:00:05,489 So they're often thinking about making a change. 3 00:00:05,970 --> 00:00:07,710 When does it make sense to do that? 4 00:00:07,710 --> 00:00:09,480 And what's the best way to do it. 5 00:00:09,960 --> 00:00:13,620 Today, we answer these questions and we make sure you understand the 6 00:00:13,620 --> 00:00:16,470 risks of changing your backup system. 7 00:00:16,740 --> 00:00:18,060 Along with the rewards. 8 00:00:18,480 --> 00:00:19,430 Hi, I'm W. 9 00:00:19,430 --> 00:00:21,090 Curtis Preston AKA Mr. 10 00:00:21,090 --> 00:00:21,630 ATR2500x-USB Microphone & Logitech BRIO: Backup. 11 00:00:21,870 --> 00:00:23,310 And I've been where you are. 12 00:00:23,580 --> 00:00:25,800 I've been stuck with backup software. 13 00:00:25,800 --> 00:00:28,890 I hated and wanted so badly to change. 14 00:00:29,190 --> 00:00:30,660 So I know how it feels. 15 00:00:31,200 --> 00:00:34,350 On each episode of this show, we dive deep on one topic, 16 00:00:34,350 --> 00:00:35,850 helpful to you and your backups. 17 00:00:36,150 --> 00:00:37,890 And this week it's about change. 18 00:00:38,370 --> 00:00:43,440 We turn unappreciated backup admins into cyber recovery heroes. 19 00:00:43,740 --> 00:00:45,900 This is the backup wrap up. 20 00:00:58,729 --> 00:01:00,169 W. Curtis Preston: Welcome to the backup wrap up. 21 00:01:00,706 --> 00:01:04,751 I'm your host, w Curtis Preston, and I have with me my personal 22 00:01:04,751 --> 00:01:08,531 interface into the SpongeBob world. 23 00:01:09,171 --> 00:01:10,451 Prasanna Malaiyandi, 24 00:01:12,316 --> 00:01:13,351 Prasanna Malaiyandi: am good Curtis. 25 00:01:13,351 --> 00:01:15,931 Yeah, it's SpongeBob amazing show. 26 00:01:15,931 --> 00:01:20,821 So growing up I didn't have access to SpongeBob 'cause I'm a little 27 00:01:20,821 --> 00:01:26,101 older than SpongeBob, but I remember I was probably in college and I 28 00:01:26,101 --> 00:01:30,331 went to a good friend's house and his six-year-old nephew was there. 29 00:01:30,751 --> 00:01:33,272 And that's the first time I saw SpongeBob Squarepants. 30 00:01:33,277 --> 00:01:36,541 And ever since then I'm addicted, so I do watch it. 31 00:01:36,946 --> 00:01:44,176 Even to this day, I may or may not have SpongeBob Squarepants socks that I wear. 32 00:01:44,176 --> 00:01:44,806 Also. 33 00:01:47,141 --> 00:01:50,501 W. Curtis Preston: And I have like zero connection to the SpongeBob world. 34 00:01:50,561 --> 00:01:53,681 Again, you know, if you're too old for it, I'm way too old for it. 35 00:01:54,141 --> 00:01:58,851 It was just a few days ago that I found out that the phrase, if you 36 00:01:58,851 --> 00:02:01,671 moments at Atar, uh, is from SpongeBob. 37 00:02:02,421 --> 00:02:03,021 I didn't know 38 00:02:05,051 --> 00:02:05,621 Prasanna Malaiyandi: Great show. 39 00:02:05,621 --> 00:02:06,851 I think you should start watching it. 40 00:02:08,121 --> 00:02:08,691 W. Curtis Preston: Really? 41 00:02:08,751 --> 00:02:09,861 Yeah, that's what I'm gonna do. 42 00:02:10,461 --> 00:02:13,481 In the midst of all of 43 00:02:13,571 --> 00:02:15,131 Prasanna Malaiyandi: a great background show to 44 00:02:16,221 --> 00:02:17,361 W. Curtis Preston: Oh, is it a background show? 45 00:02:17,441 --> 00:02:17,741 Prasanna Malaiyandi: Yeah. 46 00:02:19,991 --> 00:02:24,311 And they have the first six seasons on Amazon Prime for free, so 47 00:02:24,811 --> 00:02:25,921 W. Curtis Preston: How can I resist it? 48 00:02:29,536 --> 00:02:31,621 You know, I've never actually watched an entire episode. 49 00:02:31,621 --> 00:02:33,691 I, maybe I'll watch an episode or two 50 00:02:35,821 --> 00:02:40,261 Well, it is time for us to get into the backup news or the, you 51 00:02:40,261 --> 00:02:42,811 know, the news of, of our world. 52 00:02:43,141 --> 00:02:45,481 Uh, do we wanna start? 53 00:02:45,486 --> 00:02:47,491 I, I should start with yours. 54 00:02:47,971 --> 00:02:53,671 Uh, our news from the AWS Storage Day back, uh, looks like about 55 00:02:55,306 --> 00:03:00,796 Prasanna Malaiyandi: So this recently came out, um, it is AWS trying 56 00:03:00,801 --> 00:03:03,106 to help with ransomware attacks. 57 00:03:03,436 --> 00:03:08,146 Um, for folks who don't know, AWS offers a service called AWS backup, 58 00:03:08,146 --> 00:03:13,606 which allows you to protect and manage some of your AWS resources, like EBS 59 00:03:13,606 --> 00:03:16,756 volumes, EC2 instances, and others. 60 00:03:17,266 --> 00:03:19,426 And so what they've recently done. 61 00:03:20,821 --> 00:03:25,591 Previous to this new release, what they had was the ability to sort of create 62 00:03:25,591 --> 00:03:29,101 a vault, is what they called it, where you kind of squirrel away your backups. 63 00:03:29,401 --> 00:03:31,921 It would be stored there, it would be protected, so they 64 00:03:31,921 --> 00:03:33,781 had like retention settings. 65 00:03:33,786 --> 00:03:37,351 It could be supported using the immutable feature, object lock 66 00:03:37,356 --> 00:03:41,731 capability of AWS and basically prevent backups from being deleted. 67 00:03:42,366 --> 00:03:48,276 But this was all within the customer's account, and it was either AWS 68 00:03:48,276 --> 00:03:53,886 managed keys or customer managed keys, and so that was great, but someone 69 00:03:53,886 --> 00:03:57,516 could potentially still get into the system, start deleting backups. 70 00:03:57,786 --> 00:03:59,526 It's not completely foolproof. 71 00:03:59,526 --> 00:04:03,276 And I know Curtis, we've talked in past episodes, just actually just 72 00:04:03,276 --> 00:04:08,016 recently, about air gapping and what air gaps mean and virtual air gaps. 73 00:04:09,091 --> 00:04:13,801 And so now what Air AWS has offered is, let me make sure I got the words right. 74 00:04:14,281 --> 00:04:16,831 A logically air gapped vault. 75 00:04:17,701 --> 00:04:18,691 That's a mouthful. 76 00:04:19,631 --> 00:04:19,901 Yeah. 77 00:04:20,036 --> 00:04:21,626 W. Curtis Preston: fine with that term. 78 00:04:22,286 --> 00:04:24,956 I'm glad that they used that term, right. 79 00:04:24,961 --> 00:04:28,666 The, put the logically, um, 80 00:04:29,266 --> 00:04:32,866 Prasanna Malaiyandi: what it is, is it is a more locked down vault 81 00:04:33,286 --> 00:04:37,936 where unlike before, uh, where the customer was managing the keys or 82 00:04:37,936 --> 00:04:41,326 using AWS managed keys, these are keys that are actually owned by AWS. 83 00:04:41,326 --> 00:04:46,306 You can't delete the keys, which means if you can't delete the keys, then you can't. 84 00:04:46,846 --> 00:04:48,826 Prevent access to the data. 85 00:04:49,516 --> 00:04:53,176 Um, and once again, they also have the ability to set retention 86 00:04:53,176 --> 00:04:55,996 that says, okay, make sure that the minimum anything between like 87 00:04:55,996 --> 00:04:59,956 this retention and this retention don't allow anything to be deleted. 88 00:04:59,956 --> 00:05:04,066 And once you set these policies, you can't actually go back and change it. 89 00:05:04,546 --> 00:05:08,321 So it's a good thing because it prevents people from like malicious 90 00:05:08,321 --> 00:05:12,196 actors, from going and changing the settings and sort of changing your 91 00:05:12,196 --> 00:05:14,986 retention policy down to one day and boom, all your backups are gone. 92 00:05:16,921 --> 00:05:17,101 Which 93 00:05:17,171 --> 00:05:17,471 W. Curtis Preston: Yeah. 94 00:05:17,491 --> 00:05:17,641 Prasanna Malaiyandi: thing. 95 00:05:19,001 --> 00:05:22,631 W. Curtis Preston: It looks like, um, it looks like it's 96 00:05:22,631 --> 00:05:24,821 designed to be used cross account. 97 00:05:24,821 --> 00:05:29,351 So one of the things we've talked about in the past is to create an account 98 00:05:29,351 --> 00:05:30,911 that holds the backups for everything. 99 00:05:31,301 --> 00:05:34,961 And that's what it looks like this is designed for, because also 100 00:05:34,966 --> 00:05:40,541 it talks about offering direct cross account, restore, um, which 101 00:05:41,141 --> 00:05:42,731 again, I'm not exactly sure what, 102 00:05:45,001 --> 00:05:47,851 Prasanna Malaiyandi: I today, order do your restores, you kind of have to 103 00:05:47,851 --> 00:05:51,661 copy it back into the account first before you can start accessing it. 104 00:05:51,661 --> 00:05:57,241 And so they've, I think, integrated with AWS resource account access 105 00:05:57,241 --> 00:06:02,731 manager to allow instant access to those copies having to first copy it across. 106 00:06:04,231 --> 00:06:06,541 Which is cool because I think that's another piece that a lot of people 107 00:06:08,531 --> 00:06:09,371 W. Curtis Preston: Right, right. 108 00:06:09,671 --> 00:06:09,911 Yeah. 109 00:06:09,911 --> 00:06:14,441 So I, I think this is, you know, again, it's another step in the right direction. 110 00:06:14,771 --> 00:06:20,351 I like the idea of having the, I do wonder, and I would like to know, 111 00:06:21,521 --> 00:06:28,691 does having it ecr encrypted with AWS owned You know what I'm asking? 112 00:06:30,131 --> 00:06:30,491 Yeah. 113 00:06:30,491 --> 00:06:32,441 Does that mean that AWS can my 114 00:06:34,351 --> 00:06:37,831 Prasanna Malaiyandi: I am sure a lot of enterprise customers would be concerned 115 00:06:37,831 --> 00:06:43,501 about, um, is how do you prevent AWS or someone who has access to the AWS 116 00:06:43,501 --> 00:06:45,961 infrastructure that that data is secure? 117 00:06:46,831 --> 00:06:52,171 Um, in my mind, I think customers today could almost hand roll 118 00:06:52,171 --> 00:06:53,791 this solution on their own. 119 00:06:54,331 --> 00:06:58,831 By using a third party key management service with the current AWS backup, 120 00:06:58,831 --> 00:07:01,051 where they're kind of using customer managed keys, but they're using 121 00:07:01,051 --> 00:07:02,491 a third party service for that. 122 00:07:03,421 --> 00:07:09,151 Uh, and so AWS in AWS fashion is like, Hey, see this as a customer pain point. 123 00:07:09,151 --> 00:07:12,841 Let's build something in natively to simplify things for customers. 124 00:07:13,771 --> 00:07:15,121 So kudos to AWS. 125 00:07:16,116 --> 00:07:16,406 W. Curtis Preston: Yeah. 126 00:07:16,686 --> 00:07:17,801 Kudos to AWS. 127 00:07:18,281 --> 00:07:20,306 Uh, although I do want to ask that. 128 00:07:22,516 --> 00:07:24,166 Prasanna Malaiyandi: Oh, by the way, this is in preview, 129 00:07:25,456 --> 00:07:29,506 Hasn't been, yeah, so it hasn't GAD yet, but should probably be 130 00:07:29,506 --> 00:07:31,311 coming out soon-ish is my guess. 131 00:07:32,871 --> 00:07:34,701 W. Curtis Preston: So the next is another. 132 00:07:36,126 --> 00:07:40,026 Completely different solution, but aimed at the same problem. 133 00:07:40,026 --> 00:07:45,876 A lot of companies are worrying about this, the, the concern of, of 134 00:07:45,876 --> 00:07:48,006 backups being attacked or whatever. 135 00:07:48,336 --> 00:07:52,836 And one of the things that we have consistently said is that one of the 136 00:07:52,836 --> 00:07:56,316 things that you want to do is to make sure that you have a different, you know, a 137 00:07:56,316 --> 00:08:00,846 separate authentication and authorization system for your backup and Dr. 138 00:08:00,846 --> 00:08:02,646 Data, which. 139 00:08:02,976 --> 00:08:05,466 Which would mean that if you're an on-prem system and you're backing 140 00:08:05,466 --> 00:08:09,666 up to the cloud, that you would, uh, that if active directory, for 141 00:08:09,666 --> 00:08:12,576 example, was hacked, it wouldn't be able to attack your backups. 142 00:08:12,816 --> 00:08:16,866 And that is, by the way, no one does this from what I can see. 143 00:08:17,556 --> 00:08:17,976 Right. 144 00:08:18,066 --> 00:08:22,416 One of the most often requested features that I remember back, uh, 145 00:08:22,446 --> 00:08:25,986 when, when I worked at DVA was, you know, active directory integration. 146 00:08:25,986 --> 00:08:26,196 It's like. 147 00:08:26,821 --> 00:08:28,891 But it's not a good idea. 148 00:08:29,191 --> 00:08:29,581 Right. 149 00:08:29,671 --> 00:08:35,941 Um, so the, um, anyway, so this is taking, it's not the opposite 150 00:08:35,941 --> 00:08:37,591 approach, but it kind of is. 151 00:08:37,591 --> 00:08:43,051 So this is from Cloud, cloud casa, um, which I guess is like 152 00:08:43,101 --> 00:08:45,631 a house for your cloud, I guess. 153 00:08:45,771 --> 00:08:46,911 Is what they're going for there. 154 00:08:47,151 --> 00:08:51,021 So it's from Cata Logic, the, the, the company, and it's 155 00:08:51,021 --> 00:08:53,241 specifically designed for Kubernetes. 156 00:08:53,271 --> 00:08:55,581 Uh, it's a Kubernetes backup, uh, system. 157 00:08:55,881 --> 00:09:01,281 And what they're now allowing is for you to do self-hosted, uh, versions of 158 00:09:01,281 --> 00:09:09,381 this soft of this software, and they're specifically billing it in that, let's 159 00:09:09,386 --> 00:09:14,811 say you're running in the cloud and you want to get an air gap backup of that. 160 00:09:15,366 --> 00:09:19,866 The only way to do that in their mind, or one way to do that in their mind 161 00:09:19,866 --> 00:09:23,526 is to put the, the backup on-prem. 162 00:09:24,036 --> 00:09:29,346 So it kind of follows the logic that we have used. 163 00:09:29,346 --> 00:09:35,406 I myself, I would prefer that the, that air gap ba, you know, that air 164 00:09:35,406 --> 00:09:39,936 gap, as I make quotes in the air, I would prefer that they are on some 165 00:09:39,936 --> 00:09:41,766 sort of right protected storage. 166 00:09:42,216 --> 00:09:42,576 Some 167 00:09:44,711 --> 00:09:47,261 Prasanna Malaiyandi: and case Cloud Casa, they do say they 168 00:09:47,261 --> 00:09:50,111 support an S3 compatible backend. 169 00:09:50,501 --> 00:09:54,191 So if that is the case, then I'm sure that there are mechanisms 170 00:09:54,196 --> 00:09:55,601 to provide immutability. 171 00:09:56,991 --> 00:09:59,541 W. Curtis Preston: Yeah, I, yeah, I, I would like to see that. 172 00:09:59,541 --> 00:10:05,061 But the idea here is that you can run their software now on-Prem, separating 173 00:10:05,061 --> 00:10:06,771 it from your cloud environment. 174 00:10:07,731 --> 00:10:10,431 I guess it's very common to run Kubernetes in the cloud. 175 00:10:11,676 --> 00:10:16,956 So then you run this on-prem and so that you have a backup in, in a different, um, 176 00:10:17,256 --> 00:10:21,836 again, that different authe authentication 177 00:10:22,651 --> 00:10:23,936 Prasanna Malaiyandi: I think the other. 178 00:10:24,536 --> 00:10:27,296 Thing that this could be useful for is for those customers who are 179 00:10:27,296 --> 00:10:30,176 running Kubernetes internally, right? 180 00:10:30,176 --> 00:10:34,526 It gives them a mechanism to have a completely siloed environment where, 181 00:10:34,736 --> 00:10:39,056 'cause I think a lot of more modern, uh, Kubernetes data protection 182 00:10:39,056 --> 00:10:44,516 platforms sort of have some sort of SaaS connectivity, if you will. 183 00:10:45,461 --> 00:10:50,201 And for those people who want complete control and complete isolation, this 184 00:10:50,201 --> 00:10:53,951 gives them that mechanism where if they're running something locally in 185 00:10:53,951 --> 00:10:58,181 their on-premises infrastructure, they have the ability to protect those in a 186 00:10:58,181 --> 00:11:02,651 simplified way without having to require centralized management and other things. 187 00:11:02,651 --> 00:11:02,711 I. 188 00:11:04,896 --> 00:11:08,936 W. Curtis Preston: Yeah, so it looks like, I guess if you have an on-prem deployment 189 00:11:08,936 --> 00:11:14,276 of Kubernetes, you can use the Cloud casa service that already runs in the cloud. 190 00:11:14,786 --> 00:11:17,966 But if you have, uh, Kubernetes in the cloud and you'd like 191 00:11:17,971 --> 00:11:20,936 to protect it on-prem, you can now run the, the self-hosted 192 00:11:22,706 --> 00:11:23,216 So 193 00:11:23,506 --> 00:11:23,841 Prasanna Malaiyandi: are good. 194 00:11:23,876 --> 00:11:26,636 W. Curtis Preston: um, options are good. 195 00:11:27,006 --> 00:11:27,696 Well, there you go. 196 00:11:27,816 --> 00:11:29,796 That is the news of the day. 197 00:11:34,666 --> 00:11:36,586 I hope you enjoyed the news. 198 00:11:36,826 --> 00:11:37,726 Today. 199 00:11:37,726 --> 00:11:39,706 I thought we would focus on. 200 00:11:40,936 --> 00:11:44,506 Basically, how do we make sense of everything we just covered? 201 00:11:44,556 --> 00:11:49,146 We covered a whole bunch of different ways to do backup, right? 202 00:11:49,151 --> 00:11:54,606 We covered like the traditional full and incremental backup system, which 203 00:11:54,611 --> 00:11:56,196 may go to disc, may go to tape. 204 00:11:56,196 --> 00:11:58,566 Most likely we go to disk, it may go to cloud. 205 00:11:59,136 --> 00:12:03,126 We talked about CDP replication near CDP. 206 00:12:03,801 --> 00:12:05,511 You know, cloud-based system. 207 00:12:05,511 --> 00:12:07,881 I mean, we, we covered a whole bunch. 208 00:12:07,881 --> 00:12:08,151 Like, 209 00:12:08,481 --> 00:12:09,681 Prasanna Malaiyandi: You just throw a dart. 210 00:12:09,711 --> 00:12:12,801 W. Curtis Preston: is just, just throw a tart. 211 00:12:13,101 --> 00:12:17,001 So now you are thinking about picking a backup product. 212 00:12:18,261 --> 00:12:20,331 How do you do that? 213 00:12:20,451 --> 00:12:20,901 Right? 214 00:12:20,901 --> 00:12:22,911 How do you pick a backup product? 215 00:12:23,121 --> 00:12:25,551 Prasanna Malaiyandi: just starting with the basics, I think it is figuring 216 00:12:25,551 --> 00:12:29,661 out what are your requirements, what are you trying to solve for? 217 00:12:29,691 --> 00:12:33,621 Because if you don't know what those are, it's gonna be hard to pick a backup 218 00:12:33,626 --> 00:12:35,691 product that meets those expectations. 219 00:12:36,126 --> 00:12:38,106 W. Curtis Preston: If you don't know where you're going, you'll 220 00:12:38,106 --> 00:12:39,636 probably end up somewhere else. 221 00:12:40,296 --> 00:12:42,726 Um, if you've ever heard that before. 222 00:12:42,981 --> 00:12:43,201 Um. 223 00:12:44,313 --> 00:12:47,598 I, I, I completely agree with you I think that's a message that we put out 224 00:12:47,598 --> 00:12:54,198 pretty consistently here, is that the more you can set expectations and document 225 00:12:54,198 --> 00:13:00,918 expectations, the more success you will have at meeting those expectations. 226 00:13:01,098 --> 00:13:06,258 If you don't set expectations and document expectations, then. 227 00:13:06,768 --> 00:13:09,948 No matter how good you are, you can't compare them to anything. 228 00:13:09,948 --> 00:13:10,338 Right? 229 00:13:10,578 --> 00:13:13,638 So the same is true of requirements. 230 00:13:13,998 --> 00:13:19,578 If your requirement, I mean, when I go back, I go back to the early days 231 00:13:20,303 --> 00:13:21,588 Prasanna Malaiyandi: back in the day. 232 00:13:21,618 --> 00:13:22,758 W. Curtis Preston: commercial backup product. 233 00:13:25,008 --> 00:13:32,173 When I think back in the day I remember going to a bunch of backup vendors 234 00:13:32,203 --> 00:13:39,103 and I went with what at that time were really basic requirements, but 235 00:13:39,643 --> 00:13:45,163 they very quickly knocked out many, if not most of the backup products 236 00:13:45,163 --> 00:13:46,723 that were on the market at the time. 237 00:13:48,103 --> 00:13:53,023 And so and so what I remember is, and, and that's a great way to do it. 238 00:13:54,523 --> 00:13:59,913 If you have solid requirements that you can dictate let's say a requirement of 239 00:13:59,913 --> 00:14:04,983 you've got to be able to back up Mac oss that's gonna NOC out a bunch of vendors. 240 00:14:06,603 --> 00:14:08,283 Well, why is that a requirement for you? 241 00:14:08,313 --> 00:14:10,143 Well, because we run on Mac oss us. 242 00:14:10,873 --> 00:14:13,003 Prasanna Malaiyandi: Well, and I think that gets to a key point. 243 00:14:13,003 --> 00:14:18,853 It's make sure your requirements are justified and valid because sometimes 244 00:14:18,858 --> 00:14:21,253 people are like, oh, I want a Ferrari. 245 00:14:21,823 --> 00:14:22,093 Right? 246 00:14:22,093 --> 00:14:24,643 But they only have a budget of like a Toyota. 247 00:14:25,248 --> 00:14:30,588 So you have to make sure you understand what are the requirements that you really 248 00:14:30,588 --> 00:14:33,513 need to hit versus what's your wishlist. 249 00:14:33,998 --> 00:14:34,358 W. Curtis Preston: Yeah. 250 00:14:34,358 --> 00:14:36,063 Wishlist versus requirements, right? 251 00:14:36,668 --> 00:14:40,628 So you, you can have, you know, when we talk about requirements, I put 252 00:14:40,628 --> 00:14:42,098 them in three categories, right? 253 00:14:42,098 --> 00:14:42,278 There is. 254 00:14:43,298 --> 00:14:45,038 Basically showstoppers. 255 00:14:45,128 --> 00:14:46,358 You either do or you do not. 256 00:14:46,358 --> 00:14:50,018 Back up Mac oss or whatever it is, whatever that is for you. 257 00:14:50,048 --> 00:14:55,808 Oracle AWS, whatev, whatever that is, you know, for you that, that list. 258 00:14:56,828 --> 00:15:00,788 Then there's g We'd really like it if you could do this. 259 00:15:01,268 --> 00:15:01,748 Right. 260 00:15:02,078 --> 00:15:03,818 Backups by osmosis. 261 00:15:03,878 --> 00:15:05,198 That would be really nice. 262 00:15:05,348 --> 00:15:05,768 Right. 263 00:15:06,368 --> 00:15:09,788 Um, and those aren't going to. 264 00:15:10,838 --> 00:15:16,928 Rule out products, they're gonna help you make a choice when you're confront, 265 00:15:16,933 --> 00:15:20,798 when you get down to that, like three, that list of three products, all 266 00:15:20,803 --> 00:15:26,728 three products meet the showstopper requirements, but one of them has. 267 00:15:27,523 --> 00:15:31,063 75% of your nice hat, nice to haves. 268 00:15:31,063 --> 00:15:31,423 Right? 269 00:15:31,933 --> 00:15:38,533 Um, and then, and then there's like a third category of these sound cool, right? 270 00:15:38,713 --> 00:15:42,763 But honestly, you know, we're, it's not gonna, it's not gonna 271 00:15:42,973 --> 00:15:44,233 swing us one way or the other. 272 00:15:45,058 --> 00:15:49,873 I, I, I can't think of a good example of, of what that might be, but I remember 273 00:15:49,873 --> 00:15:52,063 having that, having that category right. 274 00:15:52,378 --> 00:15:55,288 You know, so it's sort of like required important. 275 00:15:55,288 --> 00:15:56,908 And I guess the third is 276 00:15:57,103 --> 00:15:57,313 Prasanna Malaiyandi: Yeah. 277 00:15:57,523 --> 00:16:03,223 And even for these three categories, Curtis, I think it's important to also 278 00:16:03,223 --> 00:16:08,053 consider, it's not just what you need today, but you also wanna think about 279 00:16:08,053 --> 00:16:09,793 sort of the next three years, right? 280 00:16:09,793 --> 00:16:15,193 What those requirements, the must haves, the nice to haves the moonshots will be 281 00:16:15,565 --> 00:16:16,500 W. Curtis Preston: Yeah, that's a good point. 282 00:16:16,575 --> 00:16:16,935 Prasanna Malaiyandi: keeping around 283 00:16:17,053 --> 00:16:17,683 W. Curtis Preston: Exactly. 284 00:16:17,983 --> 00:16:22,453 It's a good point because you should think about the requirements, not just for 285 00:16:22,453 --> 00:16:24,493 today, like you said, but for the future. 286 00:16:24,493 --> 00:16:29,983 So if you are aware of an upcoming project where you're going to migrate 287 00:16:29,983 --> 00:16:31,438 your entire environment to Azure. 288 00:16:32,578 --> 00:16:35,758 Maybe Azure backup might be important to you, right? 289 00:16:36,028 --> 00:16:38,488 It's not today, but it will be in a year or so. 290 00:16:38,758 --> 00:16:40,318 Now would be a time to think about it. 291 00:16:40,498 --> 00:16:44,878 And, and by the way, that's when you can, when you're having that conversation 292 00:16:44,878 --> 00:16:48,088 with the backup vendor and you say, Hey, we really need this feature. 293 00:16:48,088 --> 00:16:48,148 I. 294 00:16:49,663 --> 00:16:53,443 a year, and they go, okay, well we're coming out with it in two to three months. 295 00:16:53,803 --> 00:16:54,193 Right? 296 00:16:54,733 --> 00:16:57,013 And again, get that contractually and all that kind of stuff. 297 00:16:57,013 --> 00:16:57,193 Right. 298 00:16:57,193 --> 00:17:01,103 But, the big thing with the needs is, you know, you, you talked about making 299 00:17:01,103 --> 00:17:02,543 sure that they're tied to something. 300 00:17:03,143 --> 00:17:07,763 I just wanna make sure that we dictate the difference between 301 00:17:08,603 --> 00:17:10,523 a requirement and a design. 302 00:17:11,423 --> 00:17:11,933 Right? 303 00:17:12,383 --> 00:17:15,143 So I, I, I've used this example before. 304 00:17:15,983 --> 00:17:17,633 Uh, I live in San Diego. 305 00:17:17,633 --> 00:17:23,363 We have, um, Coronado on the other side of the, of the San Diego Bay. 306 00:17:23,363 --> 00:17:24,353 It's not an island. 307 00:17:24,353 --> 00:17:28,553 It's technically just a really big peninsula, but so many 308 00:17:28,558 --> 00:17:30,113 people call it Coronado Island. 309 00:17:31,748 --> 00:17:33,218 The, there are two ways to get there. 310 00:17:33,218 --> 00:17:36,158 One is to go, you drive all the way down to Imperial Beach and 311 00:17:36,158 --> 00:17:37,268 then you drive all the way back. 312 00:17:37,268 --> 00:17:37,568 Right? 313 00:17:37,568 --> 00:17:41,438 If you're downtown San Diego, that's a, like a 30 mile round trip. 314 00:17:42,338 --> 00:17:45,128 Um, the other way is to go over the Coronado Bridge. 315 00:17:45,128 --> 00:17:46,568 That's a mile and a half. 316 00:17:48,098 --> 00:17:50,228 So what, what has that got to do with the requirements? 317 00:17:50,378 --> 00:17:51,938 So, so. 318 00:17:52,373 --> 00:17:56,783 At some point somebody said, we've got to get a bunch of cars from here 319 00:17:56,873 --> 00:18:02,033 over to there in a lot quicker way than driving 30 miles round trip. 320 00:18:02,603 --> 00:18:04,913 That's the requirement, right? 321 00:18:06,413 --> 00:18:10,193 Then somebody else said, well, we, you know, we need a bridge. 322 00:18:11,048 --> 00:18:14,528 No, you, you need a way to get cars from here to there. 323 00:18:14,618 --> 00:18:15,668 That's your requirement. 324 00:18:16,028 --> 00:18:17,468 The bridge is the design. 325 00:18:17,678 --> 00:18:20,138 Another, another design would be tunnel. 326 00:18:20,288 --> 00:18:22,058 Another design would be ferry, 327 00:18:22,213 --> 00:18:22,773 Prasanna Malaiyandi: like the how. 328 00:18:23,228 --> 00:18:24,458 W. Curtis Preston: Um, yeah. 329 00:18:24,458 --> 00:18:30,878 That's the how a lot of people, they very quickly get excited about the how. 330 00:18:31,838 --> 00:18:37,388 They forget to look at the why and where this happens a lot, you know, nerds like 331 00:18:37,388 --> 00:18:44,458 you and me, we see this presentation you've likened a CDP to TiVo, right? 332 00:18:45,178 --> 00:18:50,413 I remember the first time I saw TiVo the first time you got to pause live tv. 333 00:18:51,658 --> 00:18:55,648 was like the most amazing thing, right? 334 00:18:55,678 --> 00:18:56,878 You, you remember that, right? 335 00:18:56,908 --> 00:19:00,208 The first time you get to pause live, I'm gonna go to the bathroom 336 00:19:00,208 --> 00:19:03,238 for a minute, pause, live tv, right? 337 00:19:03,238 --> 00:19:06,508 Or somebody wants to, you know, my wife wants to say something to me 338 00:19:06,508 --> 00:19:10,228 and I can just pause, answer her question and I can go back to the show. 339 00:19:10,963 --> 00:19:12,223 That was amazing. 340 00:19:12,433 --> 00:19:12,943 Right? 341 00:19:13,213 --> 00:19:15,763 Well, the same thing happens when you, you know, when somebody shows 342 00:19:15,763 --> 00:19:20,413 you CDP for the first time or, uh, you know what, whatever, pick 343 00:19:20,413 --> 00:19:22,093 your, you know, backup by osmosis. 344 00:19:22,963 --> 00:19:26,293 The first time you see that, you get excited about that. 345 00:19:27,913 --> 00:19:31,153 point is, do you need that? 346 00:19:31,993 --> 00:19:32,683 Right? 347 00:19:33,163 --> 00:19:44,653 You have a requirement to have an RPO and an RTO of x and CDP could meet it because 348 00:19:44,653 --> 00:19:46,843 CD can meet all the way down to zero. 349 00:19:47,173 --> 00:19:52,393 But what is, what is X for you and what are the other ways that you can meet 350 00:19:52,468 --> 00:19:52,768 Prasanna Malaiyandi: Yeah. 351 00:19:53,038 --> 00:19:56,398 And remember that X may be different for different workloads 352 00:19:56,398 --> 00:19:57,598 in your environment as well. 353 00:19:57,598 --> 00:19:58,648 So those are other things. 354 00:19:58,648 --> 00:19:59,548 You have to think about it 355 00:20:01,138 --> 00:20:02,128 W. Curtis Preston: Right, right. 356 00:20:02,128 --> 00:20:02,788 Exactly. 357 00:20:03,118 --> 00:20:05,698 Um, we're gonna cover that here in just a minute. 358 00:20:05,698 --> 00:20:08,248 That, that, that's, we're gonna take a turn 359 00:20:08,698 --> 00:20:11,428 Prasanna Malaiyandi: and, and, but wait, before you get there, since you 360 00:20:11,428 --> 00:20:15,988 threw out some acronyms, do you want to define RTO and RPO for our listeners? 361 00:20:16,224 --> 00:20:16,514 W. Curtis Preston: sure. 362 00:20:16,982 --> 00:20:18,632 and then we'll throw on two more acronyms. 363 00:20:18,632 --> 00:20:21,902 So, recovery time objective, recovery point objective, recovery time 364 00:20:21,907 --> 00:20:26,522 objective, or RTO is the amount of time that a restore will take. 365 00:20:27,137 --> 00:20:27,587 Right. 366 00:20:27,827 --> 00:20:31,937 Um, well, that it will take to bring the system back to 367 00:20:31,937 --> 00:20:33,857 operational readiness, right? 368 00:20:34,097 --> 00:20:35,657 So within that. 369 00:20:36,167 --> 00:20:40,187 Let's say we've got a four hour RTO within that four hour RTO. 370 00:20:40,397 --> 00:20:43,337 One hour of that might be dedicated to the actual restore. 371 00:20:43,667 --> 00:20:47,297 Three hours might be dedicated to getting the, the hardware back up 372 00:20:47,297 --> 00:20:50,297 and running and connecting it back to the rest of the environment, right? 373 00:20:50,747 --> 00:20:54,737 Uh, but that's what recovery time, objective, recovery point objective 374 00:20:55,127 --> 00:20:57,477 is how much data we can lose. 375 00:20:58,137 --> 00:20:59,637 As measured by time. 376 00:20:59,637 --> 00:21:02,337 So one hour, we can lose one hour's worth of data. 377 00:21:02,847 --> 00:21:07,677 And then we talk about RTA and RPA recovery time, actual recovery point, 378 00:21:07,677 --> 00:21:10,197 actual, so this is the RTO and RPO. 379 00:21:10,197 --> 00:21:11,397 That's your objective. 380 00:21:11,877 --> 00:21:13,587 That's the thing you're gonna try to meet. 381 00:21:14,037 --> 00:21:18,627 Um, and you maybe you have to meet RTA and RPA are what the system 382 00:21:18,627 --> 00:21:21,327 that you actually have, what, what it's actually capable of doing. 383 00:21:21,442 --> 00:21:22,507 Prasanna Malaiyandi: Because sometimes they don't match. 384 00:21:24,297 --> 00:21:26,787 W. Curtis Preston: Especially if you didn't go through this 385 00:21:26,787 --> 00:21:28,017 process on the front end. 386 00:21:28,077 --> 00:21:28,437 Right. 387 00:21:28,680 --> 00:21:35,130 aNother thing that's very closely related to what I said before is sometimes 388 00:21:35,135 --> 00:21:37,140 you don't need to make a change. 389 00:21:37,590 --> 00:21:41,657 Sometimes you see something really cool, you're like, oh, that looks 390 00:21:41,662 --> 00:21:43,817 like a really cool new backup product. 391 00:21:44,417 --> 00:21:48,827 Sometimes the best choice is to do nothing, right? 392 00:21:49,307 --> 00:21:52,937 The question is, are you meeting the requirements with what you currently 393 00:21:52,937 --> 00:21:59,807 have and slash or could you meet your requirements with what you currently 394 00:21:59,807 --> 00:22:05,867 have and perhaps some re slight redesign or replacement of a, of a piece of it, 395 00:22:06,137 --> 00:22:10,607 changing the, the backup target that you're using or something like that. 396 00:22:11,027 --> 00:22:17,147 Or do you need, need to replace it? 397 00:22:17,147 --> 00:22:19,667 Is there no way right to, 398 00:22:19,952 --> 00:22:22,502 Prasanna Malaiyandi: But, but we all like new toys, Curtis. 399 00:22:22,502 --> 00:22:23,162 Come on. 400 00:22:23,777 --> 00:22:24,137 W. Curtis Preston: Yeah. 401 00:22:24,137 --> 00:22:24,827 We all like new 402 00:22:24,932 --> 00:22:27,782 Prasanna Malaiyandi: and I think the other thing people sometimes don't think about 403 00:22:27,782 --> 00:22:32,995 going to that point you just mentioned is you could replace the system, but 404 00:22:32,995 --> 00:22:39,235 sometimes you have to also take into consideration retraining, retooling, uh. 405 00:22:39,745 --> 00:22:42,895 Thinking about your existing infrastructure, keeping that up 406 00:22:42,895 --> 00:22:46,945 and running, migrating all your workloads over to use the new system. 407 00:22:46,945 --> 00:22:52,015 There's a big cost with migrating a backup system that you need 408 00:22:52,020 --> 00:22:53,365 to take into consideration. 409 00:22:53,395 --> 00:22:56,635 If you do decide, okay, I wanna swap out my existing system. 410 00:22:57,009 --> 00:23:01,255 W. Curtis Preston: that is absolutely a reason not to migrate. 411 00:23:01,675 --> 00:23:03,865 If you don't have to migrate, right. 412 00:23:04,345 --> 00:23:10,015 Um, realize that this is your last line of defense and every time you make a change, 413 00:23:10,015 --> 00:23:15,025 you introduce instability and risk, uh, et cetera, et cetera, et cetera, right? 414 00:23:15,180 --> 00:23:15,470 Prasanna Malaiyandi: Yeah. 415 00:23:16,405 --> 00:23:17,725 W. Curtis Preston: It's just like everything else in it. 416 00:23:18,175 --> 00:23:21,898 Prasanna Malaiyandi: The other the other thing with backup systems as well is. 417 00:23:22,813 --> 00:23:26,533 If I look at it, budgets, typically, most of your money is probably 418 00:23:26,533 --> 00:23:29,743 gonna be spent on the production side of the house or other things, 419 00:23:30,283 --> 00:23:32,653 not so much on the backup systems. 420 00:23:32,953 --> 00:23:36,193 And so you need to be wise with your dollars. 421 00:23:36,793 --> 00:23:40,633 So deciding, Hey, I'm gonna swap out my existing infrastructure for something 422 00:23:40,633 --> 00:23:43,783 completely different and it's not gonna make a huge difference for me. 423 00:23:44,323 --> 00:23:46,363 That's kind of a waste of money that you could have been 424 00:23:46,363 --> 00:23:47,743 using to do something else. 425 00:23:48,065 --> 00:23:48,545 W. Curtis Preston: Exactly. 426 00:23:49,720 --> 00:23:55,570 So once we have a handle on the requirements, it's 427 00:23:55,570 --> 00:23:57,155 time to start talking about. 428 00:23:57,940 --> 00:24:01,870 The, the various different ways that we can do this. 429 00:24:02,560 --> 00:24:11,620 And I think that nowadays one of the things that should bubble up to the 430 00:24:11,620 --> 00:24:18,070 top from a requirements perspective and, and should really take the lead 431 00:24:18,550 --> 00:24:23,830 in this part of the discussion is when we start looking at the capabilities 432 00:24:23,830 --> 00:24:26,800 of the different products is the cyber. 433 00:24:27,655 --> 00:24:30,115 Aspect, right? 434 00:24:30,205 --> 00:24:38,275 Because it's no good to have like the fastest backup and recovery system in 435 00:24:38,275 --> 00:24:45,085 the world and the one that has the most beautiful ui, et cetera, et cetera, and 436 00:24:45,085 --> 00:24:52,585 maybe costs the the least if that system can be hacked in a ransomware attack. 437 00:24:53,541 --> 00:24:55,251 Prasanna Malaiyandi: I agree. 438 00:24:55,825 --> 00:25:04,135 But I think no, but, but, but I think that there is various 439 00:25:04,135 --> 00:25:07,195 degrees of cyber resiliency. 440 00:25:07,840 --> 00:25:13,300 And you could also look to figure out, like it may not be directly supported 441 00:25:13,300 --> 00:25:17,860 by the backup vendor itself, but there might be say, storage systems 442 00:25:17,860 --> 00:25:21,460 that go alongside with the backup system that offer that capability. 443 00:25:21,730 --> 00:25:25,600 Or how you, going back to what you were saying, Curtis, how you design the system 444 00:25:26,020 --> 00:25:28,300 might lend itself to cyber resiliency. 445 00:25:28,300 --> 00:25:32,110 So I do agree with your requirement that your system needs to have 446 00:25:32,110 --> 00:25:35,140 cyber resiliency, but how it goes about may not be one specific 447 00:25:35,145 --> 00:25:36,520 vendor providing that solution. 448 00:25:36,935 --> 00:25:39,785 W. Curtis Preston: You, you may be looking at an overall solution to 449 00:25:39,785 --> 00:25:41,795 solve the, to solve the problem, right? 450 00:25:42,485 --> 00:25:47,135 And, and I think that that would be, you could say, well, with this vendor, 451 00:25:47,135 --> 00:25:50,705 I need to buy this box and I need to buy that box, and I need to buy 452 00:25:50,705 --> 00:25:56,105 this oss and I also need to buy some stuff from Amazon with this vendor. 453 00:25:56,110 --> 00:25:58,115 I get all of that in one place. 454 00:25:58,595 --> 00:25:59,015 Right. 455 00:25:59,020 --> 00:25:59,440 Prasanna Malaiyandi: Mm-Hmm. 456 00:26:00,245 --> 00:26:02,465 W. Curtis Preston: Um, so that's part of your discussion. 457 00:26:02,495 --> 00:26:03,065 What, what was that? 458 00:26:04,465 --> 00:26:05,305 Prasanna Malaiyandi: simplicity. 459 00:26:05,450 --> 00:26:06,350 W. Curtis Preston: yeah, simplicity. 460 00:26:06,620 --> 00:26:11,030 Simplicity is, is the, it is the, or. 461 00:26:11,030 --> 00:26:14,750 Complexity I will say is the enemy of security. 462 00:26:15,470 --> 00:26:16,670 I, I think, right? 463 00:26:16,910 --> 00:26:21,320 So yes, while I agree with what you're saying, the sometimes you can get the 464 00:26:21,320 --> 00:26:23,540 things that you need from multiple pieces. 465 00:26:24,050 --> 00:26:28,550 I would also argue if you had two systems that are equivalent in every other 466 00:26:28,550 --> 00:26:31,940 way, the one with fewer pieces wins. 467 00:26:32,905 --> 00:26:33,745 Prasanna Malaiyandi: Oh agree. 468 00:26:33,775 --> 00:26:34,285 For sure. 469 00:26:34,340 --> 00:26:34,730 W. Curtis Preston: Yeah. 470 00:26:35,390 --> 00:26:42,110 Um, and so you look at all of the different aspects, things like RTO and 471 00:26:42,115 --> 00:26:49,730 RPO, you really, really should look at ease of use, ease of configuration, ease 472 00:26:49,790 --> 00:26:55,880 of basically daily management, what kind of daily management that you have to have. 473 00:26:56,480 --> 00:26:58,340 And you should also be looking at. 474 00:26:59,375 --> 00:27:01,985 The, again, these security aspects. 475 00:27:01,985 --> 00:27:06,065 I think when we look at requirements, I, I think perhaps we should just do a 476 00:27:06,065 --> 00:27:12,755 whole separate episode of what are the things that I think are table stakes 477 00:27:12,755 --> 00:27:15,875 at this point for a backup system. 478 00:27:15,875 --> 00:27:16,655 Now, you're right. 479 00:27:17,045 --> 00:27:22,835 Some of these things may be provided by a second vendor, for example. 480 00:27:22,865 --> 00:27:27,845 I think that at this point, true actual complete immutability. 481 00:27:28,580 --> 00:27:30,260 Is table stakes. 482 00:27:31,265 --> 00:27:35,150 The, the problem is that there's a whole lot of companies that use the word 483 00:27:35,150 --> 00:27:37,970 immutability when it, it, it's, it's not 484 00:27:38,110 --> 00:27:38,800 Prasanna Malaiyandi: Like air gap. 485 00:27:39,680 --> 00:27:39,920 W. Curtis Preston: Yeah. 486 00:27:39,920 --> 00:27:40,820 Like the term air gap. 487 00:27:40,880 --> 00:27:41,150 Yeah. 488 00:27:41,360 --> 00:27:49,865 Um, and so you, you have to ask specific questions to find out, you know, because. 489 00:27:54,020 --> 00:27:54,980 You have to ask questions. 490 00:27:54,980 --> 00:27:58,220 For example, if I change, you have to ask them. 491 00:27:58,940 --> 00:28:00,620 I, I'm a little devious. 492 00:28:02,030 --> 00:28:04,790 I dunno if you know this, but you have to, 493 00:28:04,900 --> 00:28:05,725 Prasanna Malaiyandi: I never expected that. 494 00:28:05,960 --> 00:28:10,640 W. Curtis Preston: you have to ask the questions in such a way that it 495 00:28:10,645 --> 00:28:13,280 makes it sound like you're asking for something good, but you're 496 00:28:13,280 --> 00:28:14,720 actually asking for something bad. 497 00:28:14,720 --> 00:28:15,980 Let me give you a perfect example. 498 00:28:18,665 --> 00:28:20,855 Your product offers immutability. 499 00:28:21,695 --> 00:28:23,555 What if I change my mind? 500 00:28:24,965 --> 00:28:31,565 Is there a way for me to, as the administrator, undo the immutability 501 00:28:31,715 --> 00:28:33,245 of a particular set of data? 502 00:28:33,900 --> 00:28:34,020 I. 503 00:28:34,820 --> 00:28:37,160 And, and give a reason as to give an example. 504 00:28:37,220 --> 00:28:40,520 Uh, let's say we decided we're no longer backing up an 505 00:28:40,520 --> 00:28:42,200 entire section of the company. 506 00:28:42,470 --> 00:28:46,550 We sold off a company or whatever, and we, you know, we, we'd like 507 00:28:46,550 --> 00:28:49,790 to reclaim that storage, but we turned on the immutability flag. 508 00:28:51,140 --> 00:28:54,200 Um, is there a way to undo that? 509 00:28:55,010 --> 00:28:56,630 The best answer? 510 00:28:56,690 --> 00:28:56,990 Yeah. 511 00:28:56,990 --> 00:28:59,360 The best answer is no, sorry. 512 00:29:00,920 --> 00:29:02,750 The worst answer is, oh yeah. 513 00:29:02,755 --> 00:29:04,400 You just, you just push the thing. 514 00:29:04,400 --> 00:29:05,180 You just push the thing. 515 00:29:05,360 --> 00:29:08,420 It's not really immutability, it's just, uh, you just, you just 516 00:29:08,420 --> 00:29:11,480 push the little, the super secret button that's over here, right? 517 00:29:11,930 --> 00:29:13,940 Um, that only we know is there. 518 00:29:14,450 --> 00:29:20,420 Somewhere in the middle is, yes you can, but we make you jump through 10 hoops. 519 00:29:20,960 --> 00:29:28,340 Um, and we do all sorts of manual, human based, face based verification. 520 00:29:29,330 --> 00:29:32,660 Although as I, as I say that, I'm like, I immediately go deep fake. 521 00:29:33,110 --> 00:29:34,370 Um, and I, I 522 00:29:34,780 --> 00:29:35,020 Prasanna Malaiyandi: that. 523 00:29:35,020 --> 00:29:36,250 Can't be trusted anymore. 524 00:29:36,275 --> 00:29:36,565 W. Curtis Preston: yeah. 525 00:29:37,040 --> 00:29:37,880 Goodness gracious. 526 00:29:38,120 --> 00:29:39,470 What a world we live in. 527 00:29:39,620 --> 00:29:40,940 What a world we live in. 528 00:29:42,920 --> 00:29:43,700 Um, 529 00:29:43,960 --> 00:29:44,200 Prasanna Malaiyandi: soon. 530 00:29:44,200 --> 00:29:45,850 This podcast will be a deep fake. 531 00:29:47,030 --> 00:29:49,760 W. Curtis Preston: how do we know this isn't a deep fake, I'm just saying. 532 00:29:49,930 --> 00:29:50,440 Prasanna Malaiyandi: Ah, good point. 533 00:29:53,930 --> 00:29:55,580 W. Curtis Preston: I mean, all you have to do is watch a 534 00:29:55,585 --> 00:29:57,260 couple of those videos where. 535 00:29:57,620 --> 00:30:01,490 You, you know, it's a fake video, but it really doesn't look like a fake video. 536 00:30:03,860 --> 00:30:04,610 It's a little freaky. 537 00:30:05,090 --> 00:30:05,600 Um, 538 00:30:06,175 --> 00:30:06,395 Prasanna Malaiyandi: Oh. 539 00:30:07,040 --> 00:30:07,280 W. Curtis Preston: yeah. 540 00:30:07,280 --> 00:30:12,410 So how do you, those are, those are your answers. 541 00:30:12,410 --> 00:30:19,925 And I think that that is to, that's question number one in this system. 542 00:30:20,785 --> 00:30:26,090 If I, so for example, if you use AWS and Object lock, the answer is no. 543 00:30:28,415 --> 00:30:28,835 Prasanna Malaiyandi: Unless, 544 00:30:29,215 --> 00:30:29,565 W. Curtis Preston: Right. 545 00:30:29,570 --> 00:30:30,920 Unless, unless 546 00:30:31,030 --> 00:30:33,850 Prasanna Malaiyandi: unless you are using No. 547 00:30:33,850 --> 00:30:36,880 So there are two modes of object lock, if I recall. 548 00:30:37,480 --> 00:30:39,160 One is governance, one is compliance. 549 00:30:39,165 --> 00:30:43,210 I can't remember which one is more strict, but one does allow the admin 550 00:30:43,210 --> 00:30:45,725 to change it, the other one does not unless you delete your account. 551 00:30:45,830 --> 00:30:49,040 W. Curtis Preston: So you should be using whichever one is the, the one 552 00:30:49,040 --> 00:30:50,570 that doesn't allow you to delete it. 553 00:30:50,600 --> 00:30:50,990 Right. 554 00:30:51,625 --> 00:30:51,915 Prasanna Malaiyandi: Yeah, 555 00:30:52,415 --> 00:30:56,015 W. Curtis Preston: And, uh, although there, there is, 556 00:30:56,215 --> 00:30:57,491 Prasanna Malaiyandi: least I believe that's the case. 557 00:30:58,025 --> 00:30:59,555 W. Curtis Preston: yeah, there is still that question. 558 00:30:59,555 --> 00:31:02,345 And I, and I really want to get an answer to this que a 559 00:31:02,345 --> 00:31:03,965 definitive answer to this question. 560 00:31:04,175 --> 00:31:05,855 What happens when I delete my account? 561 00:31:07,150 --> 00:31:09,820 Now I've been told that it doesn't go away right away. 562 00:31:11,890 --> 00:31:16,480 And that, um, there's a way to recover that account if it's, 563 00:31:16,570 --> 00:31:18,490 uh, if it has optic clock on. 564 00:31:19,120 --> 00:31:22,210 But I haven't, I don't see that in writing and I haven't, and I 565 00:31:22,210 --> 00:31:24,520 certainly haven't, uh, tried it. 566 00:31:25,030 --> 00:31:25,930 That's what I need to do. 567 00:31:25,930 --> 00:31:26,020 I 568 00:31:26,175 --> 00:31:27,135 Prasanna Malaiyandi: Try it, Curtis. 569 00:31:27,550 --> 00:31:30,850 W. Curtis Preston: Just create an account, create object clock, delete 570 00:31:30,850 --> 00:31:34,090 some data, or put some data in there and then delete the account, and then, 571 00:31:34,319 --> 00:31:35,129 Prasanna Malaiyandi: See what happens. 572 00:31:35,425 --> 00:31:35,665 Yeah. 573 00:31:35,973 --> 00:31:36,573 W. Curtis Preston: so what else? 574 00:31:36,573 --> 00:31:41,193 Uh, we, we look at the different, um, you know, the different areas of 575 00:31:41,193 --> 00:31:45,903 functionality for the different areas of your environment, and then to allude 576 00:31:45,903 --> 00:31:47,673 to something that you had said earlier. 577 00:31:50,403 --> 00:31:56,493 I, I think it's important to talk about the fact that, let's talk about 578 00:31:56,643 --> 00:31:59,133 basically best of breed versus all in one. 579 00:32:00,183 --> 00:32:09,303 So is it better to have one backup system that does everything, or three backup 580 00:32:09,303 --> 00:32:11,108 systems that do three things really well? 581 00:32:11,528 --> 00:32:12,268 That's a question. 582 00:32:13,794 --> 00:32:17,364 Prasanna Malaiyandi: So assuming that everything is equal, it's better to have 583 00:32:17,369 --> 00:32:20,004 the one system that can do everything. 584 00:32:20,424 --> 00:32:22,849 However, that's usually not the case. 585 00:32:23,038 --> 00:32:23,328 W. Curtis Preston: Yeah. 586 00:32:23,784 --> 00:32:28,014 Prasanna Malaiyandi: And there might be certain workloads that are more optimized 587 00:32:28,404 --> 00:32:30,714 and significantly better than that. 588 00:32:30,714 --> 00:32:32,784 all-in-one solution in some areas, 589 00:32:33,423 --> 00:32:33,753 W. Curtis Preston: Yeah, 590 00:32:33,924 --> 00:32:36,024 Prasanna Malaiyandi: which case, for those specific cases. 591 00:32:37,524 --> 00:32:41,364 And so for those specific workloads, you might decide, okay, everything else 592 00:32:41,364 --> 00:32:43,104 I'm gonna protect with this all-in-one. 593 00:32:43,109 --> 00:32:45,894 And for this one particular specialized use case, I'm 594 00:32:45,894 --> 00:32:48,054 gonna use this special product. 595 00:32:49,108 --> 00:32:51,183 W. Curtis Preston: and this is kind of what I wanted to talk 596 00:32:51,183 --> 00:32:57,573 about is that the answer should be. 597 00:32:59,163 --> 00:33:03,843 It's okay to do, to, you know, to, to have that specialized workload 598 00:33:03,933 --> 00:33:09,033 protected by the specialized product that specializes in that workload, right? 599 00:33:10,083 --> 00:33:17,043 If you're unable to meet your requirements with the more general product, that's 600 00:33:17,048 --> 00:33:19,803 really the only time to deviate. 601 00:33:20,733 --> 00:33:24,663 And this is, this is just like when, when I talked in the beginning. 602 00:33:25,458 --> 00:33:28,818 The only time to move off of a backup product is if you can no 603 00:33:28,818 --> 00:33:32,178 longer meet your requirements with the current backup product. 604 00:33:32,688 --> 00:33:37,458 The only time to deviate from the central design and the central, you 605 00:33:37,458 --> 00:33:43,308 know, one sort of product to rule them all is when you can't, um, 606 00:33:43,878 --> 00:33:47,658 you can't meet your requirements for one part of your organization. 607 00:33:48,123 --> 00:33:51,723 With the, you know, the, the one big backup product that you're 608 00:33:51,723 --> 00:33:55,293 planning to do everything with, and then suddenly somebody brings in. 609 00:33:55,293 --> 00:34:00,963 I don't have a modern equivalent of this, but I'm thinking about back when. 610 00:34:01,923 --> 00:34:06,213 You know, back in the day when I was in the data center, we had like 611 00:34:06,513 --> 00:34:13,683 nine different types of Unix and we had, we had the top three databases. 612 00:34:13,683 --> 00:34:20,883 We had Oracle and Informix and Sybase, and, and pretty much any popular flavor 613 00:34:20,883 --> 00:34:22,563 of Unix we had in the data center. 614 00:34:23,703 --> 00:34:25,493 And then we had an AS400. 615 00:34:26,553 --> 00:34:29,673 There was no backup product in the world. 616 00:34:30,363 --> 00:34:34,833 That backed up Unix and AS400. 617 00:34:35,283 --> 00:34:35,733 Right? 618 00:34:36,303 --> 00:34:40,653 So we needed a separate backup product for the AS400 because there was just, 619 00:34:40,653 --> 00:34:42,213 there was just literally no other way. 620 00:34:42,243 --> 00:34:44,313 That's an example of what I'm talking about. 621 00:34:44,913 --> 00:34:49,803 Um, can you think of a, of a modern equivalent to that? 622 00:34:50,043 --> 00:34:54,063 Prasanna Malaiyandi: At one of my previous employers, one of the things that I ran 623 00:34:54,063 --> 00:35:00,153 into was when you had very, very, very large databases running on tier one 624 00:35:00,153 --> 00:35:03,153 storage, backing them up was too painful, 625 00:35:03,303 --> 00:35:03,723 W. Curtis Preston: mm-Hmm. 626 00:35:04,443 --> 00:35:06,543 Prasanna Malaiyandi: and I'm talking about hundreds of terabytes. 627 00:35:07,103 --> 00:35:07,453 W. Curtis Preston: Right. 628 00:35:07,923 --> 00:35:12,873 Prasanna Malaiyandi: And so there was a solution developed called Protect 629 00:35:12,873 --> 00:35:16,503 point to allow direct backups of those. 630 00:35:16,998 --> 00:35:20,628 From the storage rate to a data domain system 631 00:35:20,818 --> 00:35:20,968 W. Curtis Preston: Mm-Hmm. 632 00:35:21,738 --> 00:35:24,978 Prasanna Malaiyandi: and intended only for that particular use case, right? 633 00:35:25,068 --> 00:35:28,878 But it allowed them to actually get a backup done rather than all of the 634 00:35:28,883 --> 00:35:31,248 pain that they were going through, or the fact that they weren't able 635 00:35:31,253 --> 00:35:32,508 to backup at all to start with. 636 00:35:33,118 --> 00:35:36,808 W. Curtis Preston: Yeah, I, that, that's, I think that's a good example. 637 00:35:36,838 --> 00:35:43,323 I was thinking when I was trying to come up with a modern equivalent, um, I. 638 00:35:43,978 --> 00:35:51,778 I was thinking of like, maybe you're not running VMware or HyperV or KVM, you are 639 00:35:51,778 --> 00:35:54,178 running some other hypervisor, right? 640 00:35:54,178 --> 00:35:57,298 I, I know people that work at some of these other hypervisor companies 641 00:35:57,358 --> 00:35:58,798 and they're, they're doing just fine. 642 00:35:58,798 --> 00:36:01,798 They're doing, they're having an exciting time right now with the 643 00:36:02,308 --> 00:36:04,588 Broadcom acquisition of VMware. 644 00:36:04,648 --> 00:36:04,858 Right. 645 00:36:04,858 --> 00:36:08,788 It's a, it's, it's fun days for these guys, right? 646 00:36:08,998 --> 00:36:11,818 So you're obviously not going to be able to use your. 647 00:36:12,388 --> 00:36:16,828 Mainstream backup product to back up the non-mainstream virtualization 648 00:36:16,828 --> 00:36:22,288 product, you're going to have to have something else for that product, right? 649 00:36:22,468 --> 00:36:24,928 Um, and that, and that is okay. 650 00:36:25,798 --> 00:36:28,813 Uh, if you have no other choice, um. 651 00:36:29,253 --> 00:36:29,523 Prasanna Malaiyandi: Yeah. 652 00:36:29,973 --> 00:36:33,243 But yeah, and that's just life, right? 653 00:36:33,243 --> 00:36:34,293 You need to back up that data. 654 00:36:34,293 --> 00:36:35,253 It's important to you. 655 00:36:35,793 --> 00:36:37,383 You'll figure out a way the perfect. 656 00:36:37,383 --> 00:36:40,263 The other example, Curtis, as we were chatting, I was just thinking about this. 657 00:36:40,803 --> 00:36:42,783 Most SaaS applications, right? 658 00:36:43,263 --> 00:36:46,803 Most of those are the common vendors don't always support it. 659 00:36:46,808 --> 00:36:51,243 And so you might have one that requires a specific backup product to back it up. 660 00:36:52,438 --> 00:36:55,233 W. Curtis Preston: exactly, because we're gonna back up our SaaS apps, right? 661 00:36:57,438 --> 00:36:59,418 Prasanna Malaiyandi: No, SAS doesn't need to be backed up. 662 00:37:01,198 --> 00:37:01,678 W. Curtis Preston: Don't make, 663 00:37:01,818 --> 00:37:03,018 Prasanna Malaiyandi: I am not serious. 664 00:37:03,143 --> 00:37:03,433 Yeah. 665 00:37:05,363 --> 00:37:07,223 W. Curtis Preston: When I look at all of the different ways 666 00:37:07,223 --> 00:37:10,703 that we do backups, I think that. 667 00:37:12,553 --> 00:37:15,788 Uh, the cyber requirements need to be, I think they need 668 00:37:15,788 --> 00:37:17,468 to be front and center, right? 669 00:37:17,978 --> 00:37:20,918 Because it doesn't matter how good the system is, if it disappears in 670 00:37:20,918 --> 00:37:22,448 a ransomware attack, it's no good. 671 00:37:23,918 --> 00:37:32,288 And I think that the ways that we can do backup today, that offer s restores 672 00:37:32,288 --> 00:37:38,888 that are so much quicker that, um, it. 673 00:37:39,713 --> 00:37:43,673 May cause me to waffle a bit on this. 674 00:37:43,793 --> 00:37:47,303 Don't do it unless you have an absolute requirement bit. 675 00:37:48,083 --> 00:37:53,352 And here, and here's what I mean by that, when you think about cyber recoveries, 676 00:37:53,357 --> 00:37:57,822 when you think about recovering from a ransomware, uh, attack, well, it 677 00:37:57,822 --> 00:38:01,482 might not be an absolute requirement. 678 00:38:02,247 --> 00:38:05,157 For a normal restore to be of a certain speed. 679 00:38:06,357 --> 00:38:06,657 Right. 680 00:38:06,657 --> 00:38:13,017 The recover, the RTO, the, the previous part. 681 00:38:13,022 --> 00:38:15,237 I, I guess I'm not, I'm not changing my answer. 682 00:38:15,237 --> 00:38:19,407 I'm just saying I'm, I guess I'm saying, I'm going back to the beginning and 683 00:38:19,412 --> 00:38:25,487 saying, when you're determining your RTO and RPO, just think about the cyber 684 00:38:25,487 --> 00:38:36,062 aspects When you have a cyber attack, you are going to spend your entire 685 00:38:36,062 --> 00:38:43,562 RTO and probably past your RTO, just figuring out what needs to be restored. 686 00:38:44,772 --> 00:38:45,112 Prasanna Malaiyandi: Yeah. 687 00:38:45,422 --> 00:38:52,472 W. Curtis Preston: So then think about the likely recovery that 688 00:38:52,472 --> 00:38:53,792 you're going to need to do. 689 00:38:54,152 --> 00:38:58,592 And think about how that potentially affects the RTO capabilities 690 00:38:58,682 --> 00:39:03,122 of a backup product or a DR product that you're buying. 691 00:39:04,112 --> 00:39:06,872 Because basically they're gonna finally figure it out. 692 00:39:06,872 --> 00:39:09,092 It's taken 'em two weeks and they're gonna be, okay. 693 00:39:09,612 --> 00:39:15,362 Prasanna just now just restore these 17 boxes, right? 694 00:39:15,842 --> 00:39:18,752 And they're not gonna go, oh, well, okay, well I guess I 695 00:39:18,752 --> 00:39:21,032 can start my 24 hour RTO now. 696 00:39:21,392 --> 00:39:21,842 No. 697 00:39:22,637 --> 00:39:24,707 You got no minutes at this point. 698 00:39:25,337 --> 00:39:26,597 So I guess what I'm 699 00:39:26,707 --> 00:39:28,237 Prasanna Malaiyandi: go run as quickly as you can. 700 00:39:28,427 --> 00:39:29,687 W. Curtis Preston: yeah, yeah, exactly. 701 00:39:30,107 --> 00:39:37,337 Um, I'm just saying that perhaps in the modern climate, the, the restore aspects, 702 00:39:39,407 --> 00:39:45,677 perhaps you should give a little bit more weight to products that can do restores. 703 00:39:46,022 --> 00:39:49,442 Really, really, really, really quickly. 704 00:39:50,042 --> 00:39:51,362 This, I get, this is what I'm saying. 705 00:39:51,362 --> 00:39:56,822 I'm, I'm kind of waffling on the requirement, but I'm kind of not, 706 00:39:57,002 --> 00:40:02,122 because you're not gonna have the RTO set to two weeks, right? 707 00:40:02,127 --> 00:40:07,402 You're gonna have the RTO set to something probably in hours, and 708 00:40:08,542 --> 00:40:10,122 when you get a cyber attack. 709 00:40:11,177 --> 00:40:14,327 It's gonna, whatever, whatever you set it to, it's gonna eat it up. 710 00:40:14,327 --> 00:40:18,047 And then you're just gonna need, need to be able to restore as quickly as possible. 711 00:40:19,517 --> 00:40:26,567 Um, and so just think, just figure that into, when you're talking to, 712 00:40:26,957 --> 00:40:29,207 uh, vendors, when you're thinking about their backup products. 713 00:40:30,527 --> 00:40:31,337 Um, 714 00:40:31,522 --> 00:40:32,632 Prasanna Malaiyandi: I like that. 715 00:40:33,047 --> 00:40:37,427 W. Curtis Preston: yeah, it's all cagey and weird and, uh, it's just, 716 00:40:37,427 --> 00:40:39,137 I'm trying to, I'm just trying to. 717 00:40:40,712 --> 00:40:42,392 Get you to think about that. 718 00:40:42,542 --> 00:40:46,532 If you're thinking about changing your backup product, just think about how, 719 00:40:46,922 --> 00:40:52,532 think about what a likely cyber recovery will actually look like, um, and how 720 00:40:52,532 --> 00:41:00,602 you'll, um, it, I don't know if I've told this story on the podcast, but 721 00:41:00,602 --> 00:41:01,922 I'm pretty sure I've told it to you. 722 00:41:02,882 --> 00:41:04,112 I go back to. 723 00:41:05,162 --> 00:41:09,482 One of the first major restorers that I participated in, and I was 724 00:41:09,482 --> 00:41:13,052 at a bank and we had a, we had a NOC right network operations center. 725 00:41:13,952 --> 00:41:19,982 And when we were doing a large restore, there was someone who was at a console 726 00:41:20,642 --> 00:41:24,872 that was a remote console to system we were restoring and they were sort of, 727 00:41:24,992 --> 00:41:26,792 they were the operation center, right? 728 00:41:27,182 --> 00:41:30,512 And so they were talking to people on phones and you know, we had, we 729 00:41:30,512 --> 00:41:33,092 had, uh, um, I'm trying to remember. 730 00:41:33,092 --> 00:41:34,412 I don't, I don't think we had. 731 00:41:35,642 --> 00:41:36,332 Flip phones. 732 00:41:36,332 --> 00:41:39,152 I think we just had, we just had phones, right? 733 00:41:39,182 --> 00:41:42,002 Regular hardwired phones and beepers. 734 00:41:42,002 --> 00:41:42,332 Right. 735 00:41:43,132 --> 00:41:43,432 Prasanna Malaiyandi: Yep. 736 00:41:43,712 --> 00:41:49,172 W. Curtis Preston: And I remember that, um, we had the guy in the data center. 737 00:41:49,682 --> 00:41:52,082 Uh, I only saw the other half of this story. 738 00:41:52,082 --> 00:41:55,322 I didn't, I didn't see this, the, the, the funny part 739 00:41:55,432 --> 00:41:56,692 Prasanna Malaiyandi: Because you were out in the data center 740 00:41:56,822 --> 00:41:59,552 W. Curtis Preston: 'cause I was the one in the data center doing the thing. 741 00:41:59,822 --> 00:42:00,212 Right. 742 00:42:00,692 --> 00:42:01,232 So. 743 00:42:01,727 --> 00:42:02,937 In the NOC. 744 00:42:03,117 --> 00:42:08,037 There, there was the, the, you know, the guy sitting at the, um, at the, 745 00:42:08,217 --> 00:42:13,737 you know, the console and standing behind him were two managers. 746 00:42:13,787 --> 00:42:18,767 His boss's boss and his boss's boss's boss standing, you know, and it just 747 00:42:18,767 --> 00:42:21,767 so happened that their first name, they're both, first, both of their 748 00:42:21,767 --> 00:42:29,182 first names were Tom and, One of my cohorts was talking to this guy on 749 00:42:29,182 --> 00:42:32,242 the speaker, on speaker phone, not knowing he was on speaker phone. 750 00:42:33,457 --> 00:42:33,677 Prasanna Malaiyandi: Oh 751 00:42:33,982 --> 00:42:35,902 W. Curtis Preston: And so we were in the middle of this big recovery. 752 00:42:36,382 --> 00:42:39,439 And, it's just what I thought about, you know, when you come 753 00:42:39,439 --> 00:42:42,559 time to do the restore, you've got, you've got the attention of the, 754 00:42:42,649 --> 00:42:44,059 you know, the powers that be right. 755 00:42:44,118 --> 00:42:46,218 So he said, you know, so yeah, where are you? 756 00:42:46,218 --> 00:42:49,368 Oh, I'm in, I'm in, you know, this data center and you know, where are you? 757 00:42:49,368 --> 00:42:52,128 Oh, I'm in the NOC, you know, sitting here at the console. 758 00:42:52,278 --> 00:42:53,568 And he goes, let me guess. 759 00:42:53,568 --> 00:42:56,148 You got Tom and Tom over your left and right shoulder. 760 00:42:59,808 --> 00:43:03,678 And apparently Tom and Tom just took like one step back. 761 00:43:06,243 --> 00:43:09,903 Because yes, when the feces hits the rotary oscillator, 762 00:43:09,903 --> 00:43:11,193 that's exactly what happened. 763 00:43:11,193 --> 00:43:16,953 You've got all that attention, a very unwarranted, unwelcome, uh, 764 00:43:17,133 --> 00:43:18,423 well not warrant, unwarranted. 765 00:43:18,423 --> 00:43:20,583 It's warranted, uh, unwelcome. 766 00:43:21,068 --> 00:43:21,188 I. 767 00:43:21,564 --> 00:43:22,779 Prasanna Malaiyandi: All eyes on you. 768 00:43:23,223 --> 00:43:23,643 W. Curtis Preston: Yeah. 769 00:43:23,643 --> 00:43:29,613 So, uh, just my final thought, just make sure that the first time you're firing the 770 00:43:29,613 --> 00:43:32,853 backup system in anger is not the first time you're firing your backup system. 771 00:43:33,723 --> 00:43:34,113 Right. 772 00:43:34,353 --> 00:43:36,393 Make sure that you've got a solid handle. 773 00:43:36,393 --> 00:43:42,153 Once they say, go, and I know I've got 15 systems to restore, I 774 00:43:42,153 --> 00:43:43,533 know how long that's gonna take. 775 00:43:43,533 --> 00:43:46,473 So that you can, you know, and hopefully that, that you can reduce 776 00:43:46,473 --> 00:43:48,333 that time down as, as much as you can. 777 00:43:49,089 --> 00:43:49,329 Prasanna Malaiyandi: Yeah, 778 00:43:50,268 --> 00:43:50,808 W. Curtis Preston: Anyway. 779 00:43:51,648 --> 00:43:53,628 Um, well this has been fun. 780 00:43:56,478 --> 00:44:01,098 Anytime I can reminiscent over a, uh, a scary event from my 781 00:44:01,098 --> 00:44:02,508 past, it's a beautiful thing. 782 00:44:03,288 --> 00:44:03,408 Well, 783 00:44:03,519 --> 00:44:05,289 Prasanna Malaiyandi: which you have quite a lot of, I must say. 784 00:44:05,568 --> 00:44:06,558 W. Curtis Preston: I do, I do that. 785 00:44:06,588 --> 00:44:07,368 I'm a storyteller. 786 00:44:07,368 --> 00:44:08,028 What can I say? 787 00:44:09,018 --> 00:44:10,668 So thanks for hanging out, Prasanna. 788 00:44:11,829 --> 00:44:12,729 Prasanna Malaiyandi: as always. 789 00:44:12,729 --> 00:44:13,599 Thanks Curtis. 790 00:44:13,788 --> 00:44:14,058 W. Curtis Preston: All right. 791 00:44:14,058 --> 00:44:15,048 And thanks to our listeners. 792 00:44:15,048 --> 00:44:16,278 We'd be nothing without you. 793 00:44:16,458 --> 00:44:17,688 That is a wrap.