All the latest UK technology news, reviews and analysis

Poor backup policies leaving huge security holes

by Ian Williams

16 Oct 2008

Be the first to comment

  • Tweet this
Storage Expo 2008
The majority of backups are performed with root access

Many companies are leaving themselves exposed to a data leak through poor backup policies, according to a stark warning from GlassHouse Technologies.

Despite the huge publicity surrounding data breaches and the clamour to make sure all data is protected, the majority of businesses are ignoring a fundamental point of attack in the backup process.

Curtis Preston, vice president of data protection at GlassHouse, told vnunet.com at the Storage Expo show in London that the majority of organisations treat backup as an ignored and feared part of the business, relegating the task to the newest person on the team who often has no experience and never looks back once promoted to something else.

"This is folly. Backup is the most powerful data system in the entire company," he said. "All data flows through it and it cuts right through any encryption or other security, policy or 'auditability' measures in place throughout the rest of the organisation."

To make matters worse, the majority of backups are performed with root access, giving the user complete control with little or no chance of detection should they do something malicious.

"The log-ins are usually never changed from their default setting, even when the password is 'changeme'. It boggles the mind when everyone is banging on about data leaks, but leaving the back door wide open," said Preston.

Because many backup systems allow users to run scripts elsewhere in the system in case they need to shut down processes that are locking files or something similar, someone in this privileged position could steal valuable company data undetected and wreak havoc across the entire business if so inclined.

Preston believes that businesses need to stop ignoring backup as some dark art and regulate the area as with the rest of business, bringing in proper password management, user policies and auditing.

"And if a company is going to insist in assigning the job of data backup to the new guy, they need to perform proper background checks before hiring him," he concluded.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

.Net Principal Development Engineer Lead- London

Principal Development Engineer Lead- London - Smart TV...

.Net Development Engineer - HTML, XHTML, CSS, DOM

Development Engineer - London - Smart TV, Gaming, Tablets...

Principal Development Engineer - .Net ,C# or Java -

Principal Development Engineer - London - Smart TV, Gaming...

Test Engineer -London - Smart TV, Gaming, Tablets, PC& Mac

Test Engineer -London - Smart TV, Gaming, Tablets, PC...

To send to more than one email address, simply separate each address with a comma.