Storage Expo 2008
The majority of backups are performed with root access

Poor backup policies leaving huge security holes

Businesses exposed by poor practice, says data protection expert

Ian Williams

Many companies are leaving themselves exposed to a data leak through poor backup policies, according to a stark warning from GlassHouse Technologies.

Despite the huge publicity surrounding data breaches and the clamour to make sure all data is protected, the majority of businesses are ignoring a fundamental point of attack in the backup process.

Advertisement

Curtis Preston, vice president of data protection at GlassHouse, told vnunet.com at the Storage Expo show in London that the majority of organisations treat backup as an ignored and feared part of the business, relegating the task to the newest person on the team who often has no experience and never looks back once promoted to something else.

"This is folly. Backup is the most powerful data system in the entire company," he said. "All data flows through it and it cuts right through any encryption or other security, policy or 'auditability' measures in place throughout the rest of the organisation."

To make matters worse, the majority of backups are performed with root access, giving the user complete control with little or no chance of detection should they do something malicious.

"The log-ins are usually never changed from their default setting, even when the password is 'changeme'. It boggles the mind when everyone is banging on about data leaks, but leaving the back door wide open," said Preston.

Because many backup systems allow users to run scripts elsewhere in the system in case they need to shut down processes that are locking files or something similar, someone in this privileged position could steal valuable company data undetected and wreak havoc across the entire business if so inclined.

Preston believes that businesses need to stop ignoring backup as some dark art and regulate the area as with the rest of business, bringing in proper password management, user policies and auditing.

"And if a company is going to insist in assigning the job of data backup to the new guy, they need to perform proper background checks before hiring him," he concluded.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Storage Expo 2008

Tape is alive and well for storage

Hybrid of disk and tape ideal for effective backup and archiving

Virtualisation

GlassHouse Technologies launches virtual services

IT consulting firm will unveil managed services for virtual environments at VMworld 2008

HP boosts encryption for disk arrays and tapes

Reduced risk of security breaches, says vendor

Imation adds RFID tags to tapes

Better tracking for off-site backup, claims firm

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Top 10 IT thrillers

Off-the-wall innovations that make life as easy as 1-2-3

Windows logo

What does Windows 7 mean for Microsoft?

With the sting of Vista still fresh, Redmond has to...

david cameron

V3.co.uk weekly debrief, 10 July 09

This week Conservative Party plans for decentralised data storage and...

Small office

SME tech sales tough despite projected success

Midmarket organisations still tend to rely on manual processes

Primary Navigation