What is CISO-approved backup?

Background of Keepit’s CISO Kim Larsen

My journey into cybersecurity started long ago when I was a police officer. I was working in serious crime investigation, which then took me to the internet as the world went to cyber, and eventually I joined the intelligence service in Denmark as CSO. After that, I was working with NATO and the EU as a delegate to the security committees.

This background has been incredibly beneficial as it taught me to handle crises, assess risks, and maintain a certain calmness under pressure. These skills are vital in the cybersecurity world, where threats are ever-present and evolving daily. As a police officer, I was trained to see risks that others might overlook, and this perspective has been invaluable in my career role as a CISO.

Understanding the cybercrime landscape

One of the significant challenges in cybersecurity, as I see it, is the dynamic nature of cybercrime. Criminals can constantly change their tactics and crime scenes, making it difficult to combat them. Therefore, it’s crucial to have a strong collaboration between governments and enterprises to prevent these crimes effectively. The cooperation between different sectors is vital because cybersecurity threats don’t respect borders, and international collaboration is often required to address them.

Having the right level of security is key to earning customer trust.

The critical role of a CISO in backup solutions 

At Keepit, we recognize that we are the last line of defense for an enterprise. When everything else fails, businesses rely on their backup systems to recover and continue operations. This is why backup solutions need to be robust, reliable, and secure. My role involves ensuring that we stay ahead of compliance regulations, understand the threats we face, and mitigate those risks effectively. 

Bringing backup to the forefront 

Traditionally, backup systems have been viewed as something in the corner (or quite literally the basement), often neglected until disaster strikes, where it’s hoped everything will work for a recovery.

However, I believe that backup solutions, like those provided by Keepit, should be brought to the forefront of an organization’s strategy. Our solution ensures that data is not only backed up but secure, readily accessible, and restorable, aligning with the critical needs of modern enterprises, such as ensuring business continuity and compliance even in the face of disruptions.

Backup systems aren’t just an IT concern but should be a significant consideration for management, C-level, and the board. Regular testing and daily engagement with backup solutions are essential to ensure they are ready when they are desperately needed — after an attack or other data loss event. 

The Keepit approach to backup 

At Keepit, we provide backup solutions for software-as-a-service (SaaS) environments. This means that we back up data and allow businesses to work live with the information, whether it’s a regional backup or a cloud backup. One of the key features of our solution is the ability to reverse cloud backups to local backups. This ensures that businesses can always access their data, even if they lose connection to their cloud provider, such as Microsoft, Google, or Amazon. This dual approach provides a significant advantage in terms of compliance and business continuity. 

Security measures and certifications 

We pride ourselves on using a well-proven, robust data center solution and maintaining rigorous security standards. Our security measures are based on ISO 27001 certification, which, while not providing security on its own, assures our customers that the entire Keepit organization lives up to the highest international security standards and ensures that we have the necessary controls in place. We focus on maintaining strict control over access, keeping IDs updated, and ensuring that only authorized personnel have access to our servers. 

Identity management and zero trust 

Credential management is critical in cybersecurity. While the concept of zero trust is often more theoretical, we strive to implement as many controls as possible to minimize risks.  To me, zero trust is mostly theory because I don’t think anyone has total control over all of the processes in their infrastructure. For a deeper understanding of zero trust principles, you can refer to the NIST Zero Trust Architecture

So, my advice is to build a control framework that, first of all, protects your critical assets and ensures that you have identified and protected those frameworks of controls that work. By doing that you also map what you might not have sufficient control over, be aware of that, and then protect it even more than you do with the rest of your assets.

It’s essential to understand which assets you need to protect the most and to build a governance framework around those assets. This approach helps in identifying and safeguarding the crown jewels of your enterprise; it’s all about asset identification.

He who defends everything, defends nothing.

Frederick the Great

Compliance and regulations 

Compliance with regulations is a global concern. Whether it’s GDPR or NIS2 compliance in Europe or other data protection laws in the US like DORA (Digital Operational Resilience Act) and others around the world, businesses need to be aware of and comply with these regulations. It’s not just about having a certificate; it’s about living the compliance regulations and integrating them into the enterprise culture. Trust is paramount in our industry, and if customers don’t trust us, they won’t buy our services. 

The impact of AI and future threats 

Artificial Intelligence is rapidly changing the threat landscape. The ability of AI to mimic human behavior and infiltrate systems is a growing concern. It’s crucial to know where your data is and ensure it’s adequately protected. This includes being cautious about using public AI services and understanding what data can be shared and what must remain secure. 

Data management challenges 

One of the biggest challenges in data management is knowing where your data is and how it’s protected. This includes understanding where data is stored when it’s in the cloud, how it’s transported, and how employees share it. Most data breaches occur due to unintentional data sharing rather than malicious intent. Therefore, it’s essential to provide clear guidelines and establish a framework that aligns with how employees work. 

Balancing security and collaboration 

The foundation of any business is data sharing, but this must be balanced with security needs. Over-classification of data can impede collaboration and productivity. It’s about finding the right balance where security measures protect the most critical data while allowing for effective collaboration within the organization. 

The importance of regular testing 

A backup solution is only as good as its last test. Regular testing ensures that the backup system is functional and ready to be deployed when needed. It’s essential to integrate this testing into the daily operations of the organization rather than waiting for a disaster to strike. 

Conclusion 

A CISO-approved backup solution is one that is robust, reliable, and secure. It involves regular testing, strong compliance with regulations, effective identity management, and a balanced approach to data security and collaboration. If you have active backup that is also used on a daily basis for file recovery, for example, the chance that it works and that your organization knows how to use it is significantly raised in case of a large-scale incident. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

Top 10 considerations for a recovery solution RFP

As we all know, the threat of ransomware continues to grow, and so does the importance of ensuring that your business remains resilient and prepared to respond to and recover from ransomware attacks. To help you with your ransomware readiness, ESG (Enterprise Strategy Group) has created “The Ransomware Preparedness Top Ten Recovery Solution RFP” in their report focused on ransomware readiness and cyber resilience.

Here’s what they find are the 10 most important considerations when selecting solutions for data recovery, which will help you shortlist potential data backup and recovery platforms.

Vendor selection checklist key considerations:

1.       Data encryption (at rest and/or in flight)

2.       Ability to protect SaaS data

3.       Ability to detect ransomware in data copies/backups

4.       Integrated cloud services capabilities

5.       Ability to recover to any point or location

6.       Ability to protect endpoint devices

7.       Ability to protect virtual machines

8.       End-to-end recovery services

9.       Protected/immutable data copies/backups

10.   Continuous data protection/replication/journaling

Understanding these factors will help guide you toward writing a more effective proposal and to evaluate and select the most effective backup and recovery services for your organization’s needs. Let’s look a bit more deeply into each of them.

Read the full ESG report

 

Top 10 considerations for ransomware recovery solutions

Creating an RFP (request for proposal) for ransomware recovery solutions is a critical task, so let’s expand a bit on why each pointer ESG has identified is important and also add some key considerations that can be included to help you build the best protection portfolio for your specific needs.

Of course, before you can do so, you need to evaluate which data has value to your business and is most critical to back up since no single solution does everything. For instance, those solutions focusing on on-prem VM aren’t going to be able to cover all SaaS. Likewise, if a solution is optimized for cloud data, it’s not going to be strong for on-prem configurations. So, considering your specific data protection needs beforehand will help you have the right tool for the right job:

1. Data encryption (at rest and/or in flight)

Importance: Data encryption is crucial for protecting sensitive information from unauthorized access and ensuring data integrity. Encryption at rest protects data stored on disks and storage devices, while encryption in flight secures data during transmission.

Considerations:

• Encryption standards: Specify the encryption algorithms (e.g., AES-256) and protocols (e.g., TLS, SSL) that the solution must support.

• Key management: Detail the requirements for key management practices, including generation, storage, rotation, and destruction.

• Compliance: Ensure the solution meets industry standards and regulatory requirements (e.g., GDPR, HIPAA).

• Performance impact: Evaluate the impact of encryption on system performance and backup/recovery speeds.

2. Ability to protect SaaS data

Importance: With the increasing adoption of SaaS applications, more and more business-essential data is stored in SaaS applications, therefore ensuring the protection and backup of data hosted in the cloud is vital for business continuity, compliance, and more.

Considerations:

• SaaS integrations: Identify specific SaaS applications (e.g., Office 365, Salesforce) and ensure the solution supports seamless integration.

• API support: Ensure the solution can interact with SaaS APIs for automated backup and recovery.

• Data ownership: Clarify data ownership and access rights in the context of SaaS providers’ terms of service.

• Recovery options: Provide details on how data can be restored, including granularity (e.g., individual items vs. entire datasets).

3. Ability to detect ransomware in data copies/backups

Importance: Early detection of ransomware within backup data can prevent the spread and mitigate damage.

Considerations:

• Anomaly detection: Ensure the solution includes advanced anomaly detection techniques to identify unusual patterns indicative of ransomware.

• Scanning tools: Integrate with malware scanning tools to analyze backup data.

• Monitoring/notification systems: Set up real-time alerts for detected anomalies or potential ransomware activity.

• Historical analysis: Implement capabilities to review historical backup data for signs of previously undetected ransomware.

4. Integrated cloud services capabilities

Importance: Leveraging cloud services for backup and recovery enhances scalability, reliability, and accessibility.

Considerations:

• Cloud providers: Specify preferred cloud providers (e.g., AWS, Azure, Google Cloud) and their service offerings, while also considering data protection best practices, such as air gapping in line with the 3-2-1 backup rule.

• Cost management: Tools for monitoring and managing cloud storage costs. Many providers have additional costs based on, e.g., consumption, egress/ingress, retention, archiving departed users, and more.

• Disaster recovery: Utilize cloud for disaster recovery solutions with geographically dispersed data centers.

5. Ability to recover to any point or location

Importance: Flexibility in recovery options ensures that data can be restored to different points in time or alternate locations as needed.

Considerations:

• Granularity: Support for granular recovery points (e.g., hourly, daily) to minimize data loss.

• Flexibility: The ability to prioritize and recover the most critical data first is vital for ensuring business continuity.

• Cross-platform recovery: Ensure compatibility across different platforms and environments. Multi-workload coverage from a single provider provides additional value.

• Testing: Regularly test recovery processes to ensure reliability.

• Failover mechanisms: Include automatic failover options for critical systems.

6. Ability to protect endpoint devices

Importance: Endpoint devices are often the entry points for ransomware attacks. Protecting them is essential for overall security.

Considerations:

• Endpoint agents: Deploy lightweight agents on endpoints to monitor and protect against ransomware.

• Centralized management: Centralized dashboard for managing and monitoring endpoints.

• Data encryption: Ensure data on endpoints is encrypted.

• Backup frequency: Define how often endpoint data should be backed up.

7. Ability to protect virtual machines

Importance: Virtual machines (VMs) are integral to modern IT environments. Their protection is critical for maintaining business continuity.

Considerations:

• Hypervisor compatibility: Ensure support for major hypervisors (e.g., VMware, Hyper-V).

• Snapshot management: Use VM snapshots for efficient backup and recovery.

• Performance: Minimize performance impact during backup operations.

• Disaster recovery: Integrate with DR solutions for automated VM recovery.

8. End-to-end recovery services

Importance: Comprehensive recovery services ensure that all aspects of data and system restoration are covered.

Considerations:

• Service levels: Define SLAs for recovery time and recovery point objectives.

• Support: 24/7 support and clear escalation paths.

• Testing and validation: Regularly test recovery processes and validate data integrity.

• Documentation: Detailed documentation of recovery procedures and guidelines.

9. Protected/immutable data copies/backups

Importance: Immutable backups cannot be altered, deleted, or encrypted by ransomware, ensuring data safety.

Considerations:

• Immutability features: Implement write-once-read-many (WORM) technology.

• Retention policies: Define retention periods for immutable backups.

• Access controls: Restrict access to backup data to prevent tampering.

• Storage solutions: Use storage solutions that support immutability.

10. Continuous data protection/replication/journaling

Importance: Continuous data protection (CDP) and replication ensure minimal data loss and quick recovery.

Considerations:

• Replication methods: Choose between synchronous and asynchronous replication based on requirements.

• Data journaling: Implement journaling to track and store changes for quick rollback.

• Network bandwidth: Optimize replication processes to minimize network bandwidth usage.

• Recovery flexibility: Provide options for rolling back to specific points in time.

Conclusion

By addressing these key areas in your RFP, you’ll be better equipped to evaluate vendors and select a ransomware recovery solution that meets your organization’s specific needs. This comprehensive approach will help ensure the robustness and reliability of your data protection strategies. Ultimately, understanding your overall security structure will help you understand which tools you’ll need to use.

 

This blog article is part of a series of articles on ransomware resilience and the key role data protection plays in ensuring business continuity. Below are the three other related articles in the series for further reading.

To continue learning more about ransomware backup protection, watch our on-demand webinar.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

Keepit platform named winner at the 2024 SaaS Awards

Keepit named winner in the 2024 Cloud SaaS Awards program in “Best Use of SaaS in a Cloud Ecosystem” category.

COPENHAGEN, DENMARK. August 13, 2024 – Keepit, a global provider of a comprehensive cloud backup and recovery platform, announced today its success in the 2024 Cloud SaaS Awards program by being named a winner in the “Best Use of SaaS in a Cloud Ecosystem” category. Keepit was also a finalist in the “Best Security Innovation in a SaaS Product (SME)” and “Best Security Innovation in a SaaS Product (Enterprise)” category.

A long-established awards program spanning 56 categories, The SaaS Awards recognizes the leading innovations and applications of software-as-a-service solutions across a wide range of use cases and sectors. The program received entries from organizations worldwide, including North America, across Europe, and APAC.

 

“The Keepit platform is a must for companies looking to ensure cyber resiliency. We are honored to have been named as a winner at the 2024 SaaS Awards. This, alongside the slew of other recent accolades, underscores our cloud native roots and commitment to providing our customers with best-in-class data protection”, says Michele Hayes, CMO at Keepit.

 

CEO of The Cloud Awards, James Williams, said: “We’re thrilled to reveal the winners of the 2024 SaaS Awards after three intense rounds of judging. It’s been an outstanding edition of the awards this year, and the team and I would like to thank all those organizations that entered.

 

“Keepit has demonstrated an unwavering commitment to innovation and excellence and is a more than deserving winner of Best Use of SaaS in a Cloud Ecosystem. The caliber of the finalists this year was particularly high, which is a testament to this wonderful achievement.

 

“A huge congratulations to Keepit, and to all of 2024’s winners. We are extremely excited to see how they continue to drive the industry forwards in the coming years.”

Secure by design, the Keepit cloud is owned and run by Keepit. Customer data is kept in a separate, dedicated infrastructure, with the backed-up data stored fully isolated from the SaaS vendor’s cloud. With a user-friendly interface, robust data security, and the ability to adapt to your cloud environment, Keepit ensures your data is always accessible and protected.
Recognition for the Keepit platform

 

The Keepit platform has also been named “Best Cybersecurity Backup Service” by the Business Awards UK, 2024 Cybersecurity and Resilience Awards and “Best Security Solution for Data Management / Data Protection” by the Cloud Security Awards 2024. Keepit was recognized in four categories at the Global Infosec Awards 2024 (at RSA), including “Most Innovative Compliance”, “Publisher’s Choice Cyber Resilience”, “Best Product Data Recovery”, and “Hot Company Ransomware Recovery”.

 

 

About the Cloud Awards

The Cloud Awards is an international program which has been recognizing and honoring industry leaders, innovators and organizational transformation in cloud computing since 2011. The Cloud Awards comprises five awards programs, each uniquely celebrating success across cloud computing, software-as-a-service (SaaS), cloud security, artificial intelligence (AI), and financial technologies (FinTech).

Winners are selected by a judging panel of international industry experts. For more information about the Cloud Awards, please visit https://www.cloud-awards.com/.

About The Cloud Awards Program

The Cloud Awards identifies and celebrates the most innovative organizations, technologies, individuals and teams in the world of cloud computing. The program spans 36 categories, including ‘Best Cloud Infrastructure’ and ‘Best Cloud Automation Solution’.

 

About The SaaS Awards

The SaaS Awards focuses on recognizing excellence and innovation in software solutions. Categories range from Best Enterprise-Level SaaS to Best UX or UI Design in a SaaS Product.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

Welcome, Microsoft 365 Backup!

Microsoft has unique access to back up data – Keepit offers a unique guarantee that you can get to it without losing control of costs.

I had the good fortune to have the early part of my career coincide with a time of huge battles in the computing world. The competition between Apple, Microsoft, IBM, Lotus, Oracle, Sun, Netscape, and other titans was fascinating, and often entertaining, to watch. For every example of bare-knuckle (or flat-out anti-competitive) brawling, there are stories of humor and grace, like the fleet of buses adorned with Lotus logos that Lotus hired when Microsoft brought the Microsoft Exchange Conference to their hometown of Boston.

It’s in that spirit that I write this blog post congratulating Microsoft on the general availability of Microsoft 365 Backup and the underlying storage layer that powers it, Microsoft 365 Backup Storage (MBS).

We know how important business continuity is for the enterprise. Since Keepit’s first cloud backup offering in 2016, we’ve been helping our customers protect their SaaS application data. During that time, the backup market has matured, and so have customers. An increasing number of enterprises understand how critical it is to have data protection for their most important SaaS applications.

Here at Keepit, we’re excited to see Microsoft reach this important milestone. Let me tell you why. 

The discussion is shifting

We are obviously fierce advocates for enterprise data management and protection. It is literally the single thing that our entire platform was built to deliver. We have had some frank and open discussions with our more than 10,000 customers around the world to help them understand the value of protecting their SaaS application and control plane data.

Sometimes reaching this understanding has been an uphill battle, though, because Microsoft has delivered some native data protection capabilities such as the mechanism of recycle bin recovery options — which is not backup — but has been considered good enough to satisfy many customers over the years. Lately, the discussion is changing with the increased recognition that you, the customer, are responsible for ensuring the security and availability of your own SaaS control plane and application data in a world that is increasingly insecure. Your SaaS vendor can do a lot to help you, but ultimately, it’s your organization’s responsibility. You ignore that at your peril. 

Going legit

Having Microsoft formally enter the backup market themselves is important for another reason. Microsoft’s own estimates say that more than 90% of their enterprise customers don’t have backup in place. From my own discussions with enterprise customers around the world, a surprising number of them do not have complete disaster recovery capability for their most important cloud applications. Some of this gap is because organizations historically have not understood their part in the shared responsibility model. But some of it comes from a mistaken belief that “if Microsoft doesn’t make a product for it, it isn’t important.” We’ve seen this same belief play out in other contexts like antivirus, compliance, and email hygiene. As soon as Microsoft commits resources and talent to delivering a new capability, enterprises perk up and start asking great questions about whether they need the shiny new thing.

The Microsoft platform advantage

Microsoft has invested decades of engineering experience and knowledge into the Microsoft 365, Entra ID, Power Platform, and Dynamics 365 platforms. Because they have complete control over and visibility into every aspect of those platforms, their first-party backup solution delivers some great technical capabilities, including high restore speeds at large scale and great data fidelity. The combination of database level backup for SharePoint and OneDrive and copy-on-write backup for Exchange Online gives customers a powerful new tool for large-scale recovery. No other vendor can provide the same direct capabilities because none of us are “inside the blue curtain.” We just do not have the same access to the platform that Microsoft does.

Because Microsoft understands that different enterprises around the world have different requirements, they have made the critical, and welcome, decision to offer their backup storage system as a platform that third parties can use.

Keepit is proud to be partnering with Microsoft to build support for Microsoft 365 Backup Storage into our native platform for an integrated backup and recovery solution that offers great customer value:  While Microsoft has unique access to their platform, what we contribute is unique separation of environments and guaranteed access to data: With data stored in the independent Keepit cloud, customers retain access even if they lose access to Microsoft.

Making “better together” a reality

The Keepit platform today offers fast, immutable, independent, always-online storage that protects Microsoft 365, Entra ID, Google Workspace, Salesforce, and more—built on a platform that delivers award-winning ease of use and a transparent and easily understood and predictable pricing model. We are adding support for Microsoft 365 Backup Storage so that you can flexibly choose to add rapid-restore protection for your most critical Microsoft 365 assets.

This combination gives you the best of both worlds: Keepit’s reliable, broad, and inexpensive protection for every asset, plus fast, full-scale restores from Microsoft, all managed through a single console. Keepit protects the full range of critical objects, including conditional access policies, application registrations, users, mailboxes, SharePoint sites, Teams channels, Microsoft 365 Groups, CRM data, and more; Microsoft 365 Backup Storage adds rapid-restore protection for the object types they protect.

Future best practice?

For customers, the perfect backup setup for Microsoft 365 will be this: A full, immutable, logically and physically separate backup of all of Microsoft 365 and Entra ID in Keepit, with extra restore capabilities of critical data sets in Microsoft 365 Backup Storage. In this setup, customers can keep costs under control, and have guaranteed access to all data, in the event of losing access to Microsoft tenants or administrator credentials.

Where next?

Our integration with Microsoft 365 Backup Storage is currently in private preview  and we are rolling this feature out to eligible customers soon. Joining the preview is the best way to engage with our product team and give us feedback during the adoption cycle. This initial integration is just the start—as part of our overall initiative to deliver more intelligent guided data protection, we  are able to leverage the combined strengths of Microsoft and Keepit’s respective platforms. That puts Keepit in a unique position to leverage key intelligence from customer tenants to both recommend backup configuration and to intelligently provide access and provide “Guided Recovery” when needed.

Some examples of what  Keepit’s integrated solution will deliver over time: 

  • Keepit will suggest which data items might benefit from rapid restore protection, using data about activity and cost to intelligently balance recovery time, coverage, and cost. 
  • When a user requests a restore, Keepit will know exactly where to retrieve the data from to get it back both completely and quickly.  
  • Seamless integrated restore across both storage platforms, allowing one-click restore of Entra ID alongside Microsoft 365 data 
  • Automatic migration of data between platforms to provide cost-effective long-term data preservation giving you the right protection for the different types of data you have at the right cost. 
  • Integrated auditing and management to help define, monitor, and enforce backup and compliance policies

We have lots more planned that we’ll be sharing as planning and development advance.  

If you’re interested in joining the preview program, or learning more about Keepit’s data protection platform, visit https://www.keepit.com.  

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

CISOs and CIOs confront growing data protection challenges in the era of AI and cloud

Foundry survey and in-depth interviews reveal critical gaps in disaster recovery strategies and highlight the pressing need for enhanced data security measures.

COPENHAGEN, DENMARK. July 23, 2024 – Keepit, a global provider of a comprehensive cloud backup and recovery platform, today released a survey conducted by Foundry, as well as a study based on in-depth interviews conducted by Keepit. Both reveal critical gaps in disaster recovery strategies and highlight the pressing need for enhanced data security measures.

In an evolving technological landscape, enterprise IT leaders are grappling with unprecedented challenges in data protection and governance, driven by the rapid adoption of cloud applications and generative AI.

The CISOs and CIOs interviewed by Keepit for the study: “The great balancing act: Cybersecurity leaders tackle rising pressures” spoke to the necessity of rising to the challenge by adopting a mindset of continuous improvement. They are building collaborative best practices, partnering to bring in needed expertise, and investing in data-centric solutions optimized for security and simplicity.

Data protection struggles amid cloud and AI expansion

Enterprise disaster recovery strategies, traditionally designed for on-premises IT infrastructure, are lagging behind the surge in cloud application usage and the integration of AI technologies. Foundry’s survey: “Can data protection keep pace with the shifting landscape?” underscores this trend. The respondents of the survey represent IT decision-makers from companies with over 1,000 global employees. While 70% of respondents report that their financial applications are covered by data protection strategies, a significant portion of other key systems and custom applications remain vulnerable.

Survey highlights

• Financial systems: 70% are covered by data protection strategies.

• E-commerce and HR Management Systems: 50% are covered.

• CRM and ERP systems: 48% and 42% respectively.

• Critical transaction-based systems, custom applications, and collaboration and productivity tools: Are lagging behind with only between a third and a quarter of systems covered.

“Anything related to finance is important, most people will agree. And it’s an obvious place to start when you map your critical systems and data. The survey shows that financial systems are by far the most incorporated in data protection strategies, and when you look at verticals, financial institutions are also a little more mature than others,” says Kim Larsen, CISO at Keepit, an industry professional with a background in advising public and private sector organizations in cyber security and cyber resilience.

Strategic gaps and vulnerabilities

The survey reveals that only half of the organizations have incorporated cloud-stored SaaS data into their disaster recovery plans. Another 40% plan to address this gap soon. A decision-maker participating in a recent Keepit CISO roundtable remarked, “We solved many of these challenges 10 to 15 years ago, but with the move to cloud, it’s like we’re starting from scratch again.”

The current state of data protection is also seen as a significant barrier to expanding the use of generative AI technologies.

Strategic gaps:

• Critical SaaS data applications: 50% of respondents have included cloud-stored data for critical SaaS applications in their disaster recovery plans, and 40% plan to do so.

• AI data protection: Nearly all organizations prioritize AI data protection, with 52% already implementing tools for chatbots and AI platforms and 43% considering them.

“Good data protection is essentially ‘data classification plus good recovery capabilities’: If you understand your data, and can recover uncorrupted versions of it fast, you have a solid foundation to ensure business continuity, compliance and recovery. But this is easier said than done: The complexity of implementing new initiatives, such as governance over data used by large language models (LLMs), and the need to balance conflicting IT demands, pose additional challenges for any industry,” adds Kim Larsen, CISO at Keepit.

Compliance and future-proofing

Data protection is a top concern for 73% of survey respondents heading into 2024, with data governance (53%) and enterprise backup and recovery (45%) also ranking high. Regulatory scrutiny is increasing globally, with mandates from agencies like the SEC in the US and the upcoming Digital Operational Resiliency Act (DORA) in the EU.

Compliance challenges:

• Regulatory mandates: New cybersecurity resilience requirements.

• Cybersecurity risks: Continued threats, notably ransomware.

“Cyber strategy must be perfectly aligned with the business to effectively support it. The more global an organization becomes, the more difficult this is – to align access, and comply with regulations. This is backed up in our study, where CISOs emphasized the need for a unified risk management strategy that aligns with regional regulatory requirements,” said Kim Larsen.

Organizational maturity and risk management

Keepit’s interviews with over 30 CISOs and CIOs reveal the importance of organizational maturity in handling data security. The variability in CISOs’ backgrounds and responsibilities was cited as a reason for the slow implementation of data-focused innovations.

Key findings:

• Cloud flexibility: 80% of organizations adopt a “cloud smart” approach, introducing new security and compliance challenges.

• Regulatory and expertise challenges: The rise of GenAI and the need for specialized knowledge in AI and cybersecurity.

“One thing stands out: Organizations have very different levels of maturity. A lot of the governance activities are so obvious, you would think everyone is doing them. But they aren’t. Classic difficulties include managing multiple security vendors, leading to gaps in protection. Another is circumstances – one CISO told us how he had experienced five major cyber events in the previous year, prompting a complete overhaul of their cyber response plan,” says Kim Larsen, CISO at Keepit.

Strategies for success

CISOs and CIOs are adopting continuous improvement mindsets, building collaborative best practices, and investing in data-centric solutions. Establishing effective data governance frameworks and engaging the board of directors are seen as crucial steps forward.

Strategic recommendations:

• Align with business objectives: Frame cybersecurity in the context of business goals.

• Translate technical concepts: Communicate in terms stakeholders understand.

• Demonstrate ROI: Highlight cost savings, risk reductions, and business benefits.

• Board engagement: Seek feedback and support from the board for cybersecurity initiatives.

“The conclusion is that data protection remains a cornerstone of organizational resilience in the face of growing technological advancements. As CISOs and CIOs navigate these challenges, their ability to enable and protect data-driven innovation will define their success. Robust data security and backup strategies are essential for balancing innovation and protection, ensuring that organizations can thrive in the digital age. Effective communication of cyber risks to stakeholders and demonstrating the ROI of cybersecurity initiatives are critical,” ends Kim Larsen.

### ENDS ###

About Foundry, and IDG, Inc. Company:

Foundry has played a key role in every major milestone, announcement, and development in modern technology since 1964. We engage and activate the world’s most influential tech buyers and early adopters via the award-winning journalism and trusted media brands they’ve turned to for decades. Our integrated ecosystem of owned and operated editorial sites, awards, events, and tech communities is engineered to enable global audience activation through innovative marketing campaigns. Backed by robust audience insights and data from across our network, Foundry sets the standard for delivering business results to help companies grow.

With 38 offices in markets around the globe, Foundry is a wholly owned subsidiary of International Data Group, Inc. (IDG), the world’s leading tech media, data, research and marketing services company.

To learn more about Foundry, visit foundryco.com.

About CSO:

CSO serves enterprise security decision-makers and users with the critical information they need to stay ahead of evolving threats and defend against criminal cyberattacks. With incisive content that addresses all security disciplines, from risk management to network defense to fraud and data loss prevention, CSO offers unparalleled depth and insight to support key decisions and investments for IT security professionals. www.csoonline.com

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.