we copy our backups to an external drive, they're unencrypted, if an attacker steals this drive is the data exposed
external backup drives should be kept encrypted (BitLocker FileVault). even if the disk is lost the data won't be exposed.
- Job title
- Data entry clerk
- Sector
- Sports and fitness
- Organization type
- early-stage startup
- Joined
- Feb 2023
- Message
- 10
I felt relieved reading this answer, so it's not just me. The biggest time-waster for us was not knowing who had the final say.
I'm also curious if anyone does it differently.
- Job title
- Software team lead
- Sector
- Packaging
- Organization type
- 8-person team
- Joined
- Dec 2024
- Message
- 348
I completely agree. Trying to do this alone is the most expensive way.
When making a decision, first look at what data you have on hand. Proven by experience.
- Job title
- Clinic manager
- Sector
- Cosmetics
- Organization type
- 120-person company
- Joined
- Aug 2023
- Message
- 335
Let me summarize the topic, since several different answers were given. If you scold false alarms, nobody will report again.
If permission and scope aren't in writing, don't start that test. If you have questions, write them; I'll answer as best I can.
I disagree with you on this point. Processes without records never improve because you don't know what to fix.
If I were you I'd go this route.
I completely agree. Having backups accessible on the same network and with the same identity makes them part of the target.
If I were you I'd go this route.
- Job title
- Network Administrator
- Sector
- Livestock
- Organization type
- medium-sized business
- Joined
- Aug 2024
- Message
- 136
Doki · Interface design · 2024
Quick summary for newcomers: If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.
When we decide without measuring we always end up in the same place. That's all sorry if I went on too long.
- Job title
- Human Resources Manager
- Sector
- Logistics
- Organization type
- workshop
- Joined
- Nov 2022
- Message
- 49
Let me summarize the topic since several different answers were given. Most time waste accumulates in tasks waiting for approval.
If I were you, I'd go this route.
I partly agree, partly disagree. Trying to do this alone is the most expensive way.
Everything goes well for the first three months; problems arise in the fourth. If I were you, I'd go this route.
- Job title
- Customer Relations Manager
- Sector
- Law
- Organization type
- boutique agency
- Joined
- Oct 2024
- Message
- 380
I agree, and I'd like to emphasize that. Having backups accessible on the same network and with the same identity makes them part of the target.
That's all, sorry if I went on too long.
I agree with this. Everyone rushing into backup encryption gets stuck at the same point.
If you have questions, write them; I'll answer as best I can.
- Job title
- QA Tester
- Sector
- Law
- Organization type
- early-stage startup
- Joined
- Feb 2022
- Message
- 11