Transcript
medical students, really just to kind of ensure that they have the best terms and conditions and are able to fulfill their roles on a day-to-day basis. We have a vast influence across the whole medical arena within the UK. Pratt & Bransonware is a big one and it's various guises and forms, but also just to ensure that we have immutable backups. I think backups has been a big, in terms of our resilience, it's been a big project for us to ensure that not only are we backing up our most important data, but actually that data is kept in a secure air-gapped environment so that if we were impacted, then okay, at least we have that to fall back on. Everybody wants to build services in the cloud. Well, are you architecting correctly? Are your workloads secure? Are you looking after them? And we know that a lot of the attacks can come about because of misconfigurations of workloads in the cloud. But then once you migrate or you create workloads in the cloud, what have you got left? What's your technology depth? Are you looking after, are you patching your systems? For example, are you used to have good endpoint detection and response? Are you monitoring? And then there's a culture piece as well. So organizations, they're not very good at letting go. So you build a new solution over here, you migrate your data over here, but for some reason, they need access to this data over here. It's really about ensuring that what we build into the cloud and where our data sits, that we're building appropriately, that we've got a good architecture in there, that we've got a baseline set of standards as well. So what we do build is data is encrypted, whether it's at rest or it's in transit. It's about having a landing zone, if you will, with those safeguards to ensure that when we do create workloads in the cloud, that actually it's safe to do so and that there's a minimum set of standards. So as I said, we created a virtual machine. That virtual machine has, from a functional perspective, it has the right RAM, etc. But what about those access controls? Is it encrypted? Is it protected by an EDR? Is the telemetry being siphoned off somewhere for monitoring, for example? Is there a web application firewall that's looking at all the traffic that's hitting that environment as well? So if you've got a bunch of services, are they behind a web application firewall, not just a security group? So what are those protections in place? I think the first thing for us was about our data. Are we backing up our data? And we were in a lot of areas. I don't think we were completely backing up our data or in the way that we should. So we engaged with Commvault, who've been absolutely fantastic at helping us along that journey. So we're now in a position, I can say actually just yesterday, that all of our data is not just backed up, but immutably backed up. I think what gives me a bit of comfort as well is the fact that we can take advantage of Commvault's clean room environment, that if we were impacted by a major cyber attack, whether it's ransomware or what have you, I am able to utilise the Commvault solution of clean room to restore data cleanly and back to an operational status.