Transcript
I work for the Coventry, as we call it, colloquially, and we're sort of the second largest building society in the UK. Unlike a bank, it's mutual in that it's owned by its members, so it doesn't need to make a profit. The highlight of ransomware in the media and actually happening, it's actually given me the opportunity to show what Commvault could do as part of our overall cyber-resilience strategy. So the recent things that they've brought out, like ThreatScan, when they've acquired Plumio, so they can do Cloud Rewind and AppRenix, so they can do the S3 revisions. They're solid, useful tools that I can present to the various teams, to my cloud team, to my security team, the forest level recovery, to my Windows team. So they're real tools I can present and say, look, this enterprise level backup system that we've got is now more than just backups. If you back something up every 15 minutes, which we sometimes do for some of our databases, you notice a fault with that database often before the team that supports it does, because you notice your backups failing. So it's almost, I've already got a foothold in there, and I'm just trying to extend the visibility of what we could do. Ideally, you don't want to be recovering. You want to be spotting it before it's gone anywhere and doing something about it. And I found particularly interesting, like the Commvault cleanroom recovery tools, where if we think something's been ransomwared, I can restore it into an isolated environment and we can have a look at it. Because at the moment, I do audited restore testing every month, but I'm only, I'm restoring a production workload, but I'm restoring it into a dev area. So it doesn't, I can prove that I can restore some data, but I can't necessarily prove that I'm restoring the service. So this cleanroom would allow me to spin up all the service components in an isolated environment, so the EC2s that I needed, the databases, files, and prove that that service was restorable. So I think that's going to be a huge, a huge change in the way we look at restore testing. Because at the moment I've restored data types, so yes, I can restore our database, but I don't restore services because I've nowhere to restore them to. I can sound like a Commvault fanboy, but I actually do love it. I love it for its breadth of capability and what it can back up and how resilient it is to failures at the client side. So like a client can go down, a database can go down, the backup will go pending, and when the database comes back up, it'll carry on where it left off. And that actually, that saves me a lot of problems. And internally it's very resilient, so I very rarely get failures off the infrastructure itself. It's got an amazing amount of inbuilt resilience, and you can lose nodes and disks and all that exciting stuff, and it'll carry on working.