Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zero Day Resilience, CDP & Firmware Failure: Veeam Community Recap

Veeam
10/02/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Today we are recording 277. And since Rick is traveling to Latin America for VIMON tours, we're going to talk more about VIMON tours in Latin America later on. I decided to have some special guests. So I have Shane and Carolina. Thank you for accepting my invite. How are you doing today, Shane? I haven't seen you in a while. How have you been? That's probably a bad question. I'm doing fairly well, but I've just been extremely, extremely busy. Work is really crazy this time of year, working at a school district. Plus I have a lot of venues coming up. One of them we'll be talking about here later on in the show. And then a webinar coming up as well on the VMC plus study hall page. So I just have a lot going on. Work is crazy. And then a lot of community things going on as well. But thanks for having me. I really, really enjoyed being here. It's always great to have you, Shane. And, I mean, busy is not always bad, right? And community stuff are always a good thing. Yeah. I didn't mean to sound like it was bad. It wasn't bad. It was just really, really, really busy. Yeah. I mean, there are times and times. But, yeah, thank you for taking the time to be with us today. And I also have Carolina with us. Actually, I spent three weeks with Carolina in Latin America. She's going to talk a little bit more about it later on. But how are you, Caro, today? All good. We are back, yeah. Maddy is also here, even after spending so much time with me. So I assume that it was, well, kind of still fighting with adjusting to this time zone. But, yeah, it's all good. Things are slowly coming back to routine, you know? Thanks for your invitation. You are welcome and great to have you. It was amazing to spend three weeks together and meet our community. But, yeah, let's talk about it later on. Because, as always, we really got ready a good playlist with great content from our community members. And at the end, we're going to share as well as promised some pics and some stories from our journey in Latin America. But are you guys ready to jump in in the content? Oh, yeah. Let's go. Let's start. Okay. So we have the first article. I'm going to share the screen now. Let me see if I can find the first one. This was the first one from Stephen, actually. This is the first time we are mentioning Stephen in the show. So welcome to the recap. You know, he talks about a zero-day resilience workshop in El Segundo, California, that he helped organize, where IT and security leaders went through a simulated cyber attack, starting with the first signs of compromise, then dealing with the disruption, and finally getting to recovery. You know what this reminded me of, Carolina? No. VUG Ecuador. VUG Ecuador. They actually had a lab in there. They had, like, five teams, and they also had a similar exercise. So when I went through this article, it just kind of reminded me of what we kind of did in VUG Ecuador last week. So this is pretty great. But, you know, this is nothing really new. Like, the topic is nothing really new. I'm very grateful to Stephen that put it together, and he shared his experience with us. We talk a lot about it at the Hub, you know, about resilience and about the fact that resilience isn't just about having a disaster recovery plan sitting just somewhere on your shelf. You actually need to practice how you're going to respond and how you're going to make some decisions under pressure, and whether you can recover safely when a real attack is going to happen, because it's not about if, it's about when, as we know, and we always say it in the backup world, right? But, Shane, I would like to actually invite you to this conversation and tell me your opinion about this article, and then I would also like to ask you a few questions. But let's start with what's your opinion about it? What do you think? Yeah. So, excuse me. This was somewhat similar, at least in the beginning of his article. I don't know if you could scroll up a little bit. He shared some data points similar to Jason Buffington from Veeam that has spoken to us in the Veeam 100 in the past, kind of about the same thing. It was more data points that Jason shared. This was more of hands-on type thing. I really, really like this. I wasn't aware that Veeam provided workshops like this. What really struck me most was the tabletop discussions, and that's really, really awesome because it gives attendees the opportunity to kind of think about their own processes within their organization and to kind of, well, give an opportunity for them to see where their gaps are and where they lag in their recovery or remediation or forensics steps whenever they experience some kind of an attack or malicious attempt. But at the end of the day, I like at the very bottom where he spoke, at the end of the day, every organization is different, and there's no one-size-fits-all approach to how you address these concerns. I actually want to throw back to you real quick, Maddy, before we continue discussion here. I wasn't aware that Veeam had workshops like this. How does one find out more about workshops like this in our local area? Do we have to reach out to our Veeam SE then? I was not aware of this either. I think it's probably, I don't think it's something that we do it at the global level, but I would assume there are maybe some initiatives that some systems engineers and like the sales engineers, maybe they put together for their customers, for some of the partners. So I would think maybe just reach out to Stephen and ask him. Maybe he can give more information on that. Maybe Stephen is going to hear us speaking about his article and talking about his experience, and he's going to share some information in the comments with us. But if he's not doing so, I would say, Shane, just reach out to Stephen and ask him. Because I am not aware of these workshops like on a global level. I do know that sometimes they happen in different regions, but just because it's an individual kind of initiative. Gotcha. Okay. Yeah, will do. Yeah. But yeah, that's actually great. And as I said, thank you, Stephen, for sharing. But I wanted to ask you a few questions as well, Shane. Sure. This is a really interesting topic. And how do you know that the backup you're restoring from is actually safe? That's a good question. For those of us that use Veeam, this should be easy to answer. There's two means that you can do, or rather two and a half or three. Sure Backup to verify recovery. But within Sure Backup, you have the opportunity to do AV scans against your backups to make sure nothing is infiltrated within your backups. There's also another feature called Scan Backup where you don't have to utilize a Sure Backup job to perform a scan, and you can just basically scan your backup to your restore points using generally, you can do it some kind of Linux-based AV tool that for Windows, the default is Defender. But obviously, Veeam has Threat Hunter, and it's recommended to use that as it's faster to do. So one of those two tools Veeam offers, so you can basically know that all your restore points are the ones that you choose to scan are not infected with any kind of malicious actor. Yeah, no, that's great advice. Now that you're mentioning these two, I remember they were also kind of presented in one of the conversations that we had the Veeam user group in Panama. So it's great to kind of confirm it on your side as well. But is there something that organizations should be looking at before they put that data backup into production? Well, just that. Not only can you do scans against any type of AV issue, you can do YARV scans, which really is geared towards the malicious intent, onion links, ransomware, that kind of thing. So the scan backup feature was really, really a great implementation that Veeam came up with. I believe that came out in V12. It's just I don't like to use the phrase. It just gets overused, but it really was a game changer from a security standpoint just to be able to do it because it's time-saver. So you don't have to take up resources and implement share backup. It's a great feature in and of itself. But when push comes to shove and you're basically going through these issues on a potential attack, you want to be able to tackle them and do your forensics and remediation as quickly as possible. Time is of the essence, right? So scan backup allows that to happen. Yeah. No, that's really good points. Thank you for that, Shane. I appreciate it. And thank you once again, Stephen, for putting this article together. Really looking forward to seeing more from you. And now I'm going to move forward with our second article. This one comes from Chris. And, okay, let me just replace in here. So this one comes from Chris, actually. Chris is doing a series in here. We already mentioned, I think, two recaps ago, we already mentioned one of the articles he wrote about Universal CDP. And now Chris looks at Universal CDP in Veeam 13.1, and even more important than that, where it actually fits compared to traditional replication. So the big advantage with Universal CDP is near zero RPO with continuous write capture, journal-based recovery. But then also Chris looks at some of the current limitations around plan failover and failback. So I think this article, it's around understanding which workloads justify that extra complexity. What do you think about this topic, Shane? Well, I wasn't aware, first of all, or I'd forgotten. I don't use CDP at all in the SMB. We just don't have a need for that. But I had forgotten that CDP was VMware-specific. It was limited to just that architecture. But one thing I like, if you scroll down there a little bit, Maddy, right there, that table, I really love that. It kind of summarizes everything that he wrote about, hey, when should I implement this, when should I not? When's standard replication good enough? And when can I maybe go to Universal CDP? I like the table format. It kind of gives a quick overview of the whole article in a really quick snapshot. Yeah, it's really good. You kind of visualize it very well, when and how and in what scenarios you should actually use it. So yeah, this is a pretty good one as well. You can see how to configure it in vim13.1. He's covering quite a lot. I was actually surprised about the limitations there. That would really almost instantly prevent me from even going to it. That's not being able to fail back to the original location and not having a plan failover so you can even test with software upgrades or any kind of maintenance. Those are two really key features. functions of regular BVR replication. So not having that would kind of prevent me from using CVP from the get-go until those two functions are enabled with Universal. Okay, that's interesting. And now, because you mentioned that, I'm going to ask you what's your thought? You said you are not using it, but do you think most organizations need CVP or traditional replication is still good enough for the majority? What do you think? What are your thoughts? I think Chris summarizes it pretty accurately in his article. I don't hear or see too many posts or see articles about organizations using CVP. Myself, I come from an SMB background and that's my whole IT career and just nobody has a need for that really. But I do see the benefit with organizations in the financial industries or time is of the essence and data, low, low, low, low RPOs is really crucial. So I wouldn't say most companies have a need for CVP, but there are some niche industry verticals where I could see this being a benefit to them. Yeah, fair enough. And I agree on that. Do you think it would be more like enterprise level that would be the target or just like, as you said, I agree with you that some vertical industries like health care, financial, yeah. Any company, even an SMB, to be honest, but any company that has the need to have extremely low RPOs, it may not even be their main system, but if they have the backend database where they need, they want to recover in seconds or minutes, CVP is the way to go because standard replication does provide minutes recovery, but it's kind of a little bit longer minutes. I can't think of the shortest minutes to be able to recover offhand with regular replication, but CVP is generally the way to go for low RPOs. And it doesn't matter the business. It's just, I mentioned health care and finance for, I think those are obvious ones where data loss is critical. Yeah. So you kind of answer my next question. What is the biggest benefit of Universal CDP? Extremely low RPO. Yeah, exactly. And I mean, Chris definitely mentioned that and he's kind of stressing out the importance of that kind of thing with Universal CDP in 13.1. So yeah, fantastic. Right up in here, Chris, thank you for sharing and looking forward to see what you're going to share with us in this series, because I don't know, I feel like you covered, it's covered so much, but let's see, I'm sure you're going to come up with more. Thank you. Once again, great to mention you in the recap as always. Ready to move to the third article of the show. And that comes from Michael Melter. If I can actually find it in here, there you go. Thank you, Michael, for sharing this interesting article with us. A great example of how a hardware problem doesn't always look like a hardware failure. So that was very interesting to see. A long article in here. And in his case, the systems were kind of still running and everything looked healthy, but performance had completely collapsed. So I can't believe that it was almost two weeks of troubleshooting. And then the root cause turned out to be a firmware issue in aging micron SSDs that had crossed 65.535 power on hours. This is insane. What do you think about that? Well, I learned something new here. All drives have a mean to live, an MTT that you need to pay attention to. I don't know that any of us kind of, I don't want to say pay attention to it too in detail. Hardware refresh happens like happened here with on his customers. So I actually learned something and what could happen. And he details, provides details on his troubleshooting and what the core issue was. Thankfully, at least in my environments, before I even run into that issue, I do hardware refresh. And those systems that I have that are a bit older, I use for testing. I don't use hard drives or SSDs in my servers anyway. I use backend storage arrays to present storage to those systems. And then for the OS, I just use small boss cards. So I don't generally run that, although, you know, hard drives and backend arrays and boss cards, they have a, they have a time span as well. So you kind of just, you're, you're playing with fire there if you're running them too long. But there's just as a classic issue of having to be aware of when your hardware refresh cycle is. And I actually think this is pretty good to come to light. I'm glad he shared this because with, I don't, how's a nice way to say it? The issue with VMware, let's just say in Broadcom, I think people are going to, are running, and I am one of those as well. People are going to be running their systems longer than what they normally would as they decide what they're going to do as far as transitioning from VMware or to retain it, which more than likely requires a refresh. So it supports newer versions of VMware. So this, this may come into play with more organizations. They may see this issue. So it's good that Michael posted this on the community. Yeah, totally. But I don't think I've ever, because there are a lot of our community members that are sharing, you know, troubleshooting, but I don't think I've ever read about, you know, almost two weeks troubleshooting. Well, it's almost embarrassing, actually. There's, there's, there's something, I don't know, two weeks, but I've several days in troubleshooting some things for sure. Yeah. Okay. But what, what do you think, you know, why was so difficult, you know, to diagnose it? Why did it take so long? What, why do you think? Well, he says it in his article here, and I think you mentioned it earlier at the beginning, because most things are running. So where do you start? The only thing you can start with is performance or what can cause degradation of performance. I mean, battery backup, storage controller in the, in the system, drives, network throughput. I mean, those, all those things you're, and you're talking about each layer of the stack, talking about hardware. So the physical, you're talking about network side, you're talking about storage. So it's not narrowed down at all. I mean, you're looking at the whole range, the whole gamut there. And it's, so that's where the two weeks comes into play. And knowing Michael, a little bit like I do, he's really detail oriented. So them taking two weeks, it just means they were looking at everything. So it's no surprise. When you put it like that, it makes sense. You know, when you just, you know, kind of said storage and you know, everything that you mentioned, you know, it's just like, yeah, everything would just take at least a day, you know, to just kind of troubleshoot. So yeah, all together, it makes sense that it took almost two weeks. But yeah, thank you, Michael, for sharing. I think this is a, this is a fantastic write up. And I think the troubleshooting articles are really, really useful. I don't know what you think, Shane, but I find it useful. And I think it helps the community. Because when you are in a situation like that, you kind of, you know, jump to the community hub or Reddit or wherever, you know, just look for the same situation, find it, you know, you are like, you have to kind of start it from the scratch, like Michael in this case. So I think it's great that, you know, our community members are taking the time to put it all together and share it and, you know, just educate others from their experience. And I think at the end of his article, he mentions about, you know, not the whole environment was on the same hardware, like, the production was different from the backup, let's just say it, in other words, it ran different hardware and different system types. I think that's important that, that you have some separation there, you choose certain hardware for production, and then you choose another type of hardware for say, backups. For this very reason, you run into an issue, not everything is down. You know, you have you have some separation there, you're not siloed into a certain vendor, certain piece of hardware, certain system. And that way, you can troubleshoot different areas instead of looking at it again. I mean, you're looking at he had to look at everything, but at least it was just narrowed down to micron, right? And those not his whatever systems, his customers reason for his backup. And that's good, right? You want to have different systems to be able to hopefully be able to recover. Yeah, absolutely. I think this is a great point that you just made. And you know, he made it as well in he mentioned it in the article. But yeah, thank you for, you know, just stressing that out. Because I don't know, maybe other some organization might not take that into account. And it's an important point. But yeah, all good stuff. Amazing articles, we are done with the main article section now. And we are going to move to Vanguard blog spotlight. And, of course, I'm choosing once again, I'm Ben Harmer, because I do like, you know, his style and how he writes. And this one is actually a pretty good one. I'm sharing in a second, the article, I have it here. Um, yeah, this is a long one, is very much his style with a lot of green screens in here. And he's talking about migrating to Proxmox with vim 13.1. And I think the stress in here is, his focus is on instant VM recovery. And what I found interesting is how this can make migrations to Proxmox much easier, because you can actually take an existing VMware backup and recover the VM directly into into Proxmox. So this is a very interesting one, he gives a lot of in here. But I want to actually ask you, Shane, do you think this makes moving from VMware to Proxmox a lot easier? I really enjoyed this article. I'm glad you chose this one. Because I'm looking at Proxmox currently have been for a little while, it's been tough and difficult with my work being so busy. But I'm also looking at the XCPNG solution. But I really enjoyed his article, because I know some in the in the beam 100 community specifically, have had questions on this specifically, what he discusses here in his article about the vert IO driver that's needed for Proxmox VMs to run well, for VMs to be able to see certain device hardware devices in the VM, like the storage using the SCSI bus adapter and whatnot. So it was really good to see and have him discuss some of the say issues, but still some of the caveats and being able to get a VMware VM working and running in Proxmox. Mm hmm. Yeah, good points in there. Just wanted to ask you as well, you know, like, if a customer is thinking about moving, because you are in this situation, right now, right? VMware to Proxmox, or maybe any other hypervisor? What would you tell them to consider first? Support, not just enterprise-type support, but supportability. Support. Not just not just enterprise type support. What goals? A company should make a list of goals and what they're looking to achieve and what they want from their virtualization solution. Let me give you a handful of examples. First of all, hardware support. Now, generally, some of these newer systems that Veeam is now supporting, like Proxmox and XCPNG, they support various pieces of hardware, some older hardware as well. But then, like this issue at the end that you're scrolling through, a certain storage type of what's called QCOW2, a format of disk. So that needs to have supportability. In my environment, I don't have a need for some of the advanced features of VMware, like I don't use distributed switches because I script deploying my hosts. So I just use standard switches. It's fine. But live migration or DRS, as it's called in VMware, I do want that to low balance my VMs. I do want high availability. And something I use with a VDI setup I have using Microsoft RDS is GPU passthrough to use for video adapter type graphic applications like AutoCAD and Autodesk Revit and some of those things for some student labs. So those are a handful of examples like companies should come up with needs that they have in their virtualization decisions as if they want to choose to continue with VMware or transition away, they need to come up with a list of needs that they have that their hypervisor solution must meet before they move. And then seeing articles like this, it's the little things like just a simple driver can prevent VMs from working. And then how do you transition? To this new solution? Well, Veeam provides instant recovery. That's certainly one way. I know XCPNG has a built-in migration tool and you can do several VMs at a time to migrate VMs from VMware. Let's just say into XCPNG. So all those things need to be consideration and of course downtime, you know, when you know, are you allowed to have some downtime for your systems? Does it have to be all done overnight or on the weekend? Can some lesser critical ones be down for a certain amount of time? And certainly test, test migrations and like Ben's doing here. He has a lab set up to kind of see what it's like. No, I love your explanation. I think it's super valid that it's not a general available, you know, choice and you should look into your environment and your needs and then choose because luckily, I think Veeam offers an integration with a lot of hypervisors and good solutions out there in the market. I know you wrote about a few of those, if I remember. Yeah, I did. I did a couple few posts on XCP. Yeah, yeah. Maybe you wrote about Hyper-V as well or wasn't you? Maybe it was somebody else. I thought you may have been one of the Ben's over there. Might be one of the Ben's but yeah, I think there is so much information anyway, you wrote about XCP, but there are many that wrote about different, you know, now we have Proxmox, other wrote about Hyper-V. We have many more coming soon on the roadmap as far as I was able to see. I think now we have Suncor and few others. So also like some hypervisors that are more like in APJ used that you know in Americas and EMEA. So there are so many options. I think people should definitely take your advice and look into what is best for their environment and then make the decision on it and then see how they, you know, can apply it and look into the small things as you said as well as you know, Ben goes over so many other important details that could matter for what you are trying to achieve. So yeah, fantastic right up in here Ben. Thank you for the comments Shane and I'm actually, do you have anything else to add to it or should we just transition to special department news? Yeah, special department. Let's keep it moving. Okay, now I'm going to invite Karolina because she was pretty quiet in there. It's been a while, you know, not that someone for me. Yes, I'm going to actually invite her because we have some really good special department news in here. Some great events that are coming as Shane mentioned one of those is actually one that he's going to organize. Maybe he can after Karolina tells us a few things. Maybe he can share with us, not this one. Hey, the Kansas City Vimeo user group Kansas City. What can you tell us about it Karolina? Yeah, I actually thought that we are going to start with the day before but no problem. We can start with Kansas since we get Shane here. So if anyone of you is in Kansas by any chance, you should definitely step up there because it will take place and we will be actually talking about AI, which is I would say now really trend topic, but also how AI is now used, you know by cyber criminals, which are creating like pretty a lot of and they are pretty creative in terms of the ransomware attacks, how they are using it. So I would say when I came across this Vimeo user group, I wish I could be there, you know, but it's unfortunately a long way for me, but I believe that the topic is really interesting because I noticed this on a daily basis, you know, like the situation what are the risk with using it? But so definitely shout out to Shane for choosing this topic, but maybe you would like to add something since you know, you are the leader in this. No, there's nothing, not really too much to add. Object First is our sponsor, the one that's going to be talking about that AI session. I'm actually going to be talking about the new, semi-new, I guess now, the VSA. I think a lot of users that are here locally in the Kansas City area, I don't think they're, and I know I'm one of them that has not transitioned to the VSA. So I'm going to share more about the VSA, what items do you need to be aware of if you're considering migrating to Veeam 13 and using the VSA, some limitations it has, but some amazing features, of course, both of you all are aware of. So yeah, that's really about all that we're going to talk about. And then of course, we're going to have an AMA Q&A session as well. And I can see it's going to be pretty cool in a brewery. So yeah, we used to have another user group. It's been several years since I've been there, but it's a really, really good venue. It's got an outdoor patio. It's just, it's got a nice bar in the venue that, in the meeting room that we'll be in. And so it's really nice, open bar, catered food, Object First really did us up good. So looking forward to it. Yeah, they've been really good with the Veeam user group. So that's great. They always help us put together some really nice events. I can see it's just about three hours, more or less, the event. Yeah. I assume there are still like seats available so people can still go. There are. Yeah, just make sure you register. Those who haven't registered in Kansas City or the surrounding area ish, close ish to Kansas City. Make sure you register so we can have a headcount for catering. Yes. Anyone welcome, right? Like people that are interested in Veeam solutions. Yeah, absolutely. Perfect. Thank you very much for that, Shane. Really looking forward to see some pictures and to hear stories after the event. But yeah, go for it. Good topic, good food, good sponsor, awesome venue. Moving forward. Let me see which one we gonna pick now. Moving. Let's stay in the US to Minnesota one. Tell us about this one, Carol. Yeah, so we are still in US. However, this time in Minnesota, now the main focus, it will be Veeam Data Platform 13.1 and Veeam Data Cloud. So for everyone who are in this area and would like to find out more like news, maybe some insights, they should definitely attend this one because that's the place. Just to, you know, hear from the experts. Also exchange some maybe good practices because I feel that that's the biggest value which you are getting from attending such Veeam user groups to meet other members and just exchange your thoughts about it. So definitely check it out. I don't know, Maddy, if you, oh, yeah, here we go. That's what I wanted. So yeah, in like three hours, but this time in the evening, so don't forget to register and you are welcome for everyone who are in this area. Still far away for us. But yeah, really far away. Thank you, Terence, for putting this one together. I know that he's doing some really fantastic with a lot of attendance Veeam user group events. So he has a little bit of everything. He's covering V13.1, VDC updates, and then Veeam live demonstrations of what's new. So that's a surprise. Ask me anything. And also bowling tournament, you know, I would say this is, I mean, maybe let me be just silent about my bowling experience, but definitely I wouldn't be in the top ones, but for everyone who are better or just enjoy, definitely should check it out. I know a person that is really good with bowling. That's Kirsten. So if she's hearing us, she knows what I'm talking about. But yeah, I can see this one takes place. There's no, I don't see any sponsor for this one, but I can see it's a pinstripes. Maybe Shane, you heard about this. It's some chain or something like that. I assume it's a bowling place. I don't know that it's a chain. I've not heard of that one before. Okay. Anyway, check it out. There are still seats available. You can still register. This one is September 23rd. Okay, moving forward. And now we are coming close to home. Let's see how close are we talking? There you go. Okay. So now we are in UK, in Manchester this time and what a surprise the same date, you know, 24th of September. I feel like every time I'm invited to the recap, this happens that all events are taking place on the same day. But again, we will have a Veeam user group there. There will be discussion around hypervisor migrations, what's new and what's upcoming with Veeam Data Cloud. Also, you can find out more information about in-depth defense strategy. This event also is sponsored by Object First. So definitely worth checking it out. And yeah, this time in Manchester. So slightly closer, you know, to us. Yeah, definitely worth registering. For sure. I love the titles. I mean, I got 99 problems, but Veeam ain't one. Zero trust. Good, but not good enough. These are so good. I mean, it's almost as bad as you know, like you don't know. That's the UK. That's those UK folks. They're really spot on with their session titles. Yeah. Thank you, Ian. Thank you, Mark, for putting this together. The venue is the Midland Hotel, Manchester. The venue is the Midland Hotel. I've been once to Manchester. I don't know where the Midland Hotel, but I'm sure it's going to be a good one. Thank you. Check first once again. And yes, there is still time for you to register. Twenty four of September. It looks like this is going to be more or less like half day. So all good topics. You have technical experts in there. You have people to ask any questions you might have around Veeam and yeah, also have some fun with it. So all good reasons to participate in you have a raffle and price and some drinks. So as I know, British people will do some good beer. So good stuff. Moving to the next one. The last event on the 24th. Again, just even closer to home. Exactly. And now there is a saying that all roads are leading to Rome. So here we go. This time we are in Italy, in Roma. And yeah, I know that this will be also a very interesting Veeam user group because there will be like topics about integration of AI into Veeam, how it also changed the role of the backup administrations. So what is more, they will be covering like news and innovations from Veeam. So I'm sure that there is plenty, plenty to find out about this. And what I actually noticed, Maddy, if you scroll up a little, little bit, there will be a possibility to earn the Object First Technical Professional Certification. So I would say this is a huge shout out. This is great. As I can see, it's just four partners for one partner. But this is amazing. I mean, and this is a full day event if you look at it. So a lot of good stuff. And they have some degustations, tastings, tastings from the iconic. Yeah, I mean, I wouldn't be worried about, you know, I'm glad you guys can read it because I certainly can't. Yeah, no, that that looks amazing. I think it's a good one. I mean, if you are in Rome or around Rome, definitely register for this one. I know for sure there are still some seats available. Yesterday I talked to the people from Object First. So, yeah, you can still register again 24 of September. And just to end in style, moving back to America, to Latin America and to our trip, why don't you tell us a little bit about how is our trip? I'm going to share a slide with some pictures from VUG Ecuador and VIMON Ecuador. Roberto, one of the leaders, shared one picture from yesterday. So you see Rick and you see Sofia and Jada as well. But tell us about it. If you can maybe just put it in the PowerPoint slide view. So, yeah, because it's but yeah, like I don't know if we have another hour to discuss our trip because it's, you know, plenty to talk about. But I am happy to talk about VIMUSER group in Ecuador because we got the opportunity to participate in it. And, you know, I feel like already it was like two weeks ago or a month ago, even though it was just last week. Yeah, so pretty recently. And as Maddy mentioned earlier on, it was a really interesting one. As you can see, even on the participation rate, because people got the chance to participate in the lab. So basically what they were they were working on the scenario of like and I can confirm as I was witnessing that they were working really hard on this. They were brainstorming. They were really involved. So I would say a big shout out to Chris and Roberto for organizing this user group, because I would say that it was a pretty good and successful meeting. What is more, I was even happier to see more women attending because, you know, I would say it's not that common to see women. And there were also plenty of women. So I was very glad that we could be part of this. Yeah, thank you for that. I definitely confirm that it was great. It was an amazing trip. We talked about all the other events as well in the previous shows. And Carolina said it all. Thank you, guys. Thank you all, LATAM community. They are so welcoming, so amazing and always looking forward to to go back. But. You know, just saying going back now to our faces to the screen, I just want to also say thank you very much for being part of the show, I think we had some really good conversations in here, technical, fun events, special department news, all that. I can see we are already at almost an hour. So I'm not going to make it longer. But yeah. Any thoughts before we go? Your side? No, just had a really good time, really, really good content and really good discussions about it. Thanks for having me again, Maddie. Yeah, thank you very much. For everyone actually who are maybe around like LATAM right now, Mexico, Colombia, they can also check it out. The VIMON tours. I will be actually in Poland next week. So to everyone who is joining those events, see you there. But otherwise, thank you so much. Thank you, guys. And thank you all for watching us. Have a lovely weekend and we'll see you next week with 278. And I'm not sure if Rick is going to be part of it or we're going to have to have special guests again. But until then, have a great weekend. See you later, guys.

TL;DR

  • A zero-day resilience workshop in El Segundo used simulated cyber attacks and tabletop exercises to help IT leaders identify gaps in their incident response and recovery processes.
  • Veeam's SureBackup, Scan Backup, YARA scanning, and Threat Hunter tools provide layered verification to confirm backup cleanliness before returning data to production after an attack.
  • A Micron 5200 SSD firmware bug caused nearly two weeks of troubleshooting across two production sites, underscoring the value of hardware diversity between production and backup environments.
  • Veeam 13.1 instant VM recovery enables direct restoration of VMware backups into Proxmox, easing hypervisor migration — but organizations must evaluate driver compatibility, storage formats, and HA requirements before switching.
  • Multiple Veeam User Group events are scheduled for late September across the US, UK, and Italy, with Object First sponsoring the Manchester and Rome events and offering a technical certification at the Rome VUG.

Zero Day Resilience and Backup Verification

Episode 277 of the Veeam 100 Community Recap opens with a discussion of a zero-day resilience workshop held in El Segundo, California, organized by community member Stephen. The workshop walked IT and security leaders through a simulated cyber attack — from initial signs of compromise through disruption and into recovery — using tabletop exercises to expose gaps in organizational processes. Host Madi draws a parallel to a similar hands-on lab conducted at VUG Ecuador, reinforcing that resilience requires practiced response, not just documented plans. Shane elaborates on Veeam's tools for verifying backup integrity before restoration, highlighting SureBackup with AV scanning, the Scan Backup feature introduced in V12, YARA rule scanning for ransomware indicators, and Veeam Threat Hunter as the recommended engine for speed and accuracy. The panel emphasizes that knowing a backup is clean before returning it to production is a non-negotiable step in any incident response workflow.

Micron 5200 Firmware Bug and Hardware Diversity

The episode's most technically detailed segment covers a community post by Michael describing a Micron 5200 SSD firmware bug that caused degraded performance across two production sites, taking nearly two weeks to diagnose. Shane explains why the investigation took so long: with most systems still running, there was no obvious failure point, forcing the team to methodically work through every layer of the stack — storage controllers, battery backup units, drives, and network throughput. The panel draws a practical lesson from the experience: running different hardware for production and backup environments provides critical separation. When a firmware defect is isolated to one vendor's drives, the backup infrastructure remains unaffected and recovery remains viable. Shane also notes that the Broadcom-VMware transition is causing many organizations to extend hardware refresh cycles beyond their normal cadence, which may increase exposure to exactly this kind of age-related firmware issue.

VMware to Proxmox Migration and Hypervisor Considerations

The Vanguard blog spotlight features a detailed write-up by Ben Harmer on migrating VMware workloads to Proxmox using Veeam 13.1's instant VM recovery capability. The key insight is that existing VMware backups can be recovered directly into Proxmox, significantly lowering the barrier to migration. Shane, who is actively evaluating both Proxmox and XCP-ng for his school district environment, walks through the practical considerations any organization should assess before switching hypervisors: hardware compatibility, support for live migration and high availability equivalents, GPU passthrough requirements, storage format support (including QCOW2), and driver dependencies such as the VirtIO driver needed for Proxmox VMs to access storage correctly. Madi notes that Veeam's roadmap includes support for additional hypervisors beyond Proxmox and XCP-ng, including Nutanix AHV and region-specific platforms popular in APJ markets, giving organizations flexibility as they evaluate alternatives to VMware.

Community Events and LATAM VeeamON Tours

The special department news segment covers several upcoming Veeam User Group events, all coinciding on September 23rd and 24th. Highlighted events include a VUG in the United States featuring an Ask Me Anything session and a bowling tournament at Pinstripes, a Manchester UK VUG at the Midland Hotel sponsored by Object First covering hypervisor migrations, Veeam Data Cloud, and in-depth defense strategy, and a full-day Rome VUG also sponsored by Object First where attendees can earn the Object First Technical Professional Certification alongside sessions on AI integration in Veeam and evolving backup administration roles. The episode closes with Madi and Karolina reflecting on their three-week LATAM tour, specifically praising the VUG Ecuador event organized by Chris and Roberto, which featured competitive team-based lab exercises and notably strong attendance from women in technology — a positive signal for community diversity in the region.

Chapters

0:00 - Introductions and Episode Overview
2:41 - El Segundo Zero Day Resilience Workshop
8:42 - Verifying Backup Safety with Veeam Tools
20:14 - Micron 5200 Firmware Bug Case Study
26:27 - Proxmox Migration with Veeam 13.1
34:39 - Upcoming Veeam User Group Events
47:08 - LATAM VeeamON Tours Recap
49:55 - Closing Remarks

Key Quotes

4:23 "Resilience isn't just about having a disaster recovery plan sitting just somewhere on your shelf. You actually need to practice how you're going to respond and how you're going to make some decisions under pressure."
9:09 "Within Sure Backup, you have the opportunity to do AV scans against your backups to make sure nothing is infiltrated within your backups."
10:39 "Not only can you do scans against any type of AV issue, you can do YARV scans, which really is geared towards the malicious intent, onion links, ransomware, that kind of thing."
21:24 "With the issue with VMware, let's just say and Broadcom, I think people are going to be running their systems longer than what they normally would as they decide what they're going to do as far as transitioning from VMware or to retain it."
25:07 "I think that's important that you have some separation there, you choose certain hardware for production, and then you choose another type of hardware for say, backups. For this very reason, you run into an issue, not everything is down."
31:33 "It's the little things like just a simple driver can prevent VMs from working. And then how do you transition to this new solution? Well, Veeam provides instant recovery. That's certainly one way."

FAQ

How can organizations verify that a backup is safe to restore after a ransomware attack?

Veeam offers several tools for this: SureBackup can spin up a backup in an isolated environment and run AV scans against it; the Scan Backup feature (introduced in V12) allows scanning of individual restore points without a full SureBackup job; YARA rule scanning targets ransomware indicators and malicious links; and Veeam Threat Hunter is the recommended engine for speed. Using these in combination gives organizations confidence that a restore point is clean before returning it to production.

What should organizations consider before migrating from VMware to Proxmox or another hypervisor?

Shane recommends building a requirements list before choosing a hypervisor. Key considerations include hardware compatibility with the new platform, support for live migration and high availability equivalents (like DRS in VMware), GPU passthrough needs, storage format support (e.g., QCOW2 for Proxmox), and driver dependencies such as the VirtIO driver. Organizations should also plan for downtime windows, test migrations in a lab environment first, and evaluate whether Veeam's instant VM recovery can serve as the migration mechanism.

Why did the Micron 5200 firmware bug take nearly two weeks to diagnose?

Because most systems were still running — there was no hard failure to point to, only performance degradation. The team had to systematically investigate every layer of the stack: storage controllers, battery backup units, drives, and network throughput. With no obvious starting point and a wide range of potential causes, the investigation naturally took time. Shane notes that Michael's detail-oriented approach meant they were thorough, not slow — and the lesson is that hardware diversity between production and backup environments can limit the blast radius of such issues.


Categories:
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Backup & Recovery
  • Data Protection
  • Security Operations
  • Best Practices
  • Webinar
  • Getting Started
  • Cyber resilience and incident response
  • Backup verification and malware scanning
  • Ransomware recovery
  • Firmware failure troubleshooting
  • VMware to Proxmox migration
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zero Day Resilience, CDP & Firmware Failure: Veeam Community Recap

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Ensuring Compliance Through Audit Evidence: From CJIS to FERPA

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Ensuring Compliance Through Audit Evidence: From CJIS to FERPA
                      https://www.truthinit.com/index.php/channel/2159/ensuring-compliance-through-audit-evidence-from-cjis-to-ferpa/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version