Check out our companion blog!

Episodes

Aug. 28, 2023

Are password managers no longer an option?

In this episode, we look at the latest Ransomware Trends Report from Veeam, which gives us a view into the sobering world of ransomware attacks and the critical lessons they teach us about cyber defense. Join W. Curtis Preston (Mr. Backup) and Prasanna Malaiyandi, as they break down the key insights from the report. We explore the ruthless tactics of ransomware operators, the eye-opening stats on recovery time, and the evolving strategies of cyber insurers. From the importance of robust password...
Aug. 21, 2023

Identity Orchestration: Simplifying Multi-Cloud Identity Management

In this episode, W. Curtis Preston and Prasanna Malaiyandi are joined by Eric Olden, the CEO of Strata Identity. With over 25 years of experience in the cybersecurity industry, Eric sheds light on the concept of Identity Orchestration and how it addresses the complexities of modern identity management in multi-cloud environments. He discusses the evolution of technology consumption, the philosophy of "bought not sold," and the creation of a new product category in the world of identity managemen...
Aug. 14, 2023

Red team leader shares how to think like a hacker

Our guest this week is a specialist at offensive cybersecurity; that is, they keep you safe by attacking you and showing you your vulnerabilities. They're a red team. We've got the leader of their red team, Duanne Laflotte, to help us understand how hackers think – and what we can do to stop them. He confirmed some of the recommendations we often make (Ahem: password managers good), but showed us some defenses aren't that helpful. A particularly relevant part to our backup audience is what he to...
Aug. 7, 2023

Blue team stories from the cyber attack trenches

Nothing tells the story like a good story, right? This week we have Mike Saylor, the CEO of Black Swan, a cybersecurity company. Boy, has he been in the trenches. He tells some great stories about responding to cyber attacks. They're great stories and he's a great storyteller. We also learn about FBI Infragard, a partnership between the FBI and the private sector. We hope you enjoy the episode. Mentioned in this episode: Interview ad
July 31, 2023

Should you disclose your cyber attack?

This week the SEC has made a new rule that publicly traded companies must disclose any cyber attacks within four days. What if you're not a publicly traded company in the US? Should you reveal what happened to you? We bring in a wireless cyber security expert, Scott Schober of Berkeley Varitronics Systems, to talk about this topic. Closely related is also what should you do when you personally make a big mistake. Should you tell your boss? What if you're a boss and someone makes a mistake? How s...
July 24, 2023

Backup security is abysmal, says backup security expert

During this recording, Mr. Backup asked our guest how many backup systems that he had looked at had at least one critical security flaw, he said pretty much 100%. Holy. Cow. Doron Pinhas runs a company called Continuity Software, that does security assessments of storage and backup and recovery systems. They got the permission of some of their customers to anonymize and publish their findings, and the results were abysmal. (You can read the report yourself here.) He said it was extremely rare to...
July 17, 2023

Your backup product is probably lying to you

Krista Macomber, analyst from the Futurum Group, joins us this week to talk about a number of things, but one thing really bubbled up to the top: co-opting of marketing terms. That is, it's probably using terms to describe their product, because they think you want to hear them. Two big ones these days are "air gapped" and "immutable." Krista and Mr. Backup talk about what these terms really mean – and whether or not your product should be using them to describe their product. You may not get an...
July 10, 2023

Former Green Beret advises us on Cyber Security

Today we are proud to have as our guest, Zach Fuller, a founding partner of the Silent Sector, a cybersecurity firm -- and a former Green Beret who served in combat. We talk a little about how his service made him the person he is today, and how it lead him ultimately into helping people protect their own data. We talk about his top few things he wishes people would do to secure their environments (in addition to Mr. Backup's usual suggestions of password management, MFA, and patch management). ...
June 26, 2023

How to foster a culture of recovery in your organization

Our guest this week (Jim Love from the Hashtag Trending podcast and IT World Canada) touched on something we thought was profound. He felt that some organizations had what he called a "culture of recovery," meaning that they took recovery into account in all aspects of the org. He explained how he fostered this in companies where he worked, and how you can do the same. We also covered generative AI, and he shared several other tips from his many years in the business. Learn the old ways! Mentio...
June 19, 2023

How to PROPERLY back up your iPhone (iCloud is not a backup!)

iCloud is not a backup; it is a synchronization tool. If you delete things on your phone, it deletes them in iCloud. iCloud is not a backup. In fact, if you have storage optimization turned on, the high-resolution verion of your photos is stored in only one place. If you delete it, it's gone forever. Mr. Backup tries tries three different ways to back up your iPhone, and finally settled on idrive. iDrive was the only solution we found that worked for both iPhone and Android (including if you tu...
June 12, 2023

Cyber expert not happy with state of cybersecurity today

This week we talk with Eric Jeffery, a cybersecurity SE and host of the Cyber Security Grey Beard podcast, and he is just a little miffed about how organizations are responding to cyber attacks today. It's not so much about how they respond to the attack itself; it's how they communicate what happened to the public – if at all. He's submitting what happened at the LA Unified School District as his case in point. He's a bit fired up, so this will be a fun one. Mentioned in this episode: Intervi...
June 5, 2023

How do you authenticate with all new hardware?

Imagine you're a small business or household that just lost everything in a fire, and your phones, ipads, and laptops went up in flames too. Where do you start? You've got a cloud-based password manager (e.g. Dashlane, OnePassword, KeyPass) and MFA system (e.g. Google Authenticator, Authy). How do you authenticate yourself with these systems if you have all new hardware? That's what we're talking about in this episode. We reference this great previous episode about being prepared for disasters:...
May 22, 2023

You could lose access to iCloud account data forever!

There was a shocking article by Joanna Stern of the Wall Street Journal about how you are a simple bar trick away from losing access to all your photos (and some money) forever. All they need to do is steal your iPhone after seeing you type in your passcode, and they can lock you out of your account forever. 1. This is why we back up stuff and 2. There is a way to stop this. I'm not yet sure how vulnerable Android folks are to the same problem. If I've piqued your interest, this is the episode f...
May 15, 2023

How to back up and recover a database (Backup to Basics series)

Have we got a packed episode for you. This week in our continued Backup to Basics series, we dive deep into the various options for backing up and recovering databases, along with the pros and cons of each. Want to figure out the best way to back up your traditional or modern database? This is your episode. As usual, Mr. Backup and Prasanna also manage to make it fun. This is a great episode and we think you'll enjoy it. Mentioned in this episode: Interview ad
May 8, 2023

Flash expert schools Mr. Backup

A few weeks ago, Mr. Backup (W. Curtis Preston) said he didn't understand why people used flash for backups. He said it was overkill. A few days later, Howard Marks of Vast (friend of the pod) took issue with that statement, and asked for the chance to defend Vast's title, so to speak. Howard is a friend of the pod and we were happy to say yes. We also take the opportunity to get an update on Vast, and discuss their data reduction techniques in more detail. Bonus points if you get the cover art ...
May 2, 2023

What are SIEM, SOAR, EDR, XDR? Are they available as a service?

Are you doing all you can to stop ransomware attacks before they happen, or kill them the moment they show up? Have you looked into this and found yourself swimming in alphabet soup (SIEM, SOAR, EDR, XDR)? Have you looked at some of these tools and found them to be prohibitively expensive or too complex? This is the episode for you. We have Dez Rock, CEO of SIEMonster, a SIEM/SOAR/XDR as a service company. She helps us weed our way through these acronyms, and then tells us about how SIEMonster (...
April 24, 2023

What can you learn from the LastPass hack?

Last year LastPass suffered two hacks that left their customer's data exposed. What can you learn from this event, even if you're not a LastPass customer? We use this hack as an example of what your company should do (or not do) if it ever suffers such a hack. We also talk about password managers, and what this hack means to those who use them. You do use one, right? This is a great episode, chock full of information. We hope you enjoy it. Mentioned in this episode: Interview ad
April 17, 2023

Backing up databases, Part 1 (Backup to basics)

It was a dark and stormy night in 1993 when paris (the database server) went down. It would be a night the new backup admin would never forget because he couldn't restore the database from backup. The only bright side of that very sad story is that it launched a career. Yes, that's the night W. Curtis Preston started his path toward Mr. Backup. Hear him tell the story in his own words, in the middle of the backup to basics series about backing up databases. Avoid the mistake that could have (but...
April 10, 2023

What computers should you back up? (Backup to Basics Series)

Are you backing up all the things you should be backing up? In this latest episode of our Backup to Basics series, Mr. Backup & Prasanna look at the list of the traditional things we think about backing up: servers, databases, laptops, mobile devices, file servers, virtualization servers, etc. The big question tackled in this episode is what of these things should you be backing up? Mr. Backup, of course, takes a pretty hard line about backup, but he may surprise you on some of his exceptions. W...
April 3, 2023

Can you apply least privilege to private data?

You know how we tell you to limit the amount of privilege each admin gets, in order to limit the blast radius if their account is compromised? What if you could apply that concept to applications that use private data to accomplish their task? We blindly give everything we have on each person to just about any app that needs anything. But if you had an app that only needs first name and email address, why not just give it that? And if it asks for more than that, what if you had a way to give it ...
March 27, 2023

Six vulnerabilities your password manager might have

I was shocked to learn that my favorite password manager had a few known vulnerabilities, and you might be shocked too! We found this great research paper from the University of York, and invited one of the co-authors on to discuss it. Siamek Shahandasthi, an Associate Professor from the University of York, explained all the vulnerabilities discussed in the paper, and why each is important. I was able to verify that at least one is still found in my current password manager. How many are in your...
March 20, 2023

What is deduplication and how does it work? (Backup to Basics series)

In our latest episode of the Backup to Basics series, we talk about what I think is the most important invention in my career: deduplication. Without dedupe, much of what we do in backup and recovery, and disaster recovery, would simply not be possible. Without dedupe there really is no disk backup market; there is no cloud backup market. I'd be out of a job! What is dedupe, anyway, and how does it work? What are the different kinds of dedupe and does that matter? You should learn a lot about th...
March 13, 2023

Preparing an incident response plan for ransomware

An incident response plan is the key to successfully surviving a ransomware attack, and it's a bit like Dramamine. The time to get one is too late to get one. @Vmiss (Melissa Palmer) joins us again to talk about this important topic. We talk about the important role cyber insurance companies can play in helping you find an IR team and helping you develop a plan. (They can actually force you to do so in order to get coverage.) @vmiss was a blast to talk to again, and we're sure you'll enjoy this ...
March 6, 2023

What to do with your network in a ransomware attack

We have talked about this a lot on the pod, and now we have someone that can explain what you actually do with your network when you get a ransomware attack. It's Tom Hollingsworth from Gestalt IT, and we're excited to have him on the pod. Some of his recommendations of course, require some configuration in advance. We talk about VLANs, SEIM and access management tools, and why many networking admins are terrified of the "reject all" concept that would actually make your network much more resili...