39
System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” – 7/16 Dennis Kloster System Source Senior Consultant [email protected] Courtney Joyner Hyperconverged Solutions Architect, Mid-Atlantic [email protected]

System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

System Source Pizza Webinar - “Recover

from Ransomware in 60 Seconds” – 7/16

Dennis Kloster System Source Senior Consultant

[email protected]

Courtney JoynerHyperconverged Solutions Architect, Mid-Atlantic

[email protected]

Page 2: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

AgendaOpening and Introductions – Chris Riley

Dennis Kloster• Why implement ransomware & DR protection Courtney • Demonstration of data protection features for 60 second recovery• New HPE RapidDR vs. VMware Site Recovery Manager (SRM)• Compare HPE SimpliVity HCI vs. HPE Nimble Storage dHCI

Q&A Chris Riley

Page 3: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

We Hope You are

Enjoying Your

Pizza!!

If you haven’t received your pizza,

then contact Mike Jones:

[email protected]

Page 4: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

During the Webinar…

Audio – In presentation mode until end

Control Panel

View webinar in full screen mode

In Chat – Tell us what you hope to learn today?

Feel free to submit written questions

Presentation and video available after webinar

Evaluation just after webinar finish

Page 5: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster
Page 6: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Dennis Kloster

Page 7: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

1) Ransomware emails spiked 6,000% - 2018 vs. 2017

2) 40% of all spam email had ransomware

3) 92% of surveyed IT firms reported attacks on their clients

4) 70% of businesses paid the ransom

5) 20% of businesses paid more than $40,000

6) Most businesses face at least 2 days of downtime

Source: IBM via CNBC

Page 8: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Ransomware Prevention• Make sure antivirus is installed and kept up to date on all endpoints

• Computers and laptops

• Servers!!!!! (I constantly see servers that don’t have AV installed)

• Phones?

• Tablets?

Page 9: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Ransomware PreventionPatching

• Patch Windows

• Java, Flash, Adobe, etc…

• Use a patch management solution to make sure all endpoints are in compliance

• Patch everything!

Page 10: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Ransomware Prevention• Restrict admin rights on endpoints

• If someone needs admin rights, give them 2 accounts• An admin account that they are only to logon with when they actually need to use the

admin rights

• A non-admin account to be used for everything else

Page 11: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Ransomware Prevention

Enable Unified Threat Management on edge devices such as a firewall• Enable IPS

• Enable IDS

• Web site filtering

• Heuristics

Page 12: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Ransomware Prevention

AND THE SINGLE MOST IMPORTANT COMPMONENT………

Page 13: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Ransomware Prevention

END USER EDUCATION AND AWARENESS!!!!!!

Page 14: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster
Page 15: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Other Important Components of a Ransomware Readiness Plan

Backups• Test your backups! Just because the backup software says that your nightly backup was

successful doesn’t mean you can restore what you need.

• Disk to Disk backups: Ransomware can infect anything that is online. If you are using disk to disk backups, you must take your backups offline in order to protect them

• Best practice: 3 backups copies. 2 different formats. At least one copy is offsite

Page 16: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Other Important Components of a Ransomware Readiness Plan

SAN snapshots…. More valuable than a backup?• Offline unless someone manually brings them online

• Can easily have multiple copies done throughout the day

• Typically are instantaneous unlike backups

• Easy to replicate offsite

Page 17: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Other Important Components of a Ransomware Readiness Plan

VM level replication• Much quicker restore capabilities than a backup

• DR plan can be programmed ahead of time

• Easy testing capabilities

• Can be SAN based on software level (Veeam, Zerto, etc)

• Use your own DR site or a hosted site

• Major potential benefit is it (in theory) is a “clean” site

Page 18: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

REIMAGINE HYPERCONVERGED:SOFTWARE-DEFINED TO AI-DRIVENWITH HPE SIMPLIVITY

Courtney Joyner

Page 19: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

TODAY’S REALITY FOR EVERY VM ADMIN

Pressure to lower cost requiring efficient utilization at scale

Pressure to do moresupporting traditional and modern apps

Infrastructure complexityrequiring multi-domain experience

Constant fire fightingwith uncontrolled VM sprawl

19CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY

Page 20: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

ARCHITECTURAL EXPERIENCES CAN GET COMPLEX

20

For predictable workloads

• Ideal for general purpose apps, edge, and ROBO

• Compute and storage easily scale together

• Simplest for easy management

HYPERCONVERGED

For unpredictable workloads

• Ideal for larger scale and business-critical apps

• Independently scale compute and storage

• Most flexible (but at a cost of simplicity)

EXTERNAL STORAGE

Two Experiences. Too Complex.

Page 21: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

HPE APPROACH TO THE HYPERCONVERGED EXPERIENCE

21

HYPERCONVERGED CONTROL

GLOBAL INTELLIGENCE

HYPERCONVERGED DISAGGREGATED HCI

APP-AWARE DATA MOBILITY

Page 22: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 22

HPE SIMPLIVITYIntelligent HCI for general purpose

workloads, edge, and ROBO

INTELLIGENTLY SIMPLE

HYPER EFFICIENT

EDGE OPTIMIZED

CLOUD CONNECTED

Page 23: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

HPE SimpliVity Hyperconverged

Infrastructure

WHAT’S TO SIMPLIFY? EVOLUTION OF CONVERGENCE

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 23

Other Hyperconverged Solutions

Converge only

storage & server

Legacy Stack

Servers & VMware

Storage Switch

HA Shared Storage

SSD Array

Backup & Dedupe

WAN Optimization

Storage Caching

Data Protection Apps (Backup & Replication)

Switches Collapse the “entire” stack into a single, intelligently simple solution with density, resiliency, and performance• Built-in resiliency, backup,

and disaster recovery• Performance with always-on

inline deduplication and compression

• Reduced costs compared to legacy IT and other HCI

• Managed via single, familiar interface

Page 24: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

INTELLIGENTLY SIMPLE: ANYONE CAN MANAGE

24

Collapses the stack, removing silos with built-in resiliency, backup and disaster recovery

All-in-One System

Flexibly add or remove modular systems non-disruptively to meet business needs

Zero-Downtime Refresh Cycles

Always optimal performance, efficiency, resiliency without knobs or tradeoffs

Automated Tuning

Centrally manage everything including data protection

Global Unified Management

Simple lifecycle management across firmware, hypervisor, OS

One-Click Upgrades

Predictive analytics and support automation

Global Intelligence

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY

Page 25: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

HYPER EFFICIENT: ELIMINATING WASTE IN TIME AND MONEY

25

Data efficiency 90%+

Capacity savings guaranteed

Restore efficiencyPower to recover 1TB

VMs in 60 secs

System efficiencyAll-in-one collapsing

10 discrete silos

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY

Page 26: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

HYPER EFFICIENT

▪ Always-on deduplication and compression

▪ All data at inception, globally

▪ 100% software optimized

▪ Acceleration frees CPUs to run business workloads

Customers average 47:1 efficiency > 1/3rd surveyed achieve over 100:12

2 Reported in Forrester Total Economic Impact Study, 2019; TechValidate

Save 90%capacity across

storage and backup combined1

47 : 1 Guaranteed data efficiency

1HPE SimpliVity HyperGuarantee

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 26

Page 27: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

BUILT-IN BACKUP AND DISASTER RECOVERY REDUCES COSTS AND RISK

OR

+ third-party backup for operational recovery

+ replication and disaster recovery automation

+ WAN optimization

HPE SimpliVity

27

+ backup media and tape infrastructure

Alternate hyperconverged without built-in backup/recovery

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY

Page 28: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

ENHANCED BUILT-IN BACKUP: COST EFFICIENT SECONDARY BACKUPS

28

App-aware, automated protection Cost effective SLAs without compromise

Core siteEdge sites

HPE StoreOnceHPE SimpliVity federation

1 Assuming dedupe ratio of 20:1 as compared to a fully hydrated backup

20:1 storage efficiency1

100% automated, simple to configure

Up to 7x less cost

compared to HPE SimpliVity tier

60 second to restore 1 TB VM -archive VMs for years for

compliance

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY

Page 29: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

HPE SimpliVity RapidDRAUTOMATED, SIMPLIFIED RECOVERY REDUCES COSTLY DOWNTIME

• Disaster recovery orchestration automates VM failover and failback from primary site to secondary site

• Reduces costs and complexity by streamlining the DR process

• Improves service level agreements (SLAs) by lowering recovery point objectives (RPOs) and recovery time objectives (RTOs) from days or hours to minutes

• Cost of downtime: 1 hour IT downtime = $102K; IT downtime costs organizations $20.1M annually**

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 29

Miami Munich

** 2019 Availability Report

Page 30: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

VM Host VM Host VM HostVM Host

2 Controllers

1 Copy of Production Data

1 Instance of Backup Data

4 Controllers

2 Copy of Production Data

2 Instances of Backup Data

2 Controllers

4 VM Hosts4 HPE SimpliVity nodes2 HPE SimpliVity nodes

Primary Storage

Storage Controller 2

Storage Controller 1

DOING MORE WITH LESS

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 30

Network

Page 31: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

How SimpliVity writes data to diskTHE SIMPLIVITY DATA PATH

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 31

VM1

VM1

Hypervisor

NFS Datastore

Data Virtualization Platform

SimpliVity Object Store

Page 32: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

SimpliVity Local BackupsTHE SIMPLIVITY DATA PROTECTION

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 32

VM1

VM1

Hypervisor

NFS Datastore

Data Virtualization Platform

SimpliVity Object Store

Backup1Backup2

Page 33: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

SimpliVity Local BackupsTHE SIMPLIVITY DATA PROTECTION

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 33

VM1

VM1

Hypervisor

NFS Datastore

Data Virtualization Platform

SimpliVity Object Store

Backup2

VM1

VM1 (recovered)

Page 34: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Ransomware attack holds Central One Federal Credit Union data hostagePROFILE OF A CRYPTOLOCKER ATTACK

• 3:30 p.m. First signs of trouble• First noticed problem when employee couldn’t process large file from the Federal Reserve

• At first, thought it was a problem with core application vendor

• Vendor identified corrupt file as possible root cause

• 6:00 p.m. Attempt to copy folder from another branch location• Attempted to copy the folder from another branch location

• WAN connection only 1.5 Mbps took about two hours to process

• 8:00 p.m. Discovery of CryptoLocker ransomware demand • After transfer, file was still not able to process

• Team then identified the root cause as CryptoLocker

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 34

Page 35: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

RECOVERING FROM CRYPTOLOCKER WITH HPE SIMPLIVITY

• A recovery point from prior to the infection was selected

• HPE SimpliVity restored the 500 GB virtual machine (VM) in seconds

• Database was operational in minutes

• Subsequent transactions recovered and processed

• 8:30 p.m. The team left the office.• No data lost.

• No ransom paid.

• Read more: Customer success story including recovery from cyber incident

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 35

Page 36: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

HPE SIMPLIVITY HYPERGUARANTEE

36

1 HyperEfficient: save 90% capacity across storage & backup combined

2 HyperProtected: under 1 minute to complete a local backup or local restore of a 1TB VM

3 HyperSimple: 3 clicks to back up, restore, move, or clone a VM from a single console

4 HyperManageable: under 1 minute to create or update backup policies for 1000’s of VM’s across many

sites

5 HyperAvailable: add or replace HPE SimpliVity systems with zero downtime for local or remote sites✓ Zero disruption to local or remote SimpliVity backups✓ Zero reconfiguration of SimpliVity backup policies for local or remote sites✓ Zero re-entry of IP addresses in remote sites

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY

Page 37: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

HPE SIMPLIVITY PRODUCT FAMILY

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 37

SimpliVity 380 380 G 380 H (SFF) 325 2600 380 H (LFF)Positioning High performance General Purpose General Purpose Entry Level Density Backup & Archive

Use cases

• Data Center Consolidation

• Maximum general-purpose performance

• Multi-GPU VDI• Additional 1P NIC

connectivity

• High capacity, low IOPS mixed workloads

• General purpose virtualization

• ROBO, Edge• VDI• SMB deployments

• Edge, colodeployments

• VDI• Limited available

space

• Backup/archive• Longer term

SimpliVity backups

Features• CPU/Storage

Expansion• Additional PCIe

expandability • Hybrid storage

• AMD-based• TCO optimized

• Density optimized• Hybrid storage• $/GB optimized

Form Factor2U1N, 1-2P

ProLiant DL380 Gen10 SFF

2U1N, 1-2PProLiant DL380 Gen10

SFF

2U1N, 1-2PProLiant DL380 Gen10 SFF

1U1N, 1PProLiant DL325 Gen10

2U2N, 2U4N, 1-2PApollo r2600 Gen10

2U1N, 1-2PProLiant DL380

Gen10 LFF

Data Path Hardware-accelerated Software-optimized Software-optimized Software-optimized Software-optimizedSoftware-optimized

Memory Up to 1.5TB Up to 3TB Up to 3TB Up to 2TB Up to 1.5TB Up to 3TB

Usable Capacity (Before Dedupeand Compression)

XS, S, M, L, XL3, 6, 11, 16, 32 TB

x6, x8, x12, x167.5, 10, 15, 20 TB

20 TBx4, x6 SSD4.6, 7.5 TB

x6 SSD7.5 TB

25 TB

Storage Configuration

5x 960 GB to 12x 3.84 TBAll Flash

6 to 16x 1.92 TB SSDAll Flash

4x 1.92 TB SSD & 20 x 1.2 TB HDD

4x or 6x1.92 TB SSDAll Flash

6x 1.92 TB SSDAll Flash

4x 1.92 TB SSD & 8 x 4.0 TB HDD

Page 38: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Engage with HPE Storage

hpe.com/simplivity

@HPE_SimpliVity

facebook.com/HPESimpliVity

search HPE Technology

CONFIDENTIAL | AUTHORIZED HPE PARTNER USE ONLY 38

THANK YOU

a00005881enw

Page 39: System Source Pizza Webinar - “Recover from Ransomware in 60 … · 2020. 7. 23. · System Source Pizza Webinar - “Recover from Ransomware in 60 Seconds” –7/16 Dennis Kloster

Kindly complete the survey at the end of this webinar. We will use your feedback to help us improve.

THANK YOU!

For Webinars - only