<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ransomware and Disaster Recovery in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51302#M3540</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could use this type of approach, whereby in this case IBM Security and IBM Storage came together and offered a different approach to tacking the issue cited "Ransomware".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=oZUtqfZbpuA" target="_blank" rel="noopener"&gt;https://bit.ly/3N8o54b&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=oZUtqfZbpuA" target="_blank"&gt;https://www.youtube.com/watch?v=oZUtqfZbpuA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;The video explores IBM's Synergy between IBM Security and Storage products. Using IBM Flash-systems' Safe Guard Copy functions, along with QRadar and SOAR, this video shows how QRadar - SIEM will alert to a cyber attack, and then immediately launch SOAR to remediate using various automation tools, leveraging the Immutable snapshots on the Flash-system, testing and validating them, and then finally restoring one to the production server, with a full restart. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;A useful and innovative method.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Caute_Cautim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 19:52:54 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2022-05-31T19:52:54Z</dc:date>
    <item>
      <title>Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51167#M3513</link>
      <description>&lt;P&gt;When we hear of an organisation crippled by a ransomware attack - what if it had been hit by a natural disaster, terrorism, or some other threat? Does this mean that it had no functioning disaster recovery plan, or am I being naive? Crafty ransomware may introduce gradual data corruption over time to confound backups, but this seems to be the exception.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:11:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51167#M3513</guid>
      <dc:creator>gidyn</dc:creator>
      <dc:date>2023-10-09T10:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51172#M3514</link>
      <description>&lt;P&gt;I don't think you are being naïve.&amp;nbsp; I believe that anyone who has a plan will try to kick it into play, however, most plans are written for the natural disaster, etc. and someone is going to have to adjust.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Through time, we have seen many stories of companies spending $$$$ to replace equipment, find good backups (that is if they have them) and eventually restore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With other threats, there may be less real-time data loss........not always true but with Ransomware like any virus, etc, it may not be possible to restore as rapidly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a great article from Forrester on Ransomware and DR/BCP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://info.cohesity.com/rs/103-SPE-204/images/Forrester%20Ransomware%20Recoverability%20Must%20Be%20A%20Critical%20Component%20Of%20Your%20Business%20Continuity%20Plans.pdf" target="_blank"&gt;https://info.cohesity.com/rs/103-SPE-204/images/Forrester%20Ransomware%20Recoverability%20Must%20Be%20A%20Critical%20Component%20Of%20Your%20Business%20Continuity%20Plans.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Smaller and mid-size companies may or may not have embraced DR/BCP as yet but many are starting to pick up the ball.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, long winded reply to say you are not naive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 14:01:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51172#M3514</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2022-05-24T14:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51175#M3515</link>
      <description>&lt;P&gt;Not so much naive but realistic. For most organizations ransomware should be treated as a natural disaster, even if man-made.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BCP/DRM has for whatever reason faded into the background these past few years, perhaps because it doesn't sound 'cyber' or sexy enough to bother. Not sure. Nonetheless ransomware must be tied back to BCP/DRM either way or suffer the consequences.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- B/Eads&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 15:27:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51175#M3515</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2022-05-24T15:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51296#M3538</link>
      <description>&lt;P&gt;They&amp;nbsp; are just stupid. They think that having a BC plan is enough.............if they have one. A regular test of your BC plan is as important as having one. People forget updating the BC plan when changes are made.&lt;/P&gt;&lt;P&gt;Other factor is when you forget about the dependencies of your system and there is no plan for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:31:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51296#M3538</guid>
      <dc:creator>ElviaB</dc:creator>
      <dc:date>2022-05-31T15:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51300#M3539</link>
      <description>&lt;P&gt;Stupid is a bit much but I enforce my BCP/DRM plans by policy statement and audit. This way what you refer to as "stupid" becomes the law of the land and is enforceable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depends a bit more on your industry now doesn't it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- B/Eads&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 19:10:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51300#M3539</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2022-05-31T19:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51302#M3540</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could use this type of approach, whereby in this case IBM Security and IBM Storage came together and offered a different approach to tacking the issue cited "Ransomware".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=oZUtqfZbpuA" target="_blank" rel="noopener"&gt;https://bit.ly/3N8o54b&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=oZUtqfZbpuA" target="_blank"&gt;https://www.youtube.com/watch?v=oZUtqfZbpuA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;The video explores IBM's Synergy between IBM Security and Storage products. Using IBM Flash-systems' Safe Guard Copy functions, along with QRadar and SOAR, this video shows how QRadar - SIEM will alert to a cyber attack, and then immediately launch SOAR to remediate using various automation tools, leveraging the Immutable snapshots on the Flash-system, testing and validating them, and then finally restoring one to the production server, with a full restart. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;A useful and innovative method.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Caute_Cautim&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 19:52:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51302#M3540</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-05-31T19:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51314#M3541</link>
      <description>&lt;P&gt;All you could also read the definitive guide to Ransomware in 2022 and then circulate it to raise awareness.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the basis that if someone needs it they will read and apply it, hopefully before the action takes place and not after the event!!&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 22:49:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51314#M3541</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-06-01T22:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51443#M3542</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good sharing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, as an ex-IBMer, I really doubt IBM's &lt;SPAN&gt;innovation&lt;/SPAN&gt;&amp;nbsp;and execution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As IBM storage brand (tech sales) always selling dreams (things are too good on paper and only work on paper) but eventually is a lab's alpha or it's just some GTS (now is call split off as kyndryl) offering (meaning a lot of hard work on integration specialist writing custom script to make the "product" to work).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 20:04:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51443#M3542</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2022-06-08T20:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51467#M3543</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1424597851"&gt;@csjohnng&lt;/a&gt;Definitely some bad feelings or blood there.&amp;nbsp;&amp;nbsp; It definitely works, in production and not just a pipe dream.&amp;nbsp;&amp;nbsp; There have been a great deal of changes, chaotic at time, but it has come along way from the Red Books and has been turned into a reality.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen other techniques, but I just wanted to illustrate one method of recovering from Ransomware attacks.&amp;nbsp;&amp;nbsp; Now the industry feeling is that Ransomware is running out of puff, and BEC attacks are becoming more sophisticated and likely to be the next battleground.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jun 2022 01:19:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51467#M3543</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-06-11T01:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51490#M3545</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, there are good and bad within IBM. I don't really have bad feeling about IBM, but just sad to see it's falling ranks from the fortune 500 years after years.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are great time in my early career with IBM and definitely blood and sweats as well in making things work in IBM. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I still love and miss IBM's value of dedication to client success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recall there was call for invitation on writing the Redbook 15 years ago, ( we called red residency). Eventually I did not apply the red residency. I still recall it's a top priority within IBM in the old days because the redbooks benefit so many customers and IBMers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When IBM release product (esp new ones), it really took individual specialist (old day I was also GTS) to write the redbooks ( not the manual)&amp;nbsp; because the products (developed by those "lab" people) are really so "unfriendly", "sophisticated" and even "unknown" to internals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But anyway, good sharing and glad if that works, I hope there are still good talent and great vision in the IBM distinguish Engineers-DEs and as well as their senior executives&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 07:28:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51490#M3545</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2022-06-13T07:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware and Disaster Recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51590#M3547</link>
      <description>&lt;P&gt;HI &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1424597851"&gt;@csjohnng&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Yes, I was in GTS for years, before I moved out and joined the 9,000 IBM Security Business unit and have not turned back since then.&amp;nbsp; Since then I have become the ANZ Architecture Practice Leader for my sins etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, things are changing from the GTS to Kyndryl split.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IBM Garage - Co-Create, C-Execute, Co-Support is changing a lot of approaches by using a Minimum Viable Product (MVP) which means workshops are taken with the clients, and they state what is it that concerns them, rather than having ease it out of them over a period of time etc.&amp;nbsp;&amp;nbsp; A lot of this was due to the Pandemic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it has become a lot more collaborative and innovative, through ensuring that idea will work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been here for over 20 years, and I am still enjoying it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 23:22:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Ransomware-and-Disaster-Recovery/m-p/51590#M3547</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-06-16T23:22:46Z</dc:date>
    </item>
  </channel>
</rss>

