The Difference Between Backup and Disaster Recovery

We’re all familiar with the value of making a backup of business data, but how does this fit with ‘Disaster Recovery’ and ‘Business Continuity’ strategies?  This article takes a brief look at how these elements fit together to ensure that businesses can survive, function and get back up to speed when disastrous events (external or internal) pose a serious threat.

Reality

Normal life rules apply to the business environment i.e. things can and do go wrong, and backup and disaster recovery are both based upon this understanding.

Business continuity in the event of a ‘disaster’, is about making sure that your essential operations and core business functions can keep running while the repairs can be made that get you back up to speed.

What Could Go Wrong?

There is a potentially huge range of ‘disasters’ that businesses could make plans to be able to overcome, and even though organisations come in different sizes and have different budgets, the risks they face are generally the same.  Typically, the more obvious ‘disaster’ threats the business include:

  • Hardware failures/server failures.
  • Outages and/or file corruption
  • The effects of cyber-attacks.  For example, 53% of senior managers believe that a cyber-attack is the most likely thing to disrupt their business (Sungard AS 2019) and the effects could include damage to / locking out of systems (malware and ransomware), fraud and extortion, data breaches (which could also attract fines under GDPR, damaging publicity and loss of customers).
  • Environmental/natural disasters e.g. fire and flood.
  • Important 3rd supplier failure or the loss of key employees.
  • Failures of part / a component of a network e.g. as highlighted by recent problems with banking and airline industry services.
  • Theft or loss of equipment holding company data.

Backing Up Your Data – Where To Store It

When it comes to backups, security, integrity, cost, scalability, complying with legislation, your own business plans, and ease of daily use are all considerations.  Where / how to store backed-up data is a decision tackled differently by different companies.  In the UK, GDPR (the data protection regulations) should be taken into account in these decisions.  Places to back up data could include:

  • On-site – storing data in the same location e.g. on an external hard drive in the workplace.  Although the data backup is close to hand, this is not a particularly secure solution and in the event of flood/fire/theft disasters, your data would be gone.
  • Off-site – taking the data away on a hard drive or another physical storage medium.  This means it’s less at risk from local issues (e.g. loss, theft, damage) but may could mean it takes longer to restore data .
  • Online – backing up your data on hosted servers (in the cloud) and accessing them through an application. This is now becoming the preferred method for most businesses as it is convenient and fast (if you have an Internet connection) and it cuts out many of your on-site potential disaster risks (fire, flood, loss and damage of physical storage media).

Some businesses prefer to use a ‘hybrid’ cloud backup to help address any vulnerabilities that cloud-only or local-only backup solutions have.

There are many dedicated online backup solutions available e.g. IDrive Business, Backblaze Business, Carbonite Safem, or larger solutions for businesses with much bigger data backup requirements.

Backup Decisions

Taking regular, secure backups of your business data is an important part of good practice.  It is also an important element of disaster recovery and the business continuity process.

There are several types of backup that businesses need to make decisions about.  These include whether, if/when and how to make:

  • A full backup – one that covers every folder and file type and typically takes a long time.
  • An incremental backup – the first back up is a full one, followed by simply backing up any changes made to the previous backup.
  • A differential backup – similar to an incremental backup, requires more storage space but has a faster restore time.
  • A mirror backup – an exact copy of your data that has the advantage of removing the obsolete files each time.
  • An Image-based backup – captures images of all data and systems rather than just copying the files.
  • A clone of your hard drive – similar to imaging and creates an exact cloned drive with no compression.

In reality, many businesses make use of many different types of backup solutions at the same time.

Business Continuity, Backup Decisions and Disaster Recovery

Accepting that disasters happen and that you can plan how to maintain business continuity while you deal with them (using a disaster recovery plan) is an important step in safeguarding your business. Maintaining the ability to ensure that core functions and critical systems remain in place in the event of a disaster (business continuity) involves planning, an important part of which is the disaster recovery plan (DRP).  Creating this plan is usually an interdepartmental process, which is often led by information technology.

RTO & RPO – Linking Backups To Your DRP.

There are two metrics you can use to help you to make data backup decisions that relate to your DRP.

The Recovery Time Objective (RTO): the recovery window / how long (time) the business realistically has to recover from a disaster before there are unacceptable consequences.

The Recovery Point Objective (RPO): how far back (the maximum tolerable period of time) your organisation needs to go in recovering data that may have been lost due to a disaster.

By working out these time periods (particularly RPO), it can help you to decide upon the frequency of backups, which backup methods are most suitable and preferable to you e.g. the need to go back longer periods may favour online backups, and businesses with  large quantities of valuable historic data may struggle with a short RTO (which may require tiered data recovery).

In today’s business environment it is worth bearing in mind that your customers are not likely to be very tolerant of downtime, so recovery windows now need to be as short as possible. Many businesses, therefore, simply opt for a daily backup.

Disaster Recovery Plan

At the heart of your business disaster recovery strategy should be the disaster recovery plan (DRP) which should provide step-by-step workable instructions to ensure a fast recovery.  A DRP should be tested and kept up to date to ensure that it will work in reality in the event of a disaster and typically includes elements like:

  • A plan for roles and communications, detailing employee contact information and who’s responsible for what following the disaster.
  • A plan to safeguard equipment e.g. to keep it off the floor, wrapped in plastic away from flooding.
  • A data continuity system that details what the business needs to run in terms of operations, finances/accounts supplies, and communications.
  • Checking that your data backup regime is working, and that very recent copy is stored in a secure place but would be easily and quickly accessible when needed.
  • An asset inventory, including photos where possible, of the hardware (workstations, printers, phones, servers etc) reference for insurance claims after a major disaster.
  • Keeping (up to date) documentation that lists all vital components of your IT infrastructure, hardware and software, and a sequence of what needs to be done to resume business operations with them.
  • Photos showing that the hardware was in use by employees and that care had been taken to minimise risk e.g. items were off the floor (e.g. to avoid flood damage).
  • A supplier communication and service restoration plan so that you quickly restore services and key supplies after the disaster.
  • Details of a secondary location where your business could operate from if your primary location was too badly damaged in a disaster.
  • Details of the testing, optimisation and automation of your plan to ensure that it could be implemented quickly, as easily as possible, and free from human error.

Putting The Pieces Together

The basic difference between a backup and disaster recovery, therefore, is that a backup is having a copy of your data, and disaster recovery is the whole strategy to recover your business operations and essential IT environment in the event of a serious event e.g. cyber-attack, equipment failure, fire or flood.

Creating a DRP involves completing a risk assessment and business impact analysis in order to identify critical applications and services, and it is from here that your business can then create its own tailored RTOs and RPOs which in turn, will link to your backup strategy and cycles.

Backups are essential files that enable a full restore, and as such are an important element of ongoing good practice and of your DRP, and your backup should relate strongly to the underlying strategy of disaster recovery.

One thing is certain about backup and disaster recovery which is that having no plan for either is means planning to fail.

Quickly Re-Open a Closed Tab

If you have several tabs open on your browser and you accidentally close an important tab, there is and fast and easy way to re-open it.

To re-open an important tab that you’ve accidentally closed:

– Press command+shift+t on a Mac or control+shift+t on Windows PC.

– Voila! Your tab will then be restored.

Windows Still Need Some Work on Tesla’s New “Cybertruck”

Tesla’s Elon Musk proudly launched the new ‘Cybertruck’ in front of the world’s media last week, only to find that the distinctly breakable difficult-to-break windows were the main focus of media reports.

Cybertruck

The new Tesla all-electric Cybertruck is a futuristic pickup truck / armoured vehicle which will not be manufactured until late 2021 and will retail for between $39,000 and $76,900.  The Tesla website claims that the Cybertruck features “a nearly impenetrable exoskeleton” and that all of the components are “designed for superior strength and endurance”.  For example, the truck features an “Ultra-Hard” 30X Cold-Rolled stainless-steel structural skin and armour glass (toughened glass).  The smooth steel shell is intended to resist dents, damage and long-term corrosion as well as providing added safety to the truck’s occupants.

Features

Tesla says that the new Cybertruck can accelerate from 0-60 mph in only 2.9 seconds, has up to 500 miles of range (thanks to improved Tesla batteries),  a 3,500 pounds of payload capacity, offers 100 cu ft of “vault-like” storage, has adaptive suspension, and can seat six comfortably.

In addition to the futuristic exterior, the ‘cyber’ aspect of the truck appears to be focused around the 17” touchscreen with a new customized user interface.

That Glass Incident

The embarrassing aspect of the launch that international media outlets chose to focus on was when Tesla’s head of design, Franz von Holzhausen attempted to demonstrate how strong the window glass on the Cybertruck was by throwing a heavy metal ball at two different windows, only to find that both broke (although the ball didn’t end up inside the vehicle in either case).

Orders

Elon Musk tweeted on the Sunday after the Cybertruck’s (Thursday) launch that there had already been 200,000+ orders of the vehicle (with no advertising), but this figure appears to relate to pre-orders of the not-yet manufactured vehicle involving a commitment from potential customers of only $100 deposit (fully refundable).  As any car salesperson could tell you, the small deposit coupled with the long wait for manufacture may be unlikely to produce anywhere near the same number of actual sales as pre-orders.

What Does This Mean For Your Business?

There is no doubt that the major car manufacturers are committed to producing electric cars, and Tesla has achieved a great deal in establishing itself as a major player in this market, particularly with its Model 3. Much of the media attention for Tesla, however, has focused on the claims and behaviour of its charismatic leading light and often double-edged sword Elon Musk, who appears to be no stranger to controversy e.g. when he was sued by (and settled with) The US Securities and Exchange Commission for a “false and misleading” tweet about his plans for Tesla that was thought to have upset the market and investors.

Unfortunately, unpredictable and embarrassing events at the launch appear to have slightly overshadowed many of the positive aspects of the Cybertruck. Sir James Dyson also found that his ambition in the electric car market didn’t live up to reality as Dyson recently had to scrap its £2.5 billion ‘N526’ electric car project with Sir James Dyson announcing that it was “not commercially viable”.  It remains to be seen if Tesla’s Cybertruck can achieve the same levels of popularity and approval as its Tesla 3 model.

5G Mobile Network is 450% Faster Than 4G in Tests

Tests by Ookla, the developer of Speedtest.net, are reported to have shown that the new 5G mobile network is 450% faster than 4G.

Speed

According to the Speedtest.net website, the results of the testing of 5G in 29 UK cities during Q3 of 2019 generally show download speeds as being 450-475% faster than those on all mobile technologies combined, and that the 5G download speed in Northern Ireland showed a 618.3% improvement due to the fact that mean mobile download speeds on all technologies are slower in Northern Ireland than elsewhere in the U.K.

The tests also revealed that mean 5G download speeds are uniformly high across the U.K., with only 6 Mbps difference between the fastest country (England) and the slowest (Northern Ireland).

Availability

Speedtest.net says that mobile operators have embraced 5G across the UK this year.  For example, 5G is now commercially available in 22 English cities such as London, Birmingham, Bristol, Liverpool, Manchester and Wolverhampton.

5G is also now available in Edinburgh, Glasgow and Paisley in Scotland, in Belfast in Northern Ireland, and in Cardiff, Llandudno and Penarth in Wales.

Rankings

In terms of ranking operators in terms of their 5G download speed in the UK during Q3 2019, Speedtest.net put EE in first place, O2 in second and Vodafone in third place.

No Three

The Speedtest.net results and analysis didn’t include Three because they currently only offer 5G broadband in certain districts of London and their 5G has not yet been launched.

Three announced earlier this year, however, that new and existing customers with compatible handsets will be able to get 5G at no extra cost(s) when its 5G service is launched.

Upload Speeds Not As Impressive

The test results showed, however, that 5G upload speeds, although good, were not quite as impressive as the download speeds with percentage increases ranging from 38.5% to 110% faster.

Safety Concerns

One issue not covered by the testing was the safety fears surrounding 5G. For example, 5G uses 3 Spectrum bands, low-band spectrum (LTE), mid-band spectrum, and what some believe to be the potentially dangerous mmWave high-frequency spectrum.

The mmWave spectrum, however, is still not close to the kind of ionising wavelengths that can cause damage to DNA and mmWave will mostly be deployed in a spectrum that suffers from high reflection rates – 24 to 29GHz.  This should mean that any absorption by the body will be confined to the surface layers of the skin rather than the deeper tissue that is reached by lower frequency radiation.

What Does This Mean For Your Business?

Ofcom is due to auction additional spectrum for 5G in the 700 MHz and 3.6-3.8 GHz bands in spring 2020 and this should help fuel the further expansion of the 5G networks.  This is likely to be good news for businesses who have been waiting for the speed benefits that 5G can bring, for example in improving file sharing and other communication capabilities.

Although the rollout is currently only confined to major UK cities, which will, of course, favour businesses in those areas, it is good news that 5G has been achieving consistent speeds in its deployments around the world, thereby improving on one of the challenges of 4G.

Different operators look set to take different approaches to their 5G rollouts and offerings, and greater 5G availability will provide a boost to the sales of new generation mobile handsets in the UK where many people and businesses have been holding back on purchasing the latest 5G models until they could reap the benefits of having a much more established 5G network in place.

Uber Loses London Licence

A decision by Transport for London (TfL) means that ride-hailing service Uber has lost its licence to carry passengers in London over safety and security failures.

Why?

According to TfL, it had identified a pattern of failures by Uber, including breaches that had risked the safety of passengers and drivers, plus some uninsured journeys.

Prior to the decision to remove its London Licence, Uber had pledged to improve its drivers’ safety training and provide a direct connection to emergency services.

Not The First Time

Uber had its London licence removed before by TfL back in 2017 after it was decided that the company was “not fit and proper” following security issues, public safety issues, poor reporting (of serious in-car crimes), poor medical checks (of drivers) and poor background checks (of drivers). Uber’s controversial founder and CEO Travis Kalanick had already resigned (in June 2017) amid rumours that he had possibly been “pushed” by unhappy shareholders.  Mr Kalanick was replaced by Dara Khosrowshahi.

In 2018, Uber was only given a probationary 15-month license in London following changes made to improve relations with city authorities and had most recently (September) only been granted only a two-month license, which is the licence that is now about to be allowed to expire.

Black Cab Battle

Uber has not had an easy ride in London from its competitors, the drivers of the famous black cabs. The 22,000 traditional “cabbies”, who are required to pass the notoriously difficult memory test of the city’s road network known as “the Knowledge” in order to pick up passengers have objected (many would say understandably) to the loss of business as a result of having to compete with a growing number of Uber drivers who don’t face the same costs or regulations, and who don’t take the same test, and who can rely on satnav apps.

Carry On and Appeal

It has been reported that although the decision to remove the London licence has been taken, Uber will appeal and it is likely that its 45,000 drivers in London may decide to keep accepting customers until the long process of the appeal has been considered.

Trouble Around The World

It’s certainly not just the UK where Uber has found itself facing legal challenges in recent years.  For example:

In the US, in March, the company had to pay $20 million in settlement of a lawsuit brought by drivers who claimed they were employees and were therefore entitled to some wage protections. Also, in November, Uber unsuccessfully challenged a city law which limited the number of licenses for ride-hailing services.

In Australia this year, the company faced a class action on behalf of thousands of drivers who alleged that Uber was operating illegally and harming them financially, and back in December 2018 in Germany, Uber’s limousine service (stopped in 2014) was ruled to have been illegal. Uber has also faced legal problems in the Netherlands, India, and Austria.

Other Woes

Back in November 2017, Uber was handed a £385,000 fine by the ICO in the UK for data protection failings during a cyber-attack back in 2016 which involved the compromising (and theft) of data relating to 600,000 US drivers and 57 million user accounts.

Also, back in May, Uber’s trading debut at the New York Stock Exchange (NYSE) proved to be somewhat underwhelming when the opening share price was much lower than had been expected at only $45 per share.

Move to Bikes and Scooters

In August 2018, Uber announced a shift in focus towards bikes and scooters in order to drive growth and keep people using the platform. It was thought that bikes and scooters would be more effective and efficient than cars in congested city areas, could represent a way to get another slice of the lucrative mobility market, and that they could be used to help shape consumer behaviour and keep levels of engagement high.

Popular With Users

It has to be said that despite Uber’s problems with the authorities and London cabbies, the service has been popular with many users having positive things to say about the convenience of the app, Uber prices and the speed of the service.

What Does This Mean For Your Business?

Uber had already been on borrowed time in London after finally being granted a two-month licence (following on from just a 15-month probationary one).  Uber’s relationship with the UK authorities and Mayor Sadiq Khan, who had accused Uber as adding to the city’s congestion problems, has been on the edge for quite some time, and it appears as though Uber may not have made the changes that it had pledged to make in order to retain its licence.  The appeal may take a few months, so it is likely that Uber drivers will simply carry on for the time being.

For users it may come as a disappointment that a service that they found to be very convenient will soon no longer be available but it may be the case that a new London Mayor after May 2020 could take a different approach towards Uber.  For example, some Uber drivers have expressed the belief that Mayor Khan may be pandering too much to the black cabbies, and a hopeful future mayor candidate, Shaun Bailey (Conservative) has expressed regret over TfL’s decision to not grant another licence to Uber.  For the time being though, it’s a waiting game in London for Uber.

Google Or Samsung Android Cameras Could Be Spying On You

Researchers at Checkmarx say they have discovered vulnerabilities in Google and Samsung smartphone apps that could allow hackers to remotely spy on users using their phone’s camera and speakers.

Study

The proof-of-concept (PoC) study results, highlighted on the Checkmarx blog reveal how the Checkmarx Security Research Team cracked into the apps that control android phone cameras (firstly using a Google Pixel 2 XL and Pixel 3) in order to identify potential abuse scenarios.

The team reported finding “multiple concerning vulnerabilities” (CVE-2019-2234) which stemmed from “permission bypass issues”.  The team later found that camera apps from other vendors i.e. Samsung are also affected by the same vulnerabilities.

The Checkmarx team have since shared a technical report of their findings with Google, Samsung, and other Android-based smartphone OEMs to enable those companies to find fixes.

What Could Happen?

According to Checkmarx, the vulnerabilities mean that a hacker could use a rogue application (that has no authorised permissions) to take control of another person’s Android phone camera app.  This could allow the attacker to take photos and/or record videos as well as to gain access stored videos and photos, GPS metadata embedded in photos, and even to locate the user by taking a photo or video and parsing the proper EXIF data.

The researchers also found a way to enable a rogue app to force camera apps to take photos and record video even when a phone was locked or the screen is turned off, or when a user was is in the middle of a voice call.

One particularly worrying aspect of the Checkmarx findings is that if the video can be initiated during a voice call the receiver and the caller’s voices can be recorded.  This could allow eavesdropping that could enable an attacker to discover potentially sensitive personal data or to gather information that could be used for extortion.

Google

According to Checkmarx, after they shared their findings with Google, the Checkmarx team were notified by Google that the vulnerabilities weren’t confined to the Google Pixel product line but also extended to products (Android) by other manufacturers.  For example, Samsung also reportedly acknowledged that the flaws impact their Camera apps and said that they had begun taking mitigating steps. Checkmarx reports that Google has said that the problem has now been addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. Also, a patch has been made available to all Google partners.

What Does This Mean For Your Business?

It is very worrying that hundreds-of-millions of smartphone users may have been facing a serious privacy and security risk without being aware of it.  For business users, this may have left them open to industrial espionage and security threats, although there is no evidence that real hackers have exploited the vulnerabilities prior to them coming to light.

When it comes to smartphone apps, the best practice is to ensure that all apps on your device are kept updated. Other defensive actions you can take regarding your phone apps include checking the publisher of an app, checking which permissions the app requests when you install it, and deleting any apps from your phone that you no longer use.  It’s also now important to be aware of the threat posed by fake apps, and you may wish to contact your phone’s service provider or visit the high street store if you think you’ve downloaded a fake malicious/suspect app.

Each week we bring you the latest tech news and tips that may relate to your business, re-written in an techy free style. 

Archives