Two Problems, One Solution: What Enterprise Data Backup and Recovery Really Asks of an Organization

Written by David Kramer, Windval Principal Architect


Most enterprise data backup and recovery (DBR) programs do not begin as backup programs. They begin as cost problems, or sprawl problems, or as the aftermath of a security event. Where they begin shapes who sponsors them, how they are funded, and which stakeholders show up to the first meeting. What it does not change is where they have to end up.


For one of our Fortune 200 clients, their data backup and recovery program began the way that many do — as a technical debt conversation inside of infrastructure and engineering. Eight tools. No single control plane. Rising costs, rising complexity, and no clean answer to the question of what happens when something has to be restored under pressure. Windval was engaged to help frame the problem, develop the initiative, and craft the path to implementing a modern data backup and recovery solution. Our tailored approach, rooted in technical depth and cross-organization communication, serves as a blueprint for others to follow when developing an enterprise grade cyber resiliency program.

If your organization is in thinking about launching or in the beginning phases of a cyber resiliency or data backup and recovery initiative, consider lessons learned from our past engagements and the best practice recommendations from our front-line teams to set your program up for success.

The insight most organizations miss…

If there is one concept to remember when taking on a new cyber resiliency initiative, it is this one:

At the core of cyber resiliency, we’re talking about building a system to recover from security risks and ransomware — building a storage solution for a security problem. When designing that storage solution however, we must be aware of other operational or financial challenges a new architecture can solve for. It is important to bring a holistic, cross-domain view to architecture design for the full value of modern data backup and recovery solutions to be realized.

What to get ahead of…

For organizations planning to deliver a new data backup and recovery solution or are in the beginning phases of a cyber resiliency program:

  1. Validate the initiative drivers from all directions. Whether the initiative originates in infrastructure, security, or the business, it will ultimately have to satisfy all three. Interview all three at the start rather than discovering their requirements at design review.

  2. Establish common language before vendor selection. If the business, engineering, and operations cannot state the objectives in the same words, no vendor evaluation will produce agreement.

  3. Separate the two problems early. Operational recovery and cyber recovery are distinct risk problems that share an architecture. Naming that distinction up front prevents months of circular design debate.

  4. Sequence against cost and rework, not just priority. The most business-critical workload is not automatically the first workload.

  5. Plan for organizational change. Assume the sponsors, managers, and engineers at the end of the program are not the ones who started it, and design your program communications accordingly.

Next
Next

Governing the new frontier, building the infrastructure for AI at scale