『The Backup Wrap-Up』のカバーアート

The Backup Wrap-Up

The Backup Wrap-Up

著者: W. Curtis Preston (Mr. Backup)
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
Formerly known as "Restore it All," The Backup Wrap-up podcast turns unappreciated backup admins into cyber recovery heroes. After a brief analysis of backup-related news, each episode dives deep into one topic that you can use to better protect your organization from data loss, be it from accidents, disasters, or ransomware. The Backup Wrap-up is hosted by W. Curtis Preston (Mr. Backup) and his co-host Prasanna Malaiyandi. Curtis' passion for backups began over 30 years ago when his employer, a $35B bank, lost its purchasing database – and the backups he was in charge of were worthless. After miraculously not being fired, he resolved to learn everything he could about a topic most people try to get away from. His co-host, Prasanna, saw similar tragedies from the vendor side of the house and also wanted to do whatever he could to stop that from happening to others. A particular focus lately has been the scourge of ransomware that is plaguing IT organizations across the globe. That's why in addition to backup and disaster recovery, we also touch on information security techniques you can use to protect your backup systems from ransomware. If you'd like to go from being unappreciated to being a cyber recovery hero, this is the podcast for you.All rights reserved
エピソード
  • Endpoint Hardening: Closing Windows Before Somebody Climbs In
    2026/09/21

    Endpoint hardening is the unglamorous work of closing the windows and locking the doors before somebody comes along and jiggles the handle. Prasanna, Dr. Mike Saylor and I walk through what that actually looks like: secure builds and golden images, which services to shut off, which ones to uninstall so a bad guy can't just switch them back on, USB lockdown, full disk encryption, BIOS and UEFI, and the phone in your pocket that logs onto your corporate Wi-Fi every morning.

    Mike opens with the analogy he uses in the book. Bad guys casing your organization are doing what a burglar does walking down your street — checking every door, every window, every garage. An unpatched box screaming its version number to the internet is a broken window with a sign on it.

    Then we get practical. Your receptionist's computer is running a web server she will never use. Your new Dell shipped with Xbox Game Bar running by default. Mike's point is that turning those off isn't enough, because an attacker living off the land will just turn them back on. Uninstall the thing.

    We also get into the argument nobody wins: locking down USB ports. Prasanna makes the end-user case, Mike makes the red team case, and we land on data leakage controls as the middle ground. Then Mike explains how he gets into a laptop that's suspended instead of logged off, and why your encrypted drive doesn't help you in that state.

    If you've been told you should harden your endpoints and nobody ever handed you the list, this one's for you. Start with one image, the lowest common denominator, and build from there. Don't let perfect be the enemy of good.

    CHAPTERS

    00:00 Your receptionist's computer is running a web server

    01:39 Welcome, with Prasanna and Dr. Mike Saylor

    03:52 The house analogy: broken windows and unlocked doors

    06:22 Do you just have to be safer than your neighbor?

    08:49 Assume breach, and close the windows anyway

    09:52 Secure builds and golden images

    13:37 One image for everyone, or one per role?

    14:39 Level one hardening: turning off what nobody uses

    16:20 Xbox Game Bar, and why disabling isn't enough

    19:07 The USB lockdown fight

    22:46 BIOS, UEFI, and malware that survives a reimage

    26:35 Full disk encryption only works if you log off

    29:42 Physical access trumps everything

    30:07 Port scans, Nmap, and banner grabbing

    31:50 Building your hardening checklist

    33:14 The endpoint in your pocket

    続きを読む 一部表示
    38 分
  • Least Privilege Best Practices: Where to Start
    2026/09/14

    Least privilege best practices start with one uncomfortable question: does this person actually need this access? A hospital in Portugal answered yes for everybody, gave every employee doctor-level access to patient records, and got hit with a 400,000 euro GDPR fine. The court's read was that they hadn't even attempted the concept.

    Mike Saylor, Prasanna, and I get into what least privilege really means, then move straight to the part nobody wants to talk about: where you start when everybody already has domain admin. Mike lays out three approaches, from "turn everything off and see who screams" to a real analysis of job roles. We talk about why role-based administration is the vehicle that gets you there, and why role sprawl will eat you alive if you build a custom role for every human in the building.

    From there we get into segregation of duties, which accounting figured out decades before IT did. Your admin account should not be the account you use to check Gmail. That leads into non-repudiation, su versus sudo, and why logs have to leave the box and land in a SIEM before somebody edits them.

    The last third is action items. Inventory your privileged accounts, your service accounts, your support accounts, and the fire call accounts you break glass for. Track more than the name and the privilege level: who owns it, why it exists, when the password changed, when it expires. And if you run backups, split your roles apart. Editing backup configs, running backups, and doing restores should not be the same permission. Somebody quietly shortening retention is invisible to the person watching last night's job reports. A restore never trips an alarm at all.

    If your admins fight you on any of this, Mike has a thought about that too.

    00:00 The hospital where the janitor could read your chart

    04:26 The 400,000 euro fine, and the failed appeal

    07:50 What least privilege actually means

    08:54 Three ways to start when everyone has too much

    11:17 Access that follows people as jobs change

    12:57 Role-based administration is the vehicle

    16:13 Role sprawl and the 80/20 rule

    18:26 Segregation of duties, borrowed from accounting

    20:28 Back when everybody had root: su and sudo

    21:59 Non-repudiation and getting logs into a SIEM

    25:31 Inventory privileged, service, and fire call accounts

    27:41 The three backup roles you should separate

    32:39 What your account inventory should track

    35:31 Expiring accounts nobody uses

    36:42 When admins push back, be concerned

    続きを読む 一部表示
    39 分
  • Password Length vs Complexity: Why Longer Always Wins
    2026/09/07

    Password length vs complexity isn't a close call. Dr. Mike Saylor joins Curtis and Prasanna to explain why the capital letter, the number, and the special character your bank demands do less for you than simply adding characters.

    Mike walks through the rainbow table project — an operation that has spent years computing password hashes nonstop and will sell you 20 terabytes of the results. Nobody cracks your password. They look it up. The catch, and the whole reason this episode matters, is that the project has only reached ten characters after all that work.

    The three also cover why some LastPass customers had their vaults drained and others didn't, where the 16-character recommendation comes from, how to build a passphrase you'll remember, whether forced password rotation accomplishes anything, and what happened when Mike rolled out fingerprint-locked laptops to fifty field employees.

    Get the book: Learning Ransomware Response and Recovery at stopransomware.com

    続きを読む 一部表示
    33 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません