The Impact of Backup Strategy on Mitigating Information Incident Damage Part 2
Hello everyone.
I am Murashima, in charge of off-site and cold backup operations at Kachika Co., Ltd.!
It is raining hard at my place again today. They say it wouldn't be surprising if we entered the rainy season just like this. I don't like that.
So, let's start with the usual (or what I'd like to be the usual) unrelated topic.
Suppose there are 7 friendly office workers: A, B, C, D, E, F, and G.
The question of what to eat for lunch came up, and soba, pasta, and ramen were suggested as candidates.
Let's assume their "ranking of what they want to eat" among the 7 is as follows.
A: Soba, Pasta, Ramen
B: Soba, Pasta, Ramen
C: Soba, Ramen, Pasta
D: Pasta, Ramen, Soba
E: Pasta, Ramen, Soba
F: Ramen, Pasta, Soba
G: Ramen, Pasta, Soba
If we ask them to state what they "want to eat the most" in this state, soba becomes the most popular.
However, take a close look. Even if you ask them to state what they "want to eat the least," the result is still soba.
Majority rule has this kind of pitfall. It happens often, doesn't it? When everyone has to decide something, multiple proposals come up, the discussion gets tangled, and in the end, the worst option is chosen...Hey, Chuo City.
Let's learn from incidents and perform effective backups
We looked at various information incidents last time, and I would like to look at the key points of an effective backup strategy by learning from those cases.
Thorough implementation of offline backup (3-2-1 rule)
Modern ransomware attackers, after infiltrating a system, have made it a standard tactic to target the backup data itself for deletion or encryption to make recovery difficult. For this reason, backups that exist only online cannot fully protect data from a chain of attacks.
This is where "offline backup" becomes essential. This refers to a method of storing backup data in an environment that is completely isolated from the system, either physically or logically. As a result, even if an attack spreads throughout the entire system, the backup data remains safe and functions as the last line of defense for recovery. The benefits of offline backup include high security, data reliability, and easy restoration in the event of a disaster or system failure.
The "3-2-1 rule" is cited as an international recommendation for an effective backup strategy. This means keeping 3 copies, saving them on 2 different types of media, and storing 1 of them off-site (in a physically separate location or offline).
By thoroughly implementing this rule, you can eliminate the risk of a single point of failure and build a system that protects data from all kinds of disasters and cyberattacks. As the case of the Okayama Psychiatric Medical Center and reports from the National Police Agency show, the main purpose of attackers destroying backups is to force ransom payments and corner the organization. For this reason,it is extremely important that backups not only copy data but also remain in an "inviolable" state from attackers.Offline backup is the most effective means of physically and logically guaranteeing this inviolability, and it aligns with the concept of "zero-trust backup" against modern cyber threats. Companies should review the priority of their backup investments and strengthen investments in not only online backups but also offline or immutable backup solutions. This is not just a technical requirement, but the final line of defense to protect the business from the threat of ransomware, and it should be positioned as the most important item in management risk control.
Periodic verification of backup data and implementation of recovery tests
Backups are meaningless if you just acquire the data.The most important point is "can it be reliably restored when the time comes?". If the backup data is corrupted or recovery procedures are not established, the backup will become useless. The difficulty of recovery at KADOKAWA and the long-term recovery case at the Okayama Psychiatric Medical Center clearly show that the existence of a backup does not guarantee recovery.
For this reason,periodic integrity checks of backup data and the implementation of recovery tests on the actual system are essential. Through testing, it becomes possible to ensure the reliability of backups and maintain a system that can be recovered quickly in an emergency.Backup and restore are two different processes, and only by testing both can you confirm that "no problems will occur when retrieving data". The true value of a backup lies in the "recovery capability" to return the system to a normal state in an emergency. The fact that data is saved is merely an intermediate goal, and the fact that the data becomes available in a form that actually functions is the essential value for business continuity.
In recovery tests, set a Recovery Time Objective (RTO) and a Recovery Point Objective (RPO), and verify that these goals are achievable. This allows you to measure the degree of achievement of specific goals to minimize losses due to business interruption.Insufficient backup testing can lead to unexpected problems during recovery, prolonged or failed recovery, and significant business losses.Companies should prioritize ease of recovery and the richness of testing functions when selecting backup solutions. Also,testing should not just be a routine task for the IT department, but should involve management as part of BCP, and periodic audits should be conducted, which will improve the crisis management capabilities of the entire organization.
Positioning of backup strategy in Business Continuity Planning (BCP)
Data from the National Police Agency makes it clear that the recovery period and costs from ransomware attacks are greatly influenced by whether or not there is a business continuity plan that assumes cyberattacks.

(Created from "Regarding the Situation of Threats Surrounding Cyberspace in 2024")
https://www.npa.go.jp/publications/statistics/cybersecurity/index.html
As the table above shows,among organizations that required 10 million yen or more and 1 month or more for investigation and recovery due to ransomware attack damage, only 11.8% had a BCP that included cyberattacks in its assumptions. On the other hand,among organizations that recovered in less than 1 week, 23.1% had a BCP that included cyberattacks in its assumptions, showing a clear difference. Furthermore,the percentage of organizations that spent 1 billion yen or more on recovery costs was 3% in the group with a recovery period of "immediate to less than 1 week," whereas it was 14% in the group that "took 2 months or more," a difference of about 4.6 times. This data clearly shows that in cyberattack countermeasures, making efforts to establish a perfect system for both prevention and handling in an emergency will ultimately suppress the organization's financial losses.
Nevertheless,the current situation where more than half (about 50.9%) of organizations damaged by ransomware have not formulated a BCP, and if you include organizations that have formulated a BCP that does not assume cyberattacks, that percentage rises to about 83.6%, shows that many companies are insufficiently prepared for modern cyber threats. Conventional BCPs often assume natural disasters or physical failures, but cyberattacks like ransomware have different characteristics from conventional threats in that they involve data destruction, theft, and system outages. Since BCPs that assume cyberattacks create a clear difference in recovery period and costs,this means that BCP needs to evolve from mere "disaster countermeasures" to "cyber resilience" suited to the digital age. This is an essential requirement for companies to survive in the modern era where cyberattacks have become a major factor directly threatening business continuity. BCP clarifies response procedures, role assignments, communication plans, and recovery procedures from backups in the event of an incident, thereby minimizing confusion and enabling rapid business deployment. Management needs to conduct periodic reviews of BCP and scenario-based training that incorporates the latest cyber threats (especially ransomware), and backup strategy should be positioned as a core element of this cyber resilience BCP.
Coordination between log preservation and backup
It has been confirmed that ransomware groups attempt to erase the logs and backups of victim companies when infiltrating systems. This is a malicious tactic to make identifying attack routes and recovery work difficult, and to force ransom payments.
Logs are an essential source of information for investigating causes, identifying attack routes, investigating the scope of impact, and planning recurrence prevention measures when an incident occurs. If logs are not properly preserved, appropriate measures cannot be taken, increasing the risk of being victimized again.Logs are essential "evidence" in "forensic investigations" after an incident occurs to trace the traces of an attack and elucidate the intrusion route, scope of impact, and the attacker's actions. The reason attackers try to erase these is to make tracking difficult and to hinder the organization's recovery and recurrence prevention efforts.
To protect logs from tampering or deletion, it is also recommended to store them in an offline environment and perform real-time monitoring and aggregation using systems such as Security Information and Event Management (SIEM).While backups are responsible for "data restoration," logs are responsible for "investigating the situation and preventing recurrence".By preserving both in coordination, it becomes possible not only to recover the system but also to clarify the full scope of an incident and fundamentally strengthen security. Failure to preserve logs leads to difficulty in determining causes, an increased risk of recurrence of similar attacks, and the persistence of organizational vulnerabilities. Log management, like backup management, is an important indicator of the maturity of an organization's security posture. Building an appropriate system for log collection, storage, and monitoring is essential for dramatically improving response capabilities during an incident and enhancing defenses against future attacks.
A Perspective on Viewing Backups as the Cornerstone of Business Resilience
As is clear from the cases analyzed above, backups should not be merely a technical issue for the IT department or a cost center, but rather the core of a management strategy that guarantees business continuity and resilience for the entire organization. Given the immense impact that data loss and system outages have on business, it is essential to optimize the balance between advanced security measures as a preventive strategy and robust backup and recovery strategies as a recovery strategy. We must reaffirm that backups serve as the "last line of defense" to quickly resume business when unexpected situations occur and to maintain trust from customers and the market.
The Necessity of Management Involvement and Continuous Commitment
Given the current situation where a lack of BCP formulation that anticipates cyberattacks leads directly to prolonged recovery and increased costs, there is no longer any room for debate regarding the importance of management actively engaging in information security, particularly backup strategy, and continuously investing the necessary budget and resources. As pointed out in the case of the Okayama Psychiatric Medical Center, top-down cultivation of security awareness and commitment to risk management systems are essential for improving the security level of the entire organization. Investment should be viewed not as a mere cost, but as a strategic upfront investment to avoid future losses and ensure business sustainability.
Continuous Awareness Raising and Training for Employees
In many information incidents, in addition to deficiencies in technical measures, cases where human error or a lack of security awareness triggers the accident are frequently seen, such as VPN vulnerabilities and inappropriate granting of administrative privileges (Okayama Psychiatric Medical Center), or malware infection via email (KADOKAWA). An organization's security is determined by its weakest link. Therefore, I emphasize the importance of continuously improving the security awareness and response capabilities of the entire organization through regular security education and training for all employees (phishing training, incident response training, etc.). True resilience is only achieved when both technical and human measures are in place.
So, we have looked at the issues surrounding backup strategy.
Looking at it this way, it becomes clear that backups are reaching a turning point. Until now, "backup" meant copying important data to prepare for human error, but with malware like ransomware entering through networks, natural disasters like earthquakes and heavy rains that are unavoidable in Japan, a disaster-prone country, and other risks that may not yet have surfaced,
we must actively anticipate risks and prepare so that an appropriate backup strategy is always established.
Since the term "zero-trust backup" has also emerged, it can be said that it is necessary to look at an organization's network with the eye of "isn't this part weak?". In other words, it can be said that you should look for weaknesses with the eye of "if I were an attacker."Having said that,
I think the person in charge might be thinking, "I don't know what to do or how to do it". Whether it's ransomware or natural disasters, I think small and medium-sized enterprises are particularly busy and have limited personnel (I apologize if this is an offensive expression).Therefore,
let's first create a system based on the "3-2-1 backup rule". As I have said many times, if you first place backups within your own company (on-premises), use cloud storage as another backup, and then use our off-site backup service, the "3-2-1 backup rule" will have been realized just by that. On top of that, if you introduce things one by one starting from the easy parts, such as BCP formulation and regular restore training, you should surely be able to see a company with robust information security ahead.To repeat, ransomware attackers are currently mainly targeting small and medium-sized enterprises. Based on the fact that there are many small and medium-sized enterprises with insufficient security measures and training, it seems they are attacking where it is easy to attack.
This way of putting it might not be appropriate, but
attackers must be looking for targets with even slightly insufficient measures. If your company takes just one measure, the attacker will likely think, "This is troublesome, let's look elsewhere". With just this, you can break the attacker's desire to "attack this company."In this article, I have talked about various information security measures. It is probably impossible to implement them all at once. That is fine.
Please build up from the point where you think, "This is something we can manage to implement". It has been a long time, but both last time and this time, I have talked about cases that could have been avoided if there had been a backup.Thank you for your time.
And even if it gets long, I'll do it anyway.
It's the corner where we get Gemini to draw a picture. Last time, it drew a picture like this.

The task I gave Gemini was "Draw a picture of Ono no Komachi?"
Hmm, as symbolized by the fact that only her back is drawn in the Hyakunin Isshu, she is a mysterious beauty whose true appearance is unknown.
However, the kimono... well, it has elements from various eras mixed in, but it doesn't feel like the Heian period. The closest thing is that it feels like a high-ranking courtesan from the Edo period. In any case, the feeling that AI cannot be trusted becomes stronger.
She is also a person rumored to be of mixed blood with a Slav who traveled by ship or drifted ashore, as she lived on the Sea of Japan side of the Tohoku region.
There seem to be people who have drawn her face, though.

(Image from Wikipedia)
My family doctor is from Ehime, and he said that there is a place name called "Ono" near his parents' home, and there is a tradition that Ono no Komachi stayed there for a while. And he also said, "I think it's definitely a lie." Since "Ono" is a common place name, I think there are similar examples all over Japan.
Well then, shall we have it draw a picture of someone else today?

I think this is relatively easy to understand. So I will make the hints difficult.
They have a connection to Kiyomizu-dera Temple
They are also the name of a pattern of misreading
They are also a derogatory term for someone who does not pay for their own entertainment
So, everyone, please consider this.
Well then, I will take my leave for today.
Thank you for your continued support.
Table of Contents
Unique Vulnerabilities of Cloud Storage
Mutual Complementarity Between Cloud Storage and Remote Backup
Responsibility for Data Loss in Cloud Storage
Reasons Why Disaster Recovery Procedures Should Be Decided in Advance
Regarding the Data and OS Handled by Our Company
Pros and Cons of Cloud Storage
Microsoft, you can't be serious
How to Create a Business Continuity Plan Part 1
Can They Be Alternatives to Windows? Linux Mint and Chrome OS Flex
How to Create a Business Continuity Plan Part 2
Notes on How to Create a Business Continuity Plan Part 2
How to Create a Business Continuity Plan Part 3
I Tried Using BitLocker in Various Ways
How to Create a Business Continuity Plan Part 4
On the State of Backups in the Cloud-Native Era
On Backups as a Countermeasure Against Ransomware
Introducing Recommended Backup Media for Small and Medium-Sized Enterprises
Data Backup Methods for Small and Medium-Sized Enterprises: Cloud Is Recommended
Problems and Solutions for Small and Medium-Sized Enterprises When Performing Backups
A light personal information security memoir for today
Information threats that can be addressed with backups
Information threats that cannot be addressed with backups
Backup methods: What are offline and online backups?
Data backup: What is the appropriate approach for small and medium-sized enterprises?
Recent incidents regarding data backup
Let's look at the basics of security measures as defined by the IPA! Part 1
Let's look at the basics of security measures as defined by the IPA! Part 2
Let's look at the basics of security measures as defined by the IPA! Part 3
Let's look at the basics of security measures as defined by the IPA! Part 4
Let's look at the basics of security measures as defined by the IPA! Part 5
Let's look at the basics of security measures as defined by the IPA! Part 6
The difference between online and offline backups
Let's look at the basics of security measures as defined by the IPA! Part 7
Let's look at the basics of security measures as defined by the IPA! Part 8
Personal restore incident report (T△T)
Let's look at the basics of security measures as defined by the IPA! Part 9
Companies that back up vs. companies that don't
Let's look at the basics of security measures as defined by the IPA! Final
The 3-2-1 backup rule: Evolving
Let's look at the documents released by the police!
Let's look at the documents released by the police! Part 2
Let's look at the National Center of Incident Readiness and Strategy for Cybersecurity (NISC)!
Various things regarding hardware and backups
Let's look at the guidance for organizations in the event of a ransomware incident! Part 1
Let's look at the guidance for organizations in the event of a ransomware incident! Part 2
Traps hidden in commercially available USB cables
Let's look at the guidance for organizations in the event of a ransomware incident! Part 3
Does the world's No. 1 market share router have security issues?
Let's look at the guidance for organizations in the event of a ransomware incident! Part 4
Crises in network equipment one after another
Let's look at the guidance for organizations in the event of a ransomware incident! Part 5
On malware trends from 2024 to the present
Let's look at the guidance for organizations in the event of a ransomware incident! Part 6
Can cloud services be trusted?
Let's look at the guidance for organizations in the event of a ransomware incident! Part 7
A story about how backups were useful
Let's look at the guidance for organizations in the event of a ransomware incident! Part 8
On unconventional ways to use backups
Regarding the details of our services
On recent topics regarding ransomware and backups
Let's look at the guidance for organizations in the event of a ransomware incident! Part 9
Please allow me to chat a little today
Let's look at the guidance for organizations in the event of a ransomware incident! Part 10
The past and future of backups
—Solve the Case— CASE 1: Opening the folder is slow
Let's look at the guidance for organizations in the event of a ransomware incident! Part 11
—Solve the Case— CASE 2: Website data has disappeared Part 1
—Solve the Case— CASE 2: Website data has disappeared Part 2
Today I would like to ramble on about recent topics related to backups
Let's look at the guidance for organizations in the event of a ransomware incident! Part 12
—Solve the Case— CASE 3: Office Destroyed by Fire Part 1
—Solve the Case— CASE 3: Office Destroyed by Fire Part 2
Considerations regarding hybrid backups
Regarding data recovery operations Part 1
Regarding data recovery operations Part 2
Regarding data recovery operations Part 3
Data recovery operations: Music CD edition
Data recovery operations: Game CD edition & Next-generation audio edition
Data recovery operations: Other editions
A bit late, but about who I am Part 1
A bit late, but about who I am Part 2
A bit late, but about who I am Part 3
A bit late, but about who I am Part 4
A bit late, but about who I am Part 5
About server types and their backup methods
Things that, if said by someone who handles information, might be the end of them
Today I would like to ramble about recent topics related to backups Part 2
On the history of computers and backups
I would like to ramble about recent topics regarding off-site backups
Some of the latest topics regarding off-site backups Part 1
Some of the latest topics regarding off-site backups Part 2
Regarding the accounting treatment of backup costs
Regarding the cost-effectiveness of backups Part 1
Regarding the cost-effectiveness of backups Part 2
The impact of backup strategy on mitigating information security incidents Part 1
Regarding off-site backup strategies Part 1
Regarding off-site backup strategies Part 2
Regarding the latest technical trends in off-site backups Part 1
Regarding the latest technical trends in off-site backups Part 2
Regarding the latest technical trends in off-site backups Part 3
Regarding the latest technical trends in off-site backups Part 4
Regarding the latest technical trends in off-site backups Part 5
Regarding the latest trends in air-gap backups Part 1
Regarding the latest trends in air-gap backups Part 2
Regarding the latest trends in air-gap backups Part 3
Regarding the latest trends in air-gap backups Part 4
Latest Trends in Air-Gap Backups Part 5
Latest Trends in Air-Gap Backups Part 6
Latest Trends in Air-Gap Backups Part 7
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 1
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 2
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 3
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 4
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 5
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 6
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 7
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 8
Today is an Extra Edition: Feeling Like Satchmo
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 9
Simple and Inexpensive Data Backup Strategies for Small and Medium-Sized Enterprises Part 10
The Importance of Off-site Backups Using Physical Media in Large Enterprises Part 1
The Importance of Off-site Backups Using Physical Media in Large Enterprises Part 2
The Importance of Off-site Backups Using Physical Media in Large Enterprises Part 3
Practical Backup Strategies Under Time and Budget Constraints Part 1
Practical Backup Strategies Under Time and Budget Constraints Part 2
Practical Backup Strategies Under Time and Budget Constraints Part 3
Practical Backup Strategies Under Time and Budget Constraints Part 4
Practical Backup Strategies Under Time and Budget Constraints Part 5
Backup Software by OS and Its Features: Windows Edition Part 1
Backup Software by OS and Its Features: Windows Edition Part 2
