Loading...
 
Skip to main content

DRAFT

Asking why encrypt backups is like asking the same question about laptops. Why do we encrypt them? To protect your data in the event of theft or loss. 

Now, imagine you lose or have your backup disk stolen - it's the same thing. If the backup data isn't encrypted, it's like having your laptop stolen.

Even worse, imagine you lose your NAS backup disk, or someone steals it as you left your car’s door open. All your organization's key data in one place, most importantly, unsecured. If we protect our networks from outside intrusion, we also need to ensure that when our data is outside the secure perimeter, on a backup disk, that backup disk is itself secured.

Let's start with computer backups.

If you use CrashPlan for an online backup to an external disk, you're already secure without any further action on your part. CrashPlan encrypts everything it backs up, including external disks. CrashPlan encrypts your data using your SIL identity.

If you're using a program other than CrashPlan, you need to make sure you encrypt your backups. The location for this feature varies depending on the software. 

In Acronis Cyber Protect, you'll find it in the advanced options of the backup job.

AD_4nXcJSze0Dwt8wSM56Vz50Dr39_Fpt75eQ5Y4RINXQhF-hlcoAu56GZrwQ-eIt7WFVJitnbn7VhmJ0HdMejfI39DYXMA0typ1tOi7uWQs7WM2L0tZPzHxBO9ylPqo3I_d7bRDnvWUcsEx23xjO3zEdlkRzXDs?key=VdpOQZUS8WDIjYwvE-WSEg


If you use Veeam agent for Microsoft Windows you find the option at the Local Storage stage, under Advanced

AD_4nXcZvRa9l2o8-k5F4kssmo13bHlRqFBU4VCpCZ7dEbu8erSH9J6PlDXHCa7t5BAiRyZOOgaSxT-NMsxWrI5ia3WZlCnR2LK-apOGkvxfCifXf-nrmn1sGIHbueOspQ-3B65tmStULIqOxHctZYo8-C5xa2Ma?key=VdpOQZUS8WDIjYwvE-WSEg

 

Then on the Storage tap, you can enable backup file encryption

AD_4nXfijjB95D5Wyf7Ul0SuMM255svy8TPWjuP7MPXetYQJNuLdVMk-FaEA_NoHiUy0TKB9hqOt7NKjEDxISoyBcdsidP8eKPUiDsGzzR8f_xryEuI1fiVjBgiAMqSGWVVsaidWztCN0ZJTqPthExjiRG_27tjk?key=VdpOQZUS8WDIjYwvE-WSEg

With SyncBackFree, encryption can be found in the Expert view, under Compression.

AD_4nXemB3gHVnvvw4BOn29LMno1THF2J2zbQROzw4WhImtVohXIISlWrZXnuj2Z6wr-iu6tWwxIURiLdY_3QPn5nbARkLTwmyfC134PCDaEorkrRc3e7m_uxXRWT89ue-nuLKregzaKNfZu54b4aebi4T-bjWEF?key=VdpOQZUS8WDIjYwvE-WSEg

Whatever software you choose, make sure it supports encryption.

 

Let's continue with NAS backups.

Synology implements encryption at various stages. You can encrypt a shared folder (the data is then encrypted on the NAS itself should anybody steal it). If you schedule C2 for cloud backups, it will encrypt data in transit (so that nobody can spy on the traffic during backup). 

Your Synology NAS also supports backup encryption. You must set up when you create the backup task.

AD_4nXeIM3alCSZjZKzds2oojFnOZRn8awPfi6XIf1qB2zO28O0rAxmrnJBuo47XRXy-viSAJfbhjXGv6yFDvM-Y2fO_mncqb2L9jxd4KmY_DwcVEBvluwx5uF3aUzq3s5cObGp5_jP0R8xOZviaBkxiUJfTdQVZ?key=VdpOQZUS8WDIjYwvE-WSEg

 

If you tick the option and provide a password it displays the following notification:

AD_4nXcCk6GS4eIX4SiSsGu4fgekmkQ2acDjoDsVzoN23z7oKkDkGwSIoxotxpL9-9kpi3y9vmgB-O1X097rHTq8r43CqYVE2kyOjmlcjQoRsCygF9TChnU0YH3Y07i3JwzJLkj5ve5s0aA2Ld2Id6wA3mvkO88?key=VdpOQZUS8WDIjYwvE-WSEg

This is especially important! Without the password you cannot decrypt and access your backup. This is obviously what you are seeking to achieve to protect your data from robbers. But this also prevents anyone, including you, your colleagues, those who will replace you in case something happens to you or if you leave the company later on.

Should you enable backup encryption, you must make sure to store the password in a safe place that remains accessible to IT staff in the future.

After the next page (Rotation Settings), when you click “Done” on the “Summary” page, it will automatically create and download the PEM file, which is the certificate.

AD_4nXcLR-ViZtgew3GczQolDeldNptEiRRs9MS_vEul-RqNeFJD2Sk7Vg3-ep3TacKqzCqGHzTj7-NGchtEvD2SZOmjDZZvh6Juqhjyl0xwi7JvkAkZu6YzoSwxlQl9giXxsNF7MNDFQi3oOGa5efxoAF-BTG2-?key=VdpOQZUS8WDIjYwvE-WSEg

This certificate will be needed to access your backup in case you can no longer provide the password.

Make sure to store the certificate in a safe place.

You can take the module Secure Your Data in the SIL Information Security Training for End Users training to know more about secure backups.

 


Contributors to this page: admin .
Page last modified on Tuesday March 4, 2025 10:41:11 GMT-0000 by admin.
Show PHP error messages