Top Banner
Evolving Risks Of Data Storage Neville G.H. Green Group Underwriting Manager HSB Engineering Insurance Ltd
57

Evolving Risks Of Data Storage - The Canadian Boiler and

Feb 03, 2022

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Evolving Risks Of Data Storage - The Canadian Boiler and

Evolving Risks Of Data Storage

Neville G.H. GreenGroup Underwriting Manager

HSB Engineering Insurance Ltd

Page 2: Evolving Risks Of Data Storage - The Canadian Boiler and
Page 3: Evolving Risks Of Data Storage - The Canadian Boiler and
Page 4: Evolving Risks Of Data Storage - The Canadian Boiler and
Page 5: Evolving Risks Of Data Storage - The Canadian Boiler and
Page 6: Evolving Risks Of Data Storage - The Canadian Boiler and
Page 7: Evolving Risks Of Data Storage - The Canadian Boiler and

Data Loss

Data Corruption

Data TheftData Compromise

Data Damage

Page 8: Evolving Risks Of Data Storage - The Canadian Boiler and
Page 9: Evolving Risks Of Data Storage - The Canadian Boiler and

The Data “Explosion”

• 1996– Google handles 100TB of data in 1 YEAR

• 2010– Google handles 160TB in 1 SECOND

Page 10: Evolving Risks Of Data Storage - The Canadian Boiler and

Major Technology Changes

• Hard Drive Storage Density– Increasing exponetially– Price inversely proportional

• 1989 $36 / MB = $36,864 / GB• 1994 $1 / MB = $1,024 / GB• 2000 $0.02 / MB = $20 / GB• 2010 $0.00006 / MB = $0.07 / GB

Page 11: Evolving Risks Of Data Storage - The Canadian Boiler and

Storage Challenges

• Data safety and integrity– Higher storage density / same form factor

• 1989 typical hard drive 40MB• 2010 typical hard drive 1TB

• 26,000 x the data – Same Physical Area• Minor physical surface damage now

affects 26,000 x more data

Page 12: Evolving Risks Of Data Storage - The Canadian Boiler and

The Drive To Store More Data

Page 13: Evolving Risks Of Data Storage - The Canadian Boiler and

Technical Factors

• File sizes increasing– Same data in a 1995 Word Doc now takes

around 10x the storage space• Migration from Mail to e-mail• Migration from paper to e-paper• Software less “compact”

Page 14: Evolving Risks Of Data Storage - The Canadian Boiler and

Business Factors

• Business Drivers– Risk analysis– Marketing– Customer service– Ease of access– (Building) Space saving– BCP– Compliance / Regulatory

Page 15: Evolving Risks Of Data Storage - The Canadian Boiler and

Brief History Of Storage

Page 16: Evolving Risks Of Data Storage - The Canadian Boiler and

Late 40’s to Early 50’s

Pictures Coutesy of Poil

Page 17: Evolving Risks Of Data Storage - The Canadian Boiler and

Late 50’s to Early 60’s

Pictures Coutesy of Poil

Page 18: Evolving Risks Of Data Storage - The Canadian Boiler and

Mid 60’s to Mid 70’s

Page 19: Evolving Risks Of Data Storage - The Canadian Boiler and

Late 70’s to Mid 80’s

Picture Coutesy of Jkbw Picture Coutesy of Appaloosa

Page 20: Evolving Risks Of Data Storage - The Canadian Boiler and

Mid 80’s to Current Day

Page 21: Evolving Risks Of Data Storage - The Canadian Boiler and

Evolution Of Portable Storage

128 Kb 1.2 Mb 1.4 Mb

Page 22: Evolving Risks Of Data Storage - The Canadian Boiler and

Pictures Coutesy of Payam 81

Page 23: Evolving Risks Of Data Storage - The Canadian Boiler and

Picture Courtesy of Stefan-Xp/Bild-GFDL Vorlage Fremd

Page 25: Evolving Risks Of Data Storage - The Canadian Boiler and

Statistics

Page 26: Evolving Risks Of Data Storage - The Canadian Boiler and

60% of companies sustaining a major data loss will shut within 6 months

Page 27: Evolving Risks Of Data Storage - The Canadian Boiler and

Companies unable to resume operations within ten days of a data disaster are not likely to survive(Strategic Research Institute)

Page 28: Evolving Risks Of Data Storage - The Canadian Boiler and

Every week 140,000 hard drives crash in the United States. (Mozy Online Backup)

Page 29: Evolving Risks Of Data Storage - The Canadian Boiler and

Simple drive recovery can cost upwards of $7,500 and success is not guaranteed

Page 30: Evolving Risks Of Data Storage - The Canadian Boiler and

34% of companies FAIL to test tape backups, of those that DO, 77% have found tape back-up failures

Page 31: Evolving Risks Of Data Storage - The Canadian Boiler and

Physical Risks

Page 32: Evolving Risks Of Data Storage - The Canadian Boiler and

Changing Risk Profile

• Shift in risk• From

– Fire– Nat Cat

• To– The push of a button– Breakdown– Loss of a laptop or flash drive

Page 33: Evolving Risks Of Data Storage - The Canadian Boiler and

Head Crash ?

Page 34: Evolving Risks Of Data Storage - The Canadian Boiler and

Head Crash !

Picture Courtesy of Alchemist-hp

Page 35: Evolving Risks Of Data Storage - The Canadian Boiler and

Major Technology Changes

• Solid State displacing Electro Mechanical– SSD Drives in laptops now common– Improving - not yet mature technology

• Fast BUT• Limited lifespan

– Increased security risk / reliability issues

Page 36: Evolving Risks Of Data Storage - The Canadian Boiler and

SSD / Flash Issues• Advantages

– Fast– Quiet– No fragmentation

Issues– Physically robust – Flexible form factor

• Disadvantages– Limited life– 10 to 100,000 cycles

per cell• Mitigated by “Wear

Levelling”– Security Issues

• Caused by “Wear Levelling”

Page 37: Evolving Risks Of Data Storage - The Canadian Boiler and

Portable Risks

Courtesy of Secumen

Page 38: Evolving Risks Of Data Storage - The Canadian Boiler and

Cyber / E-Risks

Page 39: Evolving Risks Of Data Storage - The Canadian Boiler and

Virus

Hacking Phishing

Spoofing

SQL Injection

Cross Site ScriptingEvil Twin

Denial of Service

Snarfing

Buffer Overflow

DNS Cache Poisoning

Pharming

Drive By

Page 40: Evolving Risks Of Data Storage - The Canadian Boiler and

Minimising Data Loss Risk

Page 41: Evolving Risks Of Data Storage - The Canadian Boiler and

Key Strategies

• Defence• Backup• Data Recovery

Page 42: Evolving Risks Of Data Storage - The Canadian Boiler and

Key Strategies

• Defence– Hardware Based

• Mirroring• RAID• Firewalls

– Software Based• Virus Defence / Internet Security• Corporate “Lockdown”• Encryption

Physical Protection

Security & IntrusionPrevention

Page 43: Evolving Risks Of Data Storage - The Canadian Boiler and

Disk Mirroring

• Two (or more) identical disks• All writes and deletions copied byte for

byte

Page 44: Evolving Risks Of Data Storage - The Canadian Boiler and

RAID

• Several (usually identical) drives– Data “striped” across drives– Sometimes one “Hot” spare– Data striped by a controller / software

Page 45: Evolving Risks Of Data Storage - The Canadian Boiler and

Raid Array

D1 D2

D3 D4

D1 D2

D3

D1

D3 D4

D2

D3 D4

Raid Controller

Hot SpareContains file

allocation tables

for disks 1 - 3

Disk 1 Disk 2

Disk 3 Disk 4

Data Server

Page 46: Evolving Risks Of Data Storage - The Canadian Boiler and

RAID• Advantages

– High protection level– Limits downtime– Speed of data access– Modest cost of

individual drives

• Disadvantages– Does not eliminate

single point of failure– Complexity– Many proprietary

solutions– Disparate benchmark

standards

Page 47: Evolving Risks Of Data Storage - The Canadian Boiler and

Backup Backup StrategiesStrategies

Page 48: Evolving Risks Of Data Storage - The Canadian Boiler and

Key Strategies

• Backup– Hardware Based– Online

Page 49: Evolving Risks Of Data Storage - The Canadian Boiler and

Disk To Tape• Advantages

– Simple– Robust technology– Reasonably cost

effective• Disadvantages

– Lengthy testing and recovery times

– Tape storage

Pictures courtesy of Stetpro (B) & Darkone (T)

Page 50: Evolving Risks Of Data Storage - The Canadian Boiler and

Disk To Disk• Advantages

– Simple– Robust technology– Cost effective– Swift recovery

• Disadvantages– Second location

needed

Pictures courtesy of Stetpro (B) & Darkone (T)

Page 51: Evolving Risks Of Data Storage - The Canadian Boiler and

Disk To Disk To Tape• Advantages

– High protection level• Disadvantages

– Second location needed

Pictures courtesy of Stetpro (B) & Darkone (T)

Page 52: Evolving Risks Of Data Storage - The Canadian Boiler and

Online• “Second Layer”

Solution• Advantages

– Automated– No second location– High quality datacentres– High protection level– Multiple backups– Some Insured Solutions– Swift data recovery

• Disadvantages– Limited by connection

speed

Netw

orkInternet

Datacentre

First levelbackup

CorporateNetwork

Page 53: Evolving Risks Of Data Storage - The Canadian Boiler and

Key Strategies

• Data Recovery– Online restore– Media based restore– Disk recovery

Page 54: Evolving Risks Of Data Storage - The Canadian Boiler and
Page 55: Evolving Risks Of Data Storage - The Canadian Boiler and

Insurer Responses

• In Europe– Data written on monoline Computer

Policies and as sublimit to MB– Limits vary from $000’s to $000,000’s– Warranties / Conditions

• Backup – offsite – no less than every 48h• Firewalls• Anti virus software requirement

Page 56: Evolving Risks Of Data Storage - The Canadian Boiler and

Summary• Moore’s / Kryder’s Laws

– Storage density will double every year• Business Requirements

– If it is possible to store more – more will be stored– Dependency shift to critical more prevalent

• Effects ……– Exposure in data sublimits is compressed– Pressure to increase sublimits– Frequency and severity WILL rise where insureds

do not take adequate precautions if not mandated.

Page 57: Evolving Risks Of Data Storage - The Canadian Boiler and