• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
Compliance, IT Infrastructure, Network Security, News

Backup and Storage Devices Contain an Average of 14 Security Issues

Research from cyber resilience company Continuity shows that enterprise backup and storage devices need to be more secure.

April 5, 2023 Zachary Comeau Leave a Comment

backup storage security
andranik123/stock.adobe.com

With storage and backup devices often representing the last line of defense against ransomware attacks and outages, they should be as secure as possible so organizations can restore their data in a critical time of need.

However, new research from cyber resilience company Continuity shows that the average enterprise storage and backup device has 14 vulnerabilities, three of which are rated as high or critical. With backups such a crucial part of an organization’s infrastructure, a compromise could lead to a much more significant cyber incident.

The New York City-based company analyzed more than 700 enterprise storage and backup devices as well as nearly 10,000 security issues and found that the average backup and storage device had more than a dozen vulnerabilities. Those security flaws include insecure network settings, unaddressed vulnerabilities, access rights issues, insecure user management and authentication, and insufficient logging and auditing.

According to Continuity, unpatched vulnerabilities in storage and backup systems are main attack points for ransomware actors to cripple an organization’s restoration plans and force the victim to pay a ransom.

The company’s study, The State of Storage & Backup Security Report, finds several reasons why those security issues exist in backup and storage environments, including a growing divide between IT infrastructure and security teams.

The report suggests that security teams are developing policies and procedures that infrastructure teams are tasked with implementing, sometimes with minimal direction.

In addition, security teams may be unaware of the cyber resiliency capabilities offered by storage and backup systems, while infrastructure teams are more focused on day-to-day operations and less concerned with defending against cyberattacks.

In addition to leveraging automated security posture assessment tools, the report recommends that organizations identify storage and backup security knowledge gaps and develop a plan that puts it on par with that of compute and network security.

Continuity also offers these questions that organizations should ask themselves to help clarify their level of storage security maturity:

  • Do our security policies cover specific storage, storage networking and backup risks?
  • Are we evaluating the security of our storage & backup infrastructure on an ongoing basis?
  • Do we have detailed plans and procedures for recovery from a successful attack on a storage or backup system? Do we test such procedures?
  • How confident are we that the key findings highlighted in this report, and similar ones do not, and cannot occur in our environment?

Organizations should also read the NIST SP-800-209 Security Guidelines for Storage Infrastructure, which were co-authored by Continuity.

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Tagged With: Backup, Cybersecurity, ransomware, Storage

Related Content:

  • Cloud, SASE, Aryaka How the Cloud is Redefining Media Production and…
  • Singlewire Software mass notification interview Singlewire Software on Mass Notification Solutions
  • URI catchbox 1 Catchbox Plus: The Mic Solution That Finally Gave…
  • Engaging virtual meeting with diverse participants discussing creative ideas in a bright office space during daylight hours Diversified Survey: Workplace AV Tech is Falling Short,…

Free downloadable guide you may like:

  • Practical Design Guide for Office SpacesPractical Design Guide for Office Spaces

    Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-face time with co-workers. When designing the office spaces — and meeting spaces in particular — enabling that connection between co-workers is crucial. But introducing the right collaboration technology in meeting spaces can […]

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.