Category: Sin categoría

  • Your backup is worth nothing if you have never tried restoring it

    Your backup is worth nothing if you have never tried restoring it

    In the audits we carry out, the question “do you have backups?” is almost always answered with a relaxed yes. The next question — “when was the last time you restored one?” — tends to produce an awkward silence.

    It is nobody’s fault in particular: it is that a backup which runs every night and throws no errors looks like a backup that works. And it is not always so.

    What goes wrong in practice

    These are the cases we have come across most often, in order of frequency:

    • The backup runs, but it does not include everything: a database is missing, or a shared folder, or the server that was added eight months ago.
    • The backup sits in the same place as the original. A fire, a burglary or a ransomware attack takes both.
    • The backup goes to a USB drive that has been unplugged for months and nobody has looked at it.
    • The backup exists and is complete, but restoring it takes four days and the business can only survive one.
    • The backup is encrypted and nobody knows where the key is.

    The 3-2-1 rule, in plain English

    Three copies of your data, on two different types of media, with one of them off site. That is the bare minimum. On top of that, today we add one more condition: at least one copy must be immutable, that is, impossible to delete even with administrator credentials. It is the only thing that stands up to a well-executed ransomware attack.

    A backup with no restore test is not a backup: it is an intention.

    How to test it without turning it into a circus

    You do not need to stop the company in order to test a restore. This is how we do it:

    • The backup is brought up in an isolated environment, without touching production.
    • You check that it boots, that the data is there and that the date is what it should be.
    • It is timed: how long it takes from the moment you decide to restore until the service is usable.
    • The result is documented and compared against the agreed RTO.

    That last point is what turns the exercise into something useful. If your plan says you will be up and running in eight hours and the test says twenty-six, you have a problem to solve today, calmly, and not on the day of the disaster.

    Two questions you should be able to answer

    RPO: how many hours of work can you afford to lose? That sets how often you have to back up. RTO: how long can you afford to be down? That sets which technology you need.

    If you do not have those two numbers agreed in writing with management, everything else is technical detail without context.

  • Ransomware in a small business: what to do in the first four hours

    Ransomware in a small business: what to do in the first four hours

    If you are reading this with an encryption under way, go straight to the first point. If you are reading it calmly on an ordinary Tuesday, all the better: this is prepared beforehand, not during.

    Hour 0: contain

    • Disconnect from the network the affected machines. Cable out or Wi-Fi off. Do not shut them down completely just yet if you can avoid it: there is useful information in memory.
    • Isolate the backups before anything else. If the ransomware reaches them, the conversation is over.
    • Cut off remote access: VPN, remote desktop, supplier access. Whatever it came in through, it can come in through again.

    Hour 1: assess the scope

    Before touching anything else, you need to know what is encrypted and what is not: workstations, servers, shared folders, backups, and whether there are signs that they have taken data as well as encrypting it. That last part changes your legal obligations.

    This is also the moment to decide who is in charge: one person coordinates and communicates. In a crisis, five people making decisions in parallel do more damage than the incident itself.

    Hour 2: obligations

    If personal data has been compromised, the GDPR gives you 72 hours to notify the supervisory authority. It is not optional and it does not wait until you have got the service back. It is worth identifying in advance who writes that notification.

    You never pay the ransom without having exhausted the restore route first. And even having exhausted it, paying is no guarantee that you will recover anything.

    Hours 3 and 4: recover in the right order

    The temptation is to restore everything at once. That is a mistake: you restore first whatever keeps the business running, and only onto machines that have already been cleaned or rebuilt.

    • Directory and authentication first: without identity, nothing else works.
    • Then the system that invoices or produces. The one that stops the company if it is down.
    • Email and shared files next.
    • Workstations last, rebuilt from a clean image.

    What avoids 90% of these days

    Immutable backups, two-factor authentication on every remote access, network segmentation so that an infected machine cannot reach the server, and users without administrator rights on their own machine. It is not glamorous, but it is what works.

  • Five signs that your IT infrastructure needs an audit

    Five signs that your IT infrastructure needs an audit

    When we walk into a new company, it is hardly ever because everything is on fire. It is usually because somebody in management has spent months with the feeling that IT “isn’t quite right” and cannot put a name to it.

    These five signs are usually that name.

    1. Nobody can tell you what you have

    If you ask how many servers you have, which operating system version they run or which licences you are paying for, and the answer takes more than a day, you do not have an inventory problem: you have a control problem.

    2. Everything depends on one person

    There is one person — in-house or external — who is the only one who knows how it is all put together. It works fine until the day they go on holiday, change jobs or fall out with you. Documentation is not bureaucracy, it is the way to stop the knowledge walking out of the door.

    3. The same incidents keep coming back

    The same machine that freezes every week, the same printer that vanishes from the network, the same folder that loses its permissions. If an incident keeps repeating, it is not being resolved: it is being papered over. Somebody has to go after the cause.

    4. Buying happens in a panic

    If your criterion for buying a server is “the other one broke”, you are always paying the price of haste: worse negotiation, worse technical choice and zero planning. A three-year refresh plan costs the same and hurts far less.

    5. Nobody has looked at security from the outside

    Plenty of small businesses have ports open that they do not know are open, remote desktops exposed to the internet, or accounts belonging to people who left two years ago and are still active. None of it shows its face until it shows it all at once.

    What an audit does, specifically

    • A real inventory of machines, servers, licences and contracted services.
    • A configuration review: network, permissions, backups, updates.
    • Detection of single points of failure and of the surface exposed to the internet.
    • A report that management can understand, with prioritised risks and the cost of fixing them.

    The important thing is not the report: it is that somebody then carries out the plan. A report filed away in a drawer has never protected anybody.

  • Cloud or your own server? How to decide with numbers instead of faith

    Cloud or your own server? How to decide with numbers instead of faith

    It is the question we are asked most and the one the industry answers worst, because almost everybody has an incentive to answer it in one particular direction. Let us try to do it with numbers.

    What usually works out better in the cloud

    • Workloads that are variable or unpredictable: if you need four times the power for two months a year, paying for it all year round is throwing money away.
    • Projects that are new or short-lived: test environments, pilots, campaigns.
    • The need to grow fast with no purchasing or installation lead time.
    • Companies with no decent server room: if you have no UPS, no cooling and no proper network, your own server is a breakdown waiting its turn.

    What usually works out better on-premises

    • Workloads that are stable and predictable for years on end: that is where renting ends up costing more than buying.
    • Volumes of large amounts of data that move about a lot: egress traffic in the public cloud is charged for, and you notice it.
    • Applications that require very low latency to local machinery or devices.
    • Legal or client requirements that impose a specific location for the data.

    The costs almost nobody adds up

    When somebody compares “your own server” with “the cloud”, they usually compare the price of the hardware with the monthly bill. Things are missing on both sides.

    • On-premises: electricity, UPS, cooling, licences, disk replacement, and people’s hours to keep it running.
    • On-premises: the cost of the breakdown. A server with no 24/7 support and no spare parts can leave you down for three days.
    • In the cloud: egress traffic, backups, snapshots, static IPs and managed services that keep adding up.
    • In the cloud: the cost of leaving. Migrating 20 TB out of a provider is neither free nor quick.

    What we usually propose

    With most of the small businesses we work with, what comes out in the end is a hybrid: the stable, heavy workloads on-premises or with a dedicated hosting provider, and in the public cloud whatever benefits from elasticity — offsite backups, test environments, email and collaboration. Not as a middle-of-the-road compromise, but because each piece goes wherever it is cheapest and safest.

    And whatever the decision, one non-negotiable condition: you must be able to leave. Documentation of the architecture, your data in standard formats and no artificial locks. If a provider makes that difficult, that is all the information you need about them.

  • What an IT maintenance contract must include (and which signs look bad)

    What an IT maintenance contract must include (and which signs look bad)

    An IT maintenance contract is signed once and endured for years. It is worth spending an afternoon on it. This is what we would look at if we were on the other side of the table.

    What must be in writing

    • The exact scope: which machines, which servers, which services. And what falls outside it, spelled out just as clearly.
    • Response SLAs by severity, with specific hours. “As soon as possible” is not a commitment.
    • Cover hours and what happens outside them. If there is 24/7 on-call cover, what it costs and how it is triggered.
    • Inventory and documentation: kept up to date, and yours, not the provider’s.
    • A regular report: what has happened, what has been done, what is outstanding and what is recommended.
    • An exit clause: notice period and the obligation to hand over access, passwords and documentation.

    Signs that look bad

    • The administrator passwords are held by the provider alone and they will not hand them over to you. That is, quite simply, a polite kidnapping.
    • A long minimum term with a disproportionate penalty.
    • It is all “hours included” but nobody defines what an hour is or how it is accounted for.
    • There is no report. If you cannot find out what they have done for you this month, you will not be able to tell whether it is worth it either.
    • Monitoring gets invoiced but no alert ever arrives. Either everything is running perfectly, or nothing is being monitored.

    A good maintenance contract is one that lets you leave easily. Which is precisely why hardly anybody leaves.

    Block of hours or flat fee

    A block of hours works well when your need is occasional and you have somebody in-house handling the day-to-day. It has a well-known perverse effect: since every call eats into the balance, people tend not to call, and small problems are left to grow.

    A flat fee works out better when you want to delegate properly, because it aligns the incentives: it is in the provider’s interest for you to have no incidents, not lots of them. It is the model we recommend as soon as servers are involved.

    One final question for the salesperson

    “If I sack you tomorrow, what do you hand over and how quickly?”. The face they pull while answering will tell you almost everything you need to know.

  • “The internet is slow”: how to prove whose fault it is (and get your provider to fix it)

    “The internet is slow”: how to prove whose fault it is (and get your provider to fix it)

    “It’s slow” is not a diagnosis: it is a symptom. And it is almost always blamed on the provider, who is the most convenient suspect. In our experience, the blame is actually spread quite widely.

    The four usual culprits

    • The Wi-Fi, not the line. Patchy coverage, channels swamped by the neighbours or ageing access points. You can spot it because over cable everything works fine.
    • A machine saturating the network: a backup badly scheduled at midday, a mass update or a compromised computer.
    • The provider’s router, which in many offices is the bottleneck: it cannot cope with a company’s simultaneous connections.
    • The line, yes, but very often because of the upload, not the download: video calls and cloud backups travel upwards.

    What to measure, and why the speed test on your phone will not do

    A one-off test measures one instant from one place. The problem is almost never constant: it shows up at eleven, when everybody is online, or on Tuesdays, when the backup runs. You need to measure continuously:

    • Real throughput upstream and downstream, over a period of days.
    • Latency and jitter, which is what makes a video call break up even when the throughput is fine.
    • Packet loss: a sustained 1 % is already noticeable, and it never shows up in a speed test.
    • Saturation by time slot, to see whether the problem keeps to a schedule.

    How to get your provider to act

    A ticket saying “it’s slow for me” closes itself. A report with dated measurements, with packet loss and with a comparison against the throughput you are paying for does not. You have to ask for the fault report with an incident number and refer to the service level agreement in your contract, if there is one. Business lines usually have one; consumer lines dressed up as business ones do not.

    The measurement report is the only thing that turns “it’s slow” into a fault that somebody is obliged to fix.

    And if the line is fine

    Then it is time to look inside: cabling, network electronics, Wi-Fi and the machines themselves. That is the part almost nobody has ever reviewed, and where the real problem usually is.

  • IT support for businesses: what it really includes and what you should be demanding

    IT support for businesses: what it really includes and what you should be demanding

    When a company goes looking for IT technical support, what it is really looking for is to stop losing whole mornings. The word “support”, however, is used for very different things: from a number to ring all the way to a team that designs, maintains and monitors your entire infrastructure.

    The three levels, no mystery

    The industry organises support into levels. It is not empty jargon: it tells you who picks up and what they can actually solve.

    • Level 1 · service desk. The day-to-day: passwords, email, printers, permissions, staff joining and leaving. It resolves the bulk of what comes in and it is what the office notices most.
    • Level 2 · systems and networks. Servers, virtualisation, active directory, backups, VPN, network. It steps in when level 1 escalates and also for planned work: patching, updates, configuration changes.
    • Level 3 · engineering. Performance, architecture, high availability, incidents that have no manual and decisions that shape the next few years.

    A provider with only level 1 will sort out your printers and leave you stranded the day the storage fails. One with only level 3 will cost you a fortune to change a password.

    What the contract should include

    • Response times in writing and different according to severity. “As soon as possible” is not a commitment.
    • Monitoring, so they find out before you do that something is wrong.
    • Management and verification of the backups, with documented restore tests.
    • An up-to-date inventory of equipment, licences and passwords — and one that belongs to you.
    • A monthly report of what has happened and what is coming.
    • On-site support either included or priced in advance, not improvised.

    Questions that separate the wheat from the chaff

    • Who picks up, and at what level? Is there out-of-hours cover, and who staffs it?
    • When was the last backup restore you carried out, and how long did it take?
    • What happens to my data, my documentation and my passwords if I stop working with you?
    • What falls outside the contract, and how is it quoted before the work is done?

    “If I sack you tomorrow, what do you hand over and how quickly?” It is still the best question you can ask an IT provider.

    What it costs

    It depends on two things: how many of you there are and how long the business can afford to stop. Providing 24/7 support to a team of seven is not the same as to one of fifty with production that cannot stop. So be wary of anyone who gives you a price over the phone without asking a single question: either they are going to break it or they have already built the risk margin in.

  • Business Wi-Fi and home Wi-Fi: why your provider’s router is not good enough for your office

    Business Wi-Fi and home Wi-Fi: why your provider’s router is not good enough for your office

    The router your provider lends you is designed for a home: few devices, little concurrency and nobody losing money when it goes down. An office has all three the other way round.

    What goes wrong when you use home kit

    • Concurrency. It copes with few active connections and with thirty devices it starts dropping them.
    • Roaming. As you walk across the office, the laptop clings to the far-away access point and the video call cuts out. Business systems hand the device from one access point to the next without you noticing.
    • No segmentation. The TV in the meeting room, the visitor’s phone and the invoicing server all sit on the same network.
    • No visibility. You do not know who is connected, what they are using, or why it fails.
    • And it is not even yours. If the provider swaps it, your configuration disappears with it.

    What a corporate Wi-Fi network needs

    • A coverage survey with real measurements, not access points placed by eye.
    • Centrally managed access points with roaming properly sorted out.
    • A guest network isolated from the working network, and another one for connected devices.
    • Per-user access instead of a shared password that half the province ends up knowing.
    • Proper cabling and power: a good access point that is badly connected is worth nothing.

    How to tell whether yours is up to scratch

    You measure it. Before and after, at the same spots and at the same times: coverage, real speed by area, latency and hops between access points. If nobody shows you numbers, what they are selling you is a feeling.

  • Structured cabling: when you need it, what ignoring it costs and how it is done properly

    Structured cabling: when you need it, what ignoring it costs and how it is done properly

    Network cabling gives you no trouble… until it does. And when it does, it is the expensive kind: intermittent faults nobody can explain, breakdowns that take days to track down and a network that cannot grow without being rebuilt from scratch.

    Signs that yours has fallen short

    • Nobody knows which outlet goes to which port on the rack, and the only way to find out is to follow the cable by hand.
    • There are switches daisy-chained around the desks because “there weren’t enough outlets”.
    • The outlets are not labelled, or the label no longer matches anything.
    • When a whole floor goes down, the only way to work out where the fault is is by trial and error.
    • The rack is a bird’s nest: you cannot pull out one patch lead without disturbing ten others.

    What a properly done installation includes

    • Design up front: how many outlets per desk, where the trunking runs and where the rack goes.
    • The right category for the use, not the most expensive nor the cheapest.
    • Labelling at both ends of every patch lead, with the same naming on the drawing and on the rack.
    • Certification with test equipment for every outlet, with the report handed over. Without that you do not know whether the cabling meets spec: you assume it does.
    • Documentation: an outlet plan, a rack diagram and a list of what goes where.

    Documented cabling turns a two-day fault into a ten-minute one. That is the whole value, and you only notice it on the day something breaks.

    The rack, that piece of permanently unfinished business

    A tidy rack is not about looks: it is about repair time. Patch panels, cable managers, made-to-measure patch leads, protected power and ventilation. And planned free space, because something always gets added.

    When to take the chance to do it

    There are two moments when it comes out far cheaper: building work or a refit, and an office move. It can be done at any other time, but you pay for working around a business that is up and running.

  • ISO 27001 in a small business: when it is worth it and what it really involves

    ISO 27001 in a small business: when it is worth it and what it really involves

    ISO/IEC 27001 has become a commercial requirement. It is not an auditor who asks for it: it is the large client that is about to hire you, or the tender you want to bid for. That is, almost always, the honest reason for getting certified.

    What it is and what it is not

    It is not a list of technical measures you install. It is a management system: a way of identifying what information you hold, what risks it runs, what you do about it and how you check that it is still being done. The technical side is a consequence, not the starting point.

    What it involves in practice

    • Defining the scope: which part of the company gets certified. Starting with everything is usually a mistake.
    • Un risk assessment that is real, not copied off a template.
    • Policies and procedures that are actually going to be followed. The ones that are not get spotted at the very first audit.
    • Implementing the controls that come out of the assessment: access, backups, event logging, supplier management, training.
    • Internal audit, management review and a certification audit with an accredited body.
    • And afterwards: annual surveillance audits. A management system left in a drawer collapses on its own.

    ISO 27001, ENS and NIS2: how they relate

    • ISO 27001 is voluntary and works as a commercial argument in any sector.
    • ENS (the Spanish ENS scheme, Esquema Nacional de Seguridad) is mandatory in order to work with the Spanish public sector.
    • NIS2 is the European directive, and it reaches more companies than it seems: many are caught by it because they supply another company that is in scope.

    They share a good deal of the work. If you know you are going to need two of them, it is worth planning them together from the start instead of doing the same job twice.

    The useful question is not “should I get certified?” but “how much business am I losing by not being certified?”. With that number, the decision makes itself.