StorageGuard - by Continuity™ - is the ONLY Security Posture Management solution for Storage & Backups, helping to ensure these systems are securely configured, and compliant with industry & security standards.
A leading national bank processes billions of dollars in transactions daily. While its cybersecurity posture was mature, its storage and backup systems had been excluded from regular security audits.
This gap was exposed when unusual activity was detected: backup files accessed during off-hours, encrypted data chunks missing, and metadata inconsistencies. The evidence suggested potential unauthorized access to sensitive backup infrastructure, raising concerns about ransomware or data tampering.
A crisis team responded within the hour and took the following actions:
While the immediate threat was mitigated, the incident highlighted critical blind spots in the security of the bank’s backup. The CISO prioritized immediate action to validate the security of these systems going forward.
The bank was unable to monitor the security posture of its backup and storage infrastructure, leaving vulnerabilities and misconfigurations undetected across their on-premises and public cloud environments.
The bank required a straightforward, scalable method to detect risks – especially lateral movement into backup systems – and ensure alignment with their Cyber Security Framework.
The bank engaged Continuity to run a proof of concept of StorageGuard, a solution built to assess and secure enterprise storage and backup systems.
The proof of concept revealed:
Following the POC, the bank moved quickly to deploy StorageGuard.
Bank’s Storage, Backup, and Data Protection Environment NetApp ONTAP, Dell PowerMax, Dell PowerProtect DD, Veritas NetBackup, Brocade SAN switches | |
Pass / Fail | Risks by Categories |
A total of 289 risk types were detected, consisting of 676 individual risks. |
The bank:
StorageGuard provided immediate visibility into misconfigurations and vulnerabilities. The bank was able to resolve long-standing risks and implement continuous security validation.
Sample list of the types of risks detected by StorageGuard:
Type | Security Principle | Category | Severity | Risk Count |
NetApp StorageGRID | Centralize Audit Log Storage – Syslog Configuration | Audit | Error | 12 |
Dell PowerScale | Data In-Transit Encryption | Encryption | Error | 18 |
Dell PowerScale | Vulnerability detection | Information Security | Error | 1 |
Dell PowerProtect DD | Vulnerability detection | Information Security | Error | 2 |
Dell PowerProtect DD | Protect Recovery Data Immutable Data Copies – Backup | Malware Protection | Warning | 3 |
Hitachi Vantara VSP NAS | Centralize Authentication and Account Management | Authentication | Warning | 23 |
Hitachi Vantara VSP NAS | Enable Time Synchronization | Configuration Mgt | Warning | 16 |
NetApp StorageGRID | Idle Session Termination | Access Control | Warning | 8 |
Dell PowerProtect DD | Multifactor Authentication | Authentication | Warning | 2 |
“StorageGuard provided the clarity and actionable insights we needed to secure our most critical assets.” — VP Information Security
With StorageGuard, the bank was able to:
It’s time to automate the secure configuration of your storage & backup systems.