Session

Come With Me If You Want to Live - Ransomware-Proofing the Data Platform

Most organisations have a backup strategy. Far fewer have a recovery strategy that actually works after a ransomware attack. The difference matters when Judgment Day arrives and the clock is running.
Modern ransomware operators don't act like opportunists, they act like the T-1000. Patient, methodical, and already inside the perimeter long before they strike. Before encrypting production, they spend days or weeks compromising backup agents, corrupting backup files, stripping recovery credentials, and poisoning replicas. They can't be bargained with and they can't be reasoned with. By the time you see the ransom note, the backups you thought you had are already gone.
This session is built around that threat model and the conviction that there is no fate but what we make. We cover immutable backup architectures (Azure Blob immutability, WORM storage, deletion protection) and credential isolation: ensuring backup systems operate behind an identity boundary that production cannot cross. We look at what the 3-2-1-1 model looks like in a real database environment, how to test recovery under full-compromise conditions, and the process failures that turn survivable attacks into total losses.

Danny de Haan

Database Security & Infrastructure Advocate || Solutions Engineer @ Redgate

Roermond, The Netherlands

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top