A CBTS White Paper Offsite Backup David Imhoff Product Manager, CBTS 4/22/2012 www.cbts.cinbell.com
Overview Business Data Backup Challenges Protecting critical data is a challenge for every organization. Businesses of all sizes have seen a sharp increase in the amount of data they must store, and also protect. Customers need innovative solutions to help them protect the increased amount of data. In addition, government regulations and requests for legal discovery strain the resources and capabilities of traditional data protection solutions. Failure to comply or provide information in a timely fashion can result in significant costs and penalties. Furthermore, recent legislation has exposed the risk of shipping tapes either encrypted or unencrypted as one of the greatest security concerns in today s IT infrastructure. According to Gartner, there are more than 4 million remote offices in the U.S. alone, at least 60 percent of all enterprise data resides at remote offices, and remote office data continues to grow at more than 50 percent per year. The key challenges of remote office data protection include: a lack of trained local staff, limited WAN bandwidth, the high cost of obtaining additional bandwidth, failure-prone equipment, manual processes, lack of centralized management, and high data growth rates. The risk of data loss or exposure from remote sites can be extremely high. As a result, IT professionals are looking toward managed service providers that leverage best-in-breed technology to solve these issues. Page 2
Proposed Backup and Recovery Solution CBTS Data Protection Service provides IT organizations with a managed backup solution that provides a secure offsite copy of critical data while minimizing data transport costs. CBTS Data Protection Service is able to provide a secure offsite copy of critical data while minimizing data transport costs by utilizing source variable block deduplication at the data source, encrypting the data with 128 bit AES encryption in flight, and transporting the data to the CBTS data bunker hosted in a Tier 3 datacenter. This white paper will discuss each of these components to detail how this is accomplished. Managing data growth with source based deduplication CBTS Data Protection Service uses Avamar s deduplication technology that solves the challenge of redundancy in backup data at the source before transferring the data across the LAN or WAN during a backup operation. Backup agents are deployed on the systems to be protected (for example, servers, desktops, laptops) to identify and filter repeated data segments stored in files within a single system and across multiple systems over time. This ensures that each unique data segment is backed up only once across the enterprise. As a result, copied or edited files, shared applications, embedded attachments, and even daily changing databases generate only a small amount of incremental backup data. By moving only new, unique sub file variable length data segments, the CBTS Data Protection Service reduces the required daily network bandwidth and storage. By storing just a single instance of each sub file data segment globally, CBTS Data Protection Service also reduces total backend storage by up to 600% for cost-effective, long-term, disk-based recovery. A key factor for eliminating redundant data at a segment (or sub file) level is the method for determining segment size. Fixed-block or fixedlength segments are commonly employed by snapshot and some Page 3
deduplication technologies. Unfortunately, even small changes to a dataset (for example, inserting data into the beginning of a file) can change all fixed-length segments in a dataset, despite the fact that very little of the dataset has actually changed. Data Protection Services uses an intelligent variable length method for determining segment size that looks at the data itself to determine logical boundary points, eliminating the inefficiency. Encryption CBTS Data Protection Service provides comprehensive encryption capabilities, including the ability to encrypt backup data while in transit and at rest. For enhanced security during client/server data transfers, Data Protection Service supports SSL encryption. SSL encryption utilizes the 128-bit or 256-bit Advanced Encryption Standard (AES) algorithm and should be used for any external network communications, where security is a significant concern. The choice of encryption method can be made on a client-by-client basis or for an entire group of clients. Offsite DR Ready Copy Hosted in a Tier 3 Datacenter CBTS Data Protection Service replicates all data to a state of the art Tier 3 datacenter in order to provide a safe, offsite copy for all of your organization s data. All components and infrastructure are fully redundant and include 10 redundant UPS modules, 3 utility power feeds, and diverse underground fiber entrances. Page 4
Recommendation As organizations grow, businesses often find themselves outgrowing entry level backup products and processes. Increased scrutiny from regulatory agencies and an ever increasing amount of data lead to storage and backup issues. By leveraging a managed service like CBTS Data Protection Service that utilizes next generation backup technologies, businesses can safely and efficiently create an offsite DR backup, while drastically enhancing backup performance. Page 5