3 quick CyberSec lessons with what went wrong with Partis.si and why it should matter to YOU !
Not much to tell.
Earlier in this Covid19 infested spring of 2021, "semi/totally-(i)legal" Slovenian file sharing portal Partis.si went down (not the first time though). But this time, it was permanent. Dead, gone.
Upon typing the URL, users were greeted with a picture and a semi-offical statement telling them, that the PaaS provider OVHcloud suffered devastating fire of its ONLY site and the whole infrastructure BURNED down.
Seeing this from a business perspective: Chapter-11-bankruptcy. Game over for the "business".
OK, was the time to panic ?
Hell, yeah. Reasons:
- OVHcloud didn't have ANY DR (Disaster Recovery) or HA (High Availability) capabilitity (FAIL),
- Partis.si administrators didn't have ANY local backups of ANY servers and/or databases (FAIL),
- Partis.si administrators obviously didn't have ANY clue on what PaaS Cloud provider to choose (DOUBLE FAIL).
Now, please pay attention (to avoid chapter 11):
- #1: Before going into the "cloud", please check that the provider has DR, HA and Backup strategies in place, that WORK and can be verified,
- #2: Please do the due-dilligence of background check of the cloud PaaS provider, not ALL PROVIDERS are the same,
- #3: Regardless of fancy fairytales that cloud provider is whispering into your ear, telling you the story of beautiful backups being performed every single day and are stored in the offsite location located seven seas away in the land of Mordor: DO YOUR HOMEWORK AND MAKE YOUR OWN BACKUPS OF THE DATA TO YOUR LOCAL STORAGE.