<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Core6</title>
	<atom:link href="https://www.core6.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.core6.com/</link>
	<description>Storage &#38; Backup Systems - Autonomously Secured</description>
	<lastBuildDate>Mon, 14 Sep 2026 11:57:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.core6.com/wp-content/uploads/2025/10/cropped-favicon-32x32.png</url>
	<title>Core6</title>
	<link>https://www.core6.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Practical AI for Storage Teams (Hold the Hype)</title>
		<link>https://www.core6.com/blog/practical-ai-for-storage-teams/</link>
		
		<dc:creator><![CDATA[Doron Youngerwood]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 11:03:55 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/secure-today-exposed-tomorrow-the-case-for-continuous-storage-hardening-2/</guid>

					<description><![CDATA[<p>Three places where AI actually helps you secure storage and backup – and the one part nobody puts on the slide. If you run storage or</p>
<p>The post <a href="https://www.core6.com/blog/practical-ai-for-storage-teams/">Practical AI for Storage Teams (Hold the Hype)</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="has-medium-font-size wp-block-paragraph"><em><strong>Three places where AI actually helps you secure storage and backup – and the one part nobody puts on the slide.</strong></em></p>



<p class="wp-block-paragraph">If you run storage or backup, you&#8217;ve been pitched &#8220;AI&#8221; more times this year than you can count. And most of it is exhausting. Every product suddenly has an AI feature. Every vendor deck has “The Slide”! And almost none of it survives the only question that actually matters to you:</p>



<p class="wp-block-paragraph">What does this do for me on a Monday, when I&#8217;m three tickets deep and something&#8217;s misconfigured?</p>



<p class="wp-block-paragraph">So let&#8217;s not do that. This isn&#8217;t a post about AI changing everything or coming for your job. It&#8217;s a straight look at three specific, fairly unglamorous places where AI is genuinely making the security of storage and backup work less painful right now – plus one thing most AI pitches conveniently leave off the slide.</p>



<h2 class="wp-block-heading"><strong>First, what problem are we actually solving?</strong></h2>



<p class="wp-block-paragraph">It&#8217;s worth being clear about why this matters for storage specifically, because it&#8217;s a bit different from the rest of your IT stack.</p>



<p class="wp-block-paragraph">Enterprise storage and backup security has a knowledge problem. Every array, every backup appliance, every management console has its own settings, its own hardening guidance, its own advisories, its own special place where it hides whatever&#8217;s misconfigured.</p>



<p class="wp-block-paragraph">Nobody holds all of that in their head – not across a multi-vendor storage environment, nobody. The knowledge is fragmented across vendors, buried in documentation, and there&#8217;s never enough of it to go around.</p>



<p class="wp-block-paragraph">That&#8217;s a big reason these systems drift and stay drifted. Not because anyone stopped caring, but because checking them properly is slow, fiddly, specialist work, and there&#8217;s always something more on fire.</p>



<p class="wp-block-paragraph">And that, as it happens, is exactly the kind of thing language models are good at. Not because they&#8217;re magic. Because the job is really about reading, connecting, and explaining a mountain of technical detail faster than a person can. All three of the use cases below come back to that one idea.</p>



<h2 class="wp-block-heading"><strong>1. Just ask it: natural-language investigations</strong></h2>



<p class="wp-block-paragraph">The first place AI earns its keep is answering the questions that&#8217;d otherwise eat your afternoon.</p>



<p class="wp-block-paragraph">Picture what checking a security posture question looks like today. You want to know which of your backup systems don&#8217;t have immutability set up properly. So you log into one console, then another, then another (assuming you remember where each vendor buried that particular setting ), and you piece the answer together by hand. It&#8217;s slow, it&#8217;s easy to get wrong, and the whole thing hinges on you knowing exactly where to look on every platform you own.</p>



<p class="wp-block-paragraph">Natural-language investigation just&#8230; skips all that. You ask in plain English —<em> &#8220;show me every backup repository where immutability is off or misconfigured&#8221;</em><em>,</em> and you get an answer from across the whole estate. No memorizing each vendor&#8217;s menu tree.</p>



<p class="wp-block-paragraph">Same deal for <em>&#8220;which systems are on end-of-support firmware,&#8221;</em> or <em>&#8220;where are default credentials still sitting,&#8221;</em> or <em>&#8220;what changed in my storage config this week?&#8221;</em></p>



<p class="wp-block-paragraph">The shift is quiet but genuinely useful: the platform expertise moves from you to the tool. You don&#8217;t have to be an expert in all sixty systems to interrogate them. You just have to know what to ask, which is the part you&#8217;re already good at.</p>



<p class="wp-block-paragraph">When you&#8217;re covering more systems than any team should reasonably cover, that&#8217;s the difference between checking a thing now and adding it to the list you both know you&#8217;ll never get to.</p>



<h2 class="wp-block-heading"><strong>2. Okay, it&#8217;s broken</strong><strong>. N</strong><strong>ow what? AI-assisted hardening analysis</strong></h2>



<p class="wp-block-paragraph">Finding the security misconfiguration is a win. But a finding on its own doesn&#8217;t fix anything, and working out what to actually do about it is usually the annoying part. That&#8217;s where AI helps next.</p>



<p class="wp-block-paragraph">A raw list of findings isn&#8217;t worth much on its own. Anyone who&#8217;s run a vulnerability scanner knows the special despair of getting back 4,000 risks with zero sense of which five matter today!</p>



<p class="wp-block-paragraph">The useful questions are the ones that need judgment: Is this exposure actually dangerous in my environment, or just technically true? What&#8217;s the real fix? Will fixing it break something else at 2am? What do I do first?</p>



<p class="wp-block-paragraph">This is where AI-assisted analysis changes the day. Instead of just flagging that a setting is off-baseline, it can tell you why that gap matters, what risk it creates, and how to fix it — pointing at the specific storage or backup vendor&#8217;s best practice, not a generic checklist.</p>



<p class="wp-block-paragraph">Take a finding like <em>&#8220;time service not hardened on this backup appliance.&#8221; </em>It can explain that this could let an attacker mess with retention so your backups quietly age out early, and then hand you the exact step to fix it on that platform.</p>



<p class="wp-block-paragraph">And it can prioritize, which is the big one. Instead of an undifferentiated wall of findings, it can reason about which exposures actually carry risk given how your environment is set up, so your limited hours go to the handful of things most likely to bite you, not the busywork.</p>



<p class="wp-block-paragraph">When you&#8217;re always outnumbered by the systems you&#8217;re responsible for, that triage is where a lot of the real value lives.</p>



<h2 class="wp-block-heading"><strong>3. Help me do the thing: AI-powered administration</strong></h2>



<p class="wp-block-paragraph">The third one&#8217;s the most hands-on, and the one to be a little careful with.</p>



<p class="wp-block-paragraph">Beyond finding and analyzing, AI can help you actually do the work: draft the remediation steps, generate the config change, build the runbook, produce the evidence your auditor keeps asking for. All that tedious connective tissue that eats hours without needing much deep thought – a lot of it can be handed off.</p>



<p class="wp-block-paragraph">Ask for the exact commands to harden a specific setting on a specific box, and get them, formatted right, without reading through a 200-page PDF !</p>



<p class="wp-block-paragraph">Done well, this shrinks the distance between knowing what to fix and it being fixed. And that gap – between &#8220;found the problem&#8221; and &#8220;problem&#8217;s gone&#8221; – is where a ton of exposure time hides.</p>



<p class="wp-block-paragraph">How many issues have you spotted that then just sat in a queue because nobody had a spare hour to work through the fix by hand? Closing that gap faster is, honestly, most of the game.</p>



<p class="wp-block-paragraph">But this is also the one that needs the most discipline. Which brings us to the bit the pitches skip.</p>



<h2 class="wp-block-heading"><strong>The bit nobody puts on the slide: AI is a privileged operator</strong></h2>



<p class="wp-block-paragraph">Here&#8217;s the part to be clear-eyed about. The second AI can read your storage config, analyze your posture, or make changes, it becomes a very privileged thing in your environment – broad visibility, and maybe the power to act.</p>



<p class="wp-block-paragraph">That&#8217;s exactly the kind of access attackers break their backs trying to get. Hand it to a tool without proper controls and you haven&#8217;t removed risk, you&#8217;ve just moved it somewhere else.</p>



<p class="wp-block-paragraph">So the rule is refreshingly boring: treat AI like any other privileged operator, because that&#8217;s what it is. It gets a real identity, not some shared anonymous login. Clear ownership, so someone&#8217;s accountable for it. Least privilege – it can see and touch what its job needs, and nothing else. And everything it does gets logged, so if you need to know later exactly what it looked at and what it changed, you can.</p>



<p class="wp-block-paragraph">None of that is a reason to avoid AI. It&#8217;s the thing that makes using it safe. The storage teams that get real value out of AI here – without accidentally opening a new door – are the ones who treat &#8220;AI can do this&#8221; and &#8220;AI should do this unsupervised&#8221; as two very different sentences.</p>



<p class="wp-block-paragraph">Keep a human in the loop for anything that matters, and hold the AI to the same access discipline you&#8217;d hold any powerful account.</p>



<p class="wp-block-paragraph">And let&#8217;s be honest about the specific thing that makes storage teams nervous: the idea of an AI autonomously making changes on a production array. That&#8217;s a genuinely scary thought, and you&#8217;re right to feel it.</p>



<p class="wp-block-paragraph">One bad automated change to zoning, masking, or a retention policy doesn&#8217;t just create a ticket, it can take an application down or put data at risk.</p>



<p class="wp-block-paragraph"><em>&#8220;Trust me, the AI&#8217;s got it&#8221;</em> isn’t a sentence anyone should have to accept on a system that matters this much.</p>



<p class="wp-block-paragraph">Which is why validation before execution isn&#8217;t a nice-to-have. It&#8217;s the whole ballgame.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="461" data-id="14175" src="https://www.core6.com/wp-content/uploads/2026/09/core6_validate_before_run_inline-1-1024x461.png" alt="" class="wp-image-14175" srcset="https://www.core6.com/wp-content/uploads/2026/09/core6_validate_before_run_inline-1-1024x461.png 1024w, https://www.core6.com/wp-content/uploads/2026/09/core6_validate_before_run_inline-1-300x135.png 300w, https://www.core6.com/wp-content/uploads/2026/09/core6_validate_before_run_inline-1-150x68.png 150w, https://www.core6.com/wp-content/uploads/2026/09/core6_validate_before_run_inline-1-768x346.png 768w, https://www.core6.com/wp-content/uploads/2026/09/core6_validate_before_run_inline-1-1536x691.png 1536w, https://www.core6.com/wp-content/uploads/2026/09/core6_validate_before_run_inline-1-2048x922.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<p class="wp-block-paragraph">The useful pattern is AI that does the hard analytical work and proposes a change, but shows you exactly what it wants to do before anything happens: what the change is, why, which systems it touches, and what the blast radius looks like if it&#8217;s wrong. You review it. You approve it. Then it runs – ideally with a checked, reversible path rather than a one-way door.</p>



<p class="wp-block-paragraph">The AI drafts; a human signs off; the action is logged. You get the speed of not having to work out the fix by hand, without surrendering the judgment call about whether to actually pull the trigger.</p>



<p class="wp-block-paragraph">Full autonomy, where the AI detects, decides, and executes on its own, is something you earn gradually – on low-risk, well-understood changes, once the tool has proven itself and the guardrails are solid – not something you switch on across your whole estate on day one.</p>



<p class="wp-block-paragraph">Anyone pushing hands-off automation of destructive operations on production storage from the jump hasn&#8217;t run storage a day in their life.</p>



<p class="wp-block-paragraph">Start with AI that recommends and validates, keep the human holding the pen, and expand the autonomy only as far and as fast as you&#8217;re actually comfortable.</p>



<h2 class="wp-block-heading"><strong>So where does that leave you?</strong></h2>



<p class="wp-block-paragraph">Honestly? AI isn&#8217;t transforming storage operations overnight, and anyone who says otherwise is selling you something. What it is doing is quieter and more useful than that.</p>



<p class="wp-block-paragraph">It&#8217;s taking the slow, specialist, scattered knowledge work that made storage and backup security so hard to keep up with, and making it faster and easier to reach. Ask your posture questions in plain English. Turn a pile of raw findings into a short, explained, prioritized to-do list. Get help actually carrying out the fixes. And do all of it across a multi-vendor estate no single human could ever hold in their head.</p>



<p class="wp-block-paragraph">That&#8217;s the thinking behind how <a href="https://www.core6.com/storageguard/" target="_blank" rel="noreferrer noopener"><strong>StorageGuard</strong></a> uses AI. It points these capabilities squarely at the security of enterprise storage and backup systems, letting you investigate posture in plain language, turning drift and exposures into prioritized, explained fixes instead of a wall of alerts, and doing it with the auditability and least-privilege controls that treating AI as a privileged operator actually requires.</p>



<p class="wp-block-paragraph">It&#8217;s not there to replace your judgment. It&#8217;s there to give that judgment a lot more leverage over a storage and backup environment that got too big and too varied to secure by hand a long time ago.</p>



<p class="wp-block-paragraph">In the end, practical AI isn&#8217;t about the tech being impressive. It&#8217;s about your Monday being less painful, and your storage environment being more secure at the end of the day than it was at the start. That&#8217;s a low bar for a marketing slide and a high one for real work.</p>



<p class="wp-block-paragraph"><strong>The good news: in these specific, unglamorous corners, real work is finally starting to clear it.</strong></p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="256" data-id="14104" src="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png" alt="" class="wp-image-14104" srcset="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png 1024w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-300x75.png 300w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-150x38.png 150w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-768x192.png 768w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1536x384.png 1536w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>
</figure>



<p class="has-medium-font-size wp-block-paragraph"><strong>Want to know where you actually stand?</strong></p>



<p class="wp-block-paragraph">Reading through five domains is one thing; knowing how your own estate scores against them is another. That&#8217;s exactly why we built the <strong>Enterprise Storage &amp; Backup Security Self-Assessment</strong>.</p>



<p class="wp-block-paragraph">It walks you through these same five domains and gives you back a weighted scorecard that surfaces your gaps and shows you which controls to fix first.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel="noreferrer noopener">Take the Enterprise Storage &amp; Backup Security Self-Assessment</a></strong></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size"><strong>How can AI help infrastructure teams </strong><strong>secure </strong><strong>storage and backup </strong><strong>systems</strong><strong>?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">AI helps infrastructure teams by taking on the slow, specialized knowledge work that makes storage and backup security hard to keep up with. It enables natural-language investigation of security posture, so teams can ask plain-English questions like &#8220;which backup systems don&#8217;t have immutability configured&#8221; instead of manually checking each vendor console. It provides AI-assisted hardening analysis that explains why a misconfiguration matters and how to fix it, and prioritizes findings by real-world risk. And it can assist with administration by drafting remediation steps and configuration changes. The core benefit is speed and accessibility across a multi-vendor estate that no single person could fully master.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>What are natural-language security investigations?</strong></p>



<p class="has-small-font-size wp-block-paragraph">Natural-language security investigations let infrastructure teams query their storage and backup environment using plain English rather than logging into multiple consoles and knowing each platform&#8217;s specific settings. For example, instead of manually checking every backup appliance for immutability configuration, a team member can ask &#8220;show me every repository where immutability is off or misconfigured&#8221; and receive an answer drawn from across the whole estate. This moves the platform-specific expertise from the person to the tool, so teams can interrogate their environment without being a specialist in every vendor&#8217;s terminology and menu structure — making it far faster to check posture on demand.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>Is it safe to let AI make changes to storage and backup infrastructure?</strong></p>



<p class="has-small-font-size wp-block-paragraph">It can be safe, but only with the right controls, because AI that can read configurations, analyze posture, or execute changes becomes a highly privileged actor in the environment — exactly the kind of access attackers seek. The practical approach is to govern AI as a privileged operator: give it a real, non-shared identity; establish clear ownership and accountability; enforce least-privilege access so it can only do what its role requires; and ensure every action is auditable. Just as important is validation before execution: rather than letting AI autonomously change a production array, the safer pattern is for AI to propose a change and show exactly what it will do, which systems it affects, and the potential impact — then have a human review and approve it before anything runs, ideally through a reversible path. Full autonomy is earned gradually on low-risk changes, not switched on across the estate from day one. Treating &#8220;AI can do this&#8221; and &#8220;AI should do this unsupervised&#8221; as different questions is what allows teams to gain the efficiency benefits without creating a new attack surface.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>Will AI replace storage and infrastructure administrators?</strong></p>



<p class="has-small-font-size wp-block-paragraph">No. AI is not transforming storage operations overnight or replacing infrastructure teams. Its practical value is in augmenting them — taking on fragmented, time-consuming knowledge work like reading vendor documentation, correlating configuration details across platforms, explaining findings, and drafting remediation steps. The judgment about what matters in a specific environment, what to prioritize, and what changes are safe to make still rests with the infrastructure team. AI gives that judgment better leverage over an estate that has grown too large and varied to secure manually; it does not substitute for it.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>How does StorageGuard use AI for storage and backup operations?</strong></p>



<p class="has-small-font-size wp-block-paragraph">StorageGuard applies AI specifically to storage and backup security operations. It lets teams investigate their security posture in natural language, turns detected configuration drift and exposures into prioritized, clearly explained remediation guidance rather than an undifferentiated list of findings, and does so with the auditability and least-privilege controls appropriate for treating AI as a privileged operator. Rather than replacing the infrastructure team&#8217;s judgment, <a href="https://www.core6.com/storageguard/" target="_blank" rel="noreferrer noopener"><strong>StorageGuard</strong></a> is designed to give that judgment better leverage across a large, multi-vendor estate — helping teams secure and operate storage and backup systems faster than they could by manual, console-by-console work.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.core6.com/blog/practical-ai-for-storage-teams/">Practical AI for Storage Teams (Hold the Hype)</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Your Storage Was Hardened Once. It Isn&#8217;t Anymore.</title>
		<link>https://www.core6.com/blog/your-storage-was-hardened-once-it-isnt-anymore/</link>
		
		<dc:creator><![CDATA[Doron Youngerwood]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 09:22:43 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/secure-today-exposed-tomorrow-the-case-for-continuous-storage-hardening-2/</guid>

					<description><![CDATA[<p>Configuration drift: the silent creator of security risk in storage and backup systems. Every storage and backup environment drifts. Firmware updates reset settings back to their</p>
<p>The post <a href="https://www.core6.com/blog/your-storage-was-hardened-once-it-isnt-anymore/">Your Storage Was Hardened Once. It Isn&#8217;t Anymore.</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="has-medium-font-size wp-block-paragraph"><em><strong>Configuration drift: the silent creator of security risk in storage and backup systems.</strong></em></p>



<p class="wp-block-paragraph">Every storage and backup environment drifts. Firmware updates reset settings back to their defaults. Temporary changes made during an outage never get reverted. A vendor account created for a support engagement outlives it. A permission gets widened &#8220;just for now.&#8221; A retention policy gets adjusted to relieve pressure on a busy window. </p>



<p class="wp-block-paragraph">None of these decisions is wrong in isolation, and none trips an alarm &#8211; but together they pull a storage system, quietly, away from the hardened state it started in.</p>



<p class="wp-block-paragraph">The problem isn&#8217;t that drift happens. Drift is the unavoidable byproduct of a living environment &#8211; one that gets patched, migrated, and reconfigured to keep the business running. The problem is how long it goes unseen. </p>



<p class="wp-block-paragraph">In storage and backup infrastructure, the gap between drifted and detected is often measured in months. These systems are rarely checked with the same rigor as the compute and network layers around them.</p>



<p class="wp-block-paragraph">That neglect shows up clearly in the data. Core6&#8217;s <a href="https://www.core6.com/resources/the-2025-security-maturity-of-storage-data-protection-systems/" target="_blank" rel="noreferrer noopener">2025 Security Maturity of Storage &amp; Data Protection Systems</a> report drew on StorageGuard risk assessments across 323 enterprise environments in North America and EMEA, spanning 11,435 devices. </p>



<p class="wp-block-paragraph">The finding: the average storage or data protection device carries 1<strong>0 distinct security risks</strong> &#8211; five of them rated high or critical. </p>



<p class="wp-block-paragraph">Across the sample analyzed, 6,085 discrete misconfigurations and vulnerabilities were detected, spanning more than 390 security principles that weren&#8217;t adequately followed. </p>



<p class="wp-block-paragraph">This isn&#8217;t a story about a few sloppy outliers. <em>It&#8217;s the baseline state of the industry.</em></p>



<h2 class="wp-block-heading"><strong>Common storage and backup hardening gaps</strong></h2>



<p class="wp-block-paragraph">Drift is a general phenomenon, but it concentrates in a handful of specific, consequential places. Core6&#8217;s report ranked the five most common risk categories across every environment assessed, and they&#8217;re worth walking through, because they&#8217;re the exact areas where a drifted setting does the most damage:</p>



<ul class="wp-block-list">
<li><strong>Authentication and identity management </strong>(the single most common category). This is where over-privileged and orphaned accounts pile up. The vendor account created for a support engagement that outlived it. The admin whose privileges were never scoped back down. The service account with far more access than it needs. It also covers factory default accounts that were never locked or renamed, missing multi-factor authentication, and the absence of Dual Control over destructive operations like backup deletion or immutability changes. These are among the most basic controls in security &#8211; yet they remain the number-one source of storage risk. And they matter doubly here: an immutability lock can often be removed by whoever holds storage-admin identity, so protecting those accounts is as important as the locks themselves. The report notes that the 2024 UnitedHealth attack, which caused weeks of disruption, could have been avoided or significantly reduced by better enforcing identity best practices on its storage and data protection systems.</li>
</ul>



<p class="wp-block-paragraph"></p>



<ul class="wp-block-list">
<li><strong>Unaddressed CVEs.</strong> Storage and backup systems run a surprisingly large stack of proprietary firmware and software. Vulnerabilities in them are published constantly. The problem is that mainstream vulnerability management tools mostly don&#8217;t see them — they scan server OSes and network gear, not storage platforms. The result: 281 distinct CVEs were found across the environments assessed, with 39% of analyzed devices exposed to at least one. And these aren&#8217;t obscure. Recent examples include critical, actively exploited flaws in Dell, Veeam, Acronis, and Veritas Backup Exec products — several used directly by ransomware groups.</li>
</ul>



<p class="wp-block-paragraph"></p>



<ul class="wp-block-list">
<li><strong>Network and protocol security.</strong> This is the classic &#8220;exposed front door&#8221; problem. Storage arrays, backup appliances, and data protection software each ship with management consoles and interfaces — too often left broadly reachable. Legacy or insecure protocols are routinely left enabled: SMBv1, NFSv3, cleartext HTTP management sessions, insecure SNMP community strings. Add failures to enforce secure versions of storage-specific protocols like NDMP, replication, and SAN fabric management, and you have a set of well-understood weaknesses that quietly reappear after every migration. Restricting and monitoring administrative access is one of the most basic hardening steps — and one of the most commonly skipped.</li>
</ul>



<p class="wp-block-paragraph"></p>



<ul class="wp-block-list">
<li><strong>Encryption and key management. </strong>Immutability prevents deletion and modification — but not reading. A backup repository that&#8217;s network-accessible and not encrypted at rest can still be exfiltrated wholesale. Other common gaps: obsolete cipher suites (TLS 1.0/1.1 left enabled, SSL 2.0/3.0 not disabled — some of which must be off for PCI-DSS compliance), and unencrypted management, replication, and backup transport. Most critical of all: backup copies protected with weaker encryption than the source data they&#8217;re meant to safeguard.</li>
</ul>



<p class="wp-block-paragraph"></p>



<ul class="wp-block-list">
<li><strong>Access control and authorization. </strong>A large number of devices showed over-exposure: unrestricted access to shared storage, unrecommended zoning and masking, storage elements reachable from external networks. A recurring failure is backup copies that are less restricted than the production data they protect. When the copy is easier to reach than the original, the protection is illusory.</li>
</ul>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="512" height="341" data-id="14116" src="https://www.core6.com/wp-content/uploads/2026/08/Image-2.png" alt="" class="wp-image-14116" srcset="https://www.core6.com/wp-content/uploads/2026/08/Image-2.png 512w, https://www.core6.com/wp-content/uploads/2026/08/Image-2-300x200.png 300w, https://www.core6.com/wp-content/uploads/2026/08/Image-2-150x100.png 150w" sizes="(max-width: 512px) 100vw, 512px" /></figure>
</figure>



<p class="wp-block-paragraph">Beyond the top five, the report flags several high-severity patterns that map directly to backup resilience. The most important concerns immutability itself. Adoption is rising year-on-year, which is genuinely welcome. But the report detected a significant number of misconfigured deployments &#8211; and a partial or incorrect implementation creates a false sense of security that can be worse than none.</p>



<p class="wp-block-paragraph"><em>The specifics are telling.</em> Ransomware-protection features are frequently licensed but left inactive, or enabled without following vendor best practices. Immutable copies that aren&#8217;t actually locked. Time services left unhardened, letting an attacker roll the clock to bypass retention enforcement. Retention locks never configured &#8211; so an attacker can flood the backup pool with junk data and force the system to delete existing backups to make room. Dual authorization for deletes missing entirely. </p>



<p class="wp-block-paragraph">On top of that, a notable share of systems were running end-of-support, receiving no security updates at all. And in more than 10% of environments, approved API and CLI access paths weren&#8217;t properly hardened, with undocumented entry points discovered whose purpose couldn&#8217;t even be accounted for.</p>



<p class="wp-block-paragraph">A final, quieter gap runs underneath all of these. Many organizations never test whether their backups are actually recoverable. And they don&#8217;t log or alert on unauthorized access to backup and storage systems. The combination is dangerous: a compromised or poisoned backup job can run undetected for months, revealing itself only at the worst possible moment &#8211; during an attempted recovery.</p>



<p class="wp-block-paragraph">None of these are exotic. They&#8217;re the everyday gaps that open quietly as real environments get updated, migrated, patched, and reconfigured. The through-line the report draws is worth sitting with: storage and data protection systems suffer equally. There was no meaningful difference in hardening between primary storage and backup environments. Both drift, both are under-secured — and any one of these gaps can turn a recoverable incident into an unrecoverable one.</p>



<h2 class="wp-block-heading"><strong>How these gaps get exploited in the real world</strong></h2>



<p class="wp-block-paragraph">This isn&#8217;t theoretical. Attackers have shifted decisively toward the data layer, targeting storage and backup either as a primary objective &#8211; exfiltrating large volumes of data &#8220;under the radar&#8221; from less-defended copies &#8211; or as a secondary one, destroying every backup copy just before triggering a ransomware payload.</p>



<p class="wp-block-paragraph">The CVE examples are concrete and recent. A critical flaw in Acronis Cyber Infrastructure (CVE-2023-45249) was flagged by CISA as actively exploited, allowing remote code execution via default passwords. A patch was available for months, but many organizations never applied it &#8211; and were exploited in the wild. </p>



<p class="wp-block-paragraph">The ALPHV/BlackCat group used a set of Veritas Backup Exec (a Cohesity company) vulnerabilities for initial access to deploy ransomware. A critical Veeam flaw (CVE-2024-40711) was used in Frag ransomware attacks, prompting a warning from NHS England. In each case, the weakness lived in the backup or storage layer itself &#8211; the very system meant to be the last line of defense.</p>



<p class="wp-block-paragraph">Backups are now a primary target precisely because destroying them removes the victim&#8217;s leverage. The 2024 UnitedHealth attack is the reference case. The company restored core services in about a month, but fully resolving the fallout took several months — especially for the healthcare providers who depend on it. Core6&#8217;s report notes that stronger enforcement of identity best practices on its storage and data protection systems could have avoided or significantly diminished the incident.</p>



<p class="wp-block-paragraph">The pattern underneath these headlines is the same one the maturity data describes. The attackers aren&#8217;t necessarily using novel techniques; they&#8217;re walking through doors that drift left open &#8211; an unpatched CVE, a default password, an over-exposed backup share, an immutability setting that was licensed but never actually locked.</p>



<h2 class="wp-block-heading"><strong>Configuration baselines: the foundation of security and compliance</strong></h2>



<p class="wp-block-paragraph">If drift is the problem, a baseline is the reference point that makes it visible. A configuration baseline is simply the documented, known-good state your systems are supposed to be in. It defines what &#8220;secure&#8221; means for your environment: the specific settings, access controls, encryption requirements, immutability and retention parameters, and hardening options.</p>



<p class="wp-block-paragraph">Without a baseline, you can&#8217;t detect drift, because you have nothing to measure against. &#8220;Secure&#8221; becomes a matter of memory and assumption. With a baseline, every configuration can be continuously compared against the intended state — and any deviation becomes an answerable question rather than a silent risk.</p>



<p class="wp-block-paragraph">Baselines are also where security and compliance meet. Established frameworks &#8211; NIST, CIS Benchmarks, and vendor-specific hardening guides &#8211; give you a defensible, externally recognized definition of secure, rather than one you invented internally. That matters enormously in regulated industries. Auditors increasingly want evidence not just that you were compliant on the day of the audit, but that your systems stayed within their baseline continuously. Cyber-insurers now expect demonstrable, tested hardening rather than a signed attestation. A baseline turns &#8220;trust us, it&#8217;s secure&#8221; into &#8220;here is the standard, and here is proof we&#8217;re meeting it.&#8221;</p>



<h2 class="wp-block-heading"><strong>Maintaining secure baselines at scale</strong></h2>



<p class="wp-block-paragraph">Defining a baseline is the easy part. The hard part &#8211; the part that defeats most organizations &#8211; is keeping real environments aligned to it as they change, across a multi-vendor estate, at enterprise scale.</p>



<p class="wp-block-paragraph">This is precisely where the traditional approach falls apart. Storage and backup vendors ship their systems with only a minimal base level of security &#8211; deliberately, since they can&#8217;t know your environment. It&#8217;s left to the infrastructure team to define a hardening baseline, implement it, and &#8211; in the report&#8217;s own words &#8211; ensure that configuration is enforced continuously over time, not just at initial deployment. That last part is where most programs break down. </p>



<p class="wp-block-paragraph">A quarterly audit tells you your posture on one day and leaves the rest of the quarter as a blind spot. And in an estate spanning primary storage, secondary storage, backup appliances, and multiple vendors &#8211; each with its own settings and its own ways of drifting &#8211; manual, periodic checking simply cannot keep up.</p>



<p class="wp-block-paragraph">Maintaining baselines at scale requires three things periodic review can&#8217;t provide. Continuous assessment, rather than point-in-time snapshots. Coverage that spans every vendor and platform in the estate, rather than checking them in isolation. And prioritization that surfaces the deviations that actually matter, so teams aren&#8217;t buried under thousands of undifferentiated alerts. The goal isn&#8217;t to eliminate drift &#8211; that&#8217;s impossible in a living environment. It&#8217;s to shrink the time between when something drifts and when you know about it, from months down to something you can act on.</p>



<p class="wp-block-paragraph">This is exactly the problem <strong>StorageGuard</strong> was built to solve. It continuously assesses configurations across enterprise storage, backup, and recovery systems from multiple vendors. It checks them against established baselines like NIST and CIS, as well as vendor-specific hardening guidelines. And it flags drift and security exposures as they emerge &#8211; catching the retention lock that was never configured, the immutability setting that got disabled, the access control that quietly widened. Rather than proving your environment was hardened at a single point in time, it keeps the gap between drift and detection short. Configuration drift stops being a silent risk and becomes a managed one.</p>



<p class="wp-block-paragraph">Configuration drift will never be fully eliminated. The thing that causes it &#8211; a working environment that changes over time &#8211; is also the thing that keeps your business running. The organizations that stay secure aren&#8217;t the ones that somehow freeze their environments. They&#8217;re the ones that define what secure looks like, then catch the drift away from it fast enough that it never has time to matter.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-4 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="256" data-id="14104" src="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png" alt="" class="wp-image-14104" srcset="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png 1024w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-300x75.png 300w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-150x38.png 150w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-768x192.png 768w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1536x384.png 1536w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>
</figure>



<p class="has-medium-font-size wp-block-paragraph"><strong>Want to know where you actually stand?</strong></p>



<p class="wp-block-paragraph">Reading through five domains is one thing; knowing how your own estate scores against them is another. That&#8217;s exactly why we built the <strong>Enterprise Storage &amp; Backup Security Self-Assessment</strong>.</p>



<p class="wp-block-paragraph">It walks you through these same five domains and gives you back a weighted scorecard that surfaces your gaps and shows you which controls to fix first.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel="noreferrer noopener">Take the Enterprise Storage &amp; Backup Security Self-Assessment</a></strong></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size"><strong>What is configuration drift in storage and backup systems?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">Configuration drift is the gradual divergence of a system&#8217;s actual settings from its intended, secure configuration over time. In storage and backup environments, it happens through routine operational changes — firmware updates that reset settings to defaults, temporary changes that are never reverted, vendor accounts that outlive their purpose, widened permissions, and adjusted retention policies. Each change is individually reasonable and none triggers an alarm, but together they move the environment away from its hardened baseline. The scale is significant: Core6&#8217;s 2025 Security Maturity report found the average enterprise storage or data protection device carries 10 distinct security risks, five of them high or critical — evidence that drift, left unchecked, is the normal state of these systems rather than the exception.</p>



<h3 class="wp-block-heading has-small-font-size"><strong>Why is configuration drift such a significant security risk?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">Configuration drift is dangerous because it is invisible and cumulative, and because storage and backup systems are checked far less rigorously than the compute and network layers around them. Core6&#8217;s 2025 research found 281 distinct CVEs across the environments assessed, with 39% of analyzed devices exposed to at least one — largely because mainstream vulnerability management tools don&#8217;t scan storage platforms. In storage and backup specifically, drift can disable immutability, misconfigure retention locks, or leave management interfaces exposed, turning a recoverable ransomware incident into an unrecoverable one. Because attackers now routinely target backup repositories before encrypting production, a drifted backup configuration directly undermines an organization&#8217;s ability to recover without paying a ransom.</p>



<p class="has-small-font-size wp-block-paragraph"><strong><strong><strong>What are the most common storage and backup hardening gaps?</strong></strong></strong></p>



<p class="has-small-font-size wp-block-paragraph">The most common gaps include immutability or retention locks that are not actually enabled or are undermined by misconfigured policies; exposed management interfaces and unchanged default credentials on arrays and backup appliances; over-privileged or orphaned accounts, including vendor accounts that outlived their engagement; untested backups and unmonitored access that let compromised or poisoned backup jobs run undetected; and encryption or protocol gaps that leave network-accessible repositories open to exfiltration. These gaps are rarely the result of negligence — they open naturally as environments are updated, migrated, and reconfigured, which is why continuous checking is needed to catch them.</p>



<h3 class="wp-block-heading has-small-font-size"><strong><strong><strong>What is a configuration baseline and why does it matter?</strong></strong></strong></h3>



<p class="has-small-font-size wp-block-paragraph">A configuration baseline is the documented, known-good state that storage and backup systems are supposed to maintain — the specific settings, access controls, encryption requirements, and immutability and retention parameters that define a secure configuration. Baselines matter because you cannot detect drift without a reference point to measure against. They also form the foundation of compliance: frameworks like NIST and CIS Benchmarks provide an externally recognized definition of secure, and auditors and cyber-insurers increasingly want evidence that systems stay within their baseline continuously, not just on the day of an audit. A baseline turns security from an assumption into something verifiable.</p>



<p class="has-small-font-size wp-block-paragraph"><strong><strong>How can organizations maintain secure configuration baselines at scale?</strong></strong></p>



<p class="has-small-font-size wp-block-paragraph">Maintaining baselines at scale requires continuous assessment rather than periodic reviews, coverage across every vendor and platform in the estate, and prioritization that surfaces the deviations that matter most. Periodic auditing cannot keep pace with drift, because drift occurs continuously through everyday operational changes while manual reviews happen only occasionally — and mainstream security tools largely don&#8217;t cover storage and backup platforms at all. Solutions like <strong><a href="https://www.core6.com/storageguard/" target="_blank" rel="noreferrer noopener">StorageGuard</a></strong> address this by continuously assessing configurations across multi-vendor storage, backup, and recovery systems, checking them against baselines such as NIST and CIS and vendor hardening guidelines, and flagging drift and exposures as they emerge — shrinking the gap between when a system drifts and when the team becomes aware of it from months down to a timeframe teams can act on.</p>
<p>The post <a href="https://www.core6.com/blog/your-storage-was-hardened-once-it-isnt-anymore/">Your Storage Was Hardened Once. It Isn&#8217;t Anymore.</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Secure Today, Exposed Tomorrow: The Case for Continuous Hardening</title>
		<link>https://www.core6.com/blog/secure-today-exposed-tomorrow-the-case-for-continuous-storage-hardening/</link>
		
		<dc:creator><![CDATA[Doron Youngerwood]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 08:52:18 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/the-5-domains-to-harden-first-in-storage-and-backup-systems-2/</guid>

					<description><![CDATA[<p>Why storage and backup hardening is a process you run, not a project you finish. If you&#8217;ve spent any real time running storage or backup infrastructure,</p>
<p>The post <a href="https://www.core6.com/blog/secure-today-exposed-tomorrow-the-case-for-continuous-storage-hardening/">Secure Today, Exposed Tomorrow: The Case for Continuous Hardening</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="has-medium-font-size wp-block-paragraph"><em><strong>Why storage and backup hardening is a process you run, not a project you finish.</strong></em></p>



<p class="wp-block-paragraph">If you&#8217;ve spent any real time running storage or backup infrastructure, you know the feeling. You finish a hardening effort. You&#8217;ve gone through the arrays, closed the gaps the last audit flagged, tightened the backup configs, and documented everything. For a brief, satisfying moment, the environment is clean.</p>



<p class="wp-block-paragraph">You close the ticket. You move on to the next fire. And somewhere in the back of your mind is a quiet thought: &#8220;clean&#8221; has a shelf life. It&#8217;s shorter than anyone in the audit meeting wants to admit.</p>



<p class="wp-block-paragraph">That gap is what this post is about &#8211; the gap between the environment you signed off on and the environment you actually have three months later. Because the way most organizations still approach storage security was built for a world that no longer exists.</p>



<h2 class="wp-block-heading"><strong>The end of the periodic review</strong></h2>



<p class="wp-block-paragraph">For a long time, the periodic security review made sense. You&#8217;d bring in the checklist once a year, maybe once a quarter if you were diligent. You&#8217;d walk the environment against a baseline, fix what was broken, and produce a report that said you were in good shape. Everyone signed it. The auditors were happy.</p>



<p class="wp-block-paragraph">And for the most part, the model held. Not because it was perfect, but because infrastructure changed slowly enough that a snapshot taken in March was still roughly true in September.</p>



<p class="wp-block-paragraph">That assumption has quietly stopped being true. And if you&#8217;re honest about your own environment, you already know why.</p>



<p class="wp-block-paragraph">Think about how much your storage and backup estate actually changes in a normal quarter. Firmware and software updates land across arrays, appliances, and data protection software. Someone spins up a new volume and sets the permissions &#8220;temporarily&#8221; — and never revisits them. A replication relationship gets reconfigured during a migration. An admin account gets created for a vendor engagement and outlives it. Retention policies get adjusted. A snapshot schedule gets tweaked to relieve pressure on a busy window.</p>



<p class="wp-block-paragraph">None of these are mistakes. They&#8217;re the normal metabolism of a working infrastructure. But every one of them can move a configuration off its hardened baseline. And none of them wait politely for your next scheduled review.</p>



<p class="wp-block-paragraph">So the periodic model has a structural flaw that no amount of diligence can fix. It tells you your posture on one day, then asks you to trust it for the next ninety. The review isn&#8217;t wrong when you do it. It just starts decaying the moment you finish. And you can&#8217;t see that decay until the next review comes around &#8211; by which point you&#8217;re not looking at your current environment. You&#8217;re looking at an archaeological record of the one you used to have.</p>



<h2 class="wp-block-heading"><strong>Hardening is a process, not a project</strong></h2>



<p class="wp-block-paragraph">Here&#8217;s the mental shift that actually matters. It&#8217;s less about tooling than about how you frame the work.</p>



<p class="wp-block-paragraph">We tend to talk about hardening as a thing you do &#8211; a project with a start, a middle, and a satisfying end. You scope it, resource it, execute, and close it out. That framing is comforting. It&#8217;s how we manage most infrastructure work, and it produces a clean deliverable you can point to.</p>



<p class="wp-block-paragraph">But it misdescribes what hardening actually is. Hardening isn&#8217;t a state you reach. It&#8217;s a state you maintain, against constant pressure to drift away from it.</p>



<p class="wp-block-paragraph">The closest analogy isn&#8217;t a construction project. It&#8217;s the operational discipline you already apply everywhere else. You don&#8217;t monitor capacity once a year. You don&#8217;t check replication health quarterly and assume it holds. You don&#8217;t run a backup, confirm it worked in January, and never look again.</p>



<p class="wp-block-paragraph">Those things are continuous for a reason. You know from hard experience that the environment doesn&#8217;t sit still, and that finding out something broke months later costs far more than watching it all along. Security posture is no different. It drifts exactly the way capacity and replication health drift &#8211; silently, incrementally, through a thousand small legitimate changes. It deserves the same continuous attention, not a once-a-year physical.</p>



<p class="wp-block-paragraph">Reframing hardening this way changes what &#8220;done&#8221; means. Under the project model, done means the report is signed. Under the process model, there is no done. There&#8217;s only one question: how quickly do you notice when something moves off baseline, and how fast do you bring it back?</p>



<p class="wp-block-paragraph">That sounds like more work. In a manual world, it would be. But it&#8217;s actually the opposite. Continuous hardening replaces the huge, disruptive, all-hands effort of a periodic review-and-remediate cycle with a steady, low-drama process of catching small drifts before they compound. The annual audit stops being a scramble — because the environment was never allowed to drift far in the first place.</p>



<h2 class="wp-block-heading"><strong>Why this matters more than it used to: how attackers exploit infrastructure weaknesses</strong></h2>



<p class="wp-block-paragraph">You could reasonably ask: infrastructure has always drifted, so why is continuous hardening suddenly urgent rather than just good hygiene? The answer is speed. The people looking for these weaknesses have gotten dramatically faster and less selective. That changes the math on how long you can afford to leave a gap open.</p>



<p class="wp-block-paragraph">Start with how your infrastructure looks from an attacker&#8217;s perspective, because it&#8217;s not how we tend to think about it internally. We see arrays, appliances, and management consoles — the tools of the job. An attacker sees something else: management interfaces, service accounts, default credentials that were never changed, exposed protocols, and configuration weaknesses. Each one is a potential way in.</p>



<p class="wp-block-paragraph">And they&#8217;re specifically interested in this layer for a simple, uncomfortable reason. It&#8217;s where the data lives. More importantly, it&#8217;s where the ability to recover data lives. Compromising a backup environment isn&#8217;t a side objective anymore. For anyone running a ransomware operation, neutralizing recovery is the whole game. Corrupt or delete the backups, disable immutability, or quietly alter retention before touching production, and a recoverable incident becomes an existential one.</p>



<p class="wp-block-paragraph">What&#8217;s changed recently is how fast this happens. Finding an exploitable weakness in a specific storage or backup platform used to take real, scarce expertise &#8211; reading the advisory, understanding an unfamiliar system, working out which configurations are actually exposed, and building something to take advantage of it. That scarcity was a kind of protection. Attackers rationed their effort and left a lot of infrastructure alone simply because it wasn&#8217;t worth the hours.</p>



<p class="wp-block-paragraph">AI is dismantling that protection. The tasks that used to gate an attack are exactly the ones these tools accelerate. The window between &#8220;a weakness in your platform becomes known&#8221; and &#8220;someone is actively trying it against you&#8221; has collapsed from months toward days. And because the effort is lower, attackers are far less selective. The overlooked backup appliance in a branch site is no longer beneath notice.</p>



<p class="wp-block-paragraph">Put the two halves together and the risk is clear. Your environment drifts continuously through normal operations. The time between a weakness appearing and someone exploiting it has shrunk dramatically. A periodic review can&#8217;t close that gap, because it isn&#8217;t looking most of the time &#8211; and &#8220;most of the time&#8221; is now exactly the interval an attacker needs. The exposure isn&#8217;t just that weaknesses exist. It&#8217;s how long they sit there undetected between reviews. Duration is the variable, and the periodic model maximizes it by design.</p>



<h2 class="wp-block-heading"><strong>What continuous hardening looks like in practice</strong></h2>



<p class="wp-block-paragraph">Moving from periodic to continuous doesn&#8217;t mean auditing yourself to death or drowning your team in manual checks. That would be unsustainable, and it&#8217;s the opposite of the point. It means the environment is assessed continuously rather than occasionally.</p>



<p class="wp-block-paragraph">In practice, that&#8217;s three things. Configurations across your multi-vendor estate get checked against known-good baselines and vendor best practices on an ongoing basis. Drift is surfaced as it happens, not discovered months later. And the weaknesses that actually matter are prioritized — so your team spends its limited time on what&#8217;s most likely to be exploited, not on working through an undifferentiated list.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-5 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="724" data-id="14124" src="https://www.core6.com/wp-content/uploads/2026/08/Core6_Disciplines_of_Protection-3-1024x724.png" alt="" class="wp-image-14124" srcset="https://www.core6.com/wp-content/uploads/2026/08/Core6_Disciplines_of_Protection-3-1024x724.png 1024w, https://www.core6.com/wp-content/uploads/2026/08/Core6_Disciplines_of_Protection-3-300x212.png 300w, https://www.core6.com/wp-content/uploads/2026/08/Core6_Disciplines_of_Protection-3-150x106.png 150w, https://www.core6.com/wp-content/uploads/2026/08/Core6_Disciplines_of_Protection-3-768x543.png 768w, https://www.core6.com/wp-content/uploads/2026/08/Core6_Disciplines_of_Protection-3.png 1123w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<p class="wp-block-paragraph">This is the problem <strong><a href="https://core6.com/storageguard" target="_blank" rel="noreferrer noopener">StorageGuard</a></strong> was built to solve. Rather than treating hardening as a periodic project, it continuously assesses configurations across enterprise storage, backup, and recovery systems from multiple vendors. It checks them against vendor hardening guidelines and established baselines like NIST and CIS, and flags drift and exposures as they emerge. </p>



<p class="wp-block-paragraph">The gap between something moving off baseline and your team knowing about it stays measured in a timeframe you can actually act on. It&#8217;s built to fit the way infrastructure teams already work &#8211; continuous, prioritized, and focused on keeping the environment hardened rather than proving it was hardened once.</p>



<p class="wp-block-paragraph">The shift here isn&#8217;t really about buying a tool. It&#8217;s about retiring an assumption. The assumption that a point-in-time review reflects your live environment stopped being safe some time ago. The change in attacker speed has just made the cost of clinging to it a lot higher.</p>



<p class="wp-block-paragraph">Storage and backup infrastructure doesn&#8217;t hold still. The security posture of something that doesn&#8217;t hold still can&#8217;t be managed as though it does. Treat hardening as the continuous process it actually is, and &#8220;secure today, exposed tomorrow&#8221; stops being the quiet fear at the back of your mind. You&#8217;ll know about tomorrow&#8217;s exposure tomorrow &#8211; not at next year&#8217;s audit.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-6 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="256" data-id="14104" src="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png" alt="" class="wp-image-14104" srcset="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png 1024w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-300x75.png 300w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-150x38.png 150w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-768x192.png 768w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1536x384.png 1536w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>
</figure>



<p class="has-medium-font-size wp-block-paragraph"><strong>Want to know where you actually stand?</strong></p>



<p class="wp-block-paragraph">Reading through five domains is one thing; knowing how your own estate scores against them is another. That&#8217;s exactly why we built the <strong>Enterprise Storage &amp; Backup Security Self-Assessment</strong>.</p>



<p class="wp-block-paragraph">It walks you through these same five domains and gives you back a weighted scorecard that surfaces your gaps and shows you which controls to fix first.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel="noreferrer noopener">Take the Enterprise Storage &amp; Backup Security Self-Assessment</a></strong></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size"><strong><strong>What is continuous hardening for storage and backup infrastructure?</strong></strong></h3>



<p class="has-small-font-size wp-block-paragraph">Continuous hardening is the practice of assessing storage and backup configurations against secure baselines on an ongoing basis, rather than through periodic reviews or annual audits. Because infrastructure changes constantly — firmware updates, new volumes, permission changes, reconfigured replication, adjusted retention policies — a configuration that was hardened at the last review can quietly drift out of a secure state. Continuous hardening detects that drift as it happens, validates configurations against vendor best practices and standards like NIST and CIS, and surfaces weaknesses so they can be remediated before they are exploited. It treats hardening as an ongoing operational process rather than a one-time project.</p>



<h3 class="wp-block-heading has-small-font-size"><strong>Why are periodic storage security reviews no longer enough?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">Periodic reviews capture an environment&#8217;s security posture at a single point in time, but storage and backup infrastructure changes continuously through normal operations. Between reviews, configurations drift as teams apply updates, provision new storage, adjust policies, and make routine operational changes — none of which wait for the next scheduled audit. This means a review is only accurate on the day it&#8217;s performed and steadily decays afterward, leaving the organization blind to new exposures until the next review months later. Because AI has dramatically shortened the time between a weakness becoming known and being exploited, those blind intervals now represent real, exploitable risk.</p>



<p class="has-small-font-size wp-block-paragraph"><strong><strong>Why is hardening a process rather than a project?</strong></strong></p>



<p class="has-small-font-size wp-block-paragraph">Hardening is a process because a secure configuration is not a permanent state you reach and keep — it&#8217;s a state you have to maintain against constant pressure to drift away from it. Every legitimate operational change, from a firmware update to a new admin account, can move a system off its hardened baseline. Framing hardening as a project with a start and an end creates a false sense of completion, because the environment begins drifting the moment the project closes. Treating it as a continuous process — like capacity monitoring or backup verification, which teams already run continuously — keeps the environment close to baseline at all times and turns the annual audit into a formality rather than a scramble.</p>



<h3 class="wp-block-heading has-small-font-size"><strong><strong>How do attackers exploit storage and backup infrastructure weaknesses?</strong></strong></h3>



<p class="has-small-font-size wp-block-paragraph">Attackers target storage and backup infrastructure through exposed management interfaces, unchanged default credentials, unnecessary service accounts, open protocols, and configuration weaknesses that accumulate as environments drift. They focus on this layer because it holds both the data and the ability to recover it. In ransomware operations, compromising the backup environment is a primary objective: by corrupting or deleting backups, disabling immutability, or altering retention before attacking production, attackers remove the victim&#8217;s ability to recover without paying. AI has accelerated this by making it faster and cheaper to identify and exploit platform-specific weaknesses, shortening the time between a vulnerability becoming known and being actively targeted.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>How does StorageGuard support continuous hardening?</strong></p>



<p class="has-small-font-size wp-block-paragraph">StorageGuard continuously assesses configurations across enterprise storage, backup, and recovery systems from multiple vendors, checking them against vendor hardening guidelines and established baselines such as NIST and CIS. Instead of relying on periodic reviews, it detects configuration drift and security exposures as they emerge, and prioritizes the weaknesses most likely to be exploited so infrastructure teams can focus their remediation effort where it matters most. This keeps the gap between a system drifting off baseline and the team becoming aware of it short, allowing organizations to maintain a hardened posture continuously rather than proving it was hardened at a single point in time.</p>
<p>The post <a href="https://www.core6.com/blog/secure-today-exposed-tomorrow-the-case-for-continuous-storage-hardening/">Secure Today, Exposed Tomorrow: The Case for Continuous Hardening</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Race Between Exposure and Exploitation</title>
		<link>https://www.core6.com/blog/the-race-between-exposure-and-exploitation/</link>
		
		<dc:creator><![CDATA[Doron Youngerwood]]></dc:creator>
		<pubDate>Sun, 23 Aug 2026 11:35:13 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/the-5-domains-to-harden-first-in-storage-and-backup-systems-2/</guid>

					<description><![CDATA[<p>Why storage and backup infrastructure has become the front line &#8211; and why the clock now runs faster than it used to. There&#8217;s a quiet assumption</p>
<p>The post <a href="https://www.core6.com/blog/the-race-between-exposure-and-exploitation/">The Race Between Exposure and Exploitation</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="has-medium-font-size wp-block-paragraph"><em>Why storage and backup infrastructure has become the front line &#8211; and why the clock now runs faster than it used to.</em></p>



<p class="wp-block-paragraph">There&#8217;s a quiet assumption that has held in most security programs for years: if you find a weakness before an attacker does, you&#8217;re fine. Patch it on your next cycle, close the ticket, move on. </p>



<p class="wp-block-paragraph">That assumption was never perfectly true, but it was good enough! The gap between the moment a weakness became known and the moment someone could reliably exploit it was measured in weeks or months &#8211; enough breathing room to schedule the fix around change windows, approvals, and everything else competing for your team&#8217;s attention.</p>



<p class="wp-block-paragraph"><strong>That breathing room is disappearing</strong>. And nowhere is it disappearing faster than in the part of your environment you may have spent the least time thinking about as an attack surface: storage and backup.</p>



<h2 class="wp-block-heading"><strong>Why attackers went after storage and backup in the first place</strong></h2>



<p class="wp-block-paragraph">For most of the last two decades, storage systems sat comfortably in the background. It was plumbing. It held the data, it rarely broke, and security teams focused their energy on endpoints, identities, and the network perimeter. Backup systems were even further down the list &#8211; the safety net you hoped you&#8217;d never need, quietly running its jobs at 2 a.m.</p>



<p class="wp-block-paragraph"><strong>Attackers noticed the neglect before defenders did.</strong></p>



<p class="wp-block-paragraph">The logic is uncomfortable but simple. If your goal is to extort an organization, the most valuable thing you can take from them is not access to a single server &#8211; it&#8217;s the certainty that they can recover without paying you. </p>



<p class="wp-block-paragraph">So the modern ransomware playbook doesn&#8217;t start with encrypting production data. It starts with finding and neutralizing the recovery capability. Delete the snapshots. Corrupt or encrypt the backup repositories. Change the retention settings so that clean copies age out. Disable immutability where it was misconfigured or never turned on. By the time the production environment is hit, the escape hatch has already been welded shut.</p>



<p class="wp-block-paragraph">This changes the economics entirely. An organization with pristine, isolated, verified backups can treat ransomware as a bad weekend. An organization whose backups were quietly compromised three weeks earlier is looking at a business-defining crisis. Attackers know which of those two situations pays, and they invest accordingly.</p>



<p class="wp-block-paragraph">And storage platforms give them a lot to work with. </p>



<p class="wp-block-paragraph">Enterprise environments are rarely uniform &#8211; they&#8217;re a mix of vendors and generations of hardware accumulated over years: primary arrays, secondary storage, purpose-built backup appliances, and the software layers stitching them together. </p>



<p class="wp-block-paragraph">Each has its own management interfaces, its own default configurations, its own security advisories, and its own quiet ways of drifting out of a hardened state as people make routine operational changes. Every one of those interfaces is a door. Many of them were installed with the locks still set to the factory default.</p>



<p class="wp-block-paragraph">The result is a target that is simultaneously high-value and under-defended. That&#8217;s not a combination attackers leave alone for long.</p>



<h2 class="wp-block-heading"><strong>How AI compressed the timeline</strong></h2>



<p class="wp-block-paragraph">Here&#8217;s where the picture shifts from concerning to urgent.</p>



<p class="wp-block-paragraph">For years, the thing that protected under-hardened storage and backup infrastructure was effort. Finding an exploitable weakness in a specific storage platform took genuine expertise &#8211; someone who understood that storage system&#8217;s architecture, could read the security advisory, work out which configurations were actually exposed, and turn that knowledge into a working exploit. </p>



<p class="wp-block-paragraph">That expertise was scarce and expensive, which meant it was rationed. Attackers spent it on the highest-value targets and left the rest alone simply because it wasn&#8217;t worth the hours.</p>



<p class="wp-block-paragraph"><strong>AI is dismantling that natural rate limit.</strong></p>



<p class="wp-block-paragraph">The tasks that used to gate an attack &#8211; reading through documentation and advisories, understanding an unfamiliar platform, spotting the difference between a vulnerable and a hardened configuration, drafting the code to take advantage of it &#8211; are exactly the tasks that language models are now good at. </p>



<p class="wp-block-paragraph">What once required a specialist can increasingly be assembled by someone with far less depth, working far faster. The window between<em> &#8220;this weakness is publicly known&#8221;</em> and <em>&#8220;this weakness is being exploited at scale&#8221;</em> has collapsed from months toward days, and in many cases toward hours.</p>



<p class="wp-block-paragraph">There&#8217;s a second effect that matters just as much. </p>



<p class="wp-block-paragraph">When the cost of developing an attack falls, attackers stop being selective. The old economics protected mid-tier targets and less glamorous parts of the infrastructure because they weren&#8217;t worth the effort. Remove the effort, and everything becomes worth attacking. The overlooked backup appliance in a regional data center is no longer beneath notice &#8211; it&#8217;s just another door, and the cost of trying it has dropped to almost nothing.</p>



<p class="wp-block-paragraph">Put those two shifts together and you get the race this post is named for. </p>



<p class="wp-block-paragraph">On one side, the speed at which security weaknesses can be discovered and weaponized. On the other, the speed at which your organization can find and fix them. For most enterprises, the first side just got dramatically faster while the second stayed exactly where it was &#8211; reliant on periodic assessments, manual reviews, and remediation queued behind everything else.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-7 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="512" height="341" data-id="14116" src="https://www.core6.com/wp-content/uploads/2026/08/Image-2.png" alt="" class="wp-image-14116" srcset="https://www.core6.com/wp-content/uploads/2026/08/Image-2.png 512w, https://www.core6.com/wp-content/uploads/2026/08/Image-2-300x200.png 300w, https://www.core6.com/wp-content/uploads/2026/08/Image-2-150x100.png 150w" sizes="(max-width: 512px) 100vw, 512px" /></figure>
</figure>



<h2 class="wp-block-heading"><strong>The metric that actually matters now</strong></h2>



<p class="wp-block-paragraph">If the timeline has compressed, then the most important number in your risk management program is no longer just how many vulnerabilities you have. It&#8217;s how long each one stays open. Call it the exposure window: <strong>the time between when a weakness becomes exploitable and when you&#8217;ve actually closed it.</strong></p>



<p class="wp-block-paragraph">It&#8217;s worth being precise about why this reframing matters. A critical misconfiguration that exists for two hours and a critical misconfiguration that exists for two months represent wildly different amounts of real risk, even though a vulnerability count treats them identically. </p>



<p class="wp-block-paragraph">Risk isn&#8217;t just severity &#8211; it&#8217;s severity multiplied by the length of time you&#8217;re exposed to it. In a world where exploitation is fast and cheap, duration is the variable you have the most control over, and the one that increasingly decides outcomes.</p>



<p class="wp-block-paragraph">The problem is that the traditional way of managing the security of your storage and backup environment is structurally bad at keeping that window short. </p>



<p class="wp-block-paragraph">An annual audit tells you your posture on one day of the year. A quarterly review leaves a quarter of blind time. Configurations drift between checks as people make changes; new advisories land constantly; something that was hardened in January has quietly slipped by March. Point-in-time assessment was designed for a world where the exposure window could afford to be wide. That world is gone.</p>



<h2 class="wp-block-heading"><strong>Closing the gap</strong></h2>



<p class="wp-block-paragraph">Winning this race doesn&#8217;t require matching attackers&#8217; speed at inventing attacks &#8211; that&#8217;s not a contest defenders can win directly. It requires collapsing the exposure window on your side: knowing your storage and backup posture continuously rather than periodically, seeing weaknesses and configuration drift as they emerge rather than at the next scheduled review, and getting the highest-risk issues into remediation before the compressed timeline works against you.</p>



<p class="wp-block-paragraph">This is the specific problem <strong><a href="https://www.core6.com/storageguard/" target="_blank" rel="noreferrer noopener">StorageGuard</a></strong> was built to address. </p>



<p class="wp-block-paragraph">Rather than treating storage and backup security as something you check on a calendar, it continuously assesses configurations across multi-vendor environments &#8211; primary storage, backup platforms, and the recovery layer &#8211; against vendor best practices and established hardening baselines, surfaces drift and exposures as they appear, and prioritizes what to fix first based on real risk. </p>



<p class="wp-block-paragraph">The point isn&#8217;t to replace the security judgment your team brings; it&#8217;s to make sure that judgment is applied to a current picture instead of a stale one, and that the exposure window stays measured in the timeframe you can defend rather than the one attackers are counting on.</p>



<p class="wp-block-paragraph">The race between exposure and exploitation isn&#8217;t hypothetical, and it isn&#8217;t slowing down. AI has already changed how fast the attacker&#8217;s side of it moves. </p>



<p class="wp-block-paragraph">The organizations that stay ahead won&#8217;t be the ones with the fewest weaknesses &#8211; every enterprise of any size will always have some. They&#8217;ll be the ones who find and close their weaknesses faster than those weaknesses can be turned against them. </p>



<p class="wp-block-paragraph">In the world of storage and backup, where the stakes are your ability to recover at all, that&#8217;s a race worth taking seriously now, while there&#8217;s still room to get ahead of it.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-8 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="256" data-id="14104" src="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png" alt="" class="wp-image-14104" srcset="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png 1024w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-300x75.png 300w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-150x38.png 150w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-768x192.png 768w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1536x384.png 1536w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>
</figure>



<p class="has-medium-font-size wp-block-paragraph"><strong>Want to know where you actually stand?</strong></p>



<p class="wp-block-paragraph">Reading through five domains is one thing; knowing how your own estate scores against them is another. That&#8217;s exactly why we built the <strong>Enterprise Storage &amp; Backup Security Self-Assessment</strong>.</p>



<p class="wp-block-paragraph">It walks you through these same five domains and gives you back a weighted scorecard that surfaces your gaps and shows you which controls to fix first.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel="noreferrer noopener">Take the Enterprise Storage &amp; Backup Security Self-Assessment</a></strong></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size"><strong><strong>Why are ransomware attackers targeting storage and backup infrastructure?</strong></strong></h3>



<p class="has-small-font-size wp-block-paragraph">Attackers target storage and backup systems because compromising them removes an organization&#8217;s ability to recover without paying a ransom. Modern ransomware campaigns often begin by deleting snapshots, corrupting or encrypting backup repositories, altering retention settings, or disabling immutability — neutralizing the recovery capability before encrypting production data. This makes the attack far more profitable, since a victim with intact, isolated backups can refuse to pay, while one whose backups were quietly compromised faces a business-critical crisis. Storage estates are also frequently under-hardened, with multiple vendor platforms, exposed management interfaces, and default configurations that make them attractive, high-value targets.</p>



<h3 class="wp-block-heading has-small-font-size"><strong>How is AI changing ransomware attack timelines?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">AI is dramatically compressing the time between when a vulnerability becomes known and when it is actively exploited — shrinking that window from weeks or months toward days or even hours. Historically, exploiting a weakness in a specific storage platform required scarce, expensive expertise, which limited how many targets attackers pursued. AI now automates the tasks that used to gate an attack — reading advisories, understanding unfamiliar platforms, identifying exploitable configurations, and drafting exploit code — so attacks can be developed faster and by less-skilled actors. This also makes attackers less selective, since previously overlooked systems like regional backup appliances are now cheap enough to target.</p>



<p class="has-small-font-size wp-block-paragraph"><strong><strong>What is an exposure window in cybersecurity?</strong></strong></p>



<p class="has-small-font-size wp-block-paragraph">An exposure window is the length of time between when a security weakness becomes exploitable and when it is actually remediated. It matters because real risk is not just the severity of a vulnerability but severity multiplied by how long the system remains exposed. A critical misconfiguration open for two hours poses far less risk than the same misconfiguration open for two months, even though a simple vulnerability count treats them the same. As AI makes exploitation faster and cheaper, reducing the exposure window has become one of the most important and controllable metrics in storage and backup security.</p>



<h3 class="wp-block-heading has-small-font-size"><strong><strong>Why are periodic security assessments no longer enough for storage and backup systems?</strong></strong></h3>



<p class="has-small-font-size wp-block-paragraph">Periodic assessments — such as annual audits or quarterly reviews — only capture an organization&#8217;s security posture at a single point in time, leaving long stretches of unmonitored risk in between. Storage and backup configurations drift as teams make routine operational changes, new security advisories emerge constantly, and a system hardened one month can silently fall out of compliance the next. Because AI has compressed exploitation timelines, these gaps between reviews are now long enough for attackers to find and exploit weaknesses. This is why organizations are moving from point-in-time assessment to continuous hardening and monitoring.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>How can organizations reduce the exposure window for storage and backup security?</strong></p>



<p class="has-small-font-size wp-block-paragraph">Organizations reduce the exposure window by shifting from periodic checks to continuous assessment of their storage and backup posture, detecting configuration drift and new exposures as they emerge rather than at the next scheduled review, and prioritizing remediation based on actual risk. The goal is not to match the speed at which attackers develop new exploits, but to find and fix weaknesses faster than they can be used. Solutions like <strong>StorageGuard</strong> support this by continuously assessing configurations across multi-vendor storage, backup, and recovery environments against vendor best practices and hardening baselines, surfacing drift and exposures, and helping teams remediate the highest-risk issues first.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.core6.com/blog/the-race-between-exposure-and-exploitation/">The Race Between Exposure and Exploitation</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The 5 domains I&#8217;d harden first in storage and backup systems</title>
		<link>https://www.core6.com/blog/the-5-domains-to-harden-first-in-storage-and-backup-systems/</link>
		
		<dc:creator><![CDATA[Yaniv Valik]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 15:47:58 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/mitigating-vulnerabilities-without-sacrificing-stability-in-storage-and-backup-environments-2/</guid>

					<description><![CDATA[<p>I spend a lot of my time looking at how storage and backup systems are actually configured in the field — not how the vendor datasheet</p>
<p>The post <a href="https://www.core6.com/blog/the-5-domains-to-harden-first-in-storage-and-backup-systems/">The 5 domains I&#8217;d harden first in storage and backup systems</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I spend a lot of my time looking at how storage and backup systems are actually configured in the field — not how the vendor datasheet says they should be, but how they end up after a few years of upgrades, staff changes, and &#8220;we&#8217;ll tighten that later.&#8221; And the pattern is remarkably consistent. The same handful of gaps show up again and again, across vendors, across industries, in shops with serious security teams and shops without.</p>



<p class="wp-block-paragraph">So when people ask me where to start hardening, I don&#8217;t send them a 200-page framework. I point them at five domains. They&#8217;re the same five we built our self-assessment around — Access Control, Audit, Encryption, Cyber Resilience, and Threat Detection — because after enough environments you start to see that almost everything that matters lives in one of those buckets.</p>



<p class="wp-block-paragraph">Here&#8217;s how I think about each one, and the specific things I&#8217;d actually go look at.</p>



<h3 class="wp-block-heading has-medium-font-size"><strong>1. Access Control — this is where it&#8217;s won or lost</strong></h3>



<p class="wp-block-paragraph">If I could only fix one domain, it&#8217;d be this one. The uncomfortable truth about most storage and backup exploits is that they never get started if the attacker can&#8217;t reach your management interfaces and can&#8217;t authenticate against them. Everything else is a second line of defense.</p>



<p class="wp-block-paragraph">The first thing I check is whether the management plane is actually isolated from data traffic. Not &#8220;we intend to&#8221; — whether the management interfaces are genuinely reachable only through a dedicated network or a jump host, and not sitting there answerable from a general workstation VLAN. This is the single most common gap I see, and it&#8217;s also one of the highest-leverage things to fix.</p>



<p class="wp-block-paragraph">From there it&#8217;s the fundamentals, done properly: real authentication controls on every management interface — password complexity, idle-session timeouts, concurrent-session limits, short token lifetimes. An actual process for disabling accounts that have gone inactive, because dormant credentials are exactly what an attacker wants to find. Least-privilege roles, so no single admin can both weaken a control and delete the evidence that they did. And — I cannot say this enough — turn off the protocols and services you&#8217;re not using. Every unused iSCSI, NDMP, FTP, SNMP, or NetBIOS service is attack surface you&#8217;re defending for no reason. Check it again after every upgrade, because upgrades love to quietly re-enable defaults.</p>



<h3 class="wp-block-heading has-medium-font-size"><strong>2. Audit — you can&#8217;t prove what you didn&#8217;t record</strong></h3>



<p class="wp-block-paragraph">Audit gets treated as a compliance chore, and that framing does it a disservice. Yes, it&#8217;s how you satisfy a regulator. But it&#8217;s also the only way you reconstruct what happened after an incident — and if your logs live only on the box that got compromised, you have neither.</p>



<p class="wp-block-paragraph">What I look for: logs from every storage and backup system forwarded to a centralized, tamper-resistant destination. The moment a system goes quiet, that silence should trigger an alert, because it&#8217;s often the first sign something&#8217;s wrong. I want the logging to cover administrative and configuration-change events, not just data access — if someone weakens a hardened setting, that needs to be recorded and attributable to a person. And I want to be able to generate compliance evidence — NIST, ISO, PCI DSS, DORA, NIS2 — without a fire drill of manual data-gathering every cycle.</p>



<h3 class="wp-block-heading has-medium-font-size"><strong>3. Encryption — verify it, don&#8217;t assume it</strong></h3>



<p class="wp-block-paragraph">Encryption is the domain where I see the most false confidence. Teams assume it&#8217;s on because it was licensed, or because it&#8217;s on for <em>some</em> arrays, and never actually confirm it end to end.</p>



<p class="wp-block-paragraph">So I verify. At-rest encryption enabled at the volume, LUN, or pool level for everything sensitive or regulated — and I mean confirmed active, not just available. In-transit encryption on the paths between hosts and storage, and critically on the replication and backup sessions that cross network boundaries. And key management that&#8217;s actually disciplined: keys managed centrally, rotated, protected, with the default keys removed. Encryption you haven&#8217;t verified is a control you&#8217;re hoping works.</p>



<h3 class="wp-block-heading has-medium-font-size"><strong>4. Cyber Resilience — the one to read twice</strong></h3>



<p class="wp-block-paragraph">If you only get one of these five right, make it this one. Everything else reduces the chance of compromise; this domain determines whether you survive it.</p>



<p class="wp-block-paragraph">The whole point of ransomware is to make your data unrecoverable, and these are the controls that keep a clean, restorable copy beyond the attacker&#8217;s reach. When I look at the AI-driven insights coming out of real environments, the failure modes here are painfully common: retention-lock settings misconfigured, backups sitting in the same authentication domain as primary Active Directory, secure time sync missing entirely. Any one of those can turn an incident into a catastrophe.</p>



<p class="wp-block-paragraph">Concretely, what I want to see: local immutable or WORM copies with a retention period a storage admin can&#8217;t shorten mid-attack — because in a real ransomware event, admin credentials may already be compromised. Remote or air-gapped immutable copies isolated from the primary auth domain, so a domain compromise can&#8217;t reach them. Backup infrastructure genuinely isolated at the network, domain, DNS, and directory levels, with separate accounts for primary versus backup. Snapshots protected from deletion by anyone who isn&#8217;t a security officer, with scheduling monitored — an unexplained snapshot-policy change is often an early attack indicator. Authenticated NTP everywhere, because bad timestamps undermine both your forensics and your retention integrity. And versioning enabled so you can roll back after deletion or encryption.</p>



<h3 class="wp-block-heading has-medium-font-size"><strong>5. Threat Detection — shrink the time you&#8217;re blind</strong></h3>



<p class="wp-block-paragraph">Hardening reduces the odds of compromise. Detection reduces how long a compromise goes unnoticed — and in a world where exploitation is getting faster, that window is exactly what you&#8217;re fighting to shrink. Detection at the storage layer matters more than it used to, because that&#8217;s ultimately where the attacker wants to be.</p>



<p class="wp-block-paragraph">I look for anomaly and file-activity monitoring that alerts on the tell-tale patterns — mass reads and writes, high entropy, off-hours access, mass renames or deletions — plus malware scanning on NAS and file storage. I want drift alerting, so that when a previously-hardened system slips off its baseline, I hear about it in real time instead of discovering it at the next quarterly review. And I want regular assessment with remediation actually tracked to closure, not findings logged and forgotten.</p>



<h3 class="wp-block-heading has-medium-font-size"><strong>The honest part</strong></h3>



<p class="wp-block-paragraph">None of this is exotic. There&#8217;s no zero-day magic here — it&#8217;s disciplined configuration, done consistently, and re-checked because storage and backup systems drift the moment you stop looking. That&#8217;s the part people underestimate: hardening isn&#8217;t a state you reach, it&#8217;s a state you maintain.</p>



<p class="wp-block-paragraph">But I&#8217;ll tell you what&#8217;s changed, and why we keep coming back to these five domains now with more urgency than we used to. AI has compressed the time between a vulnerability being disclosed and a working exploit existing. When that window collapses, the controls you own outright — the ones in this checklist — become your primary defense, because they don&#8217;t wait on a vendor patch. You can&#8217;t control when an advisory lands. You can control whether your management plane is isolated, your backups are immutable, and your systems are still hardened this quarter the way they were last quarter.</p>



<p class="wp-block-paragraph"><strong><em>Start with these five. Then keep them true.</em></strong></p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-9 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="256" data-id="14104" src="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png" alt="" class="wp-image-14104" srcset="https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1024x256.png 1024w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-300x75.png 300w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-150x38.png 150w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-768x192.png 768w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2-1536x384.png 1536w, https://www.core6.com/wp-content/uploads/2026/08/Strip-2.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>
</figure>



<p class="has-medium-font-size wp-block-paragraph"><strong>Want to know where you actually stand?</strong></p>



<p class="wp-block-paragraph">Reading through five domains is one thing; knowing how your own estate scores against them is another. That&#8217;s exactly why we built the <strong>Enterprise Storage &amp; Backup Security Self-Assessment</strong>.</p>



<p class="wp-block-paragraph">It walks you through these same five domains and gives you back a weighted scorecard that surfaces your gaps and shows you which controls to fix first.</p>



<p class="wp-block-paragraph"><strong><a href="https://www.core6.com/the-enterprise-storage-security-self-assessment/" target="_blank" rel="noreferrer noopener">Take the Enterprise Storage &amp; Backup Security Self-Assessment</a></strong></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size"><strong>What are the main areas to harden in storage and backup systems?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">Storage and backup hardening breaks down into five domains: Access Control, Audit, Encryption, Cyber Resilience, and Threat Detection. Access Control is the highest-leverage of the five, because most storage and backup exploits fail if an attacker can&#8217;t reach the management plane or authenticate against it. The other four determine whether you can prove what happened, protect data if a control fails, recover after an attack, and detect intrusions quickly.</p>



<h3 class="wp-block-heading has-small-font-size"><strong>Why is hardening </strong>as <strong>important as patching &#8211; for storage and backup systems?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">Patching only helps once a vendor releases a fix, but AI-assisted vulnerability research has shrunk the gap between disclosure and a working exploit — and many of the new vulnerabilities live in embedded components (NFS/RPC stacks, TLS libraries, kernel subsystems) rather than vendor product code. Hardening is the defense you own outright: it doesn&#8217;t wait on a patch, and it reduces exposure before an advisory is even published.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>How often should storage and backup systems be re-checked?</strong></p>



<p class="has-small-font-size wp-block-paragraph">Continuously, not periodically. Storage and backup configurations drift constantly — upgrades and hotfixes silently revert hardened settings, routine changes accumulate, and new advisories arrive faster than a quarterly review can track. A system hardened last quarter is not necessarily hardened today, so the effective approach is continuous validation against a secure baseline with alerting on drift, rather than point-in-time audits.</p>



<h3 class="wp-block-heading has-small-font-size"><strong>Which storage and backup vendors do these hardening principles apply to?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">The five domains are vendor-neutral and apply across all major enterprise storage and backup platforms, including Dell, NetApp, Hitachi Vantara, Everpure (formerly Pure Storage), HPE, IBM, Infinidat, VAST Data, Nutanix, Cisco, Broadcom (Brocade), Rubrik, Cohesity (including Veritas NetBackup), Commvault, Veeam, Nasuni, and CTERA. How each control is implemented varies by platform, but what to check — access, audit, encryption, resilience, detection — stays the same.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.core6.com/blog/the-5-domains-to-harden-first-in-storage-and-backup-systems/">The 5 domains I&#8217;d harden first in storage and backup systems</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Security vs. Stability Dilemma. Mitigating Vulnerabilities Without Sacrificing Stability in Storage and Backup Environments</title>
		<link>https://www.core6.com/blog/mitigating-vulnerabilities-without-sacrificing-stability-in-storage-and-backup-environments/</link>
		
		<dc:creator><![CDATA[Yaniv Valik]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 13:15:58 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/adhering-to-uk-cyber-essentials-for-storage-and-backup-infrastructure-2/</guid>

					<description><![CDATA[<p>In the wake of AI-assisted cyberattacks, many organizations are looking for ways to accelerate the deployment of patches and software updates in production environments, including storage and backup</p>
<p>The post <a href="https://www.core6.com/blog/mitigating-vulnerabilities-without-sacrificing-stability-in-storage-and-backup-environments/">The Security vs. Stability Dilemma. Mitigating Vulnerabilities Without Sacrificing Stability in Storage and Backup Environments</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In the wake of AI-assisted cyberattacks, many organizations are looking for ways to accelerate the deployment of patches and software updates in production environments, including storage and backup infrastructure. Yet operational realities often mean that <strong>patching cycles for storage and backup systems are still measured in months</strong> rather than weeks. </p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Both realities are understandable.</strong>&nbsp;</p>



<p class="wp-block-paragraph">Accelerating patch deployment is a worthy objective. The speed, scale, and automation of modern cyberattacks demand greater efficiency in patch management, software updates, and platform upgrades. The faster a security fix reaches production, the smaller the window of opportunity for attackers to exploit a vulnerability. </p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Yet the opposite force is equally valid.</strong>&nbsp;</p>



<p class="wp-block-paragraph">Storage and backup systems sit at the core of the datacenter. A problematic software update on a storage platform can adversely affect dozens or hundreds of applications, multiple business units, and potentially critical business operations. </p>



<p class="wp-block-paragraph">As a result, organizations invest significant effort in patch review, testing, rollback planning, change management, and validation before deploying updates into production. </p>



<p class="wp-block-paragraph">The same is true for backup systems. </p>



<p class="wp-block-paragraph">Organizations are understandably cautious about introducing changes that could destabilize or disrupt their ability to recover from cyberattacks, ransomware, or operational disasters. When your backup environment is your last line of defense, reliability matters as much as security. </p>



<p class="wp-block-paragraph">Eventually, these competing priorities will find a new balance. Patching cycles will likely continue to accelerate, but rigorous testing and operational safeguards will remain essential. </p>



<p class="wp-block-paragraph">In parallel with these efforts, however, there is <strong>another security process</strong> that can significantly reduce exposure without requiring frequent software changes. In fact, it can be performed continuously. </p>



<p class="wp-block-paragraph">I&#8217;m&nbsp;talking about&nbsp;<strong>configuration hardening</strong>.&nbsp;</p>



<p class="wp-block-paragraph">By configuring storage and backup systems according to security best practices, organizations can materially reduce the likelihood of successful vulnerability exploitation for both published and zero-day vulnerabilities. </p>



<p class="wp-block-paragraph">Restricting administrative privileges, encrypting communications, limiting management access, disabling unnecessary services, protocols, and ports, and applying other hardening controls all help reduce the attack surface available to attackers. </p>



<p class="wp-block-paragraph">In many ways, <strong>hardening can be just as important as patching when it comes to reducing day-to-day exposure. </strong></p>



<p class="wp-block-paragraph">This is particularly true for storage and backup appliances. </p>



<p class="wp-block-paragraph">Unlike general-purpose servers, these platforms often provide limited flexibility for modifying the embedded operating system. As a result, organizations are frequently dependent on vendor patches. Hardening becomes one of the few controls available to reduce risk while waiting for those patches to arrive, be tested, and eventually be deployed. </p>



<p class="wp-block-paragraph"><strong>To understand why, consider the typical vulnerability lifecycle. </strong></p>



<p class="wp-block-paragraph">At some point after a storage or backup system is deployed, a vulnerability is introduced (t0).&nbsp;Later&nbsp;it becomes known publicly as a zero-day vulnerability (t1). An advisory is published (t2). Sometimes mitigation guidance becomes available (t3), although this is not always the case for storage and backup appliances. Eventually a patch is released (t4).&nbsp;</p>



<p class="wp-block-paragraph">The patch then enters the organization&#8217;s testing, validation, and change management processes before approval (t5) and finally deployment into production (t6).&nbsp;</p>



<p class="wp-block-paragraph">The reality is that&nbsp;<strong>exposure exists throughout the entire period between t0 and t6</strong>.&nbsp;</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-10 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="683" data-id="14058" src="https://www.core6.com/wp-content/uploads/2026/07/Vuln-1024x683.png" alt="" class="wp-image-14058" srcset="https://www.core6.com/wp-content/uploads/2026/07/Vuln-1024x683.png 1024w, https://www.core6.com/wp-content/uploads/2026/07/Vuln-300x200.png 300w, https://www.core6.com/wp-content/uploads/2026/07/Vuln-150x100.png 150w, https://www.core6.com/wp-content/uploads/2026/07/Vuln-768x512.png 768w, https://www.core6.com/wp-content/uploads/2026/07/Vuln.png 1536w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<p class="wp-block-paragraph">For a single vulnerability, this may seem manageable. However,&nbsp;organizations are&nbsp;rarely&nbsp;dealing&nbsp;with a single vulnerability. There is a constant stream of newly discovered issues, often dozens or hundreds of vulnerabilities across a single platform over time.&nbsp;</p>



<p class="wp-block-paragraph">Now scale that across enterprise storage arrays, file storage systems, object stores, software-defined storage platforms, SAN switches, backup appliances, and other infrastructure platforms.&nbsp;</p>



<p class="wp-block-paragraph">Suddenly, the challenge becomes clear. At any given time, organizations are dealing with X unpatched vulnerabilities across Y systems. Neither number is static. New vulnerabilities continuously emerge, systems are added or upgraded, and patches move through testing and change management processes. </p>



<p class="wp-block-paragraph">This is precisely why configuration hardening is so important. It reduces exposure continuously in a threat landscape that is itself continuously evolving. </p>



<p class="wp-block-paragraph">While patching&nbsp;remains&nbsp;essential, configuration hardening is often the only practical control that continuously reduces exposure across this entire period. Alongside foundational controls such as network segmentation, access controls, and monitoring, hardening serves as a primary defense against vulnerability exploitation.&nbsp;</p>



<p class="wp-block-paragraph">Equally important, <strong>weak, unhardened configurations are themselves security weaknesses</strong>. <strong>Attackers routinely exploit weak configurations to gain visibility into environments, expand access, move laterally, and execute malicious actions</strong>. </p>



<p class="wp-block-paragraph">Unlike software vulnerabilities, these weaknesses cannot be remediated with a software patch because they are not software defects. They must be addressed through secure configuration and ongoing hardening practices. </p>



<p class="wp-block-paragraph">Hardening also plays an important role when organizations identify <strong>high-risk vulnerabilities that cannot be patched immediately</strong>. In those cases, compensating configuration controls can help reduce risk until remediation becomes possible. </p>



<p class="wp-block-paragraph">Examples might include tightening management access control lists (ACLs), disabling optional services that are not required for operations, enforcing stronger authentication mechanisms, or introducing Multi-Person Authorization (MPA) for sensitive administrative actions. These measures may not remove the vulnerability, but they can significantly reduce the likelihood that it will be successfully exploited. </p>



<p class="wp-block-paragraph">The challenge, of course, is maintaining hardening at scale. </p>



<p class="wp-block-paragraph">In large, multi-vendor environments, <strong>ensuring that storage and backup systems are configured securely and remain secure over time is far from trivial</strong>. </p>



<p class="wp-block-paragraph">Configuration drift occurs. New software releases introduce changes. Administrative actions unintentionally weaken security settings. Meanwhile, industry best practices continue to evolve. </p>



<p class="wp-block-paragraph">Controls that are widely considered mandatory today were not necessarily part of security baselines a few years ago. Multi-Factor Authentication is an obvious example. Multi-Person Authorization is rapidly becoming another. The same pattern will continue as new threats&nbsp;emerge&nbsp;and defensive techniques mature.&nbsp;</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Hardening is therefore not a one-time activity. It is an ongoing process.</strong>&nbsp;</p>



<p class="wp-block-paragraph">Organizations need a way to continuously verify that their storage and backup infrastructure remains aligned with security best practices, vendor hardening guidance, regulatory requirements, and their own internal security standards. </p>



<p class="wp-block-paragraph">Just as importantly, they need a way to identify when configuration drift or newly introduced risks move systems away from their intended security baseline. </p>



<p class="wp-block-paragraph">As patch cycles accelerate to meet the realities of AI-driven cyber threats, hardening should not be viewed as a secondary control. It is a complementary and often indispensable layer of defense that helps reduce exposure every day between vulnerability discovery and patch deployment.&nbsp;</p>



<p class="wp-block-paragraph">In many environments, it is the most practical way to reduce risk without compromising the operational stability that storage and backup platforms demand. Patching removes vulnerabilities. Hardening reduces the opportunities to exploit them while organizations work through the realities of production deployment. </p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-11 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://www.core6.com/talk-to-an-expert/"><img decoding="async" width="1024" height="256" data-id="14059" src="https://www.core6.com/wp-content/uploads/2026/07/Strip-1-1024x256.png" alt="" class="wp-image-14059" srcset="https://www.core6.com/wp-content/uploads/2026/07/Strip-1-1024x256.png 1024w, https://www.core6.com/wp-content/uploads/2026/07/Strip-1-300x75.png 300w, https://www.core6.com/wp-content/uploads/2026/07/Strip-1-150x38.png 150w, https://www.core6.com/wp-content/uploads/2026/07/Strip-1-768x192.png 768w, https://www.core6.com/wp-content/uploads/2026/07/Strip-1-1536x384.png 1536w, https://www.core6.com/wp-content/uploads/2026/07/Strip-1.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>
</figure>



<p class="has-medium-font-size wp-block-paragraph"><strong>Want to know where your storage and backup systems stand today? <a href="https://www.core6.com/talk-to-an-expert/" target="_blank" rel="noreferrer noopener">Talk to an expert</a> and see how StorageGuard can help you continuously &#8211; and autonomously &#8211; harden your infrastructure against vulnerability exploitation.</strong></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size"><strong>What is the difference between patching and configuration hardening?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">Patching removes software vulnerabilities by applying vendor-issued fixes, while configuration hardening reduces the opportunity to exploit vulnerabilities by securing how systems are set up. Patching addresses code defects; hardening addresses weak settings like excessive administrative privileges, unnecessary open ports, unencrypted communications, and weak authentication. The two are complementary: patching eliminates the flaw, hardening limits exposure while patches are tested and deployed—and defends against configuration weaknesses that no patch can fix.</p>



<h3 class="wp-block-heading has-small-font-size">Why is configuration hardening important for storage and backup systems specifically?</h3>



<p class="has-small-font-size wp-block-paragraph">Storage and backup systems sit at the core of the datacenter, so a problematic patch can disrupt dozens or hundreds of applications, which is why patch cycles for these systems often take months. Hardening reduces risk continuously without requiring frequent software changes. Storage and backup appliances also offer limited flexibility to modify their embedded operating systems, making organizations dependent on vendor patches—so hardening becomes one of the few controls available to reduce risk in the meantime.</p>



<p class="has-small-font-size wp-block-paragraph"><strong><strong>What are common examples of storage and backup hardening controls?</strong></strong></p>



<p class="has-small-font-size wp-block-paragraph">Common hardening controls include restricting administrative privileges, encrypting management and data communications, limiting management access through tightened ACLs, disabling unnecessary services, protocols, and ports, enforcing multi-factor authentication (MFA), and introducing multi-person authorization (MPA) for sensitive administrative actions. These measures reduce the attack surface and can serve as compensating controls when high-risk vulnerabilities cannot be patched immediately.</p>



<h3 class="wp-block-heading has-small-font-size"><strong>Why is hardening more important in the age of AI-driven cyberattacks?</strong></h3>



<p class="has-small-font-size wp-block-paragraph">AI increases the speed, scale, and automation of cyberattacks, shrinking the time attackers need to exploit a vulnerability. This pressures organizations to patch faster, but storage and backup patch cycles remain slow due to operational risk. Hardening provides a continuous layer of defense that reduces exposure every day between vulnerability discovery and patch deployment, making it an indispensable complement to patching in the AI threat era.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.core6.com/blog/mitigating-vulnerabilities-without-sacrificing-stability-in-storage-and-backup-environments/">The Security vs. Stability Dilemma. Mitigating Vulnerabilities Without Sacrificing Stability in Storage and Backup Environments</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Adhering to UK Cyber Essentials for Storage &#038; Backup Infrastructure</title>
		<link>https://www.core6.com/blog/adhering-to-uk-cyber-essentials-for-storage-and-backup-infrastructure/</link>
		
		<dc:creator><![CDATA[Yaniv Valik]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 08:31:26 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/storage-in-the-ai-era-what-enterprise-leaders-are-learning-about-performance-protection-resilience-2/</guid>

					<description><![CDATA[<p>During April, we met with Aimie Coole and Gary McIntosh, Field CTOs at Dell Technologies and long-time experts in cyber resilience. As we demoed StorageGuard and</p>
<p>The post <a href="https://www.core6.com/blog/adhering-to-uk-cyber-essentials-for-storage-and-backup-infrastructure/">Adhering to UK Cyber Essentials for Storage &amp; Backup Infrastructure</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">During April, we met with <a href="https://www.linkedin.com/in/aimie-coole-7a380840/" target="_blank" rel="noreferrer noopener">Aimie Coole</a> and <a href="https://www.linkedin.com/in/mcintoshgary/" target="_blank" rel="noreferrer noopener">Gary McIntosh</a>, Field CTOs at <strong>Dell Technologies</strong> and long-time experts in cyber resilience. As we demoed StorageGuard and walked through the configuration compliance tab &#8211; showing out-of-the-box policies for NIS2, NCSC CAF, DORA, NIST, ISO, PCI DSS, CIS, and more &#8211; both Aimie and Gary pointed out how useful it would be to include the <strong>UK Cyber Essentials </strong>framework, given how widely it’s used.</p>



<p class="wp-block-paragraph">Fast forward to June &#8211; we’re happy to add UK Cyber Essentials to the list of supported standards, and to thank Aimie and Gary for highlighting the gap.</p>



<p class="has-large-font-size wp-block-paragraph"><strong>What is UK Cyber Essentials?</strong></p>



<p class="wp-block-paragraph"><a href="https://www.ncsc.gov.uk/cyberessentials/overview" target="_blank" rel="noreferrer noopener">UK Cyber Essentials</a> is a government-backed certification scheme overseen by the UK National Cyber Security Centre (NCSC). It defines a baseline set of security controls to help organizations protect against common internet-based attacks.</p>



<p class="has-large-font-size wp-block-paragraph"><strong>How StorageGuard helps</strong></p>



<p class="wp-block-paragraph"><a href="https://www.core6.com/storageguard/" target="_blank" rel="noreferrer noopener">StorageGuard</a> automatically gathers configuration data from storage and backup systems and validates it against Cyber Essentials requirements. It provides a clear status view, along with detailed evidence showing how each requirement is (or isn’t) met.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-12 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="683" data-id="14031" src="https://www.core6.com/wp-content/uploads/2026/07/Designer-49-1024x683.png" alt="" class="wp-image-14031" srcset="https://www.core6.com/wp-content/uploads/2026/07/Designer-49-1024x683.png 1024w, https://www.core6.com/wp-content/uploads/2026/07/Designer-49-300x200.png 300w, https://www.core6.com/wp-content/uploads/2026/07/Designer-49-150x100.png 150w, https://www.core6.com/wp-content/uploads/2026/07/Designer-49-768x512.png 768w, https://www.core6.com/wp-content/uploads/2026/07/Designer-49.png 1536w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<p class="wp-block-paragraph">You can generate evidence-backed compliance reports &#8211; including the underlying configuration data &#8211; and quickly prove compliance. When deviations are found, StorageGuard highlights them with actionable guidance, including recommended steps or commands, surfaced in the UI, via email, or integrated with ITSM workflows.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-13 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="683" data-id="14030" src="https://www.core6.com/wp-content/uploads/2026/07/Designer-48-1024x683.png" alt="" class="wp-image-14030" srcset="https://www.core6.com/wp-content/uploads/2026/07/Designer-48-1024x683.png 1024w, https://www.core6.com/wp-content/uploads/2026/07/Designer-48-300x200.png 300w, https://www.core6.com/wp-content/uploads/2026/07/Designer-48-150x100.png 150w, https://www.core6.com/wp-content/uploads/2026/07/Designer-48-768x512.png 768w, https://www.core6.com/wp-content/uploads/2026/07/Designer-48.png 1536w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<p class="has-large-font-size wp-block-paragraph"><strong>About Dell and StorageGuard</strong></p>



<p class="wp-block-paragraph">StorageGuard is part of the Dell Technologies <a href="https://www.dell.com/en-us/lp/dt/solutions-extended-technologies-complete" target="_blank" rel="noreferrer noopener">Extended Technologies Complete (ETC)</a> partnership program. It complements the Dell portfolio by providing security posture management &#8211; including configuration drift management &#8211; across both Dell and non-Dell storage and data protection systems. </p>



<p class="wp-block-paragraph">Through this ETC program, Dell customers can more easily access and evaluate StorageGuard in the context of their existing environments.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Review a recent joint Dell + Core6 customer story &#8211; <a href="https://www.dell.com/en-us/blog/dell-and-core6-strengthen-storage-security-for-global-insurer/" target="_blank" rel="noreferrer noopener">Dell and Core6 Strengthen Storage Security for Global Insurer</a></strong></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size">What is UK Cyber Essentials?</h3>



<p class="has-small-font-size wp-block-paragraph">UK Cyber Essentials is a UK government-backed cybersecurity certification scheme that helps organizations protect against common cyber threats by implementing a baseline set of security controls. It is overseen by the National Cyber Security Centre (NCSC).</p>



<h3 class="wp-block-heading has-small-font-size">How does UK Cyber Essentials apply to storage and backup infrastructure?</h3>



<p class="has-small-font-size wp-block-paragraph">While Cyber Essentials does not focus exclusively on storage and backup systems, many of its requirements relate to secure configuration, access control, vulnerability management, and system hardening. Storage and backup platforms play a critical role in meeting these requirements and supporting cyber resilience.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>How can organizations assess Cyber Essentials compliance for storage systems?</strong></p>



<p class="has-small-font-size wp-block-paragraph">Organizations can assess compliance by reviewing storage and backup configurations against Cyber Essentials requirements, identifying configuration gaps, documenting evidence, and implementing remediation actions where needed.</p>



<h3 class="wp-block-heading has-small-font-size">What evidence does StorageGuard provide for Cyber Essentials audits?</h3>



<p class="has-small-font-size wp-block-paragraph">StorageGuard generates detailed compliance reports that include configuration settings, assessment results, identified deviations, and supporting evidence that can help simplify Cyber Essentials audit preparation and reporting.</p>
<p>The post <a href="https://www.core6.com/blog/adhering-to-uk-cyber-essentials-for-storage-and-backup-infrastructure/">Adhering to UK Cyber Essentials for Storage &amp; Backup Infrastructure</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Storage in the AI Era: What Enterprise Leaders Are Learning About Performance, Protection &#038; Resilience </title>
		<link>https://www.core6.com/blog/storage-in-the-ai-era-what-enterprise-leaders-are-learning-about-performance-protection-resilience/</link>
		
		<dc:creator><![CDATA[Doron Youngerwood]]></dc:creator>
		<pubDate>Sun, 05 Jul 2026 12:57:05 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/we-didnt-expect-storage-security-to-be-cool-either-then-frost-sullivan-called-2/</guid>

					<description><![CDATA[<p>AI is rapidly reshaping enterprise storage.&#160; What started as a conversation about GPUs and infrastructure performance has evolved into something much broader: data growth, cyber resilience,</p>
<p>The post <a href="https://www.core6.com/blog/storage-in-the-ai-era-what-enterprise-leaders-are-learning-about-performance-protection-resilience/">Storage in the AI Era: What Enterprise Leaders Are Learning About Performance, Protection &amp; Resilience </a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">AI is rapidly reshaping enterprise storage.&nbsp;</p>



<p class="wp-block-paragraph">What started as a conversation about GPUs and infrastructure performance has evolved into something much broader: data growth, cyber resilience, recovery readiness, governance, and entirely new architectural approaches.&nbsp;</p>



<p class="wp-block-paragraph">These themes were front and center during a recent <strong><a href="https://www.core6.com/resources/storage-leaders-virtual-panel-storage-in-the-ai-era-performance-protection-resilience/" target="_blank" rel="noreferrer noopener">Storage Leaders Virtual Panel</a></strong>, which brought together experts from <strong>Dell Technologies</strong>, <strong>NetApp</strong>, <strong>Hitachi Vantara</strong>, <strong>IBM</strong>, <strong>Infinidat (Lenovo)</strong>, and <strong>VAST Data</strong> to discuss how AI is changing the way organizations think about storage. </p>



<p class="wp-block-paragraph">While the panelists represented different vendors and viewpoints, there was remarkable agreement on one point: Storage is no longer just about storing data. It&#8217;s becoming the foundation on which enterprise AI initiatives succeed &#8211; or fail. </p>



<p class="has-large-font-size wp-block-paragraph"><strong>Storage Has Moved to the Center of the AI Conversation </strong></p>



<p class="wp-block-paragraph">One of the most striking observations of the discussion was how dramatically the storage conversation has changed over the past&nbsp;18 months.&nbsp;</p>



<p class="wp-block-paragraph">According to <strong>Itzik Reich, VP Mission Alignment at VAST Data</strong>, storage discussions used to be confined to infrastructure teams and procurement departments. Today, CTOs, Chief Data Officers, AI leaders, and even board members are involved because storage has become directly tied to AI outcomes. </p>



<p class="wp-block-paragraph">The metric that increasingly matters&nbsp;isn&#8217;t&nbsp;IOPS or throughput.&nbsp;It&#8217;s&nbsp;GPU&nbsp;utilization.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Patrick Fay, AI Storage Product Manager at IBM</strong> reinforced this shift from another angle. AI is creating unprecedented pressure on infrastructure supply chains. The industry started by worrying about GPU shortages. Then memory became constrained. Now storage is experiencing similar pressures as demand drives up the cost of NAND and HDD capacity. </p>



<p class="has-large-font-size wp-block-paragraph"><strong>AI Doesn&#8217;t Create One Storage Problem. It Creates Four </strong></p>



<p class="wp-block-paragraph">According to Itzik, every phase of the AI lifecycle stresses storage differently.&nbsp;</p>



<ul class="wp-block-list">
<li>Training: Metadata often becomes the bottleneck before throughput. </li>



<li>Checkpointing: Massive bursts of write activity can leave GPUs idle while waiting for storage. </li>



<li>Inference: Latency matters more than average performance. </li>



<li>RAG: Storage must simultaneously act as a data lake, database, and vector store. </li>
</ul>



<p class="wp-block-paragraph">Patrick highlighted an&nbsp;additional&nbsp;challenge: organizations are dramatically underestimating how much data AI will generate. Many enterprises are seeing datasets expand several&nbsp;times over&nbsp;through embeddings, metadata, and AI-generated outputs.&nbsp;</p>



<p class="has-large-font-size wp-block-paragraph"><strong>The Biggest Gap Isn&#8217;t Technology. It&#8217;s Architecture </strong></p>



<p class="wp-block-paragraph"><strong>Felix Jorge, Field CTO at Hitachi Vantara</strong> argued that the biggest challenge isn&#8217;t technology. It&#8217;s architectural intent. </p>



<p class="wp-block-paragraph">Legacy environments were designed around predictable workloads and gradual growth. AI changes those assumptions completely.&nbsp;</p>



<p class="wp-block-paragraph">Organizations can no longer rely solely on capacity forecasting and periodic refresh cycles. Instead, they must design architectures that adapt continuously.&nbsp;</p>



<p class="has-large-font-size wp-block-paragraph"><strong>Ransomware Has Moved Beyond Encryption </strong></p>



<p class="wp-block-paragraph"><strong>Adam Gale, Field CTO – AI &amp; Security at NetApp</strong> observed that modern attacks are increasingly becoming three-stage operations: breach and encrypt, exfiltrate data, and corrupt recovery mechanisms. </p>



<p class="wp-block-paragraph">Felix&nbsp;expanded on&nbsp;this trend, explaining that attackers are increasingly targeting backup infrastructure, replication paths, recovery environments, privileged accounts, and immutable storage copies.&nbsp;</p>



<p class="wp-block-paragraph">The goal is no longer simply disruption.&nbsp;It&#8217;s&nbsp;the destruction of confidence in recovery.&nbsp;</p>



<p class="has-large-font-size wp-block-paragraph"><strong>Most Organizations Overestimate Their Recovery Readiness </strong></p>



<p class="wp-block-paragraph"><strong>Aimie Coole, Field CTO – Europe at Dell Technologies</strong> noted that many organizations assume recovery will work when needed. Unfortunately, that assumption is often wrong. </p>



<p class="wp-block-paragraph">Common issues include missing incident response plans, untested recovery procedures, outdated runbooks, poor communication processes, end-of-life infrastructure, and insufficient telemetry.&nbsp;</p>



<p class="wp-block-paragraph">As Aimie summarized: Most organizations test for backup success, not operational recovery success.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Eric Herzog, CMO at Infinidat (Lenovo)</strong> took this argument further, encouraging organizations to treat cyberattacks as disasters and practice recovery accordingly. </p>



<p class="has-large-font-size wp-block-paragraph"><strong>Storage Still Has a Visibility Problem </strong></p>



<p class="wp-block-paragraph">Aimie argued that while storage teams&nbsp;generally have&nbsp;good visibility into capacity, availability, and performance, many have limited visibility into identity risks, privileged account exposure, configuration drift, recovery readiness, and backup security posture.&nbsp;</p>



<p class="wp-block-paragraph">Eric reinforced this point, arguing that storage teams are too often excluded from broader cybersecurity initiatives despite managing&nbsp;the vast majority of&nbsp;enterprise data.&nbsp;</p>



<p class="has-large-font-size wp-block-paragraph"><strong>AI Is Both the Threat &#8211; And the Defense </strong></p>



<p class="wp-block-paragraph">Adam brought an important note of optimism to the discussion.&nbsp;</p>



<p class="wp-block-paragraph">His view: We are entering a golden age of cyber resilience.&nbsp;</p>



<p class="wp-block-paragraph">For the first time, defenders have access to AI-powered tools capable of&nbsp;identifying&nbsp;anomalies, accelerating investigations, and strengthening security at scales that would previously have&nbsp;required&nbsp;thousands of analysts.&nbsp;</p>



<p class="wp-block-paragraph">At the same time, AI introduces new risks, including AI-generated phishing,&nbsp;deepfake&nbsp;impersonation, voice cloning, and data poisoning.&nbsp;</p>



<p class="has-large-font-size wp-block-paragraph"><strong>The Future of Storage </strong></p>



<p class="wp-block-paragraph">The session concluded with a discussion about storage refresh cycles.&nbsp;</p>



<p class="wp-block-paragraph">Patrick believes AI-focused storage infrastructure may evolve faster than traditional storage environments. Felix argued that organizations should focus less on refresh cycles and more on building architectures that can evolve incrementally over time.&nbsp;</p>



<p class="has-large-font-size wp-block-paragraph"><strong>Final Thoughts </strong></p>



<p class="wp-block-paragraph">Storage is no longer simply an infrastructure layer.&nbsp;</p>



<p class="wp-block-paragraph">It&#8217;s&nbsp;becoming a performance platform for AI, a control point for cyber resilience, a governance and compliance layer, and a business continuity dependency.&nbsp;</p>



<p class="wp-block-paragraph">The future of storage will be defined by an organization&#8217;s ability to balance performance, protection, and resilience simultaneously. </p>



<p class="wp-block-paragraph"><strong>Watch the recording of the Storage Leaders Virtual Panel at <a href="https://www.core6.com/resources/storage-leaders-virtual-panel-storage-in-the-ai-era-performance-protection-resilience/" target="_blank" rel="noreferrer noopener">https://www.core6.com/resources/storage-leaders-virtual-panel-storage-in-the-ai-era-performance-protection-resilience/</a></strong></p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-14 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://www.core6.com/resources/storage-leaders-virtual-panel-storage-in-the-ai-era-performance-protection-resilience/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="535" data-id="13981" src="https://www.core6.com/wp-content/uploads/2026/05/LinkedIn-Images-66-1024x535.png" alt="" class="wp-image-13981" srcset="https://www.core6.com/wp-content/uploads/2026/05/LinkedIn-Images-66-1024x535.png 1024w, https://www.core6.com/wp-content/uploads/2026/05/LinkedIn-Images-66-300x157.png 300w, https://www.core6.com/wp-content/uploads/2026/05/LinkedIn-Images-66-150x78.png 150w, https://www.core6.com/wp-content/uploads/2026/05/LinkedIn-Images-66-768x401.png 768w, https://www.core6.com/wp-content/uploads/2026/05/LinkedIn-Images-66-1536x803.png 1536w, https://www.core6.com/wp-content/uploads/2026/05/LinkedIn-Images-66-2048x1070.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>
</figure>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size">What is AI-ready storage?</h3>



<p class="has-small-font-size wp-block-paragraph">AI-ready storage is storage infrastructure designed to support AI and machine learning workloads, including model training, inference, checkpointing, and retrieval-augmented generation (RAG). It must deliver high performance, low latency, scalability, and cyber resilience.</p>



<h3 class="wp-block-heading has-small-font-size">Why is cyber resilience becoming a storage issue?</h3>



<p class="has-small-font-size wp-block-paragraph">Storage and backup systems have become primary targets for ransomware attacks. If attackers compromise storage, backups, or recovery systems, organizations may be unable to restore critical business services after an attack.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>What is storage security posture management?</strong></p>



<p class="has-small-font-size wp-block-paragraph">Storage Security Posture Management (SSPM) is the practice of continuously assessing the security configuration of storage and backup systems to identify: exposure to vulnerabilities and security advisories, security misconfigurations, configuration drift, compliance violations, and missing security controls</p>



<h3 class="wp-block-heading has-small-font-size">What should infrastructure leaders prioritize when preparing storage for AI?</h3>



<p class="has-small-font-size wp-block-paragraph">Infrastructure leaders should focus on: performance, data management, cyber resilience, recovery readiness, security posture management, governance and compliance, and scalability.</p>



<p class="has-small-font-size wp-block-paragraph">The most successful organizations treat performance, protection, and resilience as equally important requirements.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.core6.com/blog/storage-in-the-ai-era-what-enterprise-leaders-are-learning-about-performance-protection-resilience/">Storage in the AI Era: What Enterprise Leaders Are Learning About Performance, Protection &amp; Resilience </a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>We Didn’t Expect Storage Security to Be Cool Either. Then Frost &#038; Sullivan Called.</title>
		<link>https://www.core6.com/blog/we-didnt-expect-storage-security-to-be-cool-either-then-frost-sullivan-called/</link>
		
		<dc:creator><![CDATA[Doron Youngerwood]]></dc:creator>
		<pubDate>Thu, 02 Jul 2026 12:23:19 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/why-oracle-zfs-security-matters-more-in-the-age-of-ai-2/</guid>

					<description><![CDATA[<p>Let&#8217;s be honest. For years, storage and backup systems have been the most overlooked part of the cybersecurity stack. When people talk about security, they talk</p>
<p>The post <a href="https://www.core6.com/blog/we-didnt-expect-storage-security-to-be-cool-either-then-frost-sullivan-called/">We Didn’t Expect Storage Security to Be Cool Either. Then Frost &amp; Sullivan Called.</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Let&#8217;s be honest.</p>



<p class="wp-block-paragraph">For years, storage and backup systems have been the most overlooked part of the cybersecurity stack.</p>



<p class="wp-block-paragraph">When people talk about security, they talk about endpoints, identities, networks, firewalls, AI threats, and whatever acronym people invented this week. Storage? It mostly sits quietly in the corner, doing its job.</p>



<p class="wp-block-paragraph">Until ransomware hits.</p>



<p class="wp-block-paragraph">Suddenly everyone remembers that storage and backup systems are the last line of defense between a bad day and a very bad day.</p>



<p class="wp-block-paragraph">That&#8217;s one of the reasons we&#8217;re especially excited that <strong><a href="https://www.core6.com/resources/frost-and-sullivan-2026-global-storage-protection-customer-value-leadership/" target="_blank" rel="noreferrer noopener">Frost &amp; Sullivan named Core6 the recipient of its 2026 Customer Value Leadership Award in the Global Storage Protection Industry</a>.</strong></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Wait. Storage Protection Is An Industry Now?<br></strong></p>



<p class="wp-block-paragraph">That&#8217;s actually one of the biggest takeaways from the report.</p>



<p class="wp-block-paragraph">For years, organizations assumed their storage and backup infrastructure was secure enough. But attackers have gotten smarter, environments have become more complex, compliance requirements have multiplied, and AI is generating more data than ever.</p>



<p class="wp-block-paragraph">The result? Storage security has become a real challenge &#8211; and one that many traditional security tools simply weren&#8217;t designed to address.</p>



<p class="wp-block-paragraph">As Frost &amp; Sullivan puts it, organizations need continuous visibility into their storage and backup environments, not just occasional assessments or generic security scans.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>So Why Did Core6 Win?<br></strong></p>



<p class="wp-block-paragraph">According to Frost &amp; Sullivan, it&#8217;s because we focus on a problem that many vendors still overlook.</p>



<p class="wp-block-paragraph">The report highlights StorageGuard&#8217;s ability to:</p>



<ul class="wp-block-list">
<li>Continuously identify security and compliance gaps across storage and backup environments</li>



<li>Improve ransomware resilience</li>



<li>Simplify compliance reporting</li>



<li>Deploy quickly without agents or disruption</li>



<li>Integrate into existing operational workflows</li>



<li>Support the leading storage and backup platforms enterprises already use (Dell, NetApp, Hitachi Vantara, HPE, Infinidat (Lenovo), IBM, Brocade (Broadcom), Rubrik, Cohesity, Commvault, Veeam, VAST Data, etc.)</li>
</ul>



<p class="wp-block-paragraph">In other words: less guesswork, fewer blind spots, and a lot less manual effort.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>The Part We&#8217;re Especially Proud Of<br></strong></p>



<p class="wp-block-paragraph">One thing Frost &amp; Sullivan repeatedly calls out is customer value.</p>



<p class="wp-block-paragraph">Not marketecture.</p>



<p class="wp-block-paragraph">Not buzzwords.</p>



<p class="wp-block-paragraph">Not &#8220;the future of synergistic AI-powered digital transformation.&#8221;</p>



<p class="wp-block-paragraph">Actual customer value.</p>



<p class="wp-block-paragraph">The report notes that organizations can gain visibility into storage security risks quickly, automate many previously manual processes, and reduce the operational burden associated with compliance and security validation.</p>



<p class="wp-block-paragraph">As marketers, we&#8217;re supposed to love phrases like &#8220;customer value leadership.&#8221;</p>



<p class="wp-block-paragraph">As humans, we just like hearing that customers can sleep a little better at night.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>And Then We Added AI<br></strong></p>



<p class="wp-block-paragraph">Because apparently every blog post in 2026 needs an AI section.</p>



<p class="wp-block-paragraph">But in our case, it&#8217;s actually relevant.</p>



<p class="wp-block-paragraph">Frost &amp; Sullivan highlighted the new <strong><a href="https://www.core6.com/resources/storageguard-mcp-ai-integration-for-natural-language/" target="_blank" rel="noreferrer noopener">StorageGuard AI Platform</a></strong>, which helps organizations interact with their storage security environment using natural language, automate tasks, and accelerate remediation.</p>



<p class="wp-block-paragraph">The goal isn&#8217;t to replace administrators.</p>



<p class="wp-block-paragraph">It&#8217;s to help them spend less time hunting for problems and more time fixing them.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>The Bigger Picture<br></strong></p>



<p class="wp-block-paragraph">This award isn&#8217;t just recognition for Core6.</p>



<p class="wp-block-paragraph">It&#8217;s recognition that storage and backup security matter.</p>



<p class="wp-block-paragraph">The systems that store your most critical business data shouldn&#8217;t be the security team&#8217;s blind spot. They deserve the same visibility, governance, and protection as every other part of the environment.</p>



<p class="wp-block-paragraph">We&#8217;re grateful to Frost &amp; Sullivan for the recognition and even more grateful to the customers who have been telling us this was a problem worth solving long before the industry started paying attention.</p>



<p class="wp-block-paragraph">After all, when ransomware hits, nobody asks whether your storage infrastructure was exciting.</p>



<p class="wp-block-paragraph">They just hope it was protected.</p>



<p class="wp-block-paragraph"><a href="https://www.core6.com/resources/frost-and-sullivan-2026-global-storage-protection-customer-value-leadership/" target="_blank" rel="noreferrer noopener">Download</a> the full report, <em>‘Frost &amp; Sullivan 2026 Global Storage Protection – Customer Value Leadership’</em></p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-15 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://www.core6.com/resources/frost-and-sullivan-2026-global-storage-protection-customer-value-leadership/"><img decoding="async" width="1024" height="938" data-id="13928" src="https://www.core6.com/wp-content/uploads/2026/06/Frost-Sullivan-logo-Core6-BPR-Logo-1024x938.png" alt="" class="wp-image-13928" srcset="https://www.core6.com/wp-content/uploads/2026/06/Frost-Sullivan-logo-Core6-BPR-Logo-1024x938.png 1024w, https://www.core6.com/wp-content/uploads/2026/06/Frost-Sullivan-logo-Core6-BPR-Logo-300x275.png 300w, https://www.core6.com/wp-content/uploads/2026/06/Frost-Sullivan-logo-Core6-BPR-Logo-150x137.png 150w, https://www.core6.com/wp-content/uploads/2026/06/Frost-Sullivan-logo-Core6-BPR-Logo-768x704.png 768w, https://www.core6.com/wp-content/uploads/2026/06/Frost-Sullivan-logo-Core6-BPR-Logo.png 1072w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>
</figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size">Why are storage and backup systems becoming a cybersecurity priority?</h3>



<p class="has-small-font-size wp-block-paragraph">According to Frost &amp; Sullivan, attackers increasingly target storage and backup systems because compromising recovery infrastructure can make ransomware attacks more effective. At the same time, organizations face growing compliance and audit requirements, making continuous validation essential.</p>



<h3 class="wp-block-heading has-small-font-size">What problem does Core6 solve?</h3>



<p class="has-small-font-size wp-block-paragraph">StorageGuard &#8211; by Core6 &#8211; helps organizations identify and remediate security risks, compliance gaps, and misconfigurations across enterprise storage and backup infrastructure &#8211; areas that are often overlooked by traditional cybersecurity tools.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>Which storage and backup vendors does StorageGuard support?</strong></p>



<p class="has-small-font-size wp-block-paragraph">Frost &amp; Sullivan highlights support for leading platforms including Dell, NetApp, IBM, HPE, Hitachi Vantara, Cisco, VMware, Nutanix, Cohesity, Commvault, Rubrik, VAST Data, Broadcom, and Veeam.</p>



<h3 class="wp-block-heading has-small-font-size">What does Frost &amp; Sullivan mean by &#8220;Customer Value Leadership&#8221;?</h3>



<p class="has-small-font-size wp-block-paragraph">The award recognizes companies that deliver a strong combination of customer outcomes, innovation, operational efficiency, and return on investment. Frost &amp; Sullivan concluded that Core6 delivers significant value through automation, compliance validation, ransomware resilience, and ease of deployment.<br></p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.core6.com/blog/we-didnt-expect-storage-security-to-be-cool-either-then-frost-sullivan-called/">We Didn’t Expect Storage Security to Be Cool Either. Then Frost &amp; Sullivan Called.</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why Oracle ZFS Security Matters More in the Age of AI</title>
		<link>https://www.core6.com/blog/why-oracle-zfs-security-matters-more-in-the-age-of-ai/</link>
		
		<dc:creator><![CDATA[Doron Youngerwood]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 11:36:58 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://core6stg.wpenginepowered.com/blog/anthropic-associated-cves-worth-watching-for-storage-and-backup-2/</guid>

					<description><![CDATA[<p>Storage infrastructure has always been critical. What has changed is the speed at which weaknesses can be discovered, chained together, and exploited. That shift is one</p>
<p>The post <a href="https://www.core6.com/blog/why-oracle-zfs-security-matters-more-in-the-age-of-ai/">Why Oracle ZFS Security Matters More in the Age of AI</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Storage infrastructure has always been critical. What has changed is the speed at which weaknesses can be discovered, chained together, and exploited.</p>



<p class="wp-block-paragraph">That shift is one of the biggest implications of the current AI wave. Across the industry, security leaders are recognizing that frontier AI models are changing the economics of cyber risk: discovery is faster, validation is faster, and the time defenders have to assess and respond is getting shorter.</p>



<p class="wp-block-paragraph">Public research and industry discussion continue to show how AI can accelerate security analysis, including vulnerability discovery and validation. For security teams, the practical implication is clear: response windows are getting shorter, and infrastructure controls need to become more continuous.</p>



<p class="wp-block-paragraph">For organizations running <a href="https://www.oracle.com/storage/nas/" target="_blank" rel="noreferrer noopener"><strong>Oracle ZFS Storage Appliance (ZFSSA)</strong></a>, this matters for a simple reason:</p>



<p class="wp-block-paragraph">Storage is no longer just an operational platform. It is part of the attack surface.</p>



<p class="wp-block-paragraph">Core6 recently expanded StorageGuard support to Oracle ZFS Storage Appliance, enabling organizations to assess Oracle ZFS environments for security misconfigurations, compliance gaps, and exposure to known vulnerabilities.</p>



<p class="wp-block-paragraph">The goal is straightforward: to help improve visibility, support hardening, and enable more continuous assessment of resilience of an infrastructure layer that many security tools still fail to cover deeply.</p>



<p class="wp-block-paragraph">That is also the focus of this <a href="https://go.oracle.com/LP=148748?elqCampaignId=628361&amp;src1=email&amp;src2=asktom" target="_blank" rel="noreferrer noopener">joint webinar</a> between <a href="https://www.oracle.com/" target="_blank" rel="noreferrer noopener">Oracle</a> and Core6, which centers on hardening and compliance for Oracle ZFSSA with StorageGuard.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>The real issue is not just vulnerabilities. It is the shrinking exploit window</strong></p>



<p class="wp-block-paragraph">Security teams have long operated with an assumption that they would have some time: time to discover a weakness, time to prioritize it, time to patch it, and time to validate the fix.</p>



<p class="wp-block-paragraph">AI is compressing that timeline.</p>



<p class="wp-block-paragraph">As both defenders and attackers operate at higher velocity, the window between vulnerability discovery and potential exploitation continues to shrink. This challenges traditional security models built on periodic reviews, and reinforces the need for continuous hardening alongside faster, more responsive remediation.</p>



<p class="wp-block-paragraph">That does not mean the answer is hype, panic, or treating every storage platform as an emergency.</p>



<p class="wp-block-paragraph">It means infrastructure and security teams should rethink where they have blind spots – especially in storage and backup systems, which are mission-critical, often under-monitored, and highly consequential if compromised.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Extending security posture management to Oracle ZFS environments</strong></p>



<p class="wp-block-paragraph">Oracle ZFS environments often sit at an important point in enterprise data infrastructure: close to valuable data, deeply tied to resilience and recovery, and operationally central to the business.</p>



<p class="wp-block-paragraph">As organizations modernize security operations, extending visibility, configuration assessment, and drift detection to storage infrastructure can help teams manage risk more consistently across critical systems.</p>



<p class="wp-block-paragraph">In Oracle ZFS environments, StorageGuard enables teams to autonomously validate configurations, detect drift from secure baselines, assess exposure to vulnerabilities, and take guided remediation actions – helping teams identify and prioritize risks before weaknesses can contribute to incidents.</p>



<p class="wp-block-paragraph">In other words, the answer to AI-accelerated risk is not a single feature. It is a tighter operating model:</p>



<ul class="wp-block-list">
<li>Know what your Oracle ZFS environment looks like now</li>



<li>Detect when it drifts from a secure baseline</li>



<li>Identify where vulnerabilities and configuration weaknesses intersect</li>



<li>Prioritize remediation faster</li>



<li>Re-validate changes continuously</li>
</ul>



<p class="wp-block-paragraph">That becomes even more important in environments where storage supports regulated workloads, recovery operations, or broader cyber resilience programs.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Where AI can help defenders. Safely</strong></p>



<p class="wp-block-paragraph">There is also a constructive side to this shift.</p>



<p class="wp-block-paragraph">StorageGuard is not about replacing operational discipline. It is about helping teams move faster within controls.</p>



<p class="wp-block-paragraph">StorageGuard enables teams to use AI to investigate risks, validate compliance, review and apply hardening recommendations, and generate insights through natural-language interaction.</p>



<p class="wp-block-paragraph">These capabilities are delivered with built-in guardrails, including role-based access control, scope limitation, no direct system access, and controls designed to help protect sensitive data, within an architecture where customers retain full control over their LLM environment.</p>



<p class="wp-block-paragraph">That distinction matters.</p>



<p class="wp-block-paragraph">In a storage environment, speed without guardrails is not helpful. But speed with policy control, scope limits, and auditability can make a real difference – especially when teams need answers quickly:</p>



<ul class="wp-block-list">
<li>Which Oracle ZFS systems have drifted from baseline?</li>



<li>Which findings matter most right now?</li>



<li>Where do current settings create resilience or compliance risk?</li>



<li>What should be fixed first?</li>
</ul>



<p class="wp-block-paragraph">Those are exactly the kinds of questions AI can help teams answer faster, provided the underlying data is authoritative and the operating model remains controlled.</p>



<p class="has-medium-font-size wp-block-paragraph"><strong>A more realistic way to think about AI and storage security</strong></p>



<p class="wp-block-paragraph">The Mythos conversation has captured attention because it makes the broader trend impossible to ignore:</p>



<p class="wp-block-paragraph">AI is increasing the pace of both discovery and response.</p>



<p class="wp-block-paragraph">For Storage and Infrastructure leaders, the takeaway is not that every headline should trigger a strategy rewrite. It is that storage can no longer sit outside modern security operations.</p>



<p class="wp-block-paragraph">If Oracle ZFS supports critical workloads in your environment, then visibility, hardening, and continuous validation belong on the security agenda – in addition to the storage team’s agenda.</p>



<p class="wp-block-paragraph">That is why this topic matters now. And that is why the Oracle and Core6 conversation around Oracle ZFS security is timely: it is not about marketing a feature in isolation. It is about helping organizations bring a critical layer of infrastructure into a more modern, continuous security model.</p>



<p class="wp-block-paragraph">If you’d like to go deeper, join this <a href="https://go.oracle.com/LP=148748?elqCampaignId=628361&amp;src1=email&amp;src2=asktom" target="_blank" rel="noreferrer noopener">joint webinar</a> with Oracle and Core6 on Oracle ZFS resilience and compliance, taking place on 24<sup>th</sup> June.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-16 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><a href="https://go.oracle.com/LP=148748?elqCampaignId=628361&amp;src1=email&amp;src2=asktom" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="610" height="567" data-id="13964" src="https://www.core6.com/wp-content/uploads/2026/06/Oracle-Webinar.png" alt="" class="wp-image-13964" srcset="https://www.core6.com/wp-content/uploads/2026/06/Oracle-Webinar.png 610w, https://www.core6.com/wp-content/uploads/2026/06/Oracle-Webinar-300x279.png 300w, https://www.core6.com/wp-content/uploads/2026/06/Oracle-Webinar-150x139.png 150w" sizes="(max-width: 610px) 100vw, 610px" /></a></figure>
</figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"></p>



<p class="has-medium-font-size wp-block-paragraph"><strong>Frequently Asked Questions (FAQs)</strong></p>



<h3 class="wp-block-heading has-small-font-size">What does Core6’s support for Oracle ZFS Storage Appliance mean?</h3>



<p class="has-small-font-size wp-block-paragraph">Core6’s support for Oracle ZFS Storage Appliance (ZFSSA) extends StorageGuard’s ability to secure, harden, and continuously validate Oracle-based storage environments. It also reflects deeper alignment with Oracle, positioning Core6 within a key enterprise ecosystem and enabling organizations to better protect mission-critical data with continuous security posture management.</p>



<h3 class="wp-block-heading has-small-font-size">What problem does StorageGuard solve for Oracle ZFS environments?</h3>



<p class="has-small-font-size wp-block-paragraph">StorageGuard addresses a key gap: storage systems are rarely monitored with the same rigor as servers or endpoints. It provides visibility into vulnerabilities and exposures, continuous security posture validation, and detection of misconfigurations and drift.</p>



<p class="has-small-font-size wp-block-paragraph"><strong>How is this different from Oracle’s built-in capabilities?</strong></p>



<p class="has-small-font-size wp-block-paragraph">Oracle provides strong infrastructure, performance, and patching tools. StorageGuard adds: security posture management, continuous compliance validation, and multi-vendor visibility across storage environments. It complements &#8211; not replaces &#8211; native Oracle capabilities.</p>



<h3 class="wp-block-heading has-small-font-size">What are the most common risks in Oracle ZFS environments?</h3>



<p class="has-small-font-size wp-block-paragraph">Security misconfigurations, lack of continuous validation, exposure to unpatched vulnerabilities, and limited visibility into compliance posture. These gaps increase the risk of ransomware impact and data loss.</p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.core6.com/blog/why-oracle-zfs-security-matters-more-in-the-age-of-ai/">Why Oracle ZFS Security Matters More in the Age of AI</a> appeared first on <a href="https://www.core6.com">Core6</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
