The Indonesian’s National Data Center (NDC) has been experiencing electronic system disruptions since Thursday, June 20, 2024, affecting various public services including immigration services such as immigration checks, AutoGate, Visa, residence permits, M-Passport, and Online Watchlist.
This disruption has also impacted over 200 public services in central and regional agencies. The government, through the BSSN and the Ministry of Communication and Information, has confirmed that the disruption was caused by the Brain Cipher Ransomware, a type of LockBit 3.0.
To address such cyberattacks, effective solutions like Disaster Recovery (DR) are necessary, especially to ensure that systems and data can be recovered, and service operations can return to normal quickly after a disruption.
So, what is a DR solution, why is it important for businesses, and how does it help in data recovery during disasters like the one that occurred at TNDC? Here’s an overview.
What Happened at the Temporary National Data Center (NDC)?
Indonesia’s National Data Center (NDC) is under public scrutiny due to a cyberattack that has paralyzed services for several days. Hackers managed to breach the TNDC servers and demanded a ransom of USD 8 million (approximately IDR 130 billion) from the Indonesian government.
The BSSN explained the chronology of this breach. Based on preliminary forensic analysis, the attack began on June 17, 2024, at 11:15 PM WIB, trying to disable the Windows Defender security feature. This allowed malicious activities to go undetected.
Due to the attack, the National Data Center (NDC) servers were disrupted, affecting over 200 central and regional agencies. This includes data from the Indonesia Smart Card (KIP), disrupting the ongoing data verification process for prospective students.
What is Disaster Recovery and Why Is It Important in Addressing Issues Like at NDC?
Cyberattacks, particularly the ransomware attack that crippled the TNDC system and public services for nearly a week, highlight the critical importance of implementing Disaster Recovery (DR) solutions in every company.
Why is this important? Because DR solutions comprise a set of procedures and steps designed to restore electronic systems and data after disruptions or disasters, whether caused by cyberattacks, natural disasters, or system failures.
These solutions have proven effective in minimizing downtime, reducing losses, and ensuring that electronic system operators can resume operations quickly and efficiently after a disruption. Moreover, effective DR implementation helps electronic system operators comply with regulations related to the security of electronic systems and operational continuity.
How Does Disaster Recovery Work?
Here are the general steps and processes involved in Disaster Recovery:
1. Planning
The first step in DR is to create a recovery plan. This involves identifying potential risks, assessing their impact on business operations, and determining recovery priorities for critical systems, applications, and data.
2. Developing Recovery Strategies
Once risks are identified, the next step is to develop appropriate recovery strategies. This includes selecting the right technologies, infrastructure, and recovery processes to meet the company’s needs in addressing various types of disasters.
3. Testing
Testing DR is crucial to ensure that the recovery plan works as expected when needed. This involves simulating disaster or emergency scenarios that allow the company to test the effectiveness of the recovery plan and identify areas for improvement.
4. Implementation
After the recovery plan is tested and refined, the next step is to implement it in a production environment. This involves adjusting technology infrastructure and operational processes to align with the established recovery strategies.
5. Monitoring and Maintenance
Disaster Recovery is not a one-time process but a continuous initiative. Companies need to constantly monitor and maintain their recovery plans and update them regularly in line with changes in the business and technological environment.
Tips for Choosing a Disaster Recovery Solution for Quick and Efficient Data Recovery
To ensure that your DR system has the best capabilities for data recovery, consider the following:
1. Automated Implementation, Operations, and Reporting
Implementation, operation, and reporting processes should be automated to save time and effort in managing data recovery.
2. Fast and Flexible Replication
Fast and flexible replication capabilities allow data to be recovered quickly in a disaster scenario.
3. Cost-Optimized Data Mobility to the Cloud
Moving data to the cloud should be cost-efficient and easy to accomplish.
4. Ransomware Detection and Prevention
The ability to detect and prevent ransomware attacks is crucial to protecting data from security threats.
5. Enterprise Scalability
The data recovery solution should be able to scale with business growth.
As mentioned earlier, using Disaster Recovery can minimize the threat of data loss. This solution enables companies to recover data and systems if infrastructure failures occur due to disasters or cyberattacks.
The Best Disaster Recovery Solution from Hitachi Data Protection Suite
To meet increasingly complex security standards and requirements, Hitachi Vantara has developed an integrated data protection solution called Hitachi Data Protection Suite. This solution encompasses multiple layers of defense, from advanced threat identification and detection to immutable storage to protect against cyberattacks, and built-in capabilities to quickly and easily respond to and recover data.
By combining the superior data protection capabilities of HDPS, supported by Commvault, with highly scalable and industry-leading object storage from HCP for Cloud Scale, your company can confidently face current and future challenges.
This solution provides comprehensive threat monitoring, including active monitoring for anomaly detection, backup monitoring to observe anomaly change rates, and rapid event monitoring and response to attacks.
The response includes steps such as removing threats from backups, continuously validating backup data to ensure its authenticity, and integrating with existing SIEM and SOAR platforms to manage and coordinate actions efficiently.
With these features, the Hitachi Data Protection Suite not only provides comprehensive protection against ransomware attacks and other disasters but also ensures that companies can quickly and efficiently recover critical data, allowing them to resume operations as soon as possible after an emergency.
How Can Hitachi Data Protection Suite Help Companies Implement Effective Disaster Recovery?
Hitachi Data Protection Suite (HDPS) is specifically designed to support the Disaster Recovery (DR) process effectively and efficiently. Here are some ways HDPS helps in Disaster Recovery:
Threat Monitoring
Equipped with active monitoring capabilities that can detect anomalies and suspicious changes in the IT environment. This helps quickly identify potential ransomware attacks or other disasters.
Rapid Data Recovery
Offers fast and flexible data recovery capabilities. With automated recovery features supported by scalable storage components, companies can quickly recover their data after a disruption.
Granular File and Server Recovery
Allows granular recovery of files and servers, enabling companies to restore only the data or applications affected by the disaster without having to restore the entire system.
High Availability and Direct Replication
Provides high availability and direct replication options to ensure high data and application availability. This helps meet strict Recovery Time Objective (RTO) requirements.
Backup Data Validation
Continuously validates backup data to ensure its authenticity and integrity. This helps ensure that the recovered data is trustworthy and not corrupted.
Orchestration with API
Can be integrated with Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms via REST APIs. This allows companies to efficiently manage and coordinate recovery actions.
Get Hitachi Data Protection Suite from CDT
Take advantage of the Hitachi Data Protection Suite solution to effectively protect your data from loss and ensure quick data recovery during disasters, ensuring smooth business operations.
As an authorized partner of Hitachi Vantara, CDT will help you avoid trial and error from the consultation, deployment, maintenance, to after-sales support stages. Supported by experienced and certified IT professionals, CDT will assist you through all processes of adopting the Hitachi Vantara solution to ensure all your business data is protected. Interested in the Hitachi Data Protection Suite solution? Contact our team by clicking the following link.
Author: Ary Adianto
Content Writer CTI Group