Backup and recovery for resiliency towards cyberattacks
Estimated reading time: 7 minutes
Lembaga Lebuhraya Malaysia (LLM) oversees the design, construction, operation, maintenance, and toll collection for highways and expressways spanning 1,820 kilometers across Malaysia. To effectively improve safety, reduce traffic congestion, and integrate automation, LLM must assess every kilometer using several IT applications such as an expressway performance indicator system, a highway construction monitoring process, and a toll-road evaluation system.
LLM’s Assistant Director of Technology, Mohd Sukri Bin Shuib explained, “As a trusted government agency, our primary goal is to constantly improve our country’s highways and make travel safer, faster, and easier for travelers. To ensure business continuity, we needed to safeguard the IT applications that support highway management and maintenance and protect crucial information about our organisation and travelers.
“When challenges arose from our outdated backup solution, we prioritised finding a replacement immediately. We were looking for a solution to make data protection easy and efficient while strengthening our backup and disaster recovery strategy.”
Read the Q and A below to for more details.
EITN: Can LLM share about the type of data that they need to be able to meet their business objectives? On what IT systems do these data reside in?
Mohd. Sukri: Every day, LLM collects a vast amount of data from various sources, ranging from government agencies to third parties and concessions, as well as through CCTV footage that monitors traffic daily. To ensure business continuity and minimise downtime in the event of a cyberattack, LLM must frequently back up both qualitative and quantitative data for its daily operations.
EITN: How does LLM utilise these data to achieve their business outcomes and goals?
Mohd. Sukri: For LLM to backup these data more effectively and efficiently, the organisation deployed the Veeam and Aegis solution. In addition to providing LLM with a strengthened Disaster Recovery and backup strategy, Veeam and Aegis have also helped the organisation to achieve the following business goals:
- By reducing its annual IT costs by 50%, allowing the organisation to re-allocate its financial resources to other business functions.
- Aegis Managed Services provided LLM with unlimited Disaster Recovery (DR) drills in a year, which Disaster Recovery drill professionals host. These drills help ensure LLM’s DR plan’s workability and secure the organisation from any unprecedented attacks.
- By monitoring and managing data backup and Disaster Recovery operations, the organisation’s IT personnel can free up time from completing administrative tasks and focus on addressing more crucial business pain points.
- Providing a consolidated dashboard for monitoring that helps streamline asset monitoring, with automated backup regularly scheduled.
In addition to providing LLM with a strengthened Disaster Recovery and backup strategy, Veeam and Aegis have also helped the organisation to achieve business goals.
EITN: What are the types of data LLM looks into to ensure safety and timely maintenance of their highway and expressway assets?
Mohd. Sukri: LLM must back up both qualitative and quantitative data as part of our daily operations to ensure the safety and timely maintenance of Malaysia’s highway and expressways. This data comes from various sources, ranging from government agencies, third parties and concessions. LLM also manages raw data such as images, videos, and traffic on highways, all of which requires a robust backup solution.
EITN: What are dedicated drill personnel? What do they do and what is their objective?
Mohd. Sukri: Every year, Aegis provides LLM with unlimited Disaster Recovery (DR) drills organised and run assisted by dedicated DR personnel. These are well-trained professionals with a profound understanding of Disaster Recovery and are trained to deal with disasters in all kinds of scenarios. They are assigned to facilitate yearly DR drills and help ensure the success of these exercises.
We were looking for a solution to make data protection easy and efficient while strengthening our backup and disaster recovery strategy.
DR drills are exercises that help the organisation test and ensure its Disaster Recovery Plan (DRP) feasibility if an actual disaster occurs. The drills can take place in various Disaster Recovery Testing levels, including data verification and database mounting. Such forms of testing can help LLM prepare for any IT disaster by ensuring critical data and IT systems are properly restored after the disaster, with minimal downtime.
EITN: What does this sentence mean? “Veeam backs up and replicates 10 TB across more than 20 physical and virtual machines (VMs) on premises and off premises to Aegis.” What is 10TB and where does it come from?
Mohd. Sukri: With raw data such as images, videos, and traffic in highways being collected in sheer volume daily, the size of data LLM has within the organisation easily amounts to 10TB. These data require solid backup and LLM thus had to deploy the Veeam and Aegis solution when their legacy backup failed to perform. Veeam Cloud Connect links LLM to Aegis, enabling the agency to extend data protection to the cloud without the cost and complexity of managing a second infrastructure.
With raw data such as images, videos, and traffic in highways being collected in sheer volume daily, the size of data LLM has within the organisation easily amounts to 10TB.
The Veeam and Aegis solution ensured backups and replicas are encrypted and secure, increasing LLM’s protection against ransomware attacks.
EITN: How does ICT being ISMS-certified enable LLM to attain ISO27001 compliance?
Mohd. Sukri: An Information Security Management System (ISMS) is a holistic approach to securing confidentiality, integrity, and availability of corporate information assets. It encompasses policies, procedures, and other controls involving people, processes, and technology. ISO 27001 is an internationally recognised best practice framework for an ISMS.
With the Infinity Consulting Technology (ICT) being ISMS-certified, we are able to demonstrate our commitment to establishing a management system that remains relevant to information security and contributes to continual digital improvement.
Through this, LLM was able to attain ISO27001 compliance. With a successful ISO 27001 implementation, LLM can deliver better security management practices moving forward. In addition, this also raises LLM’s credibility as a government representative, thereby strengthening the government’s trust in the agency to manage Malaysia’s highway operations. Beyond that, the implementation of the framework also helps to ensure business continuity, legal compliance, improved risk management, and optimal customer satisfaction.
EITN: What is Aegis’ relationship with ICT and what is Aegis’ relationship with Veeam?
Mohd. Sukri: Aegis is the in-house brand of Infinity Consulting Technology (ICT), a widely recognised cloud backup and Disaster Recovery (DR) service provider in Malaysia. Aegis focuses on delivering cloud disaster recovery services – managing and monitoring customers’ daily backup operations, maintenance, and support of customers’ backup and DR operations. With Aegis and Veeam’s rich expertise in data protection and management, we chose to deploy backup and recovery solutions from both brands to maximise our resiliency towards cyberattacks.
ICT is a Platinum Veeam® Cloud & Service Provider (VCSP) partner in Malaysia. As a VCSP, Veeam offers partners the ability to leverage their innovative solutions whilst helping them build reliable, revenue-generating Backup as a Service (BaaS) and Disaster Recovery as a Service (DRaaS) offerings.
Furthermore, Veeam is a 100 percent channel business whose ecosystem includes valued service providers, resellers, distributors, and alliance partners to service customers’ modern data protection needs. Well-known for its channel-centric business approach, Veeam has a strong partner ecosystem and breadth of integration with the highest customer satisfaction scores in the industry.
Veeam has been recognised for its investment and commitment to protecting customer’s data and delivering a complete Modern Data Protection portfolio – as reported in the latest Gartner’s 2021 Magic Quadrant for Enterprise Backup and Recovery Solutions, in which, the organisation has been named as a Magic Quadrant Leader for the fifth consecutive time.
This is also the second consecutive year Veeam is positioned highest overall in ability to execute. Going beyond a simple license transaction, Veeam is focused on delivering tailored initiatives that can help partners increase their profits and at LLM, we are convinced that deploying Veeam’s services will propel us towards a digitalised future in data protection.
EITN: Can LLM share their future plans for data protection in the next 1 to 3 years?
Mohd. Sukri: Over the next few years, we want to enhance our current digital service offerings by providing all-encompassing digital services to the public. These include enriching customer touchpoints on mobile, web, or phone calls. With the primary goal of making the customer experience seamless and effortless, we aim to establish a suitable IT infrastructure that can support fully digitalised services.
With Aegis and Veeam’s rich expertise in data protection and management, we chose to deploy backup and recovery solutions from both brands to maximise our resiliency towards cyberattacks.