Canary It Solutions

Notes from the Nest | Firing on All Cylinders: Cyber Resilience

In my younger years, I was super excited about a car I’d bought. My first naturally aspirated six-cylinder Australian monster. With my shiny new purchase, I took the car home and washed that car with great enthusiasm. Here’s the trap for young enthusiasts: if you wash the engine bay, take care to not spray the cylinder heads. 

For whatever reason, when I went to pick up my girlfriend I showed up in a car with pops, lurches and stutters worse than my Grandpa after Sunday lunch – not the experience I’d imagined. The lesson: for a car to run optimally, it needs all cylinders running perfectly!  

Now, if you’ve been in IT long enough, you know two things to be true: 

  • No environment is ever “finished 
  • Anyone who says “we’re secure” is tempting fate 

In IT nirvana, we love polarised answers. Binary logic feels comforting: zero or one, yes or no, right or wrong. Unfortunately, cyber resilience doesn’t work that way. It’s not about buying a single silver bullet product, or – as is sometimes the case – crossing your fingers and hoping today isn’t that day. 

Cyber resilience is about defence in depth: layering sensible, mostly native controls so that when something goes pear-shaped (and it will), the blast radius is limited and recovery is predictable – even boringly so. 

With that in mind, let’s talk about what “firing on all cylinders” actually looks like in a modern environment, using tools many organisations already own. 

One Fence Doesn’t Stop a Kangaroo – Defence in Dept

I’ve had a few opportunities to witness kangaroos in rural Australia. What never fails to impress is how effortlessly they clear fences that work perfectly well for the animals they were designed to contain. One clean hop and they’re gone. 

That’s defence in depth in a nutshell. You assume something will get through, and you design your environment so it doesn’t get far. 

That means protecting: 

  • The data 
  • The identity 
  • The endpoint 
  • The backup 

Miss one, and attackers will happily take the path of least resistance. Like most “perfect storm” incidents, it’ll probably happen at 2am on a public holiday. A Happy Anzac day, indeed…. 

In an effort to keep the ‘Roos’ in, here are some thoughts on practical defence in depth controls: 

  • Keep an eye on things – every monitoring system tells you something about what’s going on at your place. The challenge is making all that data useful, but we’re now in a world of AI-infused log monitoring tools. Make sure you have one and are putting it to good use. 
  • When something happens, make sure you’ve got strong playbooks to respond to the important stuff. If a fireman kicks down your door in the middle of the night it’s probably not the neighbour asking you for eggs: you need a plan for how you will respond, and this plan needs to be regularly reviewed. 
  • Think about your ecosystem from the perspectives of your data, your identities, AND your connected devices. If you’ve got the ability to monitor and control all three then the fence/s are pretty strong already. 
  • Inspect what you expect: build a culture and a practise at your place that routinely tests recovery and response scenarios, from data loss, application downtime, compromised endpoints, and network interruptions.  

Storage-Level Reality Checks: NetApp Native Ransomware Protection 

Backups are important. Everyone agrees on that. Unfortunately, ransomware doesn’t politely wait for your backup window, so both the backup and the data-at-rest need a careful review. 

This is where NetApp’s native ransomware protection earns its keep. Built directly into ONTAP, it focuses on protecting data where it lives, not just after it’s been copied somewhere else. Capabilities like Autonomous Ransomware Protection and immutable snapshots are designed to detect unusual file behaviour early and give you clean recovery points without manual heroics. 

The key point here isn’t magic AI or marketing buzzwords – it’s native integration. No bolt-ons, no agents to forget about, and no mysterious performance tax that appears during a quarterly review. When ransomware hits, your storage shouldn’t be learning on the job. 

I’ve seen this work in simulation, and I never thought a radio button could bring so much comfort. Turn on ransomware protection at the volume level, and suddenly the storage layer is doing exactly what it should: quietly minding its own business until it really matters. 

Identity Is Not “Just Cloud Stuff”: Entra ID Backup with Commvault 

The prevailing reality is that the most vulnerable threat vector still sits at OSI Layer 8 – the human 🙂 

Identity is now the front door, the side door, and the fire escape. Microsoft Entra ID underpins access to Microsoft 365, Azure, SaaS apps, and just about everything users care about – yet many organisations still assume it “just looks after itself”. 

It doesn’t. 

There’s a difference between protecting the leaves on a tree and protecting the entire specimen. You need coverage across the whole shebang. 

Accidental deletions, malicious changes, or a poorly tested script can wipe out users, groups, conditional access policies, and app registrations in seconds. Native recycle bins only go so far. 

Using Commvault to back up Entra ID gives you real recoverability – not hope, not screenshots, and not a hastily written runbook from 2019. We’re talking about recoverable identity objects, policy rollbacks, and the ability to undo damage quickly when identity goes sideways. 

In a ransomware scenario, being able to restore data but not authenticate users is like fixing the locks after the house has already burned down – or building a new house with no windows and no doors. 

Endpoints Still Matter: Intune Policy Controls

Yes, users still click things. 
Yes, laptops still get lost. 
Yes, someone will always try to install something they “found on the internet”. 
Yes, your staff may sometimes delete stuff – by accident or intentionally – that they shouldn’t. 

And here’s the thing. A bad actor just needs an entry point – from there it’s about escalating access privileges, bouncing from stone to stone. It’s as easy as finding the cookie jar once you’ve gotten access to the kitchen. 

This is where Intune policy controls quietly do the heavy lifting. Endpoint security policies, compliance rules, security baselines, and Conditional Access work together to reduce the likelihood that a compromised device becomes a stepping stone into the rest of your environment. 

It’s a bit like that quiet bloke from school. Intune isn’t flashy – and that’s a good thing. When deployed sensibly, it enforces consistent controls across devices without turning IT into the department of “no”. And that quiet bloke from school? He’s probably the most successful guy you know :-).  

Antivirus, disk encryption, firewall rules, and configuration baselines all help make endpoints less attractive – and less useful – to attackers. 

The Forgotten Cylinder: Effective Backup Controls and Recovery Testing 

Backups only matter if you can restore – and more importantly, if you know you can restore to a point in time before things went wrong. 

This is where effective backup controls step out of the shadows and into the resilience conversation. Modern backup platforms like Commvault enable structured, repeatable, and testable recovery. 

And if you’re fair dinkum about automated backup verification and recovery testing, it means that you’re no longer relying on blind faith or annual DR exercises that everyone secretly hopes will be cancelled. You can validate backup integrity, test restores, and even rehearse recovery workflows without disrupting production. 

That changes the conversation entirely. 

Instead of asking “Do we have backups?”, you’re asking: 

  • Can we restore quickly? 
  • Can we restore cleanly? 
  • When did we last prove it? 

In a cyber incident, confidence matters. Knowing that your backups are immutable, recoverable, and regularly tested removes panic from the equation. Recovery becomes a process, not a guessing game – and that’s a massive shift when time, pressure, and scrutiny are all working against you.  

Why Native Tools Matter 

There’s a clear theme running through all of this: native integration. 

  • NetApp protects data at the storage layer. 
  • Commvault protects identity and backups where native tooling falls short. 
  • Intune enforces endpoint controls tied directly into identity and access. 

These tools speak the same language, respect platform boundaries, and don’t rely on duct tape and tribal knowledge to stay operational. Defence in depth works best when each layer understands its role – and does it well. 

Putting it all together: Cyber Resilience Isn’t Paranoia, It’s Professionalism 

Cyber resilience isn’t about assuming the worst. It’s about planning for reality. 

Attacks happen. Mistakes happen. People get busy. 

The organisations that recover well aren’t luckier – they’re layered, tested, and quietly prepared. When your environment is firing on all cylinders, a security incident becomes an operational issue, not a career-limiting event. 

And in IT, that’s about as close to a win as it gets. 

Author

Notes from the Nest | Firing on All Cylinders: Cyber Resilience