Popular Backup Storage Devices
Backup storage devices are also known as external hard drives and Network-attached storage (NAS). Popular brands include Seagate, WD Black, Synology, ScanDisk, QNAP, Lacie, and Samsung. The key difference between backup storage devices that are external hard drives and the NAS variety, is that the latter has a lot more functionality and is ‘networked’. These devices are not necessarily connected to one device, but can be used to store backup files across a network or multiple devices. NAS can continue to be available when computers are turned off. NAS devices can also allow users to access their content whilst working remotely, effectively “logging in” to access files wherever a person can get online.
- Choose complex passwords. NAS devices can be subject to a brute force attack where attackers robotically persist with trying to crack the password.
- Limit Internet of Things device connectivity. Yes, your fridge and TV can connect to your NAS. Whilst this may be inadvertent or not very useful at the moment, we find that IoT devices tend to lag on their security and their updates.
- Disable default Admin Account and Create a New Administrator Account. Like most Modems and Routers and IoT devices the standard factory password for administrator accounts are widely publicised and known. To address this deficiency, disable the default account and create a new one with a new password.
- Use one that uses Multi-Factor Authentication (MFA). This means that logging in requires that users must also enter a code that is only accessible by the individual account holder. It means that the chances of a brute force attack diminish considerably.
- Hard disk encryption. Encrypt your NAS and backup drive contents so that should unauthorised access occur, the information accessible cannot be decrypted.
- Turn off services you are not using. Limit your footprint and exposure to only what’s required.
- Enable auto-updates. Like anti-virus, the best way to update applications and operating systems is to make it automatic.
- Use a Virtual Private Network. With a VPN installed on your NAS device the traffic (files) sent over the VPN network will ensure they remain private and secure.
Identity Care Australia & New Zealand Ltd (IDCARE) provides identity and cyber security incident response services (the Services) in accordance with the following disclaimer of service:
IDCARE is Australia and New Zealand’s national identity and cyber incident community support service. We are a not-for-profit charity.
- The Services provide do not constitute legal advice. IDCARE recommends that you consult a solicitor in relation to your legal rights and obligations, including but not limited to your legal rights or obligations under Australian and international privacy and data protection laws.
- While every effort has been made to ensure the accuracy of the information in this product or service, to the maximum extent permitted by law all conditions, terms, representations, and warranties (in each case, whether express or implied) in connection with the provision of the Services which might otherwise be binding upon IDCARE are excluded.
- IDCARE’S liability for any loss or damage suffered by any person or organisation (including, without limitation, any direct, indirect or consequential loss or damage) arising out of or in connection with the Services (including without limitation liability for any negligent act or omission, or statement, representation or misrepresentation of any officers, employees, agents, contractors or consultants of IDCARE) shall be limited to the fees paid by you to IDCARE in respect of the Services. For the avoidance of doubt, this limitation of liability extends to any liability arising from any actions performed or not performed as a result of any recommendations made in course of providing the Services.
- The Services provided by IDCARE are intended to be provided solely to the initial recipient of this document or service and IDCARE will not be liable to any other person who may receive this document.
While every effort has been made to ensure the accuracy of the information in this alert, IDCARE disclaims any liability to any person in respect to any actions performed or not performed as a result of the contents of the the Services or any accompanying data provided. Wider dissemination may be permitted by authority in writing from IDCARE’s Managing Director. If you would like to provide feedback please use our Feedback Form.