Module Overview

Hardening backup, failover, and encryption across enterprise networks

The module synthesised verifiable encryption and access control practices with dependable backup, failover, and monitoring strategies. Audits and executive reporting were used to convert technical findings into business-language recommendations spanning compliance, risk, and recovery posture.

Tooling decisions were exercised in depth — comparing Veeam, Commvault, Rubrik, and HashiCorp Vault — alongside hands-on traffic and log analysis with Wireshark, Splunk, Kali Linux, Nmap, and Burp Suite.

Module Learning Outcomes

The outcomes assessed by this module

🌐

Threat Analysis

Identify and analyse network security threats, selecting specific investigative methods to mitigate risks in data transmission and storage.

🔐

Control Evaluation

Critically evaluate solutions for managing risks such as encryption, IAM (Identity Access Management), and continuous monitoring.

⚖️

Standards Alignment

Align recommendations with organisational priorities and frameworks including GDPR, ISO 27001, and NIST SP 800-34.

Key Artefacts & Feedback

Audits, executive reports, and reflective submissions

🛡️

Vulnerability Audit: Baseline Analysis

AUDIT

Established an initial risk baseline covering unencrypted data paths, weak access controls, and ransomware exposure. Selected a security stack including Veeam, Commvault, HashiCorp Vault, and Wireshark to deliver a six-week programme of configuration checks and restoration drills.

📋

Executive Summary & Recommendations

REPORT

Reported on weaknesses across password policies, outdated software, and backup reliability. Recommended strengthening encryption, improving failover coverage, and institutionalising regular testing.

📝

Individual Reflective Piece

REFLECTION

Reflected on tooling decisions (comparing Rubrik vs Veeam) and the value of peer support using Kali Linux, Nmap, and Burp Suite. Identified opportunities to deepen critical analysis.

Core Reflections

Themes consolidated across the module

🛠️

Tool–Risk Linkage

Clarified how Wireshark validated secured transmissions and how Splunk surfaced log anomalies to prove control effectiveness.

📚

Standards Alignment

Ensured recommendations were traceable to ISO/IEC 27031 and NIST SP 800-34 for continuity, recovery, and legal assurance.

🗣️

Communication

Executive-facing materials emphasised business impacts — downtime, data loss, and legal exposure — paired with plain-language actions.

🤝

Collaboration

Supporting a peer with Kali and Burp Suite walkthroughs sharpened my explanations and reinforced shared understanding.

Skills Matrix

Competencies exercised through module artefacts

Competency Application in Module
Risk & Exposure Analysis Enumerated risks including unencrypted data paths, weak access controls, ransomware, and testing gaps.
Tooling & Validation Integrated Veeam and Commvault workflows; used Vault for keys; Wireshark for traffic validation.
Compliance Strategy Situated recommendations within GDPR and ISO 27001 to balance resilience and regulatory expectations.
Planning & Testing Developed a six-week roadmap covering integrity verification, monitoring, key management, and restoration drills.

Development Action Plan

Concrete, time-bound goals derived from module feedback

  1. Strengthen Research. Incorporate recent empirical studies and add in-text citations beyond core standards to reinforce recommendations. Dec 2025
  2. Link Findings. Pair each identified weakness with a specific control, KPI, and enforcement cadence (e.g., password policies vs. audit frequency). Dec 2025
  3. Tooling Analysis. Produce comparative matrices (e.g., Rubrik vs Veeam) to evidence critical evaluation of vendor capabilities. Jan 2026
  4. Evidence Dashboards. Track backup test success rates and mean time to recovery (MTTR) via quarterly dashboards. Jan 2026

Conclusion

This module synthesised verifiable encryption and access control practices with dependable backup, failover, and monitoring strategies. By linking technical actions to business risk, compliance posture, and measurable outcomes, I advanced my capability to guide enterprise network resilience.

References

International Organization for Standardization (2013) ISO/IEC 27001: Information security management systems — Requirements. Geneva: ISO.

International Organization for Standardization (2011) ISO/IEC 27031: Guidelines for information and communication technology readiness for business continuity. Geneva: ISO.

National Institute of Standards and Technology (2010) NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems. Gaithersburg, MD: NIST.

European Parliament and Council (2016) Regulation (EU) 2016/679 (General Data Protection Regulation). Brussels: Official Journal of the European Union.