ARTESCA Glossary

Clear, concise definitions of the backup, object storage, and data-protection terms that matter when you evaluate ARTESCA. Browse the terms below.

A

Administrative Blast Radius — Everything a single administrative account can reach, change or destroy if its credentials fall into the wrong hands.

B

Backup Target — The storage system where backup software writes and keeps backup copies, ready to restore.

Backup Storage Tiers — Classes of storage used for backups of different ages, from fast storage for recent copies to archive storage for long-term retention.

Backup Tampering — Unauthorized changes to backups, backup settings or backup records that remove or spoil recovery points, often without any obvious alert.

Backup Agent — A small program on a protected machine that reads its data locally and sends it to the backup system.

Backup as a Service (BaaS) — Backup delivered as a subscription service, with a provider operating the software, storage and infrastructure for its tenants.

Backup Catalog — The database a backup application keeps of restore points, their contents, storage locations and expiry dates.

Backup Encryption — The conversion of backup data into ciphertext with a cryptographic key, so stolen copies cannot be read without that key.

Backup Software — Applications that copy data to separate storage on a schedule, record each copy in a catalog and restore it on request.

Backup Window — The period in which backup jobs are allowed to run, set so that backup traffic does not slow production systems.

Bare-Metal Restore — Recovery of a complete system, including operating system, applications and data, onto hardware with no software installed.

Breach Detection — Identifying unauthorized access to systems or data by monitoring activity and investigating signs of intrusion.

C

Customer-Managed Keys (CMK) — Encryption keys that the data owner generates, holds and controls, rather than the storage or cloud provider.

Clean Room Recovery — Restoring systems into an isolated, known-good environment and checking them there before they return to production.

Continuous Data Protection (CDP) — A protection method that records every write in a time-stamped journal, so data can be recovered to almost any moment the journal covers, as in Veeam CDP.

Credential Theft — The stealing of passwords, access keys and session tokens so an attacker can sign in as a legitimate user or administrator.

Crypto Ransomware — Ransomware that encrypts the contents of files, disks or databases and demands payment for the key needed to decrypt them.

Cyber Liability Insurance — Insurance that pays an organization's own costs and its liability to others after ransomware, data breaches and other cyber incidents.

D

Data Sovereignty — The principle that data is subject to the laws of the jurisdiction that governs it, including who can compel access to it.

Data Residency — The physical location, such as a country or region, where data is stored.

Data Backup — A copy of files, systems or databases kept on separate storage so they can be restored after loss, corruption or a ransomware attack.

Data Breach Cost — The financial loss from a breach, from investigation, notification and fines to downtime and lost customers.

Double Extortion Ransomware — A ransomware attack that steals a copy of the victim's data before encrypting it, then threatens to publish it unless paid.

Data Breach — A security incident in which data is accessed, disclosed, altered, lost or destroyed without authorization.

Data Exfiltration — The unauthorized copying of data out of an organization's systems to a location an attacker controls, usually leaving the original in place.

Deduplication — A data reduction technique that stores each unique chunk of data once and replaces repeated chunks with references to the stored copy.

Differential Backup — A backup that copies all data changed since the last full backup, so a restore needs only the full and the latest differential.

F

Full Backup — A backup that copies all selected data in one run, producing a restore point that needs no other backup file to restore.

H

Hardware Security Module (HSM) — A dedicated, tamper-resistant device that generates, stores and uses encryption keys, so key material never leaves it in readable form.

I

Instant Recovery — Running a virtual machine or workload directly from backup storage so it is usable in minutes, then moving it back to production storage.

Immutable Backup — A backup copy that the storage refuses to change or delete until a set date, even when the request comes from an administrator.

Insider Threat — The risk that someone with legitimate access, such as an employee, contractor or service provider, harms the organization with that access.

L

Logical Air Gap — A backup copy kept online but cut off from production networks, logins and management tools, so a breach of production cannot reach it.

M

Multi-Tenancy — An architecture in which one shared platform serves several isolated tenants, each seeing only its own data.

P

Point-in-Time Recovery — Restoring a system, database or set of files to exactly how it was at a chosen moment, such as just before an attack.

R

Restore Testing — Restoring data from backup on purpose and checking it is complete, working and clean before a real emergency depends on it.

Restore Throughput — The speed at which a backup system brings data back, usually in terabytes per hour, which sets how long recovery takes.

Retention Policy Design — Deciding how long each kind of backup is kept, where it is stored and how long it stays locked, based on recovery needs and rules.

Ransomware as a Service (RaaS) — A criminal model in which ransomware developers lease their malware and infrastructure to affiliates in return for a share of ransoms.

Ransomware Detection — Identifying ransomware activity from intrusion behavior before encryption, or from file and storage effects while it runs.

Ransomware Incident Response — The coordinated response to ransomware, from detection and evidence collection to containment, restore and closing the incident.

Ransomware Kill Chain — The ordered stages a ransomware attack passes through, from first access to encryption and extortion, used to place defenses.

Ransomware Prevention — Measures and anti-ransomware tools that stop ransomware entering or spreading and keep recovery possible if an attack succeeds.

Ransomware Recovery — Returning systems, applications and data to a trustworthy state after ransomware without reintroducing the attacker.

Ransomware — Malware that encrypts or otherwise withholds an organization's data and demands payment in exchange for restoring access.

Ransomware Negotiation — The bargaining between a ransomware victim and the extortion group over whether to pay, how much, and on what terms.

S

S3 Object Lock — An S3 feature that stops a stored object version from being overwritten or deleted until a set date, or while a legal hold is on.

Safe Copy Isolation — Keeping one known-good backup copy apart from production systems and logins, so it survives an attack and can be trusted for recovery.

Synthetic Full Backup — A full backup assembled on the backup storage from an earlier full and later incrementals, without reading data from production again.

V

Veeam Backup & Replication — Veeam's application for backup, replication and recovery of virtual, physical and cloud workloads.

Veeam Backup to Object Storage — Using an S3 bucket as a Veeam backup repository, either as the main target for jobs or as an extra tier such as Cloud Tier.

Veeam Data Platform — Veeam's bundle of Veeam Backup & Replication, Veeam ONE and Veeam Recovery Orchestrator, sold as Foundation, Advanced and Premium editions.

Veeam Hardened Repository — A Linux server used as a Veeam repository that marks backup files immutable for a set number of days and stores no reusable login.

Veeam Immutable Backup — Veeam restore points that the storage refuses to change or delete until a set date, on a Linux hardened repository or object storage.

W

WORM (Write Once, Read Many) — A storage model where data is written once and can be read many times, but cannot be changed or deleted until its retention period ends.

Z

Zero Trust Security — A security model that removes trust based on network location and checks each access request against policy.

3

3-2-1-1-0 Backup Rule — Three copies of data on two types of storage, one offsite, one immutable or offline, and zero errors in tested restores.