
Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
Security is one thing, but you need to select the right partner because if you're going to the cloud, it's not an easy journey and you probably don't migrate all of that cloud partner anytime soon. It should be a long term relationship. So you need to make sure that you are selecting the right actor.
A
Hello and welcome to Data Security Decoded. I'm your host, Caleb Tolan. In this episode, I sat down with Fred Loest at PCCW Global, the self proclaimed automation junkie himself, to discuss navigating major infrastructure migrations, filtering out the noise on cyber resilience and the issue of archiving on the near horizon. Well, welcome to the podcast. First of all, thank you, thanks for having me. Yeah, absolutely, absolutely. So tell me a little bit about what it is like managing it for a 60 country telecom company that is, you know, navigating, you know, critical infrastructure and you're in the middle of a migration from what I understand from on prem to adopting some hybrid infrastructure as well. Um, so what does a normal day look like and what does a bad day look like?
B
Yeah, first of all, and luckily I'm not alone in, in order to do that. Well, the team is not that big, but we have at least six or seven people able to address the day to day. So. Well, ideally when everything is fine, we have all the indicators on that are all green, which is always good. A bad day starts when the first thing in the morning is of course checking your mails and your slack messages. And when you see there's a lot of people complaining about something from two hours or three hours ago, you know that you are already late into the party. But remember, we are operating all over the world so we have different time shift and we have different people able to react on time. And sometimes when you are waking up you discover that a lot has already been done, which is good because we all have the team spirit and we can definitely help each other. So yeah, then you quickly finish your breakfast or even you skip it and then you jump into the party and you try to understand what's been done and what should remain right.
A
Well, it's the most important meal of the day. You can delay it, but you shouldn't skip it. Yeah, I get that, I get that. So you published some content about automation frameworks that you've built on top of your data protection tools. What is one of the projects that you're most proud of and what problem was it solving?
B
Well, a couple of Years ago, I decided to look into the Rubrik APIs. And I started to discover that you can actually do a lot with APIs. So you start with the first function, which is, okay, list all the unprotected, snappable, my VMs, my DBs who are not protected. So it's like a kind of alarm saying, okay, this should be protected, but they are not. So this is the first one. Then you start bigger and bigger. You start to manage your users, you start to manage probably automatic restore as well. And then at the end of the day, I ended up with more than 100 functions. And then I decided, okay, that's about the right time to create a framework and to make it public. So this is why I created the PHP framework, which is publicly available on GitHub. But now for, let's say, five years, Rubrik is moving from REST API to GraphQL. And then I'm starting to redo that framework. And I got actually challenged by the Rubric Practitioner Manager, community manager. And I told, you know what, I will rebuild that framework using GraphQL. So let's commit to a 12 weeks, one blog post a week to redo that framework. And this is what I'm actually doing right now. If you look on the Rubric Practitioner website, you will see that post number five is already live and the next one are coming up until week 12. So that's quite a challenge.
A
Very cool, very cool. I love to hear it. And there's a great resource for people to check out after this too. And I know backup and recovery is obviously a major part of the work that you do. And we've seen data suggesting that two out of three ransomware attacks now are targeting backup data, because we know it's a very, very valuable part of the infrastructure in businesses. But you went through a major modernization with your own data protection strategy. What was the moment like when you realized that the old model wasn't working anymore?
B
Well, that's a very good question. So at some point in time, when you look at your infrastructure, you realize that you are using maybe more different backup tools than your actual systems. So we realized that we had more than 10 different backup tools in the company. Yeah. And this is where you need to sit down and, okay, let's think a little bit here, because it is becoming unmanageable. So this is a reflection and the thinking that we had more than 10 years ago, actually, when we jump into the Rubrik family. And this is where you're getting the most of it, because if you have a Single place to manage all your security, all your data, all your backups. This is already a win situation because you know where to go when you have an issue. And I think this is very important to have something kind of homogeneous.
A
Right, right, absolutely. And I want to talk a little bit about cyber resilience as a term. A lot of people have kind of co opted it and brought it on. It's kind of become this bit of a buzzword. But you live in the world of cyber resilience every day operationally. What are the things that tools can't fix that are important to a cyber resilience strategy?
B
Well, I think. Well, you already know. You already know that I'm an automation junkie. This is my headline on LinkedIn because I like to automate things. But there is a limit to that. If the tool that you are using or the mechanism that you are using is not able to detect the right incident, it might lead to very bad things. If you give him the right to act on your behalf. If the tool is detecting a false positive, it can lead to a total disaster. So let's say that the tool is thinking that one system is compromised, then it is switching to the fallback system. And it was not the case. And by mistake the fallback system was not in sync with the main life system. So this is where you start to have a lot of issues. So you need to make sure that when you are automating, I think the most important trigger is making sure that the system is asking you, should I do this? Do you think this is relevant? So the human behind that is always the guy who is deciding.
A
Right, right, right. And I want to go back to something that we were talking about towards the beginning. I mentioned your cloud modernization that you're beginning to work through. What are some of the considerations that you're making as you have a very, very. You admitted it yourself, you're an automation junkie, you're a deep technologist as it relates to. On prem. Data protection. As you're making that migration, what are some of the considerations you're taking that other people can learn from as they're making their cloud migrations? Because we know a lot of people go into this not understanding the security implications of securing their data in the cloud?
B
Yeah, well, the security is one thing, but you need to select the right partner because if you're going to the cloud, it's not an easy journey and you probably don't migrate all of that cloud partner anytime soon. It should be a long term relationship. So you need to make sure that you are selecting the right actor. This is I believe the first step into the journey. Then you need to think, okay, are my application already 100% cloud native? That's also a very important topic. And you need to make sure that you will be able to have enough resources resiliency between the different sites. Because if you are running a business like the one that we have, which is global, you need to make sure that the data are always located at the right place. So for example, for EU data they should be in eu. That's the same for US by the way. You need to have your US related data located in us. And yeah, this is the kind of things that entering into consideration and this is very important to plan that in the beginning.
A
Right, right. It's a very crucial step at the beginning for sure. So as we start to kind of close out the conversation, what are three actionable steps that you believe defenders should be taking who when they're working in a complex environment and they need help finding out where they can get started and automating some of their current workflows from the automation junkie himself?
B
Yeah, well, from what we have seen this morning during the keynotes, anything agentic AI is very scary these days. So you need to pay attention. You need to have a very strong AI policy in the company. So you have two types of thinking. The first one is your employees. They will use AI. So how do you control that? Because that's very crucial. Most of the attacks are actually coming from the inside and then on the other side you have very specific employee. These are the IT guys, the most advanced or the one who think they are the most advanced, they will also use AI. And I'm thinking about agentic AI in that case because it will definitely help the day to day. But okay, you need to put some limits into that. So I know there are tools in the market who are preventing copy paste of huge a section of codes or API tokens or passwords. So this is very important to make sure that you're not spreading company secrets to the cloud and especially to LLMs.
A
Very good, very good. And what are two inconvenient truths hot takes even that the industry needs to face about legacy backups and archiving.
B
Okay, the archiving topic is one of the most interesting. I already had a thought about it. If you look back 15, 20 years ago when we were looking at archives, typically what it was is at the end of the year the accounting department is starting to make the printer burning by printing a lot and a Lot of sheets. And then they were storing those sheets in a file. The file goes in a cupboard and the cupboard goes into a specific building. So finding the archive was a challenge. But as soon as you have the soft, the hard copy, then it is very easy. Today this is the opposite. Today we are very good at archiving. And if you look at a product like Rubrik, when you go to Rubrik Security Cloud, you can easily, I mean instantly find your archive, your file from two years, three years ago. That's very easy. But there is a challenge that nobody is actually foreseeing. What if in 25, 30 years from now, we would like to look at those archives? Okay, you can find it. That's fine. It's in the cloud somewhere. That's very easy to find. But how are you going to read the content? I bet I challenging you. Okay, you have a file that's written in a Word document, for example, from Office 97. Even today, are you sure that you can read that document? Maybe you will be able to open the document, but the layout will be completely broken. No, same thing with the PDF document. Look back in the mirror, all the PDF format evolve over time. It is completely different today. There's more function, there's more feature that you can't even imagine exist a long time ago. And even worse than that, let's say you have a very proprietary application who is running maybe an accounting software, and there's no really proper exporting mechanism inside the application. So the IT guy decided, okay, you know what, let's put it on a VM and let's store the VMDK or the QGO file somewhere in the cloud. And then, okay, we are 10 or 15 years later, okay, where is the hypervisor? Who is able to fire up that VM and then go inside the software and find what we are looking for? Because there are regulation in Europe who are saying, okay, you need to keep those data 30 years. And this is the real challenge. So if you want to expand the Rubrik business, dig into the archiving.
A
It's a very interesting challenge because many industries, many regulated industries have these retention policies where you have to retain copies of your data seven years, up to 30 years. You're even saying too. So that's, that's definitely a big challenge. What do you think is the single most important message you want to leave with listeners today?
B
Make sure that you have proper data protection and, and make sure that you are testing it, otherwise there's no protection.
A
It's a very important message. Testing it is so important. You can have an instant response playbook all day long, but if you never dust it off, maybe the day you need it, it's broken. It's broken. Yeah, absolutely. Well, thank you so much for joining the podcast. I really appreciate it. And until next time, thank you very much. That's a wrap on today's episode of Data Security Decoded. If you like what you heard today, please subscribe wherever you listen and leave us a review on either Apple Podcasts or Spotify. Your feedback really helps me understand what you want to hear more about. And if you want to reach out to me directly about the show, email me at data-security-decoded2k.com thank you to Rubrik for sponsoring this podcast. The team at N2K includes producer Liz Stokes and executive producer Jennifer Ibin. Content strategy by Mayan Plout Sound design by Elliot Elliot Peltzman Audio mixing by Elliott Peltzman and Trey Hester Video production support by Bridger Kirke Wilde and Sorrel Joppi. Until next time, stay resilient.
Episode: Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest
Host: Caleb Tolan
Guest: Fred Lhoest, PCCW Global
Date: July 28, 2026
This episode of Data Security Decoded dives deep into the practical realities of modernizing data protection and backup strategies in large, global organizations. Caleb Tolan speaks with Fred Lhoest—self-described "automation junkie" and senior technologist at PCCW Global—about his experiences managing critical infrastructure migrations, building automation frameworks, keeping up with evolving cyber resilience needs, and facing the complex challenges of long-term digital archiving.
On automation limitation:
“The human behind that is always the guy who is deciding.” — Fred Lhoest (07:29)
On partner selection for cloud migration:
“It should be a long term relationship. So you need to make sure that you are selecting the right actor.” — Fred Lhoest (08:30)
On digital archiving and future access:
“What if in 25, 30 years from now, we would like to look at those archives?... how are you going to read the content?” — Fred Lhoest (12:13)
On the necessity of testing your protection:
“Make sure that you have proper data protection and, and make sure that you are testing it, otherwise there's no protection.” — Fred Lhoest (14:28)
For more practical resources, Fred’s framework and continuing blog series are available via the Rubrik Practitioner website.