Security Confidential S19 E5 Murphy John

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Murphy John. Murphy John is the Chief Growth Officer at StorX Network, where he focuses on scaling decentralized data storage solutions and building strategic partnerships. Passionate about data security and privacy, Murphy works at the intersection of decentralization and distributed ledger technology (DLT), helping organizations rethink how data is stored, protected, and accessed globally. His work centers on enabling more secure, resilient, and privacy-first data infrastructure for the future.

00:00 Intro

01:17 Our Guest

02:50 Shifting from On-premise to Cloud Computing

09:30 Compliance and Data Privacy in Decentralized systems

11:22 Data Recovery

13:10 Ransomware and Data security

15:31 AI on Cybersecurity

19:25 Mindset Challenges in adopting technology

26:01 Egress Cost Awareness

33:15 Budgeting for Data backup Solutions

35:00 More about Murphy

Transcript

Manoj Tandon (00:00.916)
Hello everyone, this is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security, Security Confidential. We have a fabulous guest joining us all the way from Dubai today. And before I announce him, please hit the like and subscribe button so that we can keep bringing you these great people and bring you these wonderful educational episodes. It benefits us, it benefits you. So it’s a win-win for everyone. So without further delay,

I’d love to introduce to you Mr. John. Murphy is over in Dubai, just at the start of the hot season, but he is the Chief Growth Officer for StorX Network, where he focuses on scaling decentralized data storage solutions and building strategic partnerships. And we’re going to get into more detail around that. He’s very passionate about data security and privacy. Murphy works at the intersection of decentralization and distributed ledger technology helping organizations rethink how data is stored, protected, and accessed globally. His work centers on enabling more secure, resilient, and privacy-first data infrastructure for the future. Thank you so much for joining us today. It’s an honor to have you on the show.

Murphy John (01:19.694)
Hey, Manoj, thanks for having me in the podcast. Really excited to be a part of it.

Manoj Tandon (01:24.058)
Hey, so can you, you know, we always start off with the background because we’re very interested in how the leaders in our world came to be the leaders that they are. So where did you start off in computer science or what’s your origin story?

Murphy John (01:41.262)
So of course I started specialization computers in my early age and soon after my graduation, internet was just picking up. It was like in 1998 when the internet was really getting penetrated and we saw a lot of advantage in the benefits that it’s going to offer. And I completely figured out that this is going to be the future and I tried simply into it. Started with an organization which is basically setting up internet-based infrastructure, managing infrastructures.

I’ve been involved with that organization until I joined Storix. So my core background is into setting up of servers, managing infrastructures, managing email services, domain infrastructures for client. And we’ve been very lucky because we are very initially set up the organization. I was lucky to work with some of the most wonderful people in India who had great talent and who taught us a lot.

Manoj Tandon (02:37.466)
Fantastic. I have a side question for you since you’ve worked in setting up these infrastructures. What is the biggest change you see in going to cloud computing from where we were before in the 90s, which was all inside of the perimeter fencing when it comes to these data structures? What is the biggest thing you see with these decentralized data structures that we have now?

Murphy John (03:07.197)
I think, I’ll start with the basic background. When we started computers, I went into the workforce that’s early in my after my graduation, everything used to be on premises. All the data needs to be on premises. And that’s when the Amazon started with the cloud computing concept and that people were really, when we were talking to people, industry leaders, they were petrified. They will never be migrating the data to the cloud. That’s what they said initially. And they were like, there’s no way we’re going to move our data back into to the cloud. And that’s when the cloud service providers came up and they gave that three major promise. That’s the core fundamental, what I can tell, three promises by scalability. They could offer a very high level of scalability, high level of security, and cost optimization. So basically, they’re playing on these three promises, and that they really played really well. And I know of a of companies that were very reluctant. took almost five to 10 years to just move their workloads to the cloud. So it was indeed a very great transition that was happening. And now, recently, when there was a lot of development around these DLD technologies or distributed ledger technologies, we see the same kind of people mindset shift that they don’t want to move into something like a distributed.

How will the security be guaranteed? How will somebody ensure that the data remains safe? And there’s no major player who is providing this kind of services. Then we started telling them Amazon almost took like 20 years to come into the phase where they are today. So we’re still very early in that stage playing with mindset of people. So right now we’re still trying to gain the mindset of the people where people will feel that this is also one of the most reliable solution to store in the data.

Manoj Tandon (05:00.398)
So what is DLT for beginners? Give us, yeah.

Murphy John (05:03.661)
So yeah, basically, DLT is distributed ledger technology. So basically, we’re trying to store information in a lot of computers together and when they are in consensus. So basically, it’s a blockchain technology which ensures that your data is always protected and the data is written across multiple computers and they are always in consensus. That means any single operators are a group of computers can never get the information, you’ll never be able to modify the information basically. So it’s ensure that the data is always truthful and there’s always a consensus among the network basically.

Manoj Tandon (05:45.462)
So if I was to describe it from what you’re telling me as essentially taking a giant puzzle and then you break up that puzzle and then you put it into different places and you’re able to instantaneously reconstruct it, that’s your data, at any given time that you want. But that puzzle, if you get any different part of it, you really don’t have anything because you only have a very small part of the picture and you don’t have the context of the whole.

Murphy John (06:15.574)
Yes. So I would first like to explain what StorX is all about and then I’ll dwell into all those technology details. So what exactly we are trying to do in StorX is we are providing users an alternative to hyperscalers. Hyperscalers means all the big cloud giants. There are four of them who are majorly controlling the data across the world. So if you see the developments in the past 20 years, there are still very few operators of hyperscalers who are controlling the data.

So almost, to be very frank, there are like four hyperscalers around the world who control majority of the data. That means if out of five people, people are storing three lands in this four data centers or this four data providers. So what happens is because there is so much of concentration of data worldwide, it has become, they have become like enormous giants. And if any of the zones of any of the hyperscalers go down, even in a single zone,

It could be catastrophic in everybody’s life. So I can explain you about one of the hyperscalers. Amazon went down last October. And you saw the cascading effect all over the economy. It was not a private entity going down. But the effect was like seeing cascading all over. There was banks who were down. There was major websites which were sound. So what happens when you have so much of data stored in so few service providers?

Manoj Tandon (07:20.702)
Yep.

Murphy John (07:38.829)
They gain a lot of power. And that’s really not good for the end customers. Because what happens is so much of data concentrated with few service providers, it becomes a honeypot of information for hackers, for all the ransomware infection, for all the governments to scoop into your data. And also, people know about Cambridge Analytical, what happened, how the data was abused.

Manoj Tandon (08:03.495)
Yeah. Yeah.

Murphy John (08:05.038)
That was one thing. The second was because there are very few hyperscalers who have standard technology and this technology becomes really attractive for all the hackers to come in and attack them. So like a ransomware infection is now a 10.5 trillion business for people. So it is like bigger than any GDP of most of the country. So people are losing so much of money every year just on ransomware.

Manoj Tandon (08:29.158)
Yeah!

Murphy John (08:34.38)
What happens is if your data gets infected with ransomware, there is no guarantee that even if you pay, you will not be infected the next day. So evidently what has happened is people are looking for new alternative ways to store the data, critical data in a way where they can secure the data and not rely on any hyperscalers or any individual companies. Because what happens is if you would have noticed the recent Iran war, even the data centers were affected.

Manoj Tandon (08:43.112)
Correct.

Murphy John (09:04.344)
So in the Middle East, the data centers were… Yeah, it was two specific data centers which was bombed at two different countries, during two different times. So that means it has not only become data centers, they have in fact become one of the national, one of the key infrastructure for nations. I can bomb any of the data centers and the country goes down very bluntly, speaking very bluntly. So what we are trying to do at StorX is we are not relying on any specific service providers.

Manoj Tandon (09:04.604)
Yeah, the Amazon data center was bombed, was it not?

Murphy John (09:33.761)
or any specific technology. whenever you’re using StorX to store your data, what we do is whenever you’re uploading the data to a platform, first is your data gets encrypted in a local computer or your local laptop itself with your personal key. The encrypted data is then transferred to a server where it gets broken down into multiple chunks. Then we replicate those chunks and then we have a network of servers which are spread worldwide. like we put a little fragments of data everywhere in the network.

So your data never relies on a site on any single server. So if your server is infected, even we as the service providers cannot see your data. it’s like ultimate privacy guaranteed to your data. The second one is because your data is fragmented and distributed, nobody can get access to your data. Even somebody gets access to the storage node, it would be just a fragment of data that is actually being seen. And that will make no sense because that’s an encrypted fragment of

So that’s how we ensure that your data remains really private, secure, and reliable.

Manoj Tandon (10:40.655)
So how do you, there’s these bureaucratic regulations in place that come into play that are going to say, well, if you’re in Europe, then the data must stay in Europe. But if you have broken it up and spread it everywhere, I guess, how do you address that issue then? Or is compliance not an issue because you really

Murphy John (11:03.47)
Because compliance, yeah, compliance is not an issue because you’re not serving any compliance. So first of all, this is not specifically for compliant data. You cannot store compliant data which needs to be decided on a single location. We do have solution for that. I’ll give an example of how we can come over this. So we were working with the company based out of India. It’s an AI company which works with healthcare data. So they are having a lot of healthcare data and they process images of X-ray.

Now, know, health care data is subjected to so many regulations like HIPAA and all those compliances. And that data is not supposed to leave the country for any government. So what we have done is we’ve created a local network from them in India itself. The data never leaves any of the Indian premises. And they are often the same level of security by distribution fragmentation. So instead of that data being fragmented all over the world, the data gets fragmented only in India and complies to all their laws.

Manoj Tandon (12:04.534)
Okay. And if somebody came along and said, you mentioned like there’s privacy even from government snooping here, you’re not able to reconstruct that data set as the provider of the service.

Murphy John (12:19.266)
We cannot construct the data because the encryption key lies with the user’s laptop. So we can give you the data, but that will be always encrypted because the encryption key, you need the user’s laptop to sign in to get, or the user’s key to get the data.

Manoj Tandon (12:36.255)
Okay. Now, this is, guess, are you, is your technology pertinent to backup? Or is it also used in live operational situations where the data is getting written live from, let’s say, a database to a multiple fragmented backend and stored in real time?

Murphy John (12:59.84)
Now, majority of the use cases that we have is around backing up storage for long terms. So when an application needs to be stored over long term, when it needs to be backed up, and need not be accessed real time. So that’s when our case really gives you lot of benefits and efficiency.

Manoj Tandon (13:19.349)
Got it. Got it. So you’re not replacing a failover system for a bank per se.

Murphy John (13:26.732)
No, we were replacing the storage mechanism on a backup way, which is efficient enough in a distributed environment.

Manoj Tandon (13:37.717)
There’s a statistic, at least in the United States, that 70 % of all backups fail upon restoration.

Murphy John (13:49.955)
That’s right. That’s precisely right. So it’s not 70%, but it’s around 56 % of the data is only secured. And out of that 56%, 61 % of it fails when you’re trying to recover it.

Manoj Tandon (14:06.695)
Okay, thank you for clarifying that. what good is the backup in that case? When you need it the most, it’s not available to you.

Murphy John (14:18.648)
So yeah, so that’s because most of the people think that the backup is something that needs to just be stored and not be tested efficiently. So in order for the backup to be effective, really, you need to do checks at least two times in a year to ensure that you can recover from the data. Most of the people, just bind the services and they feel that the data is going to come up well, but they’re going to need the recovery. That’s not going to happen.

So you need to test it efficiently and ensure that it’s always available, readily available. So they don’t do kind of test or dry run when it’s required.

Manoj Tandon (14:56.723)
I agree with you. Now, is your technology at StorX doing something to ensure the data recovery?

Murphy John (15:05.102)
So our technology is basically how you secure your data and store it. The recovery would still have to be done manually tested with the users actually.

Manoj Tandon (15:15.742)
Okay. So it doesn’t eliminate the need for that testing in any way, shape,

Murphy John (15:21.11)
No, it doesn’t. You have to do it manually.

Manoj Tandon (15:26.505)
So basic good, having good basic hygiene is important. Now what about, how are you ensuring, I’m sure you’ve had clients that get hit with ransomware. And now the approach is to go after the backups first.

Murphy John (15:42.349)
Yes. So earlier it was having, they used to effect the primary servers first, and then they used to be able to run after recovery. But now they’re silently sitting on recovery, and then they destroy it completely and then go to the primary data. So that’s the problem that they generally face. So what we are trying to do instead, because what happens is your data is stored in a central location, you can just encrypt it. Our data is not stored in a single location, a single file. multiple small segments which are actually spread across multiple places. So there’s no central place where you can go and lock in the file.

Manoj Tandon (16:23.281)
But if they encrypt, let’s say even a small portion of the data, that makes it impossible to reconstruct it, Or no.

Murphy John (16:31.15)
A file, no. our technology is such a way that you have 60 % of the file which are recovered and you can still see back the file easily without any problem. So even if you lose 30 to 40 % of the files, with 60 % of the data fragments, you can still recover those files.

Manoj Tandon (16:48.645)
Hmm. It almost sounds like a NAS setup, if you will. I’m oversimplifying it, but where you could lose…

Murphy John (16:55.318)
Yes, yes, so it’s like a NAS setter. Yeah, it’s like a NAS setter, but an enhanced version of NAS setter, where you just get a couple of pieces together and you can still construct the file with the decoders.

Manoj Tandon (17:08.656)
That reduces your risk substantially.

Murphy John (17:12.494)
Yes.

Manoj Tandon (17:16.464)
Do people understand this? I guess from your…

Murphy John (17:19.758)
Actually, Actually, no. So it’s our job to explain them. But we have to just ensure that the technology is driven in such a way that they can help them to ensure that even after 40 % failure, they can still recover the files.

Manoj Tandon (17:39.863)
That’s a huge risk that can be eliminated. Because that’s one of the biggest risks is even if you do everything, you do network segmentation, MFA, single sign-on, put in ZTNA, put it, every acronym we have, you will still get hacked at some point. That’s the…

Murphy John (18:04.622)
Yes, the The time is now, it used to be like earlier used to be, you can protect yourself. Now the keyword is, in what time you can secure yourself. So it’s something like, you don’t know the time, but it’ll happen some part of time because there’s so much development happening. And now the human element is actually replaced by AI engine. So the hacking is being defined by AI engine, which can run 24 by 7. So it just need to be wrong once.

You don’t have to be, you can be right 99 % of the time, you just have to be wrong once.

Manoj Tandon (18:40.059)
Yeah, and it’s accelerating rapidly. I mean, you look at Anthropic, they have withheld the release of mitos for fear of exploitation of cybersecurity flaws.

Murphy John (18:51.916)
Yes, so they have stopped it, but I’m sure they’re pretty well. There are very specialized hackers available now who are already working on those kind of models. They’re building those kind of tools which can help them to carry on this task remotely and very efficiently.

Manoj Tandon (19:14.425)
I’m certain that that is the case, right? So how is AI playing in your field then with data storage? What are you guys leveraging it for?

Murphy John (19:27.63)
What we’re trying to leverage is we’re working with a couple of clients who have that, as I told you about this AI company, is based out of Mumbai, which is processing a lot of healthcare data. So we are, we are on the storage layer. So we provide them storage. So they have like an encrypted storage, a secure storage layer where they can put in all the data and do the kind of processing that they need.

Manoj Tandon (19:53.504)
Now, are you providing, is there an option for the client to use their own storage layers that they may have contract or their own data centers and still use your technology to distribute the data? Or is this, are you purely just a SaaS platform?

Murphy John (20:09.238)
No, video… No, no, we do have the technology licensing. So you can just come onto our website and we can set this up for you based on a consultant’s basis. So we can set up your own, we can take in your own setup and then we can do this distributed storage on your network. So instead of you having thousands of networks, which you cannot control, because there are certain compliance requirements where the people need that they identify the servers, which they store the data. So in that case, we will set that up. We’ll license the technology for you and you can set it up for your own requirement. And the data always stored in your specific servers. They don’t go out beyond your servers.

Manoj Tandon (20:48.405)
Okay. Is your technology geared? It sounds like it would be geared more towards enterprise clients. So mid-level companies, this would be beyond their ability to use and approach from an economic perspective or no?

Murphy John (21:07.214)
No, it’s so the most of our clients, can say 80 % of the clients that we work with are small and medium enterprises. And we do also have a free tier plan that is like up to 2 GB you can store without any cost. It’s free plan. You can just come and sign up. You need not sign up with a credit card or anything. You can come to our website, storage.io. You can register it and use up to 2 GB. So you can always see how it’s working.

You can be comfortable and only then you have to pay. And about the small and medium enterprises and individual users, have specific. So as we major use cases is around backup. We integrate with around 60 backup tools which are there right now available in the market. Some of the best in the industry. You can just use as the background storage and the data comes in and you can use with the software.

Manoj Tandon (22:00.965)
Okay, so you’ve made it as easy to use as possible. The DLT approach. So

Murphy John (22:07.886)
Yes, that was primary objective when we started designing the software. It has to be very easy to use. And we are S3 compatible. That means if you’re storing your data on any Amazon S3 cloud, you can store it in our software also without any changes of any code.

Manoj Tandon (22:26.717)
What is the biggest pushback you get, about DLT?

Murphy John (22:31.374)
The biggest pushback is the Same as, yes, yes. It’s just the mindset. The biggest problem is because what happens is the mindset, people are still not open to that technology and open source DLD technology because they always do with the decentralized technologies always connected to something like, is it reliable? Are they going to be in the industry for so long? Are they going to stay in the industry? Those kinds of things.

Manoj Tandon (22:34.621)
Really, it’s just the mindset.

Murphy John (23:00.854)
So that’s the mindset problem, which is the biggest problem that we face. Otherwise, technology can be tested. You can have free this thing. We integrate with lot of POCs. we have done lot of interesting use cases around this. So I still feel that the mindset is the biggest problem. And I don’t blame it, because as I said, Amazon took almost 10 to 15 years to come to this point. So it would be just like five years now in this technology. The technology is very, new.

Manoj Tandon (23:32.701)
From a cost-effective approach, what if you’re storing large data sets, what is the best or what’s the most economic way to scale this?

Murphy John (23:45.539)
So when we’re talking about storage cost, you’re talking about two costs exactly. One is the storage cost, and one is the egress cost. Storage cost primarily remains the same throughout the year, but egress cost is something that keeps on fluctuating, and that can go to any limit. Egress cost is basically the bandwidth cost which you pay to any of the hyperscalers for downloading the document from them. So upload this. Yes.

Manoj Tandon (23:54.95)
Absolutely, and that can be a very large number.

Murphy John (24:13.774)
So when you store a huge amount of data, egress costs can really make a lot of difference. So we can help you because we are in a distributed mode. We are in a platform which is decentralized. We can really save a lot of cost in that egress cost. We almost very generously place in case of egress cost. And at some companies, we are almost getting five to six times lower price compared to any other hyperscalers.

specifically for the E-Crest.

Manoj Tandon (24:44.709)
Really? Five to six times?

Murphy John (24:46.762)
Yes. Yes, yes. Because what happens is we are on distribute. So whenever you are, whenever you’re going with, when you’re going with the software, the biggest cause is the egress cost. If you look at the bills and that is something that you really don’t understand. So egress cost is like when we have worked with customers where we were able to bring down the egress cost 50 to 60 percent only because on a distributed environment.

You’re not sending data to any specific routing, you’re it to a distributed mode.

Manoj Tandon (25:21.424)
So your download is by its very nature a lot less number because you’re not downloading a massive amount of data from any one particular.

Murphy John (25:29.592)
from a central server. Yes, yes. It’s co-occurring across different places.

Manoj Tandon (25:35.748)
How big do you have to break up those data chunks? So if you’re talking about like two petabytes of data, how would that break up? Like is that 20 servers, 10 servers, you know?

Murphy John (25:49.551)
So currently, we have more than 1000 servers which are based out entirely on the data. So depending upon what is the file size in the file, the system will decide how many pieces has to be made and where it has to be sent.

Manoj Tandon (26:08.066)
Okay. So what defines a large data set for you? What would be considered large in your…

Murphy John (26:17.614)
A multimedia file, a movie file, which is there. I’m talking about the end user perspective. The multimedia file, is an unprocessed raw file, which would be a huge chunk. Those would be the biggest data that is processed by us.

Manoj Tandon (26:37.303)
So I’m thinking more like if you have transaction records, okay, that have gone back decades and it’s taking up a petabyte of data. To back that up is a non-trivial task. I mean, the only way really do it is with a petabyte set of drives that could, and if you’re gonna move the…

If you’re going to move that over the web, that’s going to cost you a lot of money. It’s going to cost you a lot.

Murphy John (27:11.116)
Yes, so that’s basically the infrastructure limitations that comes up when you’re that kind of, because you’re doing something really very big, or the internet that would consume a lot of time, and there would be frequent breakages also when you’re trying to connect it. So that’s the technical problem rather than the mindset problem which would come into backing up this kind of data.

Manoj Tandon (27:35.629)
I’m thinking, there a way to forgive me if this is a bad question. I’m allowed to ask a bad question. Again, I’m oversimplifying things, but is it possible that in a case where you have a use case where you have petabytes of data, you use your technology to back it up?

Murphy John (27:47.02)
Yeah.

Manoj Tandon (28:03.026)
locally and break it up and then send those individual SSDs.

to different locations.

Murphy John (28:10.05)
Right now we’re supporting that. But if there is an interesting use case, we would be open to try this out. I don’t have, I’ve not come across a client who has such a requirement, but it would be really interesting where we would like to check the limits of how the data can be supported by this kind of, because the architecture does support, but we have not tried it physically. But if there is some interesting cases, some challenging cases, it would be really interesting to work with them and see what is the…

achievement that we can make for this technology.

Manoj Tandon (28:41.59)
Well, I’m thinking you’re in the Middle East. look at, it’s all the process industries, oil and gas, chemicals. If you look at their SCADA data, it’s massive amounts of information, massive amounts of data. Look at the, yeah. Or even if you’re looking at the engineering build out, it’s a massive amount of data when you consider a refinery or a chemical plant. The engineering data is…

Murphy John (28:52.846)
If you look at the power projects, yeah.

Manoj Tandon (29:11.156)
ginormous if that’s a word. So.

If you’re going to really have a secure backup of all of that.

Manoj Tandon (29:25.225)
I mean, I would think it would be a challenge. Of course, you wouldn’t do it in one go, but you’re looking at so much data. One way is that you’re doing it incrementally over time, but you still don’t avoid the egress costs because if you ever need to rebuild that, you’re going to have to pull all of that back together again to make a functional system out of it. So,

Set up 10, 20 servers locally. Initiate the backup, back it all up, take the drives and send them away to different locations. And now you have an offsite backup that’s distributed using DLT technology. It’s de-risk from an on-premise backup. And…

Murphy John (30:11.5)
Yes, I think this would be an interesting case to work with. than backing it, what we could do is we could put up in the local data centers and then migrate it online over the, so it kind of takes the internal traffic routing and backs it up everywhere, rather than taking the physical hard disk and going to the different data centers and storing the data. But it looks like an interesting case to try out.

Manoj Tandon (30:35.656)
Yeah, that it would be because what you mentioned about egress costs is very, very real. And we’ve we’ve had horror stories of clients who didn’t realize that their Amazon bill would turn out to be such a large number when they went.

Murphy John (30:54.432)
In fact, yeah, in fact, if you look at the actual percentage of a software company or a SaaS company who is storing the data and receiving the data at real cost, you almost see that 20 to 25 % of the organization cost is just because of that storage and egress. And in that storage, the egress becomes the maximum part of it. And that’s something that you can really not calculate. So as a businessman, if I’m doing a business, I need to have the visibility of the cause that I’m going to have over the period of time. But this is something that is really very challenging. And if by any chances your server is hacked or anything, you may end up, you’ll have to probably sell your organization to pay the bills for Amazon. That can also happen. So I, as you said, the horror stories, we’ve also heard a lot of horror stories around egress cost, which is like gone beyond what it could be. And it really difficult to convince them. there’s a whole lot of process with the cyberscalers. convince them and bring down to that cost. that is something really very, that’s a real practical challenge that almost all the SaaS people and all the organizations have, they don’t face it.

Manoj Tandon (32:04.487)
That is the key word there until they don’t face it, right? And because most everyone is performing these backups, quote unquote, on an incremental basis online and they do not, I would say most do not have a clear understanding of the cost of egress. Whether they have not read the contract or they haven’t evaluated the amount of data they have and then projected what would be the unbudgeted because this would be an unbudgeted allocation most likely.

Murphy John (32:44.054)
I mean, a million of dollar operations where there are so many organizations, so many of distributed teams, which are storing the data across multiple clouds, across multiple offices. And then suddenly you get a tax or a shock which comes in the form of bill. It can be catastrophic for an organization which is really very huge.

Manoj Tandon (33:07.393)
It’s very interesting as I’m thinking through this, see, we’re in the business and in the cybersecurity business, we’re in the business of resiliency. And resiliency is not just having your data hacked. That’s one problem. But resiliency can also be affected by your ability to restore that information, whether that be the fact that you’re not able to restore it because your backups were never tested, which we’ve… Or…

Murphy John (33:14.989)
Yes.

Manoj Tandon (33:36.483)
You can’t pay the bill to actually restore it. So it didn’t really…

Murphy John (33:40.206)
That would be a really very very bad scenario.

Manoj Tandon (33:46.879)
I can see it happening in a variety of industries, especially in the small and medium businesses. I would never worry about like a Dow Chemical not being able to do that, They can easily, or Aramco can do it, no issues whatsoever, right? But you get a small 30 or 40 person company, this might become a real issue, right? And then by proxy, it becomes a real issue in the supply chain because they might be a supplier to an Aramco and might be governing a critical infrastructure piece. And now they have no ability to restore that.

Murphy John (34:30.558)
So it can be very catastrophic if you’re not and because what happens is during the lifetime of all the software companies, the SaaS company, they start with having free credits with all these hyperscalers. They start with business, they are not even aware. They see that they still have credits and by the end of six months, eight months, when this credit lapses, they’re going to get a shocker of what they’ve been using.

So that becomes real big problems because that’s the real genuine problem when we face most of the organization which are like in software development or providing some kind of SaaS services.

Manoj Tandon (34:58.499)
Hmm.It’s a very interesting solution. It’s a very interesting approach. And when you consider it, certainly on the risk register, the backup testing and restoration of data should be its own line item. I think that should be separate from all other budgets. It’s one that, you know, like we’ve seen in financial tech, there’s a lot of regulation. We’ve seen so far as in banks where they actually will test operating from their failover. Now, that’s a very expensive thing to do, and it requires a lot of guts to do that. Because

Murphy John (35:49.871)
And it also requires a lot of expertise because what happens is you actually have to put down your systems and hold for one day and test it across. People are really not willing to do that. That’s also, I think that’s more of a leadership challenge rather than the man power challenge. The leadership has to take care of something that is very critical.

Manoj Tandon (36:08.066)
I agree with you completely on that. And if we could force it, would love to, you know, in an ideal world, you want a complete rec replicated system that was separate, could not be accessed from your regular network infrastructure. And if something catastrophic happened, you could just flip over to your failover and not miss one minute of business. I understand there’s very serious cost limitations, manpower limitations, and even the biggest one is the mindset limitation on that one to even want to test something like that. But we have seen it, like in the financial sector, you do encounter that use case. So I guess in your experience in doing this for the last so many years, is there a particular industry that’s been more willing to accept DLT than others?

Murphy John (37:10.158)
I think the DLT is adopted in a small way, but because of the compliance and data storage industry, that is kind of trying to give the flip-in solution like a local storage, because what happens is most of the governments right now, the industries which are really controlled, the core industries are always concerned and controlled by the regulators. So we keep the key legislation that they want the data to be located locally. But this is something that they have not thought about when there is a situation like a war happening, the situation like the current censorship happening by the governments, what would happen for this kind of industry. So they need to really think about going beyond storing data locally to a multiple location where they can really have, because now we’re talking about the wars where the internet cables are being cut. At least we threatened that the internet cables would be cut.

So what would you do in that kind of scenario? That way. they should look at a holistic view, and they should give a solution which is more appropriate. In my opinion and my understanding what we’ve been reviewing, DLT is more used by companies which are seeing values. And in that, I see backup as the main use case. And really, I can talk about my business is majorly about small and medium enterprises, individuals who doing in a very big way.

Manoj Tandon (38:07.668)
Sure.

Murphy John (38:37.334)
individuals who are really are very aware of privacy and security are doing doing the backups.

Manoj Tandon (38:47.005)
Since you’re saying individuals, let’s say you are a small air conditioning contractor or engineering firm. 30 person operation, you’re not generating petabytes of data. You might have, I don’t know, maybe, let’s be generous, two terabytes for the whole company, okay? Okay. What should they budget in funds, in dollars, to have an effective backup using DLT for something like an organization of that size?

Murphy John (39:29.102)
I think if you’re talking about two, it’s like $200 to 40. Like it would be around $20 a month if they go in for two TB, $20 to $30, something around for the storage cost. The maximum is $50 per month. That’s what they have been doing with the free software. If they do a right kind of backup infrastructure, because you need two things. You need storage server as well as you need a backup software and what is the data that you need to back up. So that I think it should be like $50 to $100. $50 should be maxed, like $600 a year. Should be good enough budget for a small medium enterprise to do the backup, assuming that they have 2 DB of backup and they do an incremental backup. Not dumping up because the backup also require different ways and how we can ensure that the cost remains less and you’re doing it in a proper way.

Manoj Tandon (40:19.832)
And I’m not familiar with the current cost structures, but how much is two TBs of storage in the cloud these days?

Murphy John (40:29.482)
It would depend upon the egress cost because as I said, if the storage costs are 20, $25, but what about the egress cost? That keeps on changing. That’s something like that. That’s a big deal. Yeah.

Manoj Tandon (40:37.956)
Yeah, that’s we come back to that. We keep coming back to that.

Murphy John (40:43.128)
So there’s very one thing we have a free calculator in StorX.io. People can just go and check what is the egress cost going to be with this secure cloud providers. We have put out all the calculations there. It’s a free tool. can just go online. Without registering, you can try out this egress tool calculator.

Manoj Tandon (40:59.254)
Where, what’s the, where do they get this free tool?

Murphy John (41:02.538)
It’s our website is yeah, it’s our website is storage.io and that we have tools sections calculators are there so you can see the what is your backup reliability? What is the tools that you have and you can see what is the egress cost currently being charged as of today.

Manoj Tandon (41:18.764)
excellent. That makes-

Murphy John (41:20.864)
Maybe I can send you the links after this call is over. You can add it to the… Yes, yes.

Manoj Tandon (41:25.402)
We can add it to the show notes. If you, if you can respond back, then we’ll put them in the links in the show notes.

Murphy John (41:32.814)
So there are a couple of interesting things that you can do around your backup. We have created free calculators. You can just go and try out all the readiness of your backup. What are the egress costs that is going to be there? We’ve all calculated based on the prices that have been provided in the hyperscalers. And it’s a general tool. You don’t have do any registration either. It’s all free.

Manoj Tandon (41:53.805)
Now that’s very cool. That’s useful actually. And it can bring the realities of this home. So we’re already at the hour. We have two minutes left here in this broadcast. We want to give you the floor. Anything you want to let our audience be aware of. Anything you’d like to plug.

Murphy John (42:16.75)
I think we are great. This is great time to be surviving. There’s a lot of development happening around. They keep a tab of what are the new technologies happening. And AI is something that’s really good things. So data is really very critical for everyone. So you need to ensure that you give proper backup guidance and check it regularly. there are two things that are very, ensure that your data is secure, ensure that it’s backed up regularly, and ensure that your backup is tested regularly. Those are three key things that you should always take into consideration if you are really in the data business. Because I feel we are all in data economy, and data is something very, critical for everyone.

Manoj Tandon (43:04.534)
It very much is, and your business depends on it. And we’ve seen this time and time again. Well, John, we appreciate the information and the education on this topic. It’s a deep topic, and it’s one very important to the resiliency in any cybersecurity program. So thank you for being here, and we certainly enjoyed the conversation.

Murphy John (43:28.728)
Thank you very much. Sure, sure. Thank you very much. Thank you for having me on the podcast. And if you have any new announcements coming up, know, let us know. We’d love to have you back sometime.

Murphy John (43:41.624)
Sure, thank you very much.

Read more about Murphy on his LinkedIn

Learn More about StorX Network, visit their
Website : https://storx.io
YouTube: https://www.youtube.com/channel/UC5vUiX1eINl0gs6T3mS1CxA
Twitter: https://twitter.com/StorXNetwork
LinkedIn: https://www.linkedin.com/company/storxnetwork/
Facebook: https://www.facebook.com/StorXNetwork
Medium: https://medium.com/storx-network
Reddit: https://www.reddit.com/r/StorXNetwork
Telegram : t.me/StorXNetwork
Insta https://www.instagram.com/storxnetwork/

Calculators 
Cloud Egress Fee Calculator
AWS, Google Cloud, and Azure charge egress fees every time you retrieve data. See exactly what you’re paying in real-time.
https://tools.storx.io/egress-calculator.html

Password Strength & Breach Checker
Instantly score your password across 4 dimensions and check it against 10 billion+ compromised passwords — your password never leaves your browser.
https://tools.storx.io/password-checker.html

What Would a Ransomware Attack Cost Your Business?
Enter your company profile and get a data-backed cost estimate — downtime, recovery, ransom demand, and regulatory exposure — in under 60 seconds.
https://tools.storx.io/ransomware-cost-estimator.html

How Vulnerable Is Your Business to a Ransomware Attack?
https://tools.storx.io/ransomware-vulnerability-score.htmlHow

What Would You Lose?
Most people discover their backup wasn’t working when it’s too late. This tool shows you exactly what’s at risk — in your own terms, not gigabytes.
https://tools.storx.io/storx-data-loss-calculator.html

Check out the vCISO bot we created

Check out the other episodes in Season 19:

Ep. 0 Diyar Saadi – How Hackers Exploit Hidden Vulnerabilities

Ep. 1 Krisztian Kiraly – Who Really Controls Your Algorithm Data?

Ep. 2 Jason Roos – What the U.S.–Saudi Relationship Means for Cybersecurity

Ep. 3 Jasson Casey – Identity Attacks Are the #1 Threat

Ep. 4 Andy Smith – What Good Is Cybersecurity Tech… If It Still Fails?

Ep. 5 Murphy John – The Future of Decentralized Data

Ep. 6 David Linthicum – Artificial Intelligence Mistakes Every Company is Making Right Now

Ep. 7 Bronwen Aker – Treat Artificial Intelligence like a Drunk Intern

Ep. 8 Yagub Rahimov – You Can Get Hacked With Emojis

Ep. 9 David B. Cross – The Future of Cyber Threats

Ep. 10 Mark Kreitzman – The Hidden Cost of Mobile Identity Theft

Murphy John's profile picture for Dark Rhiino Security's Security Confidential podcast

Murphy John is the Chief Growth Officer at StorX Network, where he focuses on scaling decentralized data storage solutions and building strategic partnerships.

Passionate about data security and privacy, Murphy works at the intersection of decentralization and distributed ledger technology (DLT), helping organizations rethink how data is stored, protected, and accessed globally.

His work centers on enabling more secure, resilient, and privacy-first data infrastructure for the future.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top