Data Security Decoded 7.28.26
Ep 60 | 7.28.26

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

Show Notes

This episode delivers operational insights from the frontlines of global telecommunications, drawing on ⁠Fred Lhoest⁠'s experience managing IT infrastructure across 60 countries at ⁠PCCW Global⁠. The discussion begins with the realities of consolidating an environment that previously relied on more than 10 disparate backup tools into a single, unified data protection platform. Fred details his journey as a self-described automation junkie, explaining how he developed an open-source PHP and GraphQL framework to query APIs, detect unprotected virtual machines, and streamline automated recovery tasks.

The conversation transitions into the operational boundaries of automation and cyber resilience. Fred warns against unvetted, fully autonomous failover triggers, emphasizing that false positives can lead to catastrophic outages if fallback systems are out of sync. He advocates for a human-in-the-loop validation model to maintain control over critical infrastructure decisions.

Looking toward future infrastructure shifts, Fred examines the risks of migrating complex systems to hybrid cloud environments. He highlights the necessity of strict data residency compliance across global jurisdictions, including the European Union and the United States. Finally, Fred raises a critical warning regarding long-term digital archiving. He challenges the industry to solve the file format and hypervisor obsolescence trap, where compliance regulations require holding data for 30 years, but modern software renders the underlying files unreadable.

What You'll Learn

  • Strategies for consolidating fragmented backup tools into a single management interface.
  • Methods for leveraging GraphQL APIs to build custom security automation frameworks.
  • Risks of false positive automated failovers and human in the loop requirements.
  • Key data residency considerations for migrating workloads across international jurisdictions.
  • Practical guardrails for controlling employee and developer interaction with AI models.
  • Uncovering software obsolescence risks hidden inside long term digital data archives.
  • Why continuous recovery testing is essential to validating enterprise incident response plans.