IT Briefcase Exclusive Interview: How VMware Cloud on AWS Can Improve Data Protection and Recovery

Sep 19, 2019 | Data, Fresh Ink, Security

Matthew Wallace, CTO of Faction, sees VMware Cloud on AWS growing in 2019. Here, he shares insights about trends in VMware, best use cases, advantages, and how to avoid delays and complications in disaster recovery.

cyber security_2

  • Q. Do you see growth for VMware Cloud on AWS in 2019? 

Yes. VMware has finally reached the tipping point where customers are no longer just kicking the tires. Instead, they are adopting the platform for disaster recovery (DR) and production use cases. At Faction, we’ve seen exponential growth in our pipeline and customer base for VMware Cloud on AWS; we expect this to accelerate throughout 2019 and beyond.

  • Q. What are the industry challenges facing VMware Cloud on AWS? 

VMware has historically been a company that sold software. The company needs to pivot to selling cloud throughout their entire sales force. This could be a complex problem to solve at their global scale.

  • Q. What are the best use cases for using VMware Cloud on AWS?

There are four best use cases that we see:

1.     First is disaster recovery. VMware Cloud on AWS allows for the use of existing on-premise DR technology, like VMware Site Recovery, to reduce the cost and complexity of replicating to cloud. On-demand scale-out provided by cloud DR also eliminates the need for the upfront costs of building an entire secondary site, which would only be used in the event of a failover.

2.     Datacenter extension is a second important use for customers who need additional capacity for various reasons. Test/Dev capacity, added geographic locations or seasonal spikes can all expand a company’s on-premises footprint without adopting new and unfamiliar cloud technology or tools.

3.     The next consideration is ease of cloud migrations. VMware platform consistency—on both source and target sites— allows customers to accelerate their migration to cloud. Familiar VMware tools require fewer expenses and less time, since you do not need to hire or retain expensive public cloud talent. You can also reduce time to value by integrating VMware tools being used on-premises.

4.     The fourth and final use scenario is integrating applications with cloud services to boost business outcomes. Once you are deployed, you’ll be able to combine legacy apps that are migrated to VMware Cloud on AWS with native AWS IaaS or PaaS services. This provides your developers with tools to expand the business outcome that your application delivers.

  • Q. What are the advantages to cloud-based DR? 

In short, there are four: geographic diversity, cloud services, scale and DR software.

Specifically:

– Geographic diversity: AWS has 60 availability zones across 19 regions and growing, not counting two GovCloud regions. VMware is rapidly expanding to all of them.

– Cloud services: One thing we’ve seen is that AWS offers a lot of services that help provide functionality that might otherwise need dedicated appliances or complex on-premises setup. For example, AWS Application Load Balancer and Network Load Balancer can replace costly on-premises hardware load balancers.

– AWS CloudFront Content Delivery Network can help ensure rapid scaling and high performance. AWS marketplace appliances can help replace other on-premises appliances.

– Scale: Need we say more? AWS spent over $25 billion on capex in 2018; a great deal of that went toward hardware for AWS. One of the largest appeals of DR to the cloud is the enormous capacity of AWS.

– DR software: As DR has increasingly moved to software-defined tools, those tools have become more complex. Now electronic versions of runbooks allow sophisticated ordering, checkpoint, custom scripting, network modifications, and more, all in an easy to use format.

  • Q. What are some customer challenges to cloud-based data protection solutions?

Fortunately, Faction’s offering of disaster recovery services on VMware Cloud on AWS delivers the advantages of Public Cloud based DR, without the following disadvantages of other solutions:

– Import, export and failback issues: If you have to go through a converter (which most recover to cloud tools require, because it is not VMware on the target side), you may not convert properly. Then you could have a “disaster” during your disaster recovery. Additionally, conversion can add a lot of time, worsening your recovery time objective (RTO). Finally, most cloud tools don’t support failback and require a manual process, prone to human errors.

– Tool incompatibility: VMware has a broad ecosystem of tools with solid integrations. You lose that if you go to public cloud directly.

– RTO time: Conversion adds a lot of time. Weak runbook software adds a lot of time. This is an infamously large problem.

– People, process and technology: You are going to have hair on fire during a live-fire full failover to a DR site. This is not the time to be using new tools. For example, say there’s an error in your AWS VPC security group. How many minutes will it take to diagnose and fix it when your team doesn’t have extensive experience in public cloud technology? Add to it the considerations of VMware Private Cloud providers. In order to provide on-demand capacity, they generally use vCloud Director, which means you’ll lose vCenter access and force your team to use an unfamiliar tool in the middle of a disaster recovery event

Matt Wallace

About the Author

As CTO, Matthew Wallace is responsible for product development, managed and professional services, and architecting Faction’s cloud infrastructure offerings. Prior to Faction, Matt has worked 20 years in technology in roles at both startups and Fortune 500 companies, including leadership roles at Level 3 Communications, ViaWest, Exodus Communications, and others. Matt is the co-author of Securing the Virtual Environment: How to Defend the Enterprise Against Attack, one of the first books to holistically address cloud security concerns. Matt is an Official Member of the Forbes Technology Council.

 

 

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more