Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup and NetBackup Appliances Hardening Guide
  3. Top recommendations to improve your NetBackup and NetBackup appliances security posture
  4. Enabling encryption
NetBackup and NetBackup Appliances Hardening Guide

Enabling encryption

Cohesity recommends that you enable data encryption at rest and in transit. Encryption prevents unauthorized data access and theft. If data is encrypted with robust industry standards, attackers cannot access it even if the data is stolen.

NetBackup software provides various options to configure encryption. To ensure optimal security, NetBackup includes encryption features for data at rest and in transit. You can encrypt your data before you send it to the cloud. You can use the built-in NetBackup key manager service (KMS) or configure NetBackup with a third-party KMS during storage server configuration.

Another way that your data is protected is with certificates, which create an encrypted connection between hosts. By default, NetBackup and NetBackup appliances use self-signed certificates for host communication. You can choose to configure external certificates instead. When you use external certificates, they are validated for authenticity by an external certificate authority (CA). In this way, the identity of the certificate holder is verified through a publicly known and trusted third party.

How to enable encryption:

  • Flex Appliance

    Flex Appliance meets Federal Information Processing Standards (FIPS) 140-2 standards to keep data encrypted at rest and in transit. FIPS is enabled during the Flex Appliance installation process.

  • NetBackup Appliance

    See About data encryption .

    See FIPS 140-2 conformance for NetBackup Appliance.

  • NetBackup

    See About FIPS support in NetBackup.

    See Installing KMS.

    See Workflow for external KMS configuration.

    See Workflow to configure data-in-transit encryption.

  • Access Appliance

    See FIPS 140-2 conformance for Access Appliance.

How to configure external certificates:

  • Flex Appliance

    See Using an external certificate.

  • NetBackup Appliance

    See About implementing external certificates.

  • NetBackup

    See Workflow to use external certificates for NetBackup host communication.

  • NetBackup Flex Scale

    See Deploying external certificates on NetBackup Flex Scale.

  • Access Appliance

    See About external certificates on Access Appliance.

Feedback

Was this page helpful?
Previous

Reducing network exposure

Next

Enabling catalog protection

Feedback

Was this page helpful?