← Back to context

Comment by SatvikBeri

8 years ago

We give everyone access to production systems, but even if someone deleted everything from production, we can restore everything in ~20 minutes (this has happened), and if that process fails, we have backups on s3 that can be restored in a couple of hours (and this is tested regularly, but thankfully hasn't happened yet), and even if that fails...

There's a reason why it's called disaster recovery and prevention.

Why try to justify stupid behavior and absent security controls with the idea that your downtime is "only" 20 minutes? How silly.