Organizations and society now depend heavily on digital services, making outages and cyber incidents far more damaging—especially in highly optimized, just-in-time public services, manufacturing, and commerce. The text highlights how cyberattacks and cloud outages can quickly disrupt operations and impose major financial and continuity impacts, citing UK incidents in 2025 affecting Marks & Spencer, the Co-op Group, Jaguar Land Rover, and an AWS service outage that limited access to enterprise and government systems. The accelerating adoption of Generative AI increases the cyber risk surface and enables attackers to scale and improve techniques such as phishing, while geopolitical tensions amplify threats from state-backed actors and raise operational continuity concerns tied to digital sovereignty. In response, governments are strengthening resilience requirements through regulations such as EU NIS2 and DORA, and broader obligations such as GDPR Article 32 and SOX emphasize integrity, availability, and resilient processing systems.
Achieving cyber resilience requires going beyond preventative security controls to build robust response and recovery capabilities—particularly the ability to back up, protect, and restore not only business data but also the metadata and configuration elements that define modern virtualized and cloud infrastructure, workloads, and applications. Backup and Disaster Recovery (DR) solutions are described as providing secure creation and storage of backups that support defined Recovery Point Objectives (RPOs) and Recovery Time Objectives (RTOs), along with restoration and service recovery capabilities. Effective solutions address diverse data sources (on-premises, edge, IaaS/PaaS/SaaS), use methods like incremental/continuous backups and replication, support application-aware and snapshot backups for consistency, and protect backup repositories via encryption, malware scanning, air-gapping, immutability, and multi-copy strategies such as the 3-2-1 principle. Because attackers target backup systems and processes, the text stresses hardening backup infrastructure and administrative controls (MFA, least privilege, logging). It also covers advanced recovery needs including cross-platform recovery (e.g., cross-hypervisor, physical-to-virtual, restore into public cloud) and varying DR service models (managed DR, assisted recovery, automation and testing). Finally, it outlines key use cases (cyberattack resilience, data corruption, datacenter and cloud service resilience, migration/lock-in protection), functional selection criteria (security, interoperability, usability, SaaS/IaaS coverage, compliance, ransomware protection, DR capabilities), and practical procurement and architecture considerations, including integrating backup/DR into incident response planning and testing.
See All Locations
See All Locations