Skip to content

DATA PROTECTION

Cyber Resilience and Backup Strategy: Lessons From 3+ Decades in Data Protection

October 9, 2026
Jason BuffingtonPrincipal Analyst, Data Protection Matters

I've been in data protection for over 35 years: started by swapping tapes, spent most my career at vendors (Arcserve, DoubleTake, Microsoft, Veeam), and two stints as an industry analyst. The production platforms keep changing, as do the protection methods and recovery expectations, but there are some consistent lessons we can use here.

I recently sat down with Rob Callaghan, Principal Solutions Marketing Manager at Wasabi, for a series of conversations covering everything from multi-vendor backup strategy to AI's role in modern cyberattacks. This article shares a recap of our first conversation.

The evolution from backup to cyber resilience

For much of my early career, resilience meant a three-ring binder and a prayer. I got certified as a business continuity planner (CBCP) back in 2003, when the job still came with a satellite phone and a go-bag in the trunk of your car. Before then, if an executive wanted to sleep at night, there was exactly one question: are we backed up?

Business continuity and disaster recovery (BC/DR) has been my focus ever since, and I've watched that discipline stretch into a real continuum: from backup, to disaster recovery, to cyber resilience, each one with higher expectations and broader challenges than the last. That said, it’s always been true that channel partners and service providers have often made the difference for resilient outcomes.

Here's the version of the question I actually use now: if you depend on a system and that system disrupts the business, through malice or through plain error, can you get back to a known good state so the business can persist or resume?

That still depends on one thing working underneath all of it: whatever's backing up those systems in the first place. A lot of folks presume that once you choose a backup solution, you're going to use it everywhere. In all my years of backing stuff up, that's never been true.

Why most organizations use more than one backup solution

In spring 2026, DPM surveyed asked 440 IT leaders a simple question: how many backup solutions are you actually running? Only 7% said one. The average came out to 2.8.

The real answer why: endpoints (especially OT like on manufacturing floors or in healthcare) that aren't sustainable, hardenable, or recoverable enough and SaaS, which your legacy datacenter backup tools don't follow as fast as your business adopts new SaaSes. Bottom line: you will change backup solutions as your production landscape changes, and that's not a sign anything's wrong. It's just what a growing, real-world environment looks like.

The actual risk isn't the number of vendors. It's what happens to the data each backup vendor was storing, the moment you move on from it.

Why backup storage should be independent from backup software

I've been allergic to vendor-locked storage since I started doing data center backups. It's still the same problem today, just with different names. You'd switch platforms, but your retention requirements outlasted all of them, so you kept the data in one storage layer and just swapped the software feeding it. When you stop paying for that software, you've got two bad options: keep paying for as long as you need previous versions, or the data's gone the next day; both negate any kind of retention mandate.

That's not hypothetical for anyone with real retention obligations, whether its bio/pharma testing records, patent documentation, or even healthcare data that has to survive beyond the life of a patient. If that data sits behind an all-in-one tool, you're not storing it. You're renting it, indefinitely, from whoever happens to be your vendor the day it matters.

As an analyst and backup geek, I routinely run various backup solutions through my test lab. My only constants tend to be: 1) my diverse workloads (on- and off-prem), my on-prem storage appliance, and my Wasabi cloud.

If you aren’t testing, you don’t have a plan – you have a hope

For as long as we've been talking about IT resilience, it always comes down to one truth: if you're not testing, you don't have a plan, you have a hope. That used to mean cutting a $25,000 check to a DR vendor to kick off your DR test, even before you found out whether you could actually recover anything. If your boss knows every test costs real money, your boss will inevitably tell you to test less often or less rigorously.

One of the reasons that I like service providers that leverage Wasabi is that their testing doesn't carry that tax. No egress fees, no per-request charges turning a routine drill into a budget event. You test because it costs you nothing to find out, not because you finally got approval.

Data recovery vs. business recovery: Not the same thing

Here's a distinction many fail to draw until they're in the middle of an incident: restoring your data is not the same as restoring your business. Imagine your business has suffered a fire, flood, or tornado. But because you're prepared, the very next day a truck shows up with replacement desks, computers, and everything. The address they wheel up to is a concrete slab because that's all that's left. Most teams have a plan to repair or replace the desks or computers, but that doesn't guarantee that the business can resume operations.

Plenty of recovery plans stop with the furniture. A recovered server with nothing else around it is a black box with blinky lights. It doesn't know who's allowed to log into it, or its own name on the network. DNS, identity, license keys, the IP configuration, the runbook that says what connects to what, none of that lives on the server you just restored.

Most business recovery plans therefore need a “Go Bag” – a secure place with everything you'll need to rebuild the building, even before you restore the furniture. But don't let your recovery go bag become another source of vulnerability by others being able to access it.

Stop account compromise with MUA and Covert Copy

Once your data's immutable, a criminal can't touch it directly, so the next target is the account. Compromise the right credentials, and deleting that account is easy, unless every security contact tied to it has to independently approve first. That's Multi-User Authorization (MUA) from Wasabi, and it's a real wrench in the gears for anyone who's already gotten past your first line of defense.

Layer in Covert Copy™ on top of that: a copy of your data nobody can even see exists until every one of those contacts signs off on root access. When I first saw the demo, my reaction was that it's one of the more elegant implementations of human-in-the-loop I've come across because of what it assumes going in, that an admin account is probably already compromised, rather than hoping none are. Multiple people have to agree in parallel before anything happens, instead of one person deciding and everyone else finding out after. This is as obvious as why two or more people have to turn their nuclear keys at the same time.

Data resilience requires defense in depth

What ties all of this together is defense in depth: no single control, no single vendor, no single untested plan, not one of these is ever enough on its own. Independent storage prevents a single vendor from holding your data hostage. Testing keeps a plan from being a guess. Multi-user approval keeps one compromised account from being enough. Stack them, and an attacker, or an accident, has to clear every layer, not just one.

I wrote a book in 2010 that opened and closed on the same mandate: “Get your data out of the building.” That’s defense in depth too, just applied to geography instead of vendors or accounts. In the full webinar, Rob and I dig into why it's still critical even as everything else about recovery has gotten more complicated. We also cover more ground:

  • Why most organizations keep everything forever instead of deciding what's actually worth the cost

  • Why the GPU shortage is pushing even reluctant companies toward shared cloud capacity

  • What happens the second someone actually tries to bypass Covert Copy

WEBINAR: 2.8 Backup Products, One Recovery Strategy

Catch the full, on-demand conversation with Jason Buffington and Rob Callaghan.

Watch Now

Cyber resilience is an organization's ability to continue operating, or quickly return to a known good state, after a disruption to its IT systems, whether that disruption is caused by a cyberattack, human error, or system failure. It's broader than traditional cybersecurity, which focuses on preventing attacks. Cyber resilience assumes disruptions will happen and focuses on recovery, continuity, and minimizing business impact when they do.

Backup refers to creating copies of data so it can be restored if lost. Disaster recovery (DR) is the broader process of restoring IT systems and operations after an outage, typically at scale. Cyber resilience is the widest of the three: it includes backup and disaster recovery, but also accounts for cyber security (before, during, after), identity controls, and the ability to recover from both malicious attacks and accidental errors, not just technical failures.

Most organizations run multiple backup products because no single tool typically covers every type of workload, including legacy data center systems, SaaS applications, and specialized or industry-specific endpoints like operational technology (OT) in manufacturing or healthcare. As a business adopts new applications and infrastructure, its backup needs evolve, often faster than any single vendor can keep up with.

Defense in depth is a security strategy that layers multiple independent controls so that no single point of failure, whether a vendor, a tool, or a compromised account, can fully compromise an organization's data or recovery capability. In backup and recovery, this typically means combining storage independence from backup software, tested recovery processes, and account-level protections like multi-user approval, so that no single failure point can take down the whole system.

MUA is a security control that requires multiple designated users to independently approve sensitive or destructive actions, such as deleting backup data, before those actions can take place. It's designed to prevent a single compromised account or credential from being used to delete or damage backup data, since an attacker would need to compromise multiple approvers rather than just one.

Related article

security center
DATA PROTECTIONReady when it counts: Inside the new Wasabi Console Security Center

Most Recent

What does the 2027 EDUCAUSE Top 10 mean for higher ed storage?

EDUCAUSE's 2027 Top 10 is all about change. Here's how flat-rate pricing and immutable backups help IT teams manage AI, security, and budget risk.

Store on Wasabi, train on Vultr: A faster path to AI at scale

Wasabi has joined the Vultr Cloud Alliance, pairing Vultr Cloud GPU with Wasabi Hot Cloud Storage so AI teams can train models without per-request or egress fees driving up costs.

Wasabi + Autotask: Simplifying cloud storage management for MSPs

Wasabi's Autotask PSA integration brings account provisioning, usage reporting, and service management into the workflows MSPs already use. Learn more.

SUBSCRIBE

Storage Insights from the Storage Experts

Storage insights sent direct to your inbox.

Subscribe