Enterprise IT environments have grown more distributed than ever, with applications now spanning hybrid infrastructure, multiple cloud providers, and a mix of Windows and Linux platforms. But according to SIOS Technology’s newly released 2026 State of Application Resilience Survey, that complexity is outpacing the high availability and disaster recovery (HA/DR) strategies meant to protect it. The survey, which polled more than 250 IT leaders across North America and the UK, found that 76% of respondents experienced at least one downtime event lasting more than 10 minutes for their most critical application in the past year—despite having HA/DR protections already in place.
To dig into what’s behind these findings, VMblog spoke with Dave Bermingham, Senior Technical Evangelist at SIOS Technology, about why traditional resilience approaches are struggling to keep pace with today’s heterogeneous IT landscape. Bermingham discusses the widening gap between HA/DR investment and actual protection, the outsized role complexity plays in implementation challenges, troubling gaps in disaster recovery testing frequency, and the growing convergence between cybersecurity and application resilience. He also offers guidance for IT leaders looking to move beyond basic infrastructure protection toward a more application-aware approach to resilience.
++
VMblog: What prompted SIOS to conduct the 2026 State of Application Resilience Survey, and what did you hope to understand about how enterprises are protecting mission-critical applications?
Dave Bermingham: We conducted the survey because we wanted to get a clearer picture of how organizations are protecting mission-critical applications as IT environments become increasingly complex and distributed. We surveyed more than 250 IT leaders across North America and the UK about their current high availability and disaster recovery strategies, the challenges they face, and where they expect to invest next. What stood out to us was the widening gap between the complexity of today’s environments and the effectiveness of traditional HA/DR approaches. Most organizations are now operating across hybrid or multicloud infrastructure, with applications spanning different operating systems and platforms. We wanted to understand whether their resilience strategies are keeping pace—and the findings suggest there is still considerable room for improvement.
VMblog: What did you find most surprising about the current state of application resilience?
Bermingham: The prevalence of downtime was probably the most surprising finding for us. Despite having HA/DR protection in place, 76% of respondents experienced at least one downtime event lasting more than 10 minutes for their most critical application during the past year. Nearly one-quarter experienced that level of downtime three or four times. What makes that particularly concerning is that only about half of respondents said they were satisfied with their current HA/DR solutions, while more than one-third were neutral. To us, that points to a larger issue than simply whether organizations have invested in HA/DR. The real question is whether those strategies are delivering the level of resilience organizations need in today’s increasingly complex application environments.
VMblog: Why is application resilience becoming more difficult as organizations move to hybrid and multicloud environments?
Bermingham: From our perspective, the fundamental challenge is that enterprise IT environments are no longer standardized. Only 2% of respondents said their critical applications run exclusively on-premises, while nearly 70% operate in hybrid environments, and many are using different cloud providers for different applications. At the same time, enterprises are running critical workloads across Windows and multiple Linux distributions. That diversity creates significant management and integration challenges. Traditional approaches can require different tools, processes and expertise depending on the platform. As environments become more heterogeneous, organizations need HA/DR strategies that can work consistently across different operating systems, applications and infrastructure. We believe resilience has to follow the application rather than being tied to a particular infrastructure environment.
VMblog: The survey found that complexity is the biggest HA/DR implementation challenge. Why is complexity such a significant problem today?
Bermingham: We think complexity is really a consequence of how much the enterprise IT environment has changed. Nearly 44% of respondents identified configuration and management complexity as one of their biggest HA/DR challenges, followed by 37% who cited integration with existing systems and applications. Organizations are trying to protect mission-critical applications across multiple operating systems, cloud platforms and application environments, often with different tools and processes. That makes it harder to establish consistent policies and manage resilience effectively. What’s particularly interesting to us is that cost was actually a secondary concern compared with complexity and integration. That tells us organizations aren’t simply looking for the least expensive HA/DR solution. They’re looking for approaches that can simplify resilience while providing reliable protection across increasingly heterogeneous environments.
VMblog: How concerned should organizations be about the lack of disaster recovery testing revealed by the survey?
Bermingham: We think organizations should be very concerned because having a disaster recovery plan isn’t the same as knowing that the plan will work. Our research found that only 7% of organizations conduct full DR testing monthly, while 32% test only annually. Perhaps even more concerning, 22% of respondents didn’t know how frequently their organization conducts DR testing. That creates a significant confidence gap. When a mission-critical application fails, IT teams need to know that their recovery processes, configurations and dependencies will actually work under pressure. Regular testing is what turns a theoretical recovery plan into an operational capability. Given how widespread downtime is, we would encourage organizations to evaluate not only whether they have DR protection, but also how frequently they validate that protection and whether the results give them genuine confidence in their ability to recover.
VMblog: The research also shows a growing connection between cybersecurity and application resilience. What is driving that convergence?
Bermingham: We see cybersecurity and application resilience becoming increasingly inseparable because security incidents can quickly become availability and business continuity events. Organizations aren’t just trying to prevent attacks; they also need to recover quickly and keep the business operating when something goes wrong. The survey reflects that shift. Cybersecurity ranked as the top IT spending priority, with improving disaster recovery protection ranking second. We’re also seeing growing interest in using HA clustering as part of patch management. Fourteen percent of respondents already use HA this way, while another 31% would consider it and 27% want to learn more. To us, that shows organizations are recognizing that resilience technologies can help them apply security updates more quickly while minimizing disruption to critical applications.
VMblog: With disaster recovery ranking second among near-term HA/DR spending priorities, what does the survey tell us about where enterprises are investing next?
Bermingham: We think the survey shows that resilience is moving higher on the enterprise IT agenda. Improving application disaster recovery protection ranked second among HA/DR spending priorities, behind cybersecurity and ahead of areas such as data analytics, infrastructure upgrades and new software development. In fact, 75% of respondents characterized DR as a medium or high priority. To us, that indicates organizations are no longer viewing disaster recovery simply as an insurance policy. They’re recognizing that application availability is fundamental to business operations, particularly as applications become more distributed and organizations face greater cybersecurity threats and infrastructure complexity. It also reinforces the need for HA/DR strategies that are easier to manage and can protect applications consistently across today’s hybrid, multicloud and heterogeneous environments.
VMblog: What should IT leaders be doing differently based on these findings?
Bermingham: We think the first step is to look beyond simply having an HA/DR solution and ask whether it actually delivers the resilience the business requires. That means understanding where downtime is still occurring, testing recovery processes regularly and identifying complexity or integration gaps across the environment. Organizations should also evaluate how their resilience strategy addresses hybrid and multicloud deployments, different operating systems and increasingly distributed applications. We would also encourage IT leaders to think about resilience and cybersecurity together. HA can play a role not only in recovering from failures, but also in enabling faster patching and reducing disruption during maintenance. Ultimately, we believe the goal should be to move beyond basic infrastructure protection toward a more application-aware approach that improves availability while simplifying the management of complex IT environments.
##






