Every year on March 31 — strategically placed the day before April Fool’s Day as a reminder that only fools skip their backups — the technology industry pauses to observe World Backup Day. First launched in 2011, World Backup Day highlights the importance of protecting data and keeping systems and computers secure. What began as a grassroots Reddit conversation has grown into a globally recognized event, uniting individuals, IT professionals, and enterprises around a shared mission: ensuring that critical data is protected, recoverable, and resilient in the face of an increasingly complex threat landscape. From ransomware and cyberattacks to hardware failures and human error, the consequences of inadequate data protection have never been more severe — or more costly.
For enterprise IT teams, World Backup Day is far more than a calendar reminder. It is an annual checkpoint to evaluate backup strategies, stress-test recovery plans, and reconsider whether existing solutions are truly prepared for the demands of modern hybrid and multi-cloud environments. The stakes are high: data loss can mean regulatory penalties, operational downtime, damaged customer trust, and in the worst cases, existential business risk. With new challenges emerging around AI-driven workloads, edge computing, and evolving compliance requirements, the conversation around backup and data resilience continues to deepen and expand.
To mark this important day, VMblog reached out to some of the brightest minds across the data protection and storage industry — here is what the experts have to say.
++
Bill Andrews, President and CEO, ExaGrid
World Backup Day allows customers to take a moment to consider how backup and data protection are changing all around them.
Customers are realizing that backup/data protection is becoming more strategic and there are requirements around operations, performance, scalability, security, disaster recovery, costs including power and cooling, full useful life versus forced product obsolescence, etc.
This list of requirements is growing, starting with ingest performance for a short backup window, fast restores to keep users productive, the ability to scale as their data grows, full security including ability to recover after a ransomware event, (air gaps, locked data, immutable data, etc.), the ability to survive a natural or man-made disaster, and lastly all of the things that impact cost including rack space, power, cooling, price protection, and need at least 5 years of guaranteed useful life of the storage.
Customers are becoming educated and are not simply throwing any storage behind their backup application, as most storage does not meet the requirements that they now have in a much more dynamic data protection world.
++
Eric Schott, Chief Product Officer at Object First
Each year, World Backup Day serves as a reminder for consumers to save and backup their important data, but for businesses, it’s a call to be prepared and take action as AI-powered ransomware threats become more sophisticated. The loss of backup data leads to operational downtime, which can cost businesses substantially in lost revenue and reputational damage, not to mention if a ransom is required to recover their data. That’s why immutable storage – backup data that, once written to the device, cannot be altered by anyone, even the most privileged admin – is so important this World Backup Day. It’s the only way to guarantee a path to recovery.
++
Geoff Anderson, VP Product Marketing, Object First
World Backup Day has been raising awareness of data protection best practices for 15 years, but with the rise of AI-powered cyberattacks, its mission has taken on new urgency. A recent survey of IT and security workers by Object First found that 89% say AI-powered cyberattacks have made them more concerned about the safety of their organization’s data, and only 53% are very confident they can quickly recover from such an attack. The top-ranked defense they’ve identified is increasing backup data security, but unfortunately implementation of these solutions is lagging, with only 58% using immutable backup storage across all their data. This World Backup Day, we urge IT leaders to consider the importance of backup data security in the fight against AI cyber threats.
++
Simon Taylor, CEO, HYCU, Inc.
At HYCU, we’ve spent years talking about backup and protection. Meanwhile, the problem has fundamentally changed.
AI is creating more data than ever. SaaS is spreading it everywhere. And, most of it still remains unprotected.
If your data lives in someone else’s cloud, under someone else’s rules, with limited recovery, you don’t have protection. You have exposure and unnecessary risk.
At HYCU, we developed HYCU R-Cloud to change that. Simple to use, easy to deploy, and built for SaaS. It was designed so you own your data, not the platform it runs on.
On World Backup Day, we recognize this change as backup is not the goal. Control is.
++
Matthew Stern, Chief Security Officer at Hypori
World Backup Day is a reminder that real cyber resilience depends on both recovery and prevention working together. Companies should make routine backups a consistent part of their security operations, so critical systems and data are regularly stored. When organizations maintain reliable backup practices, they are better prepared to recover from incidents and keep operations moving without long disruptions.
At the same time, recovery should not be the first line of defense. Security should begin by reducing the chance that sensitive data is exposed in the first place. When corporate information stays inside controlled environments instead of living on phones, laptops, or other endpoints, a compromised device does not automatically become a pathway to the organization’s most valuable data. Prevention limits the impact of an incident, while strong backups ensure organizations can restore operations if an incident occurs.
++
Federico Simonetti, CTO of Xiid
World Backup Day should be a reminder that backups alone don’t equal security. Too many organizations still approach cybersecurity the way they did twenty years ago, reacting after an attack rather than designing systems that prevent attacks in the first place.
The safest assumption today is that backup systems themselves are vulnerable. If attackers can reach them, they can encrypt or destroy them.
At Xiid, we advocate for preventive security architectures that restrict the attack surface around backup environments. Access should be limited to the exact process responsible for creating the backup, not the entire machine or network.
When backup targets are only reachable by a specific, authenticated process and remain invisible to everything else, attackers lose the ability to discover or compromise them. That shift from reactive protection to deterministic prevention is what modern cybersecurity actually requires.
++
Steve Cobb, Chief Information Security Officer at SecurityScorecard
SecurityScorecard research shows that 99 percent of Global 2000 companies are directly connected to vendors that have experienced a data breach. In an ecosystem this interconnected, the risk of being impacted by a third-party incident is extremely high. When a vendor is compromised and ransomware spreads laterally, the question quickly becomes how fast companies can restore operations. An organization’s ability to recover systems quickly may determine whether it faces a contained disruption or a prolonged operational shutdown that erodes customer trust and shareholder confidence.
But recovery alone is not enough. Backups cannot safeguard a business if a compromised vendor reintroduces malware into newly restored systems, creating a cycle of disruption that is difficult to break. Organizations must focus not only on restoring data, but also on reducing the likelihood of third-party compromises in the first place. True resilience requires companies to be both preventive and fast acting by continuously monitoring their ecosystem for third party risk while maintaining strong backup practices that minimize data loss and accelerate recovery.
++
Larry O’Connor, Founder and CEO, Other World Computing (OWC)
World Backup Day is a good reminder that hoping your data is safe and actually protecting it are two very different things. If everything lives in one place, whether that’s a laptop or a single cloud account, you’re one mistake or outage away from losing something that might have taken years to create. The smartest approach we see people taking today is a mix of on-prem storage, cloud, and reliable backups so their work exists in more than one place. When your storage is fast and dependable, backing up just becomes part of the workflow instead of something you keep meaning to get around to.
++
Don Boxley, CEO and Co-Founder, DH2i
World Backup Day comes around every year for a reason. We all need an occasional reminder of the proactive actions we should be taking to protect the sensitive data our organizations are responsible for. Unfortunately, it’s still easy for this critical task to get pushed to the bottom of the list. Most organizations don’t think much about backups until the day something breaks. A drive fails, a server crashes, someone accidentally deletes the wrong thing. Suddenly, everyone realizes those files weren’t just data sitting somewhere. They were customer records, financial systems, months of work, sometimes years of it. When that disappears, it’s not just an IT problem. The business feels it immediately.
What’s changed over the last few years is just how dependent companies have become on their data being available all the time. Databases are running across Windows, Linux, containers, and multiple clouds, and everything is moving faster than it used to. Backups are still incredibly important… but they can’t be the whole strategy anymore. Businesses need systems that keep running even when something fails. And they need to know quickly when something is starting to go wrong. At the end of the day… backup is really about peace of mind. It’s about knowing that when something inevitably goes sideways, you’re not starting from zero trying to rebuild your business from scratch.
++
Richard Copeland, CEO, Leaseweb USA
World Backup Day provides a great reminder that protecting data isn’t just about copying files, and moving them somewhere else. It’s really about knowing exactly where your data lives and who has true control of it. Today’s backup strategies must respect data sovereignty, while adhering to the fundamentals that have always worked, like 3-2-1. That is, keep at least 3 copies of your data, on at least 2 unique storage devices, and store at least one copy offsite. Just as important is working with a provider that actually knows your environment and treats your data like it matters. When something goes wrong, you don’t want to feel like your business is one small account lost in a massive system. You want real expertise, real people, and a partner who understands that your data is the heartbeat of your organization.
++
Dawn-Marie Vaughan, Global Offering Lead Cybersecurity at DXC Technology
In 2026, ransomware has fundamentally re-indexed the value of a backup. What was once a simple insurance policy against hardware failure or accidental deletion is now the critical last line of defense in a high-stakes cyberwar.
Many organizations still fall into the trap of assuming that simply ‘having’ a backup is enough. But in today’s hybrid, distributed environments—stretching from on-premises stacks to diverse cloud platforms—a backup that isn’t isolated by design and regularly pressure-tested is essentially a liability. If it isn’t recoverable at the speed the business requires, it might as well not exist.
At DXC, we believe true cyber resilience is no longer an operational ‘add-on’ task. It must be built into the very architecture of modern infrastructure. This means shifting the focus from ‘storage’ to ‘recovery velocity’—protecting immutable points, isolating recovery environments, and ensuring that when (not if) an attack occurs, the path back to ‘green’ is already paved.
As we mark World Backup Day, the most important question for any leader is no longer ‘Are we backed up?’ but rather: ‘If our critical systems vanished tomorrow, how many hours until we are back in business?’
++
Crystal Morin, Senior Cybersecurity Strategist at Sysdig
With more than 1.7 million ransomware attacks happening every day, organizational security ultimately comes down to how well you can recover. When all else fails, you fall to the level of your backups.
However, recovery doesn’t begin in the middle of a breach. It starts long before. Your ability to bounce back is dependent on how well you’ve prepared to recover data and restore operations. Meanwhile, today’s ransomware landscape continues to expand, with attacks rising 53% year over year. And with 3.3 billion stolen credentials in circulation, threat actors often just need to log in. It’s a harsh reality.
When vulnerability exploitation and cloud attacks can unfold in minutes, a tested and immutable backup is the difference between a temporary disruption and a lasting catastrophe.
++
Gal Naor, CEO, StorONE
On World Backup Day last year, I said that all-flash backup architectures were an expensive and unnecessary investment for most organizations. That perspective was not based on market timing, it was based on a fundamental principle, not all data has the same value, and it should not be treated as if it does. Today, the market has caught up. Rising flash prices and supply constraints did not create a new problem, they exposed an existing one. For years, the industry optimized for peak performance at any cost. That model is now breaking under the weight of data growth.
Backup is simply where this becomes most visible. But the reality is much broader. This is not a backup problem, it is a data architecture problem. Organizations can no longer afford to build infrastructure based on the assumption that all data belongs on the fastest tier.
The shift ahead is clear. Storage must become dynamic, not static. Systems must continuously adapt data placement based on real usage, not predefined policies. Intelligent auto-tiering is not a feature, it is the foundation of a new architecture where performance and cost are no longer in conflict.
On this World Backup Day, the question is no longer how fast your backups are. The question is whether your architecture reflects how data is actually used. The organizations that understand this will not just reduce costs; they will redefine how modern data infrastructure is built.
++
Ted Oade, Director of Product Marketing, Spectra Logic
World Backup Day was originally inspired by an unfortunate data loss incident and is often framed as a reminder to back up data in case of accidental loss, hardware failures, human error, or cyberattacks. But in the current climate of explosive data growth, the proliferation of AI, and increasingly sophisticated cybercriminals, the conversation is deepening. Organizations are generating unprecedented volumes of data, and much of it is becoming strategically valuable over time. Backup is no longer just about enabling recovery—it is about ensuring that critical information assets remain trustworthy, unaltered, accessible, and preserved in perpetuity.
AI initiatives are rapidly elevating the importance of preserved data. Modern AI models depend on vast historical datasets, many of which were originally collected for entirely different purposes. Data that appears inactive today may become essential tomorrow for training models, validating results, and supporting new discoveries. At the same time, ransomware threats continue to grow, and compliance mandates require organizations to retain data for extended periods.
In response, organizations are architecting resilience across the entire data lifecycle. This includes immutable offline copies, geographic separation, and preservation architectures designed for durability at massive scale. It also reflects the reality that most data becomes inactive over time and can be stored more efficiently on secondary or tertiary tiers rather than costly high-performance infrastructure.
Today, as we recognize World Backup Day 2026, the importance of preserving data is expanding beyond recovery to encompass long-term value. The datasets organizations protect today will shape the insights, innovations, and decisions of tomorrow—making their integrity, accessibility, and longevity a strategic imperative.
++
Ken Barth, CEO, Catalogic Software
World Backup Day is a timely reminder this year. The infrastructure we rely on: cloud platforms, data centers, networks, can be disrupted in ways that are hard to predict and impossible to ignore. Backup is table stakes. What actually matters is recoverability – knowing that when something goes wrong, you can get back up. At Catalogic, that’s the design principle behind everything we build. It’s also why we give organizations the flexibility to store data where it’s safest for them on-premises, hybrid, public cloud, or tape. In today’s unpredictable world, optionality is a requirement.
++
Oded Nagel, CEO, CTERA
In today’s digital economy, trust is the ultimate currency. For too long, leadership has viewed data backup as a technical task delegated to the IT department, perhaps a checkbox on a compliance form. That era is definitively over. Ransomware has elevated the conversation around data strategy into a boardroom-level imperative, transforming it from an operational chore into a crucial pillar of corporate governance. A data breach today isn’t just an IT disruption. It can be a catastrophic failure that shatters a customer’s confidence, erodes shareholder value virtually overnight, and can irrevocably damage a brand’s reputation. This is why modern data protection, built on principles of immutability and guaranteed recovery, is not just a feature but is a fundamental component of business continuity itself. It is the ultimate digital insurance policy, not just for your files, but for your entire enterprise. On World Backup Day, my message to fellow leaders is simple: Don’t just ask your teams if they are backing up. Ask them how they are guaranteeing the swift, complete restoration of your business. The future of your company depends on their answer.
++
Carolyn Duby, Field CTO and Cyber Security GTM Lead, Cloudera
Backup and security are a matter of AI economics
IDC’s Global DataSphere Forecast estimates that global data volume will surge to 393.9 zettabytes by 2028, placing growing pressure on business continuity, data protection, governance, and the cost of sustaining them. This turns resilience into an AI economics issue, where every additional dataset retained and protected compounds spend across storage, backup operations, compliance overhead, and downstream AI quality and remediation. As World Backup Day and World Cloud Security Day approach, the real question is not whether organizations are backing up more data or adding more cloud security controls, but whether those investments are improving resilience in a way that is economically sustainable. Backup cannot be treated as an endlessly expanding insurance policy; without clear retention policies and governance, resilience programs become financially draining and operationally difficult to justify. The priority should be protecting the right data, at the right level, for the right recovery outcomes.
Governance is what makes resilience targeted, not indiscriminate
Effective data resilience begins with understanding the data estate – what exists, how it is used, and what recovery expectations apply. Without that visibility, everything is treated as equally critical, leading to oversized backup environments and unclear priorities. Governance provides the structure to classify data by business impact so protection can be tiered accordingly, aligning decisions with regulatory, contractual, operational, and reputational risks. When governance is unclear, organizations default to keeping data “just in case,” creating large volumes of low-value information. Research from the Veritas Global Databerg Report suggests that up to 85 percent of stored data may be dark or redundant, obsolete, or trivial (ROT). This drives up storage and recovery costs while increasing complexity. In AI-driven environments, poorly governed data also degrades analytics and model reliability, creating a cycle where organizations pay twice, once to store and protect bad data, and again to fix the problems it causes downstream.
Recovery testing proves governance decisions work in production, and reducing data sprawl prevents resilience costs from compounding
Governance strategies only deliver value if they produce reliable recovery outcomes. Regular restore and disaster recovery testing validates whether protection tiers align with business priorities, often revealing gaps such as non-essential data being restored or critical systems lacking sufficient protection. These exercises also expose dependencies across data pipelines, enabling more precise recovery without restoring everything. At the same time, reducing data sprawl is essential, particularly in hybrid and multi-cloud environments where uncontrolled replication increases cost and complexity. Data movement into SaaS platforms and external services should be governed deliberately, and consistency across environments is key to avoiding duplication and fragmentation. Open standards can help reduce unnecessary copies and improve interoperability. Ultimately, World Backup Day and World Cloud Security Day should reinforce that resilience is not about accumulating more data or controls, but about making intentional, governed decisions. This approach optimizes backup spend, shortens recovery times, and improves AI reliability, ensuring organizations are not paying to protect data they neither understand nor need.
++
Craig Birch, Principal Technologist, Cayosoft
World Backup Day is a reminder that backups are not just copies of data. In hybrid identity environments, they are full snapshots of how an organization operates. Users, privileges, policies, and trust relationships are all captured. That makes identity integrity the deciding factor in whether recovery actually succeeds after an incident.
Leading organizations are moving past restore-everything approaches. They validate identity before recovery, test recovery paths regularly, and use staged restoration models that bring core services online first. This makes it possible to recover clean domain services, reestablish cloud and on prem dependencies, and restore business systems in a controlled and predictable way.
When backups are paired with intelligent validation and proven recovery paths, they become more than storage. They enable faster, safer recovery of the identity layer that everything depends on. That is when backups become an active pillar of cyber resilience.
++
Cynthia Overby, Director, GTM Strategic Security Solutions, Rocket Software
World Backup Day is a timely reminder that recovery readiness has become a defining measure of an organization’s resilience. As ransomware threats continue to evolve, 69% of IT leaders cite data privacy and security as their biggest concern when adopting AI, underscoring how central backup data has become the broader security equation.
Sensitive data does not lose its value or its risk once it moves into a recovery environment. Without the right controls in place, backup systems can introduce unnecessary exposure, expand privileged access, and complicate response efforts when speed and precision matter most.
True resilience goes beyond simply maintaining a backup. It requires a strategy that ensures data is secure, governed, and readily recoverable across hybrid environments, from mainframe to cloud. Consistent controls, strong access discipline, encryption, and well-defined recovery processes are essential to limiting risk while keeping critical data available.
For organizations running mission-critical infrastructure, backup is no longer just about restoring systems after disruption. It plays a central role in maintaining continuity, supporting security objectives, and ensuring the business can recover quickly and operate with confidence in the face of constant threats.
++
Elyse Gunn, CISO at Nasuni
World Backup Day 2026 is a timely reminder that backup is not an isolated disaster recovery measure but rather a core part of practical cybersecurity resilience. Moreso, business continuity is entwined with business prosperity – every minute you are not operational is a minute of revenue lost. Your backup strategy must consider these realities. Backup should be automatic, and business continuity and disaster recovery should happen in seconds, not days.
As AI continues to accelerate the speed and sophistication of cyberattacks, organizations need to continuously adapt to protect and stay ahead of expanding threat landscapes. Recent data highlights that 72% of organizations are seeing cyber risk increase, and 47% identifying adversarial generative AI as their primary concern. It’s more vital than ever that backup strategies do more than restore operations after an incident. They need to help protect the business from complex threats and support the overall security posture of the enterprise.
This principle is even more important, given AI is only as reliable as the data it leverages. Protecting data and its integrity and providing timely, clean dataset restorations are essential components of AI performance and security success. By treating backup as an ongoing organizational priority rather than a one-time initiative, companies can build stronger resilience as both structured and unstructured data continue to grow as a foundation of modern technology.
++
Jason Lohrey at Arcitecta
Why Backup Alone Can’t Protect Data at Petabyte Scale
Conventional backup strategies were designed for a world of megabytes and gigabytes, not today’s environments where enterprises routinely manage tens or even hundreds of petabytes and billions of files. Traditional backup assumes data grows slowly and that organizations can tolerate hours or even days before recovery begins. But for modern data-driven businesses, those assumptions are no longer realistic.
On a massive scale, the idea of simply backing up everything becomes unrealistic: traditional systems cannot move hundreds of terabytes per hour or scan billions of files fast enough to keep up with modern data growth.
As data volumes explode across hybrid infrastructures, from on-prem storage and cloud environments to distributed teams, the challenge isn’t simply making copies of data. Organizations must be able to recover the right data instantly when something goes wrong, whether due to ransomware, accidental deletion, or system failure.
To do this, data protection must become an integral part of the data platform itself. Organizations need to move beyond traditional backup strategies toward continuous data availability, where every change to data is recorded in real time and where data can be instantly restored to any point in time. By embedding protection directly into the data path, every file change — such as writes, deletions, or renames — can be captured as it happens, ensuring an organization can always recover its data quickly and effectively.
++
Shankar Gomathi, SVP, Software Engineering, OpenText
Why a CMDB is ideal for backup and recovery
Although often viewed primarily as an IT operations tool, a CMDB is a powerful asset for backup and recovery. For IT Ops, a CMDB provides a single, accurate record of systems, configurations, and dependencies — functionality that can be easily leveraged for building comprehensive backup and recovery strategies and quickly executing when the need arises. Another compelling reason for using a CMDB is that it makes sense financially, as it likely already exists within an organization’s IT architecture.
Strategy and planning
On the strategic front, a CMDB’s comprehensive content catalog can be a valuable resource for developing backup and recovery strategies. One of the driving forces is a CMDB’s impact analysis functionality, which strengthens backup planning by identifying high impact components whose failure would cascade across dependent systems. It will provide a clear picture during planning systems and applications necessary to restore normal operations and provide a checklist for rehearsals and plan activation.
Recovery operations
The impact analysis insight provided by a CMDB is ideal during restoration efforts. By offering detailed attributes and relationships for every configuration item, a CMDB allows organizations to intelligently prioritize efforts. Teams are armed with knowledge about which business-critical systems should be restored first and the information needed to avoid inadvertent disruptions to systems that depend on those still being recovered.
++
John Anthony Smith, Founder and Chief Security Officer of Fenix24
On World Backup Day, I thought it pertinent to evaluate the importance of backups to ransomware recovery—and other mass destruction events like that seen at Stryker recently.
According to Coalition [a cyber liability carrier], 58% of organizations discover a partial or complete failure of backup and recovery capabilities during significant breach. According to our own statistics, we know that 84% of Organizations we meet in breach for the first time and 86% of Organizations we meet in assessment for the first time, technically, do not have a single survivable copy of backups. To make matters worse of the 16% that do have a survivable copy, during breach, only half of them will have a timely recovery [due to technical limitations of the survivable copy]. We also know from our assessments of cyber resiliency that a whopping 76% of Organizations are knowingly not backing up all their known critical data, and more than 90% of Organizations will not meet their stated RPO and RTO objectives. Recovery is commonly complicated by the lack of clear, continuously updated data discovery, dependency mapping, and correlation of that discovered data and associated dependencies to recovery protection strategies.
It is statistically unlikely for an Organization to get the orchestration of recovery right. To complicate matters, Organizations commonly attempt to “go it alone” or take bad advice on how to recover; thus, exacerbating business interruption expenses—the single biggest expense during breach. The breach prevention industry is a $200B industry, and the Recovery industry is a roughly $20B one. Largely all companies are investing significantly in preventing breach while largely ignoring recovery. Backups couple with the limiting of the destructive blast radiuses surrounding an Organization’s data are the single most important security controls—and organizations really should prioritize this.
Prioritizing recovery, however, does not look like what you might think. This doesn’t mean racing to the nearest backup technology vendor and choosing a new backup product. It also doesn’t mean purchasing “immutable” backups. We commonly see that organizations that believed themselves to have immutable backups actually didn’t. Assurance of recovery is a careful, continuous orchestration of backup products, policies, processes, and people all informed, and hardened, to what threat actors are able and willing to do. Essentially, cyber resiliency is so much more than just purchasing a product and turning on some immutability features. We know that for recovery to be predictable—you need breach informed expert advice that knows how to architect, manage, administer, monitor, harden, test, assure, and measure recovery continuously.
Call to action:
- Measure, leveraging breach informed technical realities, your backup and recovery survival—will you have a recovery?
- Understand and continuously test, harden, administer, manage, and architect, leveraging a partner that knows breach, your recovery capabilities—know how long it will take to recover.
- Continuously discover and monitor data and dependencies and correlate this to protection and rigorous testing—have confidence that all data is safe and recoverable at the RPO and RTO required.
- Reduce the blast radius of destructive acts by complicating IT access to systems—limit TA damage.
- Know your partners for breach, and have the assurance that they are breach informed, experienced professionals ready to recover at a moment’s notice—Have partners that know you, your systems, and your data intimately.
- Continuously harden, informed by breach, your resistance controls leveraged by IT—complicate IT access to systems to further limit TA progression.
++
Mark Christie, Senior Director, Technical Services, StorMagic
One shift we’re seeing in backup is how recovery expectations are changing as environments become more distributed. In the past, backup strategies were built around centralized systems and assumed that data could be restored back into the same environment. That assumption doesn’t always hold anymore.
For organizations running multiple sites or operating in environments with limited connectivity, the question is no longer just where data is backed up, but how quickly systems can be brought back online locally. If recovery depends on pulling large volumes of data from a central location, that can introduce delays at exactly the moment uptime matters most.
As a result, more teams are looking at backup and recovery together rather than separate processes. That includes keeping recent copies of data closer to where it’s used, validating recovery workflows across sites, and making sure critical applications can continue running even if the primary environment is unavailable.
World Backup Day is a good reminder that backup strategies need to reflect how systems are actually deployed. It’s not just about having a copy of the data. It’s about whether the business can keep operating when something goes wrong.
++
Emilio Escobar, CISO of Datadog
World Backup Day gives us an opportunity to step back from our work and understand some of the unseen ways technology works for us. Data protection measures are so important, but only valuable if you can rely on them during a disruption. During unexpected downtime, data loss can hinge on whether your recovery workflows are healthy, visible, and treated as a critical production system.
One of the easiest ways teams get blindsided by their technology is when their backups fail. This happens more often than expected due to complications such as quota limits, disk constraints, and connectivity issues. Recognizing that job health can be compromised by even the smallest issues is important because the longer it is since your last successful run, the more data you risk losing if you need to recover.
Recovery readiness should also be measurable. Recency point objectives (RPO) are the most practical way to quantify acceptable data loss based on time since the last good backup, and tracking RPO over time can help teams adjust replication frequency to meet targets. If done well, this can support operational resiliency and compliance expectations, especially in regulated environments.
Today, we should look at how our data protection systems are helping our everyday workflow and make sure we ask the essential questions to align on a single goal: making backup health and recovery readiness visible day to day.
++
Kurt Markley, Managing Director at Apricorn
World Backup Day is a useful reminder to have a backup plan, but backups alone aren’t enough. For that plan to be effective, organizations also need a recovery plan, and that’s where many strategies fall short. Too often, having multiple copies of data is treated as the end goal, without considering how those copies are accessed, stored, and ultimately restored. The reality is that backups are now part of the attack surface. If they’re always connected, poorly segmented, or inconsistently managed across endpoints, they can be compromised just as easily as primary systems, leaving organizations with data they can’t reliably recover.
What’s changing is where risk is accumulating. Data is no longer centralized. It’s spread across remote devices, transient work environments, and portable storage that often sits outside of formal IT oversight. That creates gaps not just in protection, but in recoverability. Without clear policies around how data moves, where it’s stored, and who is responsible for securing it at each stage, organizations may believe they have a backup plan in place, but lack a recovery plan that will actually work when needed.
This is why backup strategies need to evolve from a static checklist to an operational discipline built around recovery. It’s not just about how many copies exist, but whether at least one is isolated from day-to-day network exposure and whether recovery has been validated under realistic conditions. World Backup Day is a valuable checkpoint, but the organizations that pair backup planning with disciplined, tested recovery planning will be the ones that can restore operations with confidence when something goes wrong.
++
Paul Speciale, Chief Technology Evangelist and CMO, Scality
World Backup Day is no longer just a reminder to create copies of data and continually test and refine your recovery procedures. It is a call to rethink how resilience is engineered into the storage layer itself. As ransomware operators increasingly target backup infrastructure first, the assumption that recovery points will be available when needed is no longer safe. If attackers can delete or encrypt backups by exploiting shared administrative domains, organizations lose their ability to recover without paying a ransom. This is why modern backup strategies must extend beyond traditional recovery models and instead focus on architectural resilience by embedding immutability, high availability, and durability directly into storage platforms. This often includes leveraging object storage architectures that support immutability controls and policy-based data protection, helping ensure backup data cannot be altered or deleted once written. Approaches such as the 3-2-1-1-0 model, combined with enforced immutability, ensure that data remains protected, verified, and recoverable even in the face of sophisticated attacks.
At the same time, the concept of air-gapped backup storage has re-emerged as a foundational control in cyber resilience. Whether implemented through physical separation or logical isolation, air-gapped architectures are designed to ensure that even a full administrative compromise spanning identity systems, hypervisors, and backup management tools does not extend to recovery data. By separating control planes, restricting access, and enforcing retention policies at the storage level, organizations can reduce correlated failure risk and preserve critical decision-making leverage during an incident. This aligns closely with zero-trust principles, where systems are designed with the assumption that breaches will occur, and resilience depends on limiting blast radius rather than preventing every intrusion.
The urgency of this shift is further accelerated by the growth of AI, analytics, and other data-intensive workloads, which are driving unprecedented data volumes and complexity. Scalable object storage is becoming central to managing backup, recovery, and long-term retention at scale, but only when paired with architectures that prioritize isolation, verification, and performance under pressure. On World Backup Day, the priority is clear. Organizations must move beyond legacy backup thinking and design storage environments that can withstand real-world failure scenarios. Backup is no longer an operational afterthought. It is a strategic capability that underpins business continuity, regulatory compliance, and the ability to recover with confidence when it matters most.
++
Rafael Narazzi, CEO & Co-Founder of Centrii
World Backup Day used to be about restoring files after an IT failure. In today’s energy environment, that mindset is dangerously outdated. As power generation becomes decentralized — across solar farms, microgrids, and distributed assets — we’re not just backing up data, we’re talking about maintaining continuity of physical operations. If an attacker disrupts an OT system, you’re not recovering documents — you’re losing megawatt-hours, breaching contracts, and triggering real financial and operational consequences in minutes.
The problem is that we’re building a massively distributed energy grid with security and resilience models designed for a centralized world. Every new connected asset expands the attack surface, yet very few organizations are quantifying what recovery actually looks like in this environment. Backup strategies need to evolve beyond data replication to include operational recovery — how quickly systems can be restored, how integrity is verified, and how to prevent compromised systems from coming back online. Without that shift, ‘backup’ becomes a false sense of security rather than a true resilience strategy.
++
Chris Bonavita, Vice President of Strategy and Technology Adoption at GTT
As enterprises adopt AI, their business data expands to include training datasets, model artifacts, and complex data pipelines. Those assets are often distributed across multiple cloud platforms and global infrastructure. Losing or corrupting them can disrupt critical services just as much as losing application data. World Backup Day highlights the growing need to think about resilience in terms of entire AI ecosystems, not just individual systems or storage environments.
++
Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint
World Backup Day reminds us that backup has become significantly more complex as environments span AWS, Azure, Google Cloud, SaaS platforms, and on prem systems. Tool sprawl and rising cloud costs are pushing organizations to rethink point solutions that only protect individual platforms. Native tools often lack the visibility and consistency required to meet recovery objectives across distributed environments, leaving gaps in resilience when incidents occur. A modern infrastructure backup strategy must address fragmentation by delivering unified protection across multi cloud workloads and critical applications.
As infrastructure architectures evolve, backup is no longer just a recovery mechanism, but rather a foundational component of operational resilience and control. Organizations are increasingly looking for platform-based approaches that integrate backup, recovery, and governance across cloud infrastructure, identity, and emerging application architectures. This becomes even more critical as automation and agent-driven technologies introduce new operational risks.
World Backup Day is an opportunity to move beyond legacy backup models and focus on infrastructure resilience that scales with complexity, supports faster recovery, and reduces risk across the entire cloud estate.
++
Gary Orenstein, Chief Customer Officer at Bitwarden
World Backup Day is a reminder that protecting data is only half the equation. Backups are ineffective without secure access to the credentials that secure and unlock that data. When access is lost or compromised, recovery efforts can stall, leaving individuals and organizations unable to restore systems or accounts even when backup data is intact.
This is especially critical in zero-knowledge environments, where providers cannot recover vault data without user-held credentials. Credential protection should be treated as part of any backup strategy, ensuring vault access and authentication data are secured and recoverable through validated access methods and recovery mechanisms alongside the data they protect.
++
Brad Warbiany, Director of Planning & Strategy at WD
World Backup Day is a useful reminder, but for enterprise and data center operators, the conversation has moved well beyond backup. The real focus today is data resilience: the ability to ensure that critical data remains durable, accessible and protected against an increasingly complex threat landscape.
AI is fundamentally changing the nature of enterprise data. Organizations are no longer just storing data. They are managing a continuously expanding asset base of inference logs, model checkpoints, synthetic datasets and telemetry streams that compound in volume with every cycle of refinement. The value of any given dataset may not be fully understood until years after it was created.
This is where storage architecture becomes a strategic decision. Ransomware resilience, data immutability and air-gapped architectures are no longer optional considerations for diligent enterprise infrastructure teams. They are foundational requirements. At the same time, the economics of protecting data at scale demand intelligent tiering. Storing everything on high-performance flash is financially unsustainable. High-capacity HDDs remain the backbone of cost-efficient, scalable data resilience strategies, and can provide the density and throughput economics that allow enterprises to retain data long enough to realize its full value.
World Backup Day is an opportunity to pressure-test those strategies. Are retention policies aligned to AI workload realities? Are immutability and ransomware protection built into the architecture, not bolted on? Is the cost per terabyte of long-term retention sustainable at the scale AI demands?
The enterprises that answer those questions with confidence today will be the ones best positioned to turn their data into a competitive advantage tomorrow.
++
Justin Kappers, CIO at Infoblox
World Backup Day is a reminder that backups alone are not enough in the face of evolving cyber threats. The rise of AI-driven attacks demands advanced detection and response capabilities to ensure backup systems remain secure. Organizations must prioritize not just creating backups but also fortifying them against these increasingly sophisticated attacks.
++
Stephen Manley, CTO at Druva
The 3-2-1 backup rule is still valid. Three copies, two media types, one offsite. Follow it. But if you think following it means you’re protected, that’s where the risk begins.
The threat landscape has shifted in three important ways. Attackers are using AI to defeat defenses at machine speed, which makes recovery a front-line capability, not an afterthought. Meanwhile, your own AI is creating exposure you can’t see because it is indexing content and generating copies across systems faster than any administrator can track. And your AI deployments themselves are now critical infrastructure; you have models, pipelines, and agents that need to be protected, recoverable, and compliant.
None of these threats can be addressed by backup volume or velocity alone. They require context.
Context means three things in practice: application intelligence, identity intelligence, and data intelligence. With centralized metadata, you gain visibility into what exists, who touches it, and how it behaves, which turns data and identity sprawl from a liability into a strategic asset. With the appropriate centralized metadata, you can also use AI to detect anomalies, flag unusual access, and build recovery strategies proportional to actual risk.
3-2-1 tells you how to store your data. Context tells you what’s worth protecting and how to get it back.
Modern resilience isn’t a checklist. It’s a continuous practice of understanding your applications, identities, and data, so when something goes wrong, you know exactly what you’re recovering and whether you can trust it.
++
Nabil Hannan, Field CISO, NetSPI
World Backup Day has traditionally highlighted recovery preparation, ensuring that organizations can restore data after cyberattacks, IT outages, or plain human error. While this still matters, in today’s AI era, simple backups are not enough to achieve business resilience. In relation to AI, what modern organizations face today is less of a new attack surface, but more of a new cocktail of familiar risks in different combinations and permutations, where exposed API keys, weak authentication and authorization, and overly permissive permissions are now embedded in autonomous systems that move faster and expand the blast radius significantly. The risk is that these systems can modify, move, or corrupt data without clear visibility, meaning organizations may not realize last-defense backups have been altered until it’s too late. To be resilient today, organizations must go beyond recovery and prove not only that backups exist, but that they remain trustworthy, and that systems cannot be manipulated to misbehave or cascade failures before security teams notice.
++
Andy Stone, CTO, Americas, Everpure (formally Pure Storage)
World Backup Day is a great reminder that backing up is just the beginning. Today, the real focus is recovery and how quickly organizations can get critical applications online after disruption, whether it’s a disaster or a cyber attack. Success is not just about restoring everything but about restoring what matters the most and fast.
In the AI era, data is the lifeblood of every business. AI can handle scale and repeatable patterns, but skilled IT professionals remain responsible for outcomes. The right balance of automation and human oversight ensures resilience and agility. World Backup Day isn’t just about backups, it’s about being ready to recover quickly and keep the business running when disruption hits.
++
Munu Gandhi, President of IT Solutions at Xerox
World Backup Day is a reminder that resilience isn’t something organizations buy — it’s something they design and operate every day. As AI, automation, and digital workflows become embedded across enterprises, protecting and recovering data quickly has never been more critical. But backup alone isn’t enough. True resilience requires a modern strategy that integrates backup, security, and infrastructure across endpoints, data centers, and cloud environments—and the discipline to test recovery continuously. Increasingly, organizations are shifting from asking “Do we have backups?” to the more important question: “How fast can we restore the business if something goes wrong?”
++
Stefan Voss, VP of Product Management, N-able
World Backup Day is a reminder that business resilience isn’t just about stopping attacks, it’s about how quickly and confidently you can recover when one inevitably gets through. Our latest SOC analysis showed that nearly half of attacks never touch the endpoint, instead unfolding across cloud, network, and identity layers. At the same time, security teams are contending with more than 900,000 alerts a year, far beyond what humans can realistically manage alone. We’re also seeing a growing shift in how data loss occurs, with backups themselves increasingly targeted and data compromised through access control and identity-based attacks, even in the absence of a traditional endpoint incident.
That’s why organizations must treat data protection as a core pillar of a layered business resilience strategy, supported by automation, visibility, and strong safeguards across the stack. Data protection must protect cloud and SaaS data as rigorously as traditional endpoints, with immutable copies and multiple layers of anomaly detection adding a critical line of defense when prevention fails. Done right, this positions teams to contain incidents faster and restore operations with confidence.
++
Skip Levens, Quantum‘s Product Leader and AI Strategist, the LTO Program
World Backup Day is a great way to remind organizations of the importance of protecting their data – protecting it is integral to every organization’s mission – and like any important endeavor, it needs a great plan. In 2026, that reminder has never been more urgent, or more complicated.
Every workflow in every industry is increasingly AI amplified, and these workflows and models generate and need to be fed enormous quantities of data: training datasets, model snapshots, prompt logs, audit trails, massive telemetry trails that scale in petabytes. In fact, the notion of ‘data gravity’ is becoming a real engineering problem. Only well-designed, resilient and tiered storage architectures can ingest, move, and protect data at this scale and move it from ‘working’ to ‘standby’ repositories to match the workflows of the day.
For years, the default answer was spinning disk for everything. Need more capacity? Add more drives anytime you wish. But 2026 is exposing how fragile that assumption was. HDD manufacturers have told investors their production capacity is fully allocated through the rest of this year. Seagate and Western Digital are both emphasizing allocation discipline over volume expansion. When hyperscalers lock up supply, everyone else faces longer lead times, higher prices, and procurement uncertainty. Relying on a single storage tier seemed low-risk – but now it’s a critical gap.
Meanwhile, tape has been continuously innovating through all of this. LTO-10 delivers up to 40 terabytes of native storage per media cartridge. Retrieval performance has improved to the point where tape functions as an active tier in the data pipeline, not just a cold archive you hope you never need. If you think of tape as ‘what I send to the salt mine and never hope to need’, you’re missing out on this powerful storage capability that delivers resiliency and protection that is not possible on spinning hard drives or flash. For AI workloads that don’t require sub-second latency, tape lets organizations scale their data, maintain resilience against supply disruptions, and keep long-term costs under control.
On World Backup Day, cheers to you if you have a solid plan to keep your data ‘backed up.’ But the next question I hope you are ready for is whether your backup and protection architecture can handle what’s coming. Tape is a strategic necessity in a world where you need a storage tier that lets you keep scaling – without waiting for a disk allocation that may not come.
##






