Opens in a new tab
vmblog logo 2024 wht (updated)

The RAM Shortage Is Now a Cyber Resilience Crisis — And Most Enterprises Don’t See It Coming – VMblog QA

Share: 

David Marshall | Published: April 10, 2026
interview-assured-dp-stacy-hayes

Everyone in enterprise IT is aware that memory prices have surged and supply chains are strained. But according to Stacy Hayes, Chief Strategy Officer at Assured Data Protection, the real story runs far deeper than a procurement headache. When hardware quotes expire within hours, prices jump 70 to 120 percent in weeks, and hyperscalers pre-allocate capacity months in advance, infrastructure stops being a purchasing problem and becomes a risk management crisis — one that strikes at the very foundation of how organizations protect and recover their data.

In this candid VMblog Q&A, Hayes connects dots that much of the industry has been slow to join: that backup and disaster recovery environments depend on the same constrained compute and memory resources being consumed by AI-driven demand, that recovery SLAs built on infrastructure that may never arrive on schedule are promises waiting to break, and that ransomware groups don’t need to understand supply chain economics to exploit slower, less-tested recovery windows. For CIOs still wedded to CapEx models and periodic procurement cycles, his message is direct — the assumptions that model was built on no longer hold.

++

VMblog: Stacy, please set the context for our readers. Everyone’s talking about the RAM shortage as a supply chain headache or a cost problem. But you’re seeing something much more serious playing out at the enterprise level. What’s really going on here that the industry isn’t talking about loudly enough?

Stacy Hayes: This issue goes beyond cost and signals a loss of certainty in how infrastructure is sourced and delivered. For years, enterprise IT has operated on the assumption that infrastructure might be expensive, but it was ultimately available with procurement being straightforward. That’s no longer true. We’re now seeing a market where prices are rising week-on-week, quotes are only valid for hours, and availability is uncertain or pre-allocated months in advance.

This fundamentally changes infrastructure from a procurement exercise into a risk management problem. Once infrastructure becomes unpredictable, everything built on top of it, including backup, disaster recovery, and cyber resilience, becomes harder to guarantee.

VMblog: When we talk about hardware costs jumping 70 to 120 percent in a matter of weeks, and hyperscalers pre-allocating massive volumes of memory capacity, what does that actually look like on the ground for the businesses Assured Data Protection is working with? Are we talking about delays, cancellations, or something worse (whatever that could be)?

Hayes: On the ground, there’s evidence of confusion, delays, and projects stalling out. We are seeing situations where a quote gets approved, and by the time it’s ready to move forward, the price has already changed, or the hardware is no longer available when expected. Hardware that was budgeted for suddenly costs significantly more or isn’t available within the expected timeframe. In some cases, customers are given delivery timelines that simply don’t materialize.

There’s also a degree of denial. Many enterprises only buy infrastructure periodically, so they assume the market still behaves normally. When they run into lead times or pricing volatility, it comes as a shock.

But  perhaps the most concerning part is a  growing gap between what organizations think they can deploy and what they can deliver.

VMblog: One thing that will surprise a lot of our readers is how you’re connecting the RAM shortage directly to gaps in cyber resilience and data recovery. Walk us through the link between those. How does a memory supply crunch translate into a company potentially not being able to recover from a ransomware attack, or what am I missing?

Hayes: Recovery isn’t just about having data. It’s also about having the infrastructure to restore it. Backup and disaster recovery environments rely on compute, memory, and storage capacity to bring systems back online quickly. If hardware upgrades are delayed, or capacity can’t scale in line with production environments, recovery performance degrades.

In practical terms, that means slower recovery times, reduced ability to test recovery plans, and in some cases, recovery environments that are no longer fit for purpose.

The risk isn’t theoretical. If you can’t access the infrastructure you need, you may have the backup, but not the ability to recover at the required speed.

VMblog: Ransomware actors are nothing if not opportunistic. Is there concern in your world that threat groups are already aware of these infrastructure constraints, and that recovery windows and resilience gaps created by the shortage could be factored into how and when attacks are launched?

Hayes: Ransomware groups are highly adaptive and constantly on the lookout for vulnerabilities.If recovery times are getting longer because infrastructure isn’t available, or if organizations are delaying upgrades and running on aging systems, that creates opportunity. Attackers don’t need to understand the RAM market dynamics in detail. They just need to recognize when recovery is slower, less tested, or less reliable.

So, in that sense, infrastructure constraints don’t just increase operational risk. They make organizations more attractive targets.

VMblog: Let’s talk about the CapEx model specifically, because a lot of enterprises are still deeply wedded to owning their infrastructure. How is the RAM shortage exposing the vulnerabilities of that approach? And do you think this is the moment that finally forces a genuine rethink of how organizations fund and structure their resilience strategy?

Hayes: The CapEx model depends on predictability across pricing, supply, and deployment timelines, which are issues right now. Organizations are being asked to commit significant upfront capital without certainty on final cost or delivery. In some cases, they’re paying more than expected for infrastructure that arrives later than planned, and in some cases, not at all. This exposes a structural weakness in the ownership model. Organizations are taking on procurement, supply chain, and pricing risk, all at once.

The focus is less about owning the infrastructure and more about guaranteeing the outcome. It’s about making sure resilience is there when it’s needed. That’s a significant change in how organizations think about this space.

VMblog: As a global MSP working across businesses of all sizes, Assured sits in a pretty unique position right now. How are you navigating this on behalf of your customers? Are smaller enterprises facing a disproportionately harder time than larger organizations when it comes to securing the infrastructure they need to stay protected? 

Hayes: Yes, scale is a key concern in this environment. As a global MSP, we’ve been able to stay ahead of the volatility by investing ahead of demand, ordering infrastructure up to 12 months in advance, maintaining stockpiles, and diversifying suppliers and platforms. This allows us to absorb much of the disruption that individual organizations would otherwise face.

Smaller enterprises don’t have that same flexibility. They’re competing for the same constrained resources as hyperscalers and large enterprises, but without the buying power or long term visibility. That puts them at a disproportionate disadvantage.

This is where the managed service model becomes critical. It helps level the playing field by giving organizations access to pre-provisioned, enterprise-grade infrastructure without the burden of  navigating the supply chain themselves.

VMblog: If you’re an enterprise CIO or IT leader reading this right now, what should you be doing immediately? Not six months from now, but rather right now. What are the questions you should be asking your backup and recovery vendors, your infrastructure partners, and frankly, your own Board?

Hayes: If you’re a CIO or IT leader reading this, the first step is to assume this situation will persist. Prices and availability are unlikely to stabilize in the short term, so planning should reflect continued volatility.

Next, validate your recovery assumptions. Assess whether your recovery environment can scale in line with production, when it was last tested under real-world conditions, and whether there are dependencies on hardware that has not yet been delivered.

It’s also important to challenge your vendors and partners. Understand whether recovery SLAs rely on future infrastructure availability, how they are mitigating supply chain risk, and what guarantees they can provide around recovery performance.

This should be escalated to the Board. It’s a business continuity risk as much as an IT issue.

VMblog: Looking further ahead, do you think the RAM shortage is a temporary disruption the market will absorb? Or are we at the beginning of a longer structural shift in how enterprises need to think about resilience infrastructure? And what does the road forward look like for companies and organizations that get ahead of this now? 

Hayes: This looks much more like a structural shift than a short-term disruption. AI-driven demand is fundamentally reshaping how memory and compute resources are allocated globally. Supply is increasingly concentrated, and traditional enterprise buyers are no longer the priority. That means infrastructure availability and pricing will remain unpredictable for the foreseeable future.

The organizations that get ahead of this are the ones that separate resilience from infrastructure ownership. It becomes less about what you buy and when, and more about the outcome of protection, recovery, and continuity.

In a market like this, you can’t have your resilience strategy depend on whether infrastructure is delivered on time.

##