Opinion piece: When the last line of defence fails: The new reality of backup resilience
By Derek Street, Head of Sales & Marketing at Data Management Professionals SA
Many South African organisations have historically seen backup as the quiet, dependable safety net of their IT estate – something that can be set up once, monitored occasionally and trusted to be there when disaster strikes.
However, in a threat landscape progressively shaped by Artificial Intelligence (AI)-enabled attacks, identity compromises and increasingly destructive ransomware, this assumption is no longer safe. Organisations should no longer ask whether they have backups, but whether their backup environment is resilient enough to survive a cyberattack.
Ransomware groups have learned that the fastest way to cripple a business is not only to encrypt production systems, but to corrupt, encrypt or quietly poison the backup layer itself. Once attackers breach an environment, they move laterally with intent, escalating privileges, compromising identity stores and targeting the very tools organisations rely on for recovery.
In many cases, they sit undetected for weeks, ensuring that multiple backup cycles contain infected or manipulated data. By the time the attack detonates, the organisation discovers that its last resort is of no use.
No longer adequate
This is where traditional, set‑and‑forget backup strategies collapse. Backups designed for accidental deletion or hardware failure simply cannot withstand adversaries who actively work to undermine them. Modern resilience demands a fundamentally different architecture that is built on isolation, immutability, governance and continuous validation.
A resilient backup environment begins with segmentation, because backup networks must be isolated from production, with strict role‑based access controls that prevent administrators from having blanket privileges across the estate. Immutability is non‑negotiable as organisations need copies of data that cannot be altered, encrypted or deleted, even by privileged users. Air‑gapped or logically isolated copies add another layer of protection, ensuring that even if attackers compromise the primary environment, they cannot reach the recovery vault.
Architecture is not enough
Yet architecture alone is not enough. Organisations must interrogate whether their current design is genuinely fit for purpose. This means asking: who has access to backup systems? Are identity platforms protected? Are backup applications patched and monitored? Can we detect anomalies in historical data? And do we have a clean‑room environment to validate recovery before reintroducing data into production?
Continuous testing is the cornerstone of cyber‑resilient recovery, because a backup that has never been restored is a backup that cannot be trusted. Fire‑drill recoveries, executed regularly, instead of annually, expose weaknesses long before attackers do. They reveal whether data is clean, whether dependencies are understood, whether recovery times align with business expectations, and whether teams know how to respond under pressure. In a world where AI accelerates both attack speed and attack complexity, resilience postures should be reassessed quarterly, not once a year.
One of the most common misconceptions among enterprises is the belief that “we’re covered because we back up everything”. But volume is not the same as resilience. Many organisations unknowingly back up compromised data, store backups in environments accessible through the same identity plane attackers target, or rely on legacy architectures that cannot withstand modern ransomware behaviour.
The difficult conversation, and one that must be had, is that backup sufficiency is often an illusion. Without governance, isolation, immutability and validation, backup becomes a single point of catastrophic failure.
Regulations add another dimension
South Africa’s data privacy and localisation expectations add another dimension. Sensitive data, especially regulated or customer‑specific information, increasingly needs to remain within national borders. This influences provider selection, colocation decisions and architectural design. Organisations must ensure that their backup environments comply with residency requirements while still delivering the resilience demanded by modern threats.
Crucially, backup resilience cannot be treated as a standalone exercise, but must be integrated into broader cyber resilience reviews, identity assessments, network segmentation strategies and incident response planning. Backup is not an afterthought; it is the foundation upon which all other recovery efforts depend.
Over a period of six to 12 months, enterprises can take practical steps without derailing operations. These include segmenting backup networks, enforcing role‑based access, introducing immutable storage, deploying anomaly detection on historical data, establishing clean‑room recovery environments, and scheduling quarterly fire‑drill recoveries. These actions strengthen resilience without adding unnecessary complexity.
The core message is that backup is no longer a passive insurance policy. It is an active, strategic component of cyber resilience and, if it fails, everything fails. Organisations that modernise their backup environments now will be the ones still standing tomorrow.