Rethinking the Security Bar for Your Backup Provider

Zack Brigman, Product Marketing Director, Security

August 25, 2026

Rethinking the Security Bar for Your Backup Provider

Content

    Make no mistake: backup remains a vital insurance policy for today’s organizations. What’s dead is the legacy mindset of treating backup as a passive, overnight operation that you only think about once a year is over.

    Today, backups have evolved into an active, foundational pillar of modern cyber resilience. Yet, a new breed of risks has emerged, directly threatening the very data and utilities businesses rely on to recover.

    Attackers are no longer just targeting production environments; they are going after recovery copies directly. Instead of breaking through firewalls, they are logging in via stolen identities. At the same time, AI agents are appearing on both sides of the aisle, weaponized by adversaries to accelerate attacks and deployed internally by organizations where unintended actions can cause accidental chaos.

    Separately, each of these factors introduces complex security considerations. Combined, they fundamentally raise the bar for what’s needed, and should be demanded, from the platform trusted with your data recovery. 

    Adversarial AI moves faster than responders

    Bad actors have evolved far beyond using AI to polish phishing emails. Today, they are deploying autonomous AI agents that plan, adapt, and retry attacks on their own, collapsing traditional containment and response windows.

    The primary dangers here are speed, scale, and proficiency. AI accelerates initial reconnaissance, automates vulnerability discovery, and shortens the path to compromising data. The data is sobering: the average breakout time fell to just 29 minutes in 2025, with the fastest observed tracking at a mere matter of seconds (CrowdStrike, 2026 Global Threat Report). 

    More critically, adversaries are now employing AI to target the recovery tier itself; disabling, altering, or deleting backups to completely strip away an organization's leverage during a ransom negotiation.

    Raising the bar: When attacks run at machine speed, your backup platform must operate under the assumption that it is the target. Mitigating this risk requires a secure-by-design architecture with built-in protections that drastically reduce the attack surface, while removing the human burden of manual infrastructure updates, patching, and maintenance.

    Your own AI agents are part of the risk model 

    While adversarial AI poses a threat, the agents that organizations deploy — doing exactly what they were permitted to do — also create risk.

    In many enterprises, machine identities now outnumber human employees by around 82 to 1 (CyberArk, 2025 Identity Security Landscape). Many of these non-human identities can carry standing privilege and implicit trust, often provisioned faster than security teams can realistically review what data or systems they can reach.

    PocketOS is the cautionary tale where a coding agent ran into a credential mismatch during a routine staging task, went looking for a fix, and issued a single destructive command that deleted the production database and its backups in nine seconds (The New Stack, How a Cursor AI agent wiped PocketOS). The agent wasn't malicious. It was capable, trusted, and unconstrained, and that combination was enough to cause widespread data loss.

    Raising the bar: As autonomous agents become deeply embedded into everyday workflows, non-human identities require the same rigorous scrutiny as privileged human users. Backup environments must enforce strict least-privilege scopes, mandatory approval gates for consequential actions, and deterministic limits that hold firm regardless of what an AI model decides to do.

    Identity is a perimeter that matters

    The traditional intrusion model relied on exploiting unpatched software vulnerabilities to force entry. The modern approach is much quieter and significantly harder to detect: simply logging in. Roughly 65% of all cyber intrusions now begin with identity compromises (Palo Alto Networks, Unit 42 2026 Global Incident Response Report). From stolen credentials and sophisticated phishing to hijacked tokens and configuration drift, adversaries routinely turn trusted access against the organizations that granted it.

    The March 2026 cyberattack on Stryker put this reality on full display, where attackers leveraged harvested credentials and native device-management controls to wipe more than 200,000 endpoints and delete over 50TB of data (Coalition, How Infostealers May Have Opened the Door to the Stryker Wipe). Because those actions came from a recognized identity, traditional tooling waved them through. 

    For backup, that scenario lands hard. If a compromised but trusted administrator account can access your backup console, alter retention policies, or execute destructive actions, your last line of defense is only as strong as your weakest credential.

    Raising the bar: Internal access can no longer be assumed as inherently safe. A modern backup platform must operate under the assumption that trusted credentials will eventually be compromised, implementing structural safeguards specifically designed to mitigate the weaponization of trust.

    How Druva sets a new standard

    Your backup platform earns its place only if it holds firm under pressure. Faster adversaries, internal agents, and abused identities are distinct challenges, but they can all converge at the same place: compromising your ability to recover.

    At Druva, we built our platform for the threat landscape that exists today, not the one from a decade ago. Our goal is to eliminate systemic infrastructure risk, shrink your available attack surface, and enable continuous recovery readiness with the speed and certainty modern enterprises demand.

    As a fully managed SaaS platform, Druva is intrinsically secure and resilient. With unalterable data immutability, a true logical air-gap, and deep, zero-trust policy controls, our layered protections ensure your data remains secure, compliant, and recovery-ready.

    Our layered approach to platform security

    Managed DDR

    24/7 Monitoring & Response

    Fully managed monitoring and expert-led assistance from threat detection through incident response and recovery.

    Zero Trust Access

    Strict RBAC, IAM, & MFA Enforcement

    Verifies human and non-human identities and requests, stopping lateral movement and unauthorized access.

    Safe Mode

    Instant Environment Lockdowns

    Proactively locks down tenants, stopping destructive actions and accidental misuse from impacting data.

    User & Backup Policies 

    Governance, Guardrails, & Restrictive Actions

    Enforces strict guardrails that prohibit compromised accounts, rogue admins, or agents from taking unwanted actions or altering backups.

    Encryption

    End-to-End Encryption, Data Sharding, and Key Management

    At-rest and in-flight encryption, preventing intercepted streams and rendering backups unreadable to users or threat actors.

    Air-Gap

    Virtual Isolation from Production Blast Radius

    Severs connection to production networks, insulating backup data and infrastructure from ransomware or malware threats.

    Immutability 

    Hardened, Tamper-Proof Data Copies

    Preserves data in a hardened format that no adversary, admin, or non-human user can alter or delete.

    We eliminate the assumption that internal access is safe, scrutinize native actions to the highest level, and ensure your last line of defense holds under pressure through thoughtful architectural designs that keep customers recovery-ready even when under attack.

    Next steps

    Further Reading