The rapid expansion of SaaS has fundamentally reshaped how most organizations operate. From collaboration platforms and CRM systems to finance and HR applications, businesses are moving critical workflows into cloud environments at an unprecedented rate. Yet while adoption continues to accelerate, many resilience strategies remain rooted in assumptions formed during an earlier era of IT – creating a widening gap between where data lives and how well it is protected.
For security leaders, this gap represents one of the defining challenges of modern resilience. cloud platforms offer flexibility, scalability, and innovation, but they also introduce new questions around ownership, governance, and recovery responsibility. As more data moves beyond traditional infrastructure, organizations are beginning to recognise that resilience in the SaaS era requires a different mindset; one that combines visibility, automation, and strategic planning.
The growing resilience gap
At Technology Live!, an event which took place in London in November 2025, Keepit highlighted a concern shared across the industry: organizations are rapidly increasing their use of SaaS applications, but backup and recovery strategies are not evolving at the same pace. The result is a growing exposure to data loss and operational disruption when outages, cyber incidents, or platform failures occur.
This disconnect is partly driven by perception. Many businesses still assume that cloud providers inherently guarantee data protection, yet the reality is more nuanced. Shared responsibility models mean that while platforms ensure infrastructure availability, organizations remain responsible for safeguarding their own data and ensuring recoverability.
As SaaS estates expand across departments, from marketing and sales to legal and delivery, data becomes more distributed, harder to track, and more difficult to govern. According to industry insights referenced during the event, enterprises are expected to dramatically increase their prioritisation of SaaS backup over the next few years, reflecting a growing awareness that resilience cannot be outsourced entirely to platform providers.
More applications, more risk
The proliferation of SaaS tools has brought enormous benefits, but it has also reshaped the risk landscape. Each new application introduces another layer of data ownership, access control, and recovery complexity. As organizations adopt specialised platforms for individual teams, information becomes fragmented across environments that may lack consistent governance policies.
This trend has significant implications for resilience planning. Traditional disaster recovery strategies often focused on centralised infrastructure – data centres, servers, and core applications. Today, however, critical business information exists across hundreds of cloud services, each with unique retention policies, export capabilities, and recovery limitations.
As highlighted in recent resilience discussions, the challenge is no longer simply protecting systems; it is maintaining a clear overview of data itself. Organizations must understand where information resides, who owns it, and how quickly it can be restored in the event of an incident. Without that visibility, even well-designed strategies can struggle to ensure business continuity.
From reactive recovery to intelligent resilience
The shift toward SaaS has accelerated a broader evolution in resilience thinking. Rather than treating backup as a passive safety net, organizations are increasingly adopting a proactive approach – sometimes referred to as intelligent resilience – that focuses on anticipating disruption and reducing recovery time.
This concept moves beyond traditional disaster recovery by combining risk assessment, automation, and continuous testing. Resilience today is defined not only by whether data is protected but by how quickly and reliably organizations can return to normal operations when something goes wrong.
Key principles underpinning this approach include:
- Categorising and risk-assessing critical data to prioritise recovery.
- Designing architectures that support rapid restoration across multiple environments.
- Testing processes regularly to ensure that recovery plans work under pressure.
- Embedding governance and compliance into backup strategies from the outset.
These principles reflect a growing recognition that resilience is an ongoing capability rather than a one-time investment.
Automation and the rise of programmable resilience
One of the most significant shifts emerging from discussions around SaaS resilience is the move toward automation and programmable infrastructure. As the number of applications continues to grow, manual backup configuration and recovery processes become increasingly unsustainable.
New approaches, including the use of domain-specific languages (DSLs) and API-driven orchestration, are enabling teams to scale protection across large SaaS estates without proportionally increasing complexity. By abstracting the technical details of individual platforms, these frameworks allow resilience strategies to evolve alongside rapidly changing application landscapes.
One example of how vendors are responding to this complexity is the move toward programmable backup architectures. Rather than building bespoke integrations for each individual application, some providers are introducing domain-specific languages (DSLs) that allow new SaaS workloads to be supported more rapidly through automation.
Keepit, for example, has outlined plans to expand its coverage from just eight supported SaaS applications at the start of 2025 to hundreds within three years by using DSL-driven development. Framed within a broader industry context, this shift highlights how resilience strategies are evolving away from static tooling toward flexible frameworks that can adapt to the pace of SaaS innovation – enabling organizations to maintain governance and recovery readiness even as their application landscape grows.
Automation also introduces consistency. When recovery processes are codified and repeatable, organizations reduce the risk of human error during high-pressure incidents. Instead of relying on manual intervention, teams can execute validated workflows that restore data quickly and securely.
Governance, sovereignty, and control
Beyond operational resilience, SaaS adoption has intensified discussions around data sovereignty and governance. As geopolitical uncertainty grows and regulations evolve, organizations are placing greater emphasis on understanding where their data resides and who ultimately controls it.
Industry frameworks increasingly highlight four interconnected factors: ownership, authority, locality, and residency. Together, these elements determine how data can be accessed, migrated, or restored during a crisis.
For many organizations, the challenge lies in balancing flexibility with control. SaaS platforms offer global accessibility, but resilience strategies must account for regulatory obligations, cross-border data flows, and local recovery requirements. Without careful planning, businesses risk losing visibility into how data is managed, making recovery slower and compliance more complex.
This is why governance is emerging as a core pillar of modern resilience strategies. Rather than treating backup as a purely technical function, organizations are integrating it into broader risk management frameworks that align cyber security, compliance, and operational continuity.
Visibility through data and analytics
As resilience strategies mature, organizations are also exploring how analytics and AI can enhance visibility into their data environments. Emerging tools aim to simplify anomaly detection, monitor backup health, and provide insights into recovery readiness.
The goal is not simply automation but informed decision-making. By analysing trends in backup activity, data changes, and system behaviour, teams can identify vulnerabilities earlier and respond before disruptions escalate.
This aligns with the broader movement toward intelligent resilience, where recovery planning becomes a continuous, data-driven process rather than a reactive response.
Importantly, these capabilities are evolving alongside open APIs and interoperability standards, allowing organizations to integrate resilience insights into their wider security and operational workflows.
Preparing for the next phase of SaaS growth
The trajectory of SaaS adoption suggests that the resilience gap will remain a critical focus for years to come. As organizations expand their digital ecosystems, backup strategies must evolve from isolated tools into holistic frameworks that encompass governance, automation, and continuous improvement.
Industry forecasts indicate that by the end of the decade, SaaS backup will become a core requirement rather than an optional enhancement – underscoring the growing recognition that cloud resilience requires active management.
For CIOs and security leaders, this means reassessing assumptions about where responsibility lies and how resilience should be measured. Success will depend on the ability to maintain control over data, ensure recoverability across diverse environments, and adopt technologies that scale alongside organizational growth.
Moving resilience forward
The evolution of SaaS has transformed not only how organizations work but also how they think about risk. Resilience strategies must keep pace with the speed of digital transformation.
Relying on hope, or on the assumption that cloud providers alone will guarantee recovery, is no longer sufficient.
Instead, the future of resilience lies in proactive planning, programmable automation, and intelligent visibility. By embracing these principles, organizations can move beyond traditional backup models toward a more adaptive and resilient approach – one that ensures data remains secure, accessible, and recoverable, no matter how the technology landscape continues to evolve.
The author
Dan Middleton is Vice President UKI, Middle East & Africa at Keepit






