Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Operational resilience»Rethinking SaaS resilience: why backup strategies are struggling to keep pace (Page 20)
Operational resilience

Rethinking SaaS resilience: why backup strategies are struggling to keep pace

While most organizations now use SaaS for critical processes, in many cases ownership, governance, and recovery have yet to catch up. Dan Middleton explains why SaaS resilience needs a new approach.
March 10, 20267 Mins Read
SaaS concept - a central cloud is linked to many dependent applications.

The rapid expansion of SaaS has fundamentally reshaped how most organizations operate. From collaboration platforms and CRM systems to finance and HR applications, businesses are moving critical workflows into cloud environments at an unprecedented rate. Yet while adoption continues to accelerate, many resilience strategies remain rooted in assumptions formed during an earlier era of IT – creating a widening gap between where data lives and how well it is protected.

For security leaders, this gap represents one of the defining challenges of modern resilience. cloud platforms offer flexibility, scalability, and innovation, but they also introduce new questions around ownership, governance, and recovery responsibility. As more data moves beyond traditional infrastructure, organizations are beginning to recognise that resilience in the SaaS era requires a different mindset; one that combines visibility, automation, and strategic planning.

The growing resilience gap

At Technology Live!, an event which took place in  London in November 2025, Keepit highlighted a concern shared across the industry: organizations are rapidly increasing their use of SaaS applications, but backup and recovery strategies are not evolving at the same pace. The result is a growing exposure to data loss and operational disruption when outages, cyber incidents, or platform failures occur.

This disconnect is partly driven by perception. Many businesses still assume that cloud providers inherently guarantee data protection, yet the reality is more nuanced. Shared responsibility models mean that while platforms ensure infrastructure availability, organizations remain responsible for safeguarding their own data and ensuring recoverability.

As SaaS estates expand across departments, from marketing and sales to legal and delivery, data becomes more distributed, harder to track, and more difficult to govern. According to industry insights referenced during the event, enterprises are expected to dramatically increase their prioritisation of SaaS backup over the next few years, reflecting a growing awareness that resilience cannot be outsourced entirely to platform providers.

More applications, more risk

The proliferation of SaaS tools has brought enormous benefits, but it has also reshaped the risk landscape. Each new application introduces another layer of data ownership, access control, and recovery complexity. As organizations adopt specialised platforms for individual teams, information becomes fragmented across environments that may lack consistent governance policies.

This trend has significant implications for resilience planning. Traditional disaster recovery strategies often focused on centralised infrastructure – data centres, servers, and core applications. Today, however, critical business information exists across hundreds of cloud services, each with unique retention policies, export capabilities, and recovery limitations.

As highlighted in recent resilience discussions, the challenge is no longer simply protecting systems; it is maintaining a clear overview of data itself. Organizations must understand where information resides, who owns it, and how quickly it can be restored in the event of an incident. Without that visibility, even well-designed strategies can struggle to ensure business continuity.

From reactive recovery to intelligent resilience

The shift toward SaaS has accelerated a broader evolution in resilience thinking. Rather than treating backup as a passive safety net, organizations are increasingly adopting a proactive approach – sometimes referred to as intelligent resilience – that focuses on anticipating disruption and reducing recovery time.

This concept moves beyond traditional disaster recovery by combining risk assessment, automation, and continuous testing. Resilience today is defined not only by whether data is protected but by how quickly and reliably organizations can return to normal operations when something goes wrong.

Key principles underpinning this approach include:

  • Categorising and risk-assessing critical data to prioritise recovery.
  • Designing architectures that support rapid restoration across multiple environments.
  • Testing processes regularly to ensure that recovery plans work under pressure.
  • Embedding governance and compliance into backup strategies from the outset.

These principles reflect a growing recognition that resilience is an ongoing capability rather than a one-time investment.

Automation and the rise of programmable resilience

One of the most significant shifts emerging from discussions around SaaS resilience is the move toward automation and programmable infrastructure. As the number of applications continues to grow, manual backup configuration and recovery processes become increasingly unsustainable.

New approaches, including the use of domain-specific languages (DSLs) and API-driven orchestration, are enabling teams to scale protection across large SaaS estates without proportionally increasing complexity. By abstracting the technical details of individual platforms, these frameworks allow resilience strategies to evolve alongside rapidly changing application landscapes.

One example of how vendors are responding to this complexity is the move toward programmable backup architectures. Rather than building bespoke integrations for each individual application, some providers are introducing domain-specific languages (DSLs) that allow new SaaS workloads to be supported more rapidly through automation.

Keepit, for example, has outlined plans to expand its coverage from just eight supported SaaS applications at the start of 2025 to hundreds within three years by using DSL-driven development. Framed within a broader industry context, this shift highlights how resilience strategies are evolving away from static tooling toward flexible frameworks that can adapt to the pace of SaaS innovation – enabling organizations to maintain governance and recovery readiness even as their application landscape grows.

Automation also introduces consistency. When recovery processes are codified and repeatable, organizations reduce the risk of human error during high-pressure incidents. Instead of relying on manual intervention, teams can execute validated workflows that restore data quickly and securely.

Governance, sovereignty, and control

Beyond operational resilience, SaaS adoption has intensified discussions around data sovereignty and governance. As geopolitical uncertainty grows and regulations evolve, organizations are placing greater emphasis on understanding where their data resides and who ultimately controls it.

Industry frameworks increasingly highlight four interconnected factors: ownership, authority, locality, and residency. Together, these elements determine how data can be accessed, migrated, or restored during a crisis.

For many organizations, the challenge lies in balancing flexibility with control. SaaS platforms offer global accessibility, but resilience strategies must account for regulatory obligations, cross-border data flows, and local recovery requirements. Without careful planning, businesses risk losing visibility into how data is managed, making recovery slower and compliance more complex.

This is why governance is emerging as a core pillar of modern resilience strategies. Rather than treating backup as a purely technical function, organizations are integrating it into broader risk management frameworks that align cyber security, compliance, and operational continuity.

Visibility through data and analytics

As resilience strategies mature, organizations are also exploring how analytics and AI can enhance visibility into their data environments. Emerging tools aim to simplify anomaly detection, monitor backup health, and provide insights into recovery readiness.

The goal is not simply automation but informed decision-making. By analysing trends in backup activity, data changes, and system behaviour, teams can identify vulnerabilities earlier and respond before disruptions escalate.

This aligns with the broader movement toward intelligent resilience, where recovery planning becomes a continuous, data-driven process rather than a reactive response.

Importantly, these capabilities are evolving alongside open APIs and interoperability standards, allowing organizations to integrate resilience insights into their wider security and operational workflows.

Preparing for the next phase of SaaS growth

The trajectory of SaaS adoption suggests that the resilience gap will remain a critical focus for years to come. As organizations expand their digital ecosystems, backup strategies must evolve from isolated tools into holistic frameworks that encompass governance, automation, and continuous improvement.

Industry forecasts indicate that by the end of the decade, SaaS backup will become a core requirement rather than an optional enhancement – underscoring the growing recognition that cloud resilience requires active management.

For CIOs and security leaders, this means reassessing assumptions about where responsibility lies and how resilience should be measured. Success will depend on the ability to maintain control over data, ensure recoverability across diverse environments, and adopt technologies that scale alongside organizational growth.

Moving resilience forward

The evolution of SaaS has transformed not only how organizations work but also how they think about risk. Resilience strategies must keep pace with the speed of digital transformation.

Relying on hope, or on the assumption that cloud providers alone will guarantee recovery, is no longer sufficient.

Instead, the future of resilience lies in proactive planning, programmable automation, and intelligent visibility. By embracing these principles, organizations can move beyond traditional backup models toward a more adaptive and resilient approach – one that ensures data remains secure, accessible, and recoverable, no matter how the technology landscape continues to evolve.

The author

Dan Middleton is Vice President UKI, Middle East & Africa at Keepit

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleCorporate preparedness for the FIFA World Cup 2026: duty of care, risk, and opportunity
Next Article Research highlights six key risk areas related to Microsoft 365 deployments

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Board briefing: preparing for the post-quantum era

November 27, 2025
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?