By Sergei Serdyuk
March 31st marks World Backup Day, the annual reminder and call-to-action for organizations and individuals to re-evaluate their data protection strategies, ensuring resilient data backup and recovery approaches are in place. With the prolific nature of cyber attacks, including ransomware, DDoS (Distributed Denial-of-Service) attacks, phishing, and other scams, this day aims to reinforce the message that in current times, backup is a non-negotiable practice. Given the rapid pace of technology developments, the impact of AI advancements, cloud/hybrid cloud approaches, and more employees working remotely than ever before resulting in increased workloads at the edge – the data protection requirements of today are not what they were even five years ago. With the increased number of distributed networks and remote connections to applications and servers, business and data vulnerability to breaches and cyber attacks has never been greater.
Trends impacting backup processes
The data protection sector is expected to change dramatically, with several key trends shaping 2025 and the years to come, such as AI-driven data protection. AI technologies are increasingly being integrated into data protection solutions for threat and anomaly detection, with self-protecting systems capable of proactive monitoring and instant threat responses, and predictive analytics to prevent bottlenecks before they happen. Some advanced AI models are being used to identify ransomware attacks in real-time through dataset analysis and pattern recognition, so AI is no longer just about automation.
The flip-side of the AI coin reveals that we are also seeing an uptick in ransomware and AI-enabled attacks as well as the use of deepfakes in social engineering attacks. Cybercriminals are leveraging AI to develop more advanced attacks and phishing schemes to evade traditional security measures.
In terms of trends, hybrid and multi-cloud approaches remain very much at the forefront. As most organizations are now using a mix of on-premises, public and private clouds, and SaaS applications. Meanwhile, edge is changing how we protect data by demanding backups be closer to where data is generated, ensuring real-time recovery capabilities for latency-sensitive workloads.
There is a noticeable shift toward cyber resilience and ransomware protection. Immutable / air-gapped storage and zero trust security are becoming standard to ensure data remains untampered. We’re also seeing increased use of advanced encryption and anonymisation techniques to protect sensitive information from unauthorised access and cyber threats in accordance with regulations, rules, laws, policies, etc. Data compliance requirements are getting more stringent and complicated, while increasingly demanding regulations are pushing organizations to be more flexible when it comes to retention policies, audit trails, automation, and cyber security measures. Businesses are expected to allocate more resources toward robust data protection, including advanced backup, ransomware defense, and disaster recovery.
Challenges and data protection priorities
Even with the latest advances in data protection, organizations still face some basic challenges, such as sprawl due to data being generated massively across platforms and geographies, making data management and protection a lot harder. The storage and maintenance of large volumes of backups can become expensive – especially in the cloud – where costs can spiral out of control. Organizations must also be prepared for cyber attacks that exclusively target backups to prevent data recovery, as well as securing against an unreliable or slow recovery and failure to meet recovery objectives, leading to downtime, financial losses, and disruptions. Businesses face on-going challenges with regulatory compliance (such as GDPR, CCPA, NIS2, and other industry-specific mandates) necessitating tailored data retention and protection policies. Finally, ensuring consistency across on-premises, public cloud, and edge environments requires backup solutions capable of managing diverse workloads.
Backups for business: common mistakes
Although unintentional, companies often make preventable mistakes when they develop their data protection plans. The most common mistakes include: not backing up regularly; neglecting to test and verify backup data; failing to plan and test for data recovery from backups (testing ensures business stays operational if something goes wrong); storing all backups in a single location, sometimes within the same network as production; ignoring security protocols and exposing backups to breaches and cyber threats; and maintaining backups for either too short or too long a time – leading to compliance issues, increased storage costs, or loss of historical data. Manual backup often leads to human errors, whereas automating the process saves time and reduces the risk of human error.
Ensuring resilient backup and recovery strategies
Organizations can do a lot to ensure backup and recovery strategies are robust and that they keep pace with the threat environment. Conducting risk assessments to identify critical data, potential bottlenecks, and the best protection approach for various workloads, is a prudent initial step.
Businesses should regularly back up data and develop a recovery plan for disaster scenarios (e.g., data corruption, accidental deletion, ransomware attacks, etc.). Following the 3-2-1-1-0 rule (a variation of the standard 3-2-1 rule), with an immutable or air-gapped copy to eliminate recovery errors, is the most up-to-date approach in this area. Backups must be encrypted and enforced with strict access controls – role-based access control (RBAC), multi-factor authentication (MFA), two-factor authentication (2FA), etc. – to prevent any unauthorised changes. These controls should regularly be updated to reflect changes in roles or when an employee leaves the company.
Backup and recovery processes should be tested to validate backup integrity, identify gaps in the recovery process and ensure recovery time objectives (RTOs) are met. Backup processes can be automated to minimise errors and ensure backups are not overlooked. Automation can also facilitate regular testing of backup and recovery systems. The implementation of monitoring tools is a vital step in creating alerts as to any failures or issues, as well as to help resolve any potential setbacks. Finally, it should be ensured that backup practices align with industry standards and compliance requirements to avoid legal issues and hefty fines.
In essence, backup and recovery strategies must be living processes, continually updated to align with the latest technological, regulatory, and security challenges.
Advances in backup technologies and techniques
The most up-to-date backup capabilities and techniques focus on security, efficiency, and recovery speed, including AI-driven backup and detection, which are integrated into backup solutions to help detect anomalies like ransomware, predict job failures, and optimise performance. With the rise of hybrid and multi-cloud infrastructures, cloud-native and cross-cloud backups have become vital. While the utilisation of blockchain technology to ensure backups remain unaltered or untampered, is becoming a growing trend. Continuous data protection (CDP) has been popular for some time to close the gap between backup intervals by capturing and replicating changes in real-time. CDP allows businesses to recover data from the exact moment before a disaster occurs. Many organizations also take the additional step of deploying a zero trust backup architecture, where access to backups requires strict authentication and least privilege access.
Additional techniques worth mentioning include policy-driven automation, snapshot-based and storage-aware backups, along with immutability and air-gapping, as well as intelligent deduplication and compression.
Data backup and recovery top tips
To improve backup and recovery capabilities, organizations should follow proven backup best practices to protect data and maintain operations during unforeseen disruptions. For optimum data protection, utilising a combination of on-premises, offsite, and offline storage for maximum redundancy is a winning strategy. Clear recovery objectives should be set, with frequent recovery tests run to ensure every component operates as intended. Leveraging immutability and air-gapping is highly effective in protecting backups against ransomware and other malware. Businesses should prioritise security with encryption and strong access controls to prevent unauthorised access and data breaches. While the automation of processes is a pivotal step to ensure efficiency.
To sum-up, to enhance data protection, businesses should invest in modern backup solutions that provide a combination of cyber resilience, automation, and cloud-native capabilities. While becoming familiar with current threats and advancements in backup technologies will help companies prioritise these pivotal data protection procedures and stay up-to-date. As cybercriminals are constantly finding new ways to target data, it is imperative that organizations likewise adapt accordingly. By embracing these key steps, businesses are onto a winning strategy by doing their utmost to ensure data protection resilience.
The author
Sergei Serdyuk is VP of Product Management at NAKIVO






