The AI resilience gap starts with data: Why backup and recovery are no longer enough

Share this:
David Allott, field CISO for Asia Pacific and Japan, Veeam Software
Image generated by Deeptech Times using ChatGPT

Data determines what an AI agent can see, infer and change. If that data is poorly classified, overexposed, stale or corrupted, a guardrail applied at runtime becomes a last line of defence at the wrong layer. 

And when an agent acts incorrectly, the central problem is no longer simply model accuracy. It is whether the organisation can identify what changed, contain the blast radius, reverse the action and prove that the restored state can be trusted.

David Allott, field CISO for Asia Pacific and Japan at Veeam Software, believes this requires a fundamental rethink of resilience. The traditional model was built around recovering from an external catastrophe, then evolved to address ransomware and cyber extortion. Agentic AI moves a significant part of the risk inside the organisation.

“Resilience cannot be just about backup and recovery,” Allott told Deeptech Times. “Threat actors are stealing data. You can’t recover data that’s been stolen because it hasn’t disappeared. It’s just been stolen.”

Recovery must become granular

Autonomous agents create another complication. They are non-human actors that may touch sensitive data, operate with excessive permissions and make decisions without clear accountability. Restoring an entire application after an outage is not enough if an agent has altered a contract, exposed a customer record, contaminated a dataset or moved information across a regulated border.

The recovery unit therefore has to shrink. Organisations need the ability to trace and reverse changes at the level of files, permissions, datasets, embeddings and model components, while preserving an evidence trail of what happened. Resilience becomes less about bringing a system back online and more about restoring a trustworthy state. This is where data management becomes part of AI safety rather than an adjacent IT discipline.

“If you’re waiting to the point of runtime to try and control an agent, it’s too late,” Allott said. “Most AI projects are not failing because of the model. They’re failing because of the data.”

That argument challenges the current tendency to place most AI controls around prompts and outputs. Those controls remain important but they cannot compensate for an enterprise data estate whose sensitive information has not been discovered, classified or mapped to the right access policies. A capable model does not repair a weak data foundation but amplifies the consequences.

Unstructured data is the obvious blind spot. Files, emails, chats, comments and collaboration platforms contain much of an organisation’s institutional knowledge, but often lack the disciplined controls applied to databases and core business systems. 

Veeam’s acquisition of Securiti AI reflects an industry shift towards connecting data security posture management, governance and lineage with recovery. The larger point is that enterprises are not deploying AI onto a clean slate. They are exposing it to years of accumulated data and inherited permission decisions.

Attackers are exploiting the same weakness. Allott said AI is increasing the scale of social engineering and accelerating the identification and exfiltration of high-value information. It also creates a route to attack the integrity of AI itself: poison the training data and trust in the model becomes questionable. A backup is of limited value if the organisation cannot determine which recovery point was clean.

Zero Trust must now assume autonomy

Allott’s most useful reframing is that security must move from “assume breach” to “assume autonomy”. Zero Trust remains relevant but many identity and access systems were designed around a human approval step. Agentic systems remove that assumption.

The identity problem extends beyond agents. Attackers increasingly pursue tokens that carry legitimate permissions across cloud applications. A system may accept the token without establishing whether the entity presenting it is the person, application or agent for which access was intended. As non-human identities multiply, least-privilege access must become dynamic, purpose-bound and observable.

Every production agent should therefore have a named owner, a defined scope, an expiry or review point, an audit trail and a tested method of stopping and reversing its actions. An AI oversight committee may bring the CISO, CIO, chief data officer, risk and compliance leaders to the same table, but shared participation must not become diluted accountability.

“Who owns these agents?” Allott asked. “And importantly, who owns the outcome or the consequences of their actions?”

Governance should enable speed

The tension between control and innovation is behind Veeam’s work with SPARK on SafeAI.sg, Singapore’s industry-led centre for AI safety and governance. Its risk-weighted approach is important because both extremes are dangerous. 

Under-governed AI exposes data and people to avoidable harm, while over-governed AI applies high-stakes controls indiscriminately, slows useful experimentation and can drive adoption into the shadows.

The answer is not to slow every AI initiative. It is to apply controls according to the use case, data sensitivity, jurisdiction and potential impact, and to make those controls as automated and transparent as possible. A public-safety agent acting on live operational data plainly demands more scrutiny than an internal summarisation tool.

AI’s next major enterprise failure may not look like a conventional breach. It may involve a legitimate agent using a valid token to perform an authorised action that nobody intended. By the time a human notices, the consequences may have propagated at machine speed.

In that environment, resilience is the practical foundation of trust. The real measure of enterprise AI will be how confidently the organisation can recover when it does the wrong thing.

Leave a Reply

Your email address will not be published. Required fields are marked *

Search this website