How Rubrik Is Rewriting The Rules Of Cyber Resilience

Opening a banking app, ordering food, or buying a pair of shoes online may not feel remarkable anymore, but what’s undeniably remarkable is the robust cloud infrastructure that is powering these everyday actions.
It is this dexterity that also makes it vulnerable to cyberattacks. Over the years, while security protocols have evolved, so has the sophistication of cyberattacks. Once dominated by ransomware attacks, the threat has now become something even more damaging.
Attackers have started targeting identity systems — the credentials and access controls that give administrators the keys to their infrastructure. Some attackers go even further and hit the backups too. So, when a disaster actually strikes, there’s nothing left to fall back on. Most companies only realise this after the attack.
As the concerns get real, boardrooms across industries are realising the gravity of a weak cybersecurity wall. And with laws like India’s DPDP Act now raising the stakes for how organisations collect, store and protect data, security is increasingly becoming a business continuity issue rather than just a compliance requirement.
To understand how enterprises can navigate high-stakes situations like this, Inc42 spoke with Ananth Nag, vice president (APAC) at Rubrik, who broke down the transition to an ‘assume-breach’ architecture, the risks of unchecked data sprawl, and why recovery speed is the ultimate metric for modern business continuity.
Here are the edited excerpts…
Inc42: What is the fundamental difference between standard data backup and true ‘cyber resilience’ that many business leaders do not realise?
Ananth Nag: Many organisations continue to view backup as the ultimate safety net, assuming that if something goes wrong, they can simply restore their data and resume operations.
However, that mindset no longer reflects the realities of today’s threat landscape. There is a significant difference between having a backup and having a recovery strategy that remains effective during a cyberattack.
Targeting of backup environments is on the rise. Rather than focusing solely on production systems, attackers now attempt to compromise backup infrastructure first, knowing that it represents the organisation’s last line of defence. Backups can be altered or deleted during an attack. Their existence alone does not guarantee recoverability if they have already been compromised.
Cyber resilience is now critical.
Effective resilience is not simply about creating copies of data; it is about being able to identify a clean, trusted recovery point and restore operations quickly, even while an attack is still unfolding
The focus today needs to move beyond backup as a storage exercise and towards ensuring that recovery capabilities are resilient, tested and capable of supporting the business when it matters most.
Inc42: As someone managing diverse markets, what macro risks do you see when organisations pull unmapped, highly sensitive data into live AI pipelines without established real-time data-intelligence guardrails?
Ananth Nag: The biggest risk occurs when organisations try to secure something they can’t see. Research from Rubrik Zero Labs found that 70% of APAC respondents lack full oversight of their AI agents, and 81% believe AI agents will outpace their existing security guardrails within 12 months. Eighty-one per cent is a genuinely uncomfortable statistic for a region that’s moving as fast on AI adoption as APAC is.
The macro pattern is straightforward: teams get excited about a Gen AI or agentic use case, connect it to whatever data store is closest, and only afterwards discover that the pipeline had access to unclassified PII (Personally Identifiable Information), financial records, or regulated health data.
Separate industry research on the region has found a similar gap. A large share of APAC organisations believe they know where their data lives, yet a significant minority still struggle to actually use it because of siloed access rules.
Confidence without control is exactly how sensitive data ends up in an AI model’s training or inference pipeline without anyone even realising it.
Without real-time data intelligence (automated discovery and classification that run continuously rather than as a point-in-time audit), organisations can’t answer basic governance questions, such as what sensitive data exists, who or what can reach it, and whether an AI pipeline is already touching it.
Rubrik’s own data security posture management approach exists specifically to close that gap by classifying data before it becomes an AI liability.
Inc42: With threat actors heavily targeting the identity layer, how should enterprise leaders redefine access control when administrative accounts themselves are compromised?
Ananth Nag: The old model of access control assumes the administrator is trustworthy, that once someone has the keys, they’re the good guy. Identity-based attacks break that assumption completely. Rubrik’s research points to identity compromise as the starting point for the overwhelming majority of serious intrusions into critical infrastructure, with attackers using stolen credentials to escalate privileges and move laterally rather than technical exploits.
The redefinition enterprise leaders need to make is to treat identity infrastructure as something that must be recoverable. This is the premise behind an ‘assume breach’ mindset. So the real question becomes: If a domain controller is compromised and its database is exfiltrated, can you quickly rebuild trust in Active Directory or Entra ID (cloud-based identity and access management service) from a verified clean state without relying on the very credentials that were just compromised?
Practically speaking, that means ensuring you have immutable, air-gapped backups of identity infrastructure that sit outside the domain’s trust boundary. Organisations must also combine this with continuous monitoring for high-impact changes, such as privilege escalations or unusual changes in group membership, so that misconfiguration drift is caught and rolled back before it’s exploited.
Access control, in other words, has to be paired with access recoverability. The ability to evict an attacker and reconstitute a trusted identity plane in hours rather than the weeks that manual recovery typically requires.
Inc42: As enterprises rapidly scale across multi-cloud and SaaS environments, why has data visibility become the ultimate blind spot for regional IT leaders?
Ananth Nag: One of the biggest challenges organisations face today is a lack of visibility into their data and technology environments. It is often a blind spot that reveals itself in unexpected ways.
In one engagement with an aviation customer, we helped map where sensitive data was actually residing across the organisation. During that process, we discovered personally identifiable information in test environments where it had no legitimate purpose. Nobody had deliberately introduced that risk. It had simply built up over time as systems evolved and teams expanded.
We encountered a similar situation with another customer. The initial assumption was that its technology estate was spread fairly evenly across on-premises infrastructure, Azure and GCP. However, a closer assessment revealed a very different picture. Nearly 80% of the airline’s operations were running on Azure, while only a relatively small portion was hosted on GCP.
What made that finding significant was that the smaller GCP environment was supporting the airline’s catering application. On the surface, that may not appear to be a business-critical system. Yet if the catering platform becomes unavailable and no recovery plan is in place, the disruption can directly impact flight operations. It is a reminder that the systems perceived as less important can sometimes play an outsized role in keeping the business running.
Visibility is about far more than simply knowing where data is stored. Organisations also need a clear understanding of which applications, workloads and services are critical to day-to-day operations, including those that may be overlooked until an outage exposes their importance.
Inc42: With the DPDP Act now in its phased enforcement window, how is it actually changing buying behaviour in the boardroom today, or is it still largely a compliance tick-box exercise?
Ananth Nag: It’s honestly somewhere in between right now, and the timeline explains why. India’s DPDP Act received presidential assent in 2023, but the operative rules were only notified in November 2025, with a phased rollout that pushes full enforcement out to May 2027 and penalties of up to 250 Cr for serious violations. That long runway has, understandably, led many organisations to treat it as a future problem rather than a present one.
The limited knowledge of DPDP is starting to shift. The Data Protection Board of India became operational in late 2025, the consent manager framework activates in November 2026, and the Act’s extraterritorial reach means multinational boards can’t simply wait it out. Boards are increasingly asking about breach-notification readiness (the Act requires reporting within 72 hours) and whether significant data fiduciaries can produce audit-ready evidence of security safeguards on demand.
The honest answer is that DPDP is moving from a compliance tick-box toward a genuine boardroom risk conversation, but it’s being pulled there by the approaching enforcement deadline rather than by early conviction. Organisations that wait for the deadline to force the issue will be doing rushed, reactive data mapping exactly when they can least afford to.
Inc42: How do you counter the ‘good enough’ security mindset in markets where organisations still view passive cyber insurance as a substitute for active data defence?
Ananth Nag: Cyber insurance is a financial backstop, not a recovery mechanism. It can help absorb the cost of an incident, but it doesn’t get your systems back online or stop the reputational damage of a prolonged outage. The ‘good enough’ mindset tends to persist because insurance feels like a completed task, while active data defence feels like an ongoing, never-finished obligation.
The industry itself is quietly correcting for this: underwriters increasingly require an immutable, air-gapped backup copy as a condition of coverage, precisely because insurers have learned that clean recovery capability is what actually limits their payout exposure.
There’s also a data point worth putting in front of a ‘good enough’ sceptic: attackers have adapted specifically to organisations that think insurance covers them. Ransomware groups increasingly steal data and threaten to leak it rather than just encrypt it, because that tactic still extracts a payment even from a victim who can restore from backup. In recent research, the majority of ransom payments were driven by exactly that leak threat, not by an inability to recover.
The most effective counter-argument, in practice, isn’t a fear-based pitch but showing leadership the gap between what a policy pays out and what it doesn’t cover: customer churn, regulatory fines under frameworks like DPDP, and the weeks of lost productivity insurance was never designed to prevent in the first place.
Inc42: When autonomous systems begin interacting with core enterprise data, how must data governance strategies evolve to mitigate automated errors or anomalies?
Ananth Nag: Governance built around static, rule-based policy simply can’t keep up with an agent that generates thousands of semantically unique interactions an hour. That’s the premise behind Rubrik’s shift toward semantic governance that expresses policy in plain language (for example, agents should not share financial advice) and toward having the system interpret intent rather than matching keywords, which is fragile and easy to circumvent.
The practical evolution has three parts:
- Discovery: You need an accurate, continuously updated inventory of which agents exist, what data and systems they can reach, and what their actual behaviour has been.
- Enforcement: Guardrails have to operate in real time, at the moment an agent takes an action, rather than as a post-hoc audit log that gets reviewed after the damage is done.
- Remediation: This is the part legacy governance frameworks miss entirely. When an agent makes a destructive or erroneous change, governance must include a fast, reliable way to undo it. Rubrik’s agent Rewind capability, automatically triggered by its governance engine, is designed to reverse an agent’s unintended action and restore data integrity.
The underlying principle is that governance for autonomous systems can’t be purely preventive anymore. It has to assume errors will happen and be engineered for fast, clean recovery when they do.
Inc42: As the security landscape moves toward both attackers and defenders adopting Al, how should APAC organisations reshape the role of human oversight in their long-term defence strategy?
Ananth Nag: The uncomfortable but necessary premise is that human-speed oversight can’t keep pace with machine-speed attacks and defences anymore. Rubrik’s GM for AI put it bluntly when discussing the company’s governance engine: “You actually need to use AI to help you secure and govern these agents.” Human reviewers simply can’t evaluate thousands of semantically unique agent interactions an hour in real time.
Frontier AI models are being used offensively: the emergence of models capable of finding and exploiting vulnerabilities autonomously is a wake-up call about the “data readiness gap” inside most organisations. Many companies have adopted AI tools faster than they’ve secured the data they rely on, creating an AI readiness illusion built on a shaky foundation.
This doesn’t mean humans get removed from the loop but their role moves up a level. Instead of manually reviewing every transaction or every agent action, security teams should focus on setting the intent behind policy, handling the ambiguous edge cases an AI governance layer flags for escalation, and owning the recovery decisions after an incident, deciding what “clean” looks like and when it’s safe to resume operations.
The organisations that get this balance right will be the ones treating recovery readiness. Clean, immutable, quickly restorable data as the constant underneath an otherwise fast-moving AI arms race, rather than trying to out-automate every attacker’s move in real time themselves.
Inc42: How has the CXO conversation shifted from managing IT infrastructure storage costs to calculating the exact financial impact of recovery times?
Ananth Nag: The conversation in the boardroom has changed significantly. A few years ago, discussions around data protection were largely focused on storage costs and the expense of maintaining backups. Today, the focus is much more strategic. Business leaders want to understand the real impact of downtime and what an hour, a day, or even a week of disruption could cost the organisation.
We saw this shift firsthand while working with an international airline. In that environment, even a relatively short outage can create substantial legal, financial and operational consequences. As a result, recovery time objectives (RTOs) are no longer viewed as purely technical metrics. They have become business priorities that directly influence risk management and operational resilience.
That is also why organisations need to test their recovery plans before a crisis occurs. Too often, businesses assume that having a documented recovery strategy is enough. The real question is whether teams can execute that plan effectively when they are under pressure.
Testing allows organisations to validate their ability to recover to a clean, trusted state and restore critical operations within the recovery timeframes they have committed to their boards, customers and stakeholders.
Inc42: Amid intense security team burnout and tool sprawl across APAC, how can vendor consolidation actively improve an enterprise’s defensive posture?
Ananth Nag: Tool sprawl is a well-documented driver of burnout, not just a budget inefficiency. Industry research from ISC2 found that two in five security professionals cite tool complexity as a leading cause of burnout, and separate analysis suggests organisations can waste 20-30% of their security budget on redundant or under-used tools.
Every disconnected tool also creates its own blind spot. When your backup platform, threat detection, identity monitoring, and compliance reporting don’t share context, an attacker can exploit the gaps between them.
Consolidation helps precisely because it collapses that fragmentation into shared context. Rubrik’s approach, which combines backup, threat analytics, identity security, and recovery orchestration in one place, is built on that logic, and customers have reported concrete savings: one large retailer cited more than $3 Mn in savings by consolidating multiple data protection systems into a single platform.
Broader industry research on consolidation reports meaningful efficiency gains for teams that move from a patchwork of point solutions to a unified platform.
The caveat worth giving any leadership team is that consolidation should follow a rationalisation exercise, not replace one. The goal is fewer, better-integrated tools that retain the coverage of what’s being retired, not consolidation for its own sake.
Inc42: What is the board-level understanding of the business impact of a catastrophic identity-related incident?
Ananth Nag: Over the last few years, identity has become one of the most important areas of discussion in boardrooms because it sits at the centre of how modern organisations operate. Employees, customers, partners, applications and cloud services all rely on digital identities to access business resources. If these identity systems are compromised, the consequences can extend well beyond the IT department and affect the entire organisation.
Today, boards understand that a catastrophic identity-related incident can disrupt business operations, delay customer services, interrupt employee productivity and create financial and regulatory challenges.
If attackers gain privileged access to identity systems, they can move through the environment, access sensitive information and make recovery significantly more difficult. In many ransomware incidents, compromising identity infrastructure is one of the first objectives because it gives attackers broad control over the organisation’s environment.
As a result, the conversation at the leadership level has evolved. Instead of focusing only on preventing attacks, boards are equally concerned with the organisation’s ability to recover.
They want to know whether the business can restore trusted identities, regain control of critical systems and resume normal operations without prolonged disruption. This reflects a broader shift toward cyber resilience, where preparedness, recovery, and continuity are considered just as important as prevention.
Ultimately, identity resilience is no longer viewed as a purely technical capability. It has become a business priority because it directly influences operational continuity, customer confidence, regulatory compliance and long-term organisational resilience.
Inc42: How does identity resilience capability support an overall business strategy and commitment to valued customers?
Ananth Nag: Identity resilience plays an important role in helping organisations deliver consistent and reliable services to their customers, even in the face of increasingly sophisticated cyber threats. Every digital interaction, whether it involves employees accessing internal systems or customers using online services, depends on trusted identities. Protecting and recovering these identities quickly is essential to keeping business operations running smoothly.
From a strategic perspective, identity resilience enables organisations to respond to cyber incidents with greater confidence. Rather than focusing solely on detecting threats, it ensures that critical identity systems can be restored quickly and accurately if compromised. This reduces operational downtime, supports business continuity and allows organisations to continue serving customers with minimal disruption.
For customers, trust is built not only on the quality of products and services but also on an organisation’s ability to protect their information and maintain reliable access to digital services. A strong identity-resilience strategy helps reinforce that trust by reducing the impact of cyber incidents and enabling faster recovery. It also supports compliance with evolving regulatory requirements and strengthens the organisation’s overall risk management framework.
As businesses continue to adopt cloud technologies, identity will remain the foundation of secure access. Investing in identity resilience allows organisations to pursue innovation and digital transformation while ensuring they have the ability to recover quickly when challenges arise.
In that sense, identity resilience is not simply a cybersecurity capability. It is a business enabler that supports long-term growth, operational stability, and lasting customer trust.
The post How Rubrik Is Rewriting The Rules Of Cyber Resilience appeared first on Inc42 Media.


Superadmin 










