Pontos principais
- Years of reasonable technology decisions can accumulate into operational complexity that makes resilience harder to manage, govern, test, and maintain.
- Fragmented tools, policies, workflows, and ownership can create inconsistent recovery models and make business-wide recovery difficult to predict.
- Unified data protection can help reduce operational friction by simplifying control and standardizing protection across increasingly diverse environments.
- Cyber resilience depends not only on safeguarding individual workloads but also on building security into recovery processes and continuously proving recovery readiness.
- As cloud, SaaS, edge, and AI environments expand faster than teams, simplifying resilience architecture becomes increasingly important for reliable, repeatable recovery.
One advantage of having spent part of my career on the operational side of backup and recovery is that I still can’t help looking at resilience through the eyes of the people who have to run it every day.
Years ago, the job was complicated, but it was generally clear. Most critical systems lived within a relatively defined set of boundaries. Protection strategies were comparatively standardized. Recovery planning focused on a known set of applications, databases, and infrastructure. The technology wasn’t simple, but the operating model was understandable.
Today, those boundaries have largely disappeared.
Business processes span SaaS applications, cloud-native services, multiple clouds, edge environments, AI initiatives, and traditional infrastructure. Different teams own different parts of the stack. New technologies arrive faster than old ones are retired. And every addition introduces new dependencies that may not become obvious until something breaks or needs to be recovered.
I recently joined Michael Thelander, Senior Director of Product Marketing at Commvault, for a webinar on how to address this very issue. You can watchUnified Data Protection as the Foundation for Resilience on demand now.
Why Data Protection Keeps Getting Harder
What’s interesting is that most organizations didn’t intentionally design this complexity into their resilience architecture. They accumulated it over time.
Cloud teams adopted native protection capabilities. Application owners implemented processes that made sense for the platforms they supported. Acquisitions brought inherited technologies and operating models. Business units optimized around their own requirements. Most of those decisions were reasonable and, in many cases, necessary. The challenge is that every one of those decisions carried a cost.
There’s the obvious cost of software, infrastructure, and storage. More significant, though, is the operational cost that accumulates quietly over the years. Every new protection method introduces another policy framework to manage, another workflow to document, another exception to troubleshoot, another recovery process to test, and another set of skills the organization must maintain.
Eventually, teams spend as much time managing the complexity surrounding resilience as they do improving resilience itself.
On its own, that might sound like an efficiency problem. But over time, it evolves into a resilience problem. The more moving parts an organization introduces, the harder it becomes to maintain consistency. Recovery procedures evolve differently across teams. Policies drift. Ownership fragments. Knowledge becomes concentrated in a handful of people who understand how everything fits together.
Eventually, the challenge stops being whether individual workloads can be protected and becomes whether the organization can consistently govern, test, and recover across everything it supports. Most organizations understand how individual systems recover. Far fewer can confidently explain how the business recovers.
Umrecent cyber resilience survey found that nearly half of organizations identify IT complexity as their biggest cyber resilience challenge. That finding isn’t particularly surprising. Most enterprises aren’t struggling because they lack protection technologies. In many cases, they have more protection technologies than ever before.
The challenge is understanding how all of those technologies come together when the organization actually needs them.
AI is making this reality even more visible. Models depend on training data, pipelines, infrastructure, repositories, identities, and services that often span multiple teams and environments. Protecting those individual components is one challenge. Recovering the ecosystem they collectively support is another.
That’s one reason Michael and I spent so much time discussing complexity.
On the surface, unified data protection sounds like a conversation about backup architecture. In reality, our discussion centered on a much broader challenge: how organizations reduce the operational burden created by years of accumulated complexity while creating a more consistent foundation for resilience.
Because the goal isn’t consolidation for consolidation’s sake. It’s all about reducing operational friction. Creating consistency where consistency matters. And making recovery more predictable, repeatable, and trustworthy.
From Fragmented Tools to a Unified Foundation
During the webinar, Michael and I explored four practical ways organizations can begin reducing complexity and strengthening resilience: simplifying control, standardizing protection, building cyber resilience directly into the recovery process, and continuously proving recovery readiness.
While the tactics differ, the objective is the same. The less effort organizations spend stitching together fragmented tools, policies, and workflows, the more confidence they can have in their ability to recover when it matters most.
What stayed with me long after the conversation ended was the recognition that resilience has become as much an operational and architectural challenge as a technical one. Organizations are being asked to support more applications, more clouds, more services, more data, and more AI initiatives than ever before. Yet few have the luxury of expanding teams at the same pace. That reality makes simplicity increasingly valuable.
If I were running backup and recovery operations today and I were re-evaluating my organization’s approach, I wouldn’t start by asking whether we have enough protection tools. I’d start by asking how much complexity we’re carrying and what it’s costing us. Because those costs extend far beyond software licenses and infrastructure. They’re reflected in operational effort, fragmented processes, inconsistent recovery models, and ultimately in an organization’s ability to recover when it matters most.
Perguntas frequentes
Q: Why has data protection become more complex for organizations?R:Business processes now span SaaS applications, cloud-native services, multiple clouds, edge environments, AI initiatives, and traditional infrastructure. As teams adopt different protection methods for these environments, organizations accumulate policies, workflows, skills, and dependencies that increase the operational burden of resilience.
Q: How can technology complexity affect cyber resilience?R:More tools and processes can make it harder to maintain consistent policies, ownership, testing, and recovery procedures across an organization. Over time, this fragmentation can turn what initially appears to be an efficiency challenge into a resilience challenge.
Q: What is unified data protection intended to accomplish?R:Unified data protection is about more than consolidating backup technologies. Its broader purpose is to reduce operational friction, create consistency where it matters, and make recovery more predictable, repeatable, and trustworthy.
Q: What practical steps can organizations take to reduce resilience complexity?R:Organizations can focus on simplifying control, standardizing protection, building cyber resilience directly into recovery processes, and continuously proving recovery readiness. Together, these practices can reduce the effort required to coordinate fragmented tools, policies, and workflows.
Q: Why does AI make resilience complexity more visible?R:AI initiatives can depend on interconnected training data, pipelines, infrastructure, repositories, identities, and services spanning multiple teams and environments. Protecting each component individually does not necessarily address the larger challenge of recovering the complete ecosystem those components support.
Q: What should organizations consider when reevaluating their data protection strategy?R: Rather than starting with whether they have enough protection tools, organizations should examine how much operational complexity they are carrying and what it costs them. That includes the impact of fragmented processes, inconsistent recovery models, administrative effort, and the organization’s overall ability to recover when it matters most.
Jason Gizais Senior Manager, Partner Solutions Marketing, at Commvault.


