In the Era of the Inevitable Breach, the Data Layer Matters Most

By Brandon Willitts, Director of Cyber Resilience at Everpure [ Join Cybersecurity Insiders ]
Caucasian female IT professional data

Every enterprise should now plan on being breached. The organizations that come through it are the ones that can recover quickly, and the capacity to recover is decided at the data layer long before any attack arrives.

For more than a decade, security spending has been built around a single promise: hold the perimeter, and the data stays safe. That promise no longer holds. Increasingly, attackers do not break in. They log in with stolen credentials and use the same administrative tools your teams rely on, reaching production data before an alarm sounds. When they succeed, most companies cannot make themselves whole again. Veeam’s 2026 Data Trust and Resilience report found that 72 percent never fully recover their data.

Assume the Breach

Prevention assumes you can keep everyone out. Build your entire defense on that assumption and you have no plan for the day it fails, because capable attackers are already getting in. The useful questions become concrete once you accept that: what can an attacker reach once inside, and how quickly can you restore what they touch?

Answering those questions means looking somewhere security has rarely been able to see. Security and infrastructure teams have long worked in parallel rather than together. Security operates against adversaries through threat hunting, detection engineering, and incident response. Infrastructure and storage teams monitor too, watching observability, application health, and availability. Their focus is uptime rather than an adversary, and they run on separate tooling and separate reporting lines. The data layer, where recovery ultimately happens, was never wired into security operations. Connecting the two is what makes recovery both fast and verifiable.

AI Exposes Existing Weakness

AI is accelerating both the discovery and the exploitation of weakness. Frontier models can now surface unknown vulnerabilities across major operating systems and browsers. Tooling that once required nation-state budgets costs a few dollars in tokens. More than half of security leaders name AI-powered attacks as their top concern. Breakout time, the window from first foothold to lateral movement, has fallen to roughly 29 minutes, about two-thirds faster than a year ago. Beyond what it has enabled for attackers, AI has not created new categories of risk. What it has done is expose the ones you already have, and expose them faster.

No chain of on-call humans keeps pace with that. The traditional response, a detection that escalates from person to person while the attacker keeps moving, was designed for a slower adversary. Response now has to be automated at the point of impact: isolate the incident the moment it appears, identify a clean recovery point, and keep services running while the investigation proceeds. People become more important in that model, not less. They belong on the loop, setting policy and exercising judgment, not standing in its critical path.

Recovery Is an Architecture Problem

The outcome of an attack is usually set before the first alert, determined by how the infrastructure was built. Verizon’s Data Breach Investigations Report attributes roughly one in four breaches to misconfiguration. The result, in other words, was decided by build choices no one revisited. The same attack can produce opposite outcomes inside a single company. This past March, one did. At a large enterprise, a single attack struck two sites on the same day, using the same technique against the same technology. Tens of thousands of endpoints and virtual clusters were deleted at both. One site was running again within minutes. The other went dark for days. The difference was architectural. At the site that recovered, immutable snapshots survived the wipe. The credentials needed to restore them lived on a separate control plane, one no compromised account could reach, even with global administrator rights.

Backups are a settled practice, kept for compliance, disaster recovery, and operational continuity. The sharper question, the one a leader should be able to answer without checking, is whether those backups hold up against a determined attacker. Do they stay immutable under a full compromise? Do they run on a control plane separate from production credentials? Can they restore operations inside a window the business can survive? Leaders who take this seriously place the data layer alongside endpoint detection, identity, and SIEM, as part of the active defense rather than passive storage.

Resilience Is a Business Investment

Vendors often market security through fear: more threats, more headlines, more budget. Fear fatigues executives, and the case for resilience does not need it. The stronger argument is economic, and it starts with downtime. A serious cyber event is a capital event. Companies that suffer one tend to underperform their peers for years, because customer trust erodes and does not return on a convenient schedule. Resilience protects what the business runs on: revenue, uptime, and the confidence of the people who depend on you.

Those people sit further downstream than most infrastructure conversations admit. Consider the nurse entering data so a child can be scanned tomorrow, or the owner of a small business processing a loan at the bank they have trusted for twenty years. When the systems behind them go dark, their trust does not break with the security or infrastructure vendor first. The hospital and the bank absorb it. When their trust goes, so does a customer’s business, and in time, yours.

None of this depends on a larger budget or a new tool. What it depends on is proof. Find whoever owns your recovery testing and read the plan. Bring your security team into a disaster recovery test, or your disaster recovery team into a security exercise. The gaps you find are your priority list. Most of them will not be technical. There will be gaps in operating model and discipline: capital allocated to the wrong places, manual work left un-automated. Those are fixable, and fixing them is what separates the organizations that recover from the ones that only planned to.

The best time to prove your recovery was before an attack. The second best time is today.

Join our LinkedIn group Information Security Community!

No posts to display