Storing more data is only useful if you can recover it

By Zander Brewis, Technical Alignment Manager at IPT

Businesses are producing and retaining more data every year, often across a growing mix of systems, cloud platforms, email environments, and shared repositories. That creates an obvious storage challenge, but storage capacity is only part of the problem.

Many organisations assume they are protected because data is being copied somewhere. That can create confidence without proof. A backup may have been configured years ago and left largely unattended, or a job may have stopped because the available storage filled up. The data may also be copied successfully without anyone ever testing whether it can be restored.

That is why I regard recovery testing as the real measure of a backup strategy. A backup that has never been restored remains unproven, regardless of how reassuring the reporting dashboard may look.

Storage should follow business priorities

As data volumes grow, organisations need to become more deliberate about what they protect and how quickly they need it back. Not every dataset carries the same operational consequence, and recovery planning should reflect that.

Every business should understand how much data it can afford to lose and how long it can continue without a critical system. These are business decisions because they affect service delivery, productivity, and the organisation’s ability to continue operating.

A business that backs up once a day accepts the possibility of losing many hours of work. More frequent protection reduces that exposure, although the right schedule will depend on how the organisation operates and what the data supports.

The same principle applies to downtime. Recovering a limited set of files may be relatively quick, while rebuilding a failed server can take much longer if the organisation has not prepared for it.

A recovery plan should therefore define what comes back first, who takes responsibility, and how people will continue working while systems are restored. It should also be tested often enough to confirm that the assumptions behind it remain realistic. Without this planning, backup becomes a technical activity disconnected from the outcome the business actually needs.

Protecting the copy that protects the business

Growing volumes of data also create a larger protection burden. Keeping one copy in one location is rarely enough, particularly when ransomware can reach both production systems and connected backups.

Attackers understand that a usable backup reduces the pressure to pay. They therefore look for backup systems and try to encrypt or destroy them as part of the same incident.

Separation is one of the strongest controls available. Businesses should keep multiple copies of critical data in more than one location, with at least one copy kept offline, immutable, or otherwise beyond the reach of someone who has compromised the live environment.

Access to backup systems also needs to be restricted. Strong authentication, limited privileges, and proper monitoring can reduce the chance that an attacker gains the same level of control over both production data and the systems intended to restore it.

Recovery testing remains important here too. A backup may appear protected until the organisation attempts to use it. Testing confirms whether the data is still usable and whether the people responsible for recovery can access it when required.

Using AI without losing discipline

AI can improve the way backup environments are monitored and reviewed, particularly as data volumes become harder for teams to assess manually.

It can help identify failed backup jobs, unusual behaviour, or changes in data volume that deserve attention. It can also support decision-making by highlighting where protection may need to be strengthened based on business impact or the sensitivity of the information involved.

Reporting can become more useful as well. Instead of simply confirming that a backup ran, AI-assisted analysis may help teams see whether recovery objectives are being met and where policy changes may be needed. None of this replaces the fundamentals. AI cannot compensate for poor separation, weak access controls, unclear recovery targets, or a restore process that has never been tested.

The value of stored data is ultimately determined by whether the business can retrieve it when disruption occurs. As volumes continue to grow, organisations need to move beyond asking whether they have enough storage and start proving that their backup and recovery arrangements can support the way the business operates.