Transcript
Today I'm going to present on the current state of cloud resiliency, a topic which more often keeps the CIOs and CISOs awake at night, right? And this is very important because we are in the middle of, I would say, a perfect storm where we are seeing AI technology scaling at a very fast pace, your IT infrastructure is getting more and more distributed and complex, and unfortunately, cyber attacks are becoming more and more sophisticated and growing, evolving at machine intelligence, machine speed. So let's deep dive into this topic. I'll bring a perspective, a market perspective of some of the challenges that we hear from the organizations, the gaps in the solutions, what we hear on cyber resiliency, and also what should be the way forward for you to build a robust cyber resiliency process in the AI era. But before that, I would like to take you through some of the market growth and developments on the infrastructure. India is doing a lot, it is betting big on digital transformation, and we understand that the total IT spending in 2026 is going to grow steadily compared to 2025. And there are set technology priorities now, what we hear, cloud still remains the number one priority, sovereign cloud spending is going to grow this year, what we hear, because of your compliance, security and regulations reason, re-architecting legacy on public cloud still remains one of the top priorities. But we definitely see one interesting fact, your cyber resiliency and recovery has become one of the top three priorities now, because organizations now understand that resiliency in the multi-cloud environment is becoming more and more complex. Your edge data centers will become more and more common now with as more and more AI inferencing workloads which are coming in place. And of course, now the agentic AI solutions, which are actually gaining more and more adoption in the production stage. Let's deep dive into what we see, how AI is driving the public cloud adoption. So, the left side chart talks about the degree of adoption of public cloud today in India, almost 78 to 80% enterprises, they run production applications on public cloud, and 85 to 90% organizations are multi-public cloud, an average of two to three hyperscalers, what we hear in India. AI spending, we are very robust, very optimistic, IDC estimates the growth in AI spending to touch almost 17 billion plus by 2029, almost 5x from 2024. And the right side chart gives you the degree of agentic AI implementation or adoption now, 40% enterprises are already significantly invested in agentic AI, another 40% they say they are doing proof of concepts. The table below is interesting numbers, that's the average number of agentic AI solutions per organization in India in 2024, 11. It's going to grow to 19, average 19 agentic AI solutions by 2026, this year. The global averages are 19 and 36. So the scale of AI and cloud adoption is getting more and more complex and very fast. And what I essentially understand is enterprises are largely going hybrid multi-cloud, multiple public cloud providers, you have legacy infrastructure, you have got edge, you have got co-location data centers. Now, when we talk to enterprises, last year we spoke to close to a thousand enterprises globally asking me about their key challenges on hybrid multi-cloud environment, here is what we hear. So scaling your infrastructure and AI is definitely there, everyone wants to raise fast. But next to that, what we hear essentially, the challenges are around your observability monitoring, which is getting more and more difficult on hybrid multi-cloud. Your interoperability, basically enabling your hybrid multi-cloud management and also re-architecting security, which is becoming a bigger and bigger challenge and concern for the CIOs and CISOs. Now, what are the data security challenges? You need to manage two to three, at least multiple public cloud platforms, and you struggle to maintain consistent security and resiliency posters. And what happens is that in this case, you have been adopting native resiliency or security tools on different public cloud platforms. Now this fragmented approach may not apply, it was good in the past for your legacy infrastructure, but it may not apply very much in a multi-public cloud scenario. And on top of that, observability, as I mentioned, becomes all the more difficult in a multi-public cloud scenario. So what we understand is, I think some of the points to consider in this hybrid multi-cloud architecture is that you need to have a centralized view of not only your cyber threats, how you are infected, but also on your overall recovery process. So a unified approach to your cyber resiliency is required. Now this is not only in the case of applications, we see the same case in data. So your legacy structured databases were on-premise, but today they are across the four deployment locations. The chart gives you where all the most common structured and unstructured databases reside today. It's on on-prem VMs, public cloud, co-location data center, and we are slowly seeing the growth on on-premise private cloud as well. So my point to you is, your attack surfaces increase today. Your data sits across all the four deployment locations. Now you largely use unstructured data to train your AI models, right? But you also have to ingest data from your structured databases to train your AI models. So it increases your attack surface. The questions you need to ask today, are you feeding clean data to your agentic AI solutions or not? Or your AI models or not? Second, your data classification will be a bigger challenge because your data is constantly changing, right? Data is flowing across your different IT environments. So are you up to date on your data classification in terms of what is most critical data, less critical data? So that is something we need to plan for. And the same audience spoke about what are the challenges, overall operational challenges of building their agentic AI solutions in their environment. Dealing on the AI infrastructure is obviously the first challenge because it refers to basically how much the system can take the load or not. But you see, interesting, the second and third challenge, it's largely around security, privacy and data quality. Again the question, whether are you feeding clean data to your AI models or not? Because your data is infected or inevitably you are corrupting your AI models as well. Cost management and predictability could be a growing concern, given the fact if enterprises are using fragmented tools. So you might be doing excellent due to security features on one public cloud platform, but the security features on other public cloud may not be enough. So a fragmented approach often leads to using different tools to replicate or restore data on different platforms. It might lead to cost overruns also. That we have to be mindful of. So what does it mean? Why am I discussing a lot about hybrid multi-cloud challenges? What we really see is that your IT infrastructure has become much distributed, more complex and that opens multiple points of vulnerability. And the result is on the right side, in red. Globally last year, in the last 12 months, 69% enterprises faced at least one ransomware attack. The number was even high, close to 84 to 85% in India. And there is no single point of failure. Enterprises have mentioned as multiple areas through which they are facing attacks. In India, it is largest edge devices followed by public cloud. They are corrupting your enterprise storage system, which is essentially your backup data. And then the active directory. So the essence is that you need to manage a lot of resources across your core edge, your public cloud platforms, and their approach to cyber resiliency has to change today. So let me ask you one question here. Are you 100% confident on recovering your systems clean and on time as for your business is less? And you should be answering this question to yourself. We asked this question to a set of audience last year as part of study. And here is what we understand from what we heard from them. There is a significant gap between what enterprises perceive they can do and what actually they did in the event of a cyber attack. So the left side chart tells you about the confidence level of recovering from all kinds of attacks. 39% enterprises said they are 100% confident in recovering. Great. But there was another 40 to 45% enterprises, they mentioned about a high confidence level of recovering from cyber attacks. But the research actually showed the low levels of actual recoverability, recovering capability. Only 17% could completely recover and on time, you know, you need to recover clean, but you also need to, you also need to recover on time, right? You don't, you cannot afford to have a three to four or five days of gap between recovering a minimum viable operations. So what we hear is only 17% enterprises have recovered completely. Interestingly, in India, less than 20% enterprises, they test their cyber resiliency solution. The level of confidence falls significantly when the attacks are AI powered because a lot of organizations have not introduced AI features on their cyber resiliency processes. Now there are both operational and technical gaps because of which this is happening. Let's look at the operational gaps now. Now one of the top reasons, one of the top operational gaps that we hear is keeping updated on the cyber recovery processes. Now your infrastructure is changing, right? You're adding virtual machines, new databases, new tools. How do you keep updated to that? Second is your integration among different resources, different security products or solutions. You may be using best of breed solutions on security, but if they don't talk to each other, that's a real challenge, right? Keeping abreast on threat landscape. This is very important and in my latest slides, you will see AI will help a lot in this case. Your threats are evolving. AI is today used for creating new synthetic malware as well. So you need to understand your threat landscape, what are the different types of threats which could attack you. Cyber recovery, a moving target, which means essentially what was working last year, maybe in the past, may not work today. And of course, there are coordination between RTOps, SecOps, which is possibly the first step of your cyber recovery when you form a cross-functional team. Process automation is at the bottom of the chart, but I believe there's a lot to happen here. Imagine a situation when you have to recover a thousand virtual machines in a limited span of time. How do you do using only manual steps on time, right? So we need to automate a lot of processes on that. So these are operational gaps and there are technology gaps, which have split under security, identity, and recovery. And we see a multiple different number of gaps in terms of technology. Essentially what I understand is that a lot of organizations are using legacy and old tools, and these tools may not work in today's cloud environment. On a data backup side, a third of enterprises, they're not able to figure out which is the last clean copy. Lack of immutable backups, which means your backups can be changed, right? And air gap backups. They don't sufficiently air gap their backups. On identity, I think we expect a lot more investments to come. 37% enterprises, they do not have any investment on identity, or even they have enterprises, they are using largely legacy identity access management tools. On the recovery side also, there's a very common problem, 35% enterprise, what you see in the slide, using DRSCR, which is not the right approach today. DR admits or assumes that your data is integral, it is clean, but actually your backups could be infected, right? So cyber recovery set process should be implemented. And cleanroom, what Balaji also earlier mentioned about cleanroom, we also see a similar trend. A lot of organizations may not be investing on cleanrooms or spend heavily on legacy cleanroom solutions on-premise, which you may not be using in the event of no attack. So a cleanroom solution on cloud largely helps to cut down on your cost and scale as per the requirement. Now, these are the operational gaps. And we see the markets, while there are gaps, we see the market is changing as well now. Market is responding to these gaps now. Cyber resiliency and recovery are among the top three overall security spending now. The top one is cloud native application protection. Interestingly, a lot more organizations are spending on CNAP solutions because more and more virtual machines and now most of the AI solution services are on the public cloud today. And this chart talks about largely what is the spending forecast, how the market is going to spend. We have pulled out three key areas of cyber resiliency spending. One is the identity access management, where I believe there's a lot of gap today and enterprises really need to focus on that. We expect 19% CADR growth in the spending, followed by forensics and information and data security software. If you combine the spending, all these three areas, it's expected to cross $1 billion plus in India by 2029, whereas overall IT security spending by 2029 is expected to be around $6.5 to $7 billion. These three areas will be only $1 billion spending by 2029. So you need to respond and you need to plan accordingly. My last part of the presentation will talk about AI and cyber resiliency. So AI can definitely enhance cyber resiliency and AI can impact as well. They can create cyber threats also. How do you use AI to your defense? How do you use AI to beat AI? And I'll have some slides on some key points as guidance points, which you can take from there. Now, what we see in the market is a clear trend. When we talk to CIOs, we do our structured surveys, interviews as part of our market research. We see a clear trend where a lot of organizations are now pushing towards a more unified approach, bringing your identity, security, and recovery in one platform. What I essentially mean is a centralized platform, which will give you a centralized view of what are the different types of threats which you may encounter? What are the different assets, basically, in terms of virtual machines, data? What is protected? What is not protected? And a platform which can essentially orchestrate or curate your recovery steps, one. These unified approach and unified platform, which will go further and connect with your third-party tools like your cyber security resiliency, posture management, your collaboration tools, and other security services. What we recommend is on the right side. So this is a time I think enterprises should come out from legacy resiliency and recovery tools and invest into cloud-based tools. And cloud-based tools essentially means immutable backups, air gap backups, cloud-based replication solution, encryption, and clean room. Clean room is very important. You don't have to invest in a legacy clean room solution, which you may not be using for a quite longer period of time. You spin up resources for clean room solutions, for example, when you only need it. One of the benefits about cloud-based solution is that they can scale and they can remain updated. Second is unified approach. It's not only about... So when I suggest about unified approach, bringing the three pillars together, it's not only about efficiency, it is about effectiveness also. How well you curate, how clean you can recover, and how fast you can recover as well. Use distributed data environments. Your data classification is very important. As your data will change very fast when you adopt agentic AI solutions, you need to be updated on what is most critical data, what is critical, most important, how your data is flowing, accessed, everything, your data fabric, data security and security policies, access policies. So invest in that area. And lastly, bring AI to transform your cyber recovery. This chart talks about how AI is impacting. Interestingly, we asked around more than 500 organizations across HAP, APAC region, and this is what we hear. The different types of challenge or different types of AI-driven attacks. The top one, almost 72% enterprises, they say AI enhance phishing or impersonation, which essentially means deepfakes. Imagine you get a video call or audio call from one of your colleagues or your CFO asking for confidential information, right? It seems like the person, the person is the CFO, but actually it is AI. So it's quite dangerous, right? Second is AI-powered ransomware with real-time negotiations. So the AI agent, the fake agent will negotiate with you and it will adapt based on your responses. And that is, and it will negotiate with you on the ransom. AI prompt injection, basically it refers to model poisoning. Synthetic malware creation, which is also getting very common. Synthetic malwares, which can actually evolve very fast, faster than your current defense systems. Your model poisoning or adversarial inputs, essentially, which means if your data is corrupt, you're feeding, but your data you're feeding to train your models is corrupt, you're basically corrupting your AI models. And lastly, this is equally dangerous, only 53%, 53% enterprises say synthetic identity creation. Essentially, they are creating fake identities, which will pass your verification easily. So this is what we talk about, how AI is attacking you. And this slide is where the market is investing and where you should invest, the essential guidance for you. The same set of organizations where we talked about how they are leveraging AI, we see a lot of enterprises using AI for recovery point optimization. That's the first place, which is essentially picking the right last clean copy. So you have multiple data sets, multiple different applications, and you may have the last clean copy at a different point of time. So it is very challenging to find out the last clean copy among a set of 100 clean copies. So AI can largely help you in finding the last clean copy and help you in recovering that. So that's the first area I think enterprises should consider introducing AI for recovery point optimization. Resiliency and data posture management, AI can greatly help. I have a slide next to this, which will talk about how AI can enhance your data classification in terms of your data is changing. So you have to constantly define and be up to date on what is most critical data, which is less critical, less important, what needs to be recovered first as part of the MVC and what can be recovered later. And also on how data flows across the IT environment. All these manual steps can be automated using AI. Recovery orchestration, this essentially means you are automating the manual steps of cyber recovery. Imagine you need to recover 1000 virtual machines in a specific period of time. How do you do it? Can you do it at machine speed using manual steps? Probably not in a multi-cloud environment. So I think AI will largely help in this area. Threat analysis, which is essentially scanning through your IT states, your virtual machines, your data, and figure out what is subtle anomalies in that. And your forensics, essentially investigate what is the threat, already the cyber attack happens, extent of an attack. So that's the last slide talk, essentially how you can leverage AI to improve cyber resiliency. My last slide today talks about how you can architect AI into data fabric. So data fabric is the first step. It essentially refers to your knowledge about your entire data state, how your data flows, how your data is stored, processed, your critical data. Data protection learns from data fabric in terms of how you protect your data, what data set policies, and data security is basically you are curating all the data security processes. So AI definitely sits in the middle of all this. You should today consider implementing AI, which will help you study your data patterns. Find subtle changes, anomalies in this, keeping your data classification up to date, and help you automate a lot of manual steps in recovery. So basically send an alert, whether it detects a potential data threat, cyber threat, sorry. So lastly, I would end my presentation saying that your IT enterprise, your hybrid multi-cloud architecture is making your management operations, your cyber resiliency very complicated. Are you prepared today or not? So invest in cloud-based solutions today for a better robust resiliency solution. Second, bring AI. This is the time where the market is spending, and if you do not do that, you will be left behind. Invest into AI solutions on your cyber resiliency and set robust processes and automate them using AI. Thank you very much for your time.