Book demo
27 August 2026

Nation-state hackers are really vibing now!

We’ve all heard that hackers are using AI. That’s not news anymore. But when the latest research from Trend Micro landed in our inbox we took notice – because the report gives us the clearest picture yet of exactly how they are using it.

From vibe-coded attacks, to fully agentic reconnaissance, it’s clear that bad actors are really getting into the grove with AI. The insights are fascinating and worrying in equal measures.

The research

The APT Activity Roundup is published twice a year by Trend AI, the threat intelligence arm of Trend Micro. The latest report is based on intelligence from January to June this year. It’s not a prediction piece or a marketing trend report. Its insights are built on six months of tracked, real-world incidents pulled from Trend Micro’s global detection footprint.

While the report focuses specifically on organisations associated with nation-state backed cybercrime, the findings have implications for every business that depends on data.

Why it matters

It’s easy to be dismissive of stories about nation-state cyber attacks. It sounds like a government problem, or a defence one. The reality is that nation-state backed cybercrime isn’t all about espionage and intelligence.

Financial services, critical infrastructure, major technology vendors and the software supply chain are common targets, not collateral damage. A bank gets hit because it directly funds a sanctioned regime. A major software company gets exploited because it’s the fastest route to mass disruption. Any business can be a target for a ransomware attack to fund a foreign power.

No organisation is truly safe from nation-state hackers.

The second reason to take notice is that well-funded, state-backed bad actors are the pioneers for the cybercrime industry. Evidence shows that the innovative methods being used here will become common tactics used by hackers more broadly in 12-24 months.

Key findings

1. An AI agent ran its own attack, unsupervised.

In one documented case, an AI agent was set a goal before carrying out extensive reconnaissance and lateral movement inside a target’s network without further human direction. That’s a meaningful shift from AI as a tool an attacker uses, to AI as the thing actively running the intrusion, capable of progressing an attack even when nobody’s watching.

2. Nation-state hackers are vibe coding their exploits.
China-aligned groups built and refined exploit code by prompting an AI conversationally, iterating until it worked, rather than writing it by hand. It’s the same workflow legitimate developers now use to ship products fast. The barrier to building a working exploit just dropped, and it no longer requires deep technical skill to clear it.

3. Attackers don’t even need malware to track you anymore.
ADINT exploits the real-time bidding auctions that power online ad delivery, harvesting the location and device data those auctions carry, for surveillance, without ever installing anything on a target’s device. No file, no payload, nothing for endpoint security to catch, because nothing was ever planted.

4. Attack infrastructure is hiding in plain sight.
Command-and-control is increasingly routed through infrastructure that users already trust and can’t easily block: mainstream cloud platforms, developer tunnelling services, even blockchain transactions. It blends into legitimate traffic by riding on the same rails as legitimate traffic.


Read the full report:
The TrendAI H1 2026 APT Activity Roundup is available to download for free from the Trend Micro website.

Read it here


Trend Micro and Predatar

Having spent more than three decades tracking nation-state activity, Trend Micro remains one of the most trusted and frequently cited sources in the industry for cyber intelligence. That’s why Predatar has chosen TrendMicro as it Threat Intelligence Partner.

Visit predatar.com to learn more about how Predatar’s unique Recovery Assurance technology is helping organisations around the world protect themselves from the impacts of increasingly sophisticated attacks and giving them confidence in their ability to execute a fast and effective recovery.

Learn more about
Predatar recovery assurance

06 August 2026

Recovery You Can Bank On – Why Financial Institutions Across Latin America are Turning to Predatar.

Banks and financial services organisations across Latin America are choosing Predatar to strengthen operational resilience, prove recoverability and respond to increasingly demanding regulations. Behind much of this momentum is Nicolas Perez de Arenaza — LATAM’s leading Recovery Assurance expert.

For banks and insurers, data is everything!

Every payment, balance, policy and customer interaction depends on data. If critical systems become unavailable, operations grind to a halt. That makes recovery more than an infrastructure concern. It is a board-level, regulatory and operational resilience priority.

It is also why some of the largest and longest-established financial institutions across Argentina, Colombia, Paraguay, and Mexico have chosen to invest in Predatar this year. These organisations are not implementing Recovery Assurance technology because it is fashionable. They need proof that they can recover when it matters.

Meet a Recovery Assurance trailblazer

Based in Buenos Aires, Founder & CEO at GIUX, Nicolas Perez de Arenaza has established himself as Latin America’s leading Recovery Assurance expert.

We first met Nicolas three years ago, when he flew more than 7,000 miles to join one of Predatar’s very first hands-on technical training workshops in the UK.

Nicolas built his Recovery Assurance Cleanroom, collected his certificate, and then jumped on a motorcycle to explore some of Scotland’s most spectacular landscapes. We knew immediately that we would get along.

That adventurous spirit has shaped Nicolas’s approach to building the Recovery Assurance market. He knew that the infrastructure and cyber security markets were shifting towards a focus on resilience, but he didn’t wait for customers to begin asking for Predatar. He travelled across Argentina, Colombia, Ecuador, Perú and Paraguay, and built relationships remotely in Mexico and beyond – sharing knowledge along the way.

“I spread the word about Predatar in many countries,” Nicolas explains. “GIUX acts as a beacon: we share knowledge, let people know that we can help them move forward with this approach, and show them how to find us when they need help or advice.”

It’s not just financial institutions that have benefited from Nicolas’ expertise. He’s actively speaking with IT, security, and operational resilience leaders across many industry sectors. He has also become the go-to Recovery Assurance expert for other technology businesses in the region – including resellers and service providers.

Nicolas is always keen to point out that his successes are always part of a team effort. In most cases Nicolas and the team at GIUX are providing consultancy and technical services to end customers, working hand-in-hand with the local IBM ecosystem of IBM reps and business partners on each country to provide an exceptional end-to-end customer experience.

Why financial services?

While almost any modern business will benefit from Recovery Assurance technology, the momentum that is building in financial institutions specifically is no coincidence.

The reality is that the financial services sector already has some of the most robust resilience and continuity capabilities in place. But they also carry the biggest risks.

Nicolas explains, “These are the organisations most dependent on the continuity of IT. Banks and insurers face enormous potential costs from downtime. They are also accountable to the board, their customers, the markets – and of course – regulators.”

Supporting regulatory compliance

Financial services regulations around the world are already among the most stringent of any sector, and many are now demanding that institutions must demonstrate their resilience rather than simply document it.

What this means in practice is that recovery plans must be tested comprehensively and regularly. Recovery guarantees and Service Level Agreements (SLAs) from IT vendors must actually be validated. Organisations must demonstrate they can actually meet the targets they set around impact tolerances and Recovery Time Objectives (RTOs).

This is where Predatar delivers real value. By putting AI and automation to work, Predatar continually checks that the data that runs its customers’ most important systems and services is always recoverable and clean – every single day. Putting Predatar to work gives you the certainty that whenever needed, you will be able to recover rapidly, completely and free of malware.

Not only does this provide peace of mind, Predatar provides the evidence of resilience that many regulators now expect.

Getting started with Recovery Assurance

Can your organisation recover the data, systems and digital services it relies on quickly, cleanly and completely? All too often businesses find themselves trying to answer these high-stakes questions for the first time in the middle of a crisis.

That’s why any organisation – whether it’s in the financial services sector or not – can benefit from continuous Recovery Assurance. Download our Recovery Assurance Buyer’s Guide to learn more about this emerging technology market, or find a ‘beacon of knowledge’ in your region by visiting Predatar’s APEX Partner finder.

Predatar works with leading enterprise storage and backup solutions and can even be used to validate recoverability across complex multi-vendor infrastructure environments – making it a perfect fit for many large organisations including banks and other financial services institutions.

Learn more about
Predatar recovery assurance

22 July 2026

Cyber Attacks Don’t Kill Businesses. Slow Recoveries Do.

Most large organisations are terrified of being hit by a cyber attack. The headlines are all too familiar… “Company X hit by ransomware attack.”

The attack sounds like the disaster. It isn’t.

The disaster is what happens next – the 24 days offline. The restore that fails again and again. The backup that was “successful” every single night for a year and still won’t come back clean. Attacks are a single, dramatic event. Recovery is where businesses actually die, slowly, in front of their customers, their staff, and the board.

If you want to know whether your organisation will survive a cyber-attack, you need to start asking one question: Do you know for certain that you can get your critical systems back?

The numbers should scare you more than the attack does

  • Ransomware attacks rose 50% in 2025, hitting nearly 7,900 publicly claimed incidents – and 2026 is running over 30% hotter still.
  • The average ransomware incident now costs $5.08 million once downtime, remediation and lost business are taken into account.
  • Enterprise downtime runs at roughly $300,000 per hour. For mid-market businesses, it’s still $50,000 – $100,000 an hour. That’s not a bad quarter – that’s a business unravelling in real time.
  • Only 53% of organisations fully recovered within a week in 2025. Read that the other way round: nearly half of all businesses hit are still not operational seven days later.

Here’s the one that should really keep you up at night: Predatar has found previously undetected malware inside the backups of more than 90% of its customers – organisations that, in most cases, already had best-in-class security stacks. Not gaps in defence. Gaps in the thing everyone assumed would save them.



The lie of the green tick

For too long, the entire backup industry has run on an assumption that nobody ever stress-tests: if the backup job reports success, recovery will work too.

The reality is that a backup platform can report a clean green tick every night for a year and still fail you on the one day it matters. Restore jobs stall halfway through. Recovery performance collapses under load. Authentication breaks. Application dependencies don’t hold. RTOs that looked good in a slide deck turn into days, or weeks, once you’re actually trying to bring a production estate back from nothing.

Under normal conditions, roughly 8% of backups fail to recover. During an actual cyberattack – with corrupted volumes, dormant malware, and infrastructure under strain – that failure rate can explode ten-fold, to as high as 84%.

That gap between what businesses assume they can recover and what they can actually recover has a name: the Recovery Gap. Most organisations don’t know theirs exists until the worst possible moment reveals it – when production is already down and the safety net is full of holes.

Your SLA is not a recovery plan

Somewhere in a contract, there’s a number: an RTO of 4 hours, an RPO of 15 minutes, a vendor SLA with financial penalties attached if it’s missed. It feels like protection. It isn’t proof of anything.

An SLA is a promise. A guarantee is a sentence in a document. Neither one has ever actually restored a single terabyte of data at 2am while your board is asking for hourly updates and your customers are finding out on social media. SLAs describe what’s supposed to happen. They say nothing about whether it will.

The businesses that go dark for weeks after an attack almost always had a DR plan. Almost always had backups. Almost always had an SLA. What they didn’t have was evidence – tested, current, repeated evidence – that any of it actually worked under real conditions.

Confidence isn’t a feeling. It’s a test result.

There’s a reason ransomware payments fell 35% year-on-year even as attacks kept climbing: more organisations are refusing to pay. Not because they’re braver. Because they’ve actually tested their recovery and know it holds up. When you can prove you’ll get your systems back without the attacker’s help, their entire leverage disappears.

That’s the shift that matters here. Stop asking “do we have backups?” That question was solved a decade ago and it was never the right one. Start asking: “Have we proven – recently, repeatedly, under realistic conditions – that we can recover, that recovery lands inside our RTOs, and that what comes back isn’t still infected?”

Hoping your recovery plan works is not a strategy. It’s a bet on the worst day of your business’s life, placed on evidence you’ve never actually checked.

Backups you haven’t tested aren’t a safety net. They’re an assumption wearing a safety net’s clothing. The businesses that walk away from an attack aren’t the ones with the best-worded SLA – they’re the ones who already knew, beyond doubt, exactly how fast and how clean their recovery would be, because they’d proven it before the attackers ever showed up.

It’s time to get recovery confident!

Don’t find out which one you are during an incident. Find out now.

Discover Recovery Assurance from Predatar

Learn more about
Predatar recovery assurance

07 July 2026

Escape from Complexity. Get to Resilience Faster.

The latest Predatar release, R18.3, has been designed to help customers avoid the most common pitfalls of CleanRoom setup, so they can achieve recovery confidence sooner.


At Predatar, we operate in a world of complexity. Enterprise IT and infrastructure are a jungle of legacy systems, siloed tools, hidden dependencies, detailed information security policies and ever-changing regulations. Taking this complexity away for our customers is one of the most important drivers for our R&D team.

You want certainty that your organisation can recover its critical systems quickly and safely when you need to – without having to manage all the complexity that underpins that assurance.

With a focus on deployment and setup, the latest Predatar release R18.3 takes even more of that complexity away. The result? Predatar customers can get to ‘live’ faster – which means they can achieve recovery confidence sooner.

Building on CleanRoom 3

Back in 2024 Predatar launched CleanRoom 3. Our third generation Recovery Assurance CleanRoom significantly simplified the deployment process and shortened the time required to get a Predatar CleanRoom up and running from several days down to just a few hours.

It was – and still is – an impressive piece of engineering. Our CleanRoom remains the most advanced Recovery Assurance CleanRoom available today. And while our own engineers can – and regularly do – deploy CleanRooms before unpacking their lunch – we found the reality in the field was often different.

Customer installations would sometimes hit bottlenecks. The time-to-value would get extended, and it would take longer than expected for customers to achieve the resilience they needed.

R18.3 tackles three common obstacles that have been slowing down deployments.

Obstacle 1: The Security Checkpoint

A CleanRoom needs controlled outbound access to be built, stay current, and stay protected. Until now, this required a dynamic list of shifting destinations sitting behind CDNs and rotating IPs. It’s the kind of moving target that tends to prompt scrutiny from security teams – and rightly so – but all too often reviews would stall. The deployment would stop – for days – sometimes weeks.

R18.3 fixes this. The new Easy Networking process now connects your CleanRoom via a short, clearly documented set of fixed destinations. Security teams get something they can easily understand, review, and approve.

The security checkpoint stops being the delay.

Obstacle 2: Hidden Errors

CleanRoom installation used to run in one continuous automated workflow. You would enter your networking configuration details and the setup requirements up front, the build would begin, then let you know when it was done. Sounds easy, right?

The delay would come if there was an error in the details that were entered. Something as simple as a single digit typo would cause a deployment to fail, and it wasn’t always easy to work out where the error was.

R18.3 includes a new Admin Console, which guides you through the install, validating each stage as it happens. If something’s off, it’s flagged immediately.

Obstacle 3: Wasted Cycles

There’s another time-saving benefit of splitting the installation into a step-by-step process. Before R18.3, even once an issue had been identified and fixed, the whole install cycle would need to be started again. Not only was this time-consuming, but engineers told us that this could be pretty frustrating – and even more so if another error was found the next time around. Every small configuration mistake would cost a full cycle.

With R18.3 issues can be fixed along the way and the build carries on from that point. If the process is interrupted, it simply resumes where it left off.

The point: less friction, faster resilience

At Predatar we will never stop looking for ways to make our Recovery Assurance technology better. R18.3 is proof of our commitment to continuous improvement. Today Predatar is easier and faster to deploy than it was yesterday. That means customers achieve the resilience they need faster – and get value out of their investment sooner.

Get started with Predatar

Start your journey to recovery confidence. Contact us to a talk with member of the friendly and knowledgeable Predatar team, or book a demo to see R18.3 in action.

Learn more about
Predatar recovery assurance

24 June 2026

The rise of ResOps

A new term is taking hold in medium and large enterprises – ResOps, short for Resilience Operations. We didn’t come up with it, but we wish we had – because it’s one of those concepts that just makes sense.

ResOps describes a shift that has been happening for a few years now. Resilience is moving from something you plan, to something that is an integral part of how an organisation runs – every day. In the same way that DevOps shifted software releases from big, periodic, high-stakes events into a flow of incremental pushes delivering continuous improvements, ResOps is set to be a game-changer for the way businesses approach Disaster Recovery (DR) and Business Continuity Planning (BCP).

The idea is sound, and it matters. But most of what has been written about ResOps so far stops at the strategy. It tells you resilience should be a continuous operating model, a board-level priority, a culture that breaks down silos between IT, security, and the business. All true. But, none of it tells you how you actually start to make the move to continuous resilience. How can you begin to test your ability to recover – every day, and actually prove it works.

That operational layer is where ResOps either works or quietly fails. It is also where Predatar has been building for years.

What ResOps actually means

Strip away the vendor framing and ResOps comes down to a simple proposition. Disruption is no longer an exceptional event to be planned for. It is a normal operating condition to be managed. Ransomware, outages, cloud complexity, and now AI agents acting on your data at machine speed mean that something will go wrong, and the question that matters is not whether you have a plan, but whether your critical services can keep running, or be restored cleanly, within a pre-defined timeframe the business can tolerate.

This reframes the central question of recovery. For two decades the metrics that mattered were RTO and RPO: how fast can we restore?, and how much data might we lose?. ResOps asks harder questions. When you restore, are you restoring something clean, trusted, and actually usable?, or are you reintroducing the very problem you were trying to recover from? A growing number of teams now track Mean Time to Clean Recovery (MTCR), not just recovery time – precisely because a fast restore of compromised data is not a recovery at all.

That is the real test of ResOps. Not the strategy deck. The clean restore, under pressure, proven in advance.

The gap between the idea and the operation

The reality is that most organisations already believe they can recover. Backups are running. Immutability is in place. The plan is documented. And yet recoveries still fail – often – and expensively, when they are needed most.

There are three reasons, and ResOps as currently described by most vendors does not fully address any of them.

First, recoverability is assumed rather than proven. Backups complete successfully and everyone moves on. But a successful backup is not a successful recovery. The only way to know a system will come back is to actually bring it back and test it, continuously, not once a year in a tabletop exercise or DR test.

Second, malware is already inside the backups. Immutability protects a copy from being changed; it does nothing to verify that copy was clean when it was written. In practice, dormant ransomware and other threats sit in backup data waiting to be restored. Predatar has found previously undetected malware in the backups of more than 90% of its customers, organisations that in most cases had strong, best-in-class security tools in place. Anomaly detection alone does not catch this. You have to recover the workload, scan it properly, and verify it.

Third, real infrastructure is fragmented. Most enterprises run several backup and storage platforms, and the resilience tooling offered by each vendor only validates that vendor’s own data. Veeam’s testing covers Veeam workloads. Cohesity covers Cohesity, Rubrik’s covers Rubrik, Etc. A ResOps model that only works on one vendor’s stack is not operational resilience. It is a partial view that leaves blind spots that can be exploited.

How Predatar operationalises ResOps

Predatar exists to close the gap between believing you can recover and proving it. The approach rests on three things the broader ResOps conversation talks around but rarely operationalises.

Continuous, pre-emptive recovery testing. Instead of waiting for an incident, Predatar automatically and repeatedly restores backups and primary snapshots into an isolated environment and tests whether those systems come back clean and usable. This runs at scale, without manual effort, so that when a crisis hits you already know what recovers and what does not. Continuous validation stops being a phrase in a strategy document and becomes a daily, measurable operation.

Clean recovery, not just detection. Where most tools stop at flagging an anomaly, Predatar goes further. It restores the suspect workload, runs a full malware scan to confirm whether an infection is real, and where necessary cleans the workload before it is ever returned to production. This is the difference between knowing something might be wrong and being able to recover something you know is right. It is the operational meaning of the ‘clean’ in clean recovery.

Vendor-agnostic by design. Predatar’s CleanRoom works across Veeam, Rubrik, Cohesity, IBM Storage Protect, IBM Defender DataProtect, IBM FlashSystem, Pure Storage, and Zerto validating both backups and primary snapshots from one central place under a single subscription. Fragmented storage does not have to mean fragmented resilience. For a ResOps model to be real, it has to span the estate you actually run, not the one a single vendor wishes you ran.

Resilience operations you can start on Monday

There is a perception that resilience operations are an enterprise-scale, capital-heavy undertaking, the kind of thing tied to large hardware estates and big upfront investment. That perception is the single biggest barrier to adoption, and it is no longer true.

Predatar’s CleanRoom is delivered as a virtual appliance that deploys into infrastructure you already have. More than 70% of customers stand it up using existing resources, with no new hardware. The most successful teams do not try to operationalise everything at once. They start with a minimum viable business service, a critical application or a key set of workloads, prove recovery there, and expand. That is what makes ResOps an operation rather than a project: it is something you begin now and run continuously, not a transformation you wait a year to fund.

The point of ResOps

The industry is right that resilience needs to become an operation. Where the current conversation falls short is in treating it as primarily a matter of strategy, culture, and organisational alignment. Those things matter, but they do not restore a single system. Resilience is not proven in a framework. It is proven in a clean, complete, timely restore, on the worst day, across whatever mix of platforms you actually run.

That is the part Predatar has spent years building, and it is the part that turns ResOps from a good idea into something you can rely on.

Learn more about ResOps here:
What is ResOps? & ResOps FAQS

Take the first steps towards making ResOps a reailty.

Predatar delivers continuous, automated recovery assurance across multi-vendor storage and backup environments. Book a demo or contact our friendly team of experts.

Learn more about
Predatar recovery assurance

17 June 2026

From hoping to knowing.

Why Verticom’s partnership with Predatar is changing the game for customers.

For some businesses, an hour offline is inconvenient. For most of Verticom’s customers, it‘s the difference between a normal day and a catastrophe. The Finnish IT provider has spent more than 30 years looking after the kind of environments where systems simply cannot stop — production lines, business-critical infrastructure – the systems a company runs on, not just the ones it merely uses.

So, it will come as no big surprise that Verticom has joined forces with Predatar, the Recovery Assurance leaders, to help them move from backing up data to proving it can be recovered, as a direct response to what their customers now expect.

We sat down with Verticom’s CEO, Tiia Pohjanlehto to talk about why backup alone no longer cuts it – and what changes when you can actually prove recovery works.



Tiia Pohjanlehto
Chief Executive Officer.
Verticom.


Let’s start with your customers. Who relies on Verticom, and what do they have in common?

They range from small and mid-sized companies all the way up to large organisations, but they share one thing: their IT is business-critical. Many of them run production environments where downtime just isn’t an option – if something goes down, recovery has to be fast and effective, not improvised. That’s why we run 24/7 monitoring and on-call services. When the stakes are that high, “we’ll look at it in the morning” isn’t an answer.

Finland isn’t short of IT providers. What makes Verticom different?

We focus on making IT actually work in real life – not just on paper. Our whole strategy is built on staying close to our customers and being genuinely flexible, rather than forcing everyone into the same template. We tailor what we do to what a customer actually needs, and we build long-term relationships off the back of that. We’re a family-owned business with over 30 years managing critical environments, from hardware support to backup architecture and infrastructure design. That history matters – you can’t fake three decades of running systems that can’t fail.

You’ve said that “backup alone is no longer enough.” What do you mean by that?

The uncomfortable truth in our industry is that backups exist, but recovery is often uncertain. A backup job can report success every single night and still let you down on the day you actually need it. For years, the whole industry has been measuring the wrong thing – whether the backup ran, not whether you can get your business back. Our customers have started to feel that gap too. They no longer want to be told “the backups are in place.” They want proof that recovery works. That’s where Predatar comes in.

What does Predatar actually change for you?

It closes exactly that gap. Predatar continuously tests recovery and validates that data can actually be restored – quickly and cleanly, when it’s needed – instead of us assuming it will be. So, we move from hoping to knowing. For a customer who can’t afford downtime, that shift from assumption to evidence is everything.

Did you look at other tools before choosing Predatar?

We did. But most traditional tools are still focused on backup success rather than recovery. Predatar stood out because it’s built specifically to validate recoverability across different environments – and because it’s a European solution, which matters more and more to our customers when it comes to where their data and tooling sit.

How does this fit into where Verticom is heading?

Our vision is to be a true one-stop partner — taking responsibility for the whole IT infrastructure, from hardware through to virtual environments, security and continuous operations. Predatar fits that exactly. It lets us extend from “we manage your backups” to “we can prove your recovery.” That’s a meaningful step toward owning operational resilience for our customers, not just a piece of it.

On a personal level, what excites you most about the partnership?

It removes the guesswork. Instead of assuming things work, we can show it – clearly, and continuously – with a solution that’s both credible and European. There’s something genuinely satisfying about being able to look a customer in the eye and demonstrate it, rather than simply reassure them.

Where do you want this partnership to go?

Over the next year, we want to deepen the partnership, bring the solution to more of our customers, and establish ourselves as the leading Predatar partner in Finland. Longer term, the goal is bigger: we want continuous recovery validation to become a standard part of how IT is run – not a premium add-on, just the way things are done.


The message from Verticom is a simple one, and it reflects how the conversation around resilience is shifting. Having a backup is no longer the achievement. Being able to prove you can recover from it is.

For a company whose customers can’t afford downtime, confidence isn’t a nice-to-have. It’s everything.



If you are ready to find an IT services provider that you can trust to take ownership of your operational resilience – look no further than Verticom.

Visit www.verticom.fi

Learn more about
Predatar recovery assurance

04 June 2026

Anthropic’s Mythos hasn’t changed anything. It’s just made the truth impossible to ignore.

No one likes a know-it-all, but we’re not here to make friends. We’re here to make organisations resilient. To make sure they’re prepared for what’s coming, and to make sure they can recover quickly when they need to.

So, that’s why we don’t mind saying it:
We told you so.


As long ago as 2020, we were telling businesses that they needed to be ready for a data breach. That cyber security alone wasn’t enough. That a breach was inevitable. That they needed to shift from a defensive strategy to a resilience one.

More specifically, we’ve been telling them they need to prove they can recover their critical systems before they find themselves trying to do it for the first time in the middle of a crisis.

And, of course, it’s not only us that has been saying it. This is a point of view shared by many industry experts and analysts.

The big question is: Has anyone been listening?

While lots of organisations have taken notice — which is evident from the increasing number of them subscribing to Predatar’s Recovery Assurance platform — the reality is that far too many have chosen to keep their heads in the sand.

Until now.

What’s changed?

It’s not entirely true that Claude Mythos, the latest AI model from Anthropic, hasn’t changed anything. It is shining a huge and unignorable spotlight on the inevitability of data breaches. If you’re not familiar with Mythos, or its alarming potential in the wrong hands, you can learn more here.

Mythos is being discussed in almost every boardroom around the world. If you work in an IT, business continuity, operational resilience, or cyber security department, get ready for some tricky questions coming your way soon. Questions like:

What does Mythos mean for our business?
What are we doing about it?
Are we ready for a breach?


… but do you have the answers?

Patch faster?

The clearest recommendation from Anthropic is: patch faster, and treat CVE-related dependency updates as urgent – highlighting how Mythos-class models can be used defensively to identify and remediate vulnerabilities before hackers do.

If software manufacturers and IT teams continue to use current approaches for patch creation and deployment, they simply won’t keep up with the speed of the AI-powered vulnerability exploits that are coming down the tracks. That’s why the concept of patching at machine-speed is gathering popularity – an approach where AI and automation are deployed to dramatically close the patching window.

While this type of defensive approach will soon be essential, it’s a bit like AI-powered whack-a-mole. If faster patching is your only answer to the Mythos questions, you’re in trouble.

The unavoidable truth

Organisations simply can’t hide from the facts anymore. It isn’t possible to defend against every threat. The ability to execute a rapid, rock-solid recovery is essential.

Don’t be misled by Service Level Agreements (SLAs), untested Recovery Time Objectives (RTOs), or recovery guarantees from your suppliers and technology vendors. The only way to be certain that you can execute a fast, clean, successful recovery is to test it – to actually recover your critical systems and check that they are safe…

Not once a year.
Not once a month.
Every day!

Recovery Assurance with Predatar

Predatar’s Recovery Assurance platform puts AI and automation to work to continually validate that the critical systems your business relies on can be recovered quickly, cleanly, and completely — even if the data they are built on lives across fragmented, multi-vendor storage and backup infrastructure.

Not only is this proactive approach a good idea, it also provides the evidence of resilience that helps board-level executives sleep at night. So, when those big questions come down from the top – answer them with proof of resilience.

Start your journey to proven resilience

Talk to a Recovery Assurance expert or book a Predatar demo.

Learn more about
Predatar recovery assurance

28 April 2026

Is your next backup administrator an AI agent?

In July 2024, we asked a provocative question: Will AI replace the backup administrator? Read the original blog here.

At the time, Predatar had just released R16 Orca, and “Generative AI” was the phrase on everyone’s lips. “Agentic AI”– systems capable of autonomous, goal-driven action – was not yet part of mainstream thinking, at least not in the wider public domain. It wasn’t until later in 2024 that agentic AI began to enter the broader discourse. Since then, the conversation, and the tech, has moved at a blistering pace.

Our original conclusion still stands: the backup administrator is here to stay. But the nature of the role is changing far more dramatically than we anticipated. With the emergence of agentic AI, we are moving beyond assistance into true autonomy in backup and recovery operations.

So, what’s now possible? Agentic AI opens the door to capabilities such as automatically scheduling and optimizing backups based on real-time conditions, dynamically building and fine-tuning recovery plans, and intelligently orchestrating the order of restores to achieve the fastest recovery outcomes. It can also respond in real time to AI-driven anomaly detection, adjusting protection strategies or initiating defensive actions as threats emerge.

While it is possible to build these capabilities into operational management platforms, it’s still early days. The industry is just beginning to explore what fully autonomous data protection looks like, and it will be some time before these systems reach full maturity. We predict that until 2028, the model will be “human-on-the-loop”. The backup administrator role will remain as important as ever, perhaps even more so. From 2028 onwards, the role will evolve. The human backup administrator will take on more of an AI governance role. This is often described as “human-before-the-loop”, where the backup admin provides the initial guardrails that allow AI to act independently.

The threat landscape is accelerating. Backup vendors know this and are scrambling to catch up. They face a new kind of arms race against AI-enabled threat actors who are actively disrupting the ability to recover. This is no longer just about encryption or threat detection. It’s about proving resilience.

The response is clear: we must fight fire with fire. Embracing agentic AI within cyber resilience platforms is the only viable path to keep pace.

At Predatar, this shift is already well underway. We have made a decisive, seismic move to re-engineer our entire platform – spanning monitoring, automation, recovery assurance, and CleanRoom capabilities – around agentic AI. This is not a feature enhancement; it is a fundamental redesign.

Will we see a day when agents are truly autonomous, and the backup admin is fully “human-out-of-the-loop”? We’re not prepared to say. We are good, but not that good.


Stay in the loop with Predatar News

If you’re a human and you like being in the loop (from a news perspective), join our mailing list to get the latest news and insights from the Recovery Assurance trailblazers at Predatar. Sign up here.


Learn more about
Predatar recovery assurance

15 April 2026

Are your backup vendors marking their own homework?

If you’re a risk or compliance officer – or, in fact, anyone with a role to play in ensuring operational resilience in your organization – how do you know that the backup platforms your IT team is using are up to the task?

It’s an important question. The answer – when you think about it – is worrying.

Because typically, organizations like yours rely on the resiliency credentials that the technology vendors themselves set out. Is it any wonder that every backup vendor claims that their platform is the most resilient, when they are setting their own criteria to measure resilience?

Of course, you could ask your IT or infrastructure team – they are the experts, after all. But the brutal truth is that resilience isn’t their top priority. These teams are typically overstretched and under-resourced. Making sure that the systems and data your organization runs on every day are available under normal conditions keeps them busy enough.

Understandably, they will have a preference for the infrastructure products that make everyday management and administration easy. And, in fact, it goes beyond day-to-day practicalities. If you spend enough time with storage teams, you’ll notice that people often become deeply attached to certain vendors, defending them almost like a belief system rather than just a technology choice.

Understanding the true picture of resilience in your business becomes even more complicated when you have a large and complex infrastructure environment. An environment made up of technologies from multiple vendors – each with its own claims, its own standards, and its own devoted followers inside your business.

The idea of ‘devoted followers’ brings an interesting concept to mind – one which history has shown to be a good one: the separation of church and state. Not only has this approach been useful for monarchs who have found themselves inconveniently married, but more importantly, it has been invaluable for managing kingdoms. And, believe it or not, the concept is relevant here.

In this analogy, vendors like Dell, IBM, Pure, Veeam, Rubrik, etc are the ‘churches,’ each with its own doctrine. Useful, certainly – but not neutral.

What is needed is a ‘state’: a vendor-independent authority that sits above the fray, governing consistently across all systems. One that ensures recovery testing is meaningful, malware scanning is credible, and resilience is measured the same way everywhere.

This separation reduces conflicts of interest, standardises outcomes, and brings a much-needed layer of objectivity to an otherwise fragmented landscape.

No analogy is perfect, of course. Vendors aren’t religions, and governance platforms don’t wield civil authority, but the underlying principle still holds: resilience shouldn’t be defined by the tools themselves. Because if it is, don’t be surprised if everything looks perfect… until it really matters… and then it isn’t.


Discover Independent Recovery Assurance

Visit www.predatar.com to start your journey to independent Recovery Assurance or contact hello@predatar.com for expert advice from the leading independent Recovery Assurance experts at Predatar.

Learn more about
Predatar recovery assurance

25 March 2026

DR-Rex

5 Signs That Your Disaster Recovery Testing is Prehistoric.

Let’s be honest. In most businesses, Disaster Recovery (DR) testing still looks suspiciously like it did 20 years ago. Runbooks, war room, late night pizza delivery, a colossal spreadsheet for tracking the whole thing.

If that sounds familiar, it’s time to face up to the truth. Your outdated DR tests are putting your business continuity at serious risk. The woolly mammoth in the room is this… the world has changed and your processes are no longer fit-for-purpose.

Here are 5 warning signs that your DR testing approach is stuck in the past – and some practical advice to bring it into the 21st century.

#1. You test once or twice a year.

Traditional DR testing was designed around big, periodic exercises. Typically, annually or quarterly. Everyone gathers, the scripts come out, systems get failed over, and someone ticks the box.

Job done.

The problem here is that the data that your business runs on is changing every single day. New user profiles, software updates, hardware refreshes, security patches. Any of these can knock a restore off track and potentially derail the recovery of important services or applications that your business relies on. 

Your environment will change hundreds, if not thousands of times between DR tests. Just because a system was recoverable yesterday, it doesn’t mean that it will be today.

Resilience shouldn’t be something you check from time to time. It should be continuously validated as part of the everyday operations of your business.

#2. Your DR test relies on heroic manual effort

The people that manage the data in your business are unsung heroes. They quietly keep your organization running – every day. But, if your DR tests require dozens of these heroes to assemble, and follow a 200-page runbook into the early hours – that’s not resilience – that’s a liability.

Manual recovery processes are:

Slow
Prone to human error
Inconsistent
Impossible to scale

In a real-world data outage, when the pressure is high, and time matters – the last thing you want is a room full of people following a big, complicated document.

Modern recovery needs automation, orchestration, and repeatability.

#3. Your DR tests are designed for hardware failures — not cyberattacks

The most likely type of disaster to hit your business isn’t an earthquake, a flood, or a fire. It’s a cyberattack.

You know it. Your IT team knows it. The Business Continuity team know it. Even the executives know it – But few dare to ask the question, “Does our DR testing simulate cyber recovery scenarios?”

Ransomware doesn’t politely failover your servers. Attackers move laterally across systems. They lock-out administrators. They Infect backups. They encrypt your data. Most DR testing rarely replicates this reality. Instead, it tests a clean failover scenario where everything behaves exactly as expected. It’s just not how cyber incidents unfold.

Modern DR testing must validate whether you can recover clean, trusted data and restore operations after a cyberattack – not just after a hardware failure.

#4. Your DR tests prove compliance, not recovery.

Let’s be blunt: Most DR testing exists primarily to satisfy auditors.

• A report gets generated.
• Boxes get ticked.
• Someone signs it off.
• Everyone gets back to the day job.

But compliance reports don’t restore systems. What matters is whether you can recover quickly, recover cleanly and recover completely.

If your DR testing produces documentation but not real operational confidence, you’ve got a reporting exercise, not a resilience strategy.

#5. You don’t actually know if your recovery plan works

This might be the most dangerous problem of all.

Many organisations assume their DR plan works because it worked the last time they tested it.

But if testing is:

Infrequent
Highly manual
Limited in scope

…then what you really have is a lot of hope and not much proof.

That’s a risky place to be.

Bring your business continuity into the modern world

Modern recovery testing needs to move beyond periodic testing and manual exercises.

It should be:

• Automated — removing reliance on manual runbooks and risk of human error
• Continuous — validating recovery readiness regularly, not annually
• Realistic — simulating modern threats, including cyber incidents
• Actionable — giving teams real insight into recovery performance

This is exactly the shift Predatar was built to enable. Predatar orchestrates Recovery Assurance testing across complex enterprise environments, allowing you to automate recovery workflows, run low-impact recovery test, identify issues early, and prove recovery readiness with confidence.

Make sure your recovery processes actually work — not just on paper, but in practice.

Learn how to reduce your reliance on outdated DR tests and bring your DR testing into the modern world. Read our Recovery Assurance Buyers Guide or visit predatar.com

Learn more about
Predatar recovery assurance