Book demo
06 August 2026

Recovery You Can Bank On – Why Financial Institutions Across Latin America are Turning to Predatar.

Banks and financial services organisations across Latin America are choosing Predatar to strengthen operational resilience, prove recoverability and respond to increasingly demanding regulations. Behind much of this momentum is Nicolas Perez de Arenaza — LATAM’s leading Recovery Assurance expert.

For banks and insurers, data is everything!

Every payment, balance, policy and customer interaction depends on data. If critical systems become unavailable, operations grind to a halt. That makes recovery more than an infrastructure concern. It is a board-level, regulatory and operational resilience priority.

It is also why some of the largest and longest-established financial institutions across Argentina, Colombia, Paraguay, and Mexico have chosen to invest in Predatar this year. These organisations are not implementing Recovery Assurance technology because it is fashionable. They need proof that they can recover when it matters.

Meet a Recovery Assurance trailblazer

Based in Buenos Aires, Founder & CEO at GIUX, Nicolas Perez de Arenaza has established himself as Latin America’s leading Recovery Assurance expert.

We first met Nicolas three years ago, when he flew more than 7,000 miles to join one of Predatar’s very first hands-on technical training workshops in the UK.

Nicolas built his Recovery Assurance Cleanroom, collected his certificate, and then jumped on a motorcycle to explore some of Scotland’s most spectacular landscapes. We knew immediately that we would get along.

That adventurous spirit has shaped Nicolas’s approach to building the Recovery Assurance market. He knew that the infrastructure and cyber security markets were shifting towards a focus on resilience, but he didn’t wait for customers to begin asking for Predatar. He travelled across Argentina, Colombia, Ecuador, Perú and Paraguay, and built relationships remotely in Mexico and beyond – sharing knowledge along the way.

“I spread the word about Predatar in many countries,” Nicolas explains. “GIUX acts as a beacon: we share knowledge, let people know that we can help them move forward with this approach, and show them how to find us when they need help or advice.”

It’s not just financial institutions that have benefited from Nicolas’ expertise. He’s actively speaking with IT, security, and operational resilience leaders across many industry sectors. He has also become the go-to Recovery Assurance expert for other technology businesses in the region – including resellers and service providers.

Nicolas is always keen to point out that his successes are always part of a team effort. In most cases Nicolas and the team at GIUX are providing consultancy and technical services to end customers, working hand-in-hand with the local IBM ecosystem of IBM reps and business partners on each country to provide an exceptional end-to-end customer experience.

Why financial services?

While almost any modern business will benefit from Recovery Assurance technology, the momentum that is building in financial institutions specifically is no coincidence.

The reality is that the financial services sector already has some of the most robust resilience and continuity capabilities in place. But they also carry the biggest risks.

Nicolas explains, “These are the organisations most dependent on the continuity of IT. Banks and insurers face enormous potential costs from downtime. They are also accountable to the board, their customers, the markets – and of course – regulators.”

Supporting regulatory compliance

Financial services regulations around the world are already among the most stringent of any sector, and many are now demanding that institutions must demonstrate their resilience rather than simply document it.

What this means in practice is that recovery plans must be tested comprehensively and regularly. Recovery guarantees and Service Level Agreements (SLAs) from IT vendors must actually be validated. Organisations must demonstrate they can actually meet the targets they set around impact tolerances and Recovery Time Objectives (RTOs).

This is where Predatar delivers real value. By putting AI and automation to work, Predatar continually checks that the data that runs its customers’ most important systems and services is always recoverable and clean – every single day. Putting Predatar to work gives you the certainty that whenever needed, you will be able to recover rapidly, completely and free of malware.

Not only does this provide peace of mind, Predatar provides the evidence of resilience that many regulators now expect.

Getting started with Recovery Assurance

Can your organisation recover the data, systems and digital services it relies on quickly, cleanly and completely? All too often businesses find themselves trying to answer these high-stakes questions for the first time in the middle of a crisis.

That’s why any organisation – whether it’s in the financial services sector or not – can benefit from continuous Recovery Assurance. Download our Recovery Assurance Buyer’s Guide to learn more about this emerging technology market, or find a ‘beacon of knowledge’ in your region by visiting Predatar’s APEX Partner finder.

Predatar works with leading enterprise storage and backup solutions and can even be used to validate recoverability across complex multi-vendor infrastructure environments – making it a perfect fit for many large organisations including banks and other financial services institutions.

Learn more about
Predatar recovery assurance

22 July 2026

Cyber Attacks Don’t Kill Businesses. Slow Recoveries Do.

Most large organisations are terrified of being hit by a cyber attack. The headlines are all too familiar… “Company X hit by ransomware attack.”

The attack sounds like the disaster. It isn’t.

The disaster is what happens next – the 24 days offline. The restore that fails again and again. The backup that was “successful” every single night for a year and still won’t come back clean. Attacks are a single, dramatic event. Recovery is where businesses actually die, slowly, in front of their customers, their staff, and the board.

If you want to know whether your organisation will survive a cyber-attack, you need to start asking one question: Do you know for certain that you can get your critical systems back?

The numbers should scare you more than the attack does

  • Ransomware attacks rose 50% in 2025, hitting nearly 7,900 publicly claimed incidents – and 2026 is running over 30% hotter still.
  • The average ransomware incident now costs $5.08 million once downtime, remediation and lost business are taken into account.
  • Enterprise downtime runs at roughly $300,000 per hour. For mid-market businesses, it’s still $50,000 – $100,000 an hour. That’s not a bad quarter – that’s a business unravelling in real time.
  • Only 53% of organisations fully recovered within a week in 2025. Read that the other way round: nearly half of all businesses hit are still not operational seven days later.

Here’s the one that should really keep you up at night: Predatar has found previously undetected malware inside the backups of more than 90% of its customers – organisations that, in most cases, already had best-in-class security stacks. Not gaps in defence. Gaps in the thing everyone assumed would save them.



The lie of the green tick

For too long, the entire backup industry has run on an assumption that nobody ever stress-tests: if the backup job reports success, recovery will work too.

The reality is that a backup platform can report a clean green tick every night for a year and still fail you on the one day it matters. Restore jobs stall halfway through. Recovery performance collapses under load. Authentication breaks. Application dependencies don’t hold. RTOs that looked good in a slide deck turn into days, or weeks, once you’re actually trying to bring a production estate back from nothing.

Under normal conditions, roughly 8% of backups fail to recover. During an actual cyberattack – with corrupted volumes, dormant malware, and infrastructure under strain – that failure rate can explode ten-fold, to as high as 84%.

That gap between what businesses assume they can recover and what they can actually recover has a name: the Recovery Gap. Most organisations don’t know theirs exists until the worst possible moment reveals it – when production is already down and the safety net is full of holes.

Your SLA is not a recovery plan

Somewhere in a contract, there’s a number: an RTO of 4 hours, an RPO of 15 minutes, a vendor SLA with financial penalties attached if it’s missed. It feels like protection. It isn’t proof of anything.

An SLA is a promise. A guarantee is a sentence in a document. Neither one has ever actually restored a single terabyte of data at 2am while your board is asking for hourly updates and your customers are finding out on social media. SLAs describe what’s supposed to happen. They say nothing about whether it will.

The businesses that go dark for weeks after an attack almost always had a DR plan. Almost always had backups. Almost always had an SLA. What they didn’t have was evidence – tested, current, repeated evidence – that any of it actually worked under real conditions.

Confidence isn’t a feeling. It’s a test result.

There’s a reason ransomware payments fell 35% year-on-year even as attacks kept climbing: more organisations are refusing to pay. Not because they’re braver. Because they’ve actually tested their recovery and know it holds up. When you can prove you’ll get your systems back without the attacker’s help, their entire leverage disappears.

That’s the shift that matters here. Stop asking “do we have backups?” That question was solved a decade ago and it was never the right one. Start asking: “Have we proven – recently, repeatedly, under realistic conditions – that we can recover, that recovery lands inside our RTOs, and that what comes back isn’t still infected?”

Hoping your recovery plan works is not a strategy. It’s a bet on the worst day of your business’s life, placed on evidence you’ve never actually checked.

Backups you haven’t tested aren’t a safety net. They’re an assumption wearing a safety net’s clothing. The businesses that walk away from an attack aren’t the ones with the best-worded SLA – they’re the ones who already knew, beyond doubt, exactly how fast and how clean their recovery would be, because they’d proven it before the attackers ever showed up.

It’s time to get recovery confident!

Don’t find out which one you are during an incident. Find out now.

Discover Recovery Assurance from Predatar

Learn more about
Predatar recovery assurance

07 July 2026

Escape from Complexity. Get to Resilience Faster.

The latest Predatar release, R18.3, has been designed to help customers avoid the most common pitfalls of CleanRoom setup, so they can achieve recovery confidence sooner.


At Predatar, we operate in a world of complexity. Enterprise IT and infrastructure are a jungle of legacy systems, siloed tools, hidden dependencies, detailed information security policies and ever-changing regulations. Taking this complexity away for our customers is one of the most important drivers for our R&D team.

You want certainty that your organisation can recover its critical systems quickly and safely when you need to – without having to manage all the complexity that underpins that assurance.

With a focus on deployment and setup, the latest Predatar release R18.3 takes even more of that complexity away. The result? Predatar customers can get to ‘live’ faster – which means they can achieve recovery confidence sooner.

Building on CleanRoom 3

Back in 2024 Predatar launched CleanRoom 3. Our third generation Recovery Assurance CleanRoom significantly simplified the deployment process and shortened the time required to get a Predatar CleanRoom up and running from several days down to just a few hours.

It was – and still is – an impressive piece of engineering. Our CleanRoom remains the most advanced Recovery Assurance CleanRoom available today. And while our own engineers can – and regularly do – deploy CleanRooms before unpacking their lunch – we found the reality in the field was often different.

Customer installations would sometimes hit bottlenecks. The time-to-value would get extended, and it would take longer than expected for customers to achieve the resilience they needed.

R18.3 tackles three common obstacles that have been slowing down deployments.

Obstacle 1: The Security Checkpoint

A CleanRoom needs controlled outbound access to be built, stay current, and stay protected. Until now, this required a dynamic list of shifting destinations sitting behind CDNs and rotating IPs. It’s the kind of moving target that tends to prompt scrutiny from security teams – and rightly so – but all too often reviews would stall. The deployment would stop – for days – sometimes weeks.

R18.3 fixes this. The new Easy Networking process now connects your CleanRoom via a short, clearly documented set of fixed destinations. Security teams get something they can easily understand, review, and approve.

The security checkpoint stops being the delay.

Obstacle 2: Hidden Errors

CleanRoom installation used to run in one continuous automated workflow. You would enter your networking configuration details and the setup requirements up front, the build would begin, then let you know when it was done. Sounds easy, right?

The delay would come if there was an error in the details that were entered. Something as simple as a single digit typo would cause a deployment to fail, and it wasn’t always easy to work out where the error was.

R18.3 includes a new Admin Console, which guides you through the install, validating each stage as it happens. If something’s off, it’s flagged immediately.

Obstacle 3: Wasted Cycles

There’s another time-saving benefit of splitting the installation into a step-by-step process. Before R18.3, even once an issue had been identified and fixed, the whole install cycle would need to be started again. Not only was this time-consuming, but engineers told us that this could be pretty frustrating – and even more so if another error was found the next time around. Every small configuration mistake would cost a full cycle.

With R18.3 issues can be fixed along the way and the build carries on from that point. If the process is interrupted, it simply resumes where it left off.

The point: less friction, faster resilience

At Predatar we will never stop looking for ways to make our Recovery Assurance technology better. R18.3 is proof of our commitment to continuous improvement. Today Predatar is easier and faster to deploy than it was yesterday. That means customers achieve the resilience they need faster – and get value out of their investment sooner.

Get started with Predatar

Start your journey to recovery confidence. Contact us to a talk with member of the friendly and knowledgeable Predatar team, or book a demo to see R18.3 in action.

Learn more about
Predatar recovery assurance

24 June 2026

The rise of ResOps

A new term is taking hold in medium and large enterprises – ResOps, short for Resilience Operations. We didn’t come up with it, but we wish we had – because it’s one of those concepts that just makes sense.

ResOps describes a shift that has been happening for a few years now. Resilience is moving from something you plan, to something that is an integral part of how an organisation runs – every day. In the same way that DevOps shifted software releases from big, periodic, high-stakes events into a flow of incremental pushes delivering continuous improvements, ResOps is set to be a game-changer for the way businesses approach Disaster Recovery (DR) and Business Continuity Planning (BCP).

The idea is sound, and it matters. But most of what has been written about ResOps so far stops at the strategy. It tells you resilience should be a continuous operating model, a board-level priority, a culture that breaks down silos between IT, security, and the business. All true. But, none of it tells you how you actually start to make the move to continuous resilience. How can you begin to test your ability to recover – every day, and actually prove it works.

That operational layer is where ResOps either works or quietly fails. It is also where Predatar has been building for years.

What ResOps actually means

Strip away the vendor framing and ResOps comes down to a simple proposition. Disruption is no longer an exceptional event to be planned for. It is a normal operating condition to be managed. Ransomware, outages, cloud complexity, and now AI agents acting on your data at machine speed mean that something will go wrong, and the question that matters is not whether you have a plan, but whether your critical services can keep running, or be restored cleanly, within a pre-defined timeframe the business can tolerate.

This reframes the central question of recovery. For two decades the metrics that mattered were RTO and RPO: how fast can we restore?, and how much data might we lose?. ResOps asks harder questions. When you restore, are you restoring something clean, trusted, and actually usable?, or are you reintroducing the very problem you were trying to recover from? A growing number of teams now track Mean Time to Clean Recovery (MTCR), not just recovery time – precisely because a fast restore of compromised data is not a recovery at all.

That is the real test of ResOps. Not the strategy deck. The clean restore, under pressure, proven in advance.

The gap between the idea and the operation

The reality is that most organisations already believe they can recover. Backups are running. Immutability is in place. The plan is documented. And yet recoveries still fail – often – and expensively, when they are needed most.

There are three reasons, and ResOps as currently described by most vendors does not fully address any of them.

First, recoverability is assumed rather than proven. Backups complete successfully and everyone moves on. But a successful backup is not a successful recovery. The only way to know a system will come back is to actually bring it back and test it, continuously, not once a year in a tabletop exercise or DR test.

Second, malware is already inside the backups. Immutability protects a copy from being changed; it does nothing to verify that copy was clean when it was written. In practice, dormant ransomware and other threats sit in backup data waiting to be restored. Predatar has found previously undetected malware in the backups of more than 90% of its customers, organisations that in most cases had strong, best-in-class security tools in place. Anomaly detection alone does not catch this. You have to recover the workload, scan it properly, and verify it.

Third, real infrastructure is fragmented. Most enterprises run several backup and storage platforms, and the resilience tooling offered by each vendor only validates that vendor’s own data. Veeam’s testing covers Veeam workloads. Cohesity covers Cohesity, Rubrik’s covers Rubrik, Etc. A ResOps model that only works on one vendor’s stack is not operational resilience. It is a partial view that leaves blind spots that can be exploited.

How Predatar operationalises ResOps

Predatar exists to close the gap between believing you can recover and proving it. The approach rests on three things the broader ResOps conversation talks around but rarely operationalises.

Continuous, pre-emptive recovery testing. Instead of waiting for an incident, Predatar automatically and repeatedly restores backups and primary snapshots into an isolated environment and tests whether those systems come back clean and usable. This runs at scale, without manual effort, so that when a crisis hits you already know what recovers and what does not. Continuous validation stops being a phrase in a strategy document and becomes a daily, measurable operation.

Clean recovery, not just detection. Where most tools stop at flagging an anomaly, Predatar goes further. It restores the suspect workload, runs a full malware scan to confirm whether an infection is real, and where necessary cleans the workload before it is ever returned to production. This is the difference between knowing something might be wrong and being able to recover something you know is right. It is the operational meaning of the ‘clean’ in clean recovery.

Vendor-agnostic by design. Predatar’s CleanRoom works across Veeam, Rubrik, Cohesity, IBM Storage Protect, IBM Defender DataProtect, IBM FlashSystem, Pure Storage, and Zerto validating both backups and primary snapshots from one central place under a single subscription. Fragmented storage does not have to mean fragmented resilience. For a ResOps model to be real, it has to span the estate you actually run, not the one a single vendor wishes you ran.

Resilience operations you can start on Monday

There is a perception that resilience operations are an enterprise-scale, capital-heavy undertaking, the kind of thing tied to large hardware estates and big upfront investment. That perception is the single biggest barrier to adoption, and it is no longer true.

Predatar’s CleanRoom is delivered as a virtual appliance that deploys into infrastructure you already have. More than 70% of customers stand it up using existing resources, with no new hardware. The most successful teams do not try to operationalise everything at once. They start with a minimum viable business service, a critical application or a key set of workloads, prove recovery there, and expand. That is what makes ResOps an operation rather than a project: it is something you begin now and run continuously, not a transformation you wait a year to fund.

The point of ResOps

The industry is right that resilience needs to become an operation. Where the current conversation falls short is in treating it as primarily a matter of strategy, culture, and organisational alignment. Those things matter, but they do not restore a single system. Resilience is not proven in a framework. It is proven in a clean, complete, timely restore, on the worst day, across whatever mix of platforms you actually run.

That is the part Predatar has spent years building, and it is the part that turns ResOps from a good idea into something you can rely on.

Learn more about ResOps here:
What is ResOps? & ResOps FAQS

Take the first steps towards making ResOps a reailty.

Predatar delivers continuous, automated recovery assurance across multi-vendor storage and backup environments. Book a demo or contact our friendly team of experts.

Learn more about
Predatar recovery assurance

17 June 2026

From hoping to knowing.

Why Verticom’s partnership with Predatar is changing the game for customers.

For some businesses, an hour offline is inconvenient. For most of Verticom’s customers, it‘s the difference between a normal day and a catastrophe. The Finnish IT provider has spent more than 30 years looking after the kind of environments where systems simply cannot stop — production lines, business-critical infrastructure – the systems a company runs on, not just the ones it merely uses.

So, it will come as no big surprise that Verticom has joined forces with Predatar, the Recovery Assurance leaders, to help them move from backing up data to proving it can be recovered, as a direct response to what their customers now expect.

We sat down with Verticom’s CEO, Tiia Pohjanlehto to talk about why backup alone no longer cuts it – and what changes when you can actually prove recovery works.



Tiia Pohjanlehto
Chief Executive Officer.
Verticom.


Let’s start with your customers. Who relies on Verticom, and what do they have in common?

They range from small and mid-sized companies all the way up to large organisations, but they share one thing: their IT is business-critical. Many of them run production environments where downtime just isn’t an option – if something goes down, recovery has to be fast and effective, not improvised. That’s why we run 24/7 monitoring and on-call services. When the stakes are that high, “we’ll look at it in the morning” isn’t an answer.

Finland isn’t short of IT providers. What makes Verticom different?

We focus on making IT actually work in real life – not just on paper. Our whole strategy is built on staying close to our customers and being genuinely flexible, rather than forcing everyone into the same template. We tailor what we do to what a customer actually needs, and we build long-term relationships off the back of that. We’re a family-owned business with over 30 years managing critical environments, from hardware support to backup architecture and infrastructure design. That history matters – you can’t fake three decades of running systems that can’t fail.

You’ve said that “backup alone is no longer enough.” What do you mean by that?

The uncomfortable truth in our industry is that backups exist, but recovery is often uncertain. A backup job can report success every single night and still let you down on the day you actually need it. For years, the whole industry has been measuring the wrong thing – whether the backup ran, not whether you can get your business back. Our customers have started to feel that gap too. They no longer want to be told “the backups are in place.” They want proof that recovery works. That’s where Predatar comes in.

What does Predatar actually change for you?

It closes exactly that gap. Predatar continuously tests recovery and validates that data can actually be restored – quickly and cleanly, when it’s needed – instead of us assuming it will be. So, we move from hoping to knowing. For a customer who can’t afford downtime, that shift from assumption to evidence is everything.

Did you look at other tools before choosing Predatar?

We did. But most traditional tools are still focused on backup success rather than recovery. Predatar stood out because it’s built specifically to validate recoverability across different environments – and because it’s a European solution, which matters more and more to our customers when it comes to where their data and tooling sit.

How does this fit into where Verticom is heading?

Our vision is to be a true one-stop partner — taking responsibility for the whole IT infrastructure, from hardware through to virtual environments, security and continuous operations. Predatar fits that exactly. It lets us extend from “we manage your backups” to “we can prove your recovery.” That’s a meaningful step toward owning operational resilience for our customers, not just a piece of it.

On a personal level, what excites you most about the partnership?

It removes the guesswork. Instead of assuming things work, we can show it – clearly, and continuously – with a solution that’s both credible and European. There’s something genuinely satisfying about being able to look a customer in the eye and demonstrate it, rather than simply reassure them.

Where do you want this partnership to go?

Over the next year, we want to deepen the partnership, bring the solution to more of our customers, and establish ourselves as the leading Predatar partner in Finland. Longer term, the goal is bigger: we want continuous recovery validation to become a standard part of how IT is run – not a premium add-on, just the way things are done.


The message from Verticom is a simple one, and it reflects how the conversation around resilience is shifting. Having a backup is no longer the achievement. Being able to prove you can recover from it is.

For a company whose customers can’t afford downtime, confidence isn’t a nice-to-have. It’s everything.



If you are ready to find an IT services provider that you can trust to take ownership of your operational resilience – look no further than Verticom.

Visit www.verticom.fi

Learn more about
Predatar recovery assurance

04 June 2026

Anthropic’s Mythos hasn’t changed anything. It’s just made the truth impossible to ignore.

No one likes a know-it-all, but we’re not here to make friends. We’re here to make organisations resilient. To make sure they’re prepared for what’s coming, and to make sure they can recover quickly when they need to.

So, that’s why we don’t mind saying it:
We told you so.


As long ago as 2020, we were telling businesses that they needed to be ready for a data breach. That cyber security alone wasn’t enough. That a breach was inevitable. That they needed to shift from a defensive strategy to a resilience one.

More specifically, we’ve been telling them they need to prove they can recover their critical systems before they find themselves trying to do it for the first time in the middle of a crisis.

And, of course, it’s not only us that has been saying it. This is a point of view shared by many industry experts and analysts.

The big question is: Has anyone been listening?

While lots of organisations have taken notice — which is evident from the increasing number of them subscribing to Predatar’s Recovery Assurance platform — the reality is that far too many have chosen to keep their heads in the sand.

Until now.

What’s changed?

It’s not entirely true that Claude Mythos, the latest AI model from Anthropic, hasn’t changed anything. It is shining a huge and unignorable spotlight on the inevitability of data breaches. If you’re not familiar with Mythos, or its alarming potential in the wrong hands, you can learn more here.

Mythos is being discussed in almost every boardroom around the world. If you work in an IT, business continuity, operational resilience, or cyber security department, get ready for some tricky questions coming your way soon. Questions like:

What does Mythos mean for our business?
What are we doing about it?
Are we ready for a breach?


… but do you have the answers?

Patch faster?

The clearest recommendation from Anthropic is: patch faster, and treat CVE-related dependency updates as urgent – highlighting how Mythos-class models can be used defensively to identify and remediate vulnerabilities before hackers do.

If software manufacturers and IT teams continue to use current approaches for patch creation and deployment, they simply won’t keep up with the speed of the AI-powered vulnerability exploits that are coming down the tracks. That’s why the concept of patching at machine-speed is gathering popularity – an approach where AI and automation are deployed to dramatically close the patching window.

While this type of defensive approach will soon be essential, it’s a bit like AI-powered whack-a-mole. If faster patching is your only answer to the Mythos questions, you’re in trouble.

The unavoidable truth

Organisations simply can’t hide from the facts anymore. It isn’t possible to defend against every threat. The ability to execute a rapid, rock-solid recovery is essential.

Don’t be misled by Service Level Agreements (SLAs), untested Recovery Time Objectives (RTOs), or recovery guarantees from your suppliers and technology vendors. The only way to be certain that you can execute a fast, clean, successful recovery is to test it – to actually recover your critical systems and check that they are safe…

Not once a year.
Not once a month.
Every day!

Recovery Assurance with Predatar

Predatar’s Recovery Assurance platform puts AI and automation to work to continually validate that the critical systems your business relies on can be recovered quickly, cleanly, and completely — even if the data they are built on lives across fragmented, multi-vendor storage and backup infrastructure.

Not only is this proactive approach a good idea, it also provides the evidence of resilience that helps board-level executives sleep at night. So, when those big questions come down from the top – answer them with proof of resilience.

Start your journey to proven resilience

Talk to a Recovery Assurance expert or book a Predatar demo.

Learn more about
Predatar recovery assurance

18 May 2026

Restores tell the truth about your backups

The findings users love

When Predatar uncovers malware in a customer’s backups, they are usually delighted.

Not delighted that they have malware – obviously – but delighted that it was found inside their Predatar CleanRoom before they needed those backups for real. In fact, Predatar has found malware in more than 90% of its customer’s IT environments. That statistic alone tells you something important about the reality organisations are operating in today.

And whenever malware is discovered, customers immediately understand the value. The platform has done its job. A hidden risk has been exposed – safely – in a controlled environment, before it became a genuine recovery event.

Everyone gets that instinctively.

What’s interesting is that customers don’t always react the same way when the CleanRoom uncovers restore failures or poor recovery performance, even though the value is arguably the same.

The assumption problem

The Predatar CleanRoom exists to answer three simple questions:

  1. Can your backups actually be recovered?
  2. Can they be recovered inside your RPOs and RTOs?
  3. Are they clean?

Most people naturally focus on the last part. Malware scanning grabs the attention when potential new customers are exploring Predatar’s capabilities – and it tends to remain the focus once the platform is live.

It’s tangible. It feels urgent. You can immediately imagine the consequences of restoring infected backups after a ransomware attack.

But operational recoverability is where many of the real problems live – and these problems are no less important.

One of the biggest misconceptions in the backup industry is the idea that because backups complete successfully, recovery will also work successfully. Unfortunately, that simply isn’t true.

A backup platform can happily report green ticks all day long, while the actual restore process tells a very different story. Recovery jobs can fail halfway through. Restore performance can collapse under load. Network bottlenecks appear. Authentication breaks. Application dependencies fail. Recovery times suddenly sit miles outside the organisation’s SLA targets.

Most businesses never see these problems because they rarely perform restores – especially not at high frequency and at scale.

Predatar does.

And when you continuously test recoverability at scale, you uncover things that would otherwise stay hidden until a real disaster.

What’s wrong with the CleanRoom?

If a restore fails inside the CleanRoom or recovery speeds are slower than expected, customers will often ask “Is something wrong with the CleanRoom?”

But the better question is usually “Is something wrong with my backup estate?” Because in almost every case, the issue isn’t the tech – The CleanRoom is simply exposing it.

It might be a problem with the backup itself. It might be storage performance, network throughput, infrastructure drift, inconsistent protection policies or application level issues inside production.

The restore told the truth.

And that truth is incredibly valuable – because the worst possible moment to discover your backups are slow, inconsistent or unrecoverable – is when your production estate is already offline.

Why the reaction is different

We’ve always found it interesting that organisations naturally celebrate malware discovery, but often react differently to failed restores. In both cases, the platform is doing the same thing. It’s doing exactly what it was designed to do. It’s exposing hidden risks before they become business critical events.

The difference is emotional.

When malware is found, the platform feels like a hero.

When recoverability gaps are exposed, it can feel more personal because the findings challenge assumptions that teams have often trusted for years.

But the outcome is the same. A hidden problem was found, before a real recovery event forced the issue under pressure.

That should always be seen as a win.

The real purpose of recovery testing

The purpose of resilience testing is not to make customers feel comfortable. It’s to make sure they’re important systems are recoverable when reality gets uncomfortable.

The reality is cyber resilience isn’t about whether backups exist. It’s about whether recovery actually works when you need it most.

That means proving recoverability continuously – not assuming it.

Sometimes the process finds malware. Sometimes it finds operational weaknesses. Sometimes it finds both. All of these outcomes are valuable – because every issue discovered during testing is one less surprise during a real recovery event.

…And in a real cyber recovery scenario, surprises can be devastating.

Learn more about
Predatar recovery assurance

08 May 2026

Clean Rooms: Reactive vs Ready

Over the past few years, several leading backup vendors have popularised the idea of the Cloud Clean Room.

On paper, it’s compelling.

You spin up an isolated environment in the cloud. The provider handles the infrastructure. You bring in your backup data, start analysing it, and try to figure out what’s clean and what’s compromised.

It’s fast to deploy. Convenient. And when you’re in the middle of an incident, that simplicity matters.

But there’s a catch, actually there are a few.

First, your data has to be in the cloud. If it isn’t already, you’re now dealing with transfer times, bandwidth constraints, and inevitably cost. Egress charges alone can turn a bad day into an expensive one.

Second, these environments are fundamentally reactive. They’re built for after the attack. A forensic lab to investigate what happened and piece together a recovery plan.

And third, they tend to be vendor-specific. If your world includes multiple backup platforms or even primary storage snapshots, you may find yourself limited. One clean room, one ecosystem.

Convenient? Yes. Flexible? Not always.

A different approach: the on-prem (and everywhere) Clean Room

Now flip the perspective.

What if the clean room wasn’t something you scrambled to build after an incident…
but something you were already using before one?

That’s the idea behind the Predatar CleanRoomTM.

Instead of being tied to a single cloud or vendor, it’s deployable anywhere, on-prem, in a colo, or in the cloud. It arrives as a simple OVA and plugs into a wide range of backup and storage platforms.

But the real shift isn’t where it runs. It’s how it’s used.

This is a proactive clean room.

Rather than waiting for an attack, it continuously tests your ability to recover. Not just “does the backup exist?”, but “can I restore this data quickly, cleanly, and completely?”

That’s Recovery Assurance.

And it changes the conversation.

Proof, not promises

Most backup vendors will tell you your data is safe.

Predatar takes a different stance: Prove it.

Because it’s vendor-agnostic, it’s not marking its own homework. It’s independently validating whether your recovery actually works across all your backup tools, not just one.

There’s also an unexpected side effect.

When you’re testing recovery daily, you start to see things.

Dormant threats. Hidden artifacts. Things that slipped past production security tools.

At the time of writing, 93% of Predatar customers have discovered malware in their backups, including ransomware payloads, ransomware notes, and spyware that went undetected elsewhere.

That’s not just recovery testing. That’s early warning.

So, which is better?

It’s not a simple “this vs that.”

Cloud Clean Rooms are fast, accessible, and useful in the heat of an incident. They give you a place to investigate when things have already gone wrong.

But they’re reactive, tied to specific vendors, and dependent on cloud data logistics.

Predatar’s CleanRoomTM, on the other hand, is about readiness.
It’s flexible, vendor-agnostic, and designed to answer a big question before disaster strikes…

Can we recover – right now – without surprises?

The real takeaway

In a ransomware event, time is everything.

Cloud Clean Rooms help you respond.
Proactive Clean Rooms help you not panic in the first place.

And if you can walk into that 2:17am moment already knowing your data is clean and recoverable?

That’s not just resilience.
That’s true Recovery Assurance.



Learn more about
Predatar recovery assurance

28 April 2026

Is your next backup administrator an AI agent?

In July 2024, we asked a provocative question: Will AI replace the backup administrator? Read the original blog here.

At the time, Predatar had just released R16 Orca, and “Generative AI” was the phrase on everyone’s lips. “Agentic AI”– systems capable of autonomous, goal-driven action – was not yet part of mainstream thinking, at least not in the wider public domain. It wasn’t until later in 2024 that agentic AI began to enter the broader discourse. Since then, the conversation, and the tech, has moved at a blistering pace.

Our original conclusion still stands: the backup administrator is here to stay. But the nature of the role is changing far more dramatically than we anticipated. With the emergence of agentic AI, we are moving beyond assistance into true autonomy in backup and recovery operations.

So, what’s now possible? Agentic AI opens the door to capabilities such as automatically scheduling and optimizing backups based on real-time conditions, dynamically building and fine-tuning recovery plans, and intelligently orchestrating the order of restores to achieve the fastest recovery outcomes. It can also respond in real time to AI-driven anomaly detection, adjusting protection strategies or initiating defensive actions as threats emerge.

While it is possible to build these capabilities into operational management platforms, it’s still early days. The industry is just beginning to explore what fully autonomous data protection looks like, and it will be some time before these systems reach full maturity. We predict that until 2028, the model will be “human-on-the-loop”. The backup administrator role will remain as important as ever, perhaps even more so. From 2028 onwards, the role will evolve. The human backup administrator will take on more of an AI governance role. This is often described as “human-before-the-loop”, where the backup admin provides the initial guardrails that allow AI to act independently.

The threat landscape is accelerating. Backup vendors know this and are scrambling to catch up. They face a new kind of arms race against AI-enabled threat actors who are actively disrupting the ability to recover. This is no longer just about encryption or threat detection. It’s about proving resilience.

The response is clear: we must fight fire with fire. Embracing agentic AI within cyber resilience platforms is the only viable path to keep pace.

At Predatar, this shift is already well underway. We have made a decisive, seismic move to re-engineer our entire platform – spanning monitoring, automation, recovery assurance, and CleanRoom capabilities – around agentic AI. This is not a feature enhancement; it is a fundamental redesign.

Will we see a day when agents are truly autonomous, and the backup admin is fully “human-out-of-the-loop”? We’re not prepared to say. We are good, but not that good.


Stay in the loop with Predatar News

If you’re a human and you like being in the loop (from a news perspective), join our mailing list to get the latest news and insights from the Recovery Assurance trailblazers at Predatar. Sign up here.


Learn more about
Predatar recovery assurance

22 April 2026

Everyone Thinks Clean Rooms Are Expensive

By Rick Norgate, CEO, Predatar.

I spend a lot of my time talking to vendors, partners and customers across the storage, security and business continuity ecosystems. Different roles, different priorities, but the same conversation keeps coming up. At some point, Clean Rooms enter the discussion and almost without fail I hear a version of the same response… “We love the idea… but Clean Rooms are expensive.”

Not All Clean Rooms Are Created Equal

Not only is the perception not universally true, but there’s another layer to it as well. Ask ten people what a “Clean Room” is and you’ll get ten different answers. For some it’s about detection, for others it’s isolation, or a last resort recovery space. The reality is not all Clean Rooms are equal, and a lot of the confusion in the market comes from that.

The Industry Created This Problem

To be fair, the perception around cost didn’t come from nowhere. The industry has, over time, shaped it. The industry has tied Clean Rooms to heavy, hardware led approaches, large deployments, dedicated infrastructure and significant upfront investment before you see any value.

Traditional solutions such as the Dell Cyber Recovery Vault is a good example of where that thinking comes from. They are built around sizeable hardware estates and focus on encryption detection at scale, identifying when ransomware has started encrypting data. That has real value, but it also tells you something important. By the time you are detecting encryption, the attack is already in motion. You are reacting, not proving anything and you have likely already invested heavily just to get there.

Costs Are Making It Worse

Fast forward to 2026 and the situation is getting tougher. Hardware costs have jumped significantly, with increases of up to 50% not uncommon. So the mental equation becomes even harder to justify. People see Clean Rooms as valuable, but expensive, complex, and something to come back to later.

But that is not what a Clean Room should be.

The Only Question That Matters

When I speak to customers, especially security and business continuity teams, very few are asking for better detection tools. What they really want to know is much simpler.

“If we get hit, can we recover? Not in theory, not based on a report, but for real. Can we recover quickly, cleanly, and completely?”

That is the problem that matters, and it is the problem we set out to solve with Predatar CleanRoomTM, our Isolated Recovery Environment.

Proving Recovery Changes Everything

Instead of waiting for something bad to happen, the Predatar approach is to continuously prove that recovery works. We automatically recover backups and primary snapshots into isolation, test whether those systems come back clean and usable and scan for malware as part of that process. You do not need any manual effort to kick this off. We run fully automated restore testing at scale across both primary and secondary data and we do it in a completely vendor agnostic way.

That combination matters. It means you are not tied to a single backup platform or storage vendor, and you are not relying on periodic, manual testing that may or may not happen. You are continuously validating your ability to recover across your actual estate.

What You Find When You Actually Test

And when organisations start doing this properly, something interesting happens. They do not just gain confidence in recovery, they uncover risks they did not know existed. Dormant malware, planted threats, things that have not triggered yet but would have eventually. Across our customer base, 93% have found malware sitting in their backups. These are not organisations in the middle of an attack. These are organisations doing the right thing, testing and validating and still finding hidden exposure.

Why Cost Still Dominates the Conversation

So why does cost still dominate the conversation? Because most people still believe Clean Rooms require a huge upfront commitment. Big hardware, big rollout, big decision. And when something feels that significant, it gets delayed. I see it all the time, projects pushed into next year, endless scoping exercises, teams waiting for the right moment. But resilience doesn’t work like that. You do not get to choose when you need it.

A Clean Room Without the Hardware Burden

This is exactly why we took a different approach with Predatar. We deliver the Predatar CleanRoom as a virtual appliance. You can deploy it into your existing environment, whether that is your virtual platform, repurposed hardware or simply spare capacity you already have. In fact, over 70% of our customers deploy using resources they already own, with no new hardware investment required. What used to be a capital heavy decision becomes an operational one, and that changes how organisations approach it.

Start Small and Scale When You’re Ready

Many teams assume that if they adopt a Clean Room, they have to do everything at once. In reality, the most successful organisations start small. They focus on what matters most, a minimum viable business service, a critical application, or a subset of their environment such as key VMware workloads. They prove recovery there first and then expand over time. There is no need for a big bang rollout or an all in commitment from day one.

One View Across a Fragmented Estate

Another challenge many organisations face is fragmentation. Multiple backup platforms, multiple storage systems, and multiple tools all trying to answer the same question in slightly different ways. Can we recover? Predatar works across backups and primary snapshots, across vendors and platforms, to give you a single, consistent view of recovery confidence.

The Real Barrier Isn’t Technology

If there is one thing I have learned from these conversations, it is this: perception, not technology, is the biggest barrier to adopting Clean Rooms. If people believe they are expensive, complex, and hardware-heavy, they will keep putting them off. But when we redefine them as something lightweight, flexible, and focused on proving recovery, the conversation changes very quickly.

It All Comes Down to One Question

Because in the end, resilience is not about how fast you detect a problem. It is about what happens next. Can you recover quickly, cleanly, and completely?

That is the only question that really matters, and it is one the industry needs to get better at answering.

If you are having the same conversations and want to challenge the assumptions around Clean Rooms, we would welcome the discussion. Drop us a line.

Learn more about
Predatar recovery assurance