By Edwin Thornhill, Vice President, Enterprise Architecture, Arctiq
Cyberattacks, infrastructure outages, and platform disruptions are no longer rare operational events. For many organizations, breaches are an expected part of operation. As a result, the role of hybrid infrastructure has shifted. What used to revolve around performance optimization or cloud modernization must now also incorporate maintaining operational continuity in the event of disruption.
Today, traditional infrastructure planning is reaching its limit due to factors such as AI-enabled threats, volatile vendor pricing, and increasingly complex regulatory requirements. At the same time, workloads continue to migrate across on-premises environments, public cloud platforms, and edge locations. These changes are forcing organizations to reassess how their infrastructure, identity, and data protection strategies interact during recovery.
The central question facing infrastructure and resilience teams is no longer simply whether systems are protected, but whether the organization can restore minimum viable operations when disruption inevitably occurs.
Several developments are already reshaping how organizations design, secure, and operate hybrid environments. Together, they illustrate how cyber resilience and data protection strategies are evolving in 2026.
1. Data Protection Is Shifting from Backup to Business Recovery
For years, data protection discussions focused primarily on backup technologies, even more so, on recovery outcomes.
Modern cyberattacks rarely involve a single compromised system. Ransomware campaigns frequently target applications, identity systems, backups, and infrastructure simultaneously. As a result, organizations are focusing less on whether backups exist and more on reliably restoring operations.
The financial impact of these incidents continues to grow, with ransomware remaining one of the most disruptive threats. The Veeam Ransomware Trends Report found that ransomware continues to be a major cause of downtime, with 41% of data compromised during a cyberattack, and, on average, only 57% of data is recoverable.
In response, resilience strategies are shifting toward recovery sequencing and triage. Organizations are identifying which applications, identities, and datasets must be restored first so the business can stay operational as a minimum viable company (MVC).
The key question is no longer simply, “Is my data protected?” but rather, “How quickly can we restore the services the business depends on?”
2. Tool Consolidation Is Increasing Under Security and Cost Pressure
As hybrid environments grow more complex, organizations are consolidating backup and disaster recovery tools into broader cyber resilience platforms.
Managing multiple recovery systems introduces multiple security models, monitoring tools, and recovery workflows. During an incident, this fragmentation can slow response times and increase operational complexity.
Consolidation can provide several benefits:
- Unified visibility across data, applications, and identity
- Coordinated recovery workflows
- Reduced operational complexity during incident response
It also enables advanced capabilities such as forensic analysis of recovery points to determine when an attack began and what data can be safely restored.
At the same time, organizations are revisiting retention strategies. Data volumes continue to grow, and storage costs alongside them. Data and Storage cost increases make retaining every dataset indefinitely less and less sustainable. Instead, resilience planning increasingly focuses not only on protecting but also restoring the information required to sustain business operations.
3. Identity Is Becoming Central to Recovery Strategy
Hybrid work, SaaS adoption, and multi-cloud architectures are expanding, making identity systems the most critical components of modern infrastructure.
Compromised credentials alone account for a significant share of these security incidents. Verizon Data Breach Investigations Reports consistently find that stolen credentials are a common initial access method, appearing in roughly one-fifth of confirmed breaches in the 2025 report.
This shift has significant implications for disaster recovery planning. Even when IT teams can restore applications and data, organizations may struggle to regain control of systems if their identity services cannot be recovered.
As a result, identity infrastructure is a core recovery dependency. Directory services, cloud identity platforms, and access control systems must be protected, backed up, and recoverable alongside application data.
Organizations are strengthening identity resilience through practices such as privileged access management, least-privilege access models, and stronger administrative controls. The ability to restore identity services quickly may determine whether recovery efforts succeed.
4. Market Volatility is Influencing Infrastructure Strategy
Hybrid infrastructure decisions are increasingly shaped by rapid changes in vendor pricing, licensing models, and platform strategies.
Unexpected cost increases have forced many organizations to reassess infrastructure roadmaps. In some cases, workloads are caught between on-premises platforms and cloud environments, primarily in response to cost pressures rather than architectural strategy.
This environment introduces new complexity for resilience planning. Infrastructure migrations performed under time pressure may overlook important recovery considerations such as replication architecture, recovery locations, or application dependencies.
As a result, organizations are placing greater emphasis on long-term resilience planning when making infrastructure decisions. Rather than focusing solely on short-term cost savings, teams are evaluating how infrastructure choices affect recovery speed, operational flexibility, and vendor risk.
5. Consumption Models are Regaining Strategic Importance
Rising hardware and licensing costs are renewing interest in operational expenditure (OpEx) infrastructure models.
Consumption-based infrastructure can provide financial predictability in an environment where technology pricing is increasingly volatile. These models also help organizations to dynamically scale infrastructure capacity, which can be valuable during large-scale recovery events when legal investigations can freeze physical/virtual assets.
Beyond financial flexibility, consumption models are increasingly viewed as part of resilience planning. They enable organizations to maintain recovery capacity without large upfront capital investments and reduce exposure to sudden vendor pricing changes.
For many organizations, infrastructure procurement is becoming as much a risk management decision as a financial one.
6. Resilience Is Measured at the Application Level
Traditional disaster recovery strategies often focused on restoring infrastructure. Today, organizations recognize that infrastructure availability alone does not guarantee application availability.
Cloud outages and platform disruptions have demonstrated that failures in managed services, identity systems, or networking layers can interrupt services even when infrastructure remains online.
In response, resilience planning is shifting toward application-level recovery strategies. Organizations are mapping application dependencies, understanding access paths between users and services, and prioritizing recovery based on business impact.
Recovery is no longer about simply restoring servers; it’s about getting the services people rely on back up and running.
The Practical Reality of Resilience
In 2026, we are watching resilience requirements rather than optimization goals, which are increasingly defining hybrid infrastructure and data protection strategies. Organizations must now consider how identity systems, applications, infrastructure platforms, and recovery environments interact during disruption.
The organizations best prepared for this environment are those that clearly define their minimum viable operations, understand the dependencies that support those services, and design recovery plans around restoring them quickly.
In a world shaped by sophisticated cyber threats and growing infrastructure complexity, resilience planning has become a central discipline for protecting business continuity.
About the Author

Edwin Thornhill is Vice President, Enterprise Architecture at Arctiq, where he focuses on designing scalable, business-aligned IT solutions. With a background in solutions architecture and infrastructure strategy, he has led the development of complex technology environments that enhance customer experience while improving operational efficiency.

