
I’m a CISO and I believe in prevention not hope – patch fast, reduce attack surface, segment, monitor, and hunt. But we also need to be honest about what changes when cyber risk starts operating at machine speed. If your defence strategy relies on your team’s ability to out-pace an autonomous system, you’ve already lost the recovery race. Because ultimately, the real risk is not the breach itself, it is the inability to recover quickly enough once the breach has already happened.
The timeline between exposure and impact is collapsing
Prevention is not enough. When Anthropic introduced Claude Mythos earlier this year, much of the discussion focused on the AI model’s demonstrated ability of identifying and exploiting zero‑day vulnerabilities and turning known vulnerabilities into working exploits more quickly. The implication is simple – the path from “weakness exists” to “unauthorised access happens” is getting shorter.
Historically, the challenge for attackers was not simply finding vulnerabilities – it was turning those weaknesses into reliable exploits at speed and scale. That process required expertise, coordination, and time. As that barrier lowers, the economics of cyber risk begin to shift. Attacker throughput increases, discovery cycles compress, and organisations are forced to operate within much smaller response windows.
Where the idea of “AI vandalism” becomes important
Traditional cyber attacks were often targeted, strategic, or financially motivated. AI-driven attacks introduce the possibility of disruption at a completely different scale because the cost and effort required to create chaos drops dramatically. When autonomous systems can probe environments continuously, identify weak points, and execute attack chains without human fatigue or resource limitations, organisations are no longer defending against isolated incidents. They are defending against AI vandalism.
That does not mean prevention no longer matters, it does. However, prevention alone becomes a thinner shield when organisations are still operating within human constraints – change windows, governance processes, patch cycles, operational dependencies, and competing business priorities – while threats increasingly operate without those limitations.
AI vandalism changes the scale of disruption
AI vandalism does not operate one file at a time. Autonomous attack systems are capable of moving across environments, permissions, identities, and interconnected applications simultaneously. By the time an organisation identifies suspicious behaviour, the compromise may already extend across productivity applications, identity systems, administrative controls, and potentially even recovery pathways themselves.
This fundamentally changes the role recovery plays inside the enterprise as it is no longer simply about retrieving lost data. It is about restoring operational continuity under compressed timelines, often while investigations and containment activities are still ongoing. The organisations that recover effectively will not necessarily be the ones with the largest security teams or the most alerts. They will be the organisations that understand exactly what needs to survive for the business to continue functioning and can restore those capabilities quickly and precisely.
The next level of recovery planning
Recovery planning cannot stop at business content, it has to extend to the access layer that enables the broader SaaS environment to function. Identity applications such as Microsoft Entra ID and Okta increasingly underpin the modern SaaS estate, managing the identities, permissions, policies, and access rights that allow productivity environments to function securely. If identity systems fail, business operations slow or stop altogether.
Yet despite their operational importance, identity systems remain significantly under-tested compared to productivity applications. According to our recent data report, productivity applications are restored four times more frequently than identity applications.
That gap highlights an important maturity issue. Organisations are generally further along operationalising recovery for collaboration and productivity workloads because those systems create immediate user-facing disruption when data is missing. Identity systems, however, often remain invisible until access itself becomes compromised.
Identity has effectively become the operational control plane of the enterprise, making it an increasingly attractive target for attacks designed to exploit permissions, policies, and access pathways at scale.
The problem with shared operational dependencies
Many organisations now operate large parts of their business inside a relatively small number of hyperscaler ecosystems. Production environments, identity services, and recovery environments increasingly share the same operational dependencies. While that creates efficiency, it also introduces risk because attackers are no longer just targeting production systems. Increasingly, they are targeting recoverability itself.
Modern ransomware groups already attempt to compromise or destroy backup systems before detonating payloads. AI-enabled attacks are likely to accelerate that trend further by autonomously identifying recovery pathways and operational dependencies far faster than traditional attack workflows allowed.
Resilience is moving from policy to architecture
Immutability may not offer the strongest line of defence either, depending on how it is implemented. If it relies purely on operational settings or administrative controls, autonomous attacks capable of exploiting administrative pathways may simply disable those protections before the organisation even realises compromise has occurred. Structural immutability changes that equation because resilience becomes embedded into the architecture itself rather than dependent on operational configuration.
In practice, organisations are increasingly converging around four operational requirements for resilient SaaS data protection – architectural independence, immutable recovery design, granular restore capability, and protection of the identity layer itself. These are no longer “best practices” for mature organisations. They are becoming baseline requirements for operating safely in an AI-driven threat environment.
Why resilience can no longer be treated as “good hygiene”
Too often, resilience is still discussed as a downstream IT capability rather than a core operational requirement. Backup is frequently positioned as “good hygiene”, something that sits quietly in the background until needed. But once attackers gain access to an environment, recovery becomes the most important security control an organisation has left – not because it prevents compromise, but because it determines whether the business can continue to operate when compromise occurs.
That distinction is becoming increasingly important as organisations expand their reliance on SaaS environments and identity-driven operating models.
Our research provides a useful operational lens into how organisations actually recover data in practice. What the data shows is that restore behaviour today is still overwhelmingly shaped around smaller-scale operational incidents rather than large-scale disruption events. Single file downloads account for 90% of restore operations globally.
That pattern makes sense in the context most organisations are optimised for – deleted documents, overwritten files, missing emails, or isolated user issues that need immediate resolution. As a result, recovery systems are primarily designed and used for rapid, granular fixes rather than full-scale recovery operations.
Awareness does not equal readiness
Perhaps the most revealing insight in the research data, however, is behavioural rather than technical.
Researchers analysed restore activity around several high-profile global disruption events, including the CrowdStrike incident and major Microsoft outages, to determine whether those events changed recovery behaviour. What they found was that there was no measurable increase in restore testing activity following the incidents.
That finding highlights an uncomfortable reality across the industry that awareness does not automatically create operational readiness. Most organisations understand cyber risk conceptually. Far fewer operationalise recovery as a repeatable discipline. Recovery confidence is not created through policy documents or assumptions that backups exist somewhere in the environment. It is built through regular testing, guided recovery exercises, operational familiarity, and an understanding of how systems behave under pressure.
The resilience questions organisations now need to answer
Mythos matters not because it changes the existence of cyber risk, but because it changes the speed, scale, and operational pressure organisations must now recover under.
That leaves every leadership team facing three increasingly urgent questions:
- How quickly could you identify the last known good version of your SaaS data and prove it?
- If admin access is compromised or automation goes wrong, can your backups still be deleted or overwritten?
- Can you restore only what was affected, quickly, without a full environment rollback?
If those questions make you uncomfortable, good. Discomfort is a signal that you’re replacing assumptions with understanding.
Hope isn’t a security strategy. Recovery is.


