Partner Spotlight
Dr. Mazen Abduljabbar
Country Manager – KSA
Commvault
AI is forcing organizations to rethink resilience
Nearly four years into the GenAI revolution, many organizations have decisively moved from experimentation to operational deployment. Another sign of this market maturity is the growing emphasis on governance, ethics, security controls, and regulatory compliance, illustrated by the arrival of formalized rules.
But as is becoming increasingly clear, implementing AI is one thing; almost anyone can do that. Implementing it correctly, with the proper safeguards in place, is something else entirely, and there are some major risks to address. As was inevitable, more and more stories are emerging about what happens when organizations rely on AI outputs that later prove to be extremely damaging.
The role of ResOps
When it comes to resilience, there is now a very important question: how can organizations committed to AI define and apply a version of resilience that is fit for purpose?
Firstly, it’s important to recognize that resilience models would typically treat security and recovery as separate functions. This approach was (and still is) effective when incidents can be contained, and organizations have the time to investigate what has happened.
Identifying a problem is only part of the challenge. Organizations also need to understand where affected data has traveled and what else depends on it. Visibility into the various AI and data dependencies is becoming as important as recovery itself, because restoring systems is much harder when organizations cannot immediately determine what has been affected, unless significant.
As a result, the nature of resilience needs to change. It’s no longer good enough for it to lean towards the reactive; it needs to operate as a continuous operational discipline. In a nutshell, that is the basis for ResOps (Resilience Operations), in which data security is more closely integrated with recovery to maintain trust in operational environments over time. Recovery remains important, but it becomes part of a broader resilience process that continuously discovers, protects, monitors, and restores trusted data.
Through a ‘Resilient Operations’ approach, teams can quickly determine what has been affected and which AI workloads depend on the compromised data. The objective is not simply to recover systems but to ensure that AI continues to operate on trusted data. Given that, in many ways, AI has changed the nature of risk, resilience must follow suit if we are to avoid a situation where breaches and serious errors are to remain the exception rather than becoming the rule.