Why Backups Aren't Enough & Identity Recovery is Key against Ransomware

Why Backups Aren't Enough & Identity Recovery is Key against Ransomware

🎙 Cloud Security Podcast 👥 39K 📅 December 16, 2025 ⏱ 37 min 👁 20K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

cyber resilienceransomwareidentity recoverycloud backupDORA

Summary

In this episode of the Cloud Security Podcast, host Ashish Rajan interviews Matt Castriotta, Field CTO for Cloud at Rubrik, on the topic of cyber resilience. Matt distinguishes between disaster recovery (DR) and cyber recovery, emphasizing that DR assumes data and identity remain trusted, whereas cyber recovery must handle untrusted data and identity after an attack. He argues that simply having backups is insufficient; organizations must have the ability to recover cleanly and quickly. He highlights common misconceptions in cloud-native environments, such as relying on S3 versioning or replication, which are not valid cyber recovery strategies because they replicate the impact. The conversation covers the importance of identity as the new perimeter, noting that if identity systems like Active Directory or Entra ID are compromised, everything else is inaccessible. Matt stresses that identity must be backed up and recoverable, potentially through forest-level recovery. The discussion also touches on DORA compliance, multi-cloud resiliency, egress costs, and the shared responsibility model. Finally, they explore the impact of AI agents on data integrity and the need to ‘rewind’ AI actions, with Matt introducing Rubrik’s Agent Cloud. Practical advice includes conducting tabletop exercises, adopting an assume-breach mindset, and prioritizing identity recovery in resiliency programs.

200 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners in cloud security and resilience. Matt provides clear distinctions between operational recovery and cyber recovery, and he offers concrete examples of common pitfalls, such as S3 versioning and replication being mistaken for backups. The argumentation is solid, grounded in real-world scenarios and industry experience. He effectively explains why identity recovery is critical, using the analogy of identity as the new perimeter and ground zero. The discussion on DORA compliance and multi-cloud challenges adds practical value. However, the arguments are largely anecdotal and lack empirical data or case studies, which slightly weakens the scientific rigor. The reasoning is logical and well-structured, but it relies on expert opinion rather than verifiable evidence.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The episode is an expert opinion piece, not a peer-reviewed study. The claims are plausible and align with industry best practices, but they are not supported by cited research or data. The sources cited in the description are primarily promotional (podcast website, bootcamp, newsletter) and do not provide direct references to the topics discussed. The title accurately reflects the content, focusing on the inadequacy of backups and the importance of identity recovery. The discussion is coherent and stays on topic, with no significant digressions. No comments were provided for analysis, so public reception is not assessed.

235 words

Title / Content Match

The title accurately reflects the core themes: the inadequacy of backups alone and the critical role of identity recovery in ransomware resilience.

Quality & Reliability

7/10

The podcast features a field CTO from Rubrik, providing expert insights on cyber resilience, identity recovery, and cloud-native risks. The discussion is practical and grounded in industry experience, but it is largely opinion-based without citing specific studies or data. The claims about cloud-native recovery limitations and identity as the new perimeter are plausible and align with industry best practices, but they are not backed by empirical evidence in the episode.

Chapters

Cited Sources

Concurring Sources

Dissenting Sources

  • AWS S3 Versioning Documentation — AWS presents S3 versioning as a data protection feature, but the episode argues it is not sufficient for cyber recovery because it replicates the impact.

Contribution & Novelties

The episode provides a clear and practical framework for distinguishing between disaster recovery and cyber recovery, emphasizing the need for identity recovery as a core component. It challenges common misconceptions about cloud-native backup strategies and highlights the importance of treating identity as a critical data source. The discussion on AI agents and the need to ‘rewind’ their actions introduces a forward-looking perspective on data integrity.

Pour aller plus loin :

123 words

Radar Profile

The radar profile shows high scores in quantity of information and technical level, indicating a content-rich episode with moderate technical depth. The quality and reliability scores are slightly lower, reflecting the opinion-based nature of the discussion. The overall profile suggests a valuable resource for practitioners seeking practical insights, but with limited empirical backing.

Reliability 7/10