Key takeaways
- Opening a banking app, ordering food, or buying a pair of shoes online may not feel remarkable anymore, but what’s undeniably remarkable is…
- Once dominated by ransomware attacks, the threat has now become something even more damaging.
- As the concerns get real, boardrooms across industries are realising the gravity of a weak cybersecurity wall.
What happened
Opening a banking app, ordering food, or buying a pair of shoes online may not feel remarkable anymore, but what’s undeniably remarkable is the robust cloud infrastructure that is powering these everyday actions. It is this dexterity that also makes it vulnerable to cyberattacks. Over the years, while security protocols have evolved, so has the sophistication of cyberattacks.
Research from Rubrik Zero Labs found that 70% of APAC respondents lack full oversight of their AI agents, and 81% believe AI agents will outpace their existing security guardrails within 12 months. Eighty-one per cent is a genuinely uncomfortable statistic for a region that’s moving as fast on AI adoption as APAC is.
The macro pattern is straightforward: teams get excited about a Gen AI or agentic use case, connect it to whatever data store is closest, and only afterwards discover that the pipeline had access to unclassified PII (Personally Identifiable Information), financial records, or regulated health data. Separate industry research on the region has found a similar gap.
A large share of APAC organisations believe they know where their data lives, yet a significant minority still struggle to actually use it because of siloed access rules. Confidence without control is exactly how sensitive data ends up in an AI model’s training or inference pipeline without anyone even realising it.
Without real-time data intelligence (automated discovery and classification that run continuously rather than as a point-in-time audit), organisations can’t answer basic governance questions, such as what sensitive data exists, who or what can reach it, and whether an AI pipeline is already touching it. Rubrik’s own data security posture management approach exists specifically to close that gap by classifying data before it becomes an AI liability.
Why it matters
Once dominated by ransomware attacks, the threat has now become something even more damaging. Attackers have started targeting identity systems — the credentials and access controls that give administrators the keys to their infrastructure. Some attackers go even further and hit the backups too. So, when a disaster actually strikes, there’s nothing left to fall back on. Most companies only realise this after the attack.
As the concerns get real, boardrooms across industries are realising the gravity of a weak cybersecurity wall. And with laws like India’s DPDP Act now raising the stakes for how organisations collect, store and protect data, security is increasingly becoming a business continuity issue rather than just a compliance requirement.
To understand how enterprises can navigate high-stakes situations like this, Inc42 spoke with Ananth Nag, vice president (APAC) at Rubrik, who broke down the transition to an ‘assume-breach’ architecture, the risks of unchecked data sprawl, and why recovery speed is the ultimate metric for modern business continuity. Inc42: What is the fundamental difference between standard data backup and true ‘cyber resilience’ that many business leaders do not realise?
Ananth Nag: Many organisations continue to view backup as the ultimate safety net, assuming that if something goes wrong, they can simply restore their data and resume operations. However, that mindset no longer reflects the realities of today’s threat landscape. There is a significant difference between having a backup and having a recovery strategy that remains effective during a cyberattack. Targeting of backup environments is on the rise.
Rather than focusing solely on production systems, attackers now attempt to compromise backup infrastructure first, knowing that it represents the organisation’s last line of defence. Backups can be altered or deleted during an attack. Their existence alone does not guarantee recoverability if they have already been compromised. Cyber resilience is now critical.
Effective resilience is not simply about creating copies of data; it is about being able to identify a clean, trusted recovery point and restore operations quickly, even while an attack is still unfolding The focus today needs to move beyond backup as a storage exercise and towards ensuring that recovery capabilities are resilient, tested and capable of supporting the business when it matters most.
Inc42: As someone managing diverse markets, what macro risks do you see when organisations pull unmapped, highly sensitive data into live AI pipelines without established real-time data-intelligence guardrails? Ananth Nag: The biggest risk occurs when organisations try to secure something they can’t see.
What to watch
Inc42: With threat actors heavily targeting the identity layer, how should enterprise leaders redefine access control when administrative accounts themselves are compromised? Ananth Nag: The old model of access control assumes the administrator is trustworthy, that once someone has the keys, they’re the good guy. Identity-based attacks break that assumption completely.
Rubrik’s research points to identity compromise as the starting point for the overwhelming majority of serious intrusions into critical infrastructure, with attackers using stolen credentials to escalate privileges and move laterally rather than technical exploits. The redefinition enterprise leaders need to make is to treat identity infrastructure as something that must be recoverable. This is the premise behind an ‘assume breach’ mindset.




