惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
云风的 BLOG
云风的 BLOG
aimingoo的专栏
aimingoo的专栏
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
F
Full Disclosure
A
About on SuperTechFans
C
Check Point Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
量子位
Know Your Adversary
Know Your Adversary
K
Kaspersky official blog
L
LINUX DO - 热门话题
Recorded Future
Recorded Future
C
Cisco Blogs
M
MIT News - Artificial intelligence
T
Tenable Blog
G
GRAHAM CLULEY
月光博客
月光博客
Recent Announcements
Recent Announcements
V
Visual Studio Blog
IT之家
IT之家
T
The Exploit Database - CXSecurity.com
The GitHub Blog
The GitHub Blog
T
Threat Research - Cisco Blogs
D
DataBreaches.Net
P
Privacy International News Feed
P
Proofpoint News Feed
I
Intezer
博客园 - 叶小钗
C
CXSECURITY Database RSS Feed - CXSecurity.com
The Hacker News
The Hacker News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - Franky
SecWiki News
SecWiki News
宝玉的分享
宝玉的分享
P
Palo Alto Networks Blog
Last Week in AI
Last Week in AI
小众软件
小众软件
Hacker News - Newest:
Hacker News - Newest: "LLM"
O
OpenAI News
N
News and Events Feed by Topic
Microsoft Security Blog
Microsoft Security Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
N
News and Events Feed by Topic
The Cloudflare Blog
Spread Privacy
Spread Privacy
酷 壳 – CoolShell
酷 壳 – CoolShell
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
B
Blog RSS Feed

informationweek

2026 tech company layoffs InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO AI on trial: The Workday case that CIOs can The AI infrastructure boom is coming for enterprise budgets How CIOs can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy, Cleveland Clinic CIOs on scaling AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce The AI contract gaps the Google-Pentagon deal just made visible Non-human identity sprawl is agentic AI's real risk Anthropic's Mythos forces a rethink of vulnerability management Outsourcing contracts weren't built for AI. CIOs are renegotiating now The AI spend hangover companies didn't plan for The power of CIO networking in the competitive AI world Why CIOs see AI projects stall: Speed without structure kills scale IT leaders should never let a good crisis go to waste SFO's digital twin maps airport operations from the curb to takeoff CIOs caught in the middle as AI startups disrupt vertical Saas Submit an IT Leadership column to InformationWeek Podcast: Rightsizing AI frameworks to avoid failure modes The invisible labor crisis inside IT: AI work the org chart can't see Why AI teams treat training data like capital Ask the Experts: How CIOs can identify and overcome cultural barriers to innovation Nobody told legal about your RAG pipeline -- why that's a problem Meta's new 'AI Zuckerberg' is a mirror for every C-suite Will the music stop for AI's funding dance? Rethink tech talent: Local is the smartest play for IT InformationWeek Podcast: Catching errors in AI-powered code CIOs can combat talent scarcity with AI-augmented leadership -- Gartner How Bellevue, Wash., is applying AI to streamline a broken permitting process Ignore the hype: Smarter tech bets at speed of change Who controls the fix? Colorado's repair fight tests CIO power Ask the Experts: The red flags that signal an AI project isn't worth pursuing The hidden high cost of training AI on AI Red Hat's Marco Bill: Resource control is key for AI sovereignty InformationWeek Podcast: New IT architecture, cloud, edge and AI Enterprises need Tier 1 provider relationships to deliver on AI How CIOs run and rebuild the business at the same time in the AI era It's not your tech stack, it's your structure -- fix it Confidential computing resurfaces as security priority for CIOs FinOps: Helpful tool, or a cloud control placebo for CIOs? Cleveland's open data overhaul: From sticky notes to public dashboards As Microsoft expands Copilot, CIOs face a new AI security gap Why build vs. buy doesn't fit modern IT systems InformationWeek Podcast: Is quantum computing slumbering? Your AI vendor is now a single point of failure Vibe coding: Speed without security is a liability A practical guide to controlling AI agent costs before they spiral AI fuels a new wave of technical debt The sunsetting of Sora: A hard lesson in AI portfolio resilience HP pushes broad internal AI use after early productivity gains Why value-based pricing is inevitable InformationWeek Podcast: Safeguarding ecosystems from outsiders Why AI scaling is so hard -- and what CIOs say works Humans are the North Star for AI-native workplaces -- Gartner How IT leaders build a culture for what comes next Compliance costs risk widening the AI gap AI-driven layoffs add new demands on CIOs to prove value AI transformation: Early wins are not enough for CIOs Why CIOs can't let users wait on IT Memory shortage doesn't have to spell disaster for IT budgets Accelerate AI adoption: 3 reasons for adopting MCP How techno-nationalism is complicating IT resilience and supply chains for CIOs InformationWeek Podcast: Compliance crackdown on AI and BYOD Workday’s AI reset: Agents and the race to remake SaaS Why enterprise AI initiatives keep dying before production Metrics of meaning: What do we really measure in AI? Techno-nationalism is reshaping CIO infrastructure strategy Using AI to pick team leaders -- without crossing legal or ethical lines What Oracle's layoffs reveal about running IT with fewer people Chief AI Officer on course-correcting when AI moves too fast Large enterprises need high-performing networks to scale AI InformationWeek Podcast: When do smaller AI models make sense? The future belongs to AI-driven IT Ways AI supercharges risk awareness and data insights for CIOs How automation prepares you for agentic NetOps Should the CIO, CFO or CEO hold the kill switch on AI? The CIO's new mandate: Redesign work itself Ask the Experts: CIOs say they wouldn’t pull workloads back from the cloud How AI is Reshaping the Enterprise
AI disaster recovery planning is years behind AI adoption
Carrie Pallardy · 2026-06-24 · via informationweek

Before the current wave of AI adoption, disaster recovery focused on backing up and restoring enterprise applications, databases and all the components of traditional IT infrastructure. 

That remains the case today, but enterprises must now also think about AI models, prompts and agents. Can those resources be restored, and how can enterprises verify they remain trustworthy once they are? 

"The honest summary is that most organizations' DR plans in this space are years behind AI adoption," said Greg Sarich, CIO of Quest Software.

If CIOs and CISOs are going to help their enterprises catch up,  they must figure out how to update their disaster recovery plans and test them in advance of real-world incidents. 

Disaster in the AI era 

When an enterprise is hit with a security incident or an outage in today's AI-infused environment, the disaster recovery team has a lot to consider, including: 

  • Was the data used to train AI systems compromised? 

  • Were prompts compromised? 

Related:Why disaster recovery plans fail in geopolitical crises

Having the necessary visibility to answer these questions is a challenge, given how much AI touches across enterprise tech stacks. 

"If you're using Claude, it might be touching your Salesforce system and your SharePoint ... your Outlook system and other data that you might have in, let's say, a Snowflake or something else where you have business-critical data," Sarich said, illustrating how AI creates a web of interconnected dependencies.

"It's not only the protection of those systems, but it's all these little intersections that it touches along the way to be able to pull data and then create an outcome," he said.

As AI becomes more embedded in business processes, enterprises risk operations grinding to a halt, particularly if their teams can no longer revert to manual alternatives. 

"If we take an AI assistant copilot or chatbot that goes down, we lose access to the institutional knowledge that our employees are counting on," said Mehdi Houdaigui, principal, cyber AI leader at Deloitte. 

Risk still exists once AI resources are back up and running after an incident. Enterprises must verify the integrity of these resources, but compromises involving underlying data, prompts or models can be difficult to detect. 

"The challenge we see there is that the AI might still work. It may still look like, to the untrained eye, that it's producing confident answers, but those answers may be wrong, incomplete or manipulated," Houdaigui said.

An enterprise may be able to restore a chatbot, for example, but the disaster continues if people are acting on compromised information it provides.

Related:How CIOs can build an evolving crisis strategy

The blast radius can be considerably larger with AI agents in the picture. "Depending on how sophisticated the agent is, it's no longer just one system for it to be able to do what it's intended to do. It has the ability to touch and potentially take action on multiple systems," Houdaigui added. 

The damage can linger long after disaster recovery teams clean up compromised AI agents operating across multiple systems. 

"If our employees, our organizations lose confidence in the tools themselves, you've got a big gap in just getting further adoption going forward," Sarich said.

The challenge we see there is that the AI might still work. It may still look like, to the untrained eye, that it's producing confident answers, but those answers may be wrong, incomplete or manipulated. — Mehdi Houdaigui, principal, cyber AI leader, Deloitte

Building an AI disaster recovery plan

As CIOs and CISOs consider how their DR plans need to evolve in response to AI, there are some fundamental steps to help them get started: 

Catalog your AI assets. With AI proliferating across different business units — and shadow AI adding another layer of complexity — it can be difficult to have a full understanding of what tools are being used where. 

Related:Redefining incident response strategies beyond the breach

"Start with an AI asset inventory. If you don't have one, you've got to build one quick," Sarich said. "You can't recover what you haven't cataloged."

Determine each asset's business criticality. "Anything that's related to or has AI as part of its foundation in the operation of the business should be priority-one or red-level," said Chris Millington, global solutions lead, data and cyber resilience at Hitachi Vantara. Customer-facing tools and those that affect revenue have a higher priority, according to Sarich.

Map dependencies. With AI deeply integrated into enterprises' workflows, it is essential to understand its dependencies. "What data does it use? What model does it rely on? What vendor or vendors are involved? What are the systems that it can access? And most importantly, what credentials does it use?" Houdaigui asked. 

Evaluate permissions. To effectively recover, IT and security leaders need to know the permissions AI agents and tools have and be able to revoke credentials and kill specific tasks. Then, those AI assets need to be evaluated before they are restored and given permissions again. 

"[Verifying] that that agent is operating within what we call these approved boundaries before it goes back online is critical from a disaster recovery perspective,"Houdaigui said. 

Define recovery objectives. Organizations need to define their recovery time objective and recovery point objective, Houdaigui noted. How much data and downtime related to AI assets can an enterprise afford to lose? What is the last known trusted version of a model, prompts and data?

DR plans also need to define the necessary testing and validation steps before recovering and bringing AI infrastructure back online.

"There are significantly more steps involved with AI systems because of the complexity that the systems have inherently just by being probabilistic in nature," Houdaigui explained.

Test and validate. A disaster recovery plan is of little use to anyone if it sits on a shelf collecting dust until the panic of an incident. Testing is key, and annual or quarterly tests are inadequate, given the pace of AI change. New tools, new dependencies and new risks are part and parcel of the AI era. 

As enterprises test, they need to consider all the potential gaps in their DR plans and fill them. 

"Ask what happens if the knowledge base is corrupted or if we lose access to one of the LLM models; APIs are unavailable for whatever reason. What happens if an agent behaves unexpectedly, or if we have any instances of potential compromise where we don't believe the logs can be trusted?" Houdaigui said. "Those exercises will ... help to reveal gaps fairly quickly."

When disaster strikes

As much as AI is changing operations, the old cybersecurity adage, "It's not if, it's when," remains the same. If AI deployment continues to outstrip governance, incidents that stem from and affect agents and tools are going to happen. 

Recent research from Proofpoint found that 42% of 1,400 security professionals surveyed have experienced AI-related incidents, either suspicious or confirmed. Additionally, 52% of the surveyed security professionals said they do not have full confidence that their organizations' security controls could detect compromised AI.

Enterprises are already contending with incidents that impact their AI resources, and Sarich anticipates that sooner or later there will be a significant event that thrusts AI disaster recovery into the spotlight.

"We're going to see something major happening, I'm sure, in the not-too-distant future," he said.

Whether it is a large-scale public event or not, enterprises will have to turn to their disaster recovery plans, work through them and then conduct a postmortem to make that plan stronger for the next incident. Enterprise teams will have to ask key questions like, "What point did we recover back to and was that acceptable, or can I optimize that even further?" Millington said.

The missing metric in AI resilience 

As disaster recovery strategies mature in response to the complexity of enterprise AI, a big question remains unanswered:

Can enterprises quantify the losses associated with an outage, breach or other incident that affects their AI resources? 

Houdaigui argued that the industry has yet to align on how to quantify cyber risk, let alone on losses associated with AI. "There is an opportunity for the industry as a whole to really look at: What is the quantifiable loss exposure or risk impact of these systems?" he added. 

As enterprises gain a clearer understanding of the operational and financial consequences of AI-related incidents, the cost of disaster recovery and resilience may finally begin to catch up with AI deployment. 

About the Author

Carrie Pallardy

Contributing Reporter

Carrie Pallardy is a freelance writer and editor living in Chicago. She writes and edits in a variety of industries including cybersecurity, healthcare and personal finance.