David Bennett, CEO, Object First.
In the technology industry, the U.S. regulatory landscape typically does not garner as much discussion as its EU or U.K. counterparts.
While EU regulations such as the Digital Operational Resilience Act (DORA) and the Network and Information Security 2 (NIS2) directive take a more centralized and prescriptive approach, the U.S. regulatory landscape has remained largely fragmented by state or sector, favoring voluntary guidelines over audit-enforced requirements.
However, as AI and sophisticated cyberattacks continue to wreak havoc, especially in critical sectors such as healthcare and infrastructure, a shift is coming.
We’re already starting to see this evolution. The U.S. Department of Health and Human Services has proposed sweeping updates to the HIPAA Security Rule “to safeguard electronic protected health information to prevent, detect, contain, mitigate, and recover from cybersecurity threats.” Likewise, the Financial Industry Regulatory Authority (FINRA) also recently added new enforcement procedures that change how it conducts examinations and investigations related to business continuity.
An emphasis on recovery is a common theme among these updates. Even longstanding regulations are being overhauled to ensure that companies not only have backups but can prove they are restorable.
While the U.S. regulatory environment differs from Europe, many of the same resilience principles are already beginning to appear in sectors such as healthcare and financial services. For example, the proposed amendments to the HIPAA Security Rule place greater emphasis on cybersecurity resilience and recovery capabilities, and are currently scheduled for final action in 2027.
Increasingly, regulators are not just asking whether organizations have recovery plans, but whether leadership can demonstrate those plans will work. The time is now for leaders to get ahead of the curve and prioritize ensuring compliance where it matters most.
A Shifting Threat Landscape Prompts A Re-Evaluation Of Compliance Requirements
CDW reports 43% of organizations have experienced AI-enhanced phishing attacks. Meanwhile, threat actors now specifically target data backups in 93% of attacks, according to Veeam. Yet many organizations aren’t fully prepared to restore operations. Only 39% recovered at least 75% of their data after an attack in 2025, and only 39% were able to recover in five days or less, according to Omdia research sponsored by my company.
There’s an arms race taking place, as IT teams use AI defense systems to protect against these attacks. But, as I’ve written about previously, the reality of the current threat landscape is that it’s not a matter of if an attacker gets through, but when.
All of these factors are coming together to create a very dangerous threat landscape, and as a result, regulators are placing greater emphasis on backup integrity, business continuity and resilience. Proving a backup copy exists is no longer enough; companies must be able to demonstrably restore.
Similarly, cyber insurance requirements are also tightening in reaction to a worsening threat landscape. At a macro-level, these outside forces are all pointing at the same thing: resiliency against cyber threats.
Preparing For Increased Regulatory Scrutiny
Prioritizing proper data backup best practices and immutable storage are becoming increasingly important to meet regulations that require businesses to prove they have the ability to recover following an attack.
As the CEO of a company that builds immutable backup solutions, there are several common pitfalls I’ve seen that surface during audits when organizations attempt to prove recoverability.
In my experience, they almost all boil down to backup data being inadequately protected. The concept of immutability provides a useful example. Immutability should mean that no one, not even a highly privileged admin, can delete or modify backup data during its set retention period. But not all so-called immutable solutions live up to that promise.
It’s simple in theory but hard in practice, as attackers will take advantage of any gap in the armor. Maybe someone with the right privileges could perform a factory reset or another destructive action, for example. Maybe there’s no end-to-end encryption when the data is in transit, or a delay to immutability being applied when it’s written. In none of these cases could a backup be considered absolutely immutable.
Another common scenario is a DIY backup solution with key person dependencies—e.g., if there’s only one employee who knows how to back up and restore. This can also put a question mark over recoverability.
I began my career in EMEA and led operations in that region for over 10 years before moving to the U.S., so I am very familiar with the regulatory pressures companies in the EU and U.K. face. There are some valuable lessons we can take from their experiences as we prepare to undergo a similar shift in the U.S.
Most notably, IT and security teams are still far too often not at the table when compliance decisions are being made. As we’ve established, resiliency is a key element of any compliance strategy, and IT teams need to be involved from a technical standpoint. We need to move away from the view that resiliency is just an IT department problem. As we’ve seen with IT leaders potentially being held personally responsible for compliance failings, it should be seen as a financial and legal priority as well.
Overlooking the backup and resiliency elements of compliance can have far-reaching consequences in the event of a cyberattack, including financial penalties, denied insurance claims and law enforcement investigations delaying a full resumption of operations.
The organizations best positioned for future compliance requirements will be those that treat recoverability as a proven business capability rather than a technical afterthought.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


