Beni Sia and Sandeep Bhambure of Veeam Software, in an exclusive interaction with ET Edge CIO&Leader, on why AI agents are outpacing human traffic, and how resilience and governance must catch up.

As enterprises move beyond AI experimentation into deploying autonomous, agent-driven systems, the meaning of resilience is changing. Backup and recovery are no longer just IT functions; they are becoming central to building trust in data, strengthening cyber resilience, meeting compliance requirements, and scaling AI with confidence.
Veeam Software, a Seattle-headquartered data resilience and data security company founded in Switzerland in 2006, now operates in more than 30 countries, with a significant presence in India across Bengaluru, Pune, Mumbai, Hyderabad and other cities. Sandeep Bhambure, Vice President and Managing Director – India & SAARC, and Beni Sia, General Manager and Senior Vice President – Asia Pacific & Japan, spoke with ET Edge CIO&Leader, on how the data resilience landscape is evolving — how AI and agentic systems are challenging traditional security models, why trusted data is essential to scaling AI, what India’s DPDP framework really demands of enterprises, and what it takes to prepare for a future where resilience, security and AI increasingly converge.
ET Edge CIO&Leader: Data resilience was once largely seen as an IT hygiene issue—something to think about when systems failed, or data was lost. Why has it become a much broader business and leadership concern today?
Beni Sia: The nature of risk has changed. Organisations are dealing with two major shifts at the same time.
The first is the growing sophistication of cyber threats, particularly ransomware. Recovery is no longer simply about restoring systems after an outage; organisations need to understand how an attack happened, what was compromised and whether they can recover safely. This is why we acquired Coveware, which brought both technology for understanding compromises and intelligence based on real-world attacks. That kind of current intelligence is increasingly important because the threat landscape changes very quickly.
The second shift is around data itself. Enterprises have more data spread across applications, clouds, SaaS platforms and unstructured repositories than ever before. They need to know what data they have, where it sits, who can access it and whether it is still relevant. That is where capabilities such as Data Security Posture Management become important.
And now AI is adding another layer of complexity. With Generative AI and increasingly autonomous agents, organisations are no longer managing access only for human users. AI systems can access data, interact with applications and make decisions at machine speed.
That changes the resilience conversation. It is no longer enough to ask, “Can we back up our data?” The more important questions are: Can we trust the data? Do we know how it is being used? And if an AI system makes a wrong decision or something goes wrong, can we recover quickly and safely?
Our view is that resilience must bring these capabilities together. The ability to restore data remains fundamental, but visibility and control are becoming equally important. In an AI-driven environment, the ability to effectively “undo” an unintended outcome can be just as valuable as preventing it in the first place.
ET Edge CIO&Leader: With AI models depending entirely on trusted, governed data, does the old backup playbook still hold up?
Sandeep Bhambure: The IT industry is now dealing with a challenge that is, in many ways, outside the traditional playbook. The guardrails and security measures built during the pre-AI era, whether perimeter security, firewalls, network security or application security, were largely designed around human threat actors.
Today, we are dealing with AI agents operating at machine speed. For every human identity, there are now numerous machine identities operating under their own rules and permissions. As a result, many of the approaches organisations have traditionally relied upon for data security, trust and resilience are no longer sufficient.
Compliance also needs to evolve. It can no longer rely solely on periodic audits conducted quarterly or annually. Instead, compliance must become continuous and increasingly autonomous.
Data resilience in the AI era needs to be viewed through a data-centric lens rather than a traditional perimeter-centric approach. In many ways, there is no longer a clearly defined perimeter. AI systems can clone processes, move across environments and access information in ways that traditional security architectures were never designed to handle.
As data is increasingly consumed by AI agents, the security and governance controls associated with that data must move with it. That is one of the biggest shifts we are going to see from a data resilience perspective.
Beni Sia: For years, organisations embraced concepts such as Zero Trust. However, Zero Trust architectures were primarily designed around humans; they were not designed for agentic AI systems.
“Zero Trust architectures were primarily designed around humans; they were not designed for agentic AI systems.”
Beni Sia, General Manager and Senior Vice President – Asia Pacific & Japan, Veeam Software
Traditionally, organisations placed data at the centre and surrounded it with layers of protection, including network security, perimeter controls, data centres, enterprise applications and SaaS environments. That model assumed data would remain within those boundaries and that access would be governed through those layers.
Agentic AI changes that model entirely. These agents can bypass many of the traditional layers and interact directly with data.
As a result, organisations need to rethink how they establish guardrails, controls and security frameworks to ensure that data remains protected in an AI-driven environment.
ET Edge CIO&Leader: As agentic AI arrives alongside tightening regulation — DPDP, GDPR, and emerging AI governance frameworks — what’s the compliance challenge organisations are least prepared for?
Beni Sia: Regulations differ by country, but they’re converging on the same goal: continuous accountability and demonstrable compliance, not point-in-time audits. Organisations increasingly need to prove, on demand, that they’re compliant.
The bigger problem with agentic AI is that critical enterprise data has historically sat in highly auditable business applications — but roughly 90% of enterprise data today is unstructured: SharePoint, files, email, collaboration platforms, spread across multiple clouds. Agentic AI doesn’t limit itself to structured databases; it reaches into that unstructured layer too.
The real risk is that AI agents don’t just read this information — they learn from it and make decisions based on it. If the underlying data is outdated or wrong, so are the decisions. I joined Veeam six years ago, and there are probably still files sitting in SharePoint folders I created back then — not confidential, but obsolete. Multiply that across an enterprise, and it’s a governance problem AI makes far more consequential.
ET Edge CIO&Leader: Beyond meeting the DPDP deadline, how should Indian enterprises actually be thinking about compliance?
Sandeep Bhambure: DPDP can be a strategic asset for Indian enterprises, not just another compliance requirement. Treat it as a checkbox exercise, and you miss the larger opportunity to strengthen how you manage, protect and govern data.
Many organisations address individual pieces — consent management, say — without looking at the larger governance picture. But DPDP spans privacy, breach notification, data principal rights, fiduciary responsibility, data protection and ransomware preparedness. Handle each in isolation and you end up with compliance silos — added complexity without a stronger security or governance posture.
“DPDP can be a strategic asset for Indian enterprises, not just another compliance requirement. Treat it as a checkbox exercise, and you miss the larger opportunity to strengthen how you manage, protect and govern data.”
Sandeep Bhambure, Vice President and Managing Director – India & SAARC, Veeam Software
There’s a bigger opportunity too: the data foundation DPDP compliance requires — clean, trusted, secure, governed data — is the same foundation needed to scale AI responsibly. Get that right, and compliance and AI-readiness come together. That’s the thinking behind our Data AI Command Platform, which brings security, compliance, governance, privacy and resilience into a common framework.
Cut the “real challenge is bringing these pieces together” line since it repeats what “checkbox exercise” and “silos” already establish, and merge the two AI-foundation sentences that were saying the same thing twice.
ET Edge CIO&Leader: Is the industry’s obsession with ransomware prevention coming at the cost of recovery readiness?
Beni Sia: There is no quick fix. It starts with ensuring that organisations have the right foundation in place before an incident occurs.
One of the principles we advocate is the 3-2-1-1-0 rule: three copies of data, two different media types, one copy stored offsite, one immutable copy and zero recovery errors through regular verification.
Organisations must continuously validate that they can recover their data. Once that foundation exists, they can be confident that, when something goes wrong, they will be able to restore their business operations and data.
The challenge is not going away. If anything, the pace of innovation is increasing the sophistication and speed of threats.
One area that deserves greater attention is ROT data, redundant, obsolete and trivial data.
Managing ROT data delivers three key benefits.
First, it reduces storage and operational costs. Second, it reduces security risk because the larger your data footprint, the larger your attack surface. Third, it improves AI outcomes.
AI systems make decisions based on the data they consume. If organisations remove outdated and unnecessary information, AI models can work with cleaner and more relevant datasets.
We have also seen attackers increasingly target backup environments themselves. That creates additional challenges around recovery speed and completeness.
ET Edge CIO&Leader: Nearly 98% of attacks reportedly target backup environments directly — so even heavy investment in recovery infrastructure doesn’t guarantee organisations can recover in time. How are you closing that gap?
Beni Sia: We have built capabilities into our technology that allow organisations to continuously test their recovery readiness and validate their RTOs and RPOs. This is a well-established best practice.
We always encourage customers to regularly test recoverability because data environments are constantly changing.
In today’s cloud-first world, organisations can deploy new services very quickly, and those changes can significantly impact their recovery posture. As a result, recovery validation cannot be treated as a one-time exercise.
Organisations need to continually verify that they can recover successfully when required.
ET Edge CIO&Leader: Is the bigger challenge today technology, process or talent?
Beni Sia: Resources are always limited. Organisations cannot address every challenge simultaneously, so they need a structured framework that helps them identify the most critical priorities and focus their efforts accordingly.
ET Edge CIO&Leader: Beyond the product side, what’s Veeam doing on the ground in India — through partnerships, talent investment, and M&A — to build out its resilience ecosystem here?
Sandeep Bhambure: Through our partnership with DSCI, we are not only creating awareness around cyber resilience but also helping bridge the talent gap. On investment, we have approximately 850 employees across the country supporting product engineering, software support and sales-related functions, operating from Bengaluru, Pune, Mumbai, Hyderabad and several other cities — including teams supporting Securiti AI, which Veeam acquired towards the end of 2025. We have maintained an active M&A strategy over the past few years, expanding capabilities through acquisitions such as Coveware, CT4 and, most recently, Securiti AI, and we continue to evaluate opportunities that strengthen our ability to help customers address evolving data resilience, cybersecurity and data management challenges.
ET Edge CIO&Leader: Cyber resilience is a hard sell against AI investment for budget. How should CIOs justify it in ROI terms?
Beni Sia: Technology investments should ultimately be measured by the business outcomes they deliver.
Organisations are not investing in technology for its own sake. They are investing to drive growth, improve customer experiences and strengthen operational performance.
At the same time, cyber resilience plays a critical role in protecting those outcomes. Organisations must be able to quantify the financial impact of disruptions and assess how quickly they can recover from incidents.
The ability to recover rapidly and minimise business impact is an important measure of success, alongside innovation and transformation initiatives.
ET Edge CIO&Leader: Looking ahead to 2026 and 2027, what should be top of mind for CIOs?
Beni Sia: Organisations are at a critical inflection point in their AI journey. There’s real enthusiasm for adoption, but many CIOs are still grappling with how to deploy AI quickly, securely and at scale. The challenge isn’t implementing AI, it’s building the right foundation to support it: a resilient data platform that enables innovation while ensuring security, governance and trust. Data resilience and trust are fundamental prerequisites for scaling AI, not an afterthought to it.
That’s borne out in a recent Veeam survey of nearly 200 CIOs at large Indian enterprises, where cybersecurity and trust ranked among the top concerns. Organisations recognise AI’s potential, but many are still stuck at limited use cases rather than enterprise-wide deployment. As adoption accelerates, CIOs will increasingly have to balance innovation with resilience, moving fast without sacrificing the security, trust and operational stability that long-term outcomes depend on.