We had the opportunity to hear from Goran Garevski, CTO and co-founder, and Andy Fernandez, GM, AI & Cyber, during an ambitious session titled “Stepping into a New Era in Data Protection.” HYCU positions itself as the #1 AI resilience company, backed by investors including Bain Capital, Acrew, Cisco Investments, Okta Ventures and Atlassian. Its strategic alliances include Dell Technologies, AWS, Microsoft, Google Cloud, Nutanix, Atlassian, Okta and iManage. The company serves thousands of organizations across more than 78 countries, including Pfizer, Toshiba, Zebra, Honeywell and branches of the US military. Recent industry recognition includes being named a Leader in the IDC MarketScape for Worldwide SaaS Data Protection 2025–2026, a Visionary in the Gartner Magic Quadrant for Enterprise Backup and Recovery, and a Challenger in the Coldago Map 2025 for Modern Data Protection.

Well known for its advanced SaaS data and ransomware protection capabilities, HYCU is now entering what it describes as the era of “agentic risk.” Each previous era of data protection has been characterized by a dominant failure mode: first hardware failures, then human errors and, more recently, ransomware. HYCU argues that a new category has emerged with AI agents.
Unlike ransomware, which traditionally attacks from outside the perimeter, or human errors originating inside it, AI agents represent a “third actor”: they already operate inside the environment, hold legitimate credentials and can execute actions at machine speed. HYCU illustrated the risk with the PocketOS incident from April 2026, when an AI agent reportedly deleted a company’s production database and its backups in just nine seconds.
The company identifies three major destruction patterns. The first is “Drift,” when an agent hallucinates or incorrectly interprets the state of a system, illustrated by the Gemini CLI incident in July 2025. The second is “Misinstruction,” where a hidden or injected prompt redirects an agent toward destructive actions, as demonstrated by the Amazon Q for VS Code incident distributed to more than 964,000 installations. The third involves “Standing Credentials,” where a single over-privileged API token can enable irreversible damage.
Traditional native retention periods, 93 days for SharePoint, 90 days for Okta audit logs, 60 days for Jira and 15 days for Salesforce, were designed primarily around human mistakes rather than bulk operations executed by autonomous systems at machine speed. HYCU’s conclusion is straightforward: when prevention fails, recovery becomes the final control.

A detailed demonstration illustrated how Atlassian’s Rovo agent could receive an apparently reasonable instruction such as “archive tickets older than 90 days” and, using the permissions of a service account, execute a massive and potentially irreversible deletion. From Atlassian’s perspective, these operations remain authenticated and authorized, which makes this new risk particularly challenging.
HYCU also used the event to share exclusive news around a key evolution of its AI visibility capabilities. The company argues that visibility into AI agents and their activities has become increasingly difficult. Four years ago, enterprises were already struggling with SaaS and application sprawl; today, AI agents are spreading across virtually every system of record, including GitHub, Salesforce, Microsoft 365, Workday, Atlassian and ServiceNow. HYCU aims to map this new environment through its “aiR Graph.”
Even before the arrival of AI agents, HYCU had catalogued more than 30 scenarios in which GitHub repository data could be permanently lost, including accidental deletion, force-push operations, insider or employee offboarding risks, compromised credentials, misconfigured automation and provider failures. According to HYCU, these scenarios cannot necessarily be recovered through GitHub’s native resilience mechanisms.
AI introduces another layer of risk, with agents potentially deleting branches, force-pushing after incorrect rebases or rewriting history across multiple repositories. Once again, GitHub sees these operations as authenticated and authorized.
This is increasingly important because repositories are no longer just containers for source code. They have evolved into complete systems of record containing runbooks, SDKs, AI prompts, agent definitions and other operational assets. Losing a repository can therefore mean losing part of the specification describing how an organization operates. In Europe in particular, HYCU argues that maintaining an independent, immutable and testable copy of critical data is becoming essential to meeting regulatory and resilience requirements.

AI and associated agents are changing the data protection equation. HYCU promotes what it calls “protection at the speed of agents,” targeting a 30-minute RPO for critical repositories and considering hourly backups as the minimum baseline. The model relies on aggressive backup frequency, complete application coverage, immutable copies beyond the reach of production credentials, and recovery procedures tested quarterly.
The company also makes a clear distinction between recovery and continuity. Recovery restores lost or corrupted information, while continuity keeps critical data accessible even when the primary application or service is unavailable. As HYCU puts it, “every hour of waiting is lost work.”
This philosophy is reflected in HYCU R-Serve, introduced as an always-on, independent and self-service mechanism for accessing critical information. The solution offers a familiar, iManage-like interface and is initially launching for iManage, while HYCU also provided a sneak peek at an upcoming Confluence integration.

Another major part of the presentation focused on HYCU aiR, the company’s AI layer that allows customers to query their protected data using natural language. Examples include questions such as “Do I have PHI in Confluence?” or “What has John Smith deleted during the last seven days?”
The idea is particularly interesting because backup data represents much more than a recovery copy. Every SaaS backup can provide a complete and time-stamped historical record of files accessed or modified, permissions changed, records updated and configurations altered. HYCU argues that this historical, complete and independent dataset provides context that many traditional operational tools simply do not possess.
HYCU aiR therefore acts as an “organizational knowledge graph,” connecting protected applications, data, identities, activities and time. This opens several use cases beyond traditional backup and recovery, including security operations with insider-risk analysis and blast-radius mapping; AI governance with shadow-AI discovery and an agent “flight recorder”; compliance and privacy with PII and PHI discovery and GDPR, HIPAA and PCI reporting; and resilience with precision recovery and ransomware detection signals.
Overall, HYCU R-Cloud now protects more than 100 workloads spanning hybrid infrastructure, cloud, SaaS and AI/ML environments. Protection extends beyond basic application data to records, attachments, permissions, configurations, identities and metadata.
New generally available support for Azure DevOps covers Boards, Repos, Pipelines, Test Plans and Artifacts, completing HYCU’s protection coverage across the major Git environments: GitHub, GitLab, Bitbucket and Azure DevOps.
With HYCU aiR, the company is extending its traditional data protection role toward a broader AI resilience model. HYCU says its technology is trusted by more than 4,800 organizations across 78 countries, while its compliance and security credentials include SOC 2, ISO 27001, FIPS 140-3 and DISA STIG.
The message delivered in Ljubljana was clear: the next data protection challenge is no longer limited to hardware failures, human mistakes or ransomware. As AI agents gain privileges, access more corporate data and execute increasingly autonomous actions at machine speed, protecting enterprises will require backup, visibility, governance and recovery mechanisms capable of operating at the same speed.

0 commentaires:
Post a Comment