Editor’s note: The following is a guest post by Anthony Cusimano, solutions director at backup data storage vendor Object First.
Nearly every company is using AI, and many are leaning on service providers for guidance. So far, the technology hasn’t delivered a clear return on investment. Less than half of organizations believe AI is essential to their core work, even though 98% have adopted it, according to a July survey of more than 1,500 decision-makers by software company Aptean. Service providers are telling customers they can help close the gap.
The trouble is everyone is pitching the same fix. An AI practice and a bench of engineering talent are table stakes, and they won’t differentiate one provider from another if they don’t move the customer’s bottom line. Take off the AI-tinted glasses and a different strategy comes into focus: competitive advantage is defined by service providers who can show customers a return on what they’ve already spent, not by promises of the latest AI capabilities.
Security first
An accelerating threat landscape and evolving compliance restrictions are reshaping customer expectations, maybe even more than AI.
Attackers are moving faster and more effectively than ever, according to CrowdStrike’s 2026 threat hunting report. China-linked groups are exploiting vulnerabilities within 24 hours of a working proof of concept. Security leaders feel outpaced. In a survey of 500 CISOs commissioned by security vendor Kai, 63% said AI gave attackers the upper hand. According to an Omdia report Object First commissioned, ransomware attacks are up 26% year over year.
To make matters worse, cybercriminals are hitting victims where it hurts most: their data. Threat actors are targeting backups to debilitate organizations and force them to pay a ransom, according to Veeam’s 2025 ransomware trends report. The Omdia survey found that of the 83% of organizations that fell victim to a successful ransomware attack in the past year, only 39% recovered at least 75% of their data. As organizations grapple with data sprawl and inconsistent backup strategies, they become easy targets.
Regulators are paying attention. The Department of Health and Human Services has proposed the first major overhaul of the HIPAA security rule in two decades, including a requirement to restore certain systems within 72 hours. Final action by HHS has been delayed until at least July 2027. Whatever the final rules look like, buyers are already asking providers to prove they can keep business running and pass the audit.
It’s easier said than done. Backups can be deleted or corrupted in many ways, even when presumed safe. Attackers can take over admin credentials with the rights to delete them. No one notices until the day a restore fails.
When a customer loses backup data that they relied on and assumed was safe, it erodes confidence and trust in the service provider. The consequences of operational downtime and lost data carry reputational, legal and financial costs, and AI is making the threats behind them more capable.
Recovery readiness
The threat landscape gives service providers a new job: educating their customers on the risks of insufficient data backup strategies before something goes wrong. This focus on data resiliency also addresses many of the issues preventing customers from fully integrating AI into their core work and from seeing returns on that investment.
When companies are confident in their data security, they can move quickly with their adoption. A strong, secure data foundation accelerates procurement and decision-making timelines and builds trust among customers and employees. Most importantly, however, it prevents some of the more costly negative side effects of AI.
Internal AI tools have already gone rogue, entered backup environments and altered data even if it is not within a user’s prompt. Last year, a Replit coding agent deleted the production database behind a project SaaStr founder Jason Lemkin was building during a code freeze. It did this despite instructions to make no changes without his approval. Lemkin eventually got the data back. In April, a Cursor coding agent wiped the production database at PocketOS, which makes software for rental car businesses, in about nine seconds. The volume-level backups sitting in the same environment went with it.
When data backups are properly segmented from production environments, contain immutable copies of the data and have a tight recovery point objective, a service provider can restore at least one version of the database. Recovery is possible even if an AI agent deletes the primary database.
Service providers can help not only by offering solutions that provide this security, but also by prioritizing solutions that ensure immutability, are simple to use, require little security expertise and can be easily added to existing tech stacks. Many IT teams are stretched thin as it is and don’t need more tools that require heavy oversight and management.
A secure backup strategy provides the peace of mind and strong foundation that empowers companies to fully embrace AI. This goes a long way in developing lasting relationships that go beyond the AI hype and build customer trust.