Rubrik Logo
CXO Visionaries
CXO ExperiencesArrow Icon
CXO NewsletterZero LabsCommunity
Rubrik
LinkedInTwitterFacebookYouTubeInstagram

Call us at 1-844-478-2745

Submit Interest

ABOUT RUBRIK

CompanyLeadershipInvestor RelationsNewsroom & Press ReleasesCareersBlog

NEW TO RUBRIK

What is RubrikProductsSolutionsPartnersCustomersResources

POPULAR LINKS

Cyber RecoveryBackup & RecoveryRansomware RecoveryCloud Database Backup and Recovery ServiceCloud Disaster RecoverySaaS Backups

CompanyLeadershipInvestor RelationsNewsroom & Press ReleasesCareersBlog
What is RubrikProductsSolutionsPartnersCustomersResources
Cyber RecoveryBackup & RecoveryRansomware RecoveryCloud Database Backup and Recovery ServiceCloud Disaster RecoverySaaS Backups

CompanyLeadershipInvestor RelationsNewsroom & Press ReleasesCareersBlog
What is RubrikProductsSolutionsPartnersCustomersResources
Cyber RecoveryBackup & RecoveryRansomware RecoveryCloud Database Backup and Recovery ServiceCloud Disaster RecoverySaaS Backups
  • Legal
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
  • Trust
  • CA Residents only: Do not sell or share my personal information | Do not share my sensitive information

© 2026 Rubrik – Zero Trust Data Security™

Technical Blog Hub

Why Identity Resilience Requires a Recovery Floor

 

Technical BlogHealthcare ProvidersRansomware Recovery
SEP 8, 20264 min read
Technical BlogHealthcare ProvidersRansomware Recovery
SEP 8, 20264 min read
Why Identity Resilience Requires a Recovery Floor
Share
Background
Technical Blog Hub

Why Identity Resilience Requires a Recovery Floor

 

Technical BlogHealthcare ProvidersRansomware Recovery
SEP 8, 20264 min read
Technical BlogHealthcare ProvidersRansomware Recovery
SEP 8, 20264 min read
Why Identity Resilience Requires a Recovery Floor
Share

Table of Contents

At TELUS Health, we hold health records for more than 170 million people across the globe. When identity infrastructure fails, the workforce cannot authenticate, systems cannot communicate, and the business stops. Identity is not just another workload. It is the thing everything else depends on.

 

Most organizations have invested in preventative controls and detection and response capabilities. Those matter. But they are not enough on their own. The question that keeps me focused is what happens after the attack gets through. That is where I see the most dangerous gaps.

The Backup You Have May Already Contain the Attacker

People have had Active Directory backups for a long time. But having a backup is not the same as being able to recover. Two questions actually matter: where is that backup stored, and do you know whether it was taken before or after the attacker got in.

I have seen organizations keep backups on servers sitting next to the domain controller itself. I have seen others rely on bare metal backups where they cannot know if the attacker is already inside when they restore. A backup that lives within the attacker's blast radius is not a clean recovery point. It is a liability. We've been fortunate not to have needed ours yet - but knowing it's outside the attacker's reach changes how the whole conversation feels.

When Recovery Becomes an Open-Ended Investigation

When an attacker gets into Active Directory and you have no platform giving you precise visibility and point-in-time recovery, you are not in a recovery scenario. You are in an investigation with no known endpoint. You do not know how far they got, whether they have top-level privileges, or whether they have gone dormant and will restart after you think you have removed them.

Without the ability to go back to a verified clean point in time and roll forward without the attacker's changes, you cannot confirm it is actually over. Companies have spent weeks in that position. That uncertainty is what immutable backup and point-in-time recovery solves. Not just speed. The difference between knowing you have a clean state and hoping you do.

Putting a Floor on the Problem

Before we had assured recovery in place, a conversation about identity failure would drift toward existential risk territory. Have that conversation with an executive committee and you may as well be carrying a sandwich board that says the end is nigh. It does not lead anywhere useful.

What immutable backup and assured recovery gives you is a floor. There is now a fixed, knowable cost attached to the worst case: the time and resources required to recover the business to a functional state. That converts an open-ended existential discussion into a risk management conversation. The downside is bounded. Leadership can engage with it, make decisions around it, and factor it into broader strategy.

That shift in how the conversation lands is significant. It is not just a technical capability. It is what makes identity risk speakable at the board level.

What Comes Next?

TELUS Health has grown through acquisition. Each acquired entity brings its own identity platforms and its own legacy. We've already deployed Rubrik into a couple of business units, and our strategy is to consolidate onto a number of strategic identity platforms that are empowered by it, so that as we integrate acquired entities, the floor is in place from the start.

The other dimension is AI. There are already multiples of non-human identities compared to human users in most large organisations. AI is going to make a massive increase in that. Having a clear grasp of what identities and entitlements exist within the organisation, and the ability to manage that at scale, is not just a current requirement. It is the foundation for operating safely in an environment where identity is growing faster than any team can manually track.

Contributed by

Kevin Watkins
Kevin Watkins

Director of Cybersecurity, Telus Health

Kevin Watkins leads TELUS Health's cybersecurity function across the Americas, EU, and UK, securing a global healthcare organization handling PHI at scale. With over 30 years of experience in enterprise security architecture and risk management, Kevin has built and scaled security programs across banking, financial services, and healthcare sectors, including roles as Head of Cyber Resilience at Standard Chartered Bank and Head of Cyber Security at Tesco Bank. His focus spans identity and access management, cyber resilience, threat-driven security operations, and translating complex security challenges into business risk conversations for executive leadership.
Nikita Bhuma
Nikita Bhuma

Customer Advocacy Specialist, Rubrik

Nikita Bhuma is a Customer Advocacy Specialist at Rubrik with over a decade of experience across IT, networking, cybersecurity, and enterprise software industries. She leads the Reference Concierge program, amplifying customer voices through technical storytelling that highlights real practitioner insights and measurable outcomes.

Share Your Insights

Have an interesting story or technical findings to share? Reach out to create a blog with us.

Learning & Certifications

Access free and instructor-led training and certification paths to master Rubrik products and maximise your data security expertise.

Explore coursesNext
Background

Share Your Insights

Have an interesting story or technical findings to share? Reach out to create a blog with us.

Learning & Certifications

Access free and instructor-led training and certification paths to master Rubrik products and maximise your data security expertise.

Explore coursesNext