At TELUS Health, we hold health records for more than 170 million people across the globe. When identity infrastructure fails, the workforce cannot authenticate, systems cannot communicate, and the business stops. Identity is not just another workload. It is the thing everything else depends on.
Most organizations have invested in preventative controls and detection and response capabilities. Those matter. But they are not enough on their own. The question that keeps me focused is what happens after the attack gets through. That is where I see the most dangerous gaps.
The Backup You Have May Already Contain the Attacker
People have had Active Directory backups for a long time. But having a backup is not the same as being able to recover. Two questions actually matter: where is that backup stored, and do you know whether it was taken before or after the attacker got in.
I have seen organizations keep backups on servers sitting next to the domain controller itself. I have seen others rely on bare metal backups where they cannot know if the attacker is already inside when they restore. A backup that lives within the attacker's blast radius is not a clean recovery point. It is a liability. We've been fortunate not to have needed ours yet - but knowing it's outside the attacker's reach changes how the whole conversation feels.
When Recovery Becomes an Open-Ended Investigation
When an attacker gets into Active Directory and you have no platform giving you precise visibility and point-in-time recovery, you are not in a recovery scenario. You are in an investigation with no known endpoint. You do not know how far they got, whether they have top-level privileges, or whether they have gone dormant and will restart after you think you have removed them.
Without the ability to go back to a verified clean point in time and roll forward without the attacker's changes, you cannot confirm it is actually over. Companies have spent weeks in that position. That uncertainty is what immutable backup and point-in-time recovery solves. Not just speed. The difference between knowing you have a clean state and hoping you do.
Putting a Floor on the Problem
Before we had assured recovery in place, a conversation about identity failure would drift toward existential risk territory. Have that conversation with an executive committee and you may as well be carrying a sandwich board that says the end is nigh. It does not lead anywhere useful.
What immutable backup and assured recovery gives you is a floor. There is now a fixed, knowable cost attached to the worst case: the time and resources required to recover the business to a functional state. That converts an open-ended existential discussion into a risk management conversation. The downside is bounded. Leadership can engage with it, make decisions around it, and factor it into broader strategy.
That shift in how the conversation lands is significant. It is not just a technical capability. It is what makes identity risk speakable at the board level.
What Comes Next?
TELUS Health has grown through acquisition. Each acquired entity brings its own identity platforms and its own legacy. We've already deployed Rubrik into a couple of business units, and our strategy is to consolidate onto a number of strategic identity platforms that are empowered by it, so that as we integrate acquired entities, the floor is in place from the start.
The other dimension is AI. There are already multiples of non-human identities compared to human users in most large organisations. AI is going to make a massive increase in that. Having a clear grasp of what identities and entitlements exist within the organisation, and the ability to manage that at scale, is not just a current requirement. It is the foundation for operating safely in an environment where identity is growing faster than any team can manually track.
Contributed by

Kevin Watkins
Director of Cybersecurity, Telus Health

Nikita Bhuma
Customer Advocacy Specialist, Rubrik




