Altria Group is one of America's largest consumer packaged goods companies, a Fortune 500, publicly traded manufacturer subject to FDA oversight, the PACT Act, and SEC cybersecurity disclosure requirements. The enterprise architecture team oversees technology strategy across a hybrid environment spanning on-premises data centers, Azure workloads, and a SaaS footprint that has grown through acquisitions and international expansion.
The enterprise architecture team defined what the platform had to do: a single recovery plan tested across every workload, consolidated compliance reporting, and unified visibility across on-premises, cloud, and identity environments.
Altria aimed to achieve the following objectives:
A coordinated, tested ransomware recovery plan
Consolidated compliance reporting across the enterprise
Full active directory forest recovery, not just file and registry restore
Faster, orchestrated identity recovery
Scalable protection for an evolving environment
Partnering with Rubrik helped Altria achieve:
100x Faster Cyber RTO
Altria can now recover directly from backups and rapidly scan across backups to identify a clean recovery point. What previously required days of forensic work now happens in hours.
Multiple Tools Retired, One Platform, One Compliance Report
Rubrik replaced multiple backup tools across on-premises, cloud, and identity workloads, eliminating separate support contracts and consolidating per-cycle compliance reports into one.
Manual Identity Recovery -> Orchestrated Restoration in Hours
Recovery across Active Directory and Entra ID moved from a multi-day manual process to a direct, orchestrated restore with identity object dependencies visible in a single platform.
30%+ Operational Savings vs. Legacy On-prem
Retiring multiple tools and their associated support contracts, consolidating onto one platform, and eliminating redundant operational overhead delivered more than 30% in savings vs. the legacy on-premises environment, with an additional 19% in annual savings vs. native cloud backup.
100% SLA Compliance Across All Sites
Achieved across all on-premises data center sites, underpinned by a 3-2-1 model with an isolated, air-gapped copy.
The goal was a single platform with one support contract, one audit report, and a tested ransomware recovery plan across the full environment.
Before evaluating any vendor, the team defined what the platform had to do. Four non-negotiable capabilities: air-gapped architecture with backups isolated from the production network, immutability with backups locked at the platform level so a compromised admin credential cannot disable protection, anomaly detection built into the platform to scan for ransomware and provide clean recovery points, and unified compliance reporting across the enterprise.
Other platforms evaluated met some of these requirements but delivered them as bolted-on features across multiple portals. Rubrik met all four within a single platform, covering on-premises workloads, cloud, and Identity.
Altria never framed Rubrik as a backup tool. From the first conversation, the team treated it as a cyber resilience platform, which put it in front of a different set of decision-makers, drew sponsorship from the CISO and IT Risk Management rather than infrastructure budgets, and elevated the program to board-level reporting.
For a Fortune 500 company in a heavily regulated industry, a breach is not a technology problem. It is a business risk. When internal teams pushing back questioned why a separate platform was needed when they already had backups, the architecture team ran a structured evaluation and presented the results to the CISO. The structured evaluation gave stakeholders the confidence to move forward.
The questions the team set out to answer now have results behind them. Across all sites, Altria achieved 100% SLA compliance. Cyber RTO is 100 times faster than before. Where identifying a clean recovery point once required days of forensic work across multiple tools, Altria can now rapidly scan backups and recover directly without restoring data first. Retiring multiple tools and consolidating onto one platform delivered more than 30% in operational savings vs. the legacy on-prem environment, with an additional 19% vs. native cloud backup.
The same goals that drove the Enterprise Data Protection consolidation applied to Identity. In an environment running across Active Directory, Entra ID, and multiple IAM platforms, the team needed a platform that could recover the full AD forest, not just files and registry entries, to meet the bar for any serious incident response scenario.
On-premises Active Directory and Entra ID are two distinct identity planes. Restoring them out of sequence breaks access across cloud applications and on-premises systems simultaneously. Most organisations protect one plane and assume the other is covered. Altria needed a platform that handled both, in the right order, with dependency relationships between identity objects visible so recovery sequencing could be planned rather than reconstructed under pressure.
Before Rubrik Identity Resilience, recovering identity infrastructure required 22 manual steps spanning multiple days, with teams correlating identity object dependencies by hand. With Rubrik, those dependencies are visible within the platform and recovery runs directly from backup. Recovery that previously took days now happens in hours, with verified clean recovery points across both AD and Entra ID.
With each acquisition and expansion, the identity footprint grows - more service principals, more managed identities, more SaaS integrations. Protecting them is not a one-time project. It is an ongoing requirement that grows with the business.
We didn't treat Rubrik as a backup platform because we thought from day one it's a cyber resilience platform.

Kiran Pakkir
Sr Manager, Enterprise Architecture, Altria Group