UDP 11: Resilience That Keeps Business Moving
AI Is Everywhere. The Question Is Whether It’s Helping or Hurting IT.
Every IT team is hearing the same questions about AI: Where are we using it? Are we using enough of it? And is it actually creating value for the business? In the 2026 State of Data Resilience market study, 90.3% of organizations said they are engaging with AI in IT operations or security — but only 29.2% have AI running in production workflows.
The better question is not simply, “Are we using AI?” It is, “Is the AI we are putting into the business helping us get to a better outcome — faster, cheaper, or with less strain on the team?”
That distinction matters in data resilience. When asked to identify the highest-value AI use case for backup and recovery, 57.9% of survey respondents pointed to AI-based anomaly detection. Yet only 17.4% have deployed it.
That is how Arcserve has approached AI in UDP 11: start with the problem IT teams deal with every day, then apply AI where it can help without adding more work. AI anomaly detection is a good example. It runs behind the scenes, looks for unusual changes in backup data, and helps teams spot signs of compromise earlier.
AI Is Making Ransomware Easier to Launch — and Harder to Spot
Ransomware has been around for years. What has changed is how quickly attackers can now move — and how much harder their first touchpoints are to recognize.
Phishing emails no longer look as obvious. Over 80% of incoming phishing emails now use AI to craft more convincing messages — and 78% of those are opened. The spelling errors and awkward formatting that once made phishing easy to spot are disappearing. Training-based defenses are eroding.
Ransomware timelines have dropped from days to minutes. In 2021, an attack might take days, weeks, or even months to move through an environment. Now, with ransomware-as-a-service and AI-assisted automation, some attacks have gone from initial access to ransom demand in under 30 minutes.
Ransomware is moving downmarket. When an attack took weeks of effort, attackers needed a large payout to make the work worthwhile. But when the work can be compressed into hours — or less — the math changes. A smaller ransom can still pay off. That is why ransomware is moving toward smaller companies and aiming at a much broader set of organizations.
Attackers are getting better at finding weak spots. The hacking community is adopting AI at an accelerating rate. At a recent gathering of more than 100 security-industry CEOs ahead of RSA, there was broad consensus: attackers are integrating AI into their toolkits faster than most defenders.
The numbers from the 2026 State of Data Resilience market study confirm the exposure: 52.3% of organizations have experienced a ransomware event, and 59.0% of IT leaders rank ransomware impact on backups as a top-three concern.
That is why this is not only a prevention conversation. Prevention stUll matters, but organizations also need a reliable way to recover if ransomware gets through. In that moment, backup becomes the last line of defense.
Many Teams Believe They Can Recover. Fewer Have Proved It.
A lot of organizations feel confident about recovery. The harder question is whether they have tested that confidence.
The 2026 State of Data Resilience report found that 65.1% of organizations are confident they can recover from ransomware within 48 hours. But consider what a 48-hour outage actually means — systems unavailable, customers unable to transact, operations halted. For most companies, that is catastrophic. Which organization can comfortably absorb a 48-hour outage where customers cannot access what they need? For most companies, that would be brutal.
The testing data makes that confidence harder to rely on:
-
Only 35.4% met RPO/RTO targets in their most recent full-recovery test.
-
35.9% recovered but outside the target timeframe — too slowly for compliance or cyber insurance commitments.
- 24.1% have never tested full recovery at all.
Open-ended survey responses reinforced the pattern: practitioners cited "insufficient testing and false confidence that the backups will work as planned" and "the disconnect between what we think we can recover and what we can actually recover."
The issue is not only whether a backup exists. It is whether the recovery process has been tested well enough to trust it.
UDP 11: DR Runbooks close the gap. DR Runbooks are designed to make recovery planning and testing more repeatable. Teams can define the recovery sequence, account for workload dependencies, and run scheduled DR tests monthly, quarterly, or on demand. The goal is simple: use the same process in testing that the team would rely on during a real ransomware event, with evidence from each run to show what was tested and what happened.
Budget Pressure Is Forcing Hard Infrastructure Choices
Teams are being asked to fund more AI, defend against more capable ransomware, and absorb rising infrastructure costs at the same time.
In the 2026 State of Data Resilience market study, 53% of organizations said cost was incredibly challenging. That pressure is coming from multiple directions simultaneously: funding AI initiatives, rising hardware costs (79.0% affected by hardware price changes; 32.8% forced into architecture or vendor changes), hypervisor licensing increases (72.3% evaluating or planning platform changes), and growing ransomware defense needs.
Agentless Proxmox support. For organizations looking at alternatives in the hypervisor market, UDP 11 adds support for Proxmox with agentless, API-driven backup. That matters because teams can protect Proxmox workloads without installing agents on every VM. UDP 11 also introduces a Linux backup proxy, which helps reduce the Windows OS cost layer tied to backup infrastructure.
Cyber Resilient Storage as a VM. UDP 11 also gives teams another way to deploy Cyber Resilient Storage: as a virtual machine. That can matter when hardware budgets, procurement timelines, or supply constraints make dedicated appliances harder to justify. The ransomware-defense value is the same: keeping backup copies immutable so teams have a cleaner recovery path if an attack gets through.
AI That Helps Without Adding More Work
The useful version of AI is not the one that gives IT teams another thing to manage. It is the one that quietly helps them find problems earlier, recover faster, or reduce manual work.
AI anomaly detection runs behind the scenes during backup and looks for unusual changes in the data. If files are being encrypted in bulk upstream, those changes can show up in the backup pattern. The value is that teams can spot something sooner without adding another manual process.
Assured Security malware detection adds another layer by scanning files as they go into backup. The point is to reduce the chance that compromised data becomes part of the recovery set in the first place.
ArcGenie, the AI assistant in UDP 11, brings that same practical approach into the Arcserve Console. Admins can ask natural-language questions, get help with troubleshooting, and review environment-specific guidance without leaving the console. For newer admins, that can mean clearer next steps. For experienced admins, it can mean faster diagnosis and less time spent digging through screens.
The common thread is practical: AI should help the team get to a better outcome without asking them to spend more time and effort getting there.
Arcserve UDP Is Built to Meet Customers Where Their Environments Are
Customer environments are changing. Some teams are moving workloads across hypervisors. Others are balancing on-premises systems, cloud infrastructure, and SaaS applications. Most are trying to make those choices without adding more backup tools or more management complexity.
The 2026 State of Data Resilience market study shows 88.7% run two or more data protection tools; 50.8% manage them workload-by-workload across separate solutions.
Arcserve is built to be agnostic. UDP 11 introduces Arcserve Console with deployment choice:
-
SaaS — managed updates and lower operational overhead for teams that want the console delivered as a service.
-
On-Premises — the same console experience for teams that need management data, metadata, logs, and authentication to remain under their own control.
Both options deliver the same security posture, guided onboarding, and clear migration path from the legacy UDP Console. Customers get a modern experience without being locked into a single operating model.
The Goal Is Simple: Help Customers Recover and Keep Moving
The pressures covered in this post — AI-powered ransomware, the confidence-capability gap, budget constraints reshaping infrastructure — are not temporary disruptions. They are the operating conditions IT teams face now.
Arcserve has responded by doubling down on R&D over the past two years, shipping on a quarterly release cadence, and building based on direct customer input. NPS is up 20 points over two years.
That is the bigger idea behind UDP 11: give customers flexible, affordable data resilience that works with the environment they have today and the one they may need tomorrow. No solution can promise that ransomware will never get in. What matters is whether the business can recover when it does — and whether the team has tested that recovery before the worst day arrives.
Watch the UDP 11: Data Resilience for the AI Era virtual event on demand to hear the full discussion, see the demos, and learn how customers are approaching recovery planning in the AI era. Request a demo to see how UDP 11 can support your environment.