AsiaTechDaily – Asia's Leading Tech and Startup Media Platform
Enterprise applications are increasingly operating across infrastructure environments rather than within a single data center or cloud. F5’s 2026 State of Application Strategy report found that 93% of organizations operate in hybrid multicloud environments, while 86% operate across public cloud, private cloud and colocation. At the same time, organizations are increasingly running multiple AI models, with respondents reporting an average of seven models in use.
Kubernetes has become a central layer in this transformation. The Cloud Native Computing Foundation’s 2026 Annual Cloud Native Survey found that 82% of container users run Kubernetes in production, up from 66% in 2023. The survey also found that 66% of organizations hosting generative AI models use Kubernetes for some or all inference workloads. The result is a growing gap between how applications are built and how organizations prepare to recover them. The modern application may be distributed by design, while its resilience strategy can still be organized around individual infrastructure components.
Cloud-native architectures have changed what constitutes an application. A business-critical service may depend on Kubernetes workloads, persistent storage, databases, APIs, identity services and external platforms, with different components running across public cloud, private infrastructure and on-premises environments.
That creates a problem that traditional backup strategies were not necessarily designed to address. Protecting each environment independently does not automatically establish that the application can be restored as a functioning system. A September 2026 CNCF analysis of three reproducible Kubernetes disaster scenarios illustrates the distinction. The research specifically separates having backups from being able to recover a stateful application, examining problems involving persistent data, declared versus stored state, and consistency across multiple volumes.
The implication is significant: a successful backup operation can still leave an organization unable to reconstruct the application state it needs.
Kubernetes is partly responsible for this architectural shift because it gives organizations greater flexibility in where workloads run. That flexibility can support hybrid and multicloud strategies, but it also means that the application and its dependencies can cross traditional infrastructure boundaries. CNCF’s earlier work on cloud-native disaster recovery highlights why distributed stateful workloads introduce different recovery considerations, including availability, consistency, failure domains and the relationship between application state and infrastructure. This creates an important distinction between workload portability and resilience portability. An enterprise may be able to move a workload between environments while its recovery mechanisms, data dependencies or operational processes remain tied to the environment where the workload originated. That becomes particularly important as organizations treat Kubernetes as production infrastructure rather than simply a development platform.
AI is making the resilience question more complicated because applications increasingly depend on data, models and distributed inference infrastructure. F5’s research found that 78% of digital leaders operate their own inference infrastructure, while 52% of organizations chain or orchestrate multiple AI models. The report describes distributed inference as another source of application complexity, with additional requirements around security, observability and management. This means an AI-enabled application may depend on several interconnected layers. Losing one component can affect the wider workflow, even when the underlying data itself remains available. That is why resilience is increasingly moving beyond the traditional question of whether data has been backed up.
While conversing with AsiaTechDaily, Mark Tan, Vice President, Tech Data Singapore & Tech Data Malaysia, explained that the problem is becoming more architectural as enterprises adopt cloud-native and AI environments:
“One of the biggest gaps is the assumption that because data is backed up, the application can be recovered. Traditional backup and disaster recovery approaches were largely designed around more static environments. Today, an application and its data can span Kubernetes clusters, public and private cloud, and on-premises infrastructure, with dependencies sitting across different parts of the environment.
This creates a different recovery challenge. An organisation may have backup capabilities across individual parts of its environment, but that does not necessarily mean it can recover a cloud-native application and its associated data end-to-end. Kubernetes is designed to give organisations greater flexibility in where workloads run and move, so the protection and recovery approach needs to move with them. Otherwise, organisations may find that the workload itself is portable, but their resilience strategy is still tied to the environment it came from.
AI makes that challenge more important because the underlying data is increasingly central to how these applications operate and deliver value. Rather than treating backup as a standalone infrastructure purchase, it needs to form part of the wider conversations around cloud modernisation, cybersecurity and business continuity. As organisations adopt more specialised technologies, the challenge is increasingly how those technologies work together across cloud infrastructure, cybersecurity and resilience. Ultimately, the measure of success is not how many protection tools an organisation has, but whether the business can recover when it needs to.”
The convergence does not stop at infrastructure. Google Cloud’s M-Trends 2026 report found that attackers are increasingly targeting backups, identity services and virtualization layers specifically to deny recovery. Its analysis describes a shift toward “recovery denial,” where compromising the systems required to restore operations can be as consequential as compromising production data itself.
Veeam’s 2026 Data Trust and Resilience Report points to a similar gap between confidence and validated outcomes. While 90% of surveyed organizations said they were confident they could meet their defined recovery time objectives, only 69% said those objectives fully aligned with business continuity goals. Among organizations affected by ransomware, only 28% reported fully recovering affected data.
For enterprises, this changes the meaning of resilience. Recovery cannot be treated purely as a backup team’s responsibility when applications, identities, infrastructure and security controls are interconnected.
The challenge for enterprises is therefore less about accumulating more protection tools and more about understanding what actually needs to recover together. That increasingly means considering:
Asia’s accelerating AI adoption makes this particularly relevant. Commvault and Omdia’s 2026 research across Asian markets found that more than one-third of organizations were trialing or deploying agentic AI across IT, cybersecurity and core business processes, while 95% planned to increase AI spending. The study also identified gaps in resilience and recovery readiness across the region.
Enterprise architecture has moved from relatively self-contained systems toward distributed collections of workloads, data, services and infrastructure. Kubernetes, hybrid cloud and AI are accelerating that transition.
Resilience therefore has to evolve in the same direction. The relevant question is no longer simply whether an organization’s data is backed up or whether an individual infrastructure component can be restored. It is whether the application and the business process that depends on it can return to operation when its underlying environments fail. As enterprise applications become more distributed, resilience can no longer remain tied to the infrastructure of the past. It has to become as portable, interconnected and application-aware as the systems it is designed to protect.