From Data Resilience to AI Trust with Veeam

For 40 years, enterprise security rested on two assumptions: the actor is human, and the actor is either authorized or hostile. Anand Eswaran says both assumptions broke over the last 18 months.

At the Six Five Summit: AI Unleashed 2026, Patrick Moorhead kicked off the Data & Observability Track with Eswaran, President and CEO of Veeam, to discuss what enterprise data strategy looks like once AI agents start acting with real autonomy.

Eswaran frames the shift in three eras. Era one was backup and recovery, governed by the rule: assume restore. Era two was cybersecurity, governed by: assume breach. Era three, the one enterprises are entering now, runs on: assume drift, meaning an agent that is fully authorized and doing exactly what it was told is acting on data whose meaning has quietly changed underneath it. Eswaran compares it to GPS running on a two-year-old map, confidently routing drivers down a road that no longer exists. That reframing is also the logic behind Veeam's acquisition of Securiti AI, which fuses Veeam's resilience business with Securiti's data security and governance platform into a single DataAI Command Graph, moving the enforcement point from the agent itself to the data the agent touches.

The practical payoff is precision recovery. Instead of a full-system rewind, Veeam's approach isolates and undoes only the specific actions an agent got wrong, a capability Eswaran says depends on knowing exactly what changed, when, and under whose authority. Veeam's first version of this, Intelligent ResOps, is in private preview for Microsoft 365 now and scheduled to launch in Q4.

Key Insights:

🔹 “Assume Drift” is the new security principle for the agentic AI era, following “Assume Restore” and “Assume Breach.” The greatest risk may come from fully authorized agents acting on data whose meaning or context has changed.

🔹 Enterprise trust remains largely unfunded and unowned. In Veeam’s research of roughly 300 senior leaders, only 7% reported having a dedicated data governance leader.

🔹 Security spending remains misaligned with what happens after an incident. A BCG survey of roughly 300 CISOs placed backup and recovery well behind cloud and data security in spending priorities—even though Eswaran argues recovery becomes the most critical capability once something goes wrong.

🔹 Veeam’s acquisition of Securiti AI shifts the control point from the agent to the data itself, enforcing access and governance at the source through a unified DataAI Command Graph.

🔹 Precision recovery could replace the blunt instrument of a full-system rewind. Veeam Intelligent ResOps is designed to undo specific agent actions and is now in private preview for Microsoft 365, with general availability planned for Q4.

Eswaran's bet is that trust for the agentic era gets built directly into the data layer, ahead of wherever the next agent shows up.

Watch the full video at sixfivemedia.com, and subscribe to our YouTube channel so you never miss an episode.

Catch the rest of the Data & Observability track and full Six Five Summit: AI Unleashed 2026 coverage at sixfivemedia.com/summit.

Disclaimer: Six Five Media is for information and entertainment purposes only. Over the course of this video, we may discuss companies that are publicly traded, and we may reference their equity share prices. Nothing discussed during this webcast should be considered investment advice or a recommendation to buy or sell any security. We are not investment advisors, and you should not rely on this content as financial advice. Six Five Media collaborates with technology companies and industry leaders to produce research-driven interviews and multimedia programming for enterprise technology.

Patrick Moorhead:
Hey everybody, welcome to Six Five Summit 2026. The theme this year is AI Unleashed, and we're unleashing really good enterprise outcomes. but we're also unleashing security challenges. And today we're kicking off the data and observability track and exploring how the rise of agentic AI is reshaping enterprise priority around data trust, security, and resiliency. And joining us for this conversation is Anand Swaran, President and CEO of Veeam. Anand, welcome back to The Six Five. I think we had met up at RSA.

Anand Eswaran: 

Pleasure is all mine, Patrick. I look forward to the conversation.

Patrick Moorhead: 

Yeah, it sounds good. So why don't we just dive right in? So AI agents are starting to act on enterprise data. I know if you live in the tech bubble like us, it's happening a ton, but it's really just starting right now for the enterprise. And this brings autonomy, but also creates new risks around data quality, permissions, and getting unintended actions, agents unplugged. So as enterprises are moving toward this new era, how should enterprise leaders be rethinking? And for that matter, senior leadership rethink the assumptions about trust and resilience?

Anand Eswaran: 

It's a great question, Patrick. It's the heart of what every customer and every customer leader is thinking about. Now, the way I look at it is every security model we have built over the last 40 years almost rests on two assumptions. The first is the actor is human, and the second is that the actor is either authorized or hostile. It's one of the two, it's binary. And both of those assumptions fundamentally broke over the last 18 months, and most enterprise architectures has not caught up. And so I framed this whole thing in three eras. Era one, backup and recovery. And the rule was very simple. It was assume restore. If something breaks, you bring it back. Era two was cyber. And the rule was very simple again. Assume breach. Someone is going to breach you. And it stopped becoming if and started becoming when. And now we are in era three and the rule is assume drift and that is critical drift not overreach not autonomy. And I want to be precise about that because you know usually people think rogue agents and rogue is the easy case a compromised agent an overprivileged token. The hard one, more often, is the agent that is already registered, it's perfectly entitled, and it's doing exactly what you asked it to do on data whose meaning, whose context has completely changed. This is like a navigation system, a GPS running on a two-year-old map. It's not broken or compromised. It'll route you with complete confidence, except to a road which no longer exists. Now, that is the context. So, with that as context, I'll come back to your question. How do you rethink the assumptions for enterprise leaders on how they should rethink about data and observability and resilience? When we think of observability, it has usually meant telemetry about systems infrastructure applications latency traces saturation. All of that still matters. But none of it would have caught what I just described, drift, because at the infrastructure layer, the agent looked very healthy. In an agentic enterprise, the object of observation has to move down one layer to the data element itself. What is it? Who can see it? What changed it? What does it mean now versus an hour ago? What decisions has it already produced? That is the rethink. Shifting to the data element at its most granular level is the rethink every enterprise leader has to think about.

Patrick Moorhead: 

Yeah, I love the way you simplified a little bit of the argument here. You have friendlies and you have enemies. In the old days, it used to just be humans and some machines. And while most humans don't drift, right, and they're typically inside the organization, you know, they might be socially engineered or something like that, genes didn't necessarily do that. That's smart. So we are literally piling trillions of dollars of investments into the AI stack. And even three years ago, there was a lot of discussion around governance and security and the data layer. In fact, my I went to the original Microsoft OpenAI event. I was one of 100 people in there. And they were talking through and doing recipes. And I was thinking, how on earth are we going to apply this to the enterprise in a safe and secure way? To this day, it appears that trust is still lagging as a strategic priority. Why do you think this gap exists when it's being discussed and has been discussed at the board level?

Anand Eswaran: 

No, it's a great point, Patrick. Let me share a perspective from me and then let me tell you what we are doing about it. I think there are three structural reasons. The first, trust is no unit of measurement. It's hard to quantify. Compute has flops. It has a dollar figure associated with it. Models have benchmarks. Storage is terabytes. Every layer of the AI stack that got funded has a number associated with it, which probably a CFO could put on a line item. Trust has no number. And in large organizations a capacity with no unit of measurement does not get a funding line item. That's the first one. The second is trust is no clear single discrete owner. You know our own research across roughly 300 senior leaders 7 percent had a dedicated governance leader 7 percent. Everyone else governs this by committee which means no one owns it on the day when it really matters. And compared to security where you know 20 years getting to a named executive you have a named executive the CSO you have a board seat for that. And the third thing I look at is and this is you know interesting. BCG surveyed around 300 seasons in March and ranked you know nearly 26 security categories by spend intent for this year. And cloud security came in first. Data security came in second. Backup and recovery came in well after that. And why is that? It's because detection is visible. So it gets funded. Recovery is invisible right up to the second you actually, it's the only thing which will matter. So, you know, just as an example, you know, every infrastructure build out in history has over invested in throughput first. and under-invested in braking. We electrified cities decades before we standardized things as simple as circuit breakers and grounding. The fires came first, then the electrical code. So in some ways, we are the pre-code. And the difference this time, though, is the clock speed. We do not get decades to write it. In fact, we may not even get a month to write it. And there is also, by the way, a harder reason underneath all three. Trust requires you to really understand your own data at a very, very granular level. Where is it? What is in it? Who may see it? For what purpose? Under what consent? 90% of enterprise data is unstructured until AI made every file visible. Most of it was dark until then. So organizations skipped the trust layer, not because they did not value it, but because they could not build it without first solving a data problem they had deferred for 20 years. And that data problem is one which requires all five domains. data security, privacy, governance, compliance, resilience, you know, to come together. Historically, they've been dealt with all separately. And that is why Veeam is building the foundation of the data and AI trust layer, bringing these five domains together, which we launched in May 2026. And by the way, it's not just product. This is why we are also, the difficulty of this is also why we launched the data and AI trust maturity model. five four pillars 12 dimensions and five different maturity levels. We built it with McKinsey informed by over 300 CEOs and CEOs because our goal is not just to sell a platform it is to actually give a map and to partner with every company. You know and be the partner who actually walks it with every company.

Patrick Moorhead: 

It's ironic that I know you, it's funny, I tell my evolution story a little bit a slightly different way, but the fact that backup and resilience is number three, I don't know if that's a statement is we aren't as far along as we think we are. But listen, I think the good news is that combining these different layers, I listen, everything says that's a really good idea and having it under one company solves a lot of problem too. And listen, You built a tremendous business around data resiliency. Security brings, though, deep expertise in security and governance. And I'm curious, what becomes possible? What's the art of the possible when these two are brought together?

Anand Eswaran: 

It's a very critical question, but let me answer that by describing what that missing data and AI trust layer actually has to do, because the acquisition is actually a consequence of it, rather than the starting point. The way I look at it is, I look at it as the infrastructure for trust requires four things, and they're non-negotiable. One, you have to understand your data at a very discrete level, across data, across identity, across AI. Two, that context has to travel with the data, identity, policy, entitlements, consent, all of it moving with the data across its lifecycle, across every environment, across life and backups. Number three, you have to enforce before the agent acts. Identity aware, at runtime, before anything enters that agent context window. And finally, if something goes wrong, which you know it will, you have to isolate and undo precisely and only what went wrong. Now, here's the part which matters. The fourth one, that precision undo, is impossible without the top three. You cannot surgically undo what an agent did if you do not know what it touched, what that data was meant to be at that time, who was entitled to it, and who depended on it downstream. Precision recovery is not a recovery feature. It's actually a knowledge problem, which is super critical. And that is the entire argument or why we acquired Security AI rather than two partners with good integration. Because a partnership can exchange data, it cannot create a unified graph. Security has to know what governance knows, governance has to know what resilience knows, and resilience has to know what data meant at the moment it changed. That is not integration. It's one fabric. You know I always like to bring these to life with stories. My simple story here is the 1800s when electricity and magnetism were treated as completely separate forces. You know different rules different disciplines different teams different funding until 1831 where Michael Faraday showed that they were one field. He did not invent a new force. He actually unified two things which existed in the modern world. Everything we know today motors generators Wi-Fi computer memory became possible because of it. And I look at data and resilience as two sides of the same coin the same story. Their expressions of one underlying force treating them as two separate disciplines with separate budgets is not an option in the agentic era. And finally, I would also say, as we look at where we are in this journey, you know, bringing these together is genuine engineering work, and we are right in the middle of it. But what I'm confident about is the architecture, because the alternative, five vendors, five truths, five budgets, five different substrates of data, cannot get you to precision, not eventually, not ever.

Patrick Moorhead: 

Yeah, so it sounds like consolidation. And, you know, we saw this in the overall security market where the benefit of bringing in yet another security vendor was outweighed by the integration and the complexity of pulling that all together. So it sounds, listen, we called this we called this years ago. And that's why, I mean, one of the reasons why I think secured ISO is, was such a good acquisition. I do want to call, I do want to talk about, you know, agents are going to become more autonomous, a lot of headless type of applications being done. We've talked, we've seen swarms, agent swarms, which I know is a scary term and it probably should be. But what does a shift from, you know, control to command look for, for the teams responsible for data platforms, databases, search, and even analytics infrastructure?

Anand Eswaran: 

Yeah, it's such a key thing, actually, you call out, and it's actually very nuanced. So, if you let me just take a moment and… I look at it in a specific way. So, let me define the difference, because both these words, control and command, are very close, but the ideas are not. Control is permission at the moment that request happens. Can this identity access this resource? Yes or no? It's a binary gate, and it evaluates one actor, human or non-human, at one moment. Command is a standing condition of the environment. What is true about this data for this purpose, for this jurisdiction, for this class of identity right now? And what happens automatically the moment something acts on it wrongly? So control for me is a checkpoint, command is sort of the physics. And OpenAI actually called it out beautifully. They published something in July where their phrasing was that each step can look acceptable on its own while the sequence actually produces an outcome which is not okay. It's not approved. And that a model operating over a long time horizon can learn the blind spots of an approval system and work around them. Difference again between just control and command. So, You know, the way I look at it is, almost everyone in this industry today is searching for the same answer right now. Wrap controls around the agent, monitor it, intercept it at runtime, register it. And that approach has one fatal flaw, in my opinion. If your control point is the agent, you are only protected against the agents you know about. And shadow agents never show up in the registry. So this is not an edge case. You know, the agents most likely to hurt you are precisely the ones no one knows about. Our approach, Veeam's approach, completely inverts it. Our control point is not the agent, it's the data. classified, masked, identity aware, access controlled at the source. So an overprivileged agent doesn't get a warning, whether it's known, registered, or rogue, it just gets a brick wall. The data never enters the agent context window, and neither do you need to know about every agent in the enterprise. And that is key. And so, by the way, none of this works without one thing underneath it. A graph, a knowledge graph that actually understands all these relationships. Plenty of vendors, and that's the heart of Veeam's data command graph. Now, plenty of vendors have a graph, but what matters is what it understands. You know, R spans more than 300 connectors across every environment, identity, policy, model. That is the breadth. It goes on to an individual data element level, not just a database or a bucket level. That is the depth. And critically, it spans both your live estate and your protected copies simultaneously. It not only sees production, it can tell you what correct looks like. So wrapping controls around data and then data command graph to visually bring this life is how we bridge this gap between control and command and create the best poster for every company for their AR transformation.

Patrick Moorhead: 

And I'm just a tiny, tiny company gives us the ability to experiment. And we've rolled out about 15 or 16 agents. And I got to tell you, man, they drift. And I'm using the absolute most expensive labs-based agents that you can possibly do, and they just change. It's kind of eerie. So it just seems like a really pragmatic thing. Let's say if you're getting into compensation or you're paying an ACH, that there's certain amount of data and that, that at the data later gets blocked as opposed to it coming in. And maybe there's a, a check, the checker at the end that says, agent bow shop, don't do that. It should have never done it in the first place.

Anand Eswaran: 

And if data enters the agent context window, breaches already happened, even a few way to stop the agent. So anyway, you're saying the same thing.

Patrick Moorhead: 

I do. You know, it is a reality. You know, I like to say, you know, we went from pretending that we had perimeter defense and nobody was going to get in to, OK, the bad guys are going to get in, but we're going to get them out really quick and we're going to see what they did and do triage. And then we moved into, OK, they're going to get in, they're going to do damage. and then we'll basically do data recovery. But that can absolutely cripple an enterprise from actually getting up and running in the timeframe that they need to get up and running. How are you approaching recovery differently?

Anand Eswaran: 

Yeah, and it's this one more nuance. It's recovery quick, but also recover precise, right? Backup was invented for a world where the mistakes were human, singular, and slow.

Patrick Moorhead: 

Somebody accidentally blew away a database or something. I know, yeah.

Anand Eswaran: 

And something got deleted on Tuesday, you noticed on Wednesday, and you restored to Tuesday morning. I mean, that literally was the world we lived in. a full system rewind was an acceptable price because the alternative was losing everything. Agentic failures are different. They do not behave like that at all. An agent does not make one mistake. It makes a correct-looking sequence of 2,000 changes across, say, 10 systems and a downstream report that eight people have already made a decision on. I mean, that's the velocity and scale we are talking about. If your tool only does a full system rewind, then you are handed a genuinely terrible choice because you either restore everything and you destroy legitimate work across the entire business. At enterprise scale, that is an enormous amount of work or you restore nothing, which is obviously an option you can't live with. Now, precision resilience is the saviour. It's the critical and the only viable option, or the third option, which is undo exactly what went wrong without rewinding everything around it. You do not undo the whole system. You undo that five seconds of mistakes which shouldn't have happened. Now, every one of us has been on this, right? We have the ability to undo a document. It reverses the last thing you did, not the entire document. Why is it different for enterprise systems? And the reason is this, why it is a very hard problem is it's not a backup problem, as I said earlier. It's a knowledge problem. To undo those five seconds, you have to know exactly what changed, what they meant at the moment it changed, which identity and which agent touched them, what policy applied. And that is the Veeam Data Command Graph. Precision recovery is a consequence of the intelligence layer than a feature boarded on to a backup product. And by the way, Rubrik actually published a survey in April of 1,600 plus IT leaders. And the question was, do you want an undo button for AI agent actions, one that rolls back a specific action without a full system reset? Nine in 10 years said, yes, we need an undo button, not a rewind button. And that's why essentially what Veeam's intelligence layer does it, the reason we bought security, all of that coming together, the five domains coming together in one data command graph is exactly that, offering precision recovery for customers. And we launched that. It's not slides. It's not coming in 10 months. We launched Veeam Intelligent ResOps for the first workload, Microsoft 365, which is the most active agent-ride activity in most enterprises. We launched that. It's in private preview. It launches in Q4. And we are extending it across the entire data estate in the next several quarters. Precision recovery.

Patrick Moorhead: 

Anand. Great conversation. I've learned something, and as an analyst, we're supposed to pretend that we don't learn anything from anybody. But you've really shed huge light on data trust, security, and resiliency in the age of swarming headless agents. And everything you've said makes sense. Your acquisitions and what you built organically looks like people should be taking a close look at what you have to offer. I know you have a lot of customers, but could always use more. But quite frankly, repositioning the spend, I think, is important too. So thank you for kicking off the data and observability track at this summit.

Anand Eswaran: 

Thank you, Patrick. Always a pleasure to talk to you.

Patrick Moorhead: 

Thanks. Okay, to our viewers out there, don't forget to hit subscribe button, follow us on social media, check out all the Six Five Summit content for Veeam and also for this track. Take care. Don't go anywhere. We're going to be right back with more content.

Speaker

Anand Eswaran
Chief Executive Officer
Veeam

Anand Eswaran is the Chief Executive Officer (CEO) of Veeam. Anand’s strategic vision, inclusive leadership, and execution focus have created a track record of building and leading high-growth, successful global businesses.

Prior to joining Veeam, Anand led RingCentral to accelerating growth and innovation as its President and Chief Operating Officer (COO). Prior to RingCentral, Anand was responsible for Microsoft’s Enterprise Commercial and Public Sector business globally. Earlier in his tenure at Microsoft, he led Microsoft Services, Industry & Digital, Customer Care, and Customer Success — a global team of 24,000 professionals.

Prior to joining Microsoft, Anand was the Executive Vice President of the $5.4B Global Services business at SAP, leading 17,000 business process and technology professionals to accelerate customer and partner value creation through SAP’s enterprise applications. He has held multiple other leadership roles, including Vice President of Global Software Services at HP, Vice President of Global Professional Services at Vignette (now OpenText), and Senior Manager at Braun Consulting (now Fair Isaac).

Anand is a founding member of the Technology Services Industry Association (TSIA) and served on the executive advisory board for 12 years. He holds a master’s degree in computer science and engineering from the University of Missouri-Columbia and a bachelor’s degree in computer engineering from the University of Mumbai, India. He is married and has two children.

Anand Eswaran
Chief Executive Officer