Share This:

A lot of businesses end up with a piecemeal approach to backup. While that’s certainly better than having no backup at all, it often creates a patchwork environment that is far less reliable than it appears. As someone who regularly examines office IT systems, I’ve seen this firsthand more times than I can count.

Most SMBs don’t intentionally deploy four or five backup solutions. It happens gradually, often with the best of intentions, until an incident reveals just how complicated and fragmented the environment has become.

One department purchases a cloud backup product after a close call. IT keeps a legacy platform running because nobody wants to delete the last known good copy. An MSP introduces another solution. Microsoft 365 native backup is enabled. Before long, no one has a complete picture of what’s being backed up, where data is stored, how long it’s retained, or whether it can actually be restored when needed.

The numbers behind the problem are telling. Gartner research found that large enterprises now operate an average of 45 cybersecurity tools, reflecting years of incremental purchasing rather than intentional planning. At the same time, 36 percent of cybersecurity professionals cite excessive complexity as a major challenge, while 43 percent report compatibility issues between security tools.

When more tools create less confidence

Michael D’Angelo, founder and principal of Alethean Group, a digital forensics, incident response, and litigation support firm with more than 17 years of experience, says he regularly encounters this problem after organizations have already suffered an incident.

“The biggest problem is that multiple backup tools can create a false sense of security,” he says. “An organization may believe it has five layers of protection, when in reality it has five incomplete systems with different retention periods, permissions, encryption standards, and recovery procedures.”

During an actual incident, those differences can quickly become critical. One tool may contain the needed data but retain it for only 30 days. Another may have been configured incorrectly. A third could rely on credentials compromised during the attack. Meanwhile, nobody has verified whether any of the solutions can perform a successful full restoration.

Backup sprawl is really an asset visibility problem

Amit Shingala, CEO and co-founder of Motadata, believes the root cause often lies elsewhere. “Backup sprawl is rarely a backup problem,” he says. “It is an asset visibility problem that shows up in the backup line item.”

His company helps organizations identify which backup agents are running on endpoints, compare that against asset inventories, and determine what they’re actually paying for. “The gap between those three lists is where backup sprawl lives.”

Backup solutions are often purchased in response to immediate needs rather than through a long-term strategy. A ransomware scare leads to one purchase. A new SaaS application introduces native backup capabilities. An acquisition brings inherited tools. A department adopts its own solution while IT is focused elsewhere. Few of these purchases are ever retired, and every renewal makes the environment more difficult to untangle.

The security implications extend beyond operational complexity.

“Five tools does not mean five times the protection,” says Shingala. “It means five sets of privileged credentials, five agents with deep filesystem access, five consoles nobody is watching, and five restore paths nobody has tested. Attack surface scales with the sprawl. Assurance does not.”

According to Shingala, the most dangerous situation is not being unprotected. It’s believing you’re protected when no one has verified who owns what or whether recovery will actually work.

The path forward starts with discovery

Kirill Meshyk, Head of AI Data Collection at Unidata, says ownership gaps often turn backup sprawl into a serious business risk. “When multiple tools each cover a slice of the estate with no one person in charge of the overlapping area, you get the worst-case scenario in security: a false confidence.”

He frequently sees situations where multiple tools attempt to protect the same data on overlapping schedules. Ironically, this can leave data effectively unprotected because each solution assumes another is serving as the primary backup.

At the same time, every additional console, set of credentials, and audit log creates another potential point of exposure. The backup system nobody owns often becomes the one nobody patches.

All three experts agree that solving the problem starts with discovery, not procurement. “Consolidation starts with an audit, not a purchase,” Meshyk says.

Shingala recommends comparing active backup agents against asset inventories and software contracts. According to him, the results often surprise organizations. What surfaces is not only redundancy, but also coverage gaps, with several tools protecting the same workloads while critical systems remain completely uncovered.

For MSPs, D’Angelo believes the conversation should begin with a different question. “Do you have backups?” is the wrong question. The right one is: “When was the last time you proved you could restore from them?”

Because in the end, the value of a backup strategy isn’t measured by how many tools are deployed. It’s measured by whether data can be recovered when the business needs it most.

Photo: Andrey_Popov / Shutterstock


Share This:
Kevin Williams

Posted by Kevin Williams

Kevin Williams is a journalist based in Ohio. Williams has written for a variety of publications including the Washington Post, New York Times, USA Today, Wall Street Journal, National Geographic and others. He first wrote about the online world in its nascent stages for the now defunct “Online Access” Magazine in the mid-90s.

Leave a reply

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.