KubeCon 2022: Data Security and Protection Insights

Adoption of Kubernetes is tipping to the mainstream, with more than half of enterprises currently using Kubernetes in production according to recent Evaluator Group research. As these environments become stateful and run critical business services, IT and platform operations teams play a mission critical role in supporting the developer experience by facilitating data and infrastructure-related services. This was a major theme at KubeCon 2022 across the keynote and breakout sessions and conversations that Evaluator Group participated in.

Kubernetes Adoption Challenges

The problem is that most IT organizations today face gaps in both staffing and Kubernetes-related skills, and this is no different when it comes to data security and protection. Although some pockets of customers are ahead of the curve in their adoption and ability to utilize capabilities such as the underlying resiliency of containerized architectures, it was clear at the show that this is not the case for most IT shops.

Consequently, it is not surprising that insufficient IT staff is the third-most common problem with customers’ current data protection solutions, and nearly one on four are struggling with lack of support for new environments like Kubernetes as a top data protection-related pain point – according to a forthcoming primary research study from Evaluator Group on trends in enterprise data protection.

The State of Kubernetes Data Protection

Especially against the tide of ransomware and data privacy legislation and regulations, how does IT enable secure and compliant test/dev and production environments, while meeting business requirements for recovery points, recovery times and rollback and migration, without impeding business differentiating developer agility and productivity? Especially when it comes to cloud-native Kubernetes applications, this is a difficult feat. Open-source software such as Kubernetes is prone to code bugs and misconfigurations, as well as known vulnerabilities that regularly require updates and patches to be addressed. This task is difficult for IT to keep up with because of the cadence at which Kubernetes distributions are updated, as well as the ballooning and sprawling reach of the Cloud Native Computing Foundation (CNCF) – which now counts more than 120 projects and more than 176,000 contributors. The problem has become so pervasive, the Cloud Native Security conference has now been spun off as its own dedicated event.

Based on discussions at KubeCon 2022, Evaluator Group anticipates that the responsibility for data protection will remain with platform and IT operations, making it important to bake functionality in, in a way that makes it easier for developers to obtain their IT resources and roll applications back as needed in a secure and compliant manner. Vendor product enhancements announced at the show by and large carried a theme of simplicity in the form of automation and autonomy. This approach will help to avoid protection gaps and human error. It will also support the ability to scale policies across multi-cluster deployments, which are becoming more common to meet availability and tenant isolation requirements as Kubernetes environments scale.

Data Migration with Kubernetes

Another common theme is adding to ability to – or making it easier to – migrate data and applications, whether from on-premises to the cloud, between clusters, or between Kubernetes distributions. For customers, avoiding lock in is critically important, for several reasons including:

  • Providing the flexibility for developers to develop in the environment of their choice, and to then migrate the application to the environment that makes sense for business requirements such as security, performance, and cost.
  • Along a similar vein, providing the ability to migrate production applications and their data between cloud and Kubernetes providers as business requirements (e.g., compliance and workload performance) change, and as vendors update their feature sets and pricing.
  • Accelerating recovery from ransomware attacks – and in some cases, facilitating recovery. Evaluator Group has heard for years the desire among customers to avoid “putting all of their eggs in one basket” – for example, relying on the same cloud provider for their production and disaster recovery environment.
  • Facilitating a hybrid cloud approach.

What’s Next?

In conclusion, this is a developing market made more complex by the spattering of Kubernetes distributions and container-native approaches, as well as limited education around enterprise-grade data protection requirements for Kubernetes workloads. For IT operations, working hand-in-hand with development and security teams will be a requirement in order to facilitate a data protection approach that provides the appropriate levels of cyber-resiliency and meets service level agreements (SLAs) for data loss and downtime, without slowing down DevOps agility.

Author Information

Krista Case

Krista Case brings over 15 years of experience providing research and advisory services and creating thought leadership content. Her vantage point spans technology and vendor portfolio developments; customer buying behavior trends; and vendor ecosystems, go-to-market positioning, and business models. Her work has appeared in major publications including eWeek, TechTarget and The Register.

Related Insights
Autonomy Over Analytics The Read-Write Decree Rewiring Enterprise Data Platforms
August 28, 2026

Autonomy Over Analytics: The Read-Write Decree Rewiring Enterprise Data Platforms

Brad Shimmin, VP & Practice Lead at Futurum, reveals findings from the new Data Intelligence Platforms Signal report, highlighting how read-write AI agents and transactional execution realigned competitive market standings....
Nasuni Acquires DryvIQ to Bring AI-Ready Data Governance
August 28, 2026

Nasuni Acquires DryvIQ to Bring AI-Ready Data Governance

Alastair Cooke, analyst at Futurum, shares his insights on why Nasuni acquires DryvIQ and what the deal means for AI data governance and file platform consolidation....
In-Process Analytics Goes Hyperscale Inside the AWS DuckLabs Acqui-Hire
August 28, 2026

In-Process Analytics Goes Hyperscale: Inside the AWS DuckLabs Acqui-Hire

AWS acquires DuckLabs to embed DuckDB’s in-process OLAP engine natively into Amazon S3 storage, challenging data warehouse economics while keeping open-source governance independent....
ScyllaDB's Rust Driver Delivers 58% Throughput Gain for DynamoDB Users
August 28, 2026

ScyllaDB’s Rust Driver Delivers 58% Throughput Gain for DynamoDB Users

ScyllaDB released an open-source Rust driver for its DynamoDB-compatible Alternator API, achieving 58% higher throughput than AWS SDK on 3-node clusters. The driver maintains full API compatibility while enabling cluster-aware...
Salesforce Q2 FY 2027 Can Agentforce Drive Revenue Reacceleration
August 27, 2026

Salesforce Q2 FY 2027: Can Agentforce Drive Revenue Reacceleration?

Futurum Research analyzes Salesforce’s Q2 FY 2027 earnings, focusing on AI and data momentum, Agentforce adoption, Anthropic partnership expansion, and FY 2027 guidance....
AI Maps Cancer's Hidden States to Predict Winning Drug Combos
August 26, 2026

AI Maps Cancer’s Hidden States to Predict Winning Drug Combos

AI algorithms identified ultraconserved cancer cell states across patients and predicted synergistic drug combinations with ~90% accuracy, challenging assumptions about tumor heterogeneity....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.