Kubernetes Data Protection – Addressing Ransomware Threats and Maintaining DevOps Agility

Kubernetes is here, and it is here to stay. According to Evaluator Group primary research, not only are most enterprises already using or planning to use Kubernetes, they are using Kubernetes for production workloads. We typically associate container environments and Kubernetes with cloud-native applications, and supporting these in production remains a leading use case. We are also seeing customers refactored VMware workloads for container infrastructures. No longer an infrastructure just for test/dev use cases, Kubernetes is now being used to support a range of business-critical workloads.

Unfortunately, because Kubernetes adoption is developer-driven, happening outside of the control of central IT, many organizations are delaying and neglecting protection of Kubernetes applications and their persistent data. Adoption is proceeding faster than enterprise-level protection, creating protection gaps that lead to the risk for data loss and downtime of business services. Proper management and protection is required as Kubernetes implementations support critical workloads, and as they operate at larger scale.

Why do Kubernetes workloads need to be protected? Evaluator Group consistently hears from customers that getting applications and business services back up and running as quickly as possible following an outage is a key concern, especially with how rampant ransomware has become. Like any platform, Kubernetes has vulnerabilities. For example, recently a vulnerability was found in CRI-O, a container runtime engine for Kubernetes, that allowed for root access to the host. Adding to its security risk posture, Kubernetes is an open-source platform, which means it carries the risk for code bugs and misconfigurations that require updates and patches to be addressed. It is difficult for IT to keep up these vulnerabilities because Kubernetes is on a quarterly update cadence.

The influence of DevOps on Kubernetes adoption and usage increases the need for automated data protection functionality. This includes not only applying protection policies that are set by IT, but also for recovery and failback operations. For example, disaster recovery plans can provide workflows to identify backups to recover from and to reconfigure metadata and namespace mappings. Developers need to operate as quickly as possible, making self-service recovery that is controlled with an intuitive user interface with strong access control capabilities such as role-based access control (RBAC) and multi-factor authentication (MFA) also important.

Kubernetes workloads require special efforts when it comes to data protection. They are architected differently and as a result introduce new requirements compared to virtual and physical machines. Additionally, in many cases there has not been enough coordination during the application delivery to ensure that protection meets enterprise requirements. Finding a data protection solution that meets these requirements while at the same time addresses DevOps teams’ need for agility is important.

Author Information

Krista Case

Krista Case brings over 15 years of experience providing research and advisory services and creating thought leadership content. Her vantage point spans technology and vendor portfolio developments; customer buying behavior trends; and vendor ecosystems, go-to-market positioning, and business models. Her work has appeared in major publications including eWeek, TechTarget and The Register.

Related Insights
Autonomy Over Analytics The Read-Write Decree Rewiring Enterprise Data Platforms
August 28, 2026

Autonomy Over Analytics: The Read-Write Decree Rewiring Enterprise Data Platforms

Brad Shimmin, VP & Practice Lead at Futurum, reveals findings from the new Data Intelligence Platforms Signal report, highlighting how read-write AI agents and transactional execution realigned competitive market standings....
Nasuni Acquires DryvIQ to Bring AI-Ready Data Governance
August 28, 2026

Nasuni Acquires DryvIQ to Bring AI-Ready Data Governance

Alastair Cooke, analyst at Futurum, shares his insights on why Nasuni acquires DryvIQ and what the deal means for AI data governance and file platform consolidation....
In-Process Analytics Goes Hyperscale Inside the AWS DuckLabs Acqui-Hire
August 28, 2026

In-Process Analytics Goes Hyperscale: Inside the AWS DuckLabs Acqui-Hire

AWS acquires DuckLabs to embed DuckDB’s in-process OLAP engine natively into Amazon S3 storage, challenging data warehouse economics while keeping open-source governance independent....
ScyllaDB's Rust Driver Delivers 58% Throughput Gain for DynamoDB Users
August 28, 2026

ScyllaDB’s Rust Driver Delivers 58% Throughput Gain for DynamoDB Users

ScyllaDB released an open-source Rust driver for its DynamoDB-compatible Alternator API, achieving 58% higher throughput than AWS SDK on 3-node clusters. The driver maintains full API compatibility while enabling cluster-aware...
Salesforce Q2 FY 2027 Can Agentforce Drive Revenue Reacceleration
August 27, 2026

Salesforce Q2 FY 2027: Can Agentforce Drive Revenue Reacceleration?

Futurum Research analyzes Salesforce’s Q2 FY 2027 earnings, focusing on AI and data momentum, Agentforce adoption, Anthropic partnership expansion, and FY 2027 guidance....
AI Maps Cancer's Hidden States to Predict Winning Drug Combos
August 26, 2026

AI Maps Cancer’s Hidden States to Predict Winning Drug Combos

AI algorithms identified ultraconserved cancer cell states across patients and predicted synergistic drug combinations with ~90% accuracy, challenging assumptions about tumor heterogeneity....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.