Popular: CRM, Project Management, Analytics

How Infrastructure and Data Protection Teams Are Working More Closely Than Ever

8 Min ReadUpdated on Aug 17, 2026
Written by Perrin Johnson Published in Technology

Half a decade ago, IT infrastructure and data protection were handled by distinct, siloed teams.  One team built the infrastructure, another designed security, and a third handled data security. But this division doesn’t hold up anymore. 

Today, the ransomware groups are directly targeting the backup repositories before moving on to production data. As a result, regulators in different regions have begun treating recovery readiness as a compliance requirement rather than just a ‘best practice’.  

And for companies managing operations in multiple locations, hybrid environments have discovered that resilience cannot be glued on later, after the architecture is complete; it has to be part of it from the beginning.  

And this is why infrastructure and data protection teams are increasingly sitting at the same table, sometimes literally, often through shared tooling and joint incident playbooks. 

Why Data Security and Infrastructure Operations Are Converging 

There are three forces at play here. They are driving this shift, and none of them are going away soon. 

● Ransomware's evolution: Attackers learned that encrypting production data isn't enough if the victim can just restore from backup, so they now target backup infrastructure itself, sometimes days before the actual encryption event. That turns backup from a passive insurance policy into an active target infrastructure team must defend. 

● Regulatory pressure: Frameworks like DORA in the EU and various national cybersecurity acts across APAC now hold organizations accountable for demonstrable recovery capability, not just stated policy. Auditors want tested RTOs, not a document describing them. 

● Growing complexity: Hybrid and multi-region working environments mean a larger attack surface, more failure points, and greater coordination required between the people who run the infrastructure and those who defend it. 

It means, nowadays, a single backup admin working in isolation can no longer see the whole picture and guarantee cyber resilience. And that's the core of why this convergence is happening. 

How do IT infrastructure and security teams share operational responsibilities under a Zero Trust Framework?

Security teams and IT infrastructure teams share responsibilities under a Zero Trust Framework where the former set micro-segmentation, identity, and access policies while the infrastructure teams implement them across networks, hypervisors, and storage. Also, the security teams monitor threat signals and conduct audits while the infrastructure team automates provisioning, enforces continuous authentication protocols, and maintains patch schedules. Together, they eliminate implicit trust across hardware and workloads.

What Cross-Functional Data Protection Looks Like in Large Enterprises 

In practice, convergence shows up in a few concrete ways: 

Traditional Model Converged Model 
Infrastructure and backup teams plan separatelyJoint incident response runbooks define who does what in the first hour
Architecture judged on performance and cost aloneArchitecture also judged against recovery criteria (RTO/RPO)
Security telemetry and infrastructure telemetry live in separate toolsSignals correlated across endpoints, network, and infrastructure
Backup reviewed after deployment, if at allBackup validated as part of the design and migration process

Threat detection has also moved closer to the infrastructure layer itself. Modern security operations increasingly rely on correlating signals across endpoints, network traffic, and infrastructure telemetry rather than treating each as a separate silo.  

So, platforms built around extended detection and response exist precisely because isolated point tools miss the patterns that matter. An anomaly in storage IOPS combined with unusual lateral movement on the network tells a very different story than either signal alone. 

How Enterprises Should Evaluate Data Protection Readiness in Infrastructure Platforms 

For a CIO or infrastructure director evaluating platforms, a short list of criteria consistently separates the serious contenders from the rest: 

1. Native backup and recovery integration at the hypervisor and storage layer, rather than a bolted-on third-party dependency. 

2. Immutable and air-gapped recovery options, since attackers specifically try to corrupt or delete backup copies. 

3. Hypervisor and network defense, with Sangfor aSEC integrating security directly with the Sangfor aSV hypervisor architecture. Its next-generation firewall and micro-segmentation capabilities extend protection from the data center edge to individual virtual machines, securing east-west traffic and reducing the blind spots associated with externally added security tools.

4. Documented RTO and RPO benchmarks work as real benchmarks and not marketing claims. 

5. Compatibility with existing backup ecosystems, particularly Veeam and Cohesity, so enterprises avoid a rip-and-replace migration nobody wants to sign off on. 

What role does AI play in modern data protection strategy? 

AI plays a key role in modern data protection strategy by enabling faster anomaly detection, automated threat correlation, and streamlined recovery orchestration. For larger companies, this lowers the manual coordination burden between infrastructure and security teams during an active incident, shortening response and recovery timelines. 

How does AI-driven anomaly detection work on the storage layer? 

At the storage layer, AI-driven anomaly detection identifies metadata patterns, file entropy, and I/O traffic in real time. Also, by establishing baseline behavioral profiles, machine learning algorithms flag sudden increases in mass encryption, unexpected batch file deletions, or abnormal user read requests. And upon detecting potential ransomware, the storage array instantly triggers security teams.  

Comparing Infrastructure Platforms on Native Data Protection Capability 

Here most vendor comparisons get too broad too fast. So, it is more useful to stay at the hypervisor layer, since that's where backup integration actually lives.

LayerSangfor aSVVMware ESXi
Backup integrationNative, minimal and agent overheadOften requires third-party agents
Licensing modelSimplified, fewer add-on costsAdditional licensing for extended features
Recovery tooling compatibilityBuilt for direct Veeam/Cohesity integrationBroad ecosystem, but assembled separately

Nutanix and Proxmox occupy similar territory to aSV but generally lean on third-party backup stacks layered on top rather than native integration. That distinction, built-in versus bolted-on, shows up repeatedly in how these platforms get reviewed by the people who actually run them.  

In the G2 Summer 2026 Reports, Sangfor earned multiple badges and Leader status across categories including Hyperconverged Infrastructure, Hybrid Cloud Storage, and Disaster Recovery, with reviewers specifically calling out backup management and reliable performance under production load. 

Sangfor is Changing the Data Protection Conversation 

Sangfor is a global provider of AI-enabled cloud infrastructure, serving more than 100,000 customers across APAC, EMEA, and LATAM, including Fortune Global 500 organizations and regulated government and healthcare entities.  

So, data protection now sits inside its stack as an architectural principle rather than an afterthought. 

The clearest example of this is Sangfor Backup Platform Powered by Veeam, which combines Sangfor HCI with Veeam's Data Platform for agentless, cross-platform backup, including scenarios in which enterprises are migrating from VMware and want to retain existing Veeam workflows rather than start over.  

The company also holds a Global Strategic Partnership with Cohesity, extending native data resilience across HCI and Enterprise Distributed Storage. 

The operational payoff shows clearly in practice. One Malaysian utility company, classified as national critical infrastructure and regulated under Malaysia's Cybersecurity Act 2024, ran security and infrastructure operations. After adopting Sangfor Athena MDR, the results included: 

● 95% faster response time for critical alerts 

● 83%+ annual savings in security operations costs versus building an in-house SOC 

● Full compliance readiness aligned with mandatory audit requirements 

● Continuous visibility across on-premises and cloud environments 

It's a useful illustration of what convergence actually looks like when a lean team has to own both infrastructure and resilience at once. Sangfor's platform performance is also reflected in independent G2 and Gartner reviews, which enterprise buyers increasingly consult before shortlisting vendors. 

What Infrastructure and Security Leaders Should Plan for Next 

A few practical steps tend to separate enterprises that handle this transition well from those that struggle: 

● Test backup before cutover: Migration planning should include backup validation testing before the switch, not as an afterthought once the new environment is live, to maintain business continuity

● Recalculate the total cost of ownership: TCO needs to account for security and backup add-ons, not just base infrastructure licensing. 

● Assign runbook ownership: When infrastructure and data protection responsibilities overlap, someone has to be accountable for the joint runbook, or accountability quietly disappears during an actual incident. 

Data Protection Is Now an Infrastructure Decision, Not a Backup Policy 

The convergence between infrastructure and data protection teams isn't a temporary reaction to a bad ransomware year. It reflects a permanent change in how large enterprises think about resilient systems. Platform choice now carries security and continuity weight right alongside performance and cost, and organizations that treat it as a single decision rather than two separate ones tend to come out ahead when something actually goes wrong. 

Post Comment

Share your thoughts about this article.

Login To Post Comment

Be the first to post a comment!

Related Articles