Article

Backed up is not the same as understood: What Veeam’s acquisition of Securiti AI means for your data

Veeam has completed its acquisition of Securiti AI, bringing data security posture management, privacy and AI governance into the same platform family as backup and recovery. Here is a measured look at what that actually means for mid-market IT teams – and how it fits alongside Veeam Backup & Replication, Cloud Connect and Covenco’s data protection platform.

Is your data secure just because it is backed up?

For most of the last two decades, the honest answer to that question was ‘close enough’. If you had a verified, restorable copy of your data – ideally immutable, ideally off-site – you had done the responsible thing.

That answer has aged. Three things have changed the picture:

  1. Shadow data.
    Most organisations now hold sensitive information in places nobody formally tracks – SaaS exports, forgotten file shares, test databases, personal OneDrive folders. You cannot protect, govern or lawfully process data you do not know exists.
  2. Compliance obligations.
    UK GDPR, sector regulation and cyber insurance requirements all assume you can say, with confidence, what personal or sensitive data you hold and where. A backup catalogue is not that answer.
  3. AI adoption.
    Teams across the business are feeding internal data into AI tools, sanctioned or otherwise. The question is no longer whether that happens, but whether it happens with any guardrails.

The uncomfortable conclusion – a backup is a copy of your data, including every risk buried inside it. Recovery capability and data understanding are two different disciplines – and until recently, they lived in two different toolsets.

What has actually happened?

In December 2025, Veeam completed its $1.725 billion acquisition of Securiti AI, a recognised leader in data security posture management (DSPM), privacy, governance and AI trust. Securiti’s founder and CEO, Rehan Jalil, has joined Veeam as President of Security and AI, along with around 600 specialists.

If DSPM is not part of your daily vocabulary, the plain-English version is this: Securiti’s platform discovers data across cloud and on-premise environments, classifies it (what is personal, what is regulated, what is commercially sensitive), maps who has access to it, and applies policy – including controls on what can flow into AI models. Veeam’s stated intent is a unified platform to see, secure, govern and recover data in one place, spanning both production data and the secondary copies held in backup.

It is worth being candid: this is a recent acquisition, and the deep product integration will arrive progressively rather than overnight. But the direction of travel is clear, and it addresses genuine gaps that we see in mid-market environments every week.

Three problems this combination addresses:

  1. Visibility (Eliminating shadow data) 
    Discovery and classification across silos means you can finally answer the audit question that catches most organisations out: ‘where is our sensitive data?’ For IT managers, this shifts data protection from an infrastructure conversation to an evidence-based one.
  2. Safer AI adoption.
    Securiti brings controls such as LLM firewalls and runtime guardrails – mechanisms that inspect and police what data reaches AI models and what those models return. For organisations under pressure to ‘do something with AI’ without a data governance function to lean on, this matters. It allows adoption with defined boundaries rather than blanket prohibition or unmanaged risk.
  3. Recovery with context.
    Cleanroom and staged recoveries already let you scan restore points for malware before reintroducing them to production. Adding data intelligence extends that: a restored dataset can be checked not only for threats, but for compliance issues – for example, personal data that should have been erased under a retention policy but persists in older restore points. Recovery stops being purely a technical exercise and becomes a governed one.

How this fits your existing Covenco environment

If you are a Covenco customer, the practical question is how this lands against what you already run:

  • Veeam Backup & Replication.
    Your VBR environment remains the recovery engine. What changes over time is the intelligence layered around it – knowing what is inside your restore points, not just that they exist and are verified.
  • Veeam Cloud Connect.
    Off-site copies held on Covenco’s Cloud Connect infrastructure continue to provide the air gap and immutability that underpin ransomware resilience. Data classification strengthens the case for what you replicate, for how long, and under which retention rules.
  • Covenco’s managed platform (BaaS and DRaaS).
    As Veeam releases integrated capabilities, our role is to assess them honestly, test them against real mid-market environments, and advise on where they add value for your estate – and where they do not. Not every organisation needs every capability on day one.

A measured view

We would encourage a degree of calm before moving to action Security AI. This acquisition does not make your current backup strategy obsolete, and it does not require immediate action. What it does signal is that the industry’s definition of resilience is widening – from ‘can we get it back?’ to ‘do we understand it, can we govern it, and can we trust it enough to build on?’

For most mid-market IT teams, the sensible sequence is:

  • Keep your recovery fundamentals solid – tested restores, immutable copies, documented RTOs and RPOs.
  • Start an honest conversation about data visibility. Even a rough map of where sensitive data lives puts you ahead of most peers.
  • Get ahead of AI usage in your organisation before policy is written for you by an incident.

Covenco has worked with Veeam environments for long enough to distinguish genuine capability from launch-week enthusiasm. As the Securiti integration matures through 2026, we will keep our customers informed about what is real, what is roadmap, and what is right for organisations of your size.

If you would like to discuss how data discovery and governance could fit alongside your existing Veeam and Covenco setup, talk to our data management team.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.