New Zero Trust Data Resilience Model Introduced by IT Security and Data Protection Experts
The leader in Data Protection and Ransomware Recovery, Veeam Software has introduced Zero Trust Data Resilience (ZTDR), which is a model that is meant to help organizations reduce the risk of growing data security threats and improve their overall resilience. The ZTDR applies Zero Trust principles to backup and recovery as an extension to the

New Zero Trust Data Resilience Model Introduced by IT Security and Data Protection Experts

The leader in Data Protection and Ransomware Recovery, Veeam Software has introduced Zero Trust Data Resilience (ZTDR), which is a model that is meant to help organizations reduce the risk of growing data security threats and improve their overall resilience.
The ZTDR applies Zero Trust principles to backup and recovery as an extension to the Cybersecurity & Infrastructure Security Agency (CISA) Zero Trust Maturity Model, and it was developed in collaboration with Zero Trust expert Jason Garbis of Numberline Security.
Essential to ZTDR is the separation of backup management systems and their storage tiers into distinct resilience zones to reduce the attack surface and limit the potential blast radius from breaches; and immutable backup storage, to ensure that data cannot be modified even in the event of a ransomware attack.
Modern, effective security is based on Zero Trust, replacing the increasingly ineffective perimeter-based security approach. Yet most Zero Trust frameworks do not include the security of data backup and recovery systems, despite the fact backup data is often the primary target of malicious actors in both ransomware and data exfiltration attacks. The Veeam Data Protection Trends Report 2023 found 93% of ransomware attacks are targeting backup repositories.
“Backup infrastructure by its nature has a large attack surface, because it must have read and write access to production, spanning virtually all enterprise applications and data sources, both on-premises and in the cloud,” said Jason Garbis, Founder at Numberline Security. “To reduce that risk, Numberline and Veeam are proposing practical Zero Trust Data Resilience tools, including core principles, an architecture, and a maturity model. Our goal is to help organizations fill a gap in their security strategy by extending Zero Trust to backup and recovery to achieve greater cyber resilience.”
Within the CISA Zero Trust Maturity Model, “Data” is one of five pillars, under which it identifies five key functions: Data Inventory Management, Data Categorization, Data Availability, Data Access and Data Encryption. To extend this model to the critical function of data backup and recovery, the ZTDR principles are:
● Least Privilege Access
● Immutability
● System Resilience
● Proactive Validation
● Operational Simplicity
To help organizations begin their journey to implement these principles, Numberline has developed a detailed ZTDR Maturity Model, as well as a ZTDR Reference Architecture which includes these key attributes for improved data resilience:
● Segmentation, for clear separation of Backup Software and Backup Storage layers to create distinct resilience zones that minimize the attack surface and reduce the blast radius when an attack occurs.
● Backup storage immutability, ensuring data cannot be modified or deleted.
“The most recent Veeam study reveals that 75% of ransomware attacks directed at backups achieve success,” stated Danny Allan, Chief Technology Officer at Veeam. “Ensuring data immutability and adopting best practices such as Zero Trust Data Resilience (ZDTR) are critical to sustaining business operations. Through the ZTDR Maturity Model, any organization can map out its journey toward enhanced data security and reduced downtime. While Veeam has consistently embraced this architectural approach, we are collaborating with storage partners to implement a leading-edge zero-trust model.”
“To confront the escalating threat of cyberattacks, particularly ransomware, there’s an urgent need to consolidate and reinforce the effectiveness of IT and security by leveraging frameworks like Zero Trust,” remarked Christophe Bertrand, Practice Director at ESG. “Our latest research on the state of the ransomware market indicates that 86% of respondents view Zero Trust as a pivotal strategy for ransomware protection. Zero Trust Data Resilience plays a foundational role in addressing these needs, offering a more robust security posture through swifter and safer recovery.”
The full Zero Trust Data Resilience model, core principles, recommended architecture and maturity model are available in a free white paper here: https://go.veeam.com/zero-trust-data-resilience.



