

Cyber Resilience
How Architecture Determines Cyber Resilience at Enterprise Scale
Key takeaways: Cyber resilience features only perform as well as the architecture beneath them. As environments scale, design choices around deduplication, memory efficiency and how data is distributed determine whether you recover in hours or days.
In the previous post, we examined how efficiency-driven architectures deliver more predictable outcomes than brute-force scaling models. The natural next question is: what drives those differences in the first place? The answer lies in architecture.
Ask most vendors whether their platform supports immutability, anomaly detection, or recovery orchestration, and the answer will almost always be yes. The feature lists have converged. But none of that tells you what happens when your environment is under real pressure — running a recovery at 2am across petabytes of data, or pushing detection across a dataset that has tripled since deployment. That’s where architecture stops being a technical footnote and starts determining whether you recover in hours or days.

The question behind the feature
Take recovery time. Scale-out platforms like Rubrik and Cohesity distribute data across multiple nodes — that’s the core of how they scale. Data Domain takes a different approach: deduplication happens inline at ingestion, and data is managed within a single, unified system. Both architectures rehydrate deduplicated data on restore — that’s unavoidable. But on a distributed platform, that process has to be coordinated across nodes, introducing network overhead and failure points at exactly the moment you can least afford them — which is also, increasingly, the moment threat actors choose to layer in denial of service attacks specifically to degrade your ability to detect and respond. On Data Domain, rehydration happens locally against a compact metadata index, with none of that cross-cluster dependency.
The same logic applies to detection. An architecture that consumes significant memory and compute just to manage data across distributed nodes is competing with itself for resources — and that contention doesn’t ease up when you need detection most. In a ransomware investigation, the last thing you want is an analytics engine fighting for headroom against the infrastructure it runs on.
What scale-out architectures trade away
The scale-out pitch is compelling — add nodes, add capacity, add performance — and for many workloads it delivers, at least up to a point. The problem isn’t that scale-out can’t scale. It’s what that scaling requires. Every node added to a Rubrik or Cohesity cluster brings its own compute, memory, networking footprint and management surface — infrastructure that has to be procured, patched, and monitored. The blast radius of any problem expands proportionally.
Data Domain was designed around a fundamentally different premise. The DDOS operating environment manages deduplication in-memory with exceptional efficiency, so the system does more with less hardware. As data volumes grow, storage capacity grows — but the infrastructure footprint doesn’t have to grow at the same rate. You’re not adding more attack surface, more things to recover or more operational complexity to manage during an incident.

Why this matters more now
AI workloads are driving intense demand for DRAM and NAND flash — the same components scale-out platforms require in increasing quantities with every node added. Procurement cycles are already lengthening. Each additional node isn’t just an operational consideration; it’s a supply chain dependency. Architectures built around memory efficiency are structurally less exposed to that pressure. Data Domain’s approach to in-memory deduplication isn’t just an efficiency story — right now, it’s also a resilience story.
The questions that reveal architectural reality
Most evaluations start with features. But the revealing questions sit one layer deeper: How does recovery time change as the protected dataset grows — not in a lab, but over three years in production? Does the architecture have enough headroom to run detection effectively when recovery is also underway? What happens to operational complexity at twice the scale?
The platforms that have held up over time — including architectures like Data Domain, protecting enterprise environments for more than two decades — have done so because efficiency was built in from the ground up. That’s an observable pattern in how these systems behave when it actually matters.
In the next post, we’ll look at how supply chain dynamics are shifting the calculus for infrastructure-heavy scaling models — and what that means for long-term cyber resilience strategies.
Go deeper
Omdia validated these architectural advantages across real-world deployments — finding TCO reductions of up to 61% and typical data reduction rates of 75:1. Read the Omdia Economic Validation.
