IT Press Tour 69: HYCU
Going beyond SaaS data protection and ransomware with advanced AI control
This is a Press Release edited by StorageNewsletter.com on September 8, 2026 at 2:00 pmHYCU joined the recent 69th edition of The IT Press Tour held last week in Ljubljana, Slovenia and it was the opportunity to understand the company strategy beyond SaaS data and ransomware protection with a clear AI centric model.
We had the pleasure to hear Goran Garevski, CTO and co-founder, and Andy Fernandez, GM, AI & Cyber, HYCU, to cover this ambitious talk titled “Stepping into a New Era in Data Protection”.
HYCU positions itself as the #1 AI resilience company, backed by key investors Bain Capital, Acrew, Cisco Investments, Okta Ventures, and Atlassian, with strategic alliances including Dell Technologies, AWS, Microsoft, Google Cloud, Nutanix, Atlassian, Okta, and iManage. The company is trusted by thousands of organizations in over 78 countries, including Pfizer, Toshiba, Zebra, Honeywell, and US military branches. Recent recognition includes being named a Leader in IDC MarketScape for Worldwide SaaS Data Protection 2025–2026, a Visionary in the Gartner Magic Quadrant for Enterprise Backup and Recovery and a Challenger in the Coldago Map 2025 for Modern Data Protection.
Click to enlarge
Well known and recognized for its advanced SaaS data and ransomware protection, HYCU enters now into the era of agentic risk. Every past era of data protection was defined by its dominant failure mode, hardware failure, human error, then ransomware. HYCU argues a new, unnamed failure mode has emerged: AI agents. Unlike ransomware (outside the perimeter) or human error (inside it), agents represent a “third actor” already inside the perimeter, holding credentials and acting at machine speed, illustrated by an example where an AI agent deleted a company’s production database and its backups in 9 seconds (PocketOS, April 2026). Three destruction patterns are identified: Drift (an agent hallucinating system state, as with Gemini CLI in July 2025), Misinstruction (a hidden/injected prompt redirecting an agent toward destruction, as in an Amazon Q for VS Code incident shipped to 964,000+ installs), and Standing credentials (a single over-privileged API token causing irreversible damage). Native retention windows (93 days for SharePoint, 90 for Okta audit logs, 60 for Jira, 15 for Salesforce) were built for human mistakes, not bulk, machine-speed agent actions, reinforcing that when prevention fails, recovery is the only remaining control. A detailed walkthrough shows how Atlassian’s Rovo agent could take a reasonable instruction (“archive tickets older than 90 days”) and, acting with a service account’s permissions at machine speed, produce an irreversible bulk deletion that Atlassian itself treats as authenticated and authorized.
Click to enlarge
HYCU also shared an exclusive news for the event with its AI visibility key product iteration. The team highlights that agent visibility and usage have never been more challenging, contrasting the SaaS/tool sprawl of four years ago with today’s landscape saturated with AI agents across every system of record (GitHub, Salesforce, Microsoft 365, Workday, Atlassian, ServiceNow, etc.) via its “aiR Graph”. Even before AI, HYCU catalogued 30+ ways GitHub repository data can be permanently lost (accidental deletion/force-push, insider/offboarding risk, credential compromise, misconfigured automation, provider failures), none recoverable through the platform’s own native resilience. New AI-driven failure modes compound this (agents deleting branches, force-pushing after bad rebases, rewriting history across repos), with all such actions appearing “authenticated and authorized” to GitHub itself. Repositories are reframed as full systems of record encompassing runbooks, SDKs, AI prompts, and agent definitions, meaning losing a repo can mean losing the specification for how a company operates. In Europe specifically, an independent, immutable, testable copy of data is no longer optional but a regulatory requirement.
Click to enlarge
AI and associated AI agents changed everything now. HYCU champions “protection at the speed of agents”, a 30-minute RPO for critical repositories and hourly backups as the floor, built on aggressive cadence, full-surface coverage, immutability no token can reach, and quarterly-tested recovery. The company distinguishes recovery (restoring lost/corrupted data) from continuity (keeping data accessible even when primary systems are unreachable), noting that “every hour of waiting is lost work.” HYCU R-Serve is introduced as always-on, independent, self-serve access to critical data with a familiar iManage-like UI, launching for iManage with a Confluence integration as a “sneak peek.”
Click to enlarge
The team took advantage of the session to showcase HYCU aiR, an AI layer that lets customers “ask” their backups questions (e.g., “Do I have PHI in Confluence?”, “What has John Smith deleted in the last 7 days?”). Every SaaS backup already captures a complete, time-stamped record of every file touched, permission changed, record modified, and configuration adjusted, historical, complete, and independent data other tools lack. aiR functions as an “organizational knowledge graph” connecting protected apps, data, identities, activity, and time, enabling use cases across security operations (insider risk, blast radius mapping), AI governance (shadow AI discovery, agent flight recorder), compliance/privacy (PII/PHI discovery, GDPR/HIPAA/PCI reporting), and resilience/recovery (precision restore, ransomware signals).
To summarize, HYCU R-Cloud protects 100+ workloads across hybrid infrastructure, cloud, SaaS, and AI/ML (with depth per application spanning records, attachments, permissions, configurations, identity, and metadata), including new GA support for Azure DevOps (Boards, Repos, Pipelines, Test Plans, Artifacts), completing coverage of the full Git estate (GitHub, GitLab, Bitbucket, Azure DevOps). HYCU aiR is trusted by 4,800+ organizations in 78 countries, with compliance certifications including SOC 2, ISO 27001, FIPS 140-3, and DISA STIG.
Click to enlarge


















