In our last disaster recovery (DR) blog, we argued that redundancy is not the same as recovery, and that most strategies fail quietly because they are not tested properly under real conditions. We closed with a specific idea, namely that tools exist to test a full recovery plan during business hours, without a weekend outage or a crossed-fingers failover. This latest blog breaks down what that looks like in practice, and why the job it does has just gotten bigger.
For years, DR has meant planning for events such as hardware failures, ransomware, natural disasters and human error. Most organisations have a recovery plan of some kind, but fewer have tested it recently in a way that shows how it would perform under real conditions.
At the same time, the environments businesses are recovering have become more complex. Cloud platforms, hybrid infrastructure, growing compliance obligations and new technologies are creating more ways for systems and data to be disrupted. Recovery is now being asked to do more than it was designed for even a few years ago.
That broader role is where HPE Zerto fits. Its continuous replication capabilities support faster recovery, but they also make it possible to test recovery processes regularly without disrupting production. As we’ll explore, that same approach is increasingly relevant across cyber resilience, compliance, infrastructure modernisation projects and emerging AI-related risks.
Most IT teams know, in theory, what their DR plan is supposed to do, but far fewer have run it end-to-end under real-world conditions recently.
When a failure occurs, whether it’s ransomware, a misconfiguration, or an AI agent doing something it shouldn’t, the DR plan is often tested for the first time under the worst possible conditions. The Australian Signals Directorate (ASD) explicitly calls this out in the Essential Eight framework, stating that restoring from backups should be tested at least annually as part of regular DR exercises and shouldn’t be left until after the first major security incident.
With the ASD’s Australian Cyber Security Centre responding to more than 1,200 cyber security incidents in the 2024 to 2025 financial year1, an 11 per cent increase on the year before, recovery is something a meaningful number of Australian organisations will have to deal with directly.
However, properly testing a DR plan usually means taking systems offline, scheduling it for a weekend, and hoping nothing breaks in a way that affects production. It’s disruptive to test the thing that exists to prevent disruption, so it slips down the list, which in itself creates a specific kind of risk.
This is the specific problem Zerto, now part of Hewlett Packard Enterprise (HPE), is built to solve. Rather than relying on periodic backups or snapshots taken every few hours, Zerto continuously replicates changes to a recovery site, whether on-premises or in the cloud, as they happen. That continuous protection is what makes non-disruptive testing possible in the first place, and what makes everything else in this piece possible.
When you run a test, Zerto takes your entire replicated environment and mounts it as a live, rewritable copy in an isolated test environment, while production continues to run untouched. Inside that isolated copy, you can log in, check that applications start correctly, confirm users can access what they need and validate individual servers, server groups, application groups, or your entire environment. When you’re done, you simply blow away the test environment without any impact on production. This is what changes the economics of testing.
A process that used to require an out-of-hours outage window becomes something a team can run regularly through the working day as part of normal operations. It’s no longer a rare and dreaded (or avoided) event.
For businesses with formal compliance obligations, regulators and auditors increasingly expect proof that a DR plan works. Since 30 May 2025, Australian businesses with an annual turnover of $3 million or more, along with entities responsible for critical infrastructure, have been required to report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours. That regulatory shift has pushed DR higher on the priority list for many businesses that previously treated it as an IT-only concern.
Zerto’s testing process generates a compliance report as a byproduct of the test itself. Each test produces a record showing which workloads started successfully, which users could log in, and whether the recovery environment behaved as expected. For a compliance or audit function, that’s the evidence they need; produced automatically and without a separate exercise to document it.
Continuous replication has a second, less obvious benefit. Because Zerto is watching data changes in real time, it can detect the pattern of mass file encryption that ransomware produces while it’s happening, rather than after the fact. When it identifies that pattern, it flags it and creates a checkpoint from just before the encryption began, giving a business a clean recovery point immediately rather than forcing teams to work backwards through backups looking for one that predates the attack.
HPE has published a case study detailing this in practice. TenCate, a global materials manufacturer, used HPE Zerto Software to reduce data loss from 12 hours to 10 seconds, and recovery time from two weeks to under 10 minutes following a ransomware attack. While that’s a single customer’s documented outcome rather than a guaranteed result for every environment, it demonstrates the difference between recovery measured in weeks and recovery measured in minutes.
Ransomware is no longer the only scenario where large-scale unintended changes can occur. For years, DR has centred on events such as hardware failures, cyber attacks and human error. Organisations are now beginning to introduce AI into operational workflows, creating another potential source of data corruption, accidental changes or process failures.
As AI becomes more closely embedded within business processes, questions around recovery become just as important as questions around governance and control. If an application, process or AI-driven workflow makes changes it shouldn’t, organisations still need a way to identify when the problem started and restore a known-good state.
At HPE Discover 2026, HPE announced new capabilities for Zerto designed to extend this approach into environments using AI agents. Using the same continuous data protection principles already applied to ransomware recovery, the planned capability is intended to identify unauthorised actions and enable organisations to roll systems back to a point before the issue occurred. HPE has stated this capability will be available from the fourth quarter of 2026, making it a future capability rather than one available today.
The broader point is that the recovery challenge remains largely the same, regardless of what caused the problem. Whether the trigger is ransomware, human error or a future AI-related incident, organisations need confidence that they can recover quickly, return to a clean state and continue operating. The infrastructure put in place today to improve recovery from cyber incidents is increasingly the same infrastructure that will help manage emerging operational risks in the future.
There’s a second, more immediate reason this is important right now. Businesses are being pushed to make platform decisions whether they’re ready or not. Microsoft’s retirement of the classic experience for protecting VMware and physical machines in Azure Site Recovery on 30 March 2026 means organisations using it have needed to migrate to the modernised version or an alternative approach.
HPE is currently offering a free first year of licensing for HPE Morpheus VM Essentials, plus HPE Zerto migration licences for USD$1, to help offset the cost of running two platforms during a VMware migration.
Because Zerto’s replication engine is built for the continuous, orchestrated movement of workloads, it can be used the same way for a one-off migration as for ongoing DR, and HPE has built it into its infrastructure modernisation strategy. In a May 2026 update, HPE brought new Zerto capabilities together with its Private Cloud and storage portfolio to give customers a single path off VMware and onto HPE’s VME. Zerto now supports live workload migration from VMware environments to HPE’s own virtualisation platform.
This is key for how a migration plays out in practice. A business moving from VMware to HPE’s VME platform, or shifting workloads between on-premises infrastructure and the cloud can use Zerto to replicate the environment, bring it up in an isolated test copy first, confirm everything works and then cut over, all while remaining continuously protected rather than exposed during the transition. HPE has described this as letting customers modernise in stages rather than all at once, maintaining protection and recoverability throughout rather than treating migration and DR as two separate projects with separate tools. For a business already using Zerto for DR, that means the same platform is doing double duty rather than a second, disconnected migration exercise.
The best part is that none of this depends on a business standardising on a single hardware vendor or cloud provider. Zerto works across different storage platforms and hypervisors, cloud to cloud, on-premises to cloud and cloud to on-premises. This makes it easier for businesses running a mixed environment, migrating between platforms, or simply not wanting their DR tied to any vendor or platform.
The most common objection to any of this is cost, as continuous replication generally means running a second environment alongside production, and it usually isn’t a small one. In many environments, the secondary infrastructure used for recovery can also support production workloads, changing the economics of the traditional DR model. Either way, the businesses that push back hardest on that cost are often the ones who haven’t calculated what an hour, a day, or a week of downtime costs them. For a business where an outage costs six figures a day, the maths tends to answer itself.
What most of us are learning is that the hardest step in AI is moving from a promising pilot to something that runs reliA recovery plan only matters if it works when you need it. That means testing it regularly and making recovery part of normal operations rather than a once-a-year exercise.
Whether the immediate concern is ransomware, compliance, migration or something else entirely, the underlying question remains the same. When something goes wrong, is your recovery plan something you’ve run, or something you’re hoping will work?
As one of very few select HPE Triple Platinum Plus partners in the Asia-Pacific region, Data#3 designs and manages complex IT infrastructure solutions using HPE’s enterprise computing, storage and networking portfolios.
If you want to talk through where your current approach stands, contact us now to have a conversation with one of our infrastructure specialists.
Speak to our team of our Specialists today
Information provided within this form will be handled in accordance with our privacy statement.