Jon Brooks, Country Manager for the UKI, Nordics, and South Africa, Wasabi Technologies: “Ransomware is increasingly focused on disrupting access to data rather than simply stealing it”

Jon Brooks has built a career helping organisations keep pace in the face of innovation. Today, as Country Manager for UKI, Nordics and South Africa at Wasabi Technologies, he works directly with businesses to modernise their data storage – and strengthen their cyber resilience.

For Jon, one of the greatest changes in cybersecurity has been the fundamental shift in priorities. Take ransomware. Once it was a worry for a handful of giant organisations: now every business is a target.

And with ransomware increasingly targeting critical data, organisations must move beyond prevention alone. Instead, Jon explains, they must place a greater emphasis on cyber resilience, shifting conversations away from “Will we be attacked?” to “How quickly can we recover when an attack occurs?”

This shift has only been accelerated by AI, which Jon describes as “a powerful catalyst that can be used by both defenders and attackers”. As attackers are able to utilise AI to automate and scale their attacks, so too can defenders deploy AI tools to improve detection of these threats, monitoring them and minimise response time.

Jon highlights, however, that the power of AI tools are only as effective as the data it relies on, requiring “high-quality, accessible and well-governed data”.

When it comes to responding to these attackers, for Jon the first step is accepting that no organisation can fully prevent cyber attacks. Businesses need to operate under the assumption that they will happen, and implement resilient backups and failsafes to account for the inevitable threat. Or as Jon puts it, “No AI tool can compensate for poor cyber resilience”.

To understand the full context, and why Jon Brooks is worth listening to, we first asked Jon to introduce himself, and share how he ended up working in data and cybersecurity.

Please introduce yourself to our readers…

My name is Jon Brooks, and I’m the Country Manager for the UKI, Nordics, and South Africa regions at Wasabi Technologies. I have spent more than three decades working across the data storage, data management, data protection, and disaster recovery markets, holding various roles with several of the industry’s leading technology vendors. Throughout my career, I have helped organisations navigate the challenges of managing exponential data growth while balancing performance, resilience, security, and cost.

Today, my focus at Wasabi is helping customers and partners rethink cloud storage economics by delivering a simpler, more predictable alternative to traditional hyperscaler storage platforms, whilst supporting modern data protection, cyber resilience, AI, and digital transformation initiatives.


Related reading: Wasabi launches cloud storage emissions tracker


Ransomware is increasingly focused on disrupting access to data rather than simply stealing it. According to Wasabi’s latest Cloud Storage Index, almost half (44%) of organisations worldwide reported experiencing a cyberattack that resulted in loss of access to cloud data, highlighting how ransomware has evolved from a security issue into a business continuity issue. Downtime can have an immediate impact on revenue, operations and customer trust.

We’re also seeing organisations place greater emphasis on cyber resilience and recoverability. Businesses recognise that prevention alone is no longer enough. The focus is shifting towards ensuring data remains protected and recoverable, even if an attacker successfully gains access to part of the environment. Features such as object immutability, replication and additional recovery safeguards are becoming core components of a modern ransomware defence strategy.

What are the biggest cybersecurity challenges those in leadership roles are facing?

What I hear most frequently from customers and partners is concern around cyber resilience rather than simply cybersecurity. The question is no longer “Will we be attacked?” but “How quickly can we recover when an attack occurs?”

Ransomware, data breaches, insider threats, and operational disruptions continue to impact organisations of all sizes. At the same time, many organisations are struggling with the complexity of managing data across multiple environments, including on-premises infrastructure, public cloud platforms, SaaS applications, and edge locations.

Visibility and control of data is another significant challenge. As data volumes continue to grow exponentially, leaders need confidence that they know where their data resides, who has access to it, whether it is protected, and whether it can be recovered quickly if required. This becomes even more challenging when data is spread across multiple cloud providers and platforms.

Increasingly, we are also hearing concerns around “cloud concentration risk”. Many organisations have become heavily dependent on a small number of hyperscale cloud providers and are now actively exploring ways to improve resilience, reduce vendor lock-in, and gain greater predictability around both costs and data protection in a neutral cloud storage provider

Ultimately, leadership teams are looking for solutions that enable innovation without compromising resilience and cost. The organisations that succeed will be those that treat data as a strategic asset and build security, recoverability, and governance into their infrastructure from the outset, rather than attempting to bolt it on later.

What are some prevention strategies you believe every business should adopt?

Every organisation should assume that a cyber incident will occur at some point and build its strategy accordingly. No AI tool can compensate for poor cyber resilience. Organisations still need robust safeguards around their data, including immutability, backup and recovery capabilities, to ensure critical information remains available even if systems are compromised. In many ways, AI and cyber resilience are complementary disciplines built on the same foundation: trusted, protected data.

First, businesses should implement immutable backups so that critical data cannot be altered or deleted by attackers. Second, they should ensure copies of data are replicated and recoverable from separate environments. Third, organisations should regularly test their recovery processes to verify they can restore operations quickly following an incident.

Beyond technology, organisations should adopt a layered security approach that combines access controls, user education, monitoring and data protection. The most resilient organisations are focused on limiting their impact and accelerating recovery when they occur.

Wasabi’s research shows that object lock and immutability are now widely adopted security measures, reflecting the growing recognition that recoverability is a fundamental component of cybersecurity.

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good in cybersecurity?

Like many technologies, AI itself is not inherently good or bad; it’s a powerful catalyst that can be used by both defenders and attackers. Generative AI lowers the barrier to entry for attackers, enabling malicious actors to scale certain activities far more efficiently than before like create more convincing phishing campaigns and automate social engineering attacks. 

On the flip side, AI has significant potential to improve cybersecurity teams’ operations by helping organisations identify anomalies faster, automate elements of threat detection, and accelerate incident response. However, successful AI initiatives depend on having high-quality, accessible and well-governed data, which is why organisations are investing so heavily in data infrastructure and storage as they develop AI capabilities. 

Ultimately, AI will benefit both attackers and defenders. The key challenge for organisations is ensuring they have the right foundations in place so AI can improve resilience rather than introduce new risks.  The organisations that get the most value from AI will be those that already have strong data governance, cyber resilience, and data protection foundations in place.

Which cybersecurity best practices are being adopted with the most success by companies?

The organisations achieving the strongest cyber resilience outcomes tend to recognise data infrastructure as a crucial pillar of cyber resilience. Wasabi’s research found that 63% of organisations now use object lock as part of their security strategy. We’re also seeing increased adoption of immutable storage, replication and layered protection mechanisms that help safeguard data even if credentials are compromised.

The common thread among successful organisations is that they build resilience directly into the storage layer. By combining preventative controls with strong recovery capabilities, businesses can reduce the likelihood that a single incident turns into a prolonged outage or major business disruption.

What’s something that has drastically changed about cybersecurity since you first got started in the field?

One of the most significant changes has been the shift from perimeter-based security to resilience-based security.

Historically, many organisations focused primarily on keeping attackers out. Today, most security leaders recognise that breaches are a matter of when, not if. As a result, the conversation has expanded beyond prevention to include recovery, business continuity and operational resilience.

At the same time, the volume of data organisations manage has grown dramatically, while cloud adoption and AI initiatives have increased both the value of that data and the consequences of losing access to it. Cybersecurity is no longer solely an IT concern; it’s a business-wide issue that directly affects revenue, reputation and competitiveness.

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.