Global component shortages are increasing pressure on storage supply and pricing. But postponing backup and recovery investment to protect short-term budgets may expose organisations to a much larger operational and financial risk.
Technology leaders are facing an uncomfortable combination of pressures.
Data volumes continue to grow. Ransomware operators are actively targeting recovery infrastructure. Organisations are expected to retain more information for longer, while their boards want greater resilience and predictable costs.
Now, the underlying components needed to deliver that storage are becoming more constrained and expensive.
AI demand is reshaping the storage market
The rapid expansion of artificial intelligence infrastructure is consuming vast quantities of memory and enterprise storage capacity.
According to TrendForce, major NAND flash manufacturers are expected to add virtually no new production capacity during 2026. Strong AI-related demand is placing sustained pressure on supply, with production resources increasingly concentrated on high-value server and enterprise storage applications. Shortages are consequently expected to continue throughout the year.
The consequences are being felt across the wider technology market.
Manufacturers and infrastructure providers are competing for available components. Lead times can become harder to predict, and higher input costs eventually work their way into the price customers pay for appliances, servers and storage platforms.
For organisations planning a backup refresh, this creates a temptation to wait: delay the project, extend the existing infrastructure for another year and hope pricing settles.
That decision needs to be weighed against what is actually being deferred.
Old backup infrastructure is not a neutral risk
Backup systems are no longer passive repositories sitting quietly at the edge of the network.
They are a primary target.
Veeam’s analysis of ransomware trends found that 89% of organisations had experienced attackers targeting their backup repositories. The logic is simple: if an attacker can encrypt or delete both production data and the backups needed to recover it, the organisation loses its most credible alternative to paying a ransom.
Deferring investment can therefore prolong several risks at once.
Legacy infrastructure may be approaching the end of its supported life. Capacity limitations can force organisations to reduce retention periods. Recovery performance may no longer meet the needs of the business. Security configurations that were considered acceptable several years ago may now depend too heavily on administrator credentials or changeable policies.
Meanwhile, the amount of data requiring protection continues to rise.
The result is a growing gap between the recovery capability the organisation believes it has and what it could actually deliver during an incident.
Not all immutability is equal
Immutability has become an essential component of modern ransomware resilience, but the term can describe very different architectures.
Some platforms enforce immutability through policies or configuration settings that privileged administrators can alter. If an attacker compromises those administrative credentials, the same privileges may be used to weaken or remove the protection.
Object First takes a different approach through what it describes as Absolute Immutability.
Absolute Immutability removes access to destructive actions. Backup data cannot be modified or deleted by a storage administrator, a backup administrator or an attacker who has compromised privileged credentials. The protection is enforced across the storage stack rather than relying only on an adjustable policy.
For Veeam customers, Object First’s Ootbi appliances provide purpose-built, on-premises backup storage designed around this principle.
The objective is uncomplicated: ensure that when production systems are compromised, the organisation still has a clean and authoritative recovery point that the attacker has been unable to destroy.
Removing the CapEx barrier
The strongest backup architecture offers limited value if an organisation cannot fund it.
Object First therefore provides Ootbi through two acquisition options: a traditional capital purchase or a pay-per-use Consumption model.
Both models include the software, operating system and updates, alongside technical support and on-site service. The Consumption option removes the requirement for a large upfront investment and provides predictable monthly billing without the customer having to manage future hardware refreshes.
This creates a practical alternative for organisations whose recovery environment needs attention but whose capital budgets are constrained.
Rather than extending ageing infrastructure or reducing the scope of the project, customers can align expenditure more closely with the capacity they require and the way they prefer to consume technology.
Resilience has its own cost curve
There may never be a perfect time to invest in backup.
Component pricing changes. Data volumes grow. Budgets compete. Other transformation projects appear more urgent.
But the value of backup infrastructure is not measured on the day it is purchased. It is measured on the day the organisation needs to recover.
Through Hammer Cybersecurity, partners can help customers assess their existing Veeam backup storage, identify capacity and recovery risks, and compare the CapEx and Consumption routes available from Object First.
In a constrained market, delaying unnecessary expenditure may be sensible.
Delaying the infrastructure your organisation will depend on after an attack is a very different decision.