| TL;DR: Law firms have spent years planning how to recover information when something goes wrong. But what happens when the information is still safe and lawyers simply cannot reach it? We spoke with HYCU about why access is becoming part of the backup conversation, and what changes when AI agents can act on the same information. |
For a long time, protecting company data meant keeping another copy somewhere safe. If files were lost, damaged, or locked by an attack, the backup could restore them.
But losing the files is not the only way work can stop. The files may still exist exactly as they should, while the software people normally use to reach them is temporarily unavailable.
Consider a law firm. A lawyer may open a matter in iManage, the cloud platform many firms use to manage documents and legal work, and spend much of the day working with information stored there. If that usual route becomes unavailable, the documents may still be perfectly safe. However, the lawyer cannot reach them.
That raises a different set of questions. Is there another way into the firm’s information? Who controls that route? And has anyone actually tested whether lawyers can use it when they need to?
Sathya Sankaran, Head of Cloud Products at data protection company HYCU, kept returning to those questions when we spoke with him after ILTACON 2026. He said that five years ago, customers mostly wanted to know whether their data could be backed up and recovered. Today, they are also asking whether they control an independent copy of their information and how quickly people can regain access to it.
Those questions also help explain how HYCU is approaching data resilience for law firms. Its work with iManage offers one example. In 2024, HYCU and iManage began working together to let firms keep a protected copy of their iManage content in storage they control. Just before ILTACON this year, HYCU introduced R-Serve, which gives authorized users a separate, read-only way to reach those protected documents when normal access is interrupted.
That gives the protected copy another role. Rather than becoming useful only when something needs to be restored, it can help people keep working while their usual route to the information is unavailable.
Why HYCU Is Treating Access as Part of Data Resilience
iManage already builds redundancy, security, and business continuity into its cloud service. When the companies announced their partnership in 2024, iManage described HYCU’s backup capability as additional data protection beyond what was already available in iManage Cloud.
HYCU lets firms keep a protected copy of their iManage data outside the primary environment, including in storage they control. R-Serve makes that copy usable during an interruption by giving authorized users another way to reach their documents.
Sankaran told SaaSTake that firms should know which systems are essential, where protected data resides, and who controls it. But he kept returning to a more practical test: can the firm prove that people will be able to get to the information when they need it?

Access is only one part of the problem. The software using that information is also gaining the ability to change it.
AI Agents Can Change Data, Not Just Read It
You see, AI agents are beginning to do more than search, summarize, or generate information. When given the necessary permissions, they can take actions inside the systems to which they are connected.
Microsoft security researchers recommend giving agents only the permissions they need, requiring additional approval for high-impact actions such as deletion, and testing recovery from unintended changes.
Companies are already running into the same problem elsewhere. As we found in our reporting on AI-agent identity, AI agents can accumulate access across company systems without fitting neatly into the identity and permission processes built for employees.
Sankaran connects that risk back to the backup. He told SaaSTake that an independent copy matters more as AI agents begin operating inside core systems, because “a single instruction can change or remove data in bulk before anyone reviews it.”
A system does not have to be breached for its information to be changed incorrectly. Software with legitimate permission to act can still take an unintended action.
Law firms are already working through related questions. In our reporting on Harbor, we found firms moving beyond whether to adopt AI and toward how it should operate inside everyday legal work.
Sankaran’s point adds a data-protection question to the same conversation: What happens when software is allowed to change the information a firm depends on, and the change itself is the mistake?
That gives the protected copy another job: preserving an earlier version when something changes unexpectedly.
The Backup Has to Work Before the Firm Needs It
Sankaran’s final point was about testing. Knowing where a protected copy sits is useful; knowing that people can actually work from it requires trying the process before an interruption happens.
That takes the problem beyond IT. Losing access to matter content can affect billable work and client commitments even when the underlying information remains safe.
However, R-Serve does not recreate iManage somewhere else. When activated, authorized users receive read-only access to documents they already have permission to see. They can download what they need, work locally, and return new or modified documents after normal service resumes. HYCU describes R-Serve as independent access to protected iManage content rather than a replacement for the primary platform.
R-Serve’s limited role also says something useful about what continuity looks like in practice. A firm does not necessarily need to recreate its entire technology environment to keep essential work moving.
And that brings the question back to where it started. A firm’s documents can be backed up, intact, and exactly where they are supposed to be, yet still be of little immediate use if the people who need them cannot get to them.
That is the shift Sankaran is pointing to when he talks about data resilience. The test is no longer only whether a firm can recover its information after something goes wrong. It is whether the firm still has control of that information, an independent route to it, and confidence that the route will work when the normal one does not.
For law firms, that may be the more useful definition of resilience: not simply knowing the data survived, but knowing the work can continue because the data is still within reach.






