The recognition places ControlMonkey among the vendors defining how enterprises recover the cloud configuration required to operate – not just their data – after outages, ransomware, and unintended change.
ControlMonkey, the cyber resilience platform for Cloud Configuration Disaster Recovery, has been named a Sample Vendor for Cloud Application Infrastructure Recovery (CAIRS) in the Gartner® Hype Cycle™ for Backup and Data Protection Technologies, 2026. Published on 28 July 2026 by Gartner analyst Michael Hoeck (ID G00846536), the report identifies Cloud Application Infrastructure Recovery as an emerging technology for recovering the configuration behind modern cloud applications and lists ControlMonkey alongside Arpio, Cohesity, and Commvault as Sample Vendors for the category.

In addition, Gartner rates Cloud Application Infrastructure Recovery a high-benefit emerging technology and predicts that by 2030, 35% of organizations will use cloud application infrastructure recovery solutions to complement Infrastructure as Code (IaC)-based disaster recovery orchestration – up from less than 5% in 2026. Gartner describes the category as expanding disaster recovery for cloud applications by identifying the infrastructure services, dependencies, data, and configurations required to rebuild and recover them.
"Every security leader has invested in data backup, yet most still can’t prove they can recover the configuration their business runs on – the identity, network, and security settings that make recovered data usable. We believe being named a Sample Vendor for Cloud Application Infrastructure Recovery validates what we hear from CISOs every week: recovery has to extend beyond data to the cloud configuration required to operate."
The recovery gap CISOs can no longer ignore
The recognition puts a name to something security leaders have lived with but struggled to close: recovery plans that protect data and stop short of the configuration required to operate. Traditional backup restores data. It does not necessarily restore the identity, network, security, observability, and SaaS configuration that make that data usable. When an incident hits, files and databases can come back while applications stay unreachable, users stay locked out, and teams lose visibility exactly when they need it most. That gap sits quietly in most resilience programs until an incident forces it into view — and four pressures are now forcing it into view sooner.
Four pressures are making that gap urgent for the CISO:
- Ransomware targets recovery, not just data. Modern attacks disrupt identity providers, access policies, networking, and security rules. Restoring data alone does not bring the business back if the configuration around it is deleted, corrupted, or maliciously changed.
- Change now outpaces the people tracking it. Cloud and SaaS configuration shifts constantly across IaC, consoles, APIs, and AI-assisted workflows. As automation and AI agents gain permission to act across environments, the risk of unintended or unauthorized configuration change rises with it.
- Recovery readiness has become a board-level question. Many organizations still cannot prove which configurations are protected, what changed, or how quickly critical systems can return. The question has moved from “Do we have backups?” to “What is our real RTO and RPO for configuration?”
- Prevention can’t undo what an AI agent already did. AI agents now act with real permissions, altering configuration, identity, and infrastructure state faster than teams can investigate or contain. Guardrails can restrict those actions, but they don’t reverse an unintended or unauthorized change – the market problem behind Gartner’s new AI Agent Action Rollback technology, which recovery, not prevention, has to answer.
Closing the gap between data backup and business recovery with ControlMonkey
ControlMonkey makes critical cloud and SaaS configurations recoverable across cloud infrastructure, identity, network, observability, and third-party systems – the layer traditional data backup leaves exposed. The platform follows a simple workflow: discover, snapshot, recover, and review.
It starts read-only: ControlMonkey connects through native APIs to scan and review your cloud and SaaS configuration — across resources managed and unmanaged by IaC — with no production impact, and captures versioned snapshots as known-good recovery points. When configuration is deleted or changed, teams restore it to a previous known-good state, with dependency-aware recovery that reduces manual rebuilds during an incident. Cyber Resilience Governance then shows what is protected, what changed, what can be restored, and where recovery gaps remain — the evidence base for programs aligned with DORA, NIS2, SOC 2, ISO 27001, and NIST CSF 2.0.

That coverage extends to the systems enterprises actually run on, including identity providers such as Okta, Microsoft Entra ID, OneLogin, Ping Identity, and JumpCloud, cloud infrastructure on AWS, and services including Cloudflare and Datadog.
Validated in customer environments
The results are already showing up in production:
- Block – 80% less effort to recover its cloud infrastructure, and 100% of its multi-cloud infrastructure recoverable
- HoneyBook – 100% coverage of its critical cloud and SaaS configurations, including Cloudflare and Datadog
- Keyrock – 0% → 100% visibility into ClickOps and configuration drift
- Ubiq – 100% SOC 2 compliance acceptance rate

ControlMonkey has now backed up more than 5 million cloud and SaaS resources for enterprises, including Block, Comcast, Intel, and Veolia.
About ControlMonkey
ControlMonkey is the cyber resilience platform for Cloud Configuration Disaster Recovery. The platform helps enterprises discover, back up, compare, and recover critical cloud and SaaS configurations across infrastructure, identity, network, observability, and third-party systems. By turning configuration into a recoverable asset, ControlMonkey helps security and cloud teams close disaster recovery gaps left by traditional data backup, understand what changed, and restore known-good states when incidents occur. Founded by Aharon Twizer and Ori Yemini, both previously of Spot.io, ControlMonkey is headquartered in Tel Aviv, Israel, with operations in New York.
