/Award
July 19, 2026
.Award
STME wins 4 prestigious accolades to reinforce market leadership in the Middle East
On this page
Background
Across the GCC, enterprise backup infrastructure is at an inflection point. The tape-centric reference architectures deployed in the mid-2010s — designed for weekly full backups and 24-hour RTOs — are no longer compatible with the operating standards that regulators and boards now require.
SAMA's circular on business continuity, CBUAE's operational resilience guidance, and BMA's DR requirements all reference sub-four-hour RTOs for tier-one systems. For most banks in the region, this is not what their current backup estate was designed to achieve.
Tape estates designed for 24-hour RTOs are not compatible with modern regulatory standards across KSA, UAE, or Bahrain. The question is not whether to modernize — it is how to sequence it without disrupting live operations.
What changed
Three converging pressures are driving the rebuild cycle:
Architecture
The reference architecture STME is deploying for GCC banks in 2025–2026 follows a three-tier model:
primary → Veritas NetBackup → immutable disk (Tier 1)
secondary site → disk target (Tier 2)
air-gap → tape library (Tier 3 / ransomware isolation)
Each layer maps directly to a regulatory commitment. Tier 1 satisfies the intra-day recovery requirement. Tier 2 satisfies the DR site mandate. Tier 3 satisfies the long-term retention and ransomware isolation requirement.
What to do next
If your organization is running a backup estate that was designed before 2020, the starting point is an independent assessment against the current regulatory framework for your jurisdiction. STME conducts these assessments at no cost for existing infrastructure — typically a two-week engagement producing a gap analysis and architecture recommendation.
The assessment output is a document your internal team can own and present to the regulator. It is not a sales document.


