Rubrik Launches Iceberg Table Protection for AWS, Addressing Ransomware and Data Loss Risks
Rubrik has unveiled a new backup and recovery solution for Apache Iceberg tables on AWS that preserves metadata alongside data, filling a gap left by native tools that only capture snapshots as pointers.

Data protection and cloud management vendor Rubrik Inc. has introduced Rubrik Apache Iceberg Protection, designed to provide backup and recovery functionality for Apache Iceberg tables hosted on Amazon Web Services Inc. The offering targets what Rubrik identifies as a critical vulnerability in existing native tooling.
The core problem stems from how Iceberg snapshots function. Rather than creating full copies of data, snapshots operate as metadata pointers. When a table is deleted, compromised by ransomware, or accidentally overwritten by a malfunctioning artificial intelligence agent, the entire snapshot history disappears along with it. Simply restoring the underlying files does not reconstruct the catalog entry, forcing data teams to manually rebuild table metadata before queries can execute again.
Rubrik's solution takes a different approach by capturing metadata in addition to the underlying data files. When recovery occurs, the table gets re-registered in the catalog, allowing analysts to immediately query the restored table through Amazon Athena, Apache Spark or Trino. Without this metadata preservation, teams are stuck with disconnected Parquet files requiring extensive manual remediation.
Coverage and Storage Options
The protection capability encompasses Iceberg tables stored in the AWS Glue Data Catalog as well as Amazon Simple Storage Service or S3 tables. All backups remain immutable regardless of their destination, with customers determining whether copies reside in their own AWS account or within Rubrik's air-gapped Cloud Vault. Rubrik asserts this is the only Iceberg-aware protection product offering the in-account backup option.
Following an initial complete backup, the system only captures the most recent compacted snapshots, a design choice that maintains reasonable backup windows even as tables scale to petabyte sizes. Customers control which S3 storage class receives backup data, enabling infrequently accessed backups to avoid expensive premium storage tiers.
On-Demand Backups and Isolated Recovery
Teams can trigger on-demand backups before executing risky operations like schema modifications or large-scale batch writes. Restored data can be placed on an isolated Iceberg branch, allowing teams to validate both data and schema before returning the table to production use.
"Data lakes have grown beyond analytics and AI to now run the entire business, and Apache Iceberg is one of the most critical systems built on them," stated Anneka Gupta, chief product officer at Rubrik. Gupta noted that while the company has historically protected the object storage layer, this capability extends coverage to the lakehouse itself, with the same governance policies applying across databases, pipelines and code.
Rubrik Apache Iceberg Protection will reach general availability later this month.
Expanding Cloud-Native Capabilities
This launch continues Rubrik's broader effort to expand platform coverage into cloud-native environments throughout the year. The company introduced Cloud SQL protection and governance for Gemini agents during Google Cloud Next in April. Additionally, Agent Cloud debuted last October, introducing a control layer designed for enterprise AI agents.


