Skip to content

Die wichtigsten Erkenntnisse

  • Bei der „Minimum Viable Sovereignty“ (MVS) geht es darum, für die jeweiligen Workloads das richtige Maß an Kontrolle anzuwenden.
  • Die Gleichbehandlung aller Workloads kann zu unnötiger Komplexität und Kosten oder zu unzureichendem Schutz führen.
  • Unternehmen lassen sich in der Regel in drei Souveränitätsprofile einteilen: „True Sovereign“, „Regulated Enterprise“ und „Hybrid Multi-Cloud“.
  • Eine einheitliche Governance über gemischte Umgebungen hinweg ist eine der größten betrieblichen Herausforderungen.

There is a version of the digital sovereignty conversation that leads organizations somewhere expensive, operationally burdensome, and – if they’re being honest – further than their actual obligations require. Maximum sovereignty sounds responsible. In practice, it’s often a miscalibration.

There is an equally common version that leads somewhere dangerously thin – controls that satisfy a checklist but wouldn’t survive an audit, an incident, or a regulator who has stopped accepting documented intent as proof of demonstrated control.

The organizations that get sovereignty right tend to do something more rigorous and more practical than either extreme: They ask what they actually owe, to whom, and for what. Then they build to that standard – no more, no less.

This is the discipline of MVS, introduced in the „„Digital Sovereignty Readiness Report““  and developed in full here.

MVS isn’t a shortcut. It’s a recognition that the goal is the right level of control, applied consistently, across every workload that requires it.

Nicht alle Workloads sind gleich

The starting point for an MVS approach is workload classification – and most organizations skip it entirely.

A trading system processing regulated financial data carries fundamentally different sovereignty obligations than an internal HR collaboration tool. A database holding personal data of EU citizens is subject to a different legal and regulatory regime than a development environment running anonymized test data.

Treating all of these identically – either by applying maximum sovereign controls across the board or by assuming a single deployment model covers everything – is how organizations end up either over-engineered or under-protected.

The right question before any deployment decision: What does this workload require across each of the four sovereignty pillars? The Readiness Report includes a self-assessment structured around exactly that question.

The Three Profiles – and What They Actually Need

Regulierte Unternehmen lassen sich in drei erkennbare Profile einteilen, die jeweils unterschiedliche Hauptantriebsfaktoren und Investitionsprioritäten aufweisen.

  • The True Sovereign. Government agencies, defense contractors, and critical national infrastructure operators. For these organizations, sovereignty is not a compliance requirement – it is an operational mandate. Maximum control over every dimension of the technology stack is often legally required, and the cost tradeoffs are accepted because the alternative is not.
  • The Regulated Organization. Financial services firms, healthcare organizations, energy companies. These organizations face binding requirements from DORA, NIS2, GDPR, and sector-specific frameworks. Compliance obligations may also map to EU certification schemes – including EUCS, EUCC, BSI C5, and SecNumCloud – depending on sector and deployment context.

on-negotiable in certain areas – particularly around data residency, operational access controls, and recovery within jurisdictional boundaries. But not every workload carries the same obligation.

  • The Hybrid Multi-Cloud Organization. Organizations with existing hyperscaler investments facing increasing sovereignty pressure from customers, regulators, or procurement requirements. Their challenge is not wholesale migration – it’s layering sovereign controls onto a mixed estate and maintaining consistent governance across it.

Die Kosten einer falschen Kalibrierung

Over-engineering sovereignty creates its own operational risks. Organizations that apply maximum sovereign controls to workloads that don’t require them absorb cost and complexity that serves no regulatory or business purpose.

Under-engineering is the more common failure mode, and the more dangerous one. It typically doesn’t show up until the audit arrives – or, more seriously, until an incident occurs and recovery becomes a legally constrained problem. (That failure mode is the subject of the vierten Beitrags dieser Reihe) umfasst.

Ein praktischer Ausgangspunkt

Ein MVS-Ansatz umfasst drei Schritte:

  1. Classify workloads by their actual sovereignty requirements across each pillar – don’t start with deployment models.
  2. Ordnen Sie jede Workload-Klasse der Bereitstellungsstufe zu, die diese Anforderungen erfüllt, und zwar über das gesamte Spektrum hinweg – von Regionen öffentlicher Hyperscaler über souveräne Public Clouds bis hin zu lokal verwalteten Umgebungen.
  3. Govern the resulting mixed estate consistently – controls, audit evidence, and recovery capabilities must be demonstrable across the full environment, not just the most-sovereign tier.

The third step is where most programs struggle. Maintaining consistent sovereignty controls across a mixed estate is an operational governance challenge – and specifically the domain of Operational Sovereignty – dem Thema des dritten Beitrags dieser Reihe, der Säule, die in den meisten Strategien erst nachträglich berücksichtigt wird.

Nutzen Sie die Selbsteinschätzung im„„Digital Sovereignty Readiness Report“““, um Ihre aktuelle Situation in allen vier Säulen zu ermitteln.

FAQs

F: Was ist „Minimum Viable Sovereignty“ (MVS)?

A: MVS bezeichnet die Praxis, Souveränitätskontrollen auf der Grundlage tatsächlicher geschäftlicher und regulatorischer Anforderungen anzuwenden. Damit soll sowohl eine übermäßige Komplexität als auch ein unzureichender Schutz vermieden werden.

F: Warum ist die Einstufung der Arbeitsbelastung wichtig?

A: Verschiedene Workloads sind mit unterschiedlichen regulatorischen und betrieblichen Verpflichtungen verbunden. Die Klassifizierung von Workloads hilft Unternehmen dabei, die angemessenen Souveränitätskontrollen anzuwenden.

F: Welche drei gängigen Souveränitätsprofile gibt es?

A: Die drei Profile sind eigenständige Organisationen, regulierte Organisationen und hybride Multi-Cloud-Organisationen. Jede davon unterliegt spezifischen betrieblichen und Compliance-Anforderungen.

F: Welche Risiken ergeben sich aus einer übermäßigen Regulierung der Souveränität?

A: Übermäßige Kontrollen können die Komplexität der Geschäftsabläufe und die Kosten erhöhen, ohne dass dadurch ein nennenswerter Nutzen in Bezug auf die Einhaltung von Vorschriften oder den Geschäftswert entsteht.

F: Warum stellen gemischte Umgebungen eine Herausforderung für die Governance dar?

A: Unternehmen nutzen häufig mehrere Cloud- und Infrastrukturmodelle. Es ist schwierig, in allen Umgebungen einheitliche Kontrollmaßnahmen, Prüfungsnachweise und Recovery-Standards aufrechtzuerhalten.

Ruben Renders ist Solutions Director, MSP, bei Commvault.

More related posts


Thumbnail-Digital-Sovereignty-4

Sovereign Data You Can’t Recover Isn’t Actually Sovereign

Read more about Sovereign Data You Can’t Recover Isn’t Actually Sovereign
Thumbnail-Digital-Sovereignty-3

The Pillar Most Sovereignty Strategies Forget

Read more about The Pillar Most Sovereignty Strategies Forget
Thumbnail-Digital-Sovereignty-1

You Don’t Have a Sovereignty Strategy. You Have a Residency Policy.

Read more about You Don’t Have a Sovereignty Strategy. You Have a Residency Policy.

Die wichtigsten Erkenntnisse

  • Data residency addresses where data is stored, but digital sovereignty also requires control over access, operations, and proper understanding of jurisdictional implications.
  • Operational sovereignty is often the weakest and least-audited part of most sovereignty programs.
  • A complete sovereignty posture depends on four pillars: data locality, technological sovereignty, operational sovereignty, and jurisdictional sovereignty.
  • Sovereignty is not binary; organizations must define a posture aligned to their regulatory and operational obligations.

Here is a question worth sitting with: When your organization made its sovereignty decision, what exactly did it decide?

For most, the answer is some version of the same thing. Pick a region. Move the workloads. Choose a cloud provider with data centers in-country. Check the box. The question of where data lives was answered, and the sovereignty conversation was considered closed.

But it wasn’t closed. It had barely started.

Data residency answers one question: Where? Digital sovereignty asks three more – who, how, and under what conditions?

The conflation of residency with sovereignty is understandable. Hyperscalers have made region selection feel like a sovereignty decision. Compliance checklists ask where data is stored. Regulatory guidance, at least in its earlier iterations, focused heavily on geography.

Choosing a sovereign cloud region is a real thing – it matters, it has operational implications, and it’s a necessary first step. But it is only a first step. And most organizations stopped there.

What Residency Doesn’t Answer

Think of it this way: Choosing a sovereign cloud region is like buying a safe. It tells you where your valuables are stored. It says nothing about who has a copy of the combination, who manufactured the safe, which country’s laws govern the manufacturer, or whether you can open it if compelled to.

Region selection answers one question. Three more remain entirely open – and these are the questions regulators, procurement committees, and auditors are now asking with increasing precision:

  • Who can operate your environment, and from where? Whether your cloud provider’s support personnel are subject to foreign jurisdiction is a sovereignty question that data residency cannot resolve. A routine maintenance window performed by a support engineer in a different legal jurisdiction is an access pathway your residency policy doesn’t cover. This is the domain of Operational Sovereignty – the hardest pillar to audit and the most commonly overlooked.
  • Under what legal regime can your data be accessed? A foreign technology provider operating infrastructure in-country does not automatically remove the reach of their home jurisdiction’s law. The extraterritorial reach of foreign legal regimes is a risk that geography alone cannot eliminate.
  • Can you recover your data if something goes wrong? Most sovereignty programs are built around access control. Very few address recovery – whether your data can be restored cleanly, within defined tolerances, by personnel who operate within your sovereignty boundary. That gap is where sovereignty postures most commonly fail under real conditions.

The Framework that Fills the Gap

A complete sovereignty posture spans four interdependent pillars. The „„Digital Sovereignty Readiness Report““ – available at readiverse.com – walks through each in full. In brief:

  • Data locality addresses where data and metadata actually travel.
  • Technological sovereignty covers control over encryption, key custody, and architecture portability.
  • Operational sovereignty covers who runs the environment and from where.
  • Jurisdictional sovereignty establishes the legal framework governing and affecting all of the above.

No single pillar is sufficient. A strong data locality posture with weak operational controls is not sovereignty – it is residency with unexamined risk.

What makes the framework useful is not its complexity. It’s the questions it generates. When an organization maps its current posture against all four pillars for the first time, it almost always finds gaps it didn’t know were there – not because the controls are absent, but because the questions were never asked.

Sovereignty Is a Sliding Scale

One more thing worth naming: Sovereignty is not a binary state. There is no certification that grants it and no single deployment model that guarantees it. It is a posture – a set of deliberate, auditable decisions. And the right level of that posture varies by organization, by workload, and by what you actually owe regulators and customers.

That calibration is what minimum viable sovereignty is about – the subject of the second post in this series.

Regulatory confidence is built long before the audit itself – through clearly defined requirements, not assumptions tied to geography.

Download the „„Digital Sovereignty Readiness Report““ for the four-pillar framework and a practical self-assessment tool.

FAQs

Q: What is the difference between data residency and digital sovereignty?

A: Data residency focuses on where data is physically stored. Digital sovereignty goes further by addressing who can access the data, how systems are operated, and exposure to which jurisdictions may create legal risk.

Q: Why is region selection not enough for sovereignty?

A: Choosing a cloud region only addresses geography. It does not resolve issues related to operational access, legal risks exposure, or recovery capabilities.

Q: What are the four pillars of digital sovereignty?

A: The four pillars are data locality, technological sovereignty, operational sovereignty, and jurisdictional sovereignty. Together, they create, what we believe, is a more complete framework for assessing sovereign readiness.

Q: Why is operational sovereignty difficult to manage?

A: Operational sovereignty involves monitoring who can access systems, where they operate from, and under which legal regime. These controls are harder to audit than simple data location requirements.

Q: Is digital sovereignty a fixed certification?

A: No. Sovereignty is an ongoing posture based on deliberate, auditable decisions that vary by organization, workload, and regulatory environment.

Ruben Renders is Solutions Director, MSP, at Commvault.

More related posts


Thumbnail-Digital-Sovereignty-3

The Pillar Most Sovereignty Strategies Forget

Read more about The Pillar Most Sovereignty Strategies Forget
Thumbnail-Digital-Sovereignty-4

Sovereign Data You Can’t Recover Isn’t Actually Sovereign

Read more about Sovereign Data You Can’t Recover Isn’t Actually Sovereign
Thumbnail-Digital-Sovereignty-2

Minimum Viable Sovereignty: Why the Right Posture Isn’t the Same for Every Organization

Read more about Minimum Viable Sovereignty: Why the Right Posture Isn’t the Same for Every Organization

Die wichtigsten Erkenntnisse

  • Vishing-Angriffe haben dramatisch zugenommen, wobei organisierte Gruppen Social-Engineering-Methoden systematisch einsetzen, um sich über Helpdesks einen ersten Zugang zu verschaffen.
  • Angreifer wechseln schnell von kompromittierten Benutzerkonten zu dauerhaften Maschinenidentitäten wie OAuth-Tokens und Dienstkonten.
  • Den meisten Organisationen mangelt es an Kontrollmechanismen und Transparenz in Bezug auf nicht-menschliche Identitäten (NHI), was einen erheblichen Sicherheitsblindfleck darstellt.
  • Effective Readiness depends on linking identity signals and treating machine identities as risky resources.
  • Echte Resilienz setzt die Fähigkeit voraus, unbefugte Änderungen an Berechtigungen zu erkennen und rückgängig zu machen, bevor Angreifer eine dauerhafte Präsenz aufbauen können.

Your help desk staff just got a phone call. The caller knew the employee’s name, their manager, and the last four digits of their badge number. They asked for a password reset. Standard procedure. The IT rep complied.

That call was a fraud. And the attacker is now inside.

Voice phishing – vishing – jumped im Jahr 2025 um 449 %.. Kriminelle Gruppen haben Social Engineering zu einem skalierbaren Geschäftsmodell gemacht: Sie rekrutieren Anrufer, erstellen Skripte und500 bis 1.000 Dollar zahlen per successful help desk impersonation. They’re not looking for your data. They’re looking for a foothold.

Once inside, attackers don’t linger on the human account. They move laterally – stealing OAuth tokens, creating new administrative service accounts, embedding access in machine-layer credentials that nobody watches. Unlike human passwords, those credentials are rarely rotated. They don’t trigger login alerts. They can survive a full remediation of the original compromised user.

By the time your security team closes the ticket on the help desk incident, the attacker may have been quietly persistent in your environment for weeks. The governance gap makes it worse.

Weniger als 25 % of organizations have formal policies for creating or decommissioning NHIs – the service accounts, API keys, and OAuth tokens that now outnumber human users by 144 zu 1. Nearly all of them carry permissions far beyond what their function requires.

Most organizations have almost no confidence in their ability to detect an attack targeting this layer. That’s not a prevention failure. It’s a recovery planning failure.

Wie Readiness aussieht

Prevention at the help desk matters – training, callback verification, out-of-band confirmation. But it isn’t enough on its own. Attackers are industrializing faster than awareness programs can keep pace.

Readiness means correlating the signals: A help desk interaction followed immediately by a multi-factor authentication (MFA) reset or a new token creation is a high-probability indicator of compromise.

It means treating machine identities as Tier 0 assets – governing their creation, scoping their permissions, and monitoring for unauthorized escalation. And it means having the ability to detect and roll back malicious privilege changes quickly, before they become the new normal.

Explore how Commvault Identity Resilienceunterstützt die schnelle Erkennung, Rücknahme und Recovery Ihrer Identitätsumgebung.

FAQs

F: Was ist ein Vishing-Angriff im Zusammenhang mit der Unternehmenssicherheit?

A: Vishing (voice phishing) uses phone calls to impersonate employees and manipulate IT help desks into granting access – typically through password or MFA resets. It’s increasingly industrialized, with organized groups recruiting callers and using pre-written scripts to maximize success rates.

F: Warum wenden sich Angreifer nach einem Vishing-Angriff auf Maschinenidentitäten zu?

A: Human accounts get remediated. NHIs – OAuth tokens, service accounts, API keys – are more persistent and rarely rotated, often invisible to traditional monitoring. Migrating access to the machine layer allows attackers to maintain that persistence long after the original human credential breach is detected and closed.

Q: What does “identity resilience” mean in practice?

A: It means your organization can help detect unauthorized privilege changes in near real time and help restore the identity environment to a trusted state quickly. Detection alone isn’t sufficient – the ability to roll back malicious activity and verify that machine identities haven’t been tampered with (or if tampered with, to be rolled back to a prior good point in time) is what separates readiness from exposure.

Vidya Shankaran ist Field CTO bei Commvault.

More related posts


Thumbnail_Blog-Identity-Resilience-MachineID-2026-Linkedin

The Machine Identity Blind Spot Is Now a Primary Attack Surface

Read more about The Machine Identity Blind Spot Is Now a Primary Attack Surface
Thumbnail_Blog-Help-Desk-2026-Linkedin

When the Help Desk Becomes the Front Door to Your Entire Network

Read more about When the Help Desk Becomes the Front Door to Your Entire Network
Thumbnail_Blog-SHIFT-Identity-Resilience-2026-Linkedin

Your Identity Infrastructure Is a Target. Here’s What Commvault Is Doing About It.

Read more about Your Identity Infrastructure Is a Target. Here’s What Commvault Is Doing About It.
Thumbnail_Blog-Rise-of-AI-Agents-in-Resops-2026

Commvault and Microsoft: The Rise of AI Agents in ResOps

Read more about Commvault and Microsoft: The Rise of AI Agents in ResOps
Thumbnail_Blog_Resilient-Against-the-AI-Machine

Resilient Against the AI Machine

Read more about Resilient Against the AI Machine

Die wichtigsten Erkenntnisse

  • Social-Engineering-Angriffe auf den Helpdesk sind mittlerweile ein Hauptangriffspunkt, wobei Vishing-Angriffe (Voice-Phishing) rapide zunehmen und zum Diebstahl von Zugangsdaten führen.
  • Nicht-menschliche Identitäten wie Dienstkonten und Tokens stellen einen erheblichen Sicherheitsblindfleck dar; sie werden oft nicht verwaltet und in großem Umfang für laterale Bewegungen ausgenutzt.
  • Active Directory (AD) ist aufgrund seiner zentralisierten Steuerung und möglicher Fehlkonfigurationen ein besonders attraktives Angriffsziel.
  • Prävention allein reicht nicht aus; Unternehmen benötigen leistungsfähige Erkennungs- und schnelle Wiederherstellungsfunktionen, um den Schaden zu begrenzen.
  • Immediate operational actions – like auditing accounts and correlating help desk activity with identity changes – can significantly reduce risk.

AD ist nach wie vor ein Hauptziel für Angreifer, da es das Herzstück der Identitätsverwaltung in Unternehmen bildet.Jüngste Untersuchungen zeigen, dass67 % der Vorfälle stehen mittlerweile im Zusammenhang mit Identitätsmissbrauch, with attackers going after critical systems like AD within hours of initial access.Once compromised, recovery can take days or weeks – causing significant business disruption.
The question worth asking isn’t whether AD is a target.It’s how attackers get thier – and why the path is so much shorter than security teams might expect.

3 Schritte zu einem umfassenden Kompromiss

Angreifergruppen wie ShinyHunters und Scattered Spider haben Social Engineering zu einem industriellen Geschäft gemacht.Voice phishing – vishing – jumped 449% in 2025.Die Anrufer werden rekrutiert, erhalten ein Skript undbis zu 1.000 Dollar gezahlt depending on success and hit rate.
That means, it’s possible to start an attack with one step: Get a password reset or multi-factor authentication (MFA) change.That’s it.
From that single credential, the attacker moves laterally into cloud and virtualized environments.They harvest OAuth tokens, create new administrative service accounts, and embed access in machine-layer credentials.These non-human identities – service accounts, API keys, tokens – now outnumber human users 144 to 1.Die Ausdehnung und der operative Aufwand erschweren die Rotation und die Prüfung. Diese seitliche Bewegung hat ein Ziel: Active Directory.

AD ist das Ziel

AD is the central nervous system of enterprise identity.Control it and you control everything – user accounts, group policies, and access to every domain-joined system in the network.The reason it’s so attractive to attackers – and so difficult to defend – is structural.Any authenticated user can read the entire directory.Every domain-joined system inherits trust from it.
Group Policy Objects linked at the domain head can be weaponized to disable security controls outright.Legacy protocols left enabled for application compatibility provide straightforward access.Microsoft’s own documentation says that “most identity attacks utilize common misconfigurations in Active Directory.”

When an attacker reaches the AD, they don’t need to force entry.The door is usually open.

Prävention ist notwendig, aber nicht ausreichend

The standard security stack – MFA, endpoint detection, email filtering – is built around human behavior.It wasn’t designed to govern the machine identity layer or to detect the kind of slow, legitimate-looking privilege escalation that characterizes modern AD attacks.An attacker that moves from a compromised human account to a service account to a domain administrator over 72 hours may never trigger a single alert.
This is why the conversation must shift from prevention-first to recovery-first.
Prevention still matters.Least-privilege access, auditing AD changes, hardening default configurations, disabling inactive accounts – these can help reduce the attack surface.But given that half of organizations have already experienced an AD attack, designing only for prevention means designing to fail.
True identity resilience requires the ability to detect unauthorized privilege escalations in near real time, roll back malicious changes before they propagate, and restore the identity environment to a known-trusted state quickly – not in days or weeks, but fast enough to contain the blast radius.That means treating AD and the non-human identity layer as Tier 0 assets, with the same governance and recovery investment you’d apply to any other mission-critical system.

Was Sie jetzt tun können, um Ihre Identitätsresilienz zu stärken

The gap between whier most organizations are and whier they need to be on identity resilience is real.But it’s closeable.The immediate priorities are unglamorous and operational:

  1. Audit what’s in your AD.
  2. Find the accounts that shouldn’t still exist.
  3. Rotate the credentials that haven’t been touched in years.
  4. Stellen Sie einen Zusammenhang zwischen den Helpdesk-Aktivitäten und den Ereignissen zur Erstellung von Tokens und Konten her.

A help desk interaction followed by an MFA reset followed by a new service account is a high-confidence attack signal – and it’s detectable if you’re looking for it.
The longer-term work is architectural: Build recovery capability into your identity program so that when an attack succeeds – and it’s usually when, not if – you can contain it, reverse it, and try to restore trust faster than the attacker can consolidate their position.
Attackers are counting on your AD being ungoverned, your machine identities being invisible, and your recovery plan being theoretical.Close one of those gaps this quarter.Close all three and you’ve fundamentally changed the math. 

Erfahren Sie, wie Commvault Cloud umfassenden Schutz für Active Directory bietet – from vulnerability assessment to one-click rollback and full forest recovery.
I recently joined Vidya Shankaran on the STRIVE podcast to talk about the governance gap for non-human identities.Check out our episode hier.And be sure to read Vidya’s blog, Der blinde Fleck bei der Maschinenidentität ist mittlerweile eine der wichtigsten Angriffsflächen.

FAQs

Q: Why are help desks becoming a major security risk?

A: Help desks are often trusted to reset passwords and modify MFA settings, making them attractive targets for social engineering.Attackers exploit this trust to gain initial access with minimal resistance.
Q: What role do non-human identities play in attacks?

A: Sprawl and operational overhead make rotation and audit of non-human identities, such as service accounts and API keys, difficult.Attackers use them to maintain persistence and move undetected across systems.
Q: Why is AD such a critical target?

A: AD controls authentication and access across the network.Gaining control of it allows attackers to manage users, policies, and systems at scale.
Q: Isn’t MFA and endpoint security enough to stop these attacks?

A: These tools focus on human behavior and may not detect slow, legitimate-looking privilege escalation.Attackers can operate within normal patterns and avoid triggering alerts.
Q: What does a recovery-first security approach mean?

A: It means preparing for the reality that breaches will happen and prioritizing the ability to detect, contain, and reverse them quickly.This approach helps reduce downtime and can help limit overall impact.
Q: What are the most important steps to take immediately?

A: Start by auditing your AD, removing unnecessary accounts, rotating old credentials, and monitoring for suspicious sequences of help desk and identity-related activities.
Dan Conrad ist leitender Technologe und Field CTO bei Commvault.

More related posts


Thumbnail_Blog-Okta-Early-Access-2026

Commvault® Extends Identity Resilience to Okta

Read more about Commvault® Extends Identity Resilience to Okta
Thumbnail_Blog-Lateral-Access-2026

Staying Resilient Against Lateral Access Exploits

Read more about Staying Resilient Against Lateral Access Exploits
Thumbnail_3_AD_Blogs_2025

Active Directory Forest Recovery: Why Manual Methods Are No Longer Viable

Read more about Active Directory Forest Recovery: Why Manual Methods Are No Longer Viable
Thumbnail_6_AD_Blogs_2025

AD Recovery Testing: How to Know Your Recovery Plan Will Actually Work

Read more about AD Recovery Testing: How to Know Your Recovery Plan Will Actually Work

Die wichtigsten Erkenntnisse

  • Nicht-menschliche Identitäten (NHIs) sind mittlerweile zahlenmäßig weitaus stärker vertreten als menschliche Nutzer und nehmen deutlich schneller zu, wodurch eine erhebliche und nur unzureichend regulierte Angriffsfläche entsteht.
  • Angreifer nutzen zunehmend Social-Engineering-Methoden wie Voice-Phishing (Vishing), um menschliche Abwehrmechanismen zu umgehen und Zugriff auf Anmeldedaten auf Systemebene zu erlangen.
  • Most NHIs operate with excessive permissions and lack proper lifecycle management, contributing to accumulated “identity debt.”
  • Herkömmliche Sicherheitstools können Bedrohungen auf der Maschinenebene nicht erkennen, da sich NHIs anders verhalten als menschliche Nutzer.
  • Unternehmen müssen von Strategien, bei denen die Prävention im Vordergrund steht, zu Ansätzen übergehen, bei denen die Wiederherstellung im Vordergrund steht, und dabei der schnellen Erkennung und Abwehr identitätsbasierter Angriffe Priorität einräumen.

For the past decade, enterprise security investment has followed the human. Better authentication. Stronger multi-factor authentication (MFA). Phishing simulation. Identity-centric architecture. These investments were the right response to the threat landscape at the time.

The threat landscape has moved.

Today’s most sophisticated adversaries aren’t trying to defeat your MFA. They’re using it as a door. A convincing phone call to your IT help desk, an MFA reset, and a compromised human account – that’s the entry. What they’re actually after is what’s behind it: the sprawling, under-governed layer of NHIs that connects every system in your environment.

Das Ausmaß des Problems ist erschütternd

Service accounts, API keys, OAuth tokens, AI agents – NHIs now outnumber human users by a ratio of 144 zu 1, and they’re growing vier- bis zehnmal schnellerals menschliche Konten. Dennoch verfügenweniger als 25 % of organizations have formal policies governing their creation or decommissioning. Nearly all of them carry excessive permissions – rights that far exceed what their function requires.

This isn’t a new risk that suddenly appeared. It’s accumulated identity debt: years of provisioning without governance, automation without accountability, cloud expansion without visibility. And adversaries have noticed.

Vishing ist der Einstiegspunkt

Groups like ShinyHunters and Scattered Spider – operating under what researchers call the Scattered LAPSUS$ Hunters (SLH) cluster – have industrialized social engineering to exploit exactly this gap. Voice phishing rose im Jahr 2025 um 449 %.. These aren’t opportunistic calls. They’re coordinated operations: purpose-built scripts, recruited callers, finanzielle Anreize von bis zu 1.000 US-Dollar per successful help desk impersonation.

The call isn’t the attack. The call is the credential reset that gets an attacker past the human perimeter. The attack begins when they migrate to the machine layer – stealing OAuth tokens, creating administrative service accounts, embedding access into credentials that are rarely monitored and almost never rotated.

The human account gets remediated. The machine-layer access persists. The attacker has already moved on.

Three Vulnerabilities that Traditional Controls Can’t See

Standard security tools are designed around human behavior. They flag anomalous logins, unusual geolocation, suspicious email traffic. NHIs operate differently, and that difference is the blind spot.

OAuth abuse, for instance, looks like normal API traffic – even after a password reset. Thousands of undocumented service accounts operate in large enterprises with administrative privileges, often long after the projects that created them ended. Long-lived API keys embedded in DevOps pipelines carry broad access with no device context and no login alert.

MFA doesn’t cover them. Endpoint detection doesn’t see them. Email filtering is irrelevant to them.

Der Paradigmenwechsel: Von „Prävention zuerst“ zu „Genesung zuerst“

The logical response to a threat that often evades traditional detection is to stop assuming you can prevent every intrusion and start designing for rapid recovery from the ones that succeed.

That means treating NHIs as Tier 0 assets – with the same governance controls applied to domain administrators or cloud control planes managed with human identities. It means replacing static secrets with short-lived tokens and automatic rotation.

It also means correlating cross-domain signals: A help desk interaction followed by an MFA reset followed by a new token creation is a high-confidence indicator of compromise, and catching it early is the difference between containment and a prolonged breach. It means mapping NHIs to human identities for accountability.

Most importantly, it means having the capability to detect unauthorized privilege escalations and roll back malicious identity changes in real time – returning the environment to a known-trusted state before the damage extends.

Prevention still matters. But given the governance gap many organizations are carrying, recovery speed is becoming a primary resilience metric. Organizations should build identity programs designed for the attacks that are already happening, not the ones that were common five years ago.

Visit the Readiverseund werfen Sie einen Blick auf unser E-BookDie Identitätskrise der Nicht-Menschen“, das sich eingehend mit der gesamten Angriffsfläche von Maschinen und dem Rahmenkonzept für Identitätsresilienz befasst.

FAQs

Frage 1: Was sind nicht-menschliche Identitäten (NHIs)?

A: Zu den NHIs gehören Dienstkonten, API-Schlüssel, OAuth-Token und KI-Agenten, die die Interaktion zwischen Systemen und Anwendungen ermöglichen. Im Gegensatz zu menschlichen Nutzern arbeiten sie oft automatisch und in großem Maßstab, was ihre Überwachung und Steuerung erschwert.

Frage 2: Warum gelten NHIs als Sicherheitsrisiko?

A: NHIs verfügen oft über zu weitreichende Berechtigungen und es mangelt ihnen an einer angemessenen Governance, was sie zu attraktiven Zielen für Angreifer macht. Da sie selten überwacht oder regelmäßig ausgetauscht werden, können kompromittierte Zugangsdaten über lange Zeiträume hinweg unentdeckt bleiben.

Frage 3: Wie nutzen Angreifer NHIs aus?

A: Angreifer verschaffen sich in der Regel zunächst durch Social-Engineering-Methoden wie Voice-Phishing Zugriff und wechseln dann auf die Systemebene. Sie stehlen Tokens, erstellen neue Dienstkonten oder bauen dauerhaften Zugriff in Anmeldedaten ein, die nicht genau überwacht werden.

Q4: Why don’t traditional security tools detect these threats?

A: Die meisten Sicherheitstools sind darauf ausgelegt, menschliches Verhalten zu überwachen, beispielsweise Anomalien bei der Anmeldung oder Phishing-Versuche. NHIs erzeugen Systemverkehr, der normal aussieht, wodurch sich böswillige Aktivitäten in legitime Vorgänge einfügen können.

Q5: What is meant by a “recovery-first” security approach?

A: Ein „Recovery-First“-Ansatz konzentriert sich darauf, Sicherheitsverletzungen schnell zu erkennen und Systeme wieder in einen vertrauenswürdigen Zustand zu versetzen, anstatt davon auszugehen, dass sich alle Angriffe verhindern lassen. Dazu gehört es, unbefugte Änderungen zu identifizieren und diese in Echtzeit rückgängig zu machen.

Frage 6: Wie können Organisationen die Sicherheit des NHI verbessern?

A: Unternehmen können NHIs als kritische Vermögenswerte behandeln, strenge Governance-Richtlinien umsetzen, statische Anmeldedaten durch kurzlebige Token ersetzen und Signale systemübergreifend miteinander verknüpfen. Die Zuordnung von NHIs zu bestimmten Verantwortlichen verbessert zudem die Rechenschaftspflicht und die Aufsicht.

Vidya Shankaran ist Field CTO bei Commvault.

More related posts


Thumbnail_Blog-SHIFT-Identity-Resilience-2026-Linkedin

Your Identity Infrastructure Is a Target. Here’s What Commvault Is Doing About It.

Read more about Your Identity Infrastructure Is a Target. Here’s What Commvault Is Doing About It.
Thumbnail_Blog-Rise-of-AI-Agents-in-Resops-2026

Commvault and Microsoft: The Rise of AI Agents in ResOps

Read more about Commvault and Microsoft: The Rise of AI Agents in ResOps
Thumbnail_Blog-Unified-Resilience-2026

Why AI Is Breaking Your Resilience Strategy (And What to Do About It)

Read more about Why AI Is Breaking Your Resilience Strategy (And What to Do About It)
Thumbnail_Blog_Resilient-Against-the-AI-Machine

Resilient Against the AI Machine

Read more about Resilient Against the AI Machine

Organizations today are building applications faster, automating workflows at scale, and turning data into insights, powered by platforms like Microsoft Power Platform. What started as a low-code productivity layer has quickly become mission-critical, embedded in the processes that support revenue generation, day-to-day operations, and strategic decision-making.

But as the reliance on these business intelligence assets grows, so does the associated risk. The same platform accelerating innovation can also amplify the impact of operational errors, misconfigurations, and malicious actions.

A misconfigured workflow, a deleted report, or a broken application can disrupt business processes, compromise decision-making, and erode trust in the systems the business relies on. And when something goes wrong, recovery is rarely straightforward.

Commvault is helping address these challenges with enterprise-grade data protection and recovery for Microsoft Power Platform, starting with Power BI – allowing organizations to help keep the insights, workflows, and apps they build protected and rapidly recoverable. 

Power BI: Die Kluft zwischen Erkenntnis und Wiederherstellung

At the center of many Power Platform deployments is Microsoft Power BI, providing analytics and business intelligence, transforming data into reporting, forecasting, and operational visibility.

When Power BI assets are lost or compromised teams can quickly lose access to trusted insights, interrupting reporting cycles, and delaying business decision-making.

In practice, however, protection strategies lag behind the importance of these assets. Many organizations rely on manual file exports or limited native capabilities that weren’t designed for comprehensive recovery. When something breaks, teams are often forced to rebuild manually with no ability to restore exactly what’s needed. This makes recovery slow, error-prone, and difficult to scale.

Commvault Cloud Backup & Recovery for Microsoft Power Platform

Now generally available, Commvault Cloud Backup & Recovery for Microsoft Power Platform helps organizations protect and recover their business-critical assets, such as reports, from accidental deletion, corruption, and malicious activity.

  • Automatisierter, richtlinienbasierter Schutz: Führen Sie richtliniengesteuerte Backups für alle Ressourcen im Power BI-Arbeitsbereich durch und sorgen Sie so für eine konsistente, skalierbare Abdeckung ohne manuellen Eingriff.
  • Schnelle, detaillierte Wiederherstellung: Stellen Sie einzelne Berichte und Ordner zu einem bestimmten Zeitpunkt wieder her, um manuelle Neuerstellungen zu vermeiden und Ausfallzeiten sowie Betriebsstörungen auf ein Minimum zu reduzieren.
  • Isolierte, unveränderliche Backups: Schützen Sie Ihre Daten vor Ransomware und unbefugten Änderungen mit Backups, die so konzipiert sind, dass unbefugte Änderungen oder Löschungen verhindert werden.
  • Vereinfachte Einhaltung gesetzlicher Vorschriften: Gewährleistung einer langfristigen Aufbewahrung (bis zu 10 Jahre), zentraler Prüfprotokolle und Berichterstellung zur Erfüllung behördlicher und interner Anforderungen.

Einheitliche Platform Resilienz

Commvault Cloud eine einheitliche platform Schutz platform SaaS, cloud und lokalen Workloads, darunter Microsoft 365, Dynamics 365, Salesforce, virtuelle Maschinen, Datenbanken und Endgeräte. Dank Platform Microsoft Power Platform können Kunden den Schutz, die Wiederherstellung und die Ausfallsicherheit für mehr Workloads optimieren, wodurch sich die Vielzahl an Tools reduzieren und der Betrieb vereinfachen lässt.

Erste Schritte

Commvault Cloud Backup & Recovery for Power Platform is delivered as a SaaS solution, designed for fast deployment and minimal operational overhead. Organizations can connect their Power BI environment, apply policy-based protection, and begin backing up critical data in a matter of steps.

Die automatische Erkennung sorgt dafür, dass neue Berichte und Ordner im Zuge der Weiterentwicklung der Umgebungen berücksichtigt werden, während die zentralisierte Verwaltung eine zentrale Anlaufstelle für die Überwachung, Verwaltung und Wiederherstellung von Daten in großem Umfang bietet.

What’s Next: Expanding Across Power Platform

Wir beabsichtigen, den Schutz und die Ausfallsicherheit in Platform gesamten Microsoft Power Platform Power Apps und Power Automate auszuweiten und damit den Schutz auf die Anwendungen und Workflows zu erweitern, die Ihr Unternehmen unterstützen. Pläne, Zeitpläne und Funktionen können sich ändern und sollten nicht als Grundlage für Kaufentscheidungen herangezogen werden.

Schützen Sie das, was Ihr Unternehmen antreibt

Mit der Platform Nutzung der Microsoft Power Platform wächst auch der Bedarf an einem ausfallsicheren Schutz auf Unternehmensniveau. Mit Commvault Cloud können Sie:

  • Schützen Sie wichtige Ressourcen vor Löschung, Beschädigung und Angriffen
  • Rapidly recover exactly what you need – without rebuilding everything
  • Das Vertrauen in Daten, Entscheidungen und Automatisierung aufrechterhalten
Sind Sie bereit, Ihre Investition in Microsoft Power BI widerstandsfähig zu machen?

Erfahren Sie mehr und sehen Sie sich Commvault Cloud in Aktion an untercommvault.com/platform/Power Platform.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • Die Migration von VMs zu Red Hat OpenShift Virtualization ist ein schrittweiser Prozess, der einen durchgängigen Schutz über hybride Umgebungen hinweg erfordert.
  • Eine einheitliche, Kubernetes-native platform , die Komplexität zu verringern und den Einsatz separater Tools oder Prozesse überflüssig zu machen.
  • Reliable resilience – including immutable backups and threat detection – is critical during migration, when risks are highest.
  • Dank flexibler Wiederherstellungsoptionen können Unternehmen schnell reagieren, falls Migrationsschritte fehlschlagen oder sich Zeitpläne verschieben.
  • Die Konsolidierung der Sicherheitsmaßnahmen für VMs und Container trägt dazu bei, die Vielzahl an Tools zu reduzieren und eine einheitliche Governance zu gewährleisten.

If you’re an IT leader today, chances are your virtualization strategy is under active review.

Rising costs, licensing uncertainty, and long-term vendor lock-in have many organizations reassessing their reliance on traditional hypervisors. At the same time, Kubernetes has matured into the operational foundation for modern applications.

These two realities are converging – and for many enterprises, Red Hat OpenShift Virtualization is emerging as a preferred destination for running virtual machines within a Kubernetes-native operating model.

This transition is accelerating across industries. As organizations modernize infrastructure on their own terms, Red Hat OpenShift Virtualization is increasingly viewed as a way to modernize the platform without the need for application refactoring. With that momentum comes a critical question:

How do you migrate virtual machines while maintaining consistent protection, resilience, and recoverability throughout the process?

To answer it, you need to examine how most enterprise migrations actually unfold – and where protection and resilience become critical.

Migration ist eine Reise, kein einmaliges Ereignis

Seasoned IT leaders know that infrastructure transitions rarely happen all at once.

For enterprises opting to move from hypervisors like VMware to Red Hat OpenShift Virtualization, the transition typically unfolds in phases. During this time, organizations inevitably operate in a mixed state:

  • VMware-basierte virtuelle Maschinen unterstützen weiterhin die Kerngeschäftsprozesse.
  • VMs, die nun auf Red Hat OpenShift Virtualization laufen.
  • Containerisierte Anwendungen, die dieselben Red Hat OpenShift-Cluster gemeinsam nutzen.

This coexistence period introduces complexity and risk. Data is in motion, environments are changing, and protection gaps can appear if tooling and processes don’t evolve alongside workloads.

Ein zuverlässiger Schutz ist unerlässlich

Commvault bietet seit langem Lösungen für die Datensicherung und -wiederherstellung sowohl für VMware-Umgebungen als auch für Kubernetes-Workloads, die auf Red Hat OpenShift ausgeführt werden. Dasselbe Kubernetes-native, richtliniengesteuerte Schutzmodell gilt nun auch für VMs, die auf Red Hat OpenShift Virtualization ausgeführt werden. Was bei den Kunden wirklich Anklang findet, ist die Beständigkeit:

  • Eine einzige platform Schutz und Wiederherstellung.
  • Richtlinienbasierte Abläufe, die einheitlich auf alle Workloads angewendet werden.
  • Entwickelt, um mit Ihren bestehenden Tools und Prozessen zu harmonieren, während sich die Umgebungen weiterentwickeln.

VMs, die auf Red Hat OpenShift Virtualization ausgeführt werden, werden mithilfe derselben Workflows und Governance-Strukturen geschützt wie containerisierte Anwendungen. Dieser einheitliche Ansatz wird von Unternehmen genutzt, die auf Red Hat OpenShift standardisieren und eine einfachere, einheitlichere Methode zur Verwaltung von Daten über verschiedene Umgebungen hinweg anstreben. Diese Funktion ist ab sofort verfügbar.Cloudunterstützt die Sicherung von Red Hat OpenShift Virtualization-Umgebungen, die auf die Long-Term-Support-Version 11.40 und die Innovation-Version 11.42 abgestimmt sind. Das bedeutet, dass Kunden diese Funktionen bereits jetzt in der Produktion einsetzen können.

You Shouldn’t Need to Manage Protection Differently

Once VMs move to Red Hat OpenShift Virtualization, they shouldn’t require special handling from a protection standpoint.

Cloud discovers and protects Red Hat OpenShift Virtualization VMs alongside containerized applications, helping give teams centralized visibility, consistent policy enforcement, and simplified recovery operations. Virtualized and containerized workloads are managed together – without introducing operational silos.

For organizations managing diverse application portfolios, this treatment of VMs inside Kubernetes helps reduce operational friction while maintaining enterprise-grade controls.

Cyber-Resilienz ist entscheidend, wenn die Migration das Risiko erhöht.

Migration periods represent a uniquely vulnerable window. Change creates complexity, and complexity increases exposure to data loss and ransomware.

Cloud helps maintain resilience throughout this phase with:

  • Air-Gapped- und unveränderliche Backups für Workloads unter Red Hat OpenShift Virtualization.
  • Sicherungsdaten, die die Bedrohungssuche und forensische Analysen unterstützen und den Teams dabei helfen, die Wiederherstellungsbereitschaft vor der Wiederherstellung von Workloads zu überprüfen.
  • Advanced recovery capabilities designed to help organizations minimize operational disruption.

Unabhängig davon, ob sich die Workloads in der Vorbereitungsphase der Migration, mitten in der Umstellung oder bereits voll im Betrieb auf Red Hat OpenShift Virtualization befinden, bleibt die Ausfallsicherheit gewährleistet.

Flexibilität bei der Genesung schafft Vertrauen

Every modernization initiative needs room for adjustment.

Commvault supports both in-place and out-of-place recovery for Red Hat OpenShift Virtualization virtual machines, including full VM context and configuration. If a migration step doesn’t go as planned – or timelines need to shift – teams may recover quickly and move forward without compromising availability or data integrity.

Kubernetes-nativer Schutz über VMs hinaus

For many enterprises, virtualization is only one piece of a broader application modernization strategy.

Cloud also provides application-centric, Kubernetes-native protection for containerized workloads, including persistent volumes and application metadata, across all CNCF-certified Kubernetes distributions. This enables mobility and recovery for cloud-native applications while helping maintain operational consistency across environments.

Eindämmung der Tool-Flut im Zuge der Weiterentwicklung der Infrastruktur

Platform transitions often introduce new tools, new processes – and new complexity.

By using Cloud as a unified protection platform for:

  • VMware-VMs.
  • Red Hat OpenShift Virtualization-VMs.
  • Containerisierte Anwendungen.

Unternehmen können dazu beitragen, die Vielzahl an Tools zu reduzieren, die Verwaltung zu vereinfachen und eine einheitliche Governance aufrechtzuerhalten, auch wenn sich die Infrastrukturstrategien weiterentwickeln.

Wie alles zusammenkommt

During any migration, it helps to understand how the pieces work together. Red Hat’s Migration Toolkit for Virtualization takes care of moving VMs from VMware into Red Hat OpenShift Virtualization.

Cloud helps provide the protection and resilience that stays with your workloads throughout the process, so data can remain protected before, during, and after migration. This can help keep recoverability from falling behind as workloads move.

Continuing the Conversation at Red Hat Summit

We’re already working with customers that are actively moving virtual machines onto OpenShift Virtualization – and we’re continuing these discussions at Red Hat Summit, May 11–14 in Atlanta.

At the Commvault booth, we’ll be:

  • Gespräche mit IT-Führungskräften über praktische Herausforderungen im Bereich der Ausfallsicherheit.
  • Praktische Tipps für eine reibungslose Migration.
  • Demonstrating Cloud protection for Red Hat OpenShift Virtualization.

If maintaining resilience and recoverability throughout your virtualization strategy is a priority, we’d welcome the opportunity to connect.

Mit Zuversicht in die Zukunft

Red Hat OpenShift Virtualization is becoming a foundational component of modern enterprise infrastructure. But you can’t rush migration at any cost; you must build protection, resilience, and recovery into the process from the beginning.

With Cloud, protecting Red Hat OpenShift Virtualization workloads isn’t a future aspiration. It’s something customers already are doing – using a unified platform to modernize confidently while staying resilient and recoverable.

“Red Hat OpenShift Virtualization delivers a reliable, consistent foundation for organizations to support their entire virtualized estate,” says Steve Gordon, Senior Director, Product Management, Hybrid Cloud Platforms, at Red Hat. “By leveraging an optimized integration like Cloud with Red Hat OpenShift Virtualization, our customers can move forward with greater confidence, knowing their workloads are protected consistently before, during, and after migration.”

FAQs

F: Warum wird die VM-Migration als mehrstufiger Prozess betrachtet?

A: Die meisten Unternehmen können nicht alle Workloads auf einmal migrieren, sodass sie in einem Hybridzustand arbeiten, in dem alte und neue Umgebungen gleichzeitig betrieben werden. Dieser schrittweise Ansatz bringt Komplexität mit sich, weshalb ein einheitlicher Schutz und eine durchgängige Transparenz während des gesamten Übergangs unerlässlich sind.

F: Welche Rolle spielt die Ausfallsicherheit bei der VM-Migration?

A: Dank Ausfallsicherheit können Unternehmen den Datenschutz gewährleisten, sich schnell von Ausfällen erholen und sich gegen Bedrohungen wie Ransomware schützen. Während der Migration, wenn sich die Systeme im Umbruch befinden, können wirksame Maßnahmen zur Ausfallsicherheit dazu beitragen, Datenverluste und Betriebsstörungen zu verhindern.

Q: How does Cloud simplify protection across environments?

A: Cloud provides a single platform with policy-driven protection for VMware VMs, OpenShift Virtualization VMs, and containerized applications. This unified approach enables consistent operations without introducing new tools or workflows.

F: Warum ist ein Kubernetes-nativer Schutz so wichtig?

A: Der Kubernetes-native Schutz ist auf die Art und Weise abgestimmt, wie moderne Anwendungen bereitgestellt und verwaltet werden, und deckt sowohl Container als auch virtuelle Maschinen ab. Er ermöglicht eine einfache Datenverwaltung, Mobilität und Wiederherstellung in cloud Umgebungen.

F: Inwiefern trägt die Flexibilität bei der Wiederherstellung dazu bei, das Vertrauen in die Migration zu stärken?

A: Flexible Wiederherstellungsoptionen, wie beispielsweise In-Place- und Out-of-Place-Wiederherstellungen, können Teams dabei helfen, Workloads schnell wiederherzustellen, falls etwas schiefgeht. Diese Flexibilität trägt dazu bei, Ausfallzeiten zu reduzieren, und ermöglicht es Unternehmen, ihre Migrationspläne anzupassen, ohne die Datenintegrität zu gefährden.

F: Wie können Unternehmen die Komplexität bei Infrastrukturumstellungen reduzieren?

A: By adopting a unified data protection platform, organizations can manage all workloads – virtualized and containerized – through a single interface. This approach helps reduce tool sprawl, simplify administration, and maintain consistent governance across evolving environments.

Jason Gizaist Senior Manager im Bereich „Global Content Partner Marketing“ bei Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • Die Readiverse-Akademie hat einen strukturierten, mehrstufigen Zertifizierungspfad eingeführt, der von den Grundlagen bis hin zu fortgeschrittenen Fachkenntnissen cloud reicht.
  • Die Zertifizierungen sind auf reale Aufgabenbereiche abgestimmt und helfen den Lernenden dabei, Fähigkeiten zu erwerben, die für ihre Aufgaben in Cloud relevant sind.
  • The program includes four tiers – Practitioner, Specialist, Professional, and Expert – each increasing in depth and operational capability.
  • Das Lernen stützt sich auf drei Kernsäulen: platform , Cyber-Resilienz und Fachwissen im Bereich Workloads.
  • Flexible Lernmöglichkeiten, darunter sowohl selbstbestimmte als auch von Lehrkräften geleitete Formate, ermöglichen es Berufstätigen, entsprechend ihrem Zeitplan und ihren Zielen Fortschritte zu erzielen.

The environments you protect with Commvault® Cloud are increasingly complex, and the expectations on your teams that run them are higher than ever. It’s no longer just about knowing the platform. It’s about being able to operate, protect, and recover, often under pressure.

If you’ve already started your learning journey in the Readiverse-Akademie, welcome back. And if you’re new here, you’re joining at the right time.

Today, we’re introducing a structured, tiered certification approach that gives learners a clear, skill‑based path from foundational platform knowledge to advanced cloud engineering expertise.

Wir erstellen Inhalte für Sie

Commvault Cloud environments demand expertise across multiple responsibilities, often within the same role. Administrators, security specialists, cloud engineers, and workload owners require different depths and breadths of knowledge. And not everyone needs to learn the same things, in the same order, to be effective.

The new Readiverse-Akademie certification tiers reflect that reality. Learners progress through clearly defined levels that build on one another so that your certification aligns to what you actually do and validates those capabilities to the teams you work with.

  • Commvault Cloud Practitioner – foundational platform and resilience knowledge.
  • Commvault Cloud Specialist – expanded operational and security depth.
  • Commvault Cloud Professional – advanced recovery and workload expertise.
  • Commvault Cloud Expert – full cloud engineering and resilience leadership.

Each tier is earned through a combination of coursework, hands‑on lab activities, and validated assessments. As learners progress, the scope and depth of operational capability demonstrated increases accordingly.

„Clear Path“ – Vom Anfänger zum Experten

Das Zertifizierungsprogramm basiert auf drei Kernkompetenzen, die sich durch alle Stufen ziehen:

  • Grundlegende platform
  • Konzepte zur Cyber-Resilienz
  • Arbeitsaufwand und Fachkenntnisse

Jede Stufe umfasst spezifische Anforderungen, die sich auf diese Säulen beziehen. Die Lernenden können einzelne Kurse absolvieren oder bestimmte Anforderungen kombinieren, um ihre Zertifizierungsziele zu erreichen.

Already in Readiverse-Akademie? What this Means for You.

With a new structure like this, the most important question is what it means for the progress you’ve already made. If you’ve already completed courses or earned certifications in the Readiverse-Akademie, congratulations! Your investment matters, and we want to be clear about what happens next.

Those certifications represent your history and accomplishments with Commvault. The new program is aligned to our expanded portfolio of cyber resilience features for Commvault Software, Commvault SaaS, and hybrid environments. As your needs grow to require more from Commvault, these courses and certifications will help you configure, manage, and optimize Commvault to meet your organization’s unique needs.

There is no direct progression from the previous certification tracks to the new program, but your existing certifications validate your expertise on the former product releases. As those releases are retired, those certifications will reach end of life as well. Learners who are already invested in the Readiverse-Akademie are well positioned to progress quickly.

Who Should Take Readiverse-Akademie Courses and Certifications

Readiverse-Akademie certifications are designed for professionals working across Commvault SaaS, Commvault Software, and hybrid environments.

  • Platform administrators managing day‑to‑day operations.
  • Sicherheitsexperten, die sich auf den Schutz von Daten und die Absicherung von Systemumgebungen konzentrieren.
  • Cloud , die für die Konfiguration der Steuerungsebene und für erweiterte Ausfallsicherheit zuständig sind.
  • Verantwortliche für Arbeitsabläufe, die über Fachkenntnisse in bestimmten Datenbereichen verfügen müssen.

All training is available for self‑paced learning, with select courses also offered in instructor‑led formats, so learners can progress in a way that fits their role and schedule.

So beginnen Sie Ihre Lernreise oder setzen sie fort

Whether you’re starting fresh or continuing your journey, the next step is simple and designed to meet you where you are.

  • Melden Sie sich beiCommvault.com.
  • Sind Sie neu bei Commvault? Beginnen Sie mit dem Kurs „Commvault Cloud “.
  • Sind Sie für die Unterstützung bei der Arbeitsbelastung zuständig? Dann schauen Sie sich unseren Kurskatalog an, der so gut wie alle Themen abdeckt.
  • Suchen Sie nach Strategien zur Unterstützung der Wiederherstellung nach einem Cyberangriff? Dann ist der Kurs „Cyber Resilience“ genau das Richtige für Sie.

Was kommt als Nächstes?

Our goal is to make advancement predictable, transparent, and aligned to real‑world roles to help learners know what’s next and how to prepare for it.

We are committed to giving every Commvault Cloud user the knowledge to operate, protect, and recover their environment with confidence. Because when it matters most, certification isn’t about credentials. It’s about being resilient and ready to recover.

FAQs

Q: What is the purpose of the Readiverse-Akademie certification program?

A: Das Programm bietet einen strukturierten, kompetenzorientierten Lernpfad, der Fachkräften dabei hilft, platform von den Grundlagen platform bis hin zu fortgeschrittenem Fachwissen cloud auszubauen. Es stimmt die Schulungen auf die Aufgaben in der Praxis ab, damit die Teilnehmer ihr Wissen in komplexen Umgebungen effektiv anwenden können.

F: Welche verschiedenen Zertifizierungsstufen gibt es?

A: Es gibt vier Stufen: Commvault Cloud , Specialist, Professional und Expert. Jede Stufe baut auf der vorherigen auf und zeichnet sich durch zunehmende technische Tiefe, einen größeren operativen Umfang sowie gestiegene Führungsfähigkeiten aus.

Q: Who should enroll in Readiverse-Akademie courses?

A: Die Kurse richten sich an platform , Sicherheitsspezialisten, cloud und Workload-Verantwortliche, die in SaaS, Software- und Hybridumgebungen tätig sind. Jede dieser Rollen kann einen auf ihre jeweiligen Aufgaben zugeschnittenen Lernpfad absolvieren.

F: Wie erlangt man die Zertifizierungen?

A: Die Zertifizierungen werden durch eine Kombination aus Kursarbeit, praktischen Übungen und validierten Prüfungen erworben. Im Laufe ihrer Ausbildung weisen die Lernenden ein zunehmend höheres Maß an Fachwissen in den Bereichen platform, Sicherheit und Workloads nach.

Q: What happens to existing Readiverse-Akademie certifications?

A: Bestehende Zertifizierungen behalten ihre Gültigkeit als Nachweis früherer Fachkenntnisse, sind jedoch an frühere Produktversionen gebunden. Wenn diese Versionen aus dem Verkehr gezogen werden, läuft die Gültigkeit der Zertifizierungen aus, was die Lernenden dazu anregen soll, auf das neue Programm umzusteigen.

F: Wie kann man mit dem neuen Programm beginnen?

A: Neue Teilnehmer können mit dem Kurs „Commvault Cloud beginnen, während sich bestehende Nutzer anmelden können, um ihre Fortschritte fortzusetzen. Je nach den jeweiligen Zielen stehen weitere Kurse zur Verfügung, beispielsweise zu den Themen Workload-Management oder Strategien zur Cyber-Resilienz.

Suzanne Klausner ist Leiter des Bereichs „Customer Enablement Strategy“ bei Commvault.

More related posts


Thumbnail_Blog-Ready-or-Not-2026

Why Every CIO Needs a ‘Ready. Or Not.’ Mindset

Read more about Why Every CIO Needs a ‘Ready. Or Not.’ Mindset
Thumbnail_Blog_Readiness-Update-2024

Boost Your Cyber Resilience and Readiness

Read more about Boost Your Cyber Resilience and Readiness
Social_Readiverse_Blog_LinkedIn-1

The Readiverse: Your Go-To Learning Resource for Cyber Resilience and Readiness

Read more about The Readiverse: Your Go-To Learning Resource for Cyber Resilience and Readiness

Die wichtigsten Erkenntnisse

  • Herkömmliche Wiederherstellungsabläufe können in von Terraform verwalteten Umgebungen zu einer Infrastrukturabweichung führen, indem neue Ressourcen außerhalb des States bereitgestellt werden.
  • Clumio Backtrack ist darauf ausgelegt, Daten direkt in bestehende S3-Buckets und DynamoDB-Tabellen wiederherzustellen, wodurch die Identität der Ressourcen erhalten bleibt.
  • Die In-Place-Wiederherstellung trägt dazu bei, den Bedarf an manuellen Terraform-Importen, der Neukonfiguration von Endpunkten und der Statusabgleichung während Vorfällen zu reduzieren.
  • Die Ausrichtung der Wiederherstellungsabläufe an den Prinzipien von „Infrastructure as Code“ (IaC) trägt dazu bei, die Konfigurationsintegrität und die Vorhersehbarkeit des Betriebs zu gewährleisten.
  • Die Planung der Wiederherstellung ist für Teams, die Produktionsumgebungen über Terraform betreiben, ebenso entscheidend wie die Planung der Datensicherung.

IaC brings consistency, repeatability, and version control to cloud environments. Terraform becomes the source of truth for what exists, how it is configured, and how it should behave. Recovery introduces a new challenge.

Traditional restore operations often create new resources – new S3 buckets, new DynamoDB tables, new endpoints. From Terraform’s perspective, those resources were not defined in code. They do not exist in state.

That creates drift. In routine operations, drift is manageable. During an incident, it compounds. This is where recovery design matters as much as backup design.

Das Problem der IaC-Abweichung

In einem typischen Wiederherstellungsmodell:

  • Eine geschützte Ressource wird als neue Ressource wiederhergestellt.
  • Die ursprüngliche Ressource befindet sich weiterhin in einem beschädigten, überschriebenen oder fehlerhaften Zustand.
  • Der Terraform-State erkennt die neue Ressource nicht.
  • Teams müssen Ressourcen manuell in den Status importieren.
  • Anwendungskonfigurationen müssen möglicherweise aktualisiert werden.

For platform teams managing production infrastructure through Terraform, this introduces friction at exactly the wrong moment. The challenge isn’t backup reliability itself, but how restore workflows integrate with infrastructure-as-code practices.

Vorstellung der In-Place-Wiederherstellung mit Clumio Backtrack

Clumio Backtrack ist eine Wiederherstellungsfunktion, mit der Daten direkt in bestehende AWS-Ressourcen wiederhergestellt werden können, anstatt eine Ersatzinfrastruktur bereitzustellen. Bei der Konfiguration über den Clumio Terraform-Provider unterstützt Backtrack die Einrichtung von Wiederherstellungsabläufen, die mit der in Code definierten Infrastruktur im Einklang stehen.

Clumio Backtrack unterstützt sowohl Amazon S3 als auch Amazon DynamoDB. Einen tiefergehenden technischen Einblick in die DynamoDB-spezifischen Wiederherstellungsabläufe finden Sie in unserem Blogbeitrag zuClumio Backtrack für DynamoDB.

Anstatt Ersatzressourcen bereitzustellen, hilft Backtrack bei der Wiederherstellung:

  • S3-Objekte direkt in den ursprünglichen Bucket.
  • DynamoDB-Daten direkt in die ursprüngliche Tabelle.

From Terraform’s perspective, the infrastructure is intended to remain unchanged, with defined resources continuing to match the declared configuration. This helps reduce the need for manual resource imports, temporary restore tables, endpoint rewiring, and state reconciliation under pressure.

Ein praktisches Beispiel

Stellen Sie sich eine Produktionsumgebung vor, die vollständig über Terraform verwaltet wird. Eine DynamoDB-Tabelle erfasst den Bestand; ein S3-Bucket speichert Anwendungsressourcen; Rollen und Richtlinien für die Identitäts- und Zugriffsverwaltung sind kodifiziert; und Schutzrichtlinien werden über Terraform definiert. Wenn es vor einem größeren Traffic-Ereignis zu einer Beschädigung kommt, können herkömmliche Wiederherstellungsansätze neue Ressourcen erstellen, die wieder in Terraform integriert werden müssen.

Bei Backtrack ist die Wiederherstellung so konzipiert, dass sie innerhalb der bestehenden Ressourcengrenzen erfolgt, wodurch die definierte Infrastruktur intakt bleibt und die Identität der Ressourcen gewahrt wird. Dieser Ansatz soll die Notwendigkeit beseitigen, Terraform zu aktualisieren, um einen neu erstellten Bucket oder eine neue Tabelle zu berücksichtigen, wobei die Wiederherstellung als Vorgang auf Datenebene und nicht als Austausch der Infrastruktur behandelt wird.

Warum dies für Platform wichtig ist

Für Teams, die auf IaC setzen, sollten Wiederherstellungsabläufe die Identität der Ressourcen, die Zustandsabgleichung, die Konfigurationsintegrität und die Vorhersehbarkeit des Betriebs gewährleisten. Die Wiederherstellung vor Ort trägt zur Erreichung dieser Ziele bei, indem sie Infrastrukturänderungen während Wiederherstellungsvorgängen begrenzt.

Wiederherstellung im Cloud

Backtrack is designed to operate at cloud scale – whether restoring a small number of objects or large datasets. Recovery performance varies based on workload size and environment configuration, but the architectural objective remains consistent: restore data without introducing new infrastructure drift.

For Terraform-driven environments, that distinction matters.

Wo sich dieser Ansatz eignet

Die Wiederherstellung vor Ort ist insbesondere relevant für:

  • DynamoDB-Workloads mit hohem Durchsatz
  • S3-Buckets mit einer großen Anzahl von Objekten
  • Produktionssysteme, die vollständig über Terraform verwaltet werden
  • komplexe Umgebungen, in denen es schwierig ist, Anwendungsabhängigkeiten auf neue Ressourcen umzuleiten

Wenn die Infrastruktur deklarativ definiert wird, sollten sich auch die Wiederherstellungsabläufe an diesem Ansatz orientieren.

Erste Schritte

So erkunden Sie Clumio Backtrack und dessen Integration mit Terraform:

Die Definition von Schutz als Code ist nur ein Teil des Ganzen. Die Entwicklung von Wiederherstellungsabläufen, die die Integrität der Infrastruktur gewährleisten, vervollständigt das Modell.

FAQs

F: Welche Probleme verursachen herkömmliche Wiederherstellungen in von Terraform verwalteten Umgebungen?

A: Bei herkömmlichen Wiederherstellungen werden häufig neue Ressourcen erstellt, wie beispielsweise Ersatz-S3-Buckets oder DynamoDB-Tabellen, die im Terraform-State nicht definiert sind. Dies kann zu einer Abweichung der Infrastruktur führen und Teams dazu zwingen, Ressourcen manuell zu importieren und Konfigurationen während kritischer Vorfälle abzugleichen.

F: Inwiefern unterscheidet sich Clumio Backtrack von herkömmlichen Wiederherstellungsverfahren?

A: Anstatt neue Infrastruktur bereitzustellen, ist Clumio Backtrack darauf ausgelegt, Daten direkt in die bestehende AWS-Ressource wiederherzustellen. Dieser Ansatz trägt dazu bei, die Identität der Ressource zu bewahren und den Terraform-Status mit der deklarierten Konfiguration abzugleichen.

F: Welche AWS-Dienste werden von Clumio Backtrack unterstützt?

A: Clumio Backtrack unterstützt Amazon S3 und Amazon DynamoDB. Die Lösung ist darauf ausgelegt, S3-Objekte im ursprünglichen Bucket und DynamoDB-Daten in der ursprünglichen Tabelle wiederherzustellen, wodurch die Konsistenz mit der in Code definierten Infrastruktur gewahrt bleibt.

F: Warum ist die In-Place-Wiederherstellung für platform wichtig?

A: Platform setzen auf „Infrastructure as Code“, um Konsistenz und Kontrolle zu gewährleisten. Die In-Place-Wiederherstellung trägt dazu bei, die Zustandsübereinstimmung, die Konfigurationsintegrität und die Vorhersehbarkeit des Betriebs aufrechtzuerhalten, ohne dass während Wiederherstellungsvorgängen zusätzliche Änderungen an der Infrastruktur vorgenommen werden müssen.

F: Wann ist eine In-Place-Wiederherstellung besonders sinnvoll?

A: It is especially useful for high-throughput DynamoDB workloads, S3-Buckets mit einer großen Anzahl von Objekten, and production systems fully managed through Terraform. It also can be beneficial in environments where redirecting application dependencies to newly created resources would be complex or risky.

F: Wie können Teams mit der Integration von Clumio Backtrack und Terraform beginnen?

A: Die Teams können dieDokumentation zum Clumio Terraform-Provider, entdecken Sie dieQuellcode des Anbieters auf GitHub, and watch the Backtrack-Demo-Video referenced in the blog to understand implementation and workflow details.

Lawrence Chang ist Chief Engineering Officer bei Clumio und Vir Choksiist Principal Product Marketing Manager bei Commvault.

More related posts


Thumbnail_Blog-AWS-Data-Protection-Terraform-Clumio-2026

Automating AWS Data Protection with Terraform and Clumio

Read more about Automating AWS Data Protection with Terraform and Clumio
Thumbnail_Blog_Clumio-Tech-2025

Restore only what matters: Clumio Backtrack for DynamoDB

Read more about Restore only what matters: Clumio Backtrack for DynamoDB
Thumbnail_Blog-GoogleWorkspace-2026

How the Move to Clumio Delivered 66.7% Savings on AWS Backups

Read more about How the Move to Clumio Delivered 66.7% Savings on AWS Backups
Thumbnail_Blog_AWS-Marketplace-AI

Commvault Featured in New AI Agent Solutions in AWS Marketplace

Read more about Commvault Featured in New AI Agent Solutions in AWS Marketplace
Man-and-woman-working-on-laptops-profile-Crocus-Thumbnail

Protecting Your Amazon S3 Data with Clumio: A Comprehensive Solution

Read more about Protecting Your Amazon S3 Data with Clumio: A Comprehensive Solution

Clumio

Read more about Clumio

Die wichtigsten Erkenntnisse

  • Die meisten Tabletop-Übungen dienen eher der Leistungsüberprüfung als der Aufdeckung tatsächlicher Lücken bei der Reaktion auf Vorfälle.
  • Damit Übungen wirksam sind, müssen sie Reibungspunkte, Unklarheiten und Druck erzeugen, um reale Vorfälle widerzuspiegeln.
  • Wenn man den Umfang der Übung auf einige wenige kritische Szenarien beschränkt und Erfolg nicht darin sieht, einen guten Eindruck zu hinterlassen, sondern vielmehr darin, Probleme aufzudecken, kann dies zu aussagekräftigeren und umsetzbareren Erkenntnissen führen.
  • Eine funktionsübergreifende Beteiligung – nicht nur die der technischen Teams – ist unerlässlich, um die Reaktionsfähigkeit der Organisation genau zu testen.
  • Echte Ausfallsicherheit zeigt sich erst in praktischen Wiederherstellungstests und nicht nur in theoretischen Szenarien.

There is a moment most security leaders recognize, even if they do not say it out loud. The tabletop just wrapped. The team is filing out. Everyone looks reasonably satisfied. And somewhere in the back of your mind, a quiet question surfaces: Did we actually learn anything?

If you are honest, the answer is often no.
That is not because tabletop exercises are a bad idea. They are one of the most valuable tools a security leader has. The problem is how most organizations run them – and what they are actually measuring when they do.

Die Leistungsfalle

The most common mistake in tabletop exercises has nothing to do with the scenario. It has to do with the goal. Most teams, consciously or not, build exercises designed to demonstrate competence rather than discover gaps.
The scenario generally follows a clean arc. Information arrives in a logical sequence. The right people say the right things. Everyone feels prepared. And that feeling – confident, well-rehearsed, almost collegial – is exactly the problem.
Real incidents do not run on clean arcs. They arrive with incomplete information, conflicting signals, unavailable people, and a business demanding answers faster than the facts support. If your tabletop does not create that kind of friction, you have not tested incident response. You have practiced a conversation.
When the exercise is designed to validate rather than stress-test, a second problem follows: People stop being honest. Nobody says, “I don’t know who owns that decision” or “we have never actually tested that recovery path.” They say what sounds right. And the gaps that should surface in a controlled environment stay hidden until they surface in a real one.

Was eine gute Übung tatsächlich testet

Before you build a scenario, you need to answer a simpler question: What do you actually want to learn? Not 20 things. Three or four.
Can your team make a shutdown decision fast enough, and does everyone know who has the authority to make it? When security, IT, legal, and communications are all in the room with conflicting priorities, can they actually reach decisions together? Can you explain the business impact of an incident clearly enough for leadership to act – not just understand? And if you had to restore a critical system in the next four hours, could you really do it?

Once you know what you are testing, build a scenario with real friction. Make a key person unavailable mid-exercise. Introduce a customer escalation. Have a regulator ask a question the team cannot answer from the runbook.
Give people incomplete information and see how they make decisions anyway. The value is not in watching people succeed under pressure. It is in finding the places where the process breaks down while the stakes are still low enough to fix it.

Sagen Sie das gleich zu Beginn laut: Erfolg bedeutet heute, Probleme zu finden, und nicht, einen guten Eindruck zu machen. Dieser eine Satz verändert die Art und Weise, wie sich die Anwesenden äußern.

Das Problem mit den Menschen

Ein Tabletop-Übung, bei der es ausschließlich um Sicherheit und IT geht, ist eine technische Diskussion und keine Übung zur Krisenbewältigung. Wenn die Rechtsabteilung nicht dabei ist, wenn die Kommunikationsabteilung nicht dabei ist, wenn die Geschäftsbereichsleiter und die Geschäftsleitung fehlen, testen Sie nicht, wie Ihre Organisation tatsächlich auf eine Krise reagiert. Sie testen lediglich, wie eine Gruppe kluger Köpfe ein hypothetisches Szenario durchspielt. Tatsächliche Vorfälle werden unternehmensweit bearbeitet. Die Übung sollte dies widerspiegeln.

Darüber zu reden reicht nicht aus

This is where most organizations stop short. A paper exercise is important – but it is not confidence.
Talking through a recovery scenario tells you something. Actually restoring a system tells you something different. Can you bring identity back to a clean point in time? Can you validate that what you are recovering is trustworthy? Can you restore a Tier 1 application and confirm it comes back cleanly, without carrying the infection with it?

Those are not questions you can answer in a conference room. At some point, the plan has to meet the environment – and you need to know whether they match.

Nach Beendigung der Übung

The debrief tells you whether the exercise mattered. If the hot wash is quiet, vague, or full of “good reminders,” the exercise did not push hard enough. A well-run tabletop should leave you with a short list of real findings, clear owners, and deadlines. If you cannot answer what broke, who is fixing it, and by when, you ran an event, not an exercise.
The goal was never to pass the exercise. It was to learn something important while the cost of being wrong was still just time.
Watch our recent episode of the STRIVE podcast, where I join my colleague Chris Mierzwa, Senior Director, Portfolio Marketing, for ein ausführliches Gespräch über Tabletop-Übungen.

FAQs

Frage: Warum bringen die meisten Tabletop-Übungen keinen wirklichen Nutzen?

A: Viele Übungen sind darauf ausgelegt, Teams als gut vorbereitet erscheinen zu lassen, anstatt Schwachstellen aufzudecken. Dies führt zu vorgefertigten Diskussionen, bei denen die Unvorhersehbarkeit und der Druck realer Vorfälle zu kurz kommen.

F: Was sollte das Ziel einer Tabletop-Übung sein?

A: Der Schwerpunkt sollte auf der Beantwortung einer kleinen Anzahl entscheidender Fragen liegen, wie beispielsweise der Geschwindigkeit der Entscheidungsfindung, der Klarheit hinsichtlich der Zuständigkeiten und der Wiederherstellungsfähigkeit. Dieser Fokus hilft den Teams dabei, wesentliche Lücken aufzudecken, anstatt sich mit oberflächlichen Erkenntnissen zu begnügen.

F: Wie können Organisationen Übungen realistischer gestalten?

A: Führen Sie im Verlauf des Szenarios Unsicherheiten, fehlende Informationen und unerwartete Störungen ein. Diese Elemente zwingen die Teams dazu, kritisch zu denken und unter Druck zu handeln – ähnlich wie unter realen Einsatzbedingungen.

F: Wer sollte an einer Tabletop-Übung teilnehmen?

A: Neben den Bereichen Sicherheit und IT sollten auch Teams wie die Rechtsabteilung und die Kommunikationsabteilung sowie Führungskräfte und leitende Angestellte einbezogen werden. So kann die Übung widerspiegeln, wie reale Vorfälle unternehmensweit bewältigt werden.

F: Warum reicht es nicht aus, über die Genesung zu sprechen?

A: Durch Diskussionen lassen sich zwar Pläne verdeutlichen, doch nur durch echte Tests lässt sich nachweisen, ob Systeme tatsächlich einwandfrei und schnell wiederhergestellt werden können. Eine praktische Überprüfung ist erforderlich, um die Wiederherstellungsbereitschaft zu bestätigen.

F: Was macht ein erfolgreiches Ergebnis einer Tabletop-Übung aus?

A: Eine gründliche Übung führt zu klaren Ergebnissen, festgelegten Verantwortlichen und definierten Zeitplänen für die Behebung der Mängel. Fehlen diese Elemente, hat die Übung das Team wahrscheinlich nicht ausreichend gefordert.

Chris Bevil is Principal, Global Cyber Resilience & AI, at Commvault.

More related posts


Readiverse-Featured-Image-888-x-500

Ready Is Good. Resilient Is Better.

Read more about Ready Is Good. Resilient Is Better.
Thumbnail_5_MV_Blogs_2025

Recovery Testing: The Missing Piece in Most Cyber Resilience Programs

Read more about Recovery Testing: The Missing Piece in Most Cyber Resilience Programs
Urgent-Need-for-Cyber-Resilience

The Urgent Need for Cyber Resilience

Read more about The Urgent Need for Cyber Resilience
Thumbnail_Blog_Modern-Playbook-2025

Your Modern Playbook for Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Rapid Response and Clean Recovery

Die wichtigsten Erkenntnisse

  • Commvault’s data access governance, powered by Satori, unifies visibility, access control, and auditability across structured data, unstructured files, SaaS apps, and AI workloads.
  • Eine einheitliche, konsistente Zugriffsrichtlinie kann sowohl für menschliche Nutzer als auch für KI-Modelle gelten und so dazu beitragen, Silos abzubauen und die übermäßige Offenlegung sensibler Daten zu begrenzen.
  • Die kontinuierliche Erfassung, Klassifizierung und Risikobewertung liefern priorisierte Einblicke darüber, wo sich sensible Daten befinden und wo das Risiko einer Offenlegung am höchsten ist.
  • Richtliniengesteuerte dynamische Maskierung und Schwärzung tragen dazu bei, den Zugriff nach dem Prinzip der geringsten Berechtigungen durchzusetzen, wodurch die autorisierte Nutzung von Daten ermöglicht und gleichzeitig der Schutz sensibler Felder gewährleistet wird.
  • Zentralisierte, nahezu in Echtzeit erfasste Prüfpfade bieten einen umfassenden Überblick über Benutzerabfragen, KI-Eingabeaufforderungen und geregelte Zugriffsereignisse und tragen so zur Einhaltung von Vorschriften und zur Nachvollziehbarkeit bei.

With AI now embedded in every workflow, from copilots and chat assistants to analytics tools, all these endpoints have become ravenous for data to ingest. Commvault’s Funktionen zur Steuerung des Datenzugriffs, die auf der Satori-Technologie basieren, wurden entwickelt, um die Leistungsfähigkeit dieser datenintensiven KI zu steigern, indem sie Transparenz, Zugriffskontrolle und Nachvollziehbarkeit in Ihrer gesamten Datenlandschaft vereinen.

Eine einheitliche Grundlage für die Datenverwaltung im Zeitalter der KI

Commvault’s data access governance features bring structured databases, unstructured files in SaaS apps, and AI workloads under one governance model, instead of treating them as separate silos. Organizations now can apply a single access policy to both human users and AI models, so that the same rules determine who or what can see sensitive information, regardless of where it lives.

By integrating Satori into the Commvault | Kommandozentrale, these capabilities extend Commvault’s traditional protection into live data and AI usage, not just backups and snapshots. This helps security and data protection teams move from reactive incident response to proactive control over how data is discovered, accessed, and used in real time.

Kontinuierliche Erkennung, Klassifizierung und Risikobewertung

Eine tragende Säule unserer Datenverwaltungsfähigkeiten isteinheitliche Ermittlung und Klassifizierungvon Daten über Clouds und SaaS hinweg. Wenn Unternehmen Verbindungen zu Umgebungen wie AWS, Azure, Google Cloud, Snowflake, Databricks und anderen herstellen, ordnet Commvault die Datenspeicher automatisch zu und klassifiziert sie kontinuierlich, unabhängig davon, ob es sich um strukturierte oder unstrukturierte Daten handelt.Jedem Vermögenswert wird eine Risikobewertung zugewiesen, wodurch Teams einen nach Prioritäten geordneten Überblick darüber erhalten, wo sich sensible Informationen befinden und wo das Risiko am größten ist. Anstatt sich auf regelmäßige Scans zu verlassen, platform die platform mit Datenbewegungen, neuen Speicherorten und Änderungen der Klassifizierung Schritt und hilft den Teams so, Probleme früher zu erkennen und sich zunächst auf die Bereiche mit dem höchsten Risiko zu konzentrieren.

Zugriff nach dem Prinzip der geringsten Berechtigungen mit dynamischer Maskierung und Schwärzung

Traditional data protection often stops at knowing where sensitive data is; Commvault’s capabilities emphasize controlling how that data is revealed. Using policy-driven masking and redaction, organizations can enforce least-privilege access so that users, services, and AI models only see the specific information they are authorized to see, with sensitive fields anonymized or hidden as needed.

Because the same masking and redaction policies apply across all connected environments, organizations can consistently safeguard access instead of fragmented, application-by-application rules. This helps reduce the risk of data overexposure, where too many people or systems have access to more data than they legitimately need.

Sicherheit und sicherer Umgang mit Prompts

A standout capability is policy-driven AI security that operates at the prompt and response level. Before data is ever sent to an AI model, Commvault, powered by Satori, can intercept the interaction, detect sensitive fields (such as regulated personal details), and apply inline masking or redaction according to existing data access policies.

Unlike solutions that simply block entire prompts or rely solely on downstream data loss prevention (making security someone else’s concern), this approach allows employees to keep using AI assistants productively while keeping sensitive data under governance. Because redaction occurs before the model processes the data, it also helps prevent sensitive information from influencing or contaminating AI training datasets, protecting both the users and the broader AI environment.

Zentralisierte Prüfpfade unterstützen die Einhaltung von Vorschriften

The final piece of our Funktionen zur Steuerung des Datenzugriffs is umfassende, zentralisierte Protokollierung von Audits. Every interaction – whether a user query, an AI prompt, or a governed access event – is captured with details such as who accessed what, which policy was applied, and what redactions occurred, in near–real time.

This unified audit visibility spans live data, AI prompts, and access governance events, giving security, IT, and compliance leaders a single authoritative record rather than disparate logs from point tools. For CISOs and CIOs, this means faster compliance reviews and clear proof that governance is not just documented on paper but actively enforced across the environment.

Unterstützung von Unternehmen bei der sicheren Einführung von KI

Insgesamt bieten diese neuen Funktionen Unternehmen einen ganzheitlichen Ansatz für die Datenverwaltung in einer KI-gestützten Welt: einheitliche Transparenz über Clouds, SaaS und KI hinweg; eine einheitliche Richtlinie für Nutzer und Modelle; dynamische Maskierung und Schwärzung für den Zugriff nach dem Prinzip der geringsten Berechtigungen; sowie richtlinienkonformer Schutz von KI-Prompts, gestützt durch lückenlose Prüfpfade. Das Ergebnis ist ein Wandel von reaktiven Kontrollen hin zu einer proaktiven, KI-fähigen Datenzugriffssteuerung, die Teams dabei unterstützt, KI-Innovationen zu nutzen und gleichzeitig die Kontrolle über ihre sensibelsten Informationen zu behalten.

FAQs

Q: What makes Commvault’s approach to AI data governance different from traditional data protection?

A: Der herkömmliche Datenschutz konzentriert sich oft auf Backups und die Reaktion auf Vorfälle, nachdem eine Datenpanne bereits eingetreten ist. Commvault erweitert die Governance auf Live-Umgebungen und KI-Interaktionen und ermöglicht so eine proaktive Kontrolle darüber, wie Daten in Echtzeit ermittelt, abgerufen und genutzt werden. Dieser Wandel hilft Unternehmen dabei, Risiken zu bewältigen, bevor sie zu einer Datenpanne führen.

Q: How does einheitliche Ermittlung und Klassifizierung improve security?

A: Durch kontinuierliche Erfassung und Klassifizierung werden strukturierte und unstrukturierte Daten über Clouds und SaaS-Plattformen hinweg automatisch abgebildet und gekennzeichnet. Indem jedem Asset Risk-Werte zugewiesen werden, erhalten Teams einen nach Prioritäten geordneten Überblick über die Gefährdung sensibler Daten. Dies trägt dazu bei, Bereiche mit hohem Risiko schneller zu identifizieren und Abhilfemaßnahmen gezielter durchzuführen.

F: Was ist dynamische Maskierung und warum ist sie für KI-Workloads wichtig?

A: Durch dynamische Maskierung und Schwärzung wird anhand vordefinierter Richtlinien eingeschränkt, was Benutzer, Dienste und KI-Modelle einsehen können. Sensible Felder können anonymisiert oder ausgeblendet werden, während der berechtigte Zugriff auf relevante Daten weiterhin möglich bleibt. Dieser Ansatz fördert die Produktivität und trägt gleichzeitig dazu bei, das Risiko einer übermäßigen Offenlegung zu verringern.

F: Wie funktioniert der richtlinienbasierte Schutz vor KI-Prompts?

A: Eine richtlinienbasierte KI-Sicherheit fängt Eingabeaufforderungen und Antworten ab, bevor die Daten das KI-Modell erreichen. Sie hilft dabei, sensible Informationen zu erkennen und entsprechend den bestehenden Richtlinien eine Inline-Maskierung oder -Schwärzung vorzunehmen. Auf diese Weise können Mitarbeiter KI-Tools weiterhin nutzen, während regulierte Daten unter Kontrolle bleiben und nicht in Trainingsdatensätze gelangen.

F: Inwiefern unterstützen zentralisierte Prüfpfade die Bemühungen zur Einhaltung von Vorschriften?

A: Eine umfassende Audit-Protokollierung erfasst Details darüber, wer auf welche Daten zugegriffen hat, welche Richtlinien angewendet wurden und welche Schwärzungen vorgenommen wurden. Diese einheitliche Transparenz erstreckt sich sowohl auf Live-Daten als auch auf KI-Interaktionen und bietet Sicherheits- und Compliance-Verantwortlichen damit eine klare und verbindliche Dokumentation. Dies ermöglicht schnellere Überprüfungen und belegt, dass Governance-Kontrollen aktiv durchgesetzt werden.

F: Inwiefern helfen diese Funktionen Unternehmen dabei, KI sicher einzuführen?

A: By combining unified visibility, consistent policy enforcement, dynamic masking, and complete audit trails, Commvault’s data governance capabilities help give organizations a cohesive framework for governing AI-era data. These controls help enable innovation while helping maintain control over sensitive information. The result is a more confident and safe path to AI adoption.

Nico Guerrera ist Senior Technical Marketing Manager bei Commvault.

More related posts


Social_Blog_Satori_GigaOm_Leader_2026_Linkedin

Satori Named Leader in GigaOm’s Data Access Governance Radar Report

Read more about Satori Named Leader in GigaOm’s Data Access Governance Radar Report
Thumbnail_Blog-Conversational-Resilience-2025-Linkedin

Conversational Resilience: The New Way to Manage and Protect Enterprise Data

Read more about Conversational Resilience: The New Way to Manage and Protect Enterprise Data
Thumbnail_Blog_Satori-Acquisition-2025

Commvault Closes Acquisition of Satori, Strengthening Data and AI Security Platform

Read more about Commvault Closes Acquisition of Satori, Strengthening Data and AI Security Platform
Thumbnail_Blog-Data-Rooms-2025-Linkedin

Data Activate: Unlocking the Power of Trusted Data for AI Innovation

Read more about Data Activate: Unlocking the Power of Trusted Data for AI Innovation

Die wichtigsten Erkenntnisse

  • Die Identitätsinfrastruktur stellt eine primäre Angriffsfläche dar, deren Kompromittierung den Geschäftsbetrieb zum Erliegen bringen kann.
  • Commvault’s vulnerability assessment helps highlight misconfigurations and risky settings through clear exposure indicators and remediation guidance.
  • Mithilfe von Echtzeit-Audits können Teams subtile böswillige Änderungen sofort erkennen und die Aktivitäten von Angreifern in Echtzeit nachverfolgen.
  • Ein Rollback mit einem Klick kann dazu beitragen, unbefugte Änderungen schnell rückgängig zu machen, wodurch Ausfallzeiten minimiert und die Ausbreitung von Angriffen eingedämmt werden können.

Cybersicherheit und die Bedeutung der Identität

When most people think about cybersecurity, they picture stolen files or encrypted databases. But there’s a layer underneath all of that which, if compromised, makes everything else irrelevant – your Identitätsinfrastruktur.​

Identity management systems like Aktives Verzeichnis(AD),Entra IDundOkta are the systems that decide who gets to log in, what they can accessundwhether your business can function at all. When attackers get in there, users can’t authenticate, applications go darkundoperations grind to a halt. It’s not a data problem at that point, it’s a control problem.​

Automatisierte Wiederherstellung von Wäldern with clean OS rebuilds helps enable organizations to restore identity systems securely without reintroducing threats. Here’s how.

Know What You’re Vulnerable to Before the Attackers Do

Commvault’s vulnerability assessment gives your AD environment a posture score.  Think of it like a health grade for your directory. Most environments have more exposure than people realizeundthis makes that visible.​

Our tool helps surface indicators of exposure (IOEs), which are specific misconfigurations or risky settings that could be exploited. One common example is accounts with passwords set to never expire. Stale, non-rotating credentials are one of the most common ways attackers maintain long-term access to an environment.

Commvault doesn’t just flag the issue, it helps identify which accounts are affected, walks through remediation stepsundlets you export the list to help simplify scripting the fix.

Catch It While It’s Happening

Knowing your weaknesses is step one. Seeing when someone is actively exploiting them is step two.

Commvault’s identity management auditing helps capture a real-time feed of every change made to identity systems like Aktives Verzeichnis and Entra ID – details like who made the change, when, from whereundwhat the values looked like before and after.

Attackers don’t usually blow the doors off; they make subtle, targeted changes. A compromised account might create a backdoor user, quietly add it to domain admins, then link a malicious Group Policy Object (GPO) designed to deploy ransomwareundevery one of those steps shows up in the audit feed.​

Once you spot a suspicious account, filtering can help you instantly pull up every change that account ever made, helping give you the full picture of what the attacker touched.​

Den Schaden schnell beheben

Detection only matters if you can act on it. From the same auditing view, you can roll back a malicious change with a single click, helping restore the environment to its last known good state without jumping between tools or writing a custom script. The aim is to help minimize downtime and limit how far the attack spreads before it is caught.​

Wenn das Schlimmste eintritt: Wiederaufforstung

Sometimes an attack gets throughundyou need to rebuild from scratch. AD forest recovery, rebuilding your entire directory environment after a ransomware hit, is notoriously complex, often involving 50 to 100+ individual steps, depending on how many domains and domain controllers you have.​

Commvault helps automate this with orchestrated runbooks that sequence every step: Rebuilding domain controllers in the right order based on their flexible single master operation (FSMO) roles, restoring SYSVOL, verifying metadataundre-establishing trust between domains. A topology view of the entire AD forest helps make it visually clear which domain controllers should come back online first.​

The standout piece here is what Commvault calls Clean OS Recovery. Instead of restoring potentially compromised virtual machines, it rebuilds domain controllers on brand-new VMs. Restoring an infected machine risks bringing the malware right back with it. Recovering onto fresh infrastructure means you’re not just getting your data back; you’re actually starting clean.​

Ein Dashboard für lokale Systeme und Cloud

Most organizations today aren’t running purely on-premises or purely in the cloud, they’re hybrid, with AD handling legacy access and Entra ID handling modern cloud-based identities. Commvault’s unified control plane can help cover both from a single console: assessments, auditing, detectionundrecovery across both platforms.​

The value is straightforward: fewer tools, less complexityunda cleaner story to tell leadership when they ask how Identitätsinfrastruktur is being protected end to end.​

Identity resilience deserves its own dedicated conversation, separate from making backups and separate from protecting endpoints. The combination of proactive vulnerability scanning, real-time change auditing, fast rollbackundclean forest recovery helps your organization treat your directory infrastructure as a security priority in its own right.

FAQs

Q: Why is Identitätsinfrastruktur such a critical security focus?

A: Identitätssysteme regeln die Authentifizierung und den Zugriff innerhalb einer Organisation. Werden sie kompromittiert, können Angreifer den Betrieb vollständig lahmlegen, wodurch andere Sicherheitsmaßnahmen wirkungslos werden.

F: Was sind Expositionsindikatoren (IOEs)?

A: IOEs sind bestimmte Fehlkonfigurationen oder risikobehaftete Einstellungen in Identitätsumgebungen, die Angreifer ausnutzen können. Ihre Aufdeckung kann Einblicke in Schwachstellen liefern und den Teams als Orientierungshilfe bei deren Behebung dienen.

F: Wie trägt die Echtzeit-Überwachung dazu bei, Angriffe abzuwehren?

A: Durch Echtzeit-Audits lassen sich alle Änderungen in Identitätssystemen nachverfolgen, einschließlich der Informationen, wer die Änderung vorgenommen hat und was sich geändert hat. Diese Transparenz hilft Sicherheitsteams dabei, verdächtiges Verhalten frühzeitig zu erkennen und den gesamten Umfang eines Angriffs zu untersuchen.

F: Können böswillige Änderungen wirklich schnell rückgängig gemacht werden?

A: Ja, Commvault ermöglicht die direkte Rückgängigmachung nicht autorisierter Änderungen über dieselbe Benutzeroberfläche. Dies trägt dazu bei, die Reaktionszeit zu verkürzen und Systeme ohne komplexe Skripte in einen sicheren Zustand zurückzusetzen.

F: Was macht die Wiederherstellung einer AD-Gesamtstruktur so schwierig?

A: Der Wiederaufbau einer AD-Gesamtstruktur umfasst viele miteinander verknüpfte Schritte, darunter die Wiederherstellung von Domänencontrollern und die erneute Einrichtung von Vertrauensbeziehungen. Die Komplexität steigt mit der Größe der Umgebung.

Q: What is Commvault’s Clean OS Recoveryundwhy does it matter?

A: „Clean OS Recovery“ unterstützt die Neuinstallation von Domänencontrollern auf neuen, nicht kompromittierten Systemen, anstatt infizierte Rechner wiederherzustellen. Dieser Ansatz trägt dazu bei, verbleibende Malware zu beseitigen und ermöglicht eine sichere Wiederherstellung.

Nico Guerrera ist Senior Technical Marketing Manager bei Commvault.

More related posts


Thumbnail_Blog-Okta-Early-Access-2026

Commvault® Extends Identity Resilience to Okta

Read more about Commvault® Extends Identity Resilience to Okta
Thumbnail_Blog-Lateral-Access-2026

Staying Resilient Against Lateral Access Exploits

Read more about Staying Resilient Against Lateral Access Exploits
Thumbnail_Blog-Linkedin 1

Security Best Practices

Read more about Security Best Practices

Die wichtigsten Erkenntnisse

  • Die Verwaltung von Backups und Wiederherstellungen als „Infrastructure as Code“ (IaC) trägt dazu bei, Konfigurationsabweichungen zu reduzieren und den Datenschutz an moderne cloud anzupassen.
  • Der Clumio Terraform-Provider ermöglicht es, AWS-Konten, Richtlinien und Schutzregeln deklarativ und versionsverwaltet zu definieren.
  • Der tagbasierte Schutz ist darauf ausgelegt, bestehende und zukünftige Ressourcen automatisch zu schützen, wodurch manuelle Eingriffe reduziert werden und eine effiziente Skalierung über verschiedene Umgebungen hinweg ermöglicht wird.
  • Die Definition von Backup-Richtlinien in Terraform trägt dazu bei, die Transparenz, Reproduzierbarkeit und Governance durch standardisierte Pull-Request-Workflows zu verbessern.
  • Dieser Ansatz kann insbesondere für AWS-Umgebungen mit mehreren Konten und für Unternehmen von großem Nutzen sein, die bereits auf Terraform standardisiert sind.

Cloud wird zunehmend als Code definiert. EC2-Instanzen, IAM-Rollen (Identity and Access Management), virtuelle private Clouds und Datenbanken befinden sich mittlerweile in versionsverwalteten Repositorys und werden vorhersehbar über IaC bereitgestellt. Allerdings werden Backup and Recovery-Richtlinien oft noch manuell in Webkonsolen konfiguriert. Diese Lücke birgt Risiken. Wenn die Infrastruktur deklarativ ist, der Datenschutz jedoch nicht, gehen Teams folgende Risiken ein:

  • Konfigurationsabweichung.
  • Uneinheitliche Schutzmaßnahmen bei den verschiedenen Konten.
  • Manuelle Fehler.
  • Begrenzte Transparenz darüber, was tatsächlich geschützt ist.

For organizations already using Terraform, backup and recovery should be managed the same way as the rest of the stack – through code.Clumio’s Terraform provider enables AWS data protection to be defined declaratively alongside infrastructure. You can explore the provider and its documentation here: https://registry.terraform.io/providers/clumio-code/clumio/latest/docs/guides/getting_started.In this post, we’ll walk through how to automate AWS workload protection using Terraform and Clumio von Commvault – and why that approach scales more effectively for modern cloud teams.

Das Problem bei der Konfiguration von Backups über die Konsole

In einer herkömmlichen Konfiguration sind für den Schutz von AWS-Ressourcen folgende Maßnahmen erforderlich:

  • AWS-Konten verbinden.
  • Separate Konfiguration des Schutzes über mehrere AWS-Dienste hinweg.
  • Erstellen von Sicherungsrichtlinien.
  • Schutzregeln definieren.
  • Ressourcen manuell zuweisen.
  • Diesen Vorgang für jedes Konto bzw. jede Umgebung wiederholen.

Selbst in gut geführten Umgebungen führt dies zu:

  • Sich wiederholende manuelle Konfiguration.
  • Uneinheitliche Anwendung der Richtlinien.
  • Verzögerter Schutz für neu erstellte Ressourcen.
  • Eingeschränkte Versionskontrolle.

Terraform trägt bereits dazu bei, dieses Problem im Bereich der Infrastruktur zu lösen. Der Clumio Terraform-Provider erweitert dieses Modell auf den Bereich der Datensicherung.

From Zero to Protected – Using Four Files

Der Schutz mehrerer AWS-Dienste lässt sich mithilfe einer kleinen Anzahl von Terraform-Dateien definieren, anstatt eine Abfolge manueller Schritte über die Benutzeroberfläche ausführen zu müssen.

Die Konfiguration folgt einer übersichtlichen Struktur.

  1. Anbieter definieren (AWS + Clumio)

Der erste Schritt besteht darin, die Provider zu deklarieren. Terraform benötigt folgende Informationen:

  • You’re using AWS.
  • You’re using the Clumio provider.

Dadurch wird Terraform mit beiden Plattformen verbunden. In der offiziellen Provider-Dokumentation wird diese Einrichtung ausführlich beschrieben in derLeitfaden für den Einstieg.

  1. AWS-Konten mit Clumio verbinden

Next, the Clumio module establishes the connection between AWS and Clumio. This abstracts away the IAM role configuration required for data protection. Instead of manually configuring roles and permissions, the module handles the integration in a repeatable way.The Quellcode des Anbieters is publicly availableauf GitHub.This means your integration is defined in code, version-controlled and reproducible across environments.

  1. Backup-Richtlinien als Code definieren

Bei der Definition von Backup-Richtlinien spielt IaC seine Stärken voll aus. In einer Terraform-basierten Konfiguration:

  • Für verschiedene Ressourcentypen können unterschiedliche Wiederherstellungsziele festgelegt werden.
  • Innerhalb derselben Richtlinie können mehrere Aufbewahrungsstufen definiert werden (beispielsweise kurzfristige und langfristige Aufbewahrung).
  • Die gleiche Richtlinie kann auf der Grundlage festgelegter Bedingungen automatisch angewendet werden.

Instead of navigating multiple consoles, a single Terraform configuration defines frequency, retention, and resource scope. That policy is reusable and reviewable like any other infrastructure configuration.

  1. Tag-basierter automatischer Schutz

Eines der skalierbarsten Elemente dieses Ansatzes ist der tagbasierte Schutz. Eine Schutzregel kann so konfiguriert werden, dass sie automatisch jede Ressource schützt, die mit einem bestimmten Schlüssel-Wert-Paar gekennzeichnet ist. Zum Beispiel: created_by = demo_script Das bedeutet:

  • Bereits vorhandene Ressourcen, die diesem Tag entsprechen, sind geschützt.
  • Zukünftige Ressourcen mit diesem Tag werden automatisch einbezogen.
  • Es ist kein manuelles Eingreifen erforderlich.

For S3 specifically, protection groups also use tags to manage hundreds of buckets as a single logical unit, allowing centralized policy changes at scale. This helps reduce configuration drift.

Anwenden der Konfiguration

Once defined, Terraform initializes the working directory, previews planned changes, and applies the configuration. Terraform is designed to respect dependencies between resources, creating them in the correct order.The configuration helps connect AWS accounts, activate policies, enforce protection rules, and protect tagged resources. And critically – the entire protection strategy exists in version-controlled code.

Warum dies für Cloud von Bedeutung ist

For teams operating with IaC principles, backup configuration should follow the same discipline as infrastructure provisioning.Defining backup in Terraform provides several practical benefits:

  • Versionskontrolle: Backup-Richtlinien werden im Code definiert und können über standardmäßige Pull-Request-Workflows überprüft, versioniert und genehmigt werden.
  • Reproduzierbarkeit: Die gleiche Konfiguration kann einheitlich in Entwicklungs-, Staging- und Produktionsumgebungen bereitgestellt werden.
  • Geringere Abweichungen: Terraform-Konfigurationen können erneut angewendet werden, um den deklarierten Zustand durchzusetzen. So lassen sich manuelle oder außerhalb des regulären Prozesses vorgenommene Änderungen wieder mit der beabsichtigten Konfiguration in Einklang bringen.
  • Klare Transparenz: Die Schutzlogik ist im Code sichtbar und nicht in der UI-Konfiguration verborgen.
  • Trennung von Konfiguration und Schnittstelle: Der Backup- Status wird deklarativ definiert und ist unabhängig vom Konsolenstatus.

Wann dieser Ansatz sinnvoll ist

Die Automatisierung von Backups mit Terraform ist besonders nützlich für:

  • AWS-Umgebungen mit mehreren Konten.
  • Regulierte Branchen, die eine überprüfbare Konfiguration erfordern.
  • Platform , die die gemeinsam genutzte Infrastruktur verwalten.
  • Unternehmen, die bereits auf Terraform umgestellt haben.

If your infrastructure is defined as code, your data protection strategy should be too.

Erste Schritte

Um diesen Ansatz weiter zu untersuchen:

Sie können Clumio auch über dieAWS-Marktplatz.

FAQs

F: Warum sollten Backup-Richtlinien als Code verwaltet werden?

A: Wenn die Infrastruktur als Code definiert wird, die Backup-Richtlinien jedoch manuell konfiguriert werden, kann es zu Lücken und Inkonsistenzen kommen. Die Verwaltung von Backups als Code trägt dazu bei, den Datenschutz an die Bereitstellungsabläufe anzupassen, manuelle Fehler zu reduzieren und eine versionsverwaltete Transparenz Ihrer Datensicherungsstrategie zu gewährleisten.

F: Was ermöglicht der Clumio Terraform-Provider?

A: The Clumio Terraform provider allows AWS data protection resources – such as account connections, backup policies, and protection rules – to be defined declaratively. This helps enable teams to manage backup configurations alongside infrastructure in the same Terraform workflow.

F: Inwiefern verbessert der tagbasierte Schutz die Skalierbarkeit?

A: Der tagbasierte Schutz ist so konzipiert, dass Richtlinien automatisch auf alle Ressourcen angewendet werden, die einem bestimmten Schlüssel-Wert-Paar entsprechen. Dies trägt zum Schutz bestehender und zukünftiger Ressourcen bei, ohne dass eine manuelle Zuweisung erforderlich ist, und erleichtert die Verwaltung des Schutzes in großem Maßstab über Konten und Dienste hinweg.

F: Wie trägt Terraform dazu bei, Konfigurationsabweichungen in Backup-Umgebungen zu reduzieren?

A: Terraform verwaltet einen deklarierten Zustand für Infrastruktur- und Sicherheitsrichtlinien. Durch das erneute Anwenden von Konfigurationen lassen sich manuelle oder außerhalb des regulären Prozesses vorgenommene Änderungen wieder mit dem beabsichtigten Zustand in Einklang bringen, was zur Verbesserung der Konsistenz über alle Umgebungen hinweg beiträgt.

F: In welchen Fällen ist die Automatisierung von Backups mit Terraform am sinnvollsten?

A: Dieser Ansatz ist besonders vorteilhaft in AWS-Umgebungen mit mehreren Konten, in regulierten Branchen, die nachprüfbare Konfigurationen erfordern, bei platform , die gemeinsam genutzte Dienste verwalten, sowie in Unternehmen, die Terraform bereits als Standard für IaC einsetzen.

F: Wie können Teams mit der Terraform-basierten AWS-Datensicherung beginnen?

A: Die Teams können damit beginnen, dieDokumentation zum Clumio Terraform-Provider, bei der Erkundung derprovider’s GitHub source code, und sich die Schnellstart-Demo anzusehen. Clumio über dieAWS-Marktplatzist ebenfalls ein sinnvoller nächster Schritt.

Lawrence Chang ist Chief Engineering Officer bei Clumio und Vir Choksiist Principal Product Marketing Manager bei Commvault.

More related posts


Thumbnail_Blog-GoogleWorkspace-2026

How the Move to Clumio Delivered 66.7% Savings on AWS Backups

Read more about How the Move to Clumio Delivered 66.7% Savings on AWS Backups
Thumbnail_Blog_AWS-Marketplace-AI

Commvault Featured in New AI Agent Solutions in AWS Marketplace

Read more about Commvault Featured in New AI Agent Solutions in AWS Marketplace
Man-and-woman-working-on-laptops-profile-Crocus-Thumbnail

Protecting Your Amazon S3 Data with Clumio: A Comprehensive Solution

Read more about Protecting Your Amazon S3 Data with Clumio: A Comprehensive Solution
Zz05MThhZTc3NmU0MTQxMWVmYTYwZWJlYTg2ZTllNjQ5Yw

A Blueprint for Effective Cloud Recovery

Read more about A Blueprint for Effective Cloud Recovery

Clumio

Read more about Clumio

Every organization that has ever failed a recovery – and there are more than anyone publicly acknowledges – had one thing in common: They believed they could recover before they tried.

The belief came from somewhere. A completed tabletop exercise. A backup system that showed green. An annual disaster recovery test that passed. All of it documented. All of it, at some point, accurate. None of it current when the incident actually hit.

This is the confidence gap. And it is the gap that continuous recovery validation is designed to close.

What ‘Testing’ Actually Means in Most Organizations

Fragt man die meisten Sicherheits- oder IT-Verantwortlichen, wie oft sie ihre Wiederherstellungsfähigkeit testen, lautet die Antwort in der Regel „einmal jährlich“, manchmal „zweimal jährlich“. Der Test umfasst die Wiederherstellung eines Teils der Systeme aus dem Backup in eine Testumgebung, die Überprüfung, ob diese ordnungsgemäß hochfahren, und die Erstellung eines Berichts. Manchmal wird parallel dazu eine Tabletop-Übung durchgeführt. Was diese Art von Tests nicht leisten: zu überprüfen, ob die Backup-Daten frei von Malware sind. Zu bestätigen, dass die Recovery-Reihenfolge bei voneinander abhängigen Diensten funktioniert. Die Recovery von Identitäten wird nicht getestet, obwohl dies unerlässlich ist, wenn kompromittierte Anmeldedaten den Angriff erst ermöglicht haben. Es wird nicht überprüft, ob das Team, das die Recovery tatsächlich durchführen würde, die aktuellen Runbooks kennt. Und es werden keine aussagekräftigen Nachweise erbracht, die eine Aufsichtsbehörde, einen Wirtschaftsprüfer oder den Vorstand davon überzeugen könnten, dass die Recovery-Fähigkeit real und aktuell ist. Kurz gesagt: Es dient der Validierung eines bestimmten Zeitpunkts. Resilience Operations (ResOps) erfordern eine kontinuierliche Validierung.

Das Modell der kontinuierlichen Validierung

Continuous recovery validation is not a single test run more frequently. It is a set of integrated practices that produce ongoing, evidence-based proof of recoverability across critical services.

Automated backup integrity scanning. Every backup, continuously evaluated for anomalies, encryption patterns, and malware signatures. Not at restore time – before restore time. The goal is to know whether your recovery points are clean before you need them, not during an incident.

Scheduled Cleanroom Recovery drills. Bi-annual at minimum, restoring from immutable backup points into an isolated Cleanroom Recovery environment – not production, not a production-adjacent test environment, but a genuinely isolated space where forensic analysis can happen without risk of reinfection. These drills produce documented evidence of recoverability against defined impact tolerances.

Identity recovery validation. With der Missbrauch von Anmeldedaten der häufigste Angriffsvektor, Active Directory and Entra ID recovery must be tested alongside data recovery. Organizations that restore systems without restoring a verified-clean identity layer may find attackers re-enter through the same door.

Service Resilience Indicator (SRI) dashboards. SRIs – continuous signals drawn from backup telemetry, dependency mapping, and test results – that give CISOs, CIOs, and boards a live view of recoverability posture. Not a point-in-time report. An ongoing operational signal.

Each of these practices feeds what Deloitte and Commvault call the resilience backlog: a continuously updated, prioritized list of gaps identified through testing and tracked to resolution. It is the mechanism by which validation drives improvement rather than just producing reports.

Was bedeutet die mittlere Zeit bis zur Wiederherstellung nach einem Ausfall?

Traditional recovery metrics – recovery time objective (RTO) and recovery point objective (RPO) – measure speed and data recency. They say nothing about whether the data being restored can be trusted. Mean Time to Clean Recovery (MTCR) fills that gap: It measures the time required to restore data that is verifiably clean, not just technically available.

MTCR matters because in a ransomware incident, the adversary’s goal is often to corrupt recovery options, not just encrypt production systems. An organization that restores quickly but restores from a compromised backup has not recovered. It has re-infected itself.

Building MTCR into your resilience measurement framework, alongside RTO and RPO, changes what you optimize for and what you report to the board. Speed plus recency plus integrity: that is the complete picture of recovery readiness.

Nachweisbare Resilienz

The organizations that navigate cyber disruptions with the least damage share one characteristic: They treat recovery capability as something to be continuously demonstrated, not periodically asserted. They know their MTCR. Their SRIs are current. Their cleanroom recovery has been tested in the last 90 days.

That posture is not the result of better technology alone. It is the result of an operating discipline – ResOps – that makes resilience continuous, measurable, and governable. Commvault’s platform provides the technical foundation: clean recovery, automated validation, and the unified visibility across data, identity, and services that ResOps requires at scale.

For the organizational side of that equation – how to define impact tolerances, align executive leadership, and build the governance structure that sustains the discipline – see the Deloitte companion blog, „The Resilience Conversation Your Board Isn’t Having Yet. Das vollständige ResOps-Framework, einschließlich der sechs ResOps-Bereiche und des Bewertungsmodells, das die technische Wiederherstellbarkeit mit der Rechenschaftspflicht auf Vorstandsebene verknüpft, finden Sie im gemeinsamen Whitepaper:„From Minimum Viability to Operational Resilience: ResOps in Practice.Bill O’Connell ist Chief Security Officer bei Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Cloud uns Flexibilität bieten, zusammen mit:

  • Erstklassige Dienstleistungen.
  • Cloud Innovation.
  • Keine Bindung an einen bestimmten Anbieter.

But when a cyber incident hits, that flexibility often becomes complexity.
In this episode of STRIVE, I sat down with Senior Director of Product Management Akshay Joshi – whose career spans IBM, AWS, Microsoft, Clumio, and now Commvault – to unpack one uncomfortable truth: Most organizations think they’re ready for multi-cloud recovery.
Until they’re not. Watch the gesamte Folge.

Das Wichtigste auf einen Blick: WasCloud wirklich erfordert

  • Backup at the service level doesn’t equal recovery at the application level. Protecting individual data sources is not the same as restoring a synchronized application ecosystem.
  • Recovery complexity multiplies across clouds. Different recovery points, different accounts, different admin teams – each adds friction when time matters most.
  • Native hyperscaler tools are necessary – but not sufficient. They protect within their own cloud but don’t orchestrate across clouds.
  • Isolation is the first domino in a cyber event. The larger the environment’s aperture, the harder it is to contain impact.
  • Resilience must be designed in – not retrofitted later. Dependency mapping and recovery planning should begin at application design, not after deployment.
  • AI-enabled automation adds power – and new risk. Agentic workflows require tight permission controls and governance discipline.

The Gap Between “On Paper” and Reality

On paper, recovery seems simple: When do you recover to? What do you recover? Where do you recover it?

But, as Akshay explains, each of those questions fractures in a multi-cloud world. Different services may have different recovery points. Some microservices may be impacted while others aren’t. Recovery may require re-architecting if restored cross-regionally or cross-account.
What looks straightforward in documentation becomes deeply complex in execution. And when ransomware hits, teams don’t calmly reference playbooks – they scramble.

Der erste Dominostein: Isolation

Each threat vector expands proportionally with environmental complexity. Multi-cloud doesn’t just diversify infrastructure – it expands operational aperture.

Sicherung auf Service-Ebene vs. Wiederherstellung auf Anwendungsebene

Here’s where most organizations get caught.
They back up:

  • Azure-Daten mit Azure Backup
  • AWS-Daten mit AWS Backup
  • Google Cloud mit einem separaten Tool

Individually, each service may be protected. Collectively, the application may not be recoverable in a synchronized state.
Native tools don’t communicate across clouds. They aren’t inherently multi-cloud in orchestration. They aren’t tuned to optimize recovery time objective (RTO) or recovery point objective (RPO) at scale for cross-cloud architectures.
And when recovery depends on aligning multiple data sources across hyperscalers, orchestration becomes the difference between hours and days. This is exactly why unified recovery strategies exist – not to replace hyperscalers, but to coordinate them.

Dependency Mapping Isn’t Optional Anymore

We’ve been talking about application dependency mapping for more than a decade. But in a multi-cloud world, it’s no longer a “nice to have.” Applications now span multiple hyperscalers, multiple DevOps teams, multiple admin domains, and multiple vendor backup tools.
Fragmented ownership slows recovery. Vendor fragmentation complicates orchestration. Operational silos create delays at the worst possible time. Resilience must be operationalized from the beginning – not bolted on after deployment.

Ein kleiner Einblick: WarumCloud ohne Abhängigkeitszuordnung scheitert

In this moment from the STRIVE conversation, Akshay explains why operationalizing resilience at the architecture stage is critical for surviving real-world cyber events.

Designing for Recovery – Not Just Protection

One of the most powerful points in this episode: Modern applications should be designed not only around performance and scale – but around recoverability. That means:

  • Ich denke genauso viel über RTO nach wie über RPO.
  • Architektur unter Berücksichtigungcloud .
  • Wo immer möglich, die Transparenz verbessern.
  • Verringerung der Fragmentierung bei Anbietern und in der Verwaltung.
  • Testen der Wiederherstellung in verschiedenen Umgebungen.

Recovery speed impacts revenue. Recovery clarity impacts reputation. Downtime impacts customer trust. Multi-cloud innovation must be matched by multi-cloud recovery discipline.

Die KI- und Automatisierungsschicht

Keine Diskussion ist vollständig, ohne auf KI einzugehen. Agentenbasierte Workflows werden zunehmend in SaaS-Plattformen von Unternehmen eingebettet. Doch die Automatisierung bringt neue Überlegungen mit sich:

  • Welche Berechtigungen haben Agenten?
  • Wie oft werden Backups durchgeführt?
  • Welche finanziellen Auswirkungen haben Automatisierungsentscheidungen?
  • Werden Agenten als Identitäten mit geregeltem Zugriff behandelt?

AI can accelerate resilience – but without guardrails, it also can amplify risk. The key is controlled delegation.

Warum wir dieses Gespräch auf STRIVE geführt haben

STRIVE isn’t about repeating what everyone already knows. It’s about confronting the gaps that surface during real-world cyber events. Multi-cloud adoption isn’t slowing down. But unless recovery strategies evolve alongside architecture, complexity will outpace preparedness.
That’s why this discussion matters. And that’s why we brought Akshay in – someone who’s operated across hyperscalers and understands both their power and their limitations.

Die ganze Folge ansehen

In the full STRIVE episode, you’ll discover:

  • Der tatsächliche Unterschied zwischen der Datensicherung auf Serviceebene und der Wiederherstellung auf Anwendungsebene.
  • Warum Isolation der erste Dominostein bei Ransomware-Angriffen ist.
  • Wie die Fragmentierung der Anbieter die Orchestrierung erschwert.
  • Worüber sich CISOs und DevOps-Verantwortliche abstimmen müssen.
  • Wie KI die Gleichung der Resilienz verändert.

Jetzt anschauen.
If you operate across AWS, Azure, or Google Cloud – this conversation is essential.

FAQs

Q: Why isn’t native hyperscaler backup enough?

A: Native tools protect data within a specific cloud but don’t orchestrate recovery across clouds. Multi-cloud applications require coordinated restoration across services and providers.

F: Was ist die größte Lücke beicloud ?

A: Die Diskrepanz zwischen der Art und Weise, wie Backups erstellt werden (Dienst für Dienst), und der Art und Weise, wie die Wiederherstellung erfolgen muss (anwendungsweit).

Q: What does “environmental aperture” mean?

A: Damit ist die Vielzahl an Konten, Clouds, Identitäten und Diensten in einer Umgebung gemeint. Mit zunehmender Breite steigen Risiko und Komplexität proportional an.

F: Warum ist das Abhängigkeits-Mapping so wichtig?

A: Anwendungen erstrecken sich mittlerweile über mehrere Clouds und Teams hinweg. Ohne eine Erfassung der Serviceabhängigkeiten wird die Reihenfolge der Wiederherstellung zu reiner Spekulation.

F: Wie wirkt sich KI auf die Notfallwiederherstellung aus?

A: KI-gestützte Arbeitsabläufe können dabei helfen, Entscheidungen zu Datensicherung und -wiederherstellung zu automatisieren, erfordern jedoch strenge Zugriffskontrollen, Kostenmanagement und Überwachung.

F: Wo sollten Unternehmen ansetzen, umcloud zu verbessern?

A: Beginnen Sie mit einer Bewertung:

    • Abgleich der Wiederherstellung auf Anwendungsebene.
    • Möglichkeiten zur Lieferantenkonsolidierung.
    • Teamübergreifende Abstimmung.
    • Isolationsstrategie bei Zwischenfällen.
    • Häufigkeitcloud .

Chris Mierzwa ist Senior Director für Portfoliomarketing bei Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • Commvault Edge Docking for SaaS die Bereitstellung am Netzwerkrand in einen zentralisierten, cloud Prozess umzuwandeln, der über eine einzige Konsole verwaltet wird. Commvault Edge war früher unter dem Namen HyperScale Edge bekannt.
  • Die automatisierte Einrichtung und die API-gesteuerte Bereitstellung tragen dazu bei, die Bereitstellungszeit an verteilten Standorten auf wenige Minuten zu verkürzen.
  • Standardisierte Arbeitsabläufe tragen dazu bei, die Konsistenz, die Datensicherheit und die Skalierbarkeit in Edge-Umgebungen zu verbessern.
  • SaaS kontinuierliche SaaS ermöglicht laufende Updates, Wartungsarbeiten und Optimierungen ohne manuellen Eingriff.
  • Integrierte Sicherheitsfunktionen wie unveränderliche Backups und eine Zero-Trust-Architektur tragen dazu bei, den Schutz vor sich ständig weiterentwickelnden Bedrohungen zu stärken.

Die Bereitstellung von Datenschutz am Edge sollte keine manuelle Konfiguration an jedem Standort erfordern. MitCommvault Edge für SaaSverwandelt Commvault die Edge-Bereitstellung in ein optimiertes, cloudbasiertes Erlebnis. Es kombiniert die Leistungsfähigkeit von Commvault Edge mit der zentralen Steuerung der SaaS-Verwaltungsebene.

Reduzierung der Komplexität durch Edge-Bereitstellung

Edge-Umgebungen erleben einen rasanten Aufschwung.IDC prognostiziert, dass die Ausgaben für Edge-IT bis 2028 380 Milliarden US-Dollar erreichen werden. Organizations are pushing compute closer to data – retail stores, branch offices, manufacturing plants, healthcare facilities – each generating and storing critical information that must be protected.

The current edge-setup process is resource-intensive, requiring physical access and time-consuming configuration steps. This extends deployment timelines and increases operational costs when scaling to multiple sites. What should take minutes can stretch into an extended period of time and potential complexity. And while organizations struggle with deployment logistics, critical edge data remains unprotected or inconsistently backed up across distributed locations.

The threat landscape doesn’t wait. Verizon’s documents a surge in breaches exploiting edge devices – and every unprotected site represents a potential entry point for ransomware, data theft, and business disruption.

SaaS für Commvault Edge

Commvault trägt dazu bei, die Edge-Bereitstellung mit„SaaS Docking“ für Commvault Edge (formerly HyperScale Edge) – a capability that brings cloud-native speed and simplicity to on-premises protection. From the Command Center, IT teams can configure, deploy, and manage every Commvault Edge system through a single SaaS console. It’s a single pane of glass that helps manage hybrid and cloud-native workloads across every site, device, and workload.

New systems follow a guided, standardized setup workflow that enables protected and consistent configuration from day one. Once powered on, each system automatically connects to Commvault SaaS, validates its configuration, registers with the platform, and begins installation. This helps minimize on-device setup and reduce the operational effort required to deploy at scale.

For larger rollouts, Commvault API-driven automation helps enable rapid onboarding of multiple systems simultaneously, supporting repeatable deployment across sites and regions.

Once systems are deployed, the global Command Center provides unified management across all locations. Each Commvault Edge system remains connected to Commvault SaaS for regular updates, maintenance, and optimization. From this single platform, you can deploy, patch, scale, and maintain every system with confidence. Deploy faster. Manage smarter. Protect data everywhere.

Auf Skalierbarkeit ausgelegt, auf Einfachheit ausgelegt

Commvault Edge Docking for SaaS is designed to deliver measurable operational advantages for IT and security leaders:

Accelerated time to value: Deploy new edge systems faster without manual, site-by-site provisioning.

Centralized visibility and governance: Manage configuration, monitor health, deploy updates, and scale infrastructure from a single SaaS management plane.

Reduced operational overhead: Limit the need for on-device configuration and streamline rollout processes, helping free IT resources for higher-value initiatives.

Consistent, rapid deployment: Standardized workflows help reduce configuration drift, deliver consistent data security posture and policy enforcement, and improve reliability across distributed environments.

Data security by design: Every system runs on , Commvault’s hardened Linux-native foundation. It’s a system that helps enable recovery that’s not just fast, but safe, with immutable local backups, multi-layer ransomware protection, and zero-trust architecture.

Warum das wichtig ist

Traditional edge deployments stretch across weeks or months when deploying at scale. Commvault Edge Docking for SaaS reinforces our commitment to delivering hybrid data protection with the speed and simplicity of SaaS, helping reduce operational costs, eliminate deployment bottlenecks, and achieve faster time to value.

But speed isn’t the only benefit. Consistency also matters. When every site deploys with the same protected baseline, compliance becomes more manageable. Automatic rollout of updates helps security posture stays current. And when recovery workflows are designed to work the same way everywhere, teams can respond confidently under pressure.

This is what unified resilience looks like at scale on the edge: Protection that deploys fast, is simple to manage, and helps provide reliable recovery across hundreds or thousands of distributed sites.

Sehen Sie es in Aktion

Sind Sie bereit, Ihre Edge-Bereitstellungsstrategie zu modernisieren? Erfahren Sie mehr auf unsererCommvault Edge-Seite und vereinbaren Sie eine Demo, um Commvault Edge Docking for SaaS Aktion zu sehen, oder wenden Sie sich an Ihren Commvault-Ansprechpartner, um zu erfahren, wie SaaS Ihre Strategie zur Sicherung der Ausfallsicherheit am Netzwerkrand revolutionieren kann.

FAQs

F: Was ist „Commvault Edge Docking for SaaS“?

A: Es handelt sich um eine Funktion von Commvault, die es Unternehmen ermöglicht, Commvault Edge-Systeme über eine zentralisierte SaaS bereitzustellen und zu verwalten. Dieser Ansatz trägt dazu bei, die Konfiguration, Bereitstellung und den laufenden Betrieb in verteilten Umgebungen zu vereinfachen.

F: Inwiefern vereinfacht diese Lösung die Bereitstellung?

A: Durch automatisierte Arbeitsabläufe und eine zentralisierte Steuerung entfällt die Notwendigkeit einer manuellen Konfiguration an jedem einzelnen Standort. Die Systeme können sich selbst konfigurieren und mit derplatform verbinden, wodurch sich der Zeit- und Arbeitsaufwand für die Einrichtung verringert.

F: Lässt sich das auf mehrere Standorte ausweiten?

A: Ja, die API-gesteuerte Automatisierung ermöglicht die schnelle Einbindung mehrerer Systeme gleichzeitig. Damit eignet sie sich ideal für Unternehmen, die Hunderte oder Tausende von Edge-Standorten verwalten.

F: Welche Sicherheitsfeatures sind enthalten?

A: The solution runs on VaultOS™, which includes immutable backups, multi-layer ransomware protection, and a zero-trust architecture. These features help provide stronger, more resilient data protection at the edge.

F: Welche Vorteile bietet eine zentralisierte Verwaltung für IT-Teams?

A: IT-Teams erhalten eine zentrale Übersicht zur Überwachung, Aktualisierung und Verwaltung aller Edge-Systeme. Dies trägt dazu bei, die Transparenz zu verbessern, den Betriebsaufwand zu reduzieren und einheitliche Richtlinien über alle Umgebungen hinweg sicherzustellen.

F: Warum ist dies für moderne Edge-Umgebungen wichtig?

A: Mit dem zunehmenden Einsatz von Edge-Computing erweisen sich herkömmliche Bereitstellungsmethoden als zu langsam und ressourcenintensiv. Diese Lösung ermöglicht eine schnelle Bereitstellung, konsistente Datensicherheit und zuverlässige Wiederherstellung und unterstützt Unternehmen dabei, mit dem Wachstum und den Risiken Schritt zu halten.

Justin Wolf ist Senior-Produktmanager und Chad Bersche ist leitender Produktmanager bei Commvault.


Verwandte Blogs

More related posts


Thumbnail_Blog_HPE-Active-Peer-Persistence-2024-_1_

A Powerful Partnership for the Future of Data Resilience

Read more about A Powerful Partnership for the Future of Data Resilience
Thumbnail_Blog_Commvault-Cloud-2025-Linkedin

Elevate Your Cyber Resilience with Commvault Cloud Enhancements

Read more about Elevate Your Cyber Resilience with Commvault Cloud Enhancements

Artificial intelligence is redefining what’s possible for modern enterprises: accelerating innovation, sharpening decision-making, and unlocking new efficiencies at scale. Behind every AI-driven insight lies a physical reality—one powered by energy, infrastructure, and data.

As AI adoption grows, so does the need to efficiently manage and protect data at scale.

The future of AI will not be defined by intelligence alone, but by how responsibly that intelligence is built and sustained.

Drei wesentliche Einflussfaktoren auf die Umweltbelastung

The environmental impact of AI is rooted in the compute infrastructure that powers it. Training and running AI models requires high-performance systems that consume electricity. But compute intensity is only part of the story.

AI depends on vast amounts of data—stored, moved, and processed across systems, each contributing to resource use.

All of this is supported by data centers, where servers must be powered and cooled. Cooling systems can represent a meaningful portion of energy use, making data infrastructure design a critical factor in AI sustainability.

Finally, the environmental impact of AI is influenced by how electricity is generated: the same workload can result in very different carbon emissions depending on the energy source.

Ineffizienz bekämpfen, nicht Innovation

KI verbreitet sich rasant, da Unternehmen sie funktionsübergreifend einsetzen, immer mehr Daten generieren und ihre Infrastruktur ausbauen, um mit dieser Entwicklung Schritt zu halten. Dabei bleibt eine wesentliche Ineffizienz oft unbemerkt: Die Hälfte der Unternehmensdaten wird nach ihrer Speicherung nie wieder abgerufen.1Companies pay to store it without realizing value from it. This is where the environmental footprint of AI can expand—not through innovation, but through inefficiency.

Addressing this starts with better visibility and control over data.

Intelligente Daten: Ein wirkungsvoller Hebel für Nachhaltigkeit

Da KI auf großen Datensätzen basiert, können Unternehmen dazu beitragen, die Umweltbelastung zu verringern, indem sie ineffiziente Datenpraktiken beseitigen, die unnötige Arbeitslasten verursachen. Die Lösungen von Commvault bieten zahlreiche Funktionen, die Unternehmen dabei unterstützen, ihre Daten effizient zu verwalten und zu nutzen:

  • Deduplication to remove redundant data
  • Tiering to align storage and processing with access needs
  • Compression to reduce storage requirements

Ein gezieltes Datenmanagement trägt dazu bei, die Effizienz zu steigern und den Ressourcenverbrauch zu senken.

Nachhaltigkeit und Resilienz: Zwei Seiten derselben Strategie

Data environments filled with redundant and unorganized data are not only energy-intensive, they are also harder to secure, govern, and recover. Complexity increases risk and complicates business continuity plans.

By helping organizations manage, protect, and leverage their data, Commvault supports systems that are both resilient and sustainable. Smarter data management can help reduce waste, improve efficiency, and strengthen cyber resilience.

Der Weg nach vorn

Die Zukunft der KI wird von den Entscheidungen geprägt sein, die Unternehmen heute treffen. Führende Akteure in diesem Bereich werden:

  • Treat data as a strategic asset—not just a growing volume
  • Entwickeln Sie KI-Systeme unter Berücksichtigung von Effizienz und Lebenszyklusmanagement
  • Resilienz in alle Bereiche ihrer Geschäftstätigkeit integrieren

With smarter data management, optimized infrastructure, and responsible design, organizations can reduce the environmental impact of AI—while unlocking its full potential.

Less waste. More resilience.


1Der Stand der Dinge bei Dark Data

Aakanksha Kashyap is ESG Specialist at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Key Takeaways:

  • Cyberattacks increasingly target both production and backup environments, making clean, verifiable recovery essential.
  • Integrated anomaly and threat detection strengthen cyber resilience by identifying compromised data, validating trusted recovery points, and accelerating restoration.
  • When embedded into data-protection workflows, anomaly and threat detection capabilities can help provide the evidence needed to recover quickly, safely, and confidently.

Why Cyber Resilience Hinges on Integrated Anomaly and Threat Detection

Anomaly detection identifies unusual behavior in backup data that may indicate compromise. Threat detection identifies known malicious activity using signatures, heuristic analysis, and scanning techniques. Together, they help validate recovery points and enable clean data recovery.

For years, security leaders focused on preventing breaches. In today’s era of persistent attacks and AI-driven threats, organizations increasingly assume compromise and design systems that can withstand disruption and recover safely when it occurs.

Modern adversaries don’t always hide their presence – they reveal it when it serves their objective. Attackers try to infiltrate environments quietly, observe systems over time, and position themselves inside critical infrastructure. The moment an attack becomes visible is rarely the moment it begins; it is the moment the attacker chooses to act.

By then, compromised data may already be woven into backup copies. Integrated anomaly and threat detection can help organizations identify compromised backup data, validate clean recovery points, and assist recovery after a cyberattack.

For security and IT teams, the challenge is no longer simply detecting an attack but predicting and managing an attacker’s possible impact. Understanding what was affected, what remains trustworthy, and how the organization can recover safely without escalating business disruption is the solution.

This is why cyber resilience benefits tremendously from integrated anomaly and threat detection. When detection capabilities are embedded into data protection and recovery workflows, they help provide the shared intelligence that teams need to identify compromised data, validate trusted recovery points, and guide response decisions with evidence rather than guesswork.

This approach aligns with the emerging ResOps™ operating model, where security, IT, and recovery teams work from shared visibility and validated recovery paths to respond to incidents together.

The New Reality: Recovery Requires Proof, Not Assumptions

Traditional threat detection tools focus on spotting threats along the perimeter. But once attackers are inside, visibility can become fragmented and determining which systems and data have been affected becomes a challenge.

Further, attackers increasingly target backup environments specifically to undermine recovery. And the moment organizations cannot confidently prove that backups remain untouched, suspicion becomes unavoidable. The result is uncertainty. Restore quickly and risk reinfection? Or delay recovery while investigating which copies remain trustworthy? IT teams are forced to guess which data is safe while downtime accumulates.

By building intelligence directly into data protection workflows, anomaly and threat detection helps transform recovery from a reactive guess into a disciplined, evidence-driven process. These capabilities can help organizations pinpoint tampered copies, validate data cleanliness, and assemble the most recent uncompromised recovery points – helping you accelerate cyber recovery and reduce operational impact.

Anomaly Detection: Your Early Signal of the Unknown

Anomaly detection acts as a sentinel, guarding your protected data integrity. It establishes a baseline of normal behavior – file sizes, growth patterns, deduplication changes, access attempts – and alerts teams when something deviates from that norm. These deviations can surface signs of silent tampering long before malware signatures do. In an era of novel and polymorphic threats, anomaly detection helps offer what static tools can’t: visibility into the unexpected.

Threat Detection: Targeted Defense Against Known Malicious Activity

While anomalies reveal what’s unusual, threat detection exposes what is malicious. By scanning protected data directly for ransomware, malware signatures, encryption patterns, and custom indicators of compromise (IoCs), threat detection helps validate that the data you protect is not already compromised.

Why a Combined Approach Matters

Neither anomaly nor threat detection alone provides the full picture. Together, they deliver a defense-in-depth strategy: Anomaly detection can highlight suspicious signals while threat detection can probe deeper to verify malicious intent. This combination helps organizations distinguish harmless anomalies from true compromises and maintain reliable, validated data for rapid recovery.

Meeting Today’s Challenges with Commvault® Cloud

Attackers increasingly target backup environments, and hidden malware within backup data can increase the risk of reinfection during recovery. Organizations need data-driven validation for their clean recovery with certainty.Cloud addresses this by combining data protection workflows with anomaly detection, threat intelligence, AI-enabled analytics, and isolated clean instances. With anomaly and threat insights applied before, during, and after backup operations, Commvault can help empower organizations to recover faster, cleaner, and confidently.

Read the full white paper, “Can You Prove You’re Recoverable Right Now?”.

FAQs

Q: What is anomaly detection in data protection?

A: Anomaly detection identifies unusual behaviors – such as unexpected backup size changes or abnormal file activity – that may signal tampering, ransomware, or emerging threats within protected data.

Q: Why do CISOs need threat detection in their backup workflows?

A: Backup environments are now prime attacker targets. Threat detection helps prevent organizations from storing or restoring compromised data, which helps reduce reinfection risk and improve chances for clean recovery.

Q: How does Commvault help enable clean data recovery?

A: Commvault uses AI-assisted threat scanning, encryption detection, custom IoC matching, and cyber deception to help validate backup integrity and assemble the most recent uncompromised data for rapid recovery.

Q: Why combine anomaly and threat detection?

A: Anomalies identify the unknown; threat detection validates the known. Together, they provide comprehensive visibility into suspicious activity, helping enable faster investigation and more confident data recovery.

Pauline Listis Product Marketing Manager at Commvault

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience