Skip to content

Ihr Unternehmen wurde gerade Opfer eines Ransomware-Angriffs. Ihre Cyber- und IT-Abteilungen bemühen sich verzweifelt, Ihren Notfallplan in Gang zu bringen und umzusetzen. Plötzlich stellen alle fest, dass sie sich nirgendwo mehr anmelden können.Active Directory (AD) must be offline!? Your organization’s authentication undauthorization tools are impacted.

After hours of triage undassessing the size of this problem, your cyber incident response team reports that restoring foundational AD undauthentication undauthorization services will take over a week, if everything goes well.

You thought your resiliency plan with AD backups unda SaaS identity platform was sufficient. But even with SaaS in the mix, recovery is complex undmanual, delaying the path back to einen minimalen Betriebsbetriebverzögert, wenn Zeit am wichtigsten ist.Ausfallsicherheitbedeutet, dass Sie Authentifizierung und Autorisierung schnell, vorhersehbar und auf vertrauenswürdige Weise wiederherstellen können – ganz gleich, ob die Störung durch böswillige Aktivitäten, einen Ausfall oder eine versehentliche Fehlkonfiguration verursacht wurde.

Die Bedrohung verstehen

Attackers target AD because it’s the identity control plane. Once they get a foothold, they’ll often establish persistence by creating shadow or backdoor accounts, then harvest credentials, undescalate privileges. With elevated access, they laterally move across systems undapplications, sometimes staying quiet long enough that the first clear signal is when authentication starts failing.

They gain a wealth of knowledge of the organizations network, people, undapplications. And when they’re ready to maximize impact, they can encrypt or corrupt the AD forest, disrupting logins undcomplicating recovery across the environment.

Warum Identität (und warum zuerst AD)?

It’s common for an organization’s identity stack, especially AD undEntra ID, to become complex over time. Forests expand, permissions sprawl, legacy policies accumulate, und“good enough” processes often turn into long-term security drift. That complexity creates blind spots, unddefenders lose crisp visibility into how roles, privileges, undpolicies evolve.

And it’s never “just AD.” Identity is an ecosystem: identity governance undaccess solutions (IGA), privileged access, customer identity, identity providers, authentication databases, undsingle sign-on all connect back to the same truth. That’s why identity incidents (undeven everyday misconfigurations) can cause outsized disruption compared to many other infrastructure failures.

The recovery challenge is where most plans get exposed. Even with backups, forest recovery is a multi-step, high-stakes process, where guidance for manual recovery can involve 50 to 100 (or more) individual steps undcan take days to weeks, depending on environment complexity undpreparedness.

The real question isn’t “do we have backups?” it’s “can the teams leverage the backups to cleanly execute under pressure, undhave runbooks been tested undverified so recovery doesn’t become an error‑prone scramble at the worst possible time?”

Die Lösung

Die Notwendigkeit eines Recovery-Plans ist groß. Er muss getestet und verifiziert werden. Unternehmen müssen wissen und verstehen, dass Ihre Identitätsmanagement-Plattform das Hauptziel für Cyberkriminelle und Angriffe ist. Sie muss entsprechend geschützt werden. Es müssen Backups erstellt, getestet und verifiziert werden, um sicherzustellen, dass eine Wiederherstellung möglich ist. Dazu gehören:

  • Sicherungen von AD-, Entra ID- und IGA-Plattformen.
  • Getestete und verifizierte Pläne für die Recovery.
  • Isolierte Recovery-Umgebungen und Cleanroom Recovery.
  • AD-Recovery-Workflow und -Automatisierung.

Strong identity governance undmonitoring are still critical, but they’re only part of the equation. You want the ability to detect suspicious identity behavior early, contain it fast, undrecover with confidence when something changes that shouldn’t (whether it’s malicious activity or an accidental modification that breaks authentication).

That also means you need to integrate identity account unduser activity into SecOps undcontinuously watch for signals like unauthorized account creation, privilege changes, undabnormal authentication patterns, undhave a recovery path that’s proven, repeatable, undclean.

Commvault undDeloitte: A Partnership for Identity Ausfallsicherheit

Identitätsresilienz is a business challenge that requires strong governance, processes, controls, undenabling technology. That’s why Deloitte undCommvault have partnered to deliver comprehensive identity protection, recovery, undresilience programs that organizations can trust when it matters most. 

Deloitte brings deep expertise in cyber risk, enterprise resilience, undidentity undaccess management to help Fortune 100 to 1000 organizations design, implement, undoperationalize identity resilience programs.

These programs help clients assess security posture, improve detection undresponse capabilities, unddefine minimum viable company requirements, undthen build tested, verified recovery plans with clear timelines undaccountability across business undIT stakeholders. Deloitte turns identity resilience into an executable program with runbooks, testing, undreadiness, so teams know what “prepared” looks like under pressure.

Commvault makes resilience programs operational with integrated protection undautomated recovery workflows across identity systems, plus Commvault AirGapundCleanroom Recoveryto support repeatable, clean, validated recovery when it matters most. Commvault provides the technology foundation with identity resilience capabilities that include:

  • Protection for critical identity systems, including AD undEntra ID, point-in-time comparison undrollback support for unwanted or accidental changes.
  • Auditing unddetection to surface suspicious modifications early (who changed what, undwhen), helping reduce the window for attackers to spread or persist.
  • Automated recovery workflows, including forest-level recovery automation, to help reduce the manual burden underror risk during identity restoration.
  • Commvault Cleanroom zur Validierung der Identitätswiederherstellung in einer isolierten Umgebung, bevor das Vertrauen in die Produktionsumgebung wiederhergestellt wird.
  • Commvault AirGapto help maintain immutable, air-gapped backup copies, creating a protected foundation that supports clean recovery undcleanroom testing when identity (or the environment around it) can’t be trusted.

Maßnahmen ergreifen

If you want to pressure-test your cyber recovery readiness, start with a Deloitte Active Directory Workshop to map dependencies undproduce a clear, actionable plan to recover AD undworkloads to production. Then validate it the right way: using Commvault to rehearse recovery in a cleanroom before you ever need it in a real event.

For organizations ready to take the next step, we can extend this into a 30-day pilot that puts clean recovery undtesting into motion with real artifacts undmeasurable outcomes. Contact your Deloitte representative at commvaultsalesteam@deloitte.comoder Ihren Commvault-Ansprechpartner unterdeloittealliance@commvault.com.Dave Nowak is Cyber Defense & Ausfallsicherheit Principal at Deloitte, undMichael Fasulo is Senior Director, Portfolio Marketing, at Commvault.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Die wichtigsten Erkenntnisse

  • IT and Security misalignment increases cyber risk.
  • Cloud enables unified response and recovery.
  • Arlie AI delivers shared intelligence and guided action.
  • Secure by Design principles underpin trust and compliance.
  • A shared mindset is foundational to cyber resilience.

In today’s enterprise environment, cyber resilience depends on more than tools. It depends on whether IT and Security teams operate with shared intent. With Cloud, organizations gain a unified platform that connects detection, response, and recovery – helping CIOs and CISOs move forward together without compromise.

Understanding the IT and Security Divide

IT and Security teams share a common mission: enable the business to succeed. Yet their paths often diverge through opposing objectives, siloed tools, and disjointed workstreams.
IT Operations prioritize speed, scalability, automation, and uptime.
Security Operations focus on protecting data, reducing risk, and maintaining compliance through the CIA triad – confidentiality, integrity, and availability.
When these perspectives collide without coordination, silos form. Communication slows. Risk increases.

Why Misalignment Undermines Cyber Resilience

Lack of alignment creates tangible consequences:

  • Slower incident detection and response.
  • Inefficient and error-prone recovery.
  • Expanded blast radius during cyberattacks.
  • Increased operational friction during crises.

Cyber resilience demands coordinated action across detection, investigation, and recovery.

Bridging the Gap with Cloud

Commvault demonstrates how technology can align teams instead of fragmenting them.

  • Faster, cleaner recoveries: Commvault provides threat insights, scanning against indicators of compromise and sharing insights with security tooling while enabling rapid, reliable recovery. Together, teams can identify affected systems and restore operations with confidence.
  • Targeted risk mitigation: Capabilities such as cyber resilience assessments, scenario simulations, and isolated testing in cleanrooms allow organizations to prepare without impacting production environments.
  • Unified incident management: Integrated workflows connect detection, investigation, and recovery, minimizing room for miscommunication, and helping to accelerate resolution.
  • Scalable, tailored services: Commvault incident response recovery services adapt to organizational needs, supporting resilience without overextending resources.
  • Shared expertise: Customers can benefit from combined guidance across architecture planning, process optimization, and operational readiness.

Arlie AI: Shared Intelligence in Action

Arlie AI, Commvault’s Autonomous Resilience copilot, strengthens collaboration by delivering real-time insights and guided workflows.
Arlie helps:

  • Surface anomalies and critical data.
  • Guide users step by step during incidents.
  • Reduce reliance on deep technical expertise.
  • Standardize response across IT and security.

With no-code integrations and platform-aware intelligence, Arlie removes guesswork and reinforces shared execution.

Secure by Design, Not by Accident

Commvault embeds security at the code level throughSecure by Designprinciples. This approach is validated through initiatives such as and the adoption ofpost-quantum cryptographic capabilitiesthat align to the new NIST standards.
These measures reduce compliance burden and support regulated industries. Additional certifications are available in theCommvault Trust Center.

Steps to a Shared Mindset

Q: Why do IT and Security teams struggle to align?

A: They operate under different priorities, KPIs, and tools, which can create silos.
Q: How does Commvault help improve cyber resilience?

A: By unifying detection, response, and recovery within Cloud.
Q: What role do security integrations play?

A: Commvault security integrations allow sharing threat insights cross-functionally and help inform faster recovery.
Q: What is Arlie AI?

A: Arlie is Commvault’s AI copilot that delivers guided, real-time resilience insights.
Q: Why is Secure by Design important?

A: It helps reduce risk at the code level and helps support compliance from the start.
Q: How can organizations measure alignment success?

A: Through shared KPIs like time to detection, recovery speed, and readiness testing

Pauline List is a Product Marketing Specialist at Commvault.


Verwandte Blogs

Aufbau von Stakeholder-Abstimmungen für Cyber-Resilienz

Der dringende Bedarf an Cyber-Resilienz

A Multi‑Layered Approach to Cyber Resilience

Konversationsbasierte Resilienz: Ein neuer Ansatz für die Verwaltung und den Schutz von Unternehmensdaten

Die nächste Evolutionsstufe im Bereich Cloud

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Die wichtigsten Erkenntnisse

  • Der laterale Zugriff in KI-Umgebungen ermöglicht es Angreifern, sich über vernetzte Systeme hinweg zu bewegen, indem sie sich das gemeinsame Vertrauensverhältnis und übermäßige Berechtigungen zunutze machen.
  • KI-Workflows können laterale Bewegungen verschleiern, da Angriffe häufig das normale Systemverhalten nachahmen.
  • Defense in depth – including identity isolation, segmentation, and dynamic access control – helps reduce the spread of compromise.
  • Die Recovery-Planung muss als zentrale Kontrollmaßnahme betrachtet werden und darf nicht erst nachträglich berücksichtigt werden, um das Vertrauen nach lateralen Sicherheitsverletzungen wiederherzustellen.
  • Commvault unterstützt die Ausfallsicherheit, indem es bei Vorfällen mit seitlichem Zugriff eine vertrauenswürdige, isolierte Recovery-Methode und schnelle Eindämmung ermöglicht.

Modern AI systems are built for speed and connectivity. That same design also makes lateral access one of the most dangerous and least visible failure modes in AI-enabled environments.

Large language models, retrieval pipelines, orchestration layers, and downstream services continuously interact to generate value. When those interactions rely on shared trust and overly broad permissions, a single compromise can spread far beyond its original scope.

What Is Lateral Access in AI Environments?

Lateral access occurs when an attacker compromises one component and then moves horizontally across connected systems by exploiting trust relationships, shared identities, or overly broad permissions.

In modern AI environments, this type of movement is especially dangerous. Models, retrieval services, orchestration layers, and data stores are designed to communicate continuously, often using shared credentials and implicit trust. Once a single component is compromised, attackers can move quickly across the environment without triggering obvious alerts.

Because AI workflows generate large volumes of legitimate activity, lateral movement often blends into normal system behavior until the blast radius already has expanded.

Why Lateral Access Is Especially Dangerous

Lateral access undermines security assumptions that many organizations still rely on. Traditional defenses focus on preventing initial compromise or vertical privilege escalation. Lateral movement bypasses those controls by abusing legitimate access paths that already exist.

In AI-enabled environments, the impact compounds rapidly. Compromised services may continue to generate valid outputs while attackers move across models, data sources, and tenants at machine speed. What begins as a single breach quickly can expand into a systemic incident.

Recovery is also more complex. When identities, orchestration layers, or shared data stores are involved, organizations must assume broader contamination and restore trust across multiple systems rather than a single endpoint.

Common Causes of Lateral Movement

Most lateral access exploits are enabled by architectural decisions rather than novel vulnerabilities. In modern AI environments, speed and integration are often prioritized before identity discipline and segmentation are fully enforced.

The most common causes include:

  • Übermäßige Berechtigungen, die KI-Diensten, Agenten oder Automatisierungskonten gewährt werden.
  • Gemeinsam genutzte Identitäten über Funktionen zur Datenerfassung, -abruf, -auswertung und -Orchestrierung hinweg.
  • Schwache Durchsetzung rollen- und attributbasierter Zugriffskontrollen.
  • Unzureichende Segmentierung zwischen Mandanten, Umgebungen oder Workloads.
  • Fehlen unveränderlicher Backups und isolierter Recovery-Workflows.

Addressing these issues requires architectural discipline and recovery planning, not reactive controls applied after compromise.

Reducing Lateral Risk with Defense in Depth

Reducing lateral access risk in AI environments requires more than perimeter controls or isolated fixes. It requires defense in depth that assumes compromise and limits how far attackers can move once inside.

Effective design focuses on four core principles:

  • Enforce identity isolation: Each AI function should operate with its own narrowly scoped identity. Ingestion services, retrieval components, orchestration layers, and inference engines should never share credentials. When identities are isolated, a single compromise cannot automatically spread across systems.
  • Apply context-aware access controls: Permissions should be evaluated dynamically based on role, environment, tenant, and operation. Combining role-based and attribute-based access controls limits abuse of legitimate access paths and reduces the opportunity for lateral movement.
  • Segment data paths and execution environments: AI components should be isolated from one another and from core business systems. Segmented networks, service boundaries, and controlled data paths help restrict how far attackers can move and contain the blast radius when compromise occurs.
  • Plan for recovery as a control: Prevention alone is insufficient. Organizations must assume lateral movement will occur and design recovery workflows that help them isolate compromised components, restore trusted systems, and reestablish control without reintroducing risk.

Together, these principles shift lateral access from an uncontrolled cascade into a contained and recoverable event.

Detecting and Responding to Lateral Behavior

Early detection is critical in limiting the impact of lateral access. Because lateral movement often mimics legitimate system behavior, traditional alerting focused on perimeter breaches or privilege escalation is frequently insufficient.

Effective detection focuses on behavioral signals rather than individual events. Unexpected interactions between services, sudden expansion of access scope, and anomalous identity usage patterns can indicate lateral movement even when individual actions appear valid.

When suspicious behavior is identified, response must prioritize containment and trust restoration. Compromised identities should be revoked quickly, affected components isolated, and recovery initiated using trusted data in controlled environments. The goal is not only to stop movement, but to reestablish confidence in system integrity.

Why Commvault Matters for AI Resilience

AI systems increase speed and scale across the enterprise. Attackers benefit from that same speed when lateral access is left unchecked.

Commvault helps organizations reduce the impact of lateral access by providingvertrauenswürdige Recovery-Grundlagenbereitstellt, die Eindämmung, Isolierung und Recovery in großem Maßstab unterstützen. Wenn eine Kompromittierung auftritt, wird die Fähigkeit, anhand bekannter, einwandfreier Daten eine Recovery durchzuführen, zu einer entscheidenden Kontrollmaßnahme.

Commvault kann Unternehmen dabei helfen:

  • Vertrauenswürdige Recovery-Punkte zu sichern, die auch bei einer weitreichenden Kompromittierung verfügbar bleiben.
  • Systeme und Daten zur Validierung in isolierte Umgebungen wiederherzustellen, bevor sie wieder in Betrieb genommen werden.
  • Identitätsabhängige Dienste wiederherzustellen, ohne die laterale Kontamination zu verstärken.
  • Ausfallzeiten zu reduzieren und das Vertrauen in den Betrieb schneller wiederherzustellen.

Resilience against lateral access is not about eliminating connectivity. It is about controlling it, monitoring it, and making sure that recovery remains possible.

Final Thought

Lateral access is not a failure of individual controls. It is a consequence of how modern AI systems are designed to connect and trust one another.

As AI environments continue to scale, resilience depends on disciplined identity design, intentional segmentation, and the ability to recover quickly from trusted data. Organizations that plan for containment and recovery alongside innovation are best positioned to limit blast radius and preserve trust when compromise occurs.

Learn how Commvault helps organizations strengthen AI resilience and accelerate recovery when it matters most.der neuen Version der Commvault Cloud Unity-Plattformkönnen Sie Datensicherheit, Identitätsresilienz und Cyber-Recovery auf Unternehmensniveau vereinen.


FAQs

Q: What does “lateral access” mean in AI-enabled environments?
A: Lateral access refers to an attacker’s ability to move horizontally between interconnected systems after compromising one component. In AI environments where models, retrieval layers, and data sources share trust, this movement can go unnoticed and expand quickly.

Q: Why is lateral access particularly dangerous for AI systems?
A: Because AI ecosystems are highly interconnected, a single compromise can cascade across multiple components. Attackers can maintain legitimate-looking activity while accessing sensitive data or systems, making detection difficult and recovery complex.

Q: What are the most common causes of lateral movement?
A: Excessive permissions, shared identities across AI services, weak access control enforcement, lack of segmentation, and missing immutable backups all create opportunities for lateral exploitation.

Q: How can organizations reduce lateral access risk?
A: Implementing identity isolation, dynamic (context-aware) access control, and segmentation across AI components limits how far attackers can move. Recovery strategies should be built into architecture to enable containment and safe system restoration.

Q: What role can Commvault play in defending against lateral access?
A: Commvault strengthens resilience by enabling organizations to maintain trusted recovery points and isolate restoration. Its tools are designed to validate, recover, and reestablish trust quickly, helping reduce downtime after compromise.

Q: How should teams detect and respond to lateral movement?
A: Commvault recommends focusing on behavioral anomalies – such as unexpected service interactions or expanded access scopes – rather than traditional alerts. Once detected, revoke compromised credentials, isolate affected systems, and recover from verified data backups.

Chris DiRado is Principal, Product Experience, at Commvault.

More related posts


Thumbnail_-Blog_Hyperscale-2025-1

Commvault On-Prem Solutions: Ransomware Resilience to AI-Ready Data Protection

Read more about Commvault On-Prem Solutions: Ransomware Resilience to AI-Ready Data Protection
Thumbnail_Blog_Resilient-Against-the-AI-Machine

Resilient Against the AI Machine

Read more about Resilient Against the AI Machine

At Commvault, support exists for one reason: to solve customer challenges as quickly and confidently as possible. Every process we refine, every tool we introduce, and every investment we make is guided by that goal – helping customers feel supported when it matters most.

Over the years, we’ve learned that great support isn’t just about resolving tickets. It’s about clarity during high-pressure moments, honest communication, and building trust that lasts beyond a single interaction. Those lessons have shaped a support ecosystem designed to move fast without losing the human connection.

Menschliche Expertise, verstärkt durch KI

Speed and empathy don’t have to compete. That’s why our approach to AI is built around partnership, not replacement. AI helps us move faster; people are dedicated to making sure we move wisely.

Arlie vereinfacht komplexe Aufgaben und lässt sich mit, our AI-enabled support assistant, analyzes logs, recognizes patterns, and surfaces insights early – often before issues escalate. Customers can use Arlie vereinfacht komplexe Aufgaben und lässt sich mit directly to find answers in real time, while our engineers use those same insights to focus less on data gathering and more on understanding each customer’s unique environment.

This balance matters. Support interactions often happen during moments of risk or stress, when customers want reassurance that a real person is invested in their success. By handling the repetitive and time-consuming tasks, AI creates space for meaningful conversations – the kind that build confidence and trust.

Das Team hinter jeder Lösung

Behind every fast resolution is a global team of highly skilled engineers who continuously learn, collaborate, and share knowledge. Our Center of Excellence model allows expertise gained in one region to strengthen support everywhere, ensuring customers benefit from collective experience – not just individual cases.

Training, certifications, case reviews, and simulations are part of everyday life for our support teams. This preparation means that when a ticket arrives, engineers respond with clarity, purpose, and deep technical understanding across cloud, storage, backup, databases, and security.

AI strengthens this model even further by capturing insights from past cases and making them instantly accessible, so knowledge never stays siloed.

Ein Support-Erlebnis, das sich ständig weiterentwickelt

The result is a support experience that feels both efficient and personal – one where customers can self-serve when they need speed, connect with experts when they need guidance, and trust that every interaction is backed by experience, empathy, and continuous learning.

We’re continuing to invest in proactive monitoring, smarter self-service, and learning paths that help customers and engineers grow together. Progress is ongoing, but the direction is clear: faster resolutions, stronger partnerships, and support that customers can truly rely on.

If you’ve interacted with Commvault Support recently, we’d love to hear your feedback. Thank you for being a Commvault customer and for providing insights that help us keep improving – for every customer, every day.

 

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Backup and recovery integrations depend on secure workload credentials. A single compromised credential can open access far beyond one system, and threat actors know it.

The best static credential is the one you don’t have. Where feasible, move from secret-based authentication to managed identities or other “secretless” approaches, so credentials are issued, protected, and rotated by the platform rather than stored and handled manually. However, we realize this is not always possible for some legacy systems and configurations.

The good news: Even when using long-lived secrets, hygiene can reduce your risk and blast radius.

This post outlines a practical routine that can help ensure your business remains cyber resilient: Rotate credentials, minimize scope, and enforce Conditional Access where possible.

Die Grundlage: Drei zentrale Kontrollmaßnahmen

Strong credential hygiene comes down to three pillars: rotation, least privilege, and Conditional Access. While you won’t always be able to implement all three for every credential type, these are the right places to start for any environment:

  1. Rotation and monitoring: Rotate credentials regularly and review authentication activity for anomalies.
  2. Least privilege: Scope permissions so credentials can perform only the required backup/restore actions. Practical steps include:
    • Trennen Sie Anmeldedaten nach Arbeitslasten.
    • Beschränken Sie die Berechtigungen auf das erforderliche Minimum an Datensätzen, Standorten, Postfächern und Datenbanken.
    • Vermeiden Sie weitreichende Administratorrollen, sofern dies nicht unbedingt erforderlich ist.
  3. Conditional Access: Where supported, set policies to limit when and where credentials can be used, such as:
    • Vertrauenswürdige Standorte und IP-Bereiche
    • Risikosignale
    • Geräte-/Sitzungskontrollen

When Conditional Access Isn’t Feasible, Rotation is the Compensating Control

Nicht jeder Anmeldedaten-Typ erfüllt die Anforderungen des bedingten Zugriffs. In diesen Fällen begrenzt die Rotation die Nutzungsdauer gestohlener Anmeldedaten, und die Überwachung hilft Ihnen, Missbrauch schnell zu erkennen.Die Commvault-Richtlinienlegen Wert darauf, Passwörter, Geheimnisse und Anmeldedaten regelmäßig in allen Umgebungen zu rotieren. Für Single-Tenant-Azure-App-Registrierungen zum Schutz von M365-/D365-/Entra ID-Workloadsempfiehlt Commvault90-day rotation cycles. Many common security and compliance frameworks (PCI DSS, ISO 27001, SOC 2, NIST) also expect disciplined credentials management, including periodic rotation and review of access.

Wenden Sie sich an Ihr Sicherheitsteam

Credential hygiene is most effective when it’s consistent. Align with your security team on:

  • Rotationsintervalle (nach Art der Anmeldedaten und Risikostufe).
  • Conditional Access policy design (what’s enforceable without breaking automation).
  • Regeln für privilegierten Zugriff, Protokollierungsanforderungen und Überprüfungszyklen.

Ressourcenleitfaden

Die folgenden Ressourcen bieten zusätzliche Hintergrundinformationen und umgebungsbezogene Anleitungen zum Schutz von Anmeldedaten und zu Zugriffskontrollen.

Commvault
Microsoft
AWS
Google Cloud (GCP)

Will Galway is Deputy Chief Security Officer at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Die wichtigsten Erkenntnisse

  • Commvault erweitert den Schutz für Google Workspace um fortschrittliche eDiscovery-Suchfunktionen zur Unterstützung von Compliance, Untersuchungen und Rechtsstreitigkeiten.
  • Die neuen Funktionen ermöglichen eine schnellere und präzisere Suche in Gmail und Google Drive mithilfe von Filtern für Schlüsselwörter, Phrasen und Metadaten.
  • Flexible Exportoptionen helfen Rechtsabteilungen dabei, die Überprüfung zu optimieren und standardisierte Export-Sets für wiederkehrende Fälle wiederzuverwenden.
  • Eine zentralisierte Discovery-Oberfläche ermöglicht es Unternehmen, eDiscovery über Google Workspace, Microsoft 365 und Endgeräte hinweg von einer einzigen Plattform aus zu verwalten.
  • Die Lösung entspricht den Standards des Electronic Discovery Reference Model (EDRM) und ist im Early Access verfügbar; die allgemeine Verfügbarkeit ist für das erste Halbjahr 2026 geplant.

Google Workspace spielt eine zentrale Rolle bei der Kommunikation und Zusammenarbeit in vielen Unternehmen und enthält geschäftskritische E-Mails, Dateien und Nachrichten, die oft fürCompliance, Untersuchungen und Rechtsstreitigkeitenvon entscheidender Bedeutung sind.

Als wichtige Quelle für auswertbare Daten benötigen Unternehmeneffiziente eDiscovery-Prozesse, um relevante elektronisch gespeicherte Informationen (ESI) über alle Google Workspace-Dienste hinweg schnell zu finden, zu verwalten und zu exportieren und so moderne gesetzliche und regulatorische Anforderungen zu erfüllen. Verzögerte Reaktionen sowie eine unvollständige oder ungenaue Erfassung von ESI können die Rechtskosten in die Höhe treiben, das regulatorische Risk erhöhen und zu Geldstrafen oder der Nichteinhaltung von Compliance-Verpflichtungen führen.

Um diesem Bedarf gerecht zu werden, erweitern wirden bestehenden Schutz von Google Workspaceumerweiterte Compliance-Suchfunktionen für unser eDiscovery-Angebot. Diese eDiscovery-Funktionen für Google Workspace ergänzen die bestehende eDiscovery-Unterstützung für Microsoft 365 und Endgeräte und erleichtern so die einheitliche Compliance-Verwaltung über mehrere Workloads hinweg von einer einzigen Plattform aus.

Vereinfachung der Compliance-Suche für Google Workspace-Umgebungen

Mit dieser Version können Kunden relevante Daten wie E-Mail-Nachrichten und Dateien in ihren Google Workspace-Backups schneller für Audits, Rechtsstreitigkeiten oder Untersuchungen finden, filtern und exportieren. Diese erweiterte Unterstützung soll Unternehmen dabei helfen, den Zeit- und Kostenaufwand im Zusammenhang mit eDiscovery zu reduzieren und ihre rechtlichen und regulatorischen Verpflichtungen zu erfüllen.

Wichtigste Merkmale und Vorteile:
  • Advanced search: Quickly find relevant emails and files using keyword, phrase, and metadata searches with granular filtering controls. Run centralized searches across Gmail and Google Drive or target a specific service to narrow the scope for focused investigations.
  • Flexible export options: Export all search results or select items for legal review or external production. Utilize standardized export sets for recurring investigations to help minimize manual effort and expedite response times for future requests.
  • Centralized discovery experience: Perform discovery across Google Workspace today, with the flexibility to extend searches to Microsoft 365 and endpoint data – all from a single, centralized interface.
  • EDRM-compliant solution: Helps maintain EDRM compliance, adhering to identification, collection, and processing protocols.

Die Compliance-Suchfunktionen für Google Workspace sind derzeit im Early Access verfügbar und sollen in der ersten Hälfte des Jahres 2026 allgemein verfügbar sein.

Möchten Sie mehr erfahren?

Erkunden SieCommvault Backup & Recovery for Google Workspaceoderfordern Sie eine individuelle Demo an, um die neuen Compliance-Suchfunktionen in Aktion zu erleben.

FAQs

Q: Why is eDiscovery important for Google Workspace data?
A: Google Workspace contains critical emails, files, and communications that are often required for legal, regulatory, and compliance matters. Efficient eDiscovery helps organizations quickly locate and produce accurate ESI while controlling costs and risk.

Q: What types of data can be searched with Commvault eDiscovery for Google Workspace?
A: The solution supports searches across Gmail and Google Drive, allowing organizations to locate relevant emails and files. Searches can be centralized across services or scoped to a specific workload for focused investigations.

Q: How do advanced search capabilities improve compliance response times?
A: Keyword, phrase, and metadata-based searches with granular filters help teams quickly narrow large data sets. This helps reduce manual effort and enable faster responses to audits, litigation, and investigations.

Q: What export options are available for legal and compliance teams?
A: Users can export all search results or select specific items for review or external production. Standardized export sets can be reused for recurring matters, enabling more consistent and efficient workflows.

Q: How does this fit into a broader, multi-platform compliance strategy?
A: Commvault provides a centralized discovery experience that spans Google Workspace, Microsoft 365, and endpoint data. This unified approach helps enable organizations to manage compliance across multiple workloads from a single interface.

Q6: When will compliance search for Google Workspace be generally available?
A: The capabilities are currently available in early access and are targeted for general availability in the first half of 2026.Katharine Colucci is a Product Marketing Manager at Commvault.


Verwandte Blogs

More related posts


Abstract-city-in-the-clouds-Crocus_PPT

Commvault Expands Collaboration with Google Cloud to Help Strengthen Enterprise Protection and Cyber Resilience

Read more about Commvault Expands Collaboration with Google Cloud to Help Strengthen Enterprise Protection and Cyber Resilience

Die wichtigsten Erkenntnisse

  • Durch Deepfake-Erpressung wird Ransomware von einer Bedrohung für den Datenzugriff zu einer Vertrauenskrise, da gestohlene Daten dazu genutzt werden, glaubwürdige Fälschungen zu erstellen.
  • The success of deepfake attacks stems from easy access to generative AI tools, limited detection capabilities, and the burden of proof shifting to victims.
  • True defense lies in protecting and proving the authenticity of data – not chasing every fake artifact.
  • Immutable storage and trusted recovery points enable organizations to demonstrate what is real when under pressure.
  • Commvault can help strengthen resilience by securing data integrity across backup and recovery workflows, allowing organizations to restore credibility quickly.

Ransomware has evolved from disrupting operations to undermining truth itself. Today’s attackers steal sensitive data and use generative AI to fabricate emails, audio, and video that appear authentic enough to deceive customers, partners, regulators, and internal teams. The challenge is no longer just restoring systems. It is proving what is real under pressure.

When Data Theft Becomes Identity Theft

Traditional ransomware denies access to data.Deepfake extortion attackstrust itself.Attackers exfiltrate sensitive corporate information, including executive communications, meeting recordings, and internal documents, and then use generative AI to create convincing forgeries. Fabricated audio or video can appear authentic enough to mislead customers, partners, regulators, and even internal teams.

In these attacks, identity and authenticity are no longer assumed. Perception becomes the weapon.

Why Deepfake Extortion Works

Deepfake extortion succeeds because three structural realities converge at once.

  • Generative tools are widely accessible: High-quality AI tools are readily available and require little expertise to operate.
  • Detection lags creation: Even experienced analysts struggle to distinguish sophisticated deepfakes from authentic content in real time.
  • The burden of proof shifts to the victim: Organizations must demonstrate that content is fabricated, often under extreme time pressure and public scrutiny.

Without trusted data foundations and provable data lineage, truth becomes negotiable.

Defense: Make Data Protected, Private, and Provably Real

Deepfake extortion is effective only when attackers have access to authentic source data. When that data is protected and provable, fabricated content loses credibility and leverage.

Effective defense begins with the recognition that deepfake extortion is not a content problem. It is adata integrity problem. The goal is not to chase every fabricated artifact, but to enable organizations to prove what is authentic when it matters most.

Defense therefore must focus on three architectural principles:

  • Protect the source data: Sensitive information must be secured before it can be exfiltrated. Executive communications, recordings, and internal documents should be tightly controlled so they cannot be repurposed for manipulation.
  • Preserve data integrity: Authentic data must remain provably unchanged.Immutable storage helps prevent backups and historical records from being altered, even by attackers with privileged access. This immutability provides a trusted reference point when authenticity is challenged.
  • Recover from a position of trust: When incidents occur, recovery must be based on verified, clean data. Restoring systems and records from trusted sources allows organizations to reestablish credibility quickly, rather than amplifying doubt through contaminated recovery points.

Together, these principles shift the balance of power. Instead of reacting defensively to fabricated content, organizations can retain the ability to prove authenticity, restore trust, and remove the attacker’s leverage.

How Commvault Supports Truth and Resilience

Commvault helps organizations strengthen resilience against deepfake extortion by protecting data integrity across backup, recovery, and restoration workflows.

By maintainingtrusted recovery pointsand isolating clean data from manipulation, Commvault enables organizations to respond to extortion attempts with evidence rather than uncertainty.

Commvault helps organizations:

  • Protect authoritative data sources so authentic records remain available when credibility is challenged.
  • Isolate trusted recovery pointsto prevent manipulation from spreading across environments.
  • Restore systems and data from verified sources without reintroducing uncertainty.
  • Re-establish operational and reputational trust as AI-enabled attacks scale.

This positions organizations to respond decisively under scrutiny, using trusted data to guide action rather than reacting defensively to fabricated narratives.

Abschließender Gedanke

Deepfake extortion is not just a cybersecurity problem. It is a challenge to truth itself. Organizations that cannot prove the authenticity of their own data risk losing trust when scrutiny is highest. In those moments, doubt spreads faster than facts.

By designing cyber resilience around protected, provable data and trusted recovery, organizations can help retain the ability to demonstrate what is real and respond decisively under pressure.

FAQs

Q: What is deepfake extortion, and how does it differ from traditional ransomware?
A: Traditional ransomware denies access to data, while deepfake extortion manipulates trust. Attackers steal sensitive information and use generative AI to create fake but convincing content, such as videos or emails, that exploit public perception.

Q: Why are deepfake attacks so effective?
A: They work because advanced generative AI tools are widely available, detection technologies lag behind creation, and organizations must prove that fabricated content is false – often under intense time pressure.

Q: How can organizations defend against deepfake extortion?
A: Defense should focus on protecting the integrity and authenticity of source data. This includes securing sensitive data, maintaining immutable backups, and verifying that recovery processes rely only on verified, clean data.

Q: What role does Commvault play in combating deepfake extortion?
A: Commvault helps maintain trusted recovery points, isolate clean data from manipulation, and enable organizations to respond confidently with verified information instead of speculation.

Q: Why is data integrity critical during a deepfake crisis?
A: When false content circulates, organizations quickly must prove what is real. Immutable and verifiable data provides the evidence needed to restore trust, counter manipulation, and maintain credibility under scrutiny.

Q: What’s the key takeaway for business leaders?
A: Deepfake extortion isn’t just a cybersecurity issue – it’s a truth crisis. Building cyber resilience around protected, provable data allows organizations to respond decisively and maintain trust when it matters most.

Chris DiRado is Principal, Product Experience, at Commvault.

Verwandte Blogs

Ein vielschichtiger Ansatz für die Cyber-Resilienz

Mastering Immutability, Air-Gapping, and Zero Trust for Unrivaled Cloud App Recovery

Der Umgang mit Ransomware auf globaler Ebene

Warum die Wiederherstellung von Reinräumen und Cyber-Tests entscheidend für die Widerstandsfähigkeit im Cyber-Bereich sind

More related posts


Cyber Resilience

Read more about Cyber Resilience

Cyber Recovery

Read more about Cyber Recovery
CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Die wichtigsten Erkenntnisse

  • Datenleck-Schleifen entstehen, wenn sensible Informationen, die in KI-Interaktionen eingebracht werden, im Laufe der Zeit gespeichert, abgerufen und verstärkt werden.
  • These loops are difficult to detect because each step appears as normal system behavior rather than a traditional security breach.
  • Prompt injection, over-broad retrieval, and excessive retention are the three core mechanisms that enable AI-driven data leakage.
  • Effective AI security requires embedding containment, least privilege, and continuous verification directly into interaction design.
  • Protection, isolation, and rapid recovery capabilities help organizations limit the blast radius when unintended exposure occurs.

The biggest AI risk is not what large language models say. It is what they remember.

A single copied API key, customer record, or internal document pasted into a prompt can quietly persist, reappear, and spread well beyond its original context.

Every prompt, retrieval, and response in an AI system creates the potential for unintended data exposure. Credentials, intellectual property, personally identifiable information, and customer data can all be introduced into AI workflows without malicious intent. Over time, these exposures compound, forming invisible feedback loops of risk until exposure is widespread.

Unlike a traditional breach, data leakage loops rarely announce themselves. They grow incrementally, interaction by interaction, until sensitive information is dispersed across systems, users, and outputs that were never meant to see it.

Data leakage loops follow a simple pattern. Sensitive data is introduced into an AI interaction, stored or embedded by the system, retrieved later in an unintended context, and reinforced with each subsequent use. Because each step looks like normal system behavior, the loop often goes unnoticed until exposure is widespread.

When Intelligence Creates Leakage

Organizations adopt generative AI to accelerate productivity, automate decisions, and improve customer experiences. The challenge lies not in intent, but in architecture.

AI systems are designed to ingest, retrieve, and contextualize information. When safeguards are insufficient, fragments of sensitive data introduced during one interaction can surface in unrelated responses later. Each use reinforces the next, creating a self-sustaining cycle of exposure.

The Architecture of Data Leakage Loops

Data leakage in AI systems typically emerges through three interconnected mechanisms:

  • Prompt injection (intentional or accidental): Users knowingly or unknowingly include sensitive data in prompts, such as passwords, customer records, or proprietary information, which the system processes and may retain.
  • Over-broad retrieval: AI systems retrieve information from data sources they should not access due to weak permissions or insufficient context filtering.
  • Excessive retention: Interaction histories, embeddings, and logs are stored longer or more broadly than necessary, allowing sensitive data to persist and resurface.

Together, these mechanisms form feedback loops where each interaction increases cumulative exposure.

Defense in AI Interaction Design

The safest design assumption is that anything provided to an AI system may be retained, reused, or disclosed.

That mindset fundamentally changes how AI systems should be secured. Protection must be embedded into interaction design rather than applied after exposure occurs. Security in AI systems begins with the assumption that exposure is possible, which makes containment, least privilege, and continuous verification core design requirements.

In practice, this means:

  • Applyingzero-trust principlesto every AI interaction.
  • Verifying and limiting data access at each stage of prompt handling, retrieval, and response generation.
  • Minimizing permissions across prompts, retrieval sources, and storage layers.
  • Enforcing context aware authorization within retrieval pipelines at query time, rather than relying on static permissions defined outside the AI workflow.
  • Designing systems to contain exposure rather than assuming prevention alone is sufficient.

This approach transforms AI security from reactive cleanup into proactive resilience.

The Role of Commvault

Commvault helps organizations protect the data that fuels AI systems, including training data, retrieval sources, and recovery paths, before, during, and after interaction.

By providing protection, isolation, and rapid recovery capabilities, Commvault enables organizations tolimit the blast radiusof unintended exposure and restore AI environments from trusted data sources.

With Commvault, enterprises can help:

When combined with fine-grained data access controls, organizations can innovate with AI without creating compounding loops of risk.

Abschließender Gedanke

Data leakage loops represent one of the most subtle and dangerous risks in AI adoption. They do not look like attacks, but they weaken security continuously. By treating every AI interaction as a potential exposure and embedding protection, isolation, and recovery into AI architectures, organizations can scale AI while helping preserve trust.

FAQs

Q: What is a data leakage loop in AI systems?
A: A data leakage loop occurs when sensitive data is introduced into an AI interaction, stored or embedded, later retrieved in an unintended context, and reinforced through repeated use. Over time, this creates a self-sustaining cycle of exposure that can spread across systems and users.

Q: Why are data leakage loops harder to detect than traditional breaches?
A: Unlike conventional breaches, data leakage loops do not trigger clear alerts or single points of failure. They grow gradually through normal-looking interactions, making exposure visible only after it has already spread widely.

Q: How does prompt injection contribute to data leakage?
A: Prompt injection occurs when users accidentally or intentionally include sensitive information in prompts. If safeguards are weak, that data can be processed, retained, or reused by the system beyond its original context.

Q: What role does AI system architecture play in preventing leakage?
A: Architecture determines how data is ingested, retrieved, stored, and reused. Designing AI systems with zero-trust principles, least-privilege, and context-aware authorization helps contain exposure instead of relying solely on prevention.

Q: How can organizations reduce risk without slowing AI adoption?
A: Organizations can reduce risk by embedding security directly into AI interaction design and planning for containment and recovery. This approach enables innovation while limiting cumulative exposure as AI usage scales.

Q: How does Commvault support protection against data leakage loops?
A: Commvault helps protect the data that fuels AI systems by providing unveränderliche Backups, isolation, and rapid recovery. These capabilities help enable organizations to limit the impact of unintended exposure and restore trusted AI environments quickly.

Chris DiRado is Principal, Product Experience, at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The board meeting started with a simple question: “Are we ready for the next disruption?”

I gave them an honest answer: “That depends on which disruption we’re talking about.”

Because here’s the reality every CIO knows but doesn’t always say out loud: Readiness isn’t a checkbox. It’s not something you achieve once with a great recovery plan or a perfectly executed disaster recovery test. Readiness is a muscle you build, test, and rebuild constantly as the threat landscape shifts beneath your feet.

That’s why we created the Readiverse. Not another content library. Not another vendor resource hub. It’s a space where CIOs, CISOs, and technology leaders can get the intelligence they need to help them stay ready – whether that means anticipating the next ransomware variant, navigating AI governance challenges, or simply having a straight answer when the board asks, “Are we protected?”

Zwei Arten der Bereitschaft

In my role, I need two things that rarely live in the same place:

Strategic insight for the boardroom: Intelligence briefs that analyze emerging threats through a business impact lens. Quick-hit perspectives from executives who’ve been in your chair – 60-second Bold Takes on what matters now. Fachgespräche with other CIOs who’ve navigated market disruptions and transformation challenges.

Practical guidance for implementation: Readiness-Bewertungen,um den Reifegrad Ihres Unternehmens zu messen. Leitfäden zur Einhaltung gesetzlicher Vorschriften, die dabei helfen, Anforderungen mit vorhandenen Fähigkeiten abzugleichen.Workshops zur Recovery und praktische Erfahrungen that sharpen your team’s ability to respond when it matters most.

The Readiverse brings both together. Because you can’t lead from the boardroom without understanding implementation realities. And you can’t build resilient systems without connecting them to business outcomes.

Bereit. Oder nicht.

That’s the choice we face every day as technology leaders. We can be ready – with tested plans, trained teams, and intelligent defenses. Or we can be caught off-guard when disruption arrives.

That’s why we’re launching our new, six-part podcast series, Bereit. Oder nicht., on the Readiverse. Our host, comedian Nathan Macintosh, and his guests cut through the AI hype and cybersecurity complexity with humor and straight talk. Check out our first episode – „KI: Agenten des Guten, trifft auf Agenten des Bösen – with guest Reid Blackman, founder and CEO of AI risk consultancy Virtue.

Jenseits des Lärms

The Readiverse exists to give you the intelligence, perspective, and practical guidance you need to build resilience that works – not just resilience that sounds good in a slide deck.

Because the board will keep asking if we’re ready. And we owe them – and ourselves – an honest, confident answer. Explore the Readiverse, and we’ll stay ready together.

Ha Hoang is Chief Information Officer at Commvault.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Belgium-based xyzt.ai was founded to help customers gain insight from their location data. Read on to hear why the company chose Clumio, a Commvault company following its acquisition in 2024, to reduce AWS backup costs and significantly improve recovery times.


Q: Lida, can you start by telling us what xyzt.ai does?

Lida: We are a cloud-based, no-code analytics platform that helps customers turn massive volumes of sensor, IoT, and mobility data into meaningful insights. We process billions of records and make it easy for users to visualize patterns, identify anomalies, and make data-driven decisions. Our customers span maritime, mobility, smart cities, and connectivity – anyone who needs to understand location-based behavior at scale.

Q: As a growing startup, how did backups fit into your early strategy?

Lida: In the beginning, AWS-native backups worked well for us. They were simple, integrated, and aligned with our cloud-first architecture. Unfortunately, over time, as our data grew, our AWS backup bill grew with it. It wasn’t dramatic at first, but every year the cost kept climbing.

Q: At what point did rising AWS backup costs become something you needed to solve?

Lida: After about five years of steady growth, the trend was impossible to ignore. Our costs were increasing year over year simply because we were scaling our data footprint. That’s when we realized we needed a more sustainable, predictable option.

Q: What led you to evaluate Clumio?

Lida: Initially, we were looking purely for cost reduction. Once we saw theClumio demo, we realized the value was much broader. Compliance, recovery, data isolation, pricing predictability – those were all important features Clumio provided.

Q: How would you describe your onboarding experience?

Lida: Surprisingly fast. We expected a time-consuming migration, but it was incredibly smooth. We had our first backup running within 30 minutes. That’s not something you expect when switching a core infrastructure component.

Q: Many organizations worry not just about backup costs but also how quickly they can recover. How has recovery performance changed since moving to Clumio?

Lida: Recovery speed is one of the areas where we saw the biggest improvement. With AWS-native tools, restoring large datasets could take hours – sometimes longer – because recoveries were tied to the time it took to fully rehydrate data back into our AWS environment. That lag was a real challenge when we needed fast access for troubleshooting or when customers required immediate data validation.

With Clumio, the experience is dramatically different. The Instant Access feature lets us mount backups in minutes without waiting for full restores. That means our team can start working with the data almost immediately, whether it’s for verification, investigation, or full-scale recovery.

The time savings are enormous – it’s not just faster, it fundamentally changes how quickly we can respond to issues. For a real-time analytics platform like ours, that makes Clumio far more effective than AWS-native options.

Q: Let’s talk results. What impact did Clumio have once you were up and running?

Lida: The most immediate impact with Clumio was cost savings. Using AWS Storage Lens, we confirmed that backups through Clumio were 66.7% cheaper than what we were paying previously. That validation came quickly, and it accelerated our internal approval to move forward.

We also gained stronger resilience by storing backups outside our main AWS environment, which improved our security and compliance posture.

Q: What advice would you share with other AWS-native startups evaluating their backup strategy, and how does Clumio fit into your long-term plans?

Lida: I would tell other startups not to be intimidated by the idea of switching backup providers. The migration was much easier than we expected, and the payoff was immediate.

If your AWS costs are climbing or your compliance requirements are evolving, it’s absolutely worth exploring alternatives. Data protection is central to our business, so we need solutions that scale with us without introducing unpredictable cost spikes – and Clumiogives us that confidence.

Cara Peterson is Voice of the Customer Manager at Commvault.

More related posts


GSI

The Importance of Cyber Resilience in a Cloud-First World

Read more about The Importance of Cyber Resilience in a Cloud-First World
Thumbnail_Blog_Clumio-Tech-2025

Restore only what matters: Clumio Backtrack for DynamoDB

Read more about Restore only what matters: Clumio Backtrack for DynamoDB

Clumio

Read more about Clumio

New Yorkers don’t settle. They expect the fastest service, the toughest infrastructure, and the boldest ideas. So it’s no shock that when it comes to data security, their expectations soar.

But here’s the twist: Laut einer kürzlich von Commvault in Auftrag gegebenen Umfrage of more than 1,000 New Yorkers, consumers hold businesses to uncompromising security standards, even as many admit they don’t follow those same practices themselves.

This isn’t just an interesting quirk. It’s a signal about the future of trust, resilience, and loyalty.

Zwei Standards, eine Stadt

The survey makes one thing clear: In New York, trust isn’t given – it’s earned. And it’s earned through action.

Most respondents said they would stop using, or seriously consider leaving, a company after a breach. Many already have. They reward businesses that prove they take data protection seriously, not just talk about it.

Yet, while they demand resilience from brands, their own habits tell a different story. Password reuse? Still common. Public Wi-Fi? Still tempting. Even with rising awareness and firsthand experience of cyber incidents, inconsistent behaviors persist.

Is that hypocrisy? No. It’s human nature.

People want safety, but they also want convenience, speed, and simplicity. And when those collide, personal cyber hygiene often slips.

Businesses don’t have that luxury.

Warum diese Lücke eine Führungsaufgabe ist

The takeaway isn’t to judge consumers; it’s to understand them. Consumers can take steps to protect themselves (and many do), but they can’t single-handedly defend against sophisticated, AI-enabled threats. Nor should they have to.

That’s where the expectation gap becomes a leadership mandate. Cyber resilience is a shared responsibility, but businesses must lead. And leadership shows up in three ways:

  • Protect before the breach: Build strong defenses, zero-trust controls, and unified resilience platforms that keep pace with evolving threats.
  • Respond fast when things go wrong: Consumers judge a breach not just by its occurrence, but by how quickly and effectively youwiederherstellen.
  • Communicate with transparency: Silence erodes trust faster than bad news. Honesty wins.

Die Abstimmung dieser Elemente stärkt das Vertrauen der Verbraucher.

New York als nationales Signal

Trends beginnen in New York. Hier kristallisieren sich Erwartungen heraus. Hier schwanken die Stimmungen stark. Wenn die New Yorker signalisieren, dass Vertrauen ein entscheidender Faktor bei der Markenwahl ist, sollten Unternehmen im ganzen Land aufmerksam werden. Was in einem wichtigen Markt beginnt, bleibt selten dort. Die Sicherheitserwartungen werden immer höher. Und im Zeitalter der KI sind die Kosten für den Verlust von Vertrauen höher denn je.

Resilienz ist das neue Treueprogramm

For years, brands have poured billions into personalization and convenience. But today’s research suggests something different is rising to the top: Consumers stay loyal to businesses they believe will protect and wiederherstellen their data, not just collect it.

Sicherheit, resilience, and trustworthiness aren’t just back-office concerns anymore. They’re front-of-brand differentiators that shape purchasing decisions, referrals, and long-term relationships.

And in a season when people are traveling, shopping, and accessing sensitive information on the go, often across unsecured networks, the stakes couldn’t be higher.

Der Moment, um zu führen

Consumers have clear demands: People know what they expect, what they’ll tolerate, and what they won’t. And they’re watching you closely.

For businesses, the opportunity is profound: Invest in resilience today and earn loyalty tomorrow. Because when it comes to cybersecurity, consumers don’t just want to feel protected, they want to be protected.

The companies that deliver on that promise will define the next era of trust.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Die wichtigsten Erkenntnisse

  • Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense hilft dabei, umfangreiche Netzwerkinformationen (Protokolle, Audits, Auftragsverläufe) in übersichtliche, umsetzbare Zusammenfassungen mit vorgeschlagenen Folgemaßnahmen und Freiformabfragen umzuwandeln.
  • New root-cause analysis helps scan failures, spots anomalies, and delivers plain-language diagnostics with recommended next steps – no manual log-diving required.
  • Video Bytes in Arlie vereinfacht komplexe Aufgaben und lässt sich mit Responses springt zu dem genauen Zeitpunkt in Langform-Videos, an dem Ihre Frage beantwortet wird, und hilft Ihnen so, Probleme schneller zu lösen.
  • Hinter den Kulissen koordiniert Arlie vereinfacht komplexe Aufgaben und lässt sich mit ETL, PII-Maskierung und Analyse-Agenten, um kontextbezogene Erkenntnisse zu generieren, auf die Sie schnell reagieren können.
  • Arlie vereinfacht komplexe Aufgaben und lässt sich mit und seine Agent-Bibliothek sind in Commvault SaaS schrittweiser Einführung verfügbar und bieten damit Parität mit Commvault-Softwarebereitstellungen.

IT teams are under pressure to do more with less. You’re expected to spot risks early and optimize performance while juggling growing infrastructure and managing thousands of daily backup events. Generating insights from this constant stream of activity across platforms can be incredibly difficult.

This allows vulnerabilities to quietly creep in, waiting to expand into a major issue. Your dashboard says green. Backups seem to be running. But behind the scenes, something’s building: a silent timeout, a log full of subtle warnings, a spike in retries you didn’t notice. By the time a backup admin spots it, it’s already an incident.

The fact is, modern IT environments don’t fail loudly – they fail subtly. And most of the time, the data that could have warned you is already there. It’s just buried in audit trails, scattered across consoles, or trapped in a 40-minute training video.

This is where Arlie vereinfacht komplexe Aufgaben und lässt sich mit really shines. Arlie vereinfacht komplexe Aufgaben und lässt sich mit isn’t just an AI assistant – it’s the intelligent, unified interface designed to help find, understand, and resolve issues faster. Arlie vereinfacht komplexe Aufgaben und lässt sich mit orchestrates advanced backend workflows (agents) that help interpret data, identify anomalies, and generate insights – and then communicates the findings to you through a simple, conversational experience.

With Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense and Video Bytes in Responses, Arlie vereinfacht komplexe Aufgaben und lässt sich mit brings context, clarity, and speed to every interaction – without the hunting. Let’s take a look at what’s new.

Netzdatenanalyse: Von der Datenflut zu Datenerkenntnissen

Modern environments generate an overwhelming amount of data‌: ‌logs, alerts, warnings, and more. On the Commvault platform, these manifest as audit trails and job histories, with hundreds or even thousands of events occurring every day.

Businesses often don’t know where to begin when analyzing their environments. Backup admins are tasked with making sense of this flood, manually scanning through sprawling rows of data across multiple consoles just to understand what’s happening. And with so many actions being logged every minute, it’s easy to miss early warning signs that could escalate into larger issues.

That’s where Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense and its grid data analysis capability come in. It ingests your platform data and distills it into clear, actionable summaries. Instead of forcing teams to scroll through thousands of rows, Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense identifies the most relevant information, delivers those summaries, and highlights what’s actionable in a clear, conversational way. Users can expect:

  • A highlighted executive summary tailored to the user’s environment.
  • Vorgeschlagene Anschlussfragen, um aufkommende Themen zu erörtern.
  • Die Möglichkeit, frei formulierte Fragen für eine tiefergehende Analyse zu stellen.

What’s more, Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense highlights ransomware protection-related events and major changes, proactively surfacing insights that help users stay ahead of potential risks.

However, behind the scenes is where the magic truly happens. Arlie vereinfacht komplexe Aufgaben und lässt sich mit orchestrates multiple backend workflows – retrieving data from Commvault, performing ETL and PII masking, and leveraging analysis agents to generate insights. Arlie vereinfacht komplexe Aufgaben und lässt sich mit’s reasoning and knowledge augmentation capabilities then transform this into actionable intelligence for the user.

With a simple click of a button, backup admins can derive key insights that highlight the exact points needed. Essentially, this allows you to converse with your platform’s data and gain a much clearer understanding of where the system stands in real time.

It’s not just alerting; ‌it’s contextual understanding. No more digging through logs. No more endless tab-hopping. It’s a smarter, faster way to help you monitor system health, troubleshoot issues, and understand your risk landscape. This kind of insight drastically improves efficiency, especially for lean teams managing complex environments‌, ‌allowing them to focus on what truly moves the needle.

Ursachenanalyse: Rohdaten aus Protokollen in Echtzeit-Antworten umwandeln

Reading logs is no one’s idea of fun. Yet buried in those logs are critical clues: ‌why something failed, where the system is strained, and what’s likely to break next. Given the monotonous nature of scouring through large volumes of log data for answers, many teams struggle to diagnose job failures.

Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense and its root-cause analysis capability do the detective work. It scans job failures, identifies root causes, spots anomalies, and generates clear, human-readable explanations – all without manual log interpretation.

Integrated directly into the Send Log Files workflow and Command Center, the agent processes log files to deliver detailed diagnostics along with potential resolutions. Arlie vereinfacht komplexe Aufgaben und lässt sich mit then communicates those findings and recommendations to users, providing clarity and saving valuable troubleshooting time.

Let’s say a job has failed intermittently over the past week. Instead of manually combing through five different logs, Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense can help flag recurring timeouts linked to a specific virtual machine (VM). Or, if backups are running slower than usual, it can help identify the underlying issue.

So, whether you’re managing a handful of backup jobs or orchestrating across hundreds of environments, Arlie vereinfacht komplexe Aufgaben und lässt sich mit helps you cut through the noise and act faster by presenting the right insights at the right time.

Ever found the perfect video that promises to answer your question‌, only to realize it’s 30 minutes long? The exact answer you’re looking for could be 20 seconds or 20 whole minutes into the video, and you have no idea where it’s actually buried. Even after finding this video, locating your answer could be a tedious, time-consuming endeavor.

With Video Bytes in Arlie vereinfacht komplexe Aufgaben und lässt sich mit Responses, that frustration is gone.

Now, when Arlie vereinfacht komplexe Aufgaben und lässt sich mit knows there’s helpful information available within Dokumentation or the Readiverse, it doesn’t just share the link‌ – ‌it pinpoints the exact moment in the video that answers your question. Just ask something like “How can I reduce my VM costs?” and Arlie vereinfacht komplexe Aufgaben und lässt sich mit will jump straight to the timestamp where that topic is addressed‌ – ‌say, Minute 12 of a 30-minute walkthrough.

This enhancement means that you don’t have to rely strictly on Dokumentation or lengthy videos to resolve your issues. It’s a smarter, more efficient, and highly focused approach that gives you exactly what you need.

From Answers to Actions: Arlie vereinfacht komplexe Aufgaben und lässt sich mit, Evolved for You

These exciting new capabilities mark a new chapter in Arlie vereinfacht komplexe Aufgaben und lässt sich mit’s journey, transforming it from being an AI assistant that helps to one that understands. Whether it’s generating key summaries or diagnosing failures through Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense or jumping to exactly what you need with Video Bytes, Arlie vereinfacht komplexe Aufgaben und lässt sich mit is AI designed specifically for you.

In a world where IT complexity is only growing, the real edge lies in proactive, contextual intelligence. With Arlie vereinfacht komplexe Aufgaben und lässt sich mit, you don’t just fix issues faster – you prevent them from happening. With minimal user input, Arlie vereinfacht komplexe Aufgaben und lässt sich mit allows you to see more, do more, and be more.

Jetzt in Commvault SaaS verfügbar

Commvault’s AI capabilities – including Arlie vereinfacht komplexe Aufgaben und lässt sich mit and its Agent-Bibliothek – are now available in Commvault SaaS. This brings feature parity with Commvault software deployments, giving SaaS customers the same intelligent, AI-enabled experience. This brings feature parity with Commvault software deployments, giving SaaS customers the same intelligent, AI-enabled experience.

These capabilities are rolling out in phases, and you’ll begin seeing them appear in your SaaS environment in the coming weeks.

With these enhancements, Arlie vereinfacht komplexe Aufgaben und lässt sich mit brings the future of intelligent, contextual resilience directly into your hands – across both Commvault software and SaaS. Get ready for faster insights, fewer surprises, and a more connected, proactive experience – all with Arlie vereinfacht komplexe Aufgaben und lässt sich mit at the center.

If you’re using Commvault software, you can enable Arlie vereinfacht komplexe Aufgaben und lässt sich mit today by following the instructions in our Dokumentation.

If you’re using Commvault SaaS and would like to enable these features early, please contact your Commvault representative.

FAQs

Q: What exactly is Arlie vereinfacht komplexe Aufgaben und lässt sich mit, and how is it different from a typical chatbot?
A: Arlie vereinfacht komplexe Aufgaben und lässt sich mit is a unified, conversational interface that orchestrates backend workflows –ingesting platform data, running analyses, and returning concise, actionable guidance – so you can move from “searching” to “solving.”

Q: How does the grid data analysis feature help me day to day?
A: Instead of sifting through thousands of rows across consoles, Arlie vereinfacht komplexe Aufgaben und lässt sich mit Data Sense highlights the most relevant signals, summarizes them for your environment, and proposes next questions to dig deeper, reducing noise and accelerating decisions.

Q: What problems does the root-cause analysis feature tackle?
A: It analyzes failures and anomalies across logs to pinpoint likely causes – like recurring timeouts tied to a specific VM – and offers human-readable explanations with potential resolutions, saving significant troubleshooting time.

Q: How do Video Bytes in Arlie vereinfacht komplexe Aufgaben und lässt sich mit Responses speed up learning and support?
A: When a relevant video exists, Arlie vereinfacht komplexe Aufgaben und lässt sich mit links directly to the precise timestamp that answers your query, eliminating the need to scrub through lengthy recordings to find the right segment.

Q: Where can I access these capabilities, and when will I see them?
A: Arlie vereinfacht komplexe Aufgaben und lässt sich mit and its agents are available in Commvault SaaS with feature parity to software deployments, and the enhancements are rolling out in phases over the coming weeks; contact Commvault to enable early access.

Q: How does this tie into resilience and business continuity efforts?
A: Proactive insight and faster root-cause analysis complement disaster recovery programs by helping teams act before minor issues escalate – supporting broader goals of resilience and continuity highlighted in industry cyber and disaster recovery practices.


Teja Medasani is Principal Product Manager, AI, and Mrityunjay Upadhyay is Director, Development, at Commvault.


Verwandte Blogs

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The threat of disruption – from ransomware attacks to natural disasters – has never been greater. For businesses, downtime isn’t just an inconvenience; it’s a direct hit to revenue, reputation, and customer trust. This reality has pushed cyber Datenresilienz to the forefront of IT strategy, demanding solutions that not only protect data but also maintain its continuous availability.

HPE und Commvaultvertiefen ihre langjährige Zusammenarbeit, um diesem dringenden Bedarf gerecht zu werden. Durch das Angebot der HPE Zerto Software mit der Commvaultplatform liefern diese beiden Branchenführer eine leistungsstarke, einheitliche Lösung für fortschrittliche Cyber-Resilienz, Datenschutz und Disaster Recovery in hybriden cloud von Unternehmen.

A Leader in Continuous Data Protection 

We’re proud to announce that the HPE Zerto Software from Commvault solution is now generally available (GA) – ready for organizations everywhere. HPE Zerto Software from Commvault is a leading solution for data Datenresilienzund Disaster Recovery, die darauf ausgelegt ist, Daten und Anwendungen über mehrere lokale und Cloud-Umgebungen hinweg zu schützen. Durch kontinuierlichen Datenschutz sorgt die HPE Zerto Software für nahezu null Datenverluste und Ausfallzeiten und ermöglicht eine schnelle Wiederherstellung nach Ransomware-Angriffen, Katastrophen und anderen Störungen.

Wichtigste Merkmale:

  • Real-time encryption to enable ransomware Datenresilienz.
  • Disaster recovery for virtualized infrastructures and cloud environments, including on-premises, public clouds (AWS, Azure), and hybrid environments. Protect workloads across different environments and cloud providers, creating a comprehensive disaster recovery solution.
  • Workload mobility delivered by simple automation and orchestration of failover, failover tests, and recovery, making it suited for cloud migrations and workload mobility.
  • Cyber Datenresilienz with a combination of regular data protection, real-time encryption detection, and immutable data recovery data.
  • Scalability and reliability with features like near-synchronous replication that can reduce recovery times significantly.

Warum Commvault und HPE Zerto?

Each customer has different needs and requirements, and there is no one-size-fits-all solution. Among the factors to consider are the workload types, the size and scale of the environment, the desired recovery point objective and recovery time objective, and the cost of the solution.

Commvault is focused on delivering end-to-end solutions that not only address the operational Datenresilienz and disaster recovery needs of our customers, but also enable cyber readiness and recovery, governance and compliance, and rapid rebuilding of cloud native applications.

HPE Zerto Software from Commvault is a direct reflection of this commitment. HPE Zerto fits well within Commvault’s Autonomous Recovery offering, providing customers regular replication and operational Datenresilienz for most critical virtualized workloads that cannot afford any downtime.

Unsere Stärken ausbauen

This offering is a testament to the deep, strategic relationship between HPE und Commvault. We amplify each other’s portfolio strengths, creating a synergy that enhances the overall value and effectiveness of our solutions. And what we jointly offer to our customers goes beyond just data protection; it’s the confidence that comes from knowing your operations are set up to be resilient and ready to face the uncertainties of the digital age.

To learn more about early access to HPE Zerto offering from Commvault, please reach out to your account team.

Sind Sie bereit, loszulegen?

The GA launch of HPE Zerto Software from Commvault means now is the time to act – don’t wait. Schedule a demo with your Commvault account team.

More related posts


Thumbnail_Blog_HPE-Zerta-Software-2025

HPE Zerto Software from Commvault: Enhancing Data Resilience and Disaster Recovery

Read more about HPE Zerto Software from Commvault: Enhancing Data Resilience and Disaster Recovery

Die wichtigsten Erkenntnisse

  • Ransomware ähnelt dem Lebenszyklus eines Hurrikans: Frühwarnungen werden oft ignoriert, die Auswirkungen sind lähmend und eine koordinierte Wiederherstellung ist unerlässlich.
  • Identitätssysteme (Aktives Verzeichnis und Entra ID) sind häufig die ersten Opfer; ohne sie kommen die Datenwiederherstellung und der Datenzugriff zum Erliegen.
  • The cost of unpreparedness is high – weeks of downtime and seven-figure losses – making identity-centric resilience a business imperative.
  • Die Vorbereitung sollte saubere, unveränderliche und luftisolierte Backups von AD/Entra ID sowie regelmäßige vollständige Wiederherstellungsübungen für die gesamte Domänenstruktur umfassen.
  • A practical blueprint – assess, protect, isolate, recover, evolve – enables faster, cleaner restoration of data, identity, and trust.

Ransomware has become the digital equivalent of a hurricane – powerful, unpredictable, and capable of wiping out years of progress in a single strike. Like natural disasters, cyber disasters are no longer if events, but when events. The question every organization must answer is not “Can we prevent the storm?” but “Will we survive and recover when it hits?”

This paper explores the parallels between ransomware and hurricanes, with a special focus on identity resilience – including Aktives Verzeichnis(AD) undMicrosoft Entra ID. These identity systems are often the first casualties of a ransomware event. When identity is compromised, recovery stalls – just as losing your address and keys after a hurricane leaves you locked out of your own home.

1. Die Parallele zwischen Stürmen und Cyberangriffen

Hurricane Lifecycle
Ransomware Lifecycle
Shared Lesson
Formation: Warm waters and unstable air pressure form the perfect storm. Exposure: Unpatched systems, weak credentials, and flat networks create ideal attack conditions. Schwache Fundamente laden zu Katastrophen ein.
Warning: Meteorologists issue alerts days in advance. Alerts: Security Information and Event Management, Endpoint Detection and Response, and threat intelligence show early warning signs – often ignored. Erkennen ohne Handeln ist Verleugnung.
Landfall: The hurricane makes impact – power lines fall, flooding begins, and communications fail. Detonation: Malware encrypts systems, disables security tools, and shuts down AD. Beides führt zu einer vollständigen Lähmung des Betriebs.
Response: First responders triage, reroute power, and rescue survivors. Response: Incident response teams isolate affected systems, assess backups, and begin recovery procedures . Geschwindigkeit, Koordination und Klarheit bestimmen den Erfolg.
Recovery: Homes are rebuilt, infrastructure restored, and new defenses added. Recovery: Clean data and identity are restored, enabling business continuity. Recovery must include identity – not just data.

2. Die versteckten Kosten des Identitätsverlusts

When a hurricane destroys your home, you can’t just rebuild walls – you need new keys, insurance, and documents to reclaim ownership. In a ransomware event, the same is true: Without AD or Entra ID, you can’t re-enter your own network.

Identity is the “address” of your digital home – lose it, and you’re stranded outside your own infrastructure.

3. Die Kosten der Unvorbereitetheit

Wenn Hurrikane zuschlagen, stehen unvorbereitete Gemeinden vor katastrophalen Verlusten. Wenn Ransomware ungeschützte Umgebungen befällt, sind die Folgen ebenso verheerend:

Unprepared organizations struggle not only to restore data but also to rebuild trust chains between systems, domains, and users – often forcing a complete forest rebuild that takes weeks or months.

4. Lehren aus dem Sturm: Aufbau von Cyber- und Identitätsresilienz

A. Vorbereitung ist Prävention

  • Exportieren und validieren Sie regelmäßig Backups des AD-Systemstatus und Entra ID-Konfigurationen.
  • Implementieren Sie rollenbasierten Zugriff und privilegiertes Identitätsmanagement, um den Schadensradius zu begrenzen.
  • Speichern Sie saubere, unveränderliche Kopien sowohl der lokalen AD- als auch der Entra ID-Schemas in einem sicheren, luftisolierten Tresor.
  • Führen SieWaldwiederherstellungsübungendurch, die vollständige AD-Wiederherstellungen simulieren.

B. Der Belastung standhalten

  • Segmentieren Sie die Identitätsinfrastruktur und beschränken Sie Replikationspfade.
  • Verwenden Sie Richtlinien für bedingten Zugriff und Authentifizierungsstärke in Entra ID, um einen adaptiven Schutz durchzusetzen.
  • Wenden Sie Zero-Trust-Prinzipien an, um laterale Bewegungen und die Ausweitung von Berechtigungen einzudämmen.

C. Mit Zuversicht genesen

  • Commvault full forest recovery helps automate the end-to-end rebuild of AD forests – restoring DCs, trusts, and configurations from clean, immutable backups.
  • Entra ID Protection lässt sich in Wiederherstellungsworkflows integrieren, sodass cloud , Multi-Faktor-Authentifizierungsrichtlinien und Einstellungen für den bedingten Zugriff synchron wiederhergestellt werden.
  • Automated validation helps verify there’s no reinfection and no cross-contamination of credentials.

5. Der Resilienz-Entwurf: Von der Katastrophe zur Kontinuität

  • Assess: Identify your “digital coastline” – the systems and identities that define business continuity.
  • Protect: Harden your identity and data perimeter through zero trust and ongoing validation.
  • Isolate: Maintain immutable, air-gapped copies of AD, Entra ID, and critical data.
  • Recover: Use orchestrated tools like Commvault’s full forest recovery to restore identity and access rapidly.
  • Evolve: Update and retest your plan with every new patch, policy, or platform integration.

6. Commvault-Perspektive: Schneller wiederherstellen. Sauber wiederherstellen. Identität wiederherstellen.

Mitvollständiger Waldwiederherstellung für AD und integriertem Entra ID-Schutz, Commvault helps enable organizations to restore on-prem and cloud data and identities with integrity, speed, and confidence after a ransomware incident.

A hurricane tests the strength of your walls. Ransomware tests the strength of your resilience. You cannot stop every storm – natural or digital – but you can decide whether it destroys or defines you.

FAQs

Q: What makes identity loss so disruptive during ransomware recovery?
A: If AD or Entra ID is compromised, organizations can’t authenticate, authorize, or re-establish trust across systems – effectively locking themselves out of their own environment. Attackers often target domain controllers and trust relationships, so recovery must start with clean identity restoration before broader services can come back online.

Q: How big is the downtime and cost risk?
A: The paper cites typical ransomware downtime measured in weeks and total incident costs in the seven-figure range, with identity systems among top targets. These impacts compound when teams lack forest-level recovery capabilities or clean, immutable backups of identity configurations.

Q: What preparation steps most effectively reduce impact?
A: Regularly export and validate AD system-state and Entra ID configurations; apply role-based access and privileged identity management; keep immutable, air-gapped copies of identity schemas; and run full-forest recovery exercises to validate speed and coordination under pressure.

Q: How should recovery be orchestrated after an attack?
A: Start by isolating affected systems and pivot immediately to identity restoration from clean, immutable backups, then rebuild domain controllers, trusts, and policies in sync with cloud identity settings. Automated validation helps confirm a clean state and prevents credential cross-contamination during bring-up.

Q: What does a resilience blueprint look like in practice?
A: Follow five steps: Assess critical “digital coastline,” protect with Zero Trust and continuous validation, isolate with immutable air-gapped copies, recover with orchestrated full-forest workflows, and evolve by testing after every change in patches, policies, or platform integrations.

Jerry Carlson is Field CTO at Commvault.


Verwandte Blogs

More related posts


Thumbnail_Blog-Ransomware-and-Hurricane-2025

Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

Read more about Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

University of Illinois Chicago (UIC) is home to more than 34,000 studentsund13,000 facultyundstaff. Technology Solutions, UIC’s central IT organization, is responsible for ensuring the resilience of research, clinical,undadministrative systems.

We spoke with Dean Dang, Director of Enterprise ApplicationsundServices, about UIC’s data protection journeyundhow Commvault helps the university safeguard mission-critical operations.

 

Q: Can you start by introducing yourselfundgiving us a sense of UIC’s missionundwhat drives your IT strategy?

Dean: My name is Dean Dang,undI serve as the Director of Enterprise ApplicationsundServices within Technology Solutions. We support the university’s administrativeundacademic functions, aligning IT with UIC’s mission: to provide the broadest access to the highest levels of educational, research,undclinical excellence. Our commitment to access, vitality, empowerment,undcreativity is our strength.

 

Q: Before onboarding Commvault, what were the biggest data protectionundresilience challenges UIC was up against?

Dean: Our legacy backup system, Spectrum Protect, had accumulated years of technical debt. Recovery was painfully slow — restoring large file servers could take weeks. We also dealt with decentralized IT management across 20+ departments, inconsistent backup policies, inefficient tape storage,undno cloud options. The risks of data lossunddowntime were too high for a university of our size.

 

Q: When it came time to modernize, what stood out about Commvault that made it the right fit for UIC?

Dean: We’d known Commvault for over a decadeundtrusted it for Aktives VerzeichnisundExchange backups. When we evaluated options, Commvault stood out. The ability to takeVM snapshots without server agents was huge. Even more important was the multi-tenant model. It let us provide departmental autonomy while maintaining centralized governanceundsupport — exactly what higher ed needs.

 

Q: What changes have you seen since implementing Commvault,undhow has it elevated UIC’s cyber resilience?

Dean: With Commvault, we do nightly backups with deduplicationundsynthetic fulls. That reduces storage demandundspeeds up restores. Departments get their own “tenants” to manage backups, but we still enforce policiesundprovide support. All backups are encryptedundcan be stored on-prem or in the cloud.

We also use Air Gap Protect for immutable copiesundCleanroom Recovery for safe recovery testing. This setup means we can recover mission-critical systems in under 8 hours — compared to days or weeks before.

 

Q: If you were talking to other higher-ed IT leaders, what top lessons or best practices would you share about building cyber resilience?

Dean:

  1. Enforce multifactor authentication everywhere, especially admin accounts. Everyone can be phished.
  2. Build a pragmatic, team-driven DR plan. Don’t try to solve everything at once — build consensusundclarity.
  3. Test nightly backups. Make them immutable, air-gapped,undvalidated so you know you can restore when it matters.

 

Q: How do you communicate cyber risks to non-technical leaders?

Dean: We translate risk into business terms. How many hours of downtime? What does that cost in productivity, reputation,undcompliance? We use “what if” scenarios, dashboards,undregular updates on metrics like backup healthundrestore times. When leaders see the financialundmission impact, the case for resilience is clear.

 

Q: Looking ahead, how does Commvault fit into UIC’s long-term strategy?

Dean: UIC is hybrid — on-campus, cloud,undSaaS. Commvault covers all of it, from VMsunddatabases to M365undeven emerging AI workloads. With 95%+ deduplicationundtiered storage, we keep costs under control. And with anomaly detection, automation,undcleanroom testing, we’re preparing for a future where downtime is measured in hours, not days.

Read more about the University of Illinois of Chicago’s data protection journey here.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The psychologist Abraham Maslow famously said that if the only tool you have is a hammer, you tend to see every problem as a nail. And everywhere you look these days, companies are wielding AI like a hammer, hoping it can solve all their pressing business problems: “How can we use AI? How can we sell AI? How can we make money on AI?”

But here’s the thing – if you’re starting with those questions, you’re starting with a broken assumption. The right question isn’t “How do we use/sell/make a fortune with AI?” The right question is “What problems are we trying to solve?”

What Problem Are You Solving?

Technology should make us more capable of doing uniquely human work, not replace our capacity to think, create, and connect with each other. The approach of starting with the tool instead of the problem is why we’re seeing many AI implementations stall. Companies are throwing technology at problems they haven’t properly defined or understood.
The approach I recommend to any leader considering AI: Start by listing your actual problems. Not theoretical problems, not problems you think you should have, but the real pain points keeping your teams from working fast. Then ask: What tools do I have that can help solve these problems? AI might be one of those tools. It makes sense to explore AI solutions for tedious, repeatable, manual tasks. You likely can identify those opportunities in your organization easily.
But let’s say your employee engagement is suffering, and people have expressed needing better support during difficult times. You want human connection and emotional intelligence here, not algorithmic responses. Starting with the problem helps reveal the appropriate solution.

Should We Engineer Out the Human Element?

Today, AI excels at automating repetitive tasks – the digital equivalent of assembly line work. If your backup administrators are turning the same widgets over and over, or your data entry teams are focused on purely laborious spreadsheet work, AI absolutely can help. But I believe relationship building, creative problem-solving, and complex decision-making require human judgment, intuition, and contextual understanding that no algorithm today can yet replicate.
At Commvault, we’re committed to the ethical development and deployment of AI. We’ve employed it for tasks like turning complex regulatory documents into succinct summaries or helping create targeted versions of content. Saving this time for employees to focus on more value-added activities. None of this work happens without careful human oversight.
The companies I see succeeding understand this distinction. They use AI to eliminate tedious tasks so workers can focus on what humans do best: nuanced decision-making, building trust, navigating complex stakeholder relationships, and thinking through problems that don’t have clear precedents.

A Framework for Smart AI Adoption

Before implementing any AI solution, leadership teams should ask themselves these questions:

  1. What specific problem are we solving? Be concrete. “We want to be more efficient” isn’t specific enough.Try: “We want to automate X.”
  2. Why is this problem worth solving? What’s the real business impact?
  3. Where do we need human judgment to remain in the loop? Identify the decision points, beyond just high-risk scenarios, that demand wisdom, not just intelligence.
  4. How will we measure success? Not just adoption rates, but actual problem resolution.
  5. Revisit the conversation. Successful AI adoption is not a point-in-time measurement.

Read more inLeitprinzipien für verantwortungsvolle KI.

Der Weg nach vorn

Make time to establish procedures for data handling, privacy protection, and decision-making authority.Who controls what information gets fed into AI systems? What data absolutely cannot be uploaded to external AI platforms? How do you prevent customer data from being used to train models?

When you put information into an AI system, you may be sharing it not only with that vendor, but also with its cloud providers, sub-processors, and others in its data supply chain. A secret known by more than three people isn’t a secret anymore – so be careful before you hand yours to dozens of entities.
Learn more about Commvault’s approach at Prinzipien für verantwortungsvolle künstliche Intelligenz.
Danielle Sheer is Chief Trust Officer at Commvault.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

We are in the most consequential moment of change in our industry, with the widespread adoption of AI reshaping how enterprises operate, how data flows, and how decisions are made.This introduces new challenges and vulnerabilities for you to manage. Like the explosive growth of data; the evolving governance requirements for human and non-human identities; and new threats to AI-oriented identities, supply chains, and models.To make matters worse, the pressure is on you and your teams to enable your business to embrace AI with data that’s distributed and fragmented across clouds, applications, and endpoints. All of which introduces business risk while increasing the fragility of your AI systems.In anticipation of this evolution, Commvault has been broadening its industry-leading resilience focus to help you to secure data at source; to control identity access; and predictably and cleanly recover following an inevitable cyberattack or disruption.We call it ResOps, or resilience operations. It’s not a product – it’s a new operational approach that enables you to actively manage resilience across increasingly complex emerging AI environments.As you know, Commvault always has been obsessed with solving our customers’ most significant resilience challenges with elegant and innovative solutions. And today, we are taking it even further with the introduction of Commvault Cloud Unity – our next-gen platform to enable ResOps.The platform was built from the ground up to help unify previously disparate data security, identity, and recovery processes across today’s workloads and tomorrow’s emerging AI stacks. It no longer matters where your data lives – if it’s on-prem, cloud-bound, cloud-borne, or an emerging AI workload.In fact, Commvault has the broadest workload support. Across the multi-cloud alone, we cover more than 160 regions and over 200 public cloud services. And we simply manage it all through a single policy engine and a unified pane of glass.None of this would have been possible without our team’s foresight, engineering prowess, and commitment to continuously innovating to solve our customers’ hardest challenges.Want to learn more about ResOps and Commvault Cloud Unity? Klicken Sie hier Commvault’s SHIFT event on demand, and read our whitepaper ResOps: Die Zukunft widerstandsfähiger Unternehmen im Zeitalter der KI.


Sanjay Mirchandani is President & Chief Executive Officer of Commvault.

More related posts


Thumbnail_Blog-SHIFT-Sanjay-2025-Linkedin

Re-envisioning Resilience for the Age of AI

Read more about Re-envisioning Resilience for the Age of AI

Die wichtigsten Erkenntnisse

  • Streamlined process: Simplifies recovery through enhanced threat detection and validation.
  • Integrated experience: One simple process from threat identification to production recovery.
  • Readiness: Configure, plan, and test cyber recovery plans to uncover gaps.
  • Rapid detection and validation: Quickly identify clean points and validate recovery.
  • Confident recovery: Helps organizations confidently recover clean data, apps, and infrastructure.

In today’s landscape of relentless cyber threats, organizations are grappling with an unprecedented challenge: maintaining business continuity in the face of potential data loss and system compromise. The recent surge in sophisticated ransomware attacks has underscored the critical need for robuste Strategien zur Cyber-Resilienzbenötigt werden, die über herkömmliche Backup- und Wiederherstellungsmethoden hinausgehen.Commvault Cloud Cleanroom Recoverybietet einen innovativen Ansatz für diese Herausforderung. Durch die Schaffung einer bedarfsgerechten, sicheren und isolierten Umgebung können Unternehmen ihre Wiederherstellungspläne testen, gründliche forensische Untersuchungen durchführen und Produktionswiederherstellungen durchführen, ohne weitere Betriebsunterbrechungen zu riskieren.

Cyber Recovery + Forensik = Optimale Wiederherstellung

Ransomware threats targeting backup systems have become increasingly common, highlighting the vulnerabilities in conventional recovery processes. It’s no longer sufficient to simply have a recovery plan in place; organizations must rigorously test and validate their strategies to prepare to withstand real-world cyberattacks.

Cleanroom Recovery can help organizations seeking to maintain uninterrupted operations amid disruption. Das Testen Ihrer Cyber-Recovery-Pläneist ein wesentlicher Bestandteil zur Erreichung echter Cyber-Resilienz. Durch die Ermöglichung einer schnellen und zuverlässigen Recovery, die Minimierung von Ausfallzeiten und die Optimierung von Prozessen spielen Tests eine entscheidende Rolle bei der Stärkung der Geschäftskontinuität.

Da Unternehmen weiterhin robusten Cyber-Notfallplänen Priorität einräumen, kann die Bedeutung strenger Tests gar nicht hoch genug eingeschätzt werden. Mit wirksamen Testprotokollen können Unternehmen Schwachstellen identifizieren und sicherstellen, dass ihre Notfallstrategien auch angesichts sich ständig weiterentwickelnder Cyber-Bedrohungen weiterhin angemessen sind. Sobald ein Unternehmen regelmäßige Malware-Scans aller Backups eingerichtet und seine Pläne getestet hat, kann es forensische Analysen durchführen, um die Ursache eines Angriffs zu identifizieren und alle betroffenen Systeme zu untersuchen. Diese beiden Anwendungsfälle erhöhen das Vertrauen in die Durchführung einer optimalen Wiederherstellung.

What’s New in Cleanroom Recovery?

Building on its foundation, the latest Cleanroom Recovery innovations are introducing significant enhancements that further strengthen cyber recovery capabilities. These advancements deliver new capabilities that help organizations protect their critical infrastructure and data.

Recent and upcoming developments have bolstered Cleanroom Recovery’s capabilities in orchestration, security, and scalability, including early access to:

  • Cleanroom creation automation: Automate cleanroom deployment, cross hypervisor recovery and threat scanning inside the cleanroom to remove manual intervention​. (Generally Available)
  • Runbook experience: Ability to create multiple runbooks for critical assets for different use cases. Runbooks provide step-by-step execution playbooks with optional manual steps.​ (Early Access)
  • Expanded workload support: You can recover Active Directory forest along with VMs and files into a cleanroom for end-to-end application validation. ​(Early Access)
  • On-premises deployment capabilities: You now can use Cleanroom Recovery to recover critical application into an isolated recovery environment in an on-premises data center using air-gapped Hyperscale X (Early Access)

These advancements illustrate a continued focus on expanding the features, capabilities, and scale of Cleanroom Recovery. This is the next phase in Cleanroom Recovery’s evolution. The solution helps provide customers with enhanced efficiency, scalability, and adaptability, with the flexibility to deploy isolated cleanroom in cloud and on-premises.

Cleanroom Recovery helps enable customers to effortlessly spin up automated cleanrooms with streamlined runbooks and features threat scanning capabilities for comprehensive threat detection and recovery.

With this new evolution, organizations will be enabled to quickly and safely test their cyber recovery plans, validate applications, and execute a confident cyber recovery. Commvault is delivering one integrated experience from identifying threats to production recovery.

FAQs

Q: What is Cleanroom Recovery, and why is it important?
A: Cleanroom Recovery is a secure, isolated environment that enables organizations to test recovery plans and conduct forensic analysis without risking production systems. This helps organizations maintain continuous business operations and improve cyber resilience against modern ransomware threats.

Q: How does Cleanroom Recovery enhance cyber recovery readiness?
A: By automating cleanroom creation to conduct recovery testing and enabling forensic investigation, it helps organizations validate their recovery strategies, uncover vulnerabilities, and execute faster, more confident recoveries after cyber incidents.

Q: What are the main new features in the Cleanroom Recovery release?
A: Key innovations include automated cleanroom deployment, new runbook capabilities for multiple recovery scenarios, support for Active Directory recovery, and the ability to deploy in on-premises data centers with air-gapped Hyperscale X.

Q: How does Cleanroom Recovery improve security during recovery operations?
A: It isolates the recovery environment, scans for threats pre-/post-recovery, provides controlled orchestration, and helps reduce the risk of reinfection or unauthorized access during recovery.

Q: Can Cleanroom Recovery be deployed both on-premises and in the cloud?
A: Yes, organizations now can deploy Cleanroom Recovery in both cloud and on-premises environments, providing flexibility for hybrid infrastructures and diverse security requirements.

Q: Who benefits most from Cleanroom Recovery?
A: Enterprises seeking to strengthen their cyber resilience, particularly those facing ransomware risks or complex recovery needs, gain value from its automation, scalability, and integrated testing capabilities.Toussaint Brock is a Product Marketing Manager at Commvault.


Verwandte Blogs

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements