Ihr Unternehmen wurde gerade Opfer eines Ransomware-Angriffs. Ihre Cyber- und IT-Abteilungen bemühen sich verzweifelt, Ihren Notfallplan in Gang zu bringen und umzusetzen. Plötzlich stellen alle fest, dass sie sich nirgendwo mehr anmelden können.Active Directory (AD) must be offline!? Your organization’s authentication undauthorization tools are impacted.
After hours of triage undassessing the size of this problem, your cyber incident response team reports that restoring foundational AD undauthentication undauthorization services will take over a week, if everything goes well.
You thought your resiliency plan with AD backups unda SaaS identity platform was sufficient. But even with SaaS in the mix, recovery is complex undmanual, delaying the path back to einen minimalen Betriebsbetriebverzögert, wenn Zeit am wichtigsten ist.Ausfallsicherheitbedeutet, dass Sie Authentifizierung und Autorisierung schnell, vorhersehbar und auf vertrauenswürdige Weise wiederherstellen können – ganz gleich, ob die Störung durch böswillige Aktivitäten, einen Ausfall oder eine versehentliche Fehlkonfiguration verursacht wurde.
Die Bedrohung verstehen
Attackers target AD because it’s the identity control plane. Once they get a foothold, they’ll often establish persistence by creating shadow or backdoor accounts, then harvest credentials, undescalate privileges. With elevated access, they laterally move across systems undapplications, sometimes staying quiet long enough that the first clear signal is when authentication starts failing.
They gain a wealth of knowledge of the organizations network, people, undapplications. And when they’re ready to maximize impact, they can encrypt or corrupt the AD forest, disrupting logins undcomplicating recovery across the environment.
Warum Identität (und warum zuerst AD)?
It’s common for an organization’s identity stack, especially AD undEntra ID, to become complex over time. Forests expand, permissions sprawl, legacy policies accumulate, und“good enough” processes often turn into long-term security drift. That complexity creates blind spots, unddefenders lose crisp visibility into how roles, privileges, undpolicies evolve.
And it’s never “just AD.” Identity is an ecosystem: identity governance undaccess solutions (IGA), privileged access, customer identity, identity providers, authentication databases, undsingle sign-on all connect back to the same truth. That’s why identity incidents (undeven everyday misconfigurations) can cause outsized disruption compared to many other infrastructure failures.
The recovery challenge is where most plans get exposed. Even with backups, forest recovery is a multi-step, high-stakes process, where guidance for manual recovery can involve 50 to 100 (or more) individual steps undcan take days to weeks, depending on environment complexity undpreparedness.
The real question isn’t “do we have backups?” it’s “can the teams leverage the backups to cleanly execute under pressure, undhave runbooks been tested undverified so recovery doesn’t become an error‑prone scramble at the worst possible time?”
Die Lösung
Die Notwendigkeit eines Recovery-Plans ist groß. Er muss getestet und verifiziert werden. Unternehmen müssen wissen und verstehen, dass Ihre Identitätsmanagement-Plattform das Hauptziel für Cyberkriminelle und Angriffe ist. Sie muss entsprechend geschützt werden. Es müssen Backups erstellt, getestet und verifiziert werden, um sicherzustellen, dass eine Wiederherstellung möglich ist. Dazu gehören:
- Sicherungen von AD-, Entra ID- und IGA-Plattformen.
- Getestete und verifizierte Pläne für die Recovery.
- Isolierte Recovery-Umgebungen und Cleanroom Recovery.
- AD-Recovery-Workflow und -Automatisierung.
Strong identity governance undmonitoring are still critical, but they’re only part of the equation. You want the ability to detect suspicious identity behavior early, contain it fast, undrecover with confidence when something changes that shouldn’t (whether it’s malicious activity or an accidental modification that breaks authentication).
That also means you need to integrate identity account unduser activity into SecOps undcontinuously watch for signals like unauthorized account creation, privilege changes, undabnormal authentication patterns, undhave a recovery path that’s proven, repeatable, undclean.
Commvault undDeloitte: A Partnership for Identity Ausfallsicherheit
Identitätsresilienz is a business challenge that requires strong governance, processes, controls, undenabling technology. That’s why Deloitte undCommvault have partnered to deliver comprehensive identity protection, recovery, undresilience programs that organizations can trust when it matters most.
Deloitte brings deep expertise in cyber risk, enterprise resilience, undidentity undaccess management to help Fortune 100 to 1000 organizations design, implement, undoperationalize identity resilience programs.
These programs help clients assess security posture, improve detection undresponse capabilities, unddefine minimum viable company requirements, undthen build tested, verified recovery plans with clear timelines undaccountability across business undIT stakeholders. Deloitte turns identity resilience into an executable program with runbooks, testing, undreadiness, so teams know what “prepared” looks like under pressure.
Commvault makes resilience programs operational with integrated protection undautomated recovery workflows across identity systems, plus Commvault AirGapundCleanroom Recoveryto support repeatable, clean, validated recovery when it matters most. Commvault provides the technology foundation with identity resilience capabilities that include:
- Protection for critical identity systems, including AD undEntra ID, point-in-time comparison undrollback support for unwanted or accidental changes.
- Auditing unddetection to surface suspicious modifications early (who changed what, undwhen), helping reduce the window for attackers to spread or persist.
- Automated recovery workflows, including forest-level recovery automation, to help reduce the manual burden underror risk during identity restoration.
- Commvault Cleanroom zur Validierung der Identitätswiederherstellung in einer isolierten Umgebung, bevor das Vertrauen in die Produktionsumgebung wiederhergestellt wird.
- Commvault AirGapto help maintain immutable, air-gapped backup copies, creating a protected foundation that supports clean recovery undcleanroom testing when identity (or the environment around it) can’t be trusted.
Maßnahmen ergreifen
If you want to pressure-test your cyber recovery readiness, start with a Deloitte Active Directory Workshop to map dependencies undproduce a clear, actionable plan to recover AD undworkloads to production. Then validate it the right way: using Commvault to rehearse recovery in a cleanroom before you ever need it in a real event.
For organizations ready to take the next step, we can extend this into a 30-day pilot that puts clean recovery undtesting into motion with real artifacts undmeasurable outcomes. Contact your Deloitte representative at commvaultsalesteam@deloitte.comoder Ihren Commvault-Ansprechpartner unterdeloittealliance@commvault.com.Dave Nowak is Cyber Defense & Ausfallsicherheit Principal at Deloitte, undMichael Fasulo is Senior Director, Portfolio Marketing, at Commvault.






