Skip to content

The importance of robust data protection solutions cannot be overstated, especially for state and local government agencies, as well as educational institutions.Commvault has achieved GovRAMP Authorized status for its cyber resilience SaaS solutions. Combined with our status of FedRAMP® High Authorized and FIPS 140-3 Validated, this accomplishment further solidifies our position as a trusted partner for public sector organizations across the United States.

Was ist GovRAMP?

GovRAMP, früher bekannt als StateRAMP, ist eine führende Instanz für Cloud-Sicherheitsstandards für Landes- und Kommunalverwaltungen. Die Organisation bietet einen standardisierten Ansatz zur Bewertung und Zulassung von Cloud-Diensten und unterstützt diese Organisationen dabei, die Komplexität der Cloud-Sicherheit souverän zu meistern.

Die Bedeutung der GovRAMP-Zulassung

Achieving GovRAMP Authorized status at the High baseline is a testament to our ability to meet the government’s stringent security and risk management standards. By securing this authorization, Commvault demonstrates our unwavering commitment to data protection and dedication to building trust within the public sector. Commvault stands out as the only cyber resilience vendor to hold all three of these authorizations:

Vorteile für Behörden

Der Status „Commvault Cloud GovRAMP Authorized“ bestätigt, dass staatliche und kommunale Behörden sowie Bildungseinrichtungen folgende Vorteile genießen:

  1. Enhanced security to help protect data is against breaches and unauthorized access according to the highest security standards.
  2. Verification assurance that demanding federal and state regulatory requirements are met, reducing the risk associated with non-compliance.
  3. Organizational trust and credibility among government agencies through adherence to recognized, rigorous security.
  4. Seamless adoption, with a simplified procurement and implementation process for agencies requiring GovRAMP Authorized solutions.
  5. Risk mitigation of operational, financial, and reputational risks associated with data breaches and legal issues.
  6. Innovation and flexibility by leveraging advanced, secure cloud solutions for cyber resilience that enable them to stay ahead of emerging threats.

For more information about Commvault Cloud and Commvault’s commitment to the public sector, visit https://www.commvault.com/use-cases/public-sector.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

This year marks two decades of collaboration between Commvault and Hitachi Vantara —20 years working side by side to support businesses through constant change and increasing complexity.

What started as a technology alliance has grown into a trusted partnership focused on helping organizations stay secure, resilient, and ready for what’s next. From global enterprises to innovative startups, we support teams modernizing data environments, scaling operations, and digitally transforming their business with robust performance and industry-leading cyber resilience capabilities.   Together, we’ve built deeply integrated solutions to enable continuous business.

Unsere Lösungen unterstützen Unternehmen dabei:

  • Anticipate and mitigate cyber threats
  • Eliminate downtime and minimize disruption
  • Schnelle Recovery ermöglichen, um die Geschäftskontinuität zu gewährleisten
  • Manage and secure data across hybrid environment

Here’s to two decades of innovation and to our 1300+ joint customers that trust us with their Cyber Resiliency journey. 


​“Commvault and Hitachi Vantara have enjoyed a longstanding partnership, collaborating to deliver advanced cutting-edge cyber resilience solutions. Our partnership has led numerous innovations aimed at enhancing data security and readiness for global enterprises. We’re excited to continue advancing our new technology offerings together with Hitachi Vantara for years ahead.”
–Alan Atkinson, Commvault Chief Partner Officer


“Celebrating 20 years of innovation, Hitachi Vantara and Commvault have built a trusted partnership focused on delivering high performance data protection and recovery solutions cutting-edge cyber resiliency solutions. We empower businesses with secure, scalable, and reliable data security in 86 countries and have protected over 1 Exabyte of data together. As we look to the future, we are excited to build upon this legacy of success, helping organizations unlock the full potential of their data, while ensuring its integrity and availability for years to come.”
Greg Bucyk, Hitachi Vantara VP, Strategic Partners and Alliances


 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Cyber resilience is more than just a buzzword – it’s a critical component of business strategy. So says Rosa Kariger, a leading expert in cybersecurity, who recently joined Commvault President and CEO Sanjay Mirchandani on the Resilience Uncompromised podcast. Rosa reflects on her experience as CISO at Iberdrola and in cybersecurity at the World Economic Forum and shares valuable insights on how organizations can build a culture of cyber resilience.

Cyber-Resilienz als operatives Risiko verstehen

Cyber resilience isn’t just about having robust disaster recovery and backup systems. It’s about enabling your business to continue to function and provide essential services even when your IT infrastructure is compromised. Rosa emphasizes that cyber resilience should be integrated into your overall risk management strategy. This means treating cybersecurity as a strategic business enabler, not just a technical challenge.

Die Bedeutung der Vorsorge

Vorbereitung ist ein Eckpfeiler der Cyber-Resilienz. Rosa betont die Notwendigkeit der Szenarioplanung, insbesondere für Situationen, in denen es zu einem vollständigen Verlust der Konnektivität kommen könnte. Es ist unerlässlich, einen Plan B für kritische Geschäftsfunktionen parat zu haben. So kann Ihr Unternehmen den Betrieb aufrechterhalten und seine Kunden auch während eines Cybervorfalls weiterhin bedienen.

Klare Zuständigkeiten und Verantwortlichkeiten

Der Aufbau einer Kultur der Cyber-Resilienz erfordert klare Zuständigkeiten und Verantwortlichkeiten. Rosa weist darauf hin, dass jeder Mitarbeiter, insbesondere diejenigen, die Technologien einsetzen, für die Cybersicherheit ihrer Prozesse verantwortlich gemacht werden sollte. Cybersicherheit sollte nicht allein in der Verantwortung des CISO oder der IT-Teams liegen. Vielmehr sollte sie eine gemeinsame Verantwortung des gesamten Unternehmens sein.

Technische Fachkräfte sollten Anreize erhalten, die Cybersicherheit zu gewährleisten, da sie für die Qualität, Effizienz und Kosten der Technologie verantwortlich sind, an der sie arbeiten. Dieser Ansatz integriert die Cybersicherheit in den Kern der Geschäftsabläufe und stellt sicher, dass sie nicht als Nebensache behandelt wird.

Die Rolle der Cybersicherheitsabteilung

Die Cybersicherheitsfunktion sollte als Berater und zweite Verteidigungslinie fungieren. Das bedeutet, dass sie der Organisation Orientierungshilfen und Informationen liefert, während die konkreten Aufgaben im Bereich der Cybersicherheit in den technischen und operativen Teams verankert sind. Auf diese Weise kann die Cybersicherheitsfunktion strategische Einblicke und Unterstützung bieten und so dazu beitragen, eine widerstandsfähigere und sicherere Organisation zu schaffen.

Praktische Schritte zum Aufbau von Cyber-Resilienz

Building a culture of cyber resilience is not just about implementing advanced security technologies; it’s about fostering a mindset where every employee understands and takes responsibility for cybersecurity. Here are some practical steps and real-world examples to help organizations achieve this:

  1. Integrate cyber risk into overall risk management: This means that risks associated with technology use are identified, accepted, and managed at all levels. By doing so, employees are better prepared to handle cyber incidents, maintaining continuous business continuity even when technology fails.
  2. Increase preparedness: Conduct regular scenarios of complete loss of connectivity or other major disruptions. This helps in increasing the organization’s tolerance to failure. For example, a financial institution might simulate a scenario where all digital transactions are halted, and employees must rely on manual processes to continue operations.
  3. Define clear roles and responsibilities: Confirm that every team, including technical and operational roles, has clear cybersecurity responsibilities. This distributed accountability makes everyone incentivized to maintain security. For instance, in an industrial setting, an engineer working on the digitalization of a process should be accountable for the cybersecurity of that process, not just the CISO.
  4. Provide proper training: Training is crucial to enable employees to manage cybersecurity risks effectively. Technical professionals should be trained to understand and mitigate cybersecurity risks in their specific roles. This verifies that they are knowledgeable and capable of implementing necessary safeguards.
  5. Implement a “sustain” strategy: Develop a Plan B to maintain continuous business during IT infrastructure disruptions. This could involve having backup systems, manual processes, or alternative communication channels. For example, a healthcare provider might have a plan to use paper records and manual check-ins if their electronic health records system goes down.

Durch die Befolgung dieser Schritte können Unternehmen eine solide Kultur der Cyber-Resilienz aufbauen. Dieser Ansatz trägt dazu bei, alle Beteiligten auf den Umgang mit Cybervorfällen vorzubereiten, den Geschäftsbetrieb aufrechtzuerhalten und sensible Informationen zu schützen.

Cyberresilienz ist ein Prozess, kein Endziel. Indem Sie Cybersicherheit in Ihre Risk-Management-Praktiken integrieren, eine Kultur der Verantwortlichkeit fördern und dafür sorgen, dass Ihre Mitarbeiter gut vorbereitet und informiert sind, können Sie dazu beitragen, ein widerstandsfähiges Unternehmen zu schaffen, das für jede Herausforderung gewappnet ist. Bleiben Sie proaktiv, bleiben Sie auf dem Laufenden und bleiben Sie widerstandsfähig.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Jane Frankland, eine erfahrene Expertin für Cybersicherheit und Verfechterin von Frauen in der Tech-Branche, war kürzlich zu Gast bei Darren Thomson im STRIVE-Podcast, um über die gravierende Kluft zwischen IT- und Sicherheitsteams zu sprechen. Mit über 28 Jahren Erfahrung in diesem Bereich bringt Jane eine einzigartige Perspektive ein, indem sie ihren Hintergrund in Kunst und Design mit ihrer fundierten Expertise im Bereich Cybersicherheit verbindet. Ihre Erkenntnisse sind nicht nur informativ, sondern bieten auch praktische Lösungen für Unternehmen, die ihre Sicherheitslage verbessern möchten.

Die Lücke zwischen IT und Sicherheit

Jane and Darren delve into the longstanding issue of the gap between IT and security teams. While both the CIO and the CISO aim to support the business, their objectives often conflict. The CIO is focused on innovation and digital transformation, driving the organization forward with new technologies and processes. On the other hand, the CISO is tasked with reducing risk and upholding compliance, which can sometimes be seen as a hindrance to the CIO’s goals.

This conflict can lead to the CISO being perceived as a disabler, rather than an enabler. Jane shares that this gap has existed for many years and is getting worse. She notes that CISOs are sometimes removed by CIOs because, in performing the duties of their job, they slow down the CIO’s mission. This highlights the need for better alignment and collaboration between these roles.

Die Lücke schließen

Jane schlägt mehrere Strategien vor, damit diese Rollen besser zusammenarbeiten können:

  1. Collaborative projects: Involve both the CIO and CISO in initiatives, such as cyber recovery planning and system patching, from the start. This enables security to be integrated into the project from the beginning, rather than being an afterthought.
  2. Aligned incentives and KPIs: When both teams work toward the same goals, it encourages collaboration and fosters a more cohesive and effective approach to security.
  3. Understanding the business: CISOs need to understand the business and build relationships with other stakeholders. This helps them serve the business better and avoid being seen as a disabler. Jane emphasizes the importance of CISOs being able to communicate the value of security to non-technical stakeholders.
  4. Defining risk tolerance: Organizations should define their risk tolerance at the board level. This provides a clear framework for both the CIO and CISO to work within, and keeps innovation and security are aligned.

Kulturelle und organisatorische Herausforderungen

Jane berichtet zudem von mehreren Anekdoten, die die kulturellen und organisatorischen Herausforderungen im Bereich der Cybersicherheit verdeutlichen. Sie erwähnt, dass die Kluft zwischen dem IT-Infrastrukturteam und dem Sicherheitsteam schon seit Langem ein Problem darstellt. Die gegensätzlichen Ziele des CIO und des CISO können zu einem toxischen Umfeld führen, in dem Sicherheit als Hindernis für den Fortschritt angesehen wird.

Um diese Herausforderungen zu bewältigen, plädiert Jane für einen kulturellen Wandel. Dazu gehört, Sicherheit fest in der Organisation zu verankern, anstatt sich ausschließlich auf Technologie zu verlassen. Sie betont, wie wichtig es ist, dass die Führungskräfte an einem Strang ziehen, und dass der CIO und der CISO auf Vorstandsebene auf einer Linie liegen müssen.

Jane’s Impact and Advocacy

Jane’s extensive experience and unique background make her a valuable voice in the cybersecurity community. She is a brand ambassador and has been recognized on the King’s New Year’s Honours List for her contributions to the field. Her IN Security Scholarships have helped 442 women, significantly increasing cyber literacy and inclusion.

Ihr Engagement für die Förderung vielfältiger Perspektiven und insbesondere für die Unterstützung von Frauen spiegelt sich deutlich in ihrer Arbeit wider. Jane ermutigt Fachleute aus anderen Bereichen als der Sicherheit, mit Sicherheitsteams zusammenzuarbeiten und ihre Cyberkompetenz zu verbessern. Dies trägt nicht nur dazu bei, die Kluft zwischen IT und Sicherheit zu überbrücken, sondern schafft auch ein relevanteres und inklusiveres Umfeld für alle.

Ein Fahrplan zur Überbrückung der Kluft

Jane and Darren’s conversation on the STRIVE podcast offer practical for organizations looking to better align their IT and security functions and leaders. By fostering collaboration, aiming for common goals, and embedding security into the organization, businesses can create a more secure and innovative environment. Jane’s advocacy for increased cyber literacy and inclusion further underscores the importance of a holistic approach to cybersecurity.

Die komplette Folge finden Siehier.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

What if AI autonomously handled software development? Agentic AI systems, like GitHub Copilot Workspace, already aim to take high-level requests and autonomously write, test, and debug code. This leap beyond generating snippets to automating end-to-end cognitive workflows reshapes knowledge work and software interaction. Understanding Agentic AI’s impact on strategy, roadmaps, and workforce is now imperative for leaders. According to respondents of a recent Boston Consulting Group survey, one in three companies globally is planning to allocate over $25 million to AI in 2025.

Definition der agentenbasierten KI: Über Chatbots hinaus zu autonomen Akteuren

Forget simple chatbots. Agentic AI represents systems designed to autonomously pursue goals. Given a high-level objective, an agentic system can devise a plan, execute steps by interacting with various digital tools (APIs, browsers, applications), and adapt based on outcomes. It’s the transition from AI that responds based on patterns to AI that acts to accomplish specific tasks.  

Much confusion stems from the fact that agentic AI often leverages powerful Gen AI models like OpenAI’s GPT-4o or Google’s Gemini as its core reasoning engine. However, the agentic framework – exemplified by platforms emerging from OpenAI’s Assistants API or open source toolkits – provides the crucial layers of autonomy, planning, memory, and tool interaction. Imagine that instead of having a powerful engine, you have a self-driving vehicle that uses that engine to navigate traffic, follow routes, and reach a destination. This dynamic capability separates it sharply from brittle, script-following robotic process automation.  

Agentische vs. generative KI: Der praktische Durchbruch, der den Hype antreibt

Generative AI’s power to create content – from code snippets via the original GitHub Copilot to marketing copy via Jasper – is undeniable. However, agentic AI harnesses this generative power and makes it actionable. It’s the difference between asking an AI to write Python code vs. asking an agent to build, test, and debug a functional Python script that integrates with a specific API to achieve a business outcome.  

The current wave of hype, evident in soaring valuations for AI startups and intense focus from tech giants, stems from this leap to autonomous action. While Gen AI might draft sections of a business plan, an agentic system could be tasked with “Analyze market trends for Product X, identify key competitors, draft a competitive strategy document, and schedule a review meeting,” orchestrating research, analysis, generation, and scheduling tools. This potential for automating complex, multi-step workflows end to end, moving beyond human-in-the-loop for every step, fuels the immense strategic interest and investment.  

Der „Agentic Imperative“: Software neu gestalten, etablierte Akteure herausfordern

Why is virtually every software company, from hyperscalers to SaaS providers, racing to develop an agentic strategy? Because it promises to redefine user interaction and software value. As Microsoft CEO Satya Nadella said, technologies like Copilot “fundamentally change how we relate to computing,” acting as orchestrators.  

Wir beobachten, wie sich dies rasch entwickelt:

  • Microsoft’s Copilot Ecosystem: The broad rollout of Microsoft 365 Copilot across Word, Excel, and Teams isn’t just about embedding generative features; it’s about enabling users to delegate tasks like “Summarize unread emails from Project Phoenix and flag action items” or “Analyze Q4 sales data in this Excel sheet and create a PowerPoint summary.” The recent launch of GitHub Copilot Workspace explicitly targets this, aiming to take developer requests from issue description to tested pull request with minimal intervention.  
  • Google’s Agentic Integrations: Google continues to weave Gemini more deeply into Workspace, enabling complex cross-app actions. The evolution of AI Overviews in Search hints at a future where Search doesn’t just provide links but performs actions or complex research tasks directly.  
  • Salesforce, ServiceNow, Adobe: These platforms are integrating agentic features (like Salesforce Einstein Copilot or ServiceNow’s Now Assist) to automate complex CRM, IT service management, and creative workflows, allowing users to interact via natural language goals rather than complex UIs.  
  • Startups: Companies like Adept AI, focused on teaching AI to use existing software interfaces, underscore the ambition to create universal agents, attracting significant venture capital interest throughout 2024.  

This trend threatens to disrupt established software models. If users can achieve complex outcomes through conversational agents layered on top of traditional applications, the underlying application’s UI and feature set become less critical. Incumbents must adapt or risk being abstracted away.

Neugestaltung des Datenschutzes: Auf dem Weg zu autonomer Cyber-Resilienz

Die Datenschutzbranche, die mit eskalierenden Cyberbedrohungen wie den ausgeklügelten, mehrstufigen Ransomware-Angriffen konfrontiert ist, die Ende 2024 zunehmend zu beobachten waren, benötigt dringend die proaktiven Fähigkeiten, die agentische KI verspricht:

  • Proactive defense beyond anomaly detection: Existing AI flags anomalies, but agentic systems could go further. Imagine an agent detecting ransomware reconnaissance patterns, autonomously snapshotting critical VMs via the backup platform, verifying snapshot integrity, and isolating suspicious endpoints before encryption begins – drastically reducing blast radius.
  • Intelligent, context-aware recovery: Instead of rigid recovery plans, an agent could analyze an attack’s scope (e.g., using threat intelligence feeds via API), identify the safest recovery points across multiple systems, orchestrate the restore using the backup infrastructure, perform automated data validation checks, and even generate post-incident reports.  
  • Dynamic policy optimization: Agents could analyze evolving compliance mandates (like updated GDPR or CCPA rulings) or observed protection gaps and automatically adjust backup policies, frequencies, and retention settings, maintaining continuous alignment without manual overhead.  

Commvault, Arlie und die Zukunft: Agente-basierte Strukturen für Datenresilienz

Navigating this evolution requires a data resilience platform built for an AI-driven world. At Commvault, our AI copilot, Arlie, already leverages AI to provide insights and streamline operations. But our vision extends further, toward enabling Agentic Fabrics.  

This concept envisions an intelligent, interconnected architecture where AI agents, guided by Arlie, operate and coordinate autonomously across your hybrid data landscape. This isn’t just about one assistant; it’s about a network of specialized agents working together:

  • Ein Agent, der den Sicherheitsstatus überwacht, könnte eine Bedrohung erkennen und über Arlie einen anderen Agenten benachrichtigen, damit dieser die entsprechenden Backups sofort sichert.
  • Following user intent (“Recover the CRM database to its state before yesterday’s suspicious activity”), Arlie could direct agents to orchestrate the complex restore across application servers, databases, and cloud storage, confirming data integrity post-recovery.
  • Die Mitarbeiter könnten proaktiv Möglichkeiten zur Kosteneinsparung identifizieren, indem sie Datennutzungsmuster analysieren und „kalte“ Daten auf der Grundlage von Richtlinienzielen automatisch in kostengünstigere Speicherebenen verschieben.

The Agentic Fabric represents the next evolution in intelligent architecture – a coordinated ecosystem where AI agents operate autonomously yet collaboratively across your entire data landscape. This isn’t merely about deploying isolated assistants; it’s about creating an interconnected network of specialized agents that communicate and coordinate seamlessly:

  • Sicherheitsagenten können Bedrohungen sofort erkennen und ohne menschliches Eingreifen Schutzmaßnahmen durch andere spezialisierte Agenten auslösen.
  • Recovery processes can follow natural language intent (“Restore our systems to before the breach”) while orchestrating complex technical workflows across hybrid environments.
  • Die Ressourcenoptimierung erfolgt kontinuierlich, da die Mitarbeiter proaktiv Effizienzpotenziale identifizieren und diese gemäß den vom Unternehmen festgelegten Richtlinien umsetzen.

This shift toward Agentic AI demands organizations reconsider three critical dimensions: their data architecture (enabling it to support autonomous yet secure agent operations), their governance frameworks (establishing appropriate guardrails for agent actions), and their resilience strategies (leveraging agents to anticipate rather than merely respond to threats). Organizations that embrace this paradigm won’t simply gain incremental efficiencies – they’ll fundamentally transform how they protect, manage, and leverage their data assets.

As the digital landscape grows increasingly complex and threat vectors multiply exponentially, the question becomes unavoidable: Is your organization preparing for a world where AI doesn’t just assist your team but actively safeguards your most valuable assets? The agentic revolution isn’t approaching – it’s already reshaping enterprise technology. Are you ready to evolve with it?

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Groundbreaking advances in cloud to massively powerful GPUs to transformer architectures and large language models have exploded the boundaries of AI, fueling optimism, experimentation, and the race to invest and implement AI solutions. Unfortunately, this enthusiasm has not only been met with mixed results, but has introduced more risk to an organization’s security, resilience, and long-term sustainability.

Wie alle Innovationen bringen auch KI-Systeme neue Schwachstellen, Angriffsvektoren und Variablen mit sich, die Ihre Anfälligkeit erhöhen und Ihre Integrität, Vertraulichkeit und Verfügbarkeit gefährden könnten. Unser WhitepaperEin pragmatischer und widerstandsfähiger Ansatz für KIhilft Ihnen dabei, eine umfassende Strategie zu entwickeln, um diesen Herausforderungen zu begegnen.

Angreifer können KI nutzen, um Malware oder raffinierte Phishing-Angriffe zu entwickeln, die Ihre Mitarbeiter ins Visier nehmen und in Ihr Unternehmen eindringen. Oder sie können gezielt Ihre KI-Systeme über eine spezielle Hardwareumgebung angreifen, versuchen, Ihre firmeneigenen KI-Modelle zu stehlen, oder mithilfe von „Data Poisoning“ Trainingsdaten für böswillige Zwecke manipulieren.

Diese KI-gesteuerten Cyberangriffe mit geringem Risiko und hoher Rendite werden immer zahlreicher und ausgefeilter – und das zu einer Zeit, in der die Aktualisierung und Bereitstellung von Gegenmaßnahmen zur Cybersicherheit immer kostspieliger wird. Die Kosten und die Komplexität werden noch dadurch verstärkt, dass KI-Daten und -Workloads sich über mehrere Systeme, Clouds und Anwendungen erstrecken.

To keep yourbusiness safe and continuous, you need to adopt a comprehensive cyber resilience strategy and platform that spans the depth of your AI data systems and the breadth of these new workloads. You need a solution that proactively scans for anomalies, remediates threats, and helps you get back to business faster through better planning, testing, and recovery capabilities.

This approach to resilience relies on the latest AI capabilities to dramatically improve recovery time. From increasing threat intelligence and anticipating risks to automating and orchestrating recoveries, AI not only responds to an attack, but adapts and learns in real time. For instance, Commvault’s cyber resilience platform leverages AI algorithms today to:

  • Identify and prioritize clean recovery points for an automated and rapid data recovery. 
  • Ermitteln Sie sensible Informationen, identifizieren Sie gefährdete Ressourcen und erfassen Sie Netzwerkkonfigurationen, Abhängigkeiten und Metadaten in einer Hybrid- oder Multi-Cloud-Umgebung.
  • Ermitteln Sie Risiken, Compliance-Aspekte und forensische Aspekte, die nachvollziehbar und umsetzbar sein müssen, damit Sie die Anforderungen des Vorstands in Bezug auf Risiken und regulatorische Vorgaben erfüllen können.
  • Verbesserung unseres Support-Erlebnisses durch die Bereitstellung automatisierter Self-Service- und Fehlerbehebungsfunktionen für Kunden.

From creating automated runbooks – to using automation to write recovery plans – to spinning up sophisticated chatbots, AI is the foundation for an entirely new resilience paradigm. Our white paper Ein pragmatischer und widerstandsfähiger Ansatz für KIwurde verfasst, um Ihnen dabei zu helfen, in einer von KI geprägten Welt widerstandsfähiger zu sein.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Here at Commvault, we’re committed to building a culture of community and belonging.

Throughout March, we celebrated Women’s History Month and honored the contributions, achievements, and resilience of women – both past and present. Here’s a recap on how we came together as a global Vaulter community this past month to celebrate the women in our lives.

We kicked off our celebrations with an energizing fireside chat event with our Chief Marketing Officer, Anna Griffin, and May Habib, CEO and co-founder of generative AI platform Writer, that focused on the importance of gender equality for International Women’s Day (IWD).

This year’s global theme was #AccelerateAction, which emphasizes the importance of taking swift and decisive steps to achieve gender equality. To share in our strength, we shared photos striking the official IWD pose. Check out this blogto learn more about how we celebrated IWD. And moreover, our female leaders also shared how they accelerate action each day in their roles – watch those videos below.

Den ganzen Monat über haben wir vier „Lean-In“-Zirkel als Pilotprojekt durchgeführt, um die Frauen bei Commvault zu befähigen, Führungsrollen zu übernehmen und sich neuen Herausforderungen zu stellen. Dieses Programm bietet die Möglichkeit, Kontakte zu knüpfen, sich zu vernetzen und über Führungskräfteentwicklung zu diskutieren – und zwar mithilfe eines erstklassigen Führungskräfte-Lehrplans in Verbindung mit regelmäßiger Beratung und Unterstützung durch Kolleginnen. Außerdem haben wir verschiedene Wellness-Veranstaltungen zu Themen wie finanzielle Absicherung, Yoga und Meditation sowie reproduktive Gesundheit organisiert.

To conclude the month, this week our Women in Technology and Multi-Culture ERGs hosted a courageous conversation with special guest, Jenny Jing Zhu, chairwoman of Lush Décor & founder of Dream Weavers Foundation. Jenny shared her journey of defying cultural expectations, navigating entrepreneurship, and building Lush Décor from the ground up and how she scaled the company to $100M+ in revenue, and founded the Dream Weavers Foundation, a mission-driven initiative empowering women to dream beyond their circumstances.

Wir unterstützen und stärken die Frauen bei Commvault jeden Tag aufs Neue.Klicken Sie hier,um mehr über unsere Commvault-Kultur und unser Engagement für Gemeinschaft und Zugehörigkeit zu erfahren.

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Microsoft Active Directory (AD) ist der Eckpfeiler der meisten IT-Netzwerke in Unternehmen und sorgt für die unverzichtbare Authentifizierung und Autorisierung geschäftskritischer Anwendungen und Ressourcen. Aufgrund seiner zentralen Rolle ist es zudem ein Hauptziel für Angreifer, die darauf abzielen, Unternehmen zu kompromittieren oder in manchen Fällen sogar das gesamte Netzwerk lahmzulegen. Wenn AD ausfällt, kommt der Geschäftsbetrieb zum Erliegen. Sind Sie auf den schlimmsten Fall vorbereitet?

Today, we’re thrilled to announce the general availability of Commvault Cloud Backup & Recovery for Active Directory Enterprise Edition, offering full, automated forest recovery for AD that enables rapid restoration of the AD forest to help maintain continuous business.

AD Recovery is Foundational to Continuous Business

AD ist das Herzstück für sichere Authentifizierung und Dienste, und seine Wiederherstellbarkeit ist bei Ausfällen oder Ransomware-Angriffen von entscheidender Bedeutung. Anwendungen, Dateisysteme, E-Mail-Dienste und Datenbanken sind alle auf AD angewiesen, um eine ordnungsgemäße Authentifizierung und eine sichere Benutzerzugriffskontrolle zu gewährleisten. Wenn AD also beschädigt oder vollständig außer Betrieb gesetzt wird, sind die kritischen Anwendungen und Dienste, die es unterstützt, nicht mehr zugänglich.

Consider the impact: Bank staff can’t access customer accounts. Doctors and nurses can’t access medical records. Coders and developers can’t publish code. Teams can’t collaborate or chat to get work done.

Ohne AD kann der Geschäftsbetrieb nicht fortgesetzt werden. Cyberkriminelle wissen das, weshalbsie AD bei 9 von 10 Cyberangriffen zu einem Hauptziel machen. Im Falle einer Katastrophe ist die Wiederherstellung von AD von entscheidender Bedeutung, doch bisher war dies sehr schwierig und erforderte komplizierte, zeitaufwändige manuelle Prozesse.

With ransomware increasingly targeting critical identity infrastructure, having a well-documented and frequently tested recovery plan to restore and rebuild your entire AD environment to a pre-attack state is essential.  

The Complexities of AD Forest Recovery

Microsoft bietet in seinemActive Directory Forest Recovery Guidekonkrete Anleitungen zum Wiederaufbau einer gesamten Active Directory-Gesamtstruktur nach einer katastrophalen Störung. Aufgrund der Komplexität von Active Directory sind die bei einer vollständigen Recovery der Gesamtstruktur erforderlichen Schritte streng vorgegeben, zeitaufwendig und äußerst anfällig für menschliche Fehler. Je nach Komplexität Ihrer Active Directory-Architektur kann der Prozess 50 bis 100 oder sogar noch mehr Aufgaben umfassen.

Due to the distributed nature and multi-master architecture of AD, restoring it demands meticulous coordination. It’s not possible to simply restore domain controllers from backup and call it a day. There are dozens of intricate hygiene steps that need to be performed on the recovered domain controllers and within AD itself at very specific points throughout the forest recovery. If these steps are not followed correctly, you risk introducing new corruption or inconsistencies in the recovered environment, which can be very difficult, if not impossible, to resolve.

Wenn man sich auf einen manuellen Notfall- oder Cyber-Recovery-Plan und Standardtools verlässt, kann die Wiederherstellung einer gesamten AD-Gesamtstruktur Tage dauern. Im Katastrophenfall ist Zeit ein entscheidender Faktor, und je länger es dauert, die AD-Komponenten wieder in einen funktionsfähigen Zustand zu versetzen, desto größer sind die Auswirkungen auf den Geschäftsbetrieb.

Automate and Accelerate AD recovery with Commvault Cloud

Commvault Cloud Backup & Recovery for AD Enterprise Edition brings a new level of resilience to AD by enabling automated, rapid recovery of the Active Directory forest to a pre-attack state. This automation eliminates slow and error-prone manual processes, reducing the risk of errors and accelerating recovery times. Here’s how it works:

  • Make AD recovery a snap via automated runbooks: Automated forest recovery runbooks orchestrate the multi-step process required for AD forest recovery, including the critical AD hygiene tasks required to verify consistency in the recovered directory, such as seizing FSMO roles and adjusting the RID pool. These runbooks also can be used for regular testing in non-production environments to enhance cyber readiness.
  • Enable fast recovery of the most important AD infrastructure: Visual topology views of your AD environment enable simple and rapid identification of which domain controllers to restore first and how they should be recovered to accelerate the availability of AD services.
  • Track recovery progress with step-by-step runbook views: Prescriptive runbook views of the recovery process provide total transparency and fine-grained control, allowing you to easily tailor the workflow to your environment. During recovery, you have total visibility into where you are in the process and how long until your AD is back online.
  • Accelerate recovery times and advance resilience: Manually recovering an AD forest can take days or even weeks to complete, but with Commvault, you can recover it in a fraction of the time. Commvault Cloud integrates AD forest recovery with granular recovery of both AD and Entra ID, providing comprehensive protection. 

Take your AD protection to the next level

Commvault Cloud Backup & Recovery for AD Enterprise Edition is now available, providing protection, recovery, and cyber resilience for your AD environment. Visit the AD-Lösungsseite to learn more or experience the solution firsthand through our interactive walk-through demo . See for yourself how Commvault can elevate your AD protection strategy.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

The rapid evolution of ransomware strains, social engineering tactics, and AI-powered attacks can make cyber resilience seem like an impossible battle. But there’s more to cybersecurity than trying to outsmart attackers. While it’s true that more sophisticated threats call for more advanced defenses, there are also surprisingly simple measures you can take to significantly reduce your risk.

In this blog, we’ll explore four easy-to-implement data protection best practices, their role in a multi-layered cyberdefense strategy, and how Commvault helps customers put them to work.

1. Stellen Sie vorab gesicherte Images bereit.

The strongest lock can’t help you if you leave your windows open. A full 23 % der Angriffe auf Cloud-Infrastrukturen involve common configuration vulnerabilities like overly permissive network policies, unnecessary services and ports, and non-secure protocols. Close these gaps and you’ve already made a big difference for the security of your attack surface.

Why do so many companies leave commonly exploited vulnerabilities in their cloud environments? Often, they’re simply moving too fast to make sure the images they deploy are secure. But Commvault can help take care of that step for them.

Commvault Cloud Platform is available in pre-hardened images that have been configured to align withCenter for Internet Security (CIS) benchmarks. These built-in best practices help reduce vulnerabilities by:

  • Änderung der Standard-Softwareeinstellungen wie Passwortrichtlinien, Einstellungen zur Kontosperrung und Protokollierungsstufen, um der Sicherheit Vorrang einzuräumen.
  • Deaktivierung veralteter oder unsicherer Protokolle wie SMBv1, SSLv3 und der RC4-Verschlüsselung.
  • Deaktivieren unnötiger Dienste und Schließen ungenutzter Ports für Betriebssysteme und Anwendungen.
  • Entfernen von Shells, die Angreifern Möglichkeiten bieten könnten, bösartigen Code auszuführen.

Neben diesen CIS-konformen Images für neue Bereitstellungen kann Commvault seinen Kunden auch Skripte zur Verfügung stellen, mit denen sie die Konfigurationen ihrer bestehenden Umgebung überprüfen und absichern können. Indem wir häufige Schwachstellen beseitigen, die auf Fehlkonfigurationen zurückzuführen sind, tragen wir dazu bei, zu verhindern, dass offene Sicherheitslücken Angriffe begünstigen.

2. Schützen Sie Active Directory.

Als zentrale Steuerungsstelle für Zugriff und Autorisierung in Ihrem gesamten Netzwerk ist Active Directory (AD) sowohl ein bevorzugtes Angriffsziel als auch ein gefährlicher Angriffsvektor. Für Angreifer ist das Eindringen in AD vergleichbar mit dem Diebstahl Ihrer Gebäudezugangskarte: Es ermöglicht ihnen, sich unbemerkt in Ihrer Umgebung zu bewegen, Berechtigungen für kritische Anwendungen und Daten zu erweitern und eine Basis zur Kontrolle Ihrer Unternehmensressourcen zu etablieren. Außerdem können sie legitime Benutzer aussperren und so Ihren Geschäftsbetrieb zum Erliegen bringen. Um diese Taktiken zu vereiteln, müssen Sie die AD-Daten schützen und alle Änderungen, die Angreifern gelingen, rückgängig machen.

Commvault can help you safeguard AD from attack by protecting your group policy objects, users, groups, conditional access policies, roles, and more. If any harmful changes are made – either intentionally by attackers or mistakenly by your own admins – you quickly can recover any deleted objects or restore overwritten attributes. To keep things simple, we also provide the granularity to roll back only the object attributes you’re concerned about without needing to do a full AD restore. Though if you do need to restore the whole AD environment, we make that simple as well.

3. Bewahren Sie Ihre Sicherungskopien außerhalb der Reichweite von Ransomware auf.

Virtually every ransomware attack targets backup infrastructure as well. After all, if organizations can simply restore their compromised assets, the initial attack falls flat – no ransom needed, no payoff for the attackers. That makes frequent, secure backups the silver bullet of ransomware defense. 

There are many ways to protect backups, but air gapping stands out as a uniquely elegant and effective measure. It’s simple: If your backups can’t be accessed from inside or outside your organization, there’s no way for attackers to reach them to manipulate or delete them. Even if all your other defenses fail and your primary data is encrypted or deleted, you’ll be able to recover quickly and get back to work.

Commvault enables air gapping with our Commvault AirGap solution. We store a tamper-proof secondary copy of your backups in an immutable format in secure, isolated cloud storage. No matter what happens on your corporate network, you’ll still have a clean, uninfected copy of your production environment to restore. That’s a win for you and a loss for the attackers.

4. Eine Genehmigung durch mehrere Personen vorschreiben.

Most companies already rely on multi-factor authentication (MFA) to prevent unauthorized access, as well they should. But in today’s lethal threat environment, some situations – like deleting a backup or authorizing a restore request – call for even higher levels of scrutiny.

Multi-person authorization goes beyond MFA by requiring not just a second proof of identity for the same person, but approval by an entirely different person – or even multiple people. That way, even if attackers gain control of multiple authentication factors, such as compromising both a user’s account and their device, they still won’t be in a position to act. The same holds for a malicious insider: With additional approvals required, a rogue employee can’t carry out an attack on their own. 

Mit den Lösungen von Commvault können Kunden mehrstufige Genehmigungsworkflows für eine Vielzahl von Aufgaben einrichten, die als datenzerstörend angesehen werden können, darunter:

  • Einen Sicherungsvorgang für ein System, einen Server oder eine Dateifreigabe anhalten.
  • Eine Sicherung löschen oder wiederherstellen.
  • Berechtigung zum Löschen eines Agenten oder eines Sicherungssatzes.

Administratoren können die Anzahl der Genehmiger, Benutzergruppen und einzelnen Benutzer festlegen, die zur Genehmigung bestimmter Aufgaben erforderlich sind.

If you’re not applying all four of these measures, you should. We’d never claim that they make up a comprehensive cyber defense strategy – you’ll still need to do all the other things, from analyzing threat intelligence and managing vulnerabilities to building out your security stack. But when steps this simple can significantly reduce your risk, the only question to consider is how soon you can get started.

Erfahren Sie mehr darüber, wie SieCloudIhnen dabei helfen kann, Ihr Netzwerk mit einer mehrschichtigen Verteidigungsstrategie vor Cyberangriffen zu schützen.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

With International Women’s Day coming up on March 8, we’re thrilled to celebrate the amazing women of Commvault. This year’s global theme, #AccelerateAction, is a key driver in our Women in Technology Employee Resource Group’s efforts throughout the year. These women, and allies, work together to elevate, advance, and celebrate the powerful impact women at Commvault have on our innovation and growth.  

In celebration of Women’s History Month 2025 and International Women’s Day, we recently hosted a virtual fireside chat with our Chief Marketing Officer, Anna Griffin, and the CEO and Co-Founder of Writer, May Habib. 

It was amazing to hear May’s perspective on being a woman in technology and her journey to launch Writer, a full-stack generative AI platform for businesses. May has received many recognitions, including the 2023 Forbes AI 50, Inc.’s 2023 Female Founder Award, and a well-earned spot among the World Economic Forum’s Young Global Leaders Class of 2024. We were honored to have May join us and share her valuable insights.

And to continue our celebration, we’ll be piloting four Lean-In Circles led by Saadia Ali (Corporate Counsel), Jagruti Dadia (Senior Designer), Saira Banu (Director, Business Technology), and Madhulika Karan (Director, Professional Services) to empower the women at Commvault to lead and take on new challenges. This program offers both men and women the opportunity to connect, network, and discuss leadership development through a world-class leadership curriculum paired with regular peer advice and support.

In honor of International Women’s Day, I encourage you to think about how YOU can #AccelerateAction with those around you. And to all the incredibly inspiring and talented women at Commvault – thank you for continuing to make an impact every day.  

Klicken Sie hier, to learn more about what it’s like to work at Commvault. 

https://play.vidyard.com/7G7bfp44N9Bq5xoc83GNXD

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Fakten

Am 20. Februar 2025 informierte uns Microsoft über unbefugte Aktivitäten in unserer Azure-Umgebung durch einen mutmaßlichen staatlich gestützten Angreifer. Wir haben daraufhin umgehend unseren Notfallplan aktiviert und dabei auf die Unterstützung führender Cybersicherheitsexperten sowie der Strafverfolgungsbehörden zurückgegriffen.

Our investigation validated that unauthorized access affected a handful of customers and we promptly contacted them to provide assistance. Our investigation also confirmed there was no unauthorized access to any data that Commvault protects for any customer, and no impact on Commvault’s business operations or ability to deliver our products and services.

Ergriffene Maßnahmen

Our forensic investigation discovered that the threat actor exploited a zero-day vulnerability, which has been behoben and we encourage our software customers to do the same. We also rotated affected credentials, continue to further harden our defenses and work with law enforcement.

Zusammenarbeit

Kein Unternehmen ist vor einem Angriff gefeit. Wir sind davon überzeugt, dass der Informationsaustausch und die Zusammenarbeit uns alle widerstandsfähiger machen. Wir danken Microsoft für die Benachrichtigung, unseren Cybersicherheitsexperten für ihre vertrauensvolle Partnerschaft und unseren Kunden für ihre Reaktionsbereitschaft und Widerstandsfähigkeit.

For further inquiries, customers may contact Commvault’s support team via our portal at https://support.commvault.com.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Für Einrichtungen des Gesundheitswesens hat der Schutz sensibler Patientendaten oberste Priorität. Da wir uns bei der Speicherung, Verarbeitung und Übertragung geschützter Gesundheitsdaten (PHI) zunehmend auf digitale Systeme verlassen, sind angemessene kryptografische Sicherheitsmaßnahmen unverzichtbar geworden. Hier kommt der Federal Information Processing Standard (FIPS) 140-2 ins Spiel.

Was ist FIPS 140-2?

FIPS 140-2 ist ein Sicherheitsstandard der US-Regierung, der Anforderungen an kryptografische Module zum Schutz sensibler Informationen festlegt. Dieser vom National Institute of Standards and Technology (NIST) veröffentlichte Standard legt spezifische Sicherheitsanforderungen fest, die kryptografische Module erfüllen müssen, um die Vertraulichkeit und Integrität der von ihnen geschützten Informationen zu gewährleisten.

Für Organisationen im Gesundheitswesen, die mit sensiblen Patientendaten umgehen, bietet FIPS 140-2 einen Rahmen für die Implementierung starker kryptografischer Schutzmaßnahmen, die den Anforderungen der Sicherheitsvorschriften des Health Insurance Portability and Accountability Act (HIPAA) zum Schutz elektronischer geschützter Gesundheitsdaten (ePHI) entsprechen. Erfahren Sie mehr über die vorgeschlagenen Aktualisierungen dieser Vorschriften in unserem Blogbeitrag„Das Rezept für Cyber-Resilienz im Gesundheitswesen“.

Wichtigste Features von FIPS 140-2

Vier Sicherheitsstufen

FIPS 140-2 verfolgt einen mehrstufigen Sicherheitsansatz mit vier unterschiedlichen Stufen, die einen zunehmend höheren Schutz bieten:

  1. Level 1: Requires production-grade equipment and at least one approved algorithm or security function. There are no specific physical security mechanisms required beyond basic production-grade components.
  1. Level 2: Adds physical security mechanisms, such as tamper-evident coatings or seals, or pick-resistant locks, and requires role-based authentication.
  1. Level 3: Enhances physical security with measures to detect and respond to attempts at physical access or modification. Prevents an intruder from gaining access to critical security parameters held within the module and includes identity-based authentication.
  1. Level 4: Provides complete protection around the cryptographic module with the intent of detecting and responding to all unauthorized physical access attempts. Level 4 modules can operate in physically unprotected environments.

Die meisten Organisationen im Gesundheitswesen setzen in der Regel Schutzmaßnahmen der Stufe 2 oder 3 um, um ein Gleichgewicht zwischen Sicherheitsanforderungen und betrieblicher Praktikabilität herzustellen.

Spezifikation des kryptografischen Moduls

FIPS 140-2 schreibt eine detaillierte Dokumentation des kryptografischen Moduls vor, einschließlich der Modulanschlüsse und -schnittstellen, manueller Vorgänge, des physikalischen Designs, der Hardware-, Software- und Firmware-Komponenten sowie der Sicherheitsfunktionen. Diese umfassende Dokumentation sorgt für Transparenz hinsichtlich des Schutzes sensibler Daten und ermöglicht gründliche Sicherheitsbewertungen.

Zugelassene Algorithmen

FIPS 140-2 schreibt die Verwendung validierter kryptografischer Algorithmen vor, darunter:

  • Symmetric key encryption: AES, Triple DES
  • Asymmetric key encryption: RSA, DSA, ECDSA
  • Secure hashing: SHA-256, SHA-384, SHA-512
  • Message authentication: HMAC, CMAC

Using only validated algorithms confirms that cryptographic implementations meet minimum security requirements and haven’t been compromised by known vulnerabilities.

Schlüsselverwaltung

Eine ordnungsgemäße Schlüsselverwaltung ist für die Aufrechterhaltung der kryptografischen Sicherheit von entscheidender Bedeutung. FIPS 140-2 legt Anforderungen für die Schlüsselgenerierung, den Schlüsselaustausch, die Schlüsseleingabe und -ausgabe, die Schlüsselspeicherung sowie die Schlüsselvernichtung (sichere Löschung) fest. Für Organisationen im Gesundheitswesen trägt eine ordnungsgemäße Schlüsselverwaltung dazu bei, dass die Verschlüsselung wirksam bleibt, und verhindert, dass kompromittierte Schlüssel zu Datenlecks führen.

Selbsttest

FIPS 140-2 requires cryptographic modules to perform self-tests to validate they’re functioning properly. These include power-up tests executed automatically, conditional tests performed when specific functions are invoked, and continuous random number generator tests. These testing requirements help maintain the ongoing reliability of cryptographic protections.

Die Bedeutung der FIPS 140-2-Konformität im Gesundheitswesen

While HIPAA doesn’t explicitly mandate compliance with FIPS 140-2, the HIPAA Security Rule requires appropriate measures to uphold the confidentiality, integrity, and availability of ePHI. FIPS 140-2 provides a recognized standard that satisfies many of HIPAA’s encryption requirements.

Furthermore, other regulations affecting healthcare organizations – such as the Federal Information Security Management Act (FISMA) – may explicitly require FIPS 140-2 compliance for federal agencies and their contractors, which can include healthcare providers working with Medicare, Medicaid, or the Veterans Administration.

Risikominderung

Datenschutzverletzungen im Gesundheitswesen können katastrophale Folgen haben – sowohl für Patienten, deren Privatsphäre verletzt wird, als auch für Organisationen, denen Geldstrafen, Kosten für Abhilfemaßnahmen und Reputationsschäden drohen. Die Einhaltung der FIPS 140-2-Vorgaben senkt das Risiko von Datenschutzverletzungen aufgrund kryptografischer Fehler erheblich, indem sie Folgendes gewährleistet:

  • Kryptografische Implementierungen orientieren sich an bewährten Best Practices.
  • Sicherheitslücken werden identifiziert und behoben.
  • Verschlüsselungsverfahren können ausgeklügelten Angriffen standhalten.
Vertrauen der Patienten

Über die gesetzlichen Anforderungen hinaus zeugt die Umsetzung strenger Datenschutzmaßnahmen von einem Engagement für den Schutz der Privatsphäre der Patienten. Wenn Einrichtungen des Gesundheitswesens ihren Patienten versichern können, dass ihre sensiblen Daten durch staatlich anerkannte Sicherheitsstandards geschützt sind, stärkt dies das Vertrauen in einer Welt, in der der Datenschutz immer mehr an Bedeutung gewinnt.

Anbieterbewertung

Die FIPS 140-2-Zertifizierung bietet einen klaren Maßstab für die Bewertung von Technologieanbietern. Bei der Auswahl von Systemen, die ePHI verarbeiten oder speichern sollen, können Organisationen im Gesundheitswesen die FIPS 140-2-Konformität als wichtiges Kriterium heranziehen, wodurch sich der Prozess der Anbieterbewertung vereinfacht und sichergestellt wird, dass die grundlegenden Sicherheitsanforderungen erfüllt sind.

Wie Commvault die Einhaltung der FIPS 140-2-Vorgaben unterstützt

Commvault’s comprehensive data management platform provides robust support for healthcare organizations seeking FIPS 140-2 compliance through several key capabilities:

FIPS-validierte kryptografische Module

Commvault verfügt über kryptografische Module, die im Rahmen des NIST Cryptographic Module Validation Program (CMVP) validiert wurden. Diese Module wurden von NIST-akkreditierten Labors strengen Tests unterzogen, um ihre Konformität mit den Anforderungen von FIPS 140-2 zu überprüfen. Dadurch erhalten Organisationen im Gesundheitswesen die Gewissheit, dass ihre Datenschutzmaßnahmen den Bundesstandards entsprechen.

End-to-End-Verschlüsselung

Commvault bietet umfassende Verschlüsselungsfunktionen, die Daten im Gesundheitswesen während ihres gesamten Lebenszyklus schützen:

  • In-flight encryption: All data transfers between Commvault components use TLS 1.2 or higher with FIPS-approved encryption algorithms, protecting sensitive healthcare information while in transit.
  • At-rest encryption: Commvault secures stored healthcare data using FIPS-approved AES-256 encryption, protecting backups, archives, and other data repositories from unauthorized access.
  • Client-side encryption: Data can be encrypted before it leaves the source system, so it remains protected throughout the entire backup and recovery process.
Sichere Schlüsselverwaltung

Commvault’s integrated key management system aligns with FIPS 140-2 requirements for secure key handling:

  • Centralized key management: Encryption keys are managed through a centralized, policy-driven system that maintains strict access controls.
  • Key rotation: Automated key rotation capabilities allow healthcare organizations to periodically update encryption keys without disrupting operations, following cryptographic best practices.
  • Secure key storage: Encryption keys are stored with multiple layers of protection, including the option to integrate with external Hardware Security Modules for enhanced security.
Identitätsbasierte Zugriffskontrollen

Commvault setzt starke Authentifizierungs- und Autorisierungsmechanismen ein, die den Sicherheitsanforderungen von FIPS 140-2 entsprechen:

  • Role-based access control: Granular permission settings allow only authorized personnel to access sensitive healthcare data or perform critical system operations.
  • Multi-factor authentication: Support for MFA provides an additional layer of security when accessing the Commvault management console or data.
  • Detailed audit logging: Comprehensive activity logs track all access to protected healthcare information, supporting compliance audits and security investigations.
Betrieb im FIPS-Modus

Commvault allows healthcare organizations to enable “FIPS mode,” which enforces the exclusive use of FIPS-approved cryptographic algorithms and modules throughout the entire data management environment. When FIPS mode is activated:

  • Algorithmen, die nicht FIPS-konform sind, werden deaktiviert.
  • Es werden ausschließlich validierte kryptografische Module verwendet.
  • Die Sicherheitseinstellungen werden automatisch so konfiguriert, dass sie den FIPS-Anforderungen entsprechen.

Dieser vereinfachte Ansatz zur Einhaltung von Vorschriften entlastet die IT-Teams im Gesundheitswesen und minimiert das Risiko von Konfigurationsfehlern, die die Sicherheit gefährden könnten.

Nahtlose Integration in Gesundheitssysteme

Commvault’s platform integrates with major healthcare information systems while maintaining FIPS 140-2 compliance:

  • Electronic health record system protection: Specialized connectors for leading EHR systems enable patient data to be backed up and recovered securely.
  • Medical imaging support: Backup capabilities meet the Digital Imaging and Communications in Medicine international standard for storing, exchanging, and using medical imaging data while preserving compliance with both HIPAA and FIPS requirements.
  • Virtual environment protection: Healthcare organizations running critical applications in virtualized environments can maintain FIPS compliance with Commvault’s virtual machine protection capabilities.
Compliance-Dokumentation und Berichterstattung

Commvault vereinfacht die Dokumentationsanforderungen im Zusammenhang mit der FIPS 140-2-Konformität:

  • Validation certificates: Access to FIPS 140-2 validation certificates for Commvault’s cryptographic modules.
  • Compliance reports: Built-in reporting tools that document encryption status, key management activities, and other security-related metrics.
  • Audit support: Comprehensive logs and reports that streamline the process of demonstrating compliance during regulatory audits.

Implementierung von FIPS 140-2 im Gesundheitswesen

Durchführung einer Bestandsaufnahme

Der erste Schritt zur Einhaltung der FIPS 140-2-Vorgaben besteht darin, alle Systeme und Anwendungen zu identifizieren, die sensible Gesundheitsdaten verarbeiten. Dazu gehören:

  • EHR-Systeme
  • Medizinische Bildgebungssysteme
  • Laborinformationssysteme
  • Abrechnungs- und Verwaltungssysteme
  • Mobile Geräte, die von Gesundheitsdienstleistern genutzt werden
  • Lösungen für Datensicherung und -speicherung
Validierung kryptografischer Module

Stellen Sie für jedes identifizierte System fest, ob es nach FIPS 140-2 validierte kryptografische Module verwendet. Das NIST führt eine Liste validierter Module, die als CMVP bezeichnet wird. Anbieter sollten in der Lage sein, ihre FIPS-140-2-Validierungszertifikate und Referenznummern vorzulegen.

Lücken schließen

For systems that don’t comply with FIPS 140-2, healthcare organizations have several options:

  • Führen Sie ein Upgrade auf FIPS-konforme Versionen durch.
  • Implementieren Sie zusätzliche Verschlüsselungsebenen mithilfe validierter Module.
  • Ersetzen Sie nicht konforme Systeme durch konforme Alternativen.
  • Beantragen Sie Ausnahmen, sofern geeignete Ausgleichsmaßnahmen vorhanden sind.
Dokumentation und Schulung

Die Führung einer umfassenden Dokumentation der Maßnahmen zur Einhaltung der FIPS 140-2-Vorgaben ist sowohl für die interne Unternehmensführung als auch für behördliche Prüfungen von entscheidender Bedeutung. Darüber hinaus sollten die Mitarbeiter in der Bedeutung der Verschlüsselung und im ordnungsgemäßen Umgang mit sensiblen Daten geschult werden.

Schlussfolgerung

FIPS 140-2 compliance represents more than just a checkbox for regulatory requirements – it’s a fundamental component of a robust healthcare data security strategy. By implementing cryptographic protections that meet this rigorous standard, healthcare organizations can significantly reduce the risk of data breaches, build patient trust, and avoid costly compliance violations.

As healthcare continues to digitize and cyber threats grow more sophisticated, adhering to recognized security standards like FIPS 140-2 is no longer optional – it’s a critical aspect of responsible healthcare delivery in the digital age.

By choosing Commvault’s FIPS 140-2–compliant data management solutions, healthcare organizations can confidently protect sensitive patient information while simplifying compliance efforts. Our comprehensive approach to data protection not only addresses current regulatory requirements but provides a foundation for addressing evolving security.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

It’s been nearly 30 years since the Health Insurance Portability and Accountability Act went into effect. Among other provisions, it protects patients by preventing disclosure of private health information without their consent. Over the years, the act has been updated and amended in response to changing technologies and related healthcare legislation and policy.

Last year, the U.S. Department of Health and Human Services (HHS) proposed significant amendments to the HIPAA Security Rule to enhance the cybersecurity of electronic health records (EHR)). The newest modifications were created in response to increased electronic record keeping and transfer, increased number and severity of security breaches, and other cybersecurity practices and enforcement issues that have changed or arisen since the rule was last updated in 2013.

Ein wesentlicher Bestandteil dieses Vorschlags sieht vor, dass die betroffenen Einrichtungen schriftliche Verfahren festlegen müssen, um kritische elektronische Informationssysteme und Daten innerhalb von 72 Stunden nach einem Ausfall wiederherzustellen.Diese Anforderungzielt darauf ab, Gesundheitsorganisationen in die Lage zu versetzen, wichtige Systeme und Daten nach einem Sicherheitsvorfall umgehend wiederherzustellen, wodurch Störungen in der Patientenversorgung minimiert und die Vertraulichkeit, Integrität und Verfügbarkeit der elektronischen Patientenakten (EHR) gewahrt werden.

Lesen Sie mehr  about how Commvault can be used to rapidly recover EHR, including in Epic and Meditech environments.

Durchsetzung des HIPAA

Die Durchsetzung des HIPAA fällt in den Zuständigkeitsbereich des Office for Civil Rights (OCR) innerhalb des HHS. Das OCR ist dafür verantwortlich, sicherzustellen, dass Gesundheitsdienstleister, Krankenkassen, Clearingstellen und deren Geschäftspartner die HIPAA-Vorschriften zu Datenschutz, Sicherheit und der Meldung von Datenschutzverletzungen einhalten.

In recent years, OCR has prioritized financial penalties for violations – particularly those related to the HIPAA Security Rule. Im Jahr 2024 berichtete die OCR, dass die Durchsetzung der HIPAA-Vorschriften ein nahezu rekordhohes Niveau erreicht habe, wobei 9,9 Millionen Dollar eingenommen wurden, darunter eine Vergleichszahlung in Höhe von 4,75 Millionen Dollar für mehrere Verstöße gegen die Sicherheitsvorschriften.Während die Zahl der Durchsetzungsmaßnahmen gestiegen ist, ist die durchschnittliche Höhe der Geldbußen jedoch aufgrund einer Neuauslegung der Strafstufen im Rahmen des HITECH-Gesetzes gesunken.

Wichtige Durchsetzungsmechanismen für neue Vorschriften

Angesichts der bevorstehenden neuen Vorschriften der HIPAA-Sicherheitsregel wird die OCR die Einhaltung der Vorschriften durch eine Kombination aus Aufklärung, Audits, Untersuchungen und Sanktionen durchsetzen. Nachfolgend finden Sie eine detaillierte Übersicht über die Funktionsweise dieser Durchsetzungsmechanismen:

1. Education & guidance (early-stage enforcement)

Die OCR bietet Beratung, Schulungen und bewährte Verfahren an, um den betroffenen Einrichtungen und Geschäftspartnern dabei zu helfen, die HIPAA-Vorschriften einzuhalten. Dazu gehören:

  • Aktualisierte FAQs, Schulungsprogramme und Online-Ressourcen.
  • Zusammenarbeit mit Branchenverbänden, um zu klären, wie die neuen Sicherheitsvorschriften umgesetzt werden sollen.
  • Technische Leitlinien zur Risk Analysis und zum Risikomanagement (ein Bereich, in dem es häufig zu Verstößen kommt).

Diese Phase ermöglicht es Unternehmen, ihre Sicherheitsprogramme, Risikomanagementrichtlinien und Mitarbeiterschulungen anzupassen, bevor die strikte Durchsetzung beginnt.

2. Compliance investigations & breach reporting

Die OCR prüft die Einhaltung der Vorschriften im Zusammenhang mit:

  • Complaints: Individuals can report HIPAA violations, triggering OCR investigations.
  • Breach reports: Any breach involving 500 or more records must be reported to OCR, which then investigates whether non-compliance contributed to the breach.

Angesichts der zunehmenden Zahl von Hackerangriffen hat sich die OCR verstärkt auf die Vorbereitung auf Cybersicherheitsrisiken konzentriert und verlangt von den Einrichtungen des Gesundheitswesens eine gründlichere Risk Analysis und Systemüberwachung.

3. HIPAA audits & risk analysis focus

Angesichts der weit verbreiteten Nichteinhaltung der Vorschriften hat die OCR die Risk Analysis als oberste Priorität bei der Durchsetzung hervorgehoben.

  • In the 2016–2017 HIPAA audits, most organizations failed to conduct a comprehensive risk analysis or update it regularly.
  • Im Jahr 2024 betrafen 14 von 22 Durchsetzungsmaßnahmen der OCR Verstöße gegen die HIPAA-Sicherheitsvorschriften, wobei Mängel bei der Risk Analysis das häufigste Problem darstellten.
  • Die OCR beabsichtigt, die Compliance-Prüfungen wieder aufzunehmen (auch wenn sich diese Initiative aufgrund von Haushaltszwängen möglicherweise verzögern könnte).

Es ist mit einer strengeren Überprüfung der Vorgehensweise von Organisationen bei der Bewertung und Minderung von Risiken für ePHI zu rechnen.

4. Financial penalties & corrective action plans (CAPs)

Die OCR kann bei Nichteinhaltung Sanktionen verhängen, wobei die Geldbußen je nach den folgenden Faktoren zwischen Tausenden und Millionen Dollar liegen können:

  • Fahrlässigkeit oder vorsätzliche Vernachlässigung
  • Unterlassung der Behebung von Verstößen nach einer Aufforderung
  • Anzahl der betroffenen Personen

Da die Bußgelder im Rahmen des HIPAA deutlich zurückgegangen sind (von durchschnittlich 2,6 Millionen US-Dollar im Jahr 2018 auf etwa 450.000 US-Dollar im Jahr 2024), hat das OCR nach alternativen Durchsetzungsstrategien gesucht, wie beispielsweise CAPs, die Organisationen dazu verpflichten, ihre Sicherheitsmaßnahmen innerhalb eines festgelegten Zeitraums zu verbessern, sowie eine strengere Durchsetzung auf staatlicher Ebene.

Was das für Ihr Unternehmen bedeutet

Da die OCR der Durchsetzung der Risk Analysis Priorität einräumt, können Ihnen diese Schritte dabei helfen, die vorgeschlagenen Änderungen einzuhalten:

  • Aktualisieren Sie die Risikobewertungen regelmäßig und beziehen Sie dabei alle ePHI-Systeme ein.
  • Stärkere Maßnahmen zur Cybersicherheit umsetzen (z. B. Verschlüsselung, Multi-Faktor-Authentifizierung und kontinuierliche Überwachung).
  • Schulen Sie die Mitarbeiter hinsichtlich der Einhaltung der HIPAA-Vorschriften und des Vorgehens bei Datenschutzverletzungen.
  • Stellen Sie zeitnahe Benachrichtigungen über Datenschutzverletzungen mit korrekten Inhalten bereit.
  • Führen Sie Unterlagen, die die Maßnahmen zur Einhaltung der Vorschriften belegen.

State attorneys general can independently enforce HIPAA and impose penalties for violations.California’s largest 2024 penalty ($6.75M)targeted a cloud storage provider for mishandling patient data security. With states passing additional cybersecurity laws (e.g.,New York’s hospital cybersecurity mandates), expect HIPAA enforcement to expand beyond OCR oversight.

Abschließende Gedanken: Die Herausforderungen der Zukunft

Despite increases in both reports of breaches and HIPAA complaints, OCR appears unlikely to receive the increased funding it says it needs to ramp up enforcement. It remains unclear how the agency will be impacted by ongoing budget cuts from the Department of Government Efficiency – and how the new administration will proceed after public comment on the proposed changes closes on March 7.

Unabhängig davon, ob die neuen HIPAA-Sicherheitsvorschriften in diesem Jahr in Kraft treten oder nicht, würden Organisationen davon profitieren, ihre Cybersicherheitsmaßnahmen, Risk Analysis, Strategien zur Notfallwiederherstellung und Compliance-Schulungen proaktiv zu verstärken. Durch die Bewältigung dieser Herausforderungen können Einrichtungen des Gesundheitswesens dazu beitragen, mögliche Strafen zu vermeiden, das Risiko von Datenschutzverletzungen zu verringern und Patientendaten wirksam zu schützen.

Mehr erfahrendarüber, wie Commvault Ihr Unternehmen bei der Einhaltung gesetzlicher Vorschriften unterstützen kann.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Den ganzen Februar über war unsere weltweite Vaulter-Community stolz darauf, den Black History Month zu feiern und zu würdigen.

Here at Commvault, we value and celebrate the unique perspectives each Vaulter brings to the table as we foster innovation and collaboration. We are proud to have an internal focus on “equity in action” as we continue to nurture our inclusive culture.

Zum Abschluss unserer Feierlichkeiten hat unsere Mitarbeitergruppe „Multi-Culture Employee Resource Group“ (ERG) gemeinsam mit derCourageous Conversation Foundation for an impactful, capacity-building training session on effectively engaging, sustaining, and deepening interracial dialogue. We were honored to have the foundation’s CEO and President, Glenn E. Singleton, join us for this thought-provoking and moving experience as we unpacked the global framework of community and belonging and how to best incorporate this culture into the workplace.

It is so important to continue our learning journey on how to have the “right” conversations – understanding that we won’t change the conversation, unless we have the conversation. Having open dialogues to exchange ideas and experiences only makes us stronger and better.

As Black History Month ends, let’s all remember the role Black history has and continues to play in American history. Each February, we acknowledge the heroes of the Black community and honor their fight by condemning racism and championing change. But this commitment shouldn’t be limited to just one month; it should be a part of our daily lives all year round.

Indem wir den Erfahrungen und Sichtweisen anderer zuhören und lernen, wie wir uns gegenseitig besser unterstützen können, schaffen wir ein Gefühl der Zugehörigkeit für alle.Klicken Sie hier,um mehr über unsere Commvault-Kultur und unser Engagement für Gemeinschaft und Zugehörigkeit zu erfahren.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

In der dynamischen Welt des Cloud-Computing sind Unternehmen zunehmend auf robuste Strategien zur Recovery angewiesen, um ihre Ausfallsicherheit zu gewährleisten und eine unterbrechungsfreie Dienstbereitstellung zu gewährleisten. Ein Ansatz, der traditionell verfolgt wird, ist die vorab erfolgte Einrichtung einer Cloud-Landing-Zone.

However, this method is fraught with inefficiencies and potential pitfalls that can undermine its effectiveness and cost organizations time, resources, and operational resilience. This blog delves into the concept of a cloud landing zone, highlights the challenges associated with pre-creating such zones for cyber recovery (CR) and disaster recovery (DR), and introduces Cloud Rewind’s rebuild model as an alternative for enabling cloud resilience.

What Is a Cloud Landing Zone?

Eine Cloud-Landezone ist eine vorkonfigurierte Umgebung innerhalb eines Cloud-Kontos, die dazu dient, Cloud-Ressourcen sicher und effizient zu verwalten. Sie bietet einen strukturierten Rahmen für die Bereitstellung von Cloud-Ressourcen, die Netzwerkkonfiguration und Sicherheitseinstellungen und orientiert sich dabei an Best Practices und Unternehmensrichtlinien. Ziel ist es, einen reibungslosen, skalierbaren und konformen Cloud-Betrieb zu ermöglichen.

Zwar bilden Cloud-Landing-Zones die Grundlage für die Bereitstellung und Verwaltung von Cloud-Ressourcen, doch ihre Anwendung in CR-/DR-Szenarien bringt einige Herausforderungen mit sich.

Challenges with Pre-Created Cloud Landing Zones for CR/DR

  • Time and resource consumption: Creating a cloud landing zone requires a comprehensive understanding of the existing production environment’s architecture and maintenance practices. This replication effort demands substantial time and resources, duplicating efforts and diverting them from value-generating activities.
  • Maintenance and configuration drift: Once established, a pre-built landing zone necessitates ongoing maintenance to stay in alignment with the production environment. However, the dynamic nature of cloud environments often leads to configuration drift – a divergence in the settings and configurations between the production and CR/DR environments. This drift complicates maintenance efforts and can compromise the efficacy of the recovery strategy.
  • Impediments to testing: The divergence between production and CR/DR environments due to drift and misalignment hampers the ability to conduct effective recovery testing. The hesitancy or inability to test recoveries undermines the resilience of IT systems, leaving organizations vulnerable in the event of a disaster or cyberattack.
  • Wasted investments: The resources expended on creating and maintaining a pre-created landing zone can be substantial, yet the return on investment (ROI) is often minimal. Organizations may find themselves with outdated or misaligned recovery environments that are not ready for immediate use after a disaster or incident. Furthermore, in the face of sophisticated ransomware attacks, the ability to rebuild systems from clean data and application images is crucial – a capability that is hampered by the constraints of a pre-created landing zone.

The Cloud Rewind Approach to Cloud Resilience: Rebuild

Cloud Rewind’s rebuild model for cloud resilience offers a more agile, efficient, and effective approach CR/DR. Unlike the traditional model of pre-creating and maintaining a cloud landing zone, Cloud Rewind allows for dynamically rebuilding cloud environments from clean copies of data and application images. This model addresses the core challenges associated with pre-created landing zones:

  • Efficiency and agility: By eliminating the need for a pre-created landing zone, organizations can allocate resources more efficiently, focusing on strategic initiatives rather than maintenance and alignment efforts.
  • Reduced configuration drift: The rebuild model mitigates the risk of configuration drift by verifying that the recovery environment is constructed with the latest, clean configurations and data, closely mirroring the production environment at the time of rebuild.
  • Enhanced testing and recovery: The dynamic nature of the rebuild approach facilitates more frequent and realistic testing of CR/DR procedures, enhancing IT system resilience.
  • Cost-effectiveness: Without the sunk cost of maintaining a pre-created landing zone, organizations can achieve better ROI on their investments, focusing on rapid CR/DR capabilities that are more aligned with modern cloud practices.

Angesichts zunehmender Cyberbedrohungen wie Ransomware ist die Möglichkeit, eine virenfreie Umgebung schnell wiederherzustellen, von unschätzbarem Wert. Mit Cloud Rewind können Unternehmen rasch auf solche Bedrohungen reagieren, Ausfallzeiten minimieren und einen unterbrechungsfreien Geschäftsbetrieb gewährleisten.

Rebuild: A Forwarding-Thinking Approach

The traditional approach of pre-creating cloud landing zones for CR/DR is fraught with inefficiencies, including wasted resources, maintenance challenges, and compromised resilience. In contrast, Commvault Cloud Rewind’s on-demand rebuild model for cloud resilience offers a more agile, cost-effective, and robust solution.

Durch die Konzentration auf den dynamischen Wiederaufbau von Cloud-Umgebungen – im Grunde genommen einen Klon der Produktionsumgebung – können Unternehmen ihre CR/DR-Fähigkeiten verbessern, Betriebsrisiken reduzieren und auch bei Störungen eine kontinuierliche Servicebereitstellung gewährleisten. Die Umstellung auf das Wiederaufbaumodell stellt einen zukunftsorientierten Ansatz für die CR/DR-Recovery dar, der den sich wandelnden Anforderungen des Cloud-Computings und der organisatorischen Resilienz gerecht wird.

Erfahren Sie mehr darüber, wie SieCommvault Cloud Zurückspulencan help you rapidly rewind; recover critical data, cloud applications, and configurations to a clean state; and swiftly rebuild your cloud environments after cyber incidents.

Additional Reading:

  1. https://www.commvault.com/blogs/Aufbau-der-Ausfallsicherheit-von-cloud-mit-commvault-cloud-rewind
  2. https://www.commvault.com/blogs/simplifying-cloud-resilience-and-cloud-recovery 
  3. https://www.commvault.com/blogs/a-blueprint-for-effective-cloud-recovery

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Our latest Commvault® Cloud software and SaaS releases provide new features and capabilities to help you elevate your cyber resilience and data protection strategy by making protecting and managing your data easier and faster. It’s designed to help you secure and recover hybrid cloud data against emerging data loss threats and recover quickly in the event of an incident or cyberattack.

Zu den neuesten Features, die nun im Rahmen dieser Version verfügbar sind, gehören:

CrowdStrike-Integration

Ihre Sicherheitsteams müssen schnell handeln. Angesichts der zunehmenden Zahl von Ransomware-Angriffen müssen Unternehmen ihre Transparenz verbessern, um Bedrohungen frühzeitig zu erkennen und zu bekämpfen.

Commvault helps youstrengthen your cyber defenses by integrating CrowdStrike Falcon with Commvault Cloud. With CrowdStrike data integrated into the Commvault dashboard, your security team can quickly identify and respond to threats. This streamlined visibility makes it easier to protect backup assets, secure sensitive data, and take proactive recovery actions.

Verbesserungen an Commvault AirGap

Die Erkennung und Abwehr von Ransomware sind von entscheidender Bedeutung. Da KundenCommvault AirGapzunehmend nutzen, erwarten sie umfassendere Funktionen und eine gleichbleibende Leistung über alle Speicherebenen hinweg.

We’ve enhanced Commvault AirGap with features like versatile tiering for both primary and secondary data, guardrails for data recovery and retention, and threat scanning for cloud and on-prem environments. This helps customers optimize storage costs while maintaining robust protection.

Commvault Edge

Unternehmen müssen Daten und Anwendungen an Remote-Standorten und in Zweigstellen genauso effektiv schützen wie bei lokalen und Cloud-basierten Bereitstellungen.

Commvault Edgebietet ein Software-Image, das auf einer Referenzarchitektur installiert werden kann und Datensicherheit an Remote-Standorten gewährleistet – alles über eine zentralisierte Steuerungsebene verwaltet. Ihre Administratoren profitieren von mehr Flexibilität und Transparenz, da sie die richtige Hardware für die Installation des HS Edge-Software-Images auswählen und so bis zu 200 TB Daten für Einzelhandelsstandorte, Fertigungsbereiche, IoT und mehr verwalten und schützen können. Darüber hinaus ermöglicht das Software-Image dank seines vorab gehärteten und vorkonfigurierten Linux-basierten Betriebssystems eine schnelle Bereitstellung und einfache Wartung.

Cloud Rewind

Mitin der Regel 70 % der Cloud-Ressourcen ungeschützt bleiben, kann die Gewährleistung von Cyber-Resilienz eine gewaltige Herausforderung darstellen. Unternehmen sind bestrebt, den Schutz aller Ressourcen zu verstärken und darauf vorbereitet zu sein, sich von Bedrohungen zu erholen.

Cloud Rewindbietet eine leistungsstarke Möglichkeit, wichtige Daten, Cloud-Anwendungen und Konfigurationen schnell in einen sauberen Zustand zurückzusetzen. Damit können Nutzer ihre Cloud-Umgebungen nach Cybervorfällen rasch in einen bekannten, sicheren Zustand zurückversetzen und so die Recovery-Zeit von Wochen auf Minuten verkürzen. Diese schnelle Recovery-Fähigkeit ist entscheidend für die Aufrechterhaltung der Cyber-Resilienz.

Clumio für Amazon S3

Mit dem Aufkommen moderner Apps und künstlicher Intelligenz hat Amazon S3 ein explosives Wachstum verzeichnet, was es zu einem bevorzugten Ziel für Angriffe macht. Die Wiederherstellung von Milliarden von Objekten aus dem Backup kann äußerst langwierig sein und zu längeren Ausfallzeiten führen.

Clumio Backtrackbietet eine bahnbrechende Lösung, die ein schnelles Zurücksetzen von Amazon S3-Objekten auf eine bestimmte Version zu jedem beliebigen Zeitpunkt ermöglicht. Dies bedeutet eine verbesserte Cyber-Resilienz gegenüber Fehlern und Angriffen sowie die Möglichkeit, Milliarden von Objekten innerhalb weniger Minuten mithilfe von S3 Versioning und serverloser Technologie wiederherzustellen. Zudem optimiert es die AWS-Kosten, da keine zusätzlichen Kopien von S3-Buckets mehr erforderlich sind.

Hinweis:Clumio für Amazon S3 ist auch im AWS Marketplace erhältlich.

Cleanroom Recovery für AWS

Kunden, die AWS für ihre Cloud-Bereitstellungen nutzen, möchten Recovery-Übungen innerhalb derselben Umgebung durchführen, um eine optimale Effizienz zu erzielen.

Commvault hatCleanroom Recoveryauf AWS ausgeweitet, sodass Sie Workloads direkt in AWS wiederherstellen können. Diese Erweiterung ermöglicht es Ihnen, Wiederherstellungstests in einer Umgebung durchzuführen, die Ihrer Produktionsumgebung entspricht, was die Konsistenz erhöht. Darüber hinaus gewinnt Ihr Unternehmen dank der umfassenderen Unterstützung von Cloud-Plattformen die Flexibilität, eine auf Ihre Bedürfnisse zugeschnittene Recovery-Strategie zu entwickeln.

Automatische Skalierung für Amazon EC2 Restore

AWS-Nutzer benötigen die automatische Skalierung von Commvault für Replikation, Recovery und Indizierung, um die Anzahl der langfristig betriebenen Commvault-Zugriffsknoten zu minimieren, die sie in ihrer AWS-Umgebung verwalten müssen. Commvault Cloud skaliert nun die Amazon EC2-Rechenkapazität während Wiederherstellungs-, Replikations- und Migrationsvorgängen dynamisch und beendet diese anschließend, um die Kosten für die Cyber-Resilienz niedrig zu halten.


Sie können die Wartung vereinfachen, indem Sie die Anzahl der langfristig betriebenen Commvault-Zugriffsknoten in Ihrer AWS-Umgebung reduzieren, und Kosten einsparen, indem Sie die elastischen EC2-Rechenressourcen nur bei Bedarf nutzen.

Backup & Recovery for Google Workspace

Sicherheitsrisiken bei SaaS-Anwendungen wie versehentliches Löschen, Datenbeschädigung und böswillige Angriffe können die Produktivität beeinträchtigen. Überraschenderweise sind sichnur 13 %der Unternehmen ihrer Verantwortung beim Datenschutz voll und ganz bewusst.

Commvault geht noch einen Schritt weiter underweitert den Schutz von SaaS-Anwendungen auf Google Workspace, wodurch Daten in Gmail, Google Drive und Shared Drive abgedeckt werden. Das bedeutet, dass Ihre wichtigen Google Workspace-Daten sicher sind und im Falle eines Datenverlusts wiederhergestellt werden können.

Your business can keep moving forward with data that’s available and quickly recoverable. Plus, maintain service-level agreement compliance with extended retention and bundled Google Cloud Storage, all managed through a single, unified solution for Google Workspace and other SaaS, hybrid, and cloud-native workloads.

Wiederherstellung einer Active Directory-Gesamtstruktur

When Active Directory (AD) goes offline, recovering the forest can be a daunting, multi-step process that must be executed perfectly. Without automation, there’s a real risk of restoring AD in an unusable state, causing further business disruption.

Commvault’s solution simplifies this with rapid recovery from schema corruption and ransomware attacks. Durch die Automatisierung des gesamten Recovery-Prozesses für die Active Directory-Gesamtstruktur können Sie im Voraus planen und Tests durchführen, wodurch Ausfallzeiten reduziert und die Cyber-Resilienz gesteigert werden. So können Sie sich darauf verlassen, dass Ihre Active Directory-Gesamtstruktur schnell und effizient in einen fehlerfreien Zustand zurückversetzt werden kann.

Nutanix AHV-Quell-VMs

Do you face the challenge of protecting diverse and complex operating environments? Do you need reliable solutions to manage these environments effectively? That’s where Cleanroom Recovery comes in. Now supporting Nutanix VMs, it helps you respond swiftly to security threats and streamline recovery validation.

Warum ist das wichtig? Es bietet umfassenden Schutz für komplexe Umgebungen und ermöglicht so eine vollständigere Recovery. Dank der Unterstützung für mehr VMs und Workloads können Unternehmen zudem schnell wieder den Betrieb aufnehmen, wodurch ihre Cyber-Resilienz gestärkt und ein reibungsloser Betriebsablauf gewährleistet wird.

Integration von Palo Alto Networks XSOAR

Sicherheitsteams nutzen häufig SIEM/SOAR-Plattformen wie XSOAR von Palo Alto Networks zur Erkennung und Bekämpfung von Bedrohungen. Da diese jedoch nicht in Recovery-Lösungen integriert sind, müssen sie zeitaufwändige manuelle Wiederherstellungsmaßnahmen durchführen, wodurch sich ihre Reaktion auf aktive Bedrohungen verzögert.

Commvault Cloud Cleanroom Recovery lässt sich nahtlos in Palo Alto Networks XSOAR integrieren, sodass Teams Wiederherstellungsmaßnahmen direkt innerhalb der XSOAR-Plattform verwalten können. Diese Integration verkürzt die Wiederherstellungszeiten durch automatisierte Workflows, reduziert manuelle Aufgaben, sodass sich die Teams auf die Bedrohungsanalyse konzentrieren können, und zentralisiert die Verwaltung, was zu einer besseren Zusammenarbeit und einer schnelleren Reaktion auf Vorfälle führt.

Backup & Recovery for Kubernetes

As businesses modernize their applications, many have chosen Kubernetes as their go-to platform to manage large amounts of data for hybrid cloud apps. Admins need to perform faster backups and improve recovery readiness for their containerized applications and data. 

Commvault enables Kubernetes backup and recovery that’s optimized for large volumes of data. This solution seamlessly integrates with the Kubernetes API server to discover and collect application data and configurations, delivering improved performance and reliability for backups. 

Testen Sie Commvault Cloud kostenlos für 30 Tage.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

With cyberattacks becoming increasingly inevitable, the ability to recover quickly and effectively is crucial for business survival. In Episode 13 of The STRIVE Podcast, host Darren Thomson delves into the critical aspects of building an effective cyber recovery plan. Here’s a summary of the key phases and principles discussed.

Phase 1: Vorbereitung

  • People: Everyone in the organization must know their role. Establish a well-defined crisis response team to take charge during an attack.
  • Process: Map out potential threat scenarios and create step-by-step recovery playbooks. The plan must align with your broader continuous business and incident response strategies.
  • Technology: Secure air-gapped backups and implement anomaly detection so that recovery points are clean. Regularly test your plan in a cleanroom to build confidence and readiness.

Phase 2: Sofortmaßnahmen

  • Detection and notification: Implement real-time monitoring tools and notify your response team immediately upon detecting an attack.
  • Isolation and containment: Disconnect infected systems and isolate critical infrastructure to prevent the spread of the threat.
  • Initial assessment: Document everything to understand the scope of the damage and identify the quickest path to recovery. Fast, decisive action is crucial to minimize disruption.

Phase 3: Recovery

  • Data integrity: Confirm backups are clean before restoration. Use air-gapped backups and cleanroom technology to help prevent reinfection.
  • System restoration: Rebuild critical infrastructure, including Active Directory, firewalls, servers, and applications, with hardened security configurations.
  • Prioritization: Restore critical infrastructure and data first, and verify system and data integrity before restoring applications.

Phase vier: Wiedereingliederung

  • Cautious reconnection: Gradually reconnect users and assets, starting with critical infrastructure. Monitor for signs of persistent threats.
  • User access and authentication: Reconfigure systems for better identity controls, such as multi-factor authentication and least-privilege policies.
  • Security monitoring: Verify all systems are secure, and monitor for any lingering vulnerabilities.

Phase 5: Kontinuierliche Verbesserung

  • Security enhancements: Apply new security controls based on lessons learned from the attack or test.
  • Forensics analysis: Investigate how the attack occurred and what weaknesses were exploited to prevent future breaches.
  • Refine the plan: Regularly test and refine your cyber recovery plan to improve its success rate. Cyber recovery is about bouncing back stronger.

Die wichtigsten Erkenntnisse

  • Preparation is key: Build and test a comprehensive recovery plan.
  • Immediate action: Detect, isolate, and assess threats quickly.
  • Data integrity: Confirm backups are clean and secure.
  • Gradual reintegration: Reconnect systems cautiously, and monitor for threats.
  • Continuous improvement: Learn from each incident to enhance your security posture.

Die ganze Folge jetzt ansehen:

STRIVE, Folge 13: Entwicklung eines effektiven Plans zur Cyber-Recovery

https://play.vidyard.com/iHS8ZZfMinwUx9HkA67u8E

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Angesichts sich rasch wandelnder Sicherheitsbedrohungen kann die Bedeutung der Cyber-Resilienz gar nicht hoch genug eingeschätzt werden. Da Angriffe immer raffinierter und häufiger werden, erkennen Unternehmen zunehmend die Notwendigkeit eines umfassenden und integrierten Ansatzes für die Cybersicherheit.

This shift is evident in the growing trend of consolidation and investment within the cybersecurity market, which is driving the development of more robust and unified solutions. The data protection industry has seen large investments, including Veeam’s recent $2B in secondary equity and the recently closed Cohesity acquisition of Veritas’ assets from Carlyle Group Inc.

Der Trend zu integrierten Lösungen

Traditionally, organizations have relied on a patchwork of best-of-breed tools to address their cybersecurity needs, including from the likes of Veeam. While these tools are often highly effective in their specific domains, using them can lead to a fragmented security landscape. This fragmentation results in data silos, increased operational costs, inefficiencies in threat response, and potential security concerns between disparate data protection silos. As threats become more complex and interconnected, this approach is no longer sufficient. 

Die Konsolidierung und die Investitionen im Bereich der Cybersicherheit spiegeln ein wachsendes Bewusstsein für diese Herausforderungen wider. Unternehmen suchen mittlerweile nach stärker integrierten und umfassenden Lösungen, die ein einheitliches, kohärentes und anpassungsfähiges Sicherheitskonzept bieten, wie es beispielsweise Commvault tut. Dieser plattformorientierte Ansatz erhöht nicht nur die allgemeine Sicherheit, sondern verbessert auch die Effizienz, senkt die Kosten und ermöglicht eine bessere Einhaltung gesetzlicher Vorschriften sowie eine optimierte Recovery.

Sicherheit auf jeder Ebene

Point products can struggle with security due to their fragmented approach of multiple disparate codebases and reliance on integration with other platforms. Unlike makers of point products, like Veeam, Commvault leverages a single codebase that integrates security into every stage of our software development lifecycle (SDLC) and in every layer of the Commvault Cloud platform. This commitment to secure software development is a cornerstone of Commvault’s strategy to provide robust and reliable solutions to our customers.

Unser Ansatz für eine sichere Softwareentwicklung beginnt bereits in der Entwurfsphase. Wir wenden eine „Security-by-Design“-Methodik an, sodass Sicherheitsaspekte von Beginn des Entwicklungsprozesses an berücksichtigt werden. Dieser proaktive Ansatz hilft dabei, potenzielle Schwachstellen frühzeitig zu erkennen und zu beheben, wodurch das Risiko von Sicherheitsverletzungen verringert wird und das Endprodukt so sicher wie möglich wird.

Regelmäßige Sicherheitsaudits und Penetrationstests

Um die Sicherheit unserer Produkte weiter zu verbessern, führen wir regelmäßig Sicherheitsaudits und Penetrationstests durch. Diese strengen Prüfungen werden sowohl von internen Sicherheitsteams als auch von externen Experten durchgeführt. Die Ergebnisse dieser Tests dienen dazu, etwaige Schwachstellen zu identifizieren und zu beheben, um sicherzustellen, dass unsere Lösungen sicher und widerstandsfähig gegenüber neuen Bedrohungen bleiben.

This testing regimen provides additional confidence to our customers and shows our commitment to securing both customer data and the platform that protects it. As a result of our high security standards, Commvault® Cloud is one of the only FedRAMP High Authorized cyber resilience platforms.

Schulung und Sensibilisierung

Commvault legt großen Wert auf Schulungen und Sensibilisierung in unseren Entwicklungsteams. Wir führen regelmäßig Sicherheitsschulungen und Workshops durch, um die Entwickler über die neuesten Best Practices im Bereich Sicherheit und aufkommende Bedrohungen auf dem Laufenden zu halten. Dank dieser kontinuierlichen Weiterbildung ist unser Entwicklungsteam bestens gerüstet, um Sicherheitsprobleme proaktiv zu erkennen und zu beheben.

Vorreiter bei der Cyber-Resilienz

VonForrester, Gartner, GigaOm, IDC und anderen Branchenanalystenals führender Anbieter von Lösungen für Datenresilienz anerkannt, haben wir unser Engagement für Innovation und Spitzenleistungen stets unter Beweis gestellt.

Unsere umfassende Plattform für Cyber-Resilienz,Cloud, wurde entwickelt, um eine kontinuierliche Geschäftsverfügbarkeit und schnelle Recovery in Hybrid-, Cloud-First- und Multi-Cloud-Umgebungen zu gewährleisten und geht damit über herkömmliche Lösungen für Backup and Recovery hinaus.

Commvault’s leadership is further solidified by our strategic acquisitions, such as Appranix and Clumio. These acquisitions have significantly enhanced our portfolio, enabling it to offer end-to-end solutions for backup, disaster recovery, and ransomware protection across on-premises, hybrid, and multi-cloud environments.

Steigern Sie Ihre Cyber-Resilienz

Die Konsolidierung und die Investitionen im Cybersicherheitsmarkt unterstreichen die entscheidende Bedeutung der Cyber-Resilienz. Unternehmen erkennen zunehmend die Notwendigkeit integrierter und umfassender Lösungen, mit denen sich die sich ständig weiterentwickelnde Bedrohungslandschaft effektiv bewältigen lässt, sowie von Plattformen, die von Grund auf auf Sicherheit ausgelegt sind. Commvault ist bestens positioniert, um diesen Wandel anzuführen. Wir laden Sie ein, unsere Plattform selbst zu testen – nutzen Sie dazuunsere kostenlose Testversion,die ab sofort verfügbar ist.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era