2022 was a BIG year for Cyber Security. According to Cyber Security Hub, more than 4100 data breaches were publicly exposed with a number of high-profile attacks including Twitter, Optus and WhatsApp.
In today’s world, bad actors are well organized, informed and also persistent with the volume and speed of attacks increasing. Their motives are changing, with data leakage, exfiltration, theft and restructure being top objectives causing data damage to now be the top concern of IT decision makers.
So what does 2023 hold? We’ve gathered thoughts from experts across Commvault to answer that very question.

Industry-Wide Shift to Proactive, Early Threat Prevention
– Matt Tyrer
In short, businesses will need and begin to implement proactive solutions to constantly monitor their environment to catch threats and enable early warning/response. Bad guys are getting in, and we aren’t knowing about it early enough.
From a cyber security and threat defence perspective, the industry today could be essentially divided in two approaches:
- Preventative Measures: These vendors are your perimeter defence vendors like firewalls, anti-virus, SIEM/SOAR tools, along with other data loss prevention (DLP) and intrusion detection/prevention solutions. Even the newer identity access management (IAM) security vendors, who are adding key security functionality to control who can see what in your environment, can be grouped in here. They are all the locks on your doors and windows actively working to keep the bad guys out of the house so that they can’t even start the fire.
- Reactive Measures: These tend to be the storage and most conventional backup vendors who are focused on protecting the data itself. Aiming to ensure it is available for recovery via table stakes features like immutability and anomaly detection (threat hunting) in the backups. These solutions are the sprinkler system and fire alarm – by the time they are triggered your house is already on fire and your only response is triage and disaster recovery.
Don’t get me wrong, both of these are critical parts of a layered security posture and strategy but there is a gap which where early warning lives. It’s the abilities to better respond when a breach occurs, while not waiting for data damage to be done before recovery is kickstarted.
This is why my prediction is an industry wide shift to more PROACTIVE warning systems, helping companies fill gaps between their preventive and reactionary toolsets.
Thankfully, Commvault is ahead of this game with our ThreatWise cyber deception technology. Get started NOW on proactively defending your data.

Rise in Managed Services Provider Spending
– Donna Namorato
The Institute of International Finance is predicting a global economic growth rate of just 1.2% in 2023, a level on par with 2009 when the world was only beginning its emergence from the from the financial crisis.1 Even with economic uncertainty looming, expect that cybersecurity spending will continue to rise but don’t be surprised if there is a decline in product and service spending.
Und obwohl die Ausgaben für Cybersicherheit steigen, gaben laut einer CIO-Umfrage von Jefferies 53 % an, dass sie die ITSM-Ausgaben kürzen würden. Sollte dies geschehen, würde ich einen Anstieg der Ausgaben für Managed Service Provider (MSP) erwarten. MSPs sind auf bestimmte IT-Segmente spezialisiert und können fundiertes IT-Fachwissen bieten, da sie Fachkräfte gewinnen und binden können – was Unternehmen hingegen schwerfällt.
To remain vigilant against ransomware and data security, organizations must adopt a ransomware strategy and develop an Plans zur Reaktion auf Vorfälle against bad actors. Incorporating a multilayered security framework is also vital to safeguard your data and reduce cybersecurity risk. And, when you need help, die „Commvault Ransomware Readiness Solutions“ is available to assist you.

Industry and Platform Consolidation
– Brian Brockway, Global Chief Technology Officer
Derzeit ist die Sicherheitslandschaft sehr unübersichtlich. Es gibt unzählige Tools auf dem Markt, und viele Unternehmen setzen mehrere Lösungen ein, um einen umfassenden Schutz zu gewährleisten. Wir beobachten jedoch, dass in der Branche eine Konsolidierung einsetzt, die sich bis ins Jahr 2023 fortsetzen dürfte. Alle Komponenten müssen zusammenwirken, um maximale Effizienz zu erzielen und die besten Schutzchancen zu bieten. Die Zusammenführung aller Komponenten auf einer einzigen Plattform wird unerlässlich sein, um sicherzustellen, dass Sie das Beste aus Ihren Lösungen herausholen, und eine zentrale Übersicht ist der Schlüssel zu deren Verwaltung. Insbesondere angesichts weiter steigender Kosten müssen Unternehmen sicherstellen, dass sie jeden Cent sinnvoll ausgeben und aus jeder Anschaffung den optimalen Nutzen ziehen.
Doch angesichts der schieren Menge an Bedrohungen, denen Unternehmen ausgesetzt sind, wächst auch das Bewusstsein, dass nicht alles verhindert werden kann – ganz gleich, wie gut Ihre Lösungen sind oder wie effektiv Sie sie verwalten. Unternehmen sollten ihren Fokus auf Resilienz richten. Es ist mittlerweile fast unvermeidlich, dass Unternehmen irgendwann angegriffen werden, aber was wirklich zählt, ist, wie schnell Sie sich davon erholen können. Es sollten regelmäßige Backups durchgeführt werden, damit selbst im schlimmsten Fall Ausfallzeiten auf ein Minimum beschränkt bleiben und der normale Geschäftsbetrieb so schnell wie möglich und mit nur geringen bleibenden Schäden wiederhergestellt werden kann.

“Inside-out” CyberSecurity, Tiger Teams and Managed Services
– Zack Brigman, Sr Product Marketing Manager
Cyberbedrohungen erreichen weiterhin Rekordhöhen, sowohl hinsichtlich der Anzahl erfolgreicher Angriffe als auch hinsichtlich der durch diese Angriffe verursachten Schäden. Mit Blick auf das Jahr 2023 gehen Experten davon aus, dass sich diese Trends weiterhin in die falsche Richtung entwickeln werden, da Angreifer neue, ausgeklügelte Taktiken anwenden, Netzwerke von Auftragshackern weiter wachsen und sich die Qualifikationslücke im Sicherheits- und IT-Bereich vergrößert. Und obwohl diese negativen Entwicklungen große Herausforderungen mit sich bringen, werden Unternehmen im kommenden Jahr einen großen Schritt nach vorne machen, um ihre Cybersicherheitsmaßnahmen besser zu planen, in diese zu investieren und weiterzuentwickeln.
Prioritization
Breaches happen. But not all assets, systems, and data are created equal. Given that a small percentage of information assets carry the majority of business risk, progressive companies will begin employing an “inside-out” cybersecurity strategy. One that starts with hardening and securing their most critical assets first – then working toward the perimeter. While perimeter defences and preventing intrusion will (and should) remain a paramount focus, this risk-aligned approach enables the prioritization of defence strategies to mitigate risk for high-value assets and functions. This reshapes conventional “outside-in” approaches, making security investments more accessible and operational.
Tiger Teams
To better manage emerging threats and respond to risk, we will continue to see a rise in fusion teams (thanks Gartner for the term!) – merging IT, security, and operational stakeholders together to drive change. These blended teams help create new synergies by pairing complementary (but often siloed) groups and capacities to achieve common goals. These cross-functional teams increase visibility across the organization, discover and eliminate blind spots, and optimize investments in existing and new tools. While many mature organizations already leverage fusion teams today, 2023 will see a more widespread adoption of these functions to better identify risks, implement cyber response strategies, and manage threats.
Managed Services
As threats mount, businesses will continue to adopt managed service (MSP) and managed security service (MSSP) offerings to augment existing tools and tactics. This is particularly true of lean IT departments and those looking to enhance their security operations centers. Leveraging these managed providers will enable organizations to close the cyber security skills gap, tap into a consortium of specialized solutions, and scale their cyber practice without managing additional headcount or disparate solutions.
Thanks to all our contributors! Stay tuned to see if their predictions come true by following Commvault and our DPaaS portfolio Metallic on Social Media.




























