Skip to content

These attacks can be used to block access to—or outright steal—essential business data, which can often include both the backup and restore data contained in places like an Amazon Cloud Backup (AWS Backup). The perpetrators will then encrypt the data and withhold it from the business until they pay a ransom, or threaten to delete it altogether if the company refuses to meet their demands.

Ransomware-Angriffe können innerhalb eines Unternehmens Chaos verursachen – durch Betriebsunterbrechungen, den Verlust von Daten, die für wesentliche Geschäftsabläufe entscheidend sind, die Offenlegung vertraulicher Kundendaten und den Verlust der öffentlichen Glaubwürdigkeit. Und das Problem verschärft sich zunehmend.

Nach Angaben des US-amerikanischen Financial Crimes Enforcement Network (FinCEN), the number of ransomware attacks in 2021 will vastly exceed the number of attacks in 2020. These attacks are growing in terms of cost as well—the average cost of reported ransomware transactions per month in 2021 was $102.3 million.

You may be wondering where Cloud-Backups und Snapshots fit into this. After all, can’t you simply restore the stolen data from a backup or snapshot in the event of an attack? Ideally, yes. But ransomware attackers also target an organization’s data backups, which is why it’s crucial to secure those backups to avoid paying outrageous ransoms while ensuring business continuity and a fast recovery.

Sicherheitslücken bei Amazon Cloud Backup

​​Although Cloud-Backup-Lösungen snapshots are great for operational recoveries, they do not provide complete protection from threats like ransomware. When used directly out of the box, AWS backup vulnerabilities include:

  • No air-gap protection – AWS snapshots are by default created in the same account as the primary data sources. In this scenario, if the primary account is compromised, so are the snapshots. And if the snapshots are compromised, there is no way to recover data deleted or encrypted by outside parties.
  • Backups are not automatically immutable – AWS on its own does not make snapshots immutable, and mutable backups can be altered—or even, in some cases, accidentally deleted.
  • Slow recovery – AWS’s lack of flexible restores impacts recovery speed and can result in disruptions to business continuity in the event of an attack that results in a need for data restore.
  • Possible script errors – Complex, manually-written scripts are required to replicate snapshots across all accounts within AWS. This is obviously time-consuming and prone to human error, which can leave the snapshots exposed during an attack.

So schützen Sie AWS-Backups vor Ransomware

The potential inherent vulnerabilities of AWS-Backups can leave your data copies at risk to bad actors. And while AWS does offer some native tools and solutions for securing backups, they can be cumbersome to use while still not providing full protection.

Hier sind einige wichtige Maßnahmen, die Sie ergreifen sollten, um Ihre wertvollen Daten und Backups vor Ransomware und anderen Angriffen zu schützen:

  • Air-gapping – Backups should be air-gapped and stored outside of the customer’s primary account and region. In the event of an attack, this prevents hackers and bad actors from corrupting and deleting the backup copies as well as the working data.
  • Immutable backups – Backup copies of data should be made immutable (unable to be altered or deleted), which preserves the data in a format that prevents it from being altered in any way.
  • Encryption for data at rest and data in transit – Both at rest and in transit, data should be encrypted, ideally with the user’s own encryption keys, and protected at a platform level with top security features in compliance with certifications such as ISO 27001, SOC II Type 1, SOC II Type 2, and PCI DSS.
  • Periodically test your data recovery abilities – In the event of an intrusion or disruption to your data and workloads, it’s essential to know you can recover quickly and ensure business continuity. Organizations should routinely test their ability to recover data from their backups.

(Is your data fully protected from ransomware? Click here to view our comprehensive Ransomware-Checkliste.)

Schützen Sie Ihr AWS-Backup mit Clumio in nur wenigen Minuten vor Ransomware

Clumio’s innovative, industry-leading platform was designed in the cloud to protect the cloud.

With Clumio, your AWS backups receive instant protection via air-gapping, which places your valuable backup data “off site” and outside of production environments and other accounts.

Data is also encrypted with your encryption key of choice before it leaves any of your cloud accounts. Built-in integrity checking, full immutability for your backup files, and testing data recovery are all only a few clicks away within the intuitive interface.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Importance of Compliance & Data Security

Unternehmen müssen nicht nur ihre eigenen sensiblen Daten schützen, sondern auch die personenbezogenen Daten ihrer Kunden und Klienten. Die Nichteinhaltung der einschlägigen Vorschriften kann zu finanziellen Einbußen und Reputationsschäden sowie zu möglichen rechtlichen Konsequenzen führen.

Betrachten wir zum Beispiel die jüngsten Datenpannen, von denen zahlreiche namhafte Unternehmen betroffen waren. Diese Vorfälle führten nicht nur zu kostspieligen Geldstrafen, sondern untergruben auch das Vertrauen der Kunden und wirkten sich negativ auf den Ruf der Marke aus. Tatsächlich werden laut einer aktuellen Umfrage des weltweit tätigen Kommunikationsunternehmens Edelman 81 % der Verbraucher den Kauf bei einem Unternehmen einstellen, wenn sich herausstellt, dass dieses Daten unsachgemäß handhabt.

Compliance with regulations can help reduce security and privacy risks, align cybersecurity requirements with business processes, maintain effective cybersecurity programs, build customer trust, and improve company reputation. As a result, companies must prioritize both compliance and data security in order to remain competitive in today’s market.

To illustrate the importance of compliance and data security further let’s consider the healthcare industry. Medical providers need to follow various laws and regulations for patient privacy and protection of confidential information such as HIPAA (Health Insurance Portability and Accountability Act), which holds organizations accountable for not protecting medical records correctly. Non-compliance with these laws could lead to customers losing trust or even being sued for neglecting confidentiality obligations at worst case scenarios.

Darüber hinaus stellt die Einführung geeigneter Compliance-Maßnahmen sicher, dass sensible Geschäftsinformationen unter den Beteiligten, die täglich darauf zugreifen müssen, vertraulich bleiben, während unbefugte Personen davon ferngehalten werden. Dies schafft ein Gefühl der Sicherheit bei den Mitarbeitern, die mit vertraulichen Informationen umgehen, und verringert so die Zahl der Datenverstöße, die schwerwiegende finanzielle Schäden verursachen könnten.

However, some people might argue that the cost associated with maintaining such compliance standards might outweigh some of the benefits derived from it. This quite untrue as the benefits of adherence to compliance regulations to data protection surpass the cost in the long-term savings and protection it provides.

  • Laut einer von Statista im Jahr 2020 durchgeführten Studie haben rund 45 % der Unternehmen weltweit ihre Ausgaben für Datenschutz und Compliance-Maßnahmen erhöht.
  • Ein Forschungsbericht des Ponemon Institute aus dem Jahr 2021 ergab, dass die durchschnittlichen Kosten einer Datenpanne in den Vereinigten Staaten bei 8,64 Millionen US-Dollar lagen, was die Bedeutung zuverlässiger Backup-Lösungen für die Einhaltung gesetzlicher Vorschriften unterstreicht.
  • In einer Umfrage von Spiceworks aus dem Jahr 2019 gaben etwa 42 % der Unternehmen an, für ihre Datensicherungen eine Kombination aus Public-Cloud-, Private-Cloud- und Hybrid-Cloud-Umgebungen zu nutzen, um eine bessere Compliance und Redundanz zu erreichen.

Die Rolle von Backups bei der Einhaltung gesetzlicher Vorschriften

When it comes to data security, backups play a crucial role in ensuring regulatory compliance and business continuity. Regulatory compliance can be extremely complex, involving strict guidelines that must be followed to avoid financial penalties, legal consequences, and damage to reputation. Having a reliable backup plan can help companies maintain compliance with regulations such as GDPR (General Data Protection Regulation), which establishes rules for protecting European Union residents’ personal data; PCI (Payment Card Industry) standards for processing and storing payment card information securely; and HIPAA (Health Insurance Portability and Accountability Act) standards for protecting health information.

In addition to satisfying compliance requirements, backups also help companies ensure business continuity. Natural disasters, power outages, cyber attacks, and other unexpected events can cause loss or corruption of data. Without an effective backup plan in place, businesses risk losing important data along with customer trust.

To understand the importance of backups further, let’s consider a company that experiences a ransomware attack. Ransomware is a type of malicious software that threatens to publish sensitive data if payment isn’t made.

If the company doesn’t have a robust backup plan in place, they may have no options but to pay the ransom or lose significant amounts of valuable data. However, if they’ve been backing up their files regularly and properly following best practice recovery protocols when implementing their backup process which involves full and partial backups implemented frequently as possible amongst other features available with top-notch services like Rewind Backup Tool according to SaaS compliance solution then they would be able to recover critical files without paying criminals for release of hijacked files or draining their resources.

Eine robuste Infrastruktur, wie sie für die Einhaltung der Backup-Vorschriften erforderlich ist, ermöglicht es Unternehmen somit, Risiken zu minimieren, die andernfalls zu Datenverlusten, Ausfallzeiten für Kunden, der Zahlung hoher Geldstrafen, Rechtsstreitigkeiten mit betroffenen Parteien sowie einem Vertrauensverlust zwischen dem Unternehmen und seinen Kunden führen würden.

Some people might argue that backups are not necessary if the data is already stored securely. However, accidents happen, and when they occur some vendors would not be able to provide data recovery services without backing up their client’s system. It is better to be safe than sorry when dealing with sensitive data which could result in a breach leading to legal consequences.

  • Backups are critical for businesses to maintain regulatory compliance and ensure business continuity. Compliance regulations can be complex, and strict guidelines must be followed to avoid financial penalties, legal consequences, and reputational damage. Reliable backups also help companies protect against the loss or corruption of data due to natural disasters, cyber attacks, or other unexpected events. Investing in a robust backup plan, including full and partial backups implemented frequently as possible amongst other features available with top-notch services like Rewind Backup Tool according to SaaS compliance solution, can help mitigate risks otherwise resulting in data loss, customer downtime, payment of expensive fines, lawsuits from affected parties, and lost trust between company and clients. Ultimately, accidents happen, so it is better to be safe than sorry when dealing with sensitive data that could result in a breach leading to legal consequences.

Auswirkungen auf die Geschäftskontinuität

The impact of compliance and data security on business continuity cannot be overstated. In fact, without a robust backup plan in place, businesses are at a significant risk of irreversible damage to their operations and reputation. With the number of cyber-attacks increasing every year, it’s crucial that companies take proactive measures to protect their data and ensure their systems remain operational in the event of an attack.

For instance, imagine a scenario where a company was hit by a ransomware attack that encrypted all their data and backups. Without a proper backup plan in place, they would lose access to all their critical files and data necessary for business continuity. As a result, they would be forced to restart from scratch, resulting in prolonged downtime, lost revenues from halted operations, and reputational damage.

A backup plan provides the assurance that, should such an attack occur, the company can quickly restore its systems’ functionality without significant disruptions to its operations. This is especially important for companies with compliance obligations or those that deal with sensitive or confidential information.

Backups also help businesses maintain customer trust and build their reputation. Companies that continuously experience service disruptions or data breaches are likely to lose customers who will take their business elsewhere. By having a reliable backup plan in place, businesses can demonstrate their commitment to protecting their customers’ sensitive information while maintaining the continuity of their services.

Manche Unternehmen argumentieren möglicherweise, dass die Erstellung eines soliden Backup-Plans unnötig sei, da dessen Umsetzung zu viel Zeit und Ressourcen in Anspruch nehme. Sie betrachten dies möglicherweise als zusätzliche Kosten ohne nennenswerten unmittelbaren Return on Investment. Die Risiken, die mit dem Fehlen eines solchen Plans einhergehen, überwiegen jedoch bei weitem die vermeintlichen Kosten. Die Kosten für die Wiederherstellung nach einem Cyberangriff ohne ordnungsgemäße Backups übersteigen bei weitem die Investitionen, die für die Umsetzung eines wirksamen Backup-Plans erforderlich sind.

Wichtige Vorschriften und Zertifizierungen

Es gibt verschiedene Vorschriften, die regeln, wie Unternehmen mit sensiblen Daten umgehen. Daher ist es unerlässlich, die Folgen einer Nichteinhaltung dieser Vorschriften zu verstehen und zu wissen, welche Zertifizierungen erforderlich sind, um diese Risiken zu mindern.

Regulations such as GDPR, PCI, and HIPAA mandate that businesses protect their customers’ sensitive information. Specifically, GDPR applies to European Union (EU) citizens’ personal data, while PCI compliances deal with payment card data handling. Similarly, HIPAA governs the handling of protected health information (PHI). Non-compliance with these regulations can result in significant legal and financial repercussions.

Wenn Unternehmen diese Vorschriften einhalten, stimmen sie ihre Anforderungen an die Cybersicherheit auf ihre Geschäftsprozesse ab, unterhalten wirksame Cybersicherheitsprogramme, die Kundendaten schützen, verringern Sicherheits- und Datenschutzrisiken und verbessern den Ruf des Unternehmens.

Obtaining certifications like ISO 27001 and SOC 2 serve as proof that an organization has implemented thorough audits of its data security compliance. ISO 27001 is an information security management certification that demands a company’s adherence to strict standards of data protection. On the other hand, SOC 2 requires adherence to specific criteria for system security, availability, confidentiality, processing integrity, and privacy. These certifications cater to different aspects of compliance but work together to ensure effective data security practices.

DSGVO, PCI und HIPAA

Was Compliance und Datensicherheit angeht, gibt es eine Reihe von Vorschriften und Zertifizierungen, die Unternehmen beachten müssen, um sicherzustellen, dass ihr Backup-Plan aktuell und wirksam ist. Zu den wichtigsten Standards zählen dabei die Datenschutz-Grundverordnung (DSGVO), der Payment Card Industry Data Security Standard (PCI DSS) und der Health Insurance Portability and Accountability Act (HIPAA).

The GDPR, which came into effect in May 2018, is designed to protect personal data belonging to European Union citizens. Any organization that collects or processes EU citizens’ data must comply with these stringent regulations. Failure to do so may result in hefty fines, loss of reputation, or legal action. To comply with the GDPR, businesses need to have a robust data management system including proper backups containing personal data.

Der PCI DSS gilt speziell für Unternehmen, die mit Zahlungskartendaten umgehen. Er regelt, wie Unternehmen sensible Kundendaten wie Kreditkartennummern verarbeiten müssen, um Betrug und Hackerangriffe zu verhindern. Der PCI DSS schreibt jährliche Audits durch einen zugelassenen Qualified Security Assessor (QSA) sowie regelmäßige Überprüfungen der Sicherungsrichtlinien vor.

HIPAA is another critical regulation for healthcare organizations. It requires strict methods for securing medical records both physically and electronically. The law also enables patients’ access to their own medical records while requiring healthcare providers provide them with proper privacy practices.

Complying with these regulations can be compared to buckling your seatbelt before driving on the road – safety first! Regulations give your business the tools it needs to protect sensitive information and avoid data breaches while keeping your customers’ trust.

ISO 27001 und SOC 2

Abgesehen von gesetzlichen Anforderungen gibt es Zertifizierungen, die das Engagement für bewährte Verfahren im Bereich des Cybersicherheitsmanagements belegen. Die Internationale Organisation für Normung (ISO) stellt sowohl Leitlinien als auch Zertifizierungen zum Thema Informationssicherheit bereit. Die Norm ISO 27001 konzentriert sich speziell auf die Einrichtung eines Informationssicherheits-Managementsystems (ISMS) in jeder Organisation.

Implementing ISO 27001 involves assessing risks, devising policies and procedures for securing data at all times, including backup data. This includes specific requirements for data redundancy, disaster recovery planning as well as testing of the policies in places such as offsite backups in particular.

Additionally, the SOC 2 examination report is an independent third-party evaluation that gives assurance about how well you perform your controls. SOC 2 reports concentrate on a company’s non-financial reporting controls as they relate to key compliance and security issues.

Obtaining these sorts of certifications can be compared to receiving your driving license- it takes dedication to learn the rules of the road before being able to safely drive where you need to go. With these certifications, businesses demonstrate their commitment to best practices in cybersecurity management that protect their customers’ sensitive information.

Erstellung eines zuverlässigen Backup-Plans

Bei der Erstellung eines soliden Backup-Plans zur Gewährleistung der Compliance und Datensicherheit müssen Unternehmen zahlreiche Faktoren berücksichtigen. Ein umfassender Backup-Plan sollte nicht nur den Schutz sensibler Daten gewährleisten, sondern auch eine Möglichkeit bieten, verlorene oder beschädigte Daten im Falle eines Angriffs oder Datenverlusts wiederherzustellen. In diesem Abschnitt werden wir einige der wichtigsten Aspekte bei der Erstellung eines soliden Backup-Plans betrachten.

First and foremost, your organization needs to decide on the type of backups it will use. This may involve implementing both full and partial backups as often as possible, depending on how critical your data is. Full backups are designed to capture all data on a system while partial backups capture only smaller subsets of data. The frequency of the backups will vary depending on factors such as how rapidly data changes within your organization and the amount of data you’re dealing with.

Sobald Sie sich für die Art und Häufigkeit der Backups entschieden haben, die Ihr Unternehmen nutzen wird, müssen Sie festlegen, wo die Backups gespeichert werden sollen. Es stehen zahlreiche Optionen zur Verfügung, darunter cloudbasierte Backup-Lösungen und physische Speichergeräte wie Festplatten und Bandlaufwerke. Backups, die an mehreren Standorten gespeichert werden, sind in der Regel sicherer als solche, die nur an einem Ort gespeichert werden.

Another important consideration when creating a backup plan is determining how long backups should be retained. While regulatory requirements drive retention policies in some cases, organizations might choose to store their backups even longer than regulations require if business continuity could be threatened without it. In short, retaining more copies does come at a cost – requiring investment in additional storage space and management efforts – but having those extra copies provides an additional layer of risk mitigation.

It’s important to remember that creating a robust backup plan is like creating a safety net for your organization’s sensitive data. If something goes wrong, having a backup plan in place will ensure that your organization can quickly recover and restore lost or corrupt data.

Let’s take a look at some of the key considerations when choosing the right backup tools for your organization.

Die Auswahl der richtigen Backup-Tools

When selecting the correct backup tools, it is essential to find a solution that aligns with your organization’s specific needs. There are several factors to consider before making a final decision, including how often backups need to happen, how they’re being created and operated—whether through an automated mechanism or manual solutions—and what type of encryption algorithms you’d prefer for protecting sensitive information.

Ein entscheidender Faktor, der bei der Auswahl von Backup-Tools zu berücksichtigen ist, sind Skalierbarkeit und Zuverlässigkeit. Unternehmen, die mit zukünftigem Wachstum rechnen, müssen Lösungen wählen, die sich an ihre sich ändernden Anforderungen anpassen lassen. Automatisierte Lösungen wie Clumio sind zu bevorzugen, da sie mehr Flexibilität bieten, um unerwartete Anstiege des Datenvolumens zu bewältigen, ohne das IT-Personal zu überlasten. Mit skalierbaren Tools profitieren Anwender von einer stabilen Plattform, während Unterbrechungen minimiert und die Geschäftskontinuität gewährleistet werden.

Darüber hinaus müssen Backup-Tools unter Berücksichtigung von Sicherheitsaspekten entwickelt werden. Sie müssen regelmäßig aktualisiert werden, um sicherzustellen, dass bekannte Sicherheitslücken umgehend behoben werden, und gleichzeitig über starke Verschlüsselungsmethoden verfügen, um sensible Daten über die gesamten Kommunikationswege hinweg während des gesamten Backup-Lebenszyklus zu schützen.

Weitere wichtige Aspekte bei der Auswahl eines Backup-Tools sind die Kosteneffizienz und eine einfache Verwaltung. Diese sind besonders entscheidend für Unternehmen mit knappen Budgets, in denen die Ressourcen möglicherweise begrenzt sind. Bevor Sie eine Entscheidung für ein Backup-Tool treffen, sollten Sie prüfen, ob es ein gutes Preis-Leistungs-Verhältnis bietet und gleichzeitig eine einfache Wartung, Bereitstellung und Verwaltung gewährleistet sowie die für Ihr Unternehmen erforderlichen Sicherheitsfunktionen bereitstellt.

Choosing the right backup tool is like finding the perfect pair of shoes. Just as finding a good pair of shoes requires careful evaluation of comfort, style, and price over time – finding an ideal solution requires taking into account key factors, including scalability, security, cost-effectivenesss and management needs, while selecting the right solution for your organization.

Now that we’ve explored some of the essential aspects to consider when creating a backup plan, let’s move on to monitoring and reporting compliance.

Vollständige und partielle Backups durchführen

When it comes to implementing backups for compliance and data security, one size does not fit all. Your organization’s specific needs will determine the type of backup strategy that works best for you. Full backups are ideal if you need complete copies of all your data on a regular basis. However, partial backups may also be necessary to ensure the protection of your most critical data.

For example, let’s say you run an e-commerce website that generates a significant amount of daily sales. In this scenario, you would likely want to implement both full and partial backups. A full backup could be performed once a week or month, while partial backups would occur several times a day, ensuring that critical sales data is always protected.

Ein weiterer Fall, in dem Teil-Backups unerlässlich wären, ist ein Biotech-Forschungsunternehmen, das komplexe Experimente durchführt. Da hier Echtzeitdaten eine entscheidende Rolle bei den Experimenten spielen, sind stündliche Backups die beste Lösung, um die Recovery verlorener Daten im Falle eines unvorhergesehenen Zwischenfalls zu gewährleisten.

Darüber hinaus kann die Umsetzung verschiedener Arten von Sicherungsstrategien zusätzliche Redundanzebenen schaffen, die dazu beitragen, den Schutz der Daten zu gewährleisten, falls eine Sicherung fehlschlagen sollte. Der Einsatz sowohl inkrementeller als auch differentieller Sicherungen bedeutet beispielsweise, dass nur die Dateien gespeichert werden, die sich seit der letzten Sicherung geändert haben. Dieser Ansatz reduziert den benötigten Speicherplatz und minimiert die für jede Sicherung erforderliche Zeit.

Andererseits dauern vollständige Sicherungen zwar länger, ermöglichen aber eine schnellere Wiederherstellung, da sie alle Systemdateien auf einmal umfassen. Der Wechsel zwischen den beiden Arten kann zwar die Komplexität erhöhen, doch die Nutzung beider Methoden bietet Schutz vor schwerwiegenden Verlusten.

Ein wesentlicher Aspekt bei der Umsetzung eines Backup-Plans ist die Berücksichtigung von externen Speicheroptionen wie Cloud-basierten Diensten oder sicheren Remote-Standorten. Dieser Schritt stellt sicher, dass Backup-Dateien vorhanden sind, falls am Hauptstandort ein katastrophales Ereignis eintritt.

Überwachung und Berichterstattung zur Einhaltung von Vorschriften

Die Nachverfolgung der Daten zu jeder Sicherungsstrategie ist für die Einhaltung von Compliance-Standards von großer Bedeutung. Durch die regelmäßige Überwachung der Sicherungsprozesse und -ergebnisse lassen sich fehlgeschlagene Sicherungen erkennen und das Risiko eines Datenverlusts verringern.

To ensure regulatory adherence, it’s crucial to define metrics that measure backup performance over time. From measuring the total storage space used for the backup process to tracking how quickly a full system restore takes, having statistics helps your organization stay on track with its goals while ensuring compliance.

Darüber hinaus können Manager mithilfe von Software-Automatisierungstools täglich Berichte über den Status der Backups erhalten, ohne dass ein manueller Eingriff erforderlich ist. Diese Tools bieten Einblicke in Echtzeit in die Backups, beispielsweise darüber, ob unbefugte Zugriffe oder Änderungen an Dateien stattgefunden haben. Heutzutage sind Protokolle eine einfache Möglichkeit, diese Informationen zu überprüfen.

Backup performance evaluations are essential for businesses to gauge their adherence to established compliance regulations such as GDPR, HIPAA, and PCI DSS. It is necessary to create policies that specify the types of tests necessary and their frequency—these policies should be reviewed regularly during audits.

While some backup approaches include using external tapes to store data redundantly, these methods aren’t always suitable for larger companies with higher processing demands or those with several locations. This approach can have long restoration times that may damage the continuity of any business.

Thus, implementing a reliable, efficient backup array works wonders here because it reduces operational downtime caused by data corruption or server crash incidents. Therefore, having scheduled “backup retention time” where IT professionals research probable risks acting on timely apparatus replacement is more practical than recurring backups.

It’s just like building a structure strong enough from natural disasters instead of only counting buckets when it floods up to your knees!

Leistungskennzahlen für Backups

One of the most critical aspects of backup planning is monitoring and reporting. In today’s compliance-driven world, organizations must be able to prove that they are adhering to regulations and protecting user data. Backup performance metrics play a vital role in ensuring regulatory adherence and avoiding data breaches.

So können beispielsweise Leistungskennzahlen für Backups Aufschluss darüber geben, wie lange die Erstellung von Backups dauert, wie oft Backups durchgeführt werden oder wie viele Backups pro Tag bzw. Woche erstellt werden. Sollten beim Backup-Prozess Probleme auftreten, können diese Kennzahlen genutzt werden, um diese zu erkennen und zu beheben, bevor sie zu einem Problem werden.

Darüber hinaus können Leistungskennzahlen für Backups auch als Nachweis für die Einhaltung gesetzlicher Vorschriften dienen. So verlangen beispielsweise Vorschriften wie HIPAA von Organisationen, dass sie einen Prüfpfad führen, aus dem hervorgeht, wer wann auf Patientenakten zugegriffen hat. In ähnlicher Weise verlangt die DSGVO von Organisationen, dass sie einen Prüfpfad für Datenschutzverletzungen bereitstellen. Leistungskennzahlen für Backups können Organisationen dabei helfen, diese Anforderungen zu erfüllen, indem sie den Nachweis für regelmäßige Backups und Recovery-Tests liefern.

However, it’s crucial to note that backup performance metrics alone won’t ensure compliance. Compliance involves implementing a wide range of security procedures, including disaster recovery planning, risk assessments, monitoring security controls, and integrating best practice security procedures into day-to-day workflows. While backup performance metrics are an essential part of compliance monitoring and reporting, they should be used in conjunction with other security measures.

Vor diesem Hintergrund stellt sich die Frage: Wie können Unternehmen sicherstellen, dass ihr Backup-Plan den Vorschriften entspricht?

Gewährleistung der Einhaltung gesetzlicher Vorschriften

Um die Einhaltung gesetzlicher Vorschriften zu gewährleisten, müssen Unternehmen bei ihrem Backup-Plan einen ganzheitlichen Ansatz verfolgen. Hier sind einige wichtige Schritte, die zu beachten sind:

Wählen Sie zunächst Backup-Tools aus, die den Branchenstandards entsprechen. Hochwertige Datensicherungstools wie Clumio können den komplexen Prozess der Compliance und Datensicherheit vereinfachen, indem sie tägliche Backups automatisieren und sicherstellen, dass eine Datenwiederherstellung möglich ist, während gleichzeitig die strengsten Sicherheitsstandards eingehalten werden.

Think of it this way: choosing the right backup tools is like choosing the right lock for your front door. Just as you want a lock that’s tough to break, you want backup tools that are hard to hack. The right tools can help you ensure that your data is safely stored and stored in compliance with industry regulations.

Führen Sie als Nächstes so oft wie möglich Voll- und Teil-Backups durch. Voll-Backups sollten regelmäßig (z. B. wöchentlich oder monatlich) durchgeführt werden, um sicherzustellen, dass alle Daten gesichert werden. Teil-Backups sollten häufiger (z. B. täglich) durchgeführt werden, um sicherzustellen, dass Datenänderungen erfasst werden.

Wenn Sie beispielsweise eine E-Commerce-Website betreiben, könnten Sie monatlich vollständige Backups durchführen, aber jede Nacht Teilbackups erstellen, um neue Bestellungen zu erfassen.

Testen Sie schließlich regelmäßig Ihre Sicherungen, um sicherzustellen, dass diese im Falle eines Angriffs oder eines Datenverlusts wiederhergestellt werden können. Die Tests sollten Failover-Tests (d. h. die Überprüfung, ob Ihr Sicherungssystem den Betrieb übernehmen kann, wenn Ihr Primärsystem ausfällt) und Failback-Tests (d. h. die Überprüfung, ob Ihr Primärsystem den Betrieb wieder übernehmen kann, sobald das Sicherungssystem zum Einsatz gekommen ist) umfassen.

However, it’s important to keep in mind that implementing a compliant backup plan isn’t a one-time thing – it’s an ongoing process. As regulations change and new threats emerge, organizations must continue to evaluate and refine their backup plans to maintain regulatory compliance and protect user data.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

One of the most essential parts of a robust and ultimately effective business continuity plan is the disaster recovery plan. After all, a business may do all it can to protect itself from a disaster event—such as a ransomware attack, a cloud outage, or corrupted data—but it still needs a failsafe plan for how it will restore data and workloads in the event of any disruption that nevertheless occurs.

Was ist Disaster Recovery?

Although “disaster recovery” is a term often used interchangeably with “business continuity,” it is actually a subset of business continuity management that mainly involves restoring crucial data and operations while minimizing any downtime caused by a disaster event.

Having a disaster recovery plan in place is essential for any enterprise. Without one, the aftermath of a disaster can spiral out of control and leave a business vulnerable to permanent data loss and disruption to operations that eventually affect everything from revenue to customers.

Cloud-Backup und Optimierung der Notfallwiederherstellung

An enterprise’s disaster recovery plan should include a way to identify all mission-critical data that should be prioritized during a restore, along with a way to quickly recover and restore lost data from backups — all while still keeping essential operations afloat during recovery. This is in addition to identifying the suitable number of backups needed to meet the recovery point objective (RPO) while avoiding excessive costs from unneeded backups creation and storage.

Alles beginnt mit der Nutzung eines Cloud-Backup-as-a-Service-Angebots zur kontinuierlichen Replikation und Speicherung von Unternehmensdaten. Hier sind drei Funktionen zur Disaster Recovery, auf die Sie bei einer Cloud-Backup-as-a-Service-Lösung achten sollten, da sie bei der Disaster Recovery erhebliche Vorteile bieten:

Inkrementelle „Forever“-Sicherung

Die „Incremental Forever“-Sicherung ist eine Art der inkrementellen Sicherung, bei der ein Verfahren namens „Changed Block Recovery“ zum Einsatz kommt. Dies optimiert den Wiederherstellungsprozess und erspart IT-Teams die mühsame Durchsicht der Sicherungen, um herauszufinden, welche Kopien wiederhergestellt werden müssen, um die aktuellsten Daten wiederherzustellen.

Die inkrementelle Dauersicherung beschleunigt den Wiederherstellungsprozess, indem nur die neuesten Versionen der Blöcke wiederhergestellt werden, die zu einer wiederhergestellten Sicherung gehören, was zu deutlich schnelleren Wiederherstellungen führt.

Granulare Verwertung

During disaster recovery, the actual speed of data restoration is at the core of an organization’s den RTO. However, during recovery, some data is more important than other data — particularly the mission-critical data and processes that the organization needs to remain operational while full recovery is in progress. Restoring an entire instance can be time-consuming and may put business continuity at risk.

Die granulare Recovery-Funktion ist die Lösung für dieses dringende Problem, da sie es IT-Teams ermöglicht, sowohl die Recovery auf Datei- als auch auf Datensatzebene aus einem einzigen Sicherungsdurchlauf heraus durchzuführen, anstatt auf eine vollständige Instanzwiederherstellung warten zu müssen. Dadurch lassen sich bestimmte geschäftskritische Daten und Workloads identifizieren und priorisieren, um wesentliche Prozesse und Abläufe aufrechtzuerhalten und gleichzeitig die Recovery drastisch zu beschleunigen.

Flexible Recovery

Die flexible Recovery ist eine weitere nützliche Funktion, die Sie über Ihre Cloud-Backup-Lösung in Ihren Notfallwiederherstellungsplan integrieren sollten. Mit der flexiblen Recovery können Sie Daten auf jedes Konto oder in jede Region wiederherstellen, die vom Notfallereignis nicht betroffen sind, und den Betrieb schnell wieder aufnehmen.

Branchenführende Disaster Recovery mit Clumio

Built in the cloud, Clumio supports optimized business continuity management and disaster recovery with capabilities such as granular recovery, incremental forever backup, flexible recovery, and more. Clumio’s industry-leading rapid restore capabilities provide enterprises of all sizes with lightning-quick data restores that can maintain and support business continuity in the face of a disaster event.

Neben optimierten Features zur Notfallwiederherstellung bietet Clumio außerdem:

  • Sofortige Backups von AWS-Daten aus jeder Region für Ihr gesamtes Unternehmen
  • Schutz vor Ransomware und anderen böswilligen Angriffen durch „Air-Gapped“-Backups
  • Vereinfachte Einhaltung globaler Richtlinien zur Datenkonformität
  • Flexibles, nutzungsabhängiges Abrechnungsmodell
  • Kosteneinsparungen durch detaillierte Einblicke in die Cloud-Ausgaben des Unternehmens

Clumio is the industry’s leading innovator for AWS cloud backup.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Cybersecurity Awareness Month is here and, as you can imagine, this topic is always part of our conversations here at Commvault and especially in my role as Chief Information Security Officer.  

Protecting our customers’ data is core to who we are as a company.    

We all know that data has never been more valuable, nor more vulnerable, than it is in today’s digital landscape. Organizations face an increasingly turbulent data environment with cyberattacks increasing year over year. That’s why it’s so important for us to be more proactive than ever – we’ve done this by deploying technologies like „Metallic Threatwise, next-generation cyber deception that immediately engages and surfaces threats the moment they happen, but we also do it by empowering our employees. We discuss data protection, recovery, and ransomware with our partners and customers every day, but it’s crucial that our employees understand that they are the first line of defense in mitigating Security Risks. 

As we look inside Commvault at how we’re talking about this with our Vaulters, creating a culture of continual education and conversation on cybersecurity topics is integral to our security strategy. We recently completed our annual Security Training, which helps us reinforce the security posture of our company and empowers our Vaulters to embrace their role as the first line of defense when it comes to cyber threats. It is our top priority to ensure our teams know how to identify, mitigate, and respond to security risks that could potentially jeopardize Commvault, our data, and impact our stakeholders. Commvault is proud to be a 2022 Champion for Cybersecurity Awareness Month and over the next few weeks we’ll be providing our Vaulters with new resources and learning opportunities on this very important topic.   

And outside the walls of Commvault, we certainly remain focused on cybersecurity. We’re continuing the conversation at Connections, our cloud data management experience. Join me as I moderate our session on Ransomware Retrospective: Supporting the Recovery, one of three Fending Off Ransomware solutions tracks that will be offered during our event. Join us to hear real customer recovery stories from our Commvault® Support & Services Team as they share the good, the bad, and the ugly. Learn why some recoveries went well and why others did not. Take advantage of this up close and personal interaction with the Commvault® Support & Services Team, which has helped organizations recover quickly and maintain a state of recovery readiness and steady response. The importance of data protection strategies and cybersecurity awareness will only continue to grow – make sure your business, and employees, are set up for success this month and beyond. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Was ist eine Vorlage für einen Notfall-Recovery-Plan?

Disaster recovery is a subcomponent of a business continuity plan. It focuses on restoring core operations while minimizing or avoiding downtime caused by a disaster event. In today’s data-centric business environment, the IT portion of a disaster recovery plan is typically the heart of a modern business continuity plan. It’s intended to ensure core operations remain online when a disaster event — such as a ransomware attack, natural disaster, or prolonged power outage — threatens the interruption of business continuity.

Viele Organisationen nutzen eine Vorlage für einen Plan zur Notfall-Recovery, um sicherzustellen, dass sie bei der Erstellung ihres Plans auch den kleinsten Aspekt berücksichtigen. Dieses Dokument deckt Aspekte ab, die von der Aufrechterhaltung der Stromversorgung über sekundäre Kommunikationswege bis hin zur Gewährleistung der Betriebsfähigkeit von IT-Systemen reichen können.

Below, we’ll look at perhaps the most important part of a disaster recovery plan template for organizations that have migrated their data and workloads to the cloud:cloud backup.

Wie sich Cloud-Backups in eine Vorlage für einen Notfall-Recovery-Plan einfügen lassen

The IT portion of a Plans für die Recovery is primarily focused on recovering and restoring the mission-critical data and workloads needed to ensure business continuity. For example, if your business has experienced a ransomware attack and lost access to its primary data, the Plans für die Recovery outlines the steps needed to restore that data so core operations can continue.

If your organization has migrated to the cloud, a cloud backup solution is the ideal method to facilitate a restore since it can leverage the scale and elasticity of the cloud. The cloud backup solution allows you to automatically back up data on a customized schedule and then store the data. Should data recovery be required, the solution can restore the data from the most recent backup.

It’s crucial to note that data can only be recovered and restored if there’s a valid backup copy to restore from, making the security of the backup data paramount. If your backup data copy is unsecured and exposed, you are risking your ability to recover the data. Plus, since business continuity is time-sensitive, the disaster recovery plan should be able to restore the most important data and workloads first so your most essential operations and processes can continue unhindered while a full restore completes.

Daher sollte eine effektive Vorlage für einen Notfall-Recovery-Plan für ein Cloud-natives Unternehmen Folgendes enthalten:

  • Eine praktikable Cloud-Backup-Lösung
  • Eine Möglichkeit, die Sicherheit der Backups zu gewährleisten
  • Eine Methode zur Ermittlung und Priorisierung der geschäftskritischen Daten, die zur Gewährleistung der Geschäftskontinuität erforderlich sind

However, not all cloud backup solutions are capable of checking all these boxes. The cloud backup tool you choose will directly affect your organization’s disaster recovery abilities.

Sichere Cloud-Backups und schnelle Notfall-Recovery mit Clumio

Clumio’s secure cloud backup platform optimizes disaster recovery with features designed to streamline data restoration—enabling an organization to meet or exceed its recovery time objective (RTO) during a disaster event.

Clumio safeguards backup copies by storing them in an encrypted, air-gapped backup solutionoutside of the primary account — meaning if your primary data is accessed or compromised, the backup remains safe. When data restoration is needed, Clumio’s granular and flexible recovery capabilities can quickly identify and rapidly restore the specific mission-critical data and applications needed to maintain business continuity while a full recovery completes.

Cloud backup is the key to a successful disaster recovery plan template. Learn why Clumio is the industry’s leading innovator for cloud backup and rapid disaster recovery by scheduling a demo today.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Our value – We Connect – is a guiding principle for my day-to-day here at Commvault.

Since I joined Commvault seven years ago, I’ve been very fortunate to work with a group of incredibly motivated and hardworking Vaulters.

I first joined Commvault as a Digital Project Manager on the Marketing team, where I assisted the digital marketing team with the planning and execution of multi-channel campaigns. When we incubated Metallic in 2019, I was recruited to join the team. It’s crazy to think that back then, the Metallic team was a small group of agile, scrappy Vaulters in a start-up culture creating and building our new software-as-a-service offering. And now, more than three years later, it’s grown to a $50 million ARR business for Commvault.

Now, as Director of Program Management for Metallic, I’m primarily responsible for managing the overall roadmap, timelines, and cross-functional coordination across the entire Metallic team. With a SaaS business, all team members—from our engineers to our marketers—need to be connected to create a flawless customer experience. My program management team and I drive communication and ensure that all teams have what they need to deliver innovative solutions, campaigns and enhanced customer experiences.

Ein großer Teil meiner Arbeit besteht darin, verschiedene Menschen und Teams miteinander zu vernetzen, und ich habe das Privileg, aus erster Hand zu erleben, wie unsere Zusammenarbeit dazu beiträgt, effizient Ergebnisse zu erzielen. Vor kurzemhat Commvault TrapX übernommenundMetallic® ThreatWise™, a newly-available data security service that provides customers with early threat detection. This is just one example of how we bring together smart people to solve tough problems for our customers—and we have fun doing it!

If you’re looking to learn more about what it’s like to work at Commvault, check out this recent blog from David to hear his perspective!  

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

With today’s announcement around „Metallic Threatwise Cyber Deception Service, Commvault is changing the game when it comes to addressing security threats including ransomware. But our innovations in enhancing data security don’t stop there. We’ve also recently released Commvault Platform Release 2022E, and with that release come additional enhancements to help our customers better protect their data. This new release introduces several new capabilities to simplify data management – in this blog, I’ll focus on the new data security additions in our new release.

Adie „Zero-Loss-Strategie“ is designed to help protect you from ransomware attacks and is anchored on the pillars of end-to-end data visibility, broadest workload protection, and faster business response, built on the foundation of Zero Trust principles. End-to-end data visibility ensures that you catch threats before they impact your data – in addition to Metallic ThreatWise for early detection through cyber deception, we have also expanded our file anomaly framework to detect malicious applications that may evade traditional detection methods by posing as safe file types.

Tiefere Einblicke in verdächtige Dateiaktivitäten ermöglichen eine bessere Erkennung und schnellere Reaktionen auf potenzielle Bedrohungen für Ihre Daten

 

This feature drives faster business response with immediate alerting of suspicious activity, along with automatic, efficient data recovery using clean versions from unaffected backups. Not just that – we’ve also expanded our data governance capabilities to now profile object storage for Azure, AWS and GCP, eliminating another common area of data leakage.

Another enhancement we’ve added is Changed Block Tracking (CBT) support for Azure Disk encryption. CBT improves backup performance while lowering backup costs, by consuming less storage and bandwidth for incremental backups. Historically, however, the ability to perform encryption while using CBT was limited, forcing a tough customer choice between security or cost savings. Working closely with Microsoft, we are excited to now introduce CBT efficiencies with Azure Disk encryption for managed and unmanaged encrypted disks. No longer do you need to make a choice between security, performance and cost efficiencies!

Zu guter Letzt freue ich mich, Ihnen mitteilen zu können, dass wir nun die WORM-konforme Sec17a-Zertifizierung für Commvault Grid erhalten haben. Diese ergänzt unsere bereits umfangreiche Liste an Sicherheitszertifizierungen – darunter FIPS 140-2, FedRAMP High „In Process“ – bereit zur Prüfung durch das PMO – und weitere – und rundet die Funktionen des unveränderlichen Dateisystems von Commvault Grid ab.

These are just some of the new Data Security capabilities available in Commvault Platform Release 2022E, a release that’s packed with new features and innovation, reflecting on our continued investment in Intelligent Data Services.

Weitere Informationen zu dieser Version finden Sie auf dieserSeite and stay tuned and we’ll be discussing more of the exciting new updates in Commvault Platform Release 2022E at our virtual event, Connections on Nov 2/3.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

On September 22, Commvault will be presenting live from San Jose, as part of Cloud Field Day 15. 

For the uninitiated, Cloud Field Day is part of the popular “Field day” series, which also includes Tech Field Day and Security Field Day. 

Hosted by Stephen Foskett, delegates from cutting edge companies, including Commvault, share their latest product news and innovations live with a group of hand-picked influencers.  A lively debate usually results, which also takes place across Social Media.

This Cloud Field Day, we’ll be taking the delegates through the very latest in data security technology including a first deep look at Metallic ThreatWise, a newly available data security service which provides customers with much needed early threat detection.  Highlights from Commvault’s recently released Platform release 2022E will also be included to showcase the breadth of Commvault’s Intelligent Data Services.

We’ll be live streaming the session right here on this blog as well as across Commvault’s LinkedIn Channels.

See you on Thursday, 22nd September at 1:30pm PT. Join in the Social Media conversation by using #CFD15.  You don’t want to miss it.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Microsoft 365 is an essential component of today’s enterprise data environment. Still, many organizations fail to include it in their data protection plan. This is partly due to the misconception that cloud service providers are responsible for both administering the solution and protecting the data created and stored within it. However, this is not the case.

Your data, your responsibility

Microsoft provides a highly resilient platform and goes to great lengths to secure data residing within its application. However, like many cloud service providers, they follow what is known as the shared responsibility model, where they are responsible for maintaining the uptime, availability, and access to the solution, while the customer is responsible for protecting the data created and stored within that solution. And now, more than ever, your Microsoft 365 data must be protected and recoverable in the face of emerging threats.

It’s no secret that cyberattacks are on the rise, and SaaS applications are not immune. And there are other potential risks for the data beyond the risks of ransomware. Accidental deletion of data, network vulnerabilities, and internal breaches are all causes of data loss in SaaS applications.

Protection measures to prevent data loss go beyond understanding the shared responsibility model. They require purpose-built tools to help you safeguard your data from today’s threats.

You need dedicated data protection and recovery

While Microsoft offers native controls for data replication, today’s businesses need long-term retention, data separation, and tools for SLA compliance and recoverability. You need a dedicated third-party backup solution that offers the essential capabilities needed to protect and secure your data.

Here are just a few components where protection from third-party backup extends beyond native capabilities to provide advanced protection from today’s threats:

  • Isolierung von Daten
  • Verlängerte Aufbewahrungsfrist
  • Flexible Wiederherstellung
  • Einhaltung von SLAs

Commvault enhances Microsoft 365 data protection

Ganz gleich, ob Sie bereits Commvault-Kunde sind oder Commvault in Zukunft einsetzen möchten – wir bieten Ihnen Datenschutz für Microsoft 365 sowohl über „Commvault Complete Data Protection“ als auch über „Metallic SaaS Backup“ an, sodass Sie die Lösung wählen können, die Ihren individuellen geschäftlichen Anforderungen am besten entspricht.

Are you looking for a SaaS-delivered solution with rapid deployments, unlimited storage and retention included, and no additional infrastructure required? Then „Metallic for Microsoft 365“ is the best fit.

Looking for on-premises data protection or want to leverage your own infrastructure? Do you have specific needs for long-term retention or migration between on-premises Exchange and Microsoft 365?  Then look to on-premises protection through Commvault Complete Data Protection for Microsoft 365.

Um mehr darüber zu erfahren, wie Commvault den Datenschutz für Microsoft 365 verbessert, besuchen Sie bittecommvault.com/microsoft-365.

Learn more about Microsoft’s das Prinzip der geteilten Verantwortung.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

https://play.vidyard.com/HSrWMH7cRstsFT42QdpTua.jpg

Wissen Ihre Teams, welche Aufgaben und Verantwortlichkeiten sie bei einem tatsächlichen Cyberangriff haben?

Verfügen Ihre Teams über die Entscheidungsbefugnis, um spontan Entscheidungen zu treffen, oder müssen sie erst eine Zoom-Konferenz einberufen, um die Genehmigung zum Herunterfahren von Servern zu erhalten?

Sind Ihre IT-, Netzwerk- und Sicherheits-OP-Teams sich einig darüber, welches Team für was zuständig ist, wann es eingreifen soll und wann nicht?

According to a recent Gartner report, multidisciplinary teams that blend technology or analytics and business domain expertise and share accountability for business and technology outcomes foster team fusion innovation for digital delivery. Fusion teams consist of business and IT staff: product owners, scrum masters, developers, and domain experts. Fusion teams help to remove friction and address companywide issues and requirements.1

A village

With so many ransomware factors, it is usually within the innocent context that someone simply clicks a link, infecting an organization’s entire network with malware. There are many considerations on how you will defend against this very prevalent threat. Defending against ransomware is a major challenge  – and no individual team can combat it on their own. It takes a well-equipped, prepared, and practiced village to deal with complex threats successfully – one that includes:

People

Die Abstimmung mit internen und externen Teams vor, während und nach einem Ransomware-Angriff ist entscheidend für eine schnelle Reaktion und Recovery, damit diese schneller reagieren und die mit Ausfallzeiten verbundenen Kosten minimieren können.

Process

It is important that internal and external teams are aware of and in sync regarding their responsibilities and what processes they need to follow during a ransomware attack. Test, test, and test your process, as speed will be essential, and you don’t want to test out your process during an attack.

Technology

Follow theNational Institute of Standards and Technology (NIST) Cybersecurity Frameworkto aid your preparation. Adopting a multi-layered security framework helps ensure your data is ready for recovery and reduces the risk of loss.

Call To Action

Datenverlust und die Unfähigkeit, Daten schnell wiederherzustellen, kosten Ihr Unternehmen Geld und Zeit und gefährden Ihren Ruf sowie Ihren Geschäftsbetrieb.

  • Identifizieren Sie die wichtigsten Beteiligten: Legen Sie fest, wer im Falle eines Cyberangriffs einbezogen werden muss.
  • Identifizieren Sie die wichtigsten Vermögenswerte: Machen Sie sich klar, was wichtig ist und was nicht.
  • Führen Sie eine Tabletop-Übung durch: Überprüfen und kommunizieren Sie Ihre Pläne proaktiv.
  • Nachbetrachtung und Umsetzung von Änderungen: Verbesserpotenziale ermitteln und diese Änderungen umsetzen.

Bitte lesen Sie unsereBook Understanding Team Roles & Responsibilities in fighting ransomware to learn more.

This content has been derived from Commvault Connections 2021. Watch Dave Martin’s presentation hier.


  1. Gartner, „I&O Forward: Wegbereiter für die nächste Wachstumsphase“, 2022

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Einige Beispiele für den Mandela-Effekt:

  • Obwohl die meisten Menschen die Kinderfigur „Curious George“ als Figur mit einem Schwanz in Erinnerung haben, hat er gar keinen.
  • Many people believe there is a brand of peanut butter called “Jiffy” but there is not. There’s Jif, and there’s Skippy, but no Jiffy.
  • In the iconic scene in “Silence of the Lambs,” Hannibal Lecter does not say “Hello Clarice” as many people remember.  He says “good morning.”

Der Mandela-Effekt in der Cloud

The Mandela effect is not just a pop culture phenomenon, it exists in the world of enterprise technology, too. It’s a common misconception that data stored in the cloud is automatically backed up.  The truth is that cloud providers operate on a shared responsibility model, in which the cloud provider is responsible for the security of the software, hardware and infrastructure, but not customers’ data.

Shared Responsibility Model from AWS

For example, when AWS refers to their highly durable Amazon S3 service, it’s true that the platform is incredibly durable, which means you’re unlikely to experience any trouble with their systems or infrastructure.  However, this has nothing to do with protecting your data from accidental deletions, ransomware attacks or insider threats. According to the shared responsibility model, that’s your job.

Maßnahmen zum Schutz Ihrer Cloud-Daten

Kunden schätzen die Zusammenarbeit mit Clumio, weil sie eine „Air-Gapped“- und unveränderliche Datensicherung mit unglaublich kurzer Amortisationszeit erhalten, während die Einfachheit von SaaS eine schnelle und unkomplizierte Erfassung, Katalogisierung, Suche und Recovery in jedem Umfang gewährleistet. Mit Clumio können Kunden den Schutz ihrer AWS- und Microsoft 365-Daten automatisieren, wodurch sie Zeit und Ressourcen sparen, sich auf strategische Initiativen konzentrieren können und im Vergleich zu anderen Optionen die Gesamtbetriebskosten senken.

Don’t let data protection misconceptions leave you vulnerable.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In diesem Blog werden wir folgende Themen behandeln:

Containerization

What is a container?

  • A Container is a basic software unit that packages up code and all its dependencies so an application can run smoothly in any environment. Each container is made up of a hardware, an operating system, a container engine, libraries, and dependency’s and finally the application. Everything the application needs to run is inside the container which means it can be created and deleted quickly using automation.
    • Bis 2025 werden 85 % der Unternehmen weltweit containerisierte Anwendungen im Produktivbetrieb einsetzen1

Container Orchestration

  • Container-Orchestrierung bezeichnet die Automatisierung containerisierter Workloads. Sie spielt bei der Arbeit mit Containern eine zentrale Rolle, da sie es ermöglicht, dieselbe Anwendung in verschiedenen Umgebungen bereitzustellen, ohne dass eine Neugestaltung erforderlich ist.

Kubernetes

What is Kubernetes (aka K8s)?

  • Kubernetes is an open-source container orchestration software designed for deploying, managing, and scaling containers. So, what does that mean? Essentially it eliminates much of the manual processes that needs to be done during deploying and scaling containerized workloads, even across various types of physical, virtual, and cloud environments.
  • Laut einer aktuellen Umfrage der Cloud Native Computing Foundation nutzen oder prüfen 96 % der 3.800 befragten Unternehmen Kubernetes2

Did you know?

  • The name Kubernetes comes Greek word κυβερνήτης (kubernḗtēs) which means pilot or helmsman therefore the Kubernetes logo is a ship’s steering wheel.  Kubernetes is often abbreviated as K8s because there are 8 letters in between ‘K’ and ‘S’
  • Kubernetes wurde ursprünglich von Google-Ingenieuren entwickelt und konzipiert und später, im Jahr 2015, an die CNCF übergeben.

How does it work?

  • Kubernetes is a concept made up of several different components, and, while there are several elements and use-cases in the implementation of Kubernetes, the main concepts to understand are: the Control PlanePods, and Nodes.
    • The Control Plane consists of elements and API processes which coordinate workloads and communications, allowing for the smooth flow of information and resource allocation across the environment.
    • Pods are the base element in Kubernetes. A Pod consists of one or more containers and are co-located on the same node.
    • A Node (also known as a minion, or worker)is a machine on which containers are deployed. Each node must run a container runtime such as Docker, CoreOS rkt, Containerd, etc. Multiple Nodes can be grouped into Clusters.

Your IT environment and Kubernetes

  • Aufgrund der Veränderungen in der modernen IT-Praxis erwarten Nutzer, dass Anwendungen rund um die Uhr verfügbar sind, und von Entwicklern wird mitunter erwartet, dass sie mehrmals täglich neue Versionen der Anwendungen bereitstellen können. Zudem werden IT-Umgebungen zunehmend hybrider und basieren auf Multi-Cloud-Ansätzen, bei denen lokale Ressourcen mit öffentlichen oder privaten Clouds verschiedener Anbieter integriert werden. Zwar ermöglichten Containersysteme den Entwicklern, Software portabler zu gestalten und alle für den Betrieb eines Dienstes erforderlichen Pakete zu bündeln, doch waren sie nach wie vor durch den manuellen Aufwand eingeschränkt, der für die Bereitstellung und Änderung jedes einzelnen Containers in einer Umgebung erforderlich war.
  • Kubernetes kann Unternehmen dabei helfen, ihre Workloads besser zu verwalten und Risiken zu reduzieren. Kubernetes ist in der Lage, Vorgänge im Container-Management zu automatisieren und die Nutzung von IT-Ressourcen zu optimieren. Es kann sogar verwaistete Container neu starten, nicht genutzte Container herunterfahren und sie neu erstellen. Kubernetes automatisiert die Bereitstellung von Containern, ohne dass das DevOps-Team alle Schritte manuell selbst durchführen muss. Dadurch können Entwickler neue Versionen bestimmter Anwendungen häufiger bereitstellen und diese ohne Ausfallzeiten veröffentlichen und aktualisieren – sogar über mehrere Umgebungen hinweg (z. B. Dev, Test, Prod).

Benefits of Kubernetes

  • Die wichtigsten Vorteile von Kubernetes lassen sich wie folgt zusammenfassen: verkürzte Entwicklungs- und Release-Zeiten für Anwendungen, Optimierung der IT-Kosten, erhöhte Skalierbarkeit und Verfügbarkeit der Software, Flexibilität in Multi-Cloud-Umgebungen sowie Cloud-Portabilität.
  • Portable Workloads
    • Because Kubernetes is an open source your workloads become portable take advantage of on-prem, hybrid, and multiple cloud environment— all while maintaining consistency across each environment.
  • Flexibilität
    • Unabhängig davon, wo Sie Kubernetes einsetzen, bietet es Flexibilität in Hybrid- und Multi-Cloud-Umgebungen und ermöglicht so den reibungslosen Betrieb all unserer Anwendungen in jeder öffentlichen oder privaten Umgebung.
  • Echte
    • Kubernetes kann containerisierte Umgebungen automatisieren, indem es als deren Betriebssystem fungiert. Dies geschieht durch die Echte der Betriebsanforderungen containerisierter Workloads.
  • Skalierbarkeit und Verfügbarkeit
    • Mit Kubernetes lassen sich komplexe containerisierte Anwendungen definieren und über Servercluster hinweg bereitstellen. Während Kubernetes Anwendungen entsprechend dem von Ihnen gewünschten Zustand skaliert, überwacht und gewährleistet es automatisch den ordnungsgemäßen Betrieb der Container.

Kubernetes Architecture 

  • Kubernetes control plane: Also known as the master machine, is the container orchestration layer that exposes the API and interfaces to define, deploy, and manage the lifecycle of containers aswell as the nodes that hold the containerized applications. It ensures that every cluster is kept in its desired state.

The components of the Control Plane

  • API Server: The Application Programming Interface also know as API is the front end of Kubernetes. It is where clients make an initial request for an object or a collection and it determines if the request is valid and then it will process it. The API server also is what is used to transmit, create, and configure data within K8 clusters.
  • K8s scheduler: The scheduler is what watches and manages pods that are newly created and assigns them to a node so they can run on it smoothly.
  • Controller manager: Within the Control Plane there are multiple controllers, they are the control loops designed to watch the state of your cluster and make or request changes as they are needed.
  • Etcd: Is a data base where all your container storage is stored. It is a strongly consistent, distributed key-value store that holds and manages the critical information that systems need to run.
  • Cluster
    • NODE: (also known as a minion, or worker)is a machine on which containers are deployed. Each node must run a container runtime such as Docker, CoreOS rkt, Containerd, etc. Multiple Nodes can be grouped into Clusters.
    • Pod: are the base element in Kubernetes. A Pod consists of one or more containers and are co-located on  nodes.
      • Hier werden alle Ihre wichtigen Informationen gespeichert

Modernize with Kubernetes

  • Kubernetes ermöglicht es, die Migration von Anwendungen aus einer lokalen Umgebung in öffentliche oder private Clouds beliebiger Anbieter zu vereinfachen und zu beschleunigen. Die Migration von Anwendungen in die Cloud kann mithilfe verschiedener Methoden erfolgen:
    • die einfache Portierung der Anwendung ohne jegliche Änderungen am Code (Lift & Shift);
    • die minimalen Änderungen, die erforderlich sind, damit die Anwendung in neuen Umgebungen funktioniert (Replatforming);
    • die umfassende Überarbeitung der Struktur und Funktionalität der Anwendung (Refactoring).
  • Modernisieren Sie Ihre Umgebung mit der Einführung von Kubernetes reibungsloser als je zuvor. Sie müssen sich nicht mehr fragen, wo sich Ihre Daten befinden – alle Ihre Daten werden an einem Ort gespeichert. Der Speicher bei Kubernetes basiert auf Volumes. Die Volumes können entweder persistent oder nicht-persistent sein. Innerhalb der Pods fordern Container zusätzlichen Speicherplatz an.
    • Kubernetes can be built once and then is able to be deployed anywhere. This means no matter where you build your cluster whether it is on prem or in the cloud you don’t need to rebuild the solution you just have to deploy a different cluster.

Challenge

  • Kubernetes clusters can be prone to ransomware attacks, like any other workload. In some cases, a hacker can gain access to what is inside of your pod –  potentially receiving critical information about your organization. Therefore, backing up and having data protection for your clusters is vital when it comes to moving your workloads around.

Kubernetes Backup

  • Hierbei handelt es sich um den Prozess der Sicherung aller Komponenten, die auf einer Kubernetes-Orchestrierungsplattform ausgeführt werden, darunter alle containerisierten Anwendungen des Unternehmens. Da ein Kubernetes-Cluster aus so vielen Komponenten besteht – Pods, Knoten, Control Plane und Volumes –, benötigt jede einzelne davon ein gewisses Maß an Schutz. Der Schutz ist für einen Cluster von entscheidender Bedeutung, insbesondere da Unternehmen zunehmend auf Kubernetes setzen. Die Sicherung eines Kubernetes-Clusters stellt sicher, dass die Daten, Konfigurationen und Dateien vor Angriffen geschützt sind. Aus diesem Grund benötigen Sie eine Lösung, die in der Lage ist, Ihren gesamten Cluster zu sichern.
  • Zu den wichtigsten Phasen der Kubernetes-Sicherung gehören:
    • Die Erfassung
    • Discovery.
    • Identifizierung von Ressourcen
      • Laut dem „State of Kubernetes Security Report 2022“ von Red Hat hatten 93 % der Befragten in den letzten 12 Monaten mindestens einen Sicherheitsvorfall in ihren Kubernetes-Umgebungen zu verzeichnen, was in einigen Fällen zu Umsatz- oder Kundenverlusten führte.³

Commvault and Metallic’s Kubernetes Backup

Commvault and Kubernetes Data Protection

  • Commvault has the ability to back up your entire cluster unlike most solutions that can only back up your containers. Commvault provides data protection for persistent storage in your stateful applications. Commvault’s solution automates back up of this data all from a single platform that increases the visibility and management capabilities of your entire environment. Our solution gives you the flexibility to migrate and deploy containers from on-prem to cloud, cloud to cloud and even back on- prem seamlessly with ease. It also offers broad support for VMs, data services and cloud services in a single platform. It is also compatible with all CNCF- certified distributions and integrated with CSI for snapshot-based backups.
  • Commvault has been recognized by the 2022 GigaOm report as a “leader and outperformer” in Kubernetes data protection for our flexible deployment architecture and single interface across multiple deployments. The report also states that our security and ransomware controls are extensive which makes it suitable for larger enterprises.

How Commvault does it

  • Commvault plant einen Pod mit temporären Mitarbeitern ein, um die Datenübertragung durchzuführen. In den Einstellungen wird eine private Container-Registry angegeben, in der Sie ein Image speichern, das Commvault herunterladen kann. Auf diese Weise können Sie Cluster konsolidieren, die clusterübergreifende Migration vereinfachen und das Lebenszyklusmanagement von Clustern optimieren.

Challenges before Commvault

  • Vor der Einführung von Commvault mussten Unternehmen sich mit einer zunehmenden Anzahl von Clustern auseinandersetzen, deren Lebenszyklen verwalten und Cluster konsolidieren. Commvault hilft bei der Bewältigung dieser Herausforderungen, indem es Ihnen ermöglicht, Ihre Kubernetes-Anwendungen mühelos in jede beliebige Cloud zu migrieren.

Metallic and Kubernetes backup

  • Metallic bietet VM & Kubernetes Backup an. Dies ist der einzige SaaS-Datensicherungsdienst, der eine umfassende Abdeckung hybrider Workloads bietet und so gewährleistet, dass Ihre Container stets geschützt sind.
  • „VM & Kubernetes Backup by Metallic“ ist eine Lösung, mit der Sie Ihre Infrastruktur ganz einfach auf Container ausweiten können, um Anwendungen sicher zu modernisieren und gleichzeitig herkömmliche Anwendungen zu schützen. Ganz gleich, ob Sie on-premise oder in der Cloud arbeiten – Metallic unterstützt alle von der Cloud Native Computing Foundation zertifizierten Kubernetes-Distributionen wie Azure Kubernetes Service (AKS), Amazon EKS, VMware, Rancher und viele weitere.
  • Metallic kann Cloud- oder lokale Datenbanken, Quellcode-Verwaltungssysteme, Image-Registerstellen und cloud-native Objektspeicher schützen.
  • Dank der unübertroffenen Flexibilität, der ultimativen Sicherheit und der unkomplizierten Verwaltung dieser Lösung sind alle Ihre Workloads bestens abgedeckt.

Schlussfolgerung

Kubernetes ist die Zukunft – jetzt ist es an der Zeit, sicherzustellen, dass alle Ihre Workloads geschützt sind und sicher in die Cloud migriert werden können. Commvault ist die naheliegende Wahl. Im GigaOm-Bericht 2022 zum Thema Kubernetes-Datensicherheit wurden wir aufgrund unserer umfassenden Workload-Unterstützung, der Kompatibilität mit CNCF-zertifizierten Distributionen und unserer umfangreichen Ransomware-Schutzmaßnahmen als „Leader“ und „Outperformer“ ausgezeichnet. Also packen Sie Ihre Koffer – das Schiff sticht noch heute in See, Richtung Cloud.

References

1. Best Practices for Running Containers and Kubernetes in Production – 4 Aug 2020 – Gartner ID G00730344 – 2. CNCF 2021, Annual Survey – 3. Red Hat 2022, State of Kubernetes Security Report

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Enterprises today are inherently heterogeneous, running applications and supporting workloads across on-prem, edge and multiple clouds. As businesses accelerate their IT transformation, this hybrid multi-cloud presence is set to further expand. It is imperative, then, that enterprise data protection and data management solutions excel in all of these areas – across on-prem, edge and multiple clouds.

Gartner Critical Capabilities report assesses these types of solutions on various key aspects such as security, efficiency, scalability and performance, Data Center ecosystem, and reporting and analytics across the key use cases of on-prem, edge and cloud. In my conversations with CIO’s, IT leaders, and architects, these are exactly the key aspects they are concerned with when architecting their data management strategy to protect their crown jewels.

This is why we are thrilled and honored that Commvault Backup & Recovery has scored the highest in all three use cases in the 2022 Gartner Critical Capabilities for Enterprise Backup and Recovery Software Solutions: Data Center Environments (4.23/5), Cloud Environments (4.18/5), and Edge Environments (4.22/5). With the highest scores in all three use cases – for the third time in a row – we believe this is yet another validation of our commitment to be a trusted partner to our customers in protecting their data and workloads – no matter where they reside.

Data Center Environments (4.23/5)
Cloud Environments (4.18/5)
Edge Environments (4.22/5)

Unternehmen entwickeln sich ständig weiter und wachsen, um den geschäftlichen Anforderungen gerecht zu werden. Daher ist ein weiterer entscheidender Beschleuniger der IT-Transformation eine Datenmanagement-Lösung, die sich flexibel zusammen mit dem Rest der IT weiterentwickeln kann.

“Our continuous innovation is designed with ultimate flexibility when it comes to data management – offering not only an enterprise software solution but also the ability to manage and protect enterprise data with Commvault Grid as an integrated solution or via Metallic as a cloud-delivered DMaaS solution.”


Unfortunately, flexibility and breadth are often offered at the cost of simplicity in our industry.  In contrast, Commvault breaks this paradigm with our “infinitely scalable, radically simple” approach. We bring together all management – across our broad set of supported workloads, flexible form factors and array of Intelligent Data Services – through the single experience of Commvault Command Center. This simplicity – with no compromise to flexibility and breadth – empowers customers to fast-track their business transformation aligning their data management to their broader IT strategy. As businesses modernize and transform, transitioning applications and workloads from one form factor or location to another (from on-prem to cloud, for example), we ensure they remain protected no matter where they are in this journey.

As an eleven-time Leader in the Gartner Magic Quadrant and back-to-back years with the highest scores in all three use cases in the Gartner Critical Capabilities report, we are grateful to our customers for partnering with us in this journey of continuous customer-first innovation and to our partners in building a data ecosystem with no boundaries. Our journey to solve the hard data management problems with elegant solutions continues … together with our dear customers and partners!

Gartner, „Magic Quadrant für Backup and Recovery-Softwarelösungen für Unternehmen“, 28. Juli 2022, Michael Hoeck u. a. Gartner, „Critical Capabilities für Backup and Recovery-Softwarelösungen für Unternehmen“, 22. August 2022, Nik Simpson u. a.

Gartner Disclaimer:

**Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.**

**GARTNER und Magic Quadrant sind eingetragene Marken und Dienstleistungsmarken von Gartner, Inc. und/oder deren Tochtergesellschaften in den USA und international und werden hier mit Genehmigung verwendet. Alle Rechte vorbehalten.**

Holen Sie sich Ihr Exemplar des Gartner-Berichts „Critical Capabilities for Enterprise Backup and Recovery Solutions 2022“

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Commvault’s long time partnership with Microsoft has once again given us the opportunity to offer our customers cutting edge features and functionality.  We are excited to have had the opportunity to develop this feature in lockstep with Microsoft allowing us to release our enhanced capabilities on Commvault Complete and Metallic® DMaaS simultaneously when Azure Restore Points became publicly available on July 19th 2022.

Commvault Protection for Azure Virtual Machines

Abbildung 1

Commvault has always offered options for protecting Azure Virtual Machines (VM) by using snapshots or even installing software on the VM to provide Application Awareness.   Each disk resource is individually snapped and protected.  The process is serial by nature as each resource request needed to be made in series. 

In Abbildung 1 müsste ein Sicherungsauftrag zunächst die Betriebssystemfestplatte, dann die Festplatte „Data 1“ und anschließend die Festplatte „Data 2“ sichern. Alle drei Festplatten bilden die virtuelle Maschine und würden gemeinsam gesichert, doch ihre Snapshots werden möglicherweise nicht genau gleichzeitig fertiggestellt, sodass eine zusätzliche Abstimmung mit der Anwendungsebene erforderlich sein könnte, um die Konsistenz auf Anwendungsebene zu gewährleisten.

New Restore Point Functionality

Abbildung 2

With Restore Points, Commvault will now have the ability to create collections of restore points across all volumes on a VM.  When doing so, the restore process is simplified, and the collection points are stored on cost efficient storage.  This is a major architectural change in data protection for Microsoft that Commvault Complete and Metallic enable with a click.

In the example in Figure 2, once a Restore Point Collection is created, the same VM would be protected as a single API call to create a Restore Point.  Every Restore Point is incremental and should complete in seconds.  All disks within the VM are consistent with the restore point automatically.  Every Restore Point will contain a Disk Restore Point for all managed disks.  The Disk Restore Point consists of a snapshot of that disk.  This reduces the restore process in this example from 3 steps to 1.  

How is it simplified? 

Leveraging the Commvault platform to orchestrate VM protection and more importantly, the recovery of VMs at enterprise scale is a critical need.  Getting away from point solutions and homebrew scripting naturally promotes growth and reduces downtime.  Being able to recover dozens or hundreds of instances with a few clicks keeps end user time from being sacrificed.

Improve resiliency while reducing tech waste

Commvault supports creating snapshots in cost audited resource groups already and automatically tags resources as they are created so that cost reporting is accurate.  Adding VM Restore Points to our portfolio now allows us to create the restore points in cost efficient and less redundant storage tiers.  It might be a minor cost difference, but at cloud scale, the billing is in the details and every improvement brings value to the solution.   There’s no tradeoff in taking advantage of Restore Points.  It simplifies and reduces cost while improving resiliency.  Azure Restore Points ensures that the applications and the operating system are consistent when creating these collections at the native instance level. 

A quick recap

Better cost efficiency, better performance, better resiliency, and a simplified design.  A resounding win!  We are excited to have had the opportunity to develop this feature in lockstep with Microsoft and prove yet again our commitment to making the latest enhancements in Azure readily available within the Commvault Intelligent Data Services portfolio of solutions.   

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In der Cloud ist das Gras tatsächlich grüner

Until very recently, many enterprises were limited by on-prem infrastructure, requiring huge data centers that had to be maintained, cooled, and secured. On top of that, the enterprise-owned server utilization rate is a measly 18%, with the majority of data centers operating at energy efficiency levels below 80%. This underutilization made on-prem ripe for disruption when the cloud came about. The cloud’s on-demand scalability provided companies the ability to optimize utilization rates without the hassle of managing, powering or cooling infrastructure. Considering the benefits, it’s not surprising that the average enterprise on-prem to cloud migration led to a 65% energy reduction and 84% carbon reduction (Accenture, „The Green Behind the Cloud“). Moreover, AWS is set to power all operations with 100% renewable energy by 2025, with a commitment to achieve net-zero carbon emissions by 2040. They use reclaimed or recycled water for cooling and have embodied carbon in the construction of newer data centers across the globe. And as an AWS recommended partner, Clumio is pushing the boundaries of environmentally sustainable computing with its on-demand hyper-scalable architecture.

Cloud-native Lösungen sind der Schlüssel zur Maximierung der Nachhaltigkeit

whether you need help protecticting your data against ransomware, meeting compliance requirements, or recovering from data loss; data backups can take up a significant amount of storage space, and increase your infrastructure footprint if done on-prem. Companies must choose carefully if they are conscious of reducing their carbon footprint from their data. Some best practices include going with a cloud-native / SaaS data protection vendor if possible, implementing incremental backups vs full system snapshots, categorizing and auto-archiving data based on criticality and usage, and most importantly, investing in a platform that is architected to scale on demand. If these concerns sound like yours, Clumio can help.

Wie Clumio helfen kann

Clumio is a cloud-native backup solution, architected with a container-based stateless data processing pipeline that leverages efficient Lambda functions. This allows adaptability and efficient scaling to optimize usage based on your exact policies. Having this scalable compute and increased utilization rates can ultimately lead to significant carbon reduction from your data estate, in addition to significantly lower TCO (save your wallet while saving the planet).

See for yourself how the industry’s first cloud-native backup and rapid recovery solution can optimize your business’s sustainability metrics. Schedule a demo and learn how your business can be up and running with Clumio in as few as 10 minutes — no need to wait for and install new infrastructure and software.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In this blog, you’ll learn how Commvault Grid makes implementing an immutable architecture easy as an integrated appliance or reference design for an all-in-one solution. With cyber-attacks increasing it delivers comprehensive data management across workloads to protect your data through 5 security layers. Commvault offers a hybrid of controls that work together to harden data against ransomware, cyber threats, and bad actors. 

What is an Immutable Architecture and how do organization benefit?   

Immutability is defined as the ability of any data to be maintained in a non-fungible state for a specific duration of time. Data immutability can be attained via various methods working in conjunction with each other.  An immutable architecture is a model in which no updates, security patches, or configuration changes happen “in-place” on production systems.  If any change is needed, a new version of the architecture is built and deployed into production.  

Organizations need an immutable architecture to ensure their data is safe and secure and more importantly, ready whenever they need to restore it. Immutability is a proven technique used to reduce cyber-attacks on backup data and ensure that backup copies aren’t changed in any way. 

Commvault Grid for Greater Immutability  

Commvault Grid makes it easier to implement an immutable architecture as an integrated appliance or reference design for an all-in-one solution. It delivers comprehensive data management for all workloads from a single, extensible platform. Commvault employs a multi-layered approach to protect against various threat vectors and ensure data is safe. Commvault’s immutable architecture consists of 5 layers which are:   

  • Storage I/O Controls   
  • Zero Trust AAA Controls   
  • Infrastructure Hardening   
  • Zero trust isolation and air gap  
  • Data Validation  

Commvault Grid leverages the entire Commvault software portfolio providing access to all the features, functions, and industry-leading integrations with applications, databases, public cloud environments, hypervisors, operating systems, containers and NextGen workloads. Wherever your data resides, you have the ability to view it, use it, and confidently protect it. Commvault Grid accelerates hybrid cloud adoption with an integrated solution built on a deeply layered system of controls that work together to harden data against ransomware, cyber threats, and bad actors.   

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Beispiele für versteckte und schwankende Kosten bei der Cloud-Datensicherung

Ausgangsgebühren

The majority of cloud providers will allow their users to place data into the cloud without any fees. However, this does not apply when their data is retrieved from the cloud. Cloud providers typically charge what’s known as egress fees any time data is retrieved.

If your enterprise is constantly pulling its data out of the cloud—such as migrating or recovering data— you can see how the fees can add up quickly and lead to inflated costs that are nearly impossible to predict. Egress fees are considered a hidden fee since they fluctuate based on usage and are tied to a common action (data retrieval).

Lizenzen

There may be a variety of licenses that are required, each with their own fee. These can snowball when cloud backup vendors require licenses for each of the data sources you back up or multiple licenses per user—something you may not realize until the bill comes.

Snapshots und Speicherkosten

It is common for enterprises to create long-term storage for their production data if they need to recover it after an attack—such as ransomware. This could involve creating massive amounts of snapshots for each account in high-tier storage. Furthermore, each time a block or file is changed, a new snapshot is automatically created. These snapshots are replicated across accounts, effectively doubling backup storage costs that continue to pile up over time. Costs are further compounded when considering industry retention requirements that go beyond 35 days.

Adding to all the complexity is the fact that it’s difficult to gauge just how many of the backup snapshots in your AWS accounts are even needed. Sure, your bill can display how much you are spending in a particular region, but it doesn’t show the level of granularity regarding the age of the snapshots or assets they are associated with.

Achieve Predictable Costs and Lower TCO with the Industry’s Leading Cloud-Native Backup Solution

You can avoid excessive cloud spending and gain control over backup costs by choosing a cloud backup solution with a simple, straightforward pricing model that clearly spells out the ongoing charges.

Built natively in AWS, Clumio’s backup solution offers the scalability, performance, data protection, and faster access to innovation made possible by the cloud while avoiding the hidden costs, complexity, and limited flexibility of snapshot-based backup solutions.

Vereinfachte Preisgestaltung

Clumio’s Pay-As-You-Go consumption model with rollover credits provides enterprises with a simplified and clear backup-as-a-service solution that ensures cost predictability while lowering TCO:

  • Transparency – No hidden costs, no license fees, and no egress charges—plus full visibility into data consumption.
  • No Friction – Choose from on-demand or commitment contracts with no setup required.
  • 100% SaaS – No complex cloud infrastructure or software to install or manage.
  • Ein integriertes Tool zur Kostenanalyse, das Einblicke liefert, mit denen sich unnötige Cloud-Ausgaben reduzieren lassen

Geringere Ausgaben für Speicherlösungen

Anstatt Amazon EBS-Snapshots aufzubewahren, senkt Clumio die Kosten noch weiter, indem die Daten in einem komprimierten, deduplizierten Format in Amazon S3 gespeichert werden, wodurch die Kosten für die langfristige Aufbewahrung von EBS-Daten effektiv gesenkt werden. So können Unternehmen Compliance-Anforderungen erfüllen und Aufbewahrungsstrategien entwickeln, die sich an geschäftlichen und regulatorischen Vorgaben orientieren und nicht an den Kosten.

Erste Schritte mit Clumio

Clumio bietet mehr als nur Kosteneinsparungen. In weniger als 15 Minuten kann Ihr Unternehmen:

  • Sichern Sie Ihre AWS-Daten unternehmensweit im Handumdrehen mit Clumio
  • Schützen Sie Ihre Daten vor Ransomware-Angriffen und anderen böswilligen Bedrohungen durch Air-Gapped-Speicher mit Clumio
  • Erfüllen Sie mit Clumio vielfältige und komplexe Datenschutzanforderungen mithilfe globaler Richtlinien
  • Senken Sie die RTO (Recovery Time Objective) und gewährleisten Sie mit Clumio die Geschäftskontinuität im Falle eines Ausfalls

Experience firsthand why Clumio is the industry’s leading innovator for AWS cloud backup. Start your free trial, all without any pre-planning or the need to install new infrastructure or software.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Elf Mal.

Das„Gartner® Magic Quadrant™ für Backup- und Recovery-Softwarelösungen für Unternehmen 2022“ marks the 11th consecutive time that Commvault has been positioned by Gartner as a “Leader” in this dynamic backup and recovery market.

Wir sind unglaublich stolz auf diese Leistung. Warum auch nicht? Wir sind schon länger in diesem Quadranten vertreten, als manche unserer Mitbewerber überhaupt schon im Geschäft sind.

As an innovation-driven company, we have always prided ourselves on building elegant solutions to your hard problems, which let’s face it, have only gotten harder over the last few years.

Living between legacy and hybrid cloud applications and systems, today’s CIOs and IT professionals grapple with more applications and workloads than ever. All while bolstering their security posture to protect their data from ransomware and advance transformational business projects with the resources they have at hand.

Now is not the time to take chances on unproven technologies in today’s increasingly uncertain macroenvironment. It is the time to invest for the future, so you and your organization come out stronger on the other side.

I’ve had a lot of these conversations with customers lately, many of whom are weighing these concerns with the need for a trusted, intelligent, and reliable cloud data management vendor. One that not only provides proven technology, but the flexibility and scalability needed to continue to evolve to meet tomorrow’s needs. And one with the demonstrated its ability to execute on a vision over and over.

In its latest report, Gartner highlighted a few of Commvault’s strengths in this area:

Zunächst bieten wir umfassende Unterstützung für Workloads vor Ort und in der Cloud. So können Sie neue Funktionen für Backup and Recovery für Ihr Unternehmen hinzufügen, unabhängig davon, welche Anwendungen Ihre geschäftskritischen Daten erstellen und nutzen. Und Sie können Ihre Daten über eine zentrale Oberfläche verwalten.

Next, based on your unique business needs, you may want to leverage backup software, an appliance, or software as a service. Commvault enables you to choose any or all these approaches – to balance your capital and operating expenses based on your business needs, staffing concerns, or even in response to supply chain delays.

Schließlich erstrecken sich unsere Lösungen und unser umfangreiches Partner-Ökosystem über mehrere Regionen und erweitern so die Reichweite und die Möglichkeiten globaler Unternehmen. Wir schützen Ihre Daten, wo immer sie sich befinden oder sein müssen.

Vielen Dank, Gartner, für die gründliche Analyse und die Veröffentlichung Ihrer Ergebnisse. Und vor allem vielen Dank an alle unsere Kunden und Partner weltweit, die Commvault weiterhin den Schutz und die Verwaltung ihrer kritischen Daten entrusten. Diese Auszeichnung verdanken wir Ihnen.

Download a copy of the 2022 Gartner® Magic Quadrant™ for Enterprise Backup and Recovery Solutions

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements