Skip to content

Here at Commvault, our values – we connect, we inspire, we care, and we deliver – are foundational to everything we do and why it matters.

Diese Woche haben wir unser vierteljährliches internes Global Town Hall Meeting abgehalten und unsere FY25 Q3 CEO Living Our Values Awards verliehen. Mit diesem Auszeichnungsprogramm werden unsere Vaulters weltweit für ihre unglaubliche Arbeit im vergangenen Quartal und dafür, dass sie unsere Werte jeden Tag leben, gewürdigt und gefeiert.

I’m so proud to announce our FY25 Q3 CEO Living Our Values Award winners and our employee-nominated Vaulters’ Choice Award winner below:

Gewinner der CEO-Auszeichnung

Nithya Suresh

Nithya Suresh

Michael Lawson

Michael Lawson

Dominique Leblond

Dominique Leblond

Social-Media-Team
Jason Meserve

Jason Meserve

Riya Borkotoky

Riya Borkotoky

Vaulter’s Choice Award Winner

Joseph Nazaro

Joseph Nazaro

Diese Vaulter geben ein inspirierendes Beispiel dafür, was es wirklich bedeutet, ein Teil von Commvault zu sein.

Um mehr darüber zu erfahren, wie es ist, bei Commvault zu arbeiten, besuchen Sie unsereKarriereseite.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Das Gesetz über die digitale Betriebsresilienz (DORA) trat am 17. Januar in Kraft und enthält umfassende Leitlinien sowie einen detaillierten Rechtsrahmen dafür, wie alle in der Europäischen Union tätigen Finanzdienstleister die Datenresilienz gegenüber unvorhergesehenen Störungen gewährleisten müssen.

DORA trägt zudem einer von Cybersicherheitsexperten weithin anerkannten Tatsache Rechnung, nämlich dass es nicht mehr darum geht, ob es zu einem Cyberangriff kommt, sondern wann. Diese entscheidende Rechtsvorschrift sorgt für ein neues Maß an Strenge und Rechenschaftspflicht in der Finanzdienstleistungsbranche, das sich zum Schutz der Stabilität des Finanzökosystems in der EU und weltweit weiterentwickeln wird.

Viele Bereiche der Finanzdienstleistungsbranche, die über traditionelle Banken und Kreditinstitute hinausgehen, fallen nun unter die DORA, darunter Zahlungsdienstleister, Wertpapierfirmen, Handelsplätze, Versicherungsanbieter sowie externe Anbieter von Informations- und Kommunikationstechnologie (IKT).

Those that are new to this level of regulation may struggle to comply, as indicated by European financial regulators’ DORA “Dry Run Exercise.”1 They also likely will face additional scrutiny by interconnected customers, partners and other stakeholders as a new operational risk. Non-compliance no longer means just the potential for a very large fine but also reputational damage and liability for a company, its directors, and its partners.


While it remains to be seen how quickly financial regulators act, DORA represents a shift from guidelines for data readiness and cyber resilience to enforcement of it. Given the expansive nature of DORA, which significantly broadens the EU’s financial regulation of IT, regulators, lacking unlimited expertise and resources, may face challenges enforcing all aspects of DORA immediately. As a result, regulators are likely to adopt a targeted approach, focusing on the most critical and visible areas of noncompliance. 

Was Finanzinstitute als Priorität betrachten

A top priority for DORA compliance is the submission of accurate and technically compliant registers of information. Financial regulators have emphasized that registers will be a primary focus of enforcement, and they expect organizations to submit them early in 2025. Submitting an accurate register that details the organization’s most significant IT providers may be more beneficial than submitting incomplete information about all of its IT providers.2

For data protection leaders and CIOs, DORA is a call to action to examine legacy systems and consider whether they are capable of withstanding today’s cyberthreats and can deliver the performance required for efficient, rapid service recovery. 

Über die Identifizierung und Erfassung der wichtigsten Systeme, Anwendungen und Workloads bei den jeweiligen IKT-Anbietern hinaus sollten Unternehmen sorgfältig die Kernkompetenzen prüfen, die diese Systeme schützen, verteidigen und wiederherstellen. Zu den entscheidenden Kompetenzen gehören:

  • Data protection and cyber recovery
    Im Rahmen von DORA sind schnelle Recovery-Möglichkeiten unerlässlich, um die betrieblichen Auswirkungen eines Angriffs zu minimieren. Die einzige Möglichkeit, die für kritische Systeme erforderlichen strengsten, extrem kurzen RTO-Werte zu erreichen, besteht in der Recovery mithilfe von unveränderlichen, speicherbasierten Snapshots. Diese Snapshots sollten sicher in einem isolierten (oder virtuell luftisolierten) Repository gespeichert werden.
  • Early-warning threat detection
    Identifying and remediating potential cyberthreats earlier is an important aspect of data protection and readiness. The capability to continuously scan data to detect anomalies and identify threats like ransomware and malware in real time and automate remediation is essential for faster containment of an attack. 
  • Isolated recovery environments (IRE) or cleanrooms for resilience testing
    Establishing a completely self-contained IRE, where data can be restored for forensic and application analysis and validated as clean before returning to production, speeds recovery. IREs also allow organizations to continuously test and improve cyber recovery practices for organizational readiness.
  • Scalability and performance

Businesses will continue to evolve their services, face new regulatory requirements, and deal with emerging cyberthreats. It’s important to consider a solution’s ability to scale as data requirements change across distributed, hybrid environments while maintaining high-performance speeds for data protection and recovery.

Compliance mit Vertrauen

Organizations that delay establishing robust capabilities to meet DORA and other evolving resilience regulations – such as PSD2, NIS2, APRA CPS 230, and the European Cyber Resilience Act coming into effect in 2026 – may find themselves with mounting challenges to overcome. They also may find themselves at competitive disadvantage to firms that can demonstrate their ability to remain resilient in the face of disruptions in the global financial ecosystem.

Working with partners that understand the regulation’s resilience requirements and deploying robust solutions can help enable organizations to be compliant and better prepared to meet new regulatory challenges and defend their data environment against emerging threats.

Pure Storage and Commvault have come together to build a joint solution, modular in design, that helps financial institutions enhance their cyber resilience practices and address key pillars of DORA for incident response and resilience testing. The solution is built by integrating the leading cyber resilience capabilities of Commvault® Cloud with the highly secure, high-performance Pure Storage platform.  Learn more about the solution and our commitment to cyber resilience hier.

Sind Sie Cyber-ready?

Readiness reflects mature cyber resilience, where technology, people, and processes work seamlessly to enable continuous business in the face of any cyber challenge. Evaluate your organization’s cyber resilience with Commvault’s dem „Cyber Maturity Assessment“.  


1 Wichtigste Ergebnisse der ESAs-Testübung 2024, Europäische Bankenaufsichtsbehörde, 17. Dezember 2024.

2 Countdown to DORA – Four Takeaway Points from Regulators’ December Statements, Skadden, Arps, Slate, Meagher & Flom, LLP, Jan. 3, 2025

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Welcome to the final installment of our three-part series on Active Directory. In ourprevious blog post, we explored small-scale disruptions that could impact AD, such as the accidental deletion of an object, and why fast, granular recovery is so critical.

Was passiert jedoch, wenn eine Katastrophe größeren Ausmaßes eintritt? Wie sieht es mit groß angelegten AD-Katastrophen wie Ransomware-Angriffen oder Schemabeschädigungen aus? In solchen Szenarien kann der Recovery-Prozess eine vollständige Wiederherstellung der AD-Gesamtstruktur erfordern. Dies beinhaltet die Wiederherstellung des Verzeichnisdienstes, einschließlich aller Domänen, Domänencontroller und zugehöriger Daten, in den Zustand vor dem Angriff.

Die drohende Gefahr durch Ransomware

Imagine this scenario: A ransomware attack strikes your organization, locking down the server that hosts AD. Suddenly, all the files on the server are encrypted, and AD goes offline. Now, all the business-critical applications that depend on AD for user authentication are inaccessible. Employees can’t log in, critical services come to a halt, and business is at a standstill.

Die Auswirkungen eines AD-Angriffs, der Domänencontroller lahmlegt, sind real und können verheerend sein. Im Jahr 2017 fiel der globale Schifffahrtsriese Maersk dem Cyberangriff „NotPetya“ zum Opfer, bei dem die Dateisysteme von 45.000 PCs, 4.000 Servern und allen bis auf einen der 150 AD-Domänencontroller verschlüsselt wurden. Da das AD vollständig offline war, kam der Betrieb sofort zum Erliegen, wodurch 17 Häfen weltweit geschlossen wurden und Hunderte von Containerschiffen zehn Tage lang festsaßen. Insgesamtkostete der Angriff das Unternehmen mindestens 300 Millionen US-Dollar.

Gartner berichtet, dass bis zum laufenden Jahr 75 % aller Unternehmen mindestens einen Cybervorfall wie beispielsweise einen Ransomware-Angriff erlebt haben werden. With such threats looming, having a well-documented and frequently tested recovery plan to restore and rebuild your entire AD environment to a pre-attack state is not just a good idea – it’s critical and the key to getting your business back fast.

Die Wiederherstellung von AD erfordert einen konkreten Plan und einen festgelegten Ablauf

Wenn eine Katastrophe eintritt, ist die Wiederherstellung des Active Directory von entscheidender Bedeutung, doch bisher war dies sehr schwierig und erforderte komplizierte, zeitaufwändige manuelle Prozesse.

Da es sich bei AD um ein Multi-Master-System mit geografisch verteilten Komponenten handelt, erfordert dessen Recovery eine sorgfältige Koordination während des Recovery-Prozesses. Jeder Domänencontroller muss synchronisiert und in abgestimmter Weise wiederhergestellt werden, um Dateninkonsistenzen und mögliche Beschädigungen im wiederhergestellten Verzeichnis zu vermeiden.

Microsoft’s Active Directory Forest Recovery Guide provides a detailed, step-by-step method for this, which can involve anywhere from 50 to 100, or even more, individual steps, depending on the size of your organization. This complexity can significantly prolong the process if done manually, often taking days to weeks to complete. All the while, business operations cease to function, and users cannot access important applications.

Die Herausforderung geht über die reine Recovery-Prozedur für das Active Directory hinaus. Bei einem Cyberangriff ist die Recovery-Prozedur für das Active Directory nur ein Teil des Ganzen. Ihr Team muss außerdem Daten, Anwendungen, Benutzerendgeräte, virtuelle Maschinen und vieles mehr wiederherstellen. Ohne einen ganzheitlichen Ansatz können diese komplexen Zusammenhänge Ausfälle und Betriebsunterbrechungen weiter verlängern.

Wir stellen vor: Commvault® Cloud Backup & Recovery for Active Directory Enterprise Edition

Last week, we announced how we are solving the challenges associated with recovering and rebuilding AD with Backup & Recovery for Active Directory Enterprise Edition. It brings a new level of resilience to AD by enabling automated, rapid recovery of the AD forest. This new offering eliminates slow and error-prone manual processes often associated with AD forest recoveries. With Backup & Recovery for AD Enterprise Edition, you will be able to:

  • Make AD recovery a snap via automated runbooks: Automated forest recovery runbooks streamline the multi-step process required for AD forest recovery, including the complex hygiene tasks essential for a clean recovery. These runbooks also can be used for regular testing in non-production environments to enhance cyber readiness.
  • Enable fast recovery of the most important AD infrastructure: Visual topology views of your AD environment enable simple and rapid identification of which domain controllers to restore first and how they should be recovered to accelerate the availability of AD services.
  • Accelerate recovery times and advance resilience: Manually recovering an AD forest can take days or even weeks to complete, but with Commvault, you can recover it in a fraction of the time. The Commvault Cloud platform integrates AD forest recovery with granular recovery of both AD and Entra ID, providing comprehensive protection. 

Um mehr zu erfahren und die Lösung in einer Demo kennenzulernen, besuchen Sie dieActive Directory solution page.

Falls Sie es verpasst haben, lesen Sieheredie vollständige Pressemitteilung, um weitere Einzelheiten zu erfahren.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

We’re thrilled to announce that Commvault COE has earned the Great Place to Work® certification for the eighth year in a row. This recognition reflects our enduring commitment to creating a workplace where employees feel valued, connected, and motivated to grow.

At Commvault, our three core principles – We Care, We Inspire, and We Deliver – shape our culture and define our success. We prioritize holistic wellbeing, diversity, equity, and inclusion, creating an environment where every individual feels supported and empowered.

We also believe that to deliver for our customers and partners, we must first deliver for ourselves – by caring for ourselves. From flexible work arrangements to programs that support mental and physical health, we aim to ensure that every Vaulter can achieve their full potential.

Unsere Unternehmenskultur basiert auf offener Kommunikation, aufrichtiger Fürsorge und regelmäßigen Feedbackkanälen wie „Vaulter Voices“, über die Mitarbeiter ihre Gedanken und Ideen einbringen können. Außerdem legen wir großen Wert auf die berufliche Weiterentwicklung durch umfassende Schulungs- und Entwicklungsprogramme, Mentoring-Möglichkeiten und Workshops zur Kompetenzsteigerung, wobei wir sicherstellen, dass die Vereinbarkeit von Beruf und Privatleben sowie das persönliche Wohlbefinden wesentliche Bestandteile des Erfolgs sind.

Being recognized as a Great Place to Work fills us with immense pride and motivates us to create a lasting impact together – not just for the organization but for each other. Looking ahead, we are committed to investing in our people through advanced collaboration tools, wellness programs, and initiatives that strengthen community engagement.

Während wir uns in einer sich wandelnden Arbeitswelt zurechtfinden, werden wir uns weiterhin darauf konzentrieren, den Menschen in den Mittelpunkt zu stellen, Innovationen voranzutreiben und unseren Kunden und Partnern stets einen außergewöhnlichen Mehrwert zu bieten. Herzlichen Glückwunsch, Team Indien!

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Imagine conducting a full-scale disaster recovery test while sipping on your latté during a coffee break. Sounds too good to be true, doesn’t it? But with Commvault Cloud Rewind’s specialized cloud resilience platform, this scenario becomes your reality. In a digital age where high-availability cloud services are non-negotiable, robust recovery strategies for cloud infrastructure are more critical than ever.

Die Notwendigkeit von Cloud-Ausfallsicherheit und Cloud-Recovery

Cloud-Dienste sind für moderne Unternehmen unverzichtbar geworden. Daher kann jede Störung dieser Dienste nicht nur zu erheblichen finanziellen Einbußen und Reputationsverlusten führen, sondern auch zu einer erheblichen Verschwendung wertvoller Entwicklungszeit und Ressourcen.

This is why cloud resilience is not just a buzzword but an essential component of any modern cloud operations strategy. Without reliable cloud-based DR systems, you’re exposing your organization to considerable risks.

Die Herausforderungen der herkömmlichen Datenwiederherstellung (DR) im Cloud-Computing

Die Durchführung eines umfassenden DR-Tests ist oft zeitaufwendig und komplex und erfordert eine sorgfältige Planung und Koordination. Diese Komplexität und der Zeitaufwand können Unternehmen davon abhalten, regelmäßige Tests durchzuführen, wodurch sie anfällig für Systemausfälle und Datenverluste bleiben.

Revolutionieren Sie Ihre Cloud-DR-Tests

Cloud Rewind offers a game-changing approach that makes this critical function not only effective but also incredibly efficient and very cost-effective. Imagine being able to run a full DR test over a coffee break. Yes, it’s that fast and simple.

One of our recent users from a multibillion organization in the insurance industry shared his experience: “I am very impressed with how simple the interface is to navigate and perform various tasks,” he said. “I ran a few recoveries earlier today, and it worked 100%.”

Warum das „Cloud Rewind Rebuild“-Modell die richtige Wahl für Cloud-DR-Tests ist

What makes Cloud Rewind unique is its laser focus on hyperscale cloud environments and our platform’s ability to rebuild isolated on-demand environments quickly. Unlike other platforms that spread their capabilities thin by trying to cover on-premises or hybrid cloud setups, Cloud Rewind is exclusively focused on cloud-based applications. This expertise results in a product that is not just effective but also highly specialized for cloud-based DR.

Die wichtigsten Vorteile von Cloud Rewind

Speed: Execute a full-scale DR test in minutes. No more prolonged downtime or exhaustive preparations or 10-member teams over a weekend.

User-friendliness: Designed with ease of use in mind, Cloud Rewind doesn’t require you to be an expert in DR in cloud computing. Navigate its simple interface and perform various tasks effortlessly.

Cost-effectiveness: The speed and efficiency of Cloud Rewind reduces the costs related to downtime and lost data, offering a highly cost-effective solution for cloud resilience.

Da sich Cloud Rewind ausschließlich auf cloudbasierte Anwendungsumgebungen konzentriert, bietet es beispiellose Fachkompetenz und Funktionalität in den Bereichen Cloud-Ausfallsicherheit und -Recovery. Erfahren Sie mehr überCloud Rewindund darüber, wie Sie damit Disaster-Recovery-Tests in wenigen Minuten durchführen können.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Ich finde es passend, dass wir kurz nach den Feierlichkeiten zum Beginn eines neuen Jahres einen Tag dem Gedenken an das Vermächtnis von Dr. Martin Luther King Jr. und der Reflexion darüber widmen.

Today, Commvault’s U.S. offices are closed to observe Martin Luther King Jr. Day. However, as a global Vaulter community, it’s a time for us to pause and reflect on the profound impact Dr. King had not just in the U.S., but around the world.

Dr. King’s unwavering commitment to equality, justice, and community has inspired generations, and his famous “I Have a Dream” speech continues to resonate today. And while we have made significant progress in the years since his famous speech, there is always more work to be done to create a just and equitable world.

As we have just wrapped up our Commvault Cares Quarter of Caring, Dr. King’s commitment to service is top of mind for me. Our Quarter of Caring is an annual initiative here at Commvault dedicated to giving back to our communities and raising awareness of causes close to our hearts. And while many see MLK Day as a day off of work or school, I see it as a day “on” for our global communities! So today, I encourage you to get involved – whether that be by volunteering, donating, or supporting a local nonprofit.

Let’s all honor Dr. King’s legacy with simple acts of kindness, understanding, and service. Together, we can build a brighter future for all.

Learn more about Commvault’s culture of caring hier.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The partnership between Commvault and HPE is redefining the world of data protection and management. HPE’s high-performance infrastructure powers an entire ecosystem of scalable, sustainable solutions, while Commvault orchestrates and protects data across that ecosystem. Together, we are empowering data-driven enterprises to securely manage, protect, and recover their data across today’s complex hybrid cloud environments.

HPE’s infrastructure solutions are purpose-built to support the most demanding workloads, delivering unmatched performance and scalability across hybrid, multi-cloud, and on-premises environments. At HPE Discover Las Vegas 2024, the company reaffirmed its commitment to leading the enterprise adoption of AI, further positioning HPE as a cornerstone for modern IT. Partnering with HPE allows Commvault to harness this infrastructure, providing our customers with cyber-resilient solutions that enhance the reliability and efficiency of data protection.

Verbesserte Ausfallsicherheit durch die Integration aktiver Peer-Persistenz

Commvault’s deep integration with HPE storage platforms includes advanced snapshot management capabilities that streamline the protection of large databases, medical imagery, and other data-intensive workloads. Building on this, our recent milestone is Commvault’s new integration with HPE’s Active Peer Persistence technology.

Currently available in HPE Alletra 9000 and HPE Alletra Storage MP B10000, HPE’s Active Peer Persistence enables synchronous replication across two geographically separated storage arrays, automatically failing over from one site to another during an outage without any disruption. This continuous availability is crucial for mission-critical applications that require minimal downtime.

With our new integration, Commvault detects when two HPE storage arrays are in an Active Peer Persistence configuration and snaps both arrays simultaneously, backing up each locally. Commvault’s robust data management tools then allow businesses to send extra copies of data to tape (HPE StoreEver), cloud, or other storage options, supporting compliance and adding another layer of data security.

Vorteile der Integration für datengesteuerte Unternehmen

Diese Integration bietet Kunden, die ihre Ausfallsicherheit maximieren, Ausfallzeiten reduzieren und Backup- sowie Recovery-Prozesse in verteilten Umgebungen optimieren möchten, erhebliche Vorteile.

  • Continuous availability: Mission-critical applications benefit from uninterrupted access to data, even in the event of planned or unplanned outages.
  • Network efficiency: By allowing data recovery directly from either primary or secondary arrays, the integration reduces the requirement for additional copies, reducing the overall load on network resources.
  • Enhanced compliance: Commvault’s flexible data management enables additional copies of data to meet various regulatory and compliance needs.

Die Partnerschaft zwischen Commvault und HPE verdeutlicht unser gemeinsames Engagement für die Bereitstellung moderner, skalierbarer und nachhaltiger Datensicherungslösungen.

“Partnering with HPE to support Active Peer Persistence underscores our dedication to delivering solutions that drive business continuity and operational efficiency,” said Jeff Carlat, Director – WW Alliances at Commvault. “Together, we are equipping our customers with the tools they need to navigate complex data environments with confidence.”

Learn more at hpe.com/storage.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Das Readiverse ist eine umfassende Informationsquelle, die Einzelpersonen und Organisationen dabei unterstützen soll, im sich ständig weiterentwickelnden Bereich der Cyber-Resilienz stets auf dem neuesten Stand zu bleiben. Es ist die erste Anlaufstelle für bewährte Verfahren und praxisorientiertes Wissen zum Thema Cyber-Resilienz.

Im Readiverse können Sie aus einer Vielzahl von Lernformaten wählen, die unterschiedlichen Bedürfnissen und Zeitplänen gerecht werden. Ganz gleich, ob Sie die Herausforderung von Tabletop-Übungen wie „Minutes to Meltdown“, die Tiefe von Zertifizierungen und Workshops, die Bequemlichkeit von Anleitungsvideos oder den Gemeinschaftsgeist des gemeinschaftlichen Lernens bevorzugen – das Readiverse bietet all das.

Unsere Plattform geht über herkömmliche Lernmethoden hinaus und bietet interaktive und dynamische Inhalte, damit Sie bestens gerüstet sind, um den neuesten Cyberbedrohungen zu begegnen.

Werden Sie noch heute Teil vonReadiverseum Ihre Cyberabwehr zu stärken und Teil einer proaktiven Community zu werden, die sich der Exzellenz im Bereich Cybersicherheit verschrieben hat.

What’s new in the Readiverse?

Das Readiverse bietet nun eine kostenlose Online-Zertifizierung zum Thema Cyber-Resilienz an, die im Selbststudium absolviert werden kann.

Diese neue Zertifizierung vermittelt IT- und Sicherheitsexperten in nur vier Stunden das Wissen und die Fähigkeiten, die sie benötigen, um einen robusten Schutz vor Cyberbedrohungen aufzubauen.

This course focuses on the fundamental principles of cyber resilience, covering topics such as early warning systems, threat detection, and advanced recovery techniques.  

Die Teilnehmer sammeln praktische Erfahrungen bei der Konfiguration und Integration von Commvault-Lösungen, einschließlich der Beherrschung derCleanroom Recovery to minimize downtime and data loss. 

Through a blend of self-paced e-learning modules and hands-on lab sessions, participants gain the practical skills and knowledge to protect their organizations’ assets. And with a certification in hand, they’ll have the confidence and peace of mind that they have the latest skills and knowledge in cyber resilience.

Kunden könnenhiermit ihren Commvault-Zugangsdaten auf die Readiverse-Kurse zugreifen, während Partner über dasCommvault-Partnerportal.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Da Unternehmen für geschäftskritische Abläufe zunehmend auf Software-as-a-Service-Plattformen (SaaS) wie Microsoft 365 und Salesforce setzen, ist ein umfassender Schutz dieser Umgebungen unverzichtbar geworden.

While many organizations assume that SaaS providers offer complete data protection, most operate under a shared responsibility model where customers remain responsible for data backup, recovery, and security. Commvault’s SaaS protection capabilities deliver comprehensive security for these critical environments.

Die Notwendigkeit des SaaS-Schutzes

Die zunehmende Verbreitung von SaaS-Plattformen hat zu erheblichen Herausforderungen im Bereich der Datensicherheit geführt:

  • Die meisten SaaS-Anbieter arbeiten nach einem Modell der geteilten Verantwortung.
  • Unternehmen sind dafür verantwortlich, ihre SaaS-Daten vor Verlust, Beschädigung und unbefugtem Zugriff zu schützen.
  • Native SaaS-Schutztools weisen häufig erhebliche Einschränkungen hinsichtlich Aufbewahrungsdauer, Granularität und Sicherheit auf.
  • SaaS environments increasingly contain an organization’s most sensitive operational data.

Diese Faktoren machen den Schutz von SaaS-Lösungen von Drittanbietern für umfassende Sicherheit und Compliance unverzichtbar.

Sicherheitsfunktionen von Microsoft 365

Commvault® Cloud Backup & Recovery for Microsoft 365 delivers SaaS resilience and recovery capabilities specifically designed to provide protection from deletion, corruption, and attack. This includes:

Exchange Online Protection:
  • Schutz für Microsoft 365-Anwendungen.
  • Bietet detaillierte Recovery-Optionen für Postfächer, E-Mails, Anhänge und andere Exchange Online-Komponenten.
Schutz für SharePoint Online und OneDrive:
  • Behält Dokumentberechtigungen, Versionshistorie und Metadaten bei.
  • Ermöglicht die detaillierte Recovery einzelner Dokumente, Bibliotheken oder ganzer Websites.
Schutz der Teams:
  • Speichert Team-Unterhaltungen, Dateien, Kanäle und Einstellungen.
  • Ermöglicht sowohl eine selektive als auch eine vollständige Recovery-Prozedur für Teams.

Sicherheitsfunktionen von Salesforce

Commvault erweitert seinen SaaS-Schutz auf Salesforce-Umgebungen, darunter:

  • Umfasst sowohl Standard- als auch benutzerdefinierte Objekte in Salesforce.
  • Beibehaltung der Beziehungen zwischen Objekten für eine vollständige Recovery.
  • Setzen, maskieren und rehydrieren Sie Sandbox-Umgebungen für beschleunigte Tests.
  • Unbegrenzter Speicherplatz, unbegrenzte Aufbewahrungsdauer und integrierte fortschrittliche Protokolle (wie FedRAMP High).

Dank dieses umfassenden Salesforce-Schutzes bleiben wichtige Kunden- und Vertriebsdaten sicher und können wiederhergestellt werden.

Erweiterte SaaS-SicherheitsFeatures

Über die grundlegenden Funktionen für Backup and Recovery hinaus bietet Commvault Sicherheitsfunktionen auf Unternehmensniveau für SaaS-Umgebungen.

Verbesserte Datensicherheit

Commvault sorgt für umfassende Sicherheit bei SaaS-Daten:

  • Die Plattform bietet von Grund auf sichere Funktionen, bei denen Unveränderlichkeit, Air-Gapping und Zero-Trust-Zugriff fest integriert sind.
  • Die Lösung bietet „Commvault AirGap“ als integriertes Cloud-Speicherziel, das es IT-Abteilungen erleichtert, Cloud-Air-Gap-Speicher einzuführen, um Risiken zu minimieren.
  • Diese Sicherheitsfeatures schützen SaaS-Daten sowohl vor externen Bedrohungen als auch vor Risiken durch Insider.

Compliance und Governance

Commvault bietet Compliance-Funktionen für SaaS-Daten:

  • Die Plattform unterstützt standardisierte Aufbewahrungsfristen, Richtlinien und Wiederherstellbarkeit für unterschiedliche hybride Workloads, einschließlich SaaS-Anwendungen.
  • Die Lösung unterstützt Unternehmen dabei, eine einheitliche Governance in SaaS-Umgebungen umzusetzen.
  • Diese Funktionen tragen dazu bei, die gesetzlichen Anforderungen an den Datenschutz und die Aufbewahrung von Daten zu erfüllen.

Zentralisiertes SaaS-Sicherheitsmanagement

Commvault bietet ein einheitliches Management für die gesamte SaaS-Sicherung:

  • Die Plattform beseitigt die Komplexität beim Einsatz mehrerer Konsolen durch eine einheitliche Verwaltung.
  • Die Lösung unterstützt standardisierte Aufbewahrungsfristen, Richtlinien und Wiederherstellbarkeit für unterschiedliche hybride Workloads, darunter SaaS-Anwendungen wie M365, Dynamics 365, Salesforce und Google Workspace.
  • Dieser einheitliche Ansatz vereinfacht die Verwaltung der Sicherheitsmaßnahmen über mehrere SaaS-Plattformen hinweg.

Die geschäftlichen Auswirkungen eines umfassenden SaaS-Schutzes

For organizations, Commvault’s SaaS protection capabilities deliver several significant business advantages:

Verbesserte Geschäftskontinuität

Umfassender SaaS-Schutz gewährleistet die Kontinuität kritischer Betriebsabläufe:

  • The solution provides fast and automated backup, flexible and granular restore, and   scalable and unlimited storage.
  • Die Plattform bietet Schutz vor Löschung, Datenbeschädigung und Angriffen und verfügt über Backup and Recovery-Funktionen für Microsoft 365- und Salesforce-Umgebungen.
  • Diese Funktionen tragen dazu bei, Störungen durch Datenverlust oder -beschädigung in SaaS-Umgebungen auf ein Minimum zu reduzieren.

Vereinfachte Bereitschaft zur Einhaltung von Vorschriften

Commvault’s SaaS protection helps streamline efforts to comply with various industry regulations:

  • Die Plattform unterstützt standardisierte Aufbewahrungsfristen, Richtlinien und Wiederherstellbarkeit, um die Einhaltung von Compliance-Anforderungen zu gewährleisten.
  • Funktionen zur Datensicherung, zum Backup und zur Wiederherstellung ermöglichen die Aufbewahrung von Daten zur Einhaltung gesetzlicher Vorschriften.
  • Diese Features vereinfachen die Prüfung und Berichterstattung im Hinblick auf regulatorische Anforderungen.

Geringeres Sicherheitsrisiko

Fortschrittliche Sicherheitsfeatures minimieren das Risiko für SaaS-Daten, da die Lösung von Haus aus Unveränderlichkeit, Air-Gapping und Zero-Trust-Zugriff umfasst.

SaaS-Schutz für kritische Umgebungen

As organizations increasingly depend on SaaS platforms for mission-critical operations, comprehensive protection has become essential for business continuity, security, and compliance. Commvault’s superior capabilities for Microsoft 365 and Salesforce protection deliver significant advantages:

  • Comprehensive coverage: Protection for all aspects of SaaS environments, not just the most common elements.
  • Granular recovery: Precise restoration options that minimize disruption and data loss.
  • Enhanced security: Integrated protection against modern threats targeting SaaS data.
  • Simplified compliance readiness: Comprehensive capabilities for helping organizations meet regulatory requirements.

Für Unternehmen, die den Schutz ihrer geschäftskritischen SaaS-Umgebungen ernst nehmen, bietet Commvault eine umfassende Lösung zum Schutz von Unternehmen, die Sicherheitslücken schließt und bei Bedarf eine vollständige Recovery ermöglicht.


Literaturverzeichnis und Anmerkungen zur Validierung

Wichtigste Quellen:
1. Commvault-Dokumentation zur SaaS-Sicherung für Microsoft 365 (Dokument 3)
2. Commvault-Features zur Salesforce-Sicherung (Dokument 3)
3. Sicherheitsfeatures für die SaaS-Sicherung (Dokumente 3, 21)

 

Validierungsanforderungen:
1. Überprüfung spezifischer Schutzfunktionen für einzelne Microsoft 365-Anwendungen (Exchange, SharePoint, Teams)
2. Überprüfung detaillierter Recovery-Optionen für Microsoft 365 und Salesforce
3. Überprüfung der speziell für den SaaS-Schutz
verfügbaren Sicherheitsfunktionen 4. Überprüfung der Aufbewahrungsfunktionen und -beschränkungen für SaaS-Daten
5. Überprüfung etwaiger spezifischer Compliance-Zertifizierungen oder -Funktionen für den SaaS-Schutz

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

As we approach the end-of-life for Actifio on-premises solutions, am 30. Juni 2025, it’s crucial for Managed Service Providers (MSPs) to prepare for the transition. After this date, Actifio will cease to provide updates for security, reliability, and performance, which could significantly impact MSPs relying on this platform for on-premises backup and disaster recovery.

Die Herausforderung

Angesichts der bevorstehenden Frist müssen MSPs ihre Kunden auf eine robuste Alternative umstellen, um einen lückenlosen Datenschutz und eine lückenlose Datensicherheit zu gewährleisten. Dieser Übergang erfordert eine sorgfältige Bewertung potenzieller Ersatzlösungen, eine detaillierte Migrationsplanung und eine reibungslose Umsetzung, um das Vertrauen der Kunden und die Datenintegrität zu wahren.

Die Chance

Diese Zeit des Wandels bietet MSPs eine hervorragende Gelegenheit, ihr Dienstleistungsangebot durch die Einführung einer fortschrittlicheren, umfassenden Lösung zu verbessern. Commvault erweist sich dabei als erstklassige Wahl und bietet umfangreiche Datensicherungsfunktionen sowie innovative Features, mit denen MSPs die Qualität der Dienstleistungen, die sie ihren Kunden anbieten, deutlich steigern können.

Warum Commvault?

Comprehensive data protection: Commvault delivers an extensive range of data protection services, including state-of-the-art backup and recovery, disaster recovery, and proactive data management. It supports a diverse set of workloads and applications, creating a holistic approach to data safety.

Scalability and flexibility: Designed to accommodate any business size, Commvault’s scalable solutions allow MSPs to tailor services to meet specific client needs, adapting effortlessly as those needs evolve.

Advanced features: With features like deduplication, compression, and encryption, Commvault not only optimizes storage but also fortifies data security. Its automation tools further streamline operations, reducing the administrative load on MSPs.

Enhanced cyber resiliency: Commvault offers robust defenses against modern cyber threats, including ransomware. Its comprehensive security measures, such as immutable backups and anomaly detection, provide MSPs and their clients with peace of mind.

MSP-centric programs: Commvault’s dedicated MSP programs offer tailored resources, support, and flexible pricing models, all designed to help MSPs thrive.

Umstieg auf Commvault

Commvault vereinfacht den Migrationsprozess mit Tools und fachkundiger Beratung, um einen reibungslosen Übergang von Actifio zu gewährleisten. Unser Team ist bestrebt, MSPs bei jedem Schritt zu unterstützen – von der ersten Planung bis zur vollständigen Umsetzung.

Die wichtigsten Vorteile für MSPs
  • Enhanced service offerings: By leveraging Commvault’s comprehensive solutions, MSPs can expand their range of services, increasing their appeal to current and potential clients.
  • Increased efficiency: Automation and streamlined operations reduce costs and improve service delivery, boosting MSPs’ bottom line.
  • Improved profitability: With MSP-friendly pricing and resource allocation, Commvault helps MSPs enhance their profitability and operational efficiency.

Fazit: Mit Commvault in die Zukunft blicken

The end of Actifio’s on-premises offerings marks a critical point for MSPs to reassess their data protection strategies. Commvault stands ready to help MSPs transition smoothly, delivering enhanced service capabilities, operational efficiency, and increased profitability in a post-Actifio landscape.

Don’t delay your preparations. Partner with Commvault today and set the stage for a more resilient, profitable future in managed services.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

When evaluating enterprise cyber resilience solutions, organizations face an important architectural choice between appliance-based approaches like Rubrik’s and software-defined platforms like Commvault’s.

Zwar bieten beide Anbieter Datenschutzfunktionen an, doch führen unterschiedliche architektonische Ansätze zu unterschiedlichen Kostenauswirkungen, die sich über den gesamten Lebenszyklus der Lösung hinweg bemerkbar machen.

Architekturansätze: Box-basiert vs. Plattform

Rubrik’s Appliance-Centric Model

Rubrik’s approach centers on physical or virtual appliances that serve as the primary deployment model:

  • Die Schutzkapazität wird durch zusätzliche Appliances in festen Schritten erweitert.
  • Eine Skalierung erfordert in der Regel die Bereitstellung neuer Appliances, wenn Leistungs- oder Kapazitätsgrenzen erreicht sind.
  • Rubrik’s solution uses an appliance-based architecture where data protection capacity comes in predefined sizing options.
Commvault’s Software-Defined Platform

Commvault nutzt eine softwaredefinierte, modulare Architektur:

  • Zu den Bereitstellungsoptionen zählen reine Softwarelösungen, Referenzarchitekturen, konvergente Systeme oder cloudbasierte Implementierungen.
  • Ressourcen können je nach Leistungs- oder Kapazitätsanforderungen unabhängig voneinander und schrittweise skaliert werden.
  • Die Commvault-Plattform kann auf bestehender Infrastruktur, auf speziell dafür entwickelten Appliances oder als Cloud-Dienst bereitgestellt werden.
Kostenauswirkungen architektonischer Unterschiede

Die architektonischen Unterschiede zwischen diesen Lösungen führen zu mehreren wichtigen Kostenaspekten:

1. Scaling flexibility and efficiency

Appliance-basierte Ansätze erfordern häufig die Bereitstellung von Kapazitäten in vorgegebenen Schritten, was zu einer Überdimensionierung führen kann, wenn der tatsächliche Bedarf zwischen den verfügbaren Appliance-Größen liegt. Laut Branchenanalysten kann diese stufenweise Skalierung dazu führen, dass während des gesamten Lebenszyklus der Bereitstellung Kapazitäten ungenutzt bleiben.

Leistung und Kapazität sind eng miteinander verknüpft. Um die Leistung zu steigern, muss ein zusätzlicher Rubrik-Knoten hinzugefügt werden, was auch Kosten für zusätzliche Speicherkapazität verursacht. Ebenso müssen Kunden zur Erhöhung der Speicherkapazität auch für zusätzliche Leistungsressourcen (CPU, RAM) aufkommen. Dies führt zu höheren Gesamtbetriebskosten (TCO).

Commvault’s platform modular approach enables more precise scaling, allowing organizations to spend as per actual requirements. This helps reduce resource wastage and improves cost efficiency.

2. Cloud integration approach

Wenn Unternehmen Cloud-Dienste einführen, hat der gewählte Architekturansatz erhebliche Auswirkungen auf die Kosten für den Cloud-Schutz:

Plattformbasierte Lösungen lassen sich über native APIs direkt in Cloud-Dienste integrieren. Commvault bietet eine direkte Integration in Cloud-Dienste, ohne dass virtuelle Appliances erforderlich sind, wodurch sich der Ressourcenbedarf für die Cloud-Sicherung potenziell verringern lässt.

Faktoren für die Gesamtbetriebskosten

Bei der Bewertung der Gesamtbetriebskosten über einen Zeitraum von drei bis fünf Jahren sollten Unternehmen mehrere wichtige Faktoren berücksichtigen:

Cost Category Appliance Approach Impact Platform Approach Advantage
Infrastrukturkosten Mögliche Überdimensionierung Optimierte Bereitstellung
Kosten für Cloud-Sicherheit Virtuelle Appliances in jeder Umgebung Direkte Integration von Cloud-Diensten
Skalierungskosten Sprungartige Erhöhungen Inkrementell je nach Bedarf
Technologie-Aktualisierung Vollständige Austauschzyklen der Appliance Aktualisierungen auf Komponentenebene

Über die Kosten hinaus: Überlegungen zur Leistungsfähigkeit

Die architektonischen Unterschiede gehen über die finanziellen Auswirkungen hinaus und führen zu Unterschieden in der Leistungsfähigkeit:

1. Multi-cloud support

Plattformarchitekturen bieten in der Regel einheitlichere Funktionen in verschiedenen Cloud-Umgebungen, da sie auf einer gemeinsamen Codebasis mit cloudspezifischen Integrationspunkten basieren. Dies kann den Schutz in unterschiedlichen Cloud-Bereitstellungen vereinfachen.

2. Workload coverage

Softwaredefinierte Plattformen unterstützen häufig ein breiteres Spektrum an Workloads, darunter Altsysteme, spezialisierte Anwendungen und verschiedene Infrastrukturtypen. Dadurch kann der Einsatz mehrerer Schutzlösungen entfallen.

3. Security integration

The architectural approach also impacts security capabilities. Commvault’s platform includes integrated security features like threat detection, while appliance-focused solutions may require additional components for comprehensive security. Rubrik’s data security solution is delivery through their SaaS, severely limiting functionality in environments where cloud connectivity is restricted or prohibited, such as dark sites or isolated clusters.

Strategische architektonische Überlegungen

The choice between Rubrik’s appliance-based approach and Commvault’s platform architecture represents a strategic decision with long-term implications.

Unternehmen sollten diese Lösungen anhand ihrer spezifischen Anforderungen bewerten und dabei nicht nur die Anschaffungskosten, sondern auch langfristige Faktoren wie Skalierungseffizienz, betrieblichen Aufwand, Cloud-Integration und Sicherheitsaspekte berücksichtigen. Durch das Verständnis der architektonischen Unterschiede und ihrer finanziellen Auswirkungen können Unternehmen fundiertere Entscheidungen über ihre Investitionen in die Cyber-Resilienz treffen.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The shift to cloud computing has become more than a strategic advantage – it’s now a business necessity. According to Gartner, by 2028, cloud computing will shift from being a technology disruptor to becoming a necessary component for maintaining business competitiveness. But with this transformation comes a critical challenge that most organizations haven’t fully addressed: true cyber resilience.

Das verborgene 70-prozentige Risk in Cloud-Umgebungen

Here’s a startling reality that most cloud and security leaders don’t realize: According to our research, in a typical cloud environment, application data makes up only 20% to 30% of the resources, while 50% to 70% consists of cloud configurations that remain completely unprotected by traditional backup solutions.

Überlegen Sie sich, was das im Falle eines Cybervorfalls oder eines Ausfalls bedeutet. Ihre Backup-Lösung kann zwar Ihre Datenbanken und Dateien wiederherstellen, aber Sie müssen auch Folgendes berücksichtigen:

  • Lastverteiler und Sicherheitsgruppen.
  • VPC-Konfigurationen und Netzwerkrichtlinien.
  • Einstellungen für die Container-Orchestrierung.
  • API-Gateways und Abhängigkeiten zwischen Microservices.
  • Konfigurationen für die Identitäts- und Zugriffsverwaltung.
  • „Infrastructure-as-Code“-Vorlagen.

This is where traditional backup falls catastrophically short.

Über den Datenschutz hinaus: Die Revolution der anwendungsorientierten Recovery-Prozesse

Commvault® Cloud Rewind represents a fundamental shift from data-centric to application-centric recovery. Rather than simply backing up and restoring data files, Cloud Rewind treats your entire cloud environment as code – discovering through collecting configuration metadata not application data, and rebuilding cloud ecosystems with all their dependencies intact.

Der Vorteil von Cloud Rewind: Recovery-as-Code

Cloud Rewind’s patented Recovery-as-Code approach automatically codifies your application’s cloud resources, dependencies, and data for hyperfast rebuild capabilities. This isn’t just backup ­– it’s a complete Cloud Time Machine that can rewind your entire environment to any point in time.

Zu den wichtigsten Fähigkeiten gehören:
Ständiges Entdecken und Lernen:
  • Nutzen Sie die nativen Backup- und Snapshot-APIs, die von Cloud-Plattformen wie AWS, Azure und GCP bereitgestellt werden.
  • Stellt komplexe Anwendungsabhängigkeiten in Echtzeit dar.
  • Passt sich an, wenn sich Ihre automatisch skalierten Umgebungen mit Lastenausgleich ändern.
  • Keine Agenten, keine Installation und keine Wartung erforderlich.
Umfassender Schutz:
  • Schützt Cloud-Konfigurationen und Abhängigkeiten für eine schnelle Wiederherstellung.
  • Snapshots mit fortlaufenden inkrementellen Backups.
  • Verwaltung der replikationsübergreifenden und cloudübergreifenden Replikation.
  • Agentenloser Schutz für Anwendungen mit automatischer Skalierung.
Intelligente Koordination der Recovery:
  • Recovery ganzer Multi-Stack-Umgebungen mit Abhängigkeiten mit nur einem Klick.
  • Recovery über Zonen, Regionen, Konten und Mandanten hinweg.
  • Automatisierte Simulationen und Tests zur Gewährleistung der Ausfallsicherheit.
  • Abhängigkeitsorientierte Sequenzierung für komplexe Anwendungen.

Warum traditionelle Wettbewerber den Anforderungen nicht gerecht werden

While competitors like Cohesity, Rubrik, and Veritas focus primarily on data protection, they fundamentally miss the application-centric nature of modern cloud environments. Even traditional cloud service providers, while responsible for protecting customer data, do not secure the underlying cloud infrastructure – leaving customers with limited ability to minimize downtime and recover quickly in the event of a cyber incident.

Zu den Nachteilen herkömmlicher Resilienz-Tools gehören:
  • Limited scope: They protect data but ignore the 70% of cloud resources that are configurations.
  • Manual resilience testing: Time-consuming, cumbersome, and often not done enough to establish cyber resilience.
  • Fragmented approach: Applications and infrastructure are treated separately, creating recovery gaps.
  • Legacy architecture: Solutions adapted from on-premises thinking rather than cloud-native design.

Cloud Rewind beseitigt diese Einschränkungen, indem es Anwendungen und die ihnen zugrunde liegende Infrastruktur, die Datenschichten, das Netzwerk sowie die Sicherheit als ein einheitliches, code-basiertes System behandelt.

Die drei Säulen der Cyber-Resilienz

Cloud Rewind sorgt durch drei Kernfunktionen für umfassende Cyber-Resilienz:

1. Das Risiko verringern:
  • Durch eine kontinuierliche Drift-Analyse lassen sich Fehlkonfigurationen erkennen, bevor sie zu Sicherheitslücken werden.
  • Proaktive Überwachung der Ausfallsicherheit über alle Cloud-Ressourcen hinweg.
  • Unveränderliche Backups verhindern die Verschlüsselung durch Ransomware.
2. Die Readiness erhöhen.
  • Automatisierte Ausfallsicherheitssimulationen dienen dazu, Recovery-Verfahren zu testen.
  • Es sind weder Runbooks noch Skripte erforderlich.
  • Stets aktueller Schutz, der sich auf über 100.000 Cloud-Ressourcen skalieren lässt.
3. Recovery aktivieren.
  • „Recovery-as-Code“ trägt dazu bei, manuelle Wiederherstellungsprozesse zu vermeiden.
  • Die Flexibilität bei der cloudübergreifenden Recovery-Prozesse verhindert eine Anbieterabhängigkeit.
  • Die Wiederherstellung mit einem Klick gewährleistet einen unterbrechungsfreien Geschäftsbetrieb und trägt dazu bei, unvorhergesehene Ausfallzeiten zu reduzieren.

Blick in die Zukunft: Die Ära der anhaltenden Recovery

As cloud environments become increasingly complex with microservices, containers, and serverless architectures, the gap between traditional backup and true resilience will only widen. Cloud Rewind’s Recovery-as-Code approach represents the future of continuous business – where applications and their complete ecosystems can be rebuilt near-instantly, automatically, and reliably.

For organizations serious about cyber resilience, the question isn’t whether you need application-centric recovery – it’s whether you can afford to operate without it. In an era where application availability directly impacts business success, Cloud Rewind provides the comprehensive protection that competitive offerings simply cannot match.

The time to act is now. Every day your organization operates without complete application protection is another day of unnecessary risk. Cloud Rewind helps reduce unknown vulnerabilities by continually discovering and mapping your cloud environment, thus helping enable your business to rewind, recover, and rebuild from cyber incidents in minutes, not weeks.

Erfahren Sie mehr darüber, wie SieCloud RewindIhrem Unternehmen dabei helfen kann, dynamische und verteilte Anwendungen nach Ausfällen und Ransomware-Angriffen blitzschnell zurückzusetzen und wiederherzustellen.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In hybriden Unternehmen ist ein umfassender Multi-Cloud-Schutz für die Cyber-Resilienz unverzichtbar geworden. Da Unternehmen ihre Workloads auf lokale Rechenzentren, mehrere öffentliche Clouds und SaaS-Anwendungen verteilen, ist es von entscheidender Bedeutung, einen einheitlichen Schutz über all diese Umgebungen hinweg zu gewährleisten. Commvault Cloud bietet gegenüber Cohesity erhebliche Vorteile hinsichtlich der Abdeckung von Workloads in Multi-Cloud-Umgebungen.

Die Multi-Cloud-Realität

Moderne Unternehmen arbeiten in komplexen IT-Umgebungen, die sich über mehrere Plattformen erstrecken. Laut demFlexera 2025 State of the Cloud Report, 70% of respondents embrace hybrid cloud strategies, using at least one public and one private cloud. This fragmentation creates potential protection gaps, particularly in multi-cloud deployments where native tools may create inconsistent protection and security postures.

Commvault vs. Cohesity: Vergleich der Workload-Abdeckung

Bei der Bewertung von Multi-Cloud-Schutzplattformen ist die Abdeckung von Workloads ein entscheidendes Unterscheidungsmerkmal. Commvault bietet in mehreren Bereichen eine umfassendere Workload-Unterstützung als Cohesity:

Abdeckung kritischer Cloud-Workloads

Commvault bietet Schutz für verschiedene kritische Workloads:

  • Oracle Cloud Infrastructure: Commvault provides integration with OCI for protection of applications and databases in Oracle’s cloud environment.
  • Cloud-native databases: Commvault supports a wide range of cloud database services across major cloud providers, including Amazon RDS, Azure SQL, and Google Cloud SQL.
  • S3 object storage: Commvault’s platform includes enterprise-grade protection for large-scale object storage deployments across cloud providers, supporting petabyte-scale environments.

Commvault’s platform provides comprehensive protection across these environments, while Cohesity’s public documentation shows more limited coverage in these specific areas.

Anerkennung durch Analysten

Industry analysts have recognized Commvault’s comprehensive workload coverage. Commvault received recognition in the Forrester Wave™ for Data Resilience Solutions (Q4 2024), with high scores in several criteria, including SaaS platform support and cloud infrastructure protection.

Cloud-Integrationsfähigkeit

Über die grundlegende Datensicherung hinaus bietet Commvault die Integration mit verschiedenen Cloud-nativen Diensten:

  • Storage tier integration: Support for various cloud storage tiers like Amazon S3 Glacier Deep Archive, Azure Archive Storage, and Google Cloud Storage Archive.
  • Database service integration: Direct integration with managed database services for application-consistent protection with minimal performance impact.
  • Security framework integration: Connections with cloud security services to enable coordinated security responses and improved cyber resilience.

Einheitliche Verwaltungserfahrung

Commvault’s Cloud Command provides a single interface for managing protection across all environments, eliminating the need for multiple management consoles when protecting diverse cloud resources. This unified approach reduces management complexity and improves operational efficiency.

Funktionen zur Datenmobilität

Commvault erleichtert den Datentransfer zwischen Cloud-Umgebungen für:

  • Notfall-Recovery über verschiedene Cloud-Plattformen hinweg.
  • Migration von Workloads zwischen verschiedenen Clouds.
  • Optimierung der Speicherkosten durch intelligentes Tiering.
  • Einhaltung der Anforderungen an die Datenhoheit bei globalen Bereitstellungen.

Kostenvorteil

Warm-Site-Recovery:
  • Commvault’s intelligent disaster recovery approach eliminates the financial burden of maintaining duplicate cloud infrastructure for non-critical workloads. Unlike traditional methods that pre-provision expensive “always-on” failover environments, Commvault delays full VM creation until actual disaster scenarios through its meta-data driven replication.
  • Für Unternehmen, die Multi-Cloud-Umgebungen verwalten, bedeutet dies jährliche Einsparungen in Millionenhöhe durch eine optimierte Cloud-Nutzung und den Wegfall von Kosten für ungenutzte Kapazitäten.
  • The solution also enables flexible cross-cloud failover strategies without vendor lock-in – a critical advantage in a hybrid cloud landscape.1
Cloud-native Cleanroom Recovery auf Abruf:
  • Zero infrastructure tax: Unlike legacy solutions requiring dedicated on-premises environments, Commvault provisions isolated recovery spaces in Azure on demand – eliminating 100% of idle infrastructure costs. Organizations pay only for active recovery/testing cycles, converting fixed CapEx into variable OpEx.
  • Continuous resilience validation: Automated weekly recovery testing (vs. costly quarterly manual drills) reduces breach-related downtime costs. Integrated AI identifies “known good” recovery points, accelerating response while minimizing forensic labor expenses.
  • Multi-cloud financial agility: Commvault’s any-to-any recovery architecture prevents vendor lock-in penalties, enabling cost-optimized failovers across AWS/Azure/GCP. Contrast this with rigid single-cloud solutions that incur premium pricing during surge events.2

Die Integration von Cohesity und Veritas

Die Fusion von Cohesity und Veritas birgt für Kunden potenzielle Herausforderungen bei der Integration. In Fachpublikationen wurde bereits erörtert, wie viel Zeit für die Integration dieser unterschiedlichen Plattformen erforderlich ist; die vollständige Integration wird voraussichtlich 18 bis 24 Monate in Anspruch nehmen. Im Gegensatz dazu bietet Commvault eine bereits integrierte Plattform an, die speziell für Hybrid- und Multi-Cloud-Umgebungen konzipiert ist.

Umfassender Multi-Cloud-Schutz

Für Unternehmen, die umfassenden Schutz in unterschiedlichen Cloud-Umgebungen benötigen, bietet Commvault Cloud erhebliche Vorteile hinsichtlich der Breite der abgedeckten Workloads. Durch die Unterstützung kritischer Cloud-Dienste, eine tiefgreifende native Integration und ein einheitliches Management bietet Commvault den umfassenden Schutz, den moderne Multi-Cloud-Unternehmen benötigen.


1https://documentation.commvault.com/11.38/essential/warm_site_recovery_for_replication_groups.html

2https://documentation.commvault.com/11.38/essential/cleanroom_recovery.html

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In Folge 13 des Podcasts „Resilience Rundown“ ist Alex Janas, Field CTO bei Commvault, zu Gast bei Moderator Thomas Bryant, Senior Director of Product Marketing bei Commvault. Die beiden befassen sich eingehend mit der Bedeutung des Bewusstseins für Cybersicherheit, insbesondere im Zusammenhang mit der Arbeit im Homeoffice. Im Mittelpunkt des Gesprächs standen praktische Tipps und Strategien zum Schutz persönlicher und beruflicher Daten in einer zunehmend digitalen und dezentralen Arbeitsumgebung.

Die Philosophie von Zero Trust

Alex emphasized a philosophy of considering everything suspect. Whether you’re an employee using a home network or a business managing remote workers, the principle of zero trust is crucial.

This means treating every network, device, and interaction as potentially hostile. For employees, this translates to using trusted VPNs to tunnel all traffic, including DNS, through secure connections. Even if a network requires a password and authentication, it’s essential to remain vigilant, as you never know who else has accessed it.

Sicherheitslücken im Heimnetzwerk

Ein wichtiger Punkt, den Alex angesprochen hat, ist die Anfälligkeit von Heimnetzwerkgeräten, wie beispielsweise von Internetanbietern bereitgestellte Router. Diese Geräte verfügen oft nur über begrenzte Sicherheitsfeatures. Die Gewinnspannen bei diesen Geräten sind gering, was zu einer kurzen Lebensdauer und einem Mangel an regelmäßigen Sicherheitsupdates führt. Das macht sie zu bevorzugten Zielen für Kriminelle, die sie nutzen könnten, um persönliche Daten zu stehlen, Daten zu sperren oder sich sogar Zugang zu Ihrer Arbeitsumgebung zu verschaffen.

Alex recommends investing in more reputable and capable networking devices that offer better security and longer support. While this may require some extra effort in setup and maintenance, it’s a worthwhile investment to protect your data and privacy.

Die Bedrohungslage

Die Bedrohungen für Heimnetzwerke und private Geräte sind vielfältig. Kriminelle könnten es auf Sie abgesehen haben, um sensible Daten wie Bankkontodaten zu stehlen oder Ihr Gerät als Bot in ihrer Command-and-Control-Infrastruktur zu nutzen.

Eine weitere gängige Taktik besteht darin, Ereignisse aus den sozialen Medien, wie zum Beispiel Dienstjubiläen, auszunutzen, um überzeugende Phishing-E-Mails zu verfassen. Diese E-Mails scheinen oft von der Personalabteilung zu stammen und fordern Sie auf, auf Links zu klicken, um Informationen zu Sozialleistungen oder Neuigkeiten zu erhalten, was zu Malware-Infektionen oder Datenlecks führen kann.

Gesunde Paranoia pflegen

Alex weist darauf hin, dass ein gewisses Maß an gesunder Skepsis viel dazu beitragen kann, sich selbst zu schützen. Vorsicht und die Bereitschaft, sich einen Moment Zeit zu nehmen, um Mitteilungen zu überprüfen, können viele häufige Fallstricke im Bereich der Cybersicherheit verhindern. Wenn Sie beispielsweise eine E-Mail mit einem Link erhalten, geben Sie die URL manuell in Ihren Browser ein, anstatt darauf zu klicken. Wenn jemand anruft und behauptet, von einem Unternehmen zu sein, legen Sie auf und rufen Sie das Unternehmen unter einer verifizierten Nummer zurück.

Praktische Tipps für die Sicherheit zu Hause

  1. Use a trusted VPN: Tunnel all your traffic, including DNS, through a secure connection to protect your data.
  2. Invest in better networking equipment: Consider purchasing a router from a reputable company that offers regular security updates.
  3. Be cautious with links and attachments: Verify URLs and attachments before clicking, especially on mobile devices where it can be harder to inspect links.
  4. Monitor your network: Regularly check your home network for suspicious activity.
  5. Educate yourself: Stay informed about the latest cybersecurity threats and best practices.

Verringern Sie Ihr Risiko durch Wachsamkeit

In a world where remote work is the norm, cybersecurity awareness is more critical than ever. By adopting a zero-trust mindset, investing in better home networking equipment, and being cautious with online interactions, you can significantly reduce the risk of becoming a victim of cybercrime. For businesses, it’s essential to monitor and protect remote workers’ devices and networks, treating every environment as potentially hostile.

Check out the full episode of the podcast hier.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

We’re thrilled to announce that Commvault® Cloud Backup & Recovery for Google Workspaceab sofort imGoogle Cloud Marketplace, so you can start safeguarding your critical Google Workspace data today. 

In today’s fast-paced business world, collaboration and efficiency are the lifeblood of success. Google Workspace, a suite of secure, online communication and collaboration tools has become a go-to platform for organizations seeking these advantages. With this cloud-based convenience comes a critical challenge that is often overlooked: data protection.

Eine einzige Schnittstelle für alle Sicherheitsanforderungen Ihrer SaaS-Anwendungen

SaaS applications are not immune to data loss. Accidental deletions, ransomware attacks, and other unforeseen events can wreak havoc on productivity. According to a recent ESG survey, when asked about the most common causes of SaaS data loss, respondents cited 34% from malicious deletions due to malicious attacks and 33% from accidental deletions.1 Given these risks, protecting the data within the SaaS applications that run your business is not just a good idea – it’s essential.

Google Workspace is a highly resilient platform and goes to great lengths to secure customer data, including built-in threat prevention, zero-trust access, and data protection controls. However, businesses typically adopt multiple SaaS apps to provide their teams with the tools they need to get the work done.

Eine einheitliche Methode zur einfachen Sicherung, schnellen Wiederherstellung und flexiblen Aufbewahrung kritischer SaaS-Anwendungsdaten bedeutet für Ihre IT-Abteilung höhere Produktivität, geringere Risiken und niedrigere Kosten. Mit Commvault erhalten Kunden eine einheitliche Plattform für den Datenschutz, die sich über On-Premises-Umgebungen, die Cloud und SaaS erstreckt und einen cyberresilienten Schutz vor Ransomware, internen Angreifern und versehentlichem Löschen bietet.

Now Available on Google Cloud Marketplace: Commvault Cloud Backup & Recovery for Google Workspace 

Commvault Cloud Backup & Recovery for Google Workspace delivers comprehensive, end-to-end enterprise-grade protection for Gmail, Google Drive, and Shared Drives, helping to keep valuable data safe and recoverable – all with the simplicity of SaaS. Commvault offers bundled Google Cloud Storage for Google Workspace protection while providing the broadest workload protection across SaaS, hybrid, and cloud-native workloads. Some key features and benefits include:

  • Comprehensive coverage across Gmail, Google Drive, and Shared Drive data. Plus, automatic discovery of new users and data for proactive protection.
  • Data isolation for air-gapped protection from malicious insiders and ransomware attacks.
  • Granular recovery with flexible point-in-time, in-/out-of-place, and item-level restore options.
  • Long-term, extended retention of active and deleted users with bundled Google Cloud Storage options to maintain SLA compliance.
  • Single, unified solution to protect data in Google Workspace and other SaaS, hybrid, and cloud-native workloads.
  • Simple cloud delivery with no hardware, maintenance, or upfront capital investments required.

“Bringing the Commvault Cloud Backup & Recovery to Google Cloud Marketplace will help customers quickly deploy, manage, and grow the data protection platform on Google Cloud’s trusted, global infrastructure,” said Dai Vu, Managing Director, Marketplace & ISV GTM Programs at Google Cloud. “Commvault can now securely scale and support customers on their digital transformation journeys.” 

Don’t let data loss disrupt your productivity. Take control with Commvault Cloud Backup & Recovery for Google Workspace. To learn more, visit commvault.com/platform/google-workspace. Sind Sie bereit, loszulegen?Demo anfordernum unsere Lösung in Aktion zu erleben.

1  Tech Target, “Caution: There are many ways to lose SaaS data,” May 2023

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Whether it’s a sudden market shift, a cybersecurity breach, or a regulatory change, the unexpected can strike at any moment. Being prepared is key to navigating these challenges successfully. This is where risk management and the Digital Operational Resilience Act (DORA) – a regulatory framework that takes effect in January to help protect financial institutions from disruptions like cyberattacks – come into play.

DORA applies to a wide range of financial entities in the European Union, including credit institutions, investment firms, payment institutions, and electronic money institutions. It also covers critical third-party service providers. Let’s explore how DORA’s risk management requirements can help you stay ahead of the game and keep your organization resilient in the face of uncertainty.

Was ist Risikomanagement?

Risk management is the process of identifying, assessing, and prioritizing risks followed by the application of resources to minimize, monitor, and control the probability or impact of unfortunate events. Effective risk management isn’t just about avoiding disasters; it’s about creating a robust framework that supports your strategic goals and enhances your decision-making.

Risk management helps protect your organization’s assets, including financial resources, physical property, and reputation. By identifying potential threats, you can take proactive steps to mitigate them.

Investoren, Kunden und Mitarbeiter vertrauen eher einem Unternehmen und unterstützen es, das sich nachdrücklich dem Risikomanagement verschrieben hat. Das Verständnis von Risiken hilft Ihnen dabei, bessere strategische Entscheidungen zu treffen. So können Sie Ressourcen effektiver einsetzen und sich auf die Bereiche konzentrieren, die wirklich wichtig sind.

Wie sich DORA in das Risikomanagement einfügt

DORA and risk management are closely aligned, as both focus on preparing for and mitigating potential disruptions. Here’s how DORA’s components fit into a broader risk management strategy:

  1. Risk management framework: DORA requires financial entities to establish a comprehensive risk management framework. This framework should include policies, procedures, and controls to identify, assess, and manage risks. It’s like having a detailed map of potential hazards, allowing you to navigate them more effectively.
  2. Incident reporting: Timely and accurate incident reporting is crucial for maintaining operational resilience. By reporting incidents, you can quickly address issues and learn from them, reducing the likelihood of similar events in the future.
  3. Testing and exercises: Regular testing and exercises are essential for verifying that your systems and processes can handle disruptions. This might include simulated cyberattacks, system outages, or other scenarios. It’s like practicing fire drills to so that everyone knows what to do in an emergency.
  4. Third-Party Dependencies: Many financial entities rely on third-party service providers for various operations. DORA emphasizes the importance of managing these dependencies so that they do not pose a risk to your operational resilience. This involves conducting due diligence, establishing service-level agreements (SLAs), and monitoring performance.

Bewährte Verfahren für das Risikomanagement und die Einhaltung der DORA-Vorgaben

  1. Stay Informed: Keep up to date with the latest regulatory changes and industry best practices. This will help you stay ahead of the curve and confirm your risk management framework remains effective.
  2. Collaborate: Work closely with other departments and stakeholders to create and maintain a holistic approach to risk management. Collaboration can help you identify and address risks that might otherwise go unnoticed.
  3. Continuous improvement: Risk management is an ongoing process. Regularly review and update your risk management approach so that it stays relevant to the current state of your organization.
  4. Technology investment: Invest in the right technology to support your risk management efforts. This might include risk management software, cybersecurity tools, and data analytics platforms.
  5. Cultural shift: Foster a culture of operational resilience within your organization. Encourage employees to report potential risks and participate in risk management activities.

Die Zukunft des Risikomanagements und DORA

As technology continues to evolve, so too will the risks and challenges faced by financial entities. DORA is a step in the right direction, but it’s just the beginning. Here are some trends to watch:

Artificial Intelligence (AI) can help automate risk management processes, making them more efficient and effective. For example, AI can be used to detect and respond to cyber threats in real-time.

Cloud security will become increasingly important as more organizations move to the cloud. DORA’s requirements will likely evolve to address this growing concern.

Regulatory changes are a constant, as governing bodies update their guidelines to address new risks. Stay informed and be prepared to adapt as needed.

Global standards for operational resilience will likely emerge as more countries adopt similar regulatory frameworks. This will make it easier for organizations to operate across different jurisdictions.

Protect Your Organization with a Proactive Approach

Risk management and DORA are powerful tools for preparing for the unexpected. By establishing a robust risk management framework and maintaining DORA compliance, you can help protect your organization’s assets, maintain stakeholder confidence, and achieve your strategic goals. Remember, the key to success is a proactive and continuous approach. Stay informed, collaborate with stakeholders, and invest in the right technology to build a resilient and thriving organization.

With the right tools and strategies, you can turn potential threats into opportunities for growth and improvement. So, take the first step today and start preparing for the unexpected. Your organization’s future depends on it.

Erfahren Sie mehr darüber, wie Sie sich auf das Gesetz zur digitalen Betriebsstabilität vorbereiten können, in unserer Blog-Reihe „Exploring DORA“:

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In the ever-evolving landscape of financial technology, regulatory compliance has become a critical aspect of business operations. One of the most significant recent developments in this area is the European Union’s Digital Operational Resilience Act (DORA), which aims to enhance the resilience of the financial sector by setting stringent standards for data management and other operational processes. This blog delves into the importance of data management in complying with DORA and how organizations can navigate these new regulations effectively.

Was ist DORA?

DORA ist ein umfassendes Regulierungsrahmenwerk, das darauf ausgelegt ist, den wachsenden digitalen Risiken im Finanzsektor zu begegnen. Es deckt ein breites Spektrum an Bereichen ab, darunter das Risikomanagement im Bereich der Informations- und Kommunikationstechnologie (IKT), die Meldung von Vorfällen sowie die Aufsicht über externe Dienstleister. Das vorrangige Ziel von DORA ist es, sicherzustellen, dass Finanzinstitute ihren Betrieb und ihre Dienstleistungen auch im Falle digitaler Störungen aufrechterhalten können, um so die Verbraucher zu schützen und die Finanzstabilität zu wahren.

Die Bedeutung des Datenmanagements

Data management is at the heart of DORA’s regulatory requirements. Financial institutions must have robust data management practices to maintain the accuracy, integrity, and availability of data. This is crucial for several reasons:

  1. Risk mitigation: Effective data management helps identify and mitigate potential risks. By maintaining accurate and up-to-date data, institutions quickly can detect anomalies and take corrective actions to prevent operational disruptions.
  2. Compliance reporting: DORA mandates detailed incident reporting and regular assessments of ICT risk management. Accurate data is essential for generating these reports and confirming that they meet regulatory standards.
  3. Operational efficiency: Well-managed data can streamline operations, reduce redundancies, and improve decision-making processes. This not only enhances compliance but also boosts overall business performance.
  4. Customer trust: With data breaches and cyberattacks commonplace, maintaining the security and privacy of customer data is paramount. DORA’s data management requirements help build and maintain customer trust.

Wichtige Anforderungen an das Datenmanagement im Rahmen von DORA

Um die DORA-Vorschriften einzuhalten, müssen Finanzinstitute mehrere wichtige Anforderungen an das Datenmanagement erfüllen:

  1. Data governance: Establish a clear and comprehensive data governance framework. This includes defining roles and responsibilities, setting data policies, and making sure that your data management practices are integrated into your overall risk management strategy.
  2. Data quality: Verify that data is accurate, complete, and consistent. This involves implementing data validation processes, regular data audits, and using advanced analytics to monitor data quality.
  3. Data security: Implement robust security measures to protect data from unauthorized access, breaches, and cyber threats. This includes encryption, access controls, and regular security assessments.
  4. Data availability: Data must be available and accessible when needed. This involves having reliable backup and recovery systems, as well as disaster recovery plans.
  5. Data privacy: Comply with data privacy regulations, such as the General Data Protection Regulation (GDPR). This includes obtaining proper consent, anonymizing data where necessary, and providing transparency to customers about how their data is used.
  6. Data lifecycle management: Manage the entire lifecycle of data, from creation to disposal. This includes data retention policies, data archiving, and secure data deletion practices.

Umsetzung von Datenmanagement-Verfahren

Die Umsetzung wirksamer Datenmanagementpraktiken zur Einhaltung der DORA-Vorgaben umfasst mehrere Schritte:

  1. Assessment and planning: Conduct a thorough assessment of your current data management practices to identify gaps and areas for improvement. Develop a comprehensive plan that aligns with DORA’s requirements and your business objectives.
  2. Technology investment: Invest in advanced data management technologies, such as data lakes, data warehouses, and data governance tools. These technologies can help automate data validation, security, and privacy processes, making compliance more manageable.
  3. Training and awareness: Educate your employees on the importance of data management and the specific requirements of DORA. Foster a culture of data responsibility and awareness throughout the organization.
  4. Regular audits and reviews: Conduct regular audits and reviews of your data management practices to maintain ongoing compliance. Use the results of these audits to make continuous improvements.
  5. Third-party oversight: If you rely on third-party service providers for data management, they also must comply with DORA. This includes conducting due diligence, signing service-level agreements (SLAs), and monitoring their performance regularly.

Bewährte Verfahren für das Datenmanagement

To better understand how to implement DORA’s data management requirements, let’s look at some best practices:

Best Practice: Data Quality Metrics

Nutzen Sie Datenqualitätskennzahlen, um die Genauigkeit, Vollständigkeit und Konsistenz Ihrer Daten zu überwachen. Diese Kennzahlen können Ihnen dabei helfen, Datenprobleme proaktiv zu erkennen und zu beheben. Eine verbesserte Datenqualität führt zu einer besseren Entscheidungsfindung und einer zuverlässigeren Compliance-Berichterstattung.

Best Practice: Automated Data Validation

Führen Sie automatisierte Datenvalidierungsprozesse ein, um sicherzustellen, dass die Daten korrekt und vollständig sind, bevor sie verwendet werden. Dadurch wird das Risiko menschlicher Fehler verringert und gewährleistet, dass Ihre Daten stets validiert sind.

Best Practice: Secure Data Access Controls

Nutzen Sie rollenbasierte Zugriffskontrollen und Multi-Faktor-Authentifizierung, um sensible Daten vor unbefugtem Zugriff zu schützen. Verbesserte Sicherheitsmaßnahmen verringern das Risiko von Datenlecks und stellen sicher, dass nur autorisierte Mitarbeiter auf sensible Informationen zugreifen können.

Herausforderungen und Lösungen

While implementing DORA’s data management requirements can be challenging, there are solutions to overcome these obstacles:

  1. Data silos: Many organizations struggle with data silos, where data is stored in isolated systems and departments. This can make it difficult to verify data consistency and availability.
    • Solution: Implement a centralized data management system that integrates data from various sources. This can help break down silos and keep data consistent and accessible.
  2. Resource constraints: Smaller financial institutions may lack the resources to invest in advanced data management technologies and training.
    • Solution: Consider outsourcing data management to third-party service providers that specialize in compliance and have the necessary resources and expertise.
  3. Complexity of regulations: DORA is a complex regulatory framework with many requirements. Understanding and implementing these requirements can be overwhelming.
    • Solution: Seek the help of regulatory compliance experts and use compliance management software to simplify the process.

Die Zukunft des Datenmanagements bei der Einhaltung gesetzlicher Vorschriften

So wie sich die Technologie weiterentwickelt, wird sich auch das regulatorische Umfeld wandeln. Finanzinstitute müssen darauf vorbereitet sein, ihre Datenverwaltungspraktiken anzupassen, um neuen und sich abzeichnenden Vorschriften gerecht zu werden. Hier sind einige Trends, die es zu beachten gilt:

  1. Artificial Intelligence and Machine Learning can help automate data management processes, improve data quality, and enhance security. These technologies also can help predict and prevent potential risks.
  2. Cloud computing offers scalable and flexible solutions for data management. It can help financial institutions manage large volumes of data more efficiently and securely.
  3. Blockchain technology can provide a secure and transparent way to manage and share data. It can help maintain data integrity and reduce the risk of fraud.
  4. Regulatory technology solutions are designed to help financial institutions comply with regulations more efficiently. These solutions can automate compliance processes, reduce manual effort, and provide real-time monitoring and reporting.

Datenmanagement ist der Schlüssel zur Einhaltung der DORA-Vorgaben

DORA represents a significant step forward in enhancing the digital operational resilience of the financial sector. Effective data management is crucial for compliance with DORA and for maintaining the trust and confidence of customers and regulators. By implementing robust data governance, maintaining data quality and security, and staying ahead of regulatory trends, financial institutions can not only meet DORA’s requirements but also gain a competitive edge in the digital age.

DORA’s data management requirements are not just a regulatory burden but an opportunity to improve operational efficiency, mitigate risks, and build a more resilient and trustworthy financial institution. Embrace these requirements and use them as a catalyst for positive change in your organization.

Erfahren Sie mehr darüber, wie Sie sich auf das Gesetz zur digitalen Betriebsstabilität vorbereiten können, in unserer Blog-Reihe „Exploring DORA“:

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Forrester recently published the “„Forrester Wave™: Data Resilience Solutions Q4 2024“,” which illustrated a shakeup from the latest 2022 version to the 2024 version by dropping two of the three former “Leaders” to “Strong Performers,” and elevating two former “Strong Performers” to “Leaders.” 

As a result, Commvault was the only vendor that has maintained a position as a “Leader” in all the publications of the Forrester Wave for Data Resilience since its inception in 2019. 

What enabled Commvault to maintain and elevate the status of a top “Leader” in the Wave from 2022 to 2024? In the words of Forrester: “Commvault’s strategic strengths include a commitment to innovation through R&D and acquisition as well as a well-developed partner ecosystem of channel, technology, go-to-market, and infrastructure partners.”  

Seit dem Börsengang im Jahr 2006 hat Commvault kontinuierlich und konsequent einen hohen Innovationsrhythmus beibehalten, um den neuesten Trends im Bereich Datenmanagement und Ausfallsicherheit immer einen Schritt voraus zu sein. Commvault hat nicht nur „Backup-as-a-Service“ für Hybrid-Cloud- und Container-Workloads bereitgestellt, sondern sein Angebot kürzlich durch die Übernahmen von Appranix – das kürzlich in Cloud Rewind umbenannt wurde – und Clumio für cloudnative, datenintensive Workloads auf moderne, cloudnative Dienste zur Ausfallsicherheit verteilter Anwendungen ausgeweitet.

Da Cloud-native Kunden nach Lösungen für den Schutz und die Recovery hyperskalierter Umgebungen suchen, bietet Commvault nun dank der einfachen Einbindung, der agentenlosen Funktionsweise und des schnell realisierbaren Mehrwerts der von ihm erworbenen modernen, cloud-nativen Software hochgradig differenzierte Funktionen für Cloud- und Cyber-Resilienz an.

Not only did Forrester recognize the distinct differentiation of Commvault’s modern cloud-native software capabilities by rating them with the highest possible score for the “Hyperscale Cloud/IaaS” and “Kubernetes and Containers” criteria, but other reports also ranked and scored Commvault’s cloud-native capabilities as the most advanced in the industry.  

In the 2024 Gartner Critical Capabilities for Enterprise Backup and Recovery Software Solutions, Commvault was ranked as the top vendor for the “Hybrid/Multicloud” and “SaaS” use cases. In addition, Commvault was positioned as the top “Leader” in GigaOm’s 2024 Sonar for Cloud Native Data Protection. With the acquisition of Appranix, Commvault also has pioneered the cloud infrastructure recovery assurance market cloud-native applications.1 

Not only is Commvault generating results in the leading industry analyst reports, but it also has reported double-digit revenue growth, positive cash flow, and profitability five quarters running. 

Indeed, Commvault’s commitment to innovation and customer-driven nature has elevated it to deliver the most advanced software to address that latest cloud resilience requirements of the modern enterprise.  

1 Hype Cycle for Backup and Data Protection Technologies, 2024, Gartner, July 2024 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements