Skip to content

At Commvault, we talk a lot about cyber resilience, the ability to recover from whatever challenges come your way. But for one engineer at Australian technology services provider Perfekt, it is his personal resilience that helps him succeed.

Viktor Trokhin left Ukraine when the war began, traveling through five countries before eventually reuniting with his family in Australia. He brought more than six years of ICT experience, deep technical expertise, and a determination to continue his career in tech.

Like many skilled professionals starting over in a new country, Viktor wasn’t just adapting to a new workplace. He was building expertise in new technologies, communicating in a second language, and finding his place in a different professional environment.

Marcus Rolim, Managed Services General Manager at Perfekt and Viktor’s manager, saw his potential immediately.

“Our engineering development program is built around people,” Marcus says. “We invest heavily in mentoring and creating opportunities for engineers from different backgrounds.”

Over the years, Perfekt has welcomed engineers from around 10 different countries. Rather than following a standard training path, the company focuses on each person’s strengths, providing mentoring, practical experience, and support where it’s needed most.

For Viktor, that meant building on his existing expertise while gaining experience with Commvault Cloud and cyber resilience.

As he worked with customers, Arlie – the AI assistant in Commvault Cloud – became a natural part of his daily workflow. Whether he was exploring product capabilities, troubleshooting an issue, or looking for guidance, Arlie helped him quickly find trusted information without interrupting his work.

Then came an unexpected benefit.

Because Arlie supports multiple languages, Viktor could work through complex concepts in his native language before switching to English when speaking with customers or colleagues. While this wasn’t the use case Perfekt originally envisioned, it quickly became a valuable learning advantage.

“When an engineer can explore a complex question in their own language, understand the reasoning behind the answer, and then communicate it clearly in English, it changes the learning experience,” Marcus says. “It allows their technical ability to come through without language becoming a barrier.”

Today, Viktor is an Infrastructure & Data Protection Engineer at Perfekt, supporting customers while continuing to deepen his expertise in cyber resilience.

When Viktor left Ukraine, he carried with him years of experience, deep technical expertise, and an unwavering determination to continue the career he had worked so hard to build. Today, he helps organizations strengthen their cyber resilience, drawing on the same resilience that helped him rebuild his own life.

Maybe that’s why this story resonates. Viktor’s resilience shaped his own future. Today, it helps him make a difference for others.

That’s what putting people first looks like: organizations like Perfekt investing in people, and technology like Commvault Cloud helping them thrive.

Chris DiRadoist Leiter des Bereichs Product Experience bei Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

How Can Security Leaders Protect Their Most Sensitive Data?

Data and AI security enables organizations to discover, classify, and govern access to sensitive data across users, systems, and AI solutions.

Die wichtigsten Erkenntnisse

Daten sind die Lebensader moderner Unternehmen – sie dienen als Grundlage für wichtige Entscheidungen und treiben KI-Initiativen voran. Angesichts ihres Wertes ist es unerlässlich, die eigenen Daten zu kennen und zu schützen.

  • 90 % der Unternehmen habensensible Cloud-Daten offengelegt, die von KI aufgedeckt werden können. Daher ist die Transparenz über Datenbestände der erste und wichtigste Schritt zur Reduzierung von Unternehmensrisiken. 
  • 40 % der Dateien, die in generative KI-Toolshochgeladen odermit diesen geteilt werden,enthalten personenbezogene Daten (PII) oder Daten der Zahlungskartenindustrie (PCI). Ein solcher Missbrauch sensibler Daten birgt für Unternehmen erhebliche Risiken in Bezug auf Datenschutz- und Regulierungsverstöße. 
  • Die Datenermittlung und -klassifizierung bilden die Grundlage für effektive Sicherheit und helfen Unternehmen dabei, sensible Daten in strukturierten, semistrukturierten und unstrukturierten Umgebungen zu identifizieren.
  • Overpermissive access is one of the most persistent data risks for modern businesses. With users, applications, and service accounts often retaining unnecessary access to sensitive data, the “attack surface” is expanded.
  • Um KI zu schützen, müssen sowohl Trainingsdaten als auch Interaktionen zur Laufzeit gesteuert werden. Unternehmen müssen sicherstellen, dass sensible Daten nicht durch Eingaben, Ausgaben oder das Modellverhalten offengelegt werden.
  • Die Einhaltung gesetzlicher Vorschriften hängt von soliden Datengrundlagen ab. Eine strenge Klassifizierung und Zugriffskontrolle ermöglicht es Unternehmen, Richtlinien durchzusetzen und die Kontrolle nachzuweisen.

Sensitive data now moves across clouds, applications, and AI workflows without clear visibility — creating exposure risks that traditional security controls cannot address alone. Commvault Data and AI Security helps organizations discover and classify sensitive data, govern access for both human and machine identities, and maintain compliance with GDPR, HIPAA, and PCI DSS across the full data lifecycle.


Why is sensitive data exposure the biggest security gap?

Data is the invaluable fuel that propels modern businesses. So, organizations have made it a priority to heavily invest in sophisticated security tools.

However, according to Varonis’ 2025 State of Data Security Report, 90% of organizations still have exposed sensitive cloud data. Similarly, 88% of organizations have stale but enabled ghost users.

Butthat’snot all.According to IBM’s Cost of a Data Breach Report 2025, 53% of breached organizations reported compromised customerPII. Thesestatistics paint a vivid image: though data is central to businesses, visibility and overall security remain critical issues. 

Data is no longer confined to structured databases. It exists across files, emails, cloud platforms, SaaS applications, and endpoints. Much of it is unstructured, duplicated, or unmanaged, making it difficult to track and protect.

AI is amplifying this problem. About40% of files uploaded to generative AI tools contains sensitive information, often without governance or oversight. As AI adoption grows, so does the number of systems and identities interacting with data.

Without visibility into what data exists and where it resides, organizations cannot effectively secure it. This lack of visibility is the root of the modern data security problem.


Was sind die Säulen der Daten- und KI-Sicherheit?

Um der Herausforderung der Datenpreisgabe zu begegnen,benötigen Unternehmen einen strukturierten Ansatz,der für Konsistenz und Kontrolle bei der Datenverwaltung sorgt. Die Daten- und KI-Sicherheit basiert auf drei Kernsäulen:Datenermittlung,Datenklassifizierung,and Data & AI Access Governance.

Jede Säule schließt eine wesentliche Lücke:

  • Discovery provides visibility into where data resides across environments. This includes structured systems such as databases,as well as semi-structured and unstructured sources that are often overlooked.
  • Classification adds context by identifying the type and sensitivity of data. It enables organizations to distinguish between operational data,sensitive personal information,financial records,intellectual property,and other high-risk categories.
  • Access governance enables organizations to verify that data is used appropriately. It defines who or what can access data,under what conditions,and with what level of control.

These three pillars do not exist independently. They create a connected system that fully covers data and AI security. Discovery identifies the complete data landscape,classification defines the appropriate sensitivity,and access governance enforces control based on that context.

This model even extends beyond human users to include machine identities such as AI models. In modern environments,these non-human identities often represent a significant portion of data access activity. Bringing these pillars together can help organizations move from fragmented security controls to a unified,policy-driven approach.


Wie können Unternehmen sensible Daten ermitteln und klassifizieren?

Ermittlung und Klassifizierung bilden die Grundlage für ein erfolgreiches Datensicherheitsmodell. Dennoch sind sie oft am schwierigsten effektiv umzusetzen.

Das liegt daran, dass moderne Datenumgebungen stark fragmentiert sind. Sensible Informationen sind über mehrere Cloud-Plattformen, lokale Systeme, SaaS-Anwendungen und Endgeräte verteilt. Ein erheblicher Teil dieser Daten ist unstrukturiert, was ihre Identifizierung und Kategorisierung erschwert.

Zu den größten Herausforderungen zählen:

  • Schattendaten, die ohne Kenntnis, Genehmigung oder Sicherheitsüberwachung existieren.
  • Uneinheitliche Formate bei strukturierten und unstrukturierten Daten.
  • Ein rasantes Datenwachstum aufgrund des Einsatzes von KI, das die manuellen Klassifizierungsbemühungen überholt.

Um dem entgegenzuwirken, benötigen Unternehmen skalierbare Erkennungsfunktionen und Klassifizierungsrahmenwerke. Durch eine ordnungsgemäße Klassifizierung lassen sich die riesigen Mengen an vorhandenen Daten sinnvoll einordnen. Dazu gehören in der Regel Kategorien wie personenbezogene Daten (PII), geschützte Gesundheitsdaten (PHI), PCI-Daten, geistiges Eigentum sowie Schlüssel und Geheimnisse.

Der Wert der Klassifizierung ergibt sich aus ihrer Anwendung. Sobald Daten klassifiziert sind, können Unternehmen Aufbewahrungs- und Löschrichtlinien effektiv anwenden, den Zugriff einschränken oder überwachen und die Maskierung oder Schwärzung sensibler Felder ermöglichen.

In großem Maßstab gewährleistet ein ausgereifter Ansatz zur Datenermittlung und -klassifizierung nicht nur eine vollständige Abdeckung, sondern trägt auch dazu bei, aussagekräftige Ergebnisse zu erzielen. Dazu können eine geringere Gefährdung, eine verbesserte Durchsetzung von Richtlinien und eine messbare Risikominderung gehören.


What are the major risks of overpermissive access?

According to research byReliaQuest, 99% of cloud identities are over-privileged. On a similar note, a2025 study by the Ponemon Institutehighlights that 61% of US firms have suffered from insider data breaches in the past two years, with the average cost of such incidents being a staggering $2.7 million.

This proves that even when organizations understand their data, access remains one of the weakest points in security.

Overpermissive access occurs when users, applications, or service accounts have more access to data than they need. This issue is widespread because access controls are often granted broadly for convenience and rarely revisited.

The impact is significant. Excessive access increases the likelihood of accidental exposure, insider risk, and exploitation during a breach.

To address this, organizations must first carefully inspect access patterns. This includes finding out who is accessing sensitive data, what systems or identities are involved, and whether that access aligns with business needs.

Particular attention must be given to privileged accounts and service identities. These often have extensive permissions and can access large volumes of sensitive data across systems.

In this landscape, effective access governance is key. This requires:

  • Aligning access policies with data classification.
  • Continuously monitoring usage patterns.
  • Identifying and remediating access drift over time.

By reducing unnecessary access, organizations help limit their attack surface and improve overall data protection.


Wie sollten Unternehmen die von KI-Systemen genutzten Daten verwalten?

Der Einsatz von KI breitet sich rasch in allen Bereichen moderner Unternehmen aus. Dies führt zu einer neuen Komplexitätsebene hinsichtlich des Zugriffs auf Daten, ihrer Verarbeitung und Offenlegung.

Trainingsdatensätze umfassen oft große Datenmengen, die aus dem gesamten Unternehmen stammen. Ohne angemessene Klassifizierung und Steuerung können diese Datensätze sensible oder regulierte Informationen enthalten.

Dies birgt Risiken in mehreren Phasen:

  • Während der Datenaufbereitung und des Trainings.
  • Wenn Modelle mit Live-Daten interagieren.
  • Durch Ergebnisse, die unbeabsichtigt sensible Informationen offenlegen könnten.

Daher muss die Klassifizierung vor dem Modelltraining erfolgen. Das bedeutet, alle in den Datensätzen verwendeten Daten zu validieren und zu klassifizieren sowie sensible Informationen bei Bedarf zu entfernen.

Ebenso müssen Datenteams nach der Bereitstellung von KI-Tools kontinuierlich bewerten, wie Modelle Daten nutzen und offenlegen. Sie sollten zudem bei Bedarf geeignete Kontrollmechanismen wie Maskierung oder Schwärzung anwenden.

KI-Systeme sollten nicht losgelöst von der Datensicherheit betrachtet werden. Sie sind eine Erweiterung der Datennutzung und müssen entsprechend geregelt werden. Durch die Integration solcher Daten- und KI-Sicherheitsfunktionen in den gesamten KI-Entwicklungszyklus können Unternehmen dazu beitragen, Risiken zu reduzieren und gleichzeitig Innovationen zu ermöglichen.


Inwiefern trägt die Datenklassifizierung zur Einhaltung gesetzlicher Vorschriften bei?

Die Einhaltung gesetzlicher Vorschriften hängt von der Fähigkeit ab, sensible Daten zu identifizieren und zu kontrollieren. Rahmenwerke wie die DSGVO, HIPAA und PCI DSS legen spezifische Anforderungen für den Umgang mit Daten fest. Diese Anforderungen können jedoch nicht durchgesetzt werden, ohne zuvor zu wissen, wo sich die betroffenen Daten befinden.

Aus diesem Grund scheitern Compliance-Programme ohne eine solide Datengrundlage.

In solchen Fällen bildet die Datenklassifizierung das Rückgrat der Compliance, indem sie Daten den regulatorischen Kategorien zuordnet. Sie ermöglicht es Unternehmen, gezielte Kontrollen auf der Grundlage der Datensensibilität anzuwenden und wichtige Richtlinien für den Datenlebenszyklus durchzusetzen.

Dies eröffnet eine Vielzahl wesentlicher Möglichkeiten:

  • Durchsetzung von Aufbewahrungs- und Löschrichtlinien
  • Einschränkung des Zugriffs auf regulierte Daten
  • Implementierung entscheidender Datenschutzkontrollen

Zudem vereinfacht sie Auditprozesse. Unternehmen können nachweisen, wo sich sensible Daten befinden, wie sie geschützt sind und wer Zugriff darauf hat. Die Zugriffssteuerung stärkt die Compliance zusätzlich, indem sie sicherstellt, dass nur autorisierte Benutzer mit regulierten Daten interagieren können.

Gemeinsam gestalten Datenklassifizierung und Zugriffskontrollen die Compliance für das moderne, KI-gestützte Zeitalter neu.


Fazit: Was erfordert heute eine wirksame Daten- und KI-Sicherheit?

Moderne Daten- und KI-Sicherheit wird nicht mehr durch Perimeter-Abwehrmaßnahmen oder isolierte Kontrollen definiert. Sie erfordert einen kontinuierlichen, einheitlichen Ansatz, der Transparenz, Klassifizierung und Zugriffssteuerung über den gesamten Datenlebenszyklus hinweg miteinander verbindet.

Um einen solchen Ansatz umzusetzen, müssen Unternehmen zunächst ihre Daten verstehen und genau ermitteln, wo sich diese befinden. Anschließend müssen sie den Zugriff darauf kontrollieren. Schließlich müssen Unternehmen sicherstellen, dass KI-Systeme die Daten verantwortungsbewusst nutzen. Diese Funktionen müssen zusammenwirken und dürfen nicht isoliert betrachtet werden, um Risiken zu minimieren und Vertrauen zu wahren.

Angesichts wachsender Datenmengen und der zunehmenden Verbreitung von KI besteht die Herausforderung nicht mehr nur darin, Daten zu sichern, sondern nachzuweisen, wo sich sensible Daten befinden, wer darauf zugreifen kann und wie sie systemübergreifend geschützt sind. Unternehmen, die einen strukturierten, richtliniengesteuerten Ansatz entwickeln, sind besser aufgestellt, um Risiken zu minimieren, regulatorische Anforderungen zu erfüllen und Innovationen mit Zuversicht voranzutreiben.

Häufig gestellte Fragen

Was versteht man unter Daten- und KI-Sicherheit?

Data and AI security is the practice of discovering, classifying, and governing access to sensitive data across systems, users, and AI models. Commvault Data and AI Security delivers these capabilities across hybrid environments — enabling organizations to confirm that data remains visible, controlled, and protected throughout its lifecycle, including how it is used in AI training and outputs.

Warum stellt die Offenlegung sensibler Daten ein großes Risiko dar?

Die Offenlegung sensibler Daten stellt ein großes Risiko dar, da Unternehmen oft keinen Überblick darüber haben, wo sich Daten befinden und wer darauf zugreifen kann, was die Wahrscheinlichkeit von Sicherheitsverletzungen, Missbrauch und Verstößen gegen gesetzliche Vorschriften erhöht. Commvault hilft dabei, dieses Risiko durch einen einheitlichen Ansatz zu mindern, der Datenermittlung, Klassifizierung und Zugriffssteuerung in hybriden Umgebungen kombiniert.

Was sind die wichtigsten Säulen der Datensicherheit?

The three core pillars of data security are discovery, classification, and access governance. Commvault delivers each — Data Discovery identifies where sensitive data exists across environments, Data Classification defines its sensitivity and type, and Data & AI Access Governance enforces access control aligned with business and regulatory policy.

Warum ist ein zu großzügiger Zugriff gefährlich?

Overpermissive access allows users, applications, and service accounts to access more data than necessary — increasing risk of accidental exposure, insider threats, and exploitation. Commvault Data & AI Access Governance addresses this by continuously monitoring access patterns, aligning permissions with data classification, and identifying and remediating access drift across hybrid environments.

Wie sollten Unternehmen zum Schutz der von KI genutzten Daten beitragen?

Organizations can protect AI data by classifying datasets before training and continuously monitoring how models access and expose data. Commvault Data and AI Security supports this through discovery, classification, and governance controls including masking, redaction, and access restrictions — helping ensure that sensitive data is not exposed through AI training, model behaviour, or outputs.

Wie trägt die Datenklassifizierung zur Einhaltung von Vorschriften bei?

Data classification supports compliance by identifying regulated data such as PII and mapping it to appropriate controls. Commvault Data Classification helps organisations enforce retention and deletion policies aligned with GDPR, HIPAA, and PCI DSS — and provides the audit-ready evidence needed to demonstrate how sensitive data is identified, protected, and governed.

Entdecken Sie weitere Ressourcen

Erkunden Sie

What are the Key Risks of Data & AI Security?

Explore how AI introduces new data vulnerabilities – from model training to exposure to runtime risks – and the layered practices organizations use to govern workloads responsibly.
Lesen Sie den Artikel zumabout What are the Key Risks of Data & AI Security?
Whitepaper

Risk Analysis der KI-Sicherheitsrisiken

Ein Readiness-Bericht für Ihren CISO und CIO, um zu erfahren, was sich mit MCP 2.0 geändert hat und was Sie tun müssen, um Ihr Unternehmen darauf vorzubereiten.
Lesen Sie das Whitepaper zum Themaabout Risk Analysis der KI-Sicherheitsrisiken


Die wichtigsten Erkenntnisse

  • Replace subjective claims about “ease of use” with a measurable data protection gearing ratio: protected capacity divided by the number of full-time administrators.
  • Die Messung der geschützten Kapazität pro Vollzeitäquivalent (FTE) liefert ein aussagekräftigeres Bild der betrieblichen Effizienz als herkömmliche Kennzahlen wie beispielsweise die Anzahl der Backup-Jobs pro Administrator.
  • Die Datenschutz-Kennzahl sollte vor einer Plattformmigration als Ausgangsbasis herangezogen und anschließend erneut gemessen werden, um betriebliche Verbesserungen zu validieren.
  • Faktoren wie Multi-Cloud-Umgebungen, Anforderungen an die Cyber-Recovery und Compliance-Verpflichtungen können die Kennzahl beeinflussen, daher sollte sie im Kontext der jeweiligen Umgebung bewertet werden.
  • Unternehmen sollten von Anbietern verlangen, sich zu messbaren betrieblichen Ergebnissen zu verpflichten, anstatt sich auf qualitative Behauptungen über die Einfachheit zu verlassen.

Every vendor evaluation I have sat in eventually reaches the same dead end. One side says the platform is simple to run. The other side says their platform is simpler.

Nobody can prove either claim, so the conversation drifts to the demo, the reference call, the gut feeling in the room. That is not how you should be making a decision that determines how your team will spend the next five years.

I have run production data protection environments. I have watched teams get buried under fragmented tooling that promised automation and delivered tickets instead.

“Reduced complexity” is not a feeling you should have to take on faith. It is something you should be able to calculate.

Die Kennzahl, die der Branche bisher gefehlt hat

We have started using a simple ratio internally and with customers: total protected capacity divided by the number of full-time staff required to run it. We call it the data protection gearing ratio.

Protected Capacity (PB) / FTEs = Data Protection Gearing Ratio

That’s it. No survey questions about satisfaction. No adjectives. A number, calculated from data you already have.

Here is why it matters more than the metrics it replaces. Calculating the number of backup jobs per person made sense a decade ago, when a job represented a discrete unit of manual effort. It does not reflect how modern platforms operate today, where automation absorbs the routine work and a single administrator can be accountable for petabytes, not job counts.

Measuring jobs per person in an automated environment tells you nothing about whether the automation is actually working.

So sieht es in der Praxis aus

One clarification before the number, because it trips people up. Protected capacity means the full, uncompressed, undeduplicated size of the applications being protected, not the physical disk behind them.

That distinction matters because it is the whole point. Commvault’s own production environment protects 4.²,39 PB of application data on 9,.²6 PB of physical disk, an 81,91 % space savings from deduplication and compression.

The ratio is not just a measure of how many petabytes a person can watch over. It is a measure of how much architecture is doing the work before headcount ever enters the picture.

With that in mind: Commvault runs its own production backup environment on 4.²,39 PB of protected capacity with two FTEs. That is a gearing ratio of .²1..²0 PB per FTE. Industry benchmarks for modern platforms typically land between 5 and .²5 PB per FTE, depending on environment complexity, so that number sits at the high end of what is achievable today.

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.MetrischDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.  gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.WertDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.  gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.DefinitionDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 
Geschützte Kapazität (Front-End)  4.²,39 PB  Full, uncompressed, undeduplicated application size protected in our environment 
Gesamtkapazität der Festplatten  9,.²6 PB  Physischer Zielspeicher 
Gesamtbelegter Speicherplatz  7,89 PB  Current utilization 
Gesamtmenge der geschriebenen Daten  7,67 PB  Auf die Festplatte geschriebene logische Daten 
Platzersparnis  81,91 %  Effizienz bei Deduplizierung und Komprimierung 
Vollzeitäquivalente (FTE) für den Datenschutz    Number of full-time admins managing Commvault’s own production backup estate 

Data Protection Gearing Ratio = 4.²,39 PB / .² FTEs = .²1..²0 PB per FTE

I want to be direct about what this number does not do. It does not account for a multi-cloud footprint, cyber recovery requirements, or a compliance-heavy application mix, all of which will pull the ratio down for reasons that have nothing to do with how good the platform is.

A ratio in isolation is not a verdict. A ratio measured before and after a migration is.

That is the actual use case. Baseline your current environment on your current tools. Set a target ratio based on your growth projections and your team’s capacity. Then hold your vendor to it after the implementation is done, not just during the sales cycle.

Die Auswirkungen auf Vorstandsebene

If you are the one signing off on a platform migration, you are not just being asked to trust that a new platform is easier to run. You are being asked to fund a specific operational outcome. A data protection gearing ratio target gives you a way to write that outcome into the business case and check it 1.² months later.

This is the same discipline we apply to mean time to clean recovery (MTCR). Recovery capability is not something you claim, it is something you measure and re-measure until the number tells you the truth. Operational efficiency deserves the same standard.

Die Herausforderung

Ask your current vendor for the gearing ratio of your own environment today. If they cannot produce it, that tells you something about how well they understand what “simple to manage” means for your team.

And if you are evaluating a new platform, do not accept “easier to use” as an answer. Ask what ratio they will commit to, and ask again after year one.

FAQs

Q: What is the data protection gearing ratio?

A: The data protection gearing ratio measures the amount of protected data capacity managed by each full-time administrator. It provides an objective way to evaluate operational efficiency rather than relying on subjective impressions of platform usability.

Q: Why is this metric more useful than backup jobs per administrator?

A: Modern data protection platforms automate much of the routine work that previously required manual effort. As a result, counting backup jobs no longer reflects the true workload or efficiency of an operations team.

Q: What does “protected capacity” mean in this calculation?

A: Protected capacity refers to the full, uncompressed, and undeduplicated size of the application data being protected. This measurement reflects the actual workload managed by the platform rather than the physical storage consumed after optimization.

Q: Does a higher gearing ratio always indicate a better platform?

A: Not necessarily. Environmental complexity, including multi-cloud deployments, cyber resilience requirements, and regulatory obligations, can reduce the ratio even when the platform performs well. The metric is most valuable when comparing the same environment before and after a migration.

Q: How should organizations use the data protection gearing ratio during vendor evaluations?

A: Organizations should establish a baseline using their current environment, define a target ratio aligned with future growth, and ask vendors to commit to achieving measurable improvements after implementation. This approach shifts the conversation from marketing claims to verifiable business outcomes.

Q: What is the broader business value of this metric?

A: The data protection gearing ratio enables executives to quantify expected operational efficiency gains and include them in the business case for a platform investment. It also provides a benchmark that can be reviewed after deployment to confirm the promised results were achieved.

Rajiv Kottomtharayilist Chief Products Officer bei Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In thefirst episode of our STRIVE series on digital sovereignty, Commvault’s Alex Zinin and Osmium Data Group’s Max Mortillaro challenged one of the biggest misconceptions in the industry: Digital sovereignty isn’t a feature you buy – it’s a business problem you have to understand before you can solve.

This conversation picks up where that one left off. This time, I sat down with Thomas Maurer, EMEA Global Black Belt for Sovereign Cloud at Microsoft, to explore what happens after an organization decides sovereignty matters. How do executive teams move from broad concerns about regulation, jurisdiction, or geopolitical uncertainty into practical architectural decisions?

The answer, it turns out, is rarely as straightforward as choosing a cloud provider or selecting the right deployment model. It’s about asking better questions before making technical decisions.

Watch the full episode.

Die wichtigsten Erkenntnisse

  • Every organization defines digital sovereignty differently – and that’s exactly where the conversation should begin.
  • Sovereignty isn’t solved by technology alone. Legal, operational, architectural, and business considerations all shape the outcome.
  • Cloud and on-premises aren’t competing strategies. For many organizations, the future is a carefully designed combination of both.
  • Risk management – not fear – should drive sovereignty decisions.
  • Good architecture starts with understanding business requirements, not choosing infrastructure.

Sovereignty Means Different Things to Different Organizations

One of the first observations Thomas made was also one of the most important.

There is no universal definition for digital sovereignty. For one organization, it may simply mean meeting regulatory requirements or keeping data within a specific geography. For another, it may involve operational independence, business continuity, or preparing for geopolitical disruption. That difference matters because it changes the conversation entirely.

Too often, organizations assume there’s a standard sovereignty blueprint waiting to be implemented. In reality, the first challenge isn’t selecting technology – it’s understanding what problem the organization is actually trying to solve.

Only then does architecture begin to make sense.

Technology Should Follow Strategy

One theme that kept surfacing throughout our discussion was the temptation to jump straight into technical design.

It’s understandable. Architects naturally think about infrastructure, workloads, connectivity, and deployment models. But Thomas emphasized that the most successful projects begin somewhere else.

They begin by listening.

What concerns are driving the initiative? Is the objective regulatory compliance? Business continuity? Data residency? Operational control? Protection against geopolitical disruption?

Different answers lead to different architectures.

That may sound obvious, but it’s surprising how often organizations begin evaluating solutions before they’ve aligned on the business outcome they’re trying to achieve.

Sneak Peek: Start With Risk, Not Assumptions

One of the most practical moments in our conversation comes when Thomas and I discuss why sovereignty initiatives should begin with a risk assessment – not an architectural diagram.

Every organization has a different risk appetite. A Formula 1 team, a government agency, and a global manufacturer won’t make the same decisions, nor should they. The key is understanding which risks matter most to your business, what trade-offs you’re willing to make, and then designing an architecture that supports those decisions.

As Thomas points out, there is no perfect solution – only informed trade-offs. The earlier organizations adopt that mindset, the stronger their sovereignty strategy will be.

‘Cloud or On-Premises?’ Is the Wrong Question to Ask

One of the more interesting parts of the conversation challenged another common assumption – that organizations must choose between public cloud and private infrastructure.

Thomas described a very different reality.

Many organizations aren’t replacing one with the other. They’re designing environments where workloads can move between them based on business need, regulatory requirements, or resilience considerations.

That flexibility changes how we should think about architecture. Instead of asking whether cloud or on-premises is better, the more useful question becomes:

“Where does this workload belong today – and could that answer change tomorrow?”

When sovereignty becomes part of the design process, workload mobility becomes just as important as workload placement.

Architecture Is Only Part of the Equation

Another takeaway I appreciate is Thomas’s reminder that architecture alone doesn’t solve sovereignty.

  • Contracts matter.
  • Legal frameworks matter.
  • Operational processes matter.
  • The people responsible for running the environment matter.

None of those disciplines can operate in isolation. Sovereignty requires legal, security, compliance, and infrastructure teams to work together from the beginning – not hand projects off to one another after decisions have already been made.

That’s a familiar pattern for anyone working in cyber resilience. The strongest outcomes rarely come from individual teams. They come from coordinated ones.

Risk Should Drive Every Decision

Toward the end of our discussion, the conversation naturally shifted toward risk. For me, this is where sovereignty starts to feel much more familiar. Every resilience project begins by asking what the organization is trying to protect, what threats matter most, and how much risk it’s willing to accept.

Digital sovereignty is no different.

Rather than searching for a perfect solution, organizations need to identify the specific sovereignty scenarios they’re concerned about and then determine which architectural, operational, or contractual controls best address those risks.

That shift – from feature comparison to risk management – is what ultimately leads to better decisions.

Why This Conversation Matters

Digital sovereignty continues to evolve rapidly. New regulations will emerge. Technology will change. Geopolitical realities will continue to shift.

That means sovereignty isn’t something organizations solve once. It’s something they regularly evaluate as business priorities and external risks evolve.

The organizations that succeed won’t necessarily have the most restrictive architectures. They’ll have the clearest understanding of their business objectives, the discipline to assess risk thoughtfully, and the flexibility to adapt as those risks change.

Ultimately, digital sovereignty isn’t something organizations can buy off a shelf. It’s an exercise in understanding risk, managing dependencies, and making informed trade-offs long before those decisions are tested.

Die ganze Folge ansehen

In this STRIVE episode, Thomas and I discuss:

  • Why sovereignty means different things to different organizations.
  • How executives should approach sovereignty strategy.
  • Public cloud versus private cloud – and why it’s often not an either/or decision.
  • Why risk management should guide architectural choices.
  • The role of resilience in modern sovereignty planning.

Jetzt anschauen.

FAQs

Q: Does digital sovereignty mean keeping everything on-premises?

A: No. Many organizations adopt hybrid approaches that balance cloud capabilities with specific sovereignty requirements.

Q: Where should sovereignty projects begin?

A: Start by defining the business problem and understanding the risks you’re trying to mitigate before evaluating technology.

Q: Is sovereignty purely a technical issue?

A: No. It requires collaboration between legal, compliance, security, operations, and architecture teams.

Q: How does sovereignty relate to resilience?

A: Both disciplines focus on maintaining operational continuity by reducing exposure to risks that could disrupt the business.

Q: What’s one big mistake organizations make in regard to digital sovereignty?

A: Jumping into architectural decisions before agreeing on what sovereignty means for their organization.

Q: What should executives ask first in terms of planning for digital sovereignty?

A: “What problem are we trying to solve?” Everything else follows from that answer.

Darren Thomsonis Vice President and Chief Technology Officer, EMEA, at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Die wichtigsten Erkenntnisse

  • Terraform manages desired state – it provisions and configures infrastructure from code.
  • Cloud Rewind captures actual deployed state – it helps restore environments to a known-good point in time.
  • Terraform-State-Dateien und der Git-Verlauf sind keine Wiederherstellungswerkzeuge; sie geben nicht wieder, was tatsächlich ausgeführt wurde.
  • Cloud Rewind hilft bei der Wiederherstellung der Infrastruktur, unabhängig davon, ob Änderungen über IaC, die Konsole oder manuell vorgenommen wurden.
  • Gemeinsam bieten Terraform und „ Cloud “ (Rewind ) Teams eine umfassende Strategie für den Betrieb von „ cloud “: Schnell entwickeln, noch schneller wiederherstellen.

If your team runs Terraform, you already know how powerful IaC can be. You define what you want, apply it, and your cloud environment materializes. Change management becomes repeatable. Provisioning becomes predictable.

But there is a gap between provisioning infrastructure and recovering it – and it matters most when something goes wrong at 2 a.m.

Terraform and Cloud Rewind address different parts of the cloud lifecycle. Understanding the difference helps you avoid a dangerous assumption: that your IaC tooling doubles as a recovery plan.

Wie sich Terraform und „ Cloud “Rewind unterscheiden

Terraform is a provisioning tool. It defines and manages desired state. When you revert a Terraform change, you are re-applying a previous desired configuration – not restoring the actual deployed environment that was running before the incident.

That distinction matters. Terraform state is not a historical recovery snapshot.

Cloud Rewind captures actual cloud configuration state and stores point-in-time snapshots. When something breaks, you do not rebuild from code and hope the environment comes back intact. You restore a known-good environment – the one that was actually running – regardless of how the change that caused the problem was introduced.

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Terraform DesignDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.  gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Cloud Rewind DesignDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 
Verwaltung des gewünschten Zustands  Recovery des tatsächlichen Zustands 
Bereitstellung der Infrastruktur  Infrastructure recovery 
Wendet Änderungen an  Macht Änderungen rückgängig 
Quelle der Wahrheit = Code  Quelle der Wahrheit = bereitgestellte Umgebung 
Zukunftsorientiert  Rückblickend 
Erstellen und aktualisieren  Wiederherstellung und Wiederaufbau 
Unterstützt die Wiederherstellung der gewünschten Konfiguration  Hilft dabei, den Bereitstellungsstatus anhand eines erfassten Zeitpunkts wiederherzustellen 

Wo Terraform an seine Grenzen stößt

Selbst in den ausgereiftesten IaC-Umgebungen kommt es zu Wiederherstellungsszenarien, in denen eine Neuerstellung anhand des Codes nicht ausreicht. Bedenken Sie Folgendes:

  • Eine fehlgeschlagene Infrastrukturänderung, die bereits in der Produktion bereitgestellt wurde.
  • Versehentliches Löschen von Ressourcen unter „ cloud “.
  • Durch manuelle oder Out-of-Band-Änderungen verursachte Infrastrukturabweichungen.
  • Änderungen, die außerhalb von Terraform vorgenommen wurden und sich nicht im Code oder im State widerspiegeln.
  • Die Notwendigkeit, die Infrastruktur genau so wiederherzustellen, wie sie zu einem bestimmten Zeitpunkt war.
Terraform does not maintain historical cloud state. It re-applies a desired configuration – it does not restore what was actually deployed and running. “Rewind to 2:15 PM yesterday” is not a Terraform feature. It is a Cloud Rewind feature.

Eine Wiederherstellung, die davon abhängt, dass Terraform-Code, Statusdateien und die Versionshistorie verfügbar, korrekt und vollständig sind, birgt ein echtes Risiko. Im Falle eines tatsächlichen Vorfalls sind diese Bedingungen nicht gewährleistet.

Zwei Werkzeuge, eine umfassende Strategie

Terraform helps you automate infrastructure creation and change management. Cloud Rewind helps you recover infrastructure quickly and consistently when deployments fail, resources are deleted, infrastructure drifts, or your team needs to restore a known-good environment.

They complement each other. Terraform is designed to make your cloud environment repeatable. Cloud Rewind is designed to make it recoverable.

Build with Terraform.Mit „ Cloud “ wiederherstellenRewind.

FAQs

Q: Does Terraform provide point-in-time recovery?

A: No. Terraform re-applies a desired configuration from code. It does not maintain historical snapshots of your deployed cloud environment. If the change that caused an incident is not captured in your Terraform state or Git history – for example, a console change or infrastructure drift – Terraform cannot help you restore it.

Q: What happens when changes are made outside Terraform?

A: Console changes, manual interventions, and out-of-band configurations are common in real environments. Terraform does not track them. Cloud Rewind captures actual deployed state – regardless of how a change was introduced – so you can restore a known-good environment even when your IaC does not reflect what was running.

Q: Is Cloud Rewind a replacement for Terraform?

A: No. They solve different problems. Terraform is your provisioning and change management tool. Cloud Rewind is your recovery tool. Most teams that use one can benefit from both – they cover different parts of the cloud operations lifecycle.

Q: What kinds of incidents does Cloud Rewind address?

A: Cloud Rewind is designed for scenarios where rebuilding from code is not enough: failed deployments already in production, accidental resource deletion, infrastructure drift, and cases where teams need to restore an environment to a specific historical point in time.

Q: Does Cloud Rewind require teams to stop using Terraform?

A: No. Cloud Rewind works alongside your existing IaC workflows. Teams continue to use Terraform for provisioning and change management and use Cloud Rewind when they need to recover from a real incident.

Cailin Pitcherist Senior Portfolio Marketing Manager bei Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Die wichtigsten Erkenntnisse 
  • Commvault integrates frontier AI vulnerability discovery into its risk-based security program rather than relying on AI as a standalone solution.
  • Jeder von einer KI generierte Befund wird von Menschen überprüft und validiert, bevor Entscheidungen zur Behebung getroffen werden.
  • Frontier AI ergänzt etablierte Sicherheitsverfahren wie statische Analyse, dynamische Analyse und Penetrationstests, indem es die Codeabdeckung erweitert und komplexere Exploit-Szenarien identifiziert.
  • Commvault wendet strenge Richtlinien hinsichtlich des Quellcodes, des Zugriffs von Lieferanten und des Umgangs mit Sicherheitslücken an.
  • Commvault investiert in skalierbare Prozesse zum Schwachstellenmanagement, um effizient reagieren zu können, da KI das Volumen potenzieller Sicherheitsbefunde erhöht.

Across the security industry, AI and large language models are being applied to vulnerability discovery – helping teams evaluate more code, explore more attack paths, and identify exploitable conditions faster than manual review alone.  

Kunden fragen ihre Softwareanbieter regelmäßig: Testen Sie Ihre eigenen Produkte mit denselben Methoden, die auch Angreifer anwenden könnten? Sind die Prozesse hinter diesen Tests streng genug, um mit den Entwicklungen Schritt zu halten? Das sind die richtigen Fragen, die man stellen sollte. 

Customers are regularly asking their software vendors: Do you test your own products against the same methods a threat actor might use? Are the processes behind that testing rigorous enough to keep pace? These are the right questions to ask. 

Our Approach: Strong Processes, no Single Tool

Commvault’s security posture is built on strong, repeatable processes rather than dependence on any single tool, model, or vendor.  

Vulnerability management follows an established, risk-based framework: Findings are assessed for practical exploitability, prioritized by severity and exposure, and remediated through our standard development lifecycle. That framework applies the same way regardless of whether a finding comes from a penetration test, an external researcher, or AI. 

AI vulnerability discovery is integrated into this framework as an additional capability, not a separate program running on its own rules. Candidate findings generated through AI methods are treated as inputs that require human confirmation of exploitability before any remediation action is taken. That step helps prevent two failure modes at once: under-prioritizing genuine risk and burning cycles on false positives. 

KI-Methoden ersetzen nicht die Disziplinen, die seit jeher ein verantwortungsbewusstes Schwachstellenmanagement ausmachen. Statische Analysen, dynamische Analysen, Penetrationstests und bewährte Scan-Tools bleiben wesentliche Bestandteile unseres Programms. Der

AI methods do not replace the disciplines that have always defined responsible vulnerability management. Static analysis, dynamic analysis, penetration testing, and established scanning tools remain essential parts of our program.  

Unser Schwachstellenprogramm ist von Grund auf tool- und modellunabhängig konzipiert. Wir sind nicht von einem bestimmten Anbieter oder Modell abhängig, und neue Ansätze können nach und nach integriert werden, sobald sie sich bewährt haben, ohne dass die Art und Weise, wie Befunde verwaltet oder behoben werden, neu gestaltet werden muss. Der Vorteil liegt nicht darin, welches Modell wir verwenden, sondern darin, ob der dahinterstehende Prozess diszipliniert genug ist, um auf die Ergebnisse dieses Modells zu reagieren. 

Our vulnerability program is tool-agnostic and model-agnostic by design. We are not dependent on any single vendor or model, and new approaches can be added as they prove out, without re-architecting how findings are governed or remediated. The advantage isn’t which model we use but whether the process behind it is disciplined enough to act on what that model finds. 

Jeder von uns durchgeführte KI-Scan unterliegt denselben Governance-Grundsätzen:

Every AI scan we run operates under the same governance principles: 

  • Die Ergebnisse werden über dieselbe Pipeline zur Sicherheitsprüfung verarbeitet, die auch für alle anderen Quellen von Sicherheitslücken verwendet wird.
  • Kein von einer KI generierter Befund wird ohne menschliche Überprüfung und Bestätigung der Verwertbarkeit weiterverfolgt.
  • Von der Kandidatensuche bis zur endgültigen Besetzung
Durch KI ermittelte Befunde werden als potenzielle Schwachstellen behandelt, nicht als bestätigte Schwachstellen. Jeder einzelne wird von Ingenieuren und Produktsicherheitsexperten hinsichtlich seiner praktischen Ausnutzbarkeit in realistischen Kundenumgebungen bewertet. Die Schweregrade werden anhand der Gefährdung, der Ausnutzbarkeit und der Auswirkungen zugewiesen – nicht danach, wie der Befund entdeckt wurde. Bestätigte Schwachstellen durchlaufen dieselben Behebungszeitpläne und Eskalationswege wie alle anderen Quellen, wobei die Priorität anhand des Schweregrads und der Gefährdung festgelegt wird.

Findings generated through AI are treated as candidates, not confirmed vulnerabilities. Each one is assessed by engineers and product security experts for practical exploitability in realistic customer environments.  

CVE-2026-13737 ratings are assigned based on exposure, exploitability, and impact – not on how the finding was discovered. Confirmed vulnerabilities move through the same remediation timelines and escalation paths as any other source, with priority set by severity and exposure. 

First Patch Tuesday Disclosures – August 2026

Our inaugural Patch Tuesday, published August 11, 2026, includes the following disclosures: 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.ZusammenfassungDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.  gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.CVE-2026-13737Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.  gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.ZusammenfassungDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 
CVE-2026-13737  Kritisch  CommServe contained an allowlist bypass affecting command execution authorization.  
CVE-2026-13738  Kritisch  CommServe contained an authorization bypass affecting a limited set of command execution operations.  
CVE-2026-13739  Hoch  Seite „Sicherheitshinweise 

 

Full technical advisories, including affected versions and remediation guidance, are available on our „Vertrauen in CVE-Offenlegungen schaffen. Read more about the move to a monthly cadence in Bringing  Trust to CVE Disclosures 

Unsere Investitionen in KI gehen Hand in Hand mit ebenso umfangreichen Investitionen in die Prozessinfrastruktur, die erforderlich ist, um auf die von der KI identifizierten Probleme zu reagieren: Triage-Kapazitäten, Priorisierung nach Schweregrad, Nachverfolgung von Abhilfemaßnahmen und koordinierte Offenlegungsverfahren. Unsere Investitionen sind nur so wertvoll wie die dahinterstehende Reaktionsfähigkeit.

As AI vulnerability discovery becomes standard practice across the industry, the volume of potential findings that security teams need to evaluate will keep rising. The question that matters for any enterprise software vendor isn’t which AI model they use. It’s whether their vulnerability management process is mature enough, and scalable enough, to handle that throughput without creating a backlog that increases customer exposure. 

We pair our investment in AI with an equal investment in the process infrastructure needed to act on what it finds: triage capacity, severity prioritization, remediation tracking, and coordinated disclosure practices. Our investment is only as valuable as the response capability behind it. 

FAQs

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: What is Commvault doing with frontier AI security testing?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.We actively evaluate our products using AI methods as part of our structured security engineering program. We are being thoughtful about testing different models and harnesses so that we find any potential vulnerabilities previously undiscovered by humans and or existing testing. That work follows the same vulnerability management process as every other form of testing. This is underway today – it isn’t a roadmap item. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: How is Commvault preparing for AI vulnerability discovery?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.We built a program that is model-agnostic and tool-agnostic by design. Our goal is to make sure our security engineering practice can incorporate the best available methods across a range of AI tooling, inside one consistent governance and risk management framework. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: Is Commvault using these models safely?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.Yes. All AI scans are thoroughly vetted. Any vendor and tool access is governed by formal NDA and engagement terms, and every AI-generated finding requires human confirmation of exploitability before any remediation action is taken. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: How is Commvault scaling vulnerability management for the AI era?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.Our focus is on making sure the response process scales with discovery volume und dem Tempo der Datenauswertung. As AI increases the number of potential findings our teams need to review, we’re investing in risk-based triage, consistent remediation service level agreements, and the operational infrastructure needed to act on higher discovery throughput within accelerated timeframes to decrease exposure for customers. 

Bill O’Connell is Chief Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

When frontier AI models started making headlines, most of the discussion centered on one question: What happens when attackers gain access to them? 

It’s a fair question.  

Models capable of discovering vulnerabilities faster, chaining exploits together, and operating at unprecedented speed naturally raise concerns for every CISO.  

But after spending time talking with customers over the past several months – and in my conversation with Tim Zonca, Commvault’s VP of Portfolio Marketing, in this episode of gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.STRIVEDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. – I think there’s an even more important question emerging. 

What happens to resilience itself? 

Because while frontier AI will undoubtedly accelerate cyber threats, it’s also accelerating something else: Enterprise complexity. 

Watch the gesamte Folge. 

 Die wichtigsten Erkenntnisse 

  • Frontier AI isn’t just accelerating cyberattacks – it’s accelerating enterprise complexity.  
  • Vulnerability management isn’t disappearing, but the speed and scale of discovery are changing dramatically.  
  • AI systems introduce entirely new recovery dependencies, including agents, vector databases, embeddings, and distributed state.  
  • Organizations need a coherent understanding of their environments before they can recover them.  
  • The next generation of resilience will depend on trusted systems of record that explain what happened, why it happened, and how to recover confidently.  
The Conversation Has Changed 

One thing Tim and I discuss early in the episode is how differently organizations are reacting to frontier AI. 

  • Some see an entirely new class of cybersecurity challenge. 
  • Others view it as simply the next evolution of vulnerability management. 

What’s interesting is that neither perspective is necessarily wrong. 

The processes organizations use to identify, prioritize, and remediate vulnerabilities remain familiar. But the pace at which AI can discover those vulnerabilities – and uncover entirely new chains of attack – is unlike anything we’ve seen before.  

That’s the shift. 

The work isn’t fundamentally different. The speed is. 

When AI Changes the Shape of Recovery 

Most conversations about AI focus on security and prevention: 

  • How do we secure models? 
  • How do we protect prompts? 
  • How do we defend against AI-assisted attacks? 

Those are important questions. But resilience introduces a different one: What exactly are we recovering? 

Traditional enterprise applications already involve complicated relationships between infrastructure, applications, and data. AI expands that picture considerably. Now there are agents operating across multiple systems. Vector databases. Embeddings. Models interacting with different data sources simultaneously. It’s become far more than a traditional application stack.  

Recovery is no longer about restoring an application. It’s about restoring an ecosystem. 

Sneak Peek: Check This Out 

In this moment from our gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.STRIVEDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. discussion, Tim and I discuss the growing complexity of AI stacks, what coherent recovery is (and why it matters), and how Commvault is helping our customers with full AI-stack recovery. 

Why Coherency Matters 

One idea that keeps surfacing throughout our conversation is coherence. 

For years, organizations have worked to map application dependencies, understand infrastructure relationships, and identify critical services. AI makes that challenge significantly more difficult. 

Applications no longer interact with a single database or service. They may depend on multiple models, agents, data stores, and orchestration layers – all changing dynamically. 

Understanding those relationships isn’t just an architectural exercise anymore. 

It’s a recovery requirement. 

Because if you don’t understand what makes up the system, it’s difficult to know whether you’ve actually recovered it. 

A New System of Record 

Another concept from Tim that I found compelling is the idea of a system of record for the AI era. Historically, systems of record gave organizations confidence in business data. Customer records lived in CRM platforms. Financial records lived in ERP systems. 

AI changes that expectation. 

Organizations increasingly need trusted visibility into how data is used, what agents interact with it, why decisions are made, and whether restored environments represent a known-good state.  

That doesn’t replace resilience. It strengthens it. Because confidence in recovery depends on confidence in what you’re recovering. 

AI Can Also Help Solve the Problem 

As organizations struggle to understand increasingly distributed environments, AI becomes a powerful tool for discovery, classification, and policy recommendation.  

Rather than manually identifying relationships across sprawling environments, organizations can use AI to help identify dependencies, recommend protection policies, and continuously update those relationships as environments evolve. 

That’s an important shift. 

The same technology that’s adding to organizational complexity may also become one of the best tools for managing it. 

Why This Conversation Matters 

Frontier AI isn’t simply introducing another cybersecurity challenge. It’s forcing organizations to rethink resilience itself. 

Recovery is becoming less about individual systems and more about restoring trusted business operations across increasingly intelligent environments. That means resilience strategies must evolve alongside the technologies they’re protecting. 

Organizations that prepare for that shift won’t just recover faster. They’ll recover with greater confidence. 

Die ganze Folge ansehen 

In this conversation, Tim and I explore: 

  • How frontier AI is changing enterprise risk.  
  • Why vulnerability management is entering a new phase.  
  • What AI means for modern recovery architectures.  
  • The role of coherent recovery across AI-enabled environments.  
  • Why trusted systems of record will become increasingly important.  

Jetzt anschauen. 


FAQs 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: What are frontier AI models?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.Frontier AI models are the latest generation of highly capable AI systems designed to solve increasingly complex reasoning and cybersecurity tasks. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: Why are organizations concerned about them?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.They dramatically accelerate vulnerability discovery, exploit chaining, and security research, increasing both defensive and offensive capabilities. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: How does AI change cyber resilience?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.AI introduces new dependencies – including agents, models, vector databases, and distributed states – that make recovery more complex. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: What is a coherent recovery strategy?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.It’s an approach that restores not only data, but also the applications, infrastructure, dependencies, and AI components required for trusted business operations. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: What is a system of record in the AI era?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.It’s a trusted source that helps organizations understand what happened, why it happened, and whether recovered systems represent a known-good state. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Q: What should organizations do now?Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.A: Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.Begin mapping AI dependencies, understand how AI changes recovery requirements, and develop resilience strategies that account for increasingly intelligent application environments. 

Chris Mierzwa is Senior Director of Portfolio Marketing at Commvault. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Unified Data Protection | Ransomware Recovery | Cleanroom Recovery | Hybrid Workloads

So vereinheitlichen Sie den Datenschutz für alle hybriden Workloads

Commvault® Cloud helps organizations discover, govern, and unify workload protection, allowing teams to rebuild critical services quickly after a cyber incident.


You’re the VP of IT Operations. It’s 2:00 a.m. on a Saturday. Your SecOps team just confirmed ransomware has encrypted files across three regions. Your last backup job completed successfully – but when your team attempts to restore the ERP system, the application fails to start.

The backup was marked successful. The data was present. But the dependencies, transaction logs, and service relationships were never captured in a consistent, recoverable state. Recovery isn’t just about data – it’s about rebuilding services.

This scenario plays out across hybrid environments every day. Modern enterprises run on interconnected cloud-native services, Kubernetes clusters, hybrid databases, and SaaS platforms – none of which recover cleanly from a simple file restore. Fragmented protection strategies designed for a simpler era leave organizations exposed at exactly the moment resilience matters most.

Cloud is an AI-enabled platform designed to help organizations discover, govern, and unify data protection across cloud-native, hybrid, and on-premises workloads – from a single control plane. Capabilities such as AI-enabled workload discovery, Cleanroom Recovery, Cleanpoint Identification, Threat Scan, and Command Center orchestration help teams validate recovery readiness and rebuild critical services in a controlled sequence after a cyber incident. 

45 %

of organizations are repeat ransomware victims – meaning fast recovery without clean validation reinfects as often as it restores. 
ESG Research — Zero Trust and Ransomware Protection Report 

What Is Unified Data Protection – and Why Does It Matter? 

Unified data protection is a backup and recovery approach that helps organizations govern the broadest range of workloads – including cloud databases, Kubernetes, SaaS, hypervisors, and on-premises systems – from a single control plane, rather than managing separate tools and policies for each environment.Commvault Cloud Unitywurde entwickelt, um diesen Ansatz zu unterstützen, und hilft Teams dabei, die betriebliche Komplexität zu reduzieren und einen konsistenten Schutz in Hybrid- und Multi-Cloud-Umgebungen zu gewährleisten.

Fragmented data protection strategies can create invisible gaps: inconsistent policies across environments, coverage blind spots that surface only during recovery, and manual overhead that scales poorly as workloads diversify. When ransomware strikes or an outage occurs, teams may discover too late that critical workloads were not protected consistently. A unified approach is designed to help address this by bringing all workloads under a centralized policy engine – so protection status, retention schedules, and recovery workflows are governed from one place.

  • Commvault Cloud workload coverage: Unified protection across cloud databases (AWS RDS, Azure SQL, SAP HANA, Oracle), hypervisors (VMware, Hyper-V), Kubernetes (AKS, EKS, GKE), SaaS (Microsoft 365, Salesforce, Google Workspace), and on-premises infrastructure.
  • Unified control plane: All workloads managed from a single AI-enabled Command Center –helping reduce fragmented policy sets and manual operational overhead.
  • AI-enabled discovery and tagging: Automated workload inventory and classification can help teams identify coverage gaps and bring unprotected resources under policy.
  • TCO analysis: Real-time visibility into protected status and cost drivers can support budget governance across cloud, hybrid, and on-premises environments.

Wie unterstützt Commvault Cloud Sie dabei, den Schutz Ihrer Workloads zu erfassen und zu steuern?

Effective data protection depends on knowing what you have before an incident occurs – not discovering gaps during recovery. Commvault Cloud is designed to help organizations continuously discover, classify, and apply backup policies across hybrid and multi-cloud assets, so coverage stays current as environments change.

Commvault Cloud begins with AI-enabled discovery –automatically inventorying cloud-native and hybrid assets, identifying resources without policy coverage, and bringing workloads under centralized governance in Command Center. Policies can be applied consistently across accounts, regions, and clouds, with real-time visibility into protected status and cost. Because environments change continuously – new workloads deployed, configurations updated, cloud resources spun up – discovery is designed to run as an ongoing process rather than a one-time assessment, helping teams maintain accurate coverage without manual audits.

  • AI-enabled discovery: Continuously inventories cloud-native and hybrid assets, identifies coverage gaps, and brings new workloads under centralized policies.
  • Centralized policy engine: Command Center applies consistent retention schedules, backup frequency, and copy policies across multi-cloud, hybrid, and on-premises workloads from a single interface.
  • Commvault Threat Scan: Continuously monitors backup data for anomalies, encryption activity, and malware indicators so security teams can act before recovery begins.
  • Cross-region and cross-cloud copies: Backup copies can be created across regions and cloud providers to support compliance, data residency requirements, and resilience posture.

Why Do Fragmented Tools Fail at Recovery Time?

89% of organizations operate in environments environments with more than one cloud, including hybrid cloud and multi-cloud set ups, yet most recovery failures don’t stem from a lack of backup jobs – they stem from protection that wasn’t built for the environment being recovered. Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.

Recovery failures surface the gap between a backup that ran and a service that actually restarts. Crash-consistent snapshots may restore raw data while leaving transaction logs, service dependencies, and cluster configurations in an inconsistent state – meaning the application cannot start even when the data is present. Unified data protection can help address this by ensuring workloads are protected in a way that reflects how they operate, and by validating recovery readiness before an incident forces the question.

Commvault Cloud supports security leaders who require audit-ready recoverability, IT teams managing hybrid and multi-cloud environments, and cloud and compliance stakeholders responsible for protecting and validating critical workloads. Commvault was recognized in the IDC MarketScape: Worldwide Cyber-Recovery 2025 Vendor Assessment for strengths in cyber recovery architecture, security ecosystem integration, and workload breadth.

  • Continuous backup monitoring: Threat Scan monitors backup data for malware indicators, encryption activity, and anomalous behavior –with alerts integrated into SIEM and SOC tools for coordinated incident response.
  • Commvault Cleanroom Recovery: Designed to stage restoration in an isolated environment so teams can validate data integrity and confirm systems are threat-free before returning to production – reducing reinfection risk.
  • Cleanpoint Identification: Designed to help pinpoint when data may have become compromised, providing more precise selection of a verified recovery point and supporting minimization of data loss.
  • Orchestrated service recovery: Command Center workflows can restore dependent services in sequence – helping reduce the manual coordination burden during high-pressure recovery events.
  • Scalable on-premises protection: HyperScale supports on-premises protection for hybrid environments, with streamlined onboarding and management through Command Center.

Microsoft Azure (Cloud)

Erkennung, Klassifizierung und anwendungsorientierte Datensicherung für Azure SQL, Azure-VMs, Azure Blob und in Azure gehostete Workloads.

Microsoft Entra ID (Identität)

Identity-based access governance integration – connects classification-based controls to Entra ID-managed users and AI service principals for policy enforcement.

AWS (Cloud)

Application-aware protection across AWS-hosted workloads including RDS, EC2, and EKS – via native API integrations.

Okta (Identität)

Identity-based access policy integration –connects Commvault access governance to Okta-managed identities for role-based enforcement.

Cloud (Cloud)

Erkennung und anwendungsorientierte Sicherung für Google Cloud Storage, GKE (Google Kubernetes Engine) und verbundene Workloads.

ServiceNow (ITSM)

Integration for incident and audit workflows – connects Commvault threat scan events and recovery actions to ServiceNow ticketing for compliance reporting.

So funktioniert es


Discover and protect

AI-enabled discovery inventories cloud-native, hybrid, and on-premises assets to identify unprotected workloads. Command Center applies centralized policies – including backup frequency and retention – across environments, with cross-region and cross-cloud copies to support resilience and compliance. 


Monitor and detect

Threat Scan monitors backup data for anomalies, encryption activity, and malware indicators. Alerts integrate with SIEM and SOC tools, helping teams isolate affected data and plan a response before recovery begins. 


Validate and recover

Cleanpoint Identification helps pinpoint when data may have been compromised and surfaces viable recovery points. Cleanroom Recovery stages restoration in an isolated environment for validation before production restore, while Command Center orchestrates service recovery in the correct sequence to support controlled, reinfection-resistant recovery.


Before unified data protection, the most dangerous moment in incident response was often the restore itself – when teams discovered coverage gaps they didn’t know existed. With Commvault Cloud, teams can move from reactive gap discovery to proactive governance: understanding which workloads are protected, at what policy level, and whether recovery points have been validated. That shift – from hoping a backup worked to demonstrating that it can – can make the difference between a measured recovery and an extended outage.

Sind Sie bereit, den Schutz für alle hybriden Workloads zu vereinheitlichen?

Erfahren Sie, wie Commvault Cloud Ihrem Team dabei helfen kann, jede Workload nahtlos zu erfassen, zu verwalten und wiederherzustellen.

Häufig gestellte Fragen

Was ist einheitlicher Datenschutz?

Unified data protection is an approach to managing backup and recovery across cloud-native, multi-cloud, and on-premises workloads from a single control plane. Commvault Cloud supports this by applying consistent policies and coverage across environments – helping teams reduce operational complexity and maintain visibility into protection status.

Warum scheitern fragmentierte Backup-Strategien in der Recovery-Phase?

Fragmentierte Backup-Strategien können zu inkonsistenten Richtlinien, versteckten Abdeckungslücken und manuellem Aufwand führen, der sich in hybriden Umgebungen nur schlecht skalieren lässt.

Commvault® Cloud addresses this with a unified control plane, centralized policies, and AI-enabled discovery – helping organizations identify and close gaps before they impact recovery.

Wie unterstützt Commvault Cloud den Datenschutz für hybride Workloads?

Commvault Cloud delivers unified data protection across cloud, SaaS, Kubernetes, and on-premises environments through a single AI-enabled platform. The Command Center, AI-enabled discovery, and Cleanroom Recovery work together to centralize policies, identify coverage gaps, and help validate data before production restoration –supporting a more controlled recovery process.

Was ist „Cleanroom Recovery“ und wie funktioniert es?

Cleanroom Recovery bietet eine isolierte Umgebung, in der Daten vor dem Einsatz in der Produktion sicher wiederhergestellt und validiert werden können. Durch die Kombination von Threat Scans mit Validierung auf Anwendungsebene hilft es Ihrem Team, das Risiko einer erneuten Infektion zu verringern und nach einem Cybervorfall mit größerer Kontrolle die Wiederherstellung durchzuführen.

Wie unterstützt ein einheitlicher Datenschutz die RTO- und RPO-Anforderungen?

Commvault Cloud hilft dabei, den Datenschutz an den geschäftlichen Prioritäten auszurichten und unterstützt RTO- und RPO-Ziele. Koordinierte Recovery-Workflows in Command Center und Cleanpoint Identification tragen in Kombination mit einer einheitlichen Steuerungsebene dazu bei, Ausfallzeiten zu reduzieren, die Konsistenz zu verbessern und Teams in die Lage zu versetzen, den Schutzstatus zu überwachen und Lücken proaktiv zu schließen.

Welche Integrationen unterstützt Commvault Cloud für die Reaktion auf Bedrohungen?

Commvault Cloud lässt sich nativ in Microsoft Azure, Entra ID, AWS, Google Cloud, Okta und ServiceNow integrieren. Signale aus dem Threat Scan werden an SIEM- und SOC-Tools weitergeleitet, und Recovery-Maßnahmen werden mit ITSM-Plattformen wie ServiceNow verknüpft, um Vorfälle nachzuverfolgen und Auditberichte zu erstellen.

Verbunde Ressourcen

Lösung kurz

Sicherer, widerstandsfähiger Datenschutz

Erfahren Sie, wie moderne Datensicherung unveränderliche Backups, Widerstandsfähigkeit gegen Ransomware und schnelle Recovery für den Geschäftsbetrieb kombiniert.
Lesen Sie die Übersichtabout Sicherer, widerstandsfähiger Datenschutz
eBook

5 Questions Most Data Protection Providers Won’t Answer

Entdecken Sie die entscheidenden Fragen, die Sie bei der Bewertung von Anbietern stellen sollten, um versteckte Kosten aufzudecken und echte Recovery-Fähigkeiten zu überprüfen.
Holen Sie sich das eBookabout 5 Questions Most Data Protection Providers Won’t Answer

For years, cyber resilience has been defined by technology – security controls, sophisticated detection capabilities, and increasingly robust backup strategies designed to prevent attacks or recover more quickly. Those investments remain essential, but they are no longer enough. 

AI has fundamentally changed the nature of cyberattacks, which now move at a speed that challenges even mature organizations. As the window between compromise and business disruption continues to shrink, resilience is becoming less about preventing every attack and more about keeping the enterprise running when prevention inevitably falls short. 

That shift is at the heart of IDC’s new report, Resilience Operations: The Discipline that Makes Readiness Provable. Based on a survey of more than 500 North American organizations, the report argues that resilience is evolving into a cross-functional operating discipline that connects business priorities with cybersecurity, ITOps, and disaster recovery. More importantly, it reveals several gaps that suggest many organizations are still preparing for a threat landscape that no longer exists. 

Here are the insights that stood out. 

Recovery should begin with business outcomes – not technical ones.

Historically, recovery planning has focused on restoring infrastructure as quickly as possible, with success judged by recovery time objectives, backup completion rates, and application availability. While those measures remain valuable, they don’t necessarily answer the question executives care about most: When can we get the business back online? 

IDC argues that resilience should be anchored to business outcomes rather than technical milestones – restoring the capabilities that allow the organization to serve customers, generate revenue, and meet its obligations. That may sound like semantics, but it changes how recovery priorities are established. Technology becomes the means to an end rather than the end itself. 

Most organizations still haven’t defined what matters most.

Nearly 6 in 10 organizations have not fully defined their minimum viable business (MVB)gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse. Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.– the smallest set of functions, systems, processes, and data required to continue operating after a disruption. 

Without a shared understanding of what the business truly depends on, every movement during recovery becomes reactive. By defining your MVB before a crisis, you’ll enable faster decisions, better coordination during recovery, and ultimately a more resilient organization. 

Automation is becoming the dividing line between resilience and recovery debt.

While attackers increasingly automate reconnaissance, exploitation, and lateral movement, many organizations still rely on manual recovery processes. 

That imbalance is becoming increasingly difficult to ignore. AI is compressing attack timelines, but recovery timelines have not kept pace. Organizations that fail to automate these recovery tasks may find themselves spending days assembling and executing plans while the damage has already been done. 

Automated recovery orchestration, clean recovery point identification, and coordinated validation are becoming foundational capabilities for recovering at the speed modern attacks demand. 

Technology isn’t the biggest resilience challenge – organizational alignment is.

Security teams focus on containment, infrastructure teams focus on restoration, business leaders focus on customer impact, and compliance teams focus on regulatory obligations. None of these priorities are inherently wrong, but when they evolve independently, organizations enter a crisis without a shared operating model. 

Enter ResOps. Rather than positioning resilience as an IT responsibility, the report frames it as a discipline that deliberately brings together business, security, infrastructure, and recovery planning. The message is clear: Resilience depends less on individual tools than on creating shared priorities before an incident forces you to make difficult decisions. 

Testing remains one of the strongest indicators of resilience.

IDC found that relatively few organizations conduct frequent tabletop exercises or cyber-range simulations, despite decades of evidence showing that rehearsal consistently improves performance during real incidents. 

Exercises reveal hidden dependencies, expose communication gaps, and allow teams to make decisions without the real consequences. Organizations that repeatedly validate their recovery processes develop a level of confidence beyond planning alone. 

Tomorrow’s resilience challenges are already taking shape.

Ransomware still dominates headlines, but the next resilience challenges have already emerged – from agentic AI and machine identities to post-quantum cryptography. 

These threats remind us that resilience planning can’t focus exclusively on today’s infrastructure. Recovery increasingly involves cloud services, SaaS applications, AI models, machine identities, third-party providers, and distributed digital ecosystems that didn’t exist a decade ago. 

Resilience is becoming measurable.

IDC’s ResOps Maturity Model is invaluable for assessing your organization’s current posture. Rather than treating resilience as something organizations either possess or lack, the framework describes a progression from reactive, siloed operations to mature, adaptive resilience built on governance, automation, and continuous improvement. 

To me, that progression acknowledges an important reality: Resilience is never finished. It’s not about purchasing a platform or completing a project. Organizations become resilient by continually improving how technology, people, and business processes work together under pressure. 

Viewed through that lens, resilience becomes less like insurance and more like operational excellence – a capability that can be assessed, strengthened, and demonstrated over time. 

We’re undergoing a broader shift in how organizations think about resilience.

Resilience conversations are evolving from protecting infrastructure to protecting the business itself. That means recovery planning starts with customers instead of servers, governance becomes as important as technology, and confidence comes from proving capabilities rather than documenting intentions. 

ResOps isn’t really a new framework; rather, it’s a broader recognition that cyber resilience has become an operational discipline. As attacks become faster and more complex, resilience will be measured not by the absence of incidents, but by an organization’s ability to continue serving customers, supporting employees, and maintaining trust despite disruption. 

That’s ultimately what ResOps is designed to prove. 

Rajiv Kottomtharayilist Chief Products Officer bei Commvault. 

More related posts


Cyber Resilience

Read more about Cyber Resilience

Die wichtigsten Erkenntnisse

  • Trust in the age of AI isn’t disappearing – it’s evolving.
  • Organizations need to verify AI continuously rather than trust it by default.
  • AI adoption should empower employees, not push them toward shadow AI.
  • Zero trust isn’t about distrusting people. It’s about continuously validating identities, devices, and actions.
  • Responsible AI adoption requires technology, governance, and people working together.

When we launched Ready. Or Not., we wanted to create a series that made some of today’s biggest AI conversations easier to understand. By pairing comedian Nathan Macintosh with industry experts, we’re exploring everything from agentic AI and cyber resilience to data management – and adding a little humor along the way.

If you caught our first episode on the opportunities and risks of agentic AI, I think you’ll enjoy this one as well. This time, we’re tackling a topic that’s at the center of every AI conversation: trust.

Nathan sits down with Diana Kelley, Chief Information Security Officer at Protect AI, for a conversation about what it means to trust technology when AI can generate convincing fake content, make decisions, and even imitate people. From deepfakes and hallucinations to zero trust and shadow AI, they explore how organizations can embrace AI without losing confidence in their people and systems.

Watch the full episode on Readiverse.I walked away from this episode feeling more optimistic than I expected. Not because AI is suddenly more trustworthy, but because Diana shows us that trust grows when organizations put the right policies, guardrails, and technology in place. Here are some themes from the conversation that put AI in a new perspective.

Trust and Technology Can Co-Exist

Diana believes trust is possible in the AI era, but it’s going to look different. We’ve always built trust through relationships with people. Now, we’re learning how to extend that trust to systems.

That doesn’t mean trusting technology blindly. It means understanding how AI works, recognizing its limitations, and putting the right safeguards in place so people and technology can work together with confidence.

“Trust has to evolve for the new world.”

– Diana Kelley

What resonated with me was the idea that trust and technology don’t have to be at odds with one another. With the right approach, they can strengthen each other.

We’re Getting Smarter About AI

Deepfakes have become one of the most talked about AI risks, and it’s easy to understand why. AI can now generate convincing voices, images, and videos that make us question what’s real. But Diana pointed out that while AI is getting more sophisticated, people are getting smarter. We’re more likely to question an unexpected phone call, take a closer look at a social media post, or pause at something that doesn’t feel quite right.

Organizations are becoming savvier, too. As AI gets better at impersonation, businesses are investing in new ways to continuously verify identities and validate information. My takeaway is this: Technology will continue to improve, but so will our ability to recognize it and respond responsibly.

“Is today a good day to start a deepfake?”

– Nathan Macintosh

Responsible AI is Good for Business

Diana shared an example that will probably sound familiar to many organizations. An employee she calls “Karen in Finance” starts using AI because it helps her complete a task in minutes instead of hours. Karen isn’t trying to work around company policy – she’s trying to be more productive.

Employees use AI because they see real value in it, and that’s an opportunity for organizations. When employees have access to approved AI tools, supported by clear policies and practical guidance, they can work more efficiently while helping protect company data and systems.

Sneak Peek: Smarter AI Adoption

The goal isn’t to stop employees from using AI. It’s to make sure they’re using it the right way. Diana explains how organizations can encourage AI adoption without creating unnecessary risk.

Zero Trust Matters More Than Ever

“When you understand how things work, then you can start to understand how to manage them.”

– Diana Kelley

Zero trust is one of those concepts that’s much easier to understand with an analogy. Diana has a great one. She describes it as moving through a building. Just because you’ve been allowed through the front door doesn’t mean every other door automatically opens for you. Each time you access a new room, there’s another quick check to confirm you’re supposed to be there.

That’s essentially how zero trust works. Instead of assuming a person or device is trustworthy after a single login, organizations continuously verify identities, devices, and actions as technology becomes more connected. Most of those checks happen quietly behind the scenes.

One of the things I appreciated about Diana’s explanation is that zero trust doesn’t feel like another security buzzword. It feels like a practical way to think about trust in a world where AI and digital identities are becoming part of everyday business.

Trust Is About People

At the end of the day, technology doesn’t create trust – people do. People define the policies, processes, and ethical boundaries that guide how AI is used, while technology helps verify that those guardrails are working as intended. It’s that partnership between people and technology that makes responsible AI possible.

Trust extends beyond our own organizations. Businesses need confidence in the partners they work with, the systems they connect to, and the technologies they adopt. That’s why transparency, shared standards, and continuous verification are becoming just as important as innovation itself. The more AI becomes part of everyday business, the more trust becomes everyone’s responsibility.

Ausblick

AI will continue to evolve, and so will the way we interact with it. The organizations that succeed won’t be the ones that trust AI blindly or avoid it altogether. They’ll be the ones that build strong policies, adopt the right technologies, and continuously verify the systems they rely on.

Trust isn’t something we lose as technology advances. It’s something we intentionally build and evolve. That’s exactly the kind of conversation we hope to continue with every episode of Ready. Or Not.

Watch the full episode on Readiverse.

FAQs

Q: What is digital trust?

A: Digital trust is the confidence that people, systems, and organizations are who they claim to be and are acting in expected, secure ways. It combines technology, governance, and verification to help organizations interact safely.

Q: What are deepfakes?

A: Deepfakes are AI-generated images, videos, or audio recordings designed to closely imitate real people. While they have legitimate uses, they can also be used to impersonate individuals or commit fraud.

Q: What is zero trust?

A: Zero trust is a security model based on continuous verification rather than automatic trust. Instead of assuming a user or device is trustworthy after one login, organizations continuously validate identities and actions.

Q: What is shadow AI?

A: Shadow AI refers to employees using AI tools that haven’t been approved or governed by their organization. While often well-intentioned, it can introduce security, privacy, and compliance risks.

Q: Why shouldn’t organizations simply block AI tools?

A: Employees typically adopt AI because it helps them work more efficiently. Rather than banning AI outright, organizations should provide approved tools, establish clear policies, and educate employees on responsible use.

Q: What’s the biggest takeaway from this episode?

A: Trust isn’t disappearing because of AI – it’s evolving. Organizations that combine people, policies, and technology with continuous verification will be better positioned to adopt AI confidently and responsibly.

Katherine Demacopoulos istist Senior Director für globale Inhaltsstrategie und Programme bei Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Our Chief Products Officer, Rajiv Kottomtharayil, recently wrote about a big shift that is taking place across industries. Frontier AI models are compressing the time between vulnerability discovery and exploitation.  

This shift is prompting organizations everywhere to re-examine their vulnerability management processes. We’re doing the same at Commvault. That’s why, starting August 11, we’re changing the rhythm of how we disclose vulnerabilities.  gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.What’s ChangingDie Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.We are raising the bar for security, transparency, and customer trust. On August 11, and on the second Tuesday of each month after that, we’re introducing Patch Tuesdays: a scheduled monthly release where we share security advisories and vulnerability patches.  

Patch Tuesdays are a hallmark of leading technology companies, because they provide customers with a predictable security rhythm.  This matters even more as the pace of vulnerability discovery accelerates. Of course, if there is an urgent vulnerability that must be reported off cycle, we will not hesitate to follow our well-established processes.  

gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Where You Can Find Up-to-Date Resources Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. 

On the second Tuesday of each month, you’ll find new information pertaining to CVEs on our „Vertrauen in CVE-Offenlegungen schaffen. You also can find the official publications at MITRE’s CVE site. 

On the Commvault Security Center, you’ll find our vulnerability management program and other security-by-design thought leadership.   

For compliance certifications, audit reports, and documentation on how Commvault protects customer data, visit the Commvault Trust Center. You can subscribe to updates from the Trust Center at the link in the upper righthand corner of the page. 

Bill O’Connell is Chief  Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

For decades, technology leaders have been trying to eliminate silos. Entire modernization programs have been built around connecting applications, consolidating platforms, and giving organizations a more complete view of their data.

Those efforts have delivered enormous value, but they also have shaped the way we think about resilience. When something goes wrong, we instinctively look for technical fragmentation. However, we’ve found the greater challenge lies elsewhere.

The most significant silos affecting cyber resilience today aren’t found in databases or applications but in organizational structures. They exist between security and infrastructure teams, between IT and the business, and between the people responsible for responding to an attack and those responsible for keeping the organization operating.

IDC’s latest research on ResOps, Resilience Operations: The Discipline that Makes Readiness Provable, suggests these organizational boundaries have become one of the defining obstacles to effective recovery. That’s a timely observation because cyberattacks have evolved in ways that can make those boundaries increasingly difficult to maintain.

Modern Attacks Don’t Follow Your Org Chart

A modern cyberattack rarely affects a single technology domain. A ransomware incident might begin with compromised identities, spread through cloud infrastructure, encrypt critical workloads, disrupt customer-facing applications, impact third-party services, and trigger regulatory Berichting requirements – all within a matter of hours. Every stage involves different teams, different tools, and different priorities.

Yet many organizations still prepare for recovery as though these responsibilities can be managed independently.

Security teams naturally focus on containing threats and preserving evidence. Infrastructure teams prioritize restoring systems and minimizing downtime. Business leaders concentrate on customers, revenue, and operational continuity. Communications teams think about reputation, while legal and compliance teams focus on regulatory obligations.

Each perspective is entirely reasonable. The problem arises when those priorities have never been reconciled before an incident occurs.

In the middle of a crisis, recovery requires decision-making under pressure. Which applications should return first? Which data can safely be restored? How much risk is acceptable before customer services resume? Who has the authority to make those decisions?

Without alignment, organizations often discover that the greatest delays aren’t caused by technology but by uncertainty – the kind that could be mitigated by better preparation.

Resilience Begins with a Shared Definition of What Matters

The Bericht places emphasis on establishing your minimum viable business (MVB). At first glance, it appears to be another recovery planning exercise, but its real value lies in the conversations it forces organizations to have.

Defining an MVB requires business leaders, security teams, infrastructure specialists, and application owners to agree on a deceptively simple question: What absolutely must continue operating if everything else stops?

That discussion changes the nature of resilience planning. Recovery priorities are no longer determined by whichever application owner argues most convincingly during an incident. Instead, they are established in advance, grounded in business outcomes, and supported by technical dependencies that everyone understands.

Perhaps more importantly, MVB creates a common language. Business leaders begin talking about critical capabilities rather than individual systems. Technology teams begin mapping infrastructure to customer outcomes rather than technical architectures. Security teams gain greater clarity about which assets deserve the highest levels of protection during recovery.

That shared understanding is precisely what many organizations have been missing.

Technology Can Automate Recovery – But it Can’t Create Alignment

The Bericht doesn’t argue that organizations need yet another platform. It argues they need a way of working that aligns people, processes, and technology around a single operational objective. This is where ResOps – a cross-functional discipline – proves its mettle.

Technology can help automate recovery, but it cannot resolve disagreements about business priorities. It cannot decide which customer services matter most. And it cannot replace the governance needed to coordinate multiple teams during a high-pressure event.

Those are leadership challenges, and they are best addressed by investing time in answering the difficult questions together, long before an attack forces your hand.

The Strongest Organizations Don’t Eliminate Silos – They Connect Them

Cyberattacks will continue evolving. AI will continue compressing attack timelines. New technologies will introduce new dependencies, and new threats will emerge alongside them. None of that changes the fundamental requirement for resilience.

Organizations don’t recover because individual teams perform brilliantly in isolation, but because those teams already know how to work together.

That may ultimately be the most important insight from IDC’s research. Resilience isn’t simply the product of better technology or more sophisticated security controls. It is the result of shared priorities, clear governance, and a tested operating model that brings the right people together before an incident occurs.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Learn about our advances through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

By Sustainability Team

As AI adoption accelerates, cyber threats are becoming more sophisticated, and data regulations are expanding. Resilience is no longer simply a defensive posture – it is a business imperative and competitive advantage.

That belief is at the center of Commvault’s FY26 Sustainability Report, which is now available. This year’s report reflects the progress we’ve made across the areas that matter most to our business, our customers, our people, and the communities where we live and work.

Anchored by our updated materiality assessment, the report highlights how we are advancing sustainability through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

Cyber resilience remains foundational to our work. As organizations rethink what it means to be ready for disruption, Commvault continues to unify data security, identity resilience, and cyber recovery to help customers detect threats faster, operate more efficiently, and recover with greater confidence. We also are integrating AI and automation designed to support smarter, more secure, and more resilient operations.

That same focus on resilience extends to our environmental commitments. Our solutions help customers optimize data storage and movement, which can help reduce energy expenditure in data centers. For Commvault, responsible innovation means building solutions that support both operational strength and more efficient use of resources.

The report also reflects the people and principles behind our progress. Strong governance, a modern Code of Ethics, and continued investment in our talent help create the foundation for trusted partnerships and long-term value. These commitments are deeply connected: Strong governance enables responsible innovation, responsible innovation helps strengthen the security and efficiency our customers depend on, and that trust is sustained by the people who bring our mission to life every day.

We invite you to read Commvault’s FY26 Sustainability Report as both a record of our progress and a look forward to the priorities that will shape our next chapter.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

A few years ago, digital sovereignty was largely viewed as a compliance conversation. If you stored data in the right geography, met the right regulatory requirements, and satisfied a handful of audit questions, you could generally move on.

That’s no longer the case.

Today, sovereignty has become a board-level discussion. Governments are rewriting policies. Regulators are increasing scrutiny. And business leaders are starting to recognize that sovereignty isn’t just about where data resides – it’s about how organizations continue operating when geopolitical, legal, or operational assumptions suddenly change.

In the first episode of our STRIVE series on digital sovereignty, I sat down with Max Mortillaro, co-founder and Chief Research Officer at Osmium Data Group. Together, we unpack what sovereignty actually means, why the conversation has accelerated so quickly, and where organizations are most likely to get it wrong.

Watch the full episode.

Die wichtigsten Erkenntnisse

  • Digital sovereignty is no longer just a compliance issue – it has become a resilience and business continuity concern.
  • Data location is only one piece of the puzzle. Jurisdiction, operations, technology dependencies, and governance all matter.
  • Many organizations focus on technical controls before understanding the business problem they’re trying to solve.
  • Geopolitical uncertainty is accelerating sovereignty initiatives, particularly across Europe.
  • There is no such thing as a perfectly sovereign environment. Every organization must make informed trade-offs between risk, cost, and operational requirements.

Why Data Location Isn’t the Whole Story

One of the most common misconceptions around digital sovereignty is that it begins and ends with geography. If data is stored in a local data center, the thinking goes, the sovereignty problem has been solved.

It’s an understandable assumption. After all, many of the early conversations around sovereignty focused heavily on data residency requirements and where information could legally be stored.

But as Max points out during our discussion, that’s only one dimension of a much larger challenge. Sovereignty isn’t simply about where a data center sits. It’s also about who operates it, which laws apply to it, who has access to it, and what dependencies exist behind the scenes.

A cloud service may be physically located within a specific country, but that doesn’t necessarily mean it’s insulated from legal, operational, or technological influence originating elsewhere.

That’s where the conversation becomes significantly more complex.

The Hidden Dependencies Most Organizations Overlook

When organizations first begin exploring sovereignty, they often approach it as a technology project. They evaluate hosting locations. They assess replication strategies. They examine where workloads should run.

Those conversations are important, but they can also create a false sense of confidence.

As Max explains, modern technology environments are built on layers of dependencies that aren’t always visible. A service may appear local on the surface but it may be relying on infrastructure, management systems, telemetry services, or operational controls that exist elsewhere.

That’s why sovereignty isn’t simply a question of location. It’s a question of influence.

Who ultimately controls the service? Which legal jurisdiction applies when disputes arise? What happens if geopolitical tensions introduce new restrictions, regulations, or limitations on access?

These aren’t hypothetical questions anymore. They’re becoming part of real-world risk assessments.

Sneak Peek: Sovereignty Is More Than a Technical Problem

In this segment from the conversation, Max explains why organizations often start sovereignty discussions in the wrong place – and why understanding the legal, operational, and business objectives must come before any technology decisions.

Why Europe Is Driving the Conversation

One of the most interesting parts of our discussion focuses on why sovereignty has become such a dominant topic across Europe.

The answer isn’t just regulation; it’s dependency.

European organizations have become increasingly aware that many of the technologies they rely on every day are owned, operated, or governed outside of their direct control. For years, that reality was largely accepted as part of the global technology ecosystem.

Today, that assumption is being reevaluated.

Geopolitical tensions, evolving regulations, and increasing concern around strategic autonomy have pushed sovereignty higher on the priority list for governments and enterprises alike. What was once considered an edge case has become a mainstream business concern.

The result is a growing recognition that resilience isn’t only about recovering from technical failures. It’s also about understanding and managing external dependencies before they become business disruptions.

Sovereignty and Resilience Are the Same Conversation

One of the themes that you’ll see repeatedly surfacing throughout the discussion is how closely sovereignty and resilience are connected.

At first glance, they may seem like separate disciplines. One focuses on governance, regulation, and control. The other focuses on recovery, continuity, and operational readiness.

In practice, they’re deeply intertwined.

If a business cannot access critical systems because of a geopolitical event, regulatory restriction, or third-party dependency, the outcome isn’t very different from other disruptions organizations spend years preparing for.

The business still needs to operate. Customers still need to be served. Recovery still needs to happen.

That’s why I increasingly view sovereignty through the same lens as cyber resilience. Both are fundamentally about reducing exposure to events that could disrupt operations and preparing the organization to continue functioning when those events occur.

Start With the Business Problem

Perhaps the most practical advice Max shares is also the simplest.

Before evaluating sovereign cloud offerings, before engaging vendors, and before debating technical architectures, organizations should first understand what problem they’re trying to solve.

That means understanding:

  • Which business processes are most critical.
  • Which data assets matter most.
  • Which regulatory requirements apply.
  • Which risks are truly being mitigated.

Only after those questions are answered does it make sense to evaluate technology options.

Too often, organizations start with solutions and work backward toward the problem. Sovereignty requires the opposite approach. The strategy should come first.

The architecture follows.

Why There Is No Perfect Answer

One of the realities leaders need to accept is that there is no such thing as a perfectly sovereign environment.

Every organization operates within a network of dependencies. Every technology choice introduces trade-offs. Every risk decision involves balancing operational requirements, compliance obligations, cost considerations, and business outcomes.

The goal isn’t perfection. The goal is understanding those trade-offs well enough to make informed decisions.

Organizations that approach sovereignty as a binary yes-or-no question often find themselves frustrated. Organizations that approach it as a risk-management exercise tend to make better progress.

Why This Conversation Matters

Digital sovereignty is moving quickly from a niche compliance topic to a strategic business issue.

Boards are asking questions. Regulators are increasing scrutiny. Customers are becoming more aware of where their data lives and who controls it.

At the same time, geopolitical uncertainty continues to reshape how organizations think about risk.

That doesn’t mean every company needs a radical sovereignty transformation tomorrow.

But it does mean that the organizations that start building a clear strategy today will be in a much stronger position than those who wait until the conversation becomes unavoidable.

Sovereignty isn’t a technology decision masquerading as a business problem. It’s a business problem that requires legal, operational, and technical decisions working together.

Die ganze Folge ansehen

In this installment, Max and I explore:

  • What digital sovereignty actually means.
  • Why data location alone isn’t enough.
  • The legal and operational dimensions organizations often overlook.
  • How geopolitical developments are influencing sovereignty strategies.
  • Why sovereignty and resilience are becoming inseparable.

Jetzt anschauen.

FAQs

Q: What is digital sovereignty? 

A: Digital sovereignty refers to an organization’s ability to maintain control over its data, technology, operations, and governance within specific legal and jurisdictional boundaries.

Q: Is digital sovereignty the same as data residency? 

A: No. Data residency is one component of sovereignty, but sovereignty also includes legal jurisdiction, operational control, technology dependencies, and governance.

Q: Why has digital sovereignty become more important recently? 

A: Growing geopolitical uncertainty, evolving regulations, and increasing concern about technology dependencies have accelerated interest in sovereignty initiatives.

Q: What is the biggest mistake organizations make? 

A: Treating sovereignty as a purely technical challenge instead of a broader business risk and resilience issue.

Q: How does sovereignty relate to cyber resilience? 

A: Both disciplines focus on maintaining operational continuity in the face of disruptions, whether those disruptions are technical, legal, geopolitical, or regulatory.

Q: Where should organizations begin? 

A: Start by understanding the business outcomes you’re trying to protect, the risks you’re trying to mitigate, and the data and processes that are most critical to your operations.

Alex Zinin is VP/GM of Managed Service Providers at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Die wichtigsten Erkenntnisse

  • The role of the backup administrator is evolving from managing infrastructure to delivering business resilience and recovery confidence.
  • Modern ResOps (resilience operations) focus on recovery readiness, continuous validation, governance, and business outcomes – not just successful backup jobs.
  • Autonomous Resilience is Commvault’s vision for the next evolution of ResOps, whier AI helps resilience teams reduce operational overhead through intent-driven, governed workflows while maintaining human oversight, approvals, and auditability.
  • By helping reduce repetitive operational work, AI enables resilience teams to spend more time improving cyber recovery, governance, and recovery readiness.
  • The future of resilience will be measured by confidence in recovery – not simply the successful completion of protection activities.

The Operational Shift at 8 a.m.

For an enterprise backup administrator, the morning routine has long followed a predictable, high-stress pattern. You log in at 8 a.m. to face a wall of dashboards. Thier are thousands of completed protection activities, but your eyes naturally scan for the exceptions – a handful of failed workloads, replication delays, and capacity alerts warning that critical storage resources are nearing their thresholds.As you begin sorting through the day’s priorities, the reality of modern infrastructure closes in. A virtualization administrator submits a request: Dozens of new workloads were provisioned overnight, and leadership needs to know whether they are automatically covered by existing protection policies.Moments later, the compliance team requests a detailed history of protection success and retention validation to prepare for an upcoming audit. Then, the security operations center (SOC) calls. An anomaly has been detected on a critical system, and they need confirmation that recovery copies remain isolated, immutable, and uncompromised.Before you can finish your first cup of coffee, leadership asks a simple but devastating question: “If we were hit by ransomware right now, how consistently and confidently could we recover?”

Ten years ago, a successful backup administrator was an infrastructure gatekeeper. Success was binary and infrastructure-centric: Did the jobs finish within the required time window? Was the data successfully protected? If the dashboard was green, the job was done.Today, that paradigm is entirely broken. The modern enterprise does not care whether data protection jobs completed successfully. It cares whether the business can survive a catastrophic disruption.Success is no longer measured by the completion of a background data protection process. It is measured by an organization’s ability to withstand ransomware, infrastructure failures, cloud outages, insider threats, and compliance events without losing data or operational momentum.The role has fundamentally evolved from infrastructure management to enterprise resilience. Yet many organizations still force administrators to spend their days managing operational tasks instead of architecting recovery confidence.Commvault is working to redesign the administrator experience to help break this cycle, enabling a shift from reactive backup management toward comprehensive ResOps.

The Drag of the Modern Administrator’s Daily Reality

To understand why this shift is necessary, one must first recognize the enormous operational burden carried by administrators every day. Consider the volume of tactical work required to maintain a modern enterprise protection environment:

  • Job and infrastructure monitoring: Reviewing overnight activities, distinguishing transient issues from legitimate failures, and validating infrastructure health across a rapidly changing hybrid environment.
  • Troubleshooting and issue resolution: Spending hours reviewing diagnostic information and operational telemetry to determine why processes stalled, services became unavailable, or critical workloads failed unexpectedly.
  • Resource optimization and performance management: Continuously identifying storage constraints, network bottlenecks, or infrastructure limitations that impact protection and recovery objectives, then manually expanding capacity as requirements grow.
  • Workload discovery and lifecycle management: Automatically discovering, classifying, and assigning appropriate protection policies to newly deployed applications, cloud services, databases, and infrastructure resources.
  • Capacity and storage management: Monitoring consumption trends, forecasting growth, and responding to unexpected increases before they threaten recovery objectives.
  • Audit and compliance support: Collecting reports, validation records, and historical evidence across multiple systems to demonstrate compliance with retention and governance requirements.

Every hour spent troubleshooting an operational issue or assembling compliance evidence is an hour taken away from strategic resilience planning. This is whier resilience teams lose time. The challenge is the operational overhead required to keep protection systems synchronized with a constantly evolving hybrid cloud environment.

The Structural Shift: From Backup Operations to ResOps

As organizational risk profiles increasingly center around cyber resilience and business continuity, the very mindset of data protection must evolve.

Old Mindset: Backup Operations

“I need my protection jobs to finish successfully.” 

New Mindset: ResOps

“I need confidence that we can recover immediately.” 

This evolution fundamentally changes the questions administrators must answer.

Backup Operations  ResOps
Did the workload complete protection last night? Are our critical applications verified as recoverable?
How much storage capacity remains? What is our verified recovery readiness posture?
Are recovery copies synchronized? Are our recovery environments protected and isolated?
Can we restore a single file? Can we recover an entire business service during a cyber event?

In this new model, recovery – not backup – becomes the primary operational metric. 

An organization can achieve near-perfect protection success rates while remaining dangerously unprepared for a ransomware attack due to compromised credentials, hidden dependencies, configuration drift, or unverified recovery processes.ResOps assumes disruption is inevitable. The focus shifts toward continuous validation, proactive risk identification, threat awareness, and deterministic recovery orchestration.At Commvault, we see this evolution leading toward Autonomous Resilience, whier AI helps resilience teams move from manual operations toward intent-driven, governed outcomes.

How Commvault is Redesigning the Experience Around Outcomes

Commvault is addressing these realities by working to redesign the administrator experience. Rather than requiring users to organize their work around infrastructure configurations, protection policies, storage resources, and system assignments, Commvault is shifting the experience toward outcomes that matter to the business.

  • Unified management and risk-driven visibility: Rather than navigating multiple interfaces to manage different environments, administrators gain visibility into their entire estate through a unified resilience experience.The focus extends beyond operational status. The platform highlights risk exposure, protection gaps, emerging threats, unprotected workloads, and configuration drift that could impact recovery readiness.
  • Policy simplification and intelligent automation: Traditional environments often require administrators to manage hundreds of static schedules and policies. Commvault is designed to replace this complexity with intent-based protection plans.

    Administrators define business outcomes, while the platform can automatically orchestrate the infrastructure, optimize workflows, and manage protection activities behind the scenes.

  • Continuous validation and clean recovery environments: True resilience requires confidence not only in protected data but also in the ability to restore it safely.

    Commvault can integrate automated recovery validation directly into operations. This includes the ability to orchestrate isolated recovery environments whier systems can be restored, validated, and inspected before production restoration occurs.

  • Threat-aware operations and intelligent detection: Modern resilience requires more than monitoring activity counts. By applying advanced analytics and machine learning to operational telemetry, the platform establishes historical baselines and detects abnormal behavior.

    When suspicious activity occurs, administrators receive contextual explanations, probable causes, impact assessments, and recommended actions – not just generic alerts.

A Day in the Life: The Outcome-Driven Workflow

To understand the potential impact of this transformation, consider an illustrative day for an administrator within an outcome-focused resilience platform. The scenario below shows how these capabilities are intended to work together.

8 a.m. – Establishing Recovery Readiness

Instead of searching through thousands of activities and alerts, you open a resilience dashboard displaying a comprehensive Recovery Readiness Score across the environment. The platform highlights a scaling concern. Recently deployed workloads have increased demand beyond recommended operational limits.Rather than manually expanding infrastructure and coordinating resources, the platform automatically recommends a corrective action: “Additional infrastructure capacity is recommended to maintain recovery objectives. Approve?” 

A single approval initiates the adjustment.

11:30 a.m. – Automated Audit Resolution

The compliance team requests evidence of protection activity and policy compliance for a previous reporting period. Rather than manually compiling reports and spreadsheets, the administrator generates a compliance package containing validation records, policy compliance evidence, and supporting documentation within minutes.Time is spent improving resilience – not producing paperwork.

2 p.m. – Threat Detection and Autonomous Response

A critical anomaly is detected. A workload exhibits behavior that significantly deviates from normal historical patterns.Instead of issuing a generic warning, the platform automatically correlates the event with known behaviors, evaluates potential causes, assesses business impact, and identifies clean recovery points.If a cyberattack is suspected, the platform highlights affected recovery data, isolates impacted assets, validates clean recovery options, and prepares recommended recovery actions.The administrator is no longer investigating what happened. The platform is helping determine what to do next.

The Power of Intent: Why Embedded Intelligence Changes Everything

The engine powering this transformation is the move from manual task execution to autonomous, intent-driven operations.Commvault’s conversational and AI-driven capabilities are designed to support the operational model that this transformation requires:

  1. An administrator expresses intent.
  2. The platform gathers context.
  3. Recommendations are generated.
  4. Actions are executed with appropriate oversight.
  5. Outcomes are validated.
  6. Activities are documented automatically for governance and audit purposes.

This fundamentally changes the relationship between administrators and the underlying technology. The goal is no longer to manage systems. The goal is to direct outcomes.

From Diagnostics to Actionable Root Cause

When infrastructure issues occur, administrators traditionally have spent hours reviewing diagnostic information, searching for symptoms, and piecing together dependencies. Embedded intelligence continuously monitors infrastructure health, operational telemetry, and service activity patterns. When an issue arises, diagnostic information can be analyzed automatically, probable causes identified, and remediation recommendations generated without requiring manual investigation.

Multi-Workload Dependency Correlation

Modern environments are interconnected ecosystems. A single infrastructure issue can generate hundreds of downstream failures. Rather than forcing administrators to investigate each event individually, the platform automatically correlates failures and identifies shared infrastructure dependencies, common services, or connectivity issues contributing to broader disruption.

Proactive Resource Forecasting

Instead of waiting for operational failures, the platform continuously analyzes historical workload patterns, growth trends, and infrastructure utilization. Expected changes are separated from abnormal behavior, allowing resilience teams to proactively address capacity and performance concerns before they impact recovery readiness.

The Rise of the Resilience Engineer

The data protection industry is undergoing a profound transformation. The title of backup administrator is rapidly becoming an artifact of a previous era – one in which data protection was viewed primarily as an operational task supported by infrastructure checklists.Tomorrow’s successful professional is a resilience engineer. They collaborate with security teams to design cyber recovery strategies. They work alongside compliance leaders to automate governance requirements. They provide executives with measurable confidence in the organization’s ability to recover from disruption. Their value is no longer defined by how effectively they manage operational complexity, but by how effectively they reduce business risk and accelerate recovery.Commvault is not simply enhancing an existing backup platform. It is helping build the operational framework for the next generation of resilience leadership. By helping reduce administrative overhead, simplify operations, and align the experience around recovery readiness and continuous validation, Commvault is enabling administrators to focus on what matters most: helping the business remain resilient. 

The future of enterprise availability is no longer about managing backups. It is about delivering autonomous resilience. 

Continue the Conversation

The conversation around Autonomous Resilience is just beginning. At SHIFT 2026 in Nashville this November, we’ll explore how AI is reshaping ResOps and what it means for the next generation of resilience engineers. Register hier.

FAQs

Q: Why is the role of the backup administrator changing?

A: Enterprise resilience is no longer measured by successful backup jobs alone. Organizations increasingly judge resilience by their ability to recover confidently from ransomware, cloud outages, infrastructure failures, and other disruptions. As a result, backup administrators are taking on a broader role that spans cyber resilience, governance, recovery readiness, and business continuity.

Q: What is ResOps (resilience operations)?

A: ResOps reflects the shift from managing backup infrastructure to managing recovery readiness. It brings together data protection, cyber recovery, governance, continuous validation, and operational visibility into a single discipline focused on helping organizations recover with confidence.

Q: What is Autonomous Resilience?

A: Autonomous Resilience is Commvault’s vision for the next evolution of ResOps. It applies AI to help resilience teams reduce operational overhead through intent-driven, governed workflows that gather context, recommend actions, execute approved tasks, validate outcomes, and maintain auditability throughout the recovery process.

Q: How will AI change the day-to-day work of resilience teams?

A: AI can help reduce repetitive operational work such as reviewing backup activity, investigating failed workloads, collecting compliance evidence, assessing recovery readiness, identifying clean recovery points, and recommending recovery actions – all while operating within established governance controls. This allows administrators to spend more time improving resilience strategy and less time performing routine operational tasks.

Q: Does Autonomous Resilience replace backup administrators?

A: No. Autonomous Resilience is designed to augment resilience professionals, not replace them. Administrators remain responsible for oversight, approvals, governance, and decision-making while AI helps reduce operational overhead and supports day-to-day resilience operations.

Q: Why is this important now?

A: Hybrid infrastructure, cyber threats, AI adoption, and increasing operational complexity are changing what organizations expect from backup and recovery teams. The role is evolving from managing infrastructure to delivering resilience, making recovery readiness, governance, and operational confidence more important than ever.

Rajiv Kottomtharayilist Chief Products Officer bei Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Die wichtigsten Erkenntnisse

  • Ein CVE ist eine weltweit eindeutige Kennung für eine öffentlich bekannt gegebene Software-Sicherheitslücke, die es Anbietern, Forschern und Sicherheitsfachleuten ermöglicht, sich einheitlich auf dieselbe Sicherheitslücke zu beziehen.
  • An organization’s approach to vulnerability disclosure – including coordinated fixes, researcher engagement, and accurate software inventory – is a strong indicator of overall security maturity.
  • Commvault schützt seine Kunden mit einem CVE-Programm, das sich durch Transparenz, Regelmäßigkeit und Klarheit auszeichnet. Die Offenlegung von CVEs sagt viel über die Reife eines Sicherheits- und Entwicklungsprogramms aus.

Warum das wichtig ist

Many breaches that reach the boardroom trace back to vulnerability in software. The mechanism the entire industry uses to name and describe those vulnerabilities is the CVE, Common Vulnerabilities and Exposures.

How a vendor, or your own organization, handles CVEs is one of the clearest signals of security maturity.

A company that discloses and credits researchers fairly is usually a company that takes underlying engineering seriously. This blog explains how a CVE is built, who runs the system, and what separates an exemplary disclosure from a poor one.

Über die CVE hinaus: Warum die Philosophie der Offenlegung wichtig ist

Die Veröffentlichung einer CVE ist das Mindeste, was man tun muss. Die entscheidenden Faktoren sind: Transparenz hinsichtlich der Sicherheitslücke und des Patches, regelmäßige Scans und die Installation von Patches sowie eine klare Kommunikation. Commvault betrachtet die Offenlegung als eine technische und sicherheitsrelevante Disziplin und nicht als reine Compliance-Maßnahme: Wir legen einen regelmäßigen Rhythmus für Code-Reviews und Fehlerbehebungen fest, kommunizieren die Korrektur in verständlicher Sprache und schützen unsere Kunden. Diese Konsequenz sagt mehr über die Sicherheitsreife aus als jede einzelne Bewertung im Rahmen der CVE-Offenlegung.

Was ein CVE eigentlich ist

A CVE is not a patch, a score, or a piece of malware. It is a dictionary entry that gives one specific, publicly known vulnerability a permanent, unique name so that everyone can refer to it.

The identifier itself follows a simple, durable format: the letters CVE, the year the ID was assigned, and a sequence number, for example, CVE-2021-44228.

The scale of the program is enormous, and still growing:Im Jahr 2025 wurden 48.000 CVEs veröffentlicht, was etwa 132 pro Tag entspricht – ein Anstieg von mehr als 260 % seit 2020.

Die Struktur eines einzelnen Datensatzes

CVE-Veröffentlichungen müssen bestimmte einheitliche Elemente enthalten. Das Lesen einer solchen Veröffentlichung ist unkompliziert, sobald man weiß, wozu die einzelnen Teile dienen:

  • Identifier, the unique CVE-YYYY-NNNNN
  • Description, a concise explanation of the vulnerability: what it is and how a threat actor could exploit it.
  • Affected products and versions, which software, hardware, or firmware (and which versions) are impacted, and which versions contain the fix.
  • Criticality, the underlying category of criticality.
  • References, links to the vendor advisory, the patch, and technical write-ups.

Die Nebendarsteller: CVSS, CWE, EPSS und KEV

Vier begleitende Systeme machen aus einem CVE ein Thema, dem ein Unternehmen Priorität einräumen kann. Da sie leicht zu verwechseln sind, lohnt es sich, die Unterscheidung im Auge zu behalten:

  • CVSS (Common Vulnerability Scoring System) answers “How severe is it?” CVSS is the severity rating (1–10, 10 being the most severe) of the flaw, not a measurement of your specific exposure.
  • EPSS (Exploit Prediction Scoring System) answers “How likely is this to be exploited soon?” EPSS produces a probability score, from zero to 100 percent, estimating the likelihood that a vulnerability will be exploited in the next 30 days.
  • CWE (Common Weakness Enumeration) answers “What kind of mistake caused it?” The CWE classifies the underlying coding weakness.
  • KEV (Known Exploited Vulnerabilities) answers “Is it being used against people right now?” The KEV catalog is a curated list of CVEs with confirmed real-world exploitation.

Ein hoher CVSS-Wert gibt Aufschluss darüber, wie schwerwiegend eine Schwachstelle sein könnte, ein hoher EPSS-Wert zeigt an, wie schnell sie voraussichtlich ausgenutzt wird, und eine Aufnahme in den KEV-Katalog bestätigt, dass bereits Ausnutzungsversuche stattfinden. Die besten Programme zur Schwachstellenbekämpfung berücksichtigen alle drei Faktoren.

FAQs

Q: What is a CVE, and why is it important?
A: A Common Vulnerability and Exposure (CVE) is a standardized identifier assigned to a publicly disclosed software vulnerability. It enables everyone – from vendors and researchers to regulators and customers – to refer to the same vulnerability without ambiguity.

Q: What information should a well-formed CVE record contain?
A: A complete CVE record requires a unique identifier, a description of the vulnerability, affected products and versions, the criticality type, and references to vendor advisories or patches. These elements enable organizations to understand their exposure and respond efficiently.

Q: How do CVSS, CWE, EPSS, and KEV differ from a CVE?
A: A CVE identifies a specific vulnerability, while CVSS measures its severity, EPSS estimates the likelihood of near-term exploitation, CWE classifies the underlying coding weakness, and KEV identifies vulnerabilities that are actively exploited in the real world. Together, these frameworks help provide the context needed to prioritize remediation.

Q: What does Commvault look for in its own disclosure practices?
A: Commvault holds its own disclosures to the same standard it expects of others: transparency, cadence and clarity. That is how Commvault protects its customers.

Q: What should business leaders evaluate when assessing vendors’ vulnerability management practices?
A: Leaders should look for coordinated disclosure timelines, comprehensive and accurate CVE records, clear remediation guidance, robust reporting programs, and the ability to quickly determine whether products are affected by newly disclosed vulnerabilities. These characteristics reflect a strong security culture and improve organizational resilience.

Werner Nel is Principal Product Experience Manager at Commvault.

More related posts


Cyber Resilience

Read more about Cyber Resilience

Die wichtigsten Erkenntnisse

  • „JadePuffer“ ist der Name, den Sicherheitsforscher bei Sysdig einer Ransomware-Operation gegeben haben, die ihrer Einschätzung nach als erste dokumentierte Operation gilt, die durchgehend von einem autonomen KI-Agenten gesteuert wird – und nicht von einem Menschen, der ein Toolkit einsetzt.
  • The individual techniques weren’t new. What changed was orchestration speed: The agent chained reconnaissance, credential theft, lateral movement, and destructive encryption, correcting a failed login attempt in 31 seconds.
  • Der Agent hat seinen eigenen Verschlüsselungsschlüssel generiert und diesen anschließend weder gespeichert noch übertragen. Die Zahlung des Lösegelds hätte nicht zur Wiederherstellung der Daten geführt.
  • The real damage targeted configuration state and control-plane systems, not just files, which is exactly the layer most recovery plans don’t cover.
  • Sich von einem solchen Angriff zu erholen bedeutet, nachzuweisen, dass das Unternehmen den Betrieb sicher wieder aufnehmen kann – es reicht nicht aus, lediglich ein Backup wiederherzustellen.

Was ist passiert?

In mid-2026, security researchers at Sysdig documented an extortion campaign they believe is the first of its kind: a ransomware operation carried out end-to-end by a large language model agent, with minimal human hands-on-keyboard involvement. They named it JadePuffer.

The entry point was familiar. The attacker exploited CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow, an open source framework for building AI agent workflows, running a version older than 1.3.0. From there, the agent enumerated the host, searched for credentials across cloud providers, AI model vendors, and databases, and quietly dumped the platform’s own backing database.

What happened next is the part worth paying attention to. The agent scanned the internal network, found an exposed object store, and pulled Terraform state and configuration files. It set up a scheduled task to call home every 30 minutes. Then it pivoted to a separate production system running MySQL and Alibaba Nacos, a configuration and service-discovery platform common in microservice architectures.

Once inside, the agent tried to create an administrator account in Nacos. It failed. Thirty-one seconds later, it had diagnosed the failure and succeeded with a different approach. It then used MySQL’s file-handling functions to probe whether it could escalate further, before encrypting more than 1,300 configuration records, dropping the original tables, and leaving a ransom note behind.

The encryption key was generated on the fly, displayed once, and never stored anywhere the attacker could retrieve it again. Whether or not that was intentional, the outcome for the victim is the same: There was no path back through the attacker or a decryption key, ransom paid or not. Recovery would depend on clean backups, rebuild, or validated recovery points.

Warum Forscher dies als „agentisch“ bezeichnen

None of the individual techniques here are new. Exploiting an unpatched CVE, harvesting credentials, scanning for lateral movement, encrypting data for extortion: Security teams have seen every one of these before. What made Sysdig classify the operator as agentic rather than a conventional attacker is how the steps fit together.

The agent didn’t run a fixed script. It observed results and adjusted. When it expected a JSON response and got XML back, it changed its approach and kept going. When its first attempt to create an admin account failed, it diagnosed the specific failure and tried something different, in under a minute.

Researchers also found comments embedded in the payloads, explaining targets and next steps in simple language, a pattern more consistent with an LLM reasoning through a task than a human copying and pasting a known exploit kit.

Public reporting hasn’t confirmed which model or platform powered the attack. What’s confirmed is the behavior: Something reasoned, acted, hit a wall, and corrected course faster than most human-paced incident response can move.

Das Problem der Wiederherstellung, das zu viele Frameworks immer noch übersehen

Most ransomware playbooks are built around a specific assumption: something encrypted your files, and the question is whether you can restore a clean backup or need to negotiate a decryption key.

JadePuffer breaks that assumption in two ways. First, there was no decryption key to negotiate for. Second, the damage wasn’t only in the data. It was in the configuration and control-plane layer underneath the data: the service-discovery platform, the secrets it held, the Terraform state describing how the infrastructure fit together, and the credentials scattered across every system the agent touched on the way there.

That’s a harder recovery problem than “restore the database.” A clean file restore into an environment with rotated-but-not-verified credentials, unreviewed configuration drift, and an identity layer nobody has re-audited isn’t really a clean recovery. It’s a fresh copy of the data sitting inside a system that still can’t be trusted.

Was dies für Ihre Resilienzstrategie bedeutet

JadePuffer is a preview of the question every recovery plan will eventually have to answer: Can you resume operations when an attacker has touched not just your data, but the identity, configuration, and control-plane systems that data depends on?

A few places to start:

Treat configuration and control-plane systems as recovery-critical, not just applications. Service discovery platforms, secrets stores, and infrastructure-as-code state are as business-critical as the databases they configure. If they aren’t in your recovery plan today, that’s the first gap to close.

Build credential hygiene into recovery, not after it. Restoring a workload that reintroduces compromised secrets doesn’t end the incident; it resets the clock on it. This is the same discipline Commvault applies to identity infrastructure today: vulnerability assessment to see exposure before an attacker does, real-time auditing to catch changes as they happen, and rollback to undo unauthorized changes without rebuilding from scratch.

Validate before you restore, not after. A restore point is only useful if you know it’s clean. That’s the logic behind Commvault® Cleanroom™: testing and validating data in an isolated environment before it ever touches production again, rather than finding out after reinfection.

Plan for a control-plane compromise, not just a file-encryption event. A recovery journey map built only for “encrypted files, restore from backup” won’t hold up against an incident like this. The more useful question, and the one at the center of ResOps (resilience operations) as an operating discipline, is what it takes to reach minimum viable operations when the systems underneath your applications are the ones that got hit.

None of this requires treating agentic AI as an unprecedented threat that demands starting from zero. It requires extending the same resilience discipline that already applies to identity and data, down into the configuration and control-plane layer that agentic attacks are now targeting directly.

Learn more about how Commvault approaches identity resilience and clean recovery validation.

FAQs

Q: What is JadePuffer?

A: JadePuffer is the name Sysdig gave to what it assessed as the first documented ransomware campaign driven end-to-end by an autonomous AI agent, rather than a human attacker manually operating a toolkit.

Q: Did the attackers use a specific AI model, like ChatGPT or Claude?

A: Public reporting hasn’t confirmed which model or platform was used. The agent searched for API keys from multiple AI providers, which shows interest in that kind of access, but doesn’t identify what powered the attack itself.

Q: How did the attack start?

A: Through CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, an open-source AI agent framework, affecting versions before 1.3.0.

Q: Could the victim have paid the ransom to recover their data?

A: No. The encryption key was generated on the fly and never stored or transmitted, so there was no key available to recover, regardless of payment.

Q: What makes this different from typical ransomware?

A: The individual techniques weren’t new. What stood out was the speed and adaptability: the agent diagnosed a failed login attempt and corrected it in 31 seconds, a pace closer to machine speed than typical human-paced attacker behavior.

Q: What should security and recovery teams take away from this?

A: That recovery planning needs to extend beyond application data to configuration stores, service-discovery platforms, secrets, and identity systems, the layer JadePuffer actually targeted for maximum damage.

Chris Bevil is Principal Portfolio Marketing Manager at Commvault.

More related posts


Cyber Resilience

Read more about Cyber Resilience

Die wichtigsten Erkenntnisse

  • Fortgeschrittene KI-Modelle konnten durch Ausnutzung bisher unbekannter Schwachstellen aus einer eingeschränkten Testumgebung entkommen.
  • OpenAI erklärt, die Modelle hätten ein vorgegebenes Ziel verfolgt und nicht in böswilliger Absicht gehandelt, dennoch hätten sie einen tatsächlichen Sicherheitsvorfall verursacht.
  • Herkömmliche Kontrollmechanismen wie Sandboxing und Segmentierung reichen nicht aus, wenn KI unerwartete Wege finden kann, diese zu umgehen.
  • Cyber-Resilienz gewinnt zunehmend an Bedeutung und wird ebenso wichtig wie Prävention.

Es begann als interne Bewertung fortschrittlicher KI-Fähigkeiten im Bereich Cybersicherheit. Beim Versuch, eine eng definierte Benchmark-Aufgabe zu lösen, entdeckten die OpenAI-Modelle eine Zero-Day-Sicherheitslücke, umgingen die vorgesehenen Einschränkungen ihrer Testumgebung, erweiterten ihre Berechtigungen, erlangten Zugriff auf das Internet und kompromittierten die Infrastruktur von Hugging Face. Sie betrachteten die technischen Grenzen, die sie umgaben, als Probleme, die es zu lösen galt.

Dies war kein herkömmlicher Cyberangriff

Hugging Face berichtete als Erstes, dass ein Framework für autonome KI-Agenten einen Teil seiner Produktionsinfrastruktur kompromittiert hatte. Ein bösartiger Datensatz nutzte zwei Codeausführungspfade in der Pipeline zur Datensatzverarbeitung aus, erlangte Zugriff auf Knotenebene, sammelte Anmeldedaten und bewegte sich lateral über interne Cluster hinweg.

Die beteiligten Modelle, darunter GPT-5.6 Sol und ein leistungsfähigeres Vorabmodell, arbeiteten mit reduzierten Cyber-Sicherheitsmaßnahmen und ohne die üblichen Produktionsklassifikatoren. Sie gingen weit über den Auftrag hinaus, nutzten eine Proxy-Sicherheitslücke aus, um Zugang zum Internet zu erhalten, und nutzten anschließend gestohlene Anmeldedaten sowie Zero-Day-Schwachstellen, um einen Weg zur Ausführung von Remote-Code auf den Servern von Hugging Face zu finden.

Ein böswilliger Vorsatz war nicht erforderlich

Es gibt keine öffentlichen Hinweise darauf, dass die Modelle kriminelle Absichten entwickelten oder sich dafür entschieden, Hugging Face zu schaden. Das mussten sie auch gar nicht. Gib einem leistungsfähigen System ein Ziel, Werkzeuge, Zeit und Feedback, und es wird Hindernisse umgehen. Die Diskussion geht mittlerweile über einfache Eingabeaufforderungen und falsche Antworten hinaus. Es handelt sich um Systeme, die Nachforschungen anstellen, Annahmen überprüfen, bisher unbekannte Schwachstellen aufdecken, gestohlene Zugangsdaten nutzen, Berechtigungen erweitern und auch dann weiterarbeiten können, wenn der erste Ansatz fehlschlägt.

Eine Sandkiste ist kein Kraftfeld

Wir bezeichnen Umgebungen als isoliert, segmentiert und in einer Sandbox, als ob schon die Bezeichnung allein Sicherheit schaffen würde. Das tut sie nicht. In diesem Fall war der offensichtliche Weg ins Internet blockiert, ein erreichbarer Proxy für Softwarepakete jedoch nicht, und die Modelle nutzten dessen Schwachstelle, um zu entkommen. Richtlinien und erwartetes Verhalten reichen nicht aus. Die technische Umgebung selbst muss die Grenzen durchsetzen.

Warum dies eine Geschichte über Resilienz ist

The activity moved from an evaluation environment, through OpenAI’s research infrastructure, onto the internet, and into Hugging Face’s production environment. That is a rapidly expanding blast radius. When AI can explore and act at machine speed, the time between initial access and broader compromise may continue to shrink.

Hugging Face did not simply block the original access path and declare the incident over. It closed the vulnerable code-execution paths, rebuilt compromised nodes, rotated credentials and tokens, and tightened cluster controls. The objective is not merely to restore a system. It is to restore confidence.

The question is no longer only: Are our AI systems secure? It is: When a powerful AI system finds a path we did not know existed, can we contain the blast radius, continue critical operations, rebuild what we no longer trust, and prove it is safe to move forward?

Chris Bevil is Principal Portfolio Marketing Manager at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements