Skip to content

Die wichtigsten Erkenntnisse

  • Advanced AI models like Claude Mythos Preview could dramatically accelerate vulnerability discovery, reshaping the cybersecurity landscape.
  • Projekt Glasswing highlights growing concerns about managing AI-enabled security risks at scale.
  • ResOps helps shift organizations from reactive defense to proactive resilience and recovery.
  • Cybersecurity tools focus heavily on prevention, while recovery capabilities remain underdeveloped.
  • In an AI-enabled world, the ability to recover quickly from disruption will define operational success.

Anthropic’s new Claude Mythos Preview modelis reportedly powerful enough to identify vulnerabilities in software systems in seconds. In early testing, the company claims the model was able to break out of its containment environment and email an engineer about the event.
Given these potential risks, Anthropic is limiting access to a small group of large organizations throughProjekt Glasswing. The goal: stay ahead of the security implications of a world where vulnerability discovery and exploitation may become trivial.
This shift strengthens the case for resilience operations (ResOps™). It could fundamentally change how organizations approach cybersecurity.
In a recent LinkedIn post, “The Beginning of the End of Cybersecurity,” Jen Easterly, CEO of RSAC and former director of CISA, argues that today’s cybersecurity industry is built to identify, defend against, and respond to software defects.
In effect, it compensates for gaps in software quality and secure development practices. If models like Claude Mythos Preview perform as described, their ability to surface vulnerabilities at scale could significantly disrupt today’s security tooling landscape.
A recent STRIVE episode – Evidence Over Hope: Will Your Recovery Plan Hold Up Under Pressure? – echoes this concern. Organizations have invested heavily in tools to prevent attacks, yet relatively little innovation exists “right of boom” – the capabilities required to recover the business when disruption inevitably occurs.

Why ResOps?

ResOps is an organizational discipline that embeds resilience into daily operations. It shifts organizations from passive, reactive backup strategies to an active, continuous model.
Traditional IT operations focus on efficiency. ResOps focuses on surviving failure. It brings together security, infrastructure, and operations teams around a common goal: Identify the organization’s minimum viable business – the critical systems, data, and processes required to operate – and enable those services to be restored quickly and cleanly after a disruption.
Most operational disciplines optimize for when systems work as expected. ResOps is designed for when they don’t. Its core question is simple: Can you recover each critical service right now – with confidence and evidence?

What Does the Future Hold?

If Easterly’s perspective proves accurate – that cybersecurity largely compensates for software defects – then technologies like Claude Mythos Preview represent more than incremental progress. They signal a structural shift in enterprise risk.
AI may help reduce the time between vulnerability discovery and remediation. It may even eliminate certain classes of software flaws. But it does not remove the risk of outages, misconfigurations, identity compromise, or cascading failures in complex systems. And it does not replace the operational discipline required to respond and recover.
Failure will still happen. That reality makes ResOps more important – not less. As prevention becomes more automated, resilience becomes the differentiator. Organizations will no longer be measured solely by their ability to block attacks. They will be measured by how effectively they recover – restoring critical services and trusted data under real-world conditions.
Cybersecurity aims to keep threats out. ResOps prepares you for when they get in. In an AI-accelerated world, the ability to survive and recover from failure may be the most important operational capability an organization can build.
Read more in our Readiness Report, Evidence Over Hope: The Executive Case for Resilience Operations, and learn more about theResOps disciplineauf derReadiverse.

FAQs

Q: What is Projekt Glasswing, and why does it matter?

A: Projekt Glasswing is an initiative by Anthropic to limit and study access to powerful AI models capable of identifying software vulnerabilities. It matters because it signals a future where vulnerability discovery becomes fast and widespread, increasing both defensive and offensive risks.

Q: What is ResOps, and how is it different from traditional IT operations?

A: ResOps is a discipline focused on enabling organizations to survive and recover from disruptions. Unlike traditional IT operations that prioritize efficiency, ResOps prioritizes continuity and rapid recovery of critical services.

Q: How could AI impact the future of cybersecurity?

A: AI may significantly reduce the time needed to detect and fix vulnerabilities, potentially disrupting existing security tools. However, it does not eliminate risks like outages or misconfigurations, making recovery capabilities even more important.

Q: Why is recovery becoming more important than prevention?

A: Despite heavy investment in preventive tools, disruptions still occur. As threats evolve and automation increases, organizations will be judged more on how quickly and effectively they can restore operations after an incident.

Q: What does “right of boom” mean in this context?

A: “Right of boom” refers to the phase after an incident has occurred, focusing on response and recovery. It highlights the gap in innovation around restoring business operations compared to preventing attacks.

Q: How can organizations start adopting ResOps?

A: Organizations can begin by identifying their minimum viable business – critical systems and data – and building processes to restore them quickly. This involves aligning security, IT, and operations teams around resilience-focused goals.

Jason Meserve is Director of Social Marketing at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • Rising operational disruption makes scalable resilience essential, but organizations commonly fall into traps like seeking “silver bullet” technology or relying on “hero worship” of individual experts.
  • ResOps bietet ein skalierbares Framework, das Mitarbeiter, Prozesse und Technologien in den Bereichen ITOps, SecOps und DevOps miteinander verbindet.
  • Die Unterstützung durch die Unternehmensleitung auf CEO-Ebene trägt dazu bei, die Verantwortlichkeit zu stärken und Resilienz als strategische Disziplin in den Vordergrund zu rücken.

Cyberattacks, cloud complexity, and AI-enabled threats are creating constant operational challenges for enterprises. To help meet business requirements in this increasingly disruptive environment, organizations need to move beyond separate recovery tools, teams, and plans to resilience as an integrated operating model.

In a recent webinar, Phil Goodwin, research vice president for IDC’s worldwide infrastructure programs, joined me for a fireside chat to explore how organizations can move beyond fragmented approaches to build resilience that scales.

Warum Unternehmen ein neues Rahmenkonzept für Resilienz benötigen

As organizations engage in daily firefighting while keeping up with new technologies and addressing new initiatives, they rarely have time to step back and reassess whether their approaches still meet requirements. But as isolated incidents become systemic disruption, this conversation has become essential.

In a simpler era, organizations focused primarily on backup and recovery. Large-scale disruptions such as Hurricane Sandy brought disaster recovery onto the agenda. Intensifying cyberthreats like ransomware added cyber resilience and business continuity to the list. Each evolution brought new capabilities, but many organizations simply bolted new approaches onto what they were already doing rather than addressing these expanding requirements holistically.

When separate teams manage different pieces with different tools and policies, gaps may emerge that can slow recovery. Despite years of investment in cybersecurity, organizations are still struggling with recovery.

More recently, AI has accelerated the urgency for a more integrated approach by reshaping both threats and defenses. Despite increasing AI investments, many businesses are delaying AI rollouts due to ongoing concerns about governance and security vulnerabilities.

On the other side of the cyber front, bad actors are using AI to create deepfakes, target users with more sophisticated and convincing phishing, and exploit vulnerabilities at scale.

Resilience operations – ResOps – treats resilience as a continuous operating discipline rather than a collection of separate tools and teams. By bringing together ITOps, SecOps, and DevOps under a unified framework, ResOps helps transform resilience to keep pace with systemic disruption.

Häufige Fehler bei der Resilienzplanung vermeiden

Even organizations that recognize the need for change often fall into traps. One is the “silver bullet” problem, which focuses on technology as the solution. Leaders want to believe that buying the right tools will solve everything, but technology alone can’t deliver positive business outcomes without proper integration and process.

“Hero worship” is another common pitfall – relying on talented staff members with expertise residing in their heads rather than in documented processes. Heroism can’t scale, and reliance on specific individuals creates vulnerability when people leave or responsibilities shift.

To move past these traps, you have to think differently about your operating model. Instead of focusing primarily on technology and people, consider the team you’ll need to build, including executive sponsorship, IT operations and security leadership, and senior leaders from the business side.

The team’s charter should focus on defining business outcomes first: What does resilience need to achieve for the organization? What KPIs, SLAs, and processes should be established to meet these requirements?

Aufbau von Resilienzmaßnahmen von oben nach unten

Da Resilienz eine Priorität auf Vorstandsebene darstellt, bedarf sie der Unterstützung durch die oberste Führungsebene. ResOps entfaltet seine größte Wirkung, wenn der CEO eingebunden ist, bei der Festlegung von Ressourcenprioritäten mitwirkt und die Verantwortlichkeit im gesamten Unternehmen fördert. Mit der Unterstützung der Führungsspitze können leitende Führungskräfte wie der CIO, der CTO, der CISO und die Geschäftsführer ihre Mitarbeiter mit der Umsetzung beauftragen.

Dieser Ansatz lässt sich auf Unternehmen jeder Größe anwenden. Selbst kleine und mittelständische Unternehmen können funktionsübergreifende Teams bilden, denen Vertreter aus dem Geschäftsbereich, IT-Teams sowie Mitarbeiter aus den Bereichen Datensicherheit und Netzwerksicherheit angehören. Mit zunehmendem Wachstum kann diese Struktur entsprechend angepasst werden, indem Personal in bestimmten Bereichen der Ausfallsicherheit hinzugewonnen wird, während ein integrierter Ansatz entlang der gesamten Kette der Ausfallsicherheitsmaßnahmen beibehalten wird. ResOps spiegelt wider, wie Teams aus den Bereichen IT-Operations, SecOps und DevOps innerhalb von Unternehmen zusammenarbeiten müssen. Datenwiederherstellung und Datensicherheit sind mittlerweile so eng miteinander verflochten, dass bei IDC Forscher aus diesen Disziplinen nun häufig bei Kundenprojekten zusammenarbeiten. Anwendungen müssen heute unter Berücksichtigung potenzieller Angreifer konzipiert werden, Zero-Trust-Architekturen integrieren und davon ausgehen, dass etwas schiefgehen wird. ResOps bietet den Rahmen für diese Konvergenz und vereint Sicherheits- und Betriebswerkzeuge in einem einheitlichen Modell, um Bedrohungen und Störungen aller Art zu begegnen.

ResOps als gemeinsames Branchen-Framework

ResOps is an operating model, not a product, and can benefit companies regardless of the specific tools they use. As Phil observed during our chat, “It really requires that community involvement where people pitch in from different perspectives, different vendors, different organizations, and different teams, just like DevOps or SecOps.”

For organizations struggling with constant disruption and the growing complexity of AI-enabled threats and defenses, ResOps offers a path beyond fragmented resilience approaches. By bringing together people, processes, and technology in a unified operating model, ResOps turns fragmented recovery efforts into enterprise-wide readiness.

Watch my vollständiges Kamingespräch mit Philan, um zu erfahren, wie ResOps Ihnen dabei helfen kann, eine skalierbare Unternehmensresilienz aufzubauen.

FAQs

F: Was ist Resilience Operations (ResOps)?

A: ResOps ist ein Betriebsmodell, das IT-Betrieb, Sicherheitsmanagement und DevOps zu einem durchgängigen Prozess integriert. Anstatt Disaster Recovery, Cyber-Resilienz und Geschäftskontinuität als separate Bereiche zu betrachten, vereint ResOps Menschen, Prozesse und Technologie unter einem einheitlichen Rahmenwerk, um eine skalierbare Unternehmensresilienz zu schaffen.

F: Warum ist die Unterstützung durch die Führungsspitze für die Cyber-Resilienz wichtig?

A: Executive sponsorship – ideally at the CEO level – helps drive accountability and priority for resilience initiatives across the organization. This top-down support is essential for organizations trying to move beyond fragmented approaches to integrated resilience operations.

F: Können kleine und mittelständische Unternehmen ResOps einführen?

A: Ja. ResOps lässt sich auf Unternehmen jeder Größe anwenden. Das Rahmenwerk passt sich in seiner Komplexität dem Wachstum der Unternehmen an, sodass es für mittelständische Firmen zugänglich ist und gleichzeitig für Großunternehmen effektiv bleibt.

F: Warum müssen IT- und Sicherheitsteams zusammenarbeiten, um die Widerstandsfähigkeit zu gewährleisten?

A: Wenn IT-Betriebs-, Sicherheits- und DevOps-Teams zusammenarbeiten, anstatt isoliert voneinander zu agieren, können Unternehmen dazu beitragen, eine widerstandsfähigere Infrastruktur aufzubauen, um den sich ständig wandelnden Bedrohungen zu begegnen.

F: Wie sollten Unternehmen mit Resilienzmaßnahmen beginnen?

A: Beginnen Sie ganz oben, indem Sie sich die Unterstützung der Führungsspitze auf CEO-Ebene sichern. Bilden Sie anschließend ein funktionsübergreifendes Team, das Vertreter aus den Bereichen IT-Betrieb, SecOps und dem Geschäft umfasst, und lassen Sie dieses Team definieren, welche geschäftlichen Ergebnisse die Resilienz für Ihr Unternehmen liefern muss. Führen Sie eine Bedrohungsanalyse durch, um die Risiken zu erfassen, denen Sie begegnen müssen. Erst nach diesen grundlegenden Schritten sollten sich Unternehmen auf die Auswahl von Technologien und die Entwicklung detaillierter Prozesse konzentrieren.

Chris Mierzwa ist Senior Director für Portfoliomarketing bei Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Hinweis: Dieser Blogbeitrag wurde ursprünglich im Oktober 2025 veröffentlicht, als „Data Rooms“ eingeführt wurde. Er wurde aktualisiert, um die nächste Entwicklungsstufe, „Data Activate“, zu berücksichtigen.

Die wichtigsten Erkenntnisse

  • Data Activate is part of Commvault’s next-generation AI capabilities – alongside „AI Protect“und„AI Studio“ – angekündigt to help organizations activate AI safely, govern AI agents,undbuild agentic workflows from Commvault Cloud.
  • Data Activate ist so konzipiert, dass Sie Backup-Daten in zuverlässige, KI-fähige Ressourcen umwandeln können und gleichzeitig die Einhaltung von Governance- und Compliance-Vorgaben gewährleisten.
  • Das Angebot verbindet Datenschutz und KI-Aktivierung, ohne neue Sicherheitsrisiken zu schaffen oder platform weitere platform zu erfordern.
  • Es lässt sich mithilfe offener Standards wie Apache Parquet und Iceberg in bestehende KI-Ökosysteme wie Microsoft Azure und Snowflake integrieren.
  • Integrierte Governance-Funktionen ermöglichen die sichere Pflege, Klassifizierung und Weitergabe von Daten innerhalb einer Zero-Trust-Architektur.
  • Durch die Aktivierung historischer Daten können Unternehmen dazu beitragen, KI-Innovationen, Analysen und Compliance-Workflows sicher zu beschleunigen.

AI innovation depends on data – but not just any data. It depends on trusted, governed,undaccessible data. Yet for most enterprises, the data that could fuel AI lives deep within backups, scattered across environments,undwrapped in compliance constraints. That’s where Commvault’s Data Activate offering, previously known as Data Rooms, comes in.

KI sicher beschleunigen

Data Activate ist nebenangekündigt as part of its next-generation AI platform – alongside „AI Protect“und„AI Studio“. As organizations race to adopt AI, many are running into a fundamental challenge: their data is fragmentedunddifficult to use. According to a recent survey, 68 % der Unternehmen cite data silos as their top concern.

Commvault’s Data Activate offering helps transform backup data – one of the most completeundtrusted datasets an organization owns – into AI-ready assets. Data Activate helps enterprises safely connect their data to AIundanalytics platforms, without creating new risks or complexity.

Unlike earlier bulk export approaches, Data Activate can regularly publish updated datasets, making it easier to keep AI pipelines in sync with the most current trusted data. Teams also can identifyundexclude sensitive data – such as personally identifiable information – before activating datasets for analytics or model development.

The Data Activate offering is not another AI platform. It’s the bridge between data protectionunddata activation, designed to make your existing AI investments work fasterundsafer. It does this by creating governed, policy-controlled “rooms” inside Commvault Cloud – spaces where data can be classified, curated,undshared with AIundanalytics tools without leaving the protection boundary.

Auf Kunden hören: Schluss mit Platform

We heard customers loudundclear: You don’t need another AI platform. You need a protected, simple way to use the data you already maintain – across the AI toolsundecosystems you’ve already chosen.

That’s why Commvault built Data Activate to integrate with partners like Microsoft AzureundSnowflake using open-standard formats such as Apache ParquetundIceberg. This helps you keep your data portable, policy-compliant,undready for activation – wherever your AI strategy takes you.

den traditionellen „Extract, Transform, Load“ („ETL“)-Workflow nach wie vor zeitaufwändig und kann Compliance-Risiken mit sich bringen, wenn er nicht ordnungsgemäß geregelt wird.

With Data Activate, authorized users can discover, classify,undprepare data directly from backup repositories – across on-premisesundcloud environments. Built-in governance helps maintain control, allowing only approved datasets to be shared, with automated classification, sensitivity tagging, redaction,undaudit trails applied every step of the way.

Data Activate acts as a governed, policy-controlled workspace inside Commvault Cloud – where data can be curatedundmade available to AI or analytics tools without leaving the protection boundary. This governed design provides a protected bridge between backup dataundactivation workflows, helping organizations unlock their information for innovation while being able to maintain complianceundcontrol.

„Data Activate“ kann Ihnen dabei helfen:

  • Accelerate insights: Quickly findundexport historical data in AI-friendly formats to train models or power analytics.
  • Simplify operations: Eliminate brittle ETL pipelines with automated data discoveryundcuration.
  • Maintain compliance: Keep governance intact with policy-based controlsundtraceability from backup to activation.

Vertrauen als Grundlage für verantwortungsvolle KI

In der Eile, KI einzuführen, wird Vertrauen oft zum Kollateralschaden. Laut einer aktuellenStudie, roughly three-quarters of surveyed IT leaders said that using AI could make their organizations more vulnerable to cyberattacks. That’s why Commvault built Data Activate within Commvault Cloud’s zero-trust architecture, complete with encryption, RBAC,undcompliance support.

By combining data protection, governance,undactivation in one platform, Commvault enables enterprises to accelerate AI innovation without compromising data security, compliance, or control.

Innovation beschleunigen, ohne Risiken einzugehen

Commvault’s Data Activate offering helps organizations move faster by making data safely accessible to the tools that drive their business forward – from AI model training to analytics, eDiscovery,undcompliance support automation. Because when backup data becomes usable data, enterprises unlock years of historical intelligenceundcontext that most AI models simply don’t have.

As Pranay Ahlawat, Commvault’s Chief TechnologyundAI Officer, said: “Organizations are beginning to realize that their historical data is more than just insurance – it’s a powerful, untapped strategic asset. With Commvault Data Activate, enterprises can confidently export their secondary dataundharness it with the AI platform of their choice to unlock new opportunities for intelligence, innovation,undbusiness growth.”

Warum es jetzt wichtig ist

Commvault’s Data Activate offering redefines what’s possible for enterprises that want to innovate responsibly. They make it possible to move from protecting data to activating data – safely, flexibly,undat scale.

In short: Commvault isn’t building another AI platform. We’re building the foundation that lets every AI platform work better – because when data is protected, trusted,undready for activation, innovation happens faster.


FAQs

Q: What is Commvault’s Data Activate offering?
A: Commvault Data Activate is a capability within Commvault Cloud that helps enterprises safely discover, classify,undactivate backup data for AIundanalytics. It supports open formats like Apache IcebergundParquetundis built on a zero-trust, governed architecture for controlled, self-service data access.

Q: How does Data Activate differ from other AI data solutions?
A: Most AI data prep tools work only on live or production data, creating complianceundcost challenges. Data Activate works from backup data – data that’s already protectedundgoverned – bringing a unique balance of accessibility, compliance support,undtrust. It’s built into Commvault Cloud’s policy-controlled environment, so it’s part of a unified cyber resilience platform. Data Activate also regularly publishes updated datasets – rather than relying on one-time bulk exports – helping keep AI pipelines current without manual intervention.

Q: What benefits do organizations gain from using Data Activate?
A: Organizations can accelerate AIundanalytics insights, simplify data operations by reducing ETL complexity,undmaintain compliance through automated classification, tagging,undauditing processes.

Q: How does Data Activate support data securityundcompliance?
A: Data Activate operates within Commvault Cloud’s zero-trust architecture, applying classification, redaction,undaudit-friendly controls automatically. It helps maintain data privacy, traceability,undcompliance throughout the data lifecycle, aligning with internalundregulatory governance standards.

Q: What types of AI or analytics platforms can connect with Data Activate?
A: Data Activate integrates with leading cloudundAI partners such as Microsoft AzureundSnowflake, supporting open-standard data formats like Apache ParquetundIceberg for maximum flexibilityundportability.

Q: Why is this offering important for enterprises today?
A: As organizations accelerate AI adoption, Data Activate enables them to responsibly unlock the value of historical, protected data – fueling innovation while helping maintain trust, compliance,undcontrol.

Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • Die zunehmende Verbreitung von Agenten stellt ein Governance-Risiko dar. Mit der zunehmenden Verbreitung von KI-Agenten können eine lückenhafte Transparenz und unzusammenhängende Wiederherstellungsabläufe zu erheblichen operativen Risiken führen.
  • AI Protect vereint die Erkennung, Überwachung und die schrittweise Wiederherstellung von Agenten und deren Abhängigkeiten plattformübergreifend in einer einzigen, agentenorientierten Oberfläche.
  • AI Protect wird so konzipiert sein, dass es nicht nur prüft, ob Ressourcen geschützt sind, sondern auch dazu beiträgt, den Agent-Stack zu schützen und Risiken zu identifizieren, je nachdem, auf welche Ressourcen die Agenten zugreifen und welche Aktionen sie ausführen.
  • AI Protect will be built on Commvault’s resilience platform – meaning recovery can be tied directly to agent-initiated impact across both data and environments.
  • AI Protect will be part of a broader platform that supports the AI resilience lifecycle – from safely activating data to governing, building, and recovering agentic workflows.

AI agents are no longer a future-state experiment. They’re running in production environments today – querying data, triggering workflows, and making decisions at machine speed. For most enterprises, that’s happening faster than governance frameworks can keep up.

The problem isn’t enthusiasm for AI. It’s the gap between deploying agents and actually knowing what those agents are doing, what data they’re touching, and what to do when something goes wrong. That gap is what Commvault AI Protect will be designed to close.

Das Governance-Problem im Kern der agentenbasierten KI

As organizations scale their AI investments, a new class of operational risk is emerging. AI agents aren’t just tools – they’re autonomous actors that can access sensitive data, interact with critical systems, and trigger cascading changes. Without a clear way to discover, monitor, and govern them, IT and security teams may be flying blind.

The symptoms are familiar:

  • Lückenhafte Transparenz: Die APIs von Hyperscalern und Observability-Tools bieten nur partielle, isolierte Einblicke in die Aktivitäten der Agenten. Es gibt keine einheitliche Übersicht, die das Verhalten der Agenten plattformübergreifend mit Datensicherheit, Risiken und Wiederherstellung verknüpft.
  • Fehlender Schutzkontext: Datenschutzteams können nicht ohne Weiteres feststellen, ob die von KI-Agenten bearbeiteten Daten ausreichend geschützt oder wiederherstellbar sind.
  • Schwache Risikosignale: Die Aktivitäten von Agenten können enorme Mengen an Telemetriedaten erzeugen, doch ohne eine Verknüpfung zwischen Identität, Zugriff und Auswirkungen bleibt die Unterscheidung zwischen harmloser Automatisierung und risikoreichem Verhalten eine manuelle Aufgabe.
  • Wiederherstellung ohne Verbindung: Wenn von Agenten ausgelöste Änderungen zu Problemen führen, kann die Ermittlung der Auswirkungen und die Einleitung der Wiederherstellung eine manuelle Korrelation zwischen verschiedenen Tools erfordern, was die Zeit bis zur Lösung verlängert.

Wir stellen vor: Commvault AI Protect

AI Protect will be designed to offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents – across enterprise, SaaS, and cloud environments. It will extend Commvault’s existing discovery, protection, and recovery capabilities with agent-centric context, helping teams operate AI agents safely and recover quickly when issues arise.

Entdecken Sie: Eine zentrale, verlässliche Übersicht über alle Agenten

AI Protect will be designed to discover AI agents (and their dependencies) operating across connected environments on a recurring basis, helping maintain a unified, up-to-date inventory based on configurable discovery cadence. Each agent record will capture its execution environment and the data sources, models, configurations, applications, and infrastructure it interacts with. It will help provide a complete, cross-environment picture of what’s running and what it touches.

Schützen: Deckungslücken schließen, bevor sie zu Vorfällen führen

AI agents interact with sensitive data and systems, but traditional protection tools don’t evaluate coverage in the context of agent behavior. AI Protect will be designed to surface protection status for every agent-touched asset – protected, partially protected, or not protected – and help identify gaps introduced by agent activity. Where gaps exist, it will offer recommended actions and protection workflows to enable teams to close them.

Monitor: Telemetriedaten in umsetzbare Risikosignale umwandeln

AI Protect will ingest agent activity from existing audit, event, and telemetry sources and present it in agent-centric context – not as raw logs. A time-ordered activity timeline will show what each agent has done and when, and risk signals will be automatically flagged and categorized when agents access sensitive data, interact with unprotected assets, or exhibit unusual patterns. This will help teams move from reactive triage to proactive awareness.

Wiederherstellung: Geführte Wiederherstellung, direkt mit dem Einfluss des Agenten verknüpft

When an agent-initiated change causes an issue, AI Protect will surface recovery point availability for impacted assets and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery will be scoped directly to the agent’s impact, not generic incidents, and every action will be time-stamped.

In addition, teams will be enabled to recover the full AI stack – not just the model, but the connected data, configurations, and underlying systems that support it – helping restore the entire environment to a known good state with a single, guided action.

Teil einer umfassenderen Vision für die Widerstandsfähigkeit künstlicher Intelligenz

AI Protect wird eine von drei Funktionen sein, die Commvault als Teil einer umfassenderen platform angekündigt hat. DataDaten aktivieren enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Studio will enable enterprises to deploy ready-made agents and build custom ones – without writing code. Using a natural language–based Agent Builder, administrators will be able to describe operational intent in plain language, review the proposed workflow, refine it, and deploy it as a governed custom agent from a single interface. AI Studio will be designed to leverage Commvault’s MCP server and integrate with other enterprise applications via MCP, enabling workflows to extend smoothly across systems.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


FAQs

Q: What is Commvault AI Protect?

A: AI Protect is slated to be a governance and resilience solution for AI agents operating across enterprise, SaaS, and cloud environments. It will be designed to automatically discover agents and dependencies, surface protection gaps for the assets they touch, monitor and provide guided recovery workflows when agent-initiated changes cause issues.

Q: How will this be different from general AI observability or monitoring tools?

A: Most observability tools surface telemetry but stop short of connecting agent activity to data protection and recovery. AI Protect will be designed to correlate agent behavior with protection coverage and recovery readiness, and when something goes wrong, provide a guided path to help restore data, configurations, or systems impacted by agent activity.

Q: What environments will AI Protect support?

A: AI Protect will be designed to work across hyperscaler environments (AWS, Azure, Google Cloud), SaaS platforms, and internal enterprise systems – offering a unified, cross-environment view of agent activity and impact.

Q: How will AI Protect identify risk?

A: Risk signals will be derived by correlating agent activity with data access patterns, sensitivity of assets involved, and protection coverage. Rather than raw log analysis, AI Protect will present risk in agent-centric context – flagging specific agents and interactions that warrant attention, along with the reason they were flagged.

Q: How will recovery work?

A: AI Protect will surface recovery point availability for assets impacted by agent activity and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery actions will be scoped to agent-initiated impact and will be fully auditable.

Q: How will AI Protect relate to AI Studio and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate governs how data is prepared and activated for AI use. AI Protect will govern agents operating in production. AI Studio will enable teams to build and manage custom agentic workflows. Together, they will form an end-to-end AI resilience lifecycle.

Teja Medasani is Principal Product Manager at Commvault and Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Commvault Cloud Compliance

Read more about Commvault Cloud Compliance

Die wichtigsten Erkenntnisse

  • AI Studio soll die Lücke zwischen experimentellen Ansätzen und skalierbarer KI-Automatisierung auf Produktionsniveau schließen.
  • Die Agent-Bibliothek bietet Unternehmen an einem zentralen Ort einen Überblick über alle Standard- und benutzerdefinierten Agenten, einschließlich klarer Beschreibungen, Kategorien und des Aktivierungsstatus.
  • The Agent Builder will make customization accessible. Natural-language inputs will be able to generate structured, reviewable workflows – no coding required, no black-box behavior.
  • Die gesamte Logik der Agenten wird vor der Bereitstellung sichtbar gemacht und explizit gespeichert, wodurch die Anforderungen des Unternehmens an Transparenz und Nachvollziehbarkeit erfüllt werden.
  • AI Studio will be part of an end-to-end platform. Combined with Data Activate and AI Protect, it will be built to support the AI resilience lifecycle.

AI automation promises enormous operational value. But for most enterprises, moving from pilot to production can be harder than expected – especially when it comes to operational workflows like backup, recovery, and incident response. Governance concerns, lack of visibility, and the complexity of stitching together tools can often prevent AI from being used in real, day-to-day resilience operations.

What organizations need is a way to apply AI directly to these workflows – safely, with control, and in a way that fits how resilience teams actually operate. That’s what Commvault AI Studio will be designed for.

Warum die KI-Automatisierung in der Pilotphase ins Stocken gerät

McKinsey’s State of AI in 2025 report reveals that 88% of organizations use AI in at least one business function – yet only about one-third have reached scaled adoption beyond early pilots. The barriers are consistent across industries:

  • Limited visibility and control over which agents exist, what they do, and where they’re active – making it difficult for IT and data security teams to oversee operational workflows.
  • High friction to customize automation – teams can be forced to rely on manual scripting or external services to adapt built-in capabilities to real workflows, slowing adoption and limiting ROI.
  • Concerns about trust and governance – without transparency, explainability, and auditability, enterprises can’t confidently move agents from experimentation into production.

As a result, organizations either underutilize AI capabilities or rely on manual processes for tasks that could be automated safely – leaving real efficiency and resilience gains on the table.

Wir stellen vor: Commvault AI Studio

AI Studio is slated to be Commvault’s answer to the governance-adoption gap. It aims to provide a centralized interface where enterprises can view and manage all agents, deploy ready-made agents, and build custom agents using a workflow-based approach that helps keep behavior visible, auditable, and under control.

Agentenbibliothek: Ein klarer Überblick über alle Agenten in Ihrer Umgebung

Dasisieren und so will be the entry point to AI Studio. It will present a structured inventory of every agent available in the environment – both default agents built by Commvault and custom agents created by the customer – grouped by type and showing each agent’s name, category, description, and enabled status at a glance.

Default agents include Commvault’s foundational cyber resilience agents, such as Arlie Advisor, Arlie Data Sense, Arlie Recover, among others. The isieren und so will offer teams a single, authoritative view of their resilience agent ecosystem before taking any action.

Agentenverwaltung: Operative Steuerung für jeden Agenten

Selecting any agent from the library will open a dedicated detail view that can help provide transparency into how that agent operates – its purpose, how it’s triggered, what data it uses as inputs, execution limits, and basic usage telemetry.

This view will also include records of agent activity and events. Following this, administrators can enable or disable the agent with a single action. This will apply consistently to both default and custom agents, so every agent in the environment can be subject to the same governance standard.

Agent Builder: Von der Absicht in Alltagssprache zum geregelten Workflow

AI Studio’s Agent Builder will enable administrators to create custom agents by leveraging Commvault’s workflows and MCP server – without writing code.
Dasexperience will start with natural language. An administrator will be able to describe what they want to automate – for example: “I need an agent that detects when storage or infrastructure issues are starting to impact backups and helps resolve them before they affect SLAs.”


Dassystem will be designed to translate that intent into a structured agent configuration, including triggers, conditions, and actions, with optional AI-enabled steps from Arlie – such as Summarize, Generate Recommendation, or Draft Notification – available as explicit workflow steps.
Dasadministrator will be able to review the proposed workflow, adjust it as needed – changing trigger frequency, specifying a distribution list, or reordering steps – and save it. The result will be an auditable custom agent that appears in the isieren und so and can be managed through Agent Management like any other agent.

Teil einer umfassenderen Vision für die Widerstandsfähigkeit künstlicher Intelligenz

AI Studio wird eine von drei Funktionen sein, die Commvault als Teil einer umfassenderen platform angekündigt hat. DataDaten aktivieren enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Protect will offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents operating across enterprise, SaaS, and cloud environments – helping teams operate agents confidently and recover quickly when something goes wrong.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


FAQs

Q: What is Commvault AI Studio?

A: AI Studio will be Commvault’s centralized platform for deploying, building, and managing AI agents. It will include an isieren und so for viewing all agents in the environment, Agent Management for operational control, and an Agent Builder for creating custom agents using workflow-based automation – all without writing code.

Q: Who will AI Studio be designed for?

A: AI Studio will be built for Commvault administrators and IT operators who want to automate operational tasks – like monitoring backup job failures or notifying stakeholders – without relying on manual scripting or external development resources.

Q: How will the Agent Builder work?

A: Administrators will be able to describe their automation intent in plain language. AI Studio will then be able to propose a structured workflow with explicit triggers, conditions, and actions. The administrator can then review, edit if needed, and save the workflow as a custom agent. The resulting agent will be visible, auditable, and managed through the same interface as all other agents.

Q: Can AI be incorporated into custom agents?

A: Yes – but intentionally. AI will be invoked deliberately, not invisibly embedded in agent behavior.

Q: What default agents are available out of the box?

A: AI Studio will launch with a library of default agents across foundational AI and cyber resilience categories, including Arlie Data Sense, Arlie Advisor, and Arlie Recover.

Q: How will AI Studio relate to AI Protect and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate helps govern how data is prepared and activated for AI use. AI Protect will help govern agents operating in production. AI Studio will help teams deploy and build custom agentic workflows. Together they will form an end-to-end AI resilience lifecycle.

Teja Medasaniist Principal Product Manager bei Commvault undVir Choksiist Principal Product Marketing Manager bei Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • Apache Iceberg hat sich zu einem wichtigen Format für Data Lakehouses entwickelt, und viele AWS-Kunden migrieren von durch Glue verwalteten Iceberg-Tabellen zu vollständig verwalteten Amazon S3-Tabellen, um eine bessere Leistung und Automatisierung zu erzielen.
  • Clumio ermöglicht einen reibungslosen, Iceberg-konformen Migrationsprozess, der dazu beiträgt, Datenintegrität, Metadaten und Versionshistorie zu bewahren und gleichzeitig einen luftisolierten, unveränderlichen Schutz bietet.
  • Die platform die Migration mithilfe eines einfachen Backup- und Wiederherstellungs-Workflows und trägt so dazu bei, den Bedarf an benutzerdefinierten Skripten oder manuellen Konfigurationen zu verringern.
  • Im Vergleich zu manuellen oder nativen AWS-Migrationsmethoden bietet Clumio eine schnellere, skalierbarere und ausfallsichere Option für die Modernisierung von Data Lakehouses in Unternehmen.
  • Clumio’s collaboration with AWSundavailability in the AWS-Marktplatz enable organizations to modernize data lakes securelyundconfidently.

AIundlatency-sensitive analytics workloads increasingly depend on data lakehouses as their underlying data architecture. Among AWS customers building these environments, Apache Iceberg has become one of the fastest-growing table formats on Amazon S3, providing the transactional consistency, schema evolution,undperformance needed for modern analytics.AWS customers manage Iceberg tables today through the AWS Glue Data Catalog or adopt AWS’s fully managed option, Amazon S3 Tables, to streamline operationsundimprove performance.As AWS customers evaluate the growing importance of their Iceberg-based data lakehouses, considerations around protection, resilience,undmigration to Amazon S3 Tables naturally become part of that planning. Many teams are now looking for a simple, reliable way to move from Glue-managed Iceberg tables to S3 Tables while strengthening the protection of these critical datasets.As AWS’s 2025 Global Storage Partner of the Year, Commvault baut seine Zusammenarbeit mit AWS weiter aus, um Kunden bei der Modernisierung, dem Schutz und der Optimierung ihrer cloud-nativen Daten zu unterstützen.DurchClumio, Commvault bietet eineEine „Iceberg“-kompatible, luftisolierte Lösung zur Stärkung der Cyber-Resilienz für AWS –undnow helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while enabling long-term protectionundrecovery. You can start your free trial in the AWS-Marktplatz.

Die Herausforderung: Begrenzte Möglichkeiten für die Migration zu S3-Tabellen

Unternehmen prüfen zunehmend die Migration von durch Glue verwalteten Iceberg-Tabellen zu vollständig verwalteten Amazon S3-Tabellen, um die Leistung ihres Data Lake zu verbessern und den Betrieb zu vereinfachen. Laut AWS können S3-Tabellen bis zu3-mal schnellere Abfrageleistung und bis zu 10-mal mehr Transaktionen pro Sekunde compared to Iceberg tables stored in general purpose S3 buckets.Many teams also want to offload undifferentiated heavy lifting – such as compaction, snapshot management,undunreferenced file cleanup – while reducing overall storageundquery costs.However, existing AWSundcommunity guidance, such as AWS’s migration framework, outlines a manual, multi-step process requiring custom scriptingundorchestration. Migrating data while maintaining schema, metadata,undversion history can be time-consumingunderror-prone,undmost current approaches focus on replication rather than Iceberg-aware recovery or rollback.Clumio’s migration support for Apache Iceberg tables provides the Iceberg-aware, enterprise-grade migrationundresilience capability that modern data lakehouses have been missing. Demo anfordern to see how Clumio streamlines your migration.

Wie Clumio Migration und Datensicherheit vereinfacht

Clumio für Apache Iceberg auf AWS helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while simultaneously enabling long-term protection for these modern data lakehouse assets.The same Iceberg-aware platform provides air-gapped, immutable backups, isolated recovery points, point-in-time or snapshot-level restores,undretention capabilities that help support compliance requirements – extending Commvault’s leadership in cloud-native cyber resilience.Migrationundprotection work hand in hand:

  • Helfen Sie mit, die im AWS Glue Data Catalog registrierten Iceberg-Tabellen zu schützen.
  • Als vollständig verwaltete Amazon S3-Tabellen wiederherstellen.
  • Continue helping protect those Iceberg tables with Clumio’s cyber resilience capabilities.

Für Teams, die eine „Infrastructure-as-Code“-Bereitstellung bevorzugen,Clumiobietet eine öffentlich zugänglicheTerraform-Modul that supports Apache Iceberg.As AWS customers adopt Amazon S3 Tables, protecting these modern data assets becomes even more important. Threat vectors such as Ransomware, versehentliches Löschen, böswillige oder irrtümliche Änderungen sowie die Kompromittierung von Konten können KI- und Analyse-Pipelines stören und zu kostspieligen Nachbearbeitungen führen. Clumio hilft Kunden dabei, diese Risiken zu minimieren, indem esunveränderliche, Air-Gap-Backupssowie flexible Recovery-Optionen über Konten, Regionen, Snapshots und Zeitpunkte hinweg. Einen ausführlicheren Einblick, warum Data Lakehouses einen speziell darauf zugeschnittenen Schutz benötigen, finden Sie unterSchließung der Lücke beim Schutz von Data Lakehouse.

How It Works – From Backup to Restore

The migration process using Clumio follows a straightforward backup-and-restore workflow, designed to minimize effortundhelp maintain Iceberg table integrity.Step 1: Connect with the Commvault team for migration program reviewundapproval. Please Kontakt.Step 2: Discoverundback up Iceberg tables registered in the AWS Glue Data Catalog, with underlying data stored in S3, using Clumio.Step 3: Restore Iceberg table backups – whether the full snapshot history, a selected subset, or a specific point-in-time version – as Amazon S3 Tables in any account or region.Step 4: Enable incremental backups to maintain protection for your new Amazon S3 Tables.Clumio’s architecture helps reduce the need forundhelps provide transactionally consistent Iceberg recovery across accounts, regions,undsnapshots.To see the full migration workflow in action – including Iceberg discovery, backup selection, snapshot options,undrestoration to Amazon S3 Tables – watch the demo video embedded below. It walks through the entire backup-and-restore flow end to end, showing how Clumio handles the data, metadata,undsnapshot migration with no manual configuration required.

Vergleich von Migrationsoptionen

Most migrations to Amazon S3 Tables today depend on manual scripts or native tooling. Here’s how those methods compare against Clumio’s Iceberg-aware approach.

Methode Beschreibung Wichtige Überlegungen
DIY-Skripte/
Open-Source-Tools
Benutzerdefinierte Skripte, die die Athena- oder Glue-APIs zum Kopieren von Daten und Metadaten nutzen Am besten geeignet für Teams mit Skript-Kenntnissen und individuellen Migrationsanforderungen
Native AWS-Prozesse/
Snapshots
In der AWS-Dokumentation und in Community-Anleitungen werden Snapshot-basierte oder abfragegesteuerte Migrationen beschrieben Geeignet für Teams, die native AWS-Dienste nutzen und mehrstufige Migrationsprozesse verwalten
Clumio SaaS, Iceberg-kompatible Backup- und Wiederherstellungslösung für AWS Einfacher, Iceberg-kompatibler Migrationsworkflow, der dabei hilft, Metadaten und die Herkunft von Snapshots zu bewahren und gleichzeitig eine kontinuierliche Datensicherung zu integrieren

Demo anfordern to learn how Clumio simplifies migration at scale.

Warum dies für AWS-Kunden wichtig ist

As AWS customers modernize their data lakehouses, they need a simple, scalable way to migrate Iceberg tables to Amazon S3 Tablesundprotect them against operationalundcyber risks. Clumio delivers this by providing Iceberg-aware migration along with air-gapped, immutable protection.AWS is working with Commvault to help customers use Clumio for both protectionundmigration to Amazon S3 Tables. The solution is available today in the AWS-Marktplatzundsupports Iceberg tables across both Glue-managedundfully managed S3 Tables environments. Together, CommvaultundAWS provide enterprises with a simple, scalable way to modernize their AI data pipelines.For organizations looking to strengthen resilience across the broader AWS data stack, see our blogs on Schutz von Amazon S3-Daten mit ClumioundClumio Backtrack für Amazon DynamoDB.If you’d like to discuss your AWS data modernization strategy, please Kontakt.

Moving Forward with ClumioundAWS

As organizations modernize their data platforms for AI, Clumio helps them migrate confidently to S3 Tables, maintain data integrity,undstrengthen their cyber resilience. Clumio simplifies migrationundprotection – helping organizations protect, recover,undmove their most valuable data faster.Start your free trial in the AWS-Marktplatz.


FAQs

Q: Why are organizations moving from self-managed Iceberg tables to Amazon S3 Tables?
A: Many teams are migrating to S3 Tables to improve performanceundsimplify management. Amazon S3 Tables deliver up to three times faster query performanceund10 times higher transaction throughput than self-managed Iceberg tables while reducing operational overhead.Q: How does Clumio simplify the migration process?
A: Clumio automates migration through a backup-and-restore workflow that maintains schemaundmetadata consistency. It avoids manual scriptingundenables restoring Iceberg backups directly as S3 Tables across accountsundregions.Q: What makes Clumio different from other migration approaches?
A: Unlike do-it-yourself scripts or AWS’s native methods, Clumio is Iceberg-awareundautomated,undit offers built-in cyber resilience features such as immutable backups, point-in-time recovery,undretention capabilities that help support compliance requirements.Q: How does Clumio enhance data protection duringundafter migration?
A: Clumio provides air-gapped, immutable backups that help protect against Ransomware, accidental deletion, or malicious changes. It also supports flexible recovery across snapshots, accounts,undregions.Q: Is Clumio available for AWS customers now?
A: Yes, Clumio is available in the AWS-Marktplatzundintegrates with both AWS GlueundAmazon S3 Tables environments. customers to modernizeundprotect their AI data pipelines.Q: What’s the first step to get started with Clumio for S3 Tables migration?
A: Organizations can start by contacting Commvault for migration program approvalundthen use Clumio to discover, back up,undrestore Iceberg tables as Amazon S3 Tables. A free trial is available in the AWS-Marktplatz.Vir Choksi ist Principal Product Marketing Manager bei Commvault. Verwandte Blogs

More related posts


Clumio

Read more about Clumio

Die wichtigsten Erkenntnisse

  • Commvault’s unified threat detection consolidates risk signals and context into a single view, integrating with partners to help reduce alert fatigue and bridge the gap between security ops and data protection teams.
  • Arlie®, Commvault’s AI assistant, helps translate complex incidents into plain-language summaries and recommends next steps – making it easier for non-experts to respond quickly and confidently.
  • Rather than treating entire backups as clean or compromised, Synthetic Recovery™ works at the file level to identify and assemble the most recent clean data, minimizing data loss and recovery downtime.
  • Cleanroom™ Recovery, an isolated environment for forensic investigation, has been enhanced with runbooks to make threat analysis more repeatable, auditable, and safe – helping minimize risks for production systems.

Commvault’s verbesserte Fähigkeiten zur Recovery nach Cyberangriffen focus less on traditional backup and more on helping organizations stay resilient in the face of modern cyber threats. They’re designed to help security and data protection teams seeking faster insights, cleaner recovery options, and stronger validation that their data can be kept safe and recoverable.

At the core is an upgraded threat-detection experience that brings risk, signals, and context together in a single, unified view. Instead of sifting through disconnected alerts, teams see prioritized risks across their environment, enriched with partner integrations like CrowdStrike and Netskope, so they can focus on what truly matters. This helps reduce alert fatigue and bridges the gap between security operations and data protection.

Arlie für die Vorlage

Auch die KI spielt eine zentrale Rolle durchArlie, Commvault’s AI-enabled assistant for data security. Arlie helps summarize complex incidents into clear, human-readable narratives: what happened, when it started, which systems were impacted, and what other tools are seeing. From there, Arlie recommends next moves – such as engaging the security team, using a cleanroom for deeper analysis, or triggering a safer recovery path – so even non-experts can act quickly and confidently.

Die synthetische Wiederherstellung hilft dabei, saubere Daten wiederherzustellen

Recovery selbst hat sich weiterentwickelt und bietet nun neue Optionen, die speziell für Cybervorfälle und nicht für routinemäßige Wiederherstellungen konzipiert sind.„Synthetic Recovery“ ermittelt automatisch die neuesten fehlerfreien Versionen und setzt diese zusammen. of data at the file level, helping reduce manual effort and lower the risk of restoring compromised content. Instead of treating entire backups as “all good” or “all bad,” Synthetic Recovery is designed to help preserve as much recent, safe data as possible, helping to minimize data loss and downtime.

Cleanroom™ Recovery for Forensic Analysis

Für Teams, die Angriffe eingehend untersuchen müssen,Cleanroom Recovery bietet eine isolierte, sichere Umgebung to help analyze suspicious data while helping to reduce risk to production systems. This environment is orchestrated with our new runbooks feature to help streamline setup and validation, making forensic work more repeatable and less error prone. It can be particularly helpful when demonstrating to auditors and regulators that steps have been taken to contain a threat, preserve evidence, and follow best practices.

Finally, the platform’s reporting and compliance capabilities tie everything together, helping to turn technical response actions into clear, defensible records. Teams can export details, show chain of custody, and support demonstration of clean, validated recoveries, helping them work toward meeting regulatory requirements and building trust with stakeholders.

Overall, these new features further enhance our Commvault cyber recovery platform to a broader cyber resilience platform that helps detect faster, recover smarter, and validate that your data is safe and clean.

To learn more, Sehen Sie sich die Demo zu Commvault Cyber Recovery an.

FAQs

Q: What makes these updates different from traditional backup solutions?

A: The focus has shifted from routine data backup to cyber resilience – emphasizing faster threat detection, cleaner recovery from cyber events specifically, and compliance validation.

Q: Who are these features designed for?

A: Primarily security and data protection teams that need faster insights, cleaner recovery processes, and documented proof that data is safe and recoverable.

Q: How does Arlie help non-technical users?

A: Arlie helps summarize incidents into clear narratives (what happened, when, which systems were affected) and recommend specific next steps, so teams don’t need deep technical expertise to act decisively.

Q: What is Synthetic Recovery, and when should I use it?

A: Synthetic Recovery automatically locates and assembles the most recent clean file versions after a cyber event. It is useful when you need to recover quickly and reduce the risk of restorating compromised data.

Q: What is Cleanroom Recovery used for?

A: It helps provide a secure, isolated environment for deep forensic analysis of an attack – useful for investigating threats, preserving evidence, and proving to regulators that proper containment procedures were followed.

Q: How does the platform support regulatory compliance? A: It generates exportable reports with chain-of-custody details and validated recovery records, giving teams the documentation needed to meet regulatory requirements and build stakeholder trust.

Nico Guerrera is Senior Technical Marketing Manager at Commvault.

More related posts


Cyber Recovery

Read more about Cyber Recovery

AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Die wichtigsten Erkenntnisse

  • Detection alone is not enough – organizations need integrated, orchestrated recovery to minimize business disruption from ransomware.
  • The CISCO XDR and Commvault® Cloud integration connects threat detection directly to clean recovery actions within the same security workflow.
  • Eine saubere Wiederherstellung erfordert validierte, isolierte Wiederherstellungsprozesse, um das Risiko einer erneuten Infektion zu verringern und den Betrieb sicher wieder aufzunehmen.
  • Das direkte Auslösen von Sicherungs- und Wiederherstellungsmaßnahmen über Sicherheitstools trägt dazu bei, wichtige Daten frühzeitig zu sichern und die Wiederherstellungszeiten zu verkürzen.
  • Eine einheitliche Resilienz vereint Sicherheit und Wiederherstellung und trägt dazu bei, Reibungsverluste zwischen XDR- (Extended Detection and Response) und SOAR- (Security Orchestration, Automation, and Response) Umgebungen zu verringern und gleichzeitig die Reaktionsgeschwindigkeit und die Zuverlässigkeit zu verbessern.

If there’s one thing I’ve learned from talking with security leaders across industries, it’s this: Detection is only half the job. The other half, the part that determines whether the business keeps moving, is response and recovery. And when ransomware hits, recovery isn’t just about speed. It’s about confidence, it’s about cleanliness, and it’s about speed.

That’s why this announcement matters. We’ve expanded our partnership with Cisco with a new integration between Cisco XDR und Cloud, built to unite ransomware response and recovery in a single, coordinated workflow.

Too many organizations still live with a painful gap between what security teams see and what IT teams can safely do next. When every second counts, that gap becomes the difference between containing an incident and watching it evolve into business disruption. With this integration, teams can move from detection to decisive recovery actions inside the security operations workflow, helping minimize impact when time is the enemy.

And here’s the truth: In a crisis, the business doesn’t care who owns which “console.” The business cares about outcomes. Can we preserve critical data early? Can we recover cleanly without reinfection? Can we restore the right systems confidently instead of guessing? How fast can we get back to „Minimum Viability“? That’s the gap we’re closing, bringing recovery actions into the zur Reaktion auf flow, where decisions are already being made.

This is where “clean recovery” stops being a talking point and becomes the new standard.

Recovery has turned into an exercise in trust: trust that your recovery points are safe, trust that your backups aren’t already compromised, and trust that you’re not reintroducing risk while trying to restore operations. The uncomfortable reality is that defenders increasingly have less time to respond.

According to Sophos’ Bericht über aktive Angreifer 2026, “the speed with which attackers attempt to go after AD after gaining access to the system sped up by 70% over last year, down to a median of just 3.40 hours.”

That kind of speed forces zur Reaktion auf to operate in an immediate, orchestrated way across silos, and it raises the bar for recovery. Because fast restores don’t help if they aren’t clean.

With this new integration, security operations teams can trigger Commvault Cloud actions directly from Cisco XDR, helping preserve data early and move toward clean recovery.

If a SOC manager gets notice of a threat detected in Cisco XDR, they can initiate a backup of core infrastructure VMs right away, and then restore impacted systems into Commvault Cloud Cleanroom Recovery, a secure, isolated cloud environment designed for investigation and validation, before confidently returning systems into production. This brings recovery actions in the same workflow as detection, so teams can respond faster and recover with confidence.

The result is a tighter connection between detection and recovery, so security teams can act decisively at the earliest signs of an attack. By validating recovery in an isolated cleanroom before returning systems to production, organizations reduce reinfection risk, preserve critical data, and shorten recovery timelines, all from tools SOC teams already trust.

 

A Commitment to Unified Resilience

Zooming out, this integration with Cisco XDR is an important milestone, and it’s also part of a bigger direction we’re committed to: unified resilience, where security and recovery work together instead of operating in separate lanes. And it’s not an “either/or” proposition. It’s a growing ecosystem designed to meet teams where they work.

Another great example of this is our integration with Splunk SOAR, that helps improve threat detection and drive faster, more automated response. Commvault can send threat detection, data security, and backup and recovery intelligence directly into Splunk, enriching security events and helping alert SecOps teams and automated actions in Splunk can reduce response time without bouncing between interfaces.

So, whether a customer’s operational hub is XDR or SOAR, the goal stays the same: reduce friction, speed decisions, and make recovery provable.

The Cisco XDR integration is generally available globally and offered at no additional cost to existing Commvault customers. If you want to dig deeper, here are a few good places to start:

OderMelde dich bei mir auf LinkedIn, and I’m happy to talk through what “detection to clean recovery” looks like in the real world.

FAQs

Q: Why is detection only half the battle in ransomware response?
A: Detection identifies threats, but response and recovery determine whether the business can continue operating. Without a coordinated recovery plan, even fast detection can still lead to prolonged downtime and disruption.

Q: What does “clean recovery” mean in practice?
A: Clean recovery involves restoring systems in a secure, isolated environment to validate that backups are uncompromised before returning them to production. This approach helps reduce the risk of reinfection and enable greater confidence in restored systems.

Q: How does the Cisco XDR and Commvault integration improve zur Reaktion auf?
A: The integration allows security teams to trigger backup and recovery actions directly from Cisco XDR. This unified workflow helps preserve data early, initiate secure restoration, and move from detection to recovery without switching between disconnected tools.

Q: What role does the Cleanroom Recovery environment play?
A: Cleanroom Recovery provides an isolated cloud space for investigation and validation of restored systems. Teams can analyze and confirm system integrity there before confidently bringing workloads back into production.

Q: How does this integration support broader security ecosystems like SOAR?
A: In addition to Cisco XDR, Commvault integrates with platforms like Splunk SOAR to enrich threat intelligence and automate response actions. This ecosystem approach helps security teams reduce friction, accelerate decisions, and make recovery outcomes more predictable.

Q: Is the Cisco XDR integration available to existing customers?
A: Yes, the integration is generally available worldwide and is offered at no additional cost to existing Commvault customers, making it easier to adopt unified detection and recovery workflows.

Michael Fasuloist Senior Director für Portfolio-Marketing bei Commvault. Verwandte BlogsCleanroom Recovery läuten eine neue Ära der Cyber-Resilienz ein

Commvault läutet eine neue Ära der einheitlichen Unternehmensresilienz ein

Die nächste Evolutionsstufe im Bereich Cloud

Die 5 kritischen Schritte zur sauberen Erholung

Ihr modernes Spielbuch für schnelle Reaktion und saubere Wiederherstellung

More related posts


Cyber Resilience

Read more about Cyber Resilience

There’s a lot of talk about modernization – Cloud, AI, automation, security transformation. But what does modernization actually look like when you’re responsible for keeping systems running, data protected, and recovery viable under pressure?

In this episode of STRIVE, I had the pleasure of sitting down with Gilman Treantos – a 25-year IT veteran whose career spans everything from mainframes to modern cyber resilience architecture. This conversation provides a practitioner’s view of what modernization really means when outages, ransomware, and operational risk are part of the daily equation.

Watch the gesamte Folge. Das Wichtigste auf einen Blick: Was moderne Cyber-Sicherheit tatsächlich erfordert

  • Modernization isn’t about new tools – it’s about resilient architecture. Technology evolves, but recovery discipline, testing, and cross-team coordination are what separate reactive organizations from resilient ones.
  • Cyber Readiness erfordert eine Zusammenarbeit zwischen den Bereichen Sicherheit und Infrastruktur. Silos führen zu blinden Flecken. Eine einheitliche Transparenz und gemeinsame Verantwortung können die Recovery beschleunigen.
  • Backup-Tools sind leistungsfähiger, als den meisten Teams bewusst ist. Bei kreativem Einsatz können sie groß angelegte Migrationen, isolierte Wiederherstellungen und Umstellungen unterstützen, die darauf ausgelegt sind, Datenverluste zu minimieren.
  • Testing is non-negotiable. A recovery plan that hasn’t been rehearsed is a liability, not a strategy.
  • Berufliche Belastbarkeit entspricht der technischen Belastbarkeit. Eigeninitiative, Neugier und die Bereitschaft, schwierige Probleme zu lösen, sind ebenso entscheidend wie jede platform.

From Blockbuster to Cyber Resilience

Gilman’s journey didn’t start in a war room or a security operations center. It started at Blockbuster.

Without formal IT training, he leaned into troubleshooting. That curiosity became mainframe work. That work became distributed systems. That evolved into data protection and cyber resilience leadership.

What stands out isn’t the career arc – it’s the mindset. He built a reputation by taking on the problems no one else wanted. Fixing fragile systems. Supporting overlooked initiatives. Solving issues that crossed organizational boundaries.

That mentality translates directly to modernization, because modern cyber readiness is built by people willing to dig into uncomfortable complexity.

Sneak Peek: The Modernization Playbook

In this segment, Gilman explains why modern cyber recovery requires more than traditional malware detection — and how anomaly detection, ThreatScan, and isolated recovery environments can help strengthen enterprise resilience.

Modernization Under Pressure

One of the most compelling parts of the episode is a real-world example: evacuating a remote data center in a single night. No data loss. No prolonged downtime. No operational chaos.

By leveraging Commvault LiveSync in a creative way, Gilman and his team were able to migrate infrastructure quickly and cost-effectively – using capabilities that weren’t originally designed for that exact scenario.

That’s modernization in practice.

The House of Cards Problem

As organizations scale, permissions sprawl. Backup systems grow complex. Security tools layer on top of infrastructure without full alignment. Over time, environments become fragile.

Gilman describes this dynamic as something many teams underestimate: a slow accumulation of technical and operational debt. Modernization, in his view, isn’t just upgrading platforms. It’s simplifying architecture, improving visibility, and breaking silos between cybersecurity and infrastructure teams.

Cyber readiness means:

  • Die Sicherheits- und Backup-Teams tauschen Telemetriedaten aus.
  • Wiederherstellungsumgebungen werden isoliert und getestet.
  • Die Erkennung von Malware geht über die primären Arbeitsabläufe hinaus.
  • Bei Infrastrukturentscheidungen wird die Wiederherstellungsgeschwindigkeit berücksichtigt.

This is where modernization and resilience intersect.

Threats Are Evolving. So Must Recovery.

Ransomware isn’t slowing down. Threat actors are more sophisticated. Malware hides inside legitimate workflows. Gilman’s perspective is blunt: Preparation must be proactive.

He advocates for:

  • Regelmäßige Tests der Notfallwiederherstellung
  • Isolierte Wiederherstellungsumgebungen, die zur Aktivierung bereitstehen
  • In Backup-Prozesse integrierte Tools zur Erkennung von Anomalien
  • Teamübergreifende Übungen, die reale Störungen simulieren

Sehen Sie sich die gesamte Folge an

Sehen Sie sich unser vollständiges STRIVE-Gespräch an und erfahren Sie:

  • Wie Gilman seinen Ansatz zum Datenschutz im Laufe von 25 Jahren weiterentwickelt hat.
  • Die Details einer Migration, die darauf ausgelegt ist, Datenverluste zu minimieren.
  • Warum die Zusammenarbeit zwischen Sicherheit und Infrastruktur unerlässlich ist.
  • Praktische Tipps für Resilienz-Experten.
  • What modernization really demands in today’s threat landscape.

Jetzt anschauen.

If you care about resilience, recovery, or leading IT through uncertainty, this is 20 minutes well spent.

FAQs

Q: What does “modernization” mean in the context of cyber readiness?

A: It means building resilient, testable, and collaborative systems that can recover quickly under real-world pressure – not just upgrading to newer platforms.

Q: Why is collaboration between security and infrastructure teams so important?

A: Because recovery depends on shared visibility. Security detects threats, but infrastructure enables restoration. Without alignment, response slows and risk increases.

Q: How can backup tools support modernization beyond recovery?

A: When used creatively, they can enable data center migrations, isolated recovery environments, anomaly detection, and large-scale operational shifts.

Q: How often should disaster recovery environments be tested?

A: Regular testing – ideally quarterly or aligned with major infrastructure changes – builds confidence and reveals gaps before an actual incident.

Chris Mierzwa ist Senior Director für Portfoliomarketing bei Commvault. Verwandte BlogsWie die SMMPA die Cyber-Resilienz durch Cleanroom Recovery gestärkt hat

Cyber-Sicherheit in Zeiten geopolitischer Spannungen: Leitlinien für unsere Kunden, Partner und die Community

Warum KI Ihre Resilienzstrategie untergräbt (und was Sie dagegen tun können)

Physik vs. Marketing: Die Erholung beschleunigen und dabei die Gesetze der Physik beachten

Modernisierung der Cybersicherheit im Finanzbereich: Von reaktiv zu widerstandsfähig

More related posts


Readiness

Read more about Readiness

The RSA Conference, held from March 23 – 26 in San Francisco, is one of the premier events in the cybersecurity industry, bringing together experts, thought leaders, and innovators to discuss the latest trends and solutions in cyber resilience and data protection.
The energy was palpable, the learning top-notch, and the city buzzing. With so much to see, including our ResOps Rumble and The Rumble After Party on Monday evening, we wanted to make sure you didn’t miss these exciting announcements from Commvault.
Die wichtigste Erkenntnis

  • Commvault wurde mit dem Global InfoSec Award für Innovationen im Bereich Cyber-Resilienz ausgezeichnet und erlangte damit große Anerkennung in der Branche.
  • Erweiterte Funktionen zur Bedrohungssuche helfen Unternehmen dabei, Risiken in Backups zu erkennen und einwandfreie Daten schneller wiederherzustellen.
  • Neue Daten und Verbesserungen im Bereich der KI-Sicherheit tragen dazu bei, die Transparenz, Klassifizierung und Governance für strukturierte und unstrukturierte Daten zu verbessern.
  • Die Integration mit Microsoft Security ermöglicht schnellere, koordinierte Workflows zur Erkennung von Bedrohungen und zur Wiederherstellung.
  • Strategische Partnerschaften und Brancheninitiativen verdeutlichen den Trend hin zu einheitlichen Resilienzmaßnahmen als zentralem Sicherheitsbereich

  1. Commvault gewinnt den „Market Disruptor Cyber Resilience Global InfoSec Award“ 2026.

After being named Outstanding in the Cyber Resilience category at the 2025 Global InfoSec Awards, we have accelerated our innovation roadmap, redefining cyber resilience beyond traditional backup and recovery to help address the realities of today’s AI-driven threat landscape.
This year, Global InfoSec has hat Commvault als „Market Disruptor“ in der Kategorie „Cyber-Resilienz“ ausgezeichnet. We provide a unified cyber resilience platform designed to deliver AI-enabled data protection, proactive threat detection, advanced ransomware recovery, and a single operational view across enterprise environments.
Unlike other solutions, Commvault® Cloud helps empower customers to protect, recover, and manage their data, applications, and production workloads – across on-premises, public, private, hybrid, SaaS, and multi-cloud environments.
Was das Thema Marktumwälzungen und Innovation angeht, haben wir im Vorfeld der Konferenz einige wichtige Ankündigungen gemacht.

  1. Commvault kündigt erweiterte Funktionen zur Bedrohungssuche an

Wirvor kurzem angekündigte Ausweitung der Bedrohungssuche capabilities within Commvault®. Cloud Threat Scan. The enhancements help organizations rapidly identify risks within backup environments and recover validated clean data, helping reduce reinfection risks and prolonged downtime.
To address this challenge, Commvault now delivers two complementary scanning modes within Commvault®. Cloud Threat Scan:

  • Hyper Threat Hunting helps enable targeted searches across backup data using threat hunting artifacts such as hashes and YARA rules to identify known indicators of compromise at scale. Hash-based hunting helps provide fast, index-based detection, while YARA-based analysis helps support more targeted pattern matching for deeper investigation.
  • Deep Inspection provides layered file-level analysis using malware signatures, machine learning, heuristic analysis, and AI-enabled encryption detection to help uncover known threats, suspicious variants, and ransomware related activity that may evade exact-match indicators alone.

Zusammen ermöglichen diese Erkennungsmodi eine enge Zusammenarbeit zwischen den Teams für die Reaktion auf Vorfälle und die Wiederherstellung, um betroffene Daten zu isolieren und fundierte Entscheidungen zur Wiederherstellung zu treffen. Sie können wiederkehrende Scans zur kontinuierlichen Überwachung planen oder gezielte Suchen während aktiver Vorfallreaktionsszenarien durchführen, was sowohl für den laufenden Schutz als auch für zeitkritische Reaktionen Flexibilität bietet.

  1. Commvault kündigt eine Erweiterung seiner Funktionen für Daten- und KI-Sicherheit an

Am selben Tag,Wir haben eine Erweiterung der Funktionen für Daten- und KI-Sicherheit innerhalb der Commvault Cloud angekündigt, enabled via our die kürzlich erfolgte Übernahme von Satori. The advancements extend data discovery, classification, and risk assessment into structured data environments and introduce real-time access governance for structured databases, including vector databases used in AI applications. These innovations expand Commvault’s existing data security posture management functionality for unstructured data, while data access governance adds real-time control of structured data access.
These advancements also unify visibility by identifying sensitive data, surfacing exposure and policy violations, and consolidating risk insights to help organizations prioritize remediation based on impact. This helps yield improved resilience, prioritized risk remediation, support for compliance, and reduced data exposure to help strengthen resilience across both production and backup data.

  1. Commvault kündigt eine erweiterte Integration mit Microsoft Security an

Am ersten Morgen der Konferenz haben wir eineErweiterte Integration mit Microsoft Security to better connect threat detection with trusted recovery. The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the Commvault Cloud Platform to streamline resilience operations (ResOps) and enable real-time data insights, helping organizations move quickly from identifying a threat to validating and restoring clean data faster and with greater confidence.
This new integration helps enable coordinated workflows between security and recovery teams. Security alerts from Commvault Cloud are ingested into Microsoft Sentinel data lake where security operations center analysts can enrich these incidents with partner intelligence to access impact and validate scope. In the coming quarters, these insights can help drive automated, policy-based recovery workflows to accelerate and orchestrate clean recovery. You can learn more from Unser Blog hier.

  1. NetApp and Commvault Advance Cyber Resilience with Strategic Alliance 

Was das Thema Allianzen angeht, so haben wir außerdemannounced a strategic alliance with NetApp® to deliver a powerful, integrated solution for enterprise data protection and cyber resilience. The unified solution enables resilience, security, and rapid recovery for customers across on-premises and cloud environments, helping give organizations confidence that their data is available, immutable, and recoverable.
This alliance addresses a critical need for scaling resilience via unified cyber detection and ransomware recovery. By combining Commvault’s leading resilience, protection, and recovery capabilities with NetApp’s enterprise-grade data platform with built-in intelligence and AI-enable ransomware detection, together we’re creating a highly differentiated, end-to-end cyber resilience solution.

  1. TIME + Commvault – CISO des Jahres

Zu guter Letzt in diesen ereignisreichen Wochen freuen wir uns sehr, dieVerleihung des erstmals vergebenen „TIME and Commvault CISO of the Year Award“. The branded award, selected by Commvault and a panel of industry experts, recognizes enterprise security leaders who are not only defending against cyber threats but also redefining resilience in an increasingly complex threat landscape.
The CISO of the Year Award recognizes leaders who are transforming cybersecurity into a driver of trust, operational strength, and long-term resilience. They embrace critical practices and emerging disciplines, including ResOps, which is rapidly becoming a core discipline for modern enterprise security.
Nominierungen for the CISO of the Year Award will be accepted by Commvault from March 23 through June 20, 2026. Submissions will be reviewed by a panel of industry experts. The panel and Commvault will choose finalists and the winning CISO of the Year based on pre-defined criteria. You can read more about the criteria on the Seite „Nominierungen“.
Commvault Cyber Resilience a Highlight of RSAC

RSAC 2026 made one thing clear: Cyber resilience is no longer a future aspiration – it’s a present-day mandate. From industry recognition to expanded threat hunting, deeper data and AI security, and stronger ecosystem integrations, Commvault continues to push the boundaries of what organizations can expect from a modern resilience platform.
These announcements reflect a broader shift toward unifying security, data protection, and recovery into a cohesive strategy that helps organizations act faster, respond smarter, and recover with confidence in the face of evolving threats.
As the threat landscape grows more complex, the ability to not only detect and defend but also recover with great confidence is becoming a defining competitive advantage. The innovations highlighted at RSAC – alongside strategic partnerships and recognition of industry leaders – underscore Commvault’s commitment to enabling that outcome.
If RSAC is any indication of where the industry is headed, ResOps will continue to take center stage, and organizations that embrace this approach will be well positioned to navigate whatever comes next.


FAQs

F: Welche neuen Funktionen zur Bedrohungssuche hat Commvault eingeführt?
A: Commvault hat „Hyper Threat Hunting“ und „Deep Inspection“ als Teil seinerThreat Scan-Lösung. These features combine fast detection with advanced analysis to help identify both known and emerging threats in backup data.
Q: How do Commvault’s new data and AI security capabilities benefit organizations?
A: The enhancements to Commvault’s data and AI security capabilities expand visibility into sensitive data across structured and unstructured environments. They also add real-time access governance, helping organizations reduce risk and improve compliance.
Q: What is the significance of the Microsoft Security integration with Commvault Cloud?
A: The integration helps connect threat detection with recovery by linking Commvault Cloud with Microsoft Sentinel and Security Copilot. This is designed to enable faster decision-making and more automated recovery processes.
Q: What does the Commvault and NetApp alliance bring to customers?
A: The alliance combines Commvault’s resilience platform with NetApp’s data infrastructure and AI-enabled ransomware detection. This creates a unified solution designed to deliver stronger data protection and faster recovery across environments.
Q: What is the TIME and Commvault CISO of the Year Award?
A: The TIME + Commvault CISO of the Year award recognizes a security leader who exemplifies modern resilience leadership through a ResOps approach.
This program celebrates CISOs who treat resilience as a core business capability not just a technical function, those bridging security, IT, and operations to enable their organizations to recover quickly, operate confidently, and innovate without increasing risk​​.
​​​The honoree selected ​by Commvault ​will be featured in a TIME​ ​branded​ ​article and video, with additional recognition across TIME and Commvault channels​. The honoree will also be invited to Commvault’s annual SHIFT event. ​

More related posts


Threat Scan

Read more about Threat Scan

Die wichtigsten Erkenntnisse

  • Sicherheit muss sich wie Agent Smith skalieren lassen: In „Matrix“ vermehrte sich Agent Smith rasant, um Neo zu überwältigen. Sicherheitsteams stehen heute vor einer ähnlichen Herausforderung, da Bedrohungen und Signale schneller zunehmen als die Kapazitäten der Analysten. KI-gestützte Sicherheitsagenten helfen den Teams dabei, ihre Untersuchungen auszuweiten, ohne dass dafür mehr Personal eingestellt werden muss.
  • Die Korrelation von Signalen erhöht die Zuverlässigkeit der Untersuchungen: Der Commvault Security Investigation Agent korreliert Backup-Daten mit Sicherheitssignalen von Plattformen wie Netskope, CrowdStrike und Palo Alto Networks, um festzustellen, ob in den Backup-Daten entdeckte Bedrohungen auch Auswirkungen auf die Produktionssysteme hatten.
  • Cyber-Resilienz wird agentengesteuert: Der Commvault Security Investigation Agent ist der erste Schritt in eine Zukunft, in der spezialisierte KI-Agenten Sicherheitsteams bei Untersuchungen, Wiederherstellungsentscheidungen und schnelleren Wiederherstellungsabläufen unterstützen.

Einführung

In The Matrix, there’s a moment that feels surprisingly relevant to today’s technology landscape. Agent Smith discovers he can duplicate himself. One becomes many, and suddenly Neo is surrounded by an army of identical agents operating simultaneously.

In many ways, that scene mirrors the world we’re entering today with agentic AI. Across industries, and especially in cybersecurity, we’re beginning to see the rise of specialized AI agents that can work independently, scale rapidly, and assist humans in ways that were previously impossible. But unlike Agent Smith’s relentless takeover, the goal of these agents isn’t domination. It’s defense.

Skalierung bei gleichzeitiger Überwindung von Silos

Security operations today face a fundamental scaling problem. The number of systems, signals, and security tools continues to grow, but the number of analysts does not.

Organizations now ingest telemetry from endpoint security platforms, network defenses, cloud monitoring tools, and identity protection systems. Each of these tools generates its own alerts and dashboards, often operating in isolation from one another. The result is an overwhelming amount of data spread across disconnected silos.

It’s tempting to assume the solution is simply hiring more analysts, but anyone who has managed large teams knows that adding people introduces its own challenges. As teams grow, communication becomes more complex, coordination slows down, and the efficiency of investigations often decreases.

What security teams really need is not just more people, but more intelligence and automation to help analysts move faster and see the bigger picture.

One of the most persistent silos in security operations has been the divide between backup systems and security tools. Traditionally, security teams monitor production environments through their security information and event management tools while backup environments operate in a separate console.

Backup data is often only examined after an incident occurs, when organizations are already deep in recovery mode. Yet attackers increasingly target backup systems precisely because they know they are critical to recovery.

Ransomware operators frequently encrypt production systems, attempt to corrupt backups, or leave malicious artifacts hidden inside protected datasets. This means that backup environments often contain valuable evidence of an attack, but that intelligence has historically been difficult for security teams to access and correlate with other signals.

Der neue Sicherheitsermittler

Commvault’s new integration with Microsoft Sentinel and Microsoft Security Copilotsoll diese Lücke schließen. Durch diese Integration können Cloud direkt in den Sentinel Data Lake gestreamt werden, wodurch Backup-Telemetriedaten in dieselbe Analyseumgebung wie cloud Endgeräten, Netzwerken und cloud eingebunden werden. Anstatt isoliert zu erfolgen, können Backup-Aktivitäten nun im Zusammenhang mit dem gesamten Sicherheitsökosystem analysiert werden. Die wahre Stärke dieser Integration liegt jedoch in der Einführung des Commvault Security Investigation Agent.

Der Security Investigation Agent unterstützt Analysten bei der Untersuchung potenzieller Bedrohungen, indem er Signale aus Backup-Umgebungen mit Signalen anderer Sicherheitsplattformen abgleicht. Wenn ein Analyst den Hostnamen eines Servers angibt, erfasst der Agent Sicherheitsereignisse, die von Commvault Threat Scan Risk Analysis generiert wurden, darunter Backup-Anomalien, Verschlüsselungsereignisse, die auf Ransomware-Aktivitäten hindeuten könnten, in geschützten Datensätzen erkannte Malware sowie Backups, die sensible Daten enthalten.

Der Agent gleicht diese Ereignisse dann mit Telemetriedaten anderer Sicherheitslösungen ab, auf die Unternehmen bereits setzen, wie beispielsweise Netskope, CrowdStrike und Palo Alto Networks. Durch die gemeinsame Analyse der Aktivitäten auf diesen Plattformen kann der Agent dabei helfen festzustellen, ob verdächtiges Verhalten, das in Backup-Daten identifiziert wurde, auch in Produktionsumgebungen auftritt.

Wie findet man einen Makler?

Let’s first walk you through how you can start with our first agent focused on security investigations. Then we’ll share how we plan to rapidly spawn new agents – just like Agent Smith – so customers can take control of investigations, recovery decisions, and restore operations, giving security and operations teams the intelligence they need to respond faster and recover with confidence.

Konfigurieren Sie den Connector

Bevor wir den Commvault Security Investigation Agent aktivieren können, müssen Sie den Commvault Cloud installieren und konfigurieren.

  1. Installation: Eine Anleitung zur Installation der Commvault Cloud sowie Informationen zu Berechtigungen und Voraussetzungen finden SieWeitere Informationen zu Commvault Cloud finden Sie

Screenshot: Installationsdetails für den Commvault Cloud Connector im Microsoft Sentinel Content Hub.

  1. Konfiguration: Nach der Installation lauten die Konfigurationsdetails wie folgt:Weitere Informationen zu Commvault Cloud finden Sie
 Use Commvault Security Investigation Agent

Sobald der Commvault Cloud für Sie installiert wurde, können Sie den neuen Security Investigation Agent nutzen.

  1. Weiter zuhttps://securitycopilot.microsoft.com/agents.
  2. Search for “Commvault Security Investigation Agent.”
  3. Click on “Set up” Agent.
  4. Click on “Weiter zuAgent.”
  5. Click on “Run” => “One time.”
  6. Provide the “Hostname” for the host you’d like help investigating, and click “Submit.”
    1. Hinweis: Der Hostname ist der Name des Servers, auf dem wir nach Ereignissen von Commvault und Partnern wie Netskope, CrowdStrike und Palo Alto suchen möchten.
  7. Der Agent wird ausgeführt, und Sie erhalten als Ergebnis eine detaillierte Analyse sowie Empfehlungen.

Screenshot: Die detaillierte Analyse des Commvault Security Investigation Agent, der auf einem Host ausgeführt wird, der Teil einer Untersuchung ist.

Schlussfolgerung

The Matrix may have dramatized the idea of multiplying agents, but it captured an important truth about scale. When Agent Smith multiplied, the dynamics of the fight changed entirely.

Cybersecurity is undergoing a similar shift. Attackers are increasingly leveraging automation and AI to scale their operations. The only way defenders can keep pace is by scaling their own capabilities through intelligent systems that augment human expertise.

With the integration between Commvault, Microsoft Sentinel, and Microsoft Security Copilot – and with the introduction of the Commvault Security Investigation Agent – we are beginning to see what that future looks like. It’s a world where security operations are no longer constrained by silos, where investigations move faster, and where AI-enabled agents work alongside analysts to strengthen cyber resilience across the entire environment.

Over the coming year, Commvault plans to introduce additional agents – just like Agent Smith multiplying in The Matrix – that can help security teams run Commvault Threat Scan, spin up Cleanroom environments for SOC analysts to safely investigate incidents, and accelerate recovery by identifying the safest data to restore.

We’re also excited to collaborate with Microsoft to enable customers to use Microsoft Foundry to build and extend their own agents, allowing them to tailor automation and investigations to their unique environments.

By combining Commvault’s deep cyber resilience capabilities with Microsoft’s AI and security ecosystem, we’re helping organizations move toward a future where intelligent agents help analysts investigate faster, break down silos, and strengthen resilience across the entire environment.


FAQs

F: Was sind KI-Agenten im Sicherheitsbetrieb (SecOps/ResOps)? A: KI-Agenten sind spezialisierte, autonome Tools, die Sicherheitsteams durch die Analyse von Daten, die Korrelation von Signalen und die Unterstützung bei Untersuchungen unterstützen. Sie arbeiten mit menschlichen Analysten zusammen, um die Entscheidungsfindung zu beschleunigen und die Reaktionszeiten in komplexen Umgebungen zu verbessern.

F: Warum ist die Skalierung von Sicherheitsabläufen heutzutage eine solche Herausforderung? A: Sicherheitsteams sehen sich mit einer Flut von Warnmeldungen und Daten aus zahlreichen Tools konfrontiert, während die Zahl der Analysten nur langsam wächst. Dieses Ungleichgewicht führt zu Engpässen, sodass es ohne Automatisierung und intelligente Unterstützung schwierig ist, Bedrohungen effizient zu untersuchen. F: Wie verbessert der Commvault Security Investigation Agent die Untersuchung von Bedrohungen?
F: Wie verbessert der Commvault Security Investigation Agent die Untersuchung von Sicherheitsbedrohungen? A: Der Agent korreliert Backup-Daten mit Signalen von Sicherheitsplattformen wie CrowdStrike, Netskope und Palo Alto Networks. Diese kombinierte Ansicht hilft Analysten dabei, festzustellen, ob in Backups erkannte Bedrohungen auch Produktionssysteme beeinträchtigt haben, was die Zuverlässigkeit der Untersuchungen erhöht. F: Welches Problem löst die Integration von Backup-Daten in Sicherheitsworkflows? A: Backup-Umgebungen enthalten oft entscheidende Beweise für Angriffe, waren jedoch bisher von Sicherheitstools isoliert. Die Integration dieser Daten ermöglicht es Teams, Bedrohungen ganzheitlich zu analysieren, verborgene Risiken aufzudecken und fundiertere Entscheidungen zur Recovery zu treffen. F: Wie können Unternehmen den Commvault Security Investigation Agent nutzen? A: Unternehmen müssen den Commvault Cloud in Microsoft Sentinel installieren und konfigurieren. Nach der Einrichtung kann über Microsoft Security Copilot auf den Agenten zugegriffen werden, um Untersuchungen durchzuführen, indem einfach ein Hostname angegeben wird.

F: Wie sieht die Zukunft von KI-Agenten im Bereich der Cyber-Resilienz aus? A: Die Zukunft deutet darauf hin, dass mehrere spezialisierte Agenten bei der Durchführung von Untersuchungen, der Planung von Wiederherstellungsmaßnahmen und der Durchführung von Wiederherstellungsvorgängen helfen werden. Diese Agenten werden dazu beitragen, Silos aufzubrechen, die Reaktionszeit zu verkürzen und widerstandsfähigere Sicherheitsabläufe in der gesamten Umgebung zu ermöglichen.Ritu Singh ist Senior-Produktmanager und Rich Vorwaller ist Leiter des Produktmanagements bei Commvault.


Verwandte Blogs

MCP 2.0 erklärt: KI-Agenten sichern, bevor sie sich selbst sichern

Warum KI Ihre Resilienzstrategie untergräbt (und was Sie dagegen tun können)

Resilienz gegenüber Exploits durch seitlichen Zugriff

Sind Sie bereit für Datenleck-Schleifen?

Ransomware-Trends für 2026: KI, Resilienz und MTCR

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • KI beschleunigt die Datengenerierung und verteilte Arbeitsabläufe, wodurch herkömmliche reaktive Ansätze nicht mehr ausreichen, um Ausfallsicherheit zu gewährleisten.
  • Resilience Operations (ResOps) helfen Teams dabei, von reaktiver Fehlerbehebung zu koordinierten Maßnahmen überzugehen, wobei Commvault KI in drei Bereichen einsetzt: Schutz von KI-Daten, -Modellen und -Pipelines; Nutzung von KI zur Steuerung und Beschleunigung von Reaktionen; sowie Ausweitung der KI auf das gesamte Resilience-Ökosystem.
  • Praktische KI-Agenten sind darauf ausgelegt, betriebliche Probleme aufzudecken (Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Data Sense), Entscheidungen zum Schutz zu unterstützen (Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Advisor) und dialogorientierte Arbeitsabläufe zu ermöglichen (MCP-Server).
  • Datensicherheit und Governance sind nach wie vor von grundlegender Bedeutung. KI muss so trainiert werden, dass sie Zugriffskontrollen einhält, die Nachvollziehbarkeit gewährleistet und innerhalb der festgelegten Richtlinien arbeitet.
  • Unternehmen können klein anfangen – mit gezielten Maßnahmen – und schrittweise zu koordinierten, intelligenten Abläufen übergehen.

AI introduces both new challenges and potential breakthroughs for enterprise resilience. On one hand, traditional siloed tools for protection, recovery, and governance weren’t designed to operate across constantly evolving AI environments that span multiple platforms.
On the other hand, AI-enabled resilience tools can deliver a transformative impact by helping teams maintain visibility, enforce policy, and recover cleanly. For IT and security teams, the question is how best to leverage the benefits of AI while mitigating the operational risks it can pose.
In einem kürzlich abgehaltenen Webinarhabe ich mich mitTeja Medasani, Principal Product Manager für KI bei Commvault, um praktische Anwendungsfälle zu beleuchten, bei denen KI-Agenten in Resilienz-Workflows auf Cloud-, SaaS-, On-Premises- und KI-nativen Plattformen zum Einsatz kommen.

Warum KI den Katastrophenschutz neu definiert

The rapid growth and dynamic nature of AI-native environments have put operational workflows under pressure. Manual tagging, spreadsheets, and logic quickly drift out of sync. Sprawling job history tables and audit trails slow manual troubleshooting and make subtle warning signs easy to miss. Recovery processes that assume centralized data and isolated failures are poorly suited for exponential data growth and fragmented workloads across platforms.
When data, workloads, and environments span platforms, resilience can’t remain siloed in separate teams, tools, and policies. A new operating model is needed: Resilienzmaßnahmen oder ResOps.

Wie ResOps in der Praxis aussieht

Das ResOps-Framework geht diese Herausforderungen in drei Dimensionen an:

  • Protect AI: Schutz von KI-Daten, -Modellen und -Pipelines in allen Umgebungen, damit diese wiederherstellbar und konform bleiben.
  • KI nutzen: Einsatz von KI zur Reduzierung des manuellen Aufwands, zur Gewinnung operativer Erkenntnisse und zur Unterstützung von Entscheidungen hinsichtlich Reaktion und Wiederherstellung.
  • Extend AI: Vernetzung von ResOps über Tools und Teams hinweg zum Schutz von Dialoginteraktionen und integrierten Arbeitsabläufen.

Im Webinar haben wir uns vor allem auf die Nutzung und den Ausbau von KI konzentriert und dabei die wichtigen Rollen hervorgehoben, die KI-Agenten im Tagesgeschäft spielen können. Diese Beispiele konzentrieren sich aufArlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit, Commvault’s AI assistant. Designed to help users interpret data, understand issues, and move toward action more efficiently, Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit includes a Agentenbibliothek purpose-built to help address specific resilience workflows.
By helping reduce repetitive analysis, surfacing meaningful signals, and guiding decisions around security-aware recovery, these agents can help teams take actions more quickly and confidently. Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Data Sense, Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Advisor, and Commvault’s MCP-Server illustrate a few of the possibilities unlocked by AI-enabled ResOps.

Surfacing Operational Issues with Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Data Sense

Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find patterns or diagnose failures, users can trigger Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit to help analyze the data and generate an executive summary highlighting anomalies and emerging issues.
Teams can ask follow-up questions in natural language and explore data further through interactive summaries or visualizations. When a job fails, Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit can help analyze logs, summarize the failure, identify the possible cause, and provide next steps for resolution.

Guiding Response Decisions with Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Advisor

Da immer neue Workloads hinzukommen, sich die Zuständigkeiten ändern und die Anforderungen sich wandeln, wird es zunehmend schwieriger, den Schutzumfang in allen Umgebungen aufrechtzuerhalten.Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Advisor is designed to help teams create and validate protection plans at scale by evaluating the characteristics and current protection coverage for each resource, and then highlighting where adjustments may be needed.
Recommendations are presented clearly with reasoning explained, so teams can evaluate them and decide how to apply them within existing governance processes. This helps teams maintain consistency across dynamic environments.

Erweiterung von Resilience-Workflows mit MCP Server

Resilience workflows often need to connect with ticketing systems, collaboration tools, and security platforms outside the Commvault platform, and they need to be accessible to users who aren’t resilience experts. Commvault’s MCP-Server makes it possible to extend workflows without custom integrations or significant training by allowing conversational interaction.
Users can ask questions or request actions in natural language, with their prompts translated into governed API calls behind the scenes – for example, to automatically create tickets in ServiceNow for failed jobs.

Koordination und Klarheit über Teams und Plattformen hinweg

The examples above share a common theme: coordination. Effective resilience requires visibility, policy enforcement, and clean recovery across environments. AI can help strengthen these capabilities by helping teams identify what matters and act more quickly.
While the evolution of resilience from reactive recovery to continuous insight and guided action has become essential, it doesn’t need to happen all at once. Teams can start with targeted agents that address specific operational pain points and then build toward more coordinated operations as capabilities mature and teams gain confidence.
The key is to begin the ResOps journey now – because the challenges posed by evolving resilience requirements will only keep growing.
Sehen Sie sich das vollständige Webinar auf Abruf an to see detailed demos of Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Data Sense, Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Advisor, and conversational resilience in action, and explore how AI-enabled ResOps can help support your operational workflows.

FAQs

Q: What is resilience operations?

A: ResOps is an operating model that unifies data security, identity resilience, and cyber recovery into a continuous, automated discipline rather than treating them as separate IT functions. ResOps helps transform resilience from a reactive response to incidents into an active practice that helps continuously understand data access patterns, detect threats and anomalies, and enable fast, intelligent recovery at scale.
Q: What is Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit and how has it evolved?

A: Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit, short for autonomous resilience, was first introduced in 2023 as an AI assistant to help users navigate the Commvault platform more easily. As AI capabilities have evolved, Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit has evolved as well.
In addition to answering questions and guiding configuration, Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit now also includes a library of purpose-built agents to address specific resilience workflows, such as surfacing operational insights, recommending protection strategies, and guiding security-aware recovery decisions. Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit has become an entry point into operational insight rather than just a how-to assistant.
Q: How does Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Data Sense help with operational troubleshooting?

A: Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find subtle warning signs or diagnose issues, users can trigger Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit to analyze the full data set and generate an executive summary highlighting patterns, anomalies, and emerging issues.
Teams can ask follow-up questions in natural language and explore data through interactive summaries or visualizations. For failed jobs, Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit provides root-cause analysis by analyzing logs, summarizing failures, identifying possible causes, and providing personalized next steps for resolution.
Q: What does “guided action” mean in the context of AI-enabled resilience?

A: Guided action refers to AI helping teams move from insight to response more efficiently by recommending specific actions based on analysis of operational data and protection coverage. Rather than simply surfacing information, AI agents like Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Advisor help evaluate resource characteristics, identify gaps between current protection and policy expectations, and present clear recommendations with reasoning.
Teams retain decision-making authority and can evaluate recommendations within their existing governance processes, but the agent helps reduce the manual effort required to identify what needs attention and what actions may be appropriate.
Q: How does MCP-Server enable conversational resilience workflows?

A: MCP-Server uses Model Context Protocol technology to enable conversational interaction with resilience workflows through natural language. Users can ask questions or request actions in everyday language, and those requests are translated into governed API calls behind the scenes.
Identity, role-based access control, and audit logging remain in place, so the conversational interface doesn’t bypass security requirements. This approach helps reduce friction for experienced teams, lower barriers for new users, and enable resilience workflows to integrate more easily with other enterprise systems like ticketing platforms through standardized interfaces.
Q: How does Commvault enable AI to respect security and governance requirements?

A: In Cloud, AI interactions inherit the same identity and role-based access controls that govern the rest of the platform. When AI surfaces insights or recommends actions, it operates within the governance framework customers already rely on.
This means AI respects existing access controls, maintains auditability through standard logging, and operates within clearly defined policy boundaries. The architecture is designed to prevent natural language interactions or agent recommendations from bypassing the security and governance requirements already in place for the platform.
Q: Can organizations adopt AI-enabled ResOps incrementally?

A: Yes. Organizations can start with targeted AI agents that address specific operational pain points rather than transforming their entire resilience practice at once. For example, teams might begin by using Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Data Sense to help surface insights from operational data, then add Arlie vereinfacht komplexe Aufgaben und lässt sich mit vereinfacht komplexe Aufgaben und lässt sich mit Advisor to help maintain protection coverage at scale, and later enable conversational workflows through MCP-Server for easier integration with other systems.
This incremental approach allows teams to build confidence with AI-enabled capabilities, demonstrate value in specific workflows, and scale toward more coordinated, intelligent operations over time as the organization’s needs and capabilities evolve.
Vir Choksi ist Principal Product Marketing Manager bei Commvault.

Verwandte Blogs

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Note: “MCP 2.0” is used here as a colloquial reference to the next-generation evolution of the Model Context Protocol. MCP itself uses date-based versioning (e.g., the latest release being 2025-11-25 at the time of this document’s release) and does not officially define a 2.0 release.

AI agents are no longer just answering questions – they’re taking action. They’re reading files. They’re modifying systems. And in some cases, they’re making decisions that ripple across an entire enterprise.That’s why Model Context Protocol (MCP) 2.0 matters.In a aktuellen Folge von STRIVE, Commvault’s thought leadership series on cyber readiness, I sat down with Werner Nel, Principal, Security and AI Intelligence, at Commvault, to unpack what MCP 2.0 really changes – and why security leaders can’t afford to treat it as a minor spec update.This isn’t a theoretical conversation. It’s a practical look at how enterprises can enable AI innovation without widening their blast radius.

Das Wichtigste in Kürze: Was sich mit MCP 2.0 wirklich ändert

  • MCP 2.0 markiert einen Wandel vom Einsatz künstlicher Intelligenz hin zur Rechenschaftspflicht.
  • OAuth kann einen Zugriff mit minimalen Berechtigungen für KI-Agenten ermöglichen.
  • Strukturierte Schemata können dazu beitragen, das Einschleusen von Befehlen und Missbrauch einzudämmen.
  • Bei der Erfassung können für risikoreiche Aktionen wichtige Haltepunkte eingefügt werden.
  • MCP 2.0 may help improve security – but doesn’t eliminate risk.
  • Es ist unerlässlich, die Befugnisse des Maklers und die Reichweite zu verstehen.

Warum MCP 2.0 einen Wendepunkt darstellt

MCP 1.x was about adoption.It gave enterprises a way to connect AI models to real tools and real data. But as Werner explains, that first wave was never designed to answer the hardest question: How do we let AI agents execute real work inside the enterprise – without turning them into a security liability?

MCP 2.0 is the industry’s first serious attempt to answer that question.Instead of focusing purely on connectivity, it shifts attention to authorization, control, and visibility – three things security teams care deeply about, especially as agents move from read-only assistants to actors with real power.

Die drei wichtigsten Veränderungen im Sicherheitsbereich

  1. OAuth comes to MCP. MCP 2.0 introduces OAuth support, giving enterprises a standardized way to assign permissions and enforce least privilege. Instead of relying on vague trust assumptions, agents can be scoped to exactly what they’re allowed to do—and nothing more.
  2. Structured schemas help reduce prompt injection risk. Structured schemas act like an allowlist for agent actions. If a tool isn’t explicitly defined in the schema, it won’t execute. This can help reduce prompt injection risk and other manipulation techniques that were easier to exploit in earlier implementations.
  3. Elicitation flows add a “pause button.” Elicitation flows can enable workflows to pause mid-execution so a high-risk step may trigger confirmation, validation, or even credential escalation. This can help shift teams from “log and hope” to more deliberate control over sensitive actions.

Vorschau: MCP 2.0 in Aktion

Diese Vorschau verdeutlicht, warum Befugnisse, Auswirkungen und Reversibilität die drei wichtigsten Fragen sind, die sich Unternehmen bei der Einführung von KI-Agenten stellen sollten.

The Gaps MCP 2.0 Doesn’t Solve (And Why That’s Important)

MCP 2.0 is a big step forward – but it’s not the finish line. As Werner highlights in STRIVE, there are still meaningful gaps enterprises need to account for in real-world deployments.For example, enterprises still can’t fully cryptographically prove that an MCP server is the authentic original (vs. a clone or modified copy). Similarly, even if the protocol improves authorization and input discipline, organizations still need to think about signing tools and binaries, and about the environment where MCP servers and models run – because a compromise can translate into broad access depending on how it’s deployed.The takeaway: MCP 2.0 improves the protocol, but organizations still have to make smart decisions about trust, containment, monitoring, and oversight.

Ein einfaches Rahmenwerk zur Bewertung des Risikos von KI-Agenten

One of the most practical moments in the episode is Werner’s three-question risk lens – something CISOs and architects can apply immediately:

  • Welche Befugnisse hat mein Vertreter?
  • Wie groß ist der Explosionsradius?
  • Inwieweit sind die ergriffenen Maßnahmen reversibel?

These questions help teams move from generic “AI risk” discussions to concrete decisions about permissions, containment, and how to handle high-impact actions that may not be easy to roll back.

Die komplette Folge von STRIVE ansehen

This blog only scratches the surface. In the full 20-minute STRIVE podcast, you’ll hear:

  • Warum sich MCP 2.0 so schnell weiterentwickelt hat.
  • Was CISOs derzeit vorrangig angehen sollten.
  • Wohin sich MCP 3.0 voraussichtlich entwickeln wird.
  • Wie Sicherheitsteams Schritt halten können, wenn die Agenten immer autonomer werden.

Schauen Sie sich die komplette STRIVE-Folge auf Readiverse an.Gehen Sie der Sache auf den Grund und prüfen Sie, ob Sie selbst bereit sind.

FAQs

Q: What is MCP 2.0?

A: MCP 2.0 is an updated protocol that governs how AI models interact with enterprise tools and data, with a strong focus on security, authorization, and control.Q: How is MCP 2.0 different from MCP 1.x?

A: MCP 1.x focused on connectivity and onboarding. MCP 2.0 prioritizes securing those interactions.Q: Does MCP 2.0 eliminate AI security risk?

A: No. It can help improve security hygiene but must be paired with strong architecture and governance.Q: What is an elicitation flow?

A: An elicitation flow allows AI workflows to pause for confirmation before executing high-risk actions.Chris Mierzwa ist Senior Director für Portfoliomarketing bei Commvault.


Verwandte Blogs

 

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

When you’re responsible for powering communities across southern Minnesota, cybersecurity isn’t just about protecting data. It’s about making sure the lights stay on. For Southern Minnesota Municipal Power Agency (SMMPA), implementing Commvault® Cleanroom Recoverywar eine strategische Entscheidung, die ihren Ansatz zur Cyber-Resilienz grundlegend verändert hat.

Der Herausforderung direkt begegnen

SMMPA serves as an electric wholesaler to 17 municipal utilities. With approximately 50 employees supporting critical power infrastructure, the organization must maintain constant resilience against increasingly sophisticated cyber threats, where even a short disruption could have widespread impact.

After more than a decade as a Commvault customer, SMMPA faced a new wave of cyber readiness requirements. Cyber insurance providers introduced stricter mandates, including „Air-Gapped“-Backups and malware scanning at rest.

At the same time, the team needed confidence that it could rapidly recover mission-critical systems such as domain controllers, SQL databases, and application servers, without risking the restoration of compromised data.

“As our cyber readiness requirements evolved, we started evaluating Cleanroom Recovery more seriously,” says Alan Wagner, Manager of IT & Corporate Cybersecurity at SMMPA. “We were thinking about additional ways to safeguard and protect ourselves. Cleanroom sounded like it would be a good solution for that.”

Having relied on Commvault for more than a decade and recently expanding into Commvault Cloud SaaSIm Hinblick auf den Schutz für Microsoft 365 betrachtete SMMPA „Cleanroom Recovery“ als logischen nächsten Schritt zur Stärkung seiner Strategie zur Cyber-Resilienz und zur Erfüllung neuer Compliance-Anforderungen.

Ein gemeinsamer Weg zur Umsetzung

SMMPA’s Cleanroom Recovery deployment in March 2025 showcased the power of collaboration between its team and Commvault. Sam Mack, IT/OT and Cybersecurity Specialist at SMMPA, appreciated the responsive partnership: “The Commvault team was quick to address any questions we had during setup.”

The team worked together to optimize its VMware virtual machine configuration for the Azure environment. “We discovered we needed to install some additional tools on the virtual machines to get them running smoothly within Cleanroom Recovery,” Sam explains. This fine-tuning meant its recovery solution was calibrated for its specific infrastructure.

The result? A successful implementation that met all SMMPA’s requirements and positioned it for robust cyber resilience.

Das schützen, was am wichtigsten ist

SMMPA uses Cleanroom Recovery to protect its critical infrastructure, including file servers, application servers, SQL servers, virtual domain controllers, and print servers.

“We’re an Office 365 shop, and we use Commvault Cloud to back up that infrastructure,” Sam says. “In the event of a compromise, getting those domain controllers, file servers, and SQL servers is going to be our priority.”

The solution was particularly well suited to SMMPA’s environment. “I have to give Commvault and their teams a lot of credit for bringing Cleanroom Recovery to our attention,” Sam says. “Our cyber insurance policy is really big on pushing for „Air-Gapped“-Backups and malware scanning at rest, so Cleanroom Recovery was the perfect fit.”

Der Wert des Selbstvertrauens

While SMMPA has been fortunate not to face a real-world cyberattack requiring Cleanroom Recovery, the solution provides valuable peace of mind to the team.

“It gives me a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time,” Alan says. “Cleanroom Recovery gives us confidence that we can restore our systems without worrying that something malicious is being brought back with the data. Nothing is ever 100% guaranteed, but since implementing Cleanroom Recovery, I’ve had far fewer concerns.”

The organization conducts annual testing of its Cleanroom Recovery capabilities, with plans to potentially increase the frequency to biannual testing. This regular validation helps keep the team familiar with the recovery process and maintain confidence in its ability to respond effectively to any incident.

“Cleanroom Recovery gives us a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time – without the concern, or with a minimal concern, that there’s something malicious in the data being restored.”

– Alan Wagner, Manager of IT & Corporate Cybersecurity, SMMPA

As SMMPA continues to refine its cybersecurity strategy, Cleanroom Recovery remains a cornerstone of its defense. The straightforward integration with its existing Commvault infrastructure, combined with the specific capabilities that meet its cyber insurance requirements, made it an obvious choice.

Cara Peterson ist „Voice of the Customer“-Manager bei Commvault.


Verwandte Blogs

More related posts


CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Die wichtigsten Erkenntnisse

  • Commvault erweitert sein Portfolio zur Identitätsresilienz um die Unterstützung von Okta; der Start des Early-Access-Programms ist für April 2026 vorgesehen.
  • Die Identität ist zu einem der wichtigsten Angriffsvektoren geworden, wobei107 Milliarden Identitätsdaten wurden im Jahr 2024 offengelegtund57 % der Cyberangriffe beginnen mit kompromittierten Zugangsdaten.
  • The new capabilities can help provide automated, policy-driven protectionundgranular, point-in-time recovery for critical Okta objectsundconfigurations.
  • Backup data is stored in immutable, air-gapped storage to help safeguard identity environments from ransomwareundunauthorized changes.
  • The solution extends Commvault’s unified Identitätsresilienz platform across hybrid environmentsundwill be priced on a per-user basis.

Identity has become the new frontline of cyber defense –undthe stakes have never been higher.

Today, Commvault is announcing the expansion of its Identitätsresilienz portfolio to include support for Okta, delivering automated protectionundrapid recovery for one of the enterprise’s most critical control planes.Early Access is expected to begin in April 2026.

As credential theft acceleratesundidentity exposures surge worldwide, organizations can no longer treat identity systems as simply another application.Identity is the gateway to everything – users, applications, APIs, automation,undincreasingly, AI agents.When identity fails, the business stops.

Warum Identitätsresilienz gerade jetzt so wichtig ist

Die Zahlen sprechen eine deutliche Sprache:

The rapid growth of non-human, agentic,undAPI-based identities has dramatically expanded the attack surface.Meanwhile, hybrid cloud adoption, SaaS sprawl,undAI-enabled automation have elevated identity providers like Okta to mission-critical infrastructure.

While Okta is built on a resilient platform, when an identity provider is disrupted – whether due to human error, misconfiguration, ransomware, or malicious tampering – the consequences are rapid:

  • Die Benutzer sind ausgesperrt.
  • Die Authentifizierung der Anwendungen schlägt fehl.
  • Umsatzgenerierende Systeme kommen ins Stocken.
  • Kundendienstleistungen werden eingestellt.

And yet, many enterprises still rely on manual scriptsundad hoc processes to restore identity environments – increasing downtime, operational complexity,undrisk.

That’s the gap Commvault is helping to close.

Automatisierte IdentitätsRecovery bei Okta

Commvault’s expanded Identitätsresilienz capabilities can help provide automated protectionundgranular recovery for critical Okta objectsundconfigurations.

Rather than rebuilding entire environments after an incident, organizations can precisely restore what was impacted – quicklyundconfidently.

“Identity is the new cyber battleground, with most modern attacks targeting identity systems,” said Pranay Ahlawat, Chief TechnologyundAI Officer at Commvault.“By extending our Identitätsresilienz capabilities to Okta, we’re helping customers protect one of their most critical control planesundhelping ensusre they can rapidly recover accessundmaintain business continuity even in the face of disruption.”

Wichtige Fähigkeiten

Accelerated recovery from identity disruptions: Automated, policy-driven protection of critical Okta objects – including users, groups, applications,undpolicies – can help organizations to restore access quickly following outages, operational mistakes, or cyber incidents.

Granular, point-in-time recovery: Can help precisely restore only deleted, misconfigured, or compromised objectsundsettings.No full-environment rebuilds required.

Ransomware-resistant protection: Backup data is stored in Commvault-managed immutable, air-gapped storage isolated from production environments, helping safeguard identity data from ransomwareundunauthorized changes.

Streamlined, integrated recovery: Recover complex, interconnected identity systems through a unified workflow – helping reduce operational overheadundsave valuable time during incidents.

Unified Identitätsresilienz platform: Support for Okta extends Commvault’s single-platform approachin hybriden Identitätsumgebungen, wodurch eine einheitliche Durchsetzung von Richtlinien gewährleistet wird,führung,undrecovery across providers.

Early Access ab April 2026

Commvault’s Identitätsresilienz support for Okta is expected to be available through public Early Access in April 2026, with general availability planned for Summer 2026.

The solution will be offered globally as part of the Commvault Cloud Identity Resilience suiteundpriced on a per-user basis.

If identity is now the enterprise control plane, resilience must extend to identity itself.With support for Okta, Commvault continues advancing unified resilience at enterprise scale – helping organizations recover faster, minimize disruption,undstay operational in the face of escalating identity-driven cyber risk.

Learn more about Identitätsresilienz hier.Jetzt anmeldenzu unserem Webinar „Identität unter Beschuss: Mit Commvault Identity Resilience die Kontrolle zurückgewinnen – jetzt auch mit Okta-Unterstützung“.

FAQs

Q: Why is Identitätsresilienz becoming a top priority for enterprises?
A: Identity systems now function as the enterprise control plane, governing access for users, applications, APIs,undAI agents.As credential theftundidentity-based attacks increase, disruptions to identity providers can immediately halt business operations.Protectingundrecovering identity infrastructure has become mission-critical.

Q: What does Commvault’s support for Okta include?
A: The expanded capabilities help provide automated protectionundgranular recovery for essential Okta objects such as users, groups, applications,undpolicies.This will help organizations restore specific items impacted by outages, misconfigurations, or cyber incidents without rebuilding entire environments.

Q: How does granular, point-in-time recovery benefit security teams?
A: Instead of performing full-environment restores, teams can precisely recover only deleted or compromised objectsundsettings.This approach helps reduce downtime, lower operational risk,undaccelerate restoration of normal access.

Q: How does Commvault protect identity data from ransomware?
A: Backup data is stored in immutable, air-gapped storage managed by Commvaultundisolated from production environments.This architecture helps safeguard identity configurations from ransomwareundunauthorized modifications.

Q: When will Okta support be available?
A: Public Early Access is expected to begin in April 2026, with general availability planned for Summer 2026.The offering will be available globally as part of the Commvault Cloud Identity Resilience suite.

Q: How does this expansion fit into Commvault’s broader resilience strategy?
A: Adding Okta support helps strengthen Commvault’s unified, single-platform approach to Identitätsresilienz across hybrid environments.It enables consistent führung, policy enforcement,undrecovery workflows, helping organizations maintain business continuity even during identity-driven disruptions.

Katharine Colucci ist Produktmarketing-Manager bei Commvault.


Verwandte Blogs

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Periods of geopolitical instability, including the current conflict in the Middle East, can lead to an increase in cyber activity from both state‑linked groups and opportunistic threat actors. Government agencies and industry organizations have encouraged businesses to maintain a heightened security posture during this time.
At Commvault, we’re doing exactly that. We’ve elevated our internal awareness, tightened our operational discipline, and reinforced our resilience measures. Commvault also works with a trusted threat intelligence partner, CloudSEK, zusammen, um sich entwickelnde Risiken zu überwachen und unsere Sicherheitsvorkehrungen entsprechend anzupassen. Wir ermutigen unsere Kunden, Partner und Branchenkollegen, ähnliche Schritte zu unternehmen, um auf dem Laufenden zu bleiben und zentrale Cybersicherheitsmaßnahmen zu verstärken.

Worauf sich Unternehmen derzeit konzentrieren sollten

1. Know when to shift into “heightened alert” mode

Have clear internal criteria for when to increase monitoring, limit non-essential changes on critical systems, or accelerate incident‑response readiness. These moves don’t need to be dramatic – they just need to be deliberate and well‑coordinated.

2. Stärkung der Identitäts- und Zugriffskontrolle

During periods of heightened regional tensions, many threat actor campaigns rely on compromising user accounts. Reinforce good hygiene: regular credential rotation, strong authentication, careful review of unusual login behavior, and prompt investigation of anything that looks out of place. For practical steps to reduce identity-related risk, see Commvault’s recent blog on Bewährte Verfahren im Bereich Sicherheit.

3. Achten Sie verstärkt auf Ihre mit dem Internet verbundenen Netzwerkränder und den Fernzugriff

Threat actors often take advantage of internet‑facing systems or remote access tools during global flare‑ups. Ensure these systems are well‑maintained, updated, and monitored.

4. Seien Sie auf mögliche Verfügbarkeitsstörungen vorbereitet

DDoS and hacktivism activity often spikes during regional conflicts. Talk with your service providers, understand your mitigation options, and rehearse your internal escalation and communications plan so you’re ready if availability becomes a target.

5. Stellen Sie sicher, dass Sie sich schnell erholen können

In times of uncertainty, resilience matters as much as prevention. Ensure your critical data is backed up securely, stored in multiple forms and locations, and restorable on short notice. Practicing recovery is just as important as having the backups themselves.

6. Achten Sie auf Falschinformationen, Social Engineering und irreführende Meldungen

Periods of conflict tend to bring surges in defacements, false breach or shutdown claims, and social‑media‑driven narratives. Treat sensational claims cautiously, verify impacts through trusted channels, report suspicious communications quickly, and maintain steady communication practices.

7. Halten Sie sich an die Empfehlungen vertrauenswürdiger Berater

Follow alerts and guidance from reputable government and industry bodies. These sources regularly highlight shifts in regional threat activity and recommend practical steps organizations can take to prepare. A few resources include: CISA-Cybersicherheitshinweise; UK NCSC Reports & Advisories; Sicherheitshinweise des CERT-EU; and die Nationale Schwachstellendatenbank des NIST.


Stay ready, stay resilient

Cybersecurity during global instability is not about panic, it’s about posture. By staying informed, tightening foundational practices, and strengthening resilience, organizations can navigate turbulent periods with confidence.
If you’d like help reviewing your preparation or refining your approach, our team is here to support you.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • Herkömmliche Strategien zur Ausfallsicherheit scheitern angesichts des Ausmaßes,der Geschwindigkeit und der Autonomie KI-gestützter Systeme.
  • Industriell gefertigte Ransomware und KI-gestützte Angriffe zielen mittlerweile auf Backup-Systeme ab und untergraben damit die Grundlage der Recovery.
  • Unternehmen müssen von isoliert arbeitenden Sicherheits- und Recovery-Teams zu einem einheitlichen,kontinuierlichen Modell übergehen,das als „Resilience Operations“ bezeichnet wird.
  • KI-gestützte Resilienz erfordert Echtzeit-Datentransparenz,kontinuierliche Bedrohungserkennung und eine intelligente,fehlerfreie Recovery in großem Maßstab.
  • Moderne Plattformen ermöglichen eine schnelle und verifizierte Recovery-Prozedur und helfen Unternehmen dabei,den Kompromiss zwischen schneller und sicherer Recovery-Prozedur zu vermeiden.

Während Unternehmen um die Einführung von KI wetteifern,kommen CISOs und CIOs zu einer ernüchternden Erkenntnis: Die Resilienzstrategien,die bei traditioneller Infrastruktur funktioniert haben,versagen. Systeme,die sich früher innerhalb von Stunden von Angriffen erholen konnten,benötigen nun möglicherweise Tage. Backup-Ansätze,die für zentralisierte Daten konzipiert wurden,haben möglicherweise Schwierigkeiten mit Workloads,die über Clouds und KI-Plattformen verteilt sind. Unterdessen nehmen Bedrohungen und potenzielle Schwachstellen von Tag zu Tag zu.In einem kürzlich abgehaltenen Webinarging Tim Zonca,Vice President of Portfolio Marketing bei Commvault,auf eine dringende Frage ein,mit der Sicherheitsverantwortliche konfrontiert sind: Wie lässt sich die Ausfallsicherheit aufrechterhalten,wenn KI die Spielregeln grundlegend verändert?

What Industrialized Ransomware and AI Mean for Resilience

CISOs and CIOs are under pressure. In spite of billions spent on cyber defense,nation-states and professional crime rings continue to reap ever larger payoffs from their victims. Ransomware-as-a-service has become widespread,and advanced AI automation is accelerating the industrialization of malware. By including backup systems in their attacks,adversaries are undermining the very foundation of resilience.

As attacks become more sophisticated,targets are becoming more vulnerable. AI is scaling faster than organizations can secure,with exponential data growth,fragmentation across environments,more complex supply chains,and autonomous systems operating with minimal oversight. AI agents and non-human identities now outnumber humans 80 to 1. When these systems make mistakes or expose vulnerabilities,the impact can cascade across interconnected business processes.

Breaches and failures are now almost inevitable; the only question is whether you can recover fast enough to keep your business running. For organizations using legacy systems that assume human-controlled systems,centralized data,and isolated failures,the answer may well be no.

Making Resilience Operational

As AI agents make decisions across the environment,including a significant number of errors,it’s no longer enough to focus on protecting infrastructure. Security leaders must now broaden their operational focus across three critical areas:

  • Kontinuierliche Sicherung der Daten an der Quelle und Überwachung auf Anomalien.
  • Kontrolle der Identitäten von Personen,nicht-menschlichen Identitäten und Geräten,die autonom auf Daten zugreifen und diese nutzen.
  • Erreichen einer vorhersehbaren Recovery von Daten in großem Maßstab ohne Kompromittierung oder Beschädigung.

Traditionell wurden Datensicherheit,Identitätsresilienz und Cyber-Recovery als eigenständige Disziplinen behandelt,jede mit eigenem Team,eigenen Tools,Richtlinien und Anforderungen. Diese Silos lassen Schwachstellen offen,die Angreifer ausnutzen können,und verlangsamen die Recovery,wenn KI-Systeme ausfallen. Um diese Lücken zu schließen,müssen Unternehmen diese Fähigkeiten in einem kontinuierlichen,automatisierten Kreislauf vereinen. Wir bezeichnen diesen Ansatz alsResilienzmaßnahmen (ResOps).

ResOps umfasst drei wesentliche Anforderungen für KI-Resilienz:

  • Understanding your data landscape: Knowing where data lives,its sensitivity,who’s accessing it (including AI agents and non-human identities),and what policies govern that access in real time. For AI workloads,this extends to protections like LLM prompt governance to control how models access data.
  • Continuous threat detection: Automated systems that constantly monitor for anomalies,compromised identities,and data corruption. When AI systems are making thousands of autonomous decisions,you can’t wait for periodic security reviews.
  • Intelligente Recovery: Automatisierte,umfassende Recovery ganzer Cloud-nativer Anwendungen und ihrer Abhängigkeiten. Um eine erneute Infizierung zu verhindern,müssen Teams die Datenintegrität überprüfen und in einer isolierten „Cleanroom“-Umgebung eine forensische Analyse durchführen,bevor vertrauenswürdige Daten wieder in die Produktion zurückgeführt werden.

ResOps in der Praxis umsetzen

Um Unternehmen beim Übergang zu ResOps zu unterstützen,hat Commvault Folgendes eingeführt:Commvault Cloud Unityeingeführt – die bedeutendste Plattformveröffentlichung in unserer Geschichte. Sie wurde entwickelt,um alle drei Dimensionen der Ausfallsicherheit zu vereinen:

  • Die Zusammenführung vonDatensicherheit,Identitätsresilienz,and Cyber-Recovery-Workflowsunter einem einzigen Betriebsmodell.
  • Protecting all workloads,from both today’s production systems to tomorrow’s emerging AI stacks.
  • Safeguarding data regardless of location,whether in clouds,regions,data centers,or edge locations.

A next-generation architecture brings AI automation to all facets of data protection,Datensicherheit,Identitätsresilienz,and recovery. For security and IT teams,the platform provides simplicity at scale with one experience,one policy engine,and one interface designed to protect data,predict threats,and accelerate clean recoveries.

As security leaders know all too well,recovering from the most recent backup minimizes data loss but risks restoring compromised data. Rolling back to a verified clean state may eliminate threats but means losing hours or days of business-critical transactions or AI model training.

With Commvault Cloud,eine kontinuierliche Bedrohungsüberwachung and verified clean recovery points help eliminate this forced choice. The platform architecture automatically maps dependencies across distributed systems,helps maintain immutable backups,and helps enable one-click restoration of entire environments. Recovery can be both fast and clean,helping minimize loss as well as risk.

See ResOps in action

Sehen Sie sich das vollständige Webinar auf Abruf an to learn more about ResOps,explore the architecture and services of Commvault Cloud,and rethink your resilience strategy for the AI age.


FAQs

 Q: What is Resilience Operations (Res Ops)?

A: ResOps is an operating model that unifies Datensicherheit,Identitätsresilienz,and Cyber-Recovery-Workflows into a continuous,automated discipline rather than treating them as separate IT functions. ResOps transforms resilience from a reactive response to incidents into an active practice that continuously understands data access patterns,helps detect threats and anomalies,and enables fast,intelligent recovery at scale.

Q: Why can’t traditional backup and recovery handle AI workloads?

A: Traditional backup tools were designed for centralized,human-controlled systems with isolated failures. AI workloads involve autonomous agents accessing distributed data across clouds and complex dependencies between microservices and containers,and they operate at a scale that manual processes can’t match.

When AI systems fail or are attacked,you need to recover not just data but entire application infrastructures with all their configurations,policies,and relationships – capabilities traditional backup tools lack.

Q: What does “unified resilience” mean in practice?

A: Unified resilience means bringing Datensicherheit,identity management,and Cyber-Recovery-Workflows together under a single platform,policy engine,and operational model rather than managing them as separate functions with different teams and tools.

In practice,this provides a consistent approach to protect all workloads and data locations,automatically correlate security events with access patterns,and orchestrate comprehensive recovery that restores both data and the complete application infrastructure needed to use it.

Q: What’s the difference between cyber resilience and AI resilience?

A: Cyber resilience focuses on protecting infrastructure and recovering from security incidents,treating resilience as an operational state for confronting threats. AI resilience expands this to address challenges unique to AI-driven systems: autonomous agents making decisions with minimal oversight,exponential growth of data and non-human identities across environments,and cascading failures where problems in interconnected AI systems impact entire business operations rather than staying isolated.

Q: How does ransomware target backup systems?

A: Ransomware increasingly targets backup systems by exploiting compromised credentials with privileged access,moving laterally from production systems to connected backup repositories,or exploiting vulnerabilities in backup software itself. Modern ransomware families specifically hunt for backup infrastructure to encrypt or delete recovery points,preventing organizations from restoring clean data and maximizing pressure to pay ransom. This makes offline,immutable,or air-gapped backups essential for resilience.

Q: What is the clean vs. complete recovery dilemma?

A: The clean vs. complete recovery dilemma is the forced choice organizations face during incident response. You can recover from the most recent backup to minimize data loss but risk restoring compromised or corrupted data; or you can roll back to a verified clean state before the incident to eliminate threats but lose significant business-critical data. Traditional backup tools make organizations choose between completeness and safety,while modern resilience platforms aim to provide both simultaneously through eine kontinuierliche Bedrohungsüberwachung and verified recovery points.

Q: What is a cleanroom in Cyber-Recovery-Workflows?

A: A cleanroom in Cyber-Recovery-Workflows is an isolated,secure environment completely separated from production systems to help organizations safely test,validate,and analyze recovered data before restoring it to active use. Cleanrooms help enable forensic investigation of compromised systems,testing of recovery procedures,and verification that restored data is free from malware or corruption – all without risking reinfection of production environments or exposing sensitive data during analysis.

Sam Curcuruto ist Leiter des Produktmarketings bei Commvault.


Verwandte BlogsResilienz für das Zeitalter der KI neu denken

A CIO’s Perspective: Strengthening Business Resilience in the AI Era

Widerstandsfähig gegen die KI-Maschine

Cleanroom Recovery läuten eine neue Ära der Cyber-Resilienz ein

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Die wichtigsten Erkenntnisse

  • “Instant restore” claims often break down at scale due to real-world I/O operations per second (IOPS), rehydration, and infrastructure constraints.
  • Eine große Anzahl von Live-Mounts auf dedupliziertem Backup-Speicher kann zu einem Leistungseinbruch führen, wodurch eine langsame Rückübertragung auf den Primärspeicher erzwungen wird.
  • Reinräume tragen dazu bei, dass forensische Untersuchungen und die Wiederherstellung des Geschäftsbetriebs parallel erfolgen können, anstatt dass es zu nacheinander auftretenden, verzögerungsbedingten Ausfallzeiten kommt.
  • Durch Identitätsmissbrauch vergrößert sich der Schadensumfang, weshalb eine isolierte Recovery-Prozedur und die Recovery von Active Directory (AD) für einen sicheren Betrieb von entscheidender Bedeutung sind.
  • Automatisierte Reinraum-Betriebsanleitungen und wiederholbare Tests helfen Unternehmen dabei, reale Recovery-Kennzahlen zu validieren, bevor eine Krise eintritt.

Let’s start with a quick story about a “ransomware‑proof” environment that took 72 hours to recover, way beyond the organization’s expectations for recovery time objective. It is exactly the kind of situation where Commvault’s Cleanroom Recovery could have helped turn a painful, three‑day outage into a faster, more controlled recovery with less risk.

Kriegsgeschichte: Physik gegen Marketing

On Reddit, a user shared how the financial services firm they work for was hit by a breach. They assumed they had a “dream stack” for quick recovery (but can you really have a “dream stack” without Cleanroom Recovery?): immutable backups, secure storage snapshots, and a modern hypervisor. The datasheets promised “instant mass restore,” yet the business sat offline for three days while everyone tried to drag their environment back to life.

The root cause was not that backups failed, but that the real‑world physics of rehydration, forensics, and identity were never tested at scale. The original poster mentioned that having access to a cleanroom environment would have sped up the process. Let’s dig into this further and address why.

Commvault’s Cleanroom Recovery is designed to address exactly these weak points: It helps automate clean, isolated recovery into the cloud, validates data, and koordiniert Recovery so, dass sie dem tatsächlichen Verlauf der Vorfälle entspricht, not just how diagrams look on slides.

Problem 1: The Rehydration Trap

In the story, “live mounting” a handful of virtual machines (VMs) worked fine, but trying to live mount hundreds crushed the backup appliance. The random I/O running directly on deduplicated, compressed backup storage collapsed the IOPS, forcing the team to rehydrate everything back to primary Non-Volatile Memory Express at about 3 TB/hour for roughly 100 TB of data.

Commvault Cleanroom Recovery helps recover workloads into an isolated Azure‑based cleanroom built on scalable cloud compute and storage instead of trying to run production at scale off a backup appliance.

This allows you to restore critical VMs into a purpose‑built recovery environment, use cloud elasticity to absorb I/O, and automate the recovery sequence so the right systems (identity, core apps, critical data) come up first without bottlenecking on a single backup target.

Problem 2: The Forensic Drag

In the audit, the tech stack was ready in about four hours, but legal delayed touching anything for 72 hours because they had no pre‑provisioned cleanroom. Without an isolated environment with zero routes back to production, the forensics team could not safely investigate while the business recovered, so everyone waited for the all-clear before starting any real restore.

Cleanroom Recovery provides an on-demand, isolated recovery environment explicitly built for simultaneous recovery and forensic analysis. Sie können innerhalb weniger Stunden einen abgeschirmten Reinraum in Azure einrichten, recover systems into it, and let security and legal teams perform read‑only forensics and threat scanning while operations validates applications and prepares for cutover – dramatically shrinking “forensic drag” as a contributor to downtime.

Problem 3: Identity Blast Radius

The environment in the story had a single admin account with access to both the hypervisor and backup console, which meant if attackers pivoted that far, immutability could become just another setting they flipped off. Identity, not just data, was the real blast radius problem.

Cleanroom Recovery is designed to help reduce dependency on the compromised production identity plane during recovery, allowing isolated access and planned support for AD restoration in the cleanroom.

Durch die Auslagerung von Identitätsdiensten in einen isolierten „Cleanroom“ and using separate, least‑privilege access paths, you can help validate AD, help enforce proper authorizations, and help protect backup control planes from being trivially compromised by the same credentials that were used in production.

Wie Cleanroom Recovery diese Geschichte verändern würde

Hätte dieser Kunde „Cleanroom Recovery“ genutzt, hätte seine Recovery-Geschichte ganz anders verlaufen können.

For organizations that already invest in “ransomware‑proof” stacks, the missing piece is often not more features but a Reinraumstrategie that respects physics, identity, and legal reality. Commvault Cleanroom Recovery is designed to close that gap and help turn recovery from a three‑day war story into a controlled, provable, and much faster operation.

FAQs

Q: Why did the “instant mass restore” approach fail in the ransomware scenario?
A: While live mounting a few VMs worked, scaling to hundreds overwhelmed the backup appliance due to I/O constraints. Deduplicated and compressed backup storage is not designed to handle full production workloads at scale, leading to performance collapse and delayed recovery.

Q: What is the “rehydration trap” in disaster recovery?
A: The rehydration trap occurs when organizations must restore large volumes of compressed backup data back to primary storage before systems can operate normally. This process is limited by throughput rates, which can dramatically extend recovery times when dealing with tens or hundreds of terabytes.

Q: How does a cleanroom help reduce forensic-related downtime?
A: A cleanroom provides an isolated environment where forensic teams can safely investigate while IT simultaneously restores systems. This parallel approach helps eliminate long waiting periods for legal or security approval before beginning recovery efforts.

Q: Why is identity such a critical factor in ransomware recovery?
A: If attackers compromise administrative credentials tied to both production and backup systems, immutability controls may no longer provide protection. Isolated identity recovery and least-privilege access can help limit blast radius and support a safer restoration process.

Q: How does Cleanroom Recovery help improve recovery orchestration?
A: Cleanroom Recovery helps automates workload sequencing, cleanpoint validation, and cloud-based recovery infrastructure provisioning. This structured approach aligns recovery with how incidents actually unfold, helping organizations regain control faster and with greater confidence.

Q: What is the strategic lesson for organizations with “ransomware-proof” stacks?
A: Advanced features alone do not guarantee fast recovery. A Reinraumstrategie that accounts for infrastructure physics, identity isolation, and legal realities helps enable organizations to turn theoretical resilience into measurable, repeatable recovery performance.

Nico Guerrera ist Senior Solutions Marketing Manager bei Commvault.

Verwandte Blogs

Active Directory-Wiederherstellung: Warum manuelle Methoden nicht mehr praktikabel sind

Wiederherstellungstests: Das fehlende Element in den meisten Cyber-Resilience-Programmen

Ihr modernes Spielbuch für schnelle Reaktion und saubere Wiederherstellung

Cyber-Resilienz freisetzen: Die Macht der Reinräume

Warum die Wiederherstellung von Reinräumen und Cyber-Tests entscheidend für die Widerstandsfähigkeit im Cyber-Bereich sind

More related posts


Cyber Resilience

Read more about Cyber Resilience