Skip to content

AWS re:Invent 2022 just wrapped up, and for me, I have finally made it back to Australian shores for our non-snowy, hopefully, hot Christmas Day.

On the long flight(s) home I was able to reflect on the 119 new services and features that were announced as part of AWS re: Invent 2022 from Nov 28 – Dec 2nd, and the myriad of new capabilities we announced in our latest innovation release, Commvault Platform Release 2023 (released Dec 15th, 2022).

I know I felt like a kid in a candy store trying to decide what I’m going to try first when I return to the office in 2023.

I saw four major themes emerge across re: Invent that underpin the responsible building of secure and sustainable cloud native applications. Builders need to consider security of data in-transit and at-rest, responsible scaling, and cloud operations that respond to planned and unplanned events:

Securing the cloud, which continues to be Job Zero for both AWS and builders alike as we strive to build more data-driven applications, that are more accessible than ever before. Some notable releases that will positively impact AWS and Commvault customers looking to protect their AWS resources were:

Scaling Cloud Operations was a recurring theme for almost all service and feature releases. As businesses expand in AWS service adoption and consumption, they need to be able to scale or automate their cloud operations. Some notable enhancements to help achieve cost-optimized operations were:

  • AWS announces Systems Manager Quick Setup for Resource Scheduler which simplifies the setup of scheduled resource power-up, power-down, and optimization of capacity to save costs.

    Commvault automates the power management of MediaAgents by powering Amazon EC2 data management resources on and off as backup and recovery activities occur. This approach saves runtime costs but migrates resource optimization to an event-driven scalable approach. You can automate resource power management. backup, and recovery operations with Commvault too, just grab an access token to access the Commvault service endpoint and start automating today.
  • Amazon CloudWatch launches cross-account observability across multiple AWS accounts and helps you monitor and troubleshoot applications that span multiple accounts. This is often critical for your data management system, like Commvault where your protected workloads and data management workloads reside in different accounts.

    Commvault recommends using AWS resource tags on all your AWS resources to improve visibility, cost transparency, and support automation efforts. Commvault ensures tags are restored on all created resources and allows the setting of tags during recovery to align with your observability, cost management, and security needs.
  • Amazon FSx for NetApp ONTAP announces four new ease-of-use features added more usability enhancements to the fully managed shared storage service built on NetApp’s popular ONTAP file system. Customers looking to expand into AWS, lift-and-shift applications with high-IOPS storage needs, or reuse on-prem storage management processes in AWS – can now adopt Amazon FSx for NetApp ONTAP.

    Commvault announced IntelliSnap® snapshot management for Amazon FSx for NetApp ONTAP in Commvault Platform Release 2023. Customers can orchestrate application-aware snapshots and service-independent streamed backup copies of Amazon FSx for NetApp ONTAP SMB shares, NFS exports, and iSCSI volumes. Snapshot-based backups can be replicated using NetApp SnapVault and SnapMirror between Amazon FSx for NetApp ONTAP file systems or between on-prem and the AWS Cloud.

Expanding to new Regions and Zones was a common theme across 2022 with AWS expanding availability into three new regions – Europe (Zurich) eu-central-2, Europe (Spain) eu-south-2, and Asia Pacific (Hyderabad) ap-south-2  and up to a total of 281 AWS Local Zones. AWS services and resources are now even more available to begin your 2023 migration projects.

Commvault makes migration simpler, more secure, and faster by converting and replicating UEFI-based VMs to Amazon EC2, including the programmatic modification of on-prem Linux hosts to automatically inject required Amazon EC2 nitro OS drivers. Get started today with a one-time conversion or set up periodic replication and cut-over to running in AWS when required.

New toys for builders is what re: Invent is all about, and 2022 was no exception.

  • Amazon RDS Optimized Reads is now available for up to 50% faster queries on Amazon RDS for MySQL offers up to 50% faster query processing compared to previous generations. Depending on the data protection scheme employed, this performance may deliver significant performance to data management activities that share processing resources on Amazon RDS instances, more in the future when our lab testing completes…
  • Introducing Elastic Network Adapter (ENA) Express for Amazon EC2 instances delivers enhanced networking performance via the introduction of the Scalable Reliable Datagram (SRD) protocol. Higher single flow bandwidth and lower latency between EC2 instances could deliver significant backup and recovery performance, more when we emerge from the Commvault labs…
  • AWS announces Amazon VPC Lattice (Preview) is an application layer networking service that simplifies the connection, securing and monitoring of service-to-service communication. As monolithic applications become more and more decomposed, and more and more decoupled – Amazon VPC Lattice becomes crucial. Commvault will watch this service closely with potential applications to our Amazon EKS and Amazon VPC protection portfolio.

Commvault eagerly awaits the impact some of these performance improvements will deliver on data protection, replication, and recovery.

You can get started today by downloading Commvault Platform Release 2023 from the Commvault Software Store, or if you want don’t want to setup and configure a data protection system – sign up for a free 30-day Metallic Trial and start protecting your AWS resources today.

Have a happy holiday and rest up, as all the work you did to be Recovery Ready with Commvault and Metallic in 2022 will pay off during the holiday break…

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The holiday period is upon us, and for me that means one thing, watching Die Hard. 

I may have a soft spot for Kevin McCallister and the charm of Home Alone, but Bruce Willis going up against a band of resolute (and Alan Rickman obviously aside) bad actors (sorry – couldn’t resist the pun) intent on gaining access to a vault of untraceable bearer bonds is the perfect holiday film.

But as I settle down watch it this year, I am struck by the parallels between the movie’s plot and a ransomware attack.  So, what lessons can Die Hard tell us about a ransomware attack?

1. Size of Attack Surface matters

The location for the majority of the Die-Hard action was the Nakatomi Plaza – a 30 plus floor sky scraper in the heart of Los Angeles. 

From airducts to elevator shafts, lobbies to rooftops, and everything in between, there’s a lot of real estate to secure and a lot of places for bad guys to hide. 

Now a data estate is exactly the same.  The more surface there is, the more vulnerabilities and failure points there may be to access or compromise your data.  And it is a big concern, in fact according to recent ESG research, only 12% of IT professionals report that their ransomware detection tools are adequate and can also cover the growing data estate, regardless of where data lives.

2. A ransom might not be what they are after

Remember that scene when Alan Rickman lists names of terrorists that the gang wishes to exchange for the hostages?  It’s a smokescreen with the aim of misdirection. 

The same is true in data security – with so many bad actors using data now in malicious ways (think leakage, exfiltration, theft and restructure) – holding data hostage for a sum of money is a prime objective anymore.  In fact, so much so that ESG estimate that preventing data damage is now the top concern of IT decision makers (88%) overtaking the concerns around recovery.

And if you actually pay the ransom, there is little guarantee that you will get your data back. In fact, according to Matthew Woodwood – only 8% of all ransomware-paying organizations got their data back even after paying the ransom.

3. Social Engineering – The bad actors will have done their research (and are very sneaky)

Just like in Die Hard, the attackers would likely have done their research and will have a sophisticated and detailed plan – that are designed to do more than just data encryption.

They are also sneaky and may employ social engineering tactics, which is a popular tactic among attackers because it is often easier to exploit people than it is to find a network or software vulnerability.  Passwords and existing security measures are very valuable and internal employees are often targets – at all levels of the organization.

Social Engineering will often be used as a first step in a larger campaign.  You can find out more in this tech target article here.

4. The attacks will keep on coming (and coming)

As well as being well informed, motivated and cunning, our attackers are persistent.  John McClane would have had a much easier job if he was fending off just one bad actor, but the reality is (as with in a ransomware attack) the numbers are stacked against him.

For attackers, a single-minded strategy rarely leads to a successful breach. Threat actors increase their chance for return on investment by following multiple paths to their target – critical business data – by diverting their attack strategies. 

5. Don’t “just” rely on recovery or insurance

If Bruce Willis just waited it out with the hope that insurance would pay out, then it would be a pretty short film, and one that might not have had a dramatic ending!  

Cyber Insurance is an area that has changed rapidly over the past 12 months.  Clauses around cybersecurity insurance are increasingly tightening – as evidenced by Lloyds of London earlier this year.  Many insurers are also imposing stricter safeguarding requirements, which although helping to support increased levels of cyber security defences, this can also leave some organizations and especially SMB’s exposed, as they are less able to meet the new minimum threshold limits.

Dr Sally Eaves covered this exact topic in this excellent blog here

Conclusion – A Proactive Approach to Ransomware is essential (be more John McClane)

OK – all film metaphors aside, we do have a serious holiday (and beyond) message for everyone. 

In addition to your overall cybersecurity plan and your established data recovery strategy, your ransomware protection needs to be proactive and start before your data is compromised. 

Metallic® ThreatWise™ is that difference.  It’s early warning ransomware detection which enables businesses to actively defend data, protect backup infrastructure, and respond to threats sooner. How does it work? Using patented deception technology, ThreatWise tricks malicious bad actors into engaging fake resources, exposing themselves before data leakage, exfiltration, or encryption. It means less risk of data impact, less downtime, and less recoveries. . 

It’s time to get ThreatWise™ and defend your data, not just recover it.  It’s the solution that John McClane would choose. 

End Credits (the cast)

  • John McClane (Bruce Willis)  – Metallic® ThreatWise™
  • Hans Gruber (Alan Rickman) and team – Hackers/ Ransomware Operatives
  • Al Powell (Reginald VelJohnson) – Your friendly IT and Security Teams

Modern Cyber Deception: Introducing Metallic® ThreatWise

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

I’m proud to be the Executive Sponsor of our CapAbilities ERG, an employee group whose mission is to raise awareness and break down the bias of workplace issues that affect people with disabilities and/or caregivers of those with a disability. We recently had a Courageous Conversation virtual event, in partnership with our Family Support Network EAG, on managing your career while caring for a loved one with a disability. I was fortunate to be able to share my own story with the support of Commvault. In honor of International Day of Persons with Disabilities on December 3rd, I wanted to share my story here as well.

My daughter Emily, now 18 years old, was born with Goldenhar syndrome, a rare craniofacial condition. She was born missing her entire lower jaw, and her craniofacial problems have required her to have more than 40 surgeries to date. While she’s come such a long way since the day she was born, Goldenhar syndrome is something she will continue to live with throughout her entire life.

I’ve been at Commvault for almost 18 years, so Emily’s journey began within my first year at Commvault. When Emily was born, I basically had to mature overnight. And I have to admit, Emily’s story was not something I shared immediately with my colleagues. There were countless times I took conference calls from hospitals and waiting rooms, and nobody knew. But as I matured professionally and became more comfortable, I went from hiding Emily’s story to advocating for it – Emily’s story eventually became a part of me at Commvault.

Our job as parents of children with disabilities is to give them the opportunity to have the best life possible, and that’s something my wife, Nancy, and I have always focused on. It’s all about advocacy – when you start with advocacy, then change will happen. And over the years, as we continued to advocate for Emily, we also instilled within her the importance of advocating for herself. And moreover, to never, ever, stop. Part of Emily’s early advocacy outreach included Bring Your Child to Work Day at our headquarters office multiple times early in her teen years.  Emily brought her service dog and shared her story with our Vaulters. She loved doing it, and this opportunity jumpstarted her own advocacy journey, as she began to present at schools and talk to students about her story. Over the years, Emily’s mission has been to spread awareness about kindness and acceptance to kids of all ages by doing presentations live on-site, through video conferences, and on social media. I couldn’t be more proud of her.

https://play.vidyard.com/wtBUwSQaydEVuGb4JrVKdQ

Emily’s journey has taught me so much, both personally and professionally. While there have been so many life sessions and learning moments, a few that we focused our discussion on during our Courageous Conversation are:

  1. Listen and pay attention to detail. When doctors start using fancy words, you have to listen. When you’re home dealing with your child with a disability, you have to be able to listen to what they’re saying (and not saying) and pay that close attention to detail. These skills have not only taught me to be a better father, but a better professional as well. Staying present and listening helps me do my job better and best support my team.
  2. Value the impact of support. It’s incredibly important to accept the support you may need, and sometimes that means being vulnerable. Lean on the resources available to you and leverage them. As I mentioned earlier, I wasn’t always open to sharing Emily’s story and accepting support at work. But to manage work-life balance and be my best self at Commvault, I realized how impactful a support network really is.   
  3. Embrace life’s challenges. Navigating the unknown and overcoming obstacles is what makes us stronger at home and at work. While there have been so many challenges related to Emily’s disability, I realize how much I have learned and grown from our situation. The life skills I’ve developed have not only made me a better person at home, but they’ve made me a better colleague and leader at Commvault.

Without the support of Commvault over the past 18 years, I wouldn’t be where I am today. Showing how we care is foundational to who we are as a company. Our CapAbilities ERG is creating a safe and empathetic space where Vaulters with disabilities, caregivers, and allies can openly and honestly have discussions and drive change together.

When I look back, I wouldn’t change a thing about Emily’s journey and our situation. It’s made me who I am today, and Emily continues to shine and make a difference in the world every day.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The holiday season is now officially upon us, and to keep with the spirit of giving we wanted to give you all another reason to be excited about our upcoming December product release.  Across industries, customers are always looking for ways to leverage cloud for the agility, simplicity and scale that it can provide. In that vein, our ecosystem partners are always looking for ways they can enhance and differentiate the hybrid cloud experience. Established industry leaders Amazon Web Services (AWS) and NetApp have collaborated on a cloud-native storage solution that provides the data accessibility and management benefits of on-premises NetApp storage married with the simplicity, predictability, and ease of a fully managed AWS service. This fantastic combination – Amazon FSx for NetApp ONTAP — not only gives existing NetApp customers an easier way to extend their on-premises deployments into the cloud, but also provides AWS customers the ability to architect modern, differentiated cloud applications that provide fast, consistent user experiences.

Commvault prides itself on being the essential layer that simplifies how our customers’ data is moved and used between cloud and on-premises environments and ensuring it is protected through the entire process. In this case, we’ve tapped into the strong relationships and many years of collaboration and innovation with both AWS and NetApp and we’re delivering support for Amazon FSx for NetApp ONTAP with Commvault Platform Release 2023. With this newly announced support, we’ll be providing customers the ability to:

  • Migrate workloads to AWS seamlessly by using Commvault to orchestrate the creation and replication of your on-premises NetApp ONTAP storage volumes to Amazon FSx for NetApp ONTAP.
  • Protect your new modern apps in AWS that leverage high-performance NetApp storage, management, and QoS controls. Commvault snapshot, SnapVault, and SnapMirror integration provide accelerated, automation protection for your Amazon FSx for NetApp ONTAP workloads.
  • Simplify business continuity and meet SLAs by adopting a snapshot backup, SnapVault replicated-backup, and SnapMirror mirrored-backup approach to recovering your applications in place or remote Regions.

Speaking of our fantastic collaboration with AWS, we’re in Las Vegas sponsoring AWS re:Invent right now!  That means you’ve got an opportunity to come and talk to us in person about our newly announced support for Amazon FSx for NetApp ONTAP, our deep integration and collaboration with AWS, or how you can get started with Commvault on AWS Marketplace today.  Here’s how you can get involved and learn more:

  • Come visit us at re:Invent 2022 at the Venetian Expo Halls.  We’re at Booth #1940 from Monday evening to Thursday afternoon. I will be personally floating around each day, so stop by and say ‘Hi’ and talk to me about your organizations’ toughest data challenges.
  • Register for a private meeting or for one of our after-hours receptions or keynote watch parties in our hospitality suite.
  • We’ll be presenting about Amazon FSx for NetApp ONTAP and our joint NetApp solutions in NetApp’s sponsor booth (Booth #2404) at the following dates/times:
  • Tuesday, November 29th at 1 PM PST
  • Wednesday, November 30th at 3 PM PST
  • Thursday, December 1st at 11 AM PST

The holiday festivities don’t end here in Vegas – we’ll be teaming up with our friends at AWS and NetApp once again for an amazing virtual holiday event where we’ll talk hybrid cloud data management and Amazon FSx for NetApp ONTAP, all while having a little bit of fun with Lego Master Tyler Clites.

 

If you missed us at AWS re:Invent – or if you just want to grab one of the great holiday-themed Lego kits – you can register for that event here.

It truly is the most wonderful time of the year – and we’re extremely excited about sponsoring and participating in AWS re: Invent, one of the biggest tech events of the year. We hope you’ll join us in Las Vegas to learn a little bit more about our solutions and to have a little bit of fun in the process. We’re also very excited and thankful for our ongoing collaboration with both AWS and NetApp, and we’re looking forward to where these partnerships will lead – for our joint customers and their valued data – in 2023 and beyond.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

IaaS, PaaS, SaaS, oh my! A lot has changed since the first recognizable platforms delivered Infrastructure-as-a-Service solutions in the early 2000s. What once seemed to be a surefire way of cutting IT costs from the outsourcing of hardware and provisioning management within the public cloud is no longer so cut-and-dry.

Over the years, the public cloud space has seen an ever-increasing rise of costs and potential nasty surprises in their delivery models leaving many IT decision makers reevaluating how and where they run their workloads.

Juggling the decision-making process of what stays in which public cloud, what workloads get “repatriated” back to on-prem solutions, and when it makes sense to leverage newly introduced delivery models is a full-time job in and of itself.

During Commvault Connections 2022, we dove into the state of the public cloud, addressed some of the common challenges that organizations face in today’s modern cloud era, and shared how Commvault solutions can simplify your journey, reduce corporate risk, and increase IT productivity.

Read on to learn more about the sessions and how Commvault takes the guesswork out of investing wisely in an uncertain world.

Navigating Cost Optimization & Risk Mitigation in the Modern Cloud Era

In today’s multi-cloud and hybrid-cloud environments, data sprawl transcends storage concerns and enters into the dangerous territory of increased corporate risk, threatened profitability, and hindered operational excellence. With so many locations for workloads being available across a multitude of delivery models and form-factors, just getting line-of-sight into all your data, no matter where it lives, is critical. Commvault solutions benefit from having the industry’s broadest workload coverage giving you capabilities and insights that allow you to rein in data sprawl, reduce your corporate attack surface, and optimize cost-effectiveness.

Embracing the Power of Automation

More than ever, today’s IT Professionals face increased pressure to do more with less. In trying to overcome the challenges and costs associated with a cloud vendor lock-in, many IT Leaders are faced with an uphill battle of finding skilled labor across all major cloud competencies…and then having to pay for it. Commvault allows you to overcome the IT skill gap by providing the ability to transform and move data from one cloud provider and/or form-factor to another, natively, all without the need for skilled labor.

More Data, More Risk? Introducing File & Object Archive backup-as-a-service

https://play.vidyard.com/9i2zJtux2kZFu7Q6zzfvuN

Got a need? Consider it covered! From informed data placement to actionable insights, Commvault’s Metallic® File & Object Archive provides you with a trusted cloud-based archive service. We use modeling tools, actionable data insights and compliance-friendly operations to reduce your costs and increase your productivity and quality of service. With Commvault, we’ve got the expertise and experience to ensure that your organization’s data will be compliant now and for years to come.

For a limited time, you can access all the Commvault Connections 22 content on demand here.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Get energized and learn new strategies and products to fight ransomware through our on-demand Fending off Ransomware sessions from Commvault Connections 2022. If you missed our event, take this opportunity to watch sessions and visit the DemoZone. This best-in-class cloud data management experience provides organizations and IT decision-makers with the insight and best practices needed to protect and recover their data from ransomware.

Ransomware Offense

Breaches, leaks, and losses don’t have to be disasters. Hear how our proactive and responsive data protection capabilities help keep your data safe and your company out of the headlines. See our full agenda here.

Ransomware Protection and Recovery: Developing Your Zero Loss Strategy

Reducing the risk of ransomware is challenging, but embracing a Zero Loss Strategy is essential to reduce the impact of an attack. Beyond simply adhering to zero trust principles and hoping for the best, the ultimate solution can reduce costs for your organization by utilizing one centralized management platform to gain end-to-end data visibility, protect hybrid workloads, and have the ability to rapidly recover – all through a unified approach.

Trailblazing Data Security – Safeguarding Data Before It’s Compromised

With data leakage, exfiltration, and theft on the rise, today’s businesses need advanced capabilities to spot and contain security threats early – not just recover from them. We spotlight how our modern ransomware detection service, Metallic® ThreatWise™, actively engages and surfaces unknown and zero-day threats the moment an attack begins. In addition, we’ll highlight our unique cyber-deception capabilities and the value of early warning.

https://play.vidyard.com/JzFwNSvsDYzzVvQ2SafRmg

Ransomware Retrospective: Supporting the Recovery

Are you confident that your organization will recover quickly in the event of a ransomware attack? Do your teams know their roles and responsibilities, and are you certain you have the proper resources? Hear real customer recovery stories from our Commvault® Support & Services Team as they share the good, the bad, and the ugly. Learn why some recoveries went well and why others did not.

Protect Your Data and Recover with Confidence

Simply put, how is your organization reducing the impact of a potential ransomware attack? How are you safeguarding data from double and triple extortion ransomware attacks (such as leakage and exfiltration)? And are you confident that your organization will recover quickly in the event of a ransomware attack? Gain the knowledge your organization needs in order to be successful against ransomware.

Our Connections event was hosted by industry leaders, customers, partners, and Commvault experts that share the insights, best practices, and technical tips you need to Innovate with Confidence and deliver whatever your business needs tomorrow.

For a limited time, you can access all the Commvault Connections 22 content on demand here.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

I’m so proud to announce the inspiring Vaulters who just won our FY’23 Q2 CEO Living Our Values Awards.

Here at Commvault, we continue to see our Vaulters live our values and empower each other to be our best selves as we connect, inspire, care, and deliver.

This week we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work.

I’m so proud to announce our FY’23 Q2 CEO Living Our Values Award winners:

Kash Ansari
Senior Director, Sales Engineering

Zack Brigman
Senior Manager, Product Marketing

Yvonne Singleton
Senior Director, Field Operations

Commvault Grid Cross-Functional Team

Gregory Jackamonis
Manager, Customer Support, Software Defined Storage

Justin Wolf
Senior Product Manager

Ram Ankireddypalle
Principal Manager, Development

Account Team

Steve Young
Senior Director, Sales Engineering

Jason Hand
Enterprise Account Executive

Jonathan Wright
Principal Sales Engineer

Richard Tynan
Senior Director, Professional Services

Jietse Vercammen
Solutions Architect

Sunil Telagamsetti
Senior Manager, Development II


All these winners set an inspiring example and embody what it truly means to be a Vaulter!

If you are interested in joining our team and becoming a Vaulter, visit our Careers site for more information.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

There are many reasons to register for our Connections 22 virtual event on November 2nd or 3rd 2022 In fact, we could have added more! 

With so many new additions to the Connections experience, including Virtual Exhibit Booths, a DemoZone, the Connections Challenge, and even more opportunities to network, here are our (non-definitive) reasons why you should spend a few hours with the best of data management.

1. Keynote – Innovate with Confidence
Our CEO Sanjay Mirchandani believes there has never been a better time to be in IT. His inspiring keynote focuses on how you and your team can innovate with confidence by removing complexity, going on the offensive, and embracing cloud data management.

2. Connections is THE Cloud Data Management Experience
As Gartner recently confirmed, *Commvault has the leading data protection solution for customers embarking on their cloud journey (and this was for the third time straight). 

Our supported technologies and partnerships with top-tier cloud providers stand apart, and Connections 22 follows suit – no other data protection event can boast Microsoft, Oracle, and Amazon Web Services (AWS) on the bill (now that’s multi-cloud).

3. Join the #CVConnections22 Social Conversation
During and after the event, make sure you keep your socials close to track and engage in the lively #CVConnections22 conversation online. Share your highlights and key takeaways – we want to know what you think!

4. Roadmap Session
For many attendees, Ranga Rajagopalan’s roadmap session is the highlight of our packed agenda. With innovations coming thick and fast, we’re delving into what’s new for our Intelligent Data Services Platform – including our #DMaaS Metallic solutions.

5. Take the Connections Challenge
Did someone say SWAG? Yes – we did, loud and clear. Points mean prizes at Connections 22, and by participating in the **Connections Challenge, you could win some awesome giveaways, including a $5,000 AMEX vacation voucher (and you can relax with the knowledge that your data is safe and sound with Commvault).

6. The Experience (no Zoom here)
Connections 22 is a Zoom-free zone – and it’s definitely NOT death by slideware. As well as our keynote sessions, you will have access to DemoZones, Exhibit Booths, and a Networking lounge.

7. Fending Off Ransomware Track
While they may be inevitable, breaches, leaks, and losses don’t have to be disasters. Go on the offense with our proactive and responsive data protection capabilities that keep your data safe and your company out of the headlines. From cyber deception to recovery, see the most comprehensive cybersecurity portfolio available in the industry today.

8. Investing Wisely Track
Innovation may be priceless, but budgets aren’t endless. We can help you find the right balance, gaining value from your data while managing your costs to protect it on your journey to the cloud.

9. Modernizing Data Management Track
When your business dreams it, you need to deliver. Take charge by embracing a modern data management strategy that intelligently and quickly scales, supports new workloads, and enables you to use your data in creative ways.

10. Customers!
Customers are a huge part of our Connections 22 agenda and take a starring role throughout the day’s sessions. As well as our top-rated customer panel starring leaders from Oral Roberts University, customers are featured throughout our technical track sessions, including CHS Inc. and Swinerton.

11. DemoZone
Sometimes there is nothing better than a good demo. At Connections 22, you’re in luck! Our DemoZone shows off our Commvault portfolio in a selection of customer use cases, including Unified Data Management and Protection and Defending Data with Cyber Deception.

12. Exhibit Booths
Another “first” for Connections 2022, make sure you visit our Exhibit Booths where our sponsors Microsoft, Oracle, and AWS are ready and waiting to engage and answer any questions you may have.

13. Networking – Engage with Peers – Community Hub
There is so much to explore at Connections 22, including our new Customer Networking area, where you can meet and rub virtual elbows with fellow attendees. Available from the home screen – it is a key destination (and where the cool kids hang out). See you there!

14. Customer Innovation Awards
Also new for this year is Commvault’s first-ever Customer Innovation Awards! The finalists are set – but who will take home the spoils? Tune in to find out!

15. Three Time Zones, One Virtual Event Experience
Connections 22 is an experience best consumed live to take advantage of all the networking and engagement opportunities we offer (see reason no. 13). To help everyone get that opportunity, we have three time zones optimized for our U.S., APJ, and EMEA attendees. Go to the agenda page here and select your preferred time zone to see what works best for your schedule.

16. First look at new Commvault Portfolio additions
Where can you get a first look at the latest Commvault Portfolio additions? Connections 22, of course. We can’t give the game away just yet, but let’s just say that you don’t want to miss our Roadmap session and our “Control Storage Costs and Lower Risks using our latest SaaS-delivered Data Service” session in our Investing Wisely Track.

17. The Modern CIO’s Journey to the Cloud
During this must-see session of Connections 22, our CMO, Isabelle Guis, interviews Michele Buschman, CIO of American Pacific Mortgage. Michele describes the ups and downs of cloud transformation within an enterprise and leaves you with a clear, five-step checklist you can use for your own cloud journey.

18. Microsoft Session – Protect Your Critical Assets with Azure
Businesses use multiple applications running their day-to-day operations, with every minute of downtime negatively impacting customer trust. Business Continuity and Disaster Recovery plans ensure that services can continue to operate during maintenance, failure, and large-scale outages.

Join Saurabh Sensharma of Microsoft and David Ngo, CTO of Metallic, for this session to learn about Azure and Commvault solutions integrated with and built on Azure that help customers protect their critical assets, including VMs, databases, PaaS and SaaS services (like M365). Check out the latest product releases, customer examples, product experience, and much more.

19. Oracle Session: Protecting Against Ransomware in a Multi-Cloud World
Multi-cloud environments bring customers options, efficiency, and price performance. They also increase complexity and the potential for security breaches. Join Joe Corvaia of Oracle and Commvault’s Alan Atkinson to discover how cloud infrastructure hyperscaler Oracle is optimized for the expanding multi-cloud universe – and how they are working with partners like Commvault to provide ransomware and security solutions for enterprise customers.

20. AWS Session: Transforming and Modernizing Your Data Strategy
Our decades-long relationship with AWS is built on a shared customer obsession. Join AWS’ Jake Burns, IDC’s Archana Venkatraman, and Commvault’s Vidya Shankaran for their Connections session on Transforming and Modernizing Your Data Strategy, where they will discuss recent trends in data management and digital transformation. You will also gain valuable insight into how your organization can be more efficient, more resilient, and better prepared should disaster strike – and do it all with minimal impact on your bottom line.

21. Celebrate three years of Metallic, our DMaaS portfolio
Our award-winning Data Management as a Service (DMaaS) portfolio, Metallic, has just turned three years old. And in that time, we’ve quadrupled offerings, geographically grown to over 33 countries, and have over 2,500 customers worldwide. Discover the latest innovations, including the recently announced Metallic® ThreatWise™ Data Security Service.

22. Getting clued up on Kubernetes with Nigel Poulton
Missing (or missed) KubeCon?

Whether you are a Kubernetes aficionado or just interested in upping your knowledge, we have the go-to trainer for Docker and Kubernetes as part of our Modernizing Data Management track. Learn about stateful containers, what efficiencies you can gain from Kubernetes adoption, and why your DevOps colleagues should become your best friends.

Ready to join the fun? Register today for Connections and hold your place for a truly unique integrated experience!

* https://www.commvault.com/blogs/three-for-three-commvault-scores-highest*

**Terms and Conditions apply.** More information will be available on the event platform during the event.
*Subject to eligibility requirements and applicable laws. Government employees are ineligible for this giveaway.*

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Commvault Connections is fast approaching and we’re excited for a lot of things – connecting with our attendees in a truly unique and interactive experience, celebrating our customers at our inaugural Customer Innovation Awards, and having insightful conversations with our peers around key market trends, like ransomware protection, data management, and smart investments.

What’s more, this year’s show features our sponsored Partner Solutions Sessions – and we’re excited to add Amazon Web Services (AWS) to the agenda!

Our decades-long relationship with AWS is built on a shared obsession with our customers, focused on enhancing AWS services with enterprise-grade data management that is built to transform. With broad native support for AWS services, API integration, and cost-saving capabilities like deduplication, compression, and smart infrastructure automation, Commvault accelerates cloud adoption and optimizes protection, migration, and disaster recovery for cloud data. Available in AWS Marketplace for push-button, automated deployment on Amazon EC2, Commvault is a turnkey solution that deploys in minutes so customers can instantly modernize how they manage their data in the cloud and transform their business.

Together, Commvault and AWS collaborate with a goal of helping our customers move, manage, and protect their data wherever it resides – whether that be traditional data centers or modern cloud native applications.

So, how do we do that? Join AWS’ Jake Burns, IDC’s Archana Venkatraman, and Commvault’s Vidya Shankaran for their Connections session on Transforming and Modernizing Your Data Strategy, where they will discuss recent trends in data management and digital transformation. Listen to these industry leaders talk candidly about the challenges their top customers actively face – and how they collaborate to find new ways to stay one step ahead in the cloud. Gain valuable insight into how your organization can be more efficient, more resilient, and better prepared should disaster strike – and do it all with minimal impact on the bottom line.

Register for Connections today and learn why Commvault and AWS are Better Together.

And we’re not done just yet! Join us at AWS re:Invent 2022 in Las Vegas, Nov 28 – Dec 2. Stay tuned for more details!

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

This blog was updated in October 2025.

A ransomware attack is far more likely to occur today than ever before, and any organization could fall victim. According to the FBI’s 2024 Internet Crime Report, 67 new ransomware variants were identified in 2024 alone, demonstrating the rapidly evolving threat landscape that organizations must defend against.

Ransomware complaints increased by 9% in 2024, with cybercrime losses reaching $16.6 billion – a 33% increase from 2023, the report revealed. If companies fall victim to an attack not only may it affect revenue, but it may also hurt their brand.

Air Gapping as a Deterrent to Ransomware Attacks

Air gapping adds a layer of security to help safeguard your data and mitigate ransomware risk. It is designed to isolate and segment secondary or tertiary backup copies and make them inaccessible from the public portions of the environment.

If your organization is infiltrated by ransomware or a malicious attacker, the cyber threat will have a limited attack surface. The public portions of the environment may get infected, but the isolated data will not because it cannot be accessed, changed, or deleted. The backups are safe, secure, and available for restoration.

Compare air gap to defending a medieval castle. The castle is surrounded by water, and the only access to the castle is if the drawbridge is let down periodically to bridge the gap. By storing a backup copy on a storage infrastructure that is physically inaccessible from an external connection, you restrict access and drastically limit the potential for infection.

Commvault Simplifies Air Gapping of Backup Data

Commvault® Cloud leverages a multi-layered approach to ransomware readiness, providing robust controls to help prevent threats and keep data available and recoverable from cyberattack. With immutable, air-gapped data copies, anomaly detection, and built-in encryption, Commvault helps safeguard critical data across apps, endpoints, on-prem, and cloud environments.

Commvault AirGap is a fully managed cloud storage target, offering security and scale for organizations adopting cloud storage. Available with Backup and Recovery, as well as with the SaaS hybrid cloud portfolio, Commvault AirGap makes it simple to leverage cloud storage – without a steep learning curve – for air-gapped ransomware protection and optimized costs.

Top challenges of cloud-based ransomware protection:

  • Increasing cloud costs with cloud expansion and cloud deployments
  • Reliable ransomware protection with a secure, air-gapped, offsite data copy
  • Trusted backup and recoverability of an organization’s most valuable asset: data

Commvault Cloud offers industry-leading durability, security, scalability, and performance, capable of protecting business data from today’s and tomorrow’s cyberthreats.

Key benefits of Commvault AirGap:

  • Ransomware and risk reduction
  • Capacity growth
  • Effectively manage cloud costs
  • Hybrid cloud adoption
  • Secondary backup copies

Flexible Storage Architecture

Commvault AirGap’s Frequent Access and Infrequent Access Storage options deliver flexibility for cloud storage deployments. This tiered architecture enables organizations to optimize their backup strategies based on specific use cases, recovery time objectives, and retention policies.

Frequent Access Storage serves as the ideal foundation for primary backup repositories where rapid data retrieval is required. Organizations that need quick access to recent backups for daily operations, frequent restores, or active data management will find this tier suited to their immediate recovery needs. The enhanced performance characteristics help enable minimal downtime during critical restore operations.

Infrequent Access Storage provides a cost-effective solution for secondary storage requirements, particularly for organizations implementing longer-term retention policies or compliance-driven storage needs. This tier excels at storing data that may be accessed less frequently but remains crucial for regulatory compliance, historical analysis, or disaster recovery scenarios.

With ransomware threats continuing to evolve and financial impacts reaching record levels, implementing air gap protection is no longer optional – it’s essential for business continuity. Commvault AirGap provides the modern approach to air gapping that organizations need: combining the security benefits of traditional air gap methods with the accessibility and scalability required for today’s business environments.

For more details, refer to the Commvault AirGap solution brief.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The cloud-native landscape is rapidly evolving, with 85% of global organizations expected to be running containers in production by 20251. To continue to meet business goals while enhancing business agility and streamlining operations, you need a holistic, comprehensive data management solution for your entire data estate.

Commvault has always been at the forefront when protecting new technologies, with containers and Kubernetes no different. We have built broad support for protecting applications running on a Kubernetes cluster and their data. Every CNCF (Cloud Native Computing Foundation) certified Kubernetes distribution is supported, and via the CSI (Container Storage Interface) framework, we also support a wide range of storage providers on Kubernetes, ensuring you have complete cloud-native data protection, managed through the simplicity of a single data management solution.

In this new release we bring two new key capabilities to Kubernetes data protection:

  • Full Cluster & namespace level protection.
  • Protecting the ETCD.

Recap

Commvault allows users to easily onboard a Kubernetes cluster into the Commvault Command CenterTM aka the single pane of glass for all your data protection, data management and data lifecycle needs.

Commvault defines a Kubernetes application as anything that is a pod or a collection of pods viz: Deployments, ReplicaSets, Statefulsets etc. and their associated components as inferred from their application yamls.

To break that down a bit, when we look at an application like a Deployment, we look at its config. spec. and discover any PVCs (Persistent Volume Claims), Secrets, ConfigMaps and other associated entities. All these together constitute an application.

A user can browse an onboarded cluster for applications, select and group them together into an “Application Group” based on backup SLAs (Service Level Agreements), retention needs or any other criteria.

Users can add applications to Application Groups in a few diverse ways:

  1. Browse and pick all applications in a namespace or multiple namespaces.
  2. Select specific applications.
  3. Use dynamic discovery rules: e.g.: Select applications that match a particular label selector or name etc.

Dynamic discovery is especially useful where a backup administrator can have the devops teams set label selectors on their applications and be guaranteed specific protection SLAs (Service Level Agreements).

Backup jobs run at an Application Group level and use the content rules to discover existing and newly created applications and their resources on the cluster at run time and perform backups. PVCs are backed up using CSI when available or alternatively Commvault can attach to PVCs directly using ReadMany semantics if CSI is not available.

A diagram that illustrates how it all happens.

With Commvault, restoring an application or its data can be done at various granular levels:

  • Application level restore: An entire application along with its associated resources and data can be restored in one shot.
  • Application files: An application’s data (or portions thereof) residing on PVCs can be restored piecemeal without having to restore the entire application.
  • Application configuration files: Configuration files constituting an application can be restored as files so that a user can manipulate them before applying them to the cluster.

Enhancements

It is now time to talk about the exciting new enhancements, delivering complete Kubernetes protection, and included in Platform Release 2022E.

1. Full Cluster Protection

With this feature we have added an easy button for the backup admin to press: Pick up everything on the cluster please. Thank you very much!

Everything in the cluster including cluster-scoped resources is picked up when configured in this manner.

Additionally, namespaces that are freshly discovered at backup time are also automagically included.

Backup admins must no longer select individual namespaces or applications within a namespace to be fully protected.

2. Namespace Level Protection

In addition to an entire cluster, users can now choose to backup an entire namespace i.e., applications (and their resources) and any unreferenced resources within the namespace (we call them orphans).

Also, users are now able to restore namespaces in their entirety while still retaining the various granular restores explained above.

3. Protecting the etcd.

etcd is a distributed, replicated database that Kubernetes uses to store the cluster configuration. The image below illustrates the usage of etcd in a typical Kubernetes cluster.

Each control plane node has a replica/copy of the etcd.

Losing/corrupting these copies can wreak havoc on a Kubernetes administrator’s day (or week).

Since etcd is replicated across the master nodes in a Kubernetes cluster, traditional solutions attempt to protect etcd by protecting the master nodes. This is often achieved by deploying solutions on those cluster nodes to protect the etcd locally. This is unwieldy and cumbersome at best because it separates protection for the applications running on the cluster and the protection for the cluster state into two very disparate mechanisms. Protecting application state and protecting cluster state go hand in hand and separating the two can lead to inconsistencies esp. when recovering from a disaster.

Commvault now seamlessly integrates etcd protection right alongside application and full cluster protection into the Command Center. A user simply needs to enable a toggle on the cluster to protect etcd and select an SLA. That is, it! Really! (See the snapshot below)

With these enhancements we have developed a holistic comprehensive solution for your Kubernetes Data Protection needs and, integrated it into our Commvault Command Center so you can simplify management of your entire data estate from a single interface. No wonder Commvault continues to be an outperformer in this space.

Reference

1 – Forbes – A CxO’s Guide To Container Monitoring

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

25 years of Microsoft + Commvault co-engineering will be highlighted at Microsoft Ignite, with a focus on a single & easy-to deploy solution for business continuity and disaster recovery (BCDR)

In a recent conversation with a long-time customer, their comments on the current state of backup and recovery (or data protection as it’s more commonly referred to) pretty much sums it up: “All of a sudden, it’s the most important thing to everyone in the organization – and it’s no longer boring!” 

With bad actors finding new ways to get to your data, combined with pressure from the highest levels of every organization to ensure that data is protected and recoverable when bad things happen, the focus on protecting data is undeniable. Agility and the ability to stay one step ahead are keys to success.

At Microsoft Ignite, running October 12th – 14th, the partnership between Commvault and Microsoft will be on full display, showcasing the over two decades of proven best practices we’ve leveraged into a powerful solution running on Azure. A single solution, the Commvault and Microsoft offering protects your entire data estate – wherever your data resides – providing the confidence you need to innovate faster while ensuring you won’t have to manage and maintain multiple solutions.

If you’re challenged to solve these five data challenges, be sure to take in all Ignite has to offer:

Beat bad actors at their own game—deceive the deceivers

Metallic, Commvault’s Data Management as a Service (DMaaS) offering, takes protecting data from ransomware threats beyond recoverability, with the introduction of ThreatWise™. Think of it as your early warning system. It’s another industry-first from Commvault, as we deliver patented cyber deception to uncover, deceive, and detect zero day and unknown threats the moment a ransomware attack begins – before your data is compromised.

Meeting you wherever you are on your cloud journey

Your cloud journey is unique – and you have unique needs. Commvault provides the flexibility you need, regardless of where you are on your cloud journey. We protect and manage all your data with a single solution that spans across on-prem, hybrid cloud, and SaaS. We’ll help you drive simplicity, which will help you reduce costs and complexity.

Confidence of knowing no matter what the workload, you’re cloud ready

Commvault’s industry leading workload coverage – across Microsoft applications, databases, and beyond – allows you to accelerate your cloud journey. Whether you’re looking to take your first workloads to Azure or your mission critical workloads to Azure (from Oracle to SAP HANA – even your industry-specific applications and Azure PaaS databases), Commvault enables you to move, protect and use your data, providing the peace of mind and agility you need. 

Seamless path to SaaS – the future of holistic data protection and data mobility

Driven by a combination of pandemic priorities and ransomware realities, the move to SaaS is on. According to major analysts, it will soon be the dominant data protection deployment option. Metallic DMaaS can help you comprehensively safeguard data while lowering costs and eliminating the need for specialized cloud skills. With Metallic, built on proven Commvault technology, your path to DMaaS is simplified and seamless, enabling you to plan how quickly and completely you move to the cloud, while providing one interface and a single view of your data through the Commvault/Metallic Command Center. Yes, the future of data protection is here now – and only from Commvault.

Explore Commvault and Metallic at Ignite

Use Ignite to see Commvault and Metallic in action. Don’t miss the on-demand session, “Modern BCDR with Metallic DMaaS and Azure,“ featuring the exceptional CTO duo of Dave Totten (Microsoft) and David Ngo (Metallic). It’s a conversation designed to help you solve your biggest BCDR challenges and future-proof your data protection.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The annual IT event season is off and running, starting with Microsoft Ignite (Oct 12-13), where Commvault’s Metallic wizard and CTO David Ngo is joining Microsoft’s Dave Totten, CTO, US Partners to talk business continuity and disaster recovery (BCDR) strategies, security, Metallic Data Management as a Service (DMaaS), and everything in between (more on that here).

Ignite doesn’t just serve as a great place for technologists to get the latest training, and learn directly from Microsoft engineers about the newest hybrid cloud technologies, it’s also the first in a rapid-fire series of great industry events packed with real-world advice on cloud transformation.

Throw in the fact that it’s International CyberSecurity Awareness Month and we’re marking the third anniversary of Commvault’s Metallic DMaaS portfolio – it’s the perfect time to get up to speed on the best and brightest innovations developed through our deep partnership with Microsoft and how we are leading the way in the industry to deliver intelligent data management and protection services.

The latest Commvault Platform Release is chock full of new features integrations, enhancements and security upgrades aimed at battling cyber threats in cloud and hybrid cloud environments. On top of its support for three of the most popular platforms in the Microsoft Cloud – Azure, Dynamics 365, and O365 – Commvault has a slew of new features across its software and SaaS portfolio designed for securing and protecting Microsoft cloud data:

What’s New: Azure Stack to Azure Replication and Disaster Recovery

Why: New Disaster Recovery and application mobility capabilities for Azure Stack and Azure customers

What’s Different:

  • Simplify your hybrid cloud strategy with Disaster Recovery and application mobility across Azure Stack and Azure deployments
  • Improve RPO/RTO over standard backup Service Level Objectives
  • Easily configure, manage, and monitor through existing Replication Group administration within Commvault Command Center

What’s New: Enhanced Capabilities with Azure Restore Points

Why: New Azure VM Restore Points create collections of restore point snap shots that span all the managed volumes within a VM

What’s Different:

  • Simplified design that leverages Commvault’s platform to enable scalable data protection and recovery with a single click
  • Improved resiliency ensuring that the applications and the operating system are consistent when creating these collections at the native instance level
  • Better cost efficiency with collection points stored on less redundant storage tiers

What’s New: Metallic now supports the broadest selection of Azure databases of any DMaaS solution

Why: Extend Microsoft native capabilities with dedicated protection for fully managed, globally distributed, multi-modal Azure databases

What’s Different:  

  • Single-solution protection for critical Azure databases, including SQL Server, SQL Managed Instance, Cosmos DB, MariaDB, MySQL, and PostgreSQL
  • Purpose-built protection for cloud development and app modernization initiatives
  • Air-gapped architecture to safeguard data from deletion, corruption, or attack
  • Extended long-term retention with rapid recoverability

And if all that wasn’t enough, we’ll be continuing the conversation with Microsoft in just a few short weeks at Commvault Connections, a true cloud data management experience, where Microsoft will lead a discussion on the topic, “Protect Your Critical IT Assets with Azure.” During this session, event attendees will learn more about the joint hybrid cloud solutions from Commvault and Microsoft and how they can be used to create a business continuity and disaster recovery plan that protects critical VMs, databases, PaaS and SaaS services (like M365), and more.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

At Microsoft Ignite, Nutanix announced support for Nutanix Cloud Clusters (NC2) running on Microsoft Azure. This will help Nutanix customers accelerate cloud adoption through unified management and seamless mobility for applications, data, and licenses across on-prem and Azure environments.1 This platform will allow Nutanix customers to move Nutanix workloads to – and from – on-prem into an Azure-based NC2 cluster, as an extension of their existing Nutanix ecosystem.

Commvault’s industry-leading platform provides seamless data protection and management for NC2 on Azure. Customers looking to extend their existing protection platform into the cloud can grow into a hybrid cloud model or even build a net new, cloud-based data protection platform to protect greenfield NC2 on Azure environments. Customers can seamlessly leverage Azure VM resources to build their data management platform and can easily consume Azure storage options for use for retention copies of their data without requiring additional resources running on the NC2 on Azure.

Easy to configure and consume

Once NC2 on Azure has been deployed, customers can create a subnet on the Prism Central management VNet created within Azure, allowing direct communication between Azure data protection resources and the NC2 on Azure. With this subnet configured, customers can deploy Commvault resources within the subnet. This can include the CommServe, MediaAgent, Access Nodes, and more, all of which will have direct access to the NC2 on Azure environment. Commvault even provides an Azure Marketplace offering that will deploy all required resources for the customer with the click of a button.

With the Commvault platform configured, setting up the Nutanix AHV hypervisor takes just seconds and data protection can begin immediately. Data protection operations can leverage the Direct NFS transport method for Nutanix AHV, reducing the resource requirements on the NC2 on Azure platform.

Simplicity in data protection and recovery

Commvault also allows customers to quickly and easily move workloads between on-prem and NC2 on Azure environments, while making it easy to move workloads – through a simple data recovery operation – into cloud-native platforms like Azure VM.

Quick Recap

Nutanix Cloud Clusters on Azure allows customers to accelerate their journey to the hybrid cloud. And Commvault is ready to protect their data and workloads wherever they reside: on-prem, in the cloud, and in hybrid environments. In addition to protecting data on the Nutanix Cloud Clusters on Azure, Commvault is the industry leader in protection of Azure VMs, Azure Storage, and virtually every other workload within an enterprise environment.

Commvault offers industry leading data protection scaling, data transformation, data management, and deduplication performance.

Reference

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Continuing our very full dance card for October, this week the Commvault team is in Las Vegas at Oracle CloudWorld and while we’re thrilled to be a gold sponsor of the show, Commvault and Oracle are so much more than just event supporters – we’re also multi-could partners! In fact, we expanded our strategic partnership with Oracle a few months ago to include the entire portfolio of Metallic Data Management as a Service (DMaaS) offerings on Oracle Cloud Infrastructure (OCI). 

It’s a simple equation: OCI + Metallic DMaaS = simple to use enterprise data management, threat protection and recovery. So, what exactly does that mean? Oracle customers can now protect critical workloads in the cloud or on-premises by maintaining flexibility across IT-managed storage or SaaS-delivered data protection of managed cloud storage. The simplicity is in the interface. All data assets protected and secured in hybrid and multi-cloud environments are managed through a single web-based console.

But that’s just the beginning. Commvault and Oracle are already well down the path on our newly minted, multi-cloud, SaaS-delivered DMaaS journey. Just this week, Commvault rolled out new support and features for the Metallic DMaaS portfolio designed specifically to expand support for OCI.

Specifically, Metallic now protects Oracle Database Cloud Service (DBCS) and Oracle Exadata Database Service on OCI, as well as OCI Object Storage.  These workloads join our existing support for Oracle, Oracle RAC, Oracle Container Engine for Kubernetes (OKE) and OCI VMs. Metallic provides support for both Metallic Recovery Reserve for OCI storage and BYO OCI Storage for air-gapped protection. 

Like my colleague Jeff mentioned in his rundown during last week’s events, the conversation doesn’t end at CloudWorld. Oracle is bringing its expertise to bear alongside our best and brightest at the upcoming Commvault Connections 22 event. Oracle’s Joe Corvaia, GVP, NACT ISV, MGS and MSP Sales, will join Commvault’s Chief Partner Officer Alan Atkinson, to discuss best practices for protecting against ransomware in a multi-cloud world. It’s just a few weeks away and I can tell you it’s going to be a world-class cloud experience. Register for Connections today and reserve your seat now for this special partner session!

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

As we continue our Commvault Cares Month celebration, we are raising awareness on causes close to our hearts.

This week I had the honor of hosting a Courageous Conversation regarding domestic violence awareness. Our Courageous Conversation platform is our way to have the tough conversation about things that matter – and this one sure did not fail!

During our Courageous Conversation, I was joined by special guests Anna Diaz-White, Caitlin Tamayo, and Randi Zamkotowicz from 180 Turning Lives Around, a local non-profit organization in the New Jersey area that empowers survivors and families affected by domestic violence and sexual assault to find the courage and strength to turn their lives around. We also had Bill Appleton from our Employee Assistance Program (EAP) to share more about the resources and support we have as Vaulters. Available 24/7, 365 days per year, our EAP connects participants with counselors specialized in a variety of focus areas, many of which are aspects of mental health.

We broadcasted our Courageous Conversation on domestic violence live from our headquarters so all our Vaulters could join the discussion. During the event, we focused on three ways to drive awareness of domestic violence – how to Recognize, Respond, and Refer – whether it’s for ourselves, our co-workers, friends, or family:

  1. Recognize signs of domestic violence and better understand how common it is. The reality is that anyone can be a victim of domestic violence, regardless of race, age, ethnicity, sexual orientation, or economic status. If you are questioning how you’re treated by your partner, I encourage you to review this checklist from the National Coalition Against Domestic Violence. And when it comes to recognizing signs of domestic violence abuse with a colleague, friend, or family member, it’s important to notice changes in behavior and dress and check in if you think someone may be in an unsafe situation.  
  2. Respond by creating a safety plan to help lower the risk of being hurt by a partner. This is a set of actions to be referenced when experiencing abuse, preparing to leave, or after a victim leaves. Having a safety plan is especially important during moments of crisis when stress makes it very hard to think clearly. An example of one of these actions is to keep a “to-go bag” ready and waiting. This way, in case of an emergency situation, someone who is being abused is able to leave immediately with all the essentials.
  3. Refer to local and/or company resources for safety planning and support. Like many local organizations across the U.S. and throughout the world, 180 Turning Lives Around has hotlines, a safe house, and counselors available to help domestic violence victims. At Commvault, our HR team and our EAP is here to help all our Vaulters through any life challenges.

And while October is Domestic Violence Awareness Month in the U.S., we continue to talk about this incredibly important topic year-round as we honor domestic violence awareness days across the world throughout the year.

We believe you need to have the conversation, to change the conversation. And any conversation, whether it’s big or small, can make a difference. I’m so proud of our Vaulter community for continuing to have open discussions as we support our culture of respect, care, and belonging.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

These attacks can be used to block access to—or outright steal—essential business data, which can often include both the backup and restore data contained in places like an Amazon Cloud Backup (AWS Backup). The perpetrators will then encrypt the data and withhold it from the business until they pay a ransom, or threaten to delete it altogether if the company refuses to meet their demands.

Ransomware attacks can create chaos within an organization due to service disruptions, loss of data critical to essential business functions, exposure of private customer information, and loss of public credibility. And the problem is only getting worse.

According to the U.S. Financial Crimes Enforcement Network (FinCEN), the number of ransomware attacks in 2021 will vastly exceed the number of attacks in 2020. These attacks are growing in terms of cost as well—the average cost of reported ransomware transactions per month in 2021 was $102.3 million.

You may be wondering where cloud backups and snapshots fit into this. After all, can’t you simply restore the stolen data from a backup or snapshot in the event of an attack? Ideally, yes. But ransomware attackers also target an organization’s data backups, which is why it’s crucial to secure those backups to avoid paying outrageous ransoms while ensuring business continuity and a fast recovery.

Vulnerabilities with Amazon Cloud Backup

​​Although cloud backup snapshots are great for operational recoveries, they do not provide complete protection from threats like ransomware. When used directly out of the box, AWS backup vulnerabilities include:

  • No air-gap protection – AWS snapshots are by default created in the same account as the primary data sources. In this scenario, if the primary account is compromised, so are the snapshots. And if the snapshots are compromised, there is no way to recover data deleted or encrypted by outside parties.
  • Backups are not automatically immutable – AWS on its own does not make snapshots immutable, and mutable backups can be altered—or even, in some cases, accidentally deleted.
  • Slow recovery – AWS’s lack of flexible restores impacts recovery speed and can result in disruptions to business continuity in the event of an attack that results in a need for data restore.
  • Possible script errors – Complex, manually-written scripts are required to replicate snapshots across all accounts within AWS. This is obviously time-consuming and prone to human error, which can leave the snapshots exposed during an attack.

How to Protect AWS Backups from Ransomware

The potential inherent vulnerabilities of AWS backups can leave your data copies at risk to bad actors. And while AWS does offer some native tools and solutions for securing backups, they can be cumbersome to use while still not providing full protection.

Here are some key steps you should take to shield your valuable data and backups from ransomware and other attacks:

  • Air-gapping – Backups should be air-gapped and stored outside of the customer’s primary account and region. In the event of an attack, this prevents hackers and bad actors from corrupting and deleting the backup copies as well as the working data.
  • Immutable backups – Backup copies of data should be made immutable (unable to be altered or deleted), which preserves the data in a format that prevents it from being altered in any way.
  • Encryption for data at rest and data in transit – Both at rest and in transit, data should be encrypted, ideally with the user’s own encryption keys, and protected at a platform level with top security features in compliance with certifications such as ISO 27001, SOC II Type 1, SOC II Type 2, and PCI DSS.
  • Periodically test your data recovery abilities – In the event of an intrusion or disruption to your data and workloads, it’s essential to know you can recover quickly and ensure business continuity. Organizations should routinely test their ability to recover data from their backups.

(Is your data fully protected from ransomware? Click here to view our comprehensive ransomware checklist.)

Safeguard Your AWS Backup from Ransomware in Just Minutes with Clumio

Clumio’s innovative, industry-leading platform was designed in the cloud to protect the cloud.

With Clumio, your AWS backups receive instant protection via air-gapping, which places your valuable backup data “off site” and outside of production environments and other accounts.

Data is also encrypted with your encryption key of choice before it leaves any of your cloud accounts. Built-in integrity checking, full immutability for your backup files, and testing data recovery are all only a few clicks away within the intuitive interface.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Importance of Compliance & Data Security

Not only do companies need to protect their own sensitive information, but they also must safeguard the personal information of their customers and clients. Failing to comply with relevant regulations can lead to financial and reputational damage, as well as potential legal consequences.

For example, consider the recent data breaches that have affected numerous high-profile companies. These incidents not only resulted in costly fines but also damaged customer trust and negatively impacted brand reputation. In fact, according to a recent survey conducted by Edelman, a global communications firm, 81% of consumers will stop buying from a company if it is found to be mishandling data.

Compliance with regulations can help reduce security and privacy risks, align cybersecurity requirements with business processes, maintain effective cybersecurity programs, build customer trust, and improve company reputation. As a result, companies must prioritize both compliance and data security in order to remain competitive in today’s market.

To illustrate the importance of compliance and data security further let’s consider the healthcare industry. Medical providers need to follow various laws and regulations for patient privacy and protection of confidential information such as HIPAA (Health Insurance Portability and Accountability Act), which holds organizations accountable for not protecting medical records correctly. Non-compliance with these laws could lead to customers losing trust or even being sued for neglecting confidentiality obligations at worst case scenarios.

Furthermore, having proper compliance measures in place ensures that sensitive business information remains confidential amongst stakeholders who require access it on an everyday basis while keeping unauthorized personnel away. It builds a sense of security within employees who handle confidential items reducing data breach cases that might cause severe financial harm.

However, some people might argue that the cost associated with maintaining such compliance standards might outweigh some of the benefits derived from it. This quite untrue as the benefits of adherence to compliance regulations to data protection surpass the cost in the long-term savings and protection it provides.

  • According to a 2020 study conducted by Statista, around 45% of organizations worldwide increased their spending on data protection and compliance efforts.
  • A Ponemon Institute research report in 2021 found that the average cost of a data breach in the United States was $8.64 million, emphasizing the importance of having reliable backup solutions for regulatory compliance.
  • In a survey by Spiceworks in 2019, approximately 42% of organizations reported using a combination of public cloud, private cloud, and hybrid cloud environments for their data backups, in order to achieve better compliance and redundancy.

Role of Backups in Regulatory Compliance

When it comes to data security, backups play a crucial role in ensuring regulatory compliance and business continuity. Regulatory compliance can be extremely complex, involving strict guidelines that must be followed to avoid financial penalties, legal consequences, and damage to reputation. Having a reliable backup plan can help companies maintain compliance with regulations such as GDPR (General Data Protection Regulation), which establishes rules for protecting European Union residents’ personal data; PCI (Payment Card Industry) standards for processing and storing payment card information securely; and HIPAA (Health Insurance Portability and Accountability Act) standards for protecting health information.

In addition to satisfying compliance requirements, backups also help companies ensure business continuity. Natural disasters, power outages, cyber attacks, and other unexpected events can cause loss or corruption of data. Without an effective backup plan in place, businesses risk losing important data along with customer trust.

To understand the importance of backups further, let’s consider a company that experiences a ransomware attack. Ransomware is a type of malicious software that threatens to publish sensitive data if payment isn’t made.

If the company doesn’t have a robust backup plan in place, they may have no options but to pay the ransom or lose significant amounts of valuable data. However, if they’ve been backing up their files regularly and properly following best practice recovery protocols when implementing their backup process which involves full and partial backups implemented frequently as possible amongst other features available with top-notch services like Rewind Backup Tool according to SaaS compliance solution then they would be able to recover critical files without paying criminals for release of hijacked files or draining their resources.

Thus having a robust set up required by backup compliance system means businesses can mitigate risks otherwise resulting in data loss, customer downtime, payment of expensive fines, lawsuits from affected parties aside from lost trust between company and clients.

Some people might argue that backups are not necessary if the data is already stored securely. However, accidents happen, and when they occur some vendors would not be able to provide data recovery services without backing up their client’s system. It is better to be safe than sorry when dealing with sensitive data which could result in a breach leading to legal consequences.

  • Backups are critical for businesses to maintain regulatory compliance and ensure business continuity. Compliance regulations can be complex, and strict guidelines must be followed to avoid financial penalties, legal consequences, and reputational damage. Reliable backups also help companies protect against the loss or corruption of data due to natural disasters, cyber attacks, or other unexpected events. Investing in a robust backup plan, including full and partial backups implemented frequently as possible amongst other features available with top-notch services like Rewind Backup Tool according to SaaS compliance solution, can help mitigate risks otherwise resulting in data loss, customer downtime, payment of expensive fines, lawsuits from affected parties, and lost trust between company and clients. Ultimately, accidents happen, so it is better to be safe than sorry when dealing with sensitive data that could result in a breach leading to legal consequences.

Impact on Business Continuity

The impact of compliance and data security on business continuity cannot be overstated. In fact, without a robust backup plan in place, businesses are at a significant risk of irreversible damage to their operations and reputation. With the number of cyber-attacks increasing every year, it’s crucial that companies take proactive measures to protect their data and ensure their systems remain operational in the event of an attack.

For instance, imagine a scenario where a company was hit by a ransomware attack that encrypted all their data and backups. Without a proper backup plan in place, they would lose access to all their critical files and data necessary for business continuity. As a result, they would be forced to restart from scratch, resulting in prolonged downtime, lost revenues from halted operations, and reputational damage.

A backup plan provides the assurance that, should such an attack occur, the company can quickly restore its systems’ functionality without significant disruptions to its operations. This is especially important for companies with compliance obligations or those that deal with sensitive or confidential information.

Backups also help businesses maintain customer trust and build their reputation. Companies that continuously experience service disruptions or data breaches are likely to lose customers who will take their business elsewhere. By having a reliable backup plan in place, businesses can demonstrate their commitment to protecting their customers’ sensitive information while maintaining the continuity of their services.

Some companies may argue that creating a robust backup plan is unnecessary because it takes too much time and resources to implement. They may consider it as an additional cost without significant immediate returns on investment. However, the risks of not having one far outweigh any perceived costs. The cost of recovering from a cyber-attack without proper backups in place greatly exceeds the investment required for implementing an effective backup plan.

Key Regulations and Certifications

Several regulations govern how organizations handle sensitive data, making it essential to understand the implications of non-compliance and what certifications are necessary to mitigate these risks.

Regulations such as GDPR, PCI, and HIPAA mandate that businesses protect their customers’ sensitive information. Specifically, GDPR applies to European Union (EU) citizens’ personal data, while PCI compliances deal with payment card data handling. Similarly, HIPAA governs the handling of protected health information (PHI). Non-compliance with these regulations can result in significant legal and financial repercussions.

When companies comply with these regulations, they align their cybersecurity requirements with business processes, maintain effective cybersecurity programs that keep customer data secure, reduce security and privacy risks, and improve company reputation.

Obtaining certifications like ISO 27001 and SOC 2 serve as proof that an organization has implemented thorough audits of its data security compliance. ISO 27001 is an information security management certification that demands a company’s adherence to strict standards of data protection. On the other hand, SOC 2 requires adherence to specific criteria for system security, availability, confidentiality, processing integrity, and privacy. These certifications cater to different aspects of compliance but work together to ensure effective data security practices.

GDPR, PCI, and HIPAA

When it comes to compliance and data security, there are a number of regulations and certifications that businesses need to be aware of to ensure their backup plan is up-to-date and effective. Among these, three important standards are the General Data Protection Regulation (GDPR), Payment Card Industry Data Security Standard (PCI DSS), and the Health Insurance Portability and Accountability Act (HIPAA).

The GDPR, which came into effect in May 2018, is designed to protect personal data belonging to European Union citizens. Any organization that collects or processes EU citizens’ data must comply with these stringent regulations. Failure to do so may result in hefty fines, loss of reputation, or legal action. To comply with the GDPR, businesses need to have a robust data management system including proper backups containing personal data.

PCI DSS applies specifically to companies that handle payment card information. It regulates how businesses should process sensitive customer information like credit card numbers to prevent fraud and hacking. PCI DSS requires annual audits from an approved Qualified Security Assessor (QSA) and regular reviews of backup policies.

HIPAA is another critical regulation for healthcare organizations. It requires strict methods for securing medical records both physically and electronically. The law also enables patients’ access to their own medical records while requiring healthcare providers provide them with proper privacy practices.

Complying with these regulations can be compared to buckling your seatbelt before driving on the road – safety first! Regulations give your business the tools it needs to protect sensitive information and avoid data breaches while keeping your customers’ trust.

ISO 27001 and SOC 2

Apart from regulatory requirements, there are certifications that demonstrate a commitment towards the best practices in cybersecurity management. The International Organization for Standardization (ISO) provides both guidelines and certification regarding information security. The ISO 27001 standard specifically focuses on the creation of an Information Security Management System (ISMS) within any organization.

Implementing ISO 27001 involves assessing risks, devising policies and procedures for securing data at all times, including backup data. This includes specific requirements for data redundancy, disaster recovery planning as well as testing of the policies in places such as offsite backups in particular.

Additionally, the SOC 2 examination report is an independent third-party evaluation that gives assurance about how well you perform your controls. SOC 2 reports concentrate on a company’s non-financial reporting controls as they relate to key compliance and security issues.

Obtaining these sorts of certifications can be compared to receiving your driving license- it takes dedication to learn the rules of the road before being able to safely drive where you need to go. With these certifications, businesses demonstrate their commitment to best practices in cybersecurity management that protect their customers’ sensitive information.

Creating a Robust Backup Plan

When it comes to creating a robust backup plan for compliance and data security, there are many factors that organizations need to consider. A comprehensive backup plan should not only ensure the protection of sensitive data, but also provide a way to restore lost or corrupted information in the event of an attack or data loss. In this section, we will look at some of the key considerations for creating a robust backup plan.

First and foremost, your organization needs to decide on the type of backups it will use. This may involve implementing both full and partial backups as often as possible, depending on how critical your data is. Full backups are designed to capture all data on a system while partial backups capture only smaller subsets of data. The frequency of the backups will vary depending on factors such as how rapidly data changes within your organization and the amount of data you’re dealing with.

Once you have decided on the type and frequency of backups that your organization will use, you need to determine where the backups will be stored. There are many options available, including cloud-based backup solutions and physical storage devices such as hard drives and tapes. Backups stored in multiple locations are generally more secure than those stored in only one place.

Another important consideration when creating a backup plan is determining how long backups should be retained. While regulatory requirements drive retention policies in some cases, organizations might choose to store their backups even longer than regulations require if business continuity could be threatened without it. In short, retaining more copies does come at a cost – requiring investment in additional storage space and management efforts – but having those extra copies provides an additional layer of risk mitigation.

It’s important to remember that creating a robust backup plan is like creating a safety net for your organization’s sensitive data. If something goes wrong, having a backup plan in place will ensure that your organization can quickly recover and restore lost or corrupt data.

Let’s take a look at some of the key considerations when choosing the right backup tools for your organization.

Choosing the Right Backup Tools

When selecting the correct backup tools, it is essential to find a solution that aligns with your organization’s specific needs. There are several factors to consider before making a final decision, including how often backups need to happen, how they’re being created and operated—whether through an automated mechanism or manual solutions—and what type of encryption algorithms you’d prefer for protecting sensitive information.

One crucial factor to consider when selecting backup tools is scalability and reliability. Organizations that expect future growth must choose solutions capable of expanding to meet their changing requirements. Automated solutions like Clumio should be preferred as they offer more flexibility to handle unexpected increases in data volume without stressing the IT personnel. With scalable tools, users benefit from a stable platform while minimizing interruptions and ensuring business continuity.

Furthermore, backup tools must be designed with security in mind. They must be updated frequently to make sure any known vulnerabilities are addressed immediately while also featuring strong encryption methods for protecting sensitive data across the communication lines throughout the backup lifecycle.

Other critical considerations when selecting a backup tool include cost-effectiveness and easier management . These are especially crucial for companies working with tight budgets where resources may not be plentiful. Before making any decisions on a backup tool, determine if it provides value for its pricing while ensuring easy maintenance, deployment, and administration, besides providing adequate security functions required by your business.

Choosing the right backup tool is like finding the perfect pair of shoes. Just as finding a good pair of shoes requires careful evaluation of comfort, style, and price over time – finding an ideal solution requires taking into account key factors, including scalability, security, cost-effectivenesss and management needs, while selecting the right solution for your organization.

Now that we’ve explored some of the essential aspects to consider when creating a backup plan, let’s move on to monitoring and reporting compliance.

Implementing Full and Partial Backups

When it comes to implementing backups for compliance and data security, one size does not fit all. Your organization’s specific needs will determine the type of backup strategy that works best for you. Full backups are ideal if you need complete copies of all your data on a regular basis. However, partial backups may also be necessary to ensure the protection of your most critical data.

For example, let’s say you run an e-commerce website that generates a significant amount of daily sales. In this scenario, you would likely want to implement both full and partial backups. A full backup could be performed once a week or month, while partial backups would occur several times a day, ensuring that critical sales data is always protected.

Another case where partial backups would be essential is in a biotech research firm that conducts complex experiments. Here, real-time data plays a crucial role in experiments, so hourly backups will work best to ensure the recovery of any lost information during any untoward incident.

Moreover, implementing multiple types of backup strategies can provide additional layers of redundancy that can help ensure data is protected should one backup fail. For instance, using both incremental and differential backups means that only changed files since the last backup are saved. This approach reduces the amount of storage space needed and minimizes the time required for each backup.

On the other hand, full backups take longer but allow quicker restoration capabilities because they include all system files at once. While switching between the two types can increase complexity, utilizing both methods provides insurance against severe losses.

One key element when implementing any backup plan is considering off-site storage options like cloud-based services or secure remote sites. This step ensures that there are backup files in place if some catastrophic event occurs at the primary location.

Monitoring and Reporting for Compliance

Tracking information on each backup strategy is very important for meeting compliance standards. Regular monitoring of backup processes and results can identify unsuccessful backups and reduce the risk of data loss.

To ensure regulatory adherence, it’s crucial to define metrics that measure backup performance over time. From measuring the total storage space used for the backup process to tracking how quickly a full system restore takes, having statistics helps your organization stay on track with its goals while ensuring compliance.

Furthermore, by using software automation tools, managers can receive daily reports regarding the status of backups without any manual intervention. These tools give real-time insights into backups, such as whether there was unauthorized access or any modification in files. Nowadays, logs have become an easy way to go through this information.

Backup performance evaluations are essential for businesses to gauge their adherence to established compliance regulations such as GDPR, HIPAA, and PCI DSS. It is necessary to create policies that specify the types of tests necessary and their frequency—these policies should be reviewed regularly during audits.

While some backup approaches include using external tapes to store data redundantly, these methods aren’t always suitable for larger companies with higher processing demands or those with several locations. This approach can have long restoration times that may damage the continuity of any business.

Thus, implementing a reliable, efficient backup array works wonders here because it reduces operational downtime caused by data corruption or server crash incidents. Therefore, having scheduled “backup retention time” where IT professionals research probable risks acting on timely apparatus replacement is more practical than recurring backups.

It’s just like building a structure strong enough from natural disasters instead of only counting buckets when it floods up to your knees!

Backup Performance Metrics

One of the most critical aspects of backup planning is monitoring and reporting. In today’s compliance-driven world, organizations must be able to prove that they are adhering to regulations and protecting user data. Backup performance metrics play a vital role in ensuring regulatory adherence and avoiding data breaches.

For instance, backup performance metrics can provide insights into the amount of time it takes to create backups, the frequency of backups, or how many backups are created per day/week. If there are any issues with the backup process, these metrics can be used to identify and address them before they become a problem.

Additionally, backup performance metrics can also provide proof of adherence to regulatory requirements. For example, regulations such as HIPAA require organizations to maintain an audit trail that shows who accessed patient records and when they were accessed. Similarly, GDPR requires organizations to provide an audit trail for data breaches. Backup performance metrics can help organizations meet these requirements by providing evidence of regular backups and recovery testing.

However, it’s crucial to note that backup performance metrics alone won’t ensure compliance. Compliance involves implementing a wide range of security procedures, including disaster recovery planning, risk assessments, monitoring security controls, and integrating best practice security procedures into day-to-day workflows. While backup performance metrics are an essential part of compliance monitoring and reporting, they should be used in conjunction with other security measures.

With that being said, how can organizations ensure that their backup plan is compliant?

Ensuring Regulatory Adherence

To ensure regulatory adherence, organizations need to take a holistic approach to their backup plan. Here are some key steps to consider:

First, choose backup tools that meet industry standards. Top-notch data backup tools like Clumio can make the complex process of compliance and data security easier by automating daily backups and ensuring that data restoration is available while following the strictest security standards.

Think of it this way: choosing the right backup tools is like choosing the right lock for your front door. Just as you want a lock that’s tough to break, you want backup tools that are hard to hack. The right tools can help you ensure that your data is safely stored and stored in compliance with industry regulations.

Next, implement full and partial backups as often as possible. Full backups should be performed regularly (e.g., weekly or monthly) to ensure that all data is backed up. Partial backups should be performed more frequently (e.g., daily) to ensure that data changes are captured.

For example, if you have an e-commerce website, you might perform full backups on a monthly basis but run partial backups every night to capture new orders.

Finally, regularly test backups to ensure they can be restored in the event of an attack or data loss. Testing should include failover testing (i.e., testing whether your backup system can take over if your primary system fails) and failback testing (i.e., testing whether your primary system can take over again once the backup system has been used).

However, it’s important to keep in mind that implementing a compliant backup plan isn’t a one-time thing – it’s an ongoing process. As regulations change and new threats emerge, organizations must continue to evaluate and refine their backup plans to maintain regulatory compliance and protect user data.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago