Skip to content

This blog was updated in October 2025.

Cyber recovery readiness planning is a proactive strategy that helps organizations prepare, respond, and recover swiftly from cyberattacks such as ransomware and data breaches. It’s the foundation of cyber resilience – helping you move from simply being ready to truly being able to recover with confidence. In today’s interconnected world, cyber threats pose a constant risk to businesses of all sizes.

A cyber recovery plan is a critical component of your organization’s overall cybersecurity strategy. It works in tandem with your incident response plan to set you on a successful path to recover from cyber incidents. While your incident response plan focuses on containing and mitigating the immediate threat, the cyber recovery plan outlines the specific steps and procedures for restoring your systems and data to a fully operational state.

Understanding Cyber Recovery Readiness Planning 

Cyber recovery readiness planning involves proactive steps to protect against cyber threats and prepare your organization to respond effectively to cyber incidents. This includes identifying critical systems and data, defining roles and responsibilities, and establishing procedures for incident response and recovery.

While readiness is the starting point, resilience is the goal. Your cyber recovery plan lays the groundwork for achieving minimum viable recovery (MVR) – the ability to recover what matters most, cleanly and quickly, when it counts.

A well-crafted plan helps to: 

  •       Minimize downtime: Quickly restore critical systems and services. 
  •       Protect data: Safeguard sensitive information and intellectual property. 
  •       Maintain trust: Preserve customer and stakeholder confidence. 
  •       Comply with regulations: Meet legal and regulatory requirements.

Why Every Business Needs a Cyber Recovery Plan 

Every organization needs a recovery strategy that doesn’t just restore data but restores confidence. A cyber recovery plan defines how you’ll rebuild, validate, and resume operations cleanly – the critical bridge from readiness to resilience.

The cyber recovery plan focuses on strategy for recovering from a major cyberattack. It outlines the steps necessary to rebuild IT systems, restore data cleanly, and resume business operations. When an incident is detected, the incident response plan is activated and guides the response team in isolating the affected systems to prevent further damage. The cyber recovery plan becomes relevant during the recovery phase with the goal of a clean recovery. 

Steps to Create a Cyber Recovery Plan 

Begin by addressing these critical prerequisites for your cyber recovery plan. 

  1. Backups: Implement a robust backup strategy with frequent backups stored securely.
  2. Documentation: Maintain comprehensive documentation of your server configurations, software versions, backup environment, and network settings.
  3. Cyber recovery team: Establish a dedicated team responsible for responding to cyberattacks.

Once these foundations are in place, you can proceed to create a comprehensive cyber recovery plan.

This template provides a very basic framework for a cyber recovery plan. It’s essential to tailor the plan to your organization’s specific needs, risk profile, and regulatory requirements. For a more comprehensive and customized approach, consider attending one of Commvault’s Cyber Resilience Planning Workshops to learn how to develop a robust plan tailored to your organization’s unique needs.

Immediate Response Phase:

  1. Threat identification: Identify the type of cyberattack (for example, ransomware, malware) to determine appropriate recovery actions.
  2. Evaluation: Assess the extent of damage caused by the attack.

Recovery Phase:

  1. Threat eradication: If possible, remove the malware or exploit from compromised systems.
  2. Server restoration: Follow documented restoration procedures to enable accurate and complete restoration.
  3. Verification and testing: Validate data integrity and confirm all applications are functioning correctly.

Reintegration:

  1. Determine if reintegration is possible: Evaluate production environment to determine if the threat has been eradicated.
  2. Phased reintegration: Carefully reintroduce the restored servers back into production.
  3. User access restoration: Gradually restore user access to applications and data on the recovered servers.

Post-Recovery Actions:

  1. Lessons learned: Conduct a post-incident review to understand the attack and identify weaknesses in your security posture.
  2. Security improvement: Implement additional security measures to address vulnerabilities exploited during the attack.
  3. Communication: Communicate effectively with stakeholders about the attack, the recovery process, and the steps being taken to improve security.
  4. Testing and maintenance: Implement a formal process for reviewing and updating the cyber recovery plan to reflect changes in technology, threats, and regulatory requirements.

Cyber Recovery Readiness Checklist 

To prepare your organization, use our comprehensive Cyber Recovery Readiness Checklist. This checklist will help you assess your current readiness and identify areas for improvement. 

Online Assessment

Take our online assessment to evaluate your organization’s cyber recovery readiness. This assessment will provide you with a detailed report and actionable recommendations. 

Readiness Helps Build Resilience

Cyber recovery readiness planning is the cornerstone of resilience. It’s what turns preparation into confidence – and confidence into fast, clean recovery when it matters most.

By following the steps outlined in this guide, and using our checklist and online assessment, you can create a robust cyber recovery plan to help prepare your business to respond effectively to any cyber threat.

Take your strategy a step further by attending one of Commvault’s Cyber Recovery Workshops. These hands-on sessions help you apply best practices, test recovery scenarios, and build a plan tailored to your organization’s unique needs.

Cyber recovery readiness planning turns uncertainty into confidence and disruption into control. In the end, resilience comes from preparation – practiced, tested, and proven when it matters most.

Want to take your recovery strategy further? Read our blog Ready Is Good. Resilient Is Better. You’ll learn more about how MVR transforms readiness into real resilience.

Chris DiRado is Principal Technologist, Product Experience, at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The number of cyberattacks and threats coming can be overwhelming. Fighting back takes deep knowledge, exclusive skills, and a certain mindset. That’s why we are excited to introduce Readiverse – a new kind of learning experience, available to anyone interested in boosting their organization’s cyber resilience and readiness, including Commvault customers, partners, and people new to Commvault and cyber readiness.

Explore a world of learning opportunities designed to boost careers, modernize cyber resilience strategies, and improve your organization’s readiness in the face of ever-changing threats.

Get Equipped for the Inevitable Attack
The Readiverse boasts workshops, courses, and certifications, many of which are designed to be hands-on and interactive so you gain the frameworks and muscle memory needed to prepare for and respond to an attack.

Cyber Resilience Resources at Your Fingertips

You can supplement these learnings with a vast library of curated webinars, how-to videos, and a plethora of other resources designed to enhance your cyber resilience.

Get Proof and Confidence of Your Knowledge

We also are expanding our achievements program, giving you proof and recognition for every new course, workshop, or event you participate in. As you gain knowledge and complete learning materials, you will receive digital badges demonstrating your achievements, easy to share on LinkedIn or anywhere else you would like to humble brag.

Experience the Power of the Readiverse
Sign up for a Cyber Resilience Planning Workshop today, and experience the power of the Readiverse. In this 2-hour, instructor-led workshop participants learn best practices, common fallacies, and how to create and test their cyber recovery plan. You can read all about it here.

Or explore all the other learning opportunities the Readiverse offers here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

At SHIFT 2024 in London and streamed virtually across the globe, we introduced the concept of Continuous Business, which creates a new state of always-on business availability and resilience for the modern, cloud-first enterprise. To support that vision, we introduced several new products and enhancements that are designed to help customers improve cyber resilience.

What does it all mean for you? Here’s how Commvault CEO Sanjay Mirchandani summed it up in five takeaways that will get you well on your way with Commvault Cloud to make you and your businesses more continuous:

  1. Know what you have. Cloud Rewind helps you through its discovery engine to automatically discover, map, and then visualize complex cloud-native applications and bring them into the fold. This is critical when it comes to recovering your data and applications. You can try it free in our Commvault Cloud trial to see what you’ve got out there that’s exposed and not protected. There’s also a webinar with a deeper look at the solution.
  2. Protect the crown jewels. In this case, the crown jewels are your Active Directory. Commvault Cloud looks at your Active Directory environment before and after an attack or an event to help you quickly identify services that need to be recovered and bring them back to life. We’ve got a free trial for that as well.
  3. Don’t wait until it’s too late. This is a serious one. You have to access your recovery plan and use the Cleanroom capability that we bring to market for you to test, test, test, and look at the recoverability of your workloads today. As part of Cleanroom RecoveryTM, you can get a ransomware readiness assessment.
  4. Mind the gap. Whether it’s for diversification, regulatory reasons, or peace of mind, take advantage of cloud scalability to store a clean copy of your data using Commvault AirGap for an immutable copy with us in any cloud of your choice.
  5. Make compliance a mandate, an absolute mandate. Commvault Cloud helps you demonstrate that you comply with your regulatory requirements while helping minimize your risk and exposure as part of your business.

You don’t have to do this alone. Commvault’s here for you, and our partners are here with you. And together, we’ll give you whatever it takes to abstract the complexity, get you started, give you recovery as code, and resilience at scale so that you can truly keep your business continuous.

If you missed SHIFT 2024, you can watch on-demand here: https://www.commvault.com/shift

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Financial institutions today face unprecedented challenges in maintaining operational resilience and data security. These organizations are all reliant on technology, and they’re responsible for handling and storing large amounts of sensitive data, making them prime targets for ransomware and other cyberattacks.

Attacks like these not only put the sensitive data and financial interests of customers at risk, but also the operations and services they provide that are heavily relied upon by other sectors. Because of this breadth of impact, the European Union has enacted strict new rules in the form of the Digital Operational Resilience Act (DORA), a critical regulatory framework designed to set up the financial sector to withstand all types of ICT-related disruptions and threats.

DORA is designed to enforce the highest standards of resilience and readiness, requiring banks, insurance companies, investment firms, and other financial entities to implement advanced strategies for risk management, incident reporting, information sharing, and continuous operational resilience testing.

Pure Storage and Commvault have come together to build a joint solution that helps these organizations enhance their cyber resilience practices and address two key pillars of DORA: risk management and digital operational resilience testing. The solution is built by integrating the leading cyber resilience capabilities of Commvault Cloud with the highly secure, high-performance Pure Storage platform.

At the core of the solution is a modular design with four distinct components. As we understand that organizations inevitably will be at varying stages of maturity in their operational resilience practices, this is not a one-size-fits-all offering. Pure and Commvault have intentionally designed the solution so these different components can be added and scaled independently as organizations and their resilience practices mature and compliance requirements change.

The components of the solution include:

  • The foundational piece, a cyber resilient vault that is air-gapped, isolated, and immutable, and has internal controls that limit communication when not in use.
  • Isolated recovery environments for validating clean recovery, digital forensics, or to continuously test cyber recovery practices.
  • A rapid recovery tier to restore operations to Tier 1 applications quickly, whether to an on-premises location or to the cloud.
  • An ultra-low RTO recovery tier leveraging storage-based snapshots for near-instant restoration of mission-critical applications (e.g. payments).

The solution addresses articles in DORA through several key capabilities, including (but not limited to):

  • Identification of sensitive and at-risk backup data
  • Security built on zero-trust principles with encryption and immutability to prevent unauthorized access to data
  • Proactive, AI-assisted threat detection and cyber deception to hunt threats for faster response
  • Fast, flexible recovery of clean data
  • Support for continuous testing of cyber recovery practices, including to on-demand cloud cleanrooms (with Commvault® Cloud Cleanroom™ Recovery) or to isolated recovery environments on-premises with Pure Storage FlashArray™ or FlashBlade® systems.

The result is assisting financial institutions in transforming their cyber readiness and operational resilience practices to meet aspects of DORA’s compliance requirements.

While the primary focus of this collaboration is to help financial institutions fulfill DORA’s operational resilience requirements, the principles and technologies employed are globally relevant. This makes the solution an ideal choice for financial institutions worldwide that are looking to enhance their operational resilience and data security to ensure theircustomers’ private information is safe and they can provide uninterrupted services to the people, companies, and industries that depend on them.

As the financial sector continues to navigate through digital transformation, the importance of operational resilience cannot be overstated. This new Pure Storage and Commvault solution is purpose-built for cyber resilience and can aid financial institutions in their DORA compliance efforts. By integrating components of this solution into their operations, financial institutions can help protect themselves against ICT threats, enable continuous business, and foster trust among their customers and stakeholders.

For more information on operational resilience in financial services and the Pure Storage and Commvault partnership, click here.  

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

SHIFT 2024 is a landmark event for Commvault, showcasing our latest innovations designed to empower organizations in their journey toward enhanced cyber resilience. The news about Commvault Cloud Rewind, our focus on AWS, and new support for Google Workplace is just the tip of the iceberg.

Here’s a comprehensive summary of the key announcements that will shape the future of data protection and cyber resilience.

Extending Resilience to the Edge

Today’s cyber resilience often focuses on data centers, leaving edge and remote sites vulnerable. Commvault introduces Commvault Edge, a solution designed to extend resilience to the edge, covering retail locations, factory floors, IoT, and beyond. This simple-to-deploy, secure outpost offers unified management, ensuring comprehensive protection across all environments.

Enhanced Compliance Capabilities

With increasing regulatory pressures, proving operational resilience is crucial. Commvault has partnered with Pure Storage to support DORA compliance. Additionally, upcoming offerings will give customers new levels of customization for on-premises, customer-managed implementations to address data privacy and regulatory requirements without sacrificing cloud-like simplicity and unified management.  

Enhanced Cybersecurity Capabilities

Recovery and Forensics

Commvault is enhancing its cybersecurity capabilities with new innovations aimed at accelerating recovery and forensics. This includes forest recovery for Active Directory and change analysis. Integration with Splunk and Palo Alto Networks XSOAR significantly improves forensic capabilities, helping organizations respond to incidents more effectively.

Minimizing Risk with Advanced Detection

Commvault Cloud capabilities are designed to minimize the impact of cyberattacks by reducing data security risks and proactively detecting threats. Key features include:

  • Early warning: Utilizing cyber deception and virtual decoys to detect bad actors early.
  • Anomaly & threat detection: Continuous monitoring for indicators of compromise across environments.
  • Data security risk analysis & remediation: Offering a clear view of data classification and protection, with actionable insights to remediate high-risk scenarios.
  • Cloud resource discovery: Through the acquisition of Appranix, now called Cloud Rewind, Commvault now can discover and protect cloud-native resources, reducing blind spots and associated risks.

Cyber Readiness and Regulatory Compliance

Improving Cyber Recovery Readiness

Commvault emphasizes the importance of continual cyber recovery readiness. Unique capabilities include:

  • On-demand cleanroom provisioning & recovery testing: Leveraging cloud elasticity for frequent, isolated recovery testing.
  • Cloud application rebuild testing: Automating daily recovery and rebuilds of cloud applications to ensure readiness.
Accelerating Recovery

Commvault Cloud helps protect organizational reputation and revenue by speeding up trusted recovery with:

  • Automated cloud application rebuilding: Eliminating the gap between data recovery and business recovery by automating the rebuild of full applications.
  • Rapid, scalable cyber recovery: The fastest, most reliable recovery at the lowest TCO utilizing AI capabilities.
  • Cleanpoint validation: Automating the validation of clean recovery points to enable rapid, trusted recovery.

Consider Commvault to Improve Your Cyber Readiness

Embracing the Cloud-First Future

Cloud is the undeniable future for modern enterprises. Commvault’s solutions address cloud-first challenges, enabling organizations to leverage cloud architectures, services, automation, and scaling to unlock revolutionary ways to strengthen resilience. This approach enables businesses to maintain a constant state of readiness, and rebuild rapidly and completely.

New Customer Education Offerings

Visit the Commvault Readiverse to explore learning opportunities designed to boost your career, modernize your cyber resilience strategies, and improve your organization’s readiness in the face of ever-changing threats. Learn what it takes to create a cyber resilience plan in the Cyber Resilience Planning Workshop, a two-hour, instructor-led workshop where participants learn how to identify and plan for mission-critical data streams, infrastructure weaknesses, and key employees.  

New Professional Services Offerings

Commvault introduces new services to enhance cyber resilience:

  • Cyber Resilience Assessment: A five-day workshop to assess and improve an organization’s cyber resilience maturity.
  • Cyber Resilience Guardian: Offering twice-a-year maturity checks and a cyber response service to boost internal collaboration and execution of cyber resiliency plans.
Conclusion

SHIFT 2024 sets the stage for a new era of cyber resilience. Commvault’s latest innovations and services are designed to help organizations navigate the complexities of a cloud-first world so that they are prepared to face and overcome cyber threats with confidence. Stay tuned for more updates as we continue to lead the way in data protection and cyber resilience.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

As more organizations turn to the cloud to improve efficiency, manage costs, and improve scalability, these same advantages come with unforeseen vulnerabilities in a cloud-first environment. Protecting data is no longer enough to maintain continuous business and operational integrity in the event of an attack. Cloud Rewind protects both cloud configurations and cloud applications in sync to rebuild and restore in minutes after a cyber incident, therefore going beyond recovery to rewind the entire enterprise and maintain operational integrity.

Over 70% of cloud resources are not protected¹. This means that recovering and rebuilding all cloud configurations after an attack takes an average of 24 days and costs organizations billions in lost revenue and brand reputation. Cloud Rewind changes the game by revolutionizing cloud protection, recovering and rebuilding after a cyber event in minutes – not days or weeks.

Rebuilding after an outage requires multiple team members and scripts to be rebuilt. This is due to the fact that cloud configurations change rapidly, averaging between 10 to 50 changes per day. True recovery means the ability to rewind and restore functionality of your cloud operations. 

How? Cloud Rewind is a powerful tool that supports multi-cloud environments, enables full cross-account and cross-region replication, and seamlessly rebuilds applications from the ground up. With Cloud Rewind, you can confidently restore and rebuild your applications no matter where they are hosted and cut restoration times to just minutes, improving organizational resilience and agility.

“The integration of Appranix into Commvault Cloud enhances data management with protection, recovery, and rebuilding,” said Venkata Sudhakar Nagandla, SVP & Global Head-IT Infrastructure & Cloud, Allcargo Group Companies. “Additionally, we can achieve better RTO and RPO to meet our business needs without requiring a parallel hot standby IT infrastructure and with minimal manual effort.”

What truly sets Cloud Rewind apart is its speed and precision. Not only does it recreate all cloud resources, but it also carefully restores inter-resource dependencies, for minimal downtime and smooth continuity of operations. This can be a game-changer for your disaster recovery strategy.

“What we are doing with Cloud Rewind is unlike anything offered on the market today. In the ransomware era, recovering data is important, but it’s table stakes,” said Brian Brockway, CTO, Commvault. “We’re ushering in an entirely new chapter in cyber resilience that not only expedites data recovery, but recovery of cloud applications. This is the gold standard in recovery for a cloud-first world.”

Product Features/Functionality:
  • Cloud map: Protect, back up, and recover dependency mappings and configuration data.  Shows changes to application and configuration data over time.
  • Multi-cloud visibility: See what is running across all cloud environments, all the time.
  • Instant cloud rebuild: Cloud Rewind rebuilds entire cloud stacks after a cloud services failure or ransomware situation in minutes instead of weeks.
Product Benefits:
  • Continuous Recovery: Rebuild and rewind automation shrinks MTTR and TCO.
  • Cost: Cloud Rewind is designed to store all the snapshots of your data and dependencies at a fraction of the cost of native hyperscaler offerings.
  • Rebalancing: Leveraging all the clouds, all the major SaaS apps, and a plethora of custom applications, Cloud Rewind is both a solution that works today, but also works across clouds and technology, allowing interoperability in the future. 
  • Confidence: Continual daily testing of full cloud application and infrastructure rebuilds means no more manual processes following a cyber incident, maintaining operational resilience.

¹2022 Cloud Security Threats Report from Wiz Research

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We live in a world held hostage by the threat of ransomware. Every business, regardless of industry or category, exists under the weight of the potential consequences of an attack. As such, cyber resilience has become an enormous business. In 2025 alone, the TAM is expected to reach $300 billion dollars, growing at an annual rate of up to 13%. That’s just how big the problem, and the opportunity is. 

Yet, today, the definition of cyber resilience is shaped (and limited) by an architectural approach that has not fundamentally changed since the days of server rooms, tape drives, and physical networks. This outmoded thinking not only fuels enormous cost and complexity for the customer, limiting their ability to affordably and effectively bounce back from a breach. 

Why? Because today the enterprise is cloud-first. Over 70% of enterprise IT spend is focused on cloud-based workloads and third-party SaaS platforms. Everything is abstracted in the cloud, including on-prem environments. Even the mainframe can be virtualized. 

Still, our category continues to bump along — offering big promises and kludged together solutions rather than doing the hard work of reinventing resilience to meet the needs of the cloud-first enterprise. This lack of vision and ambition comes at the expense of the customer and the vulnerability of their business. It’s a decision to stay on the profitable, legacy course because of the belief that the effort outweighs the reward. 

The truth is, rethinking cyber resilience to meet the needs of the cloud-first world not only changes for the better the cost, complexity, and control customers can expect in protecting their entire enterprise; it also opens up amazing new opportunities by taking best advantage of what’s possible in these modern virtualized environments. 

In short, by continuing to innovate and embrace solutions built for the modern, cloud-first enterprise, we’ve pushed past the current definition of cyber resilience to enable continuous business. 

What is Continuous Business?

Like other shift-left capabilities born of modern cloud computing, such as continuous security and continuous delivery, Continuous Business creates a new state of always-on business availability and resilience for the modern, cloud-first enterprise. It centers on four key areas: 

Continuous security
Continuous readiness
Continuous recovery
Continuous rebalance

The business and its data can now operate on a timeline, or continuum, that ensures a constant state of security and readiness, along with the ability to rewind the business literally to the point before the breach; recovering everything intelligently. Not just the raw data, but the application control and metadata enabling businesses to recover rapidly, ultimately rendering ransomware irrelevant. 

This is more than a new product feature or offering. It represents an entirely new technical approach and a vision for the next decade and beyond. 

Continuous Business is the new standard for cyber resilience in a cloud-first world. 

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

To celebrate our 10th episode of the Strive podcast, I released an extended episode covering a real-life cyberattack, which brings to life some of the topics I’ve covered in previous episodes.

I investigated this attack personally during my time working in forensics and attack modeling, before my time at Commvault. Company names have been kept anonymous here for obvious reasons, but this illustration will bring you a little closer to how a breach unfolds in the real world.

An Attacker on the Inside

This breach began when the IT team noticed unusual activity on the network. It started with a few alerts from an intrusion detection system signaling potential anomalies on the network. At first, it seemed like a false alarm. But as the alerts grew more frequent, the team realized they were facing something a little bit more substantial.

The alerts seen by the IT team were an example of too little too late in this case. The activity was network traffic stimulated by criminals already communicating with their malware through command and control, sometimes referred to as C2.

The attackers actually started their campaign against this organization about three months previously, with phishing emails crafted to appear as legitimate internal communications.

And that’s of course all it took – just for one employee to click on the embedded malicious link. A remote access Trojan, a RAT, enabled the attackers to establish a foothold in the corporate network, and the weaponization phase of the attack was complete.

Next, using a tool called Mimikatz, the criminals extracted credentials from system memory, gaining admin access to the corporate network. They could now move laterally across the network, exploiting further vulnerabilities in unpatched systems to gain a further foothold in the network.

Then, they started to remotely execute various commands on various machines and servers across the IT estate, in order to further prepare for a ransomware attack.

Once they had full control and had gathered all the information about the targeted organization as was needed, which was about three months’ worth of reconnaissance in this case, the attackers deployed ransomware known as Ryuk, notorious for its ability to encrypt entire networks very quickly.

The impact of the attack was immediate and devastating. Critical business applications came to a halt within minutes. The organization could no longer access critical data like essential systems, customer information, financial records, and internal documents.

The attackers then left a ransom note, demanding a substantial payment of Bitcoin to decrypt the data. In response to all of this, the organization activated their incident response plan. They started to isolate affected systems to prevent further spread of the Ryuk ransomware, and they engaged cyber security experts to conduct a thorough investigation.

The targeted company decided NOT to pay the ransom and instead rely on system backups and disaster recovery techniques. The recovery process was complex and time-consuming. The organization had to rebuild much of its IT infrastructure almost from the hardware up.

Basic Steps to Recovery

The first step the organization took was containment, isolating infected systems to prevent the ransomware from spreading any further. Next came eradication, the business of removing the malicious software and cleaning up the network as much as possible using advanced anti-malware tools.

After several days of working on containment and eradication, the restoration process could finally start. Unfortunately, some critical backups were compromised by the ransomware. And the restoration process here was painstakingly slow.

It took eight days to ascertain where the last clean recovery points were for most of the critical business applications. A lot of recent data was lost, and the business was pretty close to breaking point by the time critical systems could be fully recovered.

Once critical systems were back up and running, the process of rigorous monitoring began. Here, implementing enhanced monitoring solutions was necessary to try and attack any signs of residual malicious activity.

All of this was reliant on thorough communication with internal and external stakeholders on the breach itself and the steps being taken to mitigate the impacts of it.

Lessons From the Breach

This incident underscores several critical lessons for organizations of all sizes:

Firstly, regular cyber security training for employees is essential. Skepticism toward email and likely phishing attempts potentially could have thwarted the initial breach three months before the indicator of compromise.

Having up-to-date backups stored offline, immutable, that cannot be compromised, is completely vital. And of course, the regular testing of those backups would have ensured in this case that they could be relied upon in this emergency. Regular testing of restoration into a clean room would have saved this organization a great deal of recovery time.

Implementing multi-factor authentication would have significantly reduced the risks associated with that credential theft that we saw.

Employing advanced threat detection techniques and anomaly detection techniques could have helped to identify early and mitigate threats in close to real time.

The organization’s full recovery here took several months, during which they operated at a significant reduced capacity. The financial cost here was immense, not only in terms of recovery expenses, but also in lost business and reputational damage.

This attack serves as a stark reminder of ever-present threats that surround all our businesses and the necessity of vigilance and preparedness. Cybercriminals are constantly evolving their tactics, and we must stay one step ahead to protect our businesses and our data. Check out the full episode here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The Digital Operational Resilience Act (DORA) is a significant regulatory framework introduced by the European Union to enhance the operational resilience of digital systems within the financial sector. The regulations are slated to go into effect January 17, 2025.

As technology becomes increasingly integral to financial services, the need for robust cybersecurity measures and resilient digital infrastructures has never been more critical. Here’s a detailed guide on how organizations can prepare to comply with DORA and bolster their digital operational resilience.

1. Understand the Scope and Requirements of DORA

You should thoroughly understand DORA’s scope and the specific requirements it imposes on financial entities. DORA aims to consolidate and strengthen IT risk management across the financial sector. It applies to a wide range of entities, including banks, insurance companies, and investment firms, as well as critical third-party service providers, such as cloud computing services.

Organizations must assess whether they fall under the scope of DORA and understand the obligations it entails, such as incident reporting, digital operational resilience testing, and management of ICT third-party risks.

2. Conduct a Comprehensive Risk Assessment

Under DORA, financial entities are required to identify, document, and manage all risks related to their information and communication technology (ICT) systems and services. Conducting a comprehensive risk assessment is crucial.

This involves mapping out all digital assets, evaluating the risks associated with each asset, and understanding the potential impact of ICT disruptions on the organization’s services and operations. The risk assessment should be an ongoing process, with regular updates to reflect new technologies, processes, and emerging threats.

3. Strengthen ICT Security Measures

Enhancing ICT security is a core component of DORA. Organizations need to implement robust security measures to protect their digital infrastructure and data from cyber threats. This includes deploying advanced cybersecurity technologies in areas such as risk identification, protection and prevention, detection, response and recovery, and, finally backup. Leveraging the approach popularized in many best practices and standards (e.g., NIST CSF), DORA provides a series of outcomes for organizations to prioritize and address cybersecurity risks but does not specify actions for meeting those outcomes.

DORA is very adamant about the importance of testing. You should conduct regular security audits and penetration testing to identify and address vulnerabilities but also test and document your organization’s operational resilience. Confirm that your security policies and procedures are up-to-date and in line with industry best practices.

4. Develop an Incident Response Plan

DORA requires financial entities to establish and maintain an effective incident response plan. This plan should outline the procedures to be followed in the event of an ICT-related incident, so that you have a quick and organized response that minimizes impact. The plan should include clear roles and responsibilities, communication strategies, and recovery procedures. Conduct regular training and simulation exercises so that the response team is well-prepared to handle potential incidents.

5. Enable Resilience of Critical Functions

Your critical functions must be able to withstand and recover from ICT disruptions. This involves designing systems and processes that are resilient and can continue to operate under adverse conditions. Redundancies should be built into critical systems, and backup solutions should be implemented to maintain data integrity and availability. Additionally, you must clearly define recovery objectives and regularly test your recovery plans to prepare your employees.

6. Manage Third-Party Risks

With the increasing reliance on third-party service providers, managing ICT third-party risks is a key requirement of DORA. Organizations should conduct thorough due diligence when selecting third-party providers and continuously monitor their performance and compliance with internal ICT risk management framework and relevant security standards. Contracts with third-party providers should include clear terms regarding data protection, incident reporting, and audit rights. You also should have a contingency plan in case the third-party fails to deliver the required service.

7. Implement Governance and Oversight

Effective governance and oversight are essential for compliance with DORA. This includes establishing a governance framework that defines the roles and responsibilities of all parties involved in managing ICT risks. Senior management should be actively involved in overseeing the organization’s digital operational resilience. Provide regular reports to senior management, detailing risk management efforts, incident reports, and compliance with DORA requirements.

8. Prepare for Reporting and Auditing

DORA mandates regular reporting on various aspects of digital operational resilience. Organizations should have mechanisms in place to collect the necessary data and generate reports in a timely manner. This includes reports on ICT risk management, incident reports, and audit findings. Additionally, organizations should be prepared for external audits by regulators or independent auditors, keeping all documentation and evidence of compliance readily available.

9. Foster a Culture of Resilience

Finally, fostering a culture of resilience within the organization is crucial. This involves raising awareness about the importance of digital operational resilience and training employees on their roles in maintaining it. A resilient culture encourages proactive identification and management of ICT risks and promotes continuous improvement of resilience strategies.

By following these steps, organizations will not only be prepared for DORA but also will enhance their overall digital operational resilience, protecting themselves and their customers from the adverse effects of ICT disruptions. As digital transformation continues to evolve, staying ahead in terms of compliance and resilience will provide a competitive edge and better position a company for long-term sustainability.

Learn more about how you can prepare for the Digital Operational Resilience Act in our Exploring DORA blog series:

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Taylor Grossman, Deputy Director for Digital Security at the Institute for Security and Technology (IST), was a recent guest on Episode 8 of The Resilience Rundown podcast. Thomas Bryant of Commvault delved into the pressing issue of ransomware with Taylor, who brings a wealth of knowledge from the frontline of cybersecurity and shares her valuable insights into combating this ever-evolving threat.

The Genesis of the Ransomware Task Force

The IST, a nonprofit, non-partisan think tank based in the Bay Area, initiated the Ransomware Task Force in the fall of 2020 as a direct response to the alarming rise in ransomware attacks, particularly during the initial phase of the pandemic. Hospitals, educational institutions, and other critical sectors were increasingly targeted, highlighting ransomware’s evolution from a mere cybercrime to a significant national security threat. The task force, comprising over 60 experts from various sectors including government, academia, and the private sector, aims to address ransomware from a holistic perspective.

A Comprehensive Framework to Combat Ransomware

In April 2021, the task force published a pivotal report outlining a comprehensive strategy to tackle ransomware. The report includes 48 detailed recommendations categorized into four main areas: deterring threats, disrupting activities, preparing responses, and effectively responding to incidents. These recommendations emphasize the importance of coordinated law enforcement efforts, robust anti-ransomware campaigns, and the regulation of the cryptocurrency ecosystems that facilitate these crimes.

Progress and Ongoing Challenges

Since the release of the initial report, there has been significant progress in the fight against ransomware. Annual progress reports highlight improvements and identify areas needing more attention. One notable advancement is the increased focus on incident reporting, which has been bolstered by legislative actions like the Cyber Incident Reporting for Critical Infrastructure Act of 2022.

Despite these efforts, challenges remain. The healthcare sector continues to be particularly vulnerable, with recent attacks underscoring the potential for immediate and severe consequences. Strategic disruptions of ransomware operations, such as the LockBit takedown, showcase effective international cooperation but also highlight the need for continuous action to prevent the reformation of criminal groups.

The Role of Cryptocurrency in Ransomware

A significant focus for IST has been the payment ecosystem associated with ransomware. The process from ransom demand to the laundering of funds involves numerous steps where interventions can be implemented. Identifying and regulating under-monitored components of this ecosystem are crucial for dismantling the financial infrastructure that supports cybercriminals.

Everyone Has a Role to Play

The fight against ransomware requires a collective effort. Governments need to enhance policy frameworks and harmonize reporting standards. The private sector must prioritize security from the design phase to build more resilient systems. Public awareness and education also play critical roles in bolstering defenses against these threats.

Engage and Learn More

For those interested in learning more about the work of the IST or engaging with the community, Taylor recommends visiting the Institute’s website and participating in their public webinars and roundtables. These platforms offer a wealth of information and provide opportunities for direct engagement with experts in the field.

As we continue to navigate the complexities of cybersecurity, these insights remind us of the importance of resilience, collaboration, and proactive measures in the ongoing battle against ransomware.

Listen to the full podcast episode here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Healthcare organizations must be prepared for data security risks and operational disruptions from cyberattacks. Implementing best practices enhances cyber resilience, ensuring an efficient response and recovery when these incidents occur.

“Resilience in healthcare is crucial,” says David Houlding, Microsoft’s Director of Global Healthcare Security and Compliance Strategy. “Without it, timely and reliable access to data is compromised, which can critically impact patient care. Access to data at the point of care is essential, and any disruption can significantly hinder healthcare delivery, degrading the quality of patient care, or in the worst cases, jeopardizing patient safety.”

To strengthen resilience and maintain uninterrupted access to critical data, healthcare organizations should implement the following best practices.

1) Conduct a Thorough Risk Assessment

A comprehensive risk assessment helps healthcare organizations identify and address security gaps before they can be exploited by cyber threats.

The HIPAA Security Rule mandates covered entities to conduct a risk assessment and implement appropriate measures to address key areas and protect electronic protected health information. Risk analysis should be an ongoing process where covered entities and business associates continuously evaluate risks and security measures. Effective assessments identify and prioritize risks and help organizations focus limited time and resources on the highest priority risks. For each risk identified, they can then identify associated vulnerabilities, including unsecured networks, unpatched systems, and many others across the IT spectrum.

“Measuring security posture through risk assessments is vital for identifying gaps and mitigating risks,” notes Houlding. “Trusted compliance frameworks also help direct limited resources to where they can best improve security and lower risk.”

During a risk assessment, security practitioners identify risks to confidentiality, integrity, and availability of sensitive healthcare data and then prioritize risks according to impact and likelihood of occurrence. While a risk assessment won’t eliminate cyberattacks, it helps to guide limited resources to top-priority risks where they can do the most good in terms of improving security posture. This makes attacks harder for threat actors and gives the security team better visibility, improving monitoring, detection, response and recovery efforts.

2) Implement Strong Cybersecurity Policies and Procedures

After identifying security gaps through a risk assessment, healthcare organizations should implement strong cybersecurity controls and tighten procedures to reduce the occurrence and impact of cyberattacks. For example, segmenting critical systems from the network can help prevent threat actors from lateral movement inside the healthcare organization and accessing essential systems, minimizing risk of patient care disruptions.

As a preventive measure, security practitioners should address known vulnerabilities and secure medical devices prone to exploitation. Common vulnerabilities and insecure configurations in healthcare include web application vulnerabilities and unsupported software, data from the Cybersecurity and Infrastructure Security Agency shows.

Ensuring that all systems are protected by multifactor authentication (MFA) is another way to reduce the occurrence and impact of cyberattacks. Data from the HHS 405(d) Program showed that while over 90% of hospitals use MFA, its inconsistent application creates gaps. Implementing MFA across all systems strengthens network security and hinders threat actors.

Data backups and strong encryption are also critical for saving time and money during a breach. Proven best practices, including network segmentation, MFA, and vulnerability management, can help organizations mitigate risks and prepare for attacks.

3) Develop Response and Recovery Plans

The first step is recognizing that a cyberattack or data breach is likely. From there, security experts can plan response and recovery efforts in preparation for an incident. HIPAA requires that covered entities develop an incident response plan, along with a data backup, cyber recovery, and emergency mode operation plan to maintain compliance.

When a cyber incident occurs, healthcare organizations must be prepared to engage with stakeholders, legal counsel, law enforcement and patients. Conducting tabletop exercises with key stakeholders before a cyber incident can help organizations respond more efficiently and effectively amid an actual cyber event.

Incident response plans should include communication strategies, alternative ways to access patient records during EHR system downtime, and procedures to ensure the availability of critical healthcare data. After containing a threat, the focus shifts to executing a recovery plan that restores data and systems as quickly as possible.

“Cloud providers offer superior security compared to individual hospitals, enabling healthcare organizations to implement more effective response and recovery plans while securely shifting infrastructure and focusing on innovation and efficiency,” observes Jaimie Fox, Senior Technology Strategist at Microsoft.

While a cyberattack may be inevitable, conducting risk assessments, employing security best practices, and practicing incident response and recovery are domains that healthcare organizations can control.

4) Partner with a Strategic Technology and Services Partner

Partnering with a data protection provider specializing in cyber resilience and recovery in healthcare offers several critical advantages. Healthcare organizations with mixed infrastructure (on-premises, hybrid, cloud, multi-cloud) need a partner that unifies cyber resilience and data protection across environments for consistent security and availability. Consolidating backup systems into one solution reduces costs, eliminates redundant infrastructure, and minimizes technical debt, leading to improved efficiency. A specialized data recovery partner also enhances cyber resilience by ensuring recovery into clean environments, lowering the risk of reinfection after an attack.

Finally, a data protection and information management provider offering advanced capabilities around data storage, portability, and accessibility can enable seamless data movement and repurposing, supporting cloud migrations and enhancing business continuity. AI-driven automation further simplifies data protection, governance, and recovery processes, reducing administrative burdens on IT teams and enabling faster, more secure recovery from ransomware and other threats.

Commvault’s Cleanroom Recovery offers a groundbreaking solution for healthcare organizations facing ransomware, ensuring recovery into a clean environment and reducing reinfection risk. Validated by the Enterprise Strategy Group, it uses its unique any-to-any portability for efficient, secure data recovery. This capability is crucial for strengthening cyber resilience and enabling quick, safe restoration for healthcare organizations after an attack.

“Commvault is a key partner for healthcare organizations seeking cloud cyber resilience on Azure,” says Karen Cox, Microsoft’s Global Healthcare Partner Strategy Leader. “With deep Microsoft security integration, Commvault’s advanced solutions safeguard healthcare data and applications across cloud and hybrid environments.”

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Increasing cyberattacks are challenging the ability of healthcare organizations to maintain their daily operations and provide timely and effective patient care. The disruption caused by such attacks has led the Federal Bureau of Investigation(FBI) and the Department of Justice to classify them as “threats to life” crimes, posing serious risks to patient and public safety.

To combat these threats, healthcare organizations must implement strategies that consolidate data protection and improve cyber resilience. Such approaches enhance security while reducing costs, allowing funds to be reinvested in innovation and new technologies.

“Healthcare organizations are under constant cost reduction pressure, which extends to security teams,” says Microsoft’s Director of Global Healthcare Security and Compliance Strategy David Houlding CISSP, CIPP.

“Security teams are often understaffed, with skilled resources hard to find, costly, and difficult to retain,” Houlding continues. “Improving the speed, scale, accuracy, and upskilling of these teams is crucial, regardless of security operations center size.”

Reducing risk, meeting regulatory requirements, and preparing for cyber-attacks not only protect data and ensure quality and continuity of patient care, but they also drive cost savings and simplify management.

Challenges Facing Healthcare Data Security

Healthcare providers are grappling with both internal and external challenges to maintain secure operations.

Verizon’s 2023 Data Breach Investigations Report highlights an alarming rise in external threats to healthcare, with ransomware being particularly disruptive. External attackers were responsible for 66% of data breaches, primarily targeting personal and medical information.

According to the Office of the Director of National Intelligence, ransomware claims increased by 74% globally in 2023, with attacks against the U.S. healthcare sector rising by 128%. This surge affected 258 victims in 2023 compared to 113 in 2022.

External threats are on the rise just as the healthcare system struggles to maintain a skilled security workforce. The 2023 HIMSS Cybersecurity Survey reveals that 43% of healthcare organizations lack the budget to hire professionals, with many reporting shortages in both healthcare and cybersecurity experience. Furthermore, 37% of organizations struggle to find qualified candidates and 21% note that there are insufficient skills in the talent pool.

“Providing guidance and on-the-job learning opportunities enhances their skills and effectiveness in managing security challenges,” notes Houlding.

Beyond staffing shortages, many healthcare organizations are using outdated systems. A 2023 Department of Health & Human Services report on hospital cyber resiliency found inconsistent adoption of critical security measures and widespread use of outdated systems. Notably, 96% of hospitals still rely on end-of-life systems with known vulnerabilities.

Failure to update these systems not only risks patient safety but can also result in significant financial costs to healthcare organizations. Healthcare remains the most expensive industry for data breaches, with average breach costs reaching $9.77 million in 2024, according to IBM’s Cost of a Data Breach Report. It’s the sector’s reliance on outdated technologies that makes it an attractive target, as healthcare providers are intolerant to operational disruptions.

Service disruptions and system outages have immediate and lasting effects, compromising the quality and safety of patient care, eroding patient trust, jeopardizing outcomes, and threatening healthcare sustainability. Investing in cybersecurity and resilience is crucial to prevent these risks.

A Secure and Cost-Effective Path Forward

In healthcare, compliance with regulatory standards and effective risk mitigation are essential to protect sensitive patient data.

“HIPAA sets important standards for patient data protection but is widely seen as insufficient for fully mitigating today’s risks,” says Houlding. “In cyber resilience, data availability is as vital as confidentiality and integrity. Attacks like ransomware and denial of service targeting the availability of data and systems can halt operations. Addressing risks such as ransomware, insider threats, and third-party vulnerabilities is crucial for maintaining security.”

Healthcare organizations should regularly assess security gaps using Zero Trust cybersecurity frameworks, focusing on long-term strategies to address threats such as ransomware while optimizing limited resources for data resilience and breach recovery.

Integrated security solutions reduce costs and improve efficiencies, avoiding disjointed systems from overwhelming analysts and increasing the risk of missed threats. AI-driven solutions can help improve the speed, scale, and accuracy of security teams, streamlining operations, upskilling them with timely guidance in teachable moments, and improving threat detection and response.

As health systems, hospitals, and physician groups work to reduce technical debt by modernizing their IT infrastructure and moving to the cloud, resilience and security become even more critical.

“Shifting to cloud environments, including hybrid models, requires end-to-end resilience and compliance,” Houlding explains. “Healthcare organizations are migrating systems like EHRs to the cloud to reduce technical debt, improve agility and scale, and focus more on developing higher-level healthcare applications. Since migrations can take months or years, it’s crucial to maintain resilience for seamless data access and ensure compliance to protect systems and data during the transition.”

As cyber threats evolve, healthcare organizations must adopt a proactive, integrated approach to security and resilience. Prioritizing long-term strategies and leveraging advanced tools safeguards patient data, builds trust, and ensures smooth operations. Investing in robust, integrated, AI-powered cybersecurity now mitigates immediate risks and strengthens future resilience.

“Microsoft’s healthcare investment is strengthened by Commvault’s deep industry expertise,” says Karen Cox, Microsoft’s Global Healthcare Partner Strategy Leader. “Commvault’s expertise in healthcare workloads complements Microsoft’s security, making them a key partner in delivering comprehensive solutions.”

Commvault’s any-to-any portability enhances healthcare organizations’ cyber resilience, enabling rapid, infection-free recovery and safeguarding patient data. Additionally, Commvault Cloud Cleanroom Recovery, validated by TechTarget’s Enterprise Strategy Group, ensures recovery into a clean environment, protecting against ransomware and securing critical data.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Last year, the Department of Health & Human Services has issued a strong warning to U.S. hospitals, highlighting the growing cyber threats to healthcare. The Federal agency’s report on hospital cyber resiliency noted that the widespread adoption of health information technology, driven by the Health Information Technology for Economic and Clinical Health (HITECH) Act, the Affordable Care Act, and the 21st Century Cures Act, has expanded the healthcare industry’s vulnerability to cyberattacks. 

“Directly targeted ransomware attacks aimed to disrupt clinical operations are an outsized and growing cyber threat to hospitals,” HHS emphasized. “Ransomware is currently the largest threat to this sector and deserves immediate attention—especially considering the impact the nonavailability of services can have on patient care and safety.” 

Ransomware attacks are often combined with the theft of sensitive patient data. According to the HHS Cybersecurity Program, electronic health records (EHRs) are prime targets for cyberattacks because they contain valuable protected health information (PHI) such as names, social security numbers, geographic data, and biometrics. This data is highly profitable for cybercriminals and difficult to secure once exposed. 

Security Regulations Regarding EMR/EHR According to HIPAA

The HHS warning highlights significant vulnerabilities in healthcare information systems that expose organizations to ransomware attacks, data breaches, and other cyber threats. Healthcare providers must recognize these warnings as urgent calls to action rather than routine advisories. The implications extend beyond technical concerns: Inadequate EHR security creates legal liability, compromises patient care, and damages institutional reputation.

Common threats to EHR security include:

  • Insider threats: Staff members who accidentally or intentionally misuse their access to patient records.
  • Third-party risks: Vendors and business associates with access to systems but potentially inadequate security practices.
  • Legacy systems: Outdated software and hardware that no longer receive security updates.
  • Mobile device vulnerabilities: Unsecured smartphones and tablets used to access patient information.
  • Cloud security gaps: Inadequate protection for data stored in cloud environments.
  • Phishing attacks: Targeted campaigns designed to steal credentials from healthcare workers.
  • Inadequate backup protocols: Insufficient or untested backup systems that fail during recovery scenarios.

These threats directly connect to HIPAA non-compliance when organizations fail to implement required safeguards. For example, a ransomware attack exploiting unpatched software represents a violation of the HIPAA Security Rule’s system protection requirements.

The financial consequences of these attacks can be severe. According to IBM’s 2024 Cost of a Data Breach Report, healthcare breaches cost organizations an average of $9.77 million. One example is the recent ransomware settlement involving Heritage Valley Health System, where the Office for Civil Rights imposed a $950,000 fine and required a corrective action plan. Incidents like this underscore the importance of robust cybersecurity measures to prevent breaches and reduce risks. 

Security regulations regarding EMR/EHR according to HIPAA include implementing reasonable and appropriate administrative, physical, and technical safeguards for protecting ePHI. The HIPAA Security Rule establishes specific mandates for protecting EHRs. It requires regulated entities to have:

  • Administrative safeguards: Risk analysis, security management processes, workforce training, and contingency planning.
  • Physical safeguards: Facility access controls, workstation security, and device/media controls.
  • Technical safeguards: Access controls, audit controls, integrity controls, and transmission security.
  • Organizational requirements: Business associate contracts and documentation requirements.
  • Policies and procedures: Implementation of reasonable and appropriate security measures.

Healthcare organizations should conduct a comprehensive security risk assessment to identify vulnerabilities. Then they should develop a remediation plan that prioritizes critical gaps, updating security policies and procedures, implementing technical safeguards, and providing staff training on security protocols. Regular security audits help maintain ongoing compliance and adapt to emerging threats.

EHR Security Measures and Importance

Because EHRs are prime targets, security is increasingly important. EHR security encompasses specialized safeguards designed to protect ePHI within healthcare information systems. EHR security must address both the technical vulnerabilities of digital systems and the unique privacy requirements mandated by healthcare regulations.

The foundation of effective HIPAA EHR security rests on three core principles:

  1. Confidentiality protects against unauthorized access to sensitive patient data.
  2. Integrity maintains the accuracy and consistency of health records throughout their lifecycle.
  3. Availability makes certain that authorized users can access critical information when needed for patient care.

Essential EHR Security Measures

These EHR security measures can help healthcare organizations protect patient data while meeting HIPAA requirements:

  • Access controls: Role-based permissions that limit data access to authorized personnel based on job function and need-to-know basis.
  • Authentication systems: Multi-factor authentication requiring multiple verification methods before granting system access.
  • Encryption: Data encryption both at rest and in transit to protect information even if systems are breached.
  • Audit trails: Comprehensive logging of all system activities to track who accessed records and what changes were made.
  • Regular EHR security risk analysis: Systematic evaluation of security vulnerabilities and implementation of mitigation strategies.
  • Backup and recovery: Regular data backups with tested recovery procedures to maintain availability during incidents.
  • Physical safeguards: Restricted physical access to servers and workstations containing ePHI.
  • Security awareness training: Ongoing education for all staff on security protocols and threat recognition.

EHR Privacy and Security Concerns

Data integrity and privacy represent distinct but interconnected aspects of EHR privacy and security concerns. Data integrity focuses on maintaining the accuracy and completeness of health records throughout their lifecycle: preventing unauthorized alterations, detecting corrupted data, and preserving the reliability of medical information.

Privacy centers on controlling who can access patient information and under what circumstances. Both elements require dedicated protection measures to maintain HIPAA compliance.

While encryption provides a critical layer of protection for EHR data, it cannot serve as a comprehensive security solution to EHR security breaches. Encrypted data remains vulnerable if access controls are weak, authentication systems are compromised, or insiders misuse their legitimate access privileges. Healthcare organizations must implement a multi-layered security approach that addresses the full spectrum of potential vulnerabilities to address EHR privacy and security issues.

Access controls, audit logs, and regular risk assessments work together to maintain both integrity and privacy of electronic health records. Access controls limit data exposure based on role and necessity. Audit logs create accountability by tracking all interactions with protected health information. Risk assessments identify emerging vulnerabilities before they can be exploited.

“The shift to the cloud has gained momentum because it reduces technical debt and improves security,” says Jaimie Fox, Senior Technology Strategist at Microsoft. “Cloud providers offer far greater security than individual hospitals, allowing healthcare providers and EHR vendors to securely move infrastructure while focusing on innovation and efficiency.” 

Many healthcare providers are increasingly recognizing the necessity to take advantage of the cloud’s advantages over traditional infrastructure. However, this shift raises a critical question: How can healthcare organizations protect mission-critical systems from cyber threats while ensuring they remain operational for patient care? 

Enhancing Cloud Based EHR Security

With growing cyber threats to EHR systems, healthcare organizations must adopt proven strategies for cyber resilience. Key methods include leveraging cloud-based security infrastructure, comprehensive risk mitigation, and integrating AI into security workflows to enhance readiness against attacks. 

With limited cybersecurity personnel, healthcare organizations have an opportunity to use the cloud to bolster their cybersecurity posture as well as address technical debt that plagues the majority of U.S. hospitals. While complying with federal, state, and local regulations is crucial, mitigating cybersecurity risks goes beyond just meeting compliance standards.  

“In cyber resilience, protecting data availability is as critical as ensuring its confidentiality and integrity,” says David Houlding, Microsoft’s Director of Global Healthcare Security and Compliance Strategy. “Healthcare organizations must also defend against breaches, insider threats, and third-party risks, which can cause severe disruptions, including system shutdowns.” 

The cloud’s flexibility and scalability enable the rapid integration of advanced, data-intensive technologies that help healthcare cybersecurity professionals strengthen security and empower clinicians to apply cutting-edge tools to patient care. 

“AI capabilities, which enhance productivity and reduce costs in EHR systems, are only achievable in a cloud environment,” notes Fox. “Traditional on-premises systems cannot support these advanced AI functions, limiting innovation and cutting-edge solutions in clinical care.” 

AI can also revolutionize healthcare cybersecurity by quickly identifying and responding to potential threats to data, systems, and applications.  

“With AI, security analysts can detect and respond to sophisticated attacks, such as phishing and spear phishing, which are now becoming more widespread and cheaper to execute due to attackers also using AI-driven automation,” says Houlding. “Additionally, AI can provide real-time guidance, helping security teams improve their skills on the job, making them better equipped to handle the rapidly evolving threat landscape.” 

As healthcare organizations transition to the cloud, balancing innovation with security is essential.  

Choosing the Right Cyber Resilience Partner 

By leveraging cloud-based security and AI-driven protections, healthcare providers can safeguard critical systems while driving clinical innovations in patient care. 

“Commvault is a trusted Microsoft partner and a key partner for healthcare organizations seeking true cloud cyber resilience on Azure. They have an unmatched track record, and as you’ve heard from our colleagues, their value proposition is unique and industry-leading, says Karen Cox, Global Healthcare Partner Strategy Leader at Microsoft. 

“Commvault is a leader and early participant in the Microsoft Copilot for Security Partner Program, using the latest technology to protect enterprises,” she continues. “Their solutions are fully integrated with Microsoft security, co-engineered with Microsoft, and adhere to Azure Protection Services standards. This makes Commvault an ideal partner for safeguarding healthcare applications and data, whether in the cloud or a hybrid environment.” 

Healthcare organizations can strengthen their recovery strategies against EHR attacks by leveraging Commvault Cleanroom Recovery, the only solution validated by the Enterprise Strategy Group for ensuring recovery into a guaranteed clean environment. With ransomware posing a top threat, a secure and auditable recovery plan is essential for resuming operations quickly and safely.  

By using Commvault’s advanced cyber resilience platform, healthcare organizations can recover quickly and safely without the risk of reinfection, protecting patient data and ensuring long-term operational security. Download our comprehensive guide to prepare your healthcare organization with practical steps and best practices for cyber recovery.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Businesses require robust and efficient data protection solutions in the face of all the challenges in today’s digital landscape. At Commvault, we understand the critical need for swift and reliable backups that minimize the time needed to create recovery points and optimize data transfer. That’s why we are thrilled to announce the implementation of Change Block Tracking (CBT) for Oracle Cloud Infrastructure (OCI) Instance backups.

What is Change Block Tracking?

Change Block Tracking is a powerful technology that significantly enhances the efficiency of backup processes. Traditionally, backups can be time-consuming and storage-intensive, as they involve processing and copying all data, regardless of whether it has changed. CBT revolutionizes this process by only processing the changed blocks since the last backup and backing up only those data blocks. This not only reduces the amount of data that needs to be transferred but also speeds up the entire backup process.

Key Benefits of CBT for OCI Instance Backups:
  1. Faster Backups: With CBT, only modified data blocks are captured, reducing backup times significantly. This means less disruption to your business operations and more frequent backup cycles.
  2. Enhanced Data Protection: CBT enables more frequent and reliable backups, ensuring that your critical data is always protected. In the event of data loss or corruption, you can restore the latest version with minimal data loss.
A Collaborative Effort:

This achievement would not have been possible without the dedication and hard work of our valued partner, Oracle. Their expertise and collaboration have been instrumental in development and integration of Change Block Tracking within OCI. We are grateful for their commitment to delivering world-class technology solutions.

How to Get Started:

Implementing CBT for your OCI Instance backups is simple and straightforward. As of the fall release of CBT, Commvault customers will use CBT backups automatically when protecting their OCI Instances. There is no configuration required within the OCI portal or Commvault Command Center. All incremental backup operations will leverage CBT automatically.

Details:

To show a concrete example of the time savings that can be realized from OCI Instance Change Block Tracking, let’s look at the details of backups jobs with and without Change Block Tracking enabled. The VM noted below was backed up using Commvault software with deduplication enabled to object storage within OCI. The VM was a simple Linux server with a single 50GB volume.

The initial full and incremental cycle was executed without Change Block Tracking. The second full and incremental cycle used Change Block Tracking. The amount of change introduced between full and incremental was similar between the two backup runs.

VM Backup without CBT
Full 9.8 GB 1 hr 5 min
Incremental 4.2 GB 1 hr 2 min
VM Backup with CBT
Full 9.8 GB 1 hr 7 min
Incremental 3.3 GB 22 min

Without CBT, the full and incremental backups process the entire VM. This causes each backup operation to take a similar amount of time. The full moves all the data, and the incremental compares blocks with what is in storage and only moves changed data.

With CBT, only the changed data is processed and sent to backup storage. This results in reduced incremental processing time.

CBT Has a Positive Impact on Your Backup Strategy

At Commvault, we are committed to providing cutting-edge solutions that empower businesses to thrive in a digital world. The introduction of Change Block Tracking for OCI Instance backups is a testament to our dedication to innovation and excellence. We are excited to see the positive impact this technology will have on your backup strategy and overall data protection.

Stay tuned for more updates and enhancements as we continue to innovate and elevate your cloud experience. And if you want to know more OCI Change Block Tracking, please reach out to your Commvault account team.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Commvault Field CTO and Principal Technologist Dan Conrad stopped by Episode 12 of The Resilience Rundown podcast to chat with host Thomas Bryant about Active Directory. Dan has over two decades of Active Directory experience.

Common Threats to AD

Thomas mentioned that many people in the industry tend to overlook authentication and Active Directory when they’re planning for cyber incidents. Dan agreed that the most common threats haven’t changed over his career and tend to boil down to people, processes, and mentalities.

He shared that the way Active Directory was administered previously was flawed and administrators created dangerous or exploitable situations by running all over the network and doing everything with admin credentials.

The single sign-on nature of Active Directory, Dan said, makes it very easy for users and admins to use, but we leave footprints everywhere we go. And those footprints are exploitable by attackers. He mentioned many examples of breaches resulting from one user with a compromised credential.

Increased Security

Over the years, admins including Dan have made advances in security practices, such as managing his regular account separately from his admin account, and using Priviliged Access Management solutions.

“That’s much more efficient from a security perspective because every time I’m done using it, I check it back in and it changes the password, which nullifies all those hashes I just left across the network so that they can’t be exploited,” he said.

He also mentions the need to be careful about giving out credentials just because someone asks – and keep an eye on third-party domain trust relationships that can put systems at risk.

Best Practices

Thomas asked about other best practices to secure Active Directory against threats beyond separating roles and PAM. Dan mentioned patching, with an awareness of the impact to legacy applications. He also mentioned the most important thing is knowing everything you can possibly know about Active Directory.

“That’s sort of my mentality, that safety net, that you think you know how to detect, you think you know how to patch, you think you know how to do all this stuff,” Dan said. “But if you can’t recover, none of that really matters because there’s going to be something you didn’t know about.”

Role of Backup and Recovery

Thomas’ question on the role of backup and recovery in terms of protecting Active Directory prompted Dan to recall some sticky situations from the past. However, he also mentioned that “the other side of that is having the ability to recover at a granular level, is sort of a very relaxing feeling.”

Watch the full podcast here for the rest of their conversation.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Traditional disaster recovery plans are proving inadequate against the sophisticated nature of modern cyberattacks that companies are facing now. These conventional strategies often lack the necessary agility and comprehensive testing mechanisms required for effective defense and rapid recovery post-incident.

Traditional disaster recovery plans typically do not support cyber testing and are not designed for the swift recovery actions needed after a cyber breach. This limitation not only delays response times but also compromises the integrity of data recovery processes. Disaster recovery plans often fail to instill confidence and security, leaving organizations vulnerable to ongoing threats.

Commvault Cloud® Cleanroom™ Recovery was purpose-built to address these shortcomings by providing a malware-free environment coupled with isolated recovery control planes. This advanced approach delivers a secure recovery process, protected from malware and other threats through virtually air-gapped storage. This solution includes frequent, cost-effective testing to ensure data cleanliness and readiness for recovery, thereby meeting stringent compliance demands with auditable evidence.

Cleanroom Recovery leverages AI to scale recovery efforts, enabling rapid and reliable restoration of massive datasets. It incorporates built-in automation for straightforward implementation and operational ease. Furthermore, organizations can enhance their security posture by identifying and remediating vulnerabilities susceptible to ransomware attacks through built-in anomaly detection and comprehensive reporting.

The encryption of data at-rest and in-transit, secure forensic analysis using malware-free hardware in isolated cloud environments, and the automation and orchestration of recovery processes underscore the robustness of Cleanroom Recovery. Regular testing and validation of cyber recovery plans are crucial for confirming preparedness and resilience against ransomware attacks, thus proving that traditional disaster recovery plans will not prepare organizations for the nuances of cyber threats.

Get the latest insights from the Cyber Recovery Readiness Report for IT, and watch the recent webinar Going beyond Disaster Recovery to Cyber Recovery. Steps to achieve total resilience.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In today’s digital age, the threat of cyberattacks looms larger than ever, making robust cyber recovery strategies essential for safeguarding data and maintaining business continuity. Our latest guide, “Cleanroom: A Comprehensive Strategy for Cyber Recovery,” delves into the innovative concept of cleanrooms, or Isolated Recovery Environments (IREs), which are pivotal in fortifying organizations against cyber threats.

A cleanroom is not merely a secure space – it’s a comprehensive approach that integrates secure, isolated environments with thorough planning, best practices, rigorous testing, and precise procedures. This strategy is crucial in protecting against data breaches, financial losses, and reputational damage.

The guide provides an in-depth exploration of the business value of cleanrooms, illustrating how they serve as a proactive defense strategy through a blend of technology and strategic planning. This solution offers automated recovery validation, secure forensic analysis, and faster recovery times.

The guide also covers various use cases for cleanrooms, including continuous cyber recovery plan testing, incident response and forensics, and secure data recovery, highlighting the limitations of traditional recovery approaches and the advantages of Commvault® Cloud Cleanroom™ Recovery. Here’s how they compare:

Traditional ApproachesCleanroom Recovery
Reactive to threats: Many solutions lack bidirectional integration with security platforms.Proactive approach: any-to-any workload portability; continuous, automated testing capabilities.
Limited workload support: often limited to just virtual machines or on-premises workloads.Simplified management: supports legacy, hybrid, and modern cloud native apps.
Technical debt: ad-hoc solutions added over time.Consulting to plan and deploy the optimal solution.
Complex manual processes: fail to provide comprehensive orchestration for on-demand recovery.Extensive automation capabilities; streamlined recovery process to mimimize downtime.
Insufficient scale: appliance-based models; slower recovery times.Leverage the cloud for limitless scale: SaaS or on-premises deployment options.

If you’re involved in designing and executing your organization’s cyber resilience strategy, this guide is for you. It offers detailed insights into how cleanrooms provide a robust defense against cyber threats, with strategic integration of secure environments, planning, processes, and testing to enhance cyber resilience.

The guide addresses the increasing prevalence of cyberattacks and the critical need for effective recovery solutions, providing a comprehensive roadmap to implementing and benefiting from cleanrooms. Additionally, it includes valuable business perspectives, use cases, and expert quotes that underscore the practical benefits and effectiveness of cleanroom strategies in real-world scenarios.

Dive into the full guide to not only understand the strategic importance of cleanrooms but also to equip your organization with the knowledge to enhance its cyber resilience.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Social media has become an integral part of our lives, offering unparalleled convenience in communication and connection. However, this convenience comes with significant cybersecurity risks that can jeopardize both our personal and professional lives.

On Episode 9 of the STRIVE podcast, I summarize the key social media security risks and provide practical tips to protect yourself and your organization.

Here are the five main risk types to keep in mind:

1. Phishing attacks: Cyber criminals often pose as trustworthy entities to steal personal information through deceptive messages and links. Always verify the source before clicking on any link or providing information.

2. Data breaches: A breach of a social media platform could expose sensitive information from millions of users. Individuals and organizations should use strong, unique, and regularly updated passwords, and monitor their accounts for suspicious activity.

3. Identity theft: This occurs when someone uses your personal information, often for financial gain. Limit the information you share online, be cautious about who you connect with, and regularly review your privacy settings.

4. Malware: Malware can spread through social media via malicious links and downloads, compromising your devices and data. Avoid downloading files or clicking links from unknown sources, and use reputable antivirus software.

5. Data scraping: Automated tools can collect vast amounts of data from social media profiles, which can be sold or used for targeted attacks. Limit the amount of information you share, and be wary of third-party apps.

Here are some practical tips to help enhance your security while using social media:

  • Enable two-factor authentication: Do not rely solely on passwords.
  • Use unique passwords: Differentiate your passwords for various accounts.
  • Be cautious on public Wi-Fi: Use VPNs where possible to secure your connection.
  • Regularly update privacy settings: Stay on top of who can see your information.
  • Stay informed: Keep abreast of the latest security threats related to social media.

By taking these proactive steps, you can enjoy the benefits of social media without compromising your security. To see the full podcast episode, click here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery