Skip to content

When cyber attackers strike, speed isn’t everything. Restoring quickly from compromised data simply reintroduces the threat, creating a vicious cycle of infection and reinfection.

I recently wrote a whitepaper with my colleagues from Kyndryl titled, Redefining Cyber Recovery: Introducing Mean Time to Clean Recovery (MTCR) where we introduced a fundamental shift: measuring how fast you can restore from clean, verified data rather than just any available backup.

Here are the five critical steps that determine your organization’s MTCR:

 

  1. Establish a clean environment to recovery into.

The problem: Recovery to an infected infrastructure will simply reinfect your restored systems.

The solution: Isolated Recovery Environments (IREs) or cleanrooms – compute and storage infrastructure physically or virtually separated from production environments where attackers never had access.

Reality check: Without an IRE, modern forensic teams need 24 to 72 hours to certify complex hybrid environments as “clean.” Your MTCR automatically becomes measured in days, not hours.

 

  1. Find clean data to recover from.

The hidden threat: Modern attackers operate in stealth for weeks before launching attacks, seeding malicious payloads throughout your environment – including backup systems.

The breakthrough: Automated scanning for Indicators of Compromise can help identify clean backup sets without the trial-and-error cycle of testing each backup until you find one that works.

Collaboration required: This step demands tight integration between SysOps teams (who manage backups) and SecOps teams (who understand current threats). Forensic analysis reveals attack signatures that must be fed into the scanning process.

 

  1. Recover data in acceptable time.

The uncomfortable truth: Enterprise backup solutions often deliver “10+ hours per terabyte” recovery performance. Scale this to typical enterprise services requiring hundreds of terabytes, and you’re looking at weeks of recovery time.

The reality: Most backup infrastructure was designed for nightly incremental backups (5% data change), not full-scale business restoration (100% recovery).

The solution: Purpose-built cyber resilience platforms with high-performance recovery capabilities, combined with minimum viable company (MVC) prioritization – focusing on the critical 20% of services that enable 80% of business function.

 

  1. Maintain data integrity across the platform.

The challenge: Enterprise systems don’t exist in isolation. During recovery, systems restored from backups taken at different times create data integrity nightmares.

Example scenario:

  • Customer database: Tuesday 3 a.m. backup
  • Billing system: Monday 11 p.m. backup
  • Inventory system: Wednesday 6 a.m. backup

Result: Orders for customers who don’t exist, invoices for products not in inventory.

The Process: Restoration sequencing based on dependencies, data reconciliation across integrated systems, and comprehensive consistency checks before production return.

 

  1. Test before production return.

The rush trap: Under pressure, IT teams often rush systems back online without comprehensive testing, leading to partially functional systems or reintroduction of attack remnants.

 

Comprehensive validation:
  • Functional testing of core business processes
  • Security validation through vulnerability scanning
  • Data integrity verification across platforms
  • Business process validation by application teams

Critical success factor: Pre-define your MVC acceptance criteria – the specific functionality that must work before you’re truly “recovered.”

 

The Integration Challenge

These aren’t sequential steps – they’re interconnected capabilities that must work together. Your MTCR is only as fast as your slowest step and only as reliable as your weakest validation point.

The investment reality: Clean recovery requires purpose-built cyber resilience platforms, isolated recovery environments, automated scanning tools, and dedicated recovery networks. But the cost of prolonged downtime and reinfection is far greater.

 

Next steps:
  1. Assess how long each step would take in your current environment.
  2. Identify your biggest gap.
  3. Calculate the cost of extended downtime vs. infrastructure investment.
  4. Start with your most critical business services.

The era of “backup and pray” is over. Organizations that master these five steps don’t just recover faster – they recover once, cleanly, and with confidence.

 

Learn More

Watch as I discuss this new metric in the webinar, The Missing Metric for Cyber Recovery Success.

Read the full whitepaper, Redefining Cyber Recovery: Introducing Mean Time to Clean Recovery, for more about this critical metric.

Darren Thomson is a Field CTO at Commvault. Be sure to catch him in the podcast series, STRIVE.

More related posts


CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

The fifth edition of the State of Data Readiness in ANZ report, a Tech Research Asia Insights Report commissioned by Commvault, offers a critical look into the current landscape of data management, cybersecurity, and regulatory pressures faced by organisations in Australia and New Zealand (ANZ).

Based on research from 408 companies across the region, the report uncovers key trends and stark realities about how businesses are coping with an increasingly complex digital environment. Given we often look at research findings on a global scale, it is particularly valuable to have a local perspective on data readiness.

While data growth rates have seen a slight easing, the challenges surrounding data management, security, and recovery have intensified. Here are some of the standout insights from the report.

The Data and Regulatory Environment: A Tangled Web

Organisations are grappling with sprawling data estates and a tightening web of regulations.

  • Slowing growth, persistent sprawl: The annual data growth rate in ANZ has marginally slowed from 28% last year to 27% this year. A majority, 62%, continue to operate in blended (multi- or hybrid cloud) data environments, and this is projected to increase to 71% by 2026.
  • Confidence gap: A concerning number of organisations lack confidence in their ability to restore business operations after a breach, with 54% of Australian and 63% of New Zealand businesses feeling unprepared.
  • Regulatory complexity: The regulatory landscape is becoming more difficult to navigate. Fifty-five percent of Australian and 53% of New Zealand companies are now required to maintain data copies in separate cloud environments for resiliency. Furthermore, more than a third of organisations face conflicting data regulations across different geographies.
  • The rise of AI regulation: AI-specific compliance is a growing concern, with 28% of companies already subject to such regulations and another 40% expecting to be within the next year.

The AI Paradox: High Adoption Despite High Risk

Enthusiasm for AI is strong, yet it’s coupled with significant security concerns.

  • Risk vs. reward: While 73% of ANZ organisations are using business-focused AI solutions, 68% of them believe this adoption increases the likelihood of a cybersecurity breach.
  • Lack of due diligence: A significant 63% of organisations admitted to not conducting thorough and extensive security audits of their AI tools before deployment.
  • Policy deficit: Only 29% of companies have comprehensive policies in place to protect the data and content generated by AI solutions.

Recovery: A Disconnect Between Expectation and Reality

The gap between business leaders’ recovery expectations and the on-the-ground reality for IT teams remains a major issue.

  • The expectation-reality gap: Eighty percent of business leaders expect to recover from a cybersecurity incident within five days. However, the stark reality is that it takes an average of four weeks to restore a minimal level of business operation.
  • Ransomware’s reach: Seventy percent of ANZ organisations have received a ransomware demand, and of those, 20% admitted to paying it. Interestingly, of the companies with a stated “no payment” policy, 15% still ended up paying the ransom when faced with an actual attack.
  • The power of experience: The report reveals a fascinating insight: Experience is a harsh but effective teacher. Companies that have been breached are 1.5 times more likely to conduct thorough reviews of AI tools and twice as likely to test all mission-critical workloads as part of their incident response plans. Conversely, companies that have not been attacked are 1.5 times more likely to believe they can recover within a single day.

The 2025 State of Data Readiness report underscores a challenging environment for ANZ organisations. From regulatory hurdles to the double-edged sword of AI and the persistent disconnect in recovery expectations, the path to true cyber resilience is complex.

To gain a deeper understanding of these findings, download the full report.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

I’m thrilled to share that we were just announced as a winner in Udemy’s 2025 Learning Excellence Awards in the Leading With Learning Science category. In this awards program, Udemy recognized organizations that have successfully achieved impactful results in learning and development through AI-supported upskilling.

As one of the winners in the Leading With Learning Science category, Commvault was recognized for prioritizing the integration of learning into the workflow, engaging learners through micro-learning, and crafting personalized learning experiences.

We are honored to be included on a list of visionary leaders that are transforming learning at scale and equipping their employees to thrive in an AI-forward future.

The Investment in our People Matters

Over the past year, we’ve expanded on our investment in learning and development by implementing an all-new, comprehensive learning platform, Pathfinder, to provide our Vaulters with the tools, resources, and opportunities they need to enhance their skills and advance their careers.

Our new platform has a wealth of learning modules, ranging from live instructor led sessions to on-demand and self-paced learning modules, including Udemy Business’ 30,000+ expert-led courses covering topics across technology, business, leadership, productivity, cybersecurity, and GenAI. Udemy Business isn’t just another online training tool – it’s a strategic driver of capability building within Commvault, and we’re delighted to offer our global Vaulter community access to Udemy Business.

We’ve also developed curated learning paths tailored for our teams, with a focus on the power of AI. The development of our Vaulters is key to Commvault’s success, and with Udemy Business, we’re giving them the tools to build their future growth, all while harnessing the potential of AI.

To learn more about what it’s like to work at Commvault, click here.

 

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The global shift toward cloud-native architectures has redefined what it means to achieve security and resilience. Cloud environments are dynamic by design; resources are frequently updated, added, or removed; applications stretch across regions and multi-clouds; and infrastructure evolves faster than most recovery tools can track. Traditional backup models, built for static systems, struggle to keep up with this pace and complexity.

Commvault Cloud Rewind™ is built from the ground up to handle this new reality. With an architecture purpose-built for cloud-scale recovery, Cloud Rewind helps you restore entire cloud environments, including applications and their dependencies, with ease.

This becomes essential in modern environments where applications are composed of microservices, containers, and serverless components that are often ephemeral and spread across multiple platforms.

Resources may change daily, and ownership is often decentralized across teams. Configuration drift, inconsistent change management, and the growing use of third-party services all make recovery harder. Even when manual backups are available, critical infrastructure metadata is often missing, making restorations unreliable or incomplete.

In this ecosystem, Cloud Rewind brings order to the chaos. By leveraging ongoing discovery, orchestration, and cloud-native operations, it provides fast and consistent recoverability. Whether you’re dealing with a simple misconfiguration or a full-blown cyberattack, Cloud Rewind helps restore critical resources in minutes.

A Deep Dive Into the Design: The Cloud Rewind Architecture 

At the heart of Cloud Rewind are key architectural principles that prioritize automation, scalability, and recovery precision. From that foundation, it allows an integrated approach to help discover, protect, recover, and rebuild applications and data within cloud environments.

Cloud Rewind brings together powerful capabilities to strengthen cyber resilience and simplify recovery across cloud environments. Each feature plays an integral role in improving confidence in day-to-day operations and crisis response.

  • Cloud discovery and dependency mapping: Cloud Rewind automatically discovers all relevant cloud resources and captures the metadata needed for accurate and repeatable recovery. This includes complete configuration settings, dependencies, and infrastructure details.
  • Drift analysis: Cloud environments change rapidly. Cloud Rewind tracks these changes with regular drift analysis, comparing current configurations to known protected states. This keeps security teams informed about any deviations from expected configurations, helping maintain crucial alignment.
  • Automated daily cloud rebuilds: Reverting to a safe state is not enough; it has to be done quickly and without errors. Cloud Rewind helps enable this with automated recovery testing. You can rebuild entire cloud infrastructures, applications, and data using on-demand environments. These temporary environments can later be deleted to help reduce testing costs.
  • Integrated cyber recovery: Cloud Rewind works with Commvault’s broader data resilience platform, effectively combining backup, recovery, and threat intelligence. This unified approach provides better control and coordination during security incidents, helping teams move from detection to full recovery with speed and clarity.

Conquering the Competition: Where Cloud Rewind Stands Out

With a plethora of advanced features tailored for modern cloud-based organizations, Cloud Rewind provides effective and simplified recovery. While several industry solutions offer simple disaster recovery for cloud workloads, these capabilities help Cloud Rewind stand apart.

Cloud Rewind takes recovery resilience to the next level with:

  • Broad multi-cloud coverage, with native support for AWS, Azure, and GCP.
  • Full-stack resource coverage, including compute, storage, networking, IAM, DNS, containers, and serverless services.
  • Detailed infrastructure metadata protection, using a dual-vault time machine.
  • Explicit application dependency graphs, not just resource-level awareness.
  • Recovery-as-Code, for orchestrated, code-driven recovery.
  • Continuous validation, using regular automated rebuilds in isolated cloud spaces.
  • Low operational burden, with high transparency through a SaaS delivery model.

Cloud Rewind combines protection, intelligence, and automation to support fast and reliable recovery across complex cloud environments. This helps Cloud Rewind stand out in a competitive field and stay ahead.

Cloud Resilience for Complete Cloud Workload Recovery

Commvault Cloud Rewind is built for full-stack cloud resilience, offering protection for modern, cloud-native workloads. Instead of simply backing up isolated resources, capturing and recovering entire cloud applications, referred to as Cloud Assemblies.

Cloud Rewind supports a wide range of cloud-native services, including virtual machines, disks, gateways, security groups, VPCs, DBaaS platforms, and containerized workloads. Once a cloud connection is established, Cloud Rewind performs automated identification of all resources in an environment. At scale, this can be highly significant. For one Commvault customer, 94,237 resources were discovered, with 7,811 protected resources organized into 19 distinct assemblies.

For complete protection, customers can begin with the definition of policies tailored to their Cloud Assemblies. These policies govern snapshot frequency, retention rules, and replication preferences. Snapshots can be taken as frequently as every 15 minutes or as infrequently as annually, depending on the workload’s recovery objectives. These snapshots can be used for rapid, point-in-time backups and fast rehydration.

With its sophisticated use of only cloud snapshots, Cloud Rewind offers protection at a fraction of the cost of expensive traditional high-availability or read‑replica architectures. As dedicated standby infrastructure isn’t required, customers pay only for snapshot storage and temporary compute during recovery operations. This flexibility allows customers to effectively fine-tune protection schedules to balance RPO requirements against storage costs.

Finally, Cloud Rewind provides cloud data resilience by performing recovery at the Cloud Assembly level. When it’s time to restore, Cloud Rewind can recreate the complete application, including the resource configurations, network settings, and dependencies, exactly as it existed at any point in time. Recovery also can target the original region for a quick rollback or be redirected to a different region, subscription, or project to support disaster recovery use cases.

By centering recovery around customer applications, Cloud Rewind replaces traditional complexity with invaluable clarity. With automated discovery, flexible policies, and cost‑effective snapshot-based protection, Cloud Rewind can help customers meet stringent recovery objectives while minimizing infrastructure overhead.

A New Era of Resilience: Key Advantages of Cloud Rewind

Cloud Rewind introduces a new standard for resilience in the cloud, shifting away from legacy disaster recovery models toward an approach designed for dynamic, modern environments. By focusing on full application recovery instead of isolated resources, it helps avoid downtime, reduce operational risks, and support rapid, coordinated recovery and restoration across cloud platforms.

One of its core innovations is the patented dual-vault cloud time machine. This unique approach protects  immutable vaults in different hyperscale clouds for rapid application recoveries. This design not only defends against failures and cyber threats but also enables precise, point-in-time recovery of entire application environments.

With a myriad of powerful capabilities that support the growth of modern businesses, Cloud Rewind makes an impact:

  • Financial service entities leverage Cloud Rewind to help you meet stringent regulatory requirements while minimizing downtime for real-time financial systems.
  • Healthcare organizations use Cloud Rewind to help you rapidly recover electronic health records and other critical applications during cyber incidents, preventing the disruption of patient care.
  • In the education sector, Cloud Rewind provides a safety net, enabling protection against the loss of courseware, student data, and other resources.
  • Retail and manufacturing businesses leverage Cloud Rewind to quickly recover from outages or cyberattacks, leading to minimization of revenue loss and continuation of production schedules.
  • Technology and SaaS providers use Cloud Rewind to help you protect cloud-native platforms and deliver continuous service to customers.

Across sectors, Cloud Rewind is delivering measurable results. So, prominent real-world cases of organizations benefitting from this innovative solution have promptly emerged.

The Boston-based EdTech company Pragya Systems’ SaaS resiliency increased by a staggering 300% with Cloud Rewind. Similarly, backed by the powerful capabilities of Cloud Rewind, an eDiscovery leader recovered from a major ransomware attack.

Looking at the financial services sector, a top mortgage lending entity decreased cloud application resilience cost by 85% with Cloud Rewind. Finally, leveraging Cloud Rewinds’ app-centric BCDR approach, a global cloud solutions provider achieved a 99.9% cloud app resilience SLA.

Cloud Recovery Like Never Before

Commvault Cloud Rewind represents a turning point in the way organizations approach resilience. Instead of relying on fragmented tools or rigid recovery processes, Cloud Rewind provides a cloud-native architecture that keeps pace with change. With deep automation, application-centric recovery, and proven results across industries, it empowers organizations to protect what matters, recover faster, and operate with confidence.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Most enterprise documentation websites that have code blocks use styles that signal placeholders. The intent is supposed to be clear, and readers are supposed to know what they need to change, but the experience falls short.

These same styles are also used for emphasis, UI labels, or syntax elsewhere in the documentation. Common placeholder technical writing teams use to identify code blocks, which are used as other styles, include:

  • Italics
  • {Braces}
  • Bold
  • example_name_##
  • ALL_CAPS
  • Some combination of the above
  • Something completely different

This overlap makes placeholder tracking and management more complex than it should be. On a small scale, this can feel like a nuisance. But as documentation libraries grow and spread across teams and years, it creates problems for both authors and readers. What is meant to simplify placeholder management instead complicates it, because the same styling is reused elsewhere.

The result can put you in a familiar position: You must figure out the placeholder convention and attempt to update them all if you want to succeed. If you miss one placeholder, the command may not work as expected. Other issues can appear, such as errors, unexpected configurations, or even settings you didn’t know could be changed.

Other code block approaches only go so far:

  • Static blocks (with or without syntax highlighting) are essential when you already know the values. They are fast and copy-to-run ready. These are best when you don’t need to modify anything.
  • Inline editors go to the other extreme and enable you to update text directly within the code block, but often at the expense of context – undo becomes unreliable and small mistakes erase the structure you need.
  • Developer API editors let you try out requests in real time, and they’re a great fit when the main audience is developers working directly with APIs. But enterprise documentation serves broader roles and use cases, and that style of interactivity is often missing where it would still add value.

Closing the Gap With Interactive Code Blocks

Our interactive code blocks close this gap by turning a historically fragile part of documentation (the placeholder) into something clear, editable, and scalable.

You get the same command as before with the same formatting and structure, only now the placeholders have become editable fields. Each one has a clear label (like before) so you don’t have to interpret symbols or rely on guesswork.

You update the values right inside the block, with the surrounding context still visible. That means you see the example, the rest of the page’s contents, and your inputs all in one place. It can help you shape a more relevant snippet before you click Copy.

You can change those values before copying them or leave them as-is and edit them later in another editor. Either way, the structure stays the same and what you copy reflects exactly what you see in the block.

Placeholders in a code block that have the same name become linked. When you change the value of a placeholder field above the code block, all linked fields can update at the same time so that you can more consistently edit fields that have the same placeholder value. This helps reduce potential find and replace mistakes when working in a text editor.

The Experience Shift

This shift solves two problems at once. For readers, it reduces guesswork and prevents errors. No more deciphering braces or angle brackets. For writers, it separates semantics from styling, allowing placeholders to be tracked, audited, and updated programmatically. That unlocks version awareness, validation rules, and consistency across environments. Legacy inconsistencies are corrected along the way, making the overall library easier to maintain.

Interactive code blocks turn one of the hardest parts of documentation, style-based placeholders, into something precise, maintainable, and fast to use. The experience feels intentional instead of improvised. And for the first time, managing code examples at scale creates opportunities for improvement instead of obstacles.

Live Now in Software, SaaS, and More

This experience is already live across our documentation site for Software (versions 11.42, 11.40, 11.36, and 11.32), SaaS, and other related sites on https://documentation.commvault.com/.

Try it out the next time you browse and run across a code block – edit a few fields, click “Copy,” and see how much easier it is to get started after you bring it into your editor.

Notes:
  • Carefully review any code before you run it, whether it’s from an interactive or static code block.
  • When you refresh a page after changing placeholders in an interactive code block, all changed placeholders revert to their default values.

Learn more about using code blocks here.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In the race to deploy AI, organizations are investing heavily in securing traditional infrastructure. Cybersecurity teams are implementing advanced threat detection for endpoints and deploying zero-trust architectures for cloud environments. However, many are giving less attention to a critical component of modern AI systems: the orchestration layer that connects AI models to data sources and business applications.

This middle layer includes the infrastructure that makes AI functional in enterprise environments: vector databases that store embeddings, model repositories, data pipelines that process AI workloads, agent coordination frameworks, and orchestration platforms like the Model Context Protocol (MCP). Unlike traditional enterprise applications, many of these systems lack established security frameworks and best practices.

The Emerging Challenge: AI Infrastructure Security Gaps

Traditional security models were designed for databases, web servers, and file systems with well-understood attack vectors. AI infrastructure introduces new components that don’t always fit neatly into existing security frameworks. Vector databases store high-dimensional embeddings, model registries house trained algorithms, and orchestration platforms coordinate between AI agents and external systems.

Take MCP as an example. While MCP itself incorporates security considerations, the broader ecosystem of AI orchestration frameworks often operates with different security assumptions than traditional enterprise applications.

Research from organizations like NIST has highlighted that AI systems frequently require elevated privileges to access diverse data sources, communicate across network boundaries for model inference, and integrate with legacy systems not designed for AI workloads.

This creates an expanded attack surface. According to recent security research, compromise of AI orchestration layers can enable attackers to manipulate model outputs, corrupt training processes, or gain access to the valuable datasets and custom models that represent significant organizational investment.

Data Consolidation Creates New Risk Concentrations

AI adoption has accelerated data centralization initiatives across industries. Organizations are aggregating diverse datasets into centralized repositories to enable machine learning workflows. While platforms like Databricks and Snowflake have built robust security features, the challenge lies in the volume and variety of data being consolidated.

These repositories often contain some of the most sensitive organizational data: customer behavioral patterns, proprietary research datasets, financial transaction records, and competitive intelligence. The security challenge isn’t necessarily inadequate access controls, but rather the concentration of high-value data in systems optimized for analytics rather than security.

A particular concern is training data integrity. Security researchers have demonstrated that subtle corruption of training datasets can introduce persistent vulnerabilities into AI models. For instance, researchers at universities have shown how poisoned datasets can cause fraud detection models to systematically miss specific attack patterns, or cause recommendation systems to exhibit subtle biases that may not be detected for months.

Real-world examples include:

The scale of modern AI training datasets compounds these risks. When organizations process petabytes of training data, traditional point-in-time security measures like comprehensive encryption key management and detailed access logging become operationally complex. Organizations need security approaches designed for the scale and velocity of AI data processing.

AI Models as High-Value Assets Require Specialized Protection

Trained AI models represent significant organizational investment – often millions of dollars in development costs and months of training time using expensive computational resources. More importantly, they embody institutional knowledge and competitive advantages developed over years.

However, many organizations apply traditional data security approaches to AI models without accounting for their unique characteristics. Unlike conventional intellectual property, AI models face specific threat vectors:

Model extraction attacks: Researchers have demonstrated techniques where attackers can query a model repeatedly to reverse-engineer its functionality or training data. Google’s research team has published studies showing how this can be accomplished against various types of production models.

Adversarial attacks: These cause models to make specific mistakes or reveal information about their training data. The field of adversarial machine learning has documented numerous examples across different model types and use cases.

Model stealing: Beyond intellectual property theft, stolen models can reveal insights about business processes, customer patterns, and strategic approaches. For example, a compromised fraud detection model provides information about an organization’s risk assessment methodologies and customer transaction patterns.

Documented cases include:

  • Research showing extraction attacks against commercial APIs from major cloud providers.
  • Studies demonstrating how recommendation model theft reveals user behavior patterns.

Organizations are beginning to implement specialized AI model security measures, including model versioning systems that detect unauthorized modifications, secure serving architectures that limit model exposure, and incident response procedures designed specifically for AI compromise scenarios.

Building Appropriate Security for AI Infrastructure

The AI infrastructure security challenge represents a shift in enterprise security priorities. Traditional perimeter and endpoint security remains important, but organizations must also secure systems where valuable assets exist as algorithms, autonomous processes operate with elevated privileges, and training procedures consume massive computational resources across distributed systems.

Leading organizations are developing AI-specific security frameworks that address these unique characteristics. This includes implementing data lineage tracking for AI training pipelines, establishing secure model development and deployment processes, and creating monitoring systems designed to detect AI-specific attack patterns.

The security community is actively developing solutions for these challenges. Organizations like NIST are publishing AI security frameworks, cloud providers are adding AI-specific security features to their platforms, and security vendors are developing tools designed for AI infrastructure protection.

The path forward involves:

  • Implementing security controls designed for AI-specific risks and attack vectors
  • Developing incident response procedures that account for AI system characteristics
  • Creating monitoring and detection capabilities for AI-specific threats
  • Establishing governance frameworks for AI data and model management

Organizations that proactively address AI infrastructure security will be better positioned to realize AI benefits while managing associated risks. As AI systems become more central to business operations, security strategies must evolve to protect these new assets and processes effectively.

Register now for our virtual SHIFT event to learn more about our product innovations and resilience strategies for your organization.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

How do you take 40 minutes of viewpoints from a panel of leading experts and condense it into a 5-minute read designed to provide you with actionable advice you can immediately use? That’s the challenge I posed to myself as I prepared to write this blog, so let me know if I delivered.

The panel: Nathan McAfee, Lead Economic Validation Analyst at Enterprise Strategy Group; Jaimie Fox, Azure Technology Strategist at Microsoft; and Chris DiRado, Principal Technologist at Commvault.

Their goal: Unpack the key findings from this crucial research (Enterprise Strategy Group Economic Validation), providing a clear-eyed view of how organizations can prepare for, and recover from, the inevitable.

The High Stakes of Slow Recovery

A cyberattack’s impact isn’t just about the initial breach; it’s the prolonged downtime that cripples operations, erodes customer trust, and racks up exorbitant costs. As Nathan explained, the study aimed to quantify the real-world difference a modern, integrated recovery solution could make.

The findings highlight a stark contrast between traditional approaches and a prepared strategy. Without an effective plan, organizations face extended outages; significant data loss; long-lasting brand damage; and a painful, manual recovery process that can take weeks or even months.

The Solution: A Unified Defense with Commvault and Azure

The study focuses on the economic benefits of the joint solution from Commvault and Microsoft Azure. This isn’t just about backup; it’s about a holistic cyber resilience platform. Jaimie emphasized the power of the integration, which provides a secure, scalable, and intelligent foundation for data protection: “The power of the Commvault solution is in the simplicity and the thoroughness. How easy it is to do these recoveries … and in the automation of the rebuild process using Azure AI and on-demand Azure tenants.”

Breakthrough Findings: Customer Reported Results

The study provided hard numbers to back up the solution’s value. Organizations using the joint Commvault and Azure solution achieve:

  • 99% faster recovery: The most dramatic finding: where organizations previously required 8.7 hours on average (with some taking 24 days for full recovery), the joint solution between Commvault and Azure enabled one customer recovery in under an hour. Nathan noted: “The 99% faster recovery – I could put decimals on that because we had so many stories of scenarios that took months to do, and now we did it in hours.”
  • 30x more frequent testing: Organizations moved from annual tests of single systems requiring 40 FTE hours, to comprehensive monthly testing of entire ecosystems completed in 30 minutes. One customer shared: “It used to take 24 to 36 hours to recover a single server instance. We can now restore everything in less than an hour.”
  • Zero reported non-recoverable events: Every customer interviewed reported zero non-recoverable events since implementing the solution. “Every person that I interviewed told me that since they’ve gone to this solution, they haven’t had a single non-recoverable event,” Nathan emphasized.
  • 94% faster rebuild: The study documented 94% faster rebuild times through Cloud Rewind technology, enabling rapid restoration of entire application environments and infrastructure.
  • Dramatic cost reduction: Average testing costs dropped from $141,864 annually to under $11,000, even while testing frequency increased to daily in some cases.

The Mindset Transformation: From Hope to Certainty

The most powerful insight from the research wasn’t about technology – it was about mindset. Nathan repeatedly emphasized organizations moving from hoping their recovery plans would work to knowing they will.

“We were comparing hope vs. certainty,” he explained. “Certainty is a word you hear me say a lot because that really came out in the customer stories.”

As one global infrastructure director put it: “I wake up every day, check my Cleanroom Recovery report about the previous night’s restore, and know we are protected and can recover. We have eliminated downtime by always being able to recover from cyber events.”

The certainty shines through in being able to test recoverability of more than just one component. Nathan shared, “I went into this thinking about data recovery without thinking about ecosystem recovery. They’re now testing the recoverability of their entire ecosystem.”

Study participants also discussed testing in true chaotic environments. “So much of testing is done in a very calm environment. While any type of true restore is done in a chaotic environment. I heard quite a few stories about how Commvault specifically helped simulate the chaotic environment. So, in the time when it did happen, it wasn’t the first time you went through a high stress recovery,” Nathan shared.

Bonus Insights: AI Acceleration Through Confidence

Nathan shared additional findings from the research that are not called out in the report, including how organizations feel confident to accelerate their AI initiatives because they know they’re protected.

“AI comes with rapid change,” he explained, adding that the customers he interviewed “called out the assurance that no matter what happens, I can get to my minimum viable company somewhat quickly. It gave organizations more confidence in going through the rapid change that AI is injecting into their company.”

This confidence proves critical as organizations grapple with AI governance challenges. Jaimie highlighted: “One of the biggest concerns that most of my customers have with implementing AI now is how are we going to keep it safe, from an ethical standpoint, as well as from outages and a business continuity standpoint. With Commvault integrated with the Microsoft solution, the most complex and extremely large AI workloads are resilient and recoverable. Customers now have the confidence that their data is protected and recoverable with the resilience they need.”

Begin Your Transformation Today

The transformation from hope to certainty in cyber recovery isn’t just possible – it’s happening right now. The only question is: When will your organization make the leap?  Download the complete ESG Economic Validation report and watch the webinar, Cracking the Code: Recover 99% Faster from Cyber Attacks, to hear from our expert panel. Use these as your blueprint to begin your organization’s transformation.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The modern, tech-dependent businesses of today may not run entirely on Windows – but nearly every organization relies on it somewhere. Whether through business applications, identity management, or the countless tools that keep operations moving, Windows remains a critical touchpoint across industries.

This widespread adoption brings with it a unique challenge: It makes Windows solutions the natural target for cyberattackers. The more common the technology, the more determined adversaries are to find vulnerabilities. Especially in an era where cyberattacks are growing in complexity and sophistication, this poses a monumental threat to digital businesses.

In an earlier blog, we explored the need to move from reactive to proactive defense. We know that visibility and speed are integral in recovery outcomes. Now, with Threatwise v8.2, we are taking the next step.

By introducing preconfigured threat sensors for Windows Server 2022 and 2025, this release builds on the foundation we have laid. It helps you restore faster by easily understanding the blast radius and gives IT teams a stronger early warning system to keep attacks from spreading.

Deception Technology: What Is It, and Why Does It Matter?

Commvault Threatwise leverages cyber deception technology to help redirect attacks and uncover threats. Deception technology plants digital lookalikes across your environment. These decoys mirror true company assets and network activity, yet they serve a very different purpose: to lure attackers into revealing themselves.

Threatwise extends this approach with decoys that are quick to deploy and simple to scale. These lookalikes trick criminals into believing they have gained access to an enterprise’s most critical systems, when in reality, they have pulled the virtual fire alarm.

While invisible to everyday users, the moment a bad actor interacts with a sensor, security teams receive a high-fidelity signal of compromise. Such early alerts help defenders prepare a response before damage escalates.

With v8.2, organizations gain access to preconfigured sensor templates for the latest Windows Server editions. This allows you to help protect your system with faster setups, broader coverage, and greater resilience.

Minimizing the Blast Radius

Every cyberattack carries a blast radius. When it comes to cybersecurity, the blast radius refers to the potential spread and impact of a single security breach or system failure.

For backup administrators, the blast radius translates into the scale of data corruption, downtime, and recovery complexity. The larger the impact, the longer and more expensive the recovery. What’s more, beyond the operational disruption and economic losses, these attacks also can damage company reputation and trust, potentially undoing years of dedicated service.

In our proactive detection series, we discussed how reducing the blast radius requires early detection, rapid isolation, and clean recovery environments. Deception technology aligns with this model. Triggering alerts early in the attack lifecycle can help defenders contain an attack before it cascades across production systems. This early visibility can give responders the needed head start, providing valuable time to preserve clean data and maintain operational continuity.

Overcoming Adversities: Why Backup Administrators Need Threatwise

In our highly competitive business ecosystem where speed is non-negotiable, backup administrators face a unique set of challenges. Recovery windows are shrinking, applications with exponentially larger data sets, and more and more complex infrastructure, often spanning across hybrid or multi-cloud environments.

In this environment, Commvault’s deception technology can help data administrators thrive in the face of adversity in several ways:

  • The How: Preconfigured decoys mimic application hosts, allowing admins to quickly create lookalikes and multiply them across blanked instances. With Threatwise v8.2, sensor templates for Windows Server 2022 and 2025 deliver coverage for the latest systems.
  • The What: Based on organizational SLAs, Threatwise can highlight which systems to prioritize and help to keep critical company crown jewels safeguarded.
  • The Why: Early high-fidelity signals can reduce uncertainty during an incident with critical threat insights. Backup admins can pinpoint infected applications that require restoration. Further, they can effectively prepare cleanroom environments to validate restore data and processes.

These capabilities help give admins clarity and confidence, even in the high-pressure moments of a recovery emergency.

Stronger Together: IT and Security Collaboration and Synergy

Threatwise gives businesses the tools to help protect their assets against modern cyber threats and ransomware. However, detection is only as effective as the response that follows.

Threatwise, as part of Commvault Cloud, integrates with leading SIEM and SOC solutions, allowing alerts to flow across IT and security operations. This collaboration helps enable faster coordination, cross-functional communication, shared organizational awareness, and a unified incidence response plan.

Furthermore, the true opportunity lies in how backup operations can shape the broader security strategy by embracing the role of the innovator. By taking on this role and aligning with the security team, backup admins help move the needle from reactive defense toward proactive resilience. Routine testing of response runbooks and recovery initiatives reinforces this synergy and builds confidence regarding the power of a proactive approach.

What This Means for the Future of Cyber Resilience

Threatwise v8.2 helps make deception technology simpler to deploy and more effective against ever-evolving threats. By extending coverage to the latest Windows Server editions, it helps organizations stay a step ahead of attackers who seek to exploit vulnerabilities of the most widely used enterprise systems.

Early warning signals are not a luxury for a cyber resilient organization; they are vital for building business continuity by creating rapid recovery options. With deception in place, powered by Threatwise, organizations can face tomorrow’s threats with confidence.

Learn more about Threatwise here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

AI and analytics are driving competitive advantage across every industry. At the heart of this transformation are data lakehouses built on Apache Iceberg, now one of the fastest-growing standards for structured data on object storage such as Amazon S3. From retail and healthcare to finance and tech, Iceberg is powering the pipelines that fuel AI-driven insights.

But while adoption is surging, resilience has not kept pace. Native Iceberg tools weren’t built for long-term protection. They fall short when it comes to compliance, ransomware resilience, and rapid recovery. For businesses, that gap means more than data loss – it can result in regulatory fines, flawed AI models, and costly downtime that undermines innovation.

When Native Tools Fail: A Financial Firm’s Story

Consider a global financial services firm processing billions of trades every day. Every few minutes, trades are written into Iceberg tables. Regulations require this firm to keep a full history of transactions for seven-plus years.

With native Iceberg snapshots, this can quickly become unmanageable. Too many snapshots can create performance bottlenecks, and recovering to an event from just five months ago requires a slow, manual process. In finance, where downtime equals millions of dollars in losses, that’s simply unreasonable.

And the challenge isn’t limited to finance. Any industry running AI and analytics on Iceberg may face the same risks: limited retention, fragile recovery, and exposure to ransomware.

Why Generic S3 Backups Aren’t Enough

Some organizations turn to standard S3 backup tools as a workaround. While these can be air-gapped, they copy data files but don’t preserve the relationships that define an Iceberg table.

That means recovery isn’t a simple restore – it’s a complex, manual “rewiring” process to rebuild the entire table structure. For a financial firm with billions of trades, that translates into extended downtime, higher costs, and potential data loss.

Clumio can eliminate this problem by natively understanding Iceberg, enabling recovery that is fast, accurate, and transactionally consistent.

A Smart Path Forward: Clumio for Apache Iceberg

Commvault is closing this gap with the industry’s first and only solution to deliver Iceberg-aware, air-gapped cyber resilience: Clumio for Apache Iceberg on AWS.

Here’s what makes it different:

  • Unlimited retention without performance hits – adhere to long-term compliance requirements without slowing down production environments.
  • Air-gapped, immutable protection – designed to defend against ransomware, account compromise, and accidental deletions.
  • Fast, Iceberg-aware recovery – ability to restore to any point in time or named snapshot with full table integrity.
  • Cross-region and cross-account recovery – extend resilience across AWS environments for verifiable disaster recovery.
  • Cost-efficient, incremental backups – enables capturing only changes to minimize costs while scaling with massive workloads.

Read the announcement in our press release for more details.

Native Snapshots vs. Generic S3 Backups vs. Clumio for Apache Iceberg

Capability Native Iceberg Snapshots Generic S3 Backups Clumio for Apache Iceberg
Retention Limited, may cause performance bottlenecks with excessive snapshots Long-term possible, but only at file level Unlimited, cost-effective, and built for compliance
Air-gapped protection ✘ Lives in same AWS account (lost if table deleted) ✓Can be air-gapped, but not Iceberg-aware ✓Air-gapped, immutable vault for ransomware resilience
Recovery process Manual, especially for older snapshots Manual “rewiring” of table metadata and manifests Fast, automated, Iceberg-aware recovery
Data integrity Transactionally consistent, but governance and compliance liability No understanding of Iceberg metadata; inconsistent restores Transactionally consistent, full fidelity restores
Enterprise scale Impractical for long-term retention; high storage costs Brittle and error-prone at large scale Proven at petabyte scale with billions of objects

 

Why It Matters for Your Business

Clumio doesn’t just protect files – it can safeguard your AI and analytics investments so they can deliver results. This new capability helps enterprises:

  • Accelerate AI innovation with confidence by protecting the data fueling critical pipelines.
  • Avoid compliance penalties with unlimited, cost-effective snapshot retention.
  • Recover in minutes, not days, thanks to Iceberg-aware automation that is designed to eliminate brittle, manual processes.
  • Strengthen cyber resilience with actual air-gapped protection against ransomware and insider threats.

Building Resilience into the Future

As data lakehouses become the backbone of digital business, resilience shouldn’t be an afterthought. With Clumio for Apache Iceberg on AWS, enterprises finally have a solution that matches the scale, speed, and criticality of their AI and analytics workloads.

Because in the end, it’s not just about protecting data. It’s about protecting your business.

Learn how to protect Iceberg tables managed by AWS Glue and Amazon S3 Tables with Iceberg-aware resilience.

Interested in learning more? Request a demo, and sign-up for a free trial in AWS Marketplace today.

 

 

 

More related posts


Clumio

Read more about Clumio

Ransomware attacks have become inevitable in today’s threat landscape, emerging as a major concern for all businesses. In fact, ransomware incidents have surged dramatically in the first half of 2025, resulting in a 49% increase compared to the same period in 2024.

Now, as organizations face even more sophisticated threats designed to encrypt data, paralyze operations, and exploit recovery processes, these numbers show no signs of slowing down.

The stakes are rising, and it’s increasingly evident that when disaster strikes, simply having backup isn’t enough. Organizations can’t adopt a reactive security posture and hope to function successfully. You need immutable data, intelligent detection of threats, clean recovery and testing of recovery plans, and 24/7 protection.

Commvault delivers a deeply integrated, multi-layered ransomware defense framework that prioritizes security, speed, and confidence. By combining state-of-the-art threat detection, isolation, and recovery mechanisms with partner intelligence, Commvault helps enable cyber resilience.

This article explores four components of Commvault’s ransomware defense strategy: data immutability, real-time threat scanning, validated recovery, and intelligent recovery automation. Together, these capabilities form a complete and dependable response to one of the most persistent challenges plaguing modern IT teams.

Data Immutability: The First Line of Defense

Data immutability is integral to any successful ransomware defense strategy. In a world where ransomware increasingly targets not just production systems but backup infrastructure itself, immutability is a critical safeguard. Commvault leverages data immutability with an array of capabilities designed to help keep your data tamper-proof. This is achieved through immutable storage, layered access controls, and enforced authorization protocols.

Here’s a closer look at Commvault’s data immutability capabilities:

  • Immutable storage: Commvault implements a multi-layered approach to immutability. It combines its own software-level controls with hardware-enforced and cloud-based WORM (write-once, read-many) technologies. Retention Lock (formerly WORM Copy) prevents premature deletion or aging of backups, even by administrators, and protects against actions like removing storage policies or deleting storage libraries. This is a significant form of defense against rogue administrators or malicious attackers.
    Similarly, for hardware-enforced immutability, Commvault integrates with storage platforms that support the industry-standard S3 Object Lock API. S3 Object Lock operates in two primary modes: governance and compliance. While governance mode helps protect against accidental deletions and retains administrative flexibility, it is primarily suited for internal controls. The stricter compliance mode, on the other hand, enforces unbreakable retention periods and is designed to meet stringent regulatory requirements such as SEC Rule 17a-4, FINRA, and HIPAA 12.
    When Commvault writes backup data to an Object Lock–enabled target, such as an AWS S3 bucket or Zadara object store, it sets the Object-Lock-Retain-Until-Date metadata timestamp. Any API call to modify or delete the object before that date is rejected by the storage system, regardless of user permissions. Commvault also adds a default 7-day grace period to the WORM lock retention period configured in the software.
    Finally, on Commvault Grid, Commvault’s scale-out integrated appliance, Commvault delivers immutability end-to-end using Retention Lock, a hardened OS, and an immutable file system. This integrated stack is certified for SEC 17a compliance, making it a powerful all-in-one solution for immutable storage.
  • Commvault AirGap: Air-gapped protection is delivered through a Commvault-managed, logically isolated backup environment that encrypts data, separates it from the production network, and eliminates egress charges. This feature is enabled for Commvault SaaS customers by default, helping data stay protected even if production systems become compromised.
  • Zero-trust enforcement: Commvault applies strict zero-trust principles to backup infrastructure through role-based access control, multi-factor authentication, and privileged access management. These layers limit exposure and enforce least-privilege access, reducing the impact of compromised credentials.
  • Multi-Person Authorization: To prevent malicious or accidental changes to protection policies, Commvault enforces quorum-based approvals for sensitive operations. This helps prevent a single administrator from disabling or deleting protected data without oversight.

Real-Time Threat Intelligence: Proactive Detection and Containment

Commvault’s Threat Scan suite is a cornerstone of its ransomware defense. Malicious files and programs can make their way into backups and stay hidden, waiting for the perfect opportunity to strike. So, Commvault’s real-time threat intelligence is designed to identify threats at every stage: during backup, after backup, and before restore.

Commvault is also the only cyber resilience vendor with built-in deception capabilities such as Threatwise sensors and canary files. These tools can trigger alerts while a threat actor is performing reconnaissance and before ransomware even reaches backup data.

Real-time threat detection is brought to life with these powerful features:

  • Inline, pre-, and post-backup scanning: While Threat Scan is a post-backup activity, Commvault actively monitors for ransomware indicators during inline and pre-backup stages. This includes looking for changes in attributes such as MIME type, backup size, and specific extension growth that mirror ransomware activity.
    With this comprehensive approach, whether data is in transit, newly stored, or being restored, it is continuously inspected for hidden or dormant threats. This allows early detection and helps eliminate blind spots.
  • Signature-based and AI/ML detection: Commvault leverages Avira’s anti-malware SDK, a trusted OEM engine used widely across the industry, to massively enhance its defensive capabilities. This engine includes several detection layers that combine to provide a comprehensive security approach.
    Signature-based scanning compares file hashes against Avira’s vast malware signature database. Updates occur every 24 hours to keep the engine current with emerging threats. This database is automatically updated every 24 hours via a secure connection to Avira’s update servers, providing protection against the latest cataloged threats.
    Similarly, for malware that is not yet in the signature database, the Avira engine uses heuristics to analyze the code structure, behavior, and characteristics of a file. This allows it to identify variants of known malware families and other suspicious code, even without an exact signature match.
    Finally, Machine Learning (MicroVision™), Avira’s local ML model, evaluates a broad set of code attributes and anomalies to identify previously unseen threats. It is especially effective against zero-day malware that lacks a known signature but shows signs of malicious behavior.
  • Entropy and MIME Mismatch Analysis: Commvault uses encryption detection models, consisting of multiple statistical features, to identify encrypted or disguised files. One such feature is entropy, which measures the level of randomness in data at the binary level. High entropy can indicate ransomware encryption, but it is just one of several properties used in Commvault’s encryption detection model.
    In parallel, MIME mismatch detection flags files where the content does not match the expected file type, such as a script disguised as a PDF. These techniques help uncover dormant threats that might otherwise go unnoticed.
  • Anomaly detection: Commvault continuously monitors for behavioral deviations. Unusual spikes in backup volume or changes in data patterns are treated as warning signs. Once these anomalies are encountered, they can be promptly investigated, helping lead to early containment.

Comprehensive Recovery: Isolated, Validated, and Automated

As ransomware grows in complexity and speed, clean recovery is imperative. With ransomware, restoring the wrong version can cause re-infection, operational downtime, or compliance failures. And it can be detrimental to company trust, confidence, and long-term success. Commvault addresses these risks with a set of validated recovery options that not only help restore clean data but also help verify its safety before it ever touches production systems.

Commvault’s Cleanroom Recovery creates a secure, isolated recovery environment for testing and validating backup data before reintroduction. This setup is ideal for running malware scans without risking spread to production. What’s more, cleanrooms are provisioned on-demand in the cloud, avoiding the need for dedicated infrastructure.

Within the cleanroom, Commvault supports a wide range of workloads, including virtual machines, file systems, and Active Directory. This flexibility allows teams to simulate live environments and fully verify operational readiness.

Cleanroom Recovery enhances Commvault’s ransomware defense:

  • Automated recovery workflows: Commvault automates the entire recovery lifecycle, from identifying clean points to final workload restoration. These workflows help reduce manual effort, provide consistency, and help teams meet aggressive recovery objectives.
  • Pave and Repave: For systems compromised at the OS level, Commvault supports pave and repave capabilities. This approach restores machines using clean operating system images, then overlays customer data from backup. It results in a fully rebuilt system free from OS-level malware or tampering.
  • Bad file indexing: During scanning, Commvault marks any infected or suspicious file versions as “bad.” These tags are automatically referenced during recovery, enabling the platform to select clean restore points without manual review.

Auto Recovery and Operational Intelligence: Fast, Orchestrated, and Scalable

Recovering clean may be the most essential aspect, but recovering fast is also a priority. Commvault’s auto recovery capabilities allow organizations to restore systems at scale with speed, confidence, and minimal manual effort. These capabilities combine intelligent orchestration, integrated scanning, and real-time visibility to drive recovery resilience.

Here’s a deeper analysis of Commvault’s automated operational intelligence solutions:

  • Auto recovery orchestration: Commvault automatically detects the most recent clean recovery point and initiates restore workflows based on pre-defined policies. These orchestrated processes eliminate guesswork and help reduce the time it takes to bring systems back online after an attack. The full Commvault auto recovery process involves automated steps detailed here.
  • Threat Scan integration: Recovered workloads are scanned as part of the recovery workflow before they return to production. This process enhances the confidence of restored data by helping keep it free from hidden malware or residual threats.
  • Recovery validation reports: Every recovery operation produces a detailed report that outlines scan outcomes, flagged anomalies, and any corrective actions taken. These reports give security teams invaluable visibility into what was recovered and why.
  • Security IQ dashboard: The Security IQ dashboard provides real-time insight into ransomware risk, data exposure, and overall recovery readiness. It helps administrators identify critical weak spots, track improvements, and act on changes as needed.

Ransomware Resilience When It Matters Most

Commvault’s ransomware defense architecture is an intelligent, multi-layered ecosystem. From the moment data is backed up to the second it’s restored, every layer is protected, validated, and recoverable. With a comprehensive design that encompasses every aspect of ransomware defense, Commvault gives your businesses confidence, trust, and resilience.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Ransomware attacks have become inevitable in today’s threat landscape, emerging as a major concern for all businesses. In fact, ransomware incidents have surged dramatically in the first half of 2025, resulting in a 49% increase compared to the same period in 2024.

Now, as organizations face even more sophisticated threats designed to encrypt data, paralyze operations, and exploit recovery processes, these numbers show no signs of slowing down.

The stakes are rising, and it’s increasingly evident that when disaster strikes, simply having backup isn’t enough. Organizations can’t adopt a reactive security posture and hope to function successfully. You need immutable data, intelligent detection of threats, clean recovery and testing of recovery plans, and 24/7 protection.

Commvault delivers a deeply integrated, multi-layered ransomware defense framework that prioritizes security, speed, and confidence. By combining state-of-the-art threat detection, isolation, and recovery mechanisms with partner intelligence, Commvault helps enable cyber resilience.

This article explores four components of Commvault’s ransomware defense strategy: data immutability, real-time threat scanning, validated recovery, and intelligent recovery automation. Together, these capabilities form a complete and dependable response to one of the most persistent challenges plaguing modern IT teams.

Data Immutability: The First Line of Defense

Data immutability is integral to any successful ransomware defense strategy. In a world where ransomware increasingly targets not just production systems but backup infrastructure itself, immutability is a critical safeguard. Commvault leverages data immutability with an array of capabilities designed to help keep your data tamper-proof. This is achieved through immutable storage, layered access controls, and enforced authorization protocols.

Here’s a closer look at Commvault’s data immutability capabilities:

  • Immutable storage: Commvault implements a multi-layered approach to immutability. It combines its own software-level controls with hardware-enforced and cloud-based WORM (write-once, read-many) technologies. Retention Lock (formerly WORM Copy) prevents premature deletion or aging of backups, even by administrators, and protects against actions like removing storage policies or deleting storage libraries. This is a significant form of defense against rogue administrators or malicious attackers.
    Similarly, for hardware-enforced immutability, Commvault integrates with storage platforms that support the industry-standard S3 Object Lock API. S3 Object Lock operates in two primary modes: governance and compliance. While governance mode helps protect against accidental deletions and retains administrative flexibility, it is primarily suited for internal controls. The stricter compliance mode, on the other hand, enforces unbreakable retention periods and is designed to meet stringent regulatory requirements such as SEC Rule 17a-4, FINRA, and HIPAA 12.
    When Commvault writes backup data to an Object Lock–enabled target, such as an AWS S3 bucket or Zadara object store, it sets the Object-Lock-Retain-Until-Date metadata timestamp. Any API call to modify or delete the object before that date is rejected by the storage system, regardless of user permissions. Commvault also adds a default 7-day grace period to the WORM lock retention period configured in the software.
    Finally, on HyperScale X, Commvault’s scale-out integrated appliance, Commvault delivers immutability end-to-end using Retention Lock, a hardened OS, and an immutable file system. This integrated stack is certified for SEC 17a compliance, making it a powerful all-in-one solution for immutable storage.
  • Air Gap Protect: Air-gapped protection is delivered through a Commvault-managed, logically isolated backup environment that encrypts data, separates it from the production network, and eliminates egress charges. This feature is enabled for Commvault SaaS customers by default, helping data stay protected even if production systems become compromised.
  • Zero-trust enforcement: Commvault applies strict zero-trust principles to backup infrastructure through role-based access control, multi-factor authentication, and privileged access management. These layers limit exposure and enforce least-privilege access, reducing the impact of compromised credentials.
  • Multi-Person Authorization: To prevent malicious or accidental changes to protection policies, Commvault enforces quorum-based approvals for sensitive operations. This helps prevent a single administrator from disabling or deleting protected data without oversight.

Real-Time Threat Intelligence: Proactive Detection and Containment

Commvault’s Threat Scan suite is a cornerstone of its ransomware defense. Malicious files and programs can make their way into backups and stay hidden, waiting for the perfect opportunity to strike. So, Commvault’s real-time threat intelligence is designed to identify threats at every stage: during backup, after backup, and before restore.

Commvault is also the only cyber resilience vendor with built-in deception capabilities such as Threatwise sensors and canary files. These tools can trigger alerts while a threat actor is performing reconnaissance and before ransomware even reaches backup data.

Real-time threat detection is brought to life with these powerful features:

  • Inline, pre-, and post-backup scanning: While Threat Scan is a post-backup activity, Commvault actively monitors for ransomware indicators during inline and pre-backup stages. This includes looking for changes in attributes such as MIME type, backup size, and specific extension growth that mirror ransomware activity.
    With this comprehensive approach, whether data is in transit, newly stored, or being restored, it is continuously inspected for hidden or dormant threats. This allows early detection and helps eliminate blind spots.
  • Signature-based and AI/ML detection: Commvault leverages Avira’s anti-malware SDK, a trusted OEM engine used widely across the industry, to massively enhance its defensive capabilities. This engine includes several detection layers that combine to provide a comprehensive security approach.
    Signature-based scanning compares file hashes against Avira’s vast malware signature database. Updates occur every 24 hours to keep the engine current with emerging threats. This database is automatically updated every 24 hours via a secure connection to Avira’s update servers, providing protection against the latest cataloged threats.
    Similarly, for malware that is not yet in the signature database, the Avira engine uses heuristics to analyze the code structure, behavior, and characteristics of a file. This allows it to identify variants of known malware families and other suspicious code, even without an exact signature match.
    Finally, Machine Learning (MicroVision™), Avira’s local ML model, evaluates a broad set of code attributes and anomalies to identify previously unseen threats. It is especially effective against zero-day malware that lacks a known signature but shows signs of malicious behavior.
  • Entropy and MIME Mismatch Analysis: Commvault uses encryption detection models, consisting of multiple statistical features, to identify encrypted or disguised files. One such feature is entropy, which measures the level of randomness in data at the binary level. High entropy can indicate ransomware encryption, but it is just one of several properties used in Commvault’s encryption detection model.
    In parallel, MIME mismatch detection flags files where the content does not match the expected file type, such as a script disguised as a PDF. These techniques help uncover dormant threats that might otherwise go unnoticed.
  • Anomaly detection: Commvault continuously monitors for behavioral deviations. Unusual spikes in backup volume or changes in data patterns are treated as warning signs. Once these anomalies are encountered, they can be promptly investigated, helping lead to early containment.

Comprehensive Recovery: Isolated, Validated, and Automated

As ransomware grows in complexity and speed, clean recovery is imperative. With ransomware, restoring the wrong version can cause re-infection, operational downtime, or compliance failures. And it can be detrimental to company trust, confidence, and long-term success. Commvault addresses these risks with a set of validated recovery options that not only help restore clean data but also help verify its safety before it ever touches production systems.

Commvault’s Cleanroom Recovery creates a secure, isolated recovery environment for testing and validating backup data before reintroduction. This setup is ideal for running malware scans without risking spread to production. What’s more, cleanrooms are provisioned on-demand in the cloud, avoiding the need for dedicated infrastructure.

Within the cleanroom, Commvault supports a wide range of workloads, including virtual machines, file systems, and Active Directory. This flexibility allows teams to simulate live environments and fully verify operational readiness.

Cleanroom Recovery enhances Commvault’s ransomware defense:

  • Automated recovery workflows: Commvault automates the entire recovery lifecycle, from identifying clean points to final workload restoration. These workflows help reduce manual effort, provide consistency, and help teams meet aggressive recovery objectives.
  • Pave and Repave: For systems compromised at the OS level, Commvault supports pave and repave capabilities. This approach restores machines using clean operating system images, then overlays customer data from backup. It results in a fully rebuilt system free from OS-level malware or tampering.
  • Bad file indexing: During scanning, Commvault marks any infected or suspicious file versions as “bad.” These tags are automatically referenced during recovery, enabling the platform to select clean restore points without manual review.

Auto Recovery and Operational Intelligence: Fast, Orchestrated, and Scalable

Recovering clean may be the most essential aspect, but recovering fast is also a priority. Commvault’s auto recovery capabilities allow organizations to restore systems at scale with speed, confidence, and minimal manual effort. These capabilities combine intelligent orchestration, integrated scanning, and real-time visibility to drive recovery resilience.

Here’s a deeper analysis of Commvault’s automated operational intelligence solutions:

  • Auto recovery orchestration: Commvault automatically detects the most recent clean recovery point and initiates restore workflows based on pre-defined policies. These orchestrated processes eliminate guesswork and help reduce the time it takes to bring systems back online after an attack. The full Commvault auto recovery process involves automated steps detailed here.
  • Threat Scan integration: Recovered workloads are scanned as part of the recovery workflow before they return to production. This process enhances the confidence of restored data by helping keep it free from hidden malware or residual threats.
  • Recovery validation reports: Every recovery operation produces a detailed report that outlines scan outcomes, flagged anomalies, and any corrective actions taken. These reports give security teams invaluable visibility into what was recovered and why.
  • Security IQ dashboard: The Security IQ dashboard provides real-time insight into ransomware risk, data exposure, and overall recovery readiness. It helps administrators identify critical weak spots, track improvements, and act on changes as needed.

Ransomware Resilience When It Matters Most

Commvault’s ransomware defense architecture is an intelligent, multi-layered ecosystem. From the moment data is backed up to the second it’s restored, every layer is protected, validated, and recoverable. With a comprehensive design that encompasses every aspect of ransomware defense, Commvault gives your businesses confidence, trust, and resilience.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Resilience is at the core of everything we do here at Commvault. As we shared earlier this year, we are proud to partner with Warrior Canine Connection (WCC) in its mission to create resilience and strength within the veteran community.

This is a cause close to our hearts and foundational to our VALOR Employee Group’s mission to honor our veterans and increase veteran recruitment and retention, while bolstering our community outreach and building a military-friendly culture that is inclusive of all.

Over the past couple of months, we’ve been thrilled to have members of WCC, including some furry friends, join us at customer and partner events across the United States. Heidi Pius on our Sales Engineering team has witnessed the pawsitive effect these service animals have had on everyone they encounter.

“Commvault’s partnership with WCC highlights the powerful combination of innovation and resilience in supporting veterans,” Heidi said. “This partnership helps both of us further veteran resilience through the healing power of service animals.”

Here are some highlights from our events throughout the summer:

Commvault’s Annual Public Sector Partner Day – Stone Tower Winery in Leesburg, Virgina.

WCC were the capstone presenter at our Annual Public Sector Partner Day and showcased how the organization furthers veteran resilience and helps military heroes reconnect with life, their families, and their communities through the healing power of service animals.

 

AWS Summit – Washington DC

WCC added a special touch to our booth at the AWS Summit in Washington, D.C. When the service dogs weren’t present in the booth, we had people asking about them and when they would return to the booth – we even ran out of mission cards during the event.

Having WCC as part of our booth experience is not only a great marketing tool but makes the booth experience relatable on another level – adding a human element that makes it real. The handlers were excellent in telling the story of resilience from both sides.

Having an impact is fundamental to our values and our culture. We’re committed to our partnership with WCC to raise awareness and help veterans receive the support and care they deserve.

To learn more about what it’s like to work at Commvault, visit our Careers site.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

It’s no surprise that identity infrastructure, particularly Active Directory (AD), is a primary target for attackers. According to Gartner’s Market Guide for Identity Governance and Administration, more than 90% of Global 2000 organizations rely on AD for core identity and access management.

Yet, despite its critical role as the central nervous system of enterprise IT, AD security is often neglected, leaving it vulnerable to sophisticated attacks that can bring an entire organization to its knees.

The consequences of a compromised AD can be catastrophic, including widespread operational disruption, significant data loss, and a complete loss of trust. When attackers gain control of AD, they hold the keys to the kingdom – and they are able to move laterally, escalate privileges, and deploy ransomware with devastating efficiency.

Best Practices for Future-Proof AD Resilience

Achieving true AD resilience requires a strategic blend of proactive defence, meticulous planning, and robust recovery capabilities. This is not merely about having backups; it’s about cultivating a resilience-first mindset and implementing a multi-faceted strategy.

1. AD forest recovery: Planning for the worst-case scenario

A complete forest recovery remains the ultimate test of AD resilience. This involves the ability to restore the entire AD environment to a known-good state after catastrophic corruption or compromise.

  • Maintain regular, offline backups of all domain controllers.
  • Document and periodically validate the forest recovery process through tabletop exercises and simulations.
  • Leverage tools like Microsoft’s AD Forest Recovery Guide or third-party automated solutions that reduce recovery time.
  • Recovery images should remain secure, offline, and immutable.

Without these preparations, organizations risk prolonged outages, as recovering AD manually without a plan can be highly complex, error-prone, and time-consuming.

2. Entra ID recovery: Protecting and recovering break-glass accounts

Beyond restoring the forest, organizations should build resilience through Entra ID recovery – protecting and rapidly recovering break-glass accounts used in emergencies.

  • Maintain dedicated, highly secure and monitored administrative accounts that are disconnected from regular directory services (Tier-0 accounts).
  • Store credentials for these accounts in secure vaults (e.g., CyberArk, Azure Key Vault) with strict access controls.
  • Regularly rotate credentials and audit access logs.
  • Simulate account lockout or compromise scenarios to validate the recovery process.
  • Entra IDs have to be excluded from regular AD sync processes with cloud environments to reduce exposure.

These accounts should be protected as crown jewels since their compromise could derail recovery efforts entirely.

3. Proactive hardening and monitoring

This forms the bedrock of any effective AD security program. Organizations should implement a tiered access model to enforce the principle of least privilege, so that users and administrators only have access to the resources absolutely necessary for their roles.

Regularly auditing for misconfigurations, such as weak password policies or excessive permissions, is crucial. Furthermore, deploying advanced threat detection and response solutions provides real-time visibility into suspicious activities, helping enable security teams to identify and neutralize threats before they can escalate.

4. Immutable backup and recovery readiness

Backups should be stored in an immutable, air-gapped location to protect against encryption or deletion by ransomware. This provides a clean recovery point.

Recovery readiness goes a step further by regularly validating the integrity and recoverability of these backups. By automatically testing the recovery process in an isolated environment, organizations can confirm that their backups are not only safe but also fully functional, reducing the risk of a failed recovery during a real crisis.

A Unified Front: The HCLTech and Commvault Joint Solution

HCLTech and Commvault have forged a powerful partnership to deliver a comprehensive, end-to-end identity resilience solution that automates forest-level recovery for AD, helping reduce downtime from days or weeks to hours. With Commvault and HCLTech, customers can expect:

  • Knowledge and strategic guidance from the experts at HCLTech to design, implement, and sustain a resilient AD environment aligned with zero-trust principles.
  • Proactive hardening, regular testing, and continuous monitoring.
  • A comprehensive, tailored recovery plan that includes automated forest-level recovery enabled by the industry-leading capabilities of Commvault Cloud.
  • Unified protection of hybrid identity systems (AD + Entra ID) that simplifies operations and reduces tool sprawl, enabling consistent security across environments.

Together, HCLTech and Commvault provide a truly holistic approach to identity security and business continuity. By combining Commvault’s rapid, automated recovery technology with HCLTech’s strategic, security-first services, organizations are equipped not just to survive an AD-related disaster, but to emerge stronger.

This unified front helps keep your most critical identity infrastructure ready for the worst-case scenario, delivering a rapid, clean, and reliable recovery when it matters most. Don’t wait for a crisis to test your defenses. The time to act is now. Take the first step toward true AD resilience and help your organization prepare for any eventuality.

To learn more and demo the solution, visit the Active Directory solution page.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

At Commvault, we believe that the well-being of our employees is fundamental to our success as a company. That’s why we’re committed to providing a comprehensive approach to wellness that addresses the various aspects of our Vaulters’ total wellbeing.

Recognizing that wellness encompasses more than just physical health, we’ve developed a multi-faceted approach that includes medical, financial, and physical wellness initiatives.

Introducing a Comprehensive Wellness Platform

We’re thrilled to have recently launched our new wellness platform, CommWell. This innovative platform consolidates various wellness-related benefits into a single, user-friendly interface, making it easier for our employees to access the resources they need to maintain and improve their health. The platform offers a range of features, including:

  • Health assessments to identify areas for improvement.
  • Personalized wellness plans tailored to individual needs.
  • Interactive tools to track progress and encourage healthy habits.

By simplifying the management of wellness benefits, we strive to give our employees, regardless of their location, access to the support they need.

Supporting Mental Health with Spring Health

We understand that mental health is just as important as physical health. That’s why we’ve partnered with Spring Health, a global provider of mental health support services. Its comprehensive platform offers more than just traditional EAP services, providing:

  • 6 counseling sessions to address specific mental health concerns.
  • 6 coaching sessions to support personal and professional growth.
  • Access to a hub of courses and resources for ongoing development.

Empowering Financial Wellness with Origin

Financial stress can have a significant impact on overall well-being. To help alleviate this burden, we offer Origin financial services, providing employees with access to free financial advisors and Certified Financial Planners. The Origin platform offers expert guidance on a range of topics, including:

  • Tax strategies and planning.
  • Equity awards and employer benefits optimization.
  • Budgeting and cash flow management.
  • Investment selection and retirement planning
  • Risk analysis and insurance planning.

Additionally, Origin’s AI Budget Builder (currently available in the U.S. and soon to be expanded globally) provides a cutting-edge tool for managing finances.

Promoting Physical Wellness with Wellhub

Regular exercise, healthy nutrition, and mindfulness are essential components of overall wellness. To support these aspects, we offer access to Wellhub, a digital app that provides a range of fitness, nutrition, and mindfulness resources. In select locations, employees also can join gyms at a tiered level, making it easier to incorporate physical activity into their daily routine.

A Culture of Care and Support

At Commvault, we’re committed to creating a culture that prioritizes employee wellness and encourages our employees to value their wellbeing. By providing a comprehensive range of wellness initiatives, we’re empowering our teams to deliver for themselves first, which in turn allows them to thrive both personally and professionally.

To learn more about what it’s like to work at Commvault, click here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The Australian Security of Critical Infrastructure Act 2018 (SOCI) is the cornerstone of the government’s strategy to manage risks to critical infrastructure. Its objectives are to confirm operators of essential infrastructure assets take appropriate security measures and to give government the information and powers to respond to threats.

Originally targeting just four sectors (electricity, gas, water, and ports), SOCI has since been expanded to cover 11 sectors across the economy. The act aims to keep critical infrastructure assets and services across these 11 sectors protected and resilient against disruptions to Australia’s security, economy, and society.

To achieve this, the Act imposes obligations on critical-asset owners, via the form of Positive Security Obligations (PSOs)Enhanced Cyber Security Obligations (ECSOs), and Government Assistance Measures.

For example, responsible entities must register asset details and maybe required to report cyber incidents to the Australian Cyber Security Centre (ACSC) and maintain a formal risk management program known as a Critical Infrastructure Risk Management Program (CIRMP). Assets deemedSystems of National Significance could face even stricter requirements, including, for example, mandatory incident response plans, cyber exercises, and vulnerability assessments. SOCI essentially codifies what was once considered industry best practice into enforceable law.

Two camps of impact: Legacy Sectors vs. Newer Entrants

The originally regulated sectors likely view SOCI as an extension of existing frameworks. For decades, energy and utilities have operated under rigorous reliability and security standards (such as NEM codes or water safety laws), so the formalisation of these practices within SOCI may feel like a continuation of existing governance.

By contrast, organisations in the more recently added sectors, such as communications, data storage and processing, healthcare, higher education and transport, are navigating new regulatory territory. These industries often lack the legacy of infrastructure regulation, meaning SOCI compliance requires building many processes from the ground up. This includes establishing asset registers, drafting CIRMPs, implementing controls, and training teams in incident reporting procedures.

For example, a university or hospital network may now find themselves classified as operators of critical infrastructure, requiring them to identify covered assets, assess dependencies, and implement a compliant CIRMP.

This often involves building formal security governance from the ground up – aligning to frameworks such as the ASD Essential Eight, ISO 27001, or the NIST Cybersecurity Framework – and establishing mechanisms for timely incident detection, response, and reporting to the ACSC.

By contrast, operators in traditionally regulated sectors may already have mature risk programs in place and can adapt existing controls to meet SOCI’s requirements. Regardless of sector, all organisations must now integrate cyber risk management into core business processes, not treat it as a parallel or isolated activity.

OT and the IT Convergence Challenge

A significant challenge presented by SOCI lies in securing Operational Technology (OT) environments: the industrial control systems that underpin many critical assets. OT brings its own set of risks.

Many devices were never designed with cybersecurity in mind. They often run outdated operating systems or firmware that cannot be easily patched and use proprietary or legacy protocols, such as Modbus, DNP3 or Profibus, that lack basic authentication and encryption.

Concurrently, the convergence of IT and OT networks has expanded the attack surface. Previously isolated environments are now increasingly connected to enterprise IT systems and the internet to enable remote monitoring, analytics, and automation. This creates new pathways for attackers to move laterally between environments and introduces the risk of operational disruption from cyberattacks.

Industrial operators must strike a balance between system availability and cyber protection. Taking systems offline for updates or segmentation may interfere with operations, but leaving them exposed increases risk.

SOCI encourages organisations to adopt OT-specific strategies. These may include strict network segmentation, least-privilege access, out-of-band monitoring, and fail-safe designs to secure these environments.

Data Service Providers and Notification Duties

One of the lesser-discussed but critically important elements of SOCI is the responsibility to notify data service providers. If a third party stores or processes business-critical data related to your regulated asset, you are obligated to inform them that SOCI applies. This verifies that your service providers understand their role in protecting critical data and are prepared to support you during an incident or audit.

In addition, incident notification is a central requirement of SOCI. A cyber security incident that has a significant or relevant impact on your essential services must be reported to the ACSC within strict timeframes. If the impact is significant, notification must occur within 12 hours. For relevant but lower-severity incidents, notification is required within 72 hours.

This is not a best-effort or voluntary activity. It is a legal obligation. Timely reporting gives ACSC visibility into threats to national systems, allowing it to coordinate timely and effective responses. It also reinforces the principle that critical infrastructure protection is a shared responsibility between industry and government.

Beyond Prevention: The True Meaning of Resilience

Many organisations still interpret resilience as the ability to block or prevent threats. But true resilience goes beyond prevention. It is the ability to absorb shocks, recover quickly and continue operating, even under adverse conditions. SOCI pushes organisations to embrace this broader definition.

Resilience means having tested recovery plans, reliable offline backups, redundant systems, and a playbook for returning to service during or after an incident. It also means continuous improvement, learning from each event, adapting defences, and closing gaps before the next attack.

This is especially important given recent trends. Reports from the Australian Signals Directorate (ASD) and other government bodies show that cyber incidents impacting sectors like water, energy, and transport are increasing.

Even relatively minor events can cause ripple effects across interdependent systems, affecting supply chains, public safety, and essential services. These trends highlight the urgency of a recovery-focused approach.

CISOs must lead the charge in making cyber resilience more than a checkbox. That means treating resilience as a dynamic, end-to-end capability that involves people, processes, and technology working in concert.

A Regulatory Shift with Strategic Upside

SOCI has represented a significant shift in Australia’s approach to cyber regulation. It moves beyond fragmented, voluntary approaches and creates a cohesive national framework for protecting critical infrastructure. While it certainly has introduced new complexity, reporting burdens, and compliance costs, it also provides an opportunity for organisations to elevate their security maturity and embed resilience at the core of their operations.

Rather than viewing SOCI as merely a compliance task, forward-thinking CISOs can treat it as a strategic catalyst. It provides board-level backing for investment, formalises risk practices, and improves alignment between business and security. The inclusion of government assistance measures and threat-sharing mechanisms further positions SOCI as a collaborative tool, not just a mandate.

As threats evolve and digital infrastructure becomes more embedded in national life, resilience must be the priority. SOCI sets the stage. Now it’s up to us to act.

Read more about what your obligations are in A Guide to the SOCI Act.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The Security Standard That’s Reshaping Business Strategy

While most organizations view FedRAMP High as a compliance hurdle – a necessary evil for selling to federal agencies – forward-thinking enterprises are discovering something remarkable: This rigorous security framework isn’t just about meeting government requirements.

FedRAMP High serves as a smart security blueprint for the private sector, and we’re seeing this translate into something even more powerful – a strategic foundation for building the kind of cyber resilience that transforms businesses from the inside out.

The bottom line: Organizations implementing FedRAMP High controls alongside enterprise data resilience strategies aren’t just checking compliance boxes – they’re gaining massive operational efficiencies, cost savings, and competitive advantages that extend far beyond government contracts.

Why FedRAMP High and Zero Trust Are Inseparable

Here’s what’s resonating across the federal sector and bleeding into commercial enterprises: FedRAMP High controls and zero-trust architecture aren’t separate initiatives– they’re interdependent foundations that enable cyber resilience.

Think about it: How can any organization – federal agency or Fortune 500 company – achieve genuine zero trust without the stringent controls that FedRAMP High demands? FedRAMP High requires cloud providers to meet over 400 security controls, creating the robust foundation that zero-trust principles require to function effectively.

The federal government has recognized this interdependency, with zero-trust solutions now achieving FedRAMP High authorization, proving that these frameworks work best when implemented together, not as competing priorities.

The Data Resilience Advantage: Beyond Security to Business Value

When organizations implement FedRAMP High controls with an enterprise approach to data resilience – encompassing both protection and management – something powerful happens: They simultaneously enable cyber resilience for their organization’s most critical asset – data.

This approach delivers transformational value across three critical dimensions:

1. People: Consolidation and Cost Efficiency

Instead of managing multiple point solutions and training staff on disparate systems, organizations consolidate to a single, overarching data management platform. The result? Reduced personnel costs and simplified operations as teams can focus on strategic initiatives rather than managing complex, fragmented toolsets.

2. Process: Automation and AI-Driven Viability

FedRAMP High’s rigorous controls, when paired with modern data resilience platforms, enable organizations to automate critical processes and integrate AI capabilities from a position of strength. This automation helps maintain minimum viable operations during disruptions and maintain the highest security standards.

3. Technology: The Foundation for Modernization

High-security compliance using the right architecture and technology doesn’t just help build cyber resilience – it creates enormous operational efficiencies that become the basis for modernization and competitive advantage.

Real-World Impact: Government Efficiency in Action

This isn’t theoretical – organizations are already seeing these benefits. Government agencies are recognizing solutions that meet FedRAMP High requirements while delivering the cost efficiency of SaaS, with enterprise approaches eliminating redundant legacy software tools and enabling significant operational savings.

This isn’t just a government success story. It’s a preview of what commercial enterprises can achieve when they stop viewing FedRAMP High as a burden and start seeing it as a strategic advantage.

The Private Sector Awakening

Private sector organizations are increasingly recognizing that FedRAMP compliance offers high trust and oversight, enhances security, and provides a competitive edge. Companies in highly regulated industries – finance, healthcare, insurance, and defense contractors – are discovering that FedRAMP-compliant vendors often carry over lessons learned in their FedRAMP environments to their commercial environments, resulting in improved security postures, streamlined compliance efforts, and enhanced operational efficiency.

The smart money isn’t waiting for regulatory mandates. Many companies intentionally seek out FedRAMP Authorized cloud providers for their services even when they aren’t governmental agencies, specifically because they’re aware that FedRAMP is a high standard and that any cloud service provider willing to go through the work to adhere to it takes security seriously.

Three Strategic Imperatives for Modern Enterprises

1. Treat FedRAMP High as a business accelerator, not a compliance tax.

Organizations that view FedRAMP High controls as the foundation for a comprehensive data resilience strategy gain operational efficiencies that more than offset implementation costs. The framework’s rigorous requirements force organizations to eliminate redundancies, consolidate systems, and optimize processes.

2. Implement data resilience and zero trust as integrated systems.

Zero-trust architecture verifies the context available at access time, including both static user information and dynamic information such as geolocation and credentials, the sensitivity of the data and resource, access anomalies, and whether the request is allowed based on business rules. When this approach is applied to enterprise data resilience, organizations gain visibility and control over their most valuable assets.

3. Choose technology partners with proven FedRAMP High capabilities.

Selecting a SaaS vendor with FedRAMP compliance can significantly streamline procurement by providing a vetted list of vendors who already meet high-security standards, saving time, reducing risk, and simplifying the decision-making process.

The Competitive Reality: Security as Strategic Advantage

The most successful organizations of the next decade won’t be those that treat security as a cost center or compliance checkbox. They’ll be those that recognize FedRAMP High controls as the foundation for building truly resilient, efficient, and competitive operations.

The security and regulatory compliance of cloud services are paramount. Organizations that master this intersection of security, compliance, and operational efficiency aren’t just protecting themselves – they’re positioning themselves to win in an increasingly complex and dangerous digital landscape.

The Path Forward: From Compliance to Competitive Advantage

Organizations implementing enterprise data resilience strategies with FedRAMP High controls today are discovering something remarkable: The same frameworks that help protect against cyber threats also drive operational excellence, cost efficiency, and competitive differentiation. Your organization can choose between implementing FedRAMP High standards strategically to gain maximum business value, or reactively as a compliance afterthought.

The epiphany is clear: FedRAMP High isn’t just a security program – it’s a blueprint for building the kind of resilient, efficient, and competitive organization that thrives in our digital-first world.

Ready to transform your data resilience strategy? Learn how Commvault’s enterprise approach to data protection and management can help your organization achieve FedRAMP High compliance while driving operational excellence and competitive advantage.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

When someone suffers a debilitating injury, the first thing they want to know is how soon they’ll be back on their feet. Following a cyberattack, a healthcare company’s IT team faces the same question, but with added urgency.

Every minute of downtime poses a critical risk to your organization’s sensitive data, reputation, and patients. What will your answer be?

In a recent blog, Rx for Cyber Threats, we discussed the importance for healthcare organizations of having a minimum viable recovery (MVR) strategy – a business-first approach to restore the most critical services and functions for your core operations.

By prioritizing what matters most, you can recover more quickly, efficiently, and reliably. That’s especially important when lives are on the line.

But having a strategy is only the beginning. To protect your patients and your business, you also have to implement it effectively. That’s why Commvault offers a complimentary Minimum Viability Self-Assessment to help determine how well you’re prepared to resume core operations following a disaster, how you compare with peer organizations, and what you can do to improve your MVR capability. 

Do You Know Where to Begin?

According to a recent GigaOm report, “Minimum Viable Recovery: Closing the Recovery Gap,” 54% of organizations lack confidence in their own recovery plans. The Commvault Minimum Viability Self-Assessment can help you understand your readiness across the analyst firm’s three pillars of a successful MVR implementation:

  • Business-critical prioritization
  • Measurable technical response
  • Organizational recovery readiness

The first pillar focuses on identifying your most critical functions and mapping their technical dependencies. By setting priorities before an attack, you can move more quickly and effectively in an emergency. Your Minimum Viability Self-Assessment will help you determine how well you’ve laid this foundation and where additional clarity and alignment might be needed.

How Will You Proceed?

Once you’ve mapped out your MVR strategy, the next step is to confirm that you are prepared to execute it effectively. Your technical response will depend on secure backups for critical systems and data, protection for the systems used for recovery, accurate threat detection and identification, clean infrastructure within which to rebuild systems, and other capabilities.

Your Minimum Viability Self-Assessment will help you understand whether you have the technical and organizational capability to not only stop the current attack, but also recover compromised data, rebuild damaged systems, and prevent similar attacks in the future. 

Is Your Organization Ready?

The third pillar of the GigaOm model focuses on continuous recovery readiness. With healthcare companies among the most frequent targets for cybercriminals, it would be reasonable to assume that you’ll be attacked at some point and prepare accordingly.

Your Minimum Viability Self-Assessment is designed to address key elements of organizational readiness, from well-defined recovery roles, responsibilities, and procedures to clear SLAs for critical workloads. You’ll also learn whether your testing practices are sufficient to keep your plan up to date and your team ready for anything.

Your Lab Results Are Waiting …

At the end of your Minimum Viability Self-Assessment, you’ll receive a detailed report analyzing your recovery readiness across key elements of minimum viability, a high-level overview comparing your MVR strategy to your peers, and actionable recommendations to speed your response to the next disaster.

Don’t wait until you’re under attack to discover how well you’re prepared to recover. Begin your Minimum Viability Self-Assessment now to enable uninterrupted care for your patients and resilience for your business.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Threats are moving faster, hiding deeper, and striking harder than ever before. Traditional perimeter security, once sufficient, can now leave critical gaps. In this landscape, cyber resilience requires more than just detection – it requires active, collaborative threat hunting. 

Threat hunting is a proactive way to find and stop threats that may have gone past your current security measures before they become costly events. With the right tools and a plan, both security and IT teams can help stop threats quickly and recover quickly. With Commvault® Cloud, technologies such as YARA rules, deception frameworks, and canary files make this possible.

Here, we explore the hows: how threat hunting techniques work, how data admins benefit from threat hunting, and how they can help you improve your organization’s cyber resilience.

What is Threat Hunting?

Threat hunting has evolved from a niche IT security discipline into a critical component of modern cybersecurity and resilience. Today’s threats can bypass traditional detection systems and then quietly persist, conducting thorough reconnaissance and living off the land until they strike. Threat hunting has become a key part of the fight against cyber threats that are becoming more sophisticated and more common. It can help stop threats from spreading and avert big damage. 

Early adopters of threat hunting began integrating proactive threat search techniques into their incident response workflows. By the mid-2010s, threat hunting had matured into a formal discipline embraced by Security Operations Centers (SOCs) worldwide.

Threat hunting is a cross-functional effort with increased impact when IT, security, and data management teams are included. The continuous practice relies on collective intelligence and demands both vigilance and agility. When done right, threat hunting can transform your cyber strategy from reactive to resilient.

Common Techniques and Strategies: How to Threat Hunt

Threat hunting relies on a layered approach to spotting anomalies. These techniques help you detect early signs of compromise by monitoring deviations in behavior, patterns in traffic, or activity in unexpected places. These are some commonly used threat hunting techniques:

  • Threat scanning: Ongoing scanning is an integral aspect of any threat hunting effort. Scanning tools can be used to examine logs, files and file changes, network activity, and system behavior in real time or on a regular cadence. Using both signature-based and behavioral analysis, threat scanners can flag unusual activity long before standard alerts would be raised.
  • YARA rules: YARA rules allow you to define and search for specific patterns in files, processes, or memory. They’re essentially the “blueprints” of specific characteristics of malware and may be created specifically by a SOC team if they know what they’re looking for or from a threat intelligence feed of community-sourced, in-the-wild threats. Security analysts use YARA rules to identify known malware types, find strange file signatures, and surface signs of a breach.
  • Deception technology: Attackers rely on stealth, but deception technology turns that against them. By setting up decoys like honeypots, lures, and threat sensors, you can bait attackers into revealing themselves.

When attackers interact with these decoys, which appear like real systems with important data, during their reconnaissance, their attempt to communicate with these deceptive systems triggers an alert. This allows early threat detection without extra noise and without putting actual assets and business data at risk.

  • Canary files: Similarly, canary files act as simple but effective digital tripwires. These files look like valuable content to an attacker when in fact they are monitored for any access or change. If touched, they trigger alerts that signal unauthorized activity.

As threat hunting techniques mature with time, the integration of AI and machine learning are on the horizon. These new technologies have the potential to improve detection accuracy and speed by identifying patterns that humans might miss, prioritize threats more intelligently, and reduce false positives that slow down response.

How Does IT Benefit from Threat Hunting?

Traditionally, threat hunting has strictly been the domain of security professionals. But now that recovery speed and data integrity define the operational resilience of businesses, data protection administrators have become a critical piece to solving the puzzle.

IT and data admins are the guards of the data, knowing where it sits and critical interlocks. Giving them a headstart on taking the attackers’ perspective and understanding where to start digging for hidden threats.

Regular backup processes can capture everything that happens in production. Therefore, data backups can become a shared trove of security-related insights, even if attackers are successful in covering their paths.

With growing responsibilities comes increasing rewards – leveraging threat hunting techniques can provide a plethora of unique benefits for your recovery process. Threat hunting can help you achieve clean recoveries. If you detect and isolate threats early, you can understand the last clean backup and recover uncompromised copies, helping avoid the risk of reinfection. This minimizes data loss, improves your recovery time, protects backup integrity, and helps you achieve critical KPIs.

Threat hunting also reduces the need for full recovery operations by stopping issues before they escalate. Fewer recoveries overall helps lower workloads across the entire team. Early warning signals give you more time to act and reduce ‌operational burden. When recoveries are needed, they happen faster, with less guesswork and greater confidence. 

Finally, embracing threat hunting tools can enhance a data admin’s credibility as a data steward. Your systems stay trusted, your recoveries stay smooth, and your reputation as a continuity leader grows.

Commvault Cloud brings threat hunting capabilities directly into backup and recovery workflows. You don’t need to become a security analyst. State-of-the-art, built-in threat hunting tools put powerful detection capabilities in the hands of data admins without requiring additional expertise. You can take control of data protection without stepping outside your role, contributing monumentally to organizational cyber resilience.

Own the Outcome: Passive Defense to Active Control

For your modern business, security approaches are maturing into resilience strategies – going beyond reactive firewalls and antiviruses. Comprehensive cyber resilience is about knowing what lurks inside and acting before damage spreads. Now, threat hunting offers an additional way to protect data, improve recovery outcomes, and lead with confidence while also sharing intelligence with your security counterparts.

With Commvault Cloud, threat hunting becomes part of your recovery readiness. Whether through ongoing threat scanning, signature-based detection with YARA rules, or using smart deception with decoys throughout your environment, you have access to the tools needed to help your business remain resilient against ever-changing cyber threats.

For more information, visit www.commvault.com.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery