Skip to content

I’m proud to share our 2023 Corporate Social Responsibility Report, an overview of all the incredible work our Vaulters are doing every day to innovate within our environmental, social, and governance (ESG) initiatives.  

Over the past year, we continued to address barriers and biases in our workforce by hiring, mentoring, and empowering employees from underrepresented groups. Additionally, in listening to our employees, we wholeheartedly embraced a flexible, hybrid workstyle. We celebrated how our employees play a critical role in moving forward our ESG initiatives. During the year, they rallied to support local and global causes, including raising money in response to the tragic earthquake in Turkey and the Crisis in Ukraine. And they continue to innovate solutions to help customers monitor and reduce their energy usage and carbon emissions, as well as support their compliance and regulatory requirements.  

Our core values – we connect, we inspire, we care, and we deliver – empower us to drive company performance in a way that serves the planet, our people, and our communities in a responsible, sustainable, and ethical manner. Whether helping our customers and partners manage their data more sustainably, supporting the development and inclusion of our global workforce, or giving back to our communities, we continue to prioritize our stakeholders and treat long-term sustainability as a non-negotiable requirement of doing business.

“At Commvault, our foundation is built on trust. Our customers trust that we will protect their data in this difficult world. Our employees trust that we will lead them to new opportunities. Our investors trust us to responsibly manage their investment, which we proudly do. And trust is at the heart of our environmental, social, and governance (ESG) initiatives, where we have made significant strides this past year.”

– Sanjay Mirchandani
President, Chief Executive Officer & Director | Commvault   

  

We remain committed to driving change where we can generate the most influence – in our direct operations, for our partners and customers, with our employees, and within our communities. 

I hope you enjoy learning more about our efforts in this year’s report!

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Here at Commvault, we’re passionate about investing in and mentoring the next generation of leaders. This is why we started the new year by partnering with Break Through Tech to sponsor internships through their Sprinternship™ program in January.

Break Through Tech works to propel women and non-binary students into computing degrees and tech careers with a vision to achieve gender equality in tech. Their Sprinternship program is offered in three-week sessions during academic recess and has reached thousands of students, with an emphasis on welcoming Black, Latina, low-income, first-generation college students, and non-binary students to launch their tech careers.

Throughout their time with us, the “Sprinterns” tackled real business challenges and were engaged in our day-to-day operations and company culture while demonstrating their skills. We were proud to sponsor two Sprinternship Programs in January: HR Data Analytics and UX Development, with each program having a unique challenge project.

In partnership with my colleague Scott Bice, Global Head of HR Operations and Services, we oversaw the HR Data Analytics Sprinternship. This opportunity allowed students to work with our Human Resources team to develop an HR scorecard, test data in the data warehouse, innovate new and creative ways to display data and tell a story, and provide input and design on KPIs. Throughout the project, they learned how the engagement level of new hires corresponds to their onboarding experience, team experience, and time with managers. In just three weeks, students learned how to use tools like the data cube, work with Power BI, utilize Excel pivot tables to analyze the data, and tell the story of new hire engagement.

 “The Sprinternship program was truly a sprint; a compact three-week internship focused on challenging each other, mentoring for success in the workplace, and providing experiences in the technology space,” said Scott Bice, “The Sprinterns went above and beyond to embrace the opportunity, drive change, and extract value from the experience, which made it a win-win!”

The UX Development Sprinternship enabled students to develop example product pages within our design system site using our React components. Throughout their three weeks, they also acquainted themselves with our suite of products and design system, referencing existing example pages within our design system site codebase and contributing to the design system codebase. These Sprinterns worked as UX developers and gained a newfound understanding of UX and the vital role it plays in STEM. The experience certainly piqued interest in front-end in those that may not have considered a career in this field. And get this – one of our UX Sprinterns even contributed to our code base, which was published on our design system site!

It’s exciting to see the progress these students make within the three-week program. They not only learn from us, but we learned from them as well! Parisa Bazl, Director of User Experience, said, “The Sprinternship program was helpful for us because not only did it make us really create and polish an efficient onboarding process because of its timeframe, but it also offered valuable management experience to our team members.”

Our Chief People Officer Martha Delehanty was ecstatic about the opportunity to get involved and support Break Through Tech’s mission, saying, “Break Through Tech’s Sprinternship program is fueling next-gen-tech talent around the country! This has been a fantastic way for companies like Commvault to invest in future talent AND get fantastic support to drive current business challenges, a win-win! Shout out to all our amazing Sprinternship participants, as well as Judy Spitz, Founder & Executive Director of Break Through Tech, for her pioneering spirit and leadership.”

We continue to always inspire our next generation of leaders and give them an exceptional experience during their time with us – however long that may be. We look forward to continuing our partnership with Break Through Tech. These opportunities make me excited about our future as we continue to bridge the gap of gender equality in technology and incorporate diverse viewpoints into how we deliver for our customers and partners!

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Cyberthreats – like ransomware – are global businesses staffed by malicious actors, state-sponsored hackers, and criminal syndicates looking to exploit any weakness. And business is booming considering that approximately 66% of businesses have experienced a cyberattack over the past 12 months. Yet, while many companies boast ransomware panaceas and their unique ability to solve these security problems, it is not so cut and dry.

The answer is not more bolt on tools which just adds more security gaps and ultimately brings more risk to your business.

https://play.vidyard.com/4E2nVw56vPHYw92vzAET8u

For starters, today’s environments are complex. Not only is your organization hybrid and global, but you’re managing more data, applications, and technologies strewn across on-premises systems, cloud services, SaaS environments and more. And it all needs protecting. Even software vendors themselves have struggled to keep pace with sprawling data estates, adding point and niche solutions to ramp up workload support and technical capabilities to patch holes and gaps in their own portfolio. This just creates complexity you don’t want or need. After all, the more disparate, bolt-on tools you use to manage your data protection strategy and your security protocols, the wider the gap and greater the vulnerabilities for attackers to exploit.

Next, in the face of ransomware and other zero-day attacks, the lines between IT and Security are not only blurring but converging.  While traditional security approaches and applications are essential for any business, attacks are faster, stealthier, and more evasive than ever before. Relying on perimeter defenses alone is not sufficient in the face of this ever-evolving threat landscape. Companies need to embrace a unified, multi-layered approach. One where security and data protection interweave for comprehensive ransomware protection. This includes preventive and proactive measures to actively defend data (not just recover it) and to stay resilient from advanced threats and data loss threats. This will help you stay ahead of modern cyber threats, further harden defenses, and expedite response when facing a cyber incident.

And last, but not least, IT and Security teams are overburdened with the complex task of managing multiple security tools and their intricate integrations. This is especially challenging because teams often live in separate systems, adhere to their own processes, and behold unique responsibilities to the business. Removing barriers between these departments can also be challenging due to organizational priorities and limited resources.  In addition to keeping data secure, compliant, and recoverable, next-generation data protection can help unify these functions. Proactive threat detection and security system integrations equip businesses with new tools to surface attacks faster and organically connect disparate workflows, people and systems. Not only does this help improve security postures but it also increases visibility, coordination, and the response between departments to minimize the blast radius and accelerate response and recovery operations.

In short, an integrated platform is essential for shielding companies from ransomware attacks and other cyberthreats. It simplifies the management process so IT and security teams can concentrate on more strategic initiatives while still guaranteeing maximum protection against malicious actors. By leveraging such a platform, organizations can stay ahead of modern cyberthreats to anticipate and reduce risk, minimize exposure, and ensure your organization’s continuity.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Here are three best practices your organization should consider to design a robust disaster recovery plan that takes full advantage of what the cloud enables.

1. Clearly Define RPO and RTO for your disaster recovery plan

Recovery Point Objective (RPO) and Recovery Time Objective (RTO) are essential metrics to be defined when developing a disaster recovery plan.

  • RPO is the allowable period of time that can pass during a disaster event until the amount of data lost exceeds the maximum threshold that has been set in an organization’s business continuity plan.
  • RTO encompasses the entirety of an organization’s business operations and applications. It is defined as the maximum period of time an organization can remain functional during downtime caused by a disaster event before operations are either substantially restricted or taken offline altogether.

Defining RTO and RPO helps organizations decide on a clear and explicit disaster recovery plan framework to ensure their recovery goals are met during a disaster event. Update them periodically, especially if your organization has migrated to the cloud in place of legacy on-prem backup solutions.

(You can read more about RTO and RPOhere)

2. Routinely test your cloud disaster recovery plan — and update it accordingly

An unproven disaster recovery plan is one prone for potential failure.

It’s best to identify potential issues in your recovery plan on your own terms instead of finding out the hard way during a disaster event. Routinely test your disaster recovery plan to expose any shortcomings and see if any updates are required to reflect any changes and evolution in your organization’s IT needs.

3. Leverage cloud-native backup for cloud disaster recovery

The sheer amount of data being used on a daily basis has grown exponentially just within the last few years alone — a major reason why the majority of businesses have migrated to the cloud to leverage its scale and elasticity.

If your organization has moved its data and workloads to the cloud, it only makes sense to use a cloud-native backup solution that has been created specifically for the cloud. Once the cloud backup solution has been deployed, data can be automatically backed up and stored in the cloud. That way, if the data is lost or compromised due to an incident (such as a physical disaster or a ransomware attack), the most recent backup copy can be recovered and restored from any location.

However, in order for cloud backup to provide the necessary aspects needed to facilitate disaster recovery, it must provide two key capabilities:

  • Ensure the data backups are stored securely

Malicious threats like ransomware don’t just target an organization’s current data — they typically go after the backups as well. If they can steal both the primary and backup data, you are essentially at the mercy of criminals while facing potentially devastating data loss and downtime. This is precisely why backup copies should be securely stored in an air-gap manner isolated from primary accounts.

  • Rapidly restore the specific mission-critical data and workloads required to maintain business continuity

Some data is more important than other data, especially in terms of keeping operations afloat. If a disaster event threatens your data and processes, you likely don’t have time to wait for every last bit of data to be restored during recovery. You need a way to quickly prioritize and restore the mission-critical data required to keep your processes and end users online.

Secure Cloud Backup and Rapid Data Recovery with Clumio

Built natively in the cloud, Clumio provides faster disaster recovery while ensuring backup copies are kept safe by storing them in an encrypted, air-gapped environment outside of an organization’s primary account.

When data restoration is needed, Clumio’s granular and flexible recovery capabilities can identify, recover, and rapidly restore the specific mission-critical data and applications needed to maintain business continuity while a full recovery completes.

And it’s all done within an intuitive interface packed with features that provides everything from global search, browse capabilities, and ransomware risk analysis to enhanced compliance visibility.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Data is everywhere, so are cyber threats. Truly proactive defense means re-thinking conventional approaches to data protection, beyond just post-incident recovery. Data protection should (and must) start before data is compromised – with expansive capabilities that can anticipate, see, and react to threats, before its time to recover.

Mentionable facts:

  1. Teams can’t keep up: Over half of organizations only investigate between 1 and 10 alerts per day.
  2. Attacks are going unnoticed: 227 days is the average time it takes for security teams to identify and contain a data breach.
  3. Security and IT share the load: 80% of respondents reported that their cybersecurity and IT teams share the responsibility of protecting data.

ThreatWise™, from Commvault, advances data protection with unique early warning ransomware protection that surface zero-day, advanced, and unknown threats before data impact.

Leveraging patented cyber deception technology, it delivers advanced detection measures to intelligently safeguard data by identifying stealthy cyber threats in production. With advanced automation built-in, ThreatWise™ seamlessly enriches data protection strategies, connects IT and Security teams, and reduces cognitive load for admins and users.

https://play.vidyard.com/WgUpqDPrj983PLmCvmVG8H

Automated Decoys

To shield business data and systems from malicious intent and activity, ThreatWise™ blankets tripwires across on-prem, multi-cloud, and SaaS instances. Off-the-shelf, preconfigured decoys or threat sensors that replicate real network assets (such as critical workloads, IT/OT assets, etc…) rapidly cover surface areas and spot threats along the path to your data. This includes the critical moments of recon, discovery, and lateral movement – critical moments where detection provides material impact on containing a breach. From the start of an attack, data protection stakeholders can foresee malicious activity traversing environments and targeting data. ThreatWise can even coat backup infrastructure themselves, hiding these environments from threats directly aiming to neutralize backup and recovery utilities. These preconfigured decoys include baked-in recommendations, helping automate the configuration process and offering user setting recommendations and templates. This removes any expertise needed for administrators to set up decoys, offering high-fidelity fake assets that look (and behave) like real assets at the flick of a switch. 

Automated Configuration

Unlike honeypot technology, ThreatWise™ employs a lightweight and highly scalable architecture. This enables users to quickly blanket environments with hundreds or thousands of fake assets to rapidly harden data estates, mask data, and muddle bad actor attempts. But how do I know what preconfigured decoys to use for my unique environment? The ThreatWise™ Advisor intelligently connects backup environments and decoys to reduce cognitive load for users. By assessing data that’s actively being protected within Commvault backup environments, ThreatWise™ Advisor logically recommends decoy types (and their placement) to further safeguard critical workloads. By connecting the dots between backups and cyber deception users can intelligently blend decoys into the existing environments without any deception or security expertise to optimize early warning detection and lead threat actors down a rabbit hole, away from their targets (your data).

Automated Alerts

When it comes to cyber events, IT teams must seamlessly integrate with their Security counterparts. Minutes matter and visibility, telemetry, and coordination are paramount for proper and effective response. Through seamless integration with existing security stacks, ThreatWise™ automatically circulates urgent event data to key stakeholders and security teams without human intervention. And because decoys are only visible to bad actors, notifications are clear and precise, eliminating false positives. This automation amplifies Commvault’s threat detection capabilities by removing silos and prioritizing data itself, connecting IT and Security teams to streamline operations without burden. This enables organizations of every size to flag latent threats earlier and respond faster. The result? Improved observability and accelerated response to minimize impact and mitigate loss— for less risk, less recoveries, less downtime.

For more information on ThreatWise and our new Advisor capabilities, please visit the following page, or watch this On-demand Webinar on ThreatWise: Early Warning Data Protection and Its Role in Cyber Response.

References

1. WatchTower, SIEMs are Great, But They’re Also a Pain, 2022. – 2. IBM and Ponemon Institute, Cost of a Data Breach 2022, July 2022. – 3. TechTarget Inc., ESG Research Commissioned by Commvault, September 2022

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

I can’t imagine a better way to head into our new, upcoming partner program year than to take some time to recognize and thank the Americas partners that are at the heart of everything we do at Commvault.

Our ecosystem is full of exceptional partners who regularly go beyond in delivering services and solutions that make real world differences in solving some of the biggest challenges in IT like securing, protecting, defending, and recovering data and applications. Earlier today at our invitation-only Partner Summit, we had the opportunity to take it one step further with the unveiling of Commvault’s inaugural 2023 Americas Partners of the Year awards.

The awards presented at this event celebrate the accomplishments of partners who have invested their time and trust into Commvault’s Partner Advantage Program and its ability to provide reliable, innovative, and secure data protection solutions that protect their customers’ business critical data.

The top prize and bragging rights for the overall award for Americas Partner of the Year for 2023 goes to CDW, which saw a huge demand for SaaS solutions this past year and an even bigger acceleration of customer adoption of Commvault’s SaaS technologies.

Marking another win for CDW, CDW Canada was named Canada Partner of the Year for its impressive year-on-year growth, dedication to being a truly collaborative partner, and ability to grow our long list of joint customers.

On the Commvault and Metallic SaaS front, Verinext saw outstanding growth, taking home the Managed Services Partner of the Year award for being the fastest growing Metallic SaaS managed service provider of 2023. And Insight was named winner in the SaaS market, too, taking home the award for Commvault SaaS Partner of the Year for its consistent growth and remarkable performance that outshined its competition, including the onboarding of 125+ new, joint customers.

The categories for this year’s awards also centered around geography and vertical focus. Congratulations are in order for:

  • Ahead, Technical Partner of the Year
  • Carahsoft, Distribution Partner of the Year
  • Data Pivot Technologies, Americas East Regional Partner of the Year
  • Eagle Technologies, Americas West Regional Partner of the Year
  • Hitachi Vantara, Latin America Partner of the Year
  • Kelyn Technologies, Fed Partner of the Year
  • SHI, SLED Partner of the Year

This year’s award winners have adopted best practices for protecting customer data and security while providing valuable feedback on continuously enhancing the Commvault platform. This recognition serves as a testament to these partners’ hard work and dedication in providing excellent services with secure SaaS solutions through Commvault’s Partner Advantage Program.

Commvault is proud to recognize those who have risen above expectations within our Americas Region. These exceptional partners exemplify what it means to be part of an innovative team dedicated to helping customers protect their data while maintaining exacting standards for quality service delivery. We look forward to continuing our mission together with our valued partners as we strive towards excellence within our field.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Here at Commvault, we celebrate our diverse Vaulter community and honor the history of those who came before us.

This Monday is Juneteenth, a day which honors the emancipation of enslaved African Americans in the United States. We’re proud to observe the Juneteenth holiday on Monday, June 19, to commemorate history and celebrate African American culture.

Although Juneteenth is celebrated in the United States, our efforts to create awareness and have conversations on topics close to our hearts remain a key part of our global culture and core values.

This past February, I was joined by board member, Shane Sanders for a Courageous Conversation webinar panel hosted by our Diversity, Equity, and Inclusion (DEI) team and Multi-Culture Employee Resource Group (ERG) to celebrate Black History Month. During our conversation, he shared his perspectives on how the theme of “equity in action” has impacted him as a Black man and the social cost of not embracing diversity and inclusion in the workplace.

At Commvault, we are committed to furthering our DEI and belonging efforts, in partnership with our incredible ERGs, to create opportunities to drive awareness, have open conversations, and encourage reflection.

I encourage you to take a moment today to reflect, listen, and inspire!

To learn more about our DEI efforts at Commvault, click here.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

In the world of big data, organizations are constantly looking for ways to store, process, and analyze vast amounts of information. Two common solutions for handling big data are data lakes and data warehouses. While they may seem similar at first glance, these two data storage paradigms serve different purposes and have distinct characteristics.

What are Data Lakes and Data Warehouses?

Data Lakes

A data lake is a large storage repository that can hold raw, unprocessed data in its native format. Data lakes can store structured, semi-structured, and unstructured data, which makes them highly versatile. They are designed to be highly scalable, accommodating the exponential growth of data. Data lakes allow for real-time data ingestion and are ideal for organizations that need to store and analyze large volumes of diverse data types quickly.

Data Warehouses

A data warehouse, on the other hand, is a structured repository designed for storing, processing, and analyzing structured data. Data warehouses store data in a highly organized, schema-based manner, which makes it easy to query and generate insights. Data is typically cleaned, transformed, and aggregated before being loaded into a data warehouse. These systems are primarily used for business intelligence and analytical purposes, enabling organizations to make data-driven decisions.

Example Applications for Data Lakes and Data Warehouses

Data Lake Applications
  • Sentiment Analysis: Data lakes can be used to store and analyze large volumes of unstructured data, such as social media posts and customer reviews. This data can then be processed using natural language processing and machine learning (ML) algorithms to determine customer sentiment towards a product or service.
  • IoT Data Processing: Data lakes are ideal for storing and processing massive amounts of data generated by IoT devices. The real-time ingestion capabilities of data lakes allow for the processing and analysis of streaming data, enabling organizations to monitor and optimize their IoT networks.
  • Data Storage for ML/AI Training: In the medical and biotech fields, data lakes can be used to store data from diverse sources, such as genetic sequences, patient records, and clinical trial results. Machine learning algorithms can be applied to this unstructured data to identify patterns or correlations, aiding in uses from the development of personalized treatments to predicting disease outbreaks. Furthermore, algorithms can analyze real-time data from medical devices to monitor patient health and alert caregivers to any significant changes (See IoT above).
Data Warehouse Applications
  • Sales Analytics: Data warehouses can be used to store and analyze sales data, allowing organizations to identify trends, track performance, and make data-driven decisions to improve sales strategies. The structured nature of data warehouses makes it easy to create sales reports, dashboards, and visualizations.
  • Customer Segmentation: By analyzing customer data stored in a data warehouse, organizations can segment their customer base and tailor marketing efforts to target specific demographics. Data warehouses can store structured customer data, such as purchase history and demographic information, enabling organizations to create detailed customer profiles.
Example Use from Financial Industry Regulatory Authority (FINRA)

A great example of a company utilizing AWS services to build a data lake is FINRA. FINRA leverages AWS to store and analyze over 500 billion market events daily, enabling them to detect fraud and market manipulation.

FINRA’s data lake, built on AWS, processes and stores vast amounts of diverse data types, including trade data, order data, and reference data. By using Amazon S3, FINRA can store and manage their data cost-effectively and securely, while Amazon EMR and AWS Glue enable them to process and analyze the data to identify potential violations.

You can learn more about this use case by reading the AWS case study for FINRA.

Conclusion

Data lakes and data warehouses serve different purposes and are suited for different types of data storage and analysis. Understanding the differences between these two storage paradigms is essential for organizations.

Once you’ve determined which path is right for you, be sure to build data resilience into your strategy. Keep an eye out for my next blog, which discusses advanced techniques for data resilience in RDS data warehouses and S3 data lakes.

Happy reading!

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The digital landscape is evolving. Cyberthreats have become more sophisticated, data estates are growing, and IT resources are shrinking. Today’s organizations need a more proactive approach to protecting their data in an ever-changing threat landscape. And while traditional data protection solutions may play a pivotal role in recovering post-attack, they are reactionary, narrowly focused, and no longer sufficient.

Cyberthreats today are designed to silently bypass perimeter defenses and inflict pain in ways that traditional backup and recovery solutions cannot combat. The threat of data exfiltration, theft, and damage is now more prevalent than ever and can be devastating to businesses if not addressed.

Proactive, Layered Data Protection

To address these cyber threats, organizations must look beyond conventional security tools and take steps to ensure data resiliency. This requires a proactive approach with layered protection, also known as defense in depth. It is the practice of implementing multiple tools and measures to protect against a wide range of threats. Each layer has a specific function, working in unison for multi-faceted protection for your environment. Commvault applies this very principle to data protection, uniquely delivering the right breadth of detection, security, and recovery capabilities to actively secure, defend, and recover data broadly across production and backup environments.

Layered protection that actively defends data and its recoverability across the industry’s
broadest set of workloads

Secure

Hardened, zero-trust, immutable architecture with built-in security controls to secure data, prevent unwanted access and data exposure, and drive compliance in the face of evolving cyber threats.

Defend

Patented early warning and in-depth monitoring to surface and neutralize zero-day and insider threats before they cause harm; containing breaches, limiting windows of exposure, and flagging malicious activity sooner to reduce recoveries.  

Recover

Proactive and reliable recoverability across on-prem, cloud, and SaaS workloads proven to reduce downtime, prevent reinfection, and accelerate response times for unrivaled business continuity.

Innovative Data Protection with New
Products and Services

We are pushing the boundaries of data protection in this modern world, and redefining how businesses of every size combat risk, minimize threats, secure entire data estates, and drive better business outcomes. We are setting a higher standard for customers’ security posture and delivering the best value in data protection. New products and features include:

  • Commvault Auto Recovery delivers complete cyber recovery and business continuity, both on-premises and in the cloud, providing secure, reliable, and near real-time cyber resiliency.
    • Recovery orchestration with one-click recovery of clean copies across workloads to production after validating and sanitizing recovery points.
    • Recovery validation to continuously validate backups, demonstrate recovery readiness, and reduce recovery testing complexities.
  • Commvault Cloud Command provides customers global visibility and actionable insights across SaaS, cloud, and on-premises through a SaaS-delivered unified platform. It enables standardization of security postures and simplifies data risk management to make optimal decisions for recovery readiness.
  • Commvault Risk Analysis identifies, categorizes, and classifies sensitive data such as personal, financial information, and intellectual property to prioritize security efforts and take action to reduce data exfiltration.
  • Commvault Threat Scan allows organizations to scan backup content to identify malware and files that have been encrypted, corrupted, or significantly changed to recover clean data and avoid file reinfection.
  • Security ecosystem expansion with bidirectional integrations with SIEM & SOAR platforms to meet compliance and improve your security posture by helping to align your response time through automatic actions.
  • Dynamic Credential Management integration with CyberArk to minimize the risk of stored credentials for workload protection on demand, allowing organizations to securely manage credentials within CyberArk rather than within the backup environment.
  • ThreatWise Advisor assesses backup environments and intelligently recommends decoy placement to further harden critical workloads and reduce the cognitive load for users.

Delivering a proactive and reliable recovery across the industry’s broadest workload coverage is proven to reduce downtime, thwart data loss, and accelerate response times. Businesses will benefit from our end-to-end insights and observability across the entire data protection lifecycle to anticipate risk, proactively minimize threats, control data (and its access), and drive more informed recovery outcomes.

Organizations of all sizes can feel confident that with the help of Commvault’s advanced data protection and recovery solutions, you can become the face of the next generation of data protection: Data, Secured. Data, Defended. Data, Recovered.

To learn more, use our buyer’s guide to map your current cyber security protection and recovery capabilities and determine how best to optimize your readiness plan across hybrid, cloud, or SaaS workload environments.

Watch our video on Data Protection Redefined as our mission is to secure, protect, and recover all your data with the world’s only unified data protection platform, which has the lowest TCO of any solution that even comes close.

Visit our web page to learn.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

As a leader in data protection and security, Commvault values its partnerships with industry leaders, including Dell Technologies. Together, we are committed to designing, integrating, and delivering innovative solutions that meet the needs of customers. An open and extensible ecosystem is essential for the 100,000+ organizations that rely on Commvault solutions. Sanjay Mirchandani, Commvault’s CEO, explains it simply, “Integration needs to be built-in, not bolted on.” This philosophy provides that Commvault’s solutions work seamlessly with other technologies.

The new integration between Commvault and PowerProtect Data Domain delivers immediate value for PowerProtect Data Domain customers with:

  • Simplified configuration through native API-based integration
  • Improved security posture
  • Customers can leverage existing data protection plans without creating new full backups

The integration of Commvault and PowerProtect Data Domain introduces a simplified native API-based integration. This new capability allows customers to seamlessly integrate with existing PowerProtect Data Domain systems without needing the BoostFS plug-in. This reduces complexity and significantly cuts down the time it takes for customers to begin protecting their data.

Commvault customers can continue to leverage their existing data protection policies and avoid having to create new full backups or worry about increased backup set sizes thanks to the new API-based integrations. Enabling this new capability is as simple as adding a new storage unit for Data Domain Boost with valid credentials in Commvault Command Center.

Historically, Commvault has supported PowerProtect Data Domain systems as repositories, but they had to be configured as Common Internet File System (CIFS) or Network File System (NFS). The new integration enhances the security for backups with native encryption and direct data transfers without mounting a CIFS or NFS file system on the appliance, reducing the attack surface for ransomware.

Customers that leverage Security Enhanced Linux (SELinux) will also be able to natively leverage the new integrations. Providing a more secure environment where users can be confident that their data is safe from unauthorized access or manipulation.

Having a reliable and secure backup solutions is key when it comes to protecting your business’ data from cyber threats. We’re thrilled to be joining the Data Domain Boost ecosystem and continue to look for other opportunities to enhance this integration even further in the future. For organizations looking for a powerful combination of tools to protect their data, Commvault & Dell Technologies have the complete solution you need!

Make sure to subscribe to our blog for regular updates, as we’ll detail the integration process steps in the coming weeks. Sign up for our community forums to stay current on all the latest announcements, ask questions, and interact with our vibrant online community.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Last week, we hosted our FY24 Global Company Kickoff – a time when our entire Vaulter community comes together to kick off the start of our fiscal year, hear from our leadership team on our strategy, and celebrate how we’re going to continue to win together!

Yet here’s the thing – winning together can only happen if we are able to support and show up for each other. We show up for each other in bigger moments, but also (just as importantly) in smaller moments each day. Here at Commvault we always have each other’s backs, and this type of culture defines who we are.

During our Kickoff event, we had the opportunity to hear from our Vaulters across the world on how they’ve felt supported at Commvault. These are the moments that matter!


As I listened to their perspective, I realized that all our efforts – from connecting, inspiring, caring, and delivering – are rooted in trust. The trust we’ve built with each other, the trust we’ve built through our relationships with our customers and partners, and the trust we’ve built through our outreach and support of the communities we live in.  

The foundation of trust is knowing that someone is going to show up for you. They have your back. So that’s why in FY24, we are recommitting to showing up for each other and continuing to strengthen the incredible foundation we’ve laid over the past 27 years.  

Here’s to an amazing FY24!

Check out your next opportunity by visiting our careers site here https://careers.commvault.com/us/en  

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The threat from ransomware continues to be an unfortunate daily reality for technologists and security professionals. But, before we talk about “doom and gloom” we should recognize how far the industry has come. I would argue in the not too distant past, most companies were susceptible to what we would consider a relatively unsophisticated ransomware attack. Open Email -> Malware -> Network spread -> Ransomware ->

With the advancements primarily in the endpoint space, adoption of work from anywhere, and zero trust principles, the industry has made significant advances in protecting against these types of attacks.

Still, every week we see new articles on successful ransomware attacks. Many ransomware report trackers actually show an uptick in 2023. For instance Black Fog’s The State of Ransomware report shows an 8% uptick year over year. In addition, we see actors starting to target data storage outside of what traditionally is attacked, such as cloud storage and cloud databases.

“”If we truly have made advances against ransomware, why the increase in successful attacks?“”

It’s all about priorities

In analyzing these successful attacks, I’ve identified two primary categories where the system breaks down, allowing malicious actors to succeed in ransom style attacks.

  1. Lack of investment in an information security program. At the surface this seems obvious, and it is. You pay for what you get. Organizations with big-budget security teams suffer fewer ransomware attacks (with exception discussed in the next category).It’s easy to put on your curmudgeon hat and say “Well people just need to take this more seriously, and spend more on security!” The reality is most attacks we see in the news resulting from a lack of investment are against public services. Many of these organizations are simply not financially equipped to invest in the staff, time, and “cutting edge” technologies that can stop attacks. I’m going to end the thought there as it’s a different blog on politics, public policy, and unification. Public spending is not a topic that can be glazed over. But, the next category we as an industry can tackle more easily.
  2. We have on blinders. I understand this is a big statement, but when the topic is approached correctly, I often hear vigorous agreement that this is the case.
    When I say we have blinders on, I mean we are not fully vetting the risk model of ransomware. We are too focused on how common attacks succeeded to see where we have gaps in our security programs. We focus on protection of endpoints, servers, and traditional data storage technologies (SAN, NAS etc) and consequently succeed in protecting those assets from attack.

At the end of day, a threat actor who wishes to hold data for ransom only has to accomplish one task: deny availability of critical business data.

Many companies are more focused on controls for preventing attacks than implementing a holistic strategy to protect availability. In other words, don’t focus only on the ransomware attack, focus on a more general availability protection strategy inclusive of “data encryption for impact” (ATT&CK ID T1486.)

For example, many ransomware playbooks are focused on the idea that an actor could execute a binary payload and encrypt data. But the same effect could be achieved, given sufficient access, by simply swapping encryption keys on a critical database. The degree of difficulty for an attacker to pull this off varies wildly, but for many organizations it is a valid attack path. Don’t be too quick to point out that native DB backups, multi-versioning etc. can solve this. It’s not wrong by any means, but the reality is that due to performance impacts on large databases, these controls are often disabled and you may or may not be informed. In addition, management of these protection methods are often done from the same privileged credentials as normal admin activity, which are the credentials targeted by threat actors.

Okay…. but what does that mean…

All in all, it means you should revisit your ransomware playbook and consider making a top-level availability playbook if you don’t have one already (If you do, revisit it with a ransom lens). This should be a cross-functional effort. The security team should take a first pass, then sit down with data owners, infrastructure teams, and DR/BC teams to brainstorm on the most realistic protection and recovery methods. Many protection and recovery methods come with a performance trade off. Security can not ignore this reality, and IT can’t ignore security in favor of performance. There is no one size fits all answer.

The following can be used as a loose starting point for what to think about in this effort:

  1. Understand all critical business data stores, including:
    • “Private” managed data stores, NAS SAN
    • Employee devices
    • Databases (both on-prem, traditional cloud abstraction, and  as-a-service
    • Cloud storage
  2. Create a list of tactics, techniques and procedures that can be used to impact availability of your critical data stores and map to MITRE ATT&CK. (https://attack.mitre.org/tactics/TA0040/)
    • Ex 1: Mass encryption of endpoints
    • Ex 2: Theft and deletion of critical data stores (Cloud and on-prem)
  3. Map tactics to data sources, and rank based on likelihood of occurrence.
    • Prioritize based on a legal, operational, and strategic risk
  4. Evaluate controls and processes
    • Identify opportunities to implement controls for prevention, detection, response, and recovery by data source.
    • Identify gaps
    • Create new processes and controls
  5. Update your ransomware response playbook with response methods for all techniques based on your response and recovery procedures from step 4.
  6. Run a joint table top exercise (TTX) and DR exercise at the same time.
    • This is a real challenge. Combining the two to perform a “open book” TTX with some random injects will really show how the teams work under the pressure of a real ransomware incident.

Summary

Threat actors keep evolving to stay relevant and protect their income. Although we have gotten pretty good at protecting against traditional ransomware threats as an industry, every organization likely has a few blind spots. 

  • Ransomware attacks keep succeeding. 
  • As we get better at stopping traditional attacks, threat actors change their tactics to maintain success 
  • Threat actors are targeting data stores such as DBs and cloud storage 
  • Update your response playbook with detect, prevent, respond and recovery options for non-traditional availability recovery
  • Implement immutable and performant backup solutions for DBs and cloud assets.

How Clumio Helps

Clumio focuses on helping customers build resilience into their cloud applications and data. When it comes to ransomware, recovery is a key backstop to maintaining your business application availability. With Clumio’s backup options for databases like Amazon RDS, MS-SQL on EC2, and DynamoDB as well as Amazon S3, EC2, EBS, and Microsoft 365, you can create performant recovery strategies to make both infrastructure and security teams happy. 

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Do I need to backup my AWS environment?

As businesses rely on AWS for their critical operations, it becomes imperative to protect the underlying data against threats and keep up to date with compliance and user requirements. While AWS is well-known for its infrastructure resilience, it is the customer’s responsibility to protect their data. AWS does provide many resources and services to help protect data, but for many organizations, going with a specialized vendor works out simpler and cheaper. A robust backup strategy can provide peace of mind by ensuring that the company’s data is safe and can restore in the event of data loss.

A cloud shaped drawer full of files being pulled out of a server stack. Represents the customer responsibility for backing up and protecting data within the resilient AWS infrastructure.

What AWS services should I backup?

While your application architecture may be dependent upon many services, the ones housing your critical data should in most cases, enterprises emphasize the protection of Amazon S3, used for storing objects and files, and Amazon EBS, used for storing data on virtual disks. Amazon RDS, a managed relational database service, and Amazon DynamoDB, which offers a NoSQL database solution, are the other critical services to backup. Each of these services may play a vital role in the operations of your business, and backing them up will ensure that you can recover from any data loss or corruption.

What are the security best practices in AWS?

The most effective approach to backup AWS services depends on the application dependencies and its retention and recovery policies.

For business-critical services, it is important to backup data every few minutes, and keep them for as long as the most stringent compliance requirements. Amazon provides some ways to do this. For example, Amazon EBS snapshots can backup Amazon EBS volumes, while Amazon RDS snapshots can backup Amazon RDS databases. Also, some AWS services, such as Amazon S3 Glacier, support cross-region replication, which allows you to maintain a secondary copy of your data in another region. But, snapshotting or replicating each AWS service might not meet your applications recovery time and recovery point objectives. AWS also offers more granular backup tools such as AWS Backup and versioning, but the data from these services will live within your organization’s AWS account, putting it at risk in case there is a breach

A holistic way to do AWS backup is to identify a SaaS backup software vendor that backs up a large suite of AWS services, does so without the need for snapshot replication, identifies potential risks and events, scales no matter how much data you want to protect, and does so at a competitive price-point. Whichever approach you choose, it’s important to test your backups to ensure that they can be restored

Does AWS protect my data?

While AWS handles securing the underlying physical and network infrastructure that supports your workloads and data, You are responsible for securing the workloads and data you deploy in AWS. This is called the Shared Responsibility Model, and is a fundamental part of how AWS operates. Data security is the responsibility of the customer. This includes ensuring that sensitive data is encrypted and backed up, as well as implementing proper access controls to restrict who can access your data. Also, customers must also ensure that their applications and systems are patched against known vulnerabilities AWS provides a number of services and features to help customers secure their data, but it is the customer’s responsibility to implement these properly. AWS takes security very seriously and works hard to protect customer data. Yet, it is important to remember that customers have the primary responsibility in ensuring their data is secure.

What is the shared responsibility model of AWS?

Shared responsibility model means that AWS is responsible for the security of the cloud, and the customer is responsible for the security in the cloud. In simple words, it means that data is the responsibility of the customer. Shared responsibility model provides customers with control over their own data, letting them implement their own protection policies and air-gaps, and use the tools to best recover their data in the event of data lossThe Shared responsibility model is based on three pillars:

  • Security of Data: The customer is responsible for securing their data. This includes encrypting data and backing it up regularly, as well as ensuring access control.
  • Security of Infrastructure: AWS is responsible for securing the underlying infrastructure that customers use to run their applications. This includes physical security, network security, and host hardening.
  • Operational Security: both AWS and the customer are responsible for operational security. This includes tasks such as patch management and log monitoring.

What is the difference between AWS snapshots and backups?

Backups are a copy of data that can be used to restore lost or damaged files, while snapshots are a copy of the state of a system at a particular point in time. Both have their own advantages and disadvantages, and it’s important to understand the difference before deciding which to use. AWS snapshots are incremental, meaning that only changed blocks are copied since the last snapshot. This makes them very efficient in terms of storage space, but it also means that more work is required to restore a system from scratch using incremental snapshots. Backups, on the other hand, are full copies of data that can be quickly restored in the event of data loss. However, this also makes them more expensive to store and can result in a longer recovery time if a lot of data has been lost. There are multiple AWS partners – such as Clumio – that provide extreme efficiency in backups that provide all the benefits of backups at a price point that’s comparable to snapshots.

What are the key factors to keep in mind while backing up AWS?

When it comes to backing up data in the cloud, there are a few key things to keep in mind. First, recovery time and recovery point are essential. How quickly do you need to be able to access your data in the event of an outage, and how much data can you afford to lose? Second, your choice of backup solution should be simple to use and understand; the last thing you want is a complex system that’s difficult to manage in a time of crisis. Third, price is always a factor. How much are you willing to spend on backing up your data? And if you want to build it yourself, can you afford the engineering costs and complexity associated with it? Keeping these factors in mind, you can ensure that your AWS S3 backup is as effective as possible.

Is backing up AWS difficult?

Backing up data is a nuanced process, and if building a backup solution on AWS, users must have a deep understanding of the platform in order to properly configure their backup plan. Additionally, because AWS offers so many different storage and computing options, it can be difficult to know which service is best for backing up data. For this reason, many businesses choose to use turnkey SaaS backup tools from AWS partners, such as Clumio. These tools provide an easy-to-use interface for configuring backup plans and can automate many of the complex tasks involved in data protection. Moreover, they provide an air gap against ransomware attacks, as well as extreme storage efficiency and scale. Backing up AWS services need not be complex, but the right solution depends on the application, expertise of the user, and the services being protected.

How can I backup AWS?

AWS provides a first-party tool called AWS Backup that backs up many services such as DynamoDB, Amazon EBS, Amazon EC2, Amazon RDS, and Amazon S3. You can use AWS backup to protect your databases, storage volumes, and file systems. AWS backup uses incrementally updated snapshots to provide point-in-time recovery for your data. However, if you want to simplify your backup infrastructure to free up your engineers to focus on driving business value, you may want to consider using a turnkey third-party backup solution such as Clumio.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

We live in interesting times, don’t we? Data has reshaped business, how organizations operate, and what customers expect. It’s a hybrid cloud world, where companies have more data in more places, on more apps and different platforms than ever before. And AI is on the verge of changing everything in profound ways. 

All of which makes data the most critical asset you own, the heartbeat of your organization. In short, there’s nothing more important than ensuring its security and protection. 

Too bad the space is full of hype and me-too claims that all sound alike. To make smart decisions requires clarity. But some vendors seem more dedicated to throwing shade than grasping the dimensions of the problem. Trying to convince you that the only answer is a volume play—multiple solutions, more tools, more backup or a new partnership marketed heavily as solving a customer problem, but in reality, is only solving a gap in vendor capability or a workload coverage issue.

But are these claims really true? Or are they just relying on a lot of flashy buzzwords to make up for the shortcomings in their own offerings? It’s kind of insulting if you think about it—as a smart tech buyer, aren’t you going to see through this stuff?

Questions well worth asking. I did when I first joined Commvault. My take on marketing technology is simple: you find out what your product does better than your competitors and find a smart, compelling way to talk about it. You don’t lie. You don’t exaggerate. You explain.

Let’s start by explaining that Commvault protects the broadest range of workloads of any vendor. As the ultimate data protection for today’s hybrid cloud world, we cover on-premise, private and public cloud, SaaS, and almost anywhere your data lives.

1st and Only

Fully managed DPaaS to support multiple clouds.

1>6

syncreon saved $500K by consolidating six backup solutions into one.

So, when some new competitor starts labeling us as “legacy data protection”, you’re smart enough to know that really means they’re trying desperately to keep up with our multi-cloud SaaS Data Protection, cloud air-gap, and integrated threat deception technology. 

When they call our protection of a broad range of workloads  “complex”, you’re not about to confuse flexibility with complexity. Flexibility, good. Complexity, bad. Ironically, the same vendors doing this are also forcing customers to adopt and manage separate point solutions. And what does that bring with it (in addition to cost and risk)? Say it with me: complexity.

100% Protected

Commvault supports all types of workloads; it is literally universal. Metallic runs in the cloud, but Commvault has not forgotten the importance of protecting on-prem workloads.1

Now let’s talk about security. I’ve seen companies sell their products as the “only” or “best” Zero Trust security. Well, for one, Zero Trust is a comprehensive approach. Not some bolt on capability. In a hybrid world, data security only works, as it does in Commvault, when it’s built in, pervasive, has the capability to also defend beyond breaches, and guards backups, as well.

5 min vs. 24 hours

Commvault detects threats faster.

3x Lower

TCO in the Cloud than Rubrik and Cohesity.

Which brings me to my last point. A lot of what some competitors label as “unique” to them—immutability, zero trust, backup monitoring—are actually just table stakes in a robust data protection solution, like Commvault.

Don’t just take our word for it. Listen to what our customers have to say:

We were looking for an offering that could protect the many key platforms deployed across our environment, and Cohesity couldn’t check either of those boxes.

– Jeffrey Day, IT Security Architect at Nevada Department of Transportation


We hear this a lot actually; “To scale you need more boxes, more, more”.  But in data protection, bigger doesn’t mean better, and it certainly doesn’t mean smarter.  It adds more of the things you don’t need: cost, complexity and risk via a bigger cyberattack surface. 

With something as critical to the success of your business, there really isn’t room for fuzzy claims and fudged execution. A hybrid cloud world demands comprehensive data protection that gives you options (not complexity), delivers proactive security, active data defense, and rapid recovery through a single, gap-free platform. Without add-ins, bolt-ons, and upsells. It’s time to cut through the noise and deliver effective solutions, so you can focus on what really matters—running your business.

Visit www.commvault.com/questionit

Sources:

1. ESG research (From Data Backup to Data Intelligence, January 2022)

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

“We’re #1! We’re #1!”

When the dust settles on championships, that chant is heard in stadiums worldwide. High score wins, the trophy is held aloft (tossed, if you’re Tom Brady), and the celebration begins alongside Queen racking up more well-deserved royalties.

But how do you determine who’s at the top of the mountain in the data protection world? Ensuring the integrity of your crown jewels in the cloud or on-prem is not a game that ends after a preset period – it’s an ongoing battle that rages 24 x 7 and is fought by CISOs, IT Managers, Database Administrators…the list goes on. It’s complicated, requires adaptable strategy, dedication to the cause, and relentless ambition to best bad actors.

As a result, it’s always an interesting exercise to unpack claims of dominance in this market. Some are true (but come with asterisks), some are highly debatable, some are false, and others are flat-out hyperbole. Let’s look at how one vendor positions their claim of being the best.

Subjective vs. Objective…vs. the Real World

Right out of the gate, we need to understand that many cloud claims rely on two dimensions: subjective (open to opinion) and objective (factual). However, let’s not forget about what we call “real-world” claims – this is what directly impacts your business, and how you use the cloud to run it. Examples:

  • Objective claim: “81% of the Fortune 500”
    • Assuming this is correct in some capacity, there is no context to support it. 81% tried the product? Bought the product at one time? Have been using it for more than a year?
    • Is your company in the Fortune 500? If not, the message is “If it’s good enough for them, it’s good enough for you.” See? Now it’s become a subjective claim.
    • Do you have the resources/budget of a Fortune 500 company? If not, how does this help you?
  • Subjective claim: “We protect everything”
    • Everything means every single kind of data in existence, from every vendor. Which certainly encompasses every cloud workload.
    • In this case, the vendor making this claim actually does not backup certain workloads for Azure databases.
    • Are you in the Azure cloud? If so, how does that statement sit with you?

Which brings us to the real-world aspect. We know that 80% of all enterprises have a hybrid cloud strategy1…and once you are in the cloud, you’re going to stay in the cloud. You may be multi-cloud, public cloud, or hybrid cloud, but make no mistake, you’re invested. So why do broad claims like the above exist?

Because assurance is hard to come by in the real world.

And because trusting is easier to do than verifying.

14M M365 users? Ever wonder how many of those are using the free version of the app? It’s a significant number – which means you’re not being given the complete picture.

Fact: peace of mind means different things to different businesses. Different clouds, different workloads, different skill sets, different levels of security in place. They all come together to form your personal cloud strategy. And at the end of the day, what matters is that your data can be restored to its pre-attack/incident state and is 100% intact, regardless of where it resides or what workload(s) are being made whole again.

That’s the claim that matters. That’s the real-world cloud claim. Full stop.

At Commvault, we make assertions about how we stack up very, very seriously. Any claims we make are objective and rooted in 3rd-party validation, and of course, fact. There’s no better way to be transparent, and we’ve been doing so for over 26 years. Our customers and partners rely on that to defend, secure, and protect their data, day in and day out.

Are you making decisions that impact your business based on claims that at best, are not applicable to you, and at worst, completely false?

“Just the Facts, Ma’am”

The concept of Data Protection has evolved. It’s no longer sufficient to just provide backup – data protection solutions/services/platforms must now include features such as data security, analytics/insights, governance, compliance, data management, data mobility/migration, transformation, and of course, recovery. Many less capable vendors have been forced to approach this via acquisition partnerships/OEM, or via other more fragmented approaches with multiple tools.


Commvault is different.

There is an extensive list of achievements in the data protection space pioneered by us as the first to deliver on them – and in some instances, still the only vendor to do so. Consider the following:

  • First to launch fully managed DPaaS offering supporting multiple clouds (Metallic®).
  • First to launch cloud air-gapping (Metallic® Recovery Reserve™).
  • First enterprise data protection solution to support containers and Kubernetes (2017).
  • The only vendor with support for many cloud-native applications (AuroraDB, CosmosDB, OCI, more) that other vendors cannot protect.
  • The only vendor to support protecting all Azure PaaS databases.
Being #1 Means Cloud Security is Built-In–Not Bolted On

Many vendors overplay their support for immutability (either directly or via third parties) as sufficient data security, but if you don’t know you even have corrupted data, how can you truly be “protected”?

Immutability is table stakes, but it’s not enough. Without air-gapping, detection, and other layers of data security you end up with ransomware-infected immutable files. You need more than just immutability as part of your solution – things like:

  • Metallic® ThreatWiseTM cyber deception and early warning solution.
  • Support for the air gapping, – to include tape.
  • Granular “clean” recovery, ensuring ONLY the bad data is “purged,” but the good data is still available.
  • No additional tools or third-party support required.
  • Cloud extension for immutability without the need for appliances.
  • No need to LOCK the entire backup copy when corrupted data is found – which means that good data is getting thrown out with the bad, which equals data loss.
Being #1 Means Reducing TCO (or “Show me the money”)

Finally, let’s cut through the marketecture and jargon/rhetoric around TCO used by some vendors to lay claim to that #1 positioning. Today, TCO is a close second to security in terms of what you need. So, while saying things like “1.1M average cost savings” is (again) highly subjective depending on your company size, consider what real TCO looks like in any given situation:

  • True SaaS means zero infrastructure to manage; a control plane in the cloud does not mean SaaS.
  • Deduplication saves data ingress/egress charges.
  • Compression means less data mobility and more savings.
  • The ability to scale your solution up AND down depending on need – not just scaling up if demand is reduced or workloads shift to other clouds/platforms.
Being #1 Means Complementing Cloud Native Capabilities

The cloud offers data resilience, which is important to ensure that your data and applications are always available, but does not protect you from data corruption, malware, or other related incidents – you end up with highly resilient “bad data.” Data protection is critical for cloud native and SaaS-based applications.

And because being able to protect any application is the name of the data protection game, how does one claim to be #1 in modern data protection without that? Commvault offers best-in-class data protection for traditional, hybrid, cloud, modern, and containerized applications as part of a unified service and console – eliminating the need for multiple, overlapping tools. Offering the broadest spectrum of workload coverage in the industry, Commvault drives “hard cost savings for Microsoft customers” according to ESG. And the Gartner Magic Quadrant? A leader the last 11 years in a row. Add to that leader status for the most recent GigaOm Radar Hybrid Cloud Data Protection report, and you know you’re in good hands.

Wrapping up, we’re not here to debate our position on the data protection leaderboard, although we do think our case for sitting at the top is strong. The way our 100,000+ customers see it, with over 3.8EB having been moved to the cloud, Commvault is the global leader in hybrid cloud data protection. We’ve been doing this for 26 years, nearly all of it with our foundational partner Microsoft.

The TL; DR? Ask your vendor if your data is being secured, defended, and recovered with 100% efficiency, for the right workloads, in the right places, by the right vendor – both now AND in the future. You might be surprised by what you find.

Take a test drive of Commvault today https://www.commvault.com/request-demo

Reference
1. State of the Cloud Report, Flexera, 2022

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Here at Commvault, our four values – we connect, we inspire, we care, we deliver – are foundational to everything we do.

This week we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work as they live our values every day.

I’m so proud to announce our FY23 Q4 CEO Living Our Values Award winners:

Stephanie​ Cunliffe
Director | Business Systems Analysis

Jennifer​ Kelly
Administrative Assistant/Receptionist

Leah​ Flynne
Director | Compliance

David ​Stupar
Manager | Customer Success

Metallic Site​ Reliability Team

Justin Avignone​
Manager | SRE – Application

Karunakar Bojjireddy​
Director | Cloud Operations SaaS

Peter Coviello​
Senior Director | Applications, Engineering

Prashant Jayram
Senior Data Solutions Architect

Alex Piccolo
Data Scientist 2

Reddi Prasad​
SRO Engineer

Firoz Sahib​
Manager SRE

Siddhant Saini​
Director | SaaS Operations

Shankaar Thiagarajan​
Senior Architect


All these winners set an inspiring example and embody what it truly means to be a Vaulter!

To learn more about what it’s like to work at Commvault, check out our careers site.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Data resilience in the cloud can be fuzzy, and organizations at different stages of cloud maturity and use-cases approach resilience differently. To help cloud adopters evaluate where they stand compared to their peers when it comes to cloud data protection, Clumio recently worked with Enterprise Strategy Group (ESG) on their research report titled Data Protection Cloud Strategies at a Crossroads. Here are a few key takeaways to get you started:

Secondary data is first in volume

Most cloud environments contain more secondary data than primary data! About 61% more to be precise.

Source: Enterprise Strategy Group, a division of TechTarget, Inc. Research eBook, Data Protection Cloud Strategies at a Crossroads, May 2023

According to survey respondents, the estimated mean of secondary data in the cloud is 2.9 PB out of an estimated mean of 4.7 PB of total cloud data, meaning the primary data would account for only about 1.8 PB!

This indicates that for enterprises looking to optimize cloud data costs, secondary data is the place to start. You might find orphaned snapshots, unused replicas, or excess versions. It’s also a good idea to take a look at your backup spend. Could you be more efficient with it? We have a few ideas for you. 😉

ABA (Always be Assessing)

If you feel like your company reassesses its data protection strategy frequently, you’re in good company.

Source: Enterprise Strategy Group, a division of TechTarget, Inc. Research eBook, Data Protection Cloud Strategies at a Crossroads, May 2023

41% of survey respondents stated they reassess or rearchitect their cloud data protection strategy annually, and 16% said they do so on an ad hoc basis. Organizations were 4 times more likely to reassess or rearchitect cloud data protection strategies on an ad-hoc basis than on-premises. Not so surprising, when you consider the rapid scalability and constant innovation of the cloud.

Can you recover all of your data?

Here’s a surprising insight: Only 11% of respondents indicated that when recovering data, they had been able to recover 100% on average.

Source: Enterprise Strategy Group, a division of TechTarget, Inc. Research eBook, Data Protection Cloud Strategies at a Crossroads, May 2023

The takeaway: If you haven’t tested your data recovery lately, you should! Make sure you’re 100% ready to recover 100% of your data.

 

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Last month, we closed out our International Women’s Day and Women’s History Month celebration with a Courageous Conversation about working parents, the struggles of fertility, and pregnancy loss. Today marks the start of National Infertility Awareness week here in the U.S., so I wanted to share more about our recent event and how we’re supporting the women of Commvault, as well as our working partners, as they navigate these challenges.

Our Courageous Conversations are global, virtual events that are a core component of our DE&I strategy. They allow us to connect, support, and inspire each other by having open discussions about topics that are close to our hearts.  As our Chief People Officer Martha Delehanty always says, “you need to have the conversation, to change the conversation.”

During the event, we heard from our Vaulters Lisa McGahran, Stephanie Joyce, and Elliot Hujarski as they discussed their personal journeys with fertility and pregnancy loss. We also had guest speaker Stacey Skrysak join us to share her own story and how she’s helping others by being a voice for premature birth, child loss, and infertility. This Courageous Conversation was so powerful and important for our Vaulter community – our speakers courageously opened their hearts to share their stories with us as we talked about how grief and hope can co-exist.


Infertility and pregnancy loss are, unfortunately, very real issues that many women in the workplace (as well as their partners) deal with today as they continue to navigate their careers. At Commvault, we continue to show our commitment and support for not only our working parents, but those aspiring to be parents as well.

The power of hope, positivity, and support is what guides us all each day. We’re proud to support the wellness of our Vaulters and give them the resources they need throughout their journeys.  

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago