Skip to content

Key Takeaways

  • Commvault is introducing a Dedicated Tenant model that delivers an isolated SaaS environment for organizations with stringent security, sovereignty, and control requirements.
  • AI-enabled unified governance discovers workloads, classifies data, and recommends protection policies to streamline compliance and risk mitigation across hybrid and multi-cloud estates.
  • The platform helps provide instant visibility into protected and unprotected workloads and their costs, helping reduce risk exposure and optimize TCO.
  • Regional deployment control and separated tenant infrastructure support mandates tied to GDPR, HIPAA, and FedRAMP.
  • Together, dedicated isolation and AI-enabled oversight help enable resilient, forward-looking protection for mission-critical resources in highly regulated industries.

Highly regulated industries like healthcare, finance, and government face mounting cyber resilience challenges driven by evolving regulations such as GDPR, HIPAA, and FedRAMP, alongside increasingly sophisticated ransomware attacks.

Operating across complex hybrid environments – where sensitive data spans on-premises systems, public clouds, and SaaS platforms – further amplifies these risks. The need to help maintain consistent data protection policies, enforce sovereignty and compliance controls, and manage visibility across fragmented infrastructures makes resilience especially difficult.

Commvault has announced two major innovations as part of the Commvault Cloud Unity platform releaseDedicated Tenant and AI-enabled unified governance. This release marks a major step in the evolution of cloud-native data protection, particularly for mission-critical resources in highly regulated industries.

This update brings AI-enabled classification and dedicated, isolated environments to the forefront, empowering modern enterprises to protect mission-critical data and maintain compliance across hybrid and multi-cloud operations.

Dedicated Tenant: Fully isolated SaaS deployment model designed for large enterprises and highly regulated industries that require stringent compliance, sovereignty, and control. It delivers the same award-winning Commvault Cloud experience in a dedicated environment, combining SaaS agility with enterprise-grade isolation and regulatory assurance.

AI-enabled unified governance: Intelligent visibility and automation across hybrid and multi-cloud environments, simplifying compliance, policy management, and risk mitigation. By leveraging AI to unify oversight across data estates, organizations can more easily identify gaps, enforce consistent protection policies, and strengthen overall cyber resilience.

The new platform introduces an AI-enabled experience that automatically discovers workloads across cloud estates and recommends protection policies based on workload classification. This approach is particularly valuable for mission-critical resources and helps enable organizations to:

  • Rapidly identify and classify sensitive data across diverse cloud environments.
  • Automatically apply appropriate protection policies based on the classification of workloads.
  • Gain instant visibility into protected and unprotected workloads, along with their associated costs – helping reduce risk exposure and optimize total cost of ownership.

For industries handling sensitive data, such as financial services or healthcare, this level of AI-enabled classification is crucial. It helps operators protect highly sensitive workloads with the appropriate level of protection, meeting both business continuity requirements and regulatory compliance standards.

Enhanced Protection and Privacy with Dedicated Tenant

For large enterprises in highly regulated industries, Commvault Cloud has released a Dedicated Tenant offering designed for organizations with strict security, compliance, or sovereignty requirements that require strict isolation of compute, network, and storage infrastructure from other customers. It delivers the same features and UI/UX as the standard Commvault Cloud platform, with the added benefit of isolation from other tenants.

This dedicated SaaS deployment option provides:

  • Isolated environments: Customers are provisioned with dedicated SaaS environments that help keep compute, storage, and management resources completely isolated from unrelated tenants.
  • Regional control: The ability to select geographic regions for deployment helps meet sovereignty and compliance mandates.
  • Regulatory assurance: By separating tenant infrastructure, a dedicated tenant helps simplify audits and helps customers demonstrate compliance with frameworks such as HIPAA, FedRAMP, and GDPR.

Unified Governance and Isolated Control

Commvault Cloud’s latest platform release, featuring Dedicated Tenant and AI-enabled classification and governance, marks a pivotal advancement in data protection for highly regulated industries. By uniting AI-enabled classification, compliance intelligence, and dedicated, isolated SaaS environments, Commvault delivers a comprehensive solution for helping protect mission-critical resources across complex, multi-cloud ecosystems.

As data environments grow more distributed and compliance demands intensify, these innovations help empower organizations to achieve operational continuity, maintain regulatory confidence, and build resilient, forward-facing data protection frameworks that evolve with the pace of modern business.


FAQs

Q: What is Commvault Cloud Dedicated Tenant, and who is it for?
A: Dedicated Tenant is a fully isolated SaaS deployment of Commvault Cloud that separates compute, storage, network, and management resources from other customers. It’s designed for large enterprises and regulated sectors that need tight control, sovereignty, and audit-friendly separation without giving up SaaS agility.

Q: How does the AI-enabled unified governance help day to day?
A: It automatically discovers workloads across clouds, classifies sensitive data, and recommends appropriate protection policies so teams can act faster and more consistently. This unified oversight helps reduce manual policy drift, highlight coverage gaps, and prioritize remediation to strengthen cyber resilience.

Q: What compliance outcomes does this release support (e.g., GDPR, HIPAA, FedRAMP)?
A: By isolating tenant resources and providing regional control, Dedicated Tenant helps make it easier to demonstrate adherence to sovereignty and regulatory requirements. Unified governance then maps classification to policies, helping organizations document posture and respond to audits with clearer evidence.

Q: How does this reduce risk and total cost of ownership?
A: Continuous visibility into protected vs. unprotected workloads and their associated costs helps enable targeted remediation and smarter allocation of spend. Automated policy recommendations help reduce administrative overhead and the likelihood of costly protection gaps.

Q: What does regional control look like in practice?
A: Organizations can choose deployment regions for their dedicated environment to align with data residency and sovereignty mandates. This geographic placement, combined with isolated infrastructure, helps support regulatory confidence and operational control.

Q: Will this work across my hybrid and multi-cloud environment without adding complexity?
A: Yes ­– the AI-enabled experience is built to unify visibility and governance across on-prem, public cloud, and SaaS workloads. It helps centralize classification and policy management so teams can operate with a single, consistent model across distributed estates.

Cailin Pitcher is a Senior Portfolio Marketing Manager at Commvault.

More related posts


Thumbnail_Blog-SHIFT-Announcement-Recover-Clean-2025-Linkedin

Recover Clean, Recover Fast

Read more about Recover Clean, Recover Fast
Thumbnail_Blog-SHIFT-Announcement-Commvault-Cloud-Unity-2025-Linkedin

A New Era of Enterprise Resilience

Read more about A New Era of Enterprise Resilience
Readiverse_ShareImage_1200x630

The Conversations That Inspired the Readiverse

Read more about The Conversations That Inspired the Readiverse

Commvault Unveils a New Era in Enterprise Resilience with the Commvault Cloud Unity Platform Release

Commvault, a leader in unified resilience at enterprise scale, announced the Commvault Cloud Unity platform release, one of the most substantive platform releases in Commvault’s history. This next-generation, AI-enabled version of Commvault Cloud now unifies data security, cyber recovery, and identity resilience across cloud, SaaS, on-premises, and hybrid environments.

Commvault Transforms How Enterprises Make Clean, Complete, and Automated Cyber Recoveries

Commvault announced transformative innovations that redefine how organizations recover cleanly, completely, and with fine-tuned automation. Ransomware attacks can attempt to compromise backup storage, leaving organizations vulnerable in their quest to achieve clean, safe, and complete data restorations. Commvault is addressing this challenge from end-to-end.

Commvault Expands End-to-End Identity Resilience: Detect, Log, and Reverse Hard-to-Detect Threats in Active Directory

Commvault announced an expansion of its end-to-end Identity Resilience portfolio – enabling customers to find hard-to-detect threats in Active Directory (AD), automatically log and audit malicious changes, and then rapidly roll back changes to a trusted, clean state. The company also announced advancements to its Active Directory forest recovery offering that helps teams test recovery plans in good times, so they are ready for the bad times.

Commvault Cloud Unity Platform Release Brings New Levels of Simplicity, Scalability, Cost Optimization, and Resilience for Cloud-first Enterprises

Commvault announced the company is setting a new benchmark for cloud-native data protection. Purpose-built for cloud-first and hybrid enterprises, the new release introduces a re-engineered experience designed for simplicity, speed, scale, and cost optimization, as Commvault centralizes resilience operations across clouds, regions, and accounts. With AI-enabled discovery, classification, and protection policy recommendations, this platform is designed to scale resilience in minutes across multi-cloud environments – at the best TCO.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

November is a special month that honors the service and sacrifice of our men and women in the military.

We not only recognize Veterans Day, a day to celebrate those who have served and continue to serve in the United States, but we also recognize Remembrance Day across many of the Commonwealth countries – including United Kingdom, Australia, New Zealand, and Canada – to honor the ultimate sacrifice of those who gave their lives in service to their country. Though the tone differs for each of these days, one celebratory and one reflective, both honor courage, sacrifice, and commitment to something greater than oneself.

How Service and Sacrifice Unite Us Worldwide

These days certainly hold the value of one truth that is undisputed – that service and sacrifice are universal. These are values that transcend borders and unite allies and communities worldwide. As a U.S. Navy veteran currently living in Australia, I am filled with pride to see how this universal spirit of service carries across borders and cultures globally.

Here in Australia, as a U.S. veteran and as a key ally, we are invited to celebrate and be recognized with our brothers and sisters on Remembrance Day. Ceremonies across the nation reflect on the importance of our global brothers and sisters in arms and the ongoing commitment and sacrifices we continue to share on the battlefield abroad and here at home.

The Power of Operating as One Unified Team

The global culture we have at Commvault means that we are all one team, working together on the common goal of defeating threats and protecting our businesses and communities. Our resilience, teamwork, and shared belief that we always have each other’s back reminds me of the values and principles of being in the military and on the battlefield.

Integrating Key Values From Service Into the Workplace

As I reflect on November, I often think about what service means to me. Service is a lifelong commitment to giving with purpose, acting with integrity, and standing up for those who can’t stand up for themselves. It’s about doing what is right, not for recognition, but because it’s the right thing to do. The military has had a profound impact on my leadership style. It taught me to stay calm under pressure, lead from the front, and ensure no one is left behind. These principles have shaped my approach to leadership at Commvault.

Today, my team in APAC knows my three key principles of success: focus, cadence, and discipline. We focus on our goals, establish a consistent rhythm for our business, and maintain the discipline to adapt and persist until we succeed. Other military-inspired leadership principles I practice at Commvault include:

  • Leading with empathy and clarity.
  • Staying mission-focused during change.
  • Building teams based on trust, inclusion, and shared goals.

Like the core values I learned in service, Commvault thrives on resilience, purpose, and the drive to protect what matters. 

Creating a Culture of Community and Belonging

It gives me such pleasure to have served my country and our allies, and I am honored to work for a company that recognizes and supports our veterans. Not only does Commvault value resilience and teamwork, we have wonderful volunteer and community initiatives supporting organizations like Warrior Canine Connection and a dedicated Employee Resource Group – VALOR – focused on bringing awareness to the value our veterans bring to the private and public sector. To learn more about our culture of care, click here.

During this month of November, I encourage you all to reflect and celebrate the sacrifice all our men and women in uniform make on a daily basis. And if you happen to cross paths with an active military member or a veteran today, please make sure to thank them for their service.

Martin Creighan is Vice President, APAC, at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In every customer meeting over the past year, there’s been a moment where the conversation shifts from technology to business strategy to justifying an investment in cyber resilience. No longer are you – as CIOs and technologists – yearning for that seat at the table. It’s yours, and you need to be ready and empowered to lead the conversation.

We’ve Heard You

In thousands of conversations that I’ve had with our customers, I’ve heard three consistent themes:

  1. “Help us connect resilience to business outcomes.”

We know you don’t struggle with understanding backup technology. What we hear are your struggles with articulating why resilience matters to executives who think about revenue, market share, and competitive advantage, not RTO and RPO.

You need ways to translate technical capabilities into business value: benchmark data that shows where you stand compared to peers; quick, digestible perspectives from executives who’ve made these cases successfully.

  1. “Give us insight into what’s actually happening in the threat landscape.”

Security threats are daily headlines. AI-enabled attacks are evolving faster than ever. But which threats actually matter to your business? Which vulnerabilities should you address first? What are your peers seeing in real incidents?

You want curated intelligence, not more noise. You want analysis from people who’ve been CISOs and CIOs, who understand the difference between a theoretical threat and a practical business risk. You need to understand both how AI is being weaponized by attackers and how to secure your own AI implementations.

  1. “Show us what good looks like.”

When I’ve asked you, “Are you ready for the next disruption?”, many of you have honestly answered, “I don’t know.” Not because you lack capabilities, but because you lack clear benchmarks.

You want to understand: What does minimum viable recovery actually mean for your business? Where should you be on the maturity curve? What are the must-have capabilities vs. nice-to-haves? How do high-performing organizations approach resilience differently?

From Customer Feedback to Customer Value

The Readiverse exists because we listened to these conversations. We heard what you were asking for – and we built a destination that delivers it.

This isn’t a content marketing play. It’s not a place to promote products or push sales messages. It’s a purpose-built learning platform designed to make you more successful by giving you what you’ve been asking for all along:

Strategic resources you can use immediately: Readiness assessments, regulatory guides, and intelligence briefs that help you operate more effectively in your role. Bold Takes: 60-second executive perspectives on what matters right now in cyber resilience.

Intelligence that matters to your business: Analysis of emerging threats, market shifts, and regulatory changes, filtered through a business impact lens by experts who’ve been in your seat.

Peer learning and expert insight: Conversations with other CXOs navigating the same challenges. Technical deep-dives from our field experts. Hands-on workshops that sharpen response capabilities.

The Altitude That Matches Your Needs

What makes the Readiverse different is that it operates at two altitudes, because you do, too.

If you’re a CISO or CIO, you need executive-level insight for board meetings and strategic planning. But you also need practical, tactical guidance when you’re pressure-testing incident response plans or implementing new recovery capabilities.

If you’re a practitioner, you need hands-on skills to respond when the alert comes at 2 a.m. But you also want to understand the strategic context so you can grow in your career and contribute to bigger conversations.

The Readiverse serves both mindsets. Both altitudes. Because readiness isn’t just about tools and technology. It’s about building awareness and capability across every stage of the cyber resilience lifecycle.

An Always-On Destination for Continuous Learning

A key insight from all these customer conversations? Readiness isn’t a one-time achievement. It’s continuous.

Threats evolve. AI advances. Regulations change. Business priorities shift. The resilience strategy that worked last year might not be sufficient for what’s coming next. You need a place you can return to again and again, not just for information, but for strategic guidance, practical learning, and community.

That’s what the Readiverse is built to be: an always-on destination where strategic insight meets practical learning. A living platform that grows and evolves as the threat landscape changes. A place you can rely on to stay ready, not just today, but continuously.

Because a great customer experience isn’t just delivering great technology. It’s being a trusted partner who helps you succeed in your most critical mission: helping keep your business ready for whatever comes next.

Discover the Readiverse at Readiverse.com – built from customer conversations, designed for customer success. We can’t wait to hear what you think and keep these conversations going.

Sarv Saravanan is Chief Customer Officer at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Here at Commvault, our values – we connect, we inspire, we care, and we deliver – are foundational to everything we do and why it matters.

This week, we hosted our quarterly Global Town Hall meeting and presented our FY26 Q2 CEO Living Our Values Awards. This award program globally recognizes and celebrates our Vaulters for their incredible work over this past quarter and for living our values each day.

I’m so proud to announce our FY26 Q2 CEO Living Our Values Award winners and our employee-nominated Vaulters’ Choice Award winner below:

CEO Award Winners

Shree Kumar Bakthavatsalam

Shree Kumar Bakthavatsalam

Courtenay Klein

Courtenay Klein

Mahesh Prakash Rao

Mahesh Prakash Rao

Brandon Smith

Brandon Smith

Masao Watanabe

Masao Watanabe


Vaulters’ Choice Award Winner

Mia Watson

Mia Watson

These Vaulters set an inspiring example of what it truly means to be a part of Commvault. To learn more about what it is like to work at Commvault, check out our careers site.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

It shouldn’t come as a surprise, but AI is no longer a trend. It is the foundational capability embraced in every corner of your organization. However, the rush to automate and accelerate an organization’s strategies and processes is introducing new complexities and risks to an organization’s resilience.

The good news is this rapid investment and innovation has enabled us – as CIOs – to have healthier, more productive conversations with senior leaders who want to better understand how AI impacts the organization’s risk and resilience. They are no longer asking if the data is backed up.

Today, our conversations with the C-suite are all about whether we can trust the massive amount of AI-generated data that is being used to drive critical decisions. It forces us to rethink resilience in the AI era. After all, between the complexity and autonomy of AI systems, and the speed and scale at which the data is growing, there are new risks like model bias, data leakage, and an over-reliance on automation.

Consequently, resilience has evolved from just protecting the infrastructure to protecting the integrity of our decision-making capabilities. It’s up to us as CIOs to navigate AI’s use and governance internally as well as our readiness and resilience in the event of disruption or a cyberattack.

At Commvault, we are moving quickly to experiment with AI in ways that add value, but not recklessly. With transparency, accountability, and business alignment as our core principles, we believe governance isn’t a checklist – it must guide decision-making. We’ve also added guardrails around data access, use, and resiliency.

Additionally, the complexity and expansive scale of AI presents new gaps for bad actors to exploit. In response, we are partnering with our CISO and security team. By bringing our resilience priorities, organizations, and systems closer together, we are better able to detect, respond, and if necessary, recover our AI data following a disruption. One team without the other won’t work.

Finally, the AI evolution is also elevating the skills required for IT teams. While technical depth is essential, we need team members who are curious, adaptable, and understand not just how AI works, but how it fits into workflows, governance models, and resilience planning. This includes having strong communicators aligned with the business functions who can help us translate AI’s impact in business terms and measure ROI.

In summary, AI doesn’t replace the fundamentals of resilience; it raises the stakes. The organizations that will thrive are those that can harness AI to move faster and smarter, while at the same time building the guardrails and recovery strategies that keep them strong when things go wrong.

Resilience is no longer just about surviving disruptions. Organizations must create the confidence to innovate boldly, knowing we can adapt and recover at scale. To learn more, I encourage you to register for Commvault’s Virtual SHIFT event on Nov. 19.

Ha Hoang is Chief Information Officer at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Every organization wants to believe it’s ready for a cyberattack. But “ready” and “resilient” aren’t the same thing. Readiness means you have a plan. Resilience means you know it will work – fast, clean, and under pressure. To stay resilient, your cyber recovery readiness must evolve alongside your business and the ever-changing threat landscape.

Read more about cyber recovery readiness planning here.

The goal is to keep your recovery capabilities aligned with what matters most to your organization. That’s where minimum viable recovery (MVR) comes in. Commvault and GigaOm define MVR as the minimum level of recovery performance your organization must achieve to maintain critical operations after a cyberattack.

MVR helps you focus first on restoring your essential business functions, so you can resume operations faster and with measurable confidence.

Download the GigaOm Minimum Viable Recovery Report to explore how you can take readiness to the next level.

Cyber Recovery Minimum Viability Assessment

Understanding cyber recovery theory is one thing. Knowing how ready your organization truly is? That’s another. The Commvault Minimum Viability Self-Assessment helps you close that gap.

In just a few minutes, it evaluates your current recovery capabilities, highlights potential vulnerabilities, and benchmarks your readiness against industry best practices. The result is a personalized report that shows where you stand today and what steps to take next to advance toward MVR – helping your business recover faster, with greater confidence and measurable resilience.

Take the assessment.

Cyber Resilience Workshop

This interactive workshop, offered in cities worldwide, guides participants through the process of creating a robust cyber recovery plan. Using real-world scenarios, the workshop helps organizations develop strategies to withstand and recover from cyberattacks.

Sign up for a workshop.

Don’t Wait to Act

If you wait for a cyberattack to expose your weaknesses, it might be too late. By taking a proactive approach to cyber recovery readiness, you can help minimize the impact of an attack, avoid costly downtime, and support continuous business.

Cyber recovery readiness isn’t just about technology; it’s about having the right mindset, the right skills, and the unwavering determination to protect your organization. It’s also about rigorously testing your recovery plans to validate they work when you need them most. Leverage Commvault’s resources and expertise to help assess your current posture, develop a comprehensive plan, and build a truly resilient organization.

Because in the end, resilience isn’t luck. It’s preparation, proven.

Chris DiRado is Principal Technologist, Product Experience, at Commvault.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • Commvault’s Data Rooms offering transforms backup data into trusted, AI-ready assets while helping maintain governance and compliance.
  • The offering bridges data protection and AI activation without creating new security risks or requiring another platform.
  • It integrates with existing AI ecosystems like Microsoft Azure and Snowflake using open standards such as Apache Parquet and Iceberg.
  • Built-in governance helps enable secure data curation, classification, and sharing within a zero-trust architecture.
  • By activating historical data, organizations can help accelerate AI innovation, analytics, and compliance workflows safely.

AI innovation depends on data – but not just any data. It depends on trusted, governed, and accessible data. Yet for most enterprises, the data that could fuel AI lives deep within backups, scattered across environments, and wrapped in compliance constraints. That’s where Commvault’s Data Rooms offering comes in.

Accelerating AI, Safely

Commvault’s Data Rooms offering transforms backup data – one of the most complete and trusted datasets an organization owns – into AI-ready assets. This new offering helps enterprises safely connect their data to AI and analytics platforms, without creating new risks or complexity.

Unlike other approaches that bring AI models into backup environments, expanding the attack surface and compliance exposure, Commvault does the opposite. We bring governed, policy-controlled data to the AI ecosystems customers already use, preserving their freedom of choice and avoiding vendor lock-in.

The Data Rooms offering is not another AI platform. It’s the bridge between data protection and data activation, designed to make your existing AI investments work faster and safer. It does this by creating governed, policy-controlled “rooms” inside Commvault Cloud – spaces where data can be classified, curated, and shared securely with AI and analytics tools without leaving the protection boundary.

Listening to Customers: No More Platform Proliferation

We heard customers loud and clear: You don’t need another AI platform. You need a secure, simple way to use the data you already protect – across the AI tools and ecosystems you’ve already chosen.

That’s why Commvault built Data Rooms to integrate with partners like Microsoft Azure and Snowflake using open-standard formats such as Apache Parquet and Iceberg. This helps you keep your data portable, policy-compliant, and ready for activation – wherever your AI strategy takes you.

Turning Data Protection into Data Activation

With Data Rooms, authorized users can discover, classify, and prepare data directly from backup repositories – across on-premises and cloud environments. Built-in governance helps maintain control, allowing only approved datasets to be shared, with automated classification, sensitivity tagging, redaction, and audit trails applied every step of the way.

Data Rooms acts as a governed, policy-controlled workspace inside Commvault Cloud – where data can be securely curated and made available to AI or analytics tools without leaving the protection boundary. This governed design provides a secure bridge between backup data and activation workflows, helping organizations unlock their information for innovation while maintaining full compliance and control.

Data Rooms can help you:

  • Accelerate insights: Quickly find and export historical data in AI-friendly formats to train models or power analytics.
  • Simplify operations: Eliminate brittle ETL pipelines with automated data discovery and curation.
  • Maintain compliance: Keep governance intact with policy-based controls and traceability from backup to activation.

Trust as the Foundation for Responsible AI

In the rush to adopt AI, trust often becomes collateral damage. According to a recent study, roughly three-quarters of surveyed IT leaders said that using AI could make their organizations more vulnerable to cyberattacks. That’s why Commvault built Data Rooms within Commvault Cloud’s zero-trust architecture, complete with encryption, RBAC, and audit-ready compliance.

By combining data protection, governance, and activation in one platform, Commvault enables enterprises to accelerate AI innovation without compromising security, compliance, or control.

Accelerate Innovation Without Adding Risk

Commvault’s Data Rooms offering helps organizations move faster by making data safely accessible to the tools that drive their business forward – from AI model training to analytics, eDiscovery, and compliance automation. Because when backup data becomes usable data, enterprises unlock years of historical intelligence and context that most AI models simply don’t have.

As Pranay Ahlawat, Commvault’s Chief Technology and AI Officer, said: “Organizations are beginning to realize that their historical data is more than just insurance – it’s a powerful, untapped strategic asset. With Commvault Data Rooms, enterprises can confidently export their secondary data and harness it with the AI platform of their choice to unlock new opportunities for intelligence, innovation, and business growth.”

Why It Matters Now

Commvault’s Data Rooms offering redefines what’s possible for enterprises that want to innovate responsibly. They make it possible to move from protecting data to activating data – safely, flexibly, and at scale.

In short: Commvault isn’t building another AI platform. We’re building the foundation that lets every AI platform work better – because when data is protected, trusted, and ready for activation, innovation happens faster.

FAQs

Q: What is Commvault’s Data Rooms offering?

A: Commvault Data Rooms is a new capability within Commvault Cloud that helps enterprises safely discover, classify, and activate backup data for AI and analytics. It bridges data protection and data intelligence, giving organizations governed, self-service access to trusted data assets for analysis and innovation.


Q: How does Data Rooms differ from other AI data solutions?

A: Most AI data prep tools work only on live or production data, creating compliance and cost challenges. Data Rooms works from backup data – data that’s already protected and governed – bringing a unique balance of accessibility, compliance, and trust. It’s built into Commvault Cloud’s policy-controlled environment, so it’s part of a unified cyber resilience platform.


Q: What benefits do organizations gain from using Data Rooms?

A: Organizations can help accelerate AI and analytics insights, simplify data operations by reducing ETL complexity, and maintain compliance through automated classification, tagging, and auditing processes.


Q: How does Data Rooms support data security and compliance?

A: Data Rooms operates within Commvault Cloud’s zero-trust architecture, applying classification, redaction, and audit-ready controls automatically. It helps maintain data privacy, traceability, and compliance throughout the data lifecycle, aligning with internal and regulatory governance standards.


Q: What types of AI or analytics platforms can connect with Data Rooms?

A: Data Rooms integrates with leading cloud and AI partners such as Microsoft Azure and Snowflake, supporting open-standard data formats like Apache Parquet and Iceberg for maximum flexibility and portability.


Q: Why is this offering important for enterprises today?

A: As organizations accelerate AI adoption, Data Rooms enables them to responsibly unlock the value of historical, protected data – fueling innovation while maintaining trust, compliance, and control.

 

Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Conversational Resilience: The New Way to Manage and Protect Enterprise Data

Conversational resilience is a Commvault® Cloud capability that lets you manage and protect data through natural language.

Updated May 2026

Explore related resources

Datasheet

AI In Commvault Cloud

From automation and machine learning to advanced AI, learn how Metallic AI helps bring greater performance and efficiency to every aspect of the Commvault Cloud platform.
Read datasheet about AI In Commvault Cloud
White paper

Enabling a Secure AI Future

Learn how Commvault helps enable organizations to move forward with AI while protecting your data that matters most.
Read whitepaper about Enabling a Secure AI Future

We’re proud to announce that Commvault has been named a Market Leader Cyber Resilience in the 2025 Top InfoSec Innovator Awards, presented by Cyber Defense Magazine.

“Commvault embodies three major features we judges look for with the potential to become winners: understanding tomorrow’s threats today; providing a cost-effective solution; and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, the magazine’s publisher.

This recognition celebrates organizations that are innovating in unexpected and effective ways – providing cost-efficient, cutting-edge cybersecurity solutions that help businesses mitigate risk and stay one step ahead of evolving threats.

Strengthening Cyber Resilience for the Real World

As cyber threats become more complex and persistent, organizations need solutions that go beyond prevention – they need the ability to recover their minimum viable applications quickly and continue operating with confidence. Commvault’s industry-leading cyber resilience portfolio, Commvault® Cloud, helps customers do just that.

By unifying advanced data protection, threat detection, and autonomous recovery orchestration, Commvault enables enterprises to anticipate, withstand, and recover from attacks – empowering them to safeguard their business continuity and reputation in a dynamic threat landscape.

A Commitment to Continuous Innovation

“This award underscores Commvault’s leadership in helping organizations prepare for and respond to the cyber challenges of today and tomorrow,” said Bill O’Connell, Chief Security Officer at Commvault. “Our mission is to empower customers with intelligent, integrated solutions that make cyber resilience achievable and measurable – so they can stay focused on driving their business forward, not fighting fires.”

Looking Ahead

As threats continue to evolve, Commvault remains committed to delivering next-generation cyber resilience through intelligence, automation, and trust. This recognition reflects our ongoing dedication to helping customers outsmart, outlast, and outperform even the most sophisticated cyber threats.

Learn more about how Commvault helps organizations build resilience against ransomware and cyberattacks by attending our upcoming SHIFT NYC or SHIFT Virtual.

Thomas Bryant is Senior Director, Product Marketing, at Commvault.

Related Blogs

More related posts


Cyber Resilience

Read more about Cyber Resilience

Ransomware has evolved again. It is faster, smarter, and more targeted than ever before. What was once a data-encryption nuisance has become a full-scale business disruption engine powered by AI, automation, and a professionalized cybercrime economy.

In 2026, ransomware will not only be about locked files. It is about stolen identities, compromised supply chains, and operational paralysis that can spread in minutes.

“Agentic AI can reason, plan, and act autonomously, adapting attacks in real time and learning from defenders faster than they can respond,” Govind Rangasamy, head of Recovery Solutions and vice president of Portfolio Marketing at Commvault, wrote in his book, The Cyber Resilience Reckoning.

In controlled testing cited in the book, AI-driven ransomware achieved full data exfiltration 100 times faster than human attackers. This represents a fundamental shift that demands equally intelligent defenses.

For CISOs and IT leaders, 2026 will be the year when resilience replaces prevention as the true measure of readiness.

Trend 1: Agentic AI Ransomware Takes the Lead

Threat actors are now deploying agentic AI, or self-directed systems that plan and execute campaigns end to end. Unlike traditional tools that follow scripts, these AI agents can adjust to network defenses, change payloads during an attack, and learn from detection responses.

This capability may make traditional playbooks obsolete. Defenders must match machine-speed attacks with AI-assisted detection, behavioral analytics, and automated rebuild testing that validate recovery integrity continuously.

Trend 2: Identity Confidence Becomes the New Perimeter

After years of focus on “identity-centric” security, 2026 marks a new stage. Identity confidence, not just access control, will define cyber resilience.

Attackers are exploiting stolen tokens, API keys, and misconfigured entitlements to move across hybrid environments without triggering alerts. The challenge is no longer verifying who someone is. It is about knowing whether that identity still can be trusted after compromise.

As Rangasamy writes, “Resilience isn’t about avoiding failure. It’s about bouncing back from it.”

Ongoing verification and clean, verifiable rebuilds of identity infrastructure help restore trust faster than attackers can weaponize it.

Trend 3: Supply Chain and SaaS Exploitation Accelerates

Ransomware gangs increasingly are targeting third-party and SaaS ecosystems, where one breach can affect hundreds of organizations. RaaS platforms now automate reconnaissance of vendor relationships, exposing shared credentials, CI/CD pipelines, and API links.

Expect 2026 regulations to require vendor-resilience evidence. This means not just SOC 2 reports but proof of rebuild capability across dependencies.

Trend 4: Ransomware-as-a-Service Goes Corporate

What once resembled a hacker marketplace now operates like a software franchise. RaaS operators offer tiered pricing, technical support, and customization to affiliates.

This industrialization of cybercrime means even low-skill actors can rent AI-enhanced ransomware kits. Organizations must treat RaaS as a true industry competitor that innovates faster than most corporate defenders.

Trend 5: Data Extortion and Deepfake Blackmail Rise

Encryption-only attacks are becoming less common. Attackers now combine data theft, AI-generated deepfakes, and synthetic communications to coerce payments or damage reputations. This new wave of psychological ransomware weaponizes trust itself, not just technology.

Trend 6: Resilience Becomes the Metric That Matters

Leading enterprises are shifting focus from defense to demonstrated resilience.
Rangasamy defines true cyber resilience as “rebuild confidence” – the verified ability to restore business-critical applications within hours.

Speed alone is no longer enough. Recovery must be clean, not just fast.
Commvault’s whitepaper Redefining Cyber Recovery: Introducing Mean Time to Clean Recovery presents MTCR as a new benchmark for recovery success.

MTCR measures how quickly an organization can restore critical services using verified clean data, closing what Commvault calls the cyber resilience gap. It moves beyond traditional recovery time objectives and recovery point objectives to focus on trust, validation, and data integrity – the factors that determine whether recovery truly works.

Key pillars of resilience now include:

  • Immutable, air-gapped backups validated regularly.
  • Automated, policy-driven rebuilds of entire application stacks.
  • Ongoing chaos testing to expose weak links before attackers do.
  • Measurement and reporting of MTCR.
  • Unified visibility across data, identity, and infrastructure.

Trend 7: Cyber Insurance and Regulation Tighten the Bar

Governments and insurers are increasingly looking for proof of validated recovery and tested rebuild capabilities. Organizations that can demonstrate cleanroom recovery and verified data integrity see faster claim approvals and stronger regulatory standing. Resilience evidence is quickly becoming as essential as financial audits.

The Bottom Line

Ransomware has matured into a data-driven, AI-accelerated industry. Survival now depends less on stopping every attack and more on recovering faster than the attacker can adapt. Your resilience posture – measured in hours, not days – is now a competitive edge.

As Rangasamy concludes, “The organizations that embrace the Rebuild function today will become those that not only survive tomorrow’s attacks but emerge stronger from them.”

Learn More

This blog draws on insights from The Cyber Resilience Reckoning (O’Reilly Media, 2025), written by Commvault Head of Recovery Solutions and Vice President of Portfolio Marketing Govind Rangasamy, and from the Commvault whitepaper Redefining Cyber Recovery: Introducing Mean Time to Clean Recovery. For more perspectives on agentic AI, cyber recovery, and resilience metrics, visit the Readiverse.


Katherine Demacopoulous is Senior Director of Global Content Strategy and Programs at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Commvault is proud to announce our new designation as an ISC2 Authorized CPE Submitter Partner, recognizing our commitment to advancing cybersecurity knowledge and professional development.

As an authorized submitter, Commvault can now report Continuing Professional Education (CPE) credits directly to ISC2 for participants who attend qualifying Commvault learning programs and events. This means professionals with certifications such as CISSP®, CCSP®, and SSCP® can automatically earn and track CPE credits through Commvault events without the need for manual submission.

Empowering the Cybersecurity Community

Through this partnership, Commvault joins a select group of organizations authorized to deliver educational content aligned with ISC2’s domains, including:

  • Security and risk management
  • Cloud and network security
  • Incident response and forensics
  • Identity and access management

Attendees of Commvault webinars, workshops, events, and training courses will benefit from automatic credit reporting and a streamlined process to maintain their certifications.

A Shared Mission for Cyber Resilience

This partnership strengthens Commvault’s commitment to empowering security and IT professionals with the skills and knowledge needed to help protect and recover data across complex hybrid environments.

Suzanne Klausner is Director, Customer Enablement Strategy, at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

As organizations embrace generative AI to automate decisions, enhance service delivery, and optimize data management, they also are encountering a new breed of cyber threats that exploit the intelligence of these systems. One of the most concerning of these threats is the prompt injection attack, which uses language itself to manipulate AI behavior and compromise trust.

When Intelligence Becomes an Attack Surface

A prompt injection attack manipulates the instructions an AI system receives. It convinces the system to act against its original intent by embedding hidden or deceptive commands in prompts, documents, or even the external data the AI processes. This form of attack is particularly dangerous because it does not rely on traditional code exploits. Instead, it uses words to corrupt outcomes.

Imagine a generative AI tool in a customer service setting being tricked into revealing confidential data or changing workflows. In another case, an attacker might hide malicious instructions in a supplier document, causing an AI-enabled system to misroute shipments or alter invoices. These scenarios show how the language interface of AI systems has become a new and often overlooked attack surface.

Industries such as healthcare, finance, and manufacturing already are seeing examples of these tactics. Hidden instructions in data, emails, or forms can quietly override security protocols. The result is not only data exposure but also operational disruption.

The Intersection of AI Vulnerability and Cyber Resiliency

Cybersecurity teams have spent decades hardening networks, encrypting data, and deploying layered defenses. AI introduces a different challenge. These systems do not just store information; they interpret it. When an AI model is compromised, the damage extends beyond data loss. It can impact the accuracy and reliability of automated decisions that influence entire business processes.

This is why cyber resiliency has become essential. True resilience is not only about blocking attacks but also about being able to withstand and recover from them. For AI, resiliency means detecting manipulation early, isolating affected systems, and restoring normal function before significant harm occurs.

Commvault’s approach to cyber resiliency is to help organizations build for this reality. By combining data protection, threat detection, and orchestrated recovery, organizations can maintain data integrity and business continuity even when AI systems are targeted. Commvault’s goal is to provide organizations with the tools to make data not just secure, but verifiably trustworthy and recoverable.

Recognizing the Signs of Prompt Injection

The first step in building resilience is recognizing when a prompt injection might be happening. Common warning signs include:

  • Instruction overrides: Prompts that include phrases like “ignore previous instructions” or “reveal hidden data.”
  • Context switching: Sudden topic changes that move the AI system away from its intended purpose.
  • Encoded or multilingual text: Hidden characters, encoding schemes, or foreign-language commands designed to evade detection.
  • Social engineering tactics: Inputs that appear to come from an authority figure or system administrator.

Organizations should monitor AI behavior over time, establishing a baseline for what “normal” looks like. Deviations from expected responses can reveal manipulation attempts before they cause harm.

Defense in Depth: Applying Zero-Trust Principles to AI

Protecting AI systems requires the same layered mindset that has proven effective in broader cybersecurity. Zero-trust principles can apply here as well, but with added emphasis on input and output control.

  1. Validate inputs and outputs. Sanitize prompts before they are processed and review AI-generated responses for unexpected instructions or disclosures.
  2. Segment AI environments. Separate systems that process sensitive information from those that interact with untrusted data sources.
  3. Limit permissions. Use role-based access controls so that even if a model is tricked, it cannot access or modify critical systems.
  4. Continuously monitor behavior. Track AI responses over time to detect patterns that differ from expected norms.

Commvault’s ThreatWise technology can be incorporated as part of an organization’s layered protection. It detects unusual activity across AI data pipelines and flags behaviors that may signal an injection attempt. When combined with other Commvault offerings, such as Commvault Cloud, organizations can integrate early-warning detection with rapid recovery and unified visibility across hybrid environments.

AI Security and the Human Element

Technology alone cannot solve this problem. Many prompt injection attempts succeed through social engineering rather than technical exploits. They rely on human trust. Employees who use generative AI tools must understand that every prompt, file, or link can become a potential attack vector.

Regular training and simulated attack exercises can strengthen awareness. When users know what suspicious inputs look like, they become an active layer of defense rather than a weak point in the chain.

Building Trustworthy AI Through Resilient Data Practices

AI can be seen as an extension of enterprise data systems, not a separate domain, and Commvault can help customers navigate how to protect their AI. Protecting AI begins with protecting the data it learns from and the outputs it produces. That means keeping datasets, models, and metadata uncompromised, auditable, and recoverable.

Resilience must be designed into the system from the start. Whether the threat is ransomware, insider misuse, or a sophisticated prompt injection, the objective remains the same: preserve data integrity and operational availability.

AI is transforming how organizations handle information, but the foundations of cybersecurity still hold true. Data protection, ongoing monitoring, and rapid recovery remain the pillars of resilience in an increasingly intelligent world.

Final Thought

Prompt injection attacks are a reminder that innovation and risk evolve together. As enterprises accelerate their use of AI, they also must evolve their defenses. By embedding cyber resiliency into every layer of AI-supported operations, organizations can adopt new technologies with confidence, knowing that their data and decisions remain secure and reliable.

Chris DiRado is Principal Technologist, Product Experience, at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Every year on October 24, the world pauses for the International Day of Climate Action, reminding us that protecting the planet is no longer a choice, but a shared responsibility. Climate change isn’t coming – it’s here. And how we respond today will shape the future of our communities, our businesses, and our planet.

At Commvault, resilience is what we do – not just for data, but for the world we all share.

Sustainability: The Core of Resilience

Our mission to safeguard data goes hand in hand with our commitment to safeguard the environment. In FY25, we made meaningful progress toward our climate resilience goals:

  • Scope 2 emissions dropped by over 13%, driven by smarter energy use and efficient data center operations.
  • Emissions intensity fell from 12.7 to 9.6 metric tons CO₂e per million USD revenue, showing that growth and sustainability can move forward together.
  • Our LEED-certified headquarters continues to lead with renewable energy integration, water-efficient systems, and robust recycling programs.

In everything from how we power our offices to how we design our technology, we consider sustainability a key driver of business continuity.

Data That Works for the Planet

The same innovation that drives Commvault’s cyber resilience is helping advance climate resilience.

By optimizing data storage, reducing redundancies, and improving workload efficiency, our cloud solutions enable customers to use less energy and achieve their own sustainability goals. Less waste. Lower energy use. More resilience.

Because when data works smarter, the planet breathes easier.

Collective Action, Shared Progress

We know climate action is not a solo mission. That’s why Commvault collaborates with partners who share our environmental values and participates in community initiatives like the Net Zero Institute to help accelerate the transition to a low-carbon economy.

We also align our climate governance with the Task Force on Climate-Related Financial Disclosures (TCFD), driving accountability from the top down.

From Awareness to Action

The path to a sustainable future begins with small, intentional choices, like turning off a light, optimizing a server, rethinking a commute. Every decision matters.

This International Day of Climate Action, let’s all take a step toward progress. Because resilience – whether in data, business, or the environment – is built together.

Aakanksha Kashyap is ESG Specialist at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • As few as 250 poisoned samples can compromise a large AI model – turning your data lake into a prime attack surface.
  • Poisoned samples can implant backdoors that persist even after retraining or fine-tuning.
  • A practical defense centers on “protect, detect, roll back,” treating data protection as core to AI integrity.
  • Backups, versioned datasets, and fine-grained restores enable rapid recovery to a clean, trusted state.
  • Commvault + Satori add data discovery, real-time access control, LLM activity monitoring, and unified policy-plus-rollback to strengthen AI resilience.

I’ve been thinking a lot about Anthropic’s latest research – and it’s unsettling. It found that as few as 250 poisoned samples can compromise a massive AI model.
👉 [Read the research yourself.]

That’s right – a few hundred corrupted files can undo months of training and billions of parameters. Not thousands. Not millions. Just hundreds.

For anyone building or managing AI, this changes everything. Your AI data lake has become your primary attack surface – and if you can’t trust your data, you can’t trust your models.

💣 Small Samples, Big Consequences

Anthropic demonstrated that:

  • A handful of poisoned samples can implant hidden backdoors.
  • These vulnerabilities can persist through retraining and fine-tuning.
  • Attackers don’t need to flood your system – they just need a foothold.

AI integrity isn’t only a model problem – it’s a data protection problem.

🧩 The Practical Defense: Protect. Detect. Roll Back.

At Commvault, we see organizations racing to build AI pipelines without fully securing the foundation. When data is compromised, your best defense is the ability to roll back to a clean, trusted state.

That’s why backups, versioned datasets, and fine-grained restores are becoming as essential to AI as GPUs and model weights.

Commvault can help you:

  • Capture immutable snapshots of your data lake.
  • Restore to a known-good version.
  • Verify lineage, provenance, and change history.
  • Lock down backups against tampering (via WORM storage).

Because when it comes to AI, protection isn’t just about avoiding failure – it’s about being able to recover fast and clean when it happens.

🔐 The Power of Satori: Smarter, Safer AI Data

With Satori now part of Commvault, we now offer broader data security and AI governance capabilities that can help you:

  • Auto-discover sensitive data across clouds, warehouses, and lakes.
  • Control access in real time – who sees what, when, and how.
  • Monitor AI and LLM activity to detect anomalies early.
  • Unify policy and rollback – restoring data and supporting compliance from one place.

Together, Commvault + Satori provide resilient, intelligent data foundation capabilities that help detect, protect, and recover from evolving AI data threats.

🚀 The Future of AI Resilience

This is exactly what we’ll be discussing at Commvault Shift | Virtual – how to secure, protect, and recover the data that drives AI.

Join us to hear from industry leaders about building trusted, resilient AI systems that can help withstand data corruption, cyber threats, and human error.

👉 Register here: commvault.com/shift-virtual

Protect your AI. Protect your data. Build a more resilient future.

FAQs

Q: What does “250 poisoned files” actually mean for my models?
A: The blog cites Anthropic’s finding that only a few hundred corrupted samples can meaningfully compromise a massive model – no flood required. It highlights that attackers need only a small foothold to degrade behavior or implant triggers.

Q: Why might retraining fail to remove poisoning?
A: Some backdoors survive standard retraining and fine-tuning because the malicious signal is subtle and reinforced by the broader dataset. The result is a model that behaves normally until a hidden trigger appears.

Q: What immediate defenses should we prioritize?
A: Adopt a “protect, detect, roll back” strategy: Secure your data pipeline, monitor for anomalies, and maintain the ability to revert to a known-good state. Treat data protection as foundational – on par with model weights and GPUs.

Q: How do backups and versioned datasets help in practice?
A: Immutable snapshots, version history, and fine-grained restores enable you to quickly recover clean data, verify lineage and provenance, and continue operations without carrying hidden compromises forward.

Q: What additional value does Satori bring with Commvault?
A: Satori expands capabilities with automatic discovery of sensitive data across clouds and lakes, real-time access control, LLM activity monitoring for early anomaly detection, and unified policy plus rollback to support compliance and recovery.

Q: Isn’t model security enough without data protections?
A: Model-centric controls are necessary but incomplete. The post argues that AI integrity is as much a data protection problem as a model problem; without trusted data, even well-secured models can be subverted.

Thomas Bryant is Senior Director, Product Marketing, at Commvault.

Related Blogs:

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The second edition of The State of Data Readiness in Asia report, a comprehensive report from Tech Research Asia commissioned by Commvault, offers a stark look into the challenges and realities faced by organisations across the continent.

Based on a survey of 1,218 companies across Indonesia, Hong Kong, Korea, Malaysia, Philippines, Singapore, Thailand, and Vietnam, the report uncovers critical trends in data growth, regulatory pressures, AI adoption, and cyber resilience.

Here are some of the key highlights that demand the attention of business and IT leaders:

Unprecedented Data Growth and Infrastructure Complexity

Data estates are expanding at an accelerated rate.

  • The average organisation in Asia saw its data grow by 40% in the last 12 months, a significant jump from the 31% reported the previous year.
  • This explosion of data, 66% of which is unstructured, resides in increasingly complex environments.
  • A majority of companies (63%) now operate in multi-cloud or hybrid cloud environments, creating a sprawling and interdependent ecosystem that is difficult to manage and secure.
  • This complexity is taking a toll, with 38% of organisations admitting they lack confidence in their ability to restore business oeprations after a breach.

 

The AI Paradox: High Adoption Despite High Risk

AI is being enthusiastically adopted, with 74% of Asian organizations currently using business-focused AI solutions. However, there is a clear-eyed view of the risks involved.

  • This complexity is taking a toll, with 38% of organisations admitting they lack confidence in their ability to restore business oeprations after a breach.
  • A staggering 73% of these organisations believe that deploying AI increases the likelihood of a cybersecurity breach.
  • Despite this awareness, due diligence is lagging. A concerning 58% of organisations have not performed thorough security audits on their AI tools before deployment, and less than half (46%) have comprehensive policies to protect AI-generated data.

The Tangled Web of Regulations

The regulatory landscape across Asia is becoming increasingly intricate and, at times, contradictory.

  • Conflicting demands: Fifty-three percent of organisations report facing conflicting regulatory requirements for their data across different geographies.
  • Regulatory burden: Fifty-two percent of companies must comply with at least four major regulatory acts.
  • AI compliance: The challenge is compounded by AI-specific regulations, with almost 60% of companies now subject to them and another 27% expecting to be within the next year.

The Sobering Reality of Cyberattacks and Recovery

There remains a significant disconnect between the expectations of business leaders and the reality of IT recovery after a cyber incident. While 72% of business leaders expect to be back in business within five days of an incident, the reality is that 70% of businesses take more than a week to recover.

The report also sheds light on the direct impacts of attacks:

  • Of the companies that were breached, 83% experienced data exfiltration.
  • Less than half (41%) managed to recover 100% of their data.
  • While 57% of companies have a policy against paying ransoms, 34% of those with such a policy paid the ransom when attacked.

Learning the Hard Way

Interestingly, organisations that have experienced a breach demonstrate a more mature and realistic understanding of their capabilities. They are more likely to have comprehensive incident response plans and a clearer grasp of the complexities involved in recovery. For instance, breached companies are almost twice as likely to view their internal AI tools as a high cybersecurity risk compared to those that have not been breached.

To gain a deeper understanding of these findings and benchmark your organisation against your peers, download the full State of Data Readiness in Asia report. The complete report provides detailed analysis, country-specific data, and actionable insights to help you enhance your data management, recovery, and cyber resilience strategies for continuous business operations.

More related posts


Cyber Resilience

Read more about Cyber Resilience

Cyber Security

Read more about Cyber Security

In conversations with three Chief Medical Information Officers across different healthcare systems, each was asked about their most recent cybersecurity incident. The answer was unanimous and telling: None had experienced a direct attack on their own systems. Instead, all three were grappling with the aftermath of third-party vendor breaches that cascaded through their operations.

This isn’t coincidence – it’s the new reality of healthcare cybersecurity.

The Vendor’s Vendor Problem

“We are big enough to have these experts on staff that are our experts to protect us,” one CMIO explained. “Sometimes I feel that that can be a barrier to agility because of how strict we are and how thorough we are in those evaluations. But I think that we can’t ensure that our partners do the same.”

Here’s the challenge: Healthcare organizations have become incredibly sophisticated at vetting direct vendors. The contracting process is rigorous, security assessments are thorough, and compliance requirements are non-negotiable.

But what happens when your vendor makes a deal with another vendor? Suddenly, you’re exposed to risks you never evaluated, from companies you’ve never heard of, through relationships you don’t control.

One security leader illustrated this perfectly: “I’m going to make a deal to use Vendor X to do something for me here. But Vendor X may make a deal with Vendor Y that lets them do their job. So if there’s a problem with Vendor Y who I’m not technically contracted with, but my vendor needs them to function, I can’t control that.”

When the Ecosystem Fails

The Change Healthcare incident provides a stark example. When its systems went down due to a cyberattack, it wasn’t just Change Healthcare that suffered – it was every healthcare organization that relied on its prescription processing services.

One CMIO described the impact: “We had a lot of issues sending prescriptions, receiving them, having issues being unclear of what went through, what didn’t go through, and who didn’t have their medications.”

The downstream clinical impact was immediate and severe. Patients couldn’t get medications, providers couldn’t verify prescription statuses, and healthcare teams scrambled to identify which patients might be affected. This was a direct patient safety issue caused by a vendor incident completely outside the control of healthcare providers.

But the clinical impact was just the beginning. The compliance implications were equally severe, highlighting a fundamental challenge in healthcare’s regulatory landscape.

The Compliance Trap: When Vendor Failures Become Your Regulatory Problem

Healthcare organizations face a harsh regulatory reality: Vendor incidents don’t absolve them of compliance responsibilities. In fact, they often amplify them.

HIPAA requires covered entities to establish Business Associate Agreements with vendors handling protected health information. While these agreements theoretically transfer some liability, the practical reality is different. When a vendor suffers a breach, the healthcare provider still faces potential penalties, regulatory scrutiny, and mandatory reporting requirements.

The reporting burden alone creates significant operational strain. HIPAA’s proposed 72-hour reporting mandates, similar to regulations like EU NIS2 and DORA for cross-border institutions, require healthcare providers to disclose incidents quickly, regardless of whether the breach originated from their own systems or a vendor’s.

As one CMIO noted: “We actually have to communicate to the state, to the Centers for Medicaid and Medicare Services: ‘This is what’s going on. This is where we are with our recovery.’”

This means that during an active incident – when clinical teams are scrambling to maintain patient care and IT teams are coordinating recovery efforts – compliance teams must simultaneously investigate, document, and report on incidents they didn’t cause and may have limited visibility into.

The data sovereignty challenge adds complexity. Vendors storing healthcare data outside approved regions can trigger compliance violations that organizations may not even know exist until an incident forces a comprehensive audit of their vendor ecosystem.

“We require [vendors] to give us anything and everything we asked for to review,” explained one security leader who’s experienced a vendor ransomware attack. “So, there was actually no limitations on what we could ask.”

But this level of oversight is typically only possible with the largest vendor relationships, leaving many smaller but still critical vendor dependencies in compliance blind spots.

The CrowdStrike Wake-Up Call

The CrowdStrike incident drove home another reality: When critical infrastructure providers fail, the entire healthcare ecosystem fails simultaneously.

“We did [tabletop exercises] with the assumption that it would be a ransomware attack… a very kind of localized event,” one leader reflected. “And this was affecting the entire ecosystem. And that’s where we [learned] that we needed to have more resiliency practices that would incorporate where the ecosystem itself would be widely affected.”

The challenge wasn’t just technical – it was operational and regulatory. When everyone is down at once, the usual backup plans (like calling vendors for support or switching to alternate providers) simply don’t work.

Healthcare organizations faced not only interrupted patient care and massive downtime costs but also complex compliance reporting requirements for an incident that originated entirely outside their control.

Beyond Traditional Risk Assessment

Healthcare organizations are discovering that their traditional approach to vendor risk management isn’t enough. The standard process – sending questionnaires, reviewing documentation, checking compliance certifications – only covers direct relationships.

But post-incident, the conversation is changing. Instead of just asking “Do you do this? Do you do that?” organizations are demanding to see exactly how vendors execute security and recovery plans. They’re asking for evidence of testing, requiring contractual rights to review sub-vendor relationships, and building in financial protections.

The New Vendor Relationship Model

Forward-thinking healthcare organizations are taking several concrete steps to address ecosystem risk:

  • Data sovereignty: “We want to start taking more ownership over the data… so that we have something we can rebuild or even switch over to another third party if possible,” one leader said.
    Rather than letting vendors hold all the data, organizations are requiring regular data exports and maintaining their own copies of critical information. This approach helps address data residency requirements and enables compliance continuity even when vendors fail.
  • Enhanced contractual evolution: Post-incident contract negotiations now address compliance obligations explicitly. Organizations are demanding notification timelines that meet regulatory requirements, recovery guarantees that minimize downtime costs, and financial compensation for both direct losses and compliance penalties resulting from vendor-caused outages.
  • Compliance-aware update management: The CrowdStrike incident highlighted how vendor updates can create both operational and compliance risks. Many organizations have implemented “two versions behind” policies for critical security updates, balancing the risk of delayed patches against the risk of compliance violations from untested updates that could cause widespread outages.
  • Regulatory integration in vendor management: Organizations are building compliance considerations directly into vendor evaluation and ongoing oversight. This includes knowing vendors can meet the same 72-hour reporting requirements, maintain appropriate data residency, and provide the documentation needed for regulatory reporting.

The Insurance Industry’s Perspective

Perhaps most telling is how the insurance industry views these risks. As one security leader shared from a colleague in insurance risk modeling: “The number one risk that we have is the kind of outage like CrowdStrike, where we’re so dependent upon these technology platforms that when we’re out, there’s massive disruptions in services and in operations. She says that’s the number one risk in our risk model. It’s not ransomware attacks.”

This shift in risk assessment reflects a fundamental change. Traditional cybersecurity focused on preventing bad actors from getting in. Modern cybersecurity also must address the reality that critical vendors – with the best of intentions and strong security practices – still can bring down entire ecosystems through operational failures.

The Minimum Viability Challenge in an Ecosystem World

Traditional recovery planning often assumes you can restore everything systematically, but when entire ecosystems fail simultaneously, organizations must focus on minimum viable recovery (MVR).

The concept of minimum viability becomes critical when your vendors, their vendors, and potentially your backup vendors are all affected. As we’ve explored in our analysis of healthcare cyber threats and MVR, the question isn’t just “How do we recover everything?” but “What are the bare essentials we need to keep patient care running while the ecosystem rebuilds itself?”

This ecosystem reality makes organizational recovery readiness more complex than ever. When you can’t rely on your usual vendors or backup providers, your MVR plan must account for true independence from the broader ecosystem – at least temporarily.

Moving Forward

Organizations can’t just secure their own perimeter; they need to understand and plan for the interconnected web of dependencies that modern healthcare relies on. This means fundamentally rethinking business continuity planning to account for simultaneous ecosystem failures. It means maintaining data sovereignty even when using SaaS providers. And it means accepting that some risks simply can’t be eliminated – only managed and planned for.

The healthcare leaders we spoke with weren’t pessimistic about these challenges; they were pragmatic. They understand that the benefits of interconnected, cloud-based healthcare systems far outweigh the risks.

Test Your Ecosystem Resilience

Understanding the risks is just the first step. The next is honestly assessing whether your organization is prepared for the new reality of interconnected failures. How confident are you that your MVR plan would work when your usual vendors and backup systems also are compromised?

Healthcare organizations serious about ecosystem resilience should evaluate their readiness across three critical areas: business-critical prioritization, measurable technical response, and organizational recovery readiness. Commvault’s Minimum Viability Healthcare Assessment helps evaluate your current capabilities and offers actionable recommendations for closing any gaps.

Don’t wait for the next ecosystem-wide incident to discover whether your recovery plans account for the reality of interconnected healthcare IT. Take the assessment today and build true resilience for tomorrow’s challenges.


Related Blogs:

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

A powerful go-to-market strategy is what separates leaders from the pack in the competitive cyber resilience market. At Commvault, we’re dedicated to providing our partners with the strategic resources needed to help grow revenue, build customer trust, and solidify your reputation as a market leader with Commvault.

That’s why we are excited to announce two game-changing resources designed to elevate your sales and marketing efforts: a reimagined Commvault Campaigns Hub and the new At-A-Glance Partner Sales Playbooks.

Streamline Your Marketing with the Campaigns Hub

Based on partner feedback, our newly imagined Campaigns Hub is your destination for ready-to-use, results-driven marketing. The Campaigns Hub is a powerful, intuitive platform that simplifies the creation of targeted campaigns, helping you build awareness, generate leads, and upsell Commvault’s suite of solutions. And now our platform integrates seamlessly with your existing strategies, enabling cohesive brand messaging and maximum impact.

With the Campaigns Hub, you’ll find:

  • Targeted campaigns you can launch in minutes. Choose from a library of pre-built multi-language campaigns – from “Securing Continuity for Minimum Viable Business” to “Microsoft Active Directory Protection” – and customize the content to fit your audience’s unique needs.
  • A new, powerful webcast program. Leverage Commvault’s best speakers and content directly from the Campaigns Hub using our on-demand webcasts along with the promotional materials to drive leads and awareness.
  • A new, co-branded assessment tool. Contact our Marketing Concierge and request a co-branded minimum viability assessment tool that provides benchmarks to your customers in minutes and puts leads directly in your inbox.  
  • High-value customer assets to use on your platform or the hub. You can now access key Commvault customer content and promotional campaigns through the Campaigns Hub and integrate these valuable assets into your broader marketing initiatives on the hub, or download and use on your platform.
  • Our complimentary Marketing Concierge service that makes campaigns even easier. You don’t need to use MDF or pay for our Marketing Concierge service to help you customize and run the latest Commvault campaigns to grow your business. Try out the service with a 1:1 Campaign Activation Session.

Boost Sales Success with At-A-Glance Playbooks

To complement your marketing efforts, Commvault also has launched our new At-A-Glance Partner Sales Playbooks. We’ve condensed our most popular Partner Sales Playbooks into a concise, easy-to-use one-page format, packed with the essential tools you need to articulate value and enhance customer engagement.

Each playbook includes:

  • Concise call scripts: Confidently articulate the unique value propositions of Commvault’s products and solutions.
  • Objection handling: Turn potential roadblocks into opportunities with prepared responses to common customer challenges.
  • Customer-ready materials: Accelerate sales cycles by sharing curated whitepapers, solution briefs, case studies, eBooks, and more.

By combining the power of the Commvault Campaigns Hub with the strategic guidance of the At-A-Glance Sales Playbooks, you can create impactful, end-to-end campaigns that drive customer engagement and achieve greater sales success.

Unlock Your Potential with Commvault

Ready to transform your go-to-market strategy and maximize the value of Commvault’s offerings? Explore the Commvault Campaigns Hub and Partner Sales Playbooks in the Partner Portal. Dive in on your own, or schedule a 1:1 Campaign Activation Session with our complimentary Marketing Concierge for guided support.

More related posts


Cyber Resilience

Read more about Cyber Resilience