Skip to content

Key Takeaways

  • ResOps is not a technology product. It’s a cross-functional operating discipline that helps drive organizational cyber resilience.
  • It complements backup, disaster recovery, cybersecurity, business continuity, and incident response by aligning these functions around end-to-end recovery outcomes.
  • ResOps focuses on critical services and business-defined impact tolerances, rather than isolated infrastructure components.
  • It relies on the continuous production of evidence, including tested recovery results, service resilience indicators, and an owned backlog of gaps.
  • ResOps is a continuous process. Neither making a plan nor running a successful one-time exercise are enough to establish lasting recovery capability.

The New Resilience Challenge

Most organizations invest in cybersecurity, backup, disaster recovery, and business continuity. Yet many executives still face three critical questions: Can we recover? How long will recovery take? And can we prove it?

Part of the challenge is that responsibility for resilience is spread across teams that often operate in silos. Security manages threats. IT maintains systems. Backup and disaster recovery teams restore data and infrastructure. Business continuity teams focus on keeping the organization running. Each plays an important role, but responsibility for recovery can remain fragmented.

ResOps brings these functions together around shared priorities, recovery goals, and evidence. The result is a more practical way to approach resilience: know what matters most, understand what it takes to recover it, test whether recovery works, and act on the gaps you find.

What Is ResOps?

ResOps is the operational discipline that brings security, infrastructure, IT operations, business continuity, and business owners together around critical services, resilient design, and continuous validation. Put simply, ResOps helps teams prepare for disruption, recover critical services within business-defined impact tolerances, and demonstrate in an evidence-based way that recovery works.

Four characteristics define ResOps. It is:

  1. Cross-functional by design. ResOps connects distributed responsibilities through a shared operating model, named ownership, and executive governance.
  2. Centered on critical services. It prioritizes the services the organization must restore to deliver core value, serve customers, and generate revenue; as well as helping meet urgent legal, regulatory, safety, and mission obligations.
  3. Continuously validated. Resilience is a posture that teams must exercise and improve – not a state established by an annual test.
  4. Measured through evidence. ResOps produces a resilience posture score (RPS): a per-service, evidence-backed score that measures how recoverable a single critical service is based on validation results, dependency health, and clean-recovery confidence.

What Isn’t ResOps?

It’s not a product category.

No platform can create ResOps on its own. Data protection, cyber recovery, automation, observability, and testing technologies can support the discipline, but ResOps is organizational. It depends on governance, shared accountability, business priorities, operational practices, and a common standard of evidence.

It’s not a replacement for backup and recovery or disaster recovery.

ResOps does not replace strong backup and disaster recovery capabilities: it depends on them. Backup establishes whether recoverable copies exist. Disaster recovery provides the procedures and technical capabilities to help restore systems and infrastructure.

But then ResOps asks a broader question: Can the critical service return completely, cleanly, and within tolerance, including its identities, applications, data, infrastructure, cloud services, third parties, people, and decision paths?

It’s not another name for business continuity or incident response.

Business continuity defines how the business operates through disruption. Incident response detects, contains, and manages the event. ResOps connects those disciplines to the recovery outcome. It creates an operating rhythm for teams to agree on what matters, validate recovery under realistic conditions, measure results, and address the gaps that testing reveals.

It’s not a compliance exercise or one-time project.

A mature ResOps program can help generate evidence for boards, regulators, insurers, customers, and auditors. But documentation is a byproduct, not the objective. The objective is demonstrated recoverability.

And because systems, dependencies, threats, and business priorities keep changing, ResOps is never “finished.” It operates continuously, much like financial planning or security operations.

What Changes With ResOps?

ResOps shifts the focus from whether individual systems and processes are working to whether the critical service as a whole can recover. That changes the questions leaders can ask.

A successful backup is important. So is having a recovery plan. But neither one tells you whether a critical service can actually be restored when you need it. ResOps looks at the bigger picture:

  • Did we recover from a verified clean recovery point?
  • How long did it take?
  • Did we recover within the limits the business set?
  • And what still needs attention?

That’s why ResOps matters. It gives organizations a way to move beyond assumptions of resilience to programmatic, reliable demonstrations of their ability to recover. And they do it with continuous production of evidence and traceability. So when disruption happens, the question isn’t whether every team did its part or who failed at which task. It’s whether the business can restore the critical services its customers depend on.

Learn More

Commvault has published ResOps: An Executive Guide to give CISOs, CIOs, IT, security, resilience, and risk leaders a practical framework for implementing ResOps in their organizations.

Leaders will learn how to identify the services that matter most, validate recovery readiness with real evidence, and continuously test resilience. As a result, organizations can establish a single operating model that unites security, infrastructure, IT operations, and business leaders around evidence-based recoverability.

Get the guide here. 

FAQs

Q: Is ResOps simply a new name for disaster recovery?

A: No. Disaster recovery is an essential part of ResOps, but ResOps looks at the entire critical service – including technical, third-party, human, and decision dependencies – and whether it can recover within a business-defined impact tolerance.

Q: Does ResOps require buying a new platform?

A: No. Technology can support mapping, testing, recovery, and evidence collection, but ResOps starts with ownership, governance, business priorities, and operating practices.

Q: Who owns ResOps?

A: ResOps needs a named leader with cross-functional authority and executive sponsorship. Individual service owners remain accountable for their services, while security, IT, business continuity, and business teams contribute to the shared recovery outcome.

Q: How is ResOps success measured?

A: Success comes from current evidence that critical services can recover cleanly within their defined impact tolerances – not simply from completing a plan or running a successful backup job.

A resilience posture score (RPS) is also a useful measurement tool. As a per-service, evidence-backed score, RPS helps demonstrate how recoverable a single critical service is based on validation results, dependency health, and clean-recovery confidence.

Q: How do organizations get started with ResOps?

A: Start by identifying the critical services the business depends on, who owns them, what they depend on, and how quickly they need to recover. From there, teams can validate recovery, identify gaps, and prioritize the work needed to strengthen resilience.

Michael Thelander is Senior Director of Product Marketing at Commvault.

More related posts


Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.
Thumbnail_Blog_CVLT-Evaluates-Vulnerabilities (1)

When the Test Broke Containment

Read more about When the Test Broke Containment

Key Takeaways

  • Resilience depends on how quickly and confidently the business can recover – not solely on keeping every threat out.
  • Turn recovery plans into evidence – tested results are more credible to boards, regulators, and insurers than targets or assumptions.
  • Make ResOps a shared operating model for security, infrastructure, business continuity, and service owners.
  • Measure what matters: Teams should know whether critical services can be restored, how long recovery actually takes, and whether they can prove it.
  • Select one or two critical services, define successful recovery, run an honest exercise, and document the results.
  • Twenty years in security leadership teaches you one thing early: The attack you stopped never makes the board meeting. The one you didn’t is the only story anyone remembers. Somewhere along the way I stopped measuring my team by how many hits we absorbed alone and started also measuring us by how fast we got back up.
  • That’s the reason I want every CISO, CIO, and board member I know to read this new book, ResOps: An Executive Guide. Commvault sponsored it, but I’d be recommending it either way.

The Wall Was Never the Whole Plan

For most of my career, the job was building higher walls. Better detection, tighter controls, faster response. That work still matters, and it always will. But a wall only answers one question, and it’s not the one your board is asking anymore.

Last September, ransomware forced Jaguar Land Rover to halt global manufacturing. Assembly lines stopped. Supply chains froze. The UK’s Cyber Monitoring Centre put the cost to the broader economy at roughly £1.9 billion, and JLR posted its lowest monthly production output in 73 years. JLR had defenses. What the incident tested wasn’t whether the wall held. It was whether the business could get back up once it didn’t.

I’ve said this before and I’ll keep saying it: Disruption isn’t an if, it’s a when. The CISOs who sleep at night aren’t those who believe they can keep everything out; they’re those who’ve practiced getting back up so many times that the practice itself is the confidence.

Three Questions I Ask My Own Team

The book organizes the whole problem into three questions, and I’ve started opening every resilience review with them:

  • If we were hit tonight, could we recover?
  • How long would it actually take?
  • Can we prove it, with evidence, to the board?

Most organizations answer the first two with a plan and the third with silence. That silence is the resilience gap, and it’s bigger and more expensive than most executives realize.

Proof, Not Promises

Here’s a distinction the book makes better than I’ve heard it made anywhere else: A recovery time objective is a target. It tells you what you’re aiming for – but it doesn’t tell you whether you’ll hit it.

Compare “we believe we can recover the payments service in four hours” to “we restored it in 3.2 hours last quarter, from a verified clean recovery point, against a four-hour tolerance.” The first sentence is a plan. The second is evidence. Only one of them holds up when your board, your regulator, or your cyber insurer starts asking harder questions, which they will.

We calls this discipline ResOps, short for resilience operations. It’s not a product you buy or a binder you file. It’s an operating model that connects security, infrastructure, business continuity, and the business owners who depend on these services, all working from the same evidence instead of separate plans.

The Part That Should Worry Every CISO

The book also names something I’ve felt for a while and finally have language for: the AI paradox. The same AI capability helping us find vulnerabilities faster is helping attackers close the gap between discovery and exploitation just as fast, maybe faster. Finding more problems doesn’t make you safer if you can’t recover from the ones that get through. Detection speed was never the finish line. Recovery capability is.

Start with One Service

None of this requires boiling the ocean, and I’d be lying if I said my own team got it right on the first try. The book lays out a 90-day path: Pick one or two of your most critical services, define what “recovered” really means for each, run one honest recovery exercise, and produce your first piece of real evidence. That’s a project any team can start this quarter, mine included.

Proof over promises. Readiness over perfection. That’s the standard I hold my team to, and it’s the standard this book gives you a real path toward.

Get your copy of ResOps: An Executive Guide here.

FAQs

Q: What is ResOps?

A: ResOps, short for resilience operations, is an operating model that connects security, infrastructure, business continuity, and service owners around shared, evidence-based recovery practices.

Q: How is ResOps different from traditional disaster recovery?

A: Traditional disaster recovery often centers on plans and technical targets. ResOps emphasizes continuous validation, cross-functional ownership, and measurable proof that critical services can be restored within business tolerances.

Q: Why is recovery evidence important?

A: Recovery evidence shows what an organization has actually tested and achieved. It helps give boards, regulators, insurers, and business leaders greater confidence than plans or recovery targets alone.

Q: What should organizations measure in a ResOps program?

A: Organizations should measure whether critical services can be restored, how long recovery actually takes, whether recovery points are clean and verified, and whether results meet defined business tolerances.

Q: Who should be involved in ResOps?

A: ResOps should bring together security, infrastructure, business continuity, application and service owners, and executive stakeholders so that recovery priorities and evidence reflect business needs.

Q: How can an organization get started with ResOps?

A: Start with one or two critical services. Define what successful recovery means, run an honest recovery exercise, document the results, and use that evidence to improve the next test.

Bill O’Connell is Chief Security Officer at Commvault.

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.
Thumbnail_Blog_CVLT-Evaluates-Vulnerabilities (1)

When the Test Broke Containment

Read more about When the Test Broke Containment

Key Takeaways 

  • The updated federal advisory documents new Medusa tactics, techniques, and more than 500 victims across critical infrastructure sectors. 
  • Attackers target more than production data; they also disrupt backups, identity, virtualization, and other systems organizations depend on for recovery. 
  • The advisory calls on organizations to prove their resilience through testing and validation against observed attacker behaviors, not assume it from plans or successful backup jobs alone.  

The latest federal advisory on Medusa ransomware was updated for a reason: The adversary changed. 

The updated federal advisory, issued August 18, 2026, by the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS), describes an adversary that recruits new access brokers, moves faster once inside, and has gotten better at making sure the damage it causes cannot be undone.  

The Attack Is Not Just Against Your Data

Medusa actors move quickly. Investigators report that Medusa actors have leveraged newly announced exploits within 24 hours and, in some cases, have used exploits up to a week before public vulnerability disclosure. 

Once inside, they blend in using legitimate remote management tools, credential theft, and living-off-the-land techniques. 

But the advisory’s most significant finding is that Medusa attacks the recovery path itself. 

The advisory maps this activity to MITRE ATT&CK technique T1490, Inhibit System Recovery. It documents the ransomware terminating services associated with backups, security, databases, communications, file sharing, and websites. It also deletes shadow copies, and remotely shuts down and encrypts virtual machines. 

If an attacker is deliberately targeting the systems, identities, and infrastructure an organization may need to recover, the problem extends beyond data protection into cyber resilience and cyber recovery. 

Where ResOps (Resilience Operations) Comes In

ResOps is not another name for backup. It is an operating discipline that brings security, IT, infrastructure, applications, operations, and the business together around one outcome: keeping critical services running and recovering them within the time the business can tolerate. 

The Medusa advisory never uses the word ResOps, but the thinking is there. It recommends organizations exercise, test, and validate their security programs against observed attacker behaviors, align security technologies to attack techniques, test them at scale, measure performance, and tune people, processes, and technologies based on the evidence. 

A backup does not prove it is clean. A recovery-time objective in a spreadsheet does not prove the business will be operating within that window. Resilience has to move from assumption to evidence. 

Start With the Business, Not The Server

The addition of HHS in the advisory makes this especially relevant for healthcare, a sector the FBI says has been a frequent Medusa target. The recovery conversation starts with three questions: 

  • What has to keep running, and what does minimum viable operation look like? 
  • Which identities, applications, infrastructure, and data support those services? 
  • Which recovery points we can trust, and what comes back first? 

In a hospital, leaving any one of those unanswered may mean a delayed surgery, a pharmacist who can’t verify a dosage, or a diagnostic system a clinician can’t trust. No single team can answer them alone, which is the gap ResOps is designed to close. 

Use Medusa to Test Your Assumptions

Use Medusa as a test case for recovery assumptions. Can an attacker reach the systems supporting recovery? What happens if Active Directory is compromised? Can you identify a clean recovery point, restore critical services in the correct order, and prove how long that will take? 

Threat actors adapt when defenders adapt. Resilience programs need to operate the same way: continuously tested, continuously validated, and continuously improved.  

Because the middle of an incident is a terrible time to discover that the recovery plan looked better on paper than it works in real life. 

FAQs

Q: What is Medusa ransomware? 

A: Medusa is a ransomware-as-a-service operation first identified in 2021. Its developers and affiliates use a double-extortion model, encrypting systems while threatening to publish stolen data if a ransom is not paid. 

Q: Why was the federal Medusa advisory updated? 

A: The August 2026 update incorporates findings from FBI investigations as recent as April 2026. It expands the documented tactics, techniques, procedures, exploited vulnerabilities, affiliate activity, and indicators of compromise, while adding HHS insights on attacks against healthcare. 

Q: How does Medusa threaten an organization’s recovery capabilities? 

A: Medusa can terminate services associated with backups, security, databases, communications, and other critical functions. It also can delete shadow copies, alter identity-related policies, and shut down or encrypt virtual machines, putting the recovery path itself at risk. 

Q: What should organizations do to help reduce Medusa risk? 

A: Organizations should patch known vulnerabilities promptly, segment networks, restrict access to remote services, strengthen authentication, monitor lateral movement, and apply least privilege. They also should maintain separate, offline, encrypted, and immutable recovery copies and regularly test restoration workflows. 

Q: What is ResOps, and how is it different from backup? 

A: ResOps, or resilience operations, is a cross-functional operating discipline – not a backup product. It aligns security, IT, infrastructure, applications, operations, business continuity, and business owners around restoring critical services within the amount of disruption the business can tolerate. 

Q: How can an organization help prove it is ready to recover? 

A: Start with critical business services, map the identities, applications, infrastructure, data, people, and third parties they depend on, and define successful recovery. Then run realistic exercises that identify clean recovery points, restore services in the correct order, measure actual recovery time, and turn any gaps into an owned improvement backlog. 

Chris Bevil is Principal Portfolio Marketing Manager at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience

Key Takeaways 
  • Roughly 1,200 supposedly isolated agents communicated through an unauthorized message board, and about 700 participated in Hugging Face-related activity. 
  • Agents exchanged over 70,000 messages and files, combining discoveries across sessions meant to remain separate. 
  • Investigators found agents spoofing tool calls and researching ways to alter evaluation transcripts to avoid detection by the grader.  
  • Immutable, isolated backups alone are insufficient: Organizations need a validated, trustworthy recovery point before restoring to production. 
The forensic reports are finally here, and they changed the way I think about this incident. 

About a month ago, I wrote about the OpenAI and Hugging Face security incident because I thought it was something anyone responsible for cybersecurity, AI or business resilience should be watching.  

At the time, the story sounded fairly straightforward: An AI agent found a way outside the environment designed to contain it and ultimately reached Hugging Face. 

That is not really what happened. 

The Story Is Bigger Than One Rogue Agent 

The forensic reports reveal that about 1,200 agents, supposed to be operating in isolation, discovered a way to communicate through an unauthorized message board. They exchanged more than 70,000 messages and files, and roughly 700 agents participated in activity associated with Hugging Face. 

None of that was prompted or intended. The agents were persistent, they could share what they found, and they could combine effort across sessions that were supposed to have no contact with each other.  

Among the new details: GPT-5.6 Sol agents reproduced an exploit and copied private evaluation data into a public Hugging Face dataset, a concrete escalation beyond what initial reports described. 

The Reward-Hacking Problem 

The independent investigation conducted by METR and Redwood Research, published alongside OpenAI’s own report on August 26, found that agents researched ways to spoof, edit or delete portions of their own evaluation transcripts because they incorrectly believed the grader would inspect how they completed the task. Researchers found successful tool-call spoofing in about 7% of the transcripts they evaluated, though the manipulation they observed was small-scale. 

The finding is not that agents are “deceptive” in a human sense. It is that a sufficiently capable agent can search for ways around controls when those controls stand between it and the outcome it has been optimized to achieve. 

OpenAI calls the incident a “warning shot.” I think that is a fair description. 

What Happens When Containment Fails 

Most of the conversation about this incident will rightly focus on alignment, sandboxing and monitoring. But there’s a resilience question underneath it: If 700 agents can find a side door around containment, what’s the plan for when a single compromised workload does the same in your environment? 

OpenAI’s own conclusion points at the answer: Security architecture should assume an individual workload or compute node eventually can be compromised. That means air-gapped, immutable recovery data, and a way to validate what you’re restoring before it touches production again. 

But immutability alone does not prove the data was clean when it was captured. If the data was already compromised at the time of capture, immutability preserves the compromise just as faithfully as it preserves anything else. 

The practical version of that question is simple to ask and hard to answer: If this happened to us, could we prove which recovery point predates the compromise? 

We cover this operating model under ResOps (resilience operations) on the Readiverse. 

The Lesson for Every Organization 

OpenAI has since tightened workload and network isolation, expanded monitoring, and revised its model-development practices. The lesson applies beyond OpenAI: Contain the impact, preserve what you can trust, and prove you can recover before you need to. 


FAQs 

Q: What was the OpenAI-Hugging Face incident? 

During internal cybersecurity evaluations, OpenAI agents bypassed controls intended to isolate them, accessed the internet and reached third-party systems, including Hugging Face. The activity was driven primarily by an internal research model operating with reduced safeguards. 

Q: How did supposedly isolated agents communicate? 

A: They discovered an unauthorized message board in shared infrastructure. About 1,200 agents used it to exchange more than 70,000 messages and files, allowing information and tactics to carry across sessions that were designed to remain independent. 

Q: Were the agents instructed to attack Hugging Face? 

A: No. They were attempting to complete a difficult cybersecurity benchmark. When the intended route appeared blocked, some agents searched for alternative ways to achieve the evaluated outcome, and that activity expanded beyond the environment’s intended boundaries. 

Q: What does “reward hacking” mean in this context? 

A: Reward hacking occurs when an agent finds an unintended way to satisfy a metric or obtain a desired result without completing the task as intended. Investigators found agents researching ways to spoof tool calls and alter or delete portions of evaluation transcripts because they believed the grader might inspect their process. 

Q: Why are immutable backups not enough on their own? 

A: Immutability prevents stored data from being altered, but it does not prove the data was clean when it was captured. If a backup already contains compromised data, immutability preserves that compromise. Organizations therefore need isolated copies, trustworthy recovery points and validation before restoration. 

Q: What should organizations do differently after this incident? 

A: Strengthen workload and network isolation, restrict unnecessary internet and credential access, monitor agent behavior and escalation signals, and assume that prevention may fail. Pair those controls with air-gapped, immutable recovery data and a tested process for identifying and validating a clean recovery point. 

Chris Bevil is Principal Portfolio Marketing Manager at Commvault. 

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Key Takeaways

  • Certificate lifespans will shrink from 398 to 47 days by March 2029 with “domain validation reuse” shrinking to just 10 days, making manual renewal obsolete and automatic Certificate Lifecycle Management (CLM) necessary.
  • Harvest Now, Decrypt Later operations are already underway to store data with long lifespans for future decryption using quantum computers, which means there is an immediate threat to encrypted, sensitive data that have longer term retention.
  • Certificate/Crypto Inventory is most crucial for companies to start building now, as continuous and automated inventory is the first step toward long-term cyber-resilience and crypto-agility.

The Problem Hiding in the Background

Most modern enterprise networks rely on a hidden layer comprised of digital certificates and cryptography that most people never see. This layer verifies machine trust and secures data flows, but with machine identities now outnumbering human identities by more than 80 to 1 in the average enterprise according to CyberArk’s machine identity research, it can be easy to underestimate the cryptographic and certificate layer’s importance.

A helpful way to think about a digital certificate is an ID badge for a machine. If the badge is valid, the doors open automatically and no one thinks about it, but the moment that badge expires or is misconfigured, the door stops opening, regardless of how legitimate the machine behind it is. A single expired certificate can take down websites, break the APIs that let applications talk to each other, interrupt transactions, and create compliance violations, all while eroding user trust.

For years, organizations have managed certificates manually, but two changes are going to make it impossible to keep up by hand. First, the maximum lifespan of public Transport Layer Security (TLS) certificates, the protocol securing your browser, is being compressed to just 47 days by 2029. Second, the eventual arrival of quantum computers powerful enough to break today’s encryption is forcing a transition to Post-Quantum Cryptography. These two issues both point to the same solution – a governed, automated, and crypto-agile approach to CLM.

The Roadmap Behind Shrinking Certificate Lifespans

The operational window for public TLS certificates has been narrowing for a decade. In early 2023, Google first published its “Moving Forward, Together” roadmap, which proposed reducing certificate validity from 398 days to 90 days in hopes to push the industry toward automation. Apple accelerated that timeline in October 2024 by introducing a draft ballot to the CA/Browser Forum, the industry body where certificate authorities and browser makers set shared rules. Apple’s proposal, endorsed by Sectigo, Google Chrome, and Mozilla, was approved in April 2025 as Ballot SC-081v3.

This reduction happens in phases. The past 398-day maximum has already dropped to 200 days as of March 2026, with the maximum being reduced to 100 days in March 2027, and finally to 47 days in March 2029. In practical terms, an organization that currently renews each certificate about once a year will soon be renewing every certificate roughly every month and a half; by the final stage, any process that depends on a person manually requesting and installing certificates will fail.

Browser makers are pushing for these shorter lifespans to force automation, which removes the human error that causes most certificate outages in the first place. They also let the entire web adopt new cryptographic standards in weeks rather than years, since old certificates cycle out quickly. Additionally, they help reduce reliance on legacy revocation systems which suffer from performance and privacy problems. Lastly, if a Certificate Transparency log (a public record of issued certificates) is ever disqualified, short-lived certificates dramatically shrink the number that must be replaced on short notice.

The Validation Crunch

While the 47-day limit gets headlines and attention, the more disruptive change may be what happens to Domain Control Validation (DCV). DCV is the process of proving to a Certificate Authority (CA) that you control the domain you are requesting a certificate for. Historically, once an organization proved ownership, the CA could reuse that proof for up to 398 days, but under SC-081v3, the reuse window shrinks to 200 days in 2026 and to just 10 days by March 2029.

This creates a real imbalance, as even an organization that fully automates certificate installation will stall if it cannot re-prove domain ownership every 10 days. Any delay in validation halts the entire issuance pipeline and leads directly to outages.

The practical answer to this problem is adopting the Automatic Certificate Management Environment (ACME) protocol with automated DNS-01 API validation, so that proving ownership happens programmatically rather than waiting on a person.

The Quantum Threat and Timeline

While certificate lifespans shrink, the algorithms inside those certificates face a quantum threat. Traditional Public Key Infrastructure (PKI) rely on asymmetric cryptography to secure digital signatures, key exchanges, and TLS connections. A sufficiently powerful quantum computer running Shor’s algorithm could break these systems completely. Waiting until quantum computing is powerful enough to decrypt is not a viable option; as Commvault Field CTO Vidya Shankaran has written, “the exact date of Q-Day may remain uncertain. The direction of travel is not.” 

Estimates place Q-Day, the point at which a quantum computer can break public-key encryption, somewhere in the next 5 to 10 years. However, it would be a mistake to treat this as a future problem. Threat actors are already conducting Harvest Now, Decrypt Later (HNDL) operations, intercepting and storing encrypted traffic today with the intention of decrypting it once quantum computing matures. Data that must stay confidential for years, such as health records, intellectual property, and financial information, is effectively exposed the moment it is harvested.

The U.S. Federal Government has responded accordingly: In June 2026, the White House issued Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, which sets deadlines well ahead of NIST’s original 2035 target: Federal high-value systems must adopt post-quantum key establishment by the end of 2030 and post-quantum digital signatures by the end of 2031.

Despite this urgency, actual progress toward enterprise-level crypto-agility has been slow. The DigiCert Quantum Readiness Outlook found that more than half of surveyed organizations expect classical asymmetric encryption to be broken within five years, yet only 7% have deployed quantum-safe or hybrid cryptography across their certificate estates, and overall readiness improved by just 2 percentage points in the past year.

Why Does Crypto-Agility Matter?

The most practical bridge between classical and post-quantum cryptography is the hybrid composite certificate, which combines a classical algorithm (RSA or ECC) with a post-quantum algorithm (ML-DSA, the standardized lattice-based signature scheme) inside a single X.509 certificate. Combining both into a single certificate is designed so that the certificate will hold up as long as either algorithm does, which is essential, as post-quantum algorithms are new and haven’t yet survived countless attempted attacks like RSA has.

However, post-quantum keys and signatures are several kilobytes rather than a few hundred bytes, which increases network latency, risks packet fragmentation during the TLS handshake, and adds computational overhead that may require hardware upgrades for constrained devices. This is exactly why crypto-agility matters; organizations need the ability to test, deploy, and rotate algorithms without rewiring their underlying infrastructure each time standards evolve.

Automated Certificate Lifecycle Management

Manual certificate management is not just inefficient; it is a genuine operational liability. When certificates live in spreadsheets out of sight, organizations lose visibility, and the result is expired credentials, weak key sizes, outdated signature algorithms, and noncompliant configurations that no one notices until something breaks. The resulting outages can confuse users, interrupt revenue, and land on whichever team is least prepared to explain them.

A complete CLM platform addresses this across the full life of a certificate:

  • Discovery: continuous scanning of cloud environments, datacenters, containers, and external domains to find all certificates in use.
  • Monitoring: tracking expiration dates, algorithms, key strengths, and compliance with security policy in real time.
  • Validation: Utilize direct API integration with public and private CAs, while automating domain validation and approvals
  • Installation: Deploy renewed certificates and keys programmatically through ACME or secure APIs, with no manual handoffs.
  • Revocation: Executing fast, policy-driven revocation is necessary so a compromised certificate can be rotated or revoked everywhere at once rather than hunted down machine by machine.

There is also a payoff hiding in the discovery step: The certificate inventory a CLM platform maintains is, in effect, the beginning of the cryptographic inventory that post-quantum migration planning requires, which can turn a compliance chore into a head start.

Non-Human Identities and Agentic AI

The scale problem is compounded by how modern applications are built. Containers, Kubernetes pods, virtual machines, Internet of Things (IoT) devices, and APIs all need their own credentials, and many of these workloads exist for only minutes or hours before terminating. No team of humans can issue and retire certificates at that velocity.

To keep up with this breakneck pace, AI agents can be utilized to discover, issue, renew, and manage certificates on their own, while remaining inside existing guardrails such as security policies, role-based access control (RBAC), and centralized audit trails. The result is automation at machine speed without giving up enterprise governance.

Where To Start

  1. The first step toward company-wide crypto-agility and resilience is organizational rather than technical. Following guidance from NIST, enterprises should establish a central machine identity services team that owns the CLM platform, standardizes certificate templates, and maintains integrations with public and private CAs. Individual application owners and DevOps teams, in turn, should be responsible for wiring automated renewals into their own deployment pipelines, using the central platform as a shared service. This split keeps governance consistent while eliminating the manual handoffs that cause outages.
  2. Organizations should replace manual validation techniques and workflows with ACME and automated DNS-01 validation now, well before the 10-day DCV window arrives, while deprecating every manual renewal and validation process along the way.
      1. In parallel, organizations should conduct a full inventory of their cryptographic assets to surface hardcoded keys, legacy algorithms, and long-lived trust paths protecting sensitive data.
      2. Post-quantum preparation should start in a controlled environment rather than in production. A dedicated testing lab should be established to allow teams to test hybrid composite certificates and crypto-agile upgrades in a sandbox. By building applications on modular cryptographic libraries connected to a dynamic CLM platform, enterprises can gain true crypto-agility: the ability to rotate keys, ciphers, and algorithms across their infrastructure as standards change, without a rebuild.

The thread that connects all recommendations is inventory. A CLM platform’s discovery step is not busywork before the real fix; it is the same discipline organizations will need across every layer of quantum readiness. Certificates are non-human identities, and the same questions apply to service accounts, AI agents, open source dependencies, and the algorithms buried in application code: What do we have, what does it protect, and which of it matters most to the business?

Organizations that build that inventory muscle now, starting with certificates, will find the rest of the transition far less daunting, because prioritization becomes a calculation rather than a guess. Treating the next few years as a planning window rather than a grace period will help organizations make this transition on their own terms, instead of letting an outage make the decision for them.

Caitlin Dodson is a Summer 2026 Intern for FCTO – Americas at Commvault.

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Key Takeaways

  • Clumio Chat offers a faster, self-service way to evaluate Clumio’s cloud-native data protection capabilities.
  • The AI assistant provides answers about backup, recovery, cyber resilience, deployment, scalability, and cloud workload protection.
  • Explore technical questions about cloud workloads, required permissions, recovery options, and data protection costs.
  • Clumio Chat helps cloud architects, platform engineers, DevOps engineers, SREs, and technical buyers assess whether Clumio fits their environment at their own pace.
  • When ready, users can move directly from product discovery to hands-on evaluation by creating an account and starting a free trial.

A Faster Way to Evaluate Cloud-Native Data Protection

If you’re evaluating cloud-native data protection, you probably want answers before you schedule a demo or talk to Sales.

Clumio by Commvault provides cloud-native backup, recovery, and cyber resilience for AWS and Google Cloud workloads. With Clumio Chat, you can ask product and technical questions, explore how Clumio works, and decide whether it’s the right fit for your environment – all at your own pace.

 

Click “Ask Clumio” in the navigation bar on clumio.com to start a conversation with Clumio Chat.

Introducing Clumio Chat

Clumio Chat is an AI assistant designed to help you learn about Clumio’s cloud-native data protection and recovery capabilities. Whether you’re exploring key features, understanding how Clumio helps protect cloud workloads, or preparing to start a free trial, Clumio Chat gives you answers without requiring a sales conversation.

 

Get Answers to Real Cloud Data Protection Challenges

Instead of searching documentation or waiting for a meeting, you can ask the kinds of technical questions you would normally ask a solutions engineer:

  • What recovery options does Clumio provide for Amazon S3?
  • What permissions does Clumio require, and do I need to deploy any backup infrastructure in my AWS account?
  • What scale does Clumio support for Amazon S3?
  • How does Clumio help reduce the cost of long-term cloud data protection?

 

Try It Now

Clumio Chat helps you move from product discovery to hands-on evaluation with less friction. Learn how Clumio works, explore the capabilities that matter most to you, and when you’re ready, create an account and start a free trial.

Try Clumio Chat today and experience a faster, more self-service approach to evaluating cloud-native data protection.

FAQs

Q: What is Clumio Chat?

A: Clumio Chat is an AI assistant that helps you learn about Clumio’s cloud-native backup, recovery, and cyber resilience capabilities before starting a free trial.

Q: Who is Clumio Chat for?

A: Clumio Chat is designed for cloud architects, platform engineers, DevOps, SREs, and technical buyers evaluating cloud-native data protection.

Q: What kinds of questions can I ask?

A: You can ask questions about Clumio’s capabilities, deployment model, cloud workload protection, recovery options, scalability, and other technical topics related to evaluating the platform.

Q: Do I need to talk to Sales before trying Clumio?

A: No. Clumio Chat is designed to help you explore the product on your . If you decide you’d like additional guidance, you can always contact our team.

Q: Where can I try Clumio Chat?

A: Visit chat.clumio.com, or click Ask Clumio in the navigation bar on clumio.com.

Vir Choksi is Principal Product Marketing Manager at Commvault.

More related posts


Backup and Recovery

Read more about Backup and Recovery

Cyber Resilience

Read more about Cyber Resilience

Cyber Resilience for Cloud Apps

Read more about Cyber Resilience for Cloud Apps

Key Takeaways

  • Clumio by Commvault has achieved FedRAMP® Class C (Moderate) Ready status and is now listed in the FedRAMP Marketplace as Legacy FedRAMP Ready.
  • The new milestone enables agencies and regulated organizations to evaluate Clumio while it continues toward a future Class C FedRAMP certification.
  • Clumio provides cloud-native backup and recovery designed specifically for public cloud environments.
  • The announcement expands Commvault’s public sector cyber resilience portfolio, complementing Commvault Cloud for Government, which addresses organizations requiring FedRAMP Class D (High).
  • Government agencies, contractors, technology partners, and regulated commercial organizations can all benefit from additional cloud-native cyber resilience options.
    As more government agencies and regulated organizations embrace the cloud, they need data protection that’s built for modern environments and aligned with evolving federal security requirements.

Clumio by Commvault, which provides cloud-native backup and recovery designed specifically for public cloud environments, has achieved FedRAMP Class C (Moderate) Ready status and is now listed in the FedRAMP Marketplace. This important step expands cloud-native cyber resilience options for federal agencies, government contractors, and regulated organizations while moving Clumio closer to a future FedRAMP Class C certification.

Opening New Opportunities

FedRAMP is the U.S. government’s standardized approach to assessing the security of cloud services used by federal agencies. While an Authorization to Operate (ATO) is the ultimate goal, FedRAMP Class C Ready is the first major public step in that process.

After successfully completing its Readiness Assessment Report (RAR), Clumio is now listed in the FedRAMP Marketplace as Legacy FedRAMP Ready. This makes it easier for agencies, partners, and regulated organizations to discover and evaluate Clumio as it continues through the FedRAMP certification process.

Built for Modern Cloud Environments

As organizations continue updating their IT environments, traditional backup approaches often struggle to keep pace with cloud-native applications and services. Clumio was built specifically for the cloud, helping make it easier to protect data, simplify recovery, and strengthen cyber resilience without adding unnecessary complexity.

For organizations operating in FedRAMP Moderate environments, that means access to a cloud-native backup and recovery solution designed to align with federal security requirements while supporting operational efficiency.

Why This Matters for Customers

The demand for guarded, cloud-native data protection continues to grow across both the public and private sectors. Federal agencies, government contractors, and regulated commercial organizations all face increasing pressure to protect critical workloads while meeting evolving compliance expectations.

Clumio’s FedRAMP Class C Ready status helps address those needs by helping:

  • Expand cloud-native backup and recovery options for federal agencies and organizations operating in FedRAMP Moderate environments.
  • Provide greater visibility through the FedRAMP Marketplace procurement process.
  • Support customers that want to extend cloud-native data protection into regulated environments.

For existing customers, including organizations with both commercial and government cloud environments, this milestone also creates new opportunities to standardize cloud-native data protection across their operations.

Strengthening Commvault’s Government Portfolio

Clumio’s FedRAMP Class C Ready status complements Commvault® Cloud for Government, which serves organizations requiring FedRAMP Class D (High).

Together, these offerings give customers more flexibility to protect data across cloud, hybrid, and cloud-native environments while supporting different federal security requirements. Organizations with cloud-native workloads can evaluate Clumio for FedRAMP Moderate environments, while Commvault Cloud for Government addresses organizations requiring FedRAMP High.

Looking Ahead

Clumio’s FedRAMP Class C Ready status reflects Commvault’s ongoing investment in cloud-native cyber resilience for the public sector. As Clumio advances toward a future FedRAMP Class C certification, customers can begin evaluating the offering while Commvault continues expanding its public sector cyber resilience portfolio.

FAQs

Q: What is FedRAMP Class C (Moderate) Ready status?

A: FedRAMP Class C (Moderate) Ready status means Clumio has successfully completed its RAR and has been approved by the FedRAMP Program Management Office (PMO) for listing in the FedRAMP Marketplace as Legacy FedRAMP Ready. This allows federal agencies and other regulated organizations to evaluate the offering while Clumio continues through the FedRAMP process toward a potential future Class C FedRAMP certification ATO.

Q: Is FedRAMP Class C (Moderate) Ready the same as an Authorization to Operate (ATO)?

A: No. FedRAMP Class C Ready is an early milestone in the FedRAMP process. It is not equivalent to a full ATO.

Q: What is the FedRAMP Marketplace?

A: The FedRAMP Marketplace is the federal government’s official catalog of cloud service offerings participating in the FedRAMP program. It provides agencies and procurement teams with visibility into each offering’s status in the FedRAMP lifecycle.

Q: Who benefits from Clumio’s FedRAMP Class C Ready status?

A: The milestone can be valuable for federal agencies, government contractors, government-focused partners, and regulated commercial organizations that operate in FedRAMP Class C environments or use FedRAMP as a security benchmark.

Q: How does Clumio fit into Commvault’s government portfolio?

A: Clumio provides cloud-native backup and recovery for organizations with cloud-native workloads operating in FedRAMP Class C (Moderate) environments, while Commvault Cloud for Government can serve customers requiring FedRAMP Class D (High). Together, the offerings provide organizations with more flexibility based on their federal security requirements.

Poojan Kumar is Chief Product Innovation Officer at Commvault; and President & CEO of Clumio, a Commvault Company.

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Throughout the Ready. Or Not. series, we’ve explored topics like agentic AI, digital trust, the human factor, and vibe coding. In this fifth and final episode of season one, the conversation shifts to the one constant behind every AI conversation: data. 

Nathan Macintosh sits down with Ben Lorica, former chief data scientist at O’Reilly Media and founder of Gradient Flow, to discuss what AI readiness really looks like. Their conversation moves beyond algorithms and applications to the work organizations need to do before AI can succeed.  

They explore why AI is changing the way we think about governance, why collecting more data isn’t always the answer, and why preparation matters just as much as adoption. 

Watch the full episode on Readiverse. 

Key Takeaways 

  • AI readiness starts with understanding and organizing the data you already have.  
  • Governance now applies to AI systems, not just people.  
  • More data isn’t always better. Strive for better data. 
  • AI introduces new risks that require new processes, not just new technology.  
  • The organizations best prepared for AI are building strong data foundations today. 

Organizations are generating and managing more data than ever before. It’s easy to assume the next step is simply collecting more data. Ben explains why preparing and governing the data you already have may be a much stronger foundation for AI. 

One thing I appreciated about Ben’s perspective is that he never presents AI readiness as a technology problem alone. It’s an organizational challenge that starts long before teams begin putting AI to work. 

Here are a few ideas that stayed with me. 

AI Is Only as Good as the Data Behind It 

“Focus on the data you have … and get that ready for AI.”

– Ben Lorica 

One of Ben’s first points challenged a common assumption. When organizations talk about becoming “AI ready,” the instinct is often to collect more data. Ben sees it differently. Instead of prioritizing quantity, he encourages organizations to focus on quality and prepare their existing data for AI. 

That starts with understanding what data you have, organizing it, and making sure it’s accurate and well governed. As AI becomes part of more business processes, organizations will rely on many different types of information, from spreadsheets to text, images, audio, and video. If that data isn’t reliable, AI won’t fix the problem – and it can make it even more difficult to spot. 

There’s understandable pressure to move quickly with AI. This conversation reminded me that taking the time to build a solid data foundation may be one of the smartest investments we can make. Clean, well-governed data helps organizations make better decisions today while preparing them for whatever comes next. 

AI Changes the Role of Governance  

Ben points out that governance has a broader job to do. It’s no longer just about managing how people access and use information. Organizations also need to think about how AI interacts with that information and the actions it takes. 

As AI becomes part of everyday work, it can access, analyze, and act on information at a scale and speed that’s difficult for people to match. That means organizations need to understand what AI can access, how it’s using that information, and what safeguards should be in place to protect sensitive data. 

What’s interesting is that the fundamentals of governance haven’t changed. Clear policies around access, security, and accountability are just as important as they’ve always been. What is changing is the number of systems interacting with organizational data and the pace at which information moves across the business. 

To me, that’s one of the most important takeaways from this episode. AI doesn’t replace good governance. It makes it even more important. 

Sneak Peek: When Data Starts to Multiply

 

What happens when AI allows five people to do the work of 100? Ben explains why the real challenge isn’t productivity. It’s the explosion of data that comes with it. 

Responsible AI Starts With Responsible People 

One thing Ben emphasizes throughout the conversation is that organizations can’t rely on technology alone to make AI responsible. The people using AI play an important role, too.  

Whether employees are entering prompts, uploading documents, or fine-tuning models, they need to understand what information they’re sharing and how it could be used. Guardrails aren’t just about restricting access. They’re also about helping people make informed decisions when working with AI. 

Ben points out that organizations should think beyond what goes into an AI system. They should also pay attention to what comes out. AI can unintentionally generate sensitive information, making review and oversight of the outputs just as important as the prompts that started the interaction. 

It’s another reminder that responsible AI isn’t just a technology challenge. It’s a shared responsibility between the people using AI and the policies that guide them. 

Plan for the Unknown 

There’s understandable pressure to adopt AI quickly. New tools are emerging almost daily, and organizations don’t want to fall behind. But Ben makes the case that readiness isn’t just about moving fast. It’s about having the right processes in place before they’re needed. 

Toward the end of the conversation, Ben points out that many AI teams haven’t fully considered what they’ll do when things go wrong. I love Nathan’s response because it was exactly what I was thinking: 

“Why wouldn’t they think of that? That’s all I think about.”

– Nathan Macintosh 

In cybersecurity, resilient organizations don’t wait for an incident before deciding how they’ll respond. They establish roles, define processes, and prepare for different scenarios long before they’re needed. Ben argues that AI deserves the same level of preparation. 

That means asking questions many organizations haven’t fully considered yet, like: 

  • What data should AI have access to?  
  • Who should be involved if an AI-generated output creates a problem?  
  • How will decisions be made if something unexpected happens?  

These conversations may not be as exciting as launching an AI initiative, but they’re just as important. 

One Final Takeaway 

As this season of Ready. Or Not. comes to a close, one thing has become clear to me. Every episode explored a different AI concept or trend, yet they all reinforced the same idea: successful AI adoption isn’t just about the technology. It’s about the people, processes, and preparation that make it possible. 

Organizations don’t have to have every answer before embracing AI. But the more intentional they are about building strong foundations today, the more prepared they’ll be for whatever comes next. 

Watch the full episode on Readiverse. 

FAQs 

Q: What does AI readiness mean? 

A: AI readiness begins with understanding, organizing, governing, and protecting the data your organization already has. Strong data practices create the foundation AI depends on. 

Q: Should organizations collect more data for AI? 

A: Not necessarily. Ben recommends focusing first on improving the quality and organization of existing data before expanding data collection efforts. 

Q: What’s the role of employees in responsible AI use? 

A: Employees play an important role in AI governance. They need to understand what information is appropriate to share with AI, review AI-generated outputs carefully, and follow organizational policies for using AI responsibly. 

Q: Why does AI change data governance? 

A: AI systems increasingly access, analyze, and act on organizational data. That means governance policies need to apply to machines as well as people. 

Q: Why should organizations prepare for unexpected AI issues? 

A: AI can introduce new risks, from exposing sensitive information to producing unintended results. Preparing in advance by defining responsibilities and response processes helps organizations address those situations with greater confidence. 

Q: What’s the biggest takeaway from this episode? 

A: AI readiness isn’t just about adopting new technology. It’s about building solid governance, good data practices, and resilient organizational processes that help allow AI to be used responsibly and effectively. 

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Why Modern Cyber Risk Demands A-to-Z Cyber Resilience

Ransomware attacks target the full data lifecycle from backups to production systems. See how Commvaults A-to-Z cyber resilience approach unifies protection, detection, and recovery to help manage risk and restore operations fast. 

Key Takeaways 

Modern cyber risk demands unified resilience across the entire data lifecycle, from prevention to recovery, as fragmented tools fail to address today’s complex threat landscape. 

  • Cyber risk now affects customer trust, with breaches often leading to lost business and reputational damage. 
  • A-to-Z resilience brings protection, monitoring, governance, and recovery into a unified, more effective strategy. 
  • Leadership is essential in driving proactive defense, rapid response, and clear communication across the organization. 
  • Fragmented data security tools leave gaps in hybrid environments that attackers can exploit more easily. 
  • An end-to-end approach helps improve visibility, speed recovery, and maintain business continuity. 

Modern cyber risk spans the entire data lifecycle – from vulnerabilities and threats to recovery and compliance – making fragmented, reactive tools insufficient. Organizations need A-to-Z cyber resilience that unifies protection, monitoring, governance, and recovery. This approach helps manage risk, strengthen security posture, and enable faster, more reliable recovery across complex hybrid environments. 

A Single Breach Can Cost You Customer Trust

Cyber risk is no longer just an IT issue – it is a direct threat to customer trust and revenue.  

Sixty-four percent of consumers would stop doing business with a company after a significant data breach, highlighting how quickly loyalty erodes when data is compromised.  

This shift raises the stakes: Resilience is no longer optional; it is expected. 

At the same time, there is a disconnect between expectations and behavior. Consumers demand strong data protection, yet risky habits like password reuse or unsecured networks persist. That inconsistency can increase exposure and places more responsibility on organizations to protect data across every touchpoint. 

Trust is earned through consistent action – especially in cybersecurity. 

Commvault Cloud, powered by Metallic AI, helps organizations take that action by unifying protection, monitoring, and recovery across the full data lifecycle, reinforcing trust through consistent execution. The infographic reflects this A-to-Z approach, spanning early warning, threat monitoring, and rapid recovery. 

For organizations, the takeaway is clear: Resilience is not just about preventing attacks. It is about maintaining trust when prevention fails. 

 

Cyber Resilience Starts with Leadership

As threats grow more sophisticated, cyber resilience has become a business priority that extends beyond IT teams. Leadership plays a critical role in aligning strategy, investment, and accountability across the organization. 

This mandate shows up in three ways: 

  1. Protect before the breach.
    Strengthen defenses with zero-trust principles, regular monitoring, and unified platforms that adapt to evolving threats. 
  2. Respond fast when incidents occur.
    Customers and stakeholders judge organizations not just on whether a breach happens – but how quickly and effectively they recover. 
  3. Communicate with transparency
    Clear, timely communication helps preserve trust. Silence or delays can amplify reputational damage. 

According to industry data, the average cost of a breach has reached $4.88 million, reinforcing that cyber incidents are both operational and financial risks. 

Commvault Cloud supports this leadership mandate by bringing governance, threat detection, and orchestrated recovery into a single platform – helping organizations align teams and respond with greater speed and coordination.  

End-to-End Resilience Helps Manage Risk

Modern environments are too complex for fragmented tools to keep up. Data spans hybrid cloud, on-prem systems, and SaaS applications – creating a broad and dynamic attack surface. Point solutions leave gaps that attackers exploit. 

An end-to-end approach helps close those gaps by integrating capabilities across the lifecycle: vulnerability management, threat detection, immutability, air-gapped protection, and orchestrated recovery. This unified model helps improve visibility and enable faster, more reliable response. 

Commvault Cloud brings these capabilities together with AI-enabled insights, regular monitoring, and automated recovery workflows, helping organizations manage risk and maintain operational continuity across hybrid environments. 

Organizations should plan for cyber incidents as an expected event and prioritize resilience and recovery readiness. The difference lies in readiness – and having a unified approach to protection, detection, and recovery across the data lifecycle. 

Frequently Asked Questions

What is A-to-Z cyber resilience?

A-to-Z cyber resilience is a unified approach that covers the entire data lifecycle from protection and monitoring through governance and recovery. Commvault Cloud helps you implements this through its resilience operations (ResOps) framework, replacing fragmented tools with an integrated strategy that uses AI-enabled threat detection, immutable storage, and orchestrated recovery to help manage risk and improve response times across hybrid environments. 

Why is cyber resilience a business priority, not just an IT concern?

Cyber incidents can directly impact customer trust, revenue, and brand reputation. Commvault Cloud helps organizations address this risk with unified data protection and threat monitoring, giving business leaders visibility and control to be able to respond quickly and maintain trust across critical operations. 

How does a data breach affect customer trust?

A single breach can quickly erode customer confidence, especially when sensitive data is exposed. Commvault Cloud Threat Scan helps identify hidden threats in backup data, enabling safer recovery and helping organizations maintain trust through more reliable, clean restore processes. 

What role does leadership play in cyber resilience?

Leadership aligns strategy, investment, and accountability across the organization. With Commvault Cloud and its ResOps framework, leaders can unify protection, detection, and recovery efforts, helping teams act faster, coordinate response, and communicate effectively during cyber incidents. 

Why are fragmented cybersecurity tools no longer effective?

Modern environments span hybrid cloud, SaaS, and on-prem systems, creating a broad attack surface. Commvault Cloud unifies capabilities like air-gapped protection, regular monitoring, and automated recovery, helping eliminate gaps and enable more coordinated, efficient responses to threats. 

How does Commvault Cloud support cyber resilience?

Commvault Cloud integrates protection, threat detection, and recovery into a single platform. With capabilities like Commvault Cleanroom™ and automated workflows, it helps organizations manage risk, accelerate recovery, and maintain business continuity across the data lifecycle. 

Explore related resources

Explore

Unified Data Protection

Understand what a unified data protection strategy means along with tips on what enterprise organizations can follow to be truly cyber resilient.
Read more about Unified Data Protection
Solution brief

Streamlining Data Protection and Management for the Hybrid Enterprise

Learn why Commvault’s solution can help organizations streamline their data management processes, manage risk, and enable the resilience of their critical data.
Read brief about Streamlining Data Protection and Management for the Hybrid Enterprise

Every episode of Ready. Or Not. has challenged me to think about AI a little differently. The conversations have moved from understanding agentic AI to building trust and preparing organizations for responsible adoption. This episode turns its attention to vibe coding and why it’s becoming one of AI’s most talked-about ways of working.

Comedian Nathan Macintosh sits down with Microsoft engineer and open-source leader Harald Kirschner to discuss what vibe coding really means, why it’s gaining momentum, and where it can go wrong if speed outpaces oversight.

Watch the full episode on Readiverse.

Key Takeaways

  • AI is making it easier for organizations to test ideas, solve problems, and innovate faster.
  • Vibe coding helps teams quickly explore and validate ideas before making larger investments.
  • AI delivers more value when it’s used to challenge assumptions – not just generate content.
  • Human judgment, thoughtful review, and clear guardrails remain essential in an AI-driven world.
  • The organizations that learn faster will be better positioned to innovate.

I was already familiar with the term vibe coding, but after listening to this episode, I walked away with a much better understanding of why people – not just developers, but also nontechnical teams – are embracing it.

By the end of the conversation, I realized vibe coding isn’t really about coding at all. It’s about learning faster and knowing where AI fits into the creative process. The conversation also makes something else clear: AI may accelerate the work, but people are still responsible for guiding it. That’s why guardrails matter more than ever. Here are some of the themes that resonated with me.

From Idea to Reality

One thing I learned about vibe coding is that it’s changing how organizations explore ideas. Instead of spending weeks building something before finding out whether it works, teams can quickly create a prototype, gather feedback, and decide whether it’s worth pursuing.

“AI can be a really good critical thought partner if it’s applied properly.”

– Harald Kirschner

Harald explains that vibe coding uses natural language to turn ideas into working software. He uses software development as an example, but the concept extends beyond engineering teams. For a product manager testing a new feature, a designer exploring an interface, or a business leader validating a concept, AI makes it much easier to turn an idea into something people can actually experience.

That ability to experiment may be one of AI’s greatest strengths. Organizations can learn what resonates, refine ideas earlier, and invest time and resources only after they’ve gained confidence that they’re solving the right problem.

Moving Fast Still Requires Oversight

One thing Harald emphasizes throughout the conversation is that speed shouldn’t come at the expense of a thorough review.

Again, he uses software development as an example. AI can quickly generate working code, but that doesn’t automatically make it secure, reliable, or ready for production. Developers still need to review it, test it, and make sure it meets the same standards they would apply to anything else they build.

Harald’s lesson extends well beyond engineering. As AI becomes part of business processes, organizations will need the same mindset whether they’re generating software, creating content, analyzing data, or automating workflows. Vibe coding can help the work move faster, but people are still responsible for validating the results.

That’s one of the most important lessons from the episode. While AI can make it easier to create something quickly, human expertise is what turns a good idea into something people can trust.

Honest Feedback Gets Better Results

A memorable moment in this episode starts with an unexpected prompt. Instead of asking AI to write code, Harald asks it to critique his work by prompting it to “Roast my code.”

It’s funny, but it’s also an effective way to get more honest feedback from AI. Instead of acting like an assistant that simply completes a task, AI becomes more like a trusted colleague offering another perspective. Used this way, it can challenge assumptions, uncover blind spots, and improve the quality of the final result.

AI’s constructive criticism can help us improve our work, but it also becomes more useful when we continue teaching and refining it. Anyone who’s spent time working with AI knows it could use a little feedback, too.

Sneak Peek: Checking the Vibe

What happens when AI keeps making the same mistakes? Nathan compares it to an unruly party guest who eventually stops getting invited. Hear Harald explain how to train AI to become more useful over time.

Innovation Becomes More Accessible

Something that keeps resurfacing throughout the conversation is that AI is changing who gets to participate in innovation.

AI is lowering the barrier for people across an organization to explore ideas, experiment with new approaches, and quickly bring concepts to life. Instead of relying on technical specialists to validate every idea, more people can create something tangible, gather feedback, and refine their thinking before significant time and resources are invested.

“… you can actually build it and hand it to some people and see like, oh, this is flying, or this is really falling flat.”

– Harald Kirschner

To me, that’s one of AI’s most exciting opportunities. By making experimentation faster and more accessible, AI gives organizations the confidence to test more ideas, learn from them sooner, and involve more people into the creative process.

Ready for What’s Next

Vibe coding may be the workflow everyone’s talking about today, but the bigger story is how AI continues to change the way we learn, experiment, and solve problems. Every episode of Ready. Or Not. reminds me that the organizations willing to explore new technology will be the ones best prepared for what’s next.

Watch the full episode on Readiverse.

FAQs

Q: What is vibe coding?

A: Vibe coding is an emerging way of working with AI that uses natural language to quickly turn ideas into something tangible. Instead of starting from scratch, people can use AI to prototype concepts, explore solutions, gather feedback, and iterate much more quickly.

Q: Why is vibe coding generating so much interest?

A: Vibe coding lowers the barrier to experimentation. It allows more people – not just technical specialists – to test ideas, validate concepts, and learn what works before investing significant time and resources.

Q: Does vibe coding replace human expertise?

A: No. The conversation makes it clear that AI works best as a collaborator, not a replacement. People are still responsible for applying judgment, reviewing results, and deciding what should move forward.

Q: Why do organizations still need guardrails when using AI?

A: AI can accelerate work, but it doesn’t eliminate the need for thoughtful oversight. Clear policies, review processes, and human expertise help organizations validate AI-generated work and reduce unnecessary risk.

Q: How can AI improve the way organizations work?

A: Beyond generating content or prototypes, AI can help challenge assumptions, identify blind spots, suggest improvements, and accelerate learning. Used thoughtfully, it becomes another perspective that helps teams make better decisions.

Q: What’s the biggest takeaway from this episode?

A: The greatest value of AI isn’t simply helping organizations move faster. It’s helping them experiment more freely, learn more quickly, and involve more people in the innovation process – while continuing to rely on human judgment to guide the final decisions.

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Key Takeaways

  • Commvault has joined the Open Secure AI Alliance to help advance open, secure, and collaborative approaches to AI.  
  • Open source AI tools give organizations greater visibility and control, allowing experts to inspect, adapt, and strengthen systems as threats and requirements evolve.  
  • Effective AI security extends beyond models to include identity, permissions, guardrails, logging, evaluation, and the broader environment in which AI agents operate.  
  • Cross-industry collaboration and shared research can help organizations respond more quickly to the rapidly changing challenges created by increasingly capable agentic AI.  
  • Commvault will share its cyber resilience and data expertise with the Alliance, grounded in the principle that organizations can better protect systems and data they fully understand.  

Collaboration has long been one of the most effective ways the technology industry meets new challenges. The past few months have brought that lesson into sharper focus for AI. Agentic systems are becoming more capable, more independent, and more deeply connected to the technology we use every day.  

Recent events also have shown how quickly this landscape can change. When an advanced AI system created an unexpected security challenge for Hugging Face, the organization used an open-weight model on its own infrastructure to understand and contain the situation. The experience demonstrated the value of open source AI tools that organizations can inspect, adapt, and control when needed.  

Moments like this should not diminish our optimism about AI. They should deepen our commitment to shaping its future together.  

That is why Commvault is proud to join the  Open Secure AI Alliance, a community of leading organizations advancing AI through open research, shared knowledge, and practical tools.  

AI will keep evolving, and no single organization will have every answer. Bringing together deep expertise from across the industry gives the community a better chance to understand what is changing and respond with the speed this new era demands.  

Open source is central to that effort. It gives experts the ability to examine how systems work and improve what others have started. For defenders, it also provides something essential: the freedom to choose and adapt the right technology for the situation rather than depending on a single system or provider.  

NVIDIA describes this as an open defense foundation built on models, harnesses, and tools that the community can study and strengthen.  

The Alliance also recognizes that AI security extends well beyond the model. Identity, permissions, guardrails, logs, and evaluation all shape how an agent behaves. Understanding that complete environment will take new research and a willingness to share what the industry learns along the way.  

Commvault’s perspective is grounded in years of solving complex cyber resilience challenges – helping organizations understand their data, keep it trustworthy, and recover with confidence when disruption strikes.  

Much of that work comes down to the same idea the Alliance is pursuing: You can only protect what you fully understand. That’s the experience we hope to bring, alongside an eagerness to learn from others tackling these challenges from different angles. 

The opportunity ahead for AI is enormous. Realizing it will depend not only on how quickly the technology advances, but on how openly the industry works together as it does. Commvault is glad to be part of that work, and excited to help build what comes next.  

Read NVIDIA’s announcement here: Industry Leaders Join the Open Secure AI Alliance.  

FAQs

Q: What is the Open Secure AI Alliance?
A: The Open Secure AI Alliance is a community of organizations working to advance AI security through open research, shared knowledge, models, harnesses, and practical tools. Its collaborative approach gives participants opportunities to study emerging challenges and strengthen AI defenses together. 

Q: Why has Commvault joined the Open Secure AI Alliance?
A: Commvault joined the Alliance to contribute its experience in cyber resilience, data understanding, trust, and recovery. It also provides an opportunity for Commvault to learn from other industry leaders approaching AI security from different perspectives. 

Q: Why is open source important for AI security?
A: Open source allows experts to examine how AI systems work, build on existing technologies, and adapt tools to specific security situations. It also gives defenders greater freedom to select and modify technologies rather than relying on a single system or provider. 

Q: What does AI security involve beyond protecting the model?
A: AI security encompasses the broader environment in which an AI system operates, including identity, permissions, guardrails, logs, and evaluation. Understanding these interconnected elements can help organizations better assess and manage how AI agents behave. 

Q: How does Commvault’s cyber resilience experience relate to AI security?
A: Commvault’s cyber resilience work focuses on helping organizations understand their data, maintain its trustworthiness, and recover confidently after disruption. That perspective fits naturally with the Alliance’s focus on open, inspectable approaches to AI security.  

Q: Why is industry collaboration important for the future of AI?
A: AI is evolving too quickly and broadly for any single organization to have every answer. Combining expertise, research, and practical insights across the industry can help the community understand emerging challenges and respond at the speed AI development demands. 

Alexander Coombes is AVP, Strategic Partner Development, at Commvault.

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Cloud Backup and Recovery Explained: From Threat Detection to Full Recovery

Learn how cloud backup and recovery works to help protect clean data, validate recovery readiness, and restore business operations after a ransomware attack or cyber incident.


The ideal cloud backup and recovery process begins by detecting threats such as ransomware, suspicious access, or abnormal data activity. Organizations can then obtain clean, immutable backup copies; validate unaffected recovery points; and isolate compromised systems. Once verified, critical applications and data can be restored through automated recovery processes, helping minimize downtime, reduce data loss, and restore business operations quickly and safely.


Cyber resilience is increasingly measured by what happens after attackers get in. Organizations have invested heavily in prevention, detection, and response, but ransomware, vulnerability exploitation, credential abuse, cloud misconfigurations, and third-party compromise continue to disrupt operations.

For many teams, the recovery challenge is no longer simply whether backups exist. It is whether those backups are clean, protected, validated, and ready to restore critical services when production systems can no longer be trusted.

That distinction matters because cyberattacks continue to create both data risk and operational disruption. According to the Verizon 2026 Data Breach Investigations Report, ransomware was involved in 48% of breaches, up from 44% the previous year. The report also found that exploitation of vulnerabilities became the most common initial access vector for breaches, rising to 31% while credential abuse fell to 13%.

Cloud backup and recovery efforts need to support the full path from detection to restoration. That starts with identifying suspicious activity before compromised data is restored. It continues with protected, immutable recovery points that give teams usable recovery options when production systems are no longer trusted.

From there, organizations need a way to validate which recovery points are clean and restore critical workloads in the right order. The result is a recovery strategy that helps teams move from incident response to operational restoration with more confidence.

 


Why is Cloud backup and recovery a cyber resilience strategy?

Traditional backup strategies were designed to help organizations recover from hardware failures, accidental deletion, and localized outages. Those use cases still matter, but today’s recovery requirements are broader.

Cyberattacks can affect production workloads, identity systems, cloud configurations, SaaS applications, and backup environments at the same time. When that happens, recovery is not just about restoring a copy of data. It is about determining which systems can be trusted, which recovery points remain clean, and which services need to come back first.

That is why cloud backup and recovery has become a critical part of cyber resilience. A modern strategy should help teams detect suspicious activity, protect recovery data, validate backup integrity, and restore critical operations in a controlled sequence. It should also help support regular testing, because a recovery plan that has not been exercised may not perform as expected during a real incident.

This marks a shift from backup as an insurance policy to recoverability as an operational capability. Stored copies still matter, but they are only one part of the recovery equation. Teams also need confidence that recovery data has not been altered, that restoration workflows have been tested, and that the business knows which services must come back first.

Cloud backup and recovery becomes easier to understand when it is viewed as a lifecycle. The five stages below show how organizations can move from early threat detection to validated recovery and long-term resilience improvement.


Stage 1: Detect threats before recovery risk spreads

Recovery starts before systems are restored. In a cyber incident, the first priority is to understand whether suspicious activity has affected production data, backup data, or both.

If teams restore from a compromised recovery point, they may bring corrupted files, malware artifacts, or unauthorized changes back into the environment. That risk makes threat detection an important part of cloud backup and recovery, not just a security operations concern.

Modern recovery strategies should include visibility into abnormal activity across workloads, backup environments, and recovery points. Teams may need to investigate signals such as:

  • Unusual encryption behavior
  • Sudden deletion spikes
  • Unexpected privilege changes
  • Abnormal backup patterns
  • Malware indicators

These signals can help teams understand where an attack may have spread and which data may require additional review before restoration.

Timing is another essential factor. Microsoft’s 2025 Digital Defense Report found that most attacks investigated by its Detection and Response Team (DART) had short dwell times, which means recovery teams may not have weeks to understand the full scope of compromise before attackers move laterally, access sensitive data, interfere with services, or attempt to affect backup systems. Detection context can help teams avoid treating every recovery point as equally trustworthy.

59% of attacks Microsoft DART investigated had dwell times of seven days or less, making early detection critical to recovery decisions.
Source: Microsoft Digital Defense Report 2025

Threat detection doesn’t eliminate recovery risk on its own. It helps create a more informed recovery process. When suspicious activity is identified early, organizations can isolate affected systems, investigate impacted data, and avoid restoring recovery points that may reintroduce the same threat.

That gives security, IT, and recovery teams a clearer starting point for the next stage: protecting clean recovery points before attackers can alter or remove them.


Stage 2: Protect clean recovery points from attack

In a cyber incident, backups are not just stored copies. They are part of the recovery path, which means attackers may try to disrupt them. If backup data is altered, encrypted, deleted, or made inaccessible, the organization may lose one of its best options for restoring operations without relying on compromised production systems.

That’s why clean recovery points need layered protection. Immutable and indelible backup storage can help preserve data for a defined retention period. Offsite or isolated copies help add separation from the production environment. Encryption, access controls, and role-based permissions help limit who can access or change backup settings. Together, these safeguards make it harder for attackers to interfere with the data teams may need most during recovery.

The goal is to preserve recovery choice. The 2026 Verizon report found that 69% of ransomware victims in its dataset did not pay the ransom, up from 65% the prior year. The report also notes that median ransom payments continued to decline, which it links in part to improved defensive adaptations and increased victim resilience. Teams need clean backups they can actually use, so paying a ransom is not the only path back to business.

The familiar 3-2-1 backup rule still provides a useful foundation: Keep three copies of data, on two different media or platforms, with at least one copy stored offsite or isolated. Modern cloud backup and recovery strategies often extend that model with immutable storage, air-gapped patterns, policy-based retention, and replicated copies across cloud or hybrid environments.

With protected recovery points in place, teams can pare down their restore options and move into validation with a clearer view of what is ready to bring back.


Stage 3: Validate which backups are ready to restore

Having backups is not the same as being ready to recover. Before teams restore production systems, they need to know which recovery points are usable, which workloads were affected, and what dependencies must come back with them.

A recent backup may contain the latest business data, but it also may include corrupted files, unauthorized changes, or malware artifacts. An older backup may be cleaner, but it may create more data loss. Validation helps teams make that tradeoff with evidence instead of guesswork.

That work starts with scoping the incident. Security and IT teams need to understand when suspicious activity began, which systems were touched, and whether identity services, databases, file shares, SaaS applications, or cloud configurations were affected.

They also need to confirm whether the recovery point supports the application as a whole, not just the data behind it. A database restore, for example, may depend on application servers, permissions, encryption keys, network routes, and identity services all being available in the right state.

Isolated recovery environments can help teams test those conditions before restoring into production. In a controlled environment, teams can safely:

  • Scan selected recovery points.
  • Review file changes.
  • Confirm application startup.
  • Test user access.
  • Check whether dependent systems behave as expected.

Validation also should feed the recovery sequence. Teams may need to restore identity services first, then core infrastructure, then mission-critical applications, and then supporting workloads.

By testing recovery points before restoration, they can narrow their options and decide which systems are ready to bring back, which need further review, and which should remain isolated until the risk is better understood.

The next stage is where that decision turns into action: restoring the systems, applications, and data the business needs first.


Stage 4: Restore critical operations in the right order

A restore plan starts with the organization’s minimum viable operating state. That means identifying the people, systems, applications, data, and communication channels the business needs to function at a basic level during a disruption.

For some organizations, that may start with identity services and employee communications. For others, it may prioritize customer-facing applications, payment systems, clinical systems, manufacturing operations, or logistics platforms. The order should reflect business impact, not just technical convenience.

Dependencies are where many recovery plans become more complicated. An application may be listed as “critical,” but it still depends on identity, DNS, network connectivity, databases, storage, encryption keys, APIs, and monitoring. If those pieces are not restored in the right state, the application may come back online but remain unusable. That is why recovery teams need dependency mapping before an incident, not during one.

Runbooks and orchestrated workflows help turn those decisions into repeatable steps. They can define who approves the restore, which environment should be used, which checks must happen before production access is restored, and when the next tier of systems can come online. This matters when security, infrastructure, application, cloud, and business teams are all working at the same time.

Restoration also needs checkpoints. After each major workload comes back, teams should confirm that users can authenticate, data is available, integrations are working, and monitoring is in place. Those checks help catch problems before recovery expands to the next tier of systems.

Speed still matters, but control matters just as much. A fast restore can create more work if the wrong data comes back, if access controls are missing, or if an application returns without the systems it needs to run. The stronger approach is to restore in phases, confirm that each critical service is working, and then continue expanding recovery as the environment stabilizes.


Stage 5: Turn recovery lessons into stronger continuity

Once critical services are restored, teams still need to understand what worked, what slowed them down, and where the recovery plan did not match reality. That follow-through is what turns cloud backup and recovery from a response activity into an ongoing resilience practice.

The first step is reviewing the recovery itself. Teams should ask questions such as:

  • How quickly did teams detect suspicious activity?
  • Were clean recovery points easy to identify?
  • Which validation steps took longer than expected?
  • Where did restore workflows slow down?
  • Were the right people involved at the right time?

These answers can reveal gaps that are not always technical. A recovery may succeed and still expose problems with decision-making, communication, approvals, or handoffs between teams.

Those findings should feed directly into the next version of the recovery plan. If a critical application depended on a system that was not documented, update the dependency map. If access controls slowed restoration, clarify the approval process. If recovery testing missed a key workload, add it to the next exercise. If business leaders lacked visibility into what was restored and what was still offline, improve reporting and escalation paths.

Regular testing is what keeps this work grounded. Tabletop exercises, isolated restores, clean recovery testing, and cross-cloud recovery validation help teams find issues before a real incident forces them to learn under pressure. They also help give leaders better evidence of where the organization is ready and where it still has work to do.

Over time, the goal is a recovery program that gets sharper after every test and every incident. Teams are better prepared, recovery steps are better understood, and the organization has a clearer path for keeping essential operations running through disruption.


Turning Cloud recovery into business resilience

 Cloud backup and recovery now plays a larger role than traditional data protection alone. It is the connected process of detecting recovery risk, protecting backup data, validating clean restore options, and restoring critical services when production environments can no longer be trusted.

In a cyber incident, those activities cannot operate as separate handoffs. Threat context should inform which backups are reviewed. Backup protection should preserve the recovery options teams may need. Validation should determine what is ready to restore. Restoration should bring back the services the business depends on in a controlled order.

A backup that cannot be trusted, tested, or restored at the right time may not give the business the outcome it needs. A restore process that ignores identity, application dependencies, or business priorities can leave systems technically recovered but operationally incomplete.

The larger opportunity is to treat recovery as an ongoing resilience practice. That means testing plans before an incident, updating dependency maps as environments change, and using each exercise or recovery event to improve the next response.

Organizations that recover faster are not necessarily those with the most copies of data. It is imperative to know which data is usable, which services matter most, and how to restore them under pressure.

The challenge is to make recovery readiness as operational as detection and response. Cloud backup and recovery provides a practical foundation for that work when it is treated as a continuous path from risk detection to business restoration.

Organizations should build that muscle to help be better positioned to restore clean data, recover critical services, and keep the business moving when disruption hits.

 

Accelerate Clean Recovery After Cyberattacks

Learn more about how Commvault’s data backup and recovery solutions can help organizations detect threats, recover clean data, and reduce downtime.

Frequently Asked Questions

What is the difference between Cloud backup and disaster recovery?

Cloud backup focuses on creating secure copies of data for restoration, while disaster recovery focuses on restoring applications, systems, and business operations after an outage or cyberattack. Together, they help support business continuity and resilience.

Why are immutable backups important for cyber resilience?

Immutable and indelible backups are designed to help prevent backup data from being altered, encrypted, or deleted within defined retention settings. Combined with Commvault AirGap and automated Cleanpoint identification, Commvault’s immutable backup capabilities help keep organizations ready with a verified, clean recovery source available when production systems are compromised.

What should I look for in a Cloud backup and recovery solution?

Look for a platform that unifies hybrid and multi-cloud environments, immutable storage, automated recovery orchestration, and centralized management. Commvault Cloud is designed with these requirements, helping organizations protect diverse infrastructure while minimizing recovery downtime and operational complexity.

Does Commvault’s backup solution provide ransomware protection and air-gapped backups?

Yes. Commvault helps organizations strengthen cyber resilience with immutable backups, air-gapped recovery options, threat detection, clean recovery capabilities, and layered ransomware protection designed to help reduce recovery risk and downtime.

Does Commvault offer automated backup testing and compliance reporting?

Yes. Commvault provides automated recovery testing, backup validation, compliance reporting, and audit-ready visibility to help organizations verify recoverability, demonstrate compliance, and improve recovery readiness.

Related Resources

Video

Cyber Attack Recovery: How to Achieve Minimum Viability in Minutes, Not Days

When cyber attacks strike, every minute costs $14,000 and full recovery takes 24 days on average. But what if you could achieve minimum viability in minutes instead of days?
Watch the video about Cyber Attack Recovery: How to Achieve Minimum Viability in Minutes, Not Days
Solution

Commvault AirGap

Enhanced cyber protection with air-gapped, immutable cloud storage.
Explore the solution about Commvault AirGap

Key Takeaways 

  • AI adoption is accelerating, helping make employees more efficient, productive, and competitive. 
  • Organizations need governance and guardrails to adopt AI responsibly and at scale. 
  • Security and productivity don’t have to compete – they can reinforce one another.  
  • AI will become one of security’s most valuable tools for managing cyber risks.  
  • AI adoption works best when innovation and security move together. 

One of the things I’ve enjoyed about the Ready. Or Not. series is that each conversation builds on the last. We started by exploring the opportunities and risks of agentic AI. Then we looked at how organizations can build trust as AI becomes part of everyday business. This episode addresses the next logical question: How do we actually use AI safely? 

Comedian Nathan Macintosh sits down with Rinki Sethi, CISO and CSO at Upwind Security, for a conversation about what responsible AI adoption actually looks like. They cover everything from AI governance and guardrails to user experience and the growing role AI will play in cybersecurity.  

Nathan continues to ask the questions many of us are wondering. Should we be worried? How much more productive do we need to be? And can AI actually make security better?  

Watch the full episode on Readiverse. 

What I appreciated most about this conversation is that Rinki is genuinely excited about new technology and protecting it. She didn’t frame AI as something organizations need to worry about. Instead, she focused on encouraging businesses to move forward with confidence by putting the right guardrails in place. Here are the ideas that stayed with me. 

The push for AI adoption  

One thing that becomes clear from the conversation is that many organizations aren’t only encouraging their employees to adopt AI – they’re mandating it. These companies recognize that using AI helps people solve problems more efficiently, which is essential for staying competitive. 

“Every single company has a mandate … we’ve got to use AI everywhere in the company.”

– Rinki Sethi 

The question is no longer if AI belongs in the workplace, but do employees have the right guardrails to use it responsibly? As AI adoption accelerates, organizations need clear standards around which AI tools employees can use and how company data is protected. 

Sneak Peek: AI Governance

Rinki explains that governance isn’t just about protecting against new risks. It’s about creating a framework that helps employees use AI responsibly while keeping pace with evolving regulations and industry standards. 

The Hidden Benefit of Productivity 

Here’s something I never thought about before. Rinki explains that AI isn’t simply helping people work faster. In many cases, it’s leaving room for the highest-performing employees to excel.  

She used software developers as an example. When AI-powered coding assistants became available, many assumed they’d only help less experienced developers. Instead, some of the best engineers began using them to move faster. They were able to solve more complex problems and spend more time on creative work rather than repetitive tasks. 

That kind of productivity is exactly why organizations are mandating AI. It doesn’t limit what people can do – it helps give them more space to focus on higher-value work. 

“You can be way more creative with how you’re doing things … cause you’re creating the space for that.”

– Rinki Sethi 

AI’s Role in Cybersecurity 

“How can AI be used to help with security and not be just looked at as a demon thing that’s here to take us out?”

– Nathan Macintosh 

When we talk about AI and security, the conversation is often focused on risk. But Rinki believes that AI will become one of cybersecurity’s greatest advantages. 

Security teams are already overwhelmed by the volume of alerts, logs, and data they need to investigate every day. Human analysts simply can’t keep up. Rather than replacing security professionals, AI assists them by filtering through massive amounts of data in seconds. This helps analysts identify false positives so they can focus on investigating real threats. 

My takeaway is that the future of cybersecurity isn’t about people versus AI – it’s about people working alongside AI to help make better decisions, respond faster, and scale their operations in ways that weren’t possible before. 

Ready for What’s Next? 

Every episode of Ready. Or Not. has reminded me that the biggest AI conversations are often about people – how we adapt, how we learn, and how we build the confidence to use new technology responsibly. The real opportunity for organizations isn’t just adopting AI. It’s creating an environment where employees can use AI to work smarter, become more creative, and deliver better outcomes for the business. 

Watch the full episode on Readiverse. 

FAQs 

Q: Why are organizations adopting AI so quickly? 

A: Many organizations see AI as a way to help improve productivity, increase efficiency, and give employees more time to spend on higher-value work. 

Q: What is AI governance? 

A: AI governance is the combination of policies, processes, and oversight that helps organizations adopt AI responsibly while managing security, privacy, and compliance risks. 

Q: Why is user experience important for security? 

A: Security controls that create unnecessary friction often encourage people to find workarounds. Designing secure systems that are also easy to use helps improve both adoption and protection. 

Q: Can AI help improve cybersecurity? 

A: AI can help security teams analyze large amounts of data, which helps reduce false positives. This in turn helps teams prioritize threats and respond more efficiently to security events. 

Q: Should people be afraid of AI? 

A: Rinki’s perspective is that a healthy sense of skepticism is valuable, but fear shouldn’t prevent organizations from adopting technology responsibly. Education, governance, and strong security practices can help organizations use AI with confidence. 

Q: What’s the biggest takeaway from this episode? 

A: AI adoption isn’t about choosing between innovation and security. Organizations that combine strong governance with practical security measures will be better positioned to take advantage of AI’s benefits while managing its risks. 

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

How Mythos and GPT-5.5-Cyber Could Change Cloud Data Security

Specialized cyber AI models could accelerate vulnerability discovery and multi-step attack workflows. Beyond prevention, cloud data security teams need greater visibility, governance, and clean recovery readiness. 

Key Takeaways

Frontier cyber AI compresses the time between discovery and action, exposing why organizations need resilience-aware cloud data security built around clean recovery and ResOps. 

  • Claude Mythos and GPT-5.5-Cyber remain limited-access models, but they preview a future where AI can reason across complex cyber workflows and accelerate both defense and, potentially, attacker operations.
  • As the time between vulnerability discovery and exploitation shrinks, organizations need better visibility into cloud dependencies, identity risk, and interconnected attack paths before disruption occurs.
  • Recovery is no longer just about restoring backups. Organizations need to define their minimum viable company, validate trusted recovery points, and restore critical systems in the right sequence.
  • Resilience operations align security, IT, and business teams around measurable recovery outcomes, helping organizations govern data, prioritize recovery, and restore trusted operations with greater confidence.

 Claude Mythos and GPT-5.5-Cyber could affect cloud data security by speeding up how risks are discovered, tested, and acted on. Their impact is still uncertain, but they point to a need for stronger data visibility, access governance, and clean recovery across cloud environments. 

Claude Mythos and GPT-5.5-Cyber are giving security teams an early look at what more specialized cyber AI could mean for cloud data security. 

Neither model is widely available, and their long-term impact is still uncertain. But their existence matters because cloud environments are already difficult to defend. Sensitive data, identity systems, SaaS applications, development pipelines, AI workloads, and recovery infrastructure often depend on one another in ways that are hard to see until something goes wrong. 

The UK AI Security Institute’s April 2026 evaluation of Claude Mythos Preview found significant improvement on multi-step cyber-attack simulations, including the ability to execute multi-stage attacks on vulnerable networks when explicitly directed in a controlled environment.  

The same evaluation cautioned that its ranges differ from real-world environments and do not prove whether Mythos could attack well-defended systems. Still, it shows why cloud data security teams should pay attention to the direction of travel. 

As cyber AI capabilities mature, the question is not only whether attacks get faster. It’s whether the window between discovering a weakness and exploiting it continues to shrink. When that clock compresses, cloud data security is no longer just about preventing compromise. Instead, the question shifts to whether organizations can understand risk quickly enough, govern access consistently, and recover trusted operations before disruption spreads. 

Why Mythos and GPT-5.5-Cyber Matter 

The significance of Mythos and GPT-5.5-Cyber is not that every organization will suddenly have access to them. Based on current public information, they are controlled, limited-access models. For cloud data security teams, their importance is what they suggest about the direction of cyber AI: more specialized systems built to support complex security workflows. 

That distinction matters. A general-purpose AI assistant can help summarize alerts or draft an incident report. A specialized cyber AI model is different. It may be designed to reason across vulnerabilities, infrastructure, attack paths, defensive controls, and validation steps. In authorized settings, that could help security teams test environments, prioritize exposures, and strengthen recovery planning before an incident. 

For cloud data security teams, the practical impact is less about the model names and more about the workflow they represent. Cloud risk often comes from connections across systems: a misconfigured workload, an exposed dataset, an over-permissive identity, a backup dependency, or an untested recovery path. Specialized cyber AI could make it easier to evaluate those relationships more quickly, especially in large environments where manual review can miss how one issue affects another. 

That shift mirrors a broader change happening across cybersecurity. The challenge is becoming less about identifying individual vulnerabilities and more about understanding how interconnected systems behave under pressure. AI may soon help defenders reason across identities, cloud workloads, backups, SaaS applications, AI pipelines, and business dependencies simultaneously — revealing not just isolated risks, but how those risks combine into operational failure. 

It also changes how organizations should think about readiness. If AI can help defenders work through complex cyber tasks more efficiently, similar techniques may eventually influence attacker workflows as well. The concern is not only that attacks become faster. It is that the gap between finding a weakness, testing it, and acting on it could shrink. 

Cloud data security teams now have to plan for a harder question: what happens when the same types of AI-assisted workflows that help defenders validate risk also make weak points easier to find, test, and chain together? That’s where the cloud environment itself becomes the issue. 

AI Is Raising the Stakes for Cloud Data Security 

Most organizations don’t have one neat cloud environment. They have multiple clouds, SaaS platforms, data lakes, identity systems, development pipelines, backup repositories, and AI workloads that all depend on each other.  

That complexity already creates gaps: sensitive data can be overexposed, access permissions can drift, and recovery plans may not reflect how the business actually runs.  

In practice, those gaps rarely stay isolated. A storage bucket with sensitive data may not look urgent on its own. An over-permissive service account may look like a routine configuration issue. An untested recovery dependency may sit unnoticed because the system is still running. But when those issues connect, they can create a path from exposure to disruption. 

Attackers are well aware of these vulnerabilities. Mandiant’s 2026 M-Trends report notes that ransomware operators are increasingly targeting backup infrastructure, identity services, and virtualization management planes. It also highlights how attackers are using long-lived OAuth tokens, session cookies, hard-coded keys, and personal access tokens to pivot across environments. 

Now add more capable cyber AI to the picture: If models can help find vulnerabilities faster, test exploitability more effectively, or connect weak signals across systems, defenders could benefit. However, attackers may eventually benefit, too—especially if similar capabilities become more accessible or are recreated elsewhere. 

22 seconds 
Median time between an initial access event and hand-off to a secondary threat group  

Source: Mandiant’s 2026 M-Trends report 

That’s why the conversation can’t stop at “AI makes attacks faster.” Frontier cyber AI changes the tempo of security. As the time between discovery, validation, and exploitation compresses, every delay in understanding cloud dependencies or preparing recovery becomes more expensive. 

How Could Next-Gen Cyber AI Change Cloud Defense? 

While the full impact of Mythos and GPT-5.5-Cyber is still unknown, they point to three practical shifts cloud data security teams should be watching. Each one comes back to the same issue: cloud data security now depends on how quickly organizations can understand risk, act on it, and recover when something goes wrong. 

Cyber defenders need to watch for:

  • Speed: AI-assisted tools may help authorized defenders review code, triage vulnerabilities, analyze malware, validate patches, and test controls faster than traditional workflows allow. 
  • Scale: Cloud risk rarely lives in one place. A vulnerability in an application, an over-permissive identity, a misconfigured storage bucket, and an untested recovery path can become one attack chain. 
  • Pressure on recovery: If AI helps attackers move faster, organizations need to recover faster and cleaner. Backups alone aren’t enough if teams don’t know which data is clean, which identity systems can be trusted, or whether recovery will reintroduce compromised assets.

For defenders, the biggest change may be how work gets sequenced. Today, many teams move from alert to investigation to remediation to recovery planning in separate steps, often across separate teams. Cyber AI could compress that workflow by helping teams move from a signal to a set of recommended next actions more quickly. 

That doesn’t mean decisions should become automatic. It means teams may need clearer rules for when to trust a recommendation, when to escalate to a human reviewer, and when to move from investigation into recovery preparation. A model may help identify a possible attack path, but people still need to decide whether to close access, isolate a workload, preserve evidence, notify stakeholders, or prepare a clean recovery path. 

This is where process becomes as important as tools. Next-gen cyber AI could help defenders move faster, but only if teams have clear validation steps and recovery plans in place. Without that structure, speed can create confusion. With it, AI-assisted workflows could help teams act sooner while maintaining control over how risk is evaluated and how recovery decisions are made. 

Why Clean Recovery Matters More as Risk Moves Faster 

When cloud risk moves faster, recovery planning has to become more precise. It’s not enough to know that backup copies exist. Teams need confidence that the data they restore is trustworthy, the recovery environment is isolated, and the systems coming back online won’t reintroduce the same threat that caused the disruption. 

That matters because cloud environments are highly interconnected. A compromised identity, corrupted dataset, affected virtual machine, or misconfigured workload can create uncertainty across multiple services. During an incident, teams may need to determine which recovery points are clean, which dependencies should come back first, and whether restored data can safely support business operations. 

Clean recovery also changes the way teams think about priority. The goal isn’t necessarily restoring everything immediately. It’s restoring enough of the business to operate safely. 

Many organizations know which applications they consider “critical,” but far fewer have defined their minimum viable company: the smallest combination of identities, cloud services, data, applications, and infrastructure required to keep the business functioning during disruption. Those dependencies often become visible only when recovery is tested under realistic conditions. 

In an AI-dominant threat landscape, determining the minimum viable company is crucial. Faster vulnerability discovery and more efficient attack-chain development could put more pressure on recovery teams to make high-confidence decisions under tight timelines. 

What’s more, identity systems, cloud configurations, business communications, customer-facing applications, and the data they depend on may all need to come back in a deliberate sequence — not simply according to technical priority, but according to what the business needs first to operate. 

Organizations need recovery processes that can help validate clean data, stage recovery in isolated environments, protect critical identity dependencies, and test recovery plans before an incident forces the issue. As cyber AI capabilities mature, cloud data security teams should treat clean recovery as part of the security strategy, not an after-action step. 

Building Resilience-Aware Data Security 

Cloud data security has often focused on preventing exposure: finding sensitive data, classifying it, governing access, and reducing risk. That work still matters. In fact, it becomes more important as AI systems consume enterprise data through prompts, retrieval systems, training pipelines, analytics workflows, and automated decision support. 

That’s because data may move into new contexts without moving into a new system of record. A sensitive dataset might support a retrieval workflow, shape a model response, or appear in a prompt log. That makes governance less about one location and more about how data is accessed, reused, and recovered across workflows. 

But prevention alone is not enough for the next phase of cloud data security. If specialized cyber AI can help security teams discover vulnerabilities, test attack paths, and connect weak signals faster, then data security programs need to account for what happens after exposure is found or exploited. Visibility and access controls are only part of the picture. Teams also need a clear path to trusted recovery. 

Uncovering that path requires more than better security tools. It requires a recovery operating model that aligns security, IT, and business leaders around shared recovery priorities before an incident occurs. Increasingly, organizations are describing this discipline as ResOps, or resilience operations: a structured approach to making recovery measurable, repeatable, and tied to business outcomes rather than backup success alone. 

In ResOps, organizations must understand: 

  • Which datasets are most critical to business operations? 
  • Which identities, cloud services, and AI workflows depend on business-critical datasets? 
  • Are governance and access policies aligned to business risk? 
  • What is the minimum viable operating state the organization must restore first? 
  • Can those recovery decisions be validated before an incident instead of during one? 

That’s the shift Mythos and GPT-5.5-Cyber point toward. The future of cloud data security won’t be defined by prevention alone. As cyber AI compresses the time between discovery and action, organizations will need equal confidence in how they recover. That means understanding cloud dependencies before an incident, defining the minimum viable business they need to restore, and treating recovery as an operational discipline rather than a technical afterthought. 

Mythos and GPT-5.5-Cyber matter not because every organization will use these models tomorrow, but because they reveal where cybersecurity is heading. As AI accelerates both defense and attack, the organizations that perform best won’t simply be the ones with the strongest preventive controls. They’ll be the ones that can prove they know what to recover, in what order, and how to restore trusted operations before uncertainty becomes business disruption. 

Frequently Asked Questions

When will these specialized models become public?

There’s no confirmed timeline for broad public access. Current reporting indicates Claude Mythos is being limited to select organizations through controlled programs, while OpenAI describes GPT-5.5-Cyber as available only to vetted defenders through its Trusted Access for Cyber framework.

Are AI attacks likely to increase?

Not necessarily. But they do show that advanced AI can support more complex cyber workflows, which means organizations should prepare for faster discovery, testing, and exploitation cycles.

Which risks should teams prioritize first?

Start with visibility into sensitive data, access paths, cloud misconfigurations, identity dependencies, and recovery readiness. Commvault’s Data & AI Security capabilities can help teams classify data, govern access, and identify risks across cloud environments. 

Why does recovery matter for cloud data security?

Because prevention can fail. Commvault cyber resilience capabilities can help organizations identify clean recovery points, validate recovery in isolated environments, and restore data and critical services without reintroducing compromised assets. 

Does Commvault offer AI-supported threat detection?

Yes. Commvault can use AI-enabled capabilities to help identify threats, detect anomalous activity, prioritize risk, and accelerate incident response. Combined with cyber resilience and recovery workflows, we can help teams improve response workflows and recover critical data with greater confidence.


At Commvault, we talk a lot about cyber resilience, the ability to recover from whatever challenges come your way. But for one engineer at Australian technology services provider Perfekt, it is his personal resilience that helps him succeed.

Viktor Trokhin left Ukraine when the war began, traveling through five countries before eventually reuniting with his family in Australia. He brought more than six years of ICT experience, deep technical expertise, and a determination to continue his career in tech.

Like many skilled professionals starting over in a new country, Viktor wasn’t just adapting to a new workplace. He was building expertise in new technologies, communicating in a second language, and finding his place in a different professional environment.

Marcus Rolim, Managed Services General Manager at Perfekt and Viktor’s manager, saw his potential immediately.

“Our engineering development program is built around people,” Marcus says. “We invest heavily in mentoring and creating opportunities for engineers from different backgrounds.”

Over the years, Perfekt has welcomed engineers from around 10 different countries. Rather than following a standard training path, the company focuses on each person’s strengths, providing mentoring, practical experience, and support where it’s needed most.

For Viktor, that meant building on his existing expertise while gaining experience with Commvault Cloud and cyber resilience.

As he worked with customers, Arlie – the AI assistant in Commvault Cloud – became a natural part of his daily workflow. Whether he was exploring product capabilities, troubleshooting an issue, or looking for guidance, Arlie helped him quickly find trusted information without interrupting his work.

Then came an unexpected benefit.

Because Arlie supports multiple languages, Viktor could work through complex concepts in his native language before switching to English when speaking with customers or colleagues. While this wasn’t the use case Perfekt originally envisioned, it quickly became a valuable learning advantage.

“When an engineer can explore a complex question in their own language, understand the reasoning behind the answer, and then communicate it clearly in English, it changes the learning experience,” Marcus says. “It allows their technical ability to come through without language becoming a barrier.”

Today, Viktor is an Infrastructure & Data Protection Engineer at Perfekt, supporting customers while continuing to deepen his expertise in cyber resilience.

When Viktor left Ukraine, he carried with him years of experience, deep technical expertise, and an unwavering determination to continue the career he had worked so hard to build. Today, he helps organizations strengthen their cyber resilience, drawing on the same resilience that helped him rebuild his own life.

Maybe that’s why this story resonates. Viktor’s resilience shaped his own future. Today, it helps him make a difference for others.

That’s what putting people first looks like: organizations like Perfekt investing in people, and technology like Commvault Cloud helping them thrive.

Chris DiRado is Principal, Product Experience, at Commvault.

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

How Can Security Leaders Protect Their Most Sensitive Data?

Data and AI security enables organizations to discover, classify, and govern access to sensitive data across users, systems, and AI solutions.

Key Takeaways

Data is the life force of modern businesses, helping guide key decisions and power AI initiatives. Given its value, knowing and protecting your data is essential.

  • 90% of organizations have exposed sensitive cloud data that can be surfaced by AI. This makes visibility into data assets the first and most critical step in reducing enterprise risk. 
  • 40% of files uploaded into shared with generative AI tools contains Personal Identifying Information (PII) or Payment Card Industry (PCI) data. Such misuse of sensitive data causes significant risk for organizations when it comes to privacy and regulatory violations. 
  • Data discovery and classification form the foundation of effective security, helping enable organizations to identify sensitive data across structured, semi-structured, and unstructured environments.
  • Overpermissive access is one of the most persistent data risks for modern businesses. With users, applications, and service accounts often retaining unnecessary access to sensitive data, the “attack surface” is expanded.
  • Helping protect AI requires governing both training data and runtime interactions. Organizations need to verify that sensitive data is not exposed through inputs, outputs, or model behavior.
  • Regulatory compliance depends on strong data foundations. Strong classification and access governance enables organizations to enforce policies and demonstrate control.

Sensitive data now moves across clouds, applications, and AI workflows without clear visibility — creating exposure risks that traditional security controls cannot address alone. Commvault Data and AI Security helps organizations discover and classify sensitive data, govern access for both human and machine identities, and maintain compliance with GDPR, HIPAA, and PCI DSS across the full data lifecycle.


Why is sensitive data exposure the biggest security gap?

Data is the invaluable fuel that propels modern businesses. So, organizations have made it a priority to heavily invest in sophisticated security tools.

However, according to Varonis’ 2025 State of Data Security Report, 90% of organizations still have exposed sensitive cloud data. Similarly, 88% of organizations have stale but enabled ghost users.

But that’s not all. According to IBM’s Cost of a Data Breach Report 2025, 53% of breached organizations reported compromised customer PII. These statistics paint a vivid image: though data is central to businesses, visibility and overall security remain critical issues. 

Data is no longer confined to structured databases. It exists across files, emails, cloud platforms, SaaS applications, and endpoints. Much of it is unstructured, duplicated, or unmanaged, making it difficult to track and protect.

AI is amplifying this problem. About 40% of files uploaded to generative AI tools contains sensitive information, often without governance or oversight. As AI adoption grows, so does the number of systems and identities interacting with data.

Without visibility into what data exists and where it resides, organizations cannot effectively secure it. This lack of visibility is the root of the modern data security problem.


What are the pillars of data and AI security?

To address the challenge of data exposure, organizations need a structured approach that brings consistency and control to how data is managed. Data and AI security is built on three core pillars: Data Discovery, Data Classification, and Data & AI Access Governance.

Each pillar addresses a prominent gap:

  • Discovery provides visibility into where data resides across environments. This includes structured systems such as databases, as well as semi-structured and unstructured sources that are often overlooked.
  • Classification adds context by identifying the type and sensitivity of data. It enables organizations to distinguish between operational data, sensitive personal information, financial records, intellectual property, and other high-risk categories.
  • Access governance enables organizations to verify that data is used appropriately. It defines who or what can access data, under what conditions, and with what level of control.

These three pillars do not exist independently. They create a connected system that fully covers data and AI security. Discovery identifies the complete data landscape, classification defines the appropriate sensitivity, and access governance enforces control based on that context.

This model even extends beyond human users to include machine identities such as AI models. In modern environments, these non-human identities often represent a significant portion of data access activity. Bringing these pillars together can help organizations move from fragmented security controls to a unified, policy-driven approach.


How can organizations discover and classify sensitive data?

Discovery and classification are foundational to a successful data security model. Yet, they are often the most difficult to implement effectively.

This is because modern data environments are highly fragmented. Sensitive information is spread across multiple cloud platforms, on-prem systems, SaaS applications, and endpoints. A significant portion of this data is unstructured, making it harder to identify and categorize.

Some of the most notable challenges include:

  • Shadow data that exists without knowledge, approval, or security oversight.
  • Inconsistent formats across structured and unstructured data.
  • Rapid data growth due to AI adoption that outpaces manual classification efforts.

To address this, organizations need scalable discovery capabilities and classification frameworks. Proper classification can assign meaning to the vast amounts of existing data. This typically includes categories such as PII, protected health information (PHI), PCI, intellectual property, and keys and secrets.

The value of classification comes from how it is used. Once data is classified, organizations can effectively apply retention and deletion policies, restrict or monitor access, and enable masking or redaction for sensitive fields.

At scale, a mature discovery and classification approach does not just fulfill coverage but also helps produce meaningful outcomes. This can include reduced exposure, improved policy enforcement, and measurable risk reduction.


What are the major risks of overpermissive access?

According to research by ReliaQuest, 99% of cloud identities are over-privileged. On a similar note, a 2025 study by the Ponemon Institute highlights that 61% of US firms have suffered from insider data breaches in the past two years, with the average cost of such incidents being a staggering $2.7 million.

This proves that even when organizations understand their data, access remains one of the weakest points in security.

Overpermissive access occurs when users, applications, or service accounts have more access to data than they need. This issue is widespread because access controls are often granted broadly for convenience and rarely revisited.

The impact is significant. Excessive access increases the likelihood of accidental exposure, insider risk, and exploitation during a breach.

To address this, organizations must first carefully inspect access patterns. This includes finding out who is accessing sensitive data, what systems or identities are involved, and whether that access aligns with business needs.

Particular attention must be given to privileged accounts and service identities. These often have extensive permissions and can access large volumes of sensitive data across systems.

In this landscape, effective access governance is key. This requires:

  • Aligning access policies with data classification.
  • Continuously monitoring usage patterns.
  • Identifying and remediating access drift over time.

By reducing unnecessary access, organizations help limit their attack surface and improve overall data protection.


How should organizations govern data used by AI systems?

The adoption of AI is rapidly spreading across every facet of modern businesses. This introduces a new layer of complexity in how data is accessed, processed, and exposed.

Training datasets often include large volumes of data sourced from across the organization. Without proper classification and governance, these datasets may contain sensitive or regulated information.

This creates risk at multiple stages:

  • During data preparation and training.
  • When models interact with live data.
  • Through outputs that may unintentionally expose sensitive information.

So, classification must precede model training. This means validating and classifying all data used in datasets and removing sensitive information when necessary.

Likewise, after deployment of AI tools, data teams must continuously assess how models use and expose data. They also should apply appropriate control mechanisms such as masking or redaction where needed.

AI systems should not be treated as separate from data security. They are an extension of how data is used and must be governed accordingly. By integrating such data and AI security capabilities into the broader AI development lifecycle, organizations can help reduce risk while still enabling innovation.


How does data classification power regulatory compliance?

Regulatory compliance depends on the ability to identify and control sensitive data. Frameworks such as GDPR, HIPAA, and PCI DSS define specific requirements for how data must be handled. However, these requirements cannot be enforced without first understanding where regulated data exists.

This is why compliance programs fail without a proper data foundation.

In such cases, data classification acts as the backbone for compliance, mapping data to regulatory categories. It allows organizations to apply targeted controls based on data sensitivity and enforce critical data lifecycle policies.

This opens up a myriad of essential capabilities:

  • Enforcement of retention and deletion policies
  • Restriction of access to regulated data
  • Implementation of crucial privacy controls

It also simplifies audit processes. Organizations can demonstrate where sensitive data resides, how it is protected, and who has access to it. Access governance further strengthens compliance by ensuring that only authorized identities can interact with regulated data.

Together, data classification and access controls reshape compliance for the modern, AI-enabled era.


Conclusion: What does effective data and AI security require today?

Modern data and AI security is no longer defined by perimeter defenses or isolated controls. It requires a continuous, unified approach that connects visibility, classification, and access governance across the entire data lifecycle.

To bring such an approach to life, organizations must first understand their data, finding exactly where it all resides. Then they must control how it is accessed. Finally, organizations must make certain that AI systems use it responsibly. These capabilities must work together, not independently, to help reduce exposure and maintain trust.

As data volumes grow and AI adoption accelerates, the challenge will not be securing data alone, but demonstrating where sensitive data exists, who can access it, and how it is protected across systems. Those that build a structured, policy-driven approach will be better positioned to help reduce risk, meet regulatory expectations, and enable innovation with confidence.

Frequently Asked Questions

What is data and AI security?

Data and AI security is the practice of discovering, classifying, and governing access to sensitive data across systems, users, and AI models. Commvault Data and AI Security delivers these capabilities across hybrid environments — enabling organizations to confirm that data remains visible, controlled, and protected throughout its lifecycle, including how it is used in AI training and outputs.

Why is sensitive data exposure a major risk?

Sensitive data exposure is a major risk because organizations often lack visibility into where data resides and who can access it, increasing the likelihood of breaches, misuse, and regulatory violations. Commvault helps mitigate this through a unified approach that combines Data Discovery, Classification, and Access Governance across hybrid environments.

What are the key pillars of data security?

The three core pillars of data security are discovery, classification, and access governance. Commvault delivers each — Data Discovery identifies where sensitive data exists across environments, Data Classification defines its sensitivity and type, and Data & AI Access Governance enforces access control aligned with business and regulatory policy.

Why is overpermissive access dangerous?

Overpermissive access allows users, applications, and service accounts to access more data than necessary — increasing risk of accidental exposure, insider threats, and exploitation. Commvault Data & AI Access Governance addresses this by continuously monitoring access patterns, aligning permissions with data classification, and identifying and remediating access drift across hybrid environments.

How should organizations help protect data used by AI?

Organizations can protect AI data by classifying datasets before training and continuously monitoring how models access and expose data. Commvault Data and AI Security supports this through discovery, classification, and governance controls including masking, redaction, and access restrictions — helping ensure that sensitive data is not exposed through AI training, model behaviour, or outputs.

How does data classification help support compliance?

Data classification supports compliance by identifying regulated data such as PII and mapping it to appropriate controls. Commvault Data Classification helps organisations enforce retention and deletion policies aligned with GDPR, HIPAA, and PCI DSS — and provides the audit-ready evidence needed to demonstrate how sensitive data is identified, protected, and governed.

Explore Related Resources

Explore

What are the Key Risks of Data & AI Security?

Explore how AI introduces new data vulnerabilities – from model training to exposure to runtime risks – and the layered practices organizations use to govern workloads responsibly.
Read the article about What are the Key Risks of Data & AI Security?
White paper

AI Security Risks Analysis

A readiness report for your CISO and CIO to see what changed with MCP 2.0 and what to do to be prepared for your organization.
Read the white paper about AI Security Risks Analysis


Key Takeaways

  • Replace subjective claims about “ease of use” with a measurable data protection gearing ratio: protected capacity divided by the number of full-time administrators.
  • Measuring protected capacity per FTE provides a more meaningful view of operational efficiency than legacy metrics such as backup jobs per administrator.
  • The data protection gearing ratio should be used as a baseline before a platform migration and measured again afterward to validate operational improvements.
  • Factors such as multi-cloud environments, cyber recovery requirements, and compliance obligations can influence the ratio, so it should be evaluated within the context of each environment.
  • Organizations should ask vendors to commit to measurable operational outcomes instead of relying on qualitative claims about simplicity.

Every vendor evaluation I have sat in eventually reaches the same dead end. One side says the platform is simple to run. The other side says their platform is simpler.

Nobody can prove either claim, so the conversation drifts to the demo, the reference call, the gut feeling in the room. That is not how you should be making a decision that determines how your team will spend the next five years.

I have run production data protection environments. I have watched teams get buried under fragmented tooling that promised automation and delivered tickets instead.

“Reduced complexity” is not a feeling you should have to take on faith. It is something you should be able to calculate.

The Metric the Industry Has Been Missing

We have started using a simple ratio internally and with customers: total protected capacity divided by the number of full-time staff required to run it. We call it the data protection gearing ratio.

Protected Capacity (PB) / FTEs = Data Protection Gearing Ratio

That’s it. No survey questions about satisfaction. No adjectives. A number, calculated from data you already have.

Here is why it matters more than the metrics it replaces. Calculating the number of backup jobs per person made sense a decade ago, when a job represented a discrete unit of manual effort. It does not reflect how modern platforms operate today, where automation absorbs the routine work and a single administrator can be accountable for petabytes, not job counts.

Measuring jobs per person in an automated environment tells you nothing about whether the automation is actually working.

What It Looks Like in Practice

One clarification before the number, because it trips people up. Protected capacity means the full, uncompressed, undeduplicated size of the applications being protected, not the physical disk behind them.

That distinction matters because it is the whole point. Commvault’s own production environment protects 42.39 PB of application data on 9.26 PB of physical disk, an 81.91% space savings from deduplication and compression.

The ratio is not just a measure of how many petabytes a person can watch over. It is a measure of how much architecture is doing the work before headcount ever enters the picture.

With that in mind: Commvault runs its own production backup environment on 42.39 PB of protected capacity with two FTEs. That is a gearing ratio of 21.20 PB per FTE. Industry benchmarks for modern platforms typically land between 5 and 25 PB per FTE, depending on environment complexity, so that number sits at the high end of what is achievable today.

Metric  Value  Definition 
Protected Capacity (Front-End)  42.39 PB  Full, uncompressed, undeduplicated application size protected in our environment 
Total Disk Capacity  9.26 PB  Physical target storage 
Total Used Space  7.89 PB  Current utilization 
Total Data Written  7.67 PB  Logical data written to disk 
Space Savings  81.91%  Deduplication and compression efficiency 
Data Protection FTEs  2  Number of full-time admins managing Commvault’s own production backup estate 

Data Protection Gearing Ratio = 42.39 PB / 2 FTEs = 21.20 PB per FTE

I want to be direct about what this number does not do. It does not account for a multi-cloud footprint, cyber recovery requirements, or a compliance-heavy application mix, all of which will pull the ratio down for reasons that have nothing to do with how good the platform is.

A ratio in isolation is not a verdict. A ratio measured before and after a migration is.

That is the actual use case. Baseline your current environment on your current tools. Set a target ratio based on your growth projections and your team’s capacity. Then hold your vendor to it after the implementation is done, not just during the sales cycle.

The Board-Level Implication

If you are the one signing off on a platform migration, you are not just being asked to trust that a new platform is easier to run. You are being asked to fund a specific operational outcome. A data protection gearing ratio target gives you a way to write that outcome into the business case and check it 12 months later.

This is the same discipline we apply to mean time to clean recovery (MTCR). Recovery capability is not something you claim, it is something you measure and re-measure until the number tells you the truth. Operational efficiency deserves the same standard.

The Challenge

Ask your current vendor for the gearing ratio of your own environment today. If they cannot produce it, that tells you something about how well they understand what “simple to manage” means for your team.

And if you are evaluating a new platform, do not accept “easier to use” as an answer. Ask what ratio they will commit to, and ask again after year one.

FAQs

Q: What is the data protection gearing ratio?

A: The data protection gearing ratio measures the amount of protected data capacity managed by each full-time administrator. It provides an objective way to evaluate operational efficiency rather than relying on subjective impressions of platform usability.

Q: Why is this metric more useful than backup jobs per administrator?

A: Modern data protection platforms automate much of the routine work that previously required manual effort. As a result, counting backup jobs no longer reflects the true workload or efficiency of an operations team.

Q: What does “protected capacity” mean in this calculation?

A: Protected capacity refers to the full, uncompressed, and undeduplicated size of the application data being protected. This measurement reflects the actual workload managed by the platform rather than the physical storage consumed after optimization.

Q: Does a higher gearing ratio always indicate a better platform?

A: Not necessarily. Environmental complexity, including multi-cloud deployments, cyber resilience requirements, and regulatory obligations, can reduce the ratio even when the platform performs well. The metric is most valuable when comparing the same environment before and after a migration.

Q: How should organizations use the data protection gearing ratio during vendor evaluations?

A: Organizations should establish a baseline using their current environment, define a target ratio aligned with future growth, and ask vendors to commit to achieving measurable improvements after implementation. This approach shifts the conversation from marketing claims to verifiable business outcomes.

Q: What is the broader business value of this metric?

A: The data protection gearing ratio enables executives to quantify expected operational efficiency gains and include them in the business case for a platform investment. It also provides a benchmark that can be reviewed after deployment to confirm the promised results were achieved.

Rajiv Kottomtharayil is Chief Products Officer at Commvault.

More related posts


Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago
Thumbnail_Blog-Medusa-is-Evolving-2026

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Read more about Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.