Clumio Chat offers a faster, self-service way to evaluate Clumio’s cloud-native data protection capabilities.
The AI assistant provides answers about backup, recovery, cyber resilience, deployment, scalability, and cloud workload protection.
Explore technical questions about cloud workloads, required permissions, recovery options, and data protection costs.
Clumio Chat helps cloud architects, platform engineers, DevOps engineers, SREs, and technical buyers assess whether Clumio fits their environment at their own pace.
When ready, users can move directly from product discovery to hands-on evaluation by creating an account and starting a free trial.
A Faster Way to Evaluate Cloud-Native Data Protection
If you’re evaluating cloud-native data protection, you probably want answers before you schedule a demo or talk to Sales.
Clumio by Commvault provides cloud-native backup, recovery, and cyber resilience for AWS and Google Cloud workloads. With Clumio Chat, you can ask product and technical questions, explore how Clumio works, and decide whether it’s the right fit for your environment – all at your own pace.
Click “Ask Clumio” in the navigation bar on clumio.com to start a conversation with Clumio Chat.
Introducing Clumio Chat
Clumio Chat is an AI assistant designed to help you learn about Clumio’s cloud-native data protection and recovery capabilities. Whether you’re exploring key features, understanding how Clumio helps protect cloud workloads, or preparing to start a free trial, Clumio Chat gives you answers without requiring a sales conversation.
Get Answers to Real Cloud Data Protection Challenges
Instead of searching documentation or waiting for a meeting, you can ask the kinds of technical questions you would normally ask a solutions engineer:
What recovery options does Clumio provide for Amazon S3?
What permissions does Clumio require, and do I need to deploy any backup infrastructure in my AWS account?
What scale does Clumio support for Amazon S3?
How does Clumio help reduce the cost of long-term cloud data protection?
Try It Now
Clumio Chat helps you move from product discovery to hands-on evaluation with less friction. Learn how Clumio works, explore the capabilities that matter most to you, and when you’re ready, create an account and start a free trial.
Try Clumio Chat today and experience a faster, more self-service approach to evaluating cloud-native data protection.
FAQs
Q: What is Clumio Chat?
A: Clumio Chat is an AI assistant that helps you learn about Clumio’s cloud-native backup, recovery, and cyber resilience capabilities before starting a free trial.
Q: Who is Clumio Chat for?
A: Clumio Chat is designed for cloud architects, platform engineers, DevOps, SREs, and technical buyers evaluating cloud-native data protection.
Q: What kinds of questions can I ask?
A: You can ask questions about Clumio’s capabilities, deployment model, cloud workload protection, recovery options, scalability, and other technical topics related to evaluating the platform.
Q: Do I need to talk to Sales before trying Clumio?
A: No. Clumio Chat is designed to help you explore the product on your . If you decide you’d like additional guidance, you can always contact our team.
Clumio by Commvault has achieved FedRAMP® Class C (Moderate) Ready status and is now listed in the FedRAMP Marketplace as Legacy FedRAMP Ready.
The new milestone enables agencies and regulated organizations to evaluate Clumio while it continues toward a future Class C FedRAMP certification.
Clumio provides cloud-native backup and recovery designed specifically for public cloud environments.
The announcement expands Commvault’s public sector cyber resilience portfolio, complementing Commvault Cloud for Government, which addresses organizations requiring FedRAMP Class D (High).
Government agencies, contractors, technology partners, and regulated commercial organizations can all benefit from additional cloud-native cyber resilience options.
As more government agencies and regulated organizations embrace the cloud, they need data protection that’s built for modern environments and aligned with evolving federal security requirements.
Clumio by Commvault, which provides cloud-native backup and recovery designed specifically for public cloud environments, has achieved FedRAMP Class C (Moderate) Ready status and is now listed in the FedRAMP Marketplace. This important step expands cloud-native cyber resilience options for federal agencies, government contractors, and regulated organizations while moving Clumio closer to a future FedRAMP Class C certification.
Opening New Opportunities
FedRAMP is the U.S. government’s standardized approach to assessing the security of cloud services used by federal agencies. While an Authorization to Operate (ATO) is the ultimate goal, FedRAMP Class C Ready is the first major public step in that process.
After successfully completing its Readiness Assessment Report (RAR), Clumio is now listed in the FedRAMP Marketplace as Legacy FedRAMP Ready. This makes it easier for agencies, partners, and regulated organizations to discover and evaluate Clumio as it continues through the FedRAMP certification process.
Built for Modern Cloud Environments
As organizations continue updating their IT environments, traditional backup approaches often struggle to keep pace with cloud-native applications and services. Clumio was built specifically for the cloud, helping make it easier to protect data, simplify recovery, and strengthen cyber resilience without adding unnecessary complexity.
For organizations operating in FedRAMP Moderate environments, that means access to a cloud-native backup and recovery solution designed to align with federal security requirements while supporting operational efficiency.
Why This Matters for Customers
The demand for guarded, cloud-native data protection continues to grow across both the public and private sectors. Federal agencies, government contractors, and regulated commercial organizations all face increasing pressure to protect critical workloads while meeting evolving compliance expectations.
Clumio’s FedRAMP Class C Ready status helps address those needs by helping:
Expand cloud-native backup and recovery options for federal agencies and organizations operating in FedRAMP Moderate environments.
Provide greater visibility through the FedRAMP Marketplace procurement process.
Support customers that want to extend cloud-native data protection into regulated environments.
For existing customers, including organizations with both commercial and government cloud environments, this milestone also creates new opportunities to standardize cloud-native data protection across their operations.
Strengthening Commvault’s Government Portfolio
Clumio’s FedRAMP Class C Ready status complements Commvault® Cloud for Government, which serves organizations requiring FedRAMP Class D (High).
Together, these offerings give customers more flexibility to protect data across cloud, hybrid, and cloud-native environments while supporting different federal security requirements. Organizations with cloud-native workloads can evaluate Clumio for FedRAMP Moderate environments, while Commvault Cloud for Government addresses organizations requiring FedRAMP High.
Looking Ahead
Clumio’s FedRAMP Class C Ready status reflects Commvault’s ongoing investment in cloud-native cyber resilience for the public sector. As Clumio advances toward a future FedRAMP Class C certification, customers can begin evaluating the offering while Commvault continues expanding its public sector cyber resilience portfolio.
FAQs
Q: What is FedRAMP Class C (Moderate) Ready status?
A: FedRAMP Class C (Moderate) Ready status means Clumio has successfully completed its RAR and has been approved by the FedRAMP Program Management Office (PMO) for listing in the FedRAMP Marketplace as Legacy FedRAMP Ready. This allows federal agencies and other regulated organizations to evaluate the offering while Clumio continues through the FedRAMP process toward a potential future Class C FedRAMP certification ATO.
Q: Is FedRAMP Class C (Moderate) Ready the same as an Authorization to Operate (ATO)?
A: No. FedRAMP Class C Ready is an early milestone in the FedRAMP process. It is not equivalent to a full ATO.
Q: What is the FedRAMP Marketplace?
A: The FedRAMP Marketplace is the federal government’s official catalog of cloud service offerings participating in the FedRAMP program. It provides agencies and procurement teams with visibility into each offering’s status in the FedRAMP lifecycle.
Q: Who benefits from Clumio’s FedRAMP Class C Ready status?
A: The milestone can be valuable for federal agencies, government contractors, government-focused partners, and regulated commercial organizations that operate in FedRAMP Class C environments or use FedRAMP as a security benchmark.
Q: How does Clumio fit into Commvault’s government portfolio?
A: Clumio provides cloud-native backup and recovery for organizations with cloud-native workloads operating in FedRAMP Class C (Moderate) environments, while Commvault Cloud for Government can serve customers requiring FedRAMP Class D (High). Together, the offerings provide organizations with more flexibility based on their federal security requirements.
Poojan Kumar is Chief Product Innovation Officer at Commvault; and President & CEO of Clumio, a Commvault Company.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Cyber resiliency now requires trusted data, validated recovery workflows, identity readiness, and automation that can keep recovery aligned with AI-era ransomware risk.
Ransomware remains a core resilience test because recovery depends on more than backup availability. Organizations need immutable and indelible copies, isolated recovery environments, and tested workflows that can help restore critical services from trusted data.
AI can increase both operational value and data exposure. Cyber resiliency must account for AI models, pipelines, prompts, logs, and data stores so teams can govern access, classify sensitive data, and recover AI-dependent processes.
Clean recovery is now a decision problem. Teams need to know which data is trusted, which systems come back first, and how identity, applications, and data dependencies affect restoration across hybrid and multi-cloud environments.
Commvault® Cloud supports cyber resiliency through capabilities such as Commvault Cleanroom™; Commvault AirGap; Risk Analysis; Identity Resilience for Active Directory, Entra ID, and Okta; and AI-assisted recovery workflows.
A resilient organization can continue or restore critical operations when ransomware, AI-related data exposure, or infrastructure compromise disrupts normal systems. That requires trusted backups, isolated recovery environments, identity recovery, data risk visibility, automation, and tested workflows that help prove which services can return first and how safely.
Ransomware no longer tests backup strategy alone; it tests whether the business can reassemble trusted operations under pressure. AI adds another layer of complexity because more decisions, workflows, and customer experiences now depend on data pipelines, models, prompts, embeddings, and distributed cloud services. The attack surface is expanding while recovery expectations are becoming more precise.
IBM’s 2026 Cost of a Data Breach Report found that 92% of organizations reporting an AI-related breach lacked proper AI access controls, and that ransomware or extortion incidents averaged $5.12 million USD when disclosed by an attacker. Verizon’s 2026 DBIR also reported that ransomware appeared in 48% of breaches, while attacker use of generative AI is affecting targeting, initial access, and malware development.
A resilient organization must be able to identify exposed or compromised data, recover identity services, restore prioritized workloads, and validate that recovered systems are clean enough to support the next business action.
Why cyber resiliency has changed
Cyber resiliency used to be described mainly in terms of recovery speed. That is still important, but it is no longer enough. In a ransomware incident, teams have to answer harder questions before they restore:
Which data is clean?
Which systems are required for minimum viable operations?
Which identity services need to come back first?
Which dependencies could reintroduce malware, corrupted data, or unauthorized access?
This is where cyber resiliency becomes broader than backup and recovery. It connects data protection, data security, identity recovery, incident response, and operational validation. The goal is not simply to bring systems back online. The goal is to restore trusted business function in the right order, with evidence that the recovery path has been tested.
The shift is also organizational. Ransomware recovery requires coordination across infrastructure, cyber teams, application owners, legal, communications, and business leadership. Technical teams need recovery runbooks that reflect real business priorities, not just infrastructure diagrams. Executives need evidence that impact tolerances are realistic. Operators need an environment where they can test recovery without putting production systems at risk.
That is why modern cyber resiliency depends on continuous validation. It asks organizations to define critical services, protect the data and configurations those services depend on, and rehearse recovery before an incident forces those decisions in real time. In practice, that means using capabilities such as immutable storage, isolated recovery, malware and anomaly detection, and workload-aware recovery orchestration to make recovery more predictable when conditions are least predictable.
How AI changes ransomware readiness
AI changes cyber resiliency by increasing the amount of business-critical data that must be governed, protected, and recoverable. AI applications depend on training data, retrieval-augmented generation sources, vector stores, model outputs, prompts, logs, and API-connected workflows. Each element can create new exposure if access control, classification, and recovery planning do not keep pace.
Attackers are also using AI to increase scale and precision. IBM reported that 25% of breaches involved attacker use of AI, a whopping 56% increase over last year. Most of those attacks employed AI-generated phishing and deepfake impersonation. Verizon’s 2026 DBIR describes threat actors using generative AI in targeting, initial access, vulnerability research, and tool development. The practical takeaway is that recovery planning has to assume faster and more adaptive attack paths.
For defenders, AI is also part of the answer when used with governance. AI-assisted anomaly detection, threat hunting, and recovery intelligence can help teams identify unusual behavior, assess recovery points, isolate compromised files and prevent them from being restored, and prioritize response actions.
But those capabilities are most useful when they work from a clear data foundation. Organizations need to know what sensitive data exists, where it is stored, who or what can access it, and whether AI systems are using it appropriately.
Commvault capabilities such as Risk Analysis can support that foundation by helping teams discover, classify, and assess data risk. For AI-dependent environments, the resilience question becomes very specific: Can the organization recover the data, systems, and access paths required for AI-enabled operations without restoring compromised or overexposed data? Cyber resiliency has to cover that full chain.
What clean recovery requires
Clean recovery starts with the assumption that not every backup is safe to restore. Ransomware actors often try to corrupt, encrypt, delete, or tamper with recovery sources before defenders understand the full scope of compromise. That makes recovery a data trust problem. Teams need a way to help identify viable recovery points, isolate recovery activity, scan for threats, and validate restored workloads before returning them to production.
There are three essential requirements to move forward with clean recovery:
Resilient backup storage. Immutable and indelible copies help keep recovery data available within defined retention settings, even if production systems are compromised. Air-gapped architecture adds separation from the affected environment. Capabilities such as Commvault AirGap can help organizations maintain protected backup copies that support ransomware recovery planning.
An isolated place to test and stage recovery. Restoring directly into production can increase risk when teams are still investigating the blast radius. Commvault Cleanroom helps support secure, isolated recovery testing, cyber forensics, and recovery staging so teams can validate workloads before broader restoration.
Recovery prioritization. After a ransomware incident, the question is not only how fast data can be restored, it is which systems need to come back first to support minimum viable operations. Identity services, communications platforms, customer-facing applications, and core data stores may have to be recovered in a specific sequence. This is why cyber resiliency depends on runbooks, automation, and testing. A clean recovery plan must reflect how the business actually operates.
How Commvault helps support cyber resiliency
Commvault Cloud helps support cyber resiliency by connecting data protection, data security, identity recovery, and clean recovery capabilities within a unified platform. That matters because ransomware and AI-era disruption do not respect infrastructure boundaries. Critical data may be spread across on-premises systems, cloud workloads, SaaS applications, endpoints, databases, file stores, and AI data environments. Recovery planning has to span those environments without forcing teams into disconnected workflows.
For ransomware readiness, Commvault Cloud can help organizations maintain immutable and indelible backup copies, use air-gapped storage, and stage recovery in isolated environments. Commvault Cleanroom helps teams test recovery plans, conduct recovery validation, and support forensic investigation without relying on production infrastructure. AI-assisted recovery capabilities can help identify cleaner recovery options and improve decision-making during restoration.
For data security, Commvault Risk Analysis helps discover and classify sensitive data so teams can understand where exposure exists before and after an incident. This is increasingly important as AI systems consume and generate more data across business functions.
For identity resilience, Commvault’s Active Directory and Entra ID resilience capabilities help teams recover identity systems that may be required before other critical applications can be accessed and restored.
The broader value is operational. Cyber resiliency improves when teams can define recovery priorities, validate clean recovery paths, and prove that critical services can be restored under realistic conditions. Commvault does not replace the need for disciplined incident response or resilience planning. It offers teams platform capabilities that can help make those plans more measurable, repeatable, and executable across hybrid environments.
Make cyber resiliency measurable before the next attack
AI and ransomware are changing the recovery conversation from “Do we have backups?” to “Can we restore trusted operations in the right order, from trusted data, with evidence that the recovery path works?” That distinction matters because disruption can affect identity, production data, SaaS applications, cloud workloads, AI pipelines, and recovery infrastructure at the same time.
Cyber resiliency depends on data risk visibility, resilient backup copies, identity recovery, clean recovery validation, and practiced workflows tied to business priorities. Commvault Cloud brings together data protection, data security, cyber recovery, and identity resilience capabilities across hybrid environments to help support that model.
It’s critical to make resilience measurable before the next incident tests it. Teams should take steps now to define minimum viable operations, identify what must come back first, validate recovery in isolated environments, and keep recovery plans aligned with changing AI and ransomware risk.
Frequently Asked Questions
How does AI affect resiliency?
AI affects resiliency by expanding the data, access, and application dependencies organizations must protect and recover. Models, prompts, pipelines, vector databases, and AI-connected workflows need governance, classification, clean recovery planning, and controls that can help limit sensitive data exposure.
Why is clean recovery important?
Clean recovery helps teams avoid restoring compromised, encrypted, or corrupted data after a ransomware attack. Capabilities such as Commvault Cleanroom™ help support isolated testing, cyber forensics, and validation so teams can assess workloads before returning them to production environments.
How does Commvault help support ransomware recovery?
Commvault Cloud helps support ransomware recovery with immutable and indelible backup copies, Commvault AirGap, Commvault Cleanroom, threat detection, recovery orchestration, and cyber recovery testing capabilities that help organizations more predictably restore trusted data and critical workloads after disruptive cyberattacks.
How do identity providers and identity systems affect recovery?
Identity systems often need to be recovered early because users, administrators, applications, and recovery tools depend on trusted access. Commvault supports Identity Resilience for Active Directory, Entra ID, and Okta recovery to help restore identity services after corruption, accidental deletion, or cyberattack.
How can teams help protect backups?
Backup protection depends on separation, immutability, and retention controls that remain available when production systems are disrupted. Commvault AirGap provides air-gapped, immutable cloud storage designed to help preserve protected backup data within defined retention settings during ransomware recovery.
How should teams prioritize recovery?
Recovery priorities should reflect business criticality, data sensitivity, exposure risk, and system dependencies. Commvault Risk Analysis helps discover, classify, and assess data risk so teams can make more informed protection, investigation, governance, and recovery decisions during incidents.
Throughout the Ready. Or Not. series, we’ve explored topics like agentic AI, digital trust, the human factor, and vibe coding. In this fifth and final episode of season one, the conversation shifts to the one constant behind every AI conversation: data.
Nathan Macintosh sits down with Ben Lorica, former chief data scientist at O’Reilly Media and founder of Gradient Flow, to discuss what AI readiness really looks like. Their conversation moves beyond algorithms and applications to the work organizations need to do before AI can succeed.
They explore why AI is changing the way we think about governance, why collecting more data isn’t always the answer, and why preparation matters just as much as adoption.
AI readiness starts with understanding and organizing the data you already have.
Governance now applies to AI systems, not just people.
More data isn’t always better. Strive for better data.
AI introduces new risks that require new processes, not just new technology.
The organizations best prepared for AI are building strong data foundations today.
Organizations are generating and managing more data than ever before. It’s easy to assume the next step is simply collecting more data. Ben explains why preparing and governing the data you already have may be a much stronger foundation for AI.
One thing I appreciated about Ben’s perspective is that he never presents AI readiness as a technology problem alone. It’s an organizational challenge that starts long before teams begin putting AI to work.
Here are a few ideas that stayed with me.
AI Is Only as Good as the Data Behind It
“Focus on the data you have … and get that ready for AI.”
– Ben Lorica
One of Ben’s first points challenged a common assumption. When organizations talk about becoming “AI ready,” the instinct is often to collect more data. Ben sees it differently. Instead of prioritizing quantity, he encourages organizations to focus on quality and prepare their existing data for AI.
That starts with understanding what data you have, organizing it, and making sure it’s accurate and well governed. As AI becomes part of more business processes, organizations will rely on many different types of information, from spreadsheets to text, images, audio, and video. If that data isn’t reliable, AI won’t fix the problem – and it can make it even more difficult to spot.
There’s understandable pressure to move quickly with AI. This conversation reminded me that taking the time to build a solid data foundation may be one of the smartest investments we can make. Clean, well-governed data helps organizations make better decisions today while preparing them for whatever comes next.
AI Changes the Role of Governance
Ben points out that governance has a broader job to do. It’s no longer just about managing how people access and use information. Organizations also need to think about how AI interacts with that information and the actions it takes.
As AI becomes part of everyday work, it can access, analyze, and act on information at a scale and speed that’s difficult for people to match. That means organizations need to understand what AI can access, how it’s using that information, and what safeguards should be in place to protect sensitive data.
What’s interesting is that the fundamentals of governance haven’t changed. Clear policies around access, security, and accountability are just as important as they’ve always been. What is changing is the number of systems interacting with organizational data and the pace at which information moves across the business.
To me, that’s one of the most important takeaways from this episode. AI doesn’t replace good governance. It makes it even more important.
Sneak Peek: When Data Starts to Multiply
What happens when AI allows five people to do the work of 100? Ben explains why the real challenge isn’t productivity. It’s the explosion of data that comes with it.
Responsible AI Starts With Responsible People
One thing Ben emphasizes throughout the conversation is that organizations can’t rely on technology alone to make AI responsible. The people using AI play an important role, too.
Whether employees are entering prompts, uploading documents, or fine-tuning models, they need to understand what information they’re sharing and how it could be used. Guardrails aren’t just about restricting access. They’re also about helping people make informed decisions when working with AI.
Ben points out that organizations should think beyond what goes into an AI system. They should also pay attention to what comes out. AI can unintentionally generate sensitive information, making review and oversight of the outputs just as important as the prompts that started the interaction.
It’s another reminder that responsible AI isn’t just a technology challenge. It’s a shared responsibility between the people using AI and the policies that guide them.
Plan for the Unknown
There’s understandable pressure to adopt AI quickly. New tools are emerging almost daily, and organizations don’t want to fall behind. But Ben makes the case that readiness isn’t just about moving fast. It’s about having the right processes in place before they’re needed.
Toward the end of the conversation, Ben points out that many AI teams haven’t fully considered what they’ll do when things go wrong. I love Nathan’s response because it was exactly what I was thinking:
“Why wouldn’t they think of that? That’s all I think about.”
– Nathan Macintosh
In cybersecurity, resilient organizations don’t wait for an incident before deciding how they’ll respond. They establish roles, define processes, and prepare for different scenarios long before they’re needed. Ben argues that AI deserves the same level of preparation.
That means asking questions many organizations haven’t fully considered yet, like:
What data should AI have access to?
Who should be involved if an AI-generated output creates a problem?
How will decisions be made if something unexpected happens?
These conversations may not be as exciting as launching an AI initiative, but they’re just as important.
One Final Takeaway
As this season of Ready. Or Not. comes to a close, one thing has become clear to me. Every episode explored a different AI concept or trend, yet they all reinforced the same idea: successful AI adoption isn’t just about the technology. It’s about the people, processes, and preparation that make it possible.
Organizations don’t have to have every answer before embracing AI. But the more intentional they are about building strong foundations today, the more prepared they’ll be for whatever comes next.
A: AI readiness begins with understanding, organizing, governing, and protecting the data your organization already has. Strong data practices create the foundation AI depends on.
Q: Should organizations collect more data for AI?
A: Not necessarily. Ben recommends focusing first on improving the quality and organization of existing data before expanding data collection efforts.
Q: What’s the role of employees in responsible AI use?
A: Employees play an important role in AI governance. They need to understand what information is appropriate to share with AI, review AI-generated outputs carefully, and follow organizational policies for using AI responsibly.
Q: Why does AI change data governance?
A: AI systems increasingly access, analyze, and act on organizational data. That means governance policies need to apply to machines as well as people.
Q: Why should organizations prepare for unexpected AI issues?
A: AI can introduce new risks, from exposing sensitive information to producing unintended results. Preparing in advance by defining responsibilities and response processes helps organizations address those situations with greater confidence.
Q: What’s the biggest takeaway from this episode?
A: AI readiness isn’t just about adopting new technology. It’s about building solid governance, good data practices, and resilient organizational processes that help allow AI to be used responsibly and effectively.
Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Why Modern Cyber Risk Demands A-to-Z Cyber Resilience
Ransomware attacks target the full data lifecycle – from backups to production systems. See how Commvault’s A-to-Z cyber resilience approach unifies protection, detection, and recovery to help managerisk and restore operations fast.
Modern cyber risk demands unified resilience across the entire data lifecycle, from prevention to recovery, as fragmented tools fail to address today’s complex threat landscape.
Cyber risk now affects customer trust, with breaches often leading to lost business and reputational damage.
A-to-Z resilience brings protection, monitoring, governance, and recovery into a unified, more effective strategy.
Leadership is essential in driving proactive defense, rapid response, and clear communication across the organization.
Fragmented data security tools leave gaps in hybrid environments that attackers can exploit more easily.
An end-to-end approach helps improve visibility, speed recovery, and maintain business continuity.
Modern cyber risk spans the entire data lifecycle – from vulnerabilities and threats to recovery and compliance – making fragmented, reactive tools insufficient. Organizations need A-to-Z cyber resilience that unifies protection, monitoring, governance, and recovery. This approach helps managerisk, strengthen security posture, and enable faster, more reliable recovery across complex hybrid environments.
A Single Breach Can Cost You Customer Trust
Cyber risk is no longer just an IT issue – it is a direct threat to customer trust and revenue.
Sixty-four percent of consumers would stop doing business with a company after a significant data breach, highlighting how quickly loyalty erodes when data is compromised.
This shift raises the stakes: Resilience is no longer optional; it is expected.
At the same time, there is a disconnect between expectations and behavior. Consumers demand strong data protection, yet risky habits like password reuse or unsecured networks persist. That inconsistency can increase exposure and places more responsibility on organizations to protect data across every touchpoint.
Trust is earned through consistent action – especially in cybersecurity.
Commvault Cloud, powered by Metallic AI, helps organizations take that action by unifying protection, monitoring, and recovery across the full data lifecycle, reinforcing trust through consistent execution. The infographic reflects this A-to-Z approach, spanning early warning, threat monitoring, and rapid recovery.
For organizations, the takeaway is clear: Resilience is not just about preventing attacks. It is about maintaining trust when prevention fails.
Cyber Resilience Starts with Leadership
As threats grow more sophisticated, cyber resilience has become a business priority that extends beyond IT teams. Leadership plays a critical role in aligning strategy, investment, and accountability across the organization.
This mandate shows up in three ways:
Protect before the breach. Strengthen defenses with zero-trust principles, regular monitoring, and unified platforms that adapt to evolving threats.
Respond fast when incidents occur. Customers and stakeholders judge organizations not just on whether a breach happens – but how quickly and effectively they recover.
Communicate with transparency Clear, timely communication helps preserve trust. Silence or delays can amplify reputational damage.
Commvault Cloud supports this leadership mandate by bringing governance, threat detection, and orchestrated recovery into a single platform – helping organizations align teams and respond with greater speed and coordination.
End-to-End Resilience Helps Manage Risk
Modern environments are too complex for fragmented tools to keep up. Data spans hybrid cloud, on-prem systems, and SaaS applications – creating a broad and dynamic attack surface. Point solutions leave gaps that attackers exploit.
An end-to-end approach helps close those gaps by integrating capabilities across the lifecycle: vulnerability management, threat detection, immutability, air-gapped protection, and orchestrated recovery. This unified model helps improve visibility and enable faster, more reliable response.
Commvault Cloud brings these capabilities together with AI-enabled insights, regular monitoring, and automated recovery workflows, helping organizations manage risk and maintain operational continuity across hybrid environments.
Organizations should plan for cyber incidents as an expected event and prioritize resilience and recovery readiness. The difference lies in readiness – and having a unified approach to protection, detection, and recovery across the data lifecycle.
Frequently Asked Questions
What is A-to-Z cyber resilience?
A-to-Z cyber resilience is a unified approach that covers the entire data lifecycle – from protection and monitoring through governance and recovery. Commvault Cloud helps you implements this through its resilience operations (ResOps) framework, replacing fragmented tools with an integrated strategy that uses AI-enabled threat detection, immutable storage, and orchestrated recovery to help managerisk and improve response times across hybrid environments.
Why is cyber resilience a business priority, not just an IT concern?
Cyber incidents can directly impact customer trust, revenue, and brand reputation. Commvault Cloud helps organizations address this risk with unified data protection and threat monitoring, giving business leaders visibility and control to be able to respond quickly and maintain trust across critical operations.
How does a data breach affect customer trust?
A single breach can quickly erode customer confidence, especially when sensitive data is exposed. Commvault Cloud Threat Scan helps identify hidden threats in backup data, enabling safer recovery and helping organizations maintain trust through more reliable, clean restore processes.
What role does leadership play in cyber resilience?
Leadership aligns strategy, investment, and accountability across the organization. With Commvault Cloud and its ResOps framework, leaders can unify protection, detection, and recovery efforts, helping teams act faster, coordinate response, and communicate effectively during cyber incidents.
Why are fragmented cybersecurity tools no longer effective?
Modern environments span hybrid cloud, SaaS, and on-prem systems, creating a broad attack surface. Commvault Cloud unifies capabilities like air-gapped protection, regularmonitoring, and automated recovery, helping eliminate gaps and enable more coordinated, efficient responses to threats.
How does Commvault Cloud support cyber resilience?
Commvault Cloud integrates protection, threat detection, and recovery into a single platform. With capabilities like Commvault Cleanroom™ and automated workflows, it helps organizations managerisk, accelerate recovery, and maintain business continuity across the data lifecycle.
Data and ransomware protection: cyber resilience from A to Z
See a visual representation of Commvault’s solution for cyber-resilient ransomware protection that helps you secure, defend, and recover your data – from A-Z.
Streamlining Data Protection and Management for the Hybrid Enterprise
Learn why Commvault’s solution can help organizations streamline their data management processes, manage risk, and enable the resilience of their critical data.
Every episode of Ready. Or Not. has challenged me to think about AI a little differently. The conversations have moved from understanding agentic AI to building trust and preparing organizations for responsible adoption. This episode turns its attention to vibe coding and why it’s becoming one of AI’s most talked-about ways of working.
Comedian Nathan Macintosh sits down with Microsoft engineer and open-source leader Harald Kirschner to discuss what vibe coding really means, why it’s gaining momentum, and where it can go wrong if speed outpaces oversight.
AI is making it easier for organizations to test ideas, solve problems, and innovate faster.
Vibe coding helps teams quickly explore and validate ideas before making larger investments.
AI delivers more value when it’s used to challenge assumptions – not just generate content.
Human judgment, thoughtful review, and clear guardrails remain essential in an AI-driven world.
The organizations that learn faster will be better positioned to innovate.
I was already familiar with the term vibe coding, but after listening to this episode, I walked away with a much better understanding of why people – not just developers, but also nontechnical teams – are embracing it.
By the end of the conversation, I realized vibe coding isn’t really about coding at all. It’s about learning faster and knowing where AI fits into the creative process. The conversation also makes something else clear: AI may accelerate the work, but people are still responsible for guiding it. That’s why guardrails matter more than ever. Here are some of the themes that resonated with me.
From Idea to Reality
One thing I learned about vibe coding is that it’s changing how organizations explore ideas. Instead of spending weeks building something before finding out whether it works, teams can quickly create a prototype, gather feedback, and decide whether it’s worth pursuing.
“AI can be a really good critical thought partner if it’s applied properly.”
– Harald Kirschner
Harald explains that vibe coding uses natural language to turn ideas into working software. He uses software development as an example, but the concept extends beyond engineering teams. For a product manager testing a new feature, a designer exploring an interface, or a business leader validating a concept, AI makes it much easier to turn an idea into something people can actually experience.
That ability to experiment may be one of AI’s greatest strengths. Organizations can learn what resonates, refine ideas earlier, and invest time and resources only after they’ve gained confidence that they’re solving the right problem.
Moving Fast Still Requires Oversight
One thing Harald emphasizes throughout the conversation is that speed shouldn’t come at the expense of a thorough review.
Again, he uses software development as an example. AI can quickly generate working code, but that doesn’t automatically make it secure, reliable, or ready for production. Developers still need to review it, test it, and make sure it meets the same standards they would apply to anything else they build.
Harald’s lesson extends well beyond engineering. As AI becomes part of business processes, organizations will need the same mindset whether they’re generating software, creating content, analyzing data, or automating workflows. Vibe coding can help the work move faster, but people are still responsible for validating the results.
That’s one of the most important lessons from the episode. While AI can make it easier to create something quickly, human expertise is what turns a good idea into something people can trust.
Honest Feedback Gets Better Results
A memorable moment in this episode starts with an unexpected prompt. Instead of asking AI to write code, Harald asks it to critique his work by prompting it to “Roast my code.”
It’s funny, but it’s also an effective way to get more honest feedback from AI. Instead of acting like an assistant that simply completes a task, AI becomes more like a trusted colleague offering another perspective. Used this way, it can challenge assumptions, uncover blind spots, and improve the quality of the final result.
AI’s constructive criticism can help us improve our work, but it also becomes more useful when we continue teaching and refining it. Anyone who’s spent time working with AI knows it could use a little feedback, too.
Sneak Peek: Checking the Vibe
What happens when AI keeps making the same mistakes? Nathan compares it to an unruly party guest who eventually stops getting invited. Hear Harald explain how to train AI to become more useful over time.
Innovation Becomes More Accessible
Something that keeps resurfacing throughout the conversation is that AI is changing who gets to participate in innovation.
AI is lowering the barrier for people across an organization to explore ideas, experiment with new approaches, and quickly bring concepts to life. Instead of relying on technical specialists to validate every idea, more people can create something tangible, gather feedback, and refine their thinking before significant time and resources are invested.
“… you can actually build it and hand it to some people and see like, oh, this is flying, or this is really falling flat.”
– Harald Kirschner
To me, that’s one of AI’s most exciting opportunities. By making experimentation faster and more accessible, AI gives organizations the confidence to test more ideas, learn from them sooner, and involve more people into the creative process.
Ready for What’s Next
Vibe coding may be the workflow everyone’s talking about today, but the bigger story is how AI continues to change the way we learn, experiment, and solve problems. Every episode of Ready. Or Not. reminds me that the organizations willing to explore new technology will be the ones best prepared for what’s next.
A: Vibe coding is an emerging way of working with AI that uses natural language to quickly turn ideas into something tangible. Instead of starting from scratch, people can use AI to prototype concepts, explore solutions, gather feedback, and iterate much more quickly.
Q: Why is vibe coding generating so much interest?
A: Vibe coding lowers the barrier to experimentation. It allows more people – not just technical specialists – to test ideas, validate concepts, and learn what works before investing significant time and resources.
Q: Does vibe coding replace human expertise?
A: No. The conversation makes it clear that AI works best as a collaborator, not a replacement. People are still responsible for applying judgment, reviewing results, and deciding what should move forward.
Q: Why do organizations still need guardrails when using AI?
A: AI can accelerate work, but it doesn’t eliminate the need for thoughtful oversight. Clear policies, review processes, and human expertise help organizations validate AI-generated work and reduce unnecessary risk.
Q: How can AI improve the way organizations work?
A: Beyond generating content or prototypes, AI can help challenge assumptions, identify blind spots, suggest improvements, and accelerate learning. Used thoughtfully, it becomes another perspective that helps teams make better decisions.
Q: What’s the biggest takeaway from this episode?
A: The greatest value of AI isn’t simply helping organizations move faster. It’s helping them experiment more freely, learn more quickly, and involve more people in the innovation process – while continuing to rely on human judgment to guide the final decisions.
Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Commvault has joined the Open Secure AI Alliance to help advance open, secure, and collaborative approaches to AI.
Open source AI tools give organizations greater visibility and control, allowing experts to inspect, adapt, and strengthen systems as threats and requirements evolve.
Effective AI security extends beyond models to include identity, permissions, guardrails, logging, evaluation, and the broader environment in which AI agents operate.
Cross-industry collaboration and shared research can help organizations respond more quickly to the rapidly changing challenges created by increasingly capable agentic AI.
Commvault will share its cyber resilience and data expertise with the Alliance, grounded in the principle that organizations can better protect systems and data they fully understand.
Collaboration has long been one of the most effective ways the technology industry meets new challenges. The past few months have brought that lesson into sharper focus for AI. Agentic systems are becoming more capable, more independent, and more deeply connected to the technology we use every day.
Recent events also have shown how quickly this landscape can change. When an advanced AI system created an unexpected security challenge for Hugging Face, the organization used an open-weight model on its own infrastructure to understand and contain the situation. The experience demonstrated the value of open source AI tools that organizations can inspect, adapt, and control when needed.
Moments like this should not diminish our optimism about AI. They should deepen our commitment to shaping its future together.
That is why Commvault is proud to join the Open Secure AI Alliance, a community of leading organizations advancing AI through open research, shared knowledge, and practical tools.
AI will keep evolving, and no single organization will have every answer. Bringing together deep expertise from across the industry gives the community a better chance to understand what is changing and respond with the speed this new era demands.
Open source is central to that effort. It gives experts the ability to examine how systems work and improve what others have started. For defenders, it also provides something essential: the freedom to choose and adapt the right technology for the situation rather than depending on a single system or provider.
NVIDIA describes this as an open defense foundation built on models, harnesses, and tools that the community can study and strengthen.
The Alliance also recognizes that AI security extends well beyond the model. Identity, permissions, guardrails, logs, and evaluation all shape how an agent behaves. Understanding that complete environment will take new research and a willingness to share what the industry learns along the way.
Commvault’s perspective is grounded in years of solving complex cyber resilience challenges – helping organizations understand their data, keep it trustworthy, and recover with confidence when disruption strikes.
Much of that work comes down to the same idea the Alliance is pursuing: You can only protect what you fully understand. That’s the experience we hope to bring, alongside an eagerness to learn from others tackling these challenges from different angles.
The opportunity ahead for AI is enormous. Realizing it will depend not only on how quickly the technology advances, but on how openly the industry works together as it does. Commvault is glad to be part of that work, and excited to help build what comes next.
Q: What is the Open Secure AI Alliance? A: The Open Secure AI Alliance is a community of organizations working to advance AI security through open research, shared knowledge, models, harnesses, and practical tools. Its collaborative approach gives participants opportunities to study emerging challenges and strengthen AI defenses together.
Q: Why has Commvault joined the Open Secure AI Alliance? A: Commvault joined the Alliance to contribute its experience in cyber resilience, data understanding, trust, and recovery. It also provides an opportunity for Commvault to learn from other industry leaders approaching AI security from different perspectives.
Q: Why is open source important for AI security? A: Open source allows experts to examine how AI systems work, build on existing technologies, and adapt tools to specific security situations. It also gives defenders greater freedom to select and modify technologies rather than relying on a single system or provider.
Q: What does AI security involve beyond protecting the model? A: AI security encompasses the broader environment in which an AI system operates, including identity, permissions, guardrails, logs, and evaluation. Understanding these interconnected elements can help organizations better assess and manage how AI agents behave.
Q: How does Commvault’s cyber resilience experience relate to AI security? A: Commvault’s cyber resilience work focuses on helping organizations understand their data, maintain its trustworthiness, and recover confidently after disruption. That perspective fits naturally with the Alliance’s focus on open, inspectable approaches to AI security.
Q: Why is industry collaboration important for the future of AI? A: AI is evolving too quickly and broadly for any single organization to have every answer. Combining expertise, research, and practical insights across the industry can help the community understand emerging challenges and respond at the speed AI development demands.
Alexander Coombes is AVP, Strategic Partner Development, at Commvault.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Cloud Backup and Recovery Explained: From Threat Detection to Full Recovery
Learn how cloud backup and recovery works to help protect clean data, validate recovery readiness, and restore business operations after a ransomware attack or cyber incident.
Modern cloud backup and recovery is about more than backups. It should help organizations identify threats, protect data, and recover business operations quickly and confidently.
Recovery starts long before restoration. Early threat detection can help identify compromised data and prevent infected backups from being restored.
Immutable backups are essential. Organizations can leverage these guarded, isolated recovery copies to help protect against ransomware and backup-targeted attacks.
Recovery confidence requires validation; organizations must test backup integrity and recovery readiness before an incident occurs.
Cloud backup and recovery is a resilience strategy. The goal isn’t just data protection – it’s reducing downtime and restoring business operations faster.
The ideal cloud backup and recovery process begins by detecting threats such as ransomware, suspicious access, or abnormal data activity. Organizations can then obtain clean, immutable backup copies; validate unaffected recovery points; and isolate compromised systems. Once verified, critical applications and data can be restored through automated recovery processes, helping minimize downtime, reduce data loss, and restore business operations quickly and safely.
Cyber resilience is increasingly measured by what happens after attackers get in. Organizations have invested heavily in prevention, detection, and response, but ransomware, vulnerability exploitation, credential abuse, cloud misconfigurations, and third-party compromise continue to disrupt operations.
For many teams, the recovery challenge is no longer simply whether backups exist. It is whether those backups are clean, protected, validated, and ready to restore critical services when production systems can no longer be trusted.
That distinction matters because cyberattacks continue to create both data risk and operational disruption. According to the Verizon 2026 Data Breach Investigations Report, ransomware was involved in 48% of breaches, up from 44% the previous year. The report also found that exploitation of vulnerabilities became the most common initial access vector for breaches, rising to 31% while credential abuse fell to 13%.
Cloud backup and recovery efforts need to support the full path from detection to restoration. That starts with identifying suspicious activity before compromised data is restored. It continues with protected, immutable recovery points that give teams usable recovery options when production systems are no longer trusted.
From there, organizations need a way to validate which recovery points are clean and restore critical workloads in the right order. The result is a recovery strategy that helps teams move from incident response to operational restoration with more confidence.
Why is Cloud backup and recovery a cyber resilience strategy?
Traditional backup strategies were designed to help organizations recover from hardware failures, accidental deletion, and localized outages. Those use cases still matter, but today’s recovery requirements are broader.
Cyberattacks can affect production workloads, identity systems, cloud configurations, SaaS applications, and backup environments at the same time. When that happens, recovery is not just about restoring a copy of data. It is about determining which systems can be trusted, which recovery points remain clean, and which services need to come back first.
That is why cloud backup and recovery has become a critical part of cyber resilience. A modern strategy should help teams detect suspicious activity, protect recovery data, validate backup integrity, and restore critical operations in a controlled sequence. It should also help support regular testing, because a recovery plan that has not been exercised may not perform as expected during a real incident.
This marks a shift from backup as an insurance policy to recoverability as an operational capability. Stored copies still matter, but they are only one part of the recovery equation. Teams also need confidence that recovery data has not been altered, that restoration workflows have been tested, and that the business knows which services must come back first.
Cloud backup and recovery becomes easier to understand when it is viewed as a lifecycle. The five stages below show how organizations can move from early threat detection to validated recovery and long-term resilience improvement.
Stage 1: Detect threats before recovery risk spreads
Recovery starts before systems are restored. In a cyber incident, the first priority is to understand whether suspicious activity has affected production data, backup data, or both.
If teams restore from a compromised recovery point, they may bring corrupted files, malware artifacts, or unauthorized changes back into the environment. That risk makes threat detection an important part of cloud backup and recovery, not just a security operations concern.
Modern recovery strategies should include visibility into abnormal activity across workloads, backup environments, and recovery points. Teams may need to investigate signals such as:
Unusual encryption behavior
Sudden deletion spikes
Unexpected privilege changes
Abnormal backup patterns
Malware indicators
These signals can help teams understand where an attack may have spread and which data may require additional review before restoration.
Timing is another essential factor. Microsoft’s 2025 Digital Defense Report found that most attacks investigated by its Detection and Response Team (DART) had short dwell times, which means recovery teams may not have weeks to understand the full scope of compromise before attackers move laterally, access sensitive data, interfere with services, or attempt to affect backup systems. Detection context can help teams avoid treating every recovery point as equally trustworthy.
59% of attacks Microsoft DART investigated had dwell times of seven days or less, making early detection critical to recovery decisions. Source: Microsoft Digital Defense Report 2025
Threat detection doesn’t eliminate recovery risk on its own. It helps create a more informed recovery process. When suspicious activity is identified early, organizations can isolate affected systems, investigate impacted data, and avoid restoring recovery points that may reintroduce the same threat.
That gives security, IT, and recovery teams a clearer starting point for the next stage: protecting clean recovery points before attackers can alter or remove them.
Stage 2: Protect clean recovery points from attack
In a cyber incident, backups are not just stored copies. They are part of the recovery path, which means attackers may try to disrupt them. If backup data is altered, encrypted, deleted, or made inaccessible, the organization may lose one of its best options for restoring operations without relying on compromised production systems.
That’s why clean recovery points need layered protection. Immutable and indelible backup storage can help preserve data for a defined retention period. Offsite or isolated copies help add separation from the production environment. Encryption, access controls, and role-based permissions help limit who can access or change backup settings. Together, these safeguards make it harder for attackers to interfere with the data teams may need most during recovery.
The goal is to preserve recovery choice. The 2026 Verizon report found that 69% of ransomware victims in its dataset did not pay the ransom, up from 65% the prior year. The report also notes that median ransom payments continued to decline, which it links in part to improved defensive adaptations and increased victim resilience. Teams need clean backups they can actually use, so paying a ransom is not the only path back to business.
The familiar 3-2-1 backup rule still provides a useful foundation: Keep three copies of data, on two different media or platforms, with at least one copy stored offsite or isolated. Modern cloud backup and recovery strategies often extend that model with immutable storage, air-gapped patterns, policy-based retention, and replicated copies across cloud or hybrid environments.
With protected recovery points in place, teams can pare down their restore options and move into validation with a clearer view of what is ready to bring back.
Stage 3: Validate which backups are ready to restore
Having backups is not the same as being ready to recover. Before teams restore production systems, they need to know which recovery points are usable, which workloads were affected, and what dependencies must come back with them.
A recent backup may contain the latest business data, but it also may include corrupted files, unauthorized changes, or malware artifacts. An older backup may be cleaner, but it may create more data loss. Validation helps teams make that tradeoff with evidence instead of guesswork.
That work starts with scoping the incident. Security and IT teams need to understand when suspicious activity began, which systems were touched, and whether identity services, databases, file shares, SaaS applications, or cloud configurations were affected.
They also need to confirm whether the recovery point supports the application as a whole, not just the data behind it. A database restore, for example, may depend on application servers, permissions, encryption keys, network routes, and identity services all being available in the right state.
Isolated recovery environments can help teams test those conditions before restoring into production. In a controlled environment, teams can safely:
Scan selected recovery points.
Review file changes.
Confirm application startup.
Test user access.
Check whether dependent systems behave as expected.
Validation also should feed the recovery sequence. Teams may need to restore identity services first, then core infrastructure, then mission-critical applications, and then supporting workloads.
By testing recovery points before restoration, they can narrow their options and decide which systems are ready to bring back, which need further review, and which should remain isolated until the risk is better understood.
The next stage is where that decision turns into action: restoring the systems, applications, and data the business needs first.
Stage 4: Restore critical operations in the right order
A restore plan starts with the organization’s minimum viable operating state. That means identifying the people, systems, applications, data, and communication channels the business needs to function at a basic level during a disruption.
For some organizations, that may start with identity services and employee communications. For others, it may prioritize customer-facing applications, payment systems, clinical systems, manufacturing operations, or logistics platforms. The order should reflect business impact, not just technical convenience.
Dependencies are where many recovery plans become more complicated. An application may be listed as “critical,” but it still depends on identity, DNS, network connectivity, databases, storage, encryption keys, APIs, and monitoring. If those pieces are not restored in the right state, the application may come back online but remain unusable. That is why recovery teams need dependency mapping before an incident, not during one.
Runbooks and orchestrated workflows help turn those decisions into repeatable steps. They can define who approves the restore, which environment should be used, which checks must happen before production access is restored, and when the next tier of systems can come online. This matters when security, infrastructure, application, cloud, and business teams are all working at the same time.
Restoration also needs checkpoints. After each major workload comes back, teams should confirm that users can authenticate, data is available, integrations are working, and monitoring is in place. Those checks help catch problems before recovery expands to the next tier of systems.
Speed still matters, but control matters just as much. A fast restore can create more work if the wrong data comes back, if access controls are missing, or if an application returns without the systems it needs to run. The stronger approach is to restore in phases, confirm that each critical service is working, and then continue expanding recovery as the environment stabilizes.
Stage 5: Turn recovery lessons into stronger continuity
Once critical services are restored, teams still need to understand what worked, what slowed them down, and where the recovery plan did not match reality. That follow-through is what turns cloud backup and recovery from a response activity into an ongoing resilience practice.
The first step is reviewing the recovery itself. Teams should ask questions such as:
How quickly did teams detect suspicious activity?
Were clean recovery points easy to identify?
Which validation steps took longer than expected?
Where did restore workflows slow down?
Were the right people involved at the right time?
These answers can reveal gaps that are not always technical. A recovery may succeed and still expose problems with decision-making, communication, approvals, or handoffs between teams.
Those findings should feed directly into the next version of the recovery plan. If a critical application depended on a system that was not documented, update the dependency map. If access controls slowed restoration, clarify the approval process. If recovery testing missed a key workload, add it to the next exercise. If business leaders lacked visibility into what was restored and what was still offline, improve reporting and escalation paths.
Regular testing is what keeps this work grounded. Tabletop exercises, isolated restores, clean recovery testing, and cross-cloud recovery validation help teams find issues before a real incident forces them to learn under pressure. They also help give leaders better evidence of where the organization is ready and where it still has work to do.
Over time, the goal is a recovery program that gets sharper after every test and every incident. Teams are better prepared, recovery steps are better understood, and the organization has a clearer path for keeping essential operations running through disruption.
Turning Cloud recovery into business resilience
Cloud backup and recovery now plays a larger role than traditional data protection alone. It is the connected process of detecting recovery risk, protecting backup data, validating clean restore options, and restoring critical services when production environments can no longer be trusted.
In a cyber incident, those activities cannot operate as separate handoffs. Threat context should inform which backups are reviewed. Backup protection should preserve the recovery options teams may need. Validation should determine what is ready to restore. Restoration should bring back the services the business depends on in a controlled order.
A backup that cannot be trusted, tested, or restored at the right time may not give the business the outcome it needs. A restore process that ignores identity, application dependencies, or business priorities can leave systems technically recovered but operationally incomplete.
The larger opportunity is to treat recovery as an ongoing resilience practice. That means testing plans before an incident, updating dependency maps as environments change, and using each exercise or recovery event to improve the next response.
Organizations that recover faster are not necessarily those with the most copies of data. It is imperative to know which data is usable, which services matter most, and how to restore them under pressure.
The challenge is to make recovery readiness as operational as detection and response. Cloud backup and recovery provides a practical foundation for that work when it is treated as a continuous path from risk detection to business restoration.
Organizations should build that muscle to help be better positioned to restore clean data, recover critical services, and keep the business moving when disruption hits.
Accelerate Clean Recovery After Cyberattacks
Learn more about how Commvault’s data backup and recovery solutions can help organizations detect threats, recover clean data, and reduce downtime.
What is the difference between Cloud backup and disaster recovery?
Cloud backup focuses on creating secure copies of data for restoration, while disaster recovery focuses on restoring applications, systems, and business operations after an outage or cyberattack. Together, they help support business continuity and resilience.
Why are immutable backups important for cyber resilience?
Immutable and indelible backups are designed to help prevent backup data from being altered, encrypted, or deleted within defined retention settings. Combined with Commvault AirGap and automated Cleanpoint identification, Commvault’s immutable backup capabilities help keep organizations ready with a verified, clean recovery source available when production systems are compromised.
What should I look for in a Cloud backup and recovery solution?
Look for a platform that unifies hybrid and multi-cloud environments, immutable storage, automated recovery orchestration, and centralized management. Commvault Cloud is designed with these requirements, helping organizations protect diverse infrastructure while minimizing recovery downtime and operational complexity.
Does Commvault’s backup solution provide ransomware protection and air-gapped backups?
Yes. Commvault helps organizations strengthen cyber resilience with immutable backups, air-gapped recovery options, threat detection, clean recovery capabilities, and layered ransomware protection designed to help reduce recovery risk and downtime.
Does Commvault offer automated backup testing and compliance reporting?
Yes. Commvault provides automated recovery testing, backup validation, compliance reporting, and audit-ready visibility to help organizations verify recoverability, demonstrate compliance, and improve recovery readiness.
Related Resources
Blog
Multi-Cloud Recovery That Actually Works
Why backup at the service level isn’t enough – and what it really takes to recover across AWS, Azure, and Google Cloud when ransomware hits.
Cyber Attack Recovery: How to Achieve Minimum Viability in Minutes, Not Days
When cyber attacks strike, every minute costs $14,000 and full recovery takes 24 days on average. But what if you could achieve minimum viability in minutes instead of days?
AI adoption is accelerating, helping make employees more efficient, productive, and competitive.
Organizations need governance and guardrails to adopt AI responsibly and at scale.
Security and productivity don’t have to compete – they can reinforce one another.
AI will become one of security’s most valuable tools for managing cyber risks.
AI adoption works best when innovation and security move together.
One of the things I’ve enjoyed about the Ready. Or Not. series is that each conversation builds on the last. We started by exploring the opportunities and risks of agentic AI. Then we looked at how organizations can build trust as AI becomes part of everyday business. This episode addresses the next logical question: How do we actually use AI safely?
Comedian Nathan Macintosh sits down with Rinki Sethi, CISO and CSO at Upwind Security, for a conversation about what responsible AI adoption actually looks like. They cover everything from AI governance and guardrails to user experience and the growing role AI will play in cybersecurity.
Nathan continues to ask the questions many of us are wondering. Should we be worried? How much more productive do we need to be? And can AI actually make security better?
What I appreciated most about this conversation is that Rinki is genuinely excited about new technology and protecting it. She didn’t frame AI as something organizations need to worry about. Instead, she focused on encouraging businesses to move forward with confidence by putting the right guardrails in place. Here are the ideas that stayed with me.
The push for AI adoption
One thing that becomes clear from the conversation is that many organizations aren’t only encouraging their employees to adopt AI – they’re mandating it. These companies recognize that using AI helps people solve problems more efficiently, which is essential for staying competitive.
“Every single company has a mandate … we’ve got to use AI everywhere in the company.”
– Rinki Sethi
The question is no longer if AI belongs in the workplace, but do employees have the right guardrails to use it responsibly? As AI adoption accelerates, organizations need clear standards around which AI tools employees can use and how company data is protected.
Sneak Peek: AI Governance
Rinki explains that governance isn’t just about protecting against new risks. It’s about creating a framework that helps employees use AI responsibly while keeping pace with evolving regulations and industry standards.
The Hidden Benefit of Productivity
Here’s something I never thought about before. Rinki explains that AI isn’t simply helping people work faster. In many cases, it’s leaving room for the highest-performing employees to excel.
She used software developers as an example. When AI-powered coding assistants became available, many assumed they’d only help less experienced developers. Instead, some of the best engineers began using them to move faster. They were able to solve more complex problems and spend more time on creative work rather than repetitive tasks.
That kind of productivity is exactly why organizations are mandating AI. It doesn’t limit what people can do – it helps give them more space to focus on higher-value work.
“You can be way more creative with how you’re doing things … cause you’re creating the space for that.”
– Rinki Sethi
AI’s Role in Cybersecurity
“How can AI be used to help with security and not be just looked at as a demon thing that’s here to take us out?”
– Nathan Macintosh
When we talk about AI and security, the conversation is often focused on risk. But Rinki believes that AI will become one of cybersecurity’s greatest advantages.
Security teams are already overwhelmed by the volume of alerts, logs, and data they need to investigate every day. Human analysts simply can’t keep up. Rather than replacing security professionals, AI assists them by filtering through massive amounts of data in seconds. This helps analysts identify false positives so they can focus on investigating real threats.
My takeaway is that the future of cybersecurity isn’t about people versus AI – it’s about people working alongside AI to help make better decisions, respond faster, and scale their operations in ways that weren’t possible before.
Ready for What’s Next?
Every episode of Ready. Or Not. has reminded me that the biggest AI conversations are often about people – how we adapt, how we learn, and how we build the confidence to use new technology responsibly. The real opportunity for organizations isn’t just adopting AI. It’s creating an environment where employees can use AI to work smarter, become more creative, and deliver better outcomes for the business.
A: Many organizations see AI as a way to help improve productivity, increase efficiency, and give employees more time to spend on higher-value work.
Q: What is AI governance?
A: AI governance is the combination of policies, processes, and oversight that helps organizations adopt AI responsibly while managing security, privacy, and compliance risks.
Q: Why is user experience important for security?
A: Security controls that create unnecessary friction often encourage people to find workarounds. Designing secure systems that are also easy to use helps improve both adoption and protection.
Q: Can AI help improve cybersecurity?
A: AI can help security teams analyze large amounts of data, which helps reduce false positives. This in turn helps teams prioritize threats and respond more efficiently to security events.
Q: Should people be afraid of AI?
A: Rinki’s perspective is that a healthy sense of skepticism is valuable, but fear shouldn’t prevent organizations from adopting technology responsibly. Education, governance, and strong security practices can help organizations use AI with confidence.
Q: What’s the biggest takeaway from this episode?
A: AI adoption isn’t about choosing between innovation and security. Organizations that combine strong governance with practical security measures will be better positioned to take advantage of AI’s benefits while managing its risks.
Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.
How Mythos and GPT-5.5-Cyber Could Change Cloud Data Security
Specialized cyber AI models could accelerate vulnerability discovery and multi-step attack workflows. Beyond prevention, cloud data security teams need greater visibility, governance, and clean recovery readiness.
Sam Curcuruto, Director, Product Marketing, Commvault
Frontier cyber AI compresses the time between discovery and action, exposing why organizations need resilience-aware cloud data security built around clean recovery and ResOps.
Claude Mythos and GPT-5.5-Cyber remain limited-access models, but they preview a future where AI can reason across complex cyber workflows and accelerate both defense and, potentially, attacker operations.
As the time between vulnerability discovery and exploitation shrinks, organizations need better visibility into cloud dependencies, identity risk, and interconnected attack paths before disruption occurs.
Recovery is no longer just about restoring backups. Organizations need to define their minimum viable company, validate trusted recovery points, and restore critical systems in the right sequence.
Resilience operations align security, IT, and business teams around measurable recovery outcomes, helping organizations govern data, prioritize recovery, and restore trusted operations with greater confidence.
Claude Mythos and GPT-5.5-Cyber could affect cloud data security by speeding up how risks are discovered, tested, and acted on. Their impact is still uncertain, but they point to a need for stronger data visibility, access governance, and clean recovery across cloud environments.
Claude Mythos and GPT-5.5-Cyber are giving security teams an early look at what more specialized cyber AI could mean for cloud data security.
Neither model is widely available, and their long-term impact is still uncertain. But their existence matters because cloud environments are already difficult to defend. Sensitive data, identity systems, SaaS applications, development pipelines, AI workloads, and recovery infrastructure often depend on one another in ways that are hard to see until something goes wrong.
The UK AI Security Institute’s April 2026 evaluation of Claude Mythos Preview found significant improvement on multi-step cyber-attack simulations, including the ability to execute multi-stage attacks on vulnerable networks when explicitly directed in a controlled environment.
The same evaluation cautioned that its ranges differ from real-world environments and do not prove whether Mythos could attack well-defended systems. Still, it shows why cloud data security teams should pay attention to the direction of travel.
As cyber AI capabilities mature, the question is not only whether attacks get faster. It’s whether the window between discovering a weakness and exploiting it continues to shrink. When that clock compresses, cloud data security is no longer just about preventing compromise. Instead, the question shifts to whether organizations can understand risk quickly enough, govern access consistently, and recover trusted operations before disruption spreads.
Why Mythos and GPT-5.5-Cyber Matter
The significance of Mythos and GPT-5.5-Cyber is not that every organization will suddenly have access to them. Based on current public information, they are controlled, limited-access models. For cloud data security teams, their importance is what they suggest about the direction of cyber AI: more specialized systems built to support complex security workflows.
That distinction matters. A general-purpose AI assistant can help summarize alerts or draft an incident report. A specialized cyber AI model is different. It may be designed to reason across vulnerabilities, infrastructure, attack paths, defensive controls, and validation steps. In authorized settings, that could help security teams test environments, prioritize exposures, and strengthen recovery planning before an incident.
For cloud data security teams, the practical impact is less about the model names and more about the workflow they represent. Cloud risk often comes from connections across systems: a misconfigured workload, an exposed dataset, an over-permissive identity, a backup dependency, or an untested recovery path. Specialized cyber AI could make it easier to evaluate those relationships more quickly, especially in large environments where manual review can miss how one issue affects another.
That shift mirrors a broader change happening across cybersecurity. The challenge is becoming less about identifying individual vulnerabilities and more about understanding how interconnected systems behave under pressure. AI may soon help defenders reason across identities, cloud workloads, backups, SaaS applications, AI pipelines, and business dependencies simultaneously — revealing not just isolated risks, but how those risks combine into operational failure.
It also changes how organizations should think about readiness. If AI can help defenders work through complex cyber tasks more efficiently, similar techniques may eventually influence attacker workflows as well. The concern is not only that attacks become faster. It is that the gap between finding a weakness, testing it, and acting on it could shrink.
Cloud data security teams now have to plan for a harder question: what happens when the same types of AI-assisted workflows that help defenders validate risk also make weak points easier to find, test, and chain together? That’s where the cloud environment itself becomes the issue.
AI Is Raising the Stakes for Cloud Data Security
Most organizations don’t have one neat cloud environment. They have multiple clouds, SaaS platforms, data lakes, identity systems, development pipelines, backup repositories, and AI workloads that all depend on each other.
That complexity already creates gaps: sensitive data can be overexposed, access permissions can drift, and recovery plans may not reflect how the business actually runs.
In practice, those gaps rarely stay isolated. A storage bucket with sensitive data may not look urgent on its own. An over-permissive service account may look like a routine configuration issue. An untested recovery dependency may sit unnoticed because the system is still running. But when those issues connect, they can create a path from exposure to disruption.
Attackers are well aware of these vulnerabilities. Mandiant’s 2026 M-Trends report notes that ransomware operators are increasingly targeting backup infrastructure, identity services, and virtualization management planes. It also highlights how attackers are using long-lived OAuth tokens, session cookies, hard-coded keys, and personal access tokens to pivot across environments.
Now add more capable cyber AI to the picture: If models can help find vulnerabilities faster, test exploitability more effectively, or connect weak signals across systems, defenders could benefit. However, attackers may eventually benefit, too—especially if similar capabilities become more accessible or are recreated elsewhere.
22 seconds
Median time between an initial access event and hand-off to a secondary threat group
That’s why the conversation can’t stop at “AI makes attacks faster.” Frontier cyber AI changes the tempo of security. As the time between discovery, validation, and exploitation compresses, every delay in understanding cloud dependencies or preparing recovery becomes more expensive.
How Could Next-Gen Cyber AI Change Cloud Defense?
While the full impact of Mythos and GPT-5.5-Cyber is still unknown, they point to three practical shifts cloud data security teams should be watching. Each one comes back to the same issue: cloud data security now depends on how quickly organizations can understand risk, act on it, and recover when something goes wrong.
Cyber defenders need to watch for:
Speed: AI-assisted tools may help authorized defenders review code, triage vulnerabilities, analyze malware, validate patches, and test controls faster than traditional workflows allow.
Scale: Cloud risk rarely lives in one place. A vulnerability in an application, an over-permissive identity, a misconfigured storage bucket, and an untested recovery path can become one attack chain.
Pressure on recovery: If AI helps attackers move faster, organizations need to recover faster and cleaner. Backups alone aren’t enough if teams don’t know which data is clean, which identity systems can be trusted, or whether recovery will reintroduce compromised assets.
For defenders, the biggest change may be how work gets sequenced. Today, many teams move from alert to investigation to remediation to recovery planning in separate steps, often across separate teams. Cyber AI could compress that workflow by helping teams move from a signal to a set of recommended next actions more quickly.
That doesn’t mean decisions should become automatic. It means teams may need clearer rules for when to trust a recommendation, when to escalate to a human reviewer, and when to move from investigation into recovery preparation. A model may help identify a possible attack path, but people still need to decide whether to close access, isolate a workload, preserve evidence, notify stakeholders, or prepare a clean recovery path.
This is where process becomes as important as tools. Next-gen cyber AI could help defenders move faster, but only if teams have clear validation steps and recovery plans in place. Without that structure, speed can create confusion. With it, AI-assisted workflows could help teams act sooner while maintaining control over how risk is evaluated and how recovery decisions are made.
Why Clean Recovery Matters More as Risk Moves Faster
When cloud risk moves faster, recovery planning has to become more precise. It’s not enough to know that backup copies exist. Teams need confidence that the data they restore is trustworthy, the recovery environment is isolated, and the systems coming back online won’t reintroduce the same threat that caused the disruption.
That matters because cloud environments are highly interconnected. A compromised identity, corrupted dataset, affected virtual machine, or misconfigured workload can create uncertainty across multiple services. During an incident, teams may need to determine which recovery points are clean, which dependencies should come back first, and whether restored data can safely support business operations.
Clean recovery also changes the way teams think about priority. The goal isn’t necessarily restoring everything immediately. It’s restoring enough of the business to operate safely.
Many organizations know which applications they consider “critical,” but far fewer have defined their minimum viable company: the smallest combination of identities, cloud services, data, applications, and infrastructure required to keep the business functioning during disruption. Those dependencies often become visible only when recovery is tested under realistic conditions.
In an AI-dominant threat landscape, determining the minimum viable company is crucial. Faster vulnerability discovery and more efficient attack-chain development could put more pressure on recovery teams to make high-confidence decisions under tight timelines.
What’s more, identity systems, cloud configurations, business communications, customer-facing applications, and the data they depend on may all need to come back in a deliberate sequence — not simply according to technical priority, but according to what the business needs first to operate.
Organizations need recovery processes that can help validate clean data, stage recovery in isolated environments, protect critical identity dependencies, and test recovery plans before an incident forces the issue. As cyber AI capabilities mature, cloud data security teams should treat clean recovery as part of the security strategy, not an after-action step.
Building Resilience-Aware Data Security
Cloud data security has often focused on preventing exposure: finding sensitive data, classifying it, governing access, and reducing risk. That work still matters. In fact, it becomes more important as AI systems consume enterprise data through prompts, retrieval systems, training pipelines, analytics workflows, and automated decision support.
That’s because data may move into new contexts without moving into a new system of record. A sensitive dataset might support a retrieval workflow, shape a model response, or appear in a prompt log. That makes governance less about one location and more about how data is accessed, reused, and recovered across workflows.
But prevention alone is not enough for the next phase of cloud data security. If specialized cyber AI can help security teams discover vulnerabilities, test attack paths, and connect weak signals faster, then data security programs need to account for what happens after exposure is found or exploited. Visibility and access controls are only part of the picture. Teams also need a clear path to trusted recovery.
Uncovering that path requires more than better security tools. It requires a recovery operating model that aligns security, IT, and business leaders around shared recovery priorities before an incident occurs. Increasingly, organizations are describing this discipline as ResOps, or resilience operations: a structured approach to making recovery measurable, repeatable, and tied to business outcomes rather than backup success alone.
In ResOps, organizations must understand:
Which datasets are most critical to business operations?
Which identities, cloud services, and AI workflows depend on business-critical datasets?
Are governance and access policies aligned to business risk?
What is the minimum viable operating state the organization must restore first?
Can those recovery decisions be validated before an incident instead of during one?
That’s the shift Mythos and GPT-5.5-Cyber point toward. The future of cloud data security won’t be defined by prevention alone. As cyber AI compresses the time between discovery and action, organizations will need equal confidence in how they recover. That means understanding cloud dependencies before an incident, defining the minimum viable business they need to restore, and treating recovery as an operational discipline rather than a technical afterthought.
Mythos and GPT-5.5-Cyber matter not because every organization will use these models tomorrow, but because they reveal where cybersecurity is heading. As AI accelerates both defense and attack, the organizations that perform best won’t simply be the ones with the strongest preventive controls. They’ll be the ones that can prove they know what to recover, in what order, and how to restore trusted operations before uncertainty becomes business disruption.
Frequently Asked Questions
When will these specialized models become public?
There’s no confirmed timeline for broad public access. Current reporting indicates Claude Mythos is being limited to select organizations through controlled programs, while OpenAI describes GPT-5.5-Cyber as available only to vetted defenders through its Trusted Access for Cyber framework.
Are AI attacks likely to increase?
Not necessarily. But they do show that advanced AI can support more complex cyber workflows, which means organizations should prepare for faster discovery, testing, and exploitation cycles.
Which risks should teams prioritize first?
Start with visibility into sensitive data, access paths, cloud misconfigurations, identity dependencies, and recovery readiness. Commvault’s Data & AI Security capabilities can help teams classify data, govern access, and identify risks across cloud environments.
Why does recovery matter for cloud data security?
Because prevention can fail. Commvault cyber resilience capabilities can help organizations identify clean recovery points, validate recovery in isolated environments, and restore data and critical services without reintroducing compromised assets.
Does Commvault offer AI-supported threat detection?
Yes. Commvault can use AI-enabled capabilities to help identify threats, detect anomalous activity, prioritize risk, and accelerate incident response. Combined with cyber resilience and recovery workflows, we can help teams improve response workflows and recover critical data with greater confidence.
At Commvault, we talk a lot about cyber resilience, the ability to recover from whatever challenges come your way. But for one engineer at Australian technology services provider Perfekt, it is his personal resilience that helps him succeed.
Viktor Trokhin left Ukraine when the war began, traveling through five countries before eventually reuniting with his family in Australia. He brought more than six years of ICT experience, deep technical expertise, and a determination to continue his career in tech.
Like many skilled professionals starting over in a new country, Viktor wasn’t just adapting to a new workplace. He was building expertise in new technologies, communicating in a second language, and finding his place in a different professional environment.
Marcus Rolim, Managed Services General Manager at Perfekt and Viktor’s manager, saw his potential immediately.
“Our engineering development program is built around people,” Marcus says. “We invest heavily in mentoring and creating opportunities for engineers from different backgrounds.”
Over the years, Perfekt has welcomed engineers from around 10 different countries. Rather than following a standard training path, the company focuses on each person’s strengths, providing mentoring, practical experience, and support where it’s needed most.
For Viktor, that meant building on his existing expertise while gaining experience with Commvault Cloud and cyber resilience.
As he worked with customers, Arlie – the AI assistant in Commvault Cloud – became a natural part of his daily workflow. Whether he was exploring product capabilities, troubleshooting an issue, or looking for guidance, Arlie helped him quickly find trusted information without interrupting his work.
Then came an unexpected benefit.
Because Arlie supports multiple languages, Viktor could work through complex concepts in his native language before switching to English when speaking with customers or colleagues. While this wasn’t the use case Perfekt originally envisioned, it quickly became a valuable learning advantage.
“When an engineer can explore a complex question in their own language, understand the reasoning behind the answer, and then communicate it clearly in English, it changes the learning experience,” Marcus says. “It allows their technical ability to come through without language becoming a barrier.”
Today, Viktor is an Infrastructure & Data Protection Engineer at Perfekt, supporting customers while continuing to deepen his expertise in cyber resilience.
When Viktor left Ukraine, he carried with him years of experience, deep technical expertise, and an unwavering determination to continue the career he had worked so hard to build. Today, he helps organizations strengthen their cyber resilience, drawing on the same resilience that helped him rebuild his own life.
Maybe that’s why this story resonates. Viktor’s resilience shaped his own future. Today, it helps him make a difference for others.
That’s what putting people first looks like: organizations like Perfekt investing in people, and technology like Commvault Cloud helping them thrive.
Chris DiRado is Principal, Product Experience, at Commvault.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Data is the life force of modern businesses, helping guide key decisions and power AI initiatives. Given its value, knowing and protecting your data is essential.
90% of organizationshave exposed sensitive cloud data that can be surfaced by AI. This makes visibility into data assets the first and most critical step in reducing enterprise risk.
40% of filesuploaded into shared with generative AI tools contains Personal Identifying Information (PII) or Payment Card Industry (PCI) data. Such misuse of sensitive data causes significant risk for organizations when it comes to privacy and regulatory violations.
Data discovery and classification form the foundation of effective security, helping enable organizations to identify sensitive data across structured, semi-structured, and unstructured environments.
Overpermissive access is one of the most persistent data risks for modern businesses. With users, applications, and service accounts often retaining unnecessary access to sensitive data, the “attack surface” is expanded.
Helping protect AI requires governing both training data and runtime interactions. Organizations need to verify that sensitive data is not exposed through inputs, outputs, or model behavior.
Regulatory compliance depends on strong data foundations. Strong classification and access governance enables organizations to enforce policies and demonstrate control.
Sensitive data now moves across clouds, applications, and AI workflows without clear visibility — creating exposure risks that traditional security controls cannot address alone. Commvault Data and AI Security helps organizations discover and classify sensitive data, govern access for both human and machine identities, and maintain compliance with GDPR, HIPAA, and PCI DSS across the full data lifecycle.
Why is sensitive data exposure the biggest security gap?
Data is the invaluable fuel that propels modern businesses. So, organizations have made it a priority to heavily invest in sophisticated security tools.
However, according to Varonis’ 2025 State of Data Security Report, 90% of organizations still have exposed sensitive cloud data. Similarly, 88% of organizations have stale but enabled ghost users.
But that’s not all. According to IBM’sCost of a Data Breach Report 2025,53% of breached organizations reported compromised customer PII.These statistics paint a vivid image: though data is central to businesses, visibility and overall security remain critical issues.
Data is no longer confined to structured databases. It exists across files, emails, cloud platforms, SaaS applications, and endpoints. Much of it is unstructured, duplicated, or unmanaged, making it difficult to track and protect.
Without visibility into what data exists and where it resides, organizations cannot effectively secure it. This lack of visibility is the root of the modern data security problem.
What are the pillars of data and AI security?
To address the challenge of data exposure, organizations need a structured approach that brings consistency and control to how data is managed. Data and AI security is built on three core pillars: Data Discovery, Data Classification, and Data & AI Access Governance.
Each pillar addresses a prominent gap:
Discovery provides visibility into where data resides across environments. This includes structured systems such as databases, as well as semi-structured and unstructured sources that are often overlooked.
Classification adds context by identifying the type and sensitivity of data. It enables organizations to distinguish between operational data, sensitive personal information, financial records, intellectual property, and other high-risk categories.
Access governance enables organizations to verify that data is used appropriately. It defines who or what can access data, under what conditions, and with what level of control.
These three pillars do not exist independently. They create a connected system that fully covers data and AI security. Discovery identifies the complete data landscape, classification defines the appropriate sensitivity, and access governance enforces control based on that context.
This model even extends beyond human users to include machine identities such as AI models. In modern environments, these non-human identities often represent a significant portion of data access activity. Bringing these pillars together can help organizations move from fragmented security controls to a unified, policy-driven approach.
How can organizations discover and classify sensitive data?
Discovery and classification are foundational to a successful data security model. Yet, they are often the most difficult to implement effectively.
This is because modern data environments are highly fragmented. Sensitive information is spread across multiple cloud platforms, on-prem systems, SaaS applications, and endpoints. A significant portion of this data is unstructured, making it harder to identify and categorize.
Some of the most notable challenges include:
Shadow data that exists without knowledge, approval, or security oversight.
Inconsistent formats across structured and unstructured data.
Rapid data growth due to AI adoption that outpaces manual classification efforts.
To address this, organizations need scalable discovery capabilities and classification frameworks. Proper classification can assign meaning to the vast amounts of existing data. This typically includes categories such as PII, protected health information (PHI), PCI, intellectual property, and keys and secrets.
The value of classification comes from how it is used. Once data is classified, organizations can effectively apply retention and deletion policies, restrict or monitor access, and enable masking or redaction for sensitive fields.
At scale, a mature discovery and classification approach does not just fulfill coverage but also helps produce meaningful outcomes. This can include reduced exposure, improved policy enforcement, and measurable risk reduction.
What are the major risks of overpermissive access?
According to research by ReliaQuest, 99% of cloud identities are over-privileged. On a similar note, a 2025 study by the Ponemon Institute highlights that 61% of US firms have suffered from insider data breaches in the past two years, with the average cost of such incidents being a staggering $2.7 million.
This proves that even when organizations understand their data, access remains one of the weakest points in security.
Overpermissive access occurs when users, applications, or service accounts have more access to data than they need. This issue is widespread because access controls are often granted broadly for convenience and rarely revisited.
The impact is significant. Excessive access increases the likelihood of accidental exposure, insider risk, and exploitation during a breach.
To address this, organizations must first carefully inspect access patterns. This includes finding out who is accessing sensitive data, what systems or identities are involved, and whether that access aligns with business needs.
Particular attention must be given to privileged accounts and service identities. These often have extensive permissions and can access large volumes of sensitive data across systems.
In this landscape, effective access governance is key. This requires:
Aligning access policies with data classification.
Continuously monitoring usage patterns.
Identifying and remediating access drift over time.
By reducing unnecessary access, organizations help limit their attack surface and improve overall data protection.
How should organizations govern data used by AI systems?
The adoption of AI is rapidly spreading across every facet of modern businesses. This introduces a new layer of complexity in how data is accessed, processed, and exposed.
Training datasets often include large volumes of data sourced from across the organization. Without proper classification and governance, these datasets may contain sensitive or regulated information.
This creates risk at multiple stages:
During data preparation and training.
When models interact with live data.
Through outputs that may unintentionally expose sensitive information.
So, classification must precede model training. This means validating and classifying all data used in datasets and removing sensitive information when necessary.
Likewise, after deployment of AI tools, data teams must continuously assess how models use and expose data. They also should apply appropriate control mechanisms such as masking or redaction where needed.
AI systems should not be treated as separate from data security. They are an extension of how data is used and must be governed accordingly. By integrating such data and AI security capabilities into the broader AI development lifecycle, organizations can help reduce risk while still enabling innovation.
How does data classification power regulatory compliance?
Regulatory compliance depends on the ability to identify and control sensitive data. Frameworks such as GDPR, HIPAA, and PCI DSS define specific requirements for how data must be handled. However, these requirements cannot be enforced without first understanding where regulated data exists.
This is why compliance programs fail without a proper data foundation.
In such cases, data classification acts as the backbone for compliance, mapping data to regulatory categories. It allows organizations to apply targeted controls based on data sensitivity and enforce critical data lifecycle policies.
This opens up a myriad of essential capabilities:
Enforcement of retention and deletion policies
Restriction of access to regulated data
Implementation of crucial privacy controls
It also simplifies audit processes. Organizations can demonstrate where sensitive data resides, how it is protected, and who has access to it. Access governance further strengthens compliance by ensuring that only authorized identities can interact with regulated data.
Together, data classification and access controls reshape compliance for the modern, AI-enabled era.
Conclusion: What does effective data and AI security require today?
Modern data and AI security is no longer defined by perimeter defenses or isolated controls. It requires a continuous, unified approach that connects visibility, classification, and access governance across the entire data lifecycle.
To bring such an approach to life, organizations must first understand their data, finding exactly where it all resides. Then they must control how it is accessed. Finally, organizations must make certain that AI systems use it responsibly. These capabilities must work together, not independently, to help reduce exposure and maintain trust.
As data volumes grow and AI adoption accelerates, the challenge will not be securing data alone, but demonstrating where sensitive data exists, who can access it, and how it is protected across systems. Those that build a structured, policy-driven approach will be better positioned to help reduce risk, meet regulatory expectations, and enable innovation with confidence.
Frequently Asked Questions
What is data and AI security?
Data and AI security is the practice of discovering, classifying, and governing access to sensitive data across systems, users, and AI models. Commvault Data and AI Security delivers these capabilities across hybrid environments — enabling organizations to confirm that data remains visible, controlled, and protected throughout its lifecycle, including how it is used in AI training and outputs.
Why is sensitive data exposure a major risk?
Sensitive data exposure is a major risk because organizations often lack visibility into where data resides and who can access it, increasing the likelihood of breaches, misuse, and regulatory violations. Commvault helps mitigate this through a unified approach that combines Data Discovery, Classification, and Access Governance across hybrid environments.
What are the key pillars of data security?
The three core pillars of data security are discovery, classification, and access governance. Commvault delivers each — Data Discovery identifies where sensitive data exists across environments, Data Classification defines its sensitivity and type, and Data & AI Access Governance enforces access control aligned with business and regulatory policy.
Why is overpermissive access dangerous?
Overpermissive access allows users, applications, and service accounts to access more data than necessary — increasing risk of accidental exposure, insider threats, and exploitation. Commvault Data & AI Access Governance addresses this by continuously monitoring access patterns, aligning permissions with data classification, and identifying and remediating access drift across hybrid environments.
How should organizations help protect data used by AI?
Organizations can protect AI data by classifying datasets before training and continuously monitoring how models access and expose data. Commvault Data and AI Security supports this through discovery, classification, and governance controls including masking, redaction, and access restrictions — helping ensure that sensitive data is not exposed through AI training, model behaviour, or outputs.
How does data classification help support compliance?
Data classification supports compliance by identifying regulated data such as PII and mapping it to appropriate controls. Commvault Data Classification helps organisations enforce retention and deletion policies aligned with GDPR, HIPAA, and PCI DSS — and provides the audit-ready evidence needed to demonstrate how sensitive data is identified, protected, and governed.
Watch how Commvault Cloud delivers discovery, classification, and control over sensitive data – and helps remediate overpermissive sharing risks in real time.
Explore how AI introduces new data vulnerabilities – from model training to exposure to runtime risks – and the layered practices organizations use to govern workloads responsibly.
Replace subjective claims about “ease of use” with a measurable data protection gearing ratio: protected capacity divided by the number of full-time administrators.
Measuring protected capacity per FTE provides a more meaningful view of operational efficiency than legacy metrics such as backup jobs per administrator.
The data protection gearing ratio should be used as a baseline before a platform migration and measured again afterward to validate operational improvements.
Factors such as multi-cloud environments, cyber recovery requirements, and compliance obligations can influence the ratio, so it should be evaluated within the context of each environment.
Organizations should ask vendors to commit to measurable operational outcomes instead of relying on qualitative claims about simplicity.
Every vendor evaluation I have sat in eventually reaches the same dead end. One side says the platform is simple to run. The other side says their platform is simpler.
Nobody can prove either claim, so the conversation drifts to the demo, the reference call, the gut feeling in the room. That is not how you should be making a decision that determines how your team will spend the next five years.
I have run production data protection environments. I have watched teams get buried under fragmented tooling that promised automation and delivered tickets instead.
“Reduced complexity” is not a feeling you should have to take on faith. It is something you should be able to calculate.
The Metric the Industry Has Been Missing
We have started using a simple ratio internally and with customers: total protected capacity divided by the number of full-time staff required to run it. We call it the data protection gearing ratio.
Protected Capacity (PB) / FTEs = Data Protection Gearing Ratio
That’s it. No survey questions about satisfaction. No adjectives. A number, calculated from data you already have.
Here is why it matters more than the metrics it replaces. Calculating the number of backup jobs per person made sense a decade ago, when a job represented a discrete unit of manual effort. It does not reflect how modern platforms operate today, where automation absorbs the routine work and a single administrator can be accountable for petabytes, not job counts.
Measuring jobs per person in an automated environment tells you nothing about whether the automation is actually working.
What It Looks Like in Practice
One clarification before the number, because it trips people up. Protected capacity means the full, uncompressed, undeduplicated size of the applications being protected, not the physical disk behind them.
That distinction matters because it is the whole point. Commvault’s own production environment protects 42.39 PB of application data on 9.26 PB of physical disk, an 81.91% space savings from deduplication and compression.
The ratio is not just a measure of how many petabytes a person can watch over. It is a measure of how much architecture is doing the work before headcount ever enters the picture.
With that in mind: Commvault runs its own production backup environment on 42.39 PB of protected capacity with two FTEs. That is a gearing ratio of 21.20 PB per FTE. Industry benchmarks for modern platforms typically land between 5 and 25 PB per FTE, depending on environment complexity, so that number sits at the high end of what is achievable today.
Metric
Value
Definition
Protected Capacity (Front-End)
42.39 PB
Full, uncompressed, undeduplicated application size protected in our environment
Total Disk Capacity
9.26 PB
Physical target storage
Total Used Space
7.89 PB
Current utilization
Total Data Written
7.67 PB
Logical data written to disk
Space Savings
81.91%
Deduplication and compression efficiency
Data Protection FTEs
2
Number of full-time admins managing Commvault’s own production backup estate
Data Protection Gearing Ratio = 42.39 PB / 2 FTEs = 21.20 PB per FTE
I want to be direct about what this number does not do. It does not account for a multi-cloud footprint, cyber recovery requirements, or a compliance-heavy application mix, all of which will pull the ratio down for reasons that have nothing to do with how good the platform is.
A ratio in isolation is not a verdict. A ratio measured before and after a migration is.
That is the actual use case. Baseline your current environment on your current tools. Set a target ratio based on your growth projections and your team’s capacity. Then hold your vendor to it after the implementation is done, not just during the sales cycle.
The Board-Level Implication
If you are the one signing off on a platform migration, you are not just being asked to trust that a new platform is easier to run. You are being asked to fund a specific operational outcome. A data protection gearing ratio target gives you a way to write that outcome into the business case and check it 12 months later.
This is the same discipline we apply to mean time to clean recovery (MTCR). Recovery capability is not something you claim, it is something you measure and re-measure until the number tells you the truth. Operational efficiency deserves the same standard.
The Challenge
Ask your current vendor for the gearing ratio of your own environment today. If they cannot produce it, that tells you something about how well they understand what “simple to manage” means for your team.
And if you are evaluating a new platform, do not accept “easier to use” as an answer. Ask what ratio they will commit to, and ask again after year one.
FAQs
Q: What is the data protection gearing ratio?
A: The data protection gearing ratio measures the amount of protected data capacity managed by each full-time administrator. It provides an objective way to evaluate operational efficiency rather than relying on subjective impressions of platform usability.
Q: Why is this metric more useful than backup jobs per administrator?
A: Modern data protection platforms automate much of the routine work that previously required manual effort. As a result, counting backup jobs no longer reflects the true workload or efficiency of an operations team.
Q: What does “protected capacity” mean in this calculation?
A: Protected capacity refers to the full, uncompressed, and undeduplicated size of the application data being protected. This measurement reflects the actual workload managed by the platform rather than the physical storage consumed after optimization.
Q: Does a higher gearing ratio always indicate a better platform?
A: Not necessarily. Environmental complexity, including multi-cloud deployments, cyber resilience requirements, and regulatory obligations, can reduce the ratio even when the platform performs well. The metric is most valuable when comparing the same environment before and after a migration.
Q: How should organizations use the data protection gearing ratio during vendor evaluations?
A: Organizations should establish a baseline using their current environment, define a target ratio aligned with future growth, and ask vendors to commit to achieving measurable improvements after implementation. This approach shifts the conversation from marketing claims to verifiable business outcomes.
Q: What is the broader business value of this metric?
A: The data protection gearing ratio enables executives to quantify expected operational efficiency gains and include them in the business case for a platform investment. It also provides a benchmark that can be reviewed after deployment to confirm the promised results were achieved.
In the first episode of our STRIVE series on digital sovereignty, Commvault’s Alex Zinin and Osmium Data Group’s Max Mortillaro challenged one of the biggest misconceptions in the industry: Digital sovereignty isn’t a feature you buy – it’s a business problem you have to understand before you can solve.
This conversation picks up where that one left off. This time, I sat down with Thomas Maurer, EMEA Global Black Belt for Sovereign Cloud at Microsoft, to explore what happens after an organization decides sovereignty matters. How do executive teams move from broad concerns about regulation, jurisdiction, or geopolitical uncertainty into practical architectural decisions?
The answer, it turns out, is rarely as straightforward as choosing a cloud provider or selecting the right deployment model. It’s about asking better questions before making technical decisions.
Every organization defines digital sovereignty differently – and that’s exactly where the conversation should begin.
Sovereignty isn’t solved by technology alone. Legal, operational, architectural, and business considerations all shape the outcome.
Cloud and on-premises aren’t competing strategies. For many organizations, the future is a carefully designed combination of both.
Risk management – not fear – should drive sovereignty decisions.
Good architecture starts with understanding business requirements, not choosing infrastructure.
Sovereignty Means Different Things to Different Organizations
One of the first observations Thomas made was also one of the most important.
There is no universal definition for digital sovereignty. For one organization, it may simply mean meeting regulatory requirements or keeping data within a specific geography. For another, it may involve operational independence, business continuity, or preparing for geopolitical disruption. That difference matters because it changes the conversation entirely.
Too often, organizations assume there’s a standard sovereignty blueprint waiting to be implemented. In reality, the first challenge isn’t selecting technology – it’s understanding what problem the organization is actually trying to solve.
Only then does architecture begin to make sense.
Technology Should Follow Strategy
One theme that kept surfacing throughout our discussion was the temptation to jump straight into technical design.
It’s understandable. Architects naturally think about infrastructure, workloads, connectivity, and deployment models. But Thomas emphasized that the most successful projects begin somewhere else.
They begin by listening.
What concerns are driving the initiative? Is the objective regulatory compliance? Business continuity? Data residency? Operational control? Protection against geopolitical disruption?
Different answers lead to different architectures.
That may sound obvious, but it’s surprising how often organizations begin evaluating solutions before they’ve aligned on the business outcome they’re trying to achieve.
Sneak Peek: Start With Risk, Not Assumptions
One of the most practical moments in our conversation comes when Thomas and I discuss why sovereignty initiatives should begin with a risk assessment – not an architectural diagram.
Every organization has a different risk appetite. A Formula 1 team, a government agency, and a global manufacturer won’t make the same decisions, nor should they. The key is understanding which risks matter most to your business, what trade-offs you’re willing to make, and then designing an architecture that supports those decisions.
As Thomas points out, there is no perfect solution – only informed trade-offs. The earlier organizations adopt that mindset, the stronger their sovereignty strategy will be.
‘Cloud or On-Premises?’ Is the Wrong Question to Ask
One of the more interesting parts of the conversation challenged another common assumption – that organizations must choose between public cloud and private infrastructure.
Thomas described a very different reality.
Many organizations aren’t replacing one with the other. They’re designing environments where workloads can move between them based on business need, regulatory requirements, or resilience considerations.
That flexibility changes how we should think about architecture. Instead of asking whether cloud or on-premises is better, the more useful question becomes:
“Where does this workload belong today – and could that answer change tomorrow?”
When sovereignty becomes part of the design process, workload mobility becomes just as important as workload placement.
Architecture Is Only Part of the Equation
Another takeaway I appreciate is Thomas’s reminder that architecture alone doesn’t solve sovereignty.
Contracts matter.
Legal frameworks matter.
Operational processes matter.
The people responsible for running the environment matter.
None of those disciplines can operate in isolation. Sovereignty requires legal, security, compliance, and infrastructure teams to work together from the beginning – not hand projects off to one another after decisions have already been made.
That’s a familiar pattern for anyone working in cyber resilience. The strongest outcomes rarely come from individual teams. They come from coordinated ones.
Risk Should Drive Every Decision
Toward the end of our discussion, the conversation naturally shifted toward risk. For me, this is where sovereignty starts to feel much more familiar. Every resilience project begins by asking what the organization is trying to protect, what threats matter most, and how much risk it’s willing to accept.
Digital sovereignty is no different.
Rather than searching for a perfect solution, organizations need to identify the specific sovereignty scenarios they’re concerned about and then determine which architectural, operational, or contractual controls best address those risks.
That shift – from feature comparison to risk management – is what ultimately leads to better decisions.
Why This Conversation Matters
Digital sovereignty continues to evolve rapidly. New regulations will emerge. Technology will change. Geopolitical realities will continue to shift.
That means sovereignty isn’t something organizations solve once. It’s something they regularly evaluate as business priorities and external risks evolve.
The organizations that succeed won’t necessarily have the most restrictive architectures. They’ll have the clearest understanding of their business objectives, the discipline to assess risk thoughtfully, and the flexibility to adapt as those risks change.
Ultimately, digital sovereignty isn’t something organizations can buy off a shelf. It’s an exercise in understanding risk, managing dependencies, and making informed trade-offs long before those decisions are tested.
Watch the Full Episode
In this STRIVE episode, Thomas and I discuss:
Why sovereignty means different things to different organizations.
How executives should approach sovereignty strategy.
Public cloud versus private cloud – and why it’s often not an either/or decision.
Why risk management should guide architectural choices.
The role of resilience in modern sovereignty planning.
Terraform manages desired state – it provisions and configures infrastructure from code.
Cloud Rewind captures actual deployed state – it helps restore environments to a known-good point in time.
Terraform state files and Git history are not recovery tools; they do not capture what was actually running.
Cloud Rewind helps recover infrastructure whether changes were made via IaC, the console, or manual intervention.
Together, Terraform and Cloud Rewind help give teams a complete cloud operations strategy: Build fast, recover faster.
If your team runs Terraform, you already know how powerful IaC can be. You define what you want, apply it, and your cloud environment materializes. Change management becomes repeatable. Provisioning becomes predictable.
But there is a gap between provisioning infrastructure and recovering it – and it matters most when something goes wrong at 2 a.m.
Terraform and Cloud Rewind address different parts of the cloud lifecycle. Understanding the difference helps you avoid a dangerous assumption: that your IaC tooling doubles as a recovery plan.
How Terraform and Cloud Rewind Differ
Terraform is a provisioning tool. It defines and manages desired state. When you revert a Terraform change, you are re-applying a previous desired configuration – not restoring the actual deployed environment that was running before the incident.
That distinction matters. Terraform state is not a historical recovery snapshot.
Cloud Rewind captures actual cloud configuration state and stores point-in-time snapshots. When something breaks, you do not rebuild from code and hope the environment comes back intact. You restore a known-good environment – the one that was actually running – regardless of how the change that caused the problem was introduced.
Terraform Design
Cloud Rewind Design
Desired state management
Actual state recovery
Infrastructure provisioning
Infrastructure recovery
Applies changes
Rewinds changes
Source of truth = code
Source of truth = deployed environment
Forward-looking
Backward-looking
Build and update
Recover and rebuild
Helps recover desired configuration
Helps restore deployed state from a captured point in time
Where Terraform Reaches its Limit
Even the most mature IaC environments encounter recovery scenarios where rebuilding from code is not enough. Consider:
A failed infrastructure change already deployed to production.
Accidental deletion of cloud resources.
Infrastructure drift caused by manual or out-of-band changes.
Changes made outside Terraform that are not reflected in code or state.
A need to restore infrastructure to exactly where it was at a specific point in time.
Terraform does not maintain historical cloud state. It re-applies a desired configuration – it does not restore what was actually deployed and running. “Rewind to 2:15 PM yesterday” is not a Terraform feature. It is a Cloud Rewind feature.
Recovery that depends on Terraform code, state files, and version history being available, accurate, and complete is recovery that carries real risk. In a real incident, those conditions are not guaranteed.
Two Tools, One Complete Strategy
Terraform helps you automate infrastructure creation and change management. Cloud Rewind helps you recover infrastructure quickly and consistently when deployments fail, resources are deleted, infrastructure drifts, or your team needs to restore a known-good environment.
They complement each other. Terraform is designed to make your cloud environment repeatable. Cloud Rewind is designed to make it recoverable.
A: No. Terraform re-applies a desired configuration from code. It does not maintain historical snapshots of your deployed cloud environment. If the change that caused an incident is not captured in your Terraform state or Git history – for example, a console change or infrastructure drift – Terraform cannot help you restore it.
Q: What happens when changes are made outside Terraform?
A: Console changes, manual interventions, and out-of-band configurations are common in real environments. Terraform does not track them. Cloud Rewind captures actual deployed state – regardless of how a change was introduced – so you can restore a known-good environment even when your IaC does not reflect what was running.
Q: Is Cloud Rewind a replacement for Terraform?
A: No. They solve different problems. Terraform is your provisioning and change management tool. Cloud Rewind is your recovery tool. Most teams that use one can benefit from both – they cover different parts of the cloud operations lifecycle.
Q: What kinds of incidents does Cloud Rewind address?
A: Cloud Rewind is designed for scenarios where rebuilding from code is not enough: failed deployments already in production, accidental resource deletion, infrastructure drift, and cases where teams need to restore an environment to a specific historical point in time.
Q: Does Cloud Rewind require teams to stop using Terraform?
A: No. Cloud Rewind works alongside your existing IaC workflows. Teams continue to use Terraform for provisioning and change management and use Cloud Rewind when they need to recover from a real incident.
Cailin Pitcher is Senior Portfolio Marketing Manager at Commvault.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Commvault integrates frontier AI vulnerability discovery into its risk-based security program rather than relying on AI as a standalone solution.
Every AI-generated finding is reviewed and validated by humans before remediation decisions are made.
Frontier AI complements established security practices such as static analysis, dynamic analysis, and penetration testing by expanding code coverage and identifying more complex exploit scenarios.
Commvault maintains strict governance over source code, vendor access, and vulnerability handling.
Commvault is investing in scalable vulnerability management processes in order to respond efficiently as AI increases the volume of potential security findings.
Across the security industry, AI and large language models are being applied to vulnerability discovery – helping teams evaluate more code, explore more attack paths, and identify exploitable conditions faster than manual review alone.
This is not a niche experiment. It is a shift in how thorough a security evaluation can be, and it is changing what customers reasonably expect from their software vendors.
Customers are regularly asking their software vendors: Do you test your own products against the same methods a threat actor might use? Are the processes behind that testing rigorous enough to keep pace? These are the right questions to ask.
Our Approach: Strong Processes, no Single Tool
Commvault’s security posture is built on strong, repeatable processes rather than dependence on any single tool, model, or vendor.
Vulnerability management follows an established, risk-based framework: Findings are assessed for practical exploitability, prioritized by severity and exposure, and remediated through our standard development lifecycle. That framework applies the same way regardless of whether a finding comes from a penetration test, an external researcher, or AI.
AI vulnerability discovery is integrated into this framework as an additional capability, not a separate program running on its own rules. Candidate findings generated through AI methods are treated as inputs that require human confirmation of exploitability before any remediation action is taken. That step helps prevent two failure modes at once: under-prioritizing genuine risk and burning cycles on false positives.
AI Alongside Established Security Practices
AI methods do not replace the disciplines that have always defined responsible vulnerability management. Static analysis, dynamic analysis, penetration testing, and established scanning tools remain essential parts of our program.
What AI adds is coverage depth: the ability to evaluate a broader set of code paths, model more complex exploit conditions, and surface findings that require contextual understanding rather than simple pattern matching.
Our vulnerability program is tool-agnostic and model-agnostic by design. We are not dependent on any single vendor or model, and new approaches can be added as they prove out, without re-architecting how findings are governed or remediated. The advantage isn’t which model we use but whether the process behind it is disciplined enough to act on what that model finds.
Governance and Controls
Every AI scan we run operates under the same governance principles:
AI models are vetted before used. Any vendor and tooling access is governed by formal NDA and engagement terms.
Findings are processed through the same security engineering review pipeline used for every other vulnerability source.
No AI-generated finding is acted upon without human triage and exploitability confirmation.
From Candidate Finding to Confirmed Fix
Findings generated through AI are treated as candidates, not confirmed vulnerabilities. Each one is assessed by engineers and product security experts for practical exploitability in realistic customer environments.
Severity ratings are assigned based on exposure, exploitability, and impact – not on how the finding was discovered. Confirmed vulnerabilities move through the same remediation timelines and escalation paths as any other source, with priority set by severity and exposure.
First Patch Tuesday Disclosures – August 2026
Our inaugural Patch Tuesday, published August 11, 2026, includes the following disclosures:
Why Operational Readiness Matters More Than Any Single Tool
As AI vulnerability discovery becomes standard practice across the industry, the volume of potential findings that security teams need to evaluate will keep rising. The question that matters for any enterprise software vendor isn’t which AI model they use. It’s whether their vulnerability management process is mature enough, and scalable enough, to handle that throughput without creating a backlog that increases customer exposure.
We pair our investment in AI with an equal investment in the process infrastructure needed to act on what it finds: triage capacity, severity prioritization, remediation tracking, and coordinated disclosure practices. Our investment is only as valuable as the response capability behind it.
FAQs
Q: What is Commvault doing with frontier AI security testing?
A: We actively evaluate our products using AI methods as part of our structured security engineering program. We are being thoughtful about testing different models and harnesses so that we find any potential vulnerabilities previously undiscovered by humans and or existing testing. That work follows the same vulnerability management process as every other form of testing. This is underway today – it isn’t a roadmap item.
Q: How is Commvault preparing for AI vulnerability discovery?
A: We built a program that is model-agnostic and tool-agnostic by design. Our goal is to make sure our security engineering practice can incorporate the best available methods across a range of AI tooling, inside one consistent governance and risk management framework.
Q: Is Commvault using these models safely?
A: Yes. All AI scans are thoroughly vetted. Any vendor and tool access is governed by formal NDA and engagement terms, and every AI-generated finding requires human confirmation of exploitability before any remediation action is taken.
Q: How is Commvault scaling vulnerability management for the AI era?
A: Our focus is on making sure the response process scales with discovery volume and discovery pace. As AI increases the number of potential findings our teams need to review, we’re investing in risk-based triage, consistent remediation service level agreements, and the operational infrastructure needed to act on higher discovery throughput within accelerated timeframes to decrease exposure for customers.
When frontier AI models started making headlines, most of the discussion centered on one question: What happens when attackers gain access to them?
It’s a fair question.
Models capable of discovering vulnerabilities faster, chaining exploits together, and operating at unprecedented speed naturally raise concerns for every CISO.
But after spending time talking with customers over the past several months – and in my conversation with Tim Zonca, Commvault’s VP of Portfolio Marketing, in this episode of STRIVE – I think there’s an even more important question emerging.
What happens to resilience itself?
Because while frontier AI will undoubtedly accelerate cyber threats, it’s also accelerating something else: Enterprise complexity.
Frontier AI isn’t just accelerating cyberattacks – it’s accelerating enterprise complexity.
Vulnerability management isn’t disappearing, but the speed and scale of discovery are changing dramatically.
AI systems introduce entirely new recovery dependencies, including agents, vector databases, embeddings, and distributed state.
Organizations need a coherent understanding of their environments before they can recover them.
The next generation of resilience will depend on trusted systems of record that explain what happened, why it happened, and how to recover confidently.
The Conversation Has Changed
One thing Tim and I discuss early in the episode is how differently organizations are reacting to frontier AI.
Some see an entirely new class of cybersecurity challenge.
Others view it as simply the next evolution of vulnerability management.
What’s interesting is that neither perspective is necessarily wrong.
The processes organizations use to identify, prioritize, and remediate vulnerabilities remain familiar. But the pace at which AI can discover those vulnerabilities – and uncover entirely new chains of attack – is unlike anything we’ve seen before.
That’s the shift.
The work isn’t fundamentally different. The speed is.
When AI Changes the Shape of Recovery
Most conversations about AI focus on security and prevention:
How do we secure models?
How do we protect prompts?
How do we defend against AI-assisted attacks?
Those are important questions. But resilience introduces a different one: What exactly are we recovering?
Traditional enterprise applications already involve complicated relationships between infrastructure, applications, and data. AI expands that picture considerably. Now there are agents operating across multiple systems. Vector databases. Embeddings. Models interacting with different data sources simultaneously. It’s become far more than a traditional application stack.
Recovery is no longer about restoring an application. It’s about restoring an ecosystem.
Sneak Peek: Check This Out
In this moment from our STRIVE discussion, Tim and I discuss the growing complexity of AI stacks, what coherent recovery is (and why it matters), and how Commvault is helping our customers with full AI-stack recovery.
Why Coherency Matters
One idea that keeps surfacing throughout our conversation is coherence.
For years, organizations have worked to map application dependencies, understand infrastructure relationships, and identify critical services. AI makes that challenge significantly more difficult.
Applications no longer interact with a single database or service. They may depend on multiple models, agents, data stores, and orchestration layers – all changing dynamically.
Understanding those relationships isn’t just an architectural exercise anymore.
It’s a recovery requirement.
Because if you don’t understand what makes up the system, it’s difficult to know whether you’ve actually recovered it.
A New System of Record
Another concept from Tim that I found compelling is the idea of a system of record for the AI era. Historically, systems of record gave organizations confidence in business data. Customer records lived in CRM platforms. Financial records lived in ERP systems.
AI changes that expectation.
Organizations increasingly need trusted visibility into how data is used, what agents interact with it, why decisions are made, and whether restored environments represent a known-good state.
That doesn’t replace resilience. It strengthens it. Because confidence in recovery depends on confidence in what you’re recovering.
AI Can Also Help Solve the Problem
As organizations struggle to understand increasingly distributed environments, AI becomes a powerful tool for discovery, classification, and policy recommendation.
Rather than manually identifying relationships across sprawling environments, organizations can use AI to help identify dependencies, recommend protection policies, and continuously update those relationships as environments evolve.
That’s an important shift.
The same technology that’s adding to organizational complexity may also become one of the best tools for managing it.
Why This Conversation Matters
Frontier AI isn’t simply introducing another cybersecurity challenge. It’s forcing organizations to rethink resilience itself.
Recovery is becoming less about individual systems and more about restoring trusted business operations across increasingly intelligent environments. That means resilience strategies must evolve alongside the technologies they’re protecting.
Organizations that prepare for that shift won’t just recover faster. They’ll recover with greater confidence.
Watch the Full Episode
In this conversation, Tim and I explore:
How frontier AI is changing enterprise risk.
Why vulnerability management is entering a new phase.
What AI means for modern recovery architectures.
The role of coherent recovery across AI-enabled environments.
Why trusted systems of record will become increasingly important.
A: Frontier AI models are the latest generation of highly capable AI systems designed to solve increasingly complex reasoning and cybersecurity tasks.
Q: Why are organizations concerned about them?
A: They dramatically accelerate vulnerability discovery, exploit chaining, and security research, increasing both defensive and offensive capabilities.
Q: How does AI change cyber resilience?
A: AI introduces new dependencies – including agents, models, vector databases, and distributed states – that make recovery more complex.
Q: What is a coherent recovery strategy?
A: It’s an approach that restores not only data, but also the applications, infrastructure, dependencies, and AI components required for trusted business operations.
Q: What is a system of record in the AI era?
A: It’s a trusted source that helps organizations understand what happened, why it happened, and whether recovered systems represent a known-good state.
Q: What should organizations do now?
A: Begin mapping AI dependencies, understand how AI changes recovery requirements, and develop resilience strategies that account for increasingly intelligent application environments.
Chris Mierzwa is Senior Director of Portfolio Marketing at Commvault.
More related posts
Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
How to Unify Data Protection Across Every Hybrid Workload
Commvault® Cloud helps organizations discover, govern, and unify workload protection, allowing teams to rebuild critical services quickly after a cyber incident.
Hidden gaps in data protection strategies rarely reveal themselves – organizations often only discover them when a restore fails under pressure. Unified protection across every workload can help change that.
Fragmented backup strategies – separate tools for cloud databases, Kubernetes, SaaS, and on-premises systems – create inconsistent governance and coverage gaps across environments. Commvault Cloud provides unified visibility across every workload, helping teams identify risks before a recovery is put to the test.
Ransomware attacks surged126% year-over-year in Q1 2025, reaching an average of 1,925 weekly attacks –making verified, immutable backup copies a critical business requirement for organizations that need to demonstrate recoverability to auditors, boards, and regulators.
As regulations including GDPR, HIPAA, and DORA require organizations to demonstrate data recoverability within strict timeframes, protection gaps are no longer just an operational risk – they can be a compliance liability. Commvault Cloud helps organizations maintain audit-ready recoverability across hybrid and multi-cloud environments.
A unified data protection platform under a single control plane can help reduce manual overhead, enforce consistent policies, and give teams real-time visibility into protected status and costs – across cloud-native, on-premises, and edge workloads – without requiring separate management consoles per environment.
Commvault Cloud enables unified protection across the broadest range of workloads – cloud databases, Kubernetes, hypervisors, SaaS, and on-premises systems – from a single AI-enabled platform that supports rapid, clean recovery and can help organizations meet their RTO and RPO requirements.
Commvault Cleanroom Recovery is designed to help teams validate data integrity in an isolated environment before restoring to production – reducing the risk of reinfection during recovery. Pre-built orchestration workflows in Commvault Command Center help automate recovery sequencing, supporting faster and more controlled restoration of dependent services.
You’re the VP of IT Operations. It’s 2:00 a.m. on a Saturday. Your SecOps team just confirmed ransomware has encrypted files across three regions. Your last backup job completed successfully – but when your team attempts to restore the ERP system, the application fails to start.
The backup was marked successful. The data was present. But the dependencies, transaction logs, and service relationships were never captured in a consistent, recoverable state. Recovery isn’t just about data – it’s about rebuilding services.
This scenario plays out across hybrid environments every day. Modern enterprises run on interconnected cloud-native services, Kubernetes clusters, hybrid databases, and SaaS platforms – none of which recover cleanly from a simple file restore. Fragmented protection strategies designed for a simpler era leave organizations exposed at exactly the moment resilience matters most.
Commvault Cloudis an AI-enabled platform designed to help organizations discover, govern, and unify data protection across cloud-native, hybrid, and on-premises workloads – from a single control plane. Capabilities such as AI-enabled workload discovery, Cleanroom Recovery, Cleanpoint Identification, Threat Scan, and Command Center orchestration help teams validate recovery readiness and rebuild critical services in a controlled sequence after a cyber incident.
What Is Unified Data Protection – and Why Does It Matter?
Unified data protection is a backup and recovery approach that helps organizations govern the broadest range of workloads – including cloud databases, Kubernetes, SaaS, hypervisors, and on-premises systems – from a single control plane, rather than managing separate tools and policies for each environment.Commvault Cloud Unity is designed to support this approach, helping teams reduce operational complexity and maintain consistent protection across hybrid and multi-cloud environments.
Fragmented data protection strategies can create invisible gaps: inconsistent policies across environments, coverage blind spots that surface only during recovery, and manual overhead that scales poorly as workloads diversify. When ransomware strikes or an outage occurs, teams may discover too late that critical workloads were not protected consistently. A unified approach is designed to help address this by bringing all workloads under a centralized policy engine – so protection status, retention schedules, and recovery workflows are governed from one place.
Commvault Cloud workload coverage: Unified protection across cloud databases (AWS RDS, Azure SQL, SAP HANA, Oracle), hypervisors (VMware, Hyper-V), Kubernetes (AKS, EKS, GKE), SaaS (Microsoft 365, Salesforce, Google Workspace), and on-premises infrastructure.
Unified control plane: All workloads managed from a single AI-enabled Command Center –helping reduce fragmented policy sets and manual operational overhead.
AI-enabled discovery and tagging: Automated workload inventory and classification can help teams identify coverage gaps and bring unprotected resources under policy.
TCO analysis: Real-time visibility into protected status and cost drivers can support budget governance across cloud, hybrid, and on-premises environments.
How Does Commvault Cloud Help You Discover and Govern Workload Protection?
Effective data protection depends on knowing what you have before an incident occurs – not discovering gaps during recovery. Commvault Cloud is designed to help organizations continuously discover, classify, and apply backup policies across hybrid and multi-cloud assets, so coverage stays current as environments change.
Commvault Cloud begins with AI-enabled discovery –automatically inventorying cloud-native and hybrid assets, identifying resources without policy coverage, and bringing workloads under centralized governance in Command Center. Policies can be applied consistently across accounts, regions, and clouds, with real-time visibility into protected status and cost. Because environments change continuously – new workloads deployed, configurations updated, cloud resources spun up – discovery is designed to run as an ongoing process rather than a one-time assessment, helping teams maintain accurate coverage without manual audits.
AI-enabled discovery: Continuously inventories cloud-native and hybrid assets, identifies coverage gaps, and brings new workloads under centralized policies.
Centralized policy engine: Command Center applies consistent retention schedules, backup frequency, and copy policies across multi-cloud, hybrid, and on-premises workloads from a single interface.
Commvault Threat Scan: Continuously monitors backup data for anomalies, encryption activity, and malware indicators so security teams can act before recovery begins.
Cross-region and cross-cloud copies: Backup copies can be created across regions and cloud providers to support compliance, data residency requirements, and resilience posture.
Why Do Fragmented Tools Fail at Recovery Time?
89% of organizations operate in environments environments with more than one cloud, including hybrid cloud and multi-cloud set ups, yet most recovery failures don’t stem from a lack of backup jobs – they stem from protection that wasn’t built for the environment being recovered. Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.
Recovery failures surface the gap between a backup that ran and a service that actually restarts. Crash-consistent snapshots may restore raw data while leaving transaction logs, service dependencies, and cluster configurations in an inconsistent state – meaning the application cannot start even when the data is present. Unified data protection can help address this by ensuring workloads are protected in a way that reflects how they operate, and by validating recovery readiness before an incident forces the question.
Commvault Cloud supports security leaders who require audit-ready recoverability, IT teams managing hybrid and multi-cloud environments, and cloud and compliance stakeholders responsible for protecting and validating critical workloads. Commvault was recognized in the IDC MarketScape: Worldwide Cyber-Recovery 2025 Vendor Assessment for strengths in cyber recovery architecture, security ecosystem integration, and workload breadth.
Continuous backup monitoring: Threat Scan monitors backup data for malware indicators, encryption activity, and anomalous behavior –with alerts integrated into SIEM and SOC tools for coordinated incident response.
Commvault Cleanroom Recovery: Designed to stage restoration in an isolated environment so teams can validate data integrity and confirm systems are threat-free before returning to production – reducing reinfection risk.
Cleanpoint Identification: Designed to help pinpoint when data may have become compromised, providing more precise selection of a verified recovery point and supporting minimization of data loss.
Orchestrated service recovery: Command Center workflows can restore dependent services in sequence – helping reduce the manual coordination burden during high-pressure recovery events.
Scalable on-premises protection: HyperScale supports on-premises protection for hybrid environments, with streamlined onboarding and management through Command Center.
Microsoft Azure (Cloud)
Discovery, classification, and application-aware backup across Azure SQL, Azure VMs, Azure Blob, and Azure-hosted workloads.
Microsoft Entra ID (Identity)
Identity-based access governance integration – connects classification-based controls to Entra ID-managed users and AI service principals for policy enforcement.
AWS (Cloud)
Application-aware protection across AWS-hosted workloads including RDS, EC2, and EKS – via native API integrations.
Okta (Identity)
Identity-based access policy integration –connects Commvault access governance to Okta-managed identities for role-based enforcement.
Google Cloud (Cloud)
Discovery and application-aware backup across Google Cloud Storage, GKE (Google Kubernetes Engine), and connected workloads.
ServiceNow (ITSM)
Integration for incident and audit workflows – connects Commvault threat scan events and recovery actions to ServiceNow ticketing for compliance reporting.
How It Works
Discover and protect
AI-enabled discovery inventories cloud-native, hybrid, and on-premises assets to identify unprotected workloads. Command Center applies centralized policies – including backup frequency and retention – across environments, with cross-region and cross-cloud copies to support resilience and compliance.
Monitor and detect
Threat Scan monitors backup data for anomalies, encryption activity, and malware indicators. Alerts integrate with SIEM and SOC tools, helping teams isolate affected data and plan a response before recovery begins.
Validate and recover
Cleanpoint Identification helps pinpoint when data may have been compromised and surfaces viable recovery points. Cleanroom Recovery stages restoration in an isolated environment for validation before production restore, while Command Center orchestrates service recovery in the correct sequence to support controlled, reinfection-resistant recovery.
Before unified data protection, the most dangerous moment in incident response was often the restore itself – when teams discovered coverage gaps they didn’t know existed. With Commvault Cloud, teams can move from reactive gap discovery to proactive governance: understanding which workloads are protected, at what policy level, and whether recovery points have been validated. That shift – from hoping a backup worked to demonstrating that it can – can make the difference between a measured recovery and an extended outage.
Ready to Unify Protection Across Every Hybrid Workload?
See how Commvault Cloud can help your team discover, govern, and recover every workload cleanly.
Unified data protection is an approach to managing backup and recovery across cloud-native, multi-cloud, and on-premises workloads from a single control plane. Commvault Cloud supports this by applying consistent policies and coverage across environments – helping teams reduce operational complexity and maintain visibility into protection status.
Why do fragmented backup strategies fail at recovery time?
Fragmented backup strategies can create inconsistent policies, hidden coverage gaps, and manual overhead that scales poorly across hybrid environments.
Commvault® Cloud addresses this with a unified control plane, centralized policies, and AI-enabled discovery – helping organizations identify and close gaps before they impact recovery.
How does Commvault Cloud support data protection for hybrid workloads?
Commvault Cloud delivers unified data protection across cloud, SaaS, Kubernetes, and on-premises environments through a single AI-enabled platform. The Command Center, AI-enabled discovery, and Cleanroom Recovery work together to centralize policies, identify coverage gaps, and help validate data before production restoration –supporting a more controlled recovery process.
What is Cleanroom Recovery and how does it work?
Cleanroom Recovery delivers an isolated environment to safely restore and validate data before production use. By combining threat scanning with application-level validation, it helps your team reduce reinfection risk and recover with greater control after a cyber incident.
How does unified data protection support RTO and RPO requirements?
Commvault Cloud helps align data protection with business priorities and supports RTO and RPO objectives. Orchestrated recovery workflows in Command Center and Cleanpoint Identification, combined with a unified control plane, help reduce downtime, improve consistency, and enable teams to monitor protection status and address gaps proactively.
What integrations does Commvault Cloud support for threat response?
Commvault Cloud integrates natively with Microsoft Azure, Entra ID, AWS, Google Cloud, Okta, and ServiceNow. Threat Scan signals are routed to SIEM and SOC tooling, and recovery actions connect to ITSM platforms like ServiceNow for incident tracking and audit reporting.
Related resources
Solution Page
Unified Data Protection for the Modern Enterprise
Explore how Commvault Cloud is purpose-built for unified cyber resilience across cloud-native, hybrid, and on-premises environments.