Skip to content

Cyber resilience is more than just a buzzword – it’s a critical component of business strategy. So says Rosa Kariger, a leading expert in cybersecurity, who recently joined Commvault President and CEO Sanjay Mirchandani on the Resilience Uncompromised podcast. Rosa reflects on her experience as CISO at Iberdrola and in cybersecurity at the World Economic Forum and shares valuable insights on how organizations can build a culture of cyber resilience.

Understanding Cyber Resilience as an Operational Risk

Cyber resilience isn’t just about having robust disaster recovery and backup systems. It’s about enabling your business to continue to function and provide essential services even when your IT infrastructure is compromised. Rosa emphasizes that cyber resilience should be integrated into your overall risk management strategy. This means treating cybersecurity as a strategic business enabler, not just a technical challenge.

The Importance of Preparedness

Preparedness is a cornerstone of cyber resilience. Rosa stresses the need for scenario planning, particularly for situations where you might lose complete connectivity. Having a Plan B in place for critical business functions is essential. This allows your organization to maintain operations and continue to serve your customers during a cyber incident.

Clear Responsibilities and Accountability

Building a culture of cyber resilience requires clear responsibilities and accountability. Rosa points out that every employee, especially those deploying technology, should be held accountable for the cybersecurity of their processes. Cybersecurity should not be the sole responsibility of the CISO or IT teams. Instead, it should be a shared responsibility across the organization.

Technical professionals should be incentivized to uphold cybersecurity, as they are responsible for the quality, efficiency, and cost of the technology they work on. This approach integrates cybersecurity into the core of business operations and makes sure it is not treated as an afterthought.

The Role of the Cybersecurity Function

The cybersecurity function should act as a consultant and second line of defense. This means providing guidance and intelligence to the organization while specific cybersecurity responsibilities are embedded within technical and operational teams. By doing so, the cybersecurity function can offer strategic insights and support, helping to create a more resilient and secure organization.

Practical Steps for Building Cyber Resilience

Building a culture of cyber resilience is not just about implementing advanced security technologies; it’s about fostering a mindset where every employee understands and takes responsibility for cybersecurity. Here are some practical steps and real-world examples to help organizations achieve this:

  1. Integrate cyber risk into overall risk management: This means that risks associated with technology use are identified, accepted, and managed at all levels. By doing so, employees are better prepared to handle cyber incidents, maintaining continuous business continuity even when technology fails.
  2. Increase preparedness: Conduct regular scenarios of complete loss of connectivity or other major disruptions. This helps in increasing the organization’s tolerance to failure. For example, a financial institution might simulate a scenario where all digital transactions are halted, and employees must rely on manual processes to continue operations.
  3. Define clear roles and responsibilities: Confirm that every team, including technical and operational roles, has clear cybersecurity responsibilities. This distributed accountability makes everyone incentivized to maintain security. For instance, in an industrial setting, an engineer working on the digitalization of a process should be accountable for the cybersecurity of that process, not just the CISO.
  4. Provide proper training: Training is crucial to enable employees to manage cybersecurity risks effectively. Technical professionals should be trained to understand and mitigate cybersecurity risks in their specific roles. This verifies that they are knowledgeable and capable of implementing necessary safeguards.
  5. Implement a “sustain” strategy: Develop a Plan B to maintain continuous business during IT infrastructure disruptions. This could involve having backup systems, manual processes, or alternative communication channels. For example, a healthcare provider might have a plan to use paper records and manual check-ins if their electronic health records system goes down.

By following these steps, organizations can build a robust culture of cyber resilience. This approach helps prepare everyone to handle cyber incidents, maintain continuous business, and protect sensitive information.

Cyber resilience is a journey, not a destination. By integrating cybersecurity into your risk management practices, fostering a culture of accountability, and maintaining a well-prepared and informed workforce, you can help create a resilient organization that is ready to face any challenge. Stay proactive, stay informed, and stay resilient.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Jane Frankland, a cybersecurity veteran and advocate for women in tech, recently joined Darren Thomson on the STRIVE podcast to discuss the critical gap between IT and security teams. With over 28 years of experience in the field, Jane brings a unique perspective, blending her background in art and design with her deep expertise in cybersecurity. Her insights are not only informative but also offer practical solutions for organizations looking to enhance their security posture.

The Gap Between IT and Security

Jane and Darren delve into the longstanding issue of the gap between IT and security teams. While both the CIO and the CISO aim to support the business, their objectives often conflict. The CIO is focused on innovation and digital transformation, driving the organization forward with new technologies and processes. On the other hand, the CISO is tasked with reducing risk and upholding compliance, which can sometimes be seen as a hindrance to the CIO’s goals.

This conflict can lead to the CISO being perceived as a disabler, rather than an enabler. Jane shares that this gap has existed for many years and is getting worse. She notes that CISOs are sometimes removed by CIOs because, in performing the duties of their job, they slow down the CIO’s mission. This highlights the need for better alignment and collaboration between these roles.

Bridging the Gap

Jane suggests several strategies to help these roles work better together:

  1. Collaborative projects: Involve both the CIO and CISO in initiatives, such as cyber recovery planning and system patching, from the start. This enables security to be integrated into the project from the beginning, rather than being an afterthought.
  2. Aligned incentives and KPIs: When both teams work toward the same goals, it encourages collaboration and fosters a more cohesive and effective approach to security.
  3. Understanding the business: CISOs need to understand the business and build relationships with other stakeholders. This helps them serve the business better and avoid being seen as a disabler. Jane emphasizes the importance of CISOs being able to communicate the value of security to non-technical stakeholders.
  4. Defining risk tolerance: Organizations should define their risk tolerance at the board level. This provides a clear framework for both the CIO and CISO to work within, and keeps innovation and security are aligned.

Cultural and Organizational Challenges

Jane also shares several anecdotes that highlight the cultural and organizational challenges in cybersecurity. She mentions that the gap between the IT infrastructure team and the security team has been a long-standing issue. The opposing objectives of the CIO and CISO can create a toxic environment where security is seen as a barrier to progress.

To address these challenges, Jane advocates for a cultural change. This involves embedding security into the organization, rather than relying solely on technology. She emphasizes the importance of leadership alignment and the need for the CIO and CISO to be on the same page at the board level.

Jane’s Impact and Advocacy

Jane’s extensive experience and unique background make her a valuable voice in the cybersecurity community. She is a brand ambassador and has been recognized on the King’s New Year’s Honours List for her contributions to the field. Her IN Security Scholarships have helped 442 women, significantly increasing cyber literacy and inclusion.

Her commitment to advocating for diverse perspectives, and especially supporting women, is evident in her work. Jane encourages non-security professionals to engage with security teams and increase their cyber literacy. This not only helps to bridge the gap between IT and security but also creates a more relevant and inclusive environment for everyone.

A Roadmap to Bridge the Gap

Jane and Darren’s conversation on the STRIVE podcast offer practical for organizations looking to better align their IT and security functions and leaders. By fostering collaboration, aiming for common goals, and embedding security into the organization, businesses can create a more secure and innovative environment. Jane’s advocacy for increased cyber literacy and inclusion further underscores the importance of a holistic approach to cybersecurity.

See the full episode here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

What if AI autonomously handled software development? Agentic AI systems, like GitHub Copilot Workspace, already aim to take high-level requests and autonomously write, test, and debug code. This leap beyond generating snippets to automating end-to-end cognitive workflows reshapes knowledge work and software interaction. Understanding Agentic AI’s impact on strategy, roadmaps, and workforce is now imperative for leaders. According to respondents of a recent Boston Consulting Group survey, one in three companies globally is planning to allocate over $25 million to AI in 2025.

Defining Agentic AI: Beyond Chatbots to Autonomous Actors

Forget simple chatbots. Agentic AI represents systems designed to autonomously pursue goals. Given a high-level objective, an agentic system can devise a plan, execute steps by interacting with various digital tools (APIs, browsers, applications), and adapt based on outcomes. It’s the transition from AI that responds based on patterns to AI that acts to accomplish specific tasks.  

Much confusion stems from the fact that agentic AI often leverages powerful Gen AI models like OpenAI’s GPT-4o or Google’s Gemini as its core reasoning engine. However, the agentic framework – exemplified by platforms emerging from OpenAI’s Assistants API or open source toolkits – provides the crucial layers of autonomy, planning, memory, and tool interaction. Imagine that instead of having a powerful engine, you have a self-driving vehicle that uses that engine to navigate traffic, follow routes, and reach a destination. This dynamic capability separates it sharply from brittle, script-following robotic process automation.  

Agentic vs. Generative AI: The Actionable Leap Driving the Hype

Generative AI’s power to create content – from code snippets via the original GitHub Copilot to marketing copy via Jasper – is undeniable. However, agentic AI harnesses this generative power and makes it actionable. It’s the difference between asking an AI to write Python code vs. asking an agent to build, test, and debug a functional Python script that integrates with a specific API to achieve a business outcome.  

The current wave of hype, evident in soaring valuations for AI startups and intense focus from tech giants, stems from this leap to autonomous action. While Gen AI might draft sections of a business plan, an agentic system could be tasked with “Analyze market trends for Product X, identify key competitors, draft a competitive strategy document, and schedule a review meeting,” orchestrating research, analysis, generation, and scheduling tools. This potential for automating complex, multi-step workflows end to end, moving beyond human-in-the-loop for every step, fuels the immense strategic interest and investment.  

The Agentic Imperative: Reshaping Software, Challenging Incumbents

Why is virtually every software company, from hyperscalers to SaaS providers, racing to develop an agentic strategy? Because it promises to redefine user interaction and software value. As Microsoft CEO Satya Nadella said, technologies like Copilot “fundamentally change how we relate to computing,” acting as orchestrators.  

We see this playing out rapidly:

  • Microsoft’s Copilot Ecosystem: The broad rollout of Microsoft 365 Copilot across Word, Excel, and Teams isn’t just about embedding generative features; it’s about enabling users to delegate tasks like “Summarize unread emails from Project Phoenix and flag action items” or “Analyze Q4 sales data in this Excel sheet and create a PowerPoint summary.” The recent launch of GitHub Copilot Workspace explicitly targets this, aiming to take developer requests from issue description to tested pull request with minimal intervention.  
  • Google’s Agentic Integrations: Google continues to weave Gemini more deeply into Workspace, enabling complex cross-app actions. The evolution of AI Overviews in Search hints at a future where Search doesn’t just provide links but performs actions or complex research tasks directly.  
  • Salesforce, ServiceNow, Adobe: These platforms are integrating agentic features (like Salesforce Einstein Copilot or ServiceNow’s Now Assist) to automate complex CRM, IT service management, and creative workflows, allowing users to interact via natural language goals rather than complex UIs.  
  • Startups: Companies like Adept AI, focused on teaching AI to use existing software interfaces, underscore the ambition to create universal agents, attracting significant venture capital interest throughout 2024.  

This trend threatens to disrupt established software models. If users can achieve complex outcomes through conversational agents layered on top of traditional applications, the underlying application’s UI and feature set become less critical. Incumbents must adapt or risk being abstracted away.

Reshaping Data Protection: Toward Autonomous Cyber Resilience

The data protection industry, facing escalating cyber threats like the sophisticated multi-stage ransomware attacks seen increasingly in late 2024, desperately needs the proactive capabilities agentic AI promises:

  • Proactive defense beyond anomaly detection: Existing AI flags anomalies, but agentic systems could go further. Imagine an agent detecting ransomware reconnaissance patterns, autonomously snapshotting critical VMs via the backup platform, verifying snapshot integrity, and isolating suspicious endpoints before encryption begins – drastically reducing blast radius.
  • Intelligent, context-aware recovery: Instead of rigid recovery plans, an agent could analyze an attack’s scope (e.g., using threat intelligence feeds via API), identify the safest recovery points across multiple systems, orchestrate the restore using the backup infrastructure, perform automated data validation checks, and even generate post-incident reports.  
  • Dynamic policy optimization: Agents could analyze evolving compliance mandates (like updated GDPR or CCPA rulings) or observed protection gaps and automatically adjust backup policies, frequencies, and retention settings, maintaining continuous alignment without manual overhead.  

Commvault, Arlie, and the Future: Agentic Fabrics for Data Resilience

Navigating this evolution requires a data resilience platform built for an AI-driven world. At Commvault, our AI copilot, Arlie, already leverages AI to provide insights and streamline operations. But our vision extends further, toward enabling Agentic Fabrics.  

This concept envisions an intelligent, interconnected architecture where AI agents, guided by Arlie, operate and coordinate autonomously across your hybrid data landscape. This isn’t just about one assistant; it’s about a network of specialized agents working together:

  • An agent monitoring security posture might detect a threat and signal another agent via Arlie to instantly secure relevant backups.
  • Following user intent (“Recover the CRM database to its state before yesterday’s suspicious activity”), Arlie could direct agents to orchestrate the complex restore across application servers, databases, and cloud storage, confirming data integrity post-recovery.
  • Agents could proactively identify cost-saving opportunities by analyzing data usage patterns and automatically migrating cold data to less expensive storage tiers based on policy goals.

The Agentic Fabric represents the next evolution in intelligent architecture – a coordinated ecosystem where AI agents operate autonomously yet collaboratively across your entire data landscape. This isn’t merely about deploying isolated assistants; it’s about creating an interconnected network of specialized agents that communicate and coordinate seamlessly:

  • Security agents can instantly detect threats and trigger protective measures through other specialized agents without human intervention.
  • Recovery processes can follow natural language intent (“Restore our systems to before the breach”) while orchestrating complex technical workflows across hybrid environments.
  • Resource optimization becomes continuous as agents proactively identify efficiencies and implement them according to business-defined policies.

This shift toward Agentic AI demands organizations reconsider three critical dimensions: their data architecture (enabling it to support autonomous yet secure agent operations), their governance frameworks (establishing appropriate guardrails for agent actions), and their resilience strategies (leveraging agents to anticipate rather than merely respond to threats). Organizations that embrace this paradigm won’t simply gain incremental efficiencies – they’ll fundamentally transform how they protect, manage, and leverage their data assets.

As the digital landscape grows increasingly complex and threat vectors multiply exponentially, the question becomes unavoidable: Is your organization preparing for a world where AI doesn’t just assist your team but actively safeguards your most valuable assets? The agentic revolution isn’t approaching – it’s already reshaping enterprise technology. Are you ready to evolve with it?

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Groundbreaking advances in cloud to massively powerful GPUs to transformer architectures and large language models have exploded the boundaries of AI, fueling optimism, experimentation, and the race to invest and implement AI solutions. Unfortunately, this enthusiasm has not only been met with mixed results, but has introduced more risk to an organization’s security, resilience, and long-term sustainability.

Like all innovations, AI systems introduce new gaps, threat vectors, and variables that could make you more susceptible and compromise your integrity, confidentiality, and availability. Our white paper A Pragmatic and Resilient Approach to AI will help you develop a comprehensive strategy to face those challenges.

Attackers can use AI to create malware or sophisticated phishing attacks that prey on your employees and penetrate your organization. Or they can specifically target your AI systems through a dedicated hardware environment, attempt to steal your proprietary AI models, or use data poisoning to manipulate training data for malicious purposes.

These low-risk, high-return AI-driven cyberattacks are becoming more numerous and sophisticated, and it is happening as counter-cybersecurity measures get more expensive to update and deploy. The cost and complexity are compounded because AI data and workloads span multiple systems, clouds, and applications.

To keep your business safe and continuous, you need to adopt a comprehensive cyber resilience strategy and platform that spans the depth of your AI data systems and the breadth of these new workloads. You need a solution that proactively scans for anomalies, remediates threats, and helps you get back to business faster through better planning, testing, and recovery capabilities.

This approach to resilience relies on the latest AI capabilities to dramatically improve recovery time. From increasing threat intelligence and anticipating risks to automating and orchestrating recoveries, AI not only responds to an attack, but adapts and learns in real time. For instance, Commvault’s cyber resilience platform leverages AI algorithms today to:

  • Identify and prioritize clean recovery points for an automated and rapid data recovery. 
  • Locate sensitive information, identify at-risk assets, and map network configurations, interdependencies, and metadata across a hybrid or multi-cloud environment.
  • Determine risks, compliance, and forensics that must be traceable and actionable to help you comply with board-level risk and regulatory requirements.
  • Enhance our support experience offering automated self-service and troubleshooting capabilities for customers.

From creating automated runbooks – to using automation to write recovery plans – to spinning up sophisticated chatbots, AI is the foundation for an entirely new resilience paradigm. Our white paper A Pragmatic and Resilient Approach to AI was created to help you be more resilient in an AI-empowered world.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Here at Commvault, we’re committed to building a culture of community and belonging.

Throughout March, we celebrated Women’s History Month and honored the contributions, achievements, and resilience of women – both past and present. Here’s a recap on how we came together as a global Vaulter community this past month to celebrate the women in our lives.

We kicked off our celebrations with an energizing fireside chat event with our Chief Marketing Officer, Anna Griffin, and May Habib, CEO and co-founder of generative AI platform Writer, that focused on the importance of gender equality for International Women’s Day (IWD).

This year’s global theme was #AccelerateAction, which emphasizes the importance of taking swift and decisive steps to achieve gender equality. To share in our strength, we shared photos striking the official IWD pose. Check out this blog to learn more about how we celebrated IWD. And moreover, our female leaders also shared how they accelerate action each day in their roles – watch those videos below.

Throughout the month, we piloted four lean-in circles to empower the women at Commvault to lead and take on new challenges. This program offers the opportunity to connect, network, and discuss leadership development through a world-class leadership curriculum paired with regular peer advice and support. We also hosted various wellness sessions on topics including financial security, yoga and meditation, and reproductive health.

To conclude the month, this week our Women in Technology and Multi-Culture ERGs hosted a courageous conversation with special guest, Jenny Jing Zhu, chairwoman of Lush Décor & founder of Dream Weavers Foundation. Jenny shared her journey of defying cultural expectations, navigating entrepreneurship, and building Lush Décor from the ground up and how she scaled the company to $100M+ in revenue, and founded the Dream Weavers Foundation, a mission-driven initiative empowering women to dream beyond their circumstances.

We continue to support and uplift the women of Commvault every day. Click here to learn more about our Commvault culture and our commitment to community and belonging.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Microsoft Active Directory (AD) is the cornerstone of most enterprise IT networks, providing essential authentication and authorization for business-critical applications and resources. Its central role also makes it a primary target for attackers aiming to compromise enterprises or, in some cases, bring down the entire network. When AD goes offline, business comes to a standstill. Are you prepared for the worst-case scenario?

Today, we’re thrilled to announce the general availability of Commvault Cloud Backup & Recovery for Active Directory Enterprise Edition, offering full, automated forest recovery for AD that enables rapid restoration of the AD forest to help maintain continuous business.

AD Recovery is Foundational to Continuous Business

AD is the center of secure authentication and services, and its recoverability is critical when faced with outages or ransomware. Applications, file systems, email services, and databases all rely on AD for proper authentication and secure user access control, so when AD is damaged or taken completely offline, the critical applications and services it supports become inaccessible.

Consider the impact: Bank staff can’t access customer accounts. Doctors and nurses can’t access medical records. Coders and developers can’t publish code. Teams can’t collaborate or chat to get work done.

Without AD, the business cannot continue. Cybercriminals know this, which is why they make AD a primary target in 9 out of 10 cyberattacks. When disaster strikes, recovering AD is vital, yet traditionally has been very hard to do, requiring intricate, time-consuming, manual processes.

With ransomware increasingly targeting critical identity infrastructure, having a well-documented and frequently tested recovery plan to restore and rebuild your entire AD environment to a pre-attack state is essential.  

The Complexities of AD Forest Recovery

Microsoft provides prescriptive guidance on rebuilding an entire AD forest after a catastrophic disaster in its Active Directory Forest Recovery Guide. Due to the complex nature of AD, the elements involved in a full forest recovery are rigid, prescriptive, time-consuming, and highly susceptible to human error. Depending on the complexity of your AD architecture, the process can involve 50 to 100 or even more tasks.

Due to the distributed nature and multi-master architecture of AD, restoring it demands meticulous coordination. It’s not possible to simply restore domain controllers from backup and call it a day. There are dozens of intricate hygiene steps that need to be performed on the recovered domain controllers and within AD itself at very specific points throughout the forest recovery. If these steps are not followed correctly, you risk introducing new corruption or inconsistencies in the recovered environment, which can be very difficult, if not impossible, to resolve.

Relying on a manual disaster or cyber recovery plan and out-of-the-box tools could mean it takes days to restore an entire AD forest. In the face of disaster, time is of the essence, and the longer it takes to restore AD components back to a working state, the greater the disruption to the business.

Automate and Accelerate AD recovery with Commvault Cloud

Commvault Cloud Backup & Recovery for AD Enterprise Edition brings a new level of resilience to AD by enabling automated, rapid recovery of the Active Directory forest to a pre-attack state. This automation eliminates slow and error-prone manual processes, reducing the risk of errors and accelerating recovery times. Here’s how it works:

  • Make AD recovery a snap via automated runbooks: Automated forest recovery runbooks orchestrate the multi-step process required for AD forest recovery, including the critical AD hygiene tasks required to verify consistency in the recovered directory, such as seizing FSMO roles and adjusting the RID pool. These runbooks also can be used for regular testing in non-production environments to enhance cyber readiness.
  • Enable fast recovery of the most important AD infrastructure: Visual topology views of your AD environment enable simple and rapid identification of which domain controllers to restore first and how they should be recovered to accelerate the availability of AD services.
  • Track recovery progress with step-by-step runbook views: Prescriptive runbook views of the recovery process provide total transparency and fine-grained control, allowing you to easily tailor the workflow to your environment. During recovery, you have total visibility into where you are in the process and how long until your AD is back online.
  • Accelerate recovery times and advance resilience: Manually recovering an AD forest can take days or even weeks to complete, but with Commvault, you can recover it in a fraction of the time. Commvault Cloud integrates AD forest recovery with granular recovery of both AD and Entra ID, providing comprehensive protection. 

Take your AD protection to the next level

Commvault Cloud Backup & Recovery for AD Enterprise Edition is now available, providing protection, recovery, and cyber resilience for your AD environment. Visit the AD solution page to learn more or experience the solution firsthand through our interactive walk-through demo . See for yourself how Commvault can elevate your AD protection strategy.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The rapid evolution of ransomware strains, social engineering tactics, and AI-powered attacks can make cyber resilience seem like an impossible battle. But there’s more to cybersecurity than trying to outsmart attackers. While it’s true that more sophisticated threats call for more advanced defenses, there are also surprisingly simple measures you can take to significantly reduce your risk.

In this blog, we’ll explore four easy-to-implement data protection best practices, their role in a multi-layered cyberdefense strategy, and how Commvault helps customers put them to work.

1. Deploy pre-hardened images.

The strongest lock can’t help you if you leave your windows open. A full 23% of cloud infrastructure attacks involve common configuration vulnerabilities like overly permissive network policies, unnecessary services and ports, and non-secure protocols. Close these gaps and you’ve already made a big difference for the security of your attack surface.

Why do so many companies leave commonly exploited vulnerabilities in their cloud environments? Often, they’re simply moving too fast to make sure the images they deploy are secure. But Commvault can help take care of that step for them.

Commvault Cloud Platform is available in pre-hardened images that have been configured to align with Center for Internet Security (CIS) benchmarks. These built-in best practices help reduce vulnerabilities by:

  • Changing default software settings such as password policies, account lockout settings, and logging levels to prioritize security.
  • Disabling outdated or insecure protocols like SMBv1, SSLv3, and RC4 Cipher.
  • Disabling unnecessary services and closing unused ports for operating systems and applications.
  • Removing shells that can provide pathways for attackers to execute malicious code.

Beyond these CIS-hardened images for new deployments, Commvault also can provide scripts for customers to validate and harden the configurations of their existing environment. By rooting out common vulnerabilities that come from misconfigurations, we help prevent open windows from inviting attacks.

2. Protect Active Directory.

As your central control hub for access and authorization across your network, Active Directory (AD) is both a prime attack target and a lethal attack vector. For bad actors, penetrating AD is like stealing your building key card, allowing them to move silently through your environment, elevate privileges for critical applications and data, and establish a base to control your business assets. They also can lock out legitimate users, bringing your business to a halt. To block these tactics, you have to protect AD data and roll back any changes they manage to make.

Commvault can help you safeguard AD from attack by protecting your group policy objects, users, groups, conditional access policies, roles, and more. If any harmful changes are made – either intentionally by attackers or mistakenly by your own admins – you quickly can recover any deleted objects or restore overwritten attributes. To keep things simple, we also provide the granularity to roll back only the object attributes you’re concerned about without needing to do a full AD restore. Though if you do need to restore the whole AD environment, we make that simple as well.

3. Keep backups beyond the reach of ransomware.

Virtually every ransomware attack targets backup infrastructure as well. After all, if organizations can simply restore their compromised assets, the initial attack falls flat – no ransom needed, no payoff for the attackers. That makes frequent, secure backups the silver bullet of ransomware defense. 

There are many ways to protect backups, but air gapping stands out as a uniquely elegant and effective measure. It’s simple: If your backups can’t be accessed from inside or outside your organization, there’s no way for attackers to reach them to manipulate or delete them. Even if all your other defenses fail and your primary data is encrypted or deleted, you’ll be able to recover quickly and get back to work.

Commvault enables air gapping with our Commvault AirGap solution. We store a tamper-proof secondary copy of your backups in an immutable format in secure, isolated cloud storage. No matter what happens on your corporate network, you’ll still have a clean, uninfected copy of your production environment to restore. That’s a win for you and a loss for the attackers.

4. Require multi-person authorization.

Most companies already rely on multi-factor authentication (MFA) to prevent unauthorized access, as well they should. But in today’s lethal threat environment, some situations – like deleting a backup or authorizing a restore request – call for even higher levels of scrutiny.

Multi-person authorization goes beyond MFA by requiring not just a second proof of identity for the same person, but approval by an entirely different person – or even multiple people. That way, even if attackers gain control of multiple authentication factors, such as compromising both a user’s account and their device, they still won’t be in a position to act. The same holds for a malicious insider: With additional approvals required, a rogue employee can’t carry out an attack on their own. 

Commvault solutions let customers enable multi-person authorization workflows for a wide range of tasks that can be considered destructive, including:

  • Stopping a backup process for a system, server, or file share.
  • Deleting or restoring a backup.
  • Deleting agent or backup set authorization.

Admins can configure the number of approvers, user groups, and specific users required to authorize specific tasks.

If you’re not applying all four of these measures, you should. We’d never claim that they make up a comprehensive cyber defense strategy – you’ll still need to do all the other things, from analyzing threat intelligence and managing vulnerabilities to building out your security stack. But when steps this simple can significantly reduce your risk, the only question to consider is how soon you can get started.

Learn more about how Commvault Cloud can help you protect your network from cyberattacks with a multi-layered defense strategy.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

With International Women’s Day coming up on March 8, we’re thrilled to celebrate the amazing women of Commvault. This year’s global theme, #AccelerateAction, is a key driver in our Women in Technology Employee Resource Group’s efforts throughout the year. These women, and allies, work together to elevate, advance, and celebrate the powerful impact women at Commvault have on our innovation and growth.  

In celebration of Women’s History Month 2025 and International Women’s Day, we recently hosted a virtual fireside chat with our Chief Marketing Officer, Anna Griffin, and the CEO and Co-Founder of Writer, May Habib. 

It was amazing to hear May’s perspective on being a woman in technology and her journey to launch Writer, a full-stack generative AI platform for businesses. May has received many recognitions, including the 2023 Forbes AI 50, Inc.’s 2023 Female Founder Award, and a well-earned spot among the World Economic Forum’s Young Global Leaders Class of 2024. We were honored to have May join us and share her valuable insights.

And to continue our celebration, we’ll be piloting four Lean-In Circles led by Saadia Ali (Corporate Counsel), Jagruti Dadia (Senior Designer), Saira Banu (Director, Business Technology), and Madhulika Karan (Director, Professional Services) to empower the women at Commvault to lead and take on new challenges. This program offers both men and women the opportunity to connect, network, and discuss leadership development through a world-class leadership curriculum paired with regular peer advice and support.

In honor of International Women’s Day, I encourage you to think about how YOU can #AccelerateAction with those around you. And to all the incredibly inspiring and talented women at Commvault – thank you for continuing to make an impact every day.  

Click here to learn more about what it’s like to work at Commvault. 

https://play.vidyard.com/7G7bfp44N9Bq5xoc83GNXD

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Facts

On February 20, 2025, Microsoft notified us about unauthorized activity within our Azure environment by a suspected nation-state threat actor. We immediately activated our incident response plan with the assistance of leading cybersecurity experts and law enforcement.

Our investigation validated that unauthorized access affected a handful of customers and we promptly contacted them to provide assistance. Our investigation also confirmed there was no unauthorized access to any data that Commvault protects for any customer, and no impact on Commvault’s business operations or ability to deliver our products and services.

Action Taken

Our forensic investigation discovered that the threat actor exploited a zero-day vulnerability, which has been patched and we encourage our software customers to do the same. We also rotated affected credentials, continue to further harden our defenses and work with law enforcement.

Working Together

No company is immune to an attack. We believe that sharing information and working together makes us all more resilient. We thank Microsoft for their notification to us, our cybersecurity experts for their trusted partnership, and our customers for their responsiveness and resilience.

For further inquiries, customers may contact Commvault’s support team via our portal at https://support.commvault.com.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

For healthcare organizations, protecting sensitive patient information is paramount. As we increasingly rely on digital systems to store, process, and transmit protected health information (PHI), proper cryptographic safeguards have become essential. This is where Federal Information Processing Standard (FIPS) 140-2 comes into play.

What is FIPS 140-2?

FIPS 140-2 is a U.S. government security standard that specifies requirements for cryptographic modules used to protect sensitive information. Published by the National Institute of Standards and Technology (NIST), this standard establishes specific security requirements that must be satisfied by cryptographic modules to maintain the confidentiality and integrity of the information they protect.

For healthcare organizations handling sensitive patient data, FIPS 140-2 provides a framework for implementing strong cryptographic protections that align with Health Insurance Portability and Accountability (HIPAA) Security Rule requirements for protecting electronic protected health information (ePHI). Read more about the proposed updates to that rule in our blog The Prescription for Cyber Resiliency in Healthcare.

Key Features of FIPS 140-2

Four Security Levels

FIPS 140-2 has a tiered approach to security, with four distinct levels offering progressively stronger protection:

  1. Level 1: Requires production-grade equipment and at least one approved algorithm or security function. There are no specific physical security mechanisms required beyond basic production-grade components.
  1. Level 2: Adds physical security mechanisms, such as tamper-evident coatings or seals, or pick-resistant locks, and requires role-based authentication.
  1. Level 3: Enhances physical security with measures to detect and respond to attempts at physical access or modification. Prevents an intruder from gaining access to critical security parameters held within the module and includes identity-based authentication.
  1. Level 4: Provides complete protection around the cryptographic module with the intent of detecting and responding to all unauthorized physical access attempts. Level 4 modules can operate in physically unprotected environments.

Most healthcare organizations typically implement Level 2 or Level 3 protection, balancing security needs with operational practicality.

Cryptographic Module Specification

FIPS 140-2 mandates detailed documentation of the cryptographic module, including module ports and interfaces; manual operations; physical design; hardware, software, and firmware components; and security functions. This comprehensive documentation provides transparency in how sensitive data is protected and allows for thorough security assessments.

Approved Algorithms

FIPS 140-2 requires the use of validated cryptographic algorithms, including:

  • Symmetric key encryption: AES, Triple DES
  • Asymmetric key encryption: RSA, DSA, ECDSA
  • Secure hashing: SHA-256, SHA-384, SHA-512
  • Message authentication: HMAC, CMAC

Using only validated algorithms confirms that cryptographic implementations meet minimum security requirements and haven’t been compromised by known vulnerabilities.

Key Management

Proper key management is critical for maintaining cryptographic security. FIPS 140-2 specifies requirements for key generation, key establishment, key entry and output, key storage, and key zeroization (secure deletion). For healthcare organizations, proper key management helps encryption remain effective and prevents compromised keys from leading to data breaches.

Self-Testing

FIPS 140-2 requires cryptographic modules to perform self-tests to validate they’re functioning properly. These include power-up tests executed automatically, conditional tests performed when specific functions are invoked, and continuous random number generator tests. These testing requirements help maintain the ongoing reliability of cryptographic protections.

The Importance of FIPS 140-2 Compliance in Healthcare

While HIPAA doesn’t explicitly mandate compliance with FIPS 140-2, the HIPAA Security Rule requires appropriate measures to uphold the confidentiality, integrity, and availability of ePHI. FIPS 140-2 provides a recognized standard that satisfies many of HIPAA’s encryption requirements.

Furthermore, other regulations affecting healthcare organizations – such as the Federal Information Security Management Act (FISMA) – may explicitly require FIPS 140-2 compliance for federal agencies and their contractors, which can include healthcare providers working with Medicare, Medicaid, or the Veterans Administration.

Risk Mitigation

Healthcare data breaches can be catastrophic, both for patients whose privacy is compromised and for organizations facing financial penalties, remediation costs, and reputational damage. FIPS 140-2 compliance significantly reduces the risk of breaches due to cryptographic failures by confirming:

  • Cryptographic implementations follow proven best practices.
  • Security vulnerabilities are identified and addressed.
  • Encryption methods can withstand sophisticated attacks.
Patient Trust

Beyond regulatory requirements, implementing strong data protection measures demonstrates a commitment to patient privacy. When healthcare organizations can assure patients that their sensitive information is protected by government-validated security standards, it builds trust in an increasingly privacy-conscious world.

Vendor Assessment

FIPS 140-2 certification provides a clear benchmark for evaluating technology vendors. When selecting systems that will process or store ePHI, healthcare organizations can use FIPS 140-2 compliance as a key criterion, simplifying the vendor assessment process and verifying that baseline security requirements are met.

How Commvault Supports FIPS 140-2 Compliance

Commvault’s comprehensive data management platform provides robust support for healthcare organizations seeking FIPS 140-2 compliance through several key capabilities:

FIPS-Validated Cryptographic Modules

Commvault incorporates cryptographic modules that have been validated under the NIST Cryptographic Module Validation Program (CMVP). These modules have undergone rigorous testing by NIST-accredited laboratories to verify their compliance with FIPS 140-2 requirements, providing healthcare organizations with assurance that their data protection measures meet federal standards.

End-to-End Encryption

Commvault offers comprehensive encryption capabilities that protect healthcare data throughout its lifecycle:

  • In-flight encryption: All data transfers between Commvault components use TLS 1.2 or higher with FIPS-approved encryption algorithms, protecting sensitive healthcare information while in transit.
  • At-rest encryption: Commvault secures stored healthcare data using FIPS-approved AES-256 encryption, protecting backups, archives, and other data repositories from unauthorized access.
  • Client-side encryption: Data can be encrypted before it leaves the source system, so it remains protected throughout the entire backup and recovery process.
Secure Key Management

Commvault’s integrated key management system aligns with FIPS 140-2 requirements for secure key handling:

  • Centralized key management: Encryption keys are managed through a centralized, policy-driven system that maintains strict access controls.
  • Key rotation: Automated key rotation capabilities allow healthcare organizations to periodically update encryption keys without disrupting operations, following cryptographic best practices.
  • Secure key storage: Encryption keys are stored with multiple layers of protection, including the option to integrate with external Hardware Security Modules for enhanced security.
Identity-Based Access Controls

Commvault implements strong authentication and authorization mechanisms that align with FIPS 140-2 security requirements:

  • Role-based access control: Granular permission settings allow only authorized personnel to access sensitive healthcare data or perform critical system operations.
  • Multi-factor authentication: Support for MFA provides an additional layer of security when accessing the Commvault management console or data.
  • Detailed audit logging: Comprehensive activity logs track all access to protected healthcare information, supporting compliance audits and security investigations.
FIPS Mode Operation

Commvault allows healthcare organizations to enable “FIPS mode,” which enforces the exclusive use of FIPS-approved cryptographic algorithms and modules throughout the entire data management environment. When FIPS mode is activated:

  • Non-FIPS-compliant algorithms are disabled.
  • Only validated cryptographic modules are utilized.
  • Security settings are automatically configured to meet FIPS requirements.

This simplified approach to compliance reduces the administrative burden on healthcare IT teams and minimizes the risk of configuration errors that could compromise security.

Seamless Integration with Healthcare Systems

Commvault’s platform integrates with major healthcare information systems while maintaining FIPS 140-2 compliance:

  • Electronic health record system protection: Specialized connectors for leading EHR systems enable patient data to be backed up and recovered securely.
  • Medical imaging support: Backup capabilities meet the Digital Imaging and Communications in Medicine international standard for storing, exchanging, and using medical imaging data while preserving compliance with both HIPAA and FIPS requirements.
  • Virtual environment protection: Healthcare organizations running critical applications in virtualized environments can maintain FIPS compliance with Commvault’s virtual machine protection capabilities.
Compliance Documentation and Reporting

Commvault simplifies the documentation requirements associated with FIPS 140-2 compliance:

  • Validation certificates: Access to FIPS 140-2 validation certificates for Commvault’s cryptographic modules.
  • Compliance reports: Built-in reporting tools that document encryption status, key management activities, and other security-related metrics.
  • Audit support: Comprehensive logs and reports that streamline the process of demonstrating compliance during regulatory audits.

Implementing FIPS 140-2 in Healthcare Environments

Conducting an Inventory

The first step toward FIPS 140-2 compliance is identifying all systems and applications that process sensitive healthcare data. This includes:

  • EHR systems
  • Medical imaging systems
  • Laboratory information systems
  • Billing and administrative systems
  • Mobile devices used by healthcare providers
  • Data backup and storage solutions
Validating Cryptographic Modules

For each system identified, determine whether it uses FIPS 140-2 validated cryptographic modules. The NIST maintains a list of validated modules called the CMVP. Vendors should be able to provide their FIPS 140-2 validation certificates and reference numbers.

Addressing Gaps

For systems that don’t comply with FIPS 140-2, healthcare organizations have several options:

  • Upgrade to FIPS-compliant versions.
  • Implement additional encryption layers using validated modules.
  • Replace non-compliant systems with compliant alternatives.
  • Apply for exceptions if appropriate compensating controls are in place.
Documentation and Training

Maintaining comprehensive documentation of FIPS 140-2 compliance efforts is essential for both internal governance and regulatory audits. Additionally, staff should receive training on the importance of encryption and proper handling of sensitive data.

Conclusion

FIPS 140-2 compliance represents more than just a checkbox for regulatory requirements – it’s a fundamental component of a robust healthcare data security strategy. By implementing cryptographic protections that meet this rigorous standard, healthcare organizations can significantly reduce the risk of data breaches, build patient trust, and avoid costly compliance violations.

As healthcare continues to digitize and cyber threats grow more sophisticated, adhering to recognized security standards like FIPS 140-2 is no longer optional – it’s a critical aspect of responsible healthcare delivery in the digital age.

By choosing Commvault’s FIPS 140-2–compliant data management solutions, healthcare organizations can confidently protect sensitive patient information while simplifying compliance efforts. Our comprehensive approach to data protection not only addresses current regulatory requirements but provides a foundation for addressing evolving security.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

It’s been nearly 30 years since the Health Insurance Portability and Accountability Act went into effect. Among other provisions, it protects patients by preventing disclosure of private health information without their consent. Over the years, the act has been updated and amended in response to changing technologies and related healthcare legislation and policy.

Last year, the U.S. Department of Health and Human Services (HHS) proposed significant amendments to the HIPAA Security Rule to enhance the cybersecurity of electronic health records (EHR)). The newest modifications were created in response to increased electronic record keeping and transfer, increased number and severity of security breaches, and other cybersecurity practices and enforcement issues that have changed or arisen since the rule was last updated in 2013.

A key component of this proposal mandates that covered entities establish written procedures to restore critical electronic information systems and data within 72 hours of a loss. This requirement aims to enable healthcare organizations to promptly recover essential systems and data after a security incident, thereby minimizing disruptions to patient care and maintaining the confidentiality, integrity, and availability of EHR.

Read more  about how Commvault can be used to rapidly recover EHR, including in Epic and Meditech environments.

HIPAA Enforcement

HIPAA enforcement falls under the Office for Civil Rights (OCR) within HHS. The OCR is responsible for making sure that healthcare providers, health plans, clearinghouses, and their business associates comply with the HIPAA Privacy, Security, and Breach Notification Rules.

In recent years, OCR has prioritized financial penalties for violations – particularly those related to the HIPAA Security Rule. In 2024, OCR reported that HIPAA enforcement was at near-record levels, with $9.9 million collected, including one $4.75 million settlement for multiple Security Rule violations. However, while the number of enforcement actions has increased, the average penalty amount has decreased due to a reinterpretation of penalty tiers under the HITECH Act.

Key Enforcement Mechanisms for New Mandates

With new HIPAA Security Rule mandates on the horizon, OCR will enforce compliance through a mix of education, audits, investigations, and penalties. Below is a detailed breakdown of how these enforcement mechanisms work:

1. Education & guidance (early-stage enforcement)

OCR provides guidance, training, and best practices to help covered entities and business associates comply with HIPAA regulations. This includes:

  • Updated FAQs, training programs, and online resources.
  • Collaboration with industry groups to clarify how the new security mandates should be implemented.
  • Technical guidance on risk analysis and management (an area of frequent non-compliance).

This stage allows organizations to update their security programs, risk management policies, and workforce training before strict enforcement begins.

2. Compliance investigations & breach reporting

OCR investigates compliance in response to:

  • Complaints: Individuals can report HIPAA violations, triggering OCR investigations.
  • Breach reports: Any breach involving 500 or more records must be reported to OCR, which then investigates whether non-compliance contributed to the breach.

Given the rise in hacking incidents, OCR has been focusing on cybersecurity preparedness, requiring stronger risk analysis and system monitoring by healthcare organizations.

3. HIPAA audits & risk analysis focus

OCR has emphasized risk analysis as a top enforcement priority due to widespread non-compliance.

  • In the 2016–2017 HIPAA audits, most organizations failed to conduct a comprehensive risk analysis or update it regularly.
  • In 2024, 14 out of 22 OCR enforcement actions were for HIPAA Security Rule violations, with risk analysis failures being the most common issue.
  • OCR intends to relaunch compliance audits (although budget constraints may delay this initiative).

Expect stricter scrutiny on how organizations assess and mitigate risks to ePHI.

4. Financial penalties & corrective action plans (CAPs)

OCR can issue penalties for non-compliance, with fines ranging from thousands to millions of dollars based on:

  • Negligence or willful neglect
  • Failure to correct violations after notification
  • Number of individuals affected

Since HIPAA fines have decreased significantly (from an average of $2.6 million in 2018 to about $450,000 in 2024), OCR has sought alternative enforcement strategies, such as CAPs requiring organizations to improve security measures within a set timeframe and stricter state-level enforcement.

What This Means for Your Organization

With OCR prioritizing risk analysis enforcement, these steps can help you comply with the proposed updates:

  • Regularly update risk assessments and cover all ePHI systems.
  • Implement stronger cybersecurity measures (e.g., encryption, multi-factor authentication, and continuous monitoring).
  • Train employees on HIPAA compliance and breach response protocols.
  • Provide timely breach notifications with accurate content.
  • Maintain documentation proving compliance efforts.

State attorneys general can independently enforce HIPAA and impose penalties for violations. California’s largest 2024 penalty ($6.75M) targeted a cloud storage provider for mishandling patient data security. With states passing additional cybersecurity laws (e.g., New York’s hospital cybersecurity mandates), expect HIPAA enforcement to expand beyond OCR oversight.

Final Thoughts: Challenges Ahead

Despite increases in both reports of breaches and HIPAA complaints, OCR appears unlikely to receive the increased funding it says it needs to ramp up enforcement. It remains unclear how the agency will be impacted by ongoing budget cuts from the Department of Government Efficiency – and how the new administration will proceed after public comment on the proposed changes closes on March 7.

Whether or not the new HIPAA Security mandates do take effect this year, organizations would benefit by proactively strengthening their cybersecurity measures, risk analysis, disaster recovery strategies, and compliance training. By managing these issues, healthcare entities can help avoid potential penalties, reduce breach risks, and protect patient data effectively.

Learn more about how Commvault can aid your organization in its compliance efforts.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Throughout February, our global Vaulter community was proud to celebrate and honor Black History Month.

Here at Commvault, we value and celebrate the unique perspectives each Vaulter brings to the table as we foster innovation and collaboration. We are proud to have an internal focus on “equity in action” as we continue to nurture our inclusive culture.

To conclude our celebrations, our Multi-Culture Employee Resource Group (ERG) partnered with the Courageous Conversation Foundation for an impactful, capacity-building training session on effectively engaging, sustaining, and deepening interracial dialogue. We were honored to have the foundation’s CEO and President, Glenn E. Singleton, join us for this thought-provoking and moving experience as we unpacked the global framework of community and belonging and how to best incorporate this culture into the workplace.

It is so important to continue our learning journey on how to have the “right” conversations – understanding that we won’t change the conversation, unless we have the conversation. Having open dialogues to exchange ideas and experiences only makes us stronger and better.

As Black History Month ends, let’s all remember the role Black history has and continues to play in American history. Each February, we acknowledge the heroes of the Black community and honor their fight by condemning racism and championing change. But this commitment shouldn’t be limited to just one month; it should be a part of our daily lives all year round.

Listening to the experiences and perspectives of others and learning how to better support one another empowers us to create a sense of belonging for everyone. Click here to learn more about our Commvault culture and our commitment to community and belonging.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In the dynamic landscape of cloud computing, organizations are increasingly reliant on robust recovery strategies for resilience and uninterrupted service delivery. One approach that has been traditionally adopted is the pre-creation of a cloud landing zone.

However, this method is fraught with inefficiencies and potential pitfalls that can undermine its effectiveness and cost organizations time, resources, and operational resilience. This blog delves into the concept of a cloud landing zone, highlights the challenges associated with pre-creating such zones for cyber recovery (CR) and disaster recovery (DR), and introduces Cloud Rewind’s rebuild model as an alternative for enabling cloud resilience.

What Is a Cloud Landing Zone?

A cloud landing zone is a pre-configured environment within a cloud account designed to manage cloud resources securely and efficiently. It provides a structured framework for cloud resource deployment, network configuration, and security settings, aligning with best practices and organizational policies. The intent is to facilitate smooth, scalable, and compliant cloud operations.

While cloud landing zones serve as the foundation for deploying and managing cloud resources, their application in CR/DR scenarios presents several challenges.

Challenges with Pre-Created Cloud Landing Zones for CR/DR

  • Time and resource consumption: Creating a cloud landing zone requires a comprehensive understanding of the existing production environment’s architecture and maintenance practices. This replication effort demands substantial time and resources, duplicating efforts and diverting them from value-generating activities.
  • Maintenance and configuration drift: Once established, a pre-built landing zone necessitates ongoing maintenance to stay in alignment with the production environment. However, the dynamic nature of cloud environments often leads to configuration drift – a divergence in the settings and configurations between the production and CR/DR environments. This drift complicates maintenance efforts and can compromise the efficacy of the recovery strategy.
  • Impediments to testing: The divergence between production and CR/DR environments due to drift and misalignment hampers the ability to conduct effective recovery testing. The hesitancy or inability to test recoveries undermines the resilience of IT systems, leaving organizations vulnerable in the event of a disaster or cyberattack.
  • Wasted investments: The resources expended on creating and maintaining a pre-created landing zone can be substantial, yet the return on investment (ROI) is often minimal. Organizations may find themselves with outdated or misaligned recovery environments that are not ready for immediate use after a disaster or incident. Furthermore, in the face of sophisticated ransomware attacks, the ability to rebuild systems from clean data and application images is crucial – a capability that is hampered by the constraints of a pre-created landing zone.

The Cloud Rewind Approach to Cloud Resilience: Rebuild

Cloud Rewind’s rebuild model for cloud resilience offers a more agile, efficient, and effective approach CR/DR. Unlike the traditional model of pre-creating and maintaining a cloud landing zone, Cloud Rewind allows for dynamically rebuilding cloud environments from clean copies of data and application images. This model addresses the core challenges associated with pre-created landing zones:

  • Efficiency and agility: By eliminating the need for a pre-created landing zone, organizations can allocate resources more efficiently, focusing on strategic initiatives rather than maintenance and alignment efforts.
  • Reduced configuration drift: The rebuild model mitigates the risk of configuration drift by verifying that the recovery environment is constructed with the latest, clean configurations and data, closely mirroring the production environment at the time of rebuild.
  • Enhanced testing and recovery: The dynamic nature of the rebuild approach facilitates more frequent and realistic testing of CR/DR procedures, enhancing IT system resilience.
  • Cost-effectiveness: Without the sunk cost of maintaining a pre-created landing zone, organizations can achieve better ROI on their investments, focusing on rapid CR/DR capabilities that are more aligned with modern cloud practices.

In the context of increasing cyber threats like ransomware, the ability to rapidly rebuild a clean environment is invaluable. Cloud Rewind allows organizations to swiftly respond to such threats, minimizing downtime and enabling continuous business.

Rebuild: A Forwarding-Thinking Approach

The traditional approach of pre-creating cloud landing zones for CR/DR is fraught with inefficiencies, including wasted resources, maintenance challenges, and compromised resilience. In contrast, Commvault Cloud Rewind’s on-demand rebuild model for cloud resilience offers a more agile, cost-effective, and robust solution.

By focusing on the dynamic rebuild of cloud environments, basically a clone of the production environment, organizations can enhance their CR/DR capabilities, reduce operational risks, and enable continuous service delivery in the face of disruptions. The shift toward the rebuild model represents a forward-thinking approach to CR/DR recovery, aligning with the evolving demands of cloud computing and organizational resilience.

Learn more about how Commvault Cloud Rewind can help you rapidly rewind; recover critical data, cloud applications, and configurations to a clean state; and swiftly rebuild your cloud environments after cyber incidents.

Additional Reading:

  1. https://www.commvault.com/blogs/build-cloud-app-resilience-with-commvault-cloud-rewind
  2. https://www.commvault.com/blogs/simplifying-cloud-resilience-and-cloud-recovery 
  3. https://www.commvault.com/blogs/a-blueprint-for-effective-cloud-recovery

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Our latest Commvault® Cloud software and SaaS releases provide new features and capabilities to help you elevate your cyber resilience and data protection strategy by making protecting and managing your data easier and faster. It’s designed to help you secure and recover hybrid cloud data against emerging data loss threats and recover quickly in the event of an incident or cyberattack.

Among the newest features now available as part of this release:

CrowdStrike Integration

Your security teams need to act fast. With ransomware attacks on the rise, companies must enhance their visibility to detect and address threats early.

Commvault helps you strengthen your cyber defenses by integrating CrowdStrike Falcon with Commvault Cloud. With CrowdStrike data integrated into the Commvault dashboard, your security team can quickly identify and respond to threats. This streamlined visibility makes it easier to protect backup assets, secure sensitive data, and take proactive recovery actions.

Commvault AirGap Enhancements

Ransomware detection and protection are crucial. As customers increasingly use Commvault AirGap, they seek broader functionality and consistent performance across all storage tiers.

We’ve enhanced Commvault AirGap with features like versatile tiering for both primary and secondary data, guardrails for data recovery and retention, and threat scanning for cloud and on-prem environments. This helps customers optimize storage costs while maintaining robust protection.

Commvault Edge

Companies need to protect data and apps at remote and branch locations just as effectively as they do for on-premises and cloud deployments.

Commvault Edge offers a software image that can be installed on a reference architecture, providing data protection at remote sites, all managed through a centralized control plane. Your admins gain flexibility and visibility by choosing the right hardware for installing the HS Edge software image, managing and protecting up to 200TB of data for retail locations, factory floors, IoT, and more. Plus, with its pre-hardened and pre-configured Linux-based OS, the software image allows for rapid deployment and easy maintenance.

Cloud Rewind

With 70% of cloud resources typically left unprotected, achieving cyber resilience can be a daunting task. Organizations are eager to bolster protection across all assets and be ready to bounce back from threats.

Cloud Rewind offers a powerful way to quickly restore critical data, cloud applications, and configurations to a clean state. It allows users to swiftly rebuild their cloud environments to a known safe state after cyber incidents, cutting recovery time from weeks to minutes. This rapid recovery capability is crucial for maintaining cyber resilience.

Clumio for Amazon S3

With the rise of modern apps and AI, Amazon S3 has seen explosive growth, making it a prime target for attacks. Restoring billions of objects from backup can be painfully slow, leading to extended downtime.

Clumio Backtrack offers a game-changing solution by allowing rapid rollbacks of Amazon S3 objects to a specific version at any point in time. This means enhanced cyber resilience against mistakes and attacks, and the ability to restore billions of objects in minutes using S3 Versioning and serverless technology. Plus, it optimizes AWS spend by eliminating the need for extra copies of S3 buckets.

Note: Clumio for Amazon S3 is also available on AWS Marketplace.

Cleanroom Recovery for AWS

Customers using AWS for their cloud deployments want to conduct recovery exercises within the same environment for optimal efficiency.

Commvault has extended Cleanroom Recovery to AWS, allowing you to recover workloads directly into AWS. This expansion means you can perform recovery testing in an environment that mirrors their production setup, enhancing consistency. Plus, with broader cloud platform support, your business gains the flexibility to craft a recovery strategy tailored to your needs.

Auto-scaling for Amazon EC2 Restore

AWS users need Commvault auto-scaling for replication, recovery, and indexing to minimize the number of long-lived Commvault Access Nodes they must manage in their AWS environment. Commvault Cloud now dynamically scales Amazon EC2 compute during restore, replication, and migration activities, terminating them afterward to keep cyber resilience costs low.


You can simplify maintenance by reducing the number of long-lived Commvault Access Nodes in your AWS environment and save on costs by leveraging elastic EC2 compute only when necessary.

Backup & Recovery for Google Workspace

SaaS app security risks like accidental deletion, corruption, and malicious attacks can disrupt productivity. Surprisingly, only 13% of businesses fully grasp their role in protecting data.

Commvault is stepping up by expanding SaaS app protection to Google Workspace, covering Gmail, Google Drive, and Shared Drive data. This means your critical Google Workspace data can stay safe and recoverable from data loss threats.

Your business can keep moving forward with data that’s available and quickly recoverable. Plus, maintain service-level agreement compliance with extended retention and bundled Google Cloud Storage, all managed through a single, unified solution for Google Workspace and other SaaS, hybrid, and cloud-native workloads.

Active Directory Forest Recovery

When Active Directory (AD) goes offline, recovering the forest can be a daunting, multi-step process that must be executed perfectly. Without automation, there’s a real risk of restoring AD in an unusable state, causing further business disruption.

Commvault’s solution simplifies this with rapid recovery from schema corruption and ransomware attacks. By automating the full forest recovery process, you can plan and test in advance, reducing downtime and boosting cyber resilience. This means you can have peace of mind knowing your AD forest can be restored to a healthy state quickly and efficiently.

Nutanix AHV Source VMs

Do you face the challenge of protecting diverse and complex operating environments? Do you need reliable solutions to manage these environments effectively? That’s where Cleanroom Recovery comes in. Now supporting Nutanix VMs, it helps you respond swiftly to security threats and streamline recovery validation.

Why does this matter? It provides comprehensive coverage for complex environments, leading to more complete recoveries. Plus, with support for more VMs and workloads, businesses can get back up and running quickly, enhancing their cyber resilience and keeping operations smooth.

Palo Alto Networks XSOAR Integration

Security teams often rely on SIEM/SOAR platforms like Palo Alto Networks XSOAR for threat detection and response, but the lack of integration with recovery solutions means they face time-consuming manual recovery efforts, delaying their response to active threats.

Commvault Cloud Cleanroom Recovery integrates seamlessly with Palo Alto Networks XSOAR, allowing teams to manage recovery efforts directly within the XSOAR platform. This integration speeds up recovery times with automated workflows, reduces manual tasks so teams can focus on threat analysis, and centralizes management for better collaboration and faster incident response.

Backup & Recovery for Kubernetes

As businesses modernize their applications, many have chosen Kubernetes as their go-to platform to manage large amounts of data for hybrid cloud apps. Admins need to perform faster backups and improve recovery readiness for their containerized applications and data. 

Commvault enables Kubernetes backup and recovery that’s optimized for large volumes of data. This solution seamlessly integrates with the Kubernetes API server to discover and collect application data and configurations, delivering improved performance and reliability for backups. 

Try Commvault Cloud free for 30 days.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

With cyberattacks becoming increasingly inevitable, the ability to recover quickly and effectively is crucial for business survival. In Episode 13 of The STRIVE Podcast, host Darren Thomson delves into the critical aspects of building an effective cyber recovery plan. Here’s a summary of the key phases and principles discussed.

Phase One: Preparation

  • People: Everyone in the organization must know their role. Establish a well-defined crisis response team to take charge during an attack.
  • Process: Map out potential threat scenarios and create step-by-step recovery playbooks. The plan must align with your broader continuous business and incident response strategies.
  • Technology: Secure air-gapped backups and implement anomaly detection so that recovery points are clean. Regularly test your plan in a cleanroom to build confidence and readiness.

Phase Two: Immediate Response

  • Detection and notification: Implement real-time monitoring tools and notify your response team immediately upon detecting an attack.
  • Isolation and containment: Disconnect infected systems and isolate critical infrastructure to prevent the spread of the threat.
  • Initial assessment: Document everything to understand the scope of the damage and identify the quickest path to recovery. Fast, decisive action is crucial to minimize disruption.

Phase Three: Recovery

  • Data integrity: Confirm backups are clean before restoration. Use air-gapped backups and cleanroom technology to help prevent reinfection.
  • System restoration: Rebuild critical infrastructure, including Active Directory, firewalls, servers, and applications, with hardened security configurations.
  • Prioritization: Restore critical infrastructure and data first, and verify system and data integrity before restoring applications.

Phase Four: Reintegration

  • Cautious reconnection: Gradually reconnect users and assets, starting with critical infrastructure. Monitor for signs of persistent threats.
  • User access and authentication: Reconfigure systems for better identity controls, such as multi-factor authentication and least-privilege policies.
  • Security monitoring: Verify all systems are secure, and monitor for any lingering vulnerabilities.

Phase Five: Continuous Improvement

  • Security enhancements: Apply new security controls based on lessons learned from the attack or test.
  • Forensics analysis: Investigate how the attack occurred and what weaknesses were exploited to prevent future breaches.
  • Refine the plan: Regularly test and refine your cyber recovery plan to improve its success rate. Cyber recovery is about bouncing back stronger.

Key Takeaways

  • Preparation is key: Build and test a comprehensive recovery plan.
  • Immediate action: Detect, isolate, and assess threats quickly.
  • Data integrity: Confirm backups are clean and secure.
  • Gradual reintegration: Reconnect systems cautiously, and monitor for threats.
  • Continuous improvement: Learn from each incident to enhance your security posture.

Watch the full episode now:

STRIVE Episode 13: Building an Effective Cyber Recovery Plan

https://play.vidyard.com/iHS8ZZfMinwUx9HkA67u8E

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In the face of rapidly evolving security threats, the importance of cyber resilience cannot be overstated. As attacks become more sophisticated and frequent, organizations are increasingly recognizing the need for a comprehensive and integrated approach to cybersecurity.

This shift is evident in the growing trend of consolidation and investment within the cybersecurity market, which is driving the development of more robust and unified solutions. The data protection industry has seen large investments, including Veeam’s recent $2B in secondary equity and the recently closed Cohesity acquisition of Veritas’ assets from Carlyle Group Inc.

The Shift Toward Integrated Solutions

Traditionally, organizations have relied on a patchwork of best-of-breed tools to address their cybersecurity needs, including from the likes of Veeam. While these tools are often highly effective in their specific domains, using them can lead to a fragmented security landscape. This fragmentation results in data silos, increased operational costs, inefficiencies in threat response, and potential security concerns between disparate data protection silos. As threats become more complex and interconnected, this approach is no longer sufficient. 

The consolidation and investment in the cybersecurity market reflect a growing awareness of these challenges. Companies are now seeking more integrated and comprehensive solutions that can provide a unified, cohesive, and adaptable security framework like Commvault. This platform-centric approach not only enhances overall security but also improves efficiency, reduces costs, and enables better compliance and disaster recovery.

Security at Every Layer

Point products can struggle with security due to their fragmented approach of multiple disparate codebases and reliance on integration with other platforms. Unlike makers of point products, like Veeam, Commvault leverages a single codebase that integrates security into every stage of our software development lifecycle (SDLC) and in every layer of the Commvault Cloud platform. This commitment to secure software development is a cornerstone of Commvault’s strategy to provide robust and reliable solutions to our customers.

Our approach to secure software development begins at the design phase. We employ a security-by-design methodology, so that security considerations are integrated from the beginning of the development process. This proactive approach helps identify and mitigate potential vulnerabilities early on, reducing the risk of security breaches and making the final product is as secure as possible.

Regular Security Audits and Penetration Testing

To further enhance the security of our products, we conduct regular security audits and penetration testing. These rigorous assessments are performed by both internal security teams and external third-party experts. The results of these tests are used to identify and remediate any vulnerabilities, ensuring that our solutions remain secure and resilient against emerging threats.

This testing regimen provides additional confidence to our customers and shows our commitment to securing both customer data and the platform that protects it. As a result of our high security standards, Commvault® Cloud is one of the only FedRAMP High Authorized cyber resilience platforms.

Training and Awareness

Commvault places a strong emphasis on training and awareness among our development teams. We conduct regular security training sessions and workshops to keep developers informed about the latest security best practices and emerging threats. This ongoing education makes our development team is well-equipped to identify and address security issues proactively.

Leading the Charge in Cyber Resilience

Recognized by Forrester, Gartner, GigaOm, IDC and other industry analysts as a leader in data resilience solutions, we have consistently demonstrated our commitment to innovation and excellence.

Our comprehensive cyber resilience platform, Commvault Cloud, is designed to help empower continuous business availability and rapid recovery across hybrid, cloud-first, and multi-cloud environments, moving beyond traditional backup and recovery.

Commvault’s leadership is further solidified by our strategic acquisitions, such as Appranix and Clumio. These acquisitions have significantly enhanced our portfolio, enabling it to offer end-to-end solutions for backup, disaster recovery, and ransomware protection across on-premises, hybrid, and multi-cloud environments.

Enhance Your Cyber Resilience

The consolidation and investment in the cybersecurity market highlight the critical importance of cyber resilience. Organizations are increasingly recognizing the need for integrated and comprehensive solutions that can effectively manage the evolving threat landscape and platforms that are designed to be secure. Commvault is well-positioned to lead this transformation. We invite you to try our platform yourself by using our free trial available now.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

As businesses increasingly rely on multi-cloud environments, building cloud resilience becomes critical. In this article, we will explore the key components of cloud resilience and its importance in recovering from outages such as ransomware attacks.

We will delve into essential elements of cloud resilience such as cloud infrastructure backup, dual-vault cloud time machine, and recovery-as-code. By adopting these cloud-native disaster recovery practices across AWS, Azure, Google Cloud, and Kubernetes platforms, businesses can effectively safeguard their infrastructure, minimize downtime, and recover from ransomware attacks.

Understanding Cloud Resilience

Cloud resilience refers to an organization’s ability to withstand and rapidly recover from outages, assuring the continuity of its business operations. In a multi-cloud environment, resilience is achieved through a combination of robust infrastructure, efficient and comprehensive cloud infrastructure and data backup solutions, and well-defined disaster recovery strategies across multiple platforms. This is particularly crucial in the context of recovering from ransomware attacks, where the ability to quickly restore systems and data is vital to minimizing the impact of such security incidents.

Importance of Cloud Resilience in Ransomware Recovery

Ransomware attacks have become a significant threat to businesses, with devastating consequences for organizations that fall victim to them. These malicious attacks encrypt critical data and systems, holding them hostage until a ransom is paid. Cloud resilience plays a crucial role in recovering from ransomware attacks. By implementing robust backup and recovery mechanisms, a businesses’ data remains protected and recoverable even in the face of ransomware encryption.

Cloud infrastructure backup solutions enable organizations to create regular snapshots of their systems and data, providing a clean and uncorrupted copy to restore from after an attack. Additionally, the ability to automate recovery processes through recovery-as-code practices allows businesses to swiftly recover entire environments, minimizing downtime and disruption to operations. By embracing cloud resilience strategies across multiple platforms, organizations can effectively mitigate the impact of ransomware attacks and allow for continuous business.

As businesses embrace multi-cloud environments, the need for cloud resilience becomes paramount, especially in the context of recovering from ransomware attacks. By implementing robust backup solutions, leveraging automation through recovery-as-code practices, and adopting cloud-native disaster recovery strategies, organizations can effectively protect their data, systems, and applications.

Cloud resilience not only minimizes downtime but also provides tools and processes that are necessary to recover from ransomware attacks and maintain continuous business. In an increasingly interconnected and threat-prone digital landscape, embracing cloud resilience is essential to safeguarding critical assets and maintaining the long-term success of businesses in multi-cloud environments.

Learn more about how Commvault Cloud Rewind can help you rapidly rewind, and recover critical data, cloud applications and configurations to a clean state and swiftly rebuild your cloud environments after cyber incidents.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Here at Commvault, our values – we connect, we inspire, we care, and we deliver – are foundational to everything we do and why it matters.

This week, we hosted our quarterly internal Global Town Hall meeting and presented our FY25 Q3 CEO Living Our Values Awards. This award program globally recognizes and celebrates our Vaulters for their incredible work over this past quarter and for living our values each day.

I’m so proud to announce our FY25 Q3 CEO Living Our Values Award winners and our employee-nominated Vaulters’ Choice Award winner below:

CEO Award Winners

Nithya Suresh

Nithya Suresh

Michael Lawson

Michael Lawson

Dominique Leblond

Dominique Leblond

Social Media Team
Jason Meserve

Jason Meserve

Riya Borkotoky

Riya Borkotoky

Vaulter’s Choice Award Winner

Joseph Nazaro

Joseph Nazaro

These Vaulters set an inspiring example of what it truly means to be a part of Commvault.

To learn more about what it is like to work at Commvault, check out our careers site.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery