Skip to content

At Commvault, fostering an environment of belonging is a top priority. A big part of this is our commitment to specialized learning and development programs to enable our Vaulters to be their best selves so they can continue to inspire and deliver.

As part of our Diversity, Equity, and Inclusion (DEI) efforts, we recently launched a women’s leadership training session, specifically designed to empower and engage women at Commvault. This program featured inspirational executive coach Sheryl Kline, founder of the Fearless Female Leadership Program.   

The impactful session focused on giving participants the right tools and information to build the mindset and influence to increase their visibility and impact. Attendees learned how to: 

  • Achieve higher levels of team, talent, and business impact. 
  • Leverage their unique gifts and experience.  
  • Drive greater impact in 2024 and create a plan to make it happen this year and beyond. 
  • Gain clarity, up-level confidence, and build strategic influence with leadership and customers. 
  • Use Sheryl’s powerful, science-backed curriculum to gain buy-in and move key initiatives forward.

And while the training session was virtual, many participants across the world gathered at our facilities to attend the program together.

We have so many inspiring and talented women at Commvault who continue to make an impact every day. Their hard work, resilience, and determination serve as a testament to the strength and capabilities of women in the workplace and beyond.  

Click here to learn more about our DEI efforts at Commvault. 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

At Commvault, we are committed to delivering exceptional customer experiences, and this dedication is reflected in our recent win at the Zinnov Awards 2024, where we were honored with the Excellence in Customer Centricity award.

Since joining Commvault, I’ve witnessed firsthand how crucial it is to simplify the complexities of our data-driven world. We are relentlessly focused on providing the solutions our customers need most: reducing complexity, maximizing their skills, better managing hybrid environments, and minimizing risks from advanced threats.

Our Commvault® Cloud platform is designed with you in mind. It streamlines cyber resilience processes while empowering you to maximize your skills and resources. With a unified approach across SaaS and software, we’re here to make your lives easier by not forcing you to choose. Commvault Cloud offers comprehensive data protection, management, and security capabilities, giving visibility and control across on-premise, private, and public clouds. In essence, we safeguard your data securely and efficiently manage it, no matter where it resides.

When it comes to resilience, we’ve got you covered. Our platform incorporates Metallic AI, an intelligent management and control layer that leverages a mix of artificial intelligence, machine learning, Natural Language Processing, and heuristics, to automate recovery processes while responsibly managing your data. Whether you’re dealing with cyberattacks, natural disasters, or a mishap, Commvault Cloud helps to keep your data safe and your business running smoothly.

Now let’s talk about the real game-changer – Commvault Cloud Cleanroom™ Recovery. This capability levels the playing field to enable hybrid enterprises to plan for, regularly test, and if need be, recover their environment following an attack.  

Check out our recent Cyber Recovery Readiness Report, which highlights key challenges and the solutions we provide to up your game in the cyber resilience landscape.

Lastly, our commitment to your success is also reflected in the experiences of our customers. A global leader in cyber defense relies on Commvault to stay ahead of fast-evolving cyber threats. Emerson Electric has fortified its cyber resilience and operational efficiency through our comprehensive solutions. An industry-leading manufacturer has leveraged Commvault to enhance its data protection and recovery strategies to provide a more robust defense against cyber threats.

To all our incredible customers, thank you for your partnership, your invaluable feedback, and trusting us. You are the heart and soul of Commvault, and we are honored to be part of your journey. Together, let’s continue to simplify, innovate, and be resilient in the digital world. Here’s to you!

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

For years, advancements in AI have revolutionized various aspects of daily lives and industries. AI has become an omnipresent force in how we communicate and in the services we use.

AI has emerged as a powerful tool for fortifying defenses in cyber resilience. It enables quicker response times, better-focused resources, reduced alert fatigue, and more time to focus on effective threat mitigation strategies.

However, alongside its undeniable potential, the rapid adoption and hype around Generative AI ignited a chorus of concerns surrounding privacy, transparency, and ethical considerations – and for good reason. The opacity of some AI algorithms, the potential for bias and discrimination, and the misuse of AI for malicious purposes have raised valid questions about the trustworthiness of this technology. 

Companies at the forefront of AI must adopt careful and intentional strategies in its development. This is why Commvault has established principles that embody our dedication to ethical AI development and deployment.

AI at Commvault

AI is not new to Commvault. For over a decade, we have leveraged emergent artificial intelligence, machine learning, and intelligent automation to enhance our platform’s capabilities. This AI improves data protection and recovery operations, and assists customers in managing risk, locating sensitive data, and more.

Metallic AI is our intelligent control layer that powers Commvault Cloud. From automation and machine learning to advanced AI, Metallic AI brings greater performance and efficiency to every aspect of the Commvault Cloud platform.

Building Trustworthy AI

As we harness the power of AI in our products and services, we are committed to upholding ethical standards and ensuring responsible AI deployment. This is why we have incorporated the best practices outlined by NIST AI RMF 1.0. These measures help our AI deployment to be responsible, safe, and secure so that our customers can leverage the benefits of AI.

Valid and Reliable: Predictable and Accurate Results

We prioritize the reliability of our AI by implementing testing, quality assurance, and security measures.We strive to provide predictable and accurate AI responses and recommendations by using unbiased data for training and collecting feedback from human users.  This feedback gathered through a simple like/dislike feature within our product and an option for more detailed user comments is crucial for the continual improvement of our AI and the accuracy of its outputs.

Safe: Human-Centric AI

A single decision can significantly impact the outcome of any scenario. Despite its power, AI often needs help grasping context as humans do because it misses the nuances involved in complex decision-making. Therefore, AI can only be trusted as one of the decision-makers, not a sole decision-maker. Humans should always maintain control, with oversight and accountability for actions taken based on AI-generated responses or recommendations.

Our AI is designed with safety mechanisms that allow for rapid response to unexpected behavior, always maintaining human control.

With this approach, we develop AI that enhances efficiencies and human potential and improves user experiences.

Secure and Resilient: Preventing Unauthorized Access

Our AI features are tightly integrated within the Commvault® Cloud platform, which restricts access to its functionalities from outside the platform. This means Commvault Cloud’s industry-leading security features are in place, including role-based access controls, which help prevent unauthorized access and keep systems secure and resilient.

We adhere to CIS Level 1 benchmarks to harden the infrastructure and minimize vulnerabilities. Additionally, we implement secure communications through encryption, loopback mode, and enforcement of client certification authentication.

Explainable and Interpretable: Understanding the What, How, and Why

AI should not be enigmatic black boxes. Instead, it should be transparent and understandable to all users and stakeholders. This means providing clear explanations for AI-generated responses and recommendations whenever appropriate. 

We feed controlled data into the AI and maintain logs of the data sources from which responses and insights are derived. For certain Generative AI features, including Arlie™ Chatbot and API Code Assist, we provide users with references to the sources from which the answer has been extracted.

Privacy Enhanced: Protecting Customer Data

Privacy concerns surround AI risk conversations. AI relies on access to data to provide informed recommendations and predictions, making it crucial to comprehend the nuances of privacy and data security measures. Users should understand what data is utilized to train AI or might be shared with third parties.

At Commvault, safeguarding the privacy and security of personal data and sensitive information is paramount. We embed privacy and security by design principles into our Software Development Life Cycle and adhere to stringent data protection measures in alignment with industry data security standards throughout the AI life cycle.

Unlike other vendors, we make sure that customer data is never used to train our generative AI features, maintaining a strict barrier to safeguarding all customer information.

We use pre-trained LLM from OpenAI, inputting relevant data into them as context to extract responses and recommendations. For instance, Arlie utilizes pre-trained LLM along with context from Commvault product and API documentation, user query, error codes, error descriptions, and anonymized customer support resolutions. Human supervision oversees our generative AI output to confirm anonymization.   

Fair: User Agnostic and Unbiased

Recognizing that AI can inadvertently perpetuate biases and discrimination, we take great care to design our AI to minimize biases and avoid discriminatory practices. We achieve this by training and testing our AI using diverse datasets that are agnostic to any specific user and do not contain protected characteristics such as race, age, or gender.

Accountable and Transparent: Driving User Confidence

Information about AI and its outputs should be accessible to those using it. This transparency and understanding fosters confidence among users in the AI.

We provide explicit AI entry points to make sure users are well-informed about AI intervention. We also establish a feedback loop, allowing users to provide input and contribute to the continuous improvement of our AI.


Offering Customer Choice to Opt in

Suppose your organization is still developing a strategy for Responsible AI and isn’t ready to implement Generative AI features. In that case, we provide the option to keep Arlie, the AI assistant for Commvault Cloud, inactive. For installed software, Arlie is not activated by default, offering customers the choice to activate or deactivate it anytime. In Commvault Cloud SaaS, while Arlie is enabled by default to improve the user experience, it does not perform any background data collection, maintaining customer data privacy. SaaS customers may opt out of using Arlie entirely if preferred.

Certain AI functionality, such as background-running machine learning used to flag anomalies, cannot be disabled. These AI features are local to each customer and do not interact with customer data.

Read Our Responsible AI Policy: commvault.com/legal/responsible-ai

Learn more about Metallic AI: commvault.com/platform/metallic-ai

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The average dwell time – an attacker’s time in your environment before detection or executing their attack – is 204 days. For nearly seven months, attackers move around stealthily, discovering valuable data, understanding your infrastructure and backup environments, and planting back doors that give them persistent access to your organization even if you find and block them.

Data protection requires shortening the time they have to tinker in your environment. This is the goal of most detection technologies that exist today. The problem, of course, is that most detection mechanisms generate far too many alerts to false-positive actions. This leads to wasted time and effort looking into things that are simply business as usual. It also causes major burnout for cybersecurity personnel who need to be at their best when combatting real cyber threats.

Combat alert fatigue by improving alert fidelity

Cyber analysts will agree that uncovering the needle in a haystack and thwarting an attacker is a real adrenalin booster. It’s why many people get into cyber investigations to begin with. Conversely, if you ask any analyst about the worst part of their job, it’s often responding to alerts that lead down rabbit holes to nowhere.

A good way to improve your security posture and employee morale is to invest in technologies that reduce tedious, rote tasks and stop your teams from chasing ghosts.

But tuning detection tools to find the signal in the noise is tricky. You don’t want to throw out true alerts with false positives, but you also don’t want your analysts to investigate alerts that aren’t real. So, finding a better signal is key.

Plant decoys in strategic places to trap attackers

A good way to get that better signal is to use deception technologies. These technologies employ decoy assets in your environment that are never seen by legitimate users. Since decoys and traps are invisible to real, authorized users, when interactions occur with these decoys, Threatwise automatically issues high-confidence, high-fidelity alerts that indicate the presence of a malicious actor.

This significantly cuts down on the noise from traditional security tools, allowing security personnel to focus on real threats. It minimizes the chance that Dave from accounting causes an alert by accidentally clicking on something he shouldn’t and increases the confidence that an alert was triggered by something that shouldn’t be there. These alerts can be seen in Commvault® Cloud and fed automatically to SIEM, SOAR, and other alert management tools to integrate seamlessly into your security operations workflows.

Where should you place traps? Near critical data

The kinds of traps and decoys you deploy in your environment should (1) look like they belong there, and (2) mimic things that an attacker would find appealing. To do both things, you need to place the decoys near data you want to protect and deploy enough of them that the chances that an attacker interacts with the trap and not the real data are high.

Historically, it’s been difficult to spin up enough decoys in your environment to effectively dupe attackers. But today, technologies like Threatwise can easily scale and deploy dozens or hundreds of decoys from a single system, increasing your odds of detecting the threat actor.

Add to that Threatwise Advisor, our intelligent assistant that takes into account the data you have in your environment and automatically recommends where and how many decoys you should place across your infrastructure. This makes it simple to deploy and manage, requiring far less maintenance than traditional deception technologies.

Strategically deploying decoys and traps near your most critical data improves your security posture. Using a system that already understands your data and its criticality allows for intelligent recommendations for placement that will yield the best results.

Get deep insight into an attacker’s tactics, techniques, and procedures

An added benefit to using Threatwise deception technologies and decoys to detect threats is that you also can use decoys as ways to gather threat intelligence into how an attacker operates.

You can trick attackers into thinking they’ve gained access by deploying real but innocuous decoy assets, complete with things like login screens and more. This allows you to monitor their behavior and gather valuable intel, like credentials they use or test. Early visibility helps you identify and respond to threats much faster, potentially before any damage is done.

Deploying deception technology as part of your proactive defensive measures yields better security. The technology can be tailored to reflect your organization’s specific architecture, infrastructure, and risks. It also can be deployed across a wide range of environments, including areas that traditional security tools might miss. This helps to eliminate blind spots in your defenses.

If you’d like to learn more about cyber deception, reach out to our sales team and we’d be glad to show you how it works, or start your own trial today.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

July is Disability Pride Month, which celebrates disabled persons embracing their disabilities as integral parts of who they are and commemorates the Americans with Disabilities Act, which was signed into law in 1990.

Disability pride means accepting and honoring each person’s uniqueness and seeing it as a natural and beautiful part of human diversity. This year’s theme, “We Want a Life Like Yours,” comes from The Arc’s National Council of Self-Advocates and reflects the disability community’s dreams for life experiences that they are too often denied.

As co-lead of Commvault’s CapAbilities Employee Resource Group (ERG), I wanted to share my perspective on what this year’s theme means to me and how we can honor and celebrate this community:

  • Start each day with a level of gratitude for the things I take for granted.
  • Lean in and listen to the stories of others who have struggled with disabilities and discrimination and learn how to be the change I want to see in the world.
  • Teach my children to acknowledge and include those with disabilities. I’m so proud to see my daughter living these values in her school and our local community – we see and hear how wonderful she is with the students in special education. We know this is partly because of the education we provide her, but also because of her amazing heart.
  • We are starting to build a hiring process and internal infrastructure to enable us to hire more individuals with disabilities and make the environment one where Vaulters can share their disability and be comfortable doing so.

Here at Commvault, celebrating Disability Pride Month demonstrates our commitment to diversity, equity, and inclusion (DEI) as we recognize, support, and celebrate our Vaulters with disabilities. It is our CapAbilities ERG’s mission to raise awareness and break down the bias of workplace issues that affect people with disabilities and/or caregivers of those with a disability. It is equally important to be an ally to our disability community to create an environment where all our Vaulters feel valued and respected. 

Click here to learn more about our DEI efforts at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

July is Disability Pride Month, which celebrates disabled persons embracing their disabilities as integral parts of who they are and commemorates the Americans with Disabilities Act, which was signed into law in 1990.

Disability pride means accepting and honoring each person’s uniqueness and seeing it as a natural and beautiful part of human diversity. This year’s theme, “We Want a Life Like Yours,” comes from The Arc’s National Council of Self-Advocates and reflects the disability community’s dreams for life experiences that they are too often denied.

As co-lead of Commvault’s CapAbilities Employee Resource Group (ERG), I wanted to share my perspective on what this year’s theme means to me and how we can honor and celebrate this community:

  • Start each day with a level of gratitude for the things I take for granted.
  • Lean in and listen to the stories of others who have struggled with disabilities and discrimination and learn how to be the change I want to see in the world.
  • Teach my children to acknowledge and include those with disabilities. I’m so proud to see my daughter living these values in her school and our local community – we see and hear how wonderful she is with the students in special education. We know this is partly because of the education we provide her, but also because of her amazing heart.
  • We are starting to build a hiring process and internal infrastructure to enable us to hire more individuals with disabilities and make the environment one where Vaulters can share their disability and be comfortable doing so.

Here at Commvault, celebrating Disability Pride Month demonstrates our commitment to diversity, equity, and inclusion (DEI) as we recognize, support, and celebrate our Vaulters with disabilities. It is our CapAbilities ERG’s mission to raise awareness and break down the bias of workplace issues that affect people with disabilities and/or caregivers of those with a disability. It is equally important to be an ally to our disability community to create an environment where all our Vaulters feel valued and respected. 

Click here to learn more about our DEI efforts at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Organizations worldwide have aligned their security strategies with the NIST Cyber Security Framework (CSF) because it offers a good way of breaking down the tactical needs of modern cybersecurity teams. The latest version, CSF 2.0, introduced an overarching category that had been sorely overlooked – Governance.

The key point to note is that the CSF is not necessarily meant to be a “start here, finish there” type of application. The goal is for organizations to invest in people, processes, and technology across the entire framework in a balanced way that reflects business risk.

The areas of focus for the CSF

Fig. 1: A diagram of the NIST Cyber Security Framework

“Identify” is a critical element because you can’t protect it or prioritize your efforts if you don’t know what you have. What’s critical? What’s regulated? What’s necessary for our business to function and generate revenue?

Most teams struggle with this element, especially with the prevalence of decentralized and shadow IT. Aside from the CSF, most other cyber frameworks and regulatory guidance require identifying and inventorying systems and data as a foundational step.

“Protect” is all about technologies deployed to prevent attackers from gaining access to data in the first place. This spans the gamut of tech from vulnerability scanners to identity and access management to antivirus and anti-malware.

These tools need to be configured properly and, most importantly, deployed across every device and system across the organization. This isn’t always the case. Sometimes, things are purchased on corporate P cards, not through IT. Sometimes, systems simply don’t update properly and thus are running out-of-date, vulnerable software.

“Detect” is about setting traps and ensuring alarms function when actions indicate something out of the ordinary. Unfortunately, many organizations have dozens of tools that generate millions of alerts to detect threat actors infiltrating their systems.

This massive influx of alerts that may or may not be truly something awry can cause alert fatigue – spending immense amounts of time chasing down possible anomalies only to learn they were a false-positive. This also diverts attention away from other alerts, which may be real threats.

Then we have the two Rs of the framework, “Respond” and “Recover.” These two cybersecurity areas are where your mettle is tested. Organizations will be breached. It’s not a matter of “if” but “when and how bad?”

To be good at “Respond,” teams need alignment on many fronts. Good leadership, solid strategy and tactics, great documentation and planning, and the most critical thing of all – practice.

For incident response, you will not rise to the occasion but rather fall to the level of preparation. Without practice and testing the processes you’ve built, you’re being set up for potential failure, or at least more stress than needed when an actual incident occurs.

“Recover” is where the rubber hits the road. Following the inevitable breach, it’s the job of everyone on the security and IT teams to get the systems and environments back to good. But to do so requires you to step back and think about how to do this safely, effectively, and without recovering the bad guys and everything they’ve poisoned.

Each element must be given the same level of rigor and attention to be effective. Unfortunately, that’s not always the case. Historically, organizations have focused most efforts and investments on preventing cyber incidents rather than establishing technology, processes, and strict workflows to abide by when a cyber incident occurs.

With data spread across hybrid environments, prevention is no longer adequate. Enterprises of all sizes seek peace of mind in a chaotic hybrid world. Security leaders and CISOs must adapt their strategies to address frictionless recovery and cyber resilience, and implement practices, processes, and technology around data cleanliness and recoverability.

Ransomware has changed the face of recovery. Due to increased cyber threats, security leaders are evaluating isolated recovery environments (IRE) to serve as clean and uninfected locations to recover to. However, with the nuanced type of attacks that occur, that IRE needs to be more than just a secure space. It is a part of the recovery process, but not all.

Commvault® Cloud Cleanroom™ Recovery is a comprehensive testing and failover offering, providing a safe, new IRE that promotes (1) testing cyber recovery plans, (2) conducting forensic analysis, and (3) business continuity in the event of a breach.

Pivot from preventive measures and invest in response and recovery

Whether you look at the CSF as a list, organizations have, for better or worse, started at the top or the right. The problem lies in the sequential nature of the work. Most organizations don’t get to Respond or Recover because they’ve spent all their time and money on Protect and Detect.

The fact that organizations have not spread their budget and resources over all sections of the CSF has meant that attackers still have the upper hand. When they get through your defenses and evade your detection, the typical cyber security team’s incident response can do an excellent job of investigating the breach but not much in the way of recovering from it.

You can’t always rely on the IT team’s backups

With the average dwell time of attackers in organizations standing at 204 days, chances are that the attackers have likely found, infiltrated, and possibly poisoned your backups. This is something we’ll cover in a future blog, but it’s absolutely worth noting here. When dealing with breaches, not only will your production data likely be tampered with, but more threat actors are actively seeking also to take down and compromise some of the efforts you’ve made to ensure that you can restore good copies of data. 

You can’t count on just blocking an IP address

Many tools respond to breaches by blocking IP addresses to kick attackers out of the network. This doesn’t work with the cloud anymore. They’ve found or bought legitimate credentials and/or infiltrated your identity and access management systems. So now they’ve become legitimate users.

In a word, you can’t trust anything

In a world where the phrase zero trust is thrown around quite a bit following a breach, there truly is and shouldn’t be any trust. Data needs to be scrutinized and checked for infection. Infrastructure needs to be rebuilt to ensure that only authorized folks are inside.

If you’re looking for ways to improve your organization’s cyber resilience, reach out to our sales team at Commvault for a consultation. We’ll discuss all elements that make up a good cyber recovery strategy to tailor to your business.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Unfortunately, breaches are far too common, affecting companies of all sizes across all industries. Like any dramatic experience, the experience of fighting through a breach reshapes how an organization behaves and prioritizes its actions. These were among the findings in our inaugural Cyber Recovery Readiness Report, a joint effort of Commvault and GigaOm.  

We surveyed 1,000 cyber security and IT leaders from countries around the world to better understand the global state of cyber recovery readiness and to get a clear understanding of how organizations remain resilient through the chaos and damage of breaches.

Our survey confirmed the prevalence of breaches, with 83% of our respondents reporting a material security breach: over 50% of these within the past year and more than 75% in the last 18 months. With breaches costing up to $12 million per day1, the ability to recover quickly is paramount.  

One significant finding across the data set is that there are many lessons to be learned from being breached. Organizations gain experience that changes their outlook, prioritization, and often, their maturity. As an example, organizations that experienced a breach are nearly 2.5 times more likely to rank understanding data risk profile, data classifications, and relative level of risk as a top priority for their cyber recovery strategy, compared to organizations that have not been breached. 

Overall, organizations that haven’t been breached have a narrower focus, citing the need to have critical data fully backed up and recoverable as a top three choice nearly 60% of the time. Organizations that have been breached place a premium on a wider set of practices, led by understanding their data risk profile and classifications.   

This tells us that once an organization has undergone a breach and understands the implications of what it takes to respond, its priorities shift. Those organizations have learned that there are key areas to incorporate that may be less obvious to those that haven’t been breached such as: communication with stakeholders, working with vendors, clear ownership, and division of responsibilities.  Those that haven’t been breached are primarily focused on speed alone. 

Breached organizations are also less satisfied with the status of their early warning tools compared to those that did not report a breach, suggesting a level of complacency in the unbreached group. 

Overall, those that have been breached prepare more comprehensively – they are more likely to have plans, and the plans they do have, they test more frequently. And in response to a breach, they equally prioritize more capabilities and activities vs. trying to do a few things well. 

Read the full report here.


1SolarWinds: Pingdom Team, Average Cost of Downtime per Industry, Jan 9, 2023.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In an era where cyber threats loom larger and more complex than ever, the 2024 Cyber Recovery Readiness Report, a collaborative effort between Commvault and GigaOm, provides critical insights and actionable intelligence to guide CISOs, CIOs, and IT and security decision-makers through the evolving landscape of cyber resilience. 

Our comprehensive survey of 1,000 cybersecurity and IT leaders from across the globe reveals a stark reality: 83% of organizations have experienced a material security breach, with over 50% occurring in the past year alone. This prevalence underscores the urgent need for robust cyber recovery strategies that require a broader spectrum for practices that go beyond traditional disaster recovery plans. 

Key Findings:

Markers of Maturity 

While organizations may cite specific measures as priorities, it’s how they behave that truly matters. While the most resilient organizations employ many measures to boost recovery readiness, we saw five practices rise to the top when determining true readiness: 

  1. Security tools that enable early warning about risk, including insider risk. 
  2. A known-clean dark site or secondary system in place. 
  3. An isolated environment to store an immutable copy of the data. 
  4. Defined runbooks, roles, and processes for incident response. 
  5. Specific measures to show cyber recovery readiness and risk. 

An organization’s level of cyber maturity can be measured by the presence of these five markers. The most mature, cyber-ready organizations demonstrate four or five of these. In the case of cyber readiness, cutting corners can undermine success. 

Cyber Maturity and Confidence 

Only 4% of surveyed organizations have deployed all five markers of cyber recovery readiness, yet these markers are crucial for rapid recovery and resilience. Organizations with higher levels of cyber maturity report significantly greater confidence in their recovery capabilities, with mature organizations recovering 41% faster than respondents with only zero or one marker, and 24% faster than those with two or three markers.  

Challenges in Cyber Recovery 

The top challenges faced by organizations today include the complexity of critical applications and data, the cost of implementing robust recovery solutions, and a lack of clear responsibility for driving cyber resilience strategies. 

Prioritize Regular Testing 

Frequent and regular testing of cyber recovery plans is indispensable for ensuring readiness and resilience. Our findings reveal a significant disparity in testing practices between breached and non-breached organizations. While only 2% of organizations that have experienced breaches neglect testing their recovery plans, a concerning 20% of those never breached fail to test at all. A proactive approach in rigorous testing helps these organizations refine their recovery processes and maintain high readiness levels against potential cyber threats. 

How to use our report

The 2024 Cyber Recovery Readiness Report serves as a roadmap for enhancing cyber resilience, providing leaders with the insights needed to fortify their organizations against the inevitable challenges of the digital age. By understanding the landscape, acknowledging the risks, and implementing recommended practices, your organization can achieve a state of readiness that not only protects but also empowers. 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Throughout June, we’ve celebrated Pride Month across our global Vaulter community with open dialogues and educational initiatives hosted by our PRISM Employee Resource Group (ERG) and Diversity, Equity, and Inclusion (DEI) team.

Pride Month is a time dedicated to celebrating the LGBTQ+ community as a member or ally to honor and recognize their impact throughout history and raise awareness to foster equal justice and opportunity. Here at Commvault, we believe that cultivating a culture of belonging, respect, and care makes us a more sustainable and resilient company where all our Vaulters can thrive.

We celebrated Pride across our global Vaulter community with various activities, discussions, and resources, and concluded our celebrations with a virtual Courageous Conversation hosted by Chief People Officer Martha Delehanty and VP of Corporate Communications Ross Camp, Co-Executive Sponsors of our PRISM ERG.

During the conversation, Martha and Ross discussed the importance of belonging in the workplace and the role leadership plays in encouraging unique perspectives and understanding intersectionality. Ross also shared his personal experience of coming out to his family and embracing his authentic self. As a proud member of the LBGTQ+ community, Ross has experienced homophobic biases in and out of the workplace, which has made him a passionate supporter of DEI. Ross shared his perspective on what it truly means to be your authentic self and why Pride must go beyond lip service – read it here.

We are proud to show our allyship and support to our Vaulters and the extended Commvault LGBTQ+ community during Pride Month and year-round. 

To learn more about our DEI efforts at Commvault, click here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Welcome to a pivotal moment in the evolution of cyber resilience. Since the inception of The Collaborative in early 2024, our mission has been clear: to forge strong partnerships with analysts, industry leaders, and visionaries like you, to deeply explore and enhance cyber resilience across diverse organizations. Our foundational report, “Seven Emerging Trends in Cyber Resilience,” has already set the agenda for this year, addressing critical areas as we confront the escalating ransomware menace. 

We are excited to announce the release of the 2024 Cyber Recovery Readiness Report, a collaboration between Commvault and GigaOm. Your leadership and expertise in IT and security are crucial in steering the future toward enhanced cyber resilience. This report is crafted to equip you with essential insights and data, empowering your organization to stay ahead in an increasingly volatile cyber landscape. 

The insights we share are derived from an extensive survey of 1,000 global cybersecurity and IT leaders. This report not only offers a worldwide view of the challenges but also pinpoints effective strategies essential for cyber recovery readiness. It underscores the critical need for comprehensive cyber recovery strategies that surpass traditional disaster recovery plans. 

Key Findings: 

– A staggering 83% of organizations have suffered a material security breach recently, with over half occurring in the past year alone, underscoring the critical need for advanced preparedness and agile response strategies. 

– The most resilient organizations share common practices that significantly enhance their recovery readiness. Our analysis reveals that the most prepared organizations exhibit at least four out of five key markers of maturity. 

– There is a clear correlation between cyber maturity and recovery speed. Organizations with higher levels of cyber maturity recover from breaches 41% faster than those less prepared. 

– Regular testing of cyber recovery plans is not just beneficial; it is essential. Our data shows a marked difference in testing frequency between organizations that have experienced breaches and those that have not. 

Recommendations: 

1. Regularly test and enhance your recovery plans. Frequent drills and updates ensure that your organization can respond swiftly and effectively to any cyber incident. 

2. Prioritize building cyber maturity by adopting the identified markers of cyber recovery readiness. This not only mitigates risks but significantly lessens the impact of potential breaches. 

3. Develop a holistic cyber recovery strategy that extends beyond mere data backup to encompass full system recovery, ensuring comprehensive business continuity. 

We invite you to delve into the report and integrate these insights and recommendations into your strategic planning. Our goal is not merely to inform but to inspire decisive action that will robustly fortify your organization against future cyber threats. 

We are here to support you on this journey toward unparalleled cyber recovery readiness. 

Thankfully, 

The Collaborative 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Here at Commvault, we’re proud to observe the Juneteenth holiday to commemorate history and celebrate African American culture.

Juneteenth is celebrated in the United States on June 19 to honor the emancipation of enslaved African Americans in the United States and pay tribute to those who fought for change. Recognizing and honoring the importance of African American culture in the fabric of our multi-culture society is a thread in cultivating a diverse, equitable, and inclusive society.

Within our global Vaulter community, we continue to honor the theme “Equity in Action” to reinforce our values that embrace diversity and honor the history of those who came before us.

Our Diversity, Equity, and Inclusion (DEI) team and Multi-Culture Employee Resource Group (ERG) create space for conversations around diversity and inclusion in the workplace. During our global Black History Month this past February, we partnered with UNCF for one event and another event with the Black employees at Microsoft (BAM) ERG – Miami, Florida Chapter with featured speaker former NBA player, Baron Davis, for a Courageous Conversations on combating bias in the technology industry. Our goal is to pave the way for discussions that create awareness on topics close to our hearts. As we always say – you have to have the conversation to change the conversation! This is a key part of our global culture and core values.

By embracing the stories and experiences of the Black community, we aim to cultivate a workplace that promotes equity, understanding, and unity among all Vaulters, especially regarding our African American Vaulters.

To learn more about our DEI and belonging efforts at Commvault, click here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

At Commvault, our values – Connect, Inspire, Care, Deliver – are the bedrock of our culture and guide everything we do.

This week, we hosted our FY25 Q1 COE Town Hall meeting, where we proudly presented the FY24 Q4 COE Awards winners. We recently formalized our R&R awards globally, making this our way of recognizing the exceptional contributions of our team members who embody our values every day.

I am delighted to announce our FY24 Q4 COE Award winners:


Q4 Vaulter’s Value Awards

Platinum:

  1. Mohammed Haji – Finance

Gold:

  1. Manoj Kumar – Development
  2. Darshil Dipen Shah – Development
  3. Avinash Sharma – Development
  4. Chinmay Gujar –  Development
  5. Sai Ganesh Vineeth Gola – Development
  6. Konda Sai Prakash – Development
  7. Pankaj Kumar – Development
  8. Rashid Anwar – Customer Support
  9. Vigneshwar G – Customer Support
  10. Shreyas Urs – Business technology
  11. Rupa Singh – Services
  12. Lingaiah Koorakula – Finance

Silver:

  1. Akshaya Srinivasan– Development
  2. Utkarsh Gupta – Development
  3. Jagamohan Singh – Development
  4. Prachurja Basistha – Development
  5. Varun Bharadwaj – Development
  6. Harshavardhan T – Development
  7. Aakash Chakravarthy – Development
  8. Balaji C – Development
  9. Priyanshu Varshey – Development
  10. Vankayala Sri Manjari – Development
  11. Ankit Goyal – Development
  12. Rohit Siripuram – Development
  13. Swatish Attaluri – Development
  14. Kustapuram Dileep Reddy – Development
  15. Sri Sai Ram – Development
  16. Karthik Natarajan – Development
  17. Manojkumar Waghmare – Development
  18. Chandrakant Agarkar – Development
  19. Srinivas Kundaram – Development
  20. Sathish R – Customer Support
  21. Keshika Bisht – Customer Support
  22. Suleman Pasha M D – Customer Support
  23.  Mohammed Shahbaaz – Customer Support
  24. Jestin Jacob Cherian – Customer Support
  25. Soumyadip Chatterjee – Customer Support
  26. Pradeep Kumar S – Customer Support
  27. Sushma Patil – Customer Support
  28. Akhilesh Kumar – Business Technolody
  29. Rahul Chimbili Ramamurthy – Business Technology
  30. Lenin Ponappa – Sales Engineering
  31. Sourabh Bhat – Sales Engineering
  32. Yogesh Ahuja – Services
  33. Vikas Anjaneya – Services
  34. Shashank Kant – Services
  35. Sukrit Dineshkumar – Services
  36. Francis Ashvi – Enablement
  37.  Nagalakshmi S – Facilities
  38. Rakesh Vadhanan – Marketing

Bronze:

  1. Prateek Jain – Development
  2. Misha Bharti – Development
  3. Akash Kumar – Development
  4.  Aditya Sai R – Development
  5. Varun Kumar Reddy – Development
  6. Murtaza Raja – Development
  7. Shraddha Sheelwant – Business Operations
  8. Jagdish G – Business Operations
  9. Ragavi A – Business Operations
  10.  Nitin Singh – Business Operations
  11. Ashish Paul V – Customer Support
  12. Swati Viraj Kolhapure – Customer Support
  13. Dasari Sareen Kumar – Customer Support
  14. Veer Patil – Customer Support
  15. Sridhar M – Customer Support
  16. Aniket Vinze – Customer Support
  17. Vishu Ahuja – Customer Support
  18. Sudev Sundar – Services 
  19. Anand VR – Services
  20. Srinivasa Rao – Services
  21. Ranjith Kumar – Business Technology
  22. Rajeshwari C – Business Technology
  23. Abhinav Patri – Business Technology
  24. Preetham Mutyala – Business Technology
  25. Trisha Goswami – Enablement
Create ’24 Summer Edition Awards

First Prize: Vidlie

  1. Aniket Prabhu
  2. Sai Vishnu Raju Chebolu
  3. Ujjwal Kumar Verma
  4. Kavalakuntla Sudheer Reddy

Second Prize: AI Insights

  1. Aakash Chakravarthy
  2. Saurabh Rajani
  3. Siddhanth Kushwaha
  4. Manoj Kumar G
  5. Virakti Jain

Third Prize: Shift In File Indexing

  1. Somesh Kumar
  2. Naveen Kedilaya
  3. Prateek Jain
  4. P. Rakshith Shenoy
  5. Venkatesh Maharajan
  6. Aman Jhajj
CPO Award: LOG SUMMARIZER
  1. Aditya Ray
  2. Pranav Prashob
  3. Anish Mahale
  4. Nishtha Malik
CYBER HUNT Winner:

First Prize: SHOULDWARNERAPPLYFORAADHAR?

  1. Swatish Attaluri
  2.  Rakesh Sharma Rallapalli

Second Prize: TeamSSH

  1. Srinivas Kundaram
  2. Sudheer Chigullapally
  3. Harihara Kumar Jannu
  4. Chiranjeevi Marella

These winners exemplify what it truly means to be a Vaulter, setting an inspiring example for us all.

At Commvault, we believe deeply that “You Matter.” This ethos underscores our commitment to recognizing and celebrating the outstanding efforts of every member of our team. Through initiatives like these, we reaffirm our appreciation for those who consistently uphold our values and contribute to our collective success.

To learn more about what it’s like to work at Commvault, visit our careers site.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Here at Commvault, we’re committed to giving back to our communities and driving forward our passion for educating and mentoring the next generation, specifically in STEM.

We are honored to have a longstanding partnership with the National Merit Scholarship Program by National Merit Scholarship Corporation (NMSC), an independent, not-for-profit organization. Each year, Commvault sponsors scholarships through the National Merit Scholarship Corporation for children of U.S.-based Vaulters who will enter college in the fall.

Scholarship recipients are selected by a NMSC committee based on academic record, scores on the PSAT/NMSQT, student’s essay, demonstrated leadership, and contributions to school and community activities, and a school official’s written recommendation and characterization of the candidate.

This year, we’re thrilled to announce Aarav Kumar as the winner of Commvault’s 2024 Corporate-Sponsored Merit Scholarship.

Aarav is a graduating senior at Biotechnology High School, a magnet school in New Jersey with a rigorous STEM curriculum and focus on life sciences. Throughout his high school journey, Aarav has studied these disciplines by pursuing academic studies, internships, research, and other extra-curriculars, including leadership in these subject areas.

In the fall, Aarav will attend the Dyson School at Cornell University, where he will major in Applied Economics and Management with a concentration in finance as a Rawlings Presidential Research Scholar.

Aarav has many fond memories of Commvault from his childhood. Throughout his elementary school years, Aarav often visited our Tinton Falls, N.J., headquarters with his mom, Mridula Kumar. He attended events such as Take Your Child to Work day, which included STEM workshops like Kids Coding and Your PC: How It’s Made, to name a few.

Like many of our Vaulters, Aarav enjoyed the slide, playing ping pong and foosball in the lounges throughout the building, visiting the on-site cafeteria, and just generally hanging out with his mom and the Engineering department.

Mridula Kumar is a Lead Engineer in our SaaS Engineering department and has been with Commvault for 16 years. When she was notified that Aarav had won this scholarship, she said, “Commvault does a fantastic job of introducing children to STEM, and we do so in a fun way. I am very happy and excited that Aarav has been awarded the Commvault National Merit Scholarship. I’ve seen Aarav work hard over his four years of high school and consistently excel in whatever he does, so seeing his hard work receive this level of recognition makes it all worthwhile.”

We congratulate Aarav on winning Commvault’s 2024 Corporate-Sponsored Merit Scholarship and wish him good luck at Cornell.

We’re proud to cultivate a culture where investing in the next generation of leaders is a key priority.

Learn more on what it’s like to work at Commvault here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

As evident with Commvault’s recent Secure by Design Pledge, we are committed to providing our customers with a secure platform to help manage risk and remain resilient in today’s digital landscape.

In the ever-evolving cybersecurity space, threats are becoming more sophisticated and widespread. Securing privileged access has emerged as a critical imperative for organizations. Privileged access refers to elevated permissions and rights granted to certain users or accounts within an IT environment, often with the ability to delete, edit, reconfigure, or destroy parts of infrastructure or data.

In a study of more than 750 enterprises, Oracle found that more than 37% of them had accounts in their organization that were over-privileged, causing significant risk. These identities have the potential to wield significant destructive power, especially when privileged accounts are compromised. According to the 2023 Verizon Data Breach Investigation Report, around 50% of all breaches involve compromised credentials, so the threat is imminent and has become especially prevalent in the era of social engineering and spear phishing.

What Is Multi-Person Authorization?

MPA is a Zero Trust security measure that enforces a tiered approval process for privileged actions. In following Zero Trust architecture principles, an MPA process assumes the user is not trusted, regardless of their associated capabilities. A quorum of authorized approvers must approve the request before allowing the action to be submitted.

What Is Compliance Lock?

Compliance Lock allows organizations to enforce software immutability by protecting data from deletion and retention changes. It keeps your organization “compliant” to whatever policies you put in place to protect the data. Once configured, Compliance Lock is enabled on Commvault storage, so all associated plans and data are locked in and protected in accordance with the customer’s retention policies.

Why Are MPA and Compliance Lock Important?

Privileged actions are sometimes required for us to do our jobs effectively, but there must be checks and balances in place. MPA restricts privileged actions for certain tasks “just-in-time” (only as needed for a specific task), while Compliance Lock helps organizations retain their data for the defined retention period. This reduces the risk of exposure to destructive actions by accident or by a malicious insider threat.

What Does Commvault’s MPA Solution Provide?

Commvault has offered MPA controls and Compliance Lock for several releases, managed as an opt-in security control within the Security IQ dashboard. Commvault’s MPA is available across the entire Commvault cloud estate (software and SaaS). We provide MPA for data deletion, and data recoveries within the Command Center, CommServe Console, and API and CLI interfaces. Compliance Lock is available as a software immutability option that is configurable on storage targets. This is often used alongside storage level immutability/WORM options. Both security features provide a multi-layered security approach.

When Will MPA and Compliance Lock Be Available?

Commvault will enable MPA for actions that may cause bulk data deletion and compliance lock for AGP storage by default starting with release CPR 2024E (11.36) and above. This is expected to go live for Tech Preview on June 15, 2024.

Once MPA is enabled, data deletion will no longer be processed immediately. Instead, it will send out an email request to all approvers to authorize the request. Approvers can approve or deny the request by clicking the appropriate link in the email or by submitting the response within the Approvals dashboard in Command Center. The deletion request will not be submitted for processing until enough approvals have been submitted.

Compliance Lock will only be enabled by default for AGP storage. Once enabled, all apps and servers associated to the Compliance Lock storage will be locked from deletion. Retention policies cannot be changed as well.

These new controls could have operational impact for users during certain administrative maintenance periods, but, as with many other security controls, the benefits to the safety of your data far outweigh the minimal operational impact that might occur.

For deeper information on the requirements and flow for Commvault’s MPA solution, see the Commvault documentation.

Continuing to Help Build Your Cyber Resilience

At Commvault, we continuously evaluate the threat landscape, so we can build solutions and provide smart defaults to secure your digital estate. We strive to be your trusted partner as you navigate this complicated world of cyberthreats. And as your partner, we will help you achieve true cyber resilience powered by the Commvault Cloud platform.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

When I first interviewed last year with Martha Delehanty, Commvault’s Chief People Officer, the discussion took an interesting turn. I was interviewing for the role of Vice President, Corporate Communications, but communications was not the topic du jour. Instead, we discussed the importance of diversity, equity, and inclusion (DEI) and what that means at Commvault. At this point in my life, that really matters to me.  

These days, you frequently hear companies talking about “bringing your authentic self to work” but what does that really mean? It almost sounds cliché, like HR speak or fancy lip service. For me, it means being able to openly and directly ask about LBGTQ+ issues during a job interview. Being able to openly reference my same-sex partner during a team call or in a 1:1 discussion with my CEO.

It means not having to change pronouns when referencing my partner at a sales conference or company offsite. And, it means knowing that my company is going to have my back by supporting LBGTQ+ employees and our allies year-round, not just when it works for the company’s PR image. Fortunately, Commvault is truly a place where you can bring your authentic self to work. I never take that for granted. Not for a minute.  

Like so many people I know, I’ve been down that horrible road where LBGTQ+ issues and causes were not supported, discussed, or even remotely accepted at the workplace. In a previous life, I vividly remember walking into a new place of employment, meeting a top company executive and hearing him tell my direct supervisor that he was happy they didn’t hire a “fag” for the job.

I knew if I ever wanted a shot at getting promoted, or for that matter, keeping my job, I had to keep my mouth shut and my private life private. I never intend to go back down that road. I take too much pride in who I am and want to work for a company that takes pride in me.  

There’s been a lot of progress on LBGTQ+ issues, not just on the employment front, but across so many areas of life. There are many more out and open LBGTQ+ leaders being elected to office. Our LBGTQ+ policies in the U.S .military have evolved. And there is greater focus on non-discrimination practices for members of the LBGTQ+ community on fundamental issues like housing.  

But, for every two steps forward, it often seems we take three steps back. For example, the transgender community is under attack. ABC news reported in November that “thirty-three transgender and gender-nonconforming people have been killed by violence in the United States since last year’s Transgender Day of Remembrance on Nov. 20, 2022.”

That’s horrifying. And, for what? For living their lives authentically? Who are they hurting? What if that was your child, sibling, or friend? These types of challenges facing the LBGTQ+ community go well beyond U.S. borders. In many nations, just getting outed can lead to public humiliation, jail time, or death. This is why a continued focus on Pride is so critical, and why this focus must go beyond lip service.  

Ross Camp (right) with his fiancé, Jeff Braverman

I remain optimistic for many reasons. First, I feel like I have the right to love unapologetically. Jeff Braverman, my longtime partner of nearly 12 years, asked me to marry him as we stood next to a majestic bayou in my home state of Louisiana.

I immediately said yes. How could I not? He’s the love of my life. We’re getting married in the fall. Twenty years ago, I never thought marrying my same-sex partner would be possible. Now it is. We will see if that national right continues to prevail.

Second, I work for a company that supports me and embraces who I am. That’s huge. And third, I see more communities standing up for equality. Yes, there is a lot more work to do, but today, I’d like to celebrate our successes. I wish all members of the LBGTQ+ community globally and our allies a happy Pride! 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

At Commvault, fostering an environment of belonging is a top priority. Our DEI approach focuses on promoting and incorporating diverse, inclusive, and equitable practices throughout the organization. One key highlight is our dedicated DEI team, which partners with leadership and employees globally to drive our DEI strategy and support programs. Together, we’re delivering on our commitment to cultivating a culture of belonging.

We continue investing in inclusive leadership development and have implemented an inclusive recruiting strategy to increase the hiring of women and candidates from underrepresented groups. Our employee groups play a vital role in driving engagement to discuss, advocate, and champion their respective beliefs and identities within our organization and in society. Currently, we have seven vibrant employee groups, including five Employee Resource Groups (ERGs) and two Employee Affinity Groups (EAGs):

  • Multi-Culture ERG
  • Women in Technology ERG
  • CapAbilities (Disability Inclusion) ERG
  • PRISM (LGBTQ+ and Allies) ERG
  • VALOR (Veterans and Allies) ERG
  • Family Support Network EAG
  • Environmental EAG – Vaulters Advocating for Sustainability in Tech 

Throughout the year, our DEI team collaborates with employee groups to build community through “Equity in Action” events that are open to all employees virtually. Recent examples include:

  • The CapAbilities ERG (Disability Inclusion) hosted an event in 2024 on Neurodiversity and Neuroinclusivity in the Workplace, featuring Holly Foxcroft, Head of Neurodiversity in Cyber Research and Consulting.
  • The VALOR ERG (Veterans & Allies) organized a Veterans Day 2023 event with Alex Janas, Commvault Field CTO and Former Marine, along with the Wreaths Across America campaign.
  • For Hispanic Heritage Month 2023, we had a speaker event with Pico Velásquez, founder and CEO of VIIRA (Computational Architect and Artificial Intelligence).
  • During Black History Month 2024, we partnered with the United Negro College Fund for an event focused on Combating Bias in Tech

To further our DEI journey, we offer a variety of micro-learning courses covering topics like DEI Fundamentals, Inclusive Workplace Best Practices, Gender Essentialism, Intersectionality in the Workplace, Visible, Invisible and Hypervisible Identities and Religious Inclusivity. 

Our annual Commvault Cares program provides another opportunity to give back and raise awareness for causes close to our hearts. In 2023, we provided over $25,000 in philanthropic support to organizations selected by our employees and global charities like the American Red Cross and United Negro College Fund (UNCF).  Caring is at the core of who we are, and we’re committed to giving back to communities where we live and work through financial contributions and volunteering.

Additional impactful initiatives from the past year include partnering with non-profits like Building Blocks in India to sponsor their school for underprivileged children, distributing educational books and supplies through Help Educate a Child NGO, crafting festival greeting cards for underserved students with Team Everest, and teaching cyber safety to school kids in collaboration with Teach for India.

Commvault remains committed to cultivating a diverse, equitable, and inclusive workplace where every voice is heard and valued. We’re excited to continue this important journey together.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

World Environment Day puts a global spotlight on the pressing environmental challenges of our times and has become the largest global platform for environmental outreach, with millions of people from across the world engaging to protect the planet. This year’s World Environment Day campaign focuses on land restoration, desertification, and drought resilience under the slogan Our land. Our future. We are #GenerationRestoration.  

As Co-Executive Sponsors of Commvault’s Environmental Employee Affinity Group (EAG), we’re excited to celebrate World Environment Day with the launch of our 2024 Environment, Social, and Governance (ESG) Report. This year’s report marks a pivotal step in Commvault’s commitment to climate action and resilience.  

We’re proud to share key highlights from our environmental focus in this year’s report:  

  • We recognize the growing risks associated with climate change and the need for businesses to enhance their resiliency. 
  • We completed our inaugural Greenhouse Gas (GHG) emissions assessment in FY 2024, providing a comprehensive baseline to guide our environmental objectives. 
  • The assessment followed the USA Environmental Protection Agency (EPA) Center for Corporate Climate Leadership Standards, the Greenhouse Gas Protocol Corporate Standard, and the Greenhouse Gas Protocol Corporate Value Chain (Scope 3) Standard. 
  • We identified three key climate change-related developments material to our business: extreme weather events, data center energy usage, and corporate emissions. 
  • Our Scope 1 emissions are 373.2 MT CO2e, Scope 2 emissions are 10,301.8 MT CO2e, and Scope 3 emissions are 3,631.4 MT CO2e. 
  • With drought resilience as a key theme for this year’s World Environment Day, we are proud to confirm that our primary datacenter is not in a high-stress water region. 
  • We are committed to developing a climate action program to address emissions, mitigate our exposure to climate induced events, and remain compliant with emerging regulations across jurisdictions. 
  • We have adopted a dynamic materiality approach to align with the pace of change in environmental realities and regulatory landscapes.

We believe that it is our responsibility, as humans and as a company, to contribute to a healthier and more sustainable world. Commvault’s Enivronmental EAG continues to create a space for Vaulters with a passion for environmental sustainability. We strive to be champions of environmental conservation and to increase awareness for environmental issues within Commvault, our industry, and our communities.  

Commvault’s 2024 ESG Report is an encouraging example of our commitment to climate action and resilience! To learn more about our Environmental EAG, as well as Commvault’s other employee groups, click here

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery