Skip to content

Cyberattacks have evolved into a pervasive and sophisticated threat, posing a significant danger to organizations of all sizes. The ever-changing nature of cyber threats necessitates a new way of thinking when it comes to cyber resilience. Despite deploying the best perimeter security out there, the odds of bad actors getting in are very high. With that in mind, how can you help ensure that you can quickly recover when that day comes and, equally as important, how can you TEST your recovery in advance to make sure your plans are going to work?

Cleanroom Recovery, introduced in November and available today supporting software virtual machine (VM) workloads, gives organizations the knowledge to help avert attacks, defend against bad actors, and restore environments to a secure state.

But, Cleanroom Recovery also provides a safe and isolated environment where organizations can easily test their cyber recovery plans without disrupting production systems. This environment allows organizations to identify and address gaps in their plans before an actual attack occurs. Cleanroom environments also provide forensic analysis of known infected systems and provide analysis that helps organizations understand the root cause of the attack—critical information to prevent future incidents.

Cleanroom Recovery should be a primary pillar in every organization’s cyber resilience strategy.

Today’s Cyber Recovery Reality: It’s Not Easy

The frequency and severity of cyberattacks have escalated dramatically in recent years, posing a substantial threat to organizations across all industries. These attacks can have devastating consequences, including data breaches, financial losses, and irreparable reputational damage.

In a recent survey by The Futurum Group 98% of respondents indicated that data recoverability influences their resilience against ransomware attacks, with three-quarters of respondents suggesting that it is very or critically influential. Effective cyber recovery is crucial for organizations to minimize downtime, restore business operations, and safeguard their reputation after a cyberattack. However, many organizations struggle to adequately testtheir cyber recovery plans, leaving them vulnerable to real-world attacks.

In the evolving hybrid world, organizations must adhere to different legislative mandates that come into play. Specifically, the National Institute of Standards and Technology (NIST) and Digital Operational Resilience Act (DORA) frameworks have become top of mind for organizations. These legislative practices are mandating the requirements for testing, putting the responsibility on enterprises to be prepared with continuous testing that will help organizations avoid massive penalties and fines.

Organizations must continuously test their recovery approach to ensure a frictionless, rapid return to business operations.

https://play.vidyard.com/Yz7D3oyrUPoTpuEHMTWZzb
Watch our Cleanroom Recovery webinar to learn more.

The Limitations of Current Cyber Recovery Testing Approaches

Traditional cyber recovery testing methods, such as tabletop exercises, often fail to adequately prepare organizations for the complexities and chaos of real-life cyber recovery scenarios. These exercises typically involve discussions and simulations that lack the realism and urgency of an actual attack.

Moreover, testing cyber recovery plans in hybrid environments can be time-consuming, complex, and expensive. With workloads spread across multiple clouds, on-premises hypervisors, and physical servers, organizations must perform testing within each environment separately. True cyber resilience isn’t solely a technological threshold that enterprises must hurdle; organizations must also understand its role in achieving true resilience.

With multiple teams and different silos, this is as much a business-critical endeavor as it is a technological necessity. Traditionally, IT domains operated separately, but for true cyber resilience, technology teams and lines of business must collaborate and converge efforts. Top-level executives must mandate organizations to build cyber security awareness and adopt best practices to ensure rapid recovery.

As business culture evolves to encourage more and more collaboration across teams, today’s organizations are ready to embrace cleanroom recovery.

Commvault Cloud Cleanroom Recovery

In the face of the constant threat of cyber breaches, successful recovery hinges on the diligence of cyber testing and cyber resilience strategies.

Commvault Cloud’s Cleanroom Recovery addresses a critical need for cyber readiness by providing a comprehensive testing and failover solution that enables organizations to more effectively mitigate risk.

Key features of Commvault Cloud’s Cleanroom Recovery include:

  • Comprehensive testing environment: Cleanroom Recovery provides a safe and isolated environment where organizations can test their cyber recovery plans without the risk of disrupting production systems.
  • Secure forensic analysis: Cleanroom Recovery can be used to conduct forensic analysis of known infected systems and identify the root cause of an attack.
  • Faster recovery times: Cleanroom Recovery can help organizations recover from cyberattacks more quickly by providing a streamlined recovery process.
  • Reduced downtime: Cleanroom Recovery can help organizations minimize downtime by providing a production failover solution.

Cleanroom Recovery provides a safe and isolated environment for testing cyber recovery plans, conducting forensic analysis, and ensuring business continuity if a breach does occur. Cleanroom Recovery can help organizations improve their cyber resilience by providing benefits such as:

  • Reduced risk of re-infection: Cleanroom Recovery provides a safe and isolated environment where workloads can be recovered without the risk of re-infection.
  • Enhanced security: Cleanroom Recovery can be used to identify and address security vulnerabilities in cyber recovery plans.
  • Simplified failover: Cleanroom Recovery can serve as a production failover solution in the event of a breach, ensuring that production operation recovery is conducted within a sanitized environment.

Use Cases for Cleanroom Recovery

Organizations can apply Cleanroom Recovery in several scenarios today to help ensure business operations continue without incident in the face of cyberattacks.

Testing Cyber Recovery Plans in a Hybrid Environment

Cleanroom Recovery simplifies and streamlines the process of testing cyber recovery plans in hybrid environments. With its any-to-any portability feature, Cleanroom Recovery allows organizations to recover workloads from multiple clouds, on-premises hypervisors, and physical servers to a common environment within the cleanroom. This eliminates the need to perform testing within each environment separately, saving time and resources.

Forensic Analysis of Known Infected Systems

In addition to cyber recovery testing, Cleanroom Recovery provides a secure environment for conducting forensic analysis of known infected systems. This analysis can help organizations identify the root cause of an attack, understand how the attackers gained access to their systems, and take steps to prevent future incidents.

Production Failover in the Event of a Breach

Cleanroom Recovery can serve as a production failover solution in the event of a breach. This means that if a cyberattack disrupts an organization’s production systems, it can quickly and easily recover its workloads to a clean environment within the cleanroom. This can help organizations minimize downtime and get their business back up and running quickly.

Failure is Not an Option

In today’s dynamic cybersecurity landscape, organizations must proactively address the ever-increasing threat of cyberattacks. Commvault Cloud’s Cleanroom Recovery is a powerful tool for organizations to enhance their cyber resilience by providing a comprehensive testing environment, secure forensic analysis capabilities, and a production failover solution. By adopting Cleanroom Recovery, organizations can confidently test their cyber recovery plans, identify and remediate vulnerabilities, and ensure business continuity in the face of cyberattacks.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Ransomware thrives in uncertainty. Resilience suffers. Keeping your business online and fighting through an attack is stressful enough. Uncertainty and chaos should not come from vendors who proport to help maintain resilience.

The latest industry consolidation news with Cohesity announcing its intention to acquire Veritas’ data protection unit is causing uncertainty and doubt for their customers — and for good reason.

Merger Pitfalls for Veritas + Cohesity Customers to Avoid

This merger brings disconnected platforms, with disconnected approaches, and dissonant cultures, to try to address a single problem: maintaining resilience through cyberattacks. With such major redundancies in their product lines the question on customers’ and partners’ minds is, “what gets cut and what stays?”

These deals often require customers to ultimately make changes, whether they like it or not. And change has been constant for many customers. In the last few years there have been multiple changes to Veritas’s platform starting with a switch to a new vendor for SaaS workloads, only to acquire another company later and force yet another change. Customers may also wonder what other changes are in store: What changes will they need to make to their disaster and cyber recovery plans? How will all this impact costs, operational resources, and their ability to be resilient?

The integration process between any two companies is a complex and time-consuming endeavor, likely taking several years to complete. At a time when data has never been more vulnerable to attacks, the transition can be quite chaotic for impacted customers and partners. But it doesn’t have to be.

Commvault Cloud: The cure for chaos

We are biased: we exist to help customers stay online and fight through threats to their business. The cure for this chaos is consistency. Consistent innovation. Consistent focus. Consistent customer success. We have a proven track record that demonstrates our consistent leadership. We’ve been public since 2006, just had our best quarter in history, and we recently introduced a unique cyber resilience platform — Commvault Cloud — that is unlike anything else on the market today. It offers cyber resilience through a single and unified platform with the flexibility to deploy as SaaS or on-premises, all running on the same modern highly scalable and secure codebase.

Our unified architecture is different by design to help future-proof your cyber resilience. We offer the only cyber resilience platform with any-to-any portability, making it possible to protect any data, in any location, and recover it from anywhere to anywhere. The result is unparalleled resilience for the hybrid enterprise.

We also recognize that cyber resilience starts before an attack, and never stops. That’s why we built Commvault Cloud to enable customers to advance their security posture before an attack by understanding the risk of sensitive data, categorizing and remediating those risks, getting an early warning of attacks to minimize the impact, and enabling rapid recovery in the event of an attack.

We’re also revolutionizing cyber recovery with cutting-edge innovations as part of Commvault Cloud, like Cleanroom Recovery. This offering provides a clean, safe environment to perform full-scale recoveries at-scale to enable business resilience in the face of cyberattacks. Equally as important, we enable customers to test their recovery plans, closing the gap between incident response planning and recovery. With Cleanroom Recovery, you can have peace of mind knowing that your data is protected, and your operations can swiftly resume, allowing you to focus on what matters most: serving your customers’ needs.

A Connected Ecosystem

Partners are key to Commvault Cloud. Today, we have integrations with all the major cloud service providers, as well as leading GSIs, technology, channel, security, and AI partners. Commvault Cloud gets better as it scales across the partner landscape.

Make the safe bet with Commvault Cloud

When it comes to cyber resilience, there is no time for chaos. Commvault Cloud is the cure for chaos and we’re just getting started. Give us a try today: https://www.commvault.com/free-trial

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We’re thrilled to kick off February by celebrating Black History Month at Commvault. Although Black History Month is recognized in February in the United States and Canada, we’ve taken our celebratory efforts to our entire global Vaulter community! All our Vaulters across the world will be connecting and honoring how Black Americans’ rich legacy of art, resistance, and resilience has contributed to the fight for social justice and every aspect of American progress and culture.

The theme of this year’s Black History Month is “African Americans and the Arts” spanning the many impacts Black Americans have had on visual arts, music, cultural movements, and more. Our goal this month is to explore how this shows up in the world and how it can positively impact our workplace. Throughout the month, our Diversity, Equity and Inclusion (DEI) team, partnering with our Multi-Culture Employee Resource Group (ERG), will engage in various activities available to all our Vaulters, such as hosting events, featuring educational sessions, and amplifying the voices of our Multi-Culture ERG members. 

Here at Commvault, we’re actively celebrating Black history and embracing diversity year-round, as DEI is foundational to everything we do. Every day, we value and celebrate the unique perspectives each employee brings to the table as we foster innovation and collaboration. 

Keep an eye on our LinkedIn and X profiles throughout the month as we continue to share how we’re celebrating Black History Month together!
Click here to learn more about our Commvault culture and our commitment to diversity, equity, inclusion, and belonging.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We’re thrilled to kick off February by celebrating Black History Month at Commvault. Although Black History Month is recognized in February in the United States and Canada, we’ve taken our celebratory efforts to our entire global Vaulter community! All our Vaulters across the world will be connecting and honoring how Black Americans’ rich legacy of art, resistance, and resilience has contributed to the fight for social justice and every aspect of American progress and culture.

The theme of this year’s Black History Month is “African Americans and the Arts” spanning the many impacts Black Americans have had on visual arts, music, cultural movements, and more. Our goal this month is to explore how this shows up in the world and how it can positively impact our workplace. Throughout the month, our Diversity, Equity and Inclusion (DEI) team, partnering with our Multi-Culture Employee Resource Group (ERG), will engage in various activities available to all our Vaulters, such as hosting events, featuring educational sessions, and amplifying the voices of our Multi-Culture ERG members. 

Here at Commvault, we’re actively celebrating Black history and embracing diversity year-round, as DEI is foundational to everything we do. Every day, we value and celebrate the unique perspectives each employee brings to the table as we foster innovation and collaboration. 

Keep an eye on our LinkedIn and X profiles throughout the month as we continue to share how we’re celebrating Black History Month together!
Click here to learn more about our Commvault culture and our commitment to diversity, equity, inclusion, and belonging.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Here at Commvault, our values – we connect, we inspire, we care, we deliver – are foundational to everything we do. 

This week, we hosted our quarterly internal Global Town Hall meeting and presented our FY24 Q3 CEO Living Our Values Awards. This awards program helps us to globally recognize and celebrate our Vaulters for their incredible work as they live our values each day. 

I’m so proud to announce our FY24 Q3 CEO Living Our Values Award winners: 

Paul Lancaster 

Lena Halbourian 

Sajjad Petkar 

Chris Stocker

Minutes to Meltdown Team 

Alex Janas  

Amy Ngian  

Richard Gay

Jill Van Sickle  

Michael Stempf  

Curtis Moyer 

Alan Wrafter 

Zero Trust Segmentation Team 

Engineering 

  • Mike Confenti  
  • Kalyan Kota   
  • Prashanti Koti  
  • Pankaj Kumar   
  • Ravi Kumarasamy   
  • Kevin Low 

Network 

  • C Dileep  
  • Anil K  
  • Michael Montenegro  
  • Rob O’Brien  
  • Theron Parks 

IT Systems 

  • Kyle Allocca   
  • Ernie Costa 
  • Bill Huskey 
  • Tim Karaban 
  • Kirsten Krsulj 
  • Preetham Mutyala     
  • Prakash Ramakrishnan
  • Pradeep Chandregowda 

     

All these winners set an inspiring example of what it truly means to be a Vaulter! 

To learn more about what it’s like to work at Commvault, check out our careers site

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Cyber and ransomware attacks are rising, but that’s not the only risk. Far too often, a company thinks data is secure, backed up, and recoverable — when it’s not. On top of that, organizations are creating unfathomable amounts of data distributed across clouds, regions, applications, and partners. This brings a complexity that poses a significant challenge to ensuring cyber resilience. 

This blog post will guide you in safeguarding your company’s data across multiple clouds. We will cover topics such as avoiding bandwidth constraints during backup, implementing air gap ransomware protection, having the right cyber resilience plan, and making decisions in partnership with the broader business. We will also discuss the importance of staying alert with a multilayered approach to detection and response and having visibility into your cloud environment. 

Avoid Bandwidth Constraints During Backup  

Bandwidth constraints can be a significant challenge when backing up data to the cloud. Traditional backup methods can consume a large amount of bandwidth, slowing down other applications, and impacting productivity. However, there are several ways to avoid bandwidth constraints during backup. 

One effective way to reduce bandwidth consumption is to use cyber resilience and data protection solutions with advanced deduplication and compression technology. These solutions can decrease the size of the data before it is sent across the network, which can significantly reduce bandwidth usage. 

If you’re running a legacy backup product, this is one big reason to modernize your solution. Many legacy products need built-in deduplication and compression features, which can significantly slow down your backups. By modernizing your solution, you can take advantage of these features and improve your backup performance.  

As you research different backup solutions, select a provider with proven network optimization as part of the underlying technology. Some solutions may offer bandwidth optimization but fail to deliver on this promise. Make sure to test the solution before you purchase it to ensure that it meets your needs.  

Implement Air Gap Ransomware Protection 

A cyberattack has hit you — now what? Air gap ransomware protection safeguards your company’s data across multiple clouds. SaaS-delivered protection can create secondary data copies in resilient, immutable, and isolated cloud storage. This approach ensures that data remains unchangeable, isolated, and swiftly retrievable in the unfortunate event of a ransomware attack.

Air gap ransomware protection provides an additional layer of security by creating a physical or logical separation between production data and backup data. This makes it more difficult for ransomware to spread to backups and ensures a clean copy of data is available for recovery.

Air gap ransomware protection is typically delivered as a SaaS solution that can protect both on-premises and multi-cloud data. This makes it a convenient and cost-effective way to protect your data from ransomware attacks. 

Here are some additional tips for implementing air gap ransomware protection:

  • Use a backup solution that supports air gap ransomware protection. 
  • Ensure that your backup data is stored in a geographically separate location from your production data. 
  • Encrypt your backup data both at rest and in transit. 
  • Regularly test your air gap ransomware protection solution to ensure it works properly.
  • Educate your employees about ransomware and how to protect themselves from it.

You can help safeguard your company’s data from ransomware attacks and ensure that you have a clean copy of data available for recovery in the event of a disaster.

Have the Right Cyber Resilience Plan in Place  

A comprehensive cyber resilience plan is essential for safeguarding your company’s data across multiple clouds. An effective plan ensures that your data is protected against various risks, including hardware failure, software corruption, human error, and ransomware attacks. Here are some key considerations when developing a robust cyber resilience plan: 

  • Define clear Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) 
  • Choose the proper backup storage 
  • Implement appropriate retention policies 
  • Regularly test your plan 
  • Use an intelligent configuration wizard 
  • Store backup data off-site  

You can help safeguard company’s data across multiple clouds and ensure that you can quickly and easily recover your data in the event of a disaster.

Make Decisions in Partnership with the Broader Business 

Making data protection decisions with the broader business ensures a holistic and practical approach to safeguarding your company’s data across multiple clouds. Firstly, confirming that the business understands the risks and costs associated with data loss is crucial. Educating stakeholders about the potential impact of data breaches, regulatory penalties, and reputational damage emphasizes the significance of data protection investments. 

Secondly, backup parameters should be selected per compliance regulations and internal practices. Involving the business in decision-making processes around cyber resilience and data protection solutions guarantees alignment with organizational policies and legal requirements. This collaborative approach fosters a culture of shared responsibility for data security. 

Lastly, aligning the cyber resilience and data protection solution with the business’s overall goals and objectives ensures these efforts directly contribute to the company’s success. Prioritizing cyber resilience initiatives that support strategic objectives, such as improving customer experience or expanding into new markets, demonstrates the value of data as a strategic asset. 

By working with the broader business, you can ensure that your data protection strategy is effective and meets the organization’s needs. This will help to protect your company’s data from loss, theft, and unauthorized access.

Don’t Make Backup an Afterthought 

Backups are often an afterthought, done only when necessary. But in today’s digital world, where data is essential to the success of any business, backups should be a critical part of your cyber resilience strategy to ensure business continuity. 

Data loss can occur for various reasons, including hardware failure, software corruption, human error, and ransomware attacks. If you have a reliable backup, you could retain valuable data and experience significant downtime, saving your business time and money.

To avoid these risks, it’s essential to make data security and protection part of the planning process for all new applications. This includes identifying what data needs to be backed up, how often it is required, and where the backups will be stored. You should also invest in a reliable backup solution designed for hybrid clouds. 

Engage Unified Management

Avoid using many tools and platforms that create overly complex cyber resilience interfaces. A solution that operates through a single-pane-of-glass dashboard protects all your workloads while your data security remains as efficient and comprehensive as possible. 

A unified solution provides critical visibility with the ability to manage any data anywhere from one console. You can select SaaS and self-managed solutions if your strategy requires and still enjoy industry-leading technology. You get everything you need to modernize your cloud journey from a single vendor. 

Stay Alert with a Multilayered Approach to Detection and Response 

A multilayered approach to detection and response is crucial for staying alert to potential threats and safeguarding your company’s data across multiple clouds. This approach involves implementing advanced intelligence, threat detection, and early warning systems to identify and respond to security incidents proactively. 

Advanced intelligence gathers and analyzes data from various sources, such as network traffic, endpoint activity, and user behavior, to detect suspicious patterns and activities. Threat detection systems use machine learning and artificial intelligence to identify known and emerging threats, enabling you to take immediate action to mitigate risks. Early warning systems provide real-time alerts and notifications when potential threats are detected, allowing you to respond swiftly and effectively. 

By combining these layers of protection, you can stay ahead of potential data breaches and minimize the impact of security incidents. This comprehensive approach enhances your overall security posture and ensures the integrity and confidentiality of your company’s data across multiple cloud environments. 

Be Cloud Ready 

Being cloud-ready means having the proper infrastructure, processes, and skills to use cloud computing. Being cloud-ready is essential for businesses looking to safeguard their data across multiple clouds.

As companies face rapidly growing data sets and evolving technologies, traditional backup methods must be revised. If a company isn’t cloud-ready, its backups can slow down or stop working altogether as it struggles to handle more data, users, and diversified environments.

A cloud-based cyber resilience and data protection solution can help companies to be more agile and responsive to changing data needs. With a cloud-based solution, companies can:

  • Scale their backups easily
  • Back up data from multiple locations
  • Protect data from disasters
  • Recover data quickly
  • Comply with regulations

By being cloud-ready, companies can take advantage of the many benefits of cloud computing and safeguard their data across multiple clouds. You won’t have to worry about rightsizing your infrastructure because the backup system is elastic. It shrinks or grows as your needs do and is easy to implement. Consider a SaaS backup and recovery solution to protect on-premises and cloud workloads.

In Summary 

Deploying outdated strategies for data protection is an expensive mistake — and it’s not just about minimizing downtime for business continuity. Commvault’s unique platform capabilities are designed to help enterprises reduce costs by simplifying management, optimizing cloud strategies, reducing security risks, and improving business continuity. 

With Commvault, you don’t have to sacrifice. With comprehensive coverage across on-prem, multi-cloud, SaaS, and edge data, Commvault Cloud delivers single-solution protection across your entire data estate. 

Download the Free Buyers Guide to learn how to navigate the challenges of safeguarding your data. 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In the dynamic landscape of cybersecurity, businesses face an ongoing challenge to protect sensitive data, particularly payment card information. Compliance models such as the Payment Card Industry Data Security Standard 4.0 (PCI DSS v4.0) are developed to encourage and enhance data security for organizations that handle sensitive customer data. Within this standard the PCI DSS 4.0 Requirement 6 emphasizes the critical need to develop and maintain secure systems and applications, recognizing that vulnerabilities in companies’ IT are regularly exploited by malicious actors. It mandates the installation of applicable vendor-supplied security patches within one month. 

The Patchwork Challenge

On one hand, patching requirements appear trivial and necessary in today’s world. On the other hand, organizations face constraints from testing schedules and complex infrastructure including tool sprawl and legacy systems that make timely vulnerability management a nearly impossible mission for many. As a result, PCI compliance requirements, such as the one-month patching timeline, impose a crucial challenge to companies.

Even after the implementation of patches, businesses are exposed to threat actors that identify new vulnerabilities and exploit them in zero-day attacks, especially in the modern age of generative AI. Organizations inherit cyber risk from IT vulnerabilities, but vendors are responsible for promptly discovering, disclosing, and fixing them.

Research reports that 42% of vulnerabilities are continuously exploited even after a patch is issued, with an average critical exposure time for threats (the time between disclosure and patch availability) of approximately nine days. Two years before the disclosure of the MOVEit vulnerability, signs of experiments for exploiting it were observed in the recent MOVEit cyberattack.

Resolving PCI DSS Challenges with Compensatory Controls 

Though PCI DSS v4.0 has stringent requirements, it does allow some exceptions to give organizations flexibility and applicability. The one-month patch rule is one with some wiggle room: “Compensating controls may be considered when an entity cannot meet a PCI DSS requirement explicitly as stated due to legitimate and documented technical or business constraints but has sufficiently mitigated the risk associated with the requirement through the implementation of other, or compensating, controls.”

With risk mitigation in mind the imperative of the standard is to build cyber resilience into your payment card systems. To help address this challenge, Commvault© Cloud, powered by Metallic AI, offers a comprehensive approach on a single platform that goes above and beyond conventional methods. Let’s explore in a short journey how Commvault Cloud helps you:

  1. Mitigating risk for known and unknown vulnerabilities
    Our data-minded cyber deception solution Commvault Cloud’s Threatwise capability brings modern ransomware protection and early warning detection of vulnerability exploitation attempts to companies of every size. The proactive defense shields your production data against zero-day and silent threats by spotting malicious intent and activity along the path to your data. It does this by strategically blanketing vulnerable assets, critical instances, and hybrid environments with intelligent sensors that send out highly accurate early warning signals with actionable threat intelligence across the organization. The patented technology enables prompt risk remediation, redirection of the threat, and exposes silent attacks with its unique capabilities including:
    1. Tailored threat detection to industry specific risk factors (i.e., sensors mimicking Point of Sale (POS) systems)
    2. Custom sensors unique to your business
    3. Strategic sensor placement recommendations to improve cyber resilience
    4. Preconfigured reports aligned to the PCI DSS standard 
    5. Automated alerts with actionable insights to key stakeholders and security tools, such as your SIEM
  1. Keep your backup data clean
    Utilize artificial intelligence (AI) to fight AI-driven attacks by surfacing zero-day and polymorphic malware targeting your backup instance with Commvault Cloud Threat Scan. This allows you to respond and recover clean data faster. Uncover abnormalities and predict threats before they infect your backups to help achieve and exceed recovery objectives.
  2. Identify data risk and governance factors
    Commvault Cloud Risk Analysis helps find, categorize, and act on sensitive data in secure data repositories and active data sources in seconds. Risk Analysis helps you stay ahead of data sprawl and over exposure to keep sensitive data protected and avoid exfiltration of data.
  3. Secure, monitor, and response
    Commvault Cloud’s Security IQ provides visibility across data instances, so you always stay cyber ready. Continuously bolster security posture, identify data risks in real time, and remediate them to stay ahead of evolving threats. Integrations with SIEM and SOAR can further automate response to cut your time to react.

Commvault Cloud and PCI DSS v4.0

Commvault Cloud enables you to adopt a cyber resilience approach to help meet central requirements within the PCI DSS v4.0 (including Req2, Req3, Req7, Req10). The platform ensures secure configurations across all system components, safeguards stored backup account data, restricts access to cardholder backup data, and implements robust logging and monitoring. Comprehensive security control such as identification and access management controls, security posture overviews, best-in-class encryption standards, and extensive documentation capabilities are available across all system components. 

To learn more about our cutting-edge technology and recent real-world threat detection case studies contact us.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

As environments become more complex and the potential attacks more sophisticated, business leaders will drive strategic cyber resilience efforts that put business continuity and data recovery at the forefront of cyber preparedness and security efforts.

It’s no longer enough to leave the cybersecurity decisions to the security team alone. Executive business leaders in 2024—both because of new regulations and best practices—must put cybersecurity expertise on their boards and make cyber resilience a common goal across all lines of business. The onus of these efforts isn’t only to thwart bad actors and avoid attacks, but it’s also to successfully recover from malicious actions with critical resources and data safe and secure from exploitation. With cyber resilience, business continuity becomes the primary goal.

Here we compile some of our executives’ thoughts on key focus areas in 2024 that will support and enable business leaders’ efforts to transform their approach to security to ultimately achieve true cyber resilience. Emerging technologies as well as business best practices will help ensure success with data recovery, business continuity, and cyber resilience.

Executive leadership embraces security

“When it comes to cyber preparedness, I expect the level of engagement by members of the C-suite, including the CEO, to go up in 2024. It has to.” – Rahul Pawar, Global Vice President, Security GTM and CTO

C-level executives will seek security expertise to sit on their boards and guide business decisions based on cybersecurity best practices. Not only are there new regulations requiring the prompt and accurate communication of security breaches, but data protection and recovery is now considered a competitive differentiator for businesses. IDC survey data shows that just 33% of senior executives are involved in current cyber preparedness initiatives and that must change. Fostering an environment where C-suite leaders participate in recovery exercises is also seen as key to preparedness. Equipping the board with holistic security intelligence will bring businesses closer to cyber resilience and show customers the company’s commitment to protecting data. 

IT teams converge and share intelligence

“Any company that continues to operate in silos will find themselves at a serious disadvantage when they are attacked.” – Reza Morakabati, CIO

As the threat landscape expands and attacks become more sophisticated, domains across IT will join forces to prevent intrusion and speed recovery. Collaboration between IT Operations (ITOps) and Security Operations (SecOps) teams will continue to evolve in 2024 because as any company that continues to operate in silos will find themselves at a serious disadvantage when they are attacked. With intelligence from tools across networking, security, cloud, and other IT groups combined, cybersecurity professionals can more quickly identify anomalous behavior that is an early indicator of an attack. Breaking down silos among teams and building common goals for IT pros will make businesses stronger against attacks and faster at recovery.

AI and automaton speed security response

“With AI comes quicker response times, better focused resources/reduced alert fatigue, and more time to focus on effective threat mitigation strategies – all benefits for a cybersecurity team that needs to see the full picture.” – Alex Janas, Field Security CTO

Generative AI took the world by storm in 2023, and this year, leaders will explore the use cases that would best move their business forward. In the realm of cybersecurity, AI represents proactive threat management and speedy response to attacks. Coupled with automation, GenAI can more quickly parse through myriad logs across systems and devices to identify attacks and kick off actions to prevent extensive damage and mitigate risks to key resources and data. While executives must explore the ethics of AI and put proper governance guardrails in place, the technology promises to reduce the noise for IT and security pros tracking alerts, events, and incidents, and to point toward the true source of concern more quickly. 

Threats evolve as bad actors also embrace AI

“Attackers may even go so far as to run predictive modeling to understand the degree of impact or discover new parameters and techniques that lead to creating a new emerging threat.” – Alex Janas

GenAI advancements aren’t exclusive to the good guys. Bad actors with malicious plans will also tap the technology to discover vulnerable assets and innovative ways to exploit them. Using AI-driven analysis, cybercriminals will seek to impose maximum damage with minimal effort. Attackers may even go so far as to run predictive modeling to understand the degree of impact or discover new parameters and techniques that lead to creating a new emerging threat.

AI integrates into security skills

“Being the smartest person in the room will be table stakes, while knowing what you don’t know will be the killer skill of the future.” – Martha Delehanty, Chief People Officer

Cybersecurity always tops the list of hottest skills in technology, and for 2024, HR leaders and hiring managers will be most interested in candidates with diverse technological skill sets who can address everything from IT and security operations to AI management and data recovery.  In the ransomware-era, with data security and incident response skills identified as a significant gap, there will continue to be a strong demand for CISOs and CIOs that can bridge together the worlds of ITOps and SecOps so that companies can ensure they are thinking about security all the way from protecting and identifying threats to full recovery. And despite the growing popularity of GenAI, human oversight will remain crucial, requiring companies to prioritize ongoing education and upskilling to ensure their teams can leverage AI technologies to their full potential while maintaining vigilance over their systems.

“I believe within the next several years we will see more compliance, security, and cybersecurity experts fill board seats, similar to financial experts that have long been recruited as necessary board members.” – Danielle Sheer, Chief Legal and Compliance Officer

Cyber resilience in 2024 will require business leaders change the way they approach security and recovery. Those listed above and other trends will drive a transformation that enables businesses to proactively prevent more attacks, but more importantly, to also quickly recover when a threat is imminent. Being prepared and able to recoup from attacks will set your business apart in this digital era as cyber resilience becomes table stakes.

Experience for yourself how Commvault Cloud can help boost your organization’s cyber resilience here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

With an early 2025 enforcement deadline, tens of thousands of financial entities within the European Union — spanning traditional banks, credit institutions, payment service providers, third-party ICT service entities, and others—are quickly navigating the intricate landscape of compliance mandated by the Digital Operational Resilience Act (DORA). Entities outside the EU in the financial and Information Communication Technologies (ICT) sectors must also toe the line with DORA if they provide crucial ICT services to EU-based financial entities.

Failure to comply can mean substantial penalties and the looming specter of criminal charges. According to DORA regulations, ICT service providers may incur significant criminal and/or administrative fines which are yet to be laid out by EU Member States. For colossal enterprises with global turnovers reaching billions of dollars, such fines could escalate to tens or even hundreds of millions.

DORA and Commvault Cloud

As the narrative unfolds, it becomes increasingly clear: Cyber resilience has never been more critical. Commvault® Cloud can help close gaps and fortify defenses, ensuring readiness for this era of stringent compliance.

Commvault Cloud is a comprehensive solution, seamlessly helping financial entities align with the detailed requirements outlined in Articles 5 to 16. The product’s zero trust architecture and robust encryption policies safeguard financial entities’ backups. The automated disaster and cyber recovery features with AI-driven insights aim to address ICT risks efficiently while offering a tangible advantage in the implementation of digital operational resilience testing.

DORA Article 10 emphasizes the need to “test the ICT business continuity plans and the ICT response and recovery plans in relation to ICT systems supporting all functions at least yearly.” Commvault Cloud’s Cleanroom Recovery solution paired with automated disaster and cyber recovery at scale takes center stage. The solution helps financial entities swiftly navigate potential disruptions, aligning with DORA’s call for quick resolution.

Prompt detection of anomalous activity

DORA directs financial entities to detect anomalous activity promptly in Article 9. Financial entities can use Commvault Cloud Risk Analysis to identify, monitor, and remediate sensitive files. Commvault Cloud Threat Scan and proactive anomaly detection can help enhance their ability to promptly identify and respond to abnormal occurrences in workloads.

Moving to ICT-related incident reporting as outlined in Articles 17 to 23, Commvault Cloud takes center stage by recording all incidents and significant cyber threats, sending valuable logging information about backups and unusual activity. Through integration with SIEM tools like Palo Alto, Splunk, and Sentinel, and by using SIEM connectors, Syslog, Webhook, and API options, Commvault Cloud streamlines reporting on incidents, providing early warning indicators and intelligence that enhance the promptness and quality of response. This is further enhanced with immediate mitigation recommendations. The product’s capabilities extend to support comprehensive digital operational resilience testing requirements outlined in Articles 24 to 27. It offers network security assessments by gathering insights from deceptive network intelligence decoys on the network and Cleanroom Recovery solution for periodic testing and cyber forensics. This versatility positions Commvault Cloud as an asset in fortifying financial entities against potential cyber threats.

Managing third-party risk

When it comes to managing ICT third-party risk outlined in Articles 28 to 30, Commvault Cloud shines with its ability to orchestrate workload migration between clouds and on-premises environments. This option helps continuity in ICT services even in the face of disruptions from third-party providers. The product’s early warning capabilities further prove invaluable in detecting potential supply chain attacks or suspicious activities that may arise from ICT third-party service providers.

Cyber resilience and compliance

Commvault Cloud addresses many of the requirements outlined in DORA regulations while going above and beyond to provide a holistic solution for cyber resilience. Its integration with SIEM tools, AI-driven insights, disaster recovery capabilities, along with the supplementary use of Commvault Cloud Threat Scan, Commvault Cloud Risk Analysis, proactive anomaly detection, and Cleanroom Recovery, position it as a key ally for financial entities navigating the complex terrain of DORA compliance.

Start your free trial of Commvault Cloud today.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Data security is paramount in today’s digital landscape, especially regarding Software-as-a-Service (SaaS) applications. While many organizations rely on cloud service providers for data protection, it is crucial to understand that the services’ native controls may not be sufficient for long-term retention and resiliency. This is where purpose-built solutions like Commvault Cloud come into play, offering comprehensive protection for SaaS workloads. 

In this post, we will explore why we think Commvault is the ideal choice for safeguarding your SaaS applications and allowing for quick recovery in case of data loss.

The Need for Purpose-Built Solutions

Every organization has unique requirements for data protection in the cloud. SaaS providers have their own data protection strategies, but they may not align with the granularity that your business needs. Availability should not be mistaken for recovery and resilience. This is where purpose-built solutions like Commvault offer tailored protection for SaaS workloads.

https://play.vidyard.com/NDN39gQ2Vz8BMYDa9r2PHZ

Optimizing Data Protection in the Cloud with Commvault

Commvault Cloud offers deduplication and compression capabilities that help optimize cloud spend. By leveraging these features, organizations can protect their SaaS applications without incurring unnecessary costs. A prime example is how ServiceNow discusses in the video above how they utilize Commvault’s capabilities to protect its SaaS applications.

The Limitations of Native Controls

While cloud service providers offer some native controls for temporary data replication, they may not be sufficient for long-term retention and resiliency. Data experts emphasize the need for a proactive data security strategy, and cloud service providers recommend implementing third-party backup solutions. Commvault fills this gap by providing extended retention of active and deleted data, adhering to pre-established SLAs, contracts, and applicable legislation.

Best Practices for Protecting SaaS Applications

To effectively protect data living within SaaS applications, organizations should follow best practices, including:

  1. Keeping backup copy data separated from source data for air-gapped, immutable copies.
  2. Delivering extended retention of active and deleted data.
  3. Adhering to pre-established SLAs, contracts, and applicable legislation.
  4. Enabling granular backups, flexible restore, and rapid recovery options.
  5. Utilizing advanced security insights and threat monitoring.

Enterprise-Grade Protection for SaaS Applications

Commvault Cloud, powered by Metallic AI, offers enterprise-grade protection with the same benefits and consumption model as typical SaaS solutions. It enables organizations to:

  • Continually support cloud-first initiatives
  • Shed tech debt without sacrificing security
  • Rapidly deploy and scale to support ever-evolving workloads and SaaS apps

Commvault Cloud protects leading SaaS applications, including Microsoft 365, Salesforce, Dynamics 365, and Azure Active Directory, providing high-performing security and recovery capabilities with the simplicity of SaaS.

Protecting SaaS applications is crucial for data security and quick recovery in case of any data loss. While cloud service providers offer some native controls, they may not be sufficient for long-term retention and resiliency. Purpose-built solutions like Commvault provide tailored protection for SaaS workloads, offering advanced security insights, granular backups, flexible restore options, and rapid recovery capabilities. With Commvault Cloud, organizations can protect their SaaS applications while reducing costs and eliminating headaches. Don’t wait for SaaS-delivered cyber resilience; leverage Commvault’s multi-layered security and easy deployment for a low total cost of ownership.

Download our free eBook to learn about the importance of SaaS-delivered cyber resilience and the building blocks for hybrid cloud success – 5 building blocks for hybrid cloud success, and learn about our hybrid cloud solutions

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

It has always been meaningful to me that we honor and celebrate the legacy of Dr. Martin Luther King, Jr. at the start of the year. Each January, as we think about New Year’s resolutions and new beginnings we want to embark on for our health, family, and possible new adventures, MLK Day allows us to also reflect on our humanity and global communities.  

Commvault’s U.S. offices are closed for MLK Day as we all reflect and give ourselves a head start in 2024 to become agents of positive change in our communities. As a global Vaulter community, our efforts to champion positive change extend well beyond our U.S. community – we are all in this together, across the world, as we work together to make a difference.  

The past few years, we have seen traumatic events that have captured headlines and sparked discussions about injustice across the world. Discussions can end, and headlines can move on, but vital change is still needed. Inequity persists in healthcare, education, voting rights, housing, and the basic human right to live without fear of violence. We should continue to use this MLK Day and beyond to reflect on the realities of racism and injustice, and to champion a fairer, more equitable future. 

In thinking about Dr. King, I also think about his phenomenal wife, Coretta Scott King, and the work she did with him to galvanize equality for African Americans, the Civil Rights Movement, Dr. King himself, and the overall longevity of his legacy. In celebrating Dr. King, I also celebrate Coretta and what their partnership lends to the overall movement. For all the global heroes like Dr. Martin Luther King, Jr., they don’t do this work alone – it takes the collective to make change. 

At Commvault, the mantra – we’re in this together – guides our DEI efforts. Simply put, we can’t be the change we want to see in the world without one another. Dr. King famously stated, “Injustice anywhere is a threat to justice everywhere.” Today, we must remember that we, both individually and collectively, have the power to change our world for the better. I’m proud to be a part of our Commvault community as we continue to cultivate a culture of belonging, support, and respect while driving positive change in our communities across the globe.  

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We’re kicking off 2024 with a continued focus on wellness. We all know that caring for our wellbeing allows us to be our best selves both at home and at work. My mantra: Before we deliver for others, we must always deliver for ourselves first!

Over the years, we’ve developed a holistic approach to wellbeing at Commvault, with four key pillars of wellness – physical, social, mental, and financial – that are all interconnected. While each of these pillars are equally as important, we know that mental health is a crucial focus area. And with that said, we’re always looking for ways to adapt and evolve our wellness offerings to provide our Vaulters and their families with the right benefits for life’s most important moments.

For 2024, we’re excited to be using a new global mental health partner, Spring Health, which offers innovative, inclusive mental health care designed to better meet the needs of our Vaulters and their families. Spring Health gives our Vaulters access to confidential 24/7 support for a wide range of personal issues, crises, and everyday concerns, at no cost to them. With the switch to this partner, we are increasing the number of free counseling sessions from three to six and adding six additional coaching sessions, bringing the total of free sessions available to 12.

Expanding our wellness offerings to ensure we’re meeting the needs of our global Commvault community is always a priority for us, as our company’s success starts with our Vaulters and their wellbeing. 

As we move forward in the new year, I encourage you to think about what you’re doing each day to practice self-care and keep mental wellness a top priority. Whether it’s taking advantage of resources available to you at work or outside your company, we all deserve to feel like our best selves.

To learn more about our other wellness initiatives, check out Commvault’s 2023 CSR Report.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Our ecosystem of partnerships play an important role in ensuring Commvault continues to be at the forefront of developing cyber resilience solutions that anticipate emerging needs while making operational and financial sense for the industries and market segments we serve. 

For this reason, Commvault gathered an elite group of senior executives, thought leaders, and security experts from the world’s leading Global System Integrators, including Cognizant, HCLTech, Infosys, Tech Mahindra, Tata Consultancy Services, and Wipro, at our inaugural GSI SHIFT Partner Summit to discuss the increasingly AI-driven cyberthreat landscape today’s enterprises face and what it means for safeguarding the data of our mutual customers. This is the first of an ongoing series of GSI Partner Summits we’re instituting. 

A shift in defending and recovering from cyberthreats

Our discussions centered on how to help organizations identify threats earlier, respond faster, and return to business as usual with minimal impact by employing AI to fight new breeds of cyberthreats. First and foremost, we all agreed that this requires organizations to shift their thinking around cybersecurity and data protection and to assume their organizations will suffer a data breach. The new norm is when it will happen, not if  it will happen. And that the best strategy to meet a cyberattack, is to have well-documented and tested processes to create a reliable, fast recovery across complex hybrid data environments.  

We brought our elite team of product leaders and technical experts to share our vision and stepped through key digital transformation use cases such as modernizing data centers, adopting cloud-first or hybrid cloud strategies, and re-platforming business-critical applications. In every scenario, underlining each use case is the fundamental need to strengthen organization’s cybersecurity postures using intelligence and automation, as well as the importance of unifying IT and Security teams operations. Our partners didn’t hold back in diving into the nuances of our innovations and challenging us with new use cases. This dialog is priceless in the shaping of our product roadmap and future innovations.

There is no greater testament to the effectiveness of our technology than the hundreds of Global 2000 enterprises that are using Commvault solutions as part of the larger business transformations that our partners are driving. We were honored to have our GSI partners take the stage to share a few case studies on how they’ve integrated our solutions into their engagements with industry giants and market leaders to deliver cyber resilience and, in most cases, lower total cost of ownership!

 At the close of our first GSI SHIFT Partner Summit we want to recognize the importance of our collaborations with global system integration partners in developing and vetting robust solutions to address the most challenging data resilience issues in innovative ways. We value all our partners’ expertise, experience, thought leadership and investment. Each has uniquely contributed to the value and industry leading position Commvault enjoys around the world and is a testament to our mutual trust and commitment. 

https://play.vidyard.com/81rZF3AvUpZmpBMtqU5f4Y

GSI Partner Awards

Cognizant: Rising Star GSI Partner of the Year

Cognizant’s unwavering commitment to prioritizing security and resilience in their System Integration services has set them apart.

HCLTech: Pioneering GSI Partner of the Year

HCLTech has taken a proactive approach to delivering innovative solutions and has consistently brought fresh insights and expertise to address new customer needs with their VaultNXT offering.

Infosys: Hyperscale X GSI Partner of the Year

Infosys has built one of the largest Commvault Hyperscale X reference architectures with a focus on smooth implementation and user-friendly design. Their collaboration with Commvault has resulted in numerous product enhancements.

Tata Consultancy Services: Private Cloud GSI Partner of the Year

TCS’s ability to standardize Commvault as a Service has showcased their proficiency in architecting, designing, and customizing the overall offering to client needs and has resulted in the expansion of their estate to multiple PB within a remarkably short time is nothing less than stellar.

Tech Mahindra: Transformational GSI Partner of the Year

This recognition is a testament to Tech Mahindra’s outstanding performance in successfully completing a giant project with multiple complex challenges for a renowned BFSI customer resulting in transformative data resilience.  

Wipro: Emerging GSI Partner of the Year

Wipro has established a strong presence through knowledge building, the establishment of Centers of Excellence (COE), and enabling efficient delivery. Their exceptional client wins highlight their immense potential and promising synergies with Commvault.

Individual Awards:

Nagalingam Kalingaraj: Trusted Advisor Award of Excellence

Nagalingam Kalingaraj brings extensive experience and a deep understanding of all Commvault technologies in relation to overall IT infrastructure, as a lead architect at Tata Consultancy Services (TCS). His invaluable insights and guidance have played a pivotal role in securing numerous significant and complex wins in collaboration with TCS.  Commvault recognizes his trusted role in advising customers and advocating for our cyber resilience solutions.

Ramachandra Pargaonkar: Innovator Award of Excellence

Ramachandra Pargaonkar from Infosys is recognized for his exceptional contributions in generating new ideas, solutions, and approaches that have propelled Commvault to the forefront of customer preferences. His thought-provoking ideas have not only inspired innovation within our organization but have also simplified processes, minimized rework, and facilitated the development of packaged solutions.

Saurabh Rohilla & Kapil Tiwari: Catalyst Award of Excellence

Saurabh Rohilla and Kapil Tiwari from HCLTech are recognized for their exceptional ability to spark change in customers and prospects’ approach to cybersecurity and data resilience and follow through with exceptional, well-designed solutions. Saurabh and Kapil’s proactive approach and strategic positioning of Commvault solutions have acted as a catalyst for driving positive change and delivering outstanding results.  

Abhinandan Chakraborty : Trailblazer Award of Excellence

Abhinandan Chakraborty from TechMahindra, brings innovative thinking and unwavering commitment to driving positive change with our solutions. His ability to anticipate future trends, challenge the status quo, and architect solutions leveraging Commvault has resulted in multiple significant wins. He is truly a Trailblazer for Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Since a business continuity plan is a complicated endeavor that is highly customized and involves multiple departments, there are a number of business continuity services out there that offer everything from full-service consulting to hands-on assistance when a disaster event strikes.

What Are Business Continuity Services?

Many managed service providers (MSPs) offer business continuity services in several different areas, including:

  • Resiliency models, including data backup and recovery
  • Security risk assessments
  • Crisis management
  • Training and awareness
  • Return-to-office strategies
  • Risk management and insurance coverage
  • Software and Hardware Asset Management
  • IT services

Of course, every business is different and needs will vary. Not all companies will need all of the above services. But in today’s data-centric environment, every business that hosts its applications and workloads in the cloud will need a way to backup and rapidly restore its data in the event of a disaster. This is a component of business continuity that should be integrated into any business continuity conversations you may be having, no matter which services are recommended to you.

Let’s explore why, and how this works in the cloud.

How Does Data Backup—Specifically Cloud Backup—Fit with Business Continuity Services?

Backing up enterprise data has been an important part of business continuity plans for decades, dating back to when businesses stored data on multiple sets of tape copies on-premises. In today’s technology landscape, the amount of data being used on a daily basis has also grown exponentially and the majority of businesses have migrated their applications and workloads to the cloud to leverage its scale and elasticity. This evolution has created a need for cloud backup-as-a-service.

If your organization’s applications are hosted in the cloud, you are better off using a backup solution built specifically for the cloud. When the cloud backup solution is deployed, data is backed up according to a set schedule and then securely stored in the cloud. If an incident occurs that leads to loss, corruption, or, compromise of data — such as a physical disaster or a ransomware attack — the most recent copy of the data backup can be recovered and restored from any location with access to the cloud backup platform.

Data is central to your operations; whether your business has hundreds of physical locations spread across the globe or is an online-based enterprise, the necessity for both cloud backup and rapid recovery remains the same.

Organizations who use an MSP for their data protection should ensure the MSP is using a cloud-native backup solution that can:

  • Back up and store data efficiently
  • Ensure backups are stored outside of primary accounts to protect data from cyber threats such as ransomware
  • Identify, recover, and rapidly restore the most essential data and workloads needed to ensure business continuity

Safeguard Your Data With Secure, Comprehensive Cloud Backup and Rapid Recovery

Clumio’s industry-leading cloud backup-as-a-service platform boasts numerous rapid recovery capabilities —such as granular and flexible recovery — that can identify and restore specific mission-critical data and applications needed to maintain business continuity in order of priority.

In addition to Clumio’s rapid restore capabilities, organizations are also provided with features that include

  • Ransomware protection via air-gapped, immutable backups that are stored away from primary accounts
  • Automated data lifecycle management
  • Clear visibility into snapshot storage for faster, easier compliance
  • Cost analyzers to help reduce unnecessary cloud spend

Cloud backup is an essential business continuity requirement for any organization that has migrated to the cloud. Learn why Clumio is the industry’s leading innovator for cloud backup and rapid recovery by scheduling a demo today. We’ll show you how your business can be up and running with Clumio in just 15 minutes, without the need to install any new infrastructure, software, or conduct any pre-planning beforehand.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We’re thrilled to announce that the HyperScale X Appliances family is even better with the addition of new hardware options from Dell. This transformative shift in Commvault’s HyperScale X product line gives organizations increased flexibility and choice in protecting critical information.

One of the most exciting aspects of this development is the expanded range of hardware options available. Now, Dell customers can have the HyperScale X Appliance experience on the same hardware used in their existing IT data centers. With Dell joining the HyperScale offerings for 4-, 12-, and 24-drive node types, there are more solutions to cater to a wide range of needs, capacities, and preferences, benefitting companies with standardized hardware across their data centers, as they can now choose appliances that are more likely to be compatible with their existing infrastructure and management processes. Plus, they can enjoy the convenience of a single support call to Commvault, helping ensure any issues with software or hardware are promptly addressed without needing multiple service calls to different vendors.

In addition to new compatibility, the new hardware options seamlessly integrate with existing HyperScale X Appliance deployments, eliminating the need for costly and time-consuming infrastructure overhauls and allowing organizations to leverage their current investments and expertise with minimal disruption to their processes and workflows.

The advantages go beyond compatibility and integration. Dell will provide field support engineers who offer hardware service, response time options, and add-ons for media and component retention to cater to the needs of data-sensitive customers. This diverse range of choices empowers businesses to select the perfect fit for their specific requirements, whether prioritizing cutting-edge technology or unwavering reliability.

Commvault and Arrow Electronics Intelligent Solutions Business

Commvault has worked closely with Arrow’s Intelligent Solutions business to deliver this new hardware solution to enhance data management for businesses worldwide. With this new program, Arrow and Commvault will provide a turnkey solution that integrates hardware and software to meet the needs of customers seeking a comprehensive approach to data management. 

The program will feature a bundled SKU comprising Commvault HyperScale X software and Dell hardware, making it easier for customers to obtain the tools they need to manage their data effectively. 

Arrow will also provide worldwide shipping logistics to end users, including cross-border shipping, to help ensure on-time delivery. But that’s not all – Arrow will offer professional services to customers for the Rack and Stack of the appliance, allowing customers to focus on their core business. At the same time, Arrow handles the installation and configuration.

“We are excited to work with Commvault to deliver the Hyperscale X appliances solution,” said Salesh Rampersad, president of Arrow’s Intelligent Solutions Business. “This combination of Arrow’s integration services, worldwide supply chain and shipping logistics, and post-sale installation and support services displays our commitment to deliver reliable and innovative solutions to the industry, enabling customers to focus on their core business.”

“HyperScale X, as an integrated hardware and software storage solution, is designed for ultimate flexibility with hardware platform choices. With Dell now joining our appliance solution, our customers can deploy HyperScale X on top of proven and established hardware platforms,” said Pavan Bedadala, senior director of product management at Commvault. “With the added assurance of Commvault Support serving as the single point of contact for all hardware and software issues, we provide comprehensive assistance, helping ensure peace of mind for our valued customers.”  

Enhanced Backup Appliances: Empowering You with Control and Flexibility

With the introduction of our new backup appliances, we are thrilled to offer you enhanced control and flexibility over your data protection strategy. Now, you can choose from a range of HyperScale X Appliance hardware vendors, enabling you to customize your solution according to your specific requirements and budget while leveraging your existing infrastructure.

Benefits include:

  • Enhanced Choice and Flexibility: Tailor your backup solution to your specific needs and preferences.
  • Seamless Integration: Minimize disruption and maximize efficiency with smooth integration into your existing HyperScale X Appliance infrastructure.
  • Proven Performance: Benefit from Dell’s cutting-edge technology and unwavering reliability, finding the perfect fit for your organization.
  • Simplified Management: Control all your HyperScale X appliances from a single console, regardless of the hardware vendor.

Ready to learn more?

If you’d like to explore the new HyperScale X appliances with Dell hardware, our experts are available to answer your questions and help you select the ideal solution for your unique needs. Contact your account manager or our sales team today to learn more.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

If you’re using AWS to host your data and workloads, you probably know that your business is responsible for backing up and protecting the data in AWS across every associated account. Fortunately, cloud backup-as-a-service solutions offer an efficient and effective way to do just that.

Here are three benefits your business can gain by leveraging a solid cloud backup-as-a-service solution.

Three Benefits of Using Cloud Backup for Business

1. Simplicity—No New Hardware or Software Required

​​As customers move more of their production workloads to the cloud, a backup solution that can easily scale accordingly is essential. A good cloud backup solution doesn’t require any additional software or hardware to meet data storage protection and backup demands.

Once you’re up and running, your enterprise has instant access to unlimited scalability—without the need to continually spend resources on maintaining cloud resources dedicated to a backup solution. Plus, think about all the things your IT team can focus on now with simplified cloud backup management.

2. Automatic Backup, Business Continuity, Easy Compliance

After you’ve migrated your data and workloads to the cloud, you can then set up automatic backup schedules according to your business’s needs, relieving your team from the need to develop and maintain complex scripts.

This enables a fast and simple backup and recovery process that can be initiated from any location. When data recovery is needed, the user can instantly begin restoring an entire asset instance or identify individual files for an even faster recovery. This ensures business continuity in the event of downtime or an attack that compromises enterprise and customer data.

Additionally, cloud backup-as-a-service provides easier compliance by making it quick and simple to identify and locate particular backup files for fast recovery during audits.

3. Automatic Security Updates Without Disruptions

Security and software upgrades are routinely needed to protect data from emergent and evolving threats like ransomware. Cloud backup-as-a-service solutions typically offer continual security updates that keep up with the latest data threats without causing any disruptions or downtime to the user.

The same goes for the software and interface itself. Cloud backup-as-a-service solutions providers push frequent updates to the backup software to improve everything from efficiency and overall performance to the user experience.

In either case, the business using the cloud backup solution never has to worry about implementing new software updates or wondering if their data is at risk to new threats—another hands-off data protection aspect that is only available with cloud-native solutions.

How Do I Get Started with Cloud Backup for My Business?

Cloud backup is essential for businesses that wish to protect their data, enable faster and more versatile recovery, and achieve a predictable TCO. But how do you get started?

Setting up Cloud backup doesn’t have to be a complicated endeavor. In fact, you can be up and running n as few as 10 minutes with Clumio.

Built in the cloud, for the cloud, Clumio is a cloud-native backup-as-a-service (BaaS) solution for AWS that enables businesses to secure and protect their data and workloads while gaining clear insights into their data protection plans.

With Clumio’s intuitive user interface, your business can:

  • Rapidly back up AWS data across your entire organization
  • Protect data in AWS from ransomware attacks and other malicious threats
  • Meet varying data compliance objectives with global policies
  • Reduce RTO (Recovery Time Objective).” With these edits, the Clumio feature statements are accurate.
  • Optimize your backups for potential cost-savings

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Due to the varying sizes and types of data that often need to be retained, you should be very precise when creating the data retention policies themselves to avoid non-compliance, data clutter, and the wasting of IT resources.

Effective and efficient data retention policies rely on the following best practices while utilizing the right data backup tools.

Preliminary Data Retention Policy Considerations

When developing data retention policies, consider:

Compliance – Determining what data is subject to compliance regulations is paramount and requires a thorough examination of any applicable laws. Organizations also typically have their own internal compliance regulations for audits as well.
What data to retain – Which types of non-mandated data should you retain internally for your own purposes? This can range from basic files like documents and emails to database records.

Basic Steps for Creating a Data Retention Policy

Every organization is different and will have its own needs that must be addressed when implementing new data retention policies. That said, the following can be considered a basic outline for the policy creation:

  • Define the types of data being retained (see above)
  • Categorize and arrange data by lifecycle
  • Determine how many versions should be stored
  • Identify the necessary frequency of data backups
  • Determine a lifecycle policy for each dataset
  • Remove unneeded files
  • Inspect and execute the backup retention policy and evaluate the results

Data Retention Policy Best Practices

Following best practices for data retention can improve everything from compliance reliability to cost savings. Some general best practices include:

  • Be aware of how any industry regulations may affect retention policies
  • Review data recovery and restoration scenarios (like Recovery Time Objective and Recovery Point Objective)
  • Ensure incremental backups remain at a manageable size
  • Keep the last backup copy easily accessible
  • Consider cloud storage costs over the long term
  • Schedule automatic backups when bandwidth availability is at its peak

Simplify Data Retention Policy Compliance and Management With Clumio

Data retention policy best practices and proper planning will only get you so far—the tools you use for data backup and recovery are equally important. Clumio is a secure, cloud-native, backup-as-a-service solution that delivers automatic data backup and protection while providing clarity into your organization’s data retention policies and several innovative features that ensure simplified, streamlined compliance management.

Clear Policy Visibility and Easy Management

Clumio’s intuitive user interface includes a dashboard that displays a single view of all assets and resources. Amazon Web Services (AWS) accounts are automatically discovered and indexed, and uniform policies can be applied to new assets as they are added. Instant push alerts are sent out any time compliance may be at risk.

Uncompromising Data Protection

Data retention should also involve top-tier security for backup copies. Clumio creates instant data backups and stores them in an encrypted, air-gapped environment outside of the primary account to safeguard copies from being compromised by threats like ransomware, ensuring you will always have a valid backup copy on hand.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Continuously evolving ransomware and modern cyberthreats that utilize artificial intelligence (AI) and machine learning (ML) plague today’s businesses across all industries. According to IBM’s Cost of a Data Breach 2023 Report, the average cost of a single data breach reached a new all-time high with USD 4.45 million per breach. Leaving organizations with the challenge to become cyber resilient through limiting costs associated with ransomware.

Stop the Threat from Spreading

Rather than the businesse’s decision to pay a ransom or not, your company’s cyber resilience relies on its capability to remediate and recover from a breach. Data protection takes up a critical role in this effort that ensures the business can operate by evaluating and testing clean points, standing up safe environments, recovering backed up data sets, and continually protecting and testing data in air-gapped instances. Meanwhile, the scope of necessary recovery efforts per incident widely varies and increases over time, making the ability to discover threats early, react sooner, and minimize how much needs to be recovered.

According to Sophos’ The State of Ransomware 2023 report, two-thirds of organizations reported being hit by ransomware in 2023. With increasing damages year over year, conventional methods for threat detection are missing the mark to protect companies’ crown jewel: data. So how does the Commvault Cloud spot malicious activity quicker to minimize the blast radius and stop the threat from spreading?

See Threats Sooner

Threatwise cyber deception detects threats fast as bad actors move laterally across production environments in the search for your data. Indistinguishable threat sensors blanket the path to critical data instances setting up trip wires that trigger alerts upon first touch while staying invisible to legitimate users. Gathering in-depth threat intelligence data, every step of the threat actor is monitored and fed into existing security tools to surface used tactics, techniques, and procedures. By taking an inward-out approach that spots both external and internal malicious activity targeting business data, Threatwise unveils threats sooner. This allows key IT and security stakeholders to identify and remediate breaches the moment they happen and divert attacks to interact with deceptive assets instead of real machines.

Automated Best Practices Built-in

Thanks to the Commvault Cloud telemetry, Threatwise Advisor reduces the cognitive load for users by continuously monitoring data protection workflows in backup environments and recommending optimal sensor placement that further hardens critical environments. In the near future, Threatwise Advisor will take it a step further by notifying the Commvault backup environment which assets are at significant risk based on malicious activity detected by threat sensors. The unified control provided by the Commvault Cloud allows backup protection admins to take proactive steps along the lifecycle of the data, making sure backups stay clean, available, and recoverable at all times.

Start protecting your data sooner to build true cyber resilience and limit the burden of remediation and recovery across your hybrid environment. For more information on how to guard your organization against AI-driven attacks, read this blog post.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery