Skip to content

The Digital Operational Resilience Act (DORA) came into effect on January 17, with extensive guidelines and a detailed regulatory framework for how all financial services entities doing business in the European Union maintain data resilience against unplanned disruptions.

DORA also recognizes a reality broadly accepted by cybersecurity professionals that it is no longer a question of if a cyberattack occurs, but when. This crucial legislation brings a new level of rigor and accountability to the financial services industry that will continue to evolve to safeguard the stability of the EU and global financial ecosystem.

Many sectors of the financial services industry beyond traditional banks and credit institutions now fall under DORA, including payment providers, investment firms, trading venues, insurance providers, and third-party information and communication technology (ICT) service providers.

Those that are new to this level of regulation may struggle to comply, as indicated by European financial regulators’ DORA “Dry Run Exercise.”1 They also likely will face additional scrutiny by interconnected customers, partners and other stakeholders as a new operational risk. Non-compliance no longer means just the potential for a very large fine but also reputational damage and liability for a company, its directors, and its partners.


While it remains to be seen how quickly financial regulators act, DORA represents a shift from guidelines for data readiness and cyber resilience to enforcement of it. Given the expansive nature of DORA, which significantly broadens the EU’s financial regulation of IT, regulators, lacking unlimited expertise and resources, may face challenges enforcing all aspects of DORA immediately. As a result, regulators are likely to adopt a targeted approach, focusing on the most critical and visible areas of noncompliance. 

What Financial Organizations Are Prioritizing

A top priority for DORA compliance is the submission of accurate and technically compliant registers of information. Financial regulators have emphasized that registers will be a primary focus of enforcement, and they expect organizations to submit them early in 2025. Submitting an accurate register that details the organization’s most significant IT providers may be more beneficial than submitting incomplete information about all of its IT providers.2

For data protection leaders and CIOs, DORA is a call to action to examine legacy systems and consider whether they are capable of withstanding today’s cyberthreats and can deliver the performance required for efficient, rapid service recovery. 

Beyond identifying and mapping key systems, applications and workloads with respective ICT providers, organizations should carefully consider the core capabilities that protect, defend, and recover these systems. Critical capabilities include:

  • Data protection and cyber recovery
    Rapid recovery capabilities are essential under DORA to minimize the operational impact of an attack. The only way to achieve the most stringent, ultra-short RTO required for critical systems is to recover using storage-based immutable snapshots. These snapshots should be securely stored in an isolated (or virtually air-gapped) repository.
  • Early-warning threat detection
    Identifying and remediating potential cyberthreats earlier is an important aspect of data protection and readiness. The capability to continuously scan data to detect anomalies and identify threats like ransomware and malware in real time and automate remediation is essential for faster containment of an attack. 
  • Isolated recovery environments (IRE) or cleanrooms for resilience testing
    Establishing a completely self-contained IRE, where data can be restored for forensic and application analysis and validated as clean before returning to production, speeds recovery. IREs also allow organizations to continuously test and improve cyber recovery practices for organizational readiness.
  • Scalability and performance

Businesses will continue to evolve their services, face new regulatory requirements, and deal with emerging cyberthreats. It’s important to consider a solution’s ability to scale as data requirements change across distributed, hybrid environments while maintaining high-performance speeds for data protection and recovery.

Compliance With Confidence

Organizations that delay establishing robust capabilities to meet DORA and other evolving resilience regulations – such as PSD2, NIS2, APRA CPS 230, and the European Cyber Resilience Act coming into effect in 2026 – may find themselves with mounting challenges to overcome. They also may find themselves at competitive disadvantage to firms that can demonstrate their ability to remain resilient in the face of disruptions in the global financial ecosystem.

Working with partners that understand the regulation’s resilience requirements and deploying robust solutions can help enable organizations to be compliant and better prepared to meet new regulatory challenges and defend their data environment against emerging threats.

Pure Storage and Commvault have come together to build a joint solution, modular in design, that helps financial institutions enhance their cyber resilience practices and address key pillars of DORA for incident response and resilience testing. The solution is built by integrating the leading cyber resilience capabilities of Commvault® Cloud with the highly secure, high-performance Pure Storage platform.  Learn more about the solution and our commitment to cyber resilience here.

Are You Cyber-ready?

Readiness reflects mature cyber resilience, where technology, people, and processes work seamlessly to enable continuous business in the face of any cyber challenge. Evaluate your organization’s cyber resilience with Commvault’s Cyber Maturity Assessment.  


1 Key findings from the 2024 ESAs Dry Run exercise, European Banking Authority, Dec.17, 2024.

2 Countdown to DORA – Four Takeaway Points from Regulators’ December Statements, Skadden, Arps, Slate, Meagher & Flom, LLP, Jan. 3, 2025

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Welcome to the final installment of our three-part series on Active Directory. In our previous blog post, we explored small-scale disruptions that could impact AD, such as the accidental deletion of an object, and why fast, granular recovery is so critical.

But what happens when disaster strikes on a grander scale? What about large-scale AD disasters like ransomware attacks or schema corruption? In these scenarios, the recovery process may require a complete AD forest recovery. This involves restoring the directory service, including all domains, domain controllers, and associated data, to a pre-attack state.

The Looming Threat of Ransomware

Imagine this scenario: A ransomware attack strikes your organization, locking down the server that hosts AD. Suddenly, all the files on the server are encrypted, and AD goes offline. Now, all the business-critical applications that depend on AD for user authentication are inaccessible. Employees can’t log in, critical services come to a halt, and business is at a standstill.

The impact of an AD attack that disables domain controllers is real and can be devastating. In 2017, global shipping giant Maersk fell victim to the NotPetya cyberattack, which encrypted the file systems of 45,000 PCs, 4,000 servers, and all but one of its 150 AD domain controllers. With AD completely offline, operations instantly ceased, shutting down 17 global shipping ports and stranding hundreds of container ships for 10 days. In total, the attack cost the company at least $300 million.

Gartner reports that as of this year, 75% of organizations will have experienced at least one cyber incident like ransomware. With such threats looming, having a well-documented and frequently tested recovery plan to restore and rebuild your entire AD environment to a pre-attack state is not just a good idea – it’s critical and the key to getting your business back fast.

Recovering AD Requires a Specific Plan and Process

When disaster strikes, recovering AD is vital, yet traditionally has been very hard to do, requiring intricate, time-consuming, manual processes.

Given that AD is a multi-master, geographically distributed system, restoring it demands meticulous coordination during recovery. Each domain controller must be synchronized and restored in a coordinated manner to avoid data inconsistencies and potential corruption in the recovered directory.

Microsoft’s Active Directory Forest Recovery Guide provides a detailed, step-by-step method for this, which can involve anywhere from 50 to 100, or even more, individual steps, depending on the size of your organization. This complexity can significantly prolong the process if done manually, often taking days to weeks to complete. All the while, business operations cease to function, and users cannot access important applications.

The challenge extends beyond just AD recovery. During a cyberattack, AD recovery is only one part of the equation. Your team also will be recovering data, applications, user endpoints, VMs, and more. Without a holistic approach, these complexities can further prolong outages and downtime.

Introducing: Commvault® Cloud Backup & Recovery for Active Directory Enterprise Edition

Last week, we announced how we are solving the challenges associated with recovering and rebuilding AD with Backup & Recovery for Active Directory Enterprise Edition. It brings a new level of resilience to AD by enabling automated, rapid recovery of the AD forest. This new offering eliminates slow and error-prone manual processes often associated with AD forest recoveries. With Backup & Recovery for AD Enterprise Edition, you will be able to:

  • Make AD recovery a snap via automated runbooks: Automated forest recovery runbooks streamline the multi-step process required for AD forest recovery, including the complex hygiene tasks essential for a clean recovery. These runbooks also can be used for regular testing in non-production environments to enhance cyber readiness.
  • Enable fast recovery of the most important AD infrastructure: Visual topology views of your AD environment enable simple and rapid identification of which domain controllers to restore first and how they should be recovered to accelerate the availability of AD services.
  • Accelerate recovery times and advance resilience: Manually recovering an AD forest can take days or even weeks to complete, but with Commvault, you can recover it in a fraction of the time. The Commvault Cloud platform integrates AD forest recovery with granular recovery of both AD and Entra ID, providing comprehensive protection. 

To learn more and demo the solution, visit the Active Directory solution page.

If you missed it, read the full press release here for more details.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We’re thrilled to announce that Commvault COE has earned the Great Place to Work® certification for the eighth year in a row. This recognition reflects our enduring commitment to creating a workplace where employees feel valued, connected, and motivated to grow.

At Commvault, our three core principles – We Care, We Inspire, and We Deliver – shape our culture and define our success. We prioritize holistic wellbeing, diversity, equity, and inclusion, creating an environment where every individual feels supported and empowered.

We also believe that to deliver for our customers and partners, we must first deliver for ourselves – by caring for ourselves. From flexible work arrangements to programs that support mental and physical health, we aim to ensure that every Vaulter can achieve their full potential.

Our culture is built on open communication, genuine care, and regular feedback channels like Vaulter Voices, which allow employees to share their thoughts and ideas. We also place a strong emphasis on professional growth through robust learning and development programs, mentorship opportunities, and skill enhancement workshops, while ensuring work-life balance and personal wellbeing are integral to success.

Being recognized as a Great Place to Work fills us with immense pride and motivates us to create a lasting impact together – not just for the organization but for each other. Looking ahead, we are committed to investing in our people through advanced collaboration tools, wellness programs, and initiatives that strengthen community engagement.

As we navigate the evolving work landscape, our focus will remain on putting people first, driving innovation, and consistently delivering exceptional value to our customers and partners. Congratulations, Team India!

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Imagine conducting a full-scale disaster recovery test while sipping on your latté during a coffee break. Sounds too good to be true, doesn’t it? But with Commvault Cloud Rewind’s specialized cloud resilience platform, this scenario becomes your reality. In a digital age where high-availability cloud services are non-negotiable, robust recovery strategies for cloud infrastructure are more critical than ever.

The Imperative of Cloud Resilience and Cloud Recovery

Cloud services have become the lifeblood of modern enterprises. As a result, any disruption to these services can lead to not only significant financial and reputational losses but also significant waste of critical engineering time and resources.

This is why cloud resilience is not just a buzzword but an essential component of any modern cloud operations strategy. Without reliable cloud-based DR systems, you’re exposing your organization to considerable risks.

The Challenges of Traditional DR in Cloud Computing

Often, executing a full-scale DR test is time-consuming and complex, necessitating intricate planning and coordination. This complexity and investment of time can deter organizations from conducting regular tests, leaving them vulnerable to system failures and data loss.

Revolutionize Your Cloud DR Tests

Cloud Rewind offers a game-changing approach that makes this critical function not only effective but also incredibly efficient and very cost-effective. Imagine being able to run a full DR test over a coffee break. Yes, it’s that fast and simple.

One of our recent users from a multibillion organization in the insurance industry shared his experience: “I am very impressed with how simple the interface is to navigate and perform various tasks,” he said. “I ran a few recoveries earlier today, and it worked 100%.”

Why Cloud Rewind Rebuild Model is the Right Choice for Cloud DR Tests

What makes Cloud Rewind unique is its laser focus on hyperscale cloud environments and our platform’s ability to rebuild isolated on-demand environments quickly. Unlike other platforms that spread their capabilities thin by trying to cover on-premises or hybrid cloud setups, Cloud Rewind is exclusively focused on cloud-based applications. This expertise results in a product that is not just effective but also highly specialized for cloud-based DR.

Key Advantages of Choosing Cloud Rewind

Speed: Execute a full-scale DR test in minutes. No more prolonged downtime or exhaustive preparations or 10-member teams over a weekend.

User-friendliness: Designed with ease of use in mind, Cloud Rewind doesn’t require you to be an expert in DR in cloud computing. Navigate its simple interface and perform various tasks effortlessly.

Cost-effectiveness: The speed and efficiency of Cloud Rewind reduces the costs related to downtime and lost data, offering a highly cost-effective solution for cloud resilience.

By focusing solely on cloud-based application environments, Cloud Rewind offers unparalleled expertise and functionality in cloud resilience and recovery. Learn more about Cloud Rewind and how it can help you execute DR tests in minutes.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

I find it fitting that shortly after we celebrate the start of a new year, we dedicate a day to celebrate and reflect on the legacy of Dr. Martin Luther King, Jr.

Today, Commvault’s U.S. offices are closed to observe Martin Luther King Jr. Day. However, as a global Vaulter community, it’s a time for us to pause and reflect on the profound impact Dr. King had not just in the U.S., but around the world.

Dr. King’s unwavering commitment to equality, justice, and community has inspired generations, and his famous “I Have a Dream” speech continues to resonate today. And while we have made significant progress in the years since his famous speech, there is always more work to be done to create a just and equitable world.

As we have just wrapped up our Commvault Cares Quarter of Caring, Dr. King’s commitment to service is top of mind for me. Our Quarter of Caring is an annual initiative here at Commvault dedicated to giving back to our communities and raising awareness of causes close to our hearts. And while many see MLK Day as a day off of work or school, I see it as a day “on” for our global communities! So today, I encourage you to get involved – whether that be by volunteering, donating, or supporting a local nonprofit.

Let’s all honor Dr. King’s legacy with simple acts of kindness, understanding, and service. Together, we can build a brighter future for all.

Learn more about Commvault’s culture of caring here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The partnership between Commvault and HPE is redefining the world of data protection and management. HPE’s high-performance infrastructure powers an entire ecosystem of scalable, sustainable solutions, while Commvault orchestrates and protects data across that ecosystem. Together, we are empowering data-driven enterprises to securely manage, protect, and recover their data across today’s complex hybrid cloud environments.

HPE’s infrastructure solutions are purpose-built to support the most demanding workloads, delivering unmatched performance and scalability across hybrid, multi-cloud, and on-premises environments. At HPE Discover Las Vegas 2024, the company reaffirmed its commitment to leading the enterprise adoption of AI, further positioning HPE as a cornerstone for modern IT. Partnering with HPE allows Commvault to harness this infrastructure, providing our customers with cyber-resilient solutions that enhance the reliability and efficiency of data protection.

Enhanced Resilience with Active Peer Persistence Integration

Commvault’s deep integration with HPE storage platforms includes advanced snapshot management capabilities that streamline the protection of large databases, medical imagery, and other data-intensive workloads. Building on this, our recent milestone is Commvault’s new integration with HPE’s Active Peer Persistence technology.

Currently available in HPE Alletra 9000 and HPE Alletra Storage MP B10000, HPE’s Active Peer Persistence enables synchronous replication across two geographically separated storage arrays, automatically failing over from one site to another during an outage without any disruption. This continuous availability is crucial for mission-critical applications that require minimal downtime.

With our new integration, Commvault detects when two HPE storage arrays are in an Active Peer Persistence configuration and snaps both arrays simultaneously, backing up each locally. Commvault’s robust data management tools then allow businesses to send extra copies of data to tape (HPE StoreEver), cloud, or other storage options, supporting compliance and adding another layer of data security.

Benefits of the Integration for Data-Driven Businesses

This integration brings significant benefits to customers seeking to maximize resilience, reduce downtime, and streamline backup and recovery processes across distributed environments.

  • Continuous availability: Mission-critical applications benefit from uninterrupted access to data, even in the event of planned or unplanned outages.
  • Network efficiency: By allowing data recovery directly from either primary or secondary arrays, the integration reduces the requirement for additional copies, reducing the overall load on network resources.
  • Enhanced compliance: Commvault’s flexible data management enables additional copies of data to meet various regulatory and compliance needs.

The partnership between Commvault and HPE exemplifies our shared commitment to delivering modern, scalable, and sustainable data protection solutions.

“Partnering with HPE to support Active Peer Persistence underscores our dedication to delivering solutions that drive business continuity and operational efficiency,” said Jeff Carlat, Director – WW Alliances at Commvault. “Together, we are equipping our customers with the tools they need to navigate complex data environments with confidence.”

Learn more at hpe.com/storage.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The Readiverse is an all-encompassing resource designed to help individuals and organizations stay ready in the ever-evolving field of cyber resiliency. It is the ultimate destination for best practices and hands-on knowledge in cyber resilience.

In the Readiverse, you can engage in a variety of learning formats that suit different needs and schedules. Whether you prefer the challenge of tabletop exercises like Minutes to Meltdown, the depth of certifications and workshops, the convenience of how-to videos, or the collaborative spirit of community learning, the Readiverse has it all.

Our platform goes beyond traditional learning methods by offering interactive and dynamic content so that you are well-equipped to handle the latest cyber threats.

Join the Readiverse today to enhance your cyber defenses and be part of a proactive community dedicated to cybersecurity excellence.

What’s new in the Readiverse?

The Readiverse now offers a self-guided and free online Cyber Resilience Certification.

This new certification equips IT and security professionals with the knowledge and skills to build a robust defense against cyber threats in just 4 hours.

This course focuses on the fundamental principles of cyber resilience, covering topics such as early warning systems, threat detection, and advanced recovery techniques.  

Participants gain hands-on experience in configuring and integrating Commvault solutions, including mastering the art of Cleanroom Recovery to minimize downtime and data loss. 

Through a blend of self-paced e-learning modules and hands-on lab sessions, participants gain the practical skills and knowledge to protect their organizations’ assets. And with a certification in hand, they’ll have the confidence and peace of mind that they have the latest skills and knowledge in cyber resilience.

Customers can access the Readiverse courses using their Commvault credentials here, while partners can access the courses through the Commvault Partner Portal.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

When evaluating enterprise cyber resilience solutions, organizations face an important architectural choice between appliance-based approaches like Rubrik’s and software-defined platforms like Commvault’s.

While both vendors provide data protection capabilities, different architectural approaches create distinct cost implications that become apparent throughout the lifecycle of the solution.

Architectural Approaches: Box-Based vs. Platform

Rubrik’s Appliance-Centric Model

Rubrik’s approach centers on physical or virtual appliances that serve as the primary deployment model:

  • Protection capacity is added in fixed increments through additional appliances.
  • Scaling typically requires deploying new appliances when performance or capacity limits are reached.
  • Rubrik’s solution uses an appliance-based architecture where data protection capacity comes in predefined sizing options.
Commvault’s Software-Defined Platform

Commvault employs a software-defined modular architecture:

  • Deployment options include software-only, reference architectures, converged systems, or cloud-based implementations.
  • Resources can be scaled independently and incrementally based on performance or capacity requirements.
  • The Commvault platform can be deployed on existing infrastructure, purpose-built appliances, or as a cloud service.
Cost Implications of Architectural Differences

The architectural distinctions between these solutions create several significant cost considerations:

1. Scaling flexibility and efficiency

Appliance-based approaches often require provisioning capacity in predetermined increments, which can lead to overprovisioning when actual needs fall between appliance size options. According to industry analysts, this step-function scaling can result in unused capacity throughout the deployment lifecycle.

Performance and capacity are intertwined. To enhance performance, an additional Rubrik node must be added, which also incurs the cost of extra storage capacity. Similarly, to increase storage capacity, customers must also pay for additional performance resources (CPU, RAM). This results in increased TCO.

Commvault’s platform modular approach enables more precise scaling, allowing organizations to spend as per actual requirements. This helps reduce resource wastage and improves cost efficiency.

2. Cloud integration approach

As organizations adopt cloud services, the architectural approach significantly impacts cloud protection costs:

Platform approaches may integrate directly with cloud services using native APIs. Commvault offers direct integration with cloud services without requiring virtual appliances, potentially reducing the resources needed for cloud protection.

Total Cost of Ownership Factors

When evaluating total cost of ownership over a three- to five-year period, organizations should consider several key factors:

Cost Category Appliance Approach Impact Platform Approach Advantage
Infrastructure costs Potential overprovisioning Right-sized deployment
Cloud protection costs Virtual appliances in each environment Direct cloud service integration
Scaling costs Step-function increases Incremental based on needs
Technology refresh Full appliance replacement cycles Component-level updates

Beyond Cost: Capability Considerations

The architectural differences extend beyond cost implications to create capability distinctions:

1. Multi-cloud support

Platform architectures typically provide more consistent capabilities across cloud environments by using a common code base with cloud-specific integration points. This can simplify protection across diverse cloud deployments.

2. Workload coverage

Software-defined platforms often support a broader range of workloads, including legacy systems, specialized applications, and diverse infrastructure types. This can eliminate the need for multiple protection solutions.

3. Security integration

The architectural approach also impacts security capabilities. Commvault’s platform includes integrated security features like threat detection, while appliance-focused solutions may require additional components for comprehensive security. Rubrik’s data security solution is delivery through their SaaS, severely limiting functionality in environments where cloud connectivity is restricted or prohibited, such as dark sites or isolated clusters.

Strategic Architectural Considerations

The choice between Rubrik’s appliance-based approach and Commvault’s platform architecture represents a strategic decision with long-term implications.

Organizations should evaluate these solutions based on their specific requirements, considering not just initial costs but long-term factors like scaling efficiency, operational overhead, cloud integration, and security concerns. By understanding the architectural differences and their cost implications, organizations can make more informed decisions about their cyber resilience investments.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

As we approach the end-of-life for Actifio on-premises solutions, set for June 30, 2025, it’s crucial for Managed Service Providers (MSPs) to prepare for the transition. After this date, Actifio will cease to provide updates for security, reliability, and performance, which could significantly impact MSPs relying on this platform for on-premises backup and disaster recovery.

The Challenge

The upcoming deadline necessitates that MSPs migrate their clients to a robust alternative to maintain uninterrupted data protection and security. This transition requires careful evaluation of potential replacements, detailed migration planning, and a seamless execution to maintain client trust and data integrity.

The Opportunity

This period of change presents a perfect opportunity for MSPs to enhance their service offerings by adopting a more advanced, comprehensive solution. Commvault emerges as a superior choice, providing extensive data protection capabilities and innovative features that can elevate the quality of service MSPs offer to their clients.

Why Choose Commvault?

Comprehensive data protection: Commvault delivers an extensive range of data protection services, including state-of-the-art backup and recovery, disaster recovery, and proactive data management. It supports a diverse set of workloads and applications, creating a holistic approach to data safety.

Scalability and flexibility: Designed to accommodate any business size, Commvault’s scalable solutions allow MSPs to tailor services to meet specific client needs, adapting effortlessly as those needs evolve.

Advanced features: With features like deduplication, compression, and encryption, Commvault not only optimizes storage but also fortifies data security. Its automation tools further streamline operations, reducing the administrative load on MSPs.

Enhanced cyber resiliency: Commvault offers robust defenses against modern cyber threats, including ransomware. Its comprehensive security measures, such as immutable backups and anomaly detection, provide MSPs and their clients with peace of mind.

MSP-centric programs: Commvault’s dedicated MSP programs offer tailored resources, support, and flexible pricing models, all designed to help MSPs thrive.

Making the Switch to Commvault

Commvault simplifies the migration process with tools and expert guidance to complete a smooth transition from Actifio. Our team is committed to supporting MSPs every step of the way, from initial planning to full execution.

Key Benefits for MSPs
  • Enhanced service offerings: By leveraging Commvault’s comprehensive solutions, MSPs can expand their range of services, increasing their appeal to current and potential clients.
  • Increased efficiency: Automation and streamlined operations reduce costs and improve service delivery, boosting MSPs’ bottom line.
  • Improved profitability: With MSP-friendly pricing and resource allocation, Commvault helps MSPs enhance their profitability and operational efficiency.

Conclusion: Embrace the Future with Commvault

The end of Actifio’s on-premises offerings marks a critical point for MSPs to reassess their data protection strategies. Commvault stands ready to help MSPs transition smoothly, delivering enhanced service capabilities, operational efficiency, and increased profitability in a post-Actifio landscape.

Don’t delay your preparations. Partner with Commvault today and set the stage for a more resilient, profitable future in managed services.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

As organizations increasingly rely on Software-as-a-Service (SaaS) platforms like Microsoft 365 and Salesforce for business-critical operations, comprehensive protection for these environments has become essential.

While many organizations assume that SaaS providers offer complete data protection, most operate under a shared responsibility model where customers remain responsible for data backup, recovery, and security. Commvault’s SaaS protection capabilities deliver comprehensive security for these critical environments.

The SaaS Protection Imperative

The accelerating adoption of SaaS platforms has created critical protection challenges:

  • Most SaaS providers operate under a shared responsibility model.
  • Organizations are responsible for protecting their SaaS data from loss, corruption, and unauthorized access.
  • Native SaaS protection tools often have significant limitations in retention, granularity, and security.
  • SaaS environments increasingly contain an organization’s most sensitive operational data.

These factors make third-party SaaS protection essential for comprehensive security and compliance.

Microsoft 365 Protection Capabilities

Commvault® Cloud Backup & Recovery for Microsoft 365 delivers SaaS resilience and recovery capabilities specifically designed to provide protection from deletion, corruption, and attack. This includes:

Exchange Online Protection:
  • Protection for Microsoft 365 applications.
  • Provides granular recovery options for mailboxes, emails, attachments, and other Exchange Online components.
SharePoint Online and OneDrive Protection:
  • Preserves document permissions, version history, and metadata.
  • Enables granular recovery of individual documents, libraries, or entire sites.
Teams Protection:
  • Preserves Teams conversations, files, channels, and settings.
  • Enables both granular and complete Teams recovery.

Salesforce Protection Capabilities

Commvault extends its SaaS protection to Salesforce environments, including:

  • Covering both standard and custom objects within Salesforce.
  • Preserving relationships between objects for complete recovery.
  • Seed, mask, and rehydrate sandbox environments for accelerated testing.
  • Unlimited storage, unlimited retention, and advanced protocols (like FedRAMP High) built in.

This comprehensive Salesforce protection allows critical customer and sales data to remain secure and recoverable.

Advanced SaaS Security Features

Beyond basic backup and recovery, Commvault delivers enterprise-grade security capabilities for SaaS environments.

Enhanced Data Security

Commvault implements comprehensive security for SaaS data:

  • The platform offers secure-by-design capabilities with immutability, air-gapping, and zero-trust access baked in.
  • The solution offers Commvault AirGap as an integrated cloud storage target that makes it simple for IT organizations to adopt cloud air gap storage to reduce risk.
  • These security features protect SaaS data against both external threats and insider risks.

Compliance and Governance

Commvault supports compliance capabilities for SaaS data:

  • The platform supports standardized retention, policies, and recoverability across disparate hybrid workloads, including SaaS applications.
  • The solution helps organizations implement consistent governance across SaaS environments.
  • These capabilities help meet regulatory requirements for data protection and retention.

Unified SaaS Protection Management

Commvault delivers consistent management across SaaS protection:

  • The platform eliminates multi-console complexity through unified management.
  • The solution supports standardized retention, policies, and recoverability across disparate hybrid workloads, including SaaS applications like M365, Dynamics 365, Salesforce, and Google Workspace.
  • This unified approach simplifies protection management across multiple SaaS platforms.

The Business Impact of Comprehensive SaaS Protection

For organizations, Commvault’s SaaS protection capabilities deliver several significant business advantages:

Enhanced Business Continuity

Comprehensive SaaS protection enables continuity for critical operations:

  • The solution provides fast and automated backup, flexible and granular restore, and   scalable and unlimited storage.
  • The platform delivers protection from deletion, corruption, and attack with backup and recovery capabilities for Microsoft 365 and Salesforce environments.
  • These capabilities help minimize disruption from data loss or corruption in SaaS environments.

Simplified Compliance Readiness

Commvault’s SaaS protection helps streamline efforts to comply with various industry regulations:

  • The platform supports standardized retention, policies, and recoverability to help meet compliance requirements.
  • Secure, backup, and restore capabilities enable data preservation for compliance purposes.
  • These features simplify auditing and reporting for regulatory requirements.

Reduced Security Risk

Advanced security features minimize risk to SaaS data, as the solution includes immutability, air gapping, and zero-trust access baked in.

SaaS Protection for Critical Environments

As organizations increasingly depend on SaaS platforms for mission-critical operations, comprehensive protection has become essential for business continuity, security, and compliance. Commvault’s superior capabilities for Microsoft 365 and Salesforce protection deliver significant advantages:

  • Comprehensive coverage: Protection for all aspects of SaaS environments, not just the most common elements.
  • Granular recovery: Precise restoration options that minimize disruption and data loss.
  • Enhanced security: Integrated protection against modern threats targeting SaaS data.
  • Simplified compliance readiness: Comprehensive capabilities for helping organizations meet regulatory requirements.

For organizations serious about protecting their mission-critical SaaS environments, Commvault represents a comprehensive solution for protecting enterprises that eliminates gaps and delivers complete recovery when needed.


References and Validation Notes

Primary References:
1. Commvault SaaS protection documentation for Microsoft 365 (Document 3)
2. Commvault Salesforce protection capabilities (Document 3)
3. Security features for SaaS protection (Documents 3, 21)

 

Validation Requirements:
1. Verify specific protection capabilities for individual Microsoft 365 applications (Exchange, SharePoint, Teams)
2. Confirm granular recovery options for Microsoft 365 and Salesforce
3. Validate the security features specifically available for SaaS protection
4. Verify retention capabilities and limitations for SaaS data
5. Confirm any specific compliance certifications or capabilities for SaaS protection

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The shift to cloud computing has become more than a strategic advantage – it’s now a business necessity. According to Gartner, by 2028, cloud computing will shift from being a technology disruptor to becoming a necessary component for maintaining business competitiveness. But with this transformation comes a critical challenge that most organizations haven’t fully addressed: true cyber resilience.

The Hidden 70% Risk in Cloud Environments

Here’s a startling reality that most cloud and security leaders don’t realize: According to our research, in a typical cloud environment, application data makes up only 20% to 30% of the resources, while 50% to 70% consists of cloud configurations that remain completely unprotected by traditional backup solutions.

Think about what this means during a cyber incident or outage. Your backup solution might restore your databases and files, but you also need to consider:

  • Load balancers and security groups.
  • VPC configurations and network policies.
  • Container orchestration settings.
  • API gateways and microservice dependencies.
  • Identity and access management configurations.
  • Infrastructure-as-Code templates.

This is where traditional backup falls catastrophically short.

Beyond Data Protection: The Application-Centric Recovery Revolution

Commvault® Cloud Rewind represents a fundamental shift from data-centric to application-centric recovery. Rather than simply backing up and restoring data files, Cloud Rewind treats your entire cloud environment as code – discovering through collecting configuration metadata not application data, and rebuilding cloud ecosystems with all their dependencies intact.

The Cloud Rewind Advantage: Recovery-as-Code

Cloud Rewind’s patented Recovery-as-Code approach automatically codifies your application’s cloud resources, dependencies, and data for hyperfast rebuild capabilities. This isn’t just backup ­– it’s a complete Cloud Time Machine that can rewind your entire environment to any point in time.

Key capabilities include:
Continuous discovery and learning:
  • Leverage native backup and snapshot APIs provided by cloud platforms such as AWS, Azure and GCP.
  • Maps complex application dependencies in real time.
  • Adapts as your auto-scaled, load-balanced environments change.
  • No agents, no installation, and no maintenance required.
Comprehensive protection:
  • Protects cloud configurations and dependencies for rapid rebuilding.
  • Point-in-time copies with forever incremental backups.
  • Multi-region and cross-cloud replication management.
  • Agentless protection for auto-scaled applications.
Intelligent recovery orchestration:
  • One-click recovery of entire multi-stack environments with dependencies.
  • Cross-zone, cross-region, cross-account, and cross-tenant recovery.
  • Automated resilience simulations and testing.
  • Dependency-aware sequencing for complex applications.

Why Traditional Competitors Fall Short

While competitors like Cohesity, Rubrik, and Veritas focus primarily on data protection, they fundamentally miss the application-centric nature of modern cloud environments. Even traditional cloud service providers, while responsible for protecting customer data, do not secure the underlying cloud infrastructure – leaving customers with limited ability to minimize downtime and recover quickly in the event of a cyber incident.

Drawbacks of traditional resilience tools include:
  • Limited scope: They protect data but ignore the 70% of cloud resources that are configurations.
  • Manual resilience testing: Time-consuming, cumbersome, and often not done enough to establish cyber resilience.
  • Fragmented approach: Applications and infrastructure are treated separately, creating recovery gaps.
  • Legacy architecture: Solutions adapted from on-premises thinking rather than cloud-native design.

Cloud Rewind eliminates these limitations by treating applications and their underlying infrastructure, data layers, networking, and security as a unified, code-based system.

The Three Pillars of Cyber Resilience

Cloud Rewind delivers comprehensive cyber resilience through three core capabilities:

1. Reduce risk:
  • Continuous drift analysis identifies misconfigurations before they become vulnerabilities.
  • Proactive resilience monitoring across all cloud resources.
  • Immutable backups prevent ransomware encryption.
2. Increase readiness.
  • Automated resilience simulations test recovery procedures.
  • No runbooks or scripting required.
  • Always up-to-date protection that scales to 100,000+ cloud resources.
3. Enable recovery.
  • Recovery-as-Code helps eliminate manual rebuild processes.
  • Cross-cloud recovery flexibility prevents vendor lock-in.
  • One-click restoration maintains continuous business and helps reduce unforeseen downtime.

Looking Forward: The Continuous Recovery Era

As cloud environments become increasingly complex with microservices, containers, and serverless architectures, the gap between traditional backup and true resilience will only widen. Cloud Rewind’s Recovery-as-Code approach represents the future of continuous business – where applications and their complete ecosystems can be rebuilt near-instantly, automatically, and reliably.

For organizations serious about cyber resilience, the question isn’t whether you need application-centric recovery – it’s whether you can afford to operate without it. In an era where application availability directly impacts business success, Cloud Rewind provides the comprehensive protection that competitive offerings simply cannot match.

The time to act is now. Every day your organization operates without complete application protection is another day of unnecessary risk. Cloud Rewind helps reduce unknown vulnerabilities by continually discovering and mapping your cloud environment, thus helping enable your business to rewind, recover, and rebuild from cyber incidents in minutes, not weeks.

Learn more about how Cloud Rewind can help your organization rewind and rebuild dynamic and distributed applications hyper-fast from outages and ransomware attacks.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In hybrid enterprises, comprehensive multi-cloud protection has become essential for cyber resilience. As organizations distribute workloads across on-premises data centers, multiple public clouds, and SaaS applications, maintaining consistent protection across these environments is critical. Commvault Cloud offers significant advantages over Cohesity in workload coverage across multi-cloud environments.

The Multi-Cloud Reality

Modern enterprises operate in complex IT environments that span multiple platforms. According to the Flexera 2025 State of the Cloud Report, 70% of respondents embrace hybrid cloud strategies, using at least one public and one private cloud. This fragmentation creates potential protection gaps, particularly in multi-cloud deployments where native tools may create inconsistent protection and security postures.

Commvault vs. Cohesity: Workload Coverage Comparison

When evaluating multi-cloud protection platforms, workload coverage is a key differentiator. Commvault offers broader workload support than Cohesity in several areas:

Critical Cloud Workloads Coverage

Commvault provides protection for several critical workloads:

  • Oracle Cloud Infrastructure: Commvault provides integration with OCI for protection of applications and databases in Oracle’s cloud environment.
  • Cloud-native databases: Commvault supports a wide range of cloud database services across major cloud providers, including Amazon RDS, Azure SQL, and Google Cloud SQL.
  • S3 object storage: Commvault’s platform includes enterprise-grade protection for large-scale object storage deployments across cloud providers, supporting petabyte-scale environments.

Commvault’s platform provides comprehensive protection across these environments, while Cohesity’s public documentation shows more limited coverage in these specific areas.

Analyst Recognition

Industry analysts have recognized Commvault’s comprehensive workload coverage. Commvault received recognition in the Forrester Wave™ for Data Resilience Solutions (Q4 2024), with high scores in several criteria, including SaaS platform support and cloud infrastructure protection.

Cloud Integration Capabilities

Beyond basic backup, Commvault offers integration with various cloud-native services:

  • Storage tier integration: Support for various cloud storage tiers like Amazon S3 Glacier Deep Archive, Azure Archive Storage, and Google Cloud Storage Archive.
  • Database service integration: Direct integration with managed database services for application-consistent protection with minimal performance impact.
  • Security framework integration: Connections with cloud security services to enable coordinated security responses and improved cyber resilience.

Unified Management Experience

Commvault’s Cloud Command provides a single interface for managing protection across all environments, eliminating the need for multiple management consoles when protecting diverse cloud resources. This unified approach reduces management complexity and improves operational efficiency.

Data Mobility Capabilities

Commvault facilitates data movement between cloud environments for:

  • Disaster recovery across cloud platforms.
  • Workload migration between clouds.
  • Optimization of storage costs through intelligent tiering.
  • Meeting data sovereignty requirements in global deployments.

Cost Advantage

Warm site recovery:
  • Commvault’s intelligent disaster recovery approach eliminates the financial burden of maintaining duplicate cloud infrastructure for non-critical workloads. Unlike traditional methods that pre-provision expensive “always-on” failover environments, Commvault delays full VM creation until actual disaster scenarios through its meta-data driven replication.
  • For enterprises managing multi-cloud environments, this translates to millions of dollars in annual savings through optimized cloud consumption and eliminated idle capacity costs.
  • The solution also enables flexible cross-cloud failover strategies without vendor lock-in – a critical advantage in a hybrid cloud landscape.1
On-demand cloud-native cleanroom recovery:
  • Zero infrastructure tax: Unlike legacy solutions requiring dedicated on-premises environments, Commvault provisions isolated recovery spaces in Azure on demand – eliminating 100% of idle infrastructure costs. Organizations pay only for active recovery/testing cycles, converting fixed CapEx into variable OpEx.
  • Continuous resilience validation: Automated weekly recovery testing (vs. costly quarterly manual drills) reduces breach-related downtime costs. Integrated AI identifies “known good” recovery points, accelerating response while minimizing forensic labor expenses.
  • Multi-cloud financial agility: Commvault’s any-to-any recovery architecture prevents vendor lock-in penalties, enabling cost-optimized failovers across AWS/Azure/GCP. Contrast this with rigid single-cloud solutions that incur premium pricing during surge events.2

The Cohesity-Veritas Integration

The merger between Cohesity and Veritas presents potential integration challenges for customers. Industry publications have discussed the time required to integrate these different platforms, with full integration expected to take 18 to 24 months. In contrast, Commvault offers an already-integrated platform designed for hybrid and multi-cloud environments.

Complete Multi-Cloud Protection

For organizations requiring comprehensive protection across diverse cloud environments, Commvault Cloud offers significant advantages in workload coverage breadth. With support for critical cloud services, deep native integration, and unified management, Commvault provides the complete protection that modern multi-cloud enterprises require.


1 https://documentation.commvault.com/11.38/essential/warm_site_recovery_for_replication_groups.html

2 https://documentation.commvault.com/11.38/essential/cleanroom_recovery.html

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In Episode 13 of the Resilience Rundown podcast, Alex Janas, Field CTO at Commvault, joins host Thomas Bryant, Senior Director of Product Marketing at Commvault. The pair delves into the importance of cybersecurity awareness, especially in the context of remote work. The conversation centered on practical tips and strategies to protect personal and professional data in an increasingly digital and distributed work environment.

The Philosophy of Zero Trust

Alex emphasized a philosophy of considering everything suspect. Whether you’re an employee using a home network or a business managing remote workers, the principle of zero trust is crucial.

This means treating every network, device, and interaction as potentially hostile. For employees, this translates to using trusted VPNs to tunnel all traffic, including DNS, through secure connections. Even if a network requires a password and authentication, it’s essential to remain vigilant, as you never know who else has accessed it.

Home Network Vulnerabilities

One key point Alex made is the vulnerability of home networking equipment, such as routers provided by ISPs. These devices often have limited security features. The profit margins on these devices are tight, leading to a short lifespan and a lack of ongoing security updates. This makes them prime targets for bad actors who might use them to steal personal information, lock up data, or even tunnel into your work environment.

Alex recommends investing in more reputable and capable networking devices that offer better security and longer support. While this may require some extra effort in setup and maintenance, it’s a worthwhile investment to protect your data and privacy.

The Threat Landscape

The threats to home networks and personal devices are multifaceted. Bad actors might target you to steal sensitive information like bank account details or use your device as a bot in their command-and-control infrastructure.

Another common tactic is to exploit events posted on social media, such as work anniversaries, to craft convincing phishing emails. These emails often appear to come from HR and prompt you to click on links for benefits or updates, which can lead to malware infections or data breaches.

Cultivating Healthy Paranoia

Alex suggests that a bit of healthy paranoia can go a long way in protecting yourself. Being cautious and taking a moment to verify communications can prevent many common cybersecurity pitfalls. For example, if you receive an email with a link, type the URL manually into your browser instead of clicking on it. If someone calls claiming to be from a company, hang up and call the company back using a verified number.

Practical Tips for Home Security

  1. Use a trusted VPN: Tunnel all your traffic, including DNS, through a secure connection to protect your data.
  2. Invest in better networking equipment: Consider purchasing a router from a reputable company that offers regular security updates.
  3. Be cautious with links and attachments: Verify URLs and attachments before clicking, especially on mobile devices where it can be harder to inspect links.
  4. Monitor your network: Regularly check your home network for suspicious activity.
  5. Educate yourself: Stay informed about the latest cybersecurity threats and best practices.

Reduce Your Risk with Vigilance

In a world where remote work is the norm, cybersecurity awareness is more critical than ever. By adopting a zero-trust mindset, investing in better home networking equipment, and being cautious with online interactions, you can significantly reduce the risk of becoming a victim of cybercrime. For businesses, it’s essential to monitor and protect remote workers’ devices and networks, treating every environment as potentially hostile.

Check out the full episode of the podcast here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We’re thrilled to announce that Commvault® Cloud Backup & Recovery for Google Workspace is now generally available on Google Cloud Marketplace, so you can start safeguarding your critical Google Workspace data today. 

In today’s fast-paced business world, collaboration and efficiency are the lifeblood of success. Google Workspace, a suite of secure, online communication and collaboration tools has become a go-to platform for organizations seeking these advantages. With this cloud-based convenience comes a critical challenge that is often overlooked: data protection.

One Interface for Your SaaS Apps Protection Needs

SaaS applications are not immune to data loss. Accidental deletions, ransomware attacks, and other unforeseen events can wreak havoc on productivity. According to a recent ESG survey, when asked about the most common causes of SaaS data loss, respondents cited 34% from malicious deletions due to malicious attacks and 33% from accidental deletions.1 Given these risks, protecting the data within the SaaS applications that run your business is not just a good idea – it’s essential.

Google Workspace is a highly resilient platform and goes to great lengths to secure customer data, including built-in threat prevention, zero-trust access, and data protection controls. However, businesses typically adopt multiple SaaS apps to provide their teams with the tools they need to get the work done.

Having a consistent way to simply backup, rapidly restore, and flexibly retain critical SaaS application data means greater productivity, reduced risk, and lower costs for your IT organization. With Commvault, customers get a common data protection platform that extends across on premises, cloud, and SaaS, offering cyber-resilient data protection from ransomware, internal bad actors, and accidental deletion.

Now Available on Google Cloud Marketplace: Commvault Cloud Backup & Recovery for Google Workspace 

Commvault Cloud Backup & Recovery for Google Workspace delivers comprehensive, end-to-end enterprise-grade protection for Gmail, Google Drive, and Shared Drives, helping to keep valuable data safe and recoverable – all with the simplicity of SaaS. Commvault offers bundled Google Cloud Storage for Google Workspace protection while providing the broadest workload protection across SaaS, hybrid, and cloud-native workloads. Some key features and benefits include:

  • Comprehensive coverage across Gmail, Google Drive, and Shared Drive data. Plus, automatic discovery of new users and data for proactive protection.
  • Data isolation for air-gapped protection from malicious insiders and ransomware attacks.
  • Granular recovery with flexible point-in-time, in-/out-of-place, and item-level restore options.
  • Long-term, extended retention of active and deleted users with bundled Google Cloud Storage options to maintain SLA compliance.
  • Single, unified solution to protect data in Google Workspace and other SaaS, hybrid, and cloud-native workloads.
  • Simple cloud delivery with no hardware, maintenance, or upfront capital investments required.

“Bringing the Commvault Cloud Backup & Recovery to Google Cloud Marketplace will help customers quickly deploy, manage, and grow the data protection platform on Google Cloud’s trusted, global infrastructure,” said Dai Vu, Managing Director, Marketplace & ISV GTM Programs at Google Cloud. “Commvault can now securely scale and support customers on their digital transformation journeys.” 

Don’t let data loss disrupt your productivity. Take control with Commvault Cloud Backup & Recovery for Google Workspace. To learn more, visit commvault.com/platform/google-workspace. Ready to get started? Request a demo to see our solution in action.

1  Tech Target, “Caution: There are many ways to lose SaaS data,” May 2023

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Whether it’s a sudden market shift, a cybersecurity breach, or a regulatory change, the unexpected can strike at any moment. Being prepared is key to navigating these challenges successfully. This is where risk management and the Digital Operational Resilience Act (DORA) – a regulatory framework that takes effect in January to help protect financial institutions from disruptions like cyberattacks – come into play.

DORA applies to a wide range of financial entities in the European Union, including credit institutions, investment firms, payment institutions, and electronic money institutions. It also covers critical third-party service providers. Let’s explore how DORA’s risk management requirements can help you stay ahead of the game and keep your organization resilient in the face of uncertainty.

What Is Risk Management?

Risk management is the process of identifying, assessing, and prioritizing risks followed by the application of resources to minimize, monitor, and control the probability or impact of unfortunate events. Effective risk management isn’t just about avoiding disasters; it’s about creating a robust framework that supports your strategic goals and enhances your decision-making.

Risk management helps protect your organization’s assets, including financial resources, physical property, and reputation. By identifying potential threats, you can take proactive steps to mitigate them.

Investors, customers, and employees are more likely to trust and support an organization that demonstrates a strong commitment to risk management. Understanding risks helps you make better strategic decisions. It allows you to allocate resources more effectively and focus on areas that truly matter..

How DORA Aligns with Risk Management

DORA and risk management are closely aligned, as both focus on preparing for and mitigating potential disruptions. Here’s how DORA’s components fit into a broader risk management strategy:

  1. Risk management framework: DORA requires financial entities to establish a comprehensive risk management framework. This framework should include policies, procedures, and controls to identify, assess, and manage risks. It’s like having a detailed map of potential hazards, allowing you to navigate them more effectively.
  2. Incident reporting: Timely and accurate incident reporting is crucial for maintaining operational resilience. By reporting incidents, you can quickly address issues and learn from them, reducing the likelihood of similar events in the future.
  3. Testing and exercises: Regular testing and exercises are essential for verifying that your systems and processes can handle disruptions. This might include simulated cyberattacks, system outages, or other scenarios. It’s like practicing fire drills to so that everyone knows what to do in an emergency.
  4. Third-Party Dependencies: Many financial entities rely on third-party service providers for various operations. DORA emphasizes the importance of managing these dependencies so that they do not pose a risk to your operational resilience. This involves conducting due diligence, establishing service-level agreements (SLAs), and monitoring performance.

Best Practices for Risk Management and DORA Compliance

  1. Stay Informed: Keep up to date with the latest regulatory changes and industry best practices. This will help you stay ahead of the curve and confirm your risk management framework remains effective.
  2. Collaborate: Work closely with other departments and stakeholders to create and maintain a holistic approach to risk management. Collaboration can help you identify and address risks that might otherwise go unnoticed.
  3. Continuous improvement: Risk management is an ongoing process. Regularly review and update your risk management approach so that it stays relevant to the current state of your organization.
  4. Technology investment: Invest in the right technology to support your risk management efforts. This might include risk management software, cybersecurity tools, and data analytics platforms.
  5. Cultural shift: Foster a culture of operational resilience within your organization. Encourage employees to report potential risks and participate in risk management activities.

The Future of Risk Management and DORA

As technology continues to evolve, so too will the risks and challenges faced by financial entities. DORA is a step in the right direction, but it’s just the beginning. Here are some trends to watch:

Artificial Intelligence (AI) can help automate risk management processes, making them more efficient and effective. For example, AI can be used to detect and respond to cyber threats in real-time.

Cloud security will become increasingly important as more organizations move to the cloud. DORA’s requirements will likely evolve to address this growing concern.

Regulatory changes are a constant, as governing bodies update their guidelines to address new risks. Stay informed and be prepared to adapt as needed.

Global standards for operational resilience will likely emerge as more countries adopt similar regulatory frameworks. This will make it easier for organizations to operate across different jurisdictions.

Protect Your Organization with a Proactive Approach

Risk management and DORA are powerful tools for preparing for the unexpected. By establishing a robust risk management framework and maintaining DORA compliance, you can help protect your organization’s assets, maintain stakeholder confidence, and achieve your strategic goals. Remember, the key to success is a proactive and continuous approach. Stay informed, collaborate with stakeholders, and invest in the right technology to build a resilient and thriving organization.

With the right tools and strategies, you can turn potential threats into opportunities for growth and improvement. So, take the first step today and start preparing for the unexpected. Your organization’s future depends on it.

Learn more about how you can prepare for the Digital Operational Resilience Act in our Exploring DORA blog series:

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In the ever-evolving landscape of financial technology, regulatory compliance has become a critical aspect of business operations. One of the most significant recent developments in this area is the European Union’s Digital Operational Resilience Act (DORA), which aims to enhance the resilience of the financial sector by setting stringent standards for data management and other operational processes. This blog delves into the importance of data management in complying with DORA and how organizations can navigate these new regulations effectively.

What is DORA?

DORA is a comprehensive regulatory framework designed to address the growing digital risks faced by the financial sector. It covers a wide range of areas, including information and communication technology (ICT) risk management, incident reporting, and third-party service provider oversight. The primary goal of DORA is to verify that financial institutions can maintain their operations and services even in the face of digital disruptions, thereby protecting consumers and maintaining financial stability.

The Importance of Data Management

Data management is at the heart of DORA’s regulatory requirements. Financial institutions must have robust data management practices to maintain the accuracy, integrity, and availability of data. This is crucial for several reasons:

  1. Risk mitigation: Effective data management helps identify and mitigate potential risks. By maintaining accurate and up-to-date data, institutions quickly can detect anomalies and take corrective actions to prevent operational disruptions.
  2. Compliance reporting: DORA mandates detailed incident reporting and regular assessments of ICT risk management. Accurate data is essential for generating these reports and confirming that they meet regulatory standards.
  3. Operational efficiency: Well-managed data can streamline operations, reduce redundancies, and improve decision-making processes. This not only enhances compliance but also boosts overall business performance.
  4. Customer trust: With data breaches and cyberattacks commonplace, maintaining the security and privacy of customer data is paramount. DORA’s data management requirements help build and maintain customer trust.

Key Data Management Requirements Under DORA

To comply with DORA, financial institutions must adhere to several key data management requirements:

  1. Data governance: Establish a clear and comprehensive data governance framework. This includes defining roles and responsibilities, setting data policies, and making sure that your data management practices are integrated into your overall risk management strategy.
  2. Data quality: Verify that data is accurate, complete, and consistent. This involves implementing data validation processes, regular data audits, and using advanced analytics to monitor data quality.
  3. Data security: Implement robust security measures to protect data from unauthorized access, breaches, and cyber threats. This includes encryption, access controls, and regular security assessments.
  4. Data availability: Data must be available and accessible when needed. This involves having reliable backup and recovery systems, as well as disaster recovery plans.
  5. Data privacy: Comply with data privacy regulations, such as the General Data Protection Regulation (GDPR). This includes obtaining proper consent, anonymizing data where necessary, and providing transparency to customers about how their data is used.
  6. Data lifecycle management: Manage the entire lifecycle of data, from creation to disposal. This includes data retention policies, data archiving, and secure data deletion practices.

Implementing Data Management Practices

Implementing effective data management practices to comply with DORA involves several steps:

  1. Assessment and planning: Conduct a thorough assessment of your current data management practices to identify gaps and areas for improvement. Develop a comprehensive plan that aligns with DORA’s requirements and your business objectives.
  2. Technology investment: Invest in advanced data management technologies, such as data lakes, data warehouses, and data governance tools. These technologies can help automate data validation, security, and privacy processes, making compliance more manageable.
  3. Training and awareness: Educate your employees on the importance of data management and the specific requirements of DORA. Foster a culture of data responsibility and awareness throughout the organization.
  4. Regular audits and reviews: Conduct regular audits and reviews of your data management practices to maintain ongoing compliance. Use the results of these audits to make continuous improvements.
  5. Third-party oversight: If you rely on third-party service providers for data management, they also must comply with DORA. This includes conducting due diligence, signing service-level agreements (SLAs), and monitoring their performance regularly.

Best Practices for Data Management

To better understand how to implement DORA’s data management requirements, let’s look at some best practices:

Best Practice: Data Quality Metrics

Use data quality metrics to monitor the accuracy, completeness, and consistency of your data. These metrics can help you identify and address data issues proactively. Improved data quality leads to better decision-making and more reliable compliance reporting.

Best Practice: Automated Data Validation

Implement automated data validation processes to confirm that data is accurate and complete before it is used. This reduces the risk of human error and keeps your data consistently validated.

Best Practice: Secure Data Access Controls

Use role-based access controls and multi-factor authentication to protect sensitive data from unauthorized access. Enhanced security measures reduce the risk of data breaches and confirm that only authorized personnel can access sensitive information.

Challenges and Solutions

While implementing DORA’s data management requirements can be challenging, there are solutions to overcome these obstacles:

  1. Data silos: Many organizations struggle with data silos, where data is stored in isolated systems and departments. This can make it difficult to verify data consistency and availability.
    • Solution: Implement a centralized data management system that integrates data from various sources. This can help break down silos and keep data consistent and accessible.
  2. Resource constraints: Smaller financial institutions may lack the resources to invest in advanced data management technologies and training.
    • Solution: Consider outsourcing data management to third-party service providers that specialize in compliance and have the necessary resources and expertise.
  3. Complexity of regulations: DORA is a complex regulatory framework with many requirements. Understanding and implementing these requirements can be overwhelming.
    • Solution: Seek the help of regulatory compliance experts and use compliance management software to simplify the process.

The Future of Data Management in Regulatory Compliance

As technology continues to evolve, so will the regulatory landscape. Financial institutions must be prepared to adapt their data management practices to meet new and emerging regulations. Here are a few trends to watch:

  1. Artificial Intelligence and Machine Learning can help automate data management processes, improve data quality, and enhance security. These technologies also can help predict and prevent potential risks.
  2. Cloud computing offers scalable and flexible solutions for data management. It can help financial institutions manage large volumes of data more efficiently and securely.
  3. Blockchain technology can provide a secure and transparent way to manage and share data. It can help maintain data integrity and reduce the risk of fraud.
  4. Regulatory technology solutions are designed to help financial institutions comply with regulations more efficiently. These solutions can automate compliance processes, reduce manual effort, and provide real-time monitoring and reporting.

Data Management Is Key to DORA Compliance

DORA represents a significant step forward in enhancing the digital operational resilience of the financial sector. Effective data management is crucial for compliance with DORA and for maintaining the trust and confidence of customers and regulators. By implementing robust data governance, maintaining data quality and security, and staying ahead of regulatory trends, financial institutions can not only meet DORA’s requirements but also gain a competitive edge in the digital age.

DORA’s data management requirements are not just a regulatory burden but an opportunity to improve operational efficiency, mitigate risks, and build a more resilient and trustworthy financial institution. Embrace these requirements and use them as a catalyst for positive change in your organization.

Learn more about how you can prepare for the Digital Operational Resilience Act in our Exploring DORA blog series:

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Forrester recently published the “Forrester Wave: Data Resilience Solutions Q4 2024,” which illustrated a shakeup from the latest 2022 version to the 2024 version by dropping two of the three former “Leaders” to “Strong Performers,” and elevating two former “Strong Performers” to “Leaders.” 

As a result, Commvault was the only vendor that has maintained a position as a “Leader” in all the publications of the Forrester Wave for Data Resilience since its inception in 2019. 

What enabled Commvault to maintain and elevate the status of a top “Leader” in the Wave from 2022 to 2024? In the words of Forrester: “Commvault’s strategic strengths include a commitment to innovation through R&D and acquisition as well as a well-developed partner ecosystem of channel, technology, go-to-market, and infrastructure partners.”  

After going public in 2006, Commvault has continuously and vigorously maintained a cadence of innovation to stay ahead of the latest trends in data management and resilience market. Commvault has delivered not only Backup-as-a-Service for hybrid cloud and container workloads but expanded most recently to modern cloud-native distributed application resilience services through the acquisitions of Appranix, recently renamed Cloud Rewind, and Clumio for cloud-native data heavy workloads.

As cloud-native customers look for hyperscaled environment protection and recovery, Commvault now offers highly differentiated cloud and cyber resilience capabilities, thanks to the ease of onboarding, agentless, and quick-to-realize value of the modern cloud-native software it acquired.

Not only did Forrester recognize the distinct differentiation of Commvault’s modern cloud-native software capabilities by rating them with the highest possible score for the “Hyperscale Cloud/IaaS” and “Kubernetes and Containers” criteria, but other reports also ranked and scored Commvault’s cloud-native capabilities as the most advanced in the industry.  

In the 2024 Gartner Critical Capabilities for Enterprise Backup and Recovery Software Solutions, Commvault was ranked as the top vendor for the “Hybrid/Multicloud” and “SaaS” use cases. In addition, Commvault was positioned as the top “Leader” in GigaOm’s 2024 Sonar for Cloud Native Data Protection. With the acquisition of Appranix, Commvault also has pioneered the cloud infrastructure recovery assurance market cloud-native applications.1 

Not only is Commvault generating results in the leading industry analyst reports, but it also has reported double-digit revenue growth, positive cash flow, and profitability five quarters running. 

Indeed, Commvault’s commitment to innovation and customer-driven nature has elevated it to deliver the most advanced software to address that latest cloud resilience requirements of the modern enterprise.  

1 Hype Cycle for Backup and Data Protection Technologies, 2024, Gartner, July 2024 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Consolidation, like the recent Cohesity-Veritas deal, is expected in a dynamic industry that has rapidly moved from data protection to cyber resilience. We too have complemented our bold and disruptive product roadmap with a few key acquisitions – with one significant difference.

We have a well-defined strategy that includes detailed integration planning and prioritizes our customer needs. So, while Cohesity and Veritas try to make sense of a complex deal and rationalize overlapping portfolios, we are focused on you, our customers.

Our acquisition strategy is all about enhancing our Commvault Cloud cyber resilience platform with cutting-edge capabilities that give you immediate value and solve for future use cases. Case in point, bolstered by our Appranix acquisition in April, our new and unique Cloud Rewind offering helps customers quickly restore their cloud applications and data environments to where they were before a cyberattack or breach. This can mean the difference between a minor disruption and a major crisis. Cloud Rewind is already a key part of our platform and customers are seeing the benefits.

Additionally, by bringing Clumio into the Commvault family, we are revolutionizing recovery for next gen cloud-native stacks – like large and growing GenAI environments with billions of objects in a massive Amazon S3 bucket. Recovery at this scope and scale is truly game-changing, and we just announced Clumio Backtrack to make this easier for customers.

You see, when it comes to M&A, the big questions we ask ourselves are: will this benefit the customer versus forcing them to make unnatural choices? Does the integration complement our platform? And will this help our customers be more resilient?    

We are pushing the boundaries of what’s possible – bringing in the best and brightest minds, planning to invest in R&D, and where it makes sense, making acquisitions to give you cutting-edge, cloud-first technologies.

Commvault is here to help you keep your business continuous.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery