Skip to content

In honor of World Down Syndrome Day, I wanted to share my personal journey with my son Jace.

Jace came into this world in October of 2014, and 12 hours after his birth we were informed of his Down Syndrome diagnosis. Jace spent the first 10 days of his life in the Neonatal Intensive Care Unit, and during that time we quickly had to adjust and come to terms with his diagnosis.

I have to admit, I really struggled with Jace’s diagnosis in the beginning. I worried a lot about the future and the fear of the unknown – which I now know are normal thoughts that many parents have when they find out their child has a disability.

Jump forward 9 years, and Jace is rocking it! He is in Grade 4 and an active participant in his class.  Outside of school, he loves horseback riding and participating in sports. He currently plays hockey every weekend with a great organization, SuperHEROS. They provide the ability to play hockey to kids with disabilities who don’t normally have the chance. He also plays in a similar baseball league in the summer.

Commvault has been incredibly supportive over the years, giving me the flexibility I need to help Jace. And joining our CapAbilities Employee Resource Group (ERG) has been an amazing way for me to share my story with my fellow Vaulters and raise awareness. Our CapAbilities ERG’s mission is to create a safe and empathetic space where Vaulters with disabilities, caregivers, and allies can openly and honestly have discussions and drive change together.

This past November, Commvault once again sponsored a table at PREP’s annual fundraiser, Let’s Talk Hockey, a night with members of the Calgary Flames NHL team. I attended the event with some of my team members and customers, too – all proceeds went directly to the PREP foundation. Jace would not be in the place he is today without the support he receives from PREP.

On World Down Syndrome Day, I’m celebrating by wearing my funky or mismatched socks to recognize how Jace’s extra chromosome makes him extra perfect in our eyes. My goal is to continue to spread awareness and provide opportunities for Jace, and other children like him, to live their best lives and make a difference in this world. Every life deserves to be celebrated.  

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Here at Commvault, wellness continues to be a top priority across our global Vaulter community. As I shared earlier this year, caring for our wellbeing allows us to be our best selves both at home and at work!

Over the years, we’ve continued to evolve our wellness offerings to best support our Vaulters and their families with programs they need for life’s most important moments and stages. Our priority has been, and always will be, to provide inclusive support for our employees and their families. Having this type of support and the right wellness resources allows our Vaulters to thrive.

So, in honor of Women’s History Month and International Women’s Day, I want to talk about how we’re supporting the women of Commvault with specific wellness offerings this month and beyond!

On International Women’s Day, our Women in Technology Employee Resource Group hosted a women’s wellness event in our Australia office, which was also available to all our Vaulters for virtual participation. The event featured guest speaker Annerie Feldman, a Sydney-based health and wellness coach. Annerie spoke about the challenges women often face that impact their wellness, and how women can overcome these obstacles to feel empowered and confident through prioritizing self-care and gaining control of one’s wellness.

Additionally, our India team has organized a breast cancer detection and awareness initiative for our female Vaulters this month. In partnership with Enable India, a non-profit organization working for economic independence and dignity of persons with disability, our Vaulters will have the opportunity to learn more about the importance of breast cancer detection and make connections with Enable India’s knowledgeable female representatives who are visually impaired.

Beyond our March celebratory and awareness events, we also offer a variety of wellness benefits for our U.S. Vaulters, such as family planning, fertility benefits, caregiving, and more. Our family-building partner, Maven, is available to all our U.S. Vaulters. Maven provides access to top-rated fertility, maternity, pediatric, and menopausal care, and offers around-the-clock access to providers who specialize in family-building, a dedicated team of Care Advocates, and an extensive library of clinically validated educational resources. Our Maven partnership also allows us to provide reimbursement opportunities for Vaulters raising their families through adoption or a surrogacy parenting arrangement.

In addition to Maven, we offer support with Fertility Solutions through our U.S. medical partner, UnitedHealthcare. This offering provides guidance and compassionate support to help navigate complex treatment decisions, reduce financial and emotional stress, and reach pregnancy goals with lower medical costs.

We know our Vaulters and their families can face challenges when navigating child, elder, and pet care, so we’ve also partnered with Bright Horizons to help our U.S. Vaulters manage their day-to-day life efficiently and safely by finding care when they need it, both at high-quality centers and in-home.

We are proud to foster a workplace where all our teams feel their wellbeing is prioritized. Offering specific resources for our female Vaulters is crucial in fostering our inclusive culture and diverse workforce. At the end the day, caring for our wellness is crucial to allowing us to deliver for ourselves and others!

Click here to learn more about what it’s like to work at Commvault.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Cloud computing has become essential for businesses of all sizes, offering scalability, flexibility and cost savings. However, managing cloud environments can be complex and chaotic, leading to increased costs, security risks and performance issues. In this blog post, we’ll explore the challenges of cloud computing and provide practical strategies to overcome them. Following these strategies can help you tame cloud chaos and optimize your cloud computing experience. And you’ll learn about Commvault® Cloud and how it can help you achieve cloud success.

The Cloud Computing Chaos

The cloud computing landscape is constantly evolving, with new services and providers emerging regularly. This can be a major advantage for businesses, as it gives them access to a wider range of options and the ability to scale their operations quickly and easily. However, this complexity also can lead to chaos, as businesses struggle to manage multiple cloud environments and ensure that their data and applications are secure and compliant.

One of the biggest challenges of cloud computing is the potential for data breaches and security incidents. Cloud providers are responsible for securing their infrastructure, but businesses also need to take steps to protect their own data and applications. This includes implementing strong access controls, encrypting data and monitoring for suspicious activity.

Another challenge is the potential for performance issues. Cloud providers offer different levels of service, and businesses must choose the appropriate level for their needs. This can be a complex process, considering factors such as bandwidth, latency and storage capacity.

Finally, there is the investment itself. Businesses need to carefully consider the costs of cloud services, including infrastructure, software and support. They also need to factor in the cost of migrating their data and applications to the cloud.

Despite these challenges, cloud computing offers a number of significant benefits. These benefits include increased agility, scalability and cost savings. By understanding the challenges of cloud computing and taking steps to mitigate them, businesses can harness the power of the cloud to achieve their goals.

Ransomware and the Cloud

Ransomware is a type of malware that encrypts files on a victim’s computer and then demands a ransom payment in exchange for decrypting the files. Ransomware attacks can be devastating for businesses, as they can lead to lost data, downtime and financial losses.

Ransomware attacks have become increasingly prevalent in recent years, and cloud environments aren’t immune to this threat. In fact, cloud environments can be particularly vulnerable to ransomware attacks, as they often contain large amounts of sensitive data and are accessible from anywhere in the world. It has been reported that 82% of breaches involve data stored in the cloud – public, private or multiple environments.[1]

Data fragmentation is another key reason ransomware can be hard to defend against – the more widespread your data is across multiple cloud providers, the harder it is to protect. And if you use multiple data protection tools, the complexity is only driven up. As such, more than 90% of respondents surveyed indicated a level of concern that their organization will suffer a ransomware attack – and nearly 40% indicated being extremely concerned. Practically all (97%) indicated concern about the ramifications/fallout resulting from a ransomware attack.[2]

Let’s look at how you can make sense of the chaos these challenges bring in today’s hybrid cloud world.

Stay SaaS Protected

SaaS (software as a service) applications are a popular target for ransomware attacks because they often are used to store sensitive data. There are many things that businesses can do to protect their SaaS applications from ransomware attacks, including:

  • Implementing strong security measures. This includes using strong passwords, enabling two-factor authentication and keeping software up to date.
  • Using a cloud-based data protection solution. This type of solution can help protect your data from ransomware attacks by providing secure storage and backup capabilities.
  • Educating employees about ransomware. Make sure your employees are aware of the risks of ransomware and how to protect themselves from it.
  • Implementing a security incident response plan. This plan should outline the steps that you’ll take in the event of a ransomware attack.
  • Working with a cybersecurity expert. A cybersecurity expert can help you assess your risks and develop a plan to protect your business from ransomware attacks.

By taking these steps, you can help protect your business from ransomware attacks and keep your data safe. They are all proven best practices in defending against today’s threats – and tomorrow’s.

Think Hybrid First

More than likely, you have data both in a private cloud as well as one or more public clouds. Using a hybrid cloud-based approach can help businesses save money and have more control by using the right cloud environment for each task. For example, businesses can use a public cloud for workloads that require scalability and flexibility, and a private cloud for workloads that require more security and control.

Hybrid cloud allows data to move easily between clouds and on-premise environments. This gives businesses the ability to move data where they need it most. This can be especially important for businesses that have workloads that span multiple locations. Look for “any-to-any portability” when considering how to best protect your workloads.

Managing and monitoring all cloud environments in one place also can help businesses see their IT infrastructure better and work more efficiently. This can be done with a variety of tools, such as cloud management platforms and cloud monitoring tools.

Using hybrid cloud-native applications can make businesses more agile and scalable. This means they can create and launch applications that can work on different cloud platforms. This can help reduce development costs and time to market – and improve application performance and reliability.

Start Migration Planning

Data is constantly on the move – depending on how your organization’s needs change, you’ll surely need to migrate data between clouds. As a result, planning is an important part of any cloud migration project. It helps organizations to identify potential risks and challenges, and to develop a strategy for mitigating them. The following are some of the key steps involved in the planning process:

  • Identify the data and applications that need to be migrated: This can be done by conducting an inventory of all of the organization’s data and applications.
  • Evaluate if the data and applications can work with the chosen cloud: Working with the cloud provider to ensure that the data and applications are supported.
  • Develop a migration plan: The migration plan should include:
    • The order in which the data and applications will be migrated.
    • The estimated time frame.
    • The resources that will be required.
    • The risks associated with the migration.
  • Testing: Before implementing the migration plan, it’s important to test it in a non-production environment to identify any potential problems and make sure that the data and applications are migrated successfully. Ensure you’ve got access to a clean environment to do this testing, and test regularly.
  • Implement the migration plan: Once implemented, the migration process should be monitored closely to ensure that there are no problems.

Consider How AI Can Help

With all these best practices being put into place, you may wonder if there is an easier way to implement them, and there is. Generative AI also extends to data protection, and Commvault was among the first to introduce this capability. Arlie – short for “Autonomous Resilience” – is our AI assistant, available 24/7 in the Commvault Cloud platform. Arlie responds to inquiries in plain, simple language, quickly consolidates information and provides users with actionable responses to help save time, respond to threats and improve cyber resiliency.

What benefits does Arlie deliver? Every cyber resilience team is stretched thin and asked to “do more with less.” With Arlie, Commvault Cloud equips users with AI capabilities that enhance their data protection experience. Arlie empowers users across all skill levels to navigate complex tasks, improving overall efficiency and cost-effectiveness. With Arlie, users can do more, faster, without the need for extensive platform knowledge, saving time on routine tasks, quickly responding to threats and enhancing their overall cyber resiliency.

Commvault Cloud: The Solution to Cloud Chaos

We’ve covered a lot here today, so you may be wondering where to start. The Commvault Cloud platform is an AI-enabled, powerful and secure cloud-based data protection solution that can help businesses of all sizes overcome the challenges of cloud computing. Commvault Cloud helps you manage your data in all your clouds and has strong security measures to help keep your data safe from unauthorized users. Additionally, it provides tools to help you save money and enhance your cloud’s performance.

Commvault Cloud’s comprehensive data protection features are deep – they include data backup, recovery, archiving and replication. Commvault Cloud also provides advanced security features such as encryption, access control and auditing. It’s also scalable and flexible, so you can easily add or remove storage as needed. It’s a great solution to the data fragmentation issue and allows you to protect your data estate under a single pane of glass.

If you are looking for a powerful and secure cloud-based data protection solution, look no further – download our buyer’s guide for more answers to your cloud chaos questions. Commvault Cloud can help you overcome the challenges of cloud computing and ensure that your data is safe, secure and accessible, no matter where it resides.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

AI has generated a lot of excitement due to its significant influence on the data protection sector. In the previous year, the rapid expansion of generative AI brought about a revolution in multiple industries, motivating industry leaders to investigate its potential for enhancing their operations. Commvault, a pioneering force in innovation, was the first to introduce this capability, utilizing AI to facilitate prompt and efficient action. Meet Arlie, your round-the-clock AI assistant, ready to answer questions in clear and straightforward language, offering practical solutions to save time, swiftly address threats and enhance cyber resiliency.

Do More, Faster, with Speed & Certainty

Every team is stretched thin and asked to do more with less. But the pace and volume of work doesn’t decrease. Arlie empowers users of all skill levels to navigate complex tasks without the need for extensive platform knowledge – enabling you to do more, faster.

Access a wide range of AI capabilities via a global search bar, including:

  • Real-time insights into operational failures, prioritizing what matters most to you. No more sifting through filters and reports to find the most pressing information – Arlie delivers the most essential information to your fingertips.
  • A “no-code” way to build an integration or code an action where you don’t have to be an expert. Type a description of what you want to do, and Arlie will generate the code on the spot with Commvault APIs.
  • Context-sensitive, guided product walkthroughs that makes it easier for you to set up, customize and tune Commvault Cloud to your specifications. Ask “how to” questions, and get step-by-step documentation complete with annotated screenshots.
  • Advanced troubleshooting to discover operational issues and get fixes and real-time optimization recommendations for enhanced cyber resilience. Resolve problems faster with easy-to-understand resolution summaries and actionable steps.

How it Works

Arlie is designed to give real-time insights and specific action steps you can use to optimize your cyber resilience. Behind the scenes, Arlie interfaces with generative AI models that consolidate information and reports, providing personalized and actionable responses to inquiries. Need to verify a clean point of recovery for critical systems? Just ask Arlie. Want to code an action? Watch as Arlie generates code in seconds using Commvault APIs.

https://play.vidyard.com/eEq4ACirHDh6D7RCZLPhMa?

Arlie seamlessly integrates into the Commvault Cloud console, making it easily accessible without leaving the product. Whether you are a new user or a seasoned expert, Arlie transforms you into a power user by providing quick, accurate and actionable answers to questions about your data and environment.

To learn more about how Arlie is putting generative AI to use to help strengthen and accelerate your resilience practice, visit Commvault.com/Meet-Arlie.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Companies in 2024 will adopt more proactive risk management strategies to not only attempt to thwart malicious threats and data breaches but also to successfully comply with the growing number of cybersecurity regulations.

As the threat landscape expands significantly especially in this era of AI, the requirements for businesses to become transparent about security incidents and disclose attacks and breaches is increasing. These two realities will drive businesses to evolve cybersecurity strategies toward becoming cyber resilient.

Why Cyber Resilience Now?

Cyber resilience is coming to the forefront for many organizations around the global as regulators and legislators look to bolster transparency when it comes to cybersecurity events and preparedness.

“They want corporate executives to articulate whether and how cybersecurity is part of the company’s business strategy, governance processes, financial planning, and capital allocation,” said Melissa Hathaway, president of Hathaway Global Strategies and chair of Commvault’s Cyber Resilience Council, in our 7 Emerging Trends in Cyber Resilience report.

The SEC cybersecurity rule, Information Security Registered Assessors Program (IRAP) in Australia, DORA in the EU, and even state-level rules like New York’s Codes, Rules, and Regulations (23 NYCRR Part 500) are challenging companies to adopt transparency.

Here we look at the existing and emerging regulatory requirements cybersecurity leaders must master to ensure the businesses they support achieve both compliance and cyber resilience.

SEC

The recent SEC rule requires registrants to disclose material cybersecurity incidents. The effects of the rule create a need for security leaders and C-level executives to remain in lockstep when it comes to cybersecurity incidents and the reporting of such incidents. Furthermore, the SEC rule requires companies to articulate how cybersecurity and its oversight fits into their overall risk management program in their annual filings.

“Whether a company loses a factory in a fire – or millions of files in a cybersecurity incident – it maybe material to investors,” SEC Chair Gary Gensler said in a statement.

Nearly a quarter of the way through 2024 there have been a smattering of 8-K filings with the SEC around cyber incidents, and companies with fiscal years that ended December 31 are starting to roll out 10-K statements with updated cyber resilience language.

23 NYCRR Part 500 Regulation

The New York Department of Financial Services (NYDFS) created the Second Amendment to Chapter 23 of the New York Codes, Rules, and Regulations (23 NYCRR Part 500) to strengthen and protect information and financial systems against the increasing prevalence and sophistication of cyberattacks. The law requires NYDFS-covered financial institutions to implement and maintain a cybersecurity program that includes procedures designed to safeguard sensitive customer data from security threats and manage cyber risks.

Among the requirements of 23 NYCRR 500 compliance are several goals that NYCRR 500-covered companies must work to satisfy. To start, it requires entities to establish and maintain a cybersecurity program designed to safeguards the confidentiality, integrity, and availability of their information technology systems. The program should manage risks in several operational areas, including information security, data governance, asset inventory, systems operations, systems and network security, customer data privacy, and more.

The law requires companies to conduct penetration testing and vulnerability assessments. And the list goes on for covered entities.

DORA

Cybersecurity and business leaders also are keeping a close eye on the Digital Operational Resilience Act (DORA) deadlines approaching.

DORA entered into force January 16, 2023, with an implementation period of two years. Covered financial entities are expected to be compliant with the regulation by January 17, 2025. While the law is focused on organizations in the European Union (EU), entities outside the EU in the financial and Information Communication Technologies sectors must also work to align with DORA if they provide crucial ICT services to EU-based financial entities.

DORA creates a regulatory framework for digital operational resilience whereby all covered entities must work to withstand, respond to, and recover from ICT-related disruptions and threats. The law aims to attempt to prevent and mitigate cyber threats. DORA incorporates five key pillars that are as follows:

  • ICT- risk management
  • ICT-related incident reporting
  • Digital operational resilience testing
  • ICT third-party risk
  • Information sharing

DORA looks to improve the resilience of critical digital infrastructure against cybersecurity threats and attacks. By aligning with the tenets of DORA, organizations are closer to improving their cyber resilience profile.

Become Cyber Resilient

If the ever-expanding threat landscape isn’t enough to drive home the need to become cyber resilient, the flurry of new regulations is hammering the point. Businesses must understand what is required of them in terms of reporting.

For many businesses, aligning with myriad regulations will demand cybersecurity knowledge goes beyond the CISO across the organization. That means security leaders must work with C-level executives and the board toward transparency and cyber resilience.

For more information on how Commvault Cloud can help your organization’s cyber resilience journey, visit: https://www.commvault.com/platform.


More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

As Co-Executive Sponsors of our Women in Technology Employee Resource Group (ERG), we’re thrilled to celebrate International Women’s Day across our global Vaulter community! This year’s global theme, #InspireInclusion, is already engrained in Commvault’s culture and the everyday efforts of our ERG. Our Women in Technology ERG brings together both women and allies to elevate and advance gender equality in technology and celebrate the inspiring women of Commvault who are driving our innovation and growth every day.  

Check out this video to see our Vaulters across the world honor International Women’s Day and this year’s global theme!  

https://play.vidyard.com/RCAPied3RuLZVBKhdSgvnn

Today and beyond, we continue to support gender diversity initiatives and invest in our women leaders at all levels. This month, in honor of International Women’s Day and Women’s History Month, Commvault will be hosting our annual Confident U sessions, a women’s leadership development workshop. This is an opportunity for our female Vaulters to truly feel inspired to reach their full potential, as they learn how to transmit confidence, conquer self-doubt, and silence their inner critic to advance their career path.  

Supporting and empowering the women of Commvault is a key component of our DEI strategy. We continue to work together to create a world where difference is valued and belonging is a non-negotiable both inside and outside our workplaces.   

In honor of International Women’s Day, we encourage you to think about how you can #InspireInclusion with those around you.  

And to all the incredibly inspiring and talented women at Commvault – thank you for continuing to make an impact every day!  

Click here to learn more about what it’s like to work at Commvault. 

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

With the constant evolution of cyber threats and the increasing sophistication of cyberattacks, businesses must adopt a proactive approach to protect their data, systems, and operations from potential breaches and disruptions. Early warning systems play a vital role in mitigating the risk of zero-day attacks, supply chain threats, and vulnerability exploitation, which are key aspects of cyber resilience.

Exacerbating the threat is legacy systems, IoT devices, interdependencies between applications, and data sprawl which make patching vulnerabilities becomes a tedious and time-consuming task for IT teams while lengthening periods of risk exposure. Two recent incidents involving MOVEit and SysAid software are prime examples of the escalating threat posed by vulnerability exploitation and supply chain attacks.

The MOVEit attack and the SysAid vulnerability: A Wake-up Call

In May 2023, the CL0P threat group capitalized on a critical vulnerability (CVE-2023-34362) in MOVEit, a widely-used secure file transfer application. This incident, now known as the “MOVEit attack,” has been labeled as the “most impactful zero-day attack of 2023.” [MW1] [PL2] Despite early indicators of experimentation with this vulnerability dating back to 2021, the connection between initial signs and the widespread MOVEit attack was established only after the damage had been done.

In November, the same threat group struck again, this time targeting on-prem systems of SysAid, an IT service and helpdesk application. By exploiting a separate zero-day vulnerability, the attackers gained unauthorized access to sensitive data and disrupted critical business operations.

The Importance of Early Warning Systems

The MOVEit and SysAid vulnerability exploits highlight the critical need for organizations to adopt a cyber resilience strategy that includes implementing a robust early-warning system based on cyber deception to surface and respond to potential threats promptly. By adding detection layers and decoys that look like high-value targets in strategic places in the network and data stores, your security teams can be made aware of suspicious activities and indicators of compromise (IOCs) before an attacker reaches the real high-value targets, significantly reducing the risk of falling victim to zero-day attacks.

Implementing effective early warning provides several benefits to organizations, including:

  1. Proactive Threat Detection: Early warning systems shield sensitive data and business-critical systems from suspicious activities, helping organizations to identify potential threats before they can escalate into full-blown attacks.
  2. Rapid Response: By providing early alerts, organizations can respond swiftly to contain and mitigate threats, minimizing the potential impact on their operations and data.
  3. Reduced Downtime: Early detection and response can help organizations minimize the blast radius and limit downtime and disruptions caused by cyberattacks, helping ensure business continuity and productivity.
  4. Enhanced Security Posture: Early warning systems with deception capabilities help organizations identify and address vulnerabilities promptly, improving their overall security posture and reducing the risk of successful attacks.
  5. Compliance and Regulatory Adherence: Many industries and regulations require organizations to have robust security measures in place and mitigate known vulnerabilities promptly to protect sensitive data and comply with data protection laws. For example, this blog post outlines how Commvault Cloud intelligence and security controls help organizations to comply to the PCI DSS standard.

Why Commvault Cloud

Commvault offers a comprehensive cyber resilience strategy that empowers companies of all sizes and industries to shield their systems and data against bad actors. By leveraging Commvault’s platform, organizations are empowered to level up cyber readiness with proactive measures instead of staying reactive, firefighting done damage.

Download our whitepaper to learn how Commvault’s early warning system leverages advanced cyber deception to provide early warning unmasking IOCs for MOVEit and SysAid-like vulnerability exploitations, supply chain attacks, and unknown zero-day threats.


More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

We’re excited to announce that Commvault Cloud has added support for YugabyteDB, a distributed SQL database known for its horizontal scalability and built-in resilience, empowering organizations to build globally consistent applications.

With this integration, customers have complete protection of their YugabyteDB environments. In the event of failures or logical corruptions across multiple regions, Commvault Cloud provides rapid recovery, enabling you to manage and orchestrate your YugabyteDB workload easily from the Commvault Cloud console.

Protecting sensitive data across distributed applications is crucial in today’s dynamic enterprise landscape. While YugabyteDB is built to handle a number of failures, it is essential to have a dedicated data security and recovery solution to safeguard your critical data against extreme failures, evolving threats, and compliance and regulatory requirements. This is where Commvault Cloud comes in, providing unparalleled cyber resiliency.

The Commvault Cloud and YugabyteDB integration provides the following critical functionality:

  • Backup all namespaces in AWS and Azure: You can configure full and incremental backups, schedule backups, and perform individual table-level backups of YCQL and individual database backups of YSQL.
  • Browse and restore namespaces: You can easily restore individual databases and tables in place to the original cluster or out-of-place to another cluster.
  • Job monitoring and manageability: The Commvault Cloud console provides simple workflows to configure, manage, and monitor the status of any backup or restore process.

When combined, Commvault Cloud and YugabyteDB help organizations build, modernize, and protect business-critical applications against evolving threats and failures.

To get started with YugabyteDB and Commvault Cloud, visit documentation.commvault.com/YugabyteDB.

A full list of Commvault Cloud-supported databases is here.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Today we are celebrating quite a lot! Not only is it Employee Appreciation Day, but it’s also the start of Women’s History Month.  

Employee Appreciation Day is a great reminder to celebrate each other, but, for me, gratitude is always top of mind. Every day, I am so inspired by our incredible Vaulter community across the world. The innovation, care, and collaboration I see daily from our teams is what makes working at Commvault such an amazing experience. Showing that we care and appreciate one another is a core component of our culture, in fact, it’s part of our core values.  

 And speaking of our values, we recently announced our FY24 Q3 CEO Living Our Values Award winners, to recognize Vaulters who have done an exemplary job of living our values every day. With Women’s History Month kicking off today, and International Women’s Day right around the corner, I want to give a special shout-out to all the women who recently won this award. I am so appreciative of Amy, Jill, Kristen, Lena, and Prashanti for continuing to make an impact and leading by example. Thank you for continuing to inspire us all!   

Amy Ngian  

Jill Van Sickle  

Kirsten Krsulj  

Lena Halbourian 

Prashanti Koti  

Today is also an important reminder that gratitude should always be top of mind. I’ve always been so moved by the late Fred Rogers, who accepted his Lifetime Achievement Award at the Emmys in 1997 by stressing the importance of gratitude. That day, he asked this of the audience, “Take 10 seconds to think of the people who have helped you become who you are. Those who have cared about you and wanted what was best for you in life”. On that note, I’d like to ask the following of anyone reading this blog: 

  • First, take 10 seconds (or more!) to think about the people who have helped you get to where you are today. It can span beyond your colleagues. 
  • Second, take another few minutes to actually reach out and thank them. We all know that a little appreciation, even if it’s just a quick text or phone call, can go a long way.  

The power of support is truly incredible. Happy Employee Appreciation Day to all and thank you again to our amazing Vaulters for everything you do! 
 

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The New York Department of Financial Services (NYDFS) is proactively responding to escalating cyber threats with the Second Amendment to Chapter 23 of the New York Codes, Rules, and Regulations (23 NYCRR Part 500). This amendment is a strategic move to fortify information and financial systems against the increasing prevalence and sophistication of cyberattacks. The call for additional controls to manage cyber risks cost-effectively is louder than ever.

As we dissect the intricacies of this regulatory change, it becomes apparent that organizations need more than a mere rulebook; they require a robust solution ready to confront cyber challenges head-on. This is where Commvault® Cloud, powered by Metallic® AI, enters the game to help meet regulatory requirements while elevating cyber resilience. Now is the time for organizations to embrace the future with Commvault Cloud.

Let’s delve into the critical sections of the amendment, exploring how Commvault Cloud innovative solutions align seamlessly with some key requirements.

Cyber Resilience through Intelligent Risk Analysis [Sections 500.9(a), 500.2(c)]

Commvault Cloud’s Risk Analysis solution goes beyond traditional methods. It systematically identifies and categorizes sensitive data across on-premises and cloud locations. By scanning diverse data types, including images, Risk Analysis pinpoints redundant, obsolete, and trivial (ROT) data. It addresses issues related to data sprawl and duplication in addition to facilitating prompt risk assessment based on data sensitivity and impact. File access and privileges related to sensitive data can undergo thorough quick reviews for robust security measures and to intelligently inform the design of your cybersecurity program mandated by the amendment.

AI-Driven Monitoring and Training [Section 500.14(2)]

In addition to the Risk Analysis capabilities, Commvault Cloud introduces Security IQ to furnish a comprehensive security posture dashboard. It provides a dynamic score to aid organizations in identifying and mitigating security risks. Commvault Cloud Threatwise enhances further detection and monitoring capabilities by providing early detection of attempts to infect critical assets with malicious code. If activated, the Network Intelligence sensor actively monitors outbound threats and connections to botnets or malicious URLs and can assist in monitoring suspicious web traffic as required by the amendment as well.

Zero-Trust Access Controls [Section 500.7(a)]

Commvault Cloud goes beyond conventional access controls. It introduces zero-trust controls, including Multi-Factor Authentication (MFA), Multi-Partner Authorization (MPA), Privilege Access Management (PAM), Role-Based Access Control (RBAC) including granular security, and Security Assertion Mark-up Language (SAML). It also provides extensive audit logs when needed. These comprehensive security features finely tune access privileges to align with the highest security standards.

Advanced Encryption for Maximum Security [Section 500.15(a)]

Commvault Cloud meets the best-in-class encryption requirements, aiding the secure transfer of data in-flight via authenticated channels and encrypted data at rest for secured storage. Leveraging FIPS 140-3 (AES 256) and through REST TLS 1.3 authenticated API calls over HTTPS it supports compliance with the industry-standard encryption outlined in the amendment.

Notice of cybersecurity event, Early Warning System, and Cyber Deception Techniques assisting with a cyber incident determination within 72 hours [Section 500.17(a)]

With Commvault Cloud Threatwise, financial entities can receive early warning signals alerts using advanced deception techniques that can identify lateral movements in the network, reconnaissance, or attempts to infect backup workloads and production environments. Additionally, The Anomaly framework can send alerts on unusual file activity, aiding in threat identification within backups. Integrations with SIEM and XSOAR can assist in disabling data aging or users at risk. With Commvault Cloud Threatwise, financial entities can create decoys of servers, endpoints, financial decoys assets such as Swift & ATMs, networking equipment, and more, effectively mimicking financial entity assets. This proactive approach contributes to reducing response times, improving threat intelligence correlations and remediation, thus eventually assisting IRT to shorten the determination time for a cyber incident.

Incident response testing [Section 500.16]

The amendment mandates: “Each covered entity shall periodically, but at a minimum annually, test incident response and BCDR plans ….” Commvault Cloud Backup and Recovery capabilities, along with Commvault Cloud Auto Recovery, Commvault AirGap, and CommServe Recovery Validation Service provide a comprehensive and complete timely solution for this requirement. It simplifies the process for organizations to automate clean recovery of the backup infrastructure and application group recoveries, allowing periodic recovery testing in a clean environment in the cloud, which can be used for cyber forensics as well.

You can restore and support BCDR plans as well as test without impacting production environments. Moreover, the amendment requires that “backups shall be adequately protected from unauthorized alterations or destruction.” Commvault AirGap, together with the zero-trust architecture, control, data, and storage planes separation, Threatwise, security IQ posture dashboard, the anomaly framework, ThreatScan, and the Cleanroom Recovery solutions, support that.

Conclusion: Preparing for the Future with Commvault Cloud

The clock is ticking. Covered financial entities must prepare for compliance with the Second Amendment to 23 NYCRR Part 500. Commvault Cloud, powered by Metallic AI, is the timely solution to boost covered financial entities, providing the necessary tools to support compliance with the amendment. The time to get ready and prepared is now.

Note: This is Commvault’s perspective. Commvault does not provide legal or compliance guidance.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Throughout February, we’ve celebrated Black History Month across our global Vaulter community with events, educational initiatives, and open dialogues hosted by our Multi-Culture Employee Resource Group (ERG) and Diversity, Equity, and Inclusion (DEI) team.

Black History Month is a time to honor the rich heritage of African American contributions to history, culture, and society. Moreover, we’re honoring the achievements and resilience of Black individuals. By embracing the stories and experiences of the Black community, we aim to cultivate a workplace that promotes equity, understanding, and unity among all Vaulters, especially regarding our African American Vaulters. 

We took the opportunity to open the month with an event to spotlight the work and achievements of the legacy organization, United Negro College Fund (UNCF). UNCF, which celebrated 80 years of service this year, is a philanthropic organization that funds scholarships for underrepresented students and general operating support for over 37 private Historically Black Colleges and Universities (HBCUs). Over the years, this organization has cultivated some of the country’s most brilliant minds. We heard from UNCF leaders Ngozi Claire Emenyeonu, Mary Williams, and Lu Duong on how their work in the field is combating bias in the tech industry and how the Commvault community can combat bias in tech too.

To close the month, our Multi-Culture ERG partnered with the Black employees at Microsoft (BAM) ERG Miami, Florida Chapter to host an event featuring former NBA player, Baron Davis. Baron discussed the incredible work he is doing now as a Founder, Entrepreneur, and Investor after retiring from playing NBA basketball for 18 years, as he’s focused on empowering the black community through sports, media, business and technology.

As Martha Delehanty, our Chief People Officer, shared earlier this month, our commitment to Black History Month extends beyond February as we’re actively celebrating Black history and embracing diversity year-round. DEI is foundational to everything we do – every day, we value and celebrate the unique perspectives each employee brings to the table as we foster innovation and collaboration. 

Moving forward, we continue to promote ongoing dialogue, support initiatives that uplift diverse voices, and ensure that our hiring practices and career development opportunities are equitable.

To learn more about our DEI efforts at Commvault, click here.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Incident Response Teams (IRT) are the cyber guardians operating like a 24/7 commando Delta Force. Their mission is to spot cyber threats before they materialize, shielding organizations from potential breaches. In the event of an intrusion, they’re the rapid response force, minimizing impact with unwavering dedication and expertise, ensuring organizations’ digital fortress stands resilient against any challenge.

Driven by the NIST defined incident response lifecycle, this methodology seamlessly incorporates insights and best practices from NIST; MITRE ATT&CK, a globally-accessible knowledge base of adversary Tactics, Techniques, and Procedures (TTP); and CISA’s Incident Response Playbooks. This blog post explores how Commvault® Cloud, powered by Metallic® AI, and strategically combined with SIEM, XSOAR, and other ecosystem integrations, supports incident response, minimizing impacts, and elevating cyber resilience.

Preparation

Proactive preparation is a cornerstone of effective incident response. It involves documenting response policies, early detection instrumentation, and user education on cyber threats. This collaborative effort aligns with the NIST framework and incorporates TTP recommendations.

IRT and IT teams collaborate on incidents and use Commvault Cloud, which provides unified management, boasts a zero-trust architecture, data encryption key isolation, and advanced security measures. Such collaboration creates resilient architectures and preparation for the resiliency of critical operations, preparing for the worst. These efforts are boosted by Commvault Cloud’s cyber resiliency capabilities, AI-driven detection, integration with SIEM/XSOAR, and other ecosystem components.

Detection and Analysis

The detection and analysis phase, a multi-step process, demands accurate identification of incident types. Commvault Cloud, with its AI-driven detection and Threat Scan, excels in identifying suspicious binaries within backups, helping pinpoint potential threats. Commvault Cloud Threatwise complements this by enabling IRT to set countermeasures swiftly, creating decoys for proactive early detection and analysis, then conducting further dynamic analysis in a sandbox environment.

Containment

Effective containment is pivotal, especially in major incidents. Commvault Cloud Threatwise, integrated with Network Access Control (NAC) and leveraging syslog capabilities, aids containment by identifying attacking hosts. Simultaneously, upon suspicious file detections, Commvault Cloud automatically quarantines infected files in backup workloads, and its Cleanroom Recovery option can be leveraged by IRT for a controlled environment for monitoring and further cyber forensics, aligning with IRT’s strategy. The integration with SIEM and XSOAR further streamlines containment efforts when needed including disabling data aging or disabling users at risk when unusual file activity is detected, providing real-time insights and actions.

Eradication and Recovery

After containment, eradication aims to eliminate incident components. Commvault Cloud, with its comprehensive backup and recovery features, validation, and auto-recovery scaling capabilities, plays a crucial role. The Cleanroom Recovery option facilitates post-incident forensics, for a thorough examination of the environment.

Post-Incident Activity

Post-incident “Lessons Learned” meetings are pivotal for continuous improvement. Data analysis, including costs and incident characteristics, informs risk assessments. Effective coordination with external entities, such as incident response teams and law enforcement, is also important when needed. For example, CISA published guidelines to ensure a standardized and resilient approach to cybersecurity incidents for FCEB entities.

To enhance IRT’s proactive stance, IT insights and remediation steps from Commvault Cloud fortify defenses and provide a robust toolkit for comprehensive incident response.

Conclusion

In the dynamic landscape of cyber threats, the synergy between Incident Response Teams and cutting-edge capabilities provided by Commvault Cloud strategically integrated with SIEM, XSOAR, and other ecosystem integrations, is paramount. This collaboration not only minimizes the impact of incidents but also fortifies organizations against evolving cyber threats, for a resilient and effective response. The defenders of resilience, armed with Commvault Cloud, AI, and strategic integration, stand ready to face the challenges of the cyber frontier.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

As organizations grapple with the increasing frequency and sophistication of cyberattacks, it has become imperative to adopt a cyber-resilience mindset. To shed light on this crucial topic, Commvault recently hosted a webinar titled “Embrace the Breach: Business Continuity with Cleanroom Recovery.”

Webinar highlights

In this webinar, industry experts discussed the importance of cyber resilience solutions, including Commvault’s Cleanroom Recovery solution, developed in partnership with Microsoft. Among the key takeaways:

  1. The Shift Towards Cyber Resilience: The webinar emphasized the need for organizations to shift their mindset from “if” or “when” they will be attacked to preparing for recovery and resilience in the face of inevitable breaches. As Tim Zonca, VP of Portfolio Marketing at Commvault, highlighted: “Gone are the days of people thinking, if they get attacked, or even when they get attacked, and a lot of the conversation and the focus and the energy is spent around the assumption that it will happen.” This shift in perspective underscores the urgency of implementing cyber resilience solutions.
  2. The Challenges of Recovery Testing: Recovery testing is crucial for organizations to ensure readiness in the event of a cyberattack. However, the status quo of recovery testing often falls short due to its complexity and cost. Tim Zonca noted that testing the recovery of a wide range of applications is often cumbersome and unfeasible for many organizations. This highlights the need for a more efficient and cost-effective solution.
  3. Commvault Cleanroom Recovery: Developed in partnership with Microsoft, Commvault’s Cleanroom Recovery solution offers a way to securely and quickly recover applications in the event of a cyberattack. This solution provides an on-demand cleanroom that enables reliable cyber recovery. Karl Rautenstrauch, Principal Product Manager at Microsoft, said, “what if there was a way to ensure that you could recover clean, pristine applications, reliable every time? And I think that’s what we’ve built together [with Commvault].” This solution can be used for readiness testing, forensic analysis, or production failover, providing organizations with the flexibility they need.
  4. Any-to-Any Portability and Automation: One of the key advantages of Commvault’s Cleanroom Recovery solution is any-to-any portability. This means that data and applications from anywhere can be recovered to any system, enabling seamless recovery processes. Additionally, the solution is automated, simplifying the recovery process and reducing complexity.
Why you should watch

The webinar offers valuable insights into the evolving landscape of cyber threats and the importance of cyber resilience solutions. By watching, you’ll gain a deeper understanding of:

  1. The rising threat of cyberattacks and the need for cyber resilience.
  2. The challenges associated with traditional recovery testing and the need for a more efficient solution.
  3. Commvault’s Cleanroom Recovery solution and its ability to provide secure and quick recovery from ransomware and other business-impacting problems.
  4. The flexibility of the solution for readiness testing, forensic analysis, and production failover.
  5. The any-to-any portability and automation features that simplify the recovery process.

By embracing the inevitability of breaches and implementing solutions like Commvault’s Cleanroom Recovery, businesses can take positive steps to help ensure continuity and protect themselves against the ever-growing cyber threats. Watch the on-demand webinar today to stay ahead in the battle against cyberattacks.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Discover the latest enhancements and capabilities to elevate your cyber resilience and data protection strategy.

At Commvault, we’re reducing the cost and complexity of protecting your business. In December, we shared some exciting news about the availability of key features of Commvault® Cloud. But that’s not all! We’re thrilled to announce the general availability of Commvault Cloud Platform Release 2024 – our latest release packed with new capabilities and services to meet the needs of today’s hybrid enterprise.

Unlock the Power of Your Data: Unify, Protect, Manage

Platform Release 2024 introduces the latest enhancements to the Commvault Cloud console, eliminating time-consuming manual processes and multiple dashboard reviews through unified management, real-time insights, and consolidated data views – all in one convenient location.

This new approach enables you to easily configure and manage global policies, groups, and permissions in one place. Rapidly deploy them across your entire environment to optimize and unify your configuration management.

Uncover and Eliminate Cyberthreats Sooner – Before Data Is Compromised

An important part of Cyber resilience strategy is discovering and preventing threats. Building on the existing early-warning technology of our Threatwise capabilities, Platform Release 2024 introduces Threatwise Advisor, which continuously assesses workloads in the backup environments to intelligently recommend what decoy sensors to configure and where.

These new capabilities help to simplify the configuration process, reduce deployment time, and minimize the manual processes needed by identifying crucial machines and services. Users can easily and rapidly add detection layers to their production environments around these data sets to provide optimal protection for their most valuable assets.

AI-driven real-time predictive threat analysis

Malware is constantly evolving, and dynamically changing, making it more difficult to detect. Zero-day and polymorphic AI-driven malware can go undetected and remain dormant for days at a time, while backups are continuous. Infected files can end up within the backup, causing a false sense of safety while impacting the ability to recover cleanly. Platform Release 2024 introduces Threat Scan Predict, which takes our existing capabilities to the next level by leveraging AI-driven threat detection and prediction capabilities to identify potentially nefarious files within the backup content.  This provides higher levels of efficacy at detecting zero-day and AI type threats within backups and minimizes the risk of reinfection during data recovery.​

Simple, secure, and rapid recovery of applications​ into an on-demand cleanroom

CISOs are responsible for ensuring their organization is well-prepared to handle cyberattacks and their aftermath. However, recovery readiness and testing can be complex tasks rarely carried out successfully, often due to resource constraints. This puts reliable recovery, readiness, and resilience at risk.

Our new Cleanroom Recovery service for VMs provides a safe and isolated environment where organizations can test their cyber recovery plans without disrupting production systems. This environment allows organizations to identify and address plan gaps before an attack occurs. The cleanroom environment can also be used for forensic analysis of known infected systems, which helps organizations understand the root cause of an attack and take necessary steps to prevent future incidents. And when an incident does happen, our service offers a safe recovery to a cleanroom in the cloud, regardless of the source environment, with any-to-any portability.

Bolster your cyber resilience with Commvault’s latest security integrations

Commvault has partnered with cybersecurity company Netskope to enhance customers’ security posture. This partnership helps customers quickly identify and respond to potential threats by providing combined insights and visibility. Customers can enrich their security insights by integrating Commvault Cloud’s anomaly insights into Netskope Cloud Threat Exchange. SecOP’s teams can correlate existing threat intelligence with these anomaly insights, driving proactive protective actions. Additionally, customers receive threat intelligence from Netskope, such as servers that have been compromised with threat activity. These insights are displayed in Commvault’s Security IQ dashboard, empowering customers to take protective actions and ensure recoverable data.

Security teams face the challenge of responding as quickly as possible to security events to minimize the impact of cyber threats. By leveraging threat insights from DarkTrace, customers can view protected servers that are impacted on Commvault’s Security IQ dashboard. This helps inform users of potential risks to backup assets, enabling proactive measures like Threat Scanning to safeguard data and enable recoverability.

New Dell Hardware Options for Commvault Cloud HyperScale X Appliances

With the introduction of our new Dell backup appliances, we are thrilled to offer you increased flexibility and choice in protecting critical information. Customers can choose from a range of HyperScale X Appliance hardware vendors, enabling you to customize your solution according to your specific requirements and budget while leveraging your existing infrastructure.

Dell customers can now have the HyperScale X Appliance experience on the same hardware used in their existing IT data centers with more solutions to cater to a wide range of needs, capacities, and preferences.

Expanded Commvault Cloud SaaS Capabilities – Coming Soon

On top of these new features, we will also be expanding our comprehensive support for SaaS capabilities in the following areas from mid-March:

  • Threat Scan support for Files: Threat Scan for SaaS now supports Files to enable you to securely recover data as quickly as possible by identifying malware, encrypted content, and vulnerable data. This provides safe recovery options to recover clean data and avoid reinfection by accidentally restoring malicious files.
  • Risk Analysis support for M365: Risk Analysis for SaaS supports M365, offers a better way to secure and defend your M365 data by making it easy to systematically discover, classify, and protect dark and sensitive data, empowering a proactive defense against data breaches and helping you meet your compliance requirements.
  • Auto Recovery for VMs: Auto Recovery as a service for VMs delivers secure, automated recovery at scale to help you quickly and securely recover VM workloads from disasters with minimal data loss and downtime.

These are just a few of the amazing features we have in Platform Release 2024. You can learn more about the latest features:

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Cyberattacks have evolved into a pervasive and sophisticated threat, posing a significant danger to organizations of all sizes. The ever-changing nature of cyber threats necessitates a new way of thinking when it comes to cyber resilience. Despite deploying the best perimeter security out there, the odds of bad actors getting in are very high. With that in mind, how can you help ensure that you can quickly recover when that day comes and, equally as important, how can you TEST your recovery in advance to make sure your plans are going to work?

Cleanroom Recovery, introduced in November and available today supporting software virtual machine (VM) workloads, gives organizations the knowledge to help avert attacks, defend against bad actors, and restore environments to a secure state.

But, Cleanroom Recovery also provides a safe and isolated environment where organizations can easily test their cyber recovery plans without disrupting production systems. This environment allows organizations to identify and address gaps in their plans before an actual attack occurs. Cleanroom environments also provide forensic analysis of known infected systems and provide analysis that helps organizations understand the root cause of the attack—critical information to prevent future incidents.

Cleanroom Recovery should be a primary pillar in every organization’s cyber resilience strategy.

Today’s Cyber Recovery Reality: It’s Not Easy

The frequency and severity of cyberattacks have escalated dramatically in recent years, posing a substantial threat to organizations across all industries. These attacks can have devastating consequences, including data breaches, financial losses, and irreparable reputational damage.

In a recent survey by The Futurum Group 98% of respondents indicated that data recoverability influences their resilience against ransomware attacks, with three-quarters of respondents suggesting that it is very or critically influential. Effective cyber recovery is crucial for organizations to minimize downtime, restore business operations, and safeguard their reputation after a cyberattack. However, many organizations struggle to adequately testtheir cyber recovery plans, leaving them vulnerable to real-world attacks.

In the evolving hybrid world, organizations must adhere to different legislative mandates that come into play. Specifically, the National Institute of Standards and Technology (NIST) and Digital Operational Resilience Act (DORA) frameworks have become top of mind for organizations. These legislative practices are mandating the requirements for testing, putting the responsibility on enterprises to be prepared with continuous testing that will help organizations avoid massive penalties and fines.

Organizations must continuously test their recovery approach to ensure a frictionless, rapid return to business operations.

https://play.vidyard.com/Yz7D3oyrUPoTpuEHMTWZzb
Watch our Cleanroom Recovery webinar to learn more.

The Limitations of Current Cyber Recovery Testing Approaches

Traditional cyber recovery testing methods, such as tabletop exercises, often fail to adequately prepare organizations for the complexities and chaos of real-life cyber recovery scenarios. These exercises typically involve discussions and simulations that lack the realism and urgency of an actual attack.

Moreover, testing cyber recovery plans in hybrid environments can be time-consuming, complex, and expensive. With workloads spread across multiple clouds, on-premises hypervisors, and physical servers, organizations must perform testing within each environment separately. True cyber resilience isn’t solely a technological threshold that enterprises must hurdle; organizations must also understand its role in achieving true resilience.

With multiple teams and different silos, this is as much a business-critical endeavor as it is a technological necessity. Traditionally, IT domains operated separately, but for true cyber resilience, technology teams and lines of business must collaborate and converge efforts. Top-level executives must mandate organizations to build cyber security awareness and adopt best practices to ensure rapid recovery.

As business culture evolves to encourage more and more collaboration across teams, today’s organizations are ready to embrace cleanroom recovery.

Commvault Cloud Cleanroom Recovery

In the face of the constant threat of cyber breaches, successful recovery hinges on the diligence of cyber testing and cyber resilience strategies.

Commvault Cloud’s Cleanroom Recovery addresses a critical need for cyber readiness by providing a comprehensive testing and failover solution that enables organizations to more effectively mitigate risk.

Key features of Commvault Cloud’s Cleanroom Recovery include:

  • Comprehensive testing environment: Cleanroom Recovery provides a safe and isolated environment where organizations can test their cyber recovery plans without the risk of disrupting production systems.
  • Secure forensic analysis: Cleanroom Recovery can be used to conduct forensic analysis of known infected systems and identify the root cause of an attack.
  • Faster recovery times: Cleanroom Recovery can help organizations recover from cyberattacks more quickly by providing a streamlined recovery process.
  • Reduced downtime: Cleanroom Recovery can help organizations minimize downtime by providing a production failover solution.

Cleanroom Recovery provides a safe and isolated environment for testing cyber recovery plans, conducting forensic analysis, and ensuring business continuity if a breach does occur. Cleanroom Recovery can help organizations improve their cyber resilience by providing benefits such as:

  • Reduced risk of re-infection: Cleanroom Recovery provides a safe and isolated environment where workloads can be recovered without the risk of re-infection.
  • Enhanced security: Cleanroom Recovery can be used to identify and address security vulnerabilities in cyber recovery plans.
  • Simplified failover: Cleanroom Recovery can serve as a production failover solution in the event of a breach, ensuring that production operation recovery is conducted within a sanitized environment.

Use Cases for Cleanroom Recovery

Organizations can apply Cleanroom Recovery in several scenarios today to help ensure business operations continue without incident in the face of cyberattacks.

Testing Cyber Recovery Plans in a Hybrid Environment

Cleanroom Recovery simplifies and streamlines the process of testing cyber recovery plans in hybrid environments. With its any-to-any portability feature, Cleanroom Recovery allows organizations to recover workloads from multiple clouds, on-premises hypervisors, and physical servers to a common environment within the cleanroom. This eliminates the need to perform testing within each environment separately, saving time and resources.

Forensic Analysis of Known Infected Systems

In addition to cyber recovery testing, Cleanroom Recovery provides a secure environment for conducting forensic analysis of known infected systems. This analysis can help organizations identify the root cause of an attack, understand how the attackers gained access to their systems, and take steps to prevent future incidents.

Production Failover in the Event of a Breach

Cleanroom Recovery can serve as a production failover solution in the event of a breach. This means that if a cyberattack disrupts an organization’s production systems, it can quickly and easily recover its workloads to a clean environment within the cleanroom. This can help organizations minimize downtime and get their business back up and running quickly.

Failure is Not an Option

In today’s dynamic cybersecurity landscape, organizations must proactively address the ever-increasing threat of cyberattacks. Commvault Cloud’s Cleanroom Recovery is a powerful tool for organizations to enhance their cyber resilience by providing a comprehensive testing environment, secure forensic analysis capabilities, and a production failover solution. By adopting Cleanroom Recovery, organizations can confidently test their cyber recovery plans, identify and remediate vulnerabilities, and ensure business continuity in the face of cyberattacks.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Ransomware thrives in uncertainty. Resilience suffers. Keeping your business online and fighting through an attack is stressful enough. Uncertainty and chaos should not come from vendors who proport to help maintain resilience.

The latest industry consolidation news with Cohesity announcing its intention to acquire Veritas’ data protection unit is causing uncertainty and doubt for their customers — and for good reason.

Merger Pitfalls for Veritas + Cohesity Customers to Avoid

This merger brings disconnected platforms, with disconnected approaches, and dissonant cultures, to try to address a single problem: maintaining resilience through cyberattacks. With such major redundancies in their product lines the question on customers’ and partners’ minds is, “what gets cut and what stays?”

These deals often require customers to ultimately make changes, whether they like it or not. And change has been constant for many customers. In the last few years there have been multiple changes to Veritas’s platform starting with a switch to a new vendor for SaaS workloads, only to acquire another company later and force yet another change. Customers may also wonder what other changes are in store: What changes will they need to make to their disaster and cyber recovery plans? How will all this impact costs, operational resources, and their ability to be resilient?

The integration process between any two companies is a complex and time-consuming endeavor, likely taking several years to complete. At a time when data has never been more vulnerable to attacks, the transition can be quite chaotic for impacted customers and partners. But it doesn’t have to be.

Commvault Cloud: The cure for chaos

We are biased: we exist to help customers stay online and fight through threats to their business. The cure for this chaos is consistency. Consistent innovation. Consistent focus. Consistent customer success. We have a proven track record that demonstrates our consistent leadership. We’ve been public since 2006, just had our best quarter in history, and we recently introduced a unique cyber resilience platform — Commvault Cloud — that is unlike anything else on the market today. It offers cyber resilience through a single and unified platform with the flexibility to deploy as SaaS or on-premises, all running on the same modern highly scalable and secure codebase.

Our unified architecture is different by design to help future-proof your cyber resilience. We offer the only cyber resilience platform with any-to-any portability, making it possible to protect any data, in any location, and recover it from anywhere to anywhere. The result is unparalleled resilience for the hybrid enterprise.

We also recognize that cyber resilience starts before an attack, and never stops. That’s why we built Commvault Cloud to enable customers to advance their security posture before an attack by understanding the risk of sensitive data, categorizing and remediating those risks, getting an early warning of attacks to minimize the impact, and enabling rapid recovery in the event of an attack.

We’re also revolutionizing cyber recovery with cutting-edge innovations as part of Commvault Cloud, like Cleanroom Recovery. This offering provides a clean, safe environment to perform full-scale recoveries at-scale to enable business resilience in the face of cyberattacks. Equally as important, we enable customers to test their recovery plans, closing the gap between incident response planning and recovery. With Cleanroom Recovery, you can have peace of mind knowing that your data is protected, and your operations can swiftly resume, allowing you to focus on what matters most: serving your customers’ needs.

A Connected Ecosystem

Partners are key to Commvault Cloud. Today, we have integrations with all the major cloud service providers, as well as leading GSIs, technology, channel, security, and AI partners. Commvault Cloud gets better as it scales across the partner landscape.

Make the safe bet with Commvault Cloud

When it comes to cyber resilience, there is no time for chaos. Commvault Cloud is the cure for chaos and we’re just getting started. Give us a try today: https://www.commvault.com/free-trial

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Here at Commvault, our values – we connect, we inspire, we care, we deliver – are foundational to everything we do. 

This week, we hosted our quarterly internal Global Town Hall meeting and presented our FY24 Q3 CEO Living Our Values Awards. This awards program helps us to globally recognize and celebrate our Vaulters for their incredible work as they live our values each day. 

I’m so proud to announce our FY24 Q3 CEO Living Our Values Award winners: 

Paul Lancaster 

Lena Halbourian 

Sajjad Petkar 

Chris Stocker

Minutes to Meltdown Team 

Alex Janas  

Amy Ngian  

Richard Gay

Jill Van Sickle  

Michael Stempf  

Curtis Moyer 

Alan Wrafter 

Zero Trust Segmentation Team 

Engineering 

  • Mike Confenti  
  • Kalyan Kota   
  • Prashanti Koti  
  • Pankaj Kumar   
  • Ravi Kumarasamy   
  • Kevin Low 

Network 

  • C Dileep  
  • Anil K  
  • Michael Montenegro  
  • Rob O’Brien  
  • Theron Parks 

IT Systems 

  • Kyle Allocca   
  • Ernie Costa 
  • Bill Huskey 
  • Tim Karaban 
  • Kirsten Krsulj 
  • Preetham Mutyala     
  • Prakash Ramakrishnan
  • Pradeep Chandregowda 

     

All these winners set an inspiring example of what it truly means to be a Vaulter! 

To learn more about what it’s like to work at Commvault, check out our careers site

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Cyber and ransomware attacks are rising, but that’s not the only risk. Far too often, a company thinks data is secure, backed up, and recoverable — when it’s not. On top of that, organizations are creating unfathomable amounts of data distributed across clouds, regions, applications, and partners. This brings a complexity that poses a significant challenge to ensuring cyber resilience. 

This blog post will guide you in safeguarding your company’s data across multiple clouds. We will cover topics such as avoiding bandwidth constraints during backup, implementing air gap ransomware protection, having the right cyber resilience plan, and making decisions in partnership with the broader business. We will also discuss the importance of staying alert with a multilayered approach to detection and response and having visibility into your cloud environment. 

Avoid Bandwidth Constraints During Backup  

Bandwidth constraints can be a significant challenge when backing up data to the cloud. Traditional backup methods can consume a large amount of bandwidth, slowing down other applications, and impacting productivity. However, there are several ways to avoid bandwidth constraints during backup. 

One effective way to reduce bandwidth consumption is to use cyber resilience and data protection solutions with advanced deduplication and compression technology. These solutions can decrease the size of the data before it is sent across the network, which can significantly reduce bandwidth usage. 

If you’re running a legacy backup product, this is one big reason to modernize your solution. Many legacy products need built-in deduplication and compression features, which can significantly slow down your backups. By modernizing your solution, you can take advantage of these features and improve your backup performance.  

As you research different backup solutions, select a provider with proven network optimization as part of the underlying technology. Some solutions may offer bandwidth optimization but fail to deliver on this promise. Make sure to test the solution before you purchase it to ensure that it meets your needs.  

Implement Air Gap Ransomware Protection 

A cyberattack has hit you — now what? Air gap ransomware protection safeguards your company’s data across multiple clouds. SaaS-delivered protection can create secondary data copies in resilient, immutable, and isolated cloud storage. This approach ensures that data remains unchangeable, isolated, and swiftly retrievable in the unfortunate event of a ransomware attack.

Air gap ransomware protection provides an additional layer of security by creating a physical or logical separation between production data and backup data. This makes it more difficult for ransomware to spread to backups and ensures a clean copy of data is available for recovery.

Air gap ransomware protection is typically delivered as a SaaS solution that can protect both on-premises and multi-cloud data. This makes it a convenient and cost-effective way to protect your data from ransomware attacks. 

Here are some additional tips for implementing air gap ransomware protection:

  • Use a backup solution that supports air gap ransomware protection. 
  • Ensure that your backup data is stored in a geographically separate location from your production data. 
  • Encrypt your backup data both at rest and in transit. 
  • Regularly test your air gap ransomware protection solution to ensure it works properly.
  • Educate your employees about ransomware and how to protect themselves from it.

You can help safeguard your company’s data from ransomware attacks and ensure that you have a clean copy of data available for recovery in the event of a disaster.

Have the Right Cyber Resilience Plan in Place  

A comprehensive cyber resilience plan is essential for safeguarding your company’s data across multiple clouds. An effective plan ensures that your data is protected against various risks, including hardware failure, software corruption, human error, and ransomware attacks. Here are some key considerations when developing a robust cyber resilience plan: 

  • Define clear Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) 
  • Choose the proper backup storage 
  • Implement appropriate retention policies 
  • Regularly test your plan 
  • Use an intelligent configuration wizard 
  • Store backup data off-site  

You can help safeguard company’s data across multiple clouds and ensure that you can quickly and easily recover your data in the event of a disaster.

Make Decisions in Partnership with the Broader Business 

Making data protection decisions with the broader business ensures a holistic and practical approach to safeguarding your company’s data across multiple clouds. Firstly, confirming that the business understands the risks and costs associated with data loss is crucial. Educating stakeholders about the potential impact of data breaches, regulatory penalties, and reputational damage emphasizes the significance of data protection investments. 

Secondly, backup parameters should be selected per compliance regulations and internal practices. Involving the business in decision-making processes around cyber resilience and data protection solutions guarantees alignment with organizational policies and legal requirements. This collaborative approach fosters a culture of shared responsibility for data security. 

Lastly, aligning the cyber resilience and data protection solution with the business’s overall goals and objectives ensures these efforts directly contribute to the company’s success. Prioritizing cyber resilience initiatives that support strategic objectives, such as improving customer experience or expanding into new markets, demonstrates the value of data as a strategic asset. 

By working with the broader business, you can ensure that your data protection strategy is effective and meets the organization’s needs. This will help to protect your company’s data from loss, theft, and unauthorized access.

Don’t Make Backup an Afterthought 

Backups are often an afterthought, done only when necessary. But in today’s digital world, where data is essential to the success of any business, backups should be a critical part of your cyber resilience strategy to ensure business continuity. 

Data loss can occur for various reasons, including hardware failure, software corruption, human error, and ransomware attacks. If you have a reliable backup, you could retain valuable data and experience significant downtime, saving your business time and money.

To avoid these risks, it’s essential to make data security and protection part of the planning process for all new applications. This includes identifying what data needs to be backed up, how often it is required, and where the backups will be stored. You should also invest in a reliable backup solution designed for hybrid clouds. 

Engage Unified Management

Avoid using many tools and platforms that create overly complex cyber resilience interfaces. A solution that operates through a single-pane-of-glass dashboard protects all your workloads while your data security remains as efficient and comprehensive as possible. 

A unified solution provides critical visibility with the ability to manage any data anywhere from one console. You can select SaaS and self-managed solutions if your strategy requires and still enjoy industry-leading technology. You get everything you need to modernize your cloud journey from a single vendor. 

Stay Alert with a Multilayered Approach to Detection and Response 

A multilayered approach to detection and response is crucial for staying alert to potential threats and safeguarding your company’s data across multiple clouds. This approach involves implementing advanced intelligence, threat detection, and early warning systems to identify and respond to security incidents proactively. 

Advanced intelligence gathers and analyzes data from various sources, such as network traffic, endpoint activity, and user behavior, to detect suspicious patterns and activities. Threat detection systems use machine learning and artificial intelligence to identify known and emerging threats, enabling you to take immediate action to mitigate risks. Early warning systems provide real-time alerts and notifications when potential threats are detected, allowing you to respond swiftly and effectively. 

By combining these layers of protection, you can stay ahead of potential data breaches and minimize the impact of security incidents. This comprehensive approach enhances your overall security posture and ensures the integrity and confidentiality of your company’s data across multiple cloud environments. 

Be Cloud Ready 

Being cloud-ready means having the proper infrastructure, processes, and skills to use cloud computing. Being cloud-ready is essential for businesses looking to safeguard their data across multiple clouds.

As companies face rapidly growing data sets and evolving technologies, traditional backup methods must be revised. If a company isn’t cloud-ready, its backups can slow down or stop working altogether as it struggles to handle more data, users, and diversified environments.

A cloud-based cyber resilience and data protection solution can help companies to be more agile and responsive to changing data needs. With a cloud-based solution, companies can:

  • Scale their backups easily
  • Back up data from multiple locations
  • Protect data from disasters
  • Recover data quickly
  • Comply with regulations

By being cloud-ready, companies can take advantage of the many benefits of cloud computing and safeguard their data across multiple clouds. You won’t have to worry about rightsizing your infrastructure because the backup system is elastic. It shrinks or grows as your needs do and is easy to implement. Consider a SaaS backup and recovery solution to protect on-premises and cloud workloads.

In Summary 

Deploying outdated strategies for data protection is an expensive mistake — and it’s not just about minimizing downtime for business continuity. Commvault’s unique platform capabilities are designed to help enterprises reduce costs by simplifying management, optimizing cloud strategies, reducing security risks, and improving business continuity. 

With Commvault, you don’t have to sacrifice. With comprehensive coverage across on-prem, multi-cloud, SaaS, and edge data, Commvault Cloud delivers single-solution protection across your entire data estate. 

Download the Free Buyers Guide to learn how to navigate the challenges of safeguarding your data. 

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago