Skip to content

https://play.vidyard.com/hFMHqJvmMJXMVRZLNiUEnR
Takeaway 1: Despite the challenges of a ransomware attack, having data stored in the cloud can help minimize the damage and keep operations running.

The panellists discussed the challenges of a ransomware attack, with Tony Kinkead noting that ransomware cybersecurity was a big part of their product offering. Paul Vries discussed the attack they experienced, saying, “We have a nonprivice environment and everything was encrypted. Everything that was the main joint was encrypted.”

He explained that they had to use indicators of compromise to determine which files were uploaded and when the attack occurred, and then restore to a safe version of the data.

Vries further noted that they had already moved a lot of users to the cloud, which helped minimize the damage and keep operations running: “A lot of the office users could remain working because their data was already in the cloud and only the main joint device were attacked.” This allowed them to focus on documenting the attack and getting ahead of it the next time.

Takeaway 2: Cybersecurity is an arms race, and organizations need to take steps to reduce their risk of attack.

Organizations need to take steps to reduce the risk of attack, as attackers only need to find one weakness to be successful. As Kinkead put it, organizations need to create a layered level of security in order to operate in a Zero Trust security model. “You want to secure every part of your infrastructure by itself,” he said, noting that “if the attacker gets access to a portion of your network, you were lucky.”

Vries agreed, noting that “it’s an arms race, and the attackers only have to find one weakness and you have to protect against all of them.”

Martijn Hoogesteger shared an example of how this can work in practice, noting that his organization had “deployed a number of decoys” to “whitelist and take out some noise” in a South American R&D facility. This allowed them to “stop the individual” who was attempting to gain access to the “crown jewels” of the organization.

Takeaway 3: The key to successful data protection is to act quickly and have a plan in place

Kinkead stressed the importance of acting fast in the data protection phase. “You have to act immediately, but you also have to follow the plan or work with external teams to come up with the right approach,” he said.

“You have to have a strategy around the immutability of your backups to be able to recover your data yourself, even though you might still be paying to prevent them from publishing some of that data.”

Remko Deenik pointed out that there was still more that could be done to protect data, while Vries noted the importance of awareness. Kinkead suggested that collaboration was key, saying, “like I also heard from Microsoft earlier, like collaboratively define those standards and there are already a lot of those standards that we worked out, like CIS and a lot of others, where we basically agree on what should be base hardening rules, what should be best practices, et cetera.”

Vries also suggested that IP addresses and exports could be used to contact systems locally, while Deenik suggested that digital forensic investigations could be used to figure out what data had been stolen. He noted that even if the data was stolen, it may still be possible to innovate and stay in business.

Discover how prepared you are for ransomware attacks by taking our quick assessment today. Evaluate your ransomware protection and recovery capabilities and get valuable insights from Commvault’s experts. Don’t leave your business vulnerable to cyber threats, act now and find out your level of ransomware preparedness! 
https://www.commvault.com/ransomware/risk-assessment

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

As Co-Executive Sponsors of our Women in Technology Employee Resource Group (ERG), we’re thrilled to celebrate International Women’s Day as we honor women’s achievements, raise awareness about bias, and take action to drive gender equality. But we’re not just celebrating for one day… we’re honouring women the entire month of March, which also happens to be Women’s History Month! Our Women in Technology ERG brings together both women and allies to elevate and advance gender equality in technology and celebrate the inspiring women of Commvault who are driving our innovation and growth every day.

Today we’re amplifying our Vaulters’ voices across the world as they share stories of women who have inspired them throughout their lives.

In the coming weeks, we’ll be hosting a variety of learning opportunities and global events, in partnership with our DE&I team, to connect and inspire as we continue the conversation together about equity in action.

It’s so inspiring to see our Vaulter community come together and celebrate the importance of a diverse, equitable, and inclusive culture. We continue to work together to create a world where difference is valued and belonging is a non-negotiable both inside and outside our workplaces.  

Click here to learn more about what it’s like to work at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

The cloud has revolutionized how businesses operate, allowing them to take advantage of its scalability and flexibility while reducing costs. However, protecting data remains a critical challenge, with 98% of businesses reporting a cloud data breach within 1.5 years1, according to IDC research – highlighting the need for organizations to take additional measures to protect their data.

Cloud service providers understand the importance of safeguarding data and applications within their environment and have developed a Shared Responsibility Model (SRM). This model requires businesses to take ownership of securing their data and applications within the cloud environment.

Cloud providers have different approaches to protecting data, which adds to the complexity, and businesses need to understand the specific details and nuances from provider to provider.

As such, customers must develop a holistic data protection strategy to ensure they have the necessary controls to protect their data even when relying on native tools included by their provider. This post will explore what this model means for customers and why it is essential to have a comprehensive data protection strategy across cloud and hybrid environments to use cloud services safely and securely.

Why are businesses increasing their adoption of cloud computing?

Cloud computing has extended the possibilities for businesses and provides many advantages. Having workloads, applications, and services running on the cloud or hybrid environments gives businesses greater flexibility and incredible scalability to accommodate growth. In addition to these valuable benefits, having a wide variety of software as a service (SaaS) applications delivered via the cloud enhances operations, optimizes resource utilization, and brings agility and efficiency to business workloads. It’s no surprise that most companies have already embraced the cloud or are actively transitioning workloads, with Gartner estimating that over 95% of new digital workloads will be deployed on cloud-native platforms by 20253.

Another key advantage that makes cloud computing so attractive is that it allows users to access data and applications quickly and easily without requiring advanced technical knowledge or expertise. This makes it easier for businesses to deploy applications and manage data in a shorter time– something that would otherwise require significant technical know-how or experience with traditional IT environments.

For these reasons, more and more companies are turning to cloud computing to manage their data and applications. The SRM ensures that both customers and providers understand what needs to be secured within the cloud environment so that companies can take full advantage of this technology safely and securely.

What is the Shared Responsibility Model?

The Shared Responsibility Model (SRM) is a cloud security strategy that states that while cloud providers are responsible for securing their service infrastructure, customers are responsible for securing their data and applications within the cloud environment. This division of accountability is designed to ensure that both parties understand what needs to be secured and how it should be done. This model allows companies to use cloud services’ scalability and flexibility while having faith in their provider’s ability to maintain a secure infrastructure.

To use cloud services safely and securely, customers must understand their role in the SRM. This means developing a holistic data protection strategy that considers their provider’s native tools and any additional security measures the customer might need to put in place. By doing so, customers can better protect their data from threats such as malicious attacks, unauthorized access, data leakage, and more.

What Are Cloud Providers Responsible For?

Cloud providers are responsible for the security and privacy of their cloud computing infrastructure, including physical security, data storage, network protection, host firewalls, access control, and software vulnerability patching. They must also ensure that their services meet legal and regulatory compliance requirements. In addition to providing all these critical components of a secure cloud environment, they are also responsible for the operational integrity of their system, ensuring its availability, scalability, fault tolerance, performance optimization, cost management, and overall reliability.

Each provider supplies a detailed description of what falls under their cover. For example, in its simplest form, AWS states explicitly that they are “responsible for protecting the infrastructure that runs all of their services in the AWS Cloud.”  

Another critical responsibility of cloud providers is to keep their customers informed of any changes or updates to their platforms or services. This includes alerting customers when a new security patch has been released or a service is no longer supported. Providers should also have a well-defined process for responding quickly and efficiently to any security incidents that arise.

Cloud providers should also have rigorous identity management practices to control who has access to the customer’s data within the cloud environment. This includes authenticating user identities with multi-factor authentication methods and regularly reviewing permissions associated with each account to ensure only authorized personnel can access sensitive information.

Finally, cloud providers should be transparent with customers about how they are protecting their data and informing them of any new changes or compliance updates that may affect their operations.

How can responsibilities differ across cloud providers?

While the Shared Responsibility Model can initially seem simple, cloud providers have different approaches to securing their customers’ data, meaning their responsibilities can vary significantly. For example, some cloud providers may have more stringent access control policies than others, meaning customers may require higher levels of authentication or authorization when accessing their accounts and data.

Other providers also offer different tools and features that customers can use to protect their data. Some might provide advanced encryption and essential management services that customers can use to ensure their information is safe in the cloud. Others may provide customers with granular auditing capabilities to track and monitor who has accessed specific files or directories within their environment.

Furthermore, the security requirements of each provider will differ based on the type of cloud services they offer. Microsoft details how the division of responsibility changes between customers and Microsoft, according to the deployment type. Infrastructure as a Service (IaaS) providers typically require customers to maintain responsibility for protecting the operating system, applications, and data stored within their virtual machines. Whereas Platform as a Service (PaaS) providers often offer more capabilities out-of-the-box, such as managed databases, web servers, and development frameworks – all of which must be configured according to the customer’s security requirements.

Finally, customers need to remember that while cloud providers are responsible for providing secure environments and tools, there are no assurances that customer data will remain private or secure if companies do not adequately implement best practices regarding access control, encryption, and other necessary measures. That said, businesses must understand what each provider is responsible for regarding data protection to choose the right partner for their needs.

Companies should carefully review each Cloud Provider’s responsibilities to know precisely what they are responsible for versus their service provider when protecting their data from malicious actors, misconfigurations and meeting compliance requirements.

What Are Customers Responsible For?

Despite cloud data being subject to the same responsibilities as any on-premise computing system, many companies remain unaware of this fact. The Shared Responsibility Model outlines that customers are responsible for securing the data and applications within a cloud environment – yet research has found that only 39% of organizations are confident in their ability to do so effectively4.

Ensuring these responsibilities are met requires implementing additional security measures such as backup and recovery, encryption, identity and access management, and monitoring.

Key Data Protection Considerations

  •  A robust data protection strategy for all workloads is essential for the total visibility and security of hybrid cloud environments. With regular backups of all workloads, organizations can be better prepared to respond in case of data loss due to either a cybersecurity event or a natural disaster. Additionally, having data readily accessible enables IT teams to restore any lost workloads quickly and efficiently with minimal downtime.
  • Encryption is critical when protecting sensitive data, such as financial or personal information, from unauthorized access attempts from external sources and internal personnel who could misuse customer information. Still, only 17% of businesses are encrypting at least half of the sensitive data they store in the cloud5. Customers should ensure they have robust encryption protocols across their environment and regularly re-inspect and apply the latest available options.
  • Identity and Access Management (IAM) is also essential for cloud service customers. Implementing an IAM system will enable customers to control who has access to their cloud environment on a user level, allowing only authorized personnel to view or modify data. By utilizing multi-factor authentication, customers can enjoy better protection from breaches and limit the potential damage a malicious actor could cause. Additionally, customers should ensure that their authentication methods meet the standards set by their industry’s governing body or regulatory agencies. Furthermore, companies should have a Separation of Duty (SOD) policy to further protect cloud data from misuse by any single account holder.
  • Monitoring and managing cloud and hybrid environments is a complex task, as cloud-based data resources constantly change. Therefore, using a monitoring and observability service is essential for administrators to ensure the security and proper management of cloud data. Cloud-native tools such as Amazon CloudWatch and Azure Monitor enable real-time monitoring and visibility into cloud, hybrid, and on-premises applications and infrastructure resources. The provision of data analysis not only helps administrators gain actionable insights from cloud data but also access crucial information about the performance of their cloud environment.

By following the best practices regarding security protocols, businesses can ensure they have the necessary controls to protect their data while taking full advantage of the benefits offered by cloud computing services. Ultimately, it’s up to each company’s circumstances when deciding what specific measures must be taken to keep sensitive information safe from external threats or unauthorized access.

Why You Need a Holistic Data Protection Strategy

With cloud related threats topping the list of cyber security concerns for UK senior executives and 90% saying they have experienced a greater exposure to cyber risks due to increased digitization in the last two years6, customers should continuously develop and maintain a holistic data protection strategy to ensure their data is secure, even when relying on the cloud provider’s native tools. A holistic approach involves understanding the full scope of data security requirements across multiple clouds and implementing appropriate technical, operational, and physical controls.

One of the most important reasons for this type of strategy is to identify and address any potential risks or vulnerabilities that could occur due to the increased use of cloud services. While cloud providers may have robust security measures in place, only 52% of CISOs are confident they are able to fully enforce a consistent security policy across all applications in the cloud7, meaning any additional security measures taken by businesses can provide extra layers of protection against malicious attacks, unauthorized access, data leakage, and other cyber threats.

In addition to helping protect sensitive data from potential threats, a holistic data protection strategy can also help businesses comply with various industry regulations such as HIPAA or GDPR. By having an adequate data protection plan in place, companies can better ensure they meet all relevant compliance standards while still taking advantage of all the benefits of using cloud-based services.

Encryption and backup are vital considerations customers should keep in mind to ensure data protection.  To achieve this, customers should also consider investing in third-party vendors like Commvault that provide additional layers of security for their cloud environments to complement native tools, ensure they meet their responsibilities, and effectively protect their data.

Microsoft echoes this statement in their Services Agreement, stating, all online services suffer occasional disruptions and outages, and Microsoft is not liable for any disruption or loss you may suffer as a result. and we recommend that you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services.

Commvault goes beyond backup by providing a simple and unified Data Protection Platform that spans all customer data – regardless of whether legacy or modern workloads live on-premises, in the cloud, or spread across a hybrid environment. Our knowledge of cloud options and deep integrations with a broad range of cloud providers offers the integration and automation possibilities to meet your unique data management and protection requirements.

Finally, customer organizations need to have clear ownership over their data so that everyone involved knows who is responsible for what type of information and how it should be handled securely throughout its entire lifecycle. This includes identifying who has access rights over specific sets of data as well as when those rights must be revoked (e.g., after an employee leaves the organization).

By having a holistic data protection strategy in place alongside their provider’s native tools, customers can better protect their information from external threats while also ensuring their operations meet regulatory requirements as necessary.

Companies need to invest time into creating such strategies to safely take full advantage of the benefits offered by cloud computing without putting themselves at risk for costly breaches or fines due to non-compliance issues down the line.

Final Thoughts on Cloud Data Protection Strategies

With cyber-attacks increasing and nearly half of all data breaches happening in the cloud8, organizations must take adequate measures to protect their data and environment. The Shared Responsibility Model is a crucial cloud security strategy that emphasizes an effective combination of customer responsibility in developing proactive defense plans with third-party solutions for additional layers of protection when using cloud services. To successfully implement this approach, customers must understand how responsibilities differ across different providers to minimize potential risks while taking full advantage of the services offered by these platforms.

To learn more about how we protect your Cloud Environments, visit our digital transformation and SaaS-Delivered Solution pages. You can also discover more about our latest release on our what’s new page.

References

1. IDC survey, commissioned by Ermetic. – 3. Gartner IT Symposium/Xpo 2021 – 4. CSA Understanding Cloud Data Security and Priorities 2022 – 5. 2021 Thales Global Cloud Security Study – 6. PWC Cyber Security Outlook 2023 – 7. BlueFort Security 2022 CISO survey – Help net security – 8. IBM and the Ponemon Institute’s 2021 Cost of a Data Breach

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Here at Commvault, we celebrated Black History Month with a variety of experiences, virtual events, and conversations hosted by our DE&I team and Multi-Culture Employee Resource Group (ERG).

This year, the theme of Black History Month 2023 was Resistance, in recognition of those who have fought against oppression, and is a time when we remember the global heroes of Black history, honor their fight by condemning racism, and champion change not only during Black History Month but every day of the year. As a global community, our goal was to explore these concepts through our programming this month under the theme “equity in action.”

As a Commvault community, we started our celebrations by supporting and joining a virtual cultural celebration with BLK House Virtual to experience joy through Black music as a reminder that we continue connections and community-building.

Later in the month, we hosted our Black History keynote event with special guest Arika Pierce, JD. With over 15 years of experience in corporate leadership, Arika is the CEO and founder of Piercing Strategies and works with organizations to develop their professionals by ensuring they have the right tools and resources to excel in their organizations and grow and thrive as inclusive leaders. Throughout the interactive session, Arika shared challenges and strategies for motivating leaders to engage in DE&I work, actionable ways leaders can prioritize diversity, equity, and inclusion, and evidence-based DE&I practices to improve workplace culture.

To close out the month, we hosted a Courageous Conversation with our newest Board Member, Shane Sanders, and our Chief People Officer, Martha Delehanty, where they discussed his career journey and perspectives on how the theme of “equity in action” has impacted him as a Black man. Shane also shared career advice, highlights, and challenges he has experienced throughout his personal and professional life. He also shared more on the social cost of not embracing diversity and inclusion in the workplace.


Although Black History Month concludes today, we are committed to continuing these conversations about diversity, equity, and inclusion here at Commvault and are excited about the celebrations we have planned throughout the year to further our efforts.

To learn more about our DE&I efforts at Commvault, click here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

As Senior Product Marketing Manager at Metallic, I was honored to recently have been awarded a CEO Living Our Values Award by our leadership team for the Metallic Threatwise launch. With ThreatWise, Commvault moved into uncharted territory as the only data protection platform to offer fully-integrated deception technology, capable of surfacing unknown and zero-day cyber threats before they reach your data – and it’s time to recover. Bringing this next-generation service to market was a significant milestone in supporting how our customers combat and respond to cyber threats, and I was fortunate to be a part of the team who helped deliver these capabilities.

Winning this award made me reflect on my time at Commvault and how it has shaped my professional journey. I joined Commvault in 2020 and was part of the first wave of employees who started during the pandemic. Growing up in New Jersey, and having spent the majority of my career in the tech industry, I was very familiar with the Commvault name – not only for it’s reputation as a perennial leader in the data protection space but also for its reputation as a great place to work.

As a Product Marketing Manager, I live in between many different worlds, driving and supporting launch activities for our Metallic services Commvault’s portfolio of SaaS-delivered data protection solutions. Working in this cross-functional capacity has challenged me but also presented the opportunity to work alongside many different areas of our business. From Product and Engineering to Operations and Customer Success (and everything in between), I partner with various stakeholders daily to achieve one common mission: deliver the best data protection services possible. Working as a collective unit to deliver against this promise is what drives me, and my colleagues, every day. On the customer front, this high level of collaboration has paid significant dividends as we rapidly innovate to bring best-in-class products to market for businesses of all sizes. On the professional front, it has allowed me to build new connections, expand my expertise outside of the Product Marketing domain, and further hone and mature my skillset.

When first arriving to the Metallic team, we were just getting our feet underneath us. Now, just three short years in, the trajectory and the growth have been remarkable. What started as an incubation project within Commvault, Metallic has achieved hyper-growth – more than tripling our portfolio offerings, garnering around 3,000 customers, and introducing new innovations that disrupt and advance the data protection market. I know everyone in Commvault has worked so hard to make this happen – it’s the teamwork, the maniacal focus on helping our customers, and the drive of our employees that have allowed us to reach this massive achievement.

Our values – we connect, we inspire, we care, and we deliver – continue to move our business forward. The past few years have been a wild, exciting ride, and I can’t wait for what the future holds for Commvault and Metallic.   

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

This codification of privacy is transforming how businesses are expected to operate. There is no more question of what happens when a business doesn’t invest in a cyber program and who’s responsible. Let’s take a quick look at what will shape this year.

US Privacy Regulations Take Action: CCPA, NYDFS, and SEC Update Requirements

CCPA may be amended. Currently the CCPA has an open request for comment on how audits fit with CCPA. In addition, we will start seeing rulings in cases around CCPA showing what we can expect for the reality of losses from not complying. For those who want to keep track with us, Perkins Coie has a great tracker.

NYDFS will likely be amended. Industry comments are under review. Once DFS makes its recommendations it will move through the legislation process. Notable takes:

    • “The CISO and the highest-ranking officer of the covered entities are both required to sign a certificate of compliance, and notice of compliance must be delivered annually to the NYDFS.” – Morgan Lewis.
    • This is more than a privacy law, this includes business resiliency, and secure operations

The SEC wants their new rules in place ASAP. This includes provisions for Cyber Security reporting requirements alongside considering rules requiring adoption of standard practices. As with all federal rules, this one may take some time. Other provisions, notably around carbon footprint reporting, seem to be causing friction. We will see if the SEC makes their timeline.

$100 Million penalty for BIPA violations. In 2022, we saw cases relating to the Louisiana BIPA come to a close with significant penalties being doled out. The rubber is meeting the road, and liabilities are a reality. Read more at Data Protection Report.

Why Executive Leaders Must Prioritize Cybersecurity Expertise

With this strong legislative push, real world liabilities are here. Executive leaders can no longer ignore the advice of security teams. The reality is most businesses are not ready. A quick snip from Forbes illustrates this perfectly:

“Our analysis showed that only 51% of Fortune 100 companies have a director on their boards with relevant cybersecurity experience. The situation in the Fortune 200 and 500 is more concerning: only 9% have cyber-savvy directors. Worse still are the companies in the Russell 3000 smaller than those in the Fortune 500: only 8% have cyber directors. There is a total shortage of 2,724 directors with cybersecurity expertise across all Russell 3000 companies.” –Forbes

To be successful in filling these positions, security leaders will need to have an opinion on what’s changing from a legal perspective, how that impacts business strategy, and how the business creates opportunity in markets with changing regulations.

Succinctly, CISOs need to be part of every strategic board level conversation. An active CISO can actually be a competitive advantage. These active leaders will understand the business data, how to use it for market advantages, and meet new regulatory challenges. Companies that can stay ahead of the changing regulatory environment will realize greater return. Companies that view compliance as a checkbox will fall behind.

Adherence to compliance regulations is critical to your business’s operations, but it doesn’t have to consume an outsized portion of your resources. Let Clumio help automate compliance and simplify management while reducing your data protection costs. Contact us for a customized consultation.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

The past year has been amazing – our data protection portfolio has won many accolades of technology leadership from industry analysts like Gartner, Forrester and GigaOm. These wins are no doubt driven by our relentless passion to protect our customers’ data in a difficult world and our fundamental belief that continuous customer collaboration is key to pragmatic innovation.

The next chapter of our 26-year journey of customer-driven innovation is now here – we are excited to announce the General Availability of Commvault Platform Release 2023! Commvault PR 2023 introduces several new features and additions to strengthen our customers’ security posture, deepen our rich integration with all major hyperscalers and introduce more smart savings through operational efficiencies.
Hundreds of customers have already benefited from these new capabilities during the Technology Preview phase, that started on December 15, 2022.

Harnessing the power of multi-cloud

What differentiates our approach to the ecosystem – and yes, we continue to support the broadest ecosystem when it comes to data protection – is how our integrations are seamlessly built-in and not just clumsily bolted on for a quick mention. Deeper the integrations, greater the synergies enjoyed by our customers.

Commvault PR 2023 carries new deep integrations to make it easier for our customers to protect their data across Microsoft Azure, AWS Cloud, Google Cloud Platform and Oracle Cloud Infrastructure.

Take, for instance, our new integration with Microsoft Azure Restore Points. We worked closely with Microsoft to be the first data protection platform to support Azure Restore Points. While Azure has had incremental snapshot capabilities, this new integration allows for application consistency across disks, while reducing costs with the option to use more cost-efficient storage tiers for backups. Commvault PR 2023 also introduces integration with Amazon FSx for NetApp which brings the same on-premises NetApp ONTAP policy-based protection to AWS. The new release also introduces support for Oracle Cloud Infrastructure (OCI) infrequent access & combined storage tiers to help reduce costs for protecting your cloud data.

Enhancing data security

Our trusted approach to data protection is shaped by the fundamental customer direction that data security is an integral and inseparable component of data protection. Building on our robust multi-layered ransomware detection, protection and recovery framework, Commvault PR 2023 introduces new integrations to drive data protection insights into the broader security ecosystem.

An important aspect of data protection is to leverage data awareness to proactively alert IT teams when threats arise. Commvault PR 2023 introduces a new Security Information and Event Management (SIEM) connector that makes it easy to feed alerts, events, and audit data to other platforms through webhooks APIs or even Syslog. Leveraging standard protocols ensures we can work with virtually any SIEM or event management system giving security teams better visibility to anomalies and threats in their data. 

Driving smart savings

With the uncertainty of a global recession looming, customers in every industry are looking to optimize costs in their budgets to make up for the increased spending for security and mission-critical areas. We are continuing to help provide options to lower the cost for data

New capabilities to use single region snapshots vs. multi-region snapshots for GCP can save 30% of that cost to backup resources. Sometimes improving cost is as simple as reducing the time it takes to protect applications.

Our optimizations for Hadoop, leveraging snapdiff, can take what was hours long backup scans to just minutes thanks to the enhancements in how we scan for changed blocks.

These are just a few of the amazing features we have in Platform Release 2023. You can learn about more of the latest features in our What’s New page for Platform Releases. Connect with our product management team and others in our communities for all the latest news and release information. 

Join us live on March 8th, 2023 at our Platform Release 2023 customer webinar.  Register here

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

The International Day of Women and Girls in Science 2023 takes place on Saturday 11th February and is an opportunity to promote the full and equal access and participation of females in Science, Technology, Engineering and Mathematics (STEM) fields.

We caught up with two amazing and inspirational Commvault leaders, Field CTO Vidya Shankaran and Director of User Experience Parisa Bazl to get their views on a range of topics including;

  • Why a minority of women pursue careers in STEM,
  • How bringing diverse perspectives can be a huge positive in their roles and
  • What advice would they give their 18 year old selves.
  • Personal Heroes

Why is marking the International Day of Women and Girls in Science important?

Vidya

As a mother of a daughter who is in science and engineering magnet high school, I know how important it is to raise awareness of the need for gender equality and promote the empowerment and advancement of women and girls in science, technology, engineering, and mathematics (STEM) fields.

By celebrating this day, it serves as a constant reminder for all to work towards removing the barriers that prevent women and girls from participating – this helps foster a more inclusive and innovative scientific community and a better future for all.

The day recognizes the important contributions of women and girls to these fields, and it encourages more girls and women to pursue careers in STEM.

Parisa

Celebrating this day is a way to remind ourselves of how far we’ve come and the distance we still need to go. While achieving gender equality in the STEM field is an uphill battle, our progress is evidence that it is possible and we will get there. This day is also a reminder of the benefits of having diversity in technology since so many critical, fun, and interesting things — from WiFi to dating apps – had their groundwork laid by women.

Why do you think women earn STEM degrees at half the rate of men – how can we help address this?

Vidya

Despite the fact that women have had a significant role to play in the progress of science and technology, they have not received the same levels of recognition as their male colleagues is an issue that transcends centuries. 

I would not necessarily to ascribe it to lack of female role models in STEM – there are many unsung “heroes” – but rather to the gender stereotypes and societal expectations that science is a “male” field. This manifests in the form of insufficient support for work-life balance that women and girls encounter compared to their male counterparts.

Thankfully, it is not irreparable or beyond redemption yet – there are many things we are already doing today and should continue doing and maybe even accelerate.

Promoting female role models in STEM through media coverage and highlighting the achievements of successful women in science is key as this has the power to encourage girls to take up science from an early age.

Most importantly, it is imperative that we continue providing supportive environments in education and the workplace, such as mentorship programs and outreach activities. Providing flexible work arrangements ensures that women continue to remain motivated to pursue their careers in STEM. Finally, fostering a culture of diversity and inclusivity in STEM, and promoting equity and equal opportunities in hiring, promotion, and compensation are critical to improving induction and retention of women and girls in STEM careers.

Parisa

Many women grow up with the incorrect perception that STEM is a field that plays to stereotypically masculine strengths, and we do not always have the proper social support systems to address these feelings of inadequacy and lack of confidence. Technology is often equated with software, but it much more about people. By highlighting the human aspects of the discipline, we can encourage more women to see how their unique backgrounds, perspectives, and skills will serve as a strength while pursuing degrees and careers in STEM.

What can being a woman bring to your roles of field Chief Technology Officer (Vidya) and Director of User Experience (Parisa)

Vidya

In my role, which is technology evangelism with our customers and partners, in order deliver this role successfully, it requires empathy, emotional intelligence, respect for all cultures and obviously, understanding of technology. As a woman it does require a lot more effort and perseverance to get to and keep my “seat at the table”, but it is not without the support of all men and women around me.

I am also seeing an increase in the number of men who are allies, who have been instrumental in driving acceptance, encouragement, and support for women in technology. These men are invariably fathers or brothers of women and girls in STEM and are aware of the challenges that women/girls face and are happy to do their bit in removing these roadblocks. This is definitely a change in the right direction.

Parisa

Working in a field where I’ve historically been at a disadvantage means that I’ve cultivated skills which not only help me navigate the field, but also do my job very well. I have had to pay attention to the smallest details, ask incisive questions, and listen extremely closely in order to best position myself for success. These are skills that make me a better advocate for users, since great UX is built on our ability to pay attention to what their users are saying in order to piece together the optimal solutions. In addition, being an outsider within the field of technology also makes me much more conscientious of inclusivity, and how everything from the way in which my team operates down to the interface that is designed needs to be intentional about creating equitable access and success.

What advice would you give to your 18-year-old self, moving into technology?

Vidya

I would say – Hang in there for it does get better .

But again, the kind of pressure we put on ourselves to deliver our best day after day, I would only say to take slow down and “smell the roses” – that we are not expected to know everything or have all the answers and it is okay to say, “I don’t know”.  After graduating with a degree in Chemical Engineering when I moved into Information technology, it felt like a personal failure, but I would tell me 18-yo self that it is okay to fail – “Failure” is a verb not a noun.

Parisa

I would advise my 18 year old self, who never planned on getting into technology, to think about it beyond just engineering. As I mentioned earlier, technology is way more about people than it is about software. If we focus on our ability to connect with people and cultivate understanding, it makes us that much more valuable and our impact that much more positive.

Personal Heroes – Who do you admire?

Vidya

I have a lot of respect for Indra Nooyi, former CEO of Pepsico and look for every opportunity to learn from her experiences.

Parisa

I’m a big fan of Barack Obama. He is someone who also had to navigate a system that was not predisposed to his success, and he leveraged his unique skillset, background, and point of view to inspire and connect with millions of people.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

It sometimes feels like we are living in the age of the reboot.  If you’re a fan of the hit TV show “That 70’s Show,” you know that it’s all about a group of friends navigating the challenges of adolescence in the 1970s and that it’s been rebooted (and updated to the 90s) on a popular streaming service. 

And it’s not alone.  From the good (Cobra Kai anyone?) to the not so popular (did anyone actually see the Knight Rider remake??) there is always an appetite for an update which reflects the current environment and challenges.

That sentiment can also be applied to your organization’s data management and protection strategy – to ensure it stays current and effective in an ever-changing world of emerging technologies and cyber threats.

With a new year and a fresh perspective, see if any of the below signs resonate with you. If so, you may be in a great place to put together a plan to reboot your approach to data in the Modern Cloud Era:

  • Outdated & mismatched technologies: Just like the characters on the show were stuck in the 1970s, your data management and protection strategy may be relying on a “frakenstack” of mismatched and outdated technologies that sprawled organically but are now stuck in time and are no longer effective in today’s modern multi-cloud world. It’s important to regularly review and update your technology strategy to ensure that your approach to data growth and retention is not only purposeful and effective, but also provides you powerful protection and controls from the best tools available.
  • Uncertainty around shared responsibility obligations with Cloud Providers and SaaS Applications: If you don’t have a solid understanding of what your obligations are to protect your data under the shared responsibility model, you could end up losing days, weeks, or even months of valuable insights in the event of a disaster situation. In the show, the characters often found themselves in sticky situations that could have been avoided with proper situational awareness & planning. The same is true for your organization’s off-prem data.
  • Insufficient access controls: Whether resulting from innocent human error, or malicious bad actors, your data management and protection measures can often be wide open to catastrophic incident if users have too large a sandbox to play in. Our crew of misfits in “That 70’s Show” often found themselves in trouble due to a lack of boundaries and rules. The same is true for your organization’s data. With proper access controls in place, your data is more protected, your risk profiler is smaller, and you can rest easy knowing that it’s that much harder to have a major incident due to unauthorized individual actions.
  • Lack of employee & org leader education: Just like the characters on the show needed guidance and direction, your employees and cross-functional partners need to be educated on best practices for data protection. Without proper education, your organization is at risk of data breaches and other cybersecurity threats. Do all of your cross-functional partners (HR, Sales, Operations, Dev Ops, etc.) understand the implications and limitations of native SaaS applications and cloud services? Do they have a trusted partner in the IT function to ensure that their workloads are secure and backed up to cover any gaps in the service provider’s shared responsibility model while simultaneously providing upline leadership a single view of all of their distributed corporate data across all platforms and form-factors?

If any of these signs apply to your organization, it’s time to think about giving your data protection strategy a refresh.

Just like “That 70’s Show” has stood the test of time, a solid data protection strategy can help your organization stay current and protect its sensitive information. Don’t get stuck in the past – take action to ensure your data is safe and secure.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Zero trust architecture is central to an organization’s security posture to mitigate cyberattacks, and the Defense Department recently released its Zero Trust Strategy and Roadmap1 on its plan to get the DOD to a Zero Trust architecture by 2027.2

A zero trust architecture provides the foundations for micro-segmentation of the IT landscape, access limited with the Least Privilege principle, and all communication to and between the micro-segments being authenticated, audited, and verified3. The underlying philosophy for zero trust is never assume trust, but continuously validate trust, so bad actors don’t get in. Companies, organizations and government agencies need to make sure that even users inside a network can’t do serious damage.

Flag Unusual Behavior

Zero trust principles ensure user access is continuously validated and monitored for Authentication and Authorization while constantly Auditing. Commvault leverages security controls such as multi-factor authentication for everyday administrative tasks, privacy locks, and data encryption. User access can be compartmentalized, explicitly denying CommCell level access, while applying roles to micro-segmented groups of resources through multi-tenant configurations. Zero trust controls help limit internal lateral movement to prevent data loss and unauthorized access to data.

Apply Zero Trust Controls

Commvault makes it simple to apply zero trust AAA controls by using the Security Health Assessment Dashboard. The dashboard provides a single pane of glass for identifying controls, highlighting potential risks within the backup environment, and recommending interactive actions to apply controls.

Add Layers of Security

To help strengthen the resilience of your data infrastructure, the NIST Cybersecurity Framework focuses on five primary pillars for a successful and holistic cybersecurity program. Attention to these pillars can help your organization in developing a comprehensive risk management strategy. Commvault has built these security pillars into our data protection software and policies without the incremental management overhead. The Commvault data protection and management platform include five security layers:

Identify

Protect

Monitor

Respond

Recover

Our multi-layered security consists of feature sets, guidelines, and best practices to manage cybersecurity risk and ensure data is readily available. We help protect and isolate your data, provide proactive monitoring and alerts, and enable fast restores. Advanced technologies powered by artificial intelligence and machine learning, including honeypots, make it possible to detect and provide alerts on potential attacks as they happen so you can respond quickly. By keeping your backups out of danger and making it possible to restore them within your Service Level Agreements, you can minimize the impact of a ransomware attack so you can get back to business right away (and avoid paying expensive ransoms).

Immutability

Protecting and isolating your backup copies is critical for data integrity and security. Therefore, we have taken an agnostic approach to immutability. With Commvault, you do not need special hardware or cloud storage accounts to lock backup data against ransomware threats. If you happen to have Write-Once, Read Many (WORM)-, object lock- or snapshot-supported hardware (which Commvault fully supports), you can still use Commvault’s built-in locking capabilities to complement and layer on top of existing security controls. Commvault’s ability to support layered defenses for securing data sets against ransomware ensures that your organization benefits from a sound cyber recovery-ready architecture. Here are some elements to include in your immutability architecture:

  •  Access locks to isolate copy store against ransomware
  • Immutability with lifecycle locks to reduce risks, balanced with consumption impact
  • Air-gap isolation network and controls
  • Configuration governance to protect against intentional or accidental changes
  • Concurrent Recovery performance – reduce latency with due importance to speed and cost impact
  • Automatic patching to stay current, simplifying management and maintenance of data protection infrastructure
  • Alignment with the 3-2-1 data protection philosophy  (3 copies of data, 2 different media, 1 vaulted copy)

Learn more about Commvault’s immutable infrastructure architecture here.

Cyber Deception Technology

While delivering business continuity is a critical element of any multi-layered strategy, a strong security posture also includes proactive defense technology that actively surfaces and engages unknown and zero-day threats. Metallic® ThreatWiseTM changes the game in ransomware protection, combining sophisticated early warning and early action with comprehensive data protection. It enables businesses of every size to neutralize silent attacks before they cause harm, detecting and diverting the stealthiest of zero-day attacks, which evade conventional detection technology and circumvent security controls.

A Ransomware Strategy

You need a plan to remain steadfast against ransomware. Beyond simply adhering to zero trust principles and hoping for the best, the ultimate solution can manage and substantially reduce the impact of a ransomware attack. It can reduce costs for your organization by utilizing one centralized management platform, so security teams don’t have multiple product points to log in and out of. It can increase the visibility of your data through a single landscape to minimize complexity for your teams. And finally, it can protect what matters most by providing the broadest workload coverage and rapid recovery capabilities through a unified approach. For all of this to happen, a solution must embrace Zero Loss Strategy.

Become Less Vulnerable

The reality is your organization needs to be prepared and take proactive steps to protect your data and work with a provider who offers ransomware protection and recovery solutions. How prepared are you? Take our free risk assessment to find out. Also, read our eBook on Understanding Team Roles and Responsibilities in Fighting Ransomware.

References
1. US DOD, Department of Defense Releases Zero Trust Strategy and Roadmap, November 2022
2. C. Todd Lopez , DOD News, DOD Releases Path to Cyber Security Through Zero Trust Architecture, November 2022
3.Commvault, Vidya Shankaran, Ransomware Defense in Depth – Best Practices for Security and Backup Data Immutability, October 2021

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

I’m so proud to announce the inspiring Vaulters who just won our FY’23 Q3 CEO Living Our Values Awards. 

Here at Commvault, our four values – we connect, we inspire, we care, we deliver – are always top of mind! 

This week we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work as they live our values every day. 

I’m so proud to announce our FY’23 Q3 CEO Living Our Values Award winners:

Christina Manning
Director, Finance Operations

Mathew Ericson
Principal Product Manager

Jason Gerrard
Director, Sales Engineering

Parisa Bazl
Director, Development UX

Sam Hernandez
Director, Facilities Management


All these winners set an inspiring example and embody what it truly means to be a Vaulter!

To learn more about what it’s like to work at Commvault, check out our careers site.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

The challenge with audit logs today

One major challenge customers face with audit logs is that they’re not aggregated in a central location that is fully immutable. SaaS applications specifically tend to have their audit logs kept within the SaaS application itself, oftentimes with only a 90-day history.

This leads to complicated scripting or the periodic export of logs from each application to place in a centralized location to meet corporate compliance and security goals.

This is a heavy lift on IT departments, and with hundreds of applications under management in any environment, it’s oftentimes not feasible to accomplish this completely. 

Consolidating audit logs with AWS CloudTrail Lake

With the release of CloudTrail Lake, AWS has made it simpler to manage audit logs from disparate sources. CloudTrail Lake is a managed security and audit data lake that lets organizations aggregate, immutably store, and query events recorded by AWS CloudTrail.

This can be done across different regions and accounts – and is backed by a 7-year default retention policy to help you meet compliance requirements.

Customers can ingest and analyze events in an AWS CloudTrail compatible schemafrom Clumio, as well as other third-party and non-AWS sources to streamline auditing, security investigation, and operational troubleshooting.

Simpler data security with Clumio and AWS CloudTrail Lake

AWS and Clumio teamed to deliver this integration for CloudTrail Lake thatallows you to simplify and streamline the process of consolidating activity data.

Through the newly launchedPutAuditEvents API for AWS CloudTrail Lake, Clumio has created a simple integration to capture user activity information and events from your Clumio environment alongside the AWS systems you are protecting with Clumio.

Once the integration is enabled, you’ll be able to capture and store audit activity across various categories. This will allow you to easily answer many security and compliance-related questions across various categories such as:

  • Authentication– Was there a high volume of unsuccessful logins to the Clumio console, indicating a brute force entry attempt or an issue with your Single Sign On provider? 
  • User Management– When was a user added to the Development Organization in Clumio, and when were they given the backup Admin role?
  • Backups– When was a backup policy accidentally changed? This will help you quickly determine when a backup policy was changed or created to ensure you’re always meeting both long-term compliance requirements and maintaining any minimum required RPO’s (recovery point objectives).
  • Restores– Is someone browsing the CEO’s email history, or trying to recover Payroll information from a system backup? This activity is tracked even if a restore hasn’t been initiated.
  • S3 Protection Groups– When was a new S3 production bucket added to a protection group? Why was a bucket removed? 

Setup and Architecture of Clumio logs on AWS CloudTrail Lake

First, in Clumio, navigate directly to the Audit Report page. You’ll see a link to set up the integration in the upper right corner. You must have the Super Admin role to set up the integration.

AWS CloudTrail Integration

On the next screen, you will see an external ID unique to your integration with CloudTrail. Copy this value, and we will then setup the next portion of the integration in AWS directly.

After logging into the AWS Console, navigate to CloudTrail, where you will find a new Integrations section under Lake.Click on the Add Integration button to configure the Clumio integration.

You’ll first need to give a name to channel that Clumio will use to send the audit logs data through, and then selectClumioas the source.

Next, we will need a place to deliver the Clumio audit logs and determine how long you would like to get the logs. You can either use an existing event data store or create a new one for this integration.

Next, we’ll configure the resource policy which is what will provide Clumio with a secure way to send the audit log data across the channel. This is where we will paste in the external ID we copied from the Clumio interface.

Lastly, apply any tags you may want to add to the resource and select Add Integration.

The integration is now set up; however, we have one final step. We need to copy the Channel ARN value and bring it back to Clumio, so we can complete the setup.

Once you add the Channel ARN value, click on Connect to CloudTrail

An initial event will be sent to the CloudTrail Lake event data store, allowing you to verify connectivity. From there, your Clumio audit events will be regularly sent to the CloudTrail Lake data store.

Additionally, you’ll be able to monitor the health of the integration at any time through the Audit Log report.

Below is a list of all audit event categories that are sent to CloudTrail as part of this integration:

  • Authentication
  • Datasource
  • Policy
  • S3 Protection
  • Restore
  • Backup
  • Users
  • Organizational Unit
  • KMS Config
  • SSO/MFA
  • CloudFormation template

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

In the handful of months since I became Commvault’s first Chief Partner Officer, I’ve been reading the terrain, talking with our partners, and figuring out how we can better help them in the year to come. I’ve analyzed everything from program incentives to partner enablement and everything in between to plot our course. There is, however, one thing I didn’t consider. The intangible effect of being one of the coolest kids on the block.

For the 7th year in a row, Commvault has been named to CRN’s annual Cloud 100 list! Honoring the 100 Coolest Cloud Companies for 2023 across five key categories: infrastructure, monitoring and management, storage, software, and security, we rated among the Top 20 in the storage category based on CRN’s analysis.

To make the list, which is considered by most in the partner world as the trusted resource for solution providers looking for technology vendors best positioned to support their cloud product and services needs, Commvault had to prove its commitment to channel partners as well as demonstrate our innovation in the development of cloud-based technologies.

This wasn’t difficult for Commvault, as we’re a leader in data management, protecting data wherever it lives – whether on-prem, in the cloud, or in a hybrid cloud environment. We support the broadest range of workloads in the industry and most recently expanded our cloud protection for Kubernetes, positioning us as an Outperformer and Leader in GigaOm’s Radar for Kubernetes Data Protection.

“In today’s remote-facing enterprise environment, cloud services have become the critical component needed to build comprehensive and secure IT solutions,” said Blaine Raddon, CEO, The Channel Company. “The companies selected for this year’s Cloud 100 list have shown time and again that they support partners in the ever-evolving cloud computing business with state-of-the-art products and services. Our team commends those on this year’s list and looks forward to watching them drive positive change in the cloud domain throughout the year.”

CRN’s Cloud 100 list will be featured in the February 2023 issue of CRN magazine and online at www.crn.com/cloud100.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Data Privacy Week is an annual event that aims to raise awareness about the importance of data privacy and security. The goal of Data Privacy Week is to educate individuals and organizations about the importance of protecting personal data and to provide them with the tools and resources they need to do so effectively.

We’ve brought together three opinion leaders to discuss the key data privacy challenges that face businesses around the world and how to overcome them.

Bill Mew, Data Privacy Champion and CEO of the Crisis Team is joined by Jakub Lewandowski – Global Data Governance Officer, Commvault and Thomas Bryant – Product Marketing Director, Commvault as they discuss;

  • Current trends and challenges in Data Privacy and Security
  • Laws and regulations related to data privacy, such as the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States as well as DORA and NIS2
  • Best Practices for protecting data – including a modern (and tested) data protection strategy and conducting regular risk assessments
  • The current state of Data Privacy policy and legislation compliance/ enforcement  

Learn more about these topics in our Data Privacy Week Blog Series available now

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

World Privacy Day, observed annually on January 28th, serves as a reminder of the importance of protecting personal data in today’s digital age. As technology advances and more personal information is shared online, individuals and organizations must take steps to safeguard their data.

New regulations, such as DORA (Digital Operational Resiliency ACT), mandate that organizations create plans for risk management, incident reporting, and resilience testing. These regulations outline policies for data management, including encryption, data locality, and data lifecycles. Gartner projects, “by 2023, 65% of the world’s population will have its personal data covered under various privacy regulations, and companies need flexible solutions that can adapt to the multitude of legislation.” Navigating this complex environment can be challenging for both individuals and companies.

Data Privacy is protecting personal information and giving individuals control over how their data is collected, used, and stored.  On the other hand, data protection refers to the technical and organizational measures put in place to protect data (including personal data) from unauthorized access, use, alteration, or destruction. Data protection encompasses Data Privacy and other areas, including backup & recovery, disaster recovery, data security, and a host of other areas.

To help address that complexity, let’s spend some time reviewing the Top 10 topics to consider when managing Data Privacy and Data Protection.


1. Data Protection Strategy
2. Encryption
3. Multi-Person Authentication
4. Immutable Storage
5. Data Sovereignty
6. Data Governance & Discovery
7. Classification of data
8. Data Retention
9. Resilience plan testing & incident response
10. Risk Assessment

1. Data Protection Strategy

Organizations should start by creating or updating a Data Privacy, Backup & Recovery, and Disaster Recovery plan as part of an overall data protection strategy. There are many facets to a reliable data protection plan and how it specifically relates to protecting the private data your customers have shared with your organization.

2. Encryption

Encryption is a crucial feature of data protection and protecting private data. Allowing for data encryption at rest and in transit helps prevent unauthorized access to personal information. This is especially important for organizations that handle large amounts of private data, such as healthcare providers and financial institutions. Data no longer resides just in our corporate data centers, as most organizations have one or multiple public clouds with workloads and data stored in them. Securing, with encryption, for the life of the data helps mitigate potential attackers.

3. Multi-person authentication

Beyond protecting data with encryption, organizations must safeguard their systems from malicious attacks. Leveraging multi-person authentication (MPA) for your data protection systems ensures critical tasks require multiple approvals from pre-approved users. Often overlooked, this is one of the simplest ways to prevent tasks like data exfiltration or deletion.

4. Immutable Storage

Immutable storage allows for data, private or otherwise, to be written and unable to be further modified or deleted. Data that cannot be tampered with or altered ensures data integrity is maintained. Immutable storage requirements are quickly becoming a standard part of data governance regulations like GDPR, HIPAA, and others. When paired with MPA, you can create highly secure data storage tiers that are a perfect fit for storing confidential and private data.

5. Data Sovereignty

Organizations should consider regulations surrounding private data storage when developing a data protection strategy. This includes the location of data storage and compliance with regulations regarding data sovereignty. For example, a cloud-based workload on GCP in Europe or containing EU citizens’ data must comply with EU regulations. Anywhere that private data may reside, even if temporary, may be required to be in a specific region under regulatory requirements. Commvault helps to address this concern in its latest release, allowing customers to select which specific region they will leverage for snapshot & data protection storage vs. multiple regions that cost more and may have different regulatory requirements.

6. Data Governance & Discovery

In a recent survey, 57% of CISOs admit they don’t know where some or all their data is or how it is protected! As this amount of private data continues to grow, the sheer number of regulations expands exponentially, and we are confused about what and how we should protect our data.  As a result, organizations need to understand their data, where it is, and what is at risk.  Being able to prioritize data based on your organization’s policies, priorities, and applicable regulations is critical to protecting the data. You cannot protect what you don’t know about!

7. Classification of data

Knowing what data exists and where it resides is only part of the solution. Organizations must consider what data is private customer data, business-critical, etc., in terms of its importance to your business and your customers. Protecting only on-prem data may miss some critical customer data living in your SaaS-based CRM solution. Speaking of which, you must rely on something other than your SaaS vendor or even your IaaS cloud providers to provide data protection for your data. They may provide some SLAs and a level of redundancy, but that is not a replacement for a solid data protection plan. Managing data classification is no point in time operation, with data growing each year exponentially.

8. Retention

It is paramount to know what data exists and how important it is, but how long does it stay relevant? This is a hard question to answer for most organizations and one that can be seen every year when buying ever-increasing storage systems to house corporate data. The ability to assign an expected lifespan to data can significantly impact your organization’s bottom line AND protect your customers’ private data. Having systems in place to automatically find, classify, and set retention will reduce the likelihood of data sprawl, reduce the amount of time to recover unused data, and reduce costs. If you are looking for a great place to start efficiently managing your governance, risk, and compliance, read through Commvault’s unique approach to Unified Data Management.

9. Resilience plan testing & incident response

Resilience plan testing often referred to as a runbook, is an often-overlooked area of a data protection strategy. Creating or updating an outdated plan can take time and effort. Partnering with solution providers or strategic data protection companies with experience in creating a plan can significantly reduce the time it takes to get current. While it may be trivial to think runbooks are passe, I’ve found that when an actual DR event or ransomware attack hits, they are the GO-TO asset you want in your arsenal of tools. A regular cadence of updates creates an organizational posture that is ready to face data security threats head-on.

10.  Risk Assessment

As mentioned with runbook, consider working with strategic vendors to perform a risk assessment semi-annually or annually. Scheduled reviews can help build the muscle memory for a solid data protection and data privacy mindset. The benefit of working with well establish data protection & data privacy vendors is they are up to date on the latest security threats and mitigation strategies.

By implementing this list of considerations and routinely refreshing your resilience plan, you can be confident that personal information is secure and compliant with the latest privacy regulations. If you aren’t sure where to start but need help from a company that can answer all these questions.

Commvault is here to help! We continually add new capabilities, including our latest enhancements to regional data sovereignty for backup snapshots, industry certifications, immutable storage capabilities, and more.

Head over to our community to learn more or take a test drive today https://www.commvault.com/request-demo

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Happy 2023 Data Privacy Week!

Just as everyone started to get more or less cozy with the regulatory landscape in data privacy/protection and individuals and businesses learned to navigate the shallow waters of data subject requests, risk management, and impact assessments – BOOM – another tidal wave of regulatory requirements and new challenges rushed in!

2023 is the perfect moment to start internalizing new acronyms (get ready for #NIS2, #DORA, #DPDPB, #CPRA, #CCPA, #CPA, #CDPA, #UCPA, #VCDPA, #ADPPA, #PrivacyPenaltyBill) and legislative acts they stand for.

The underlying motive of the upcoming changes is to boost and enhance the cybersecurity postures of various organizations and manage evolving cyber risks more effectively.

Here is a helicopter view of selected legal developments around the world:

  • EU – Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2)
  • EU – Regulation on digital operational resilience for the financial sector (DORA)
  • US – State & Federal privacy laws
  • India – Digital Personal Data Protection Bill (DPDPB)
  • Australia – Privacy Penalty Bill & overhaul of the Privacy Act 1988

NIS2

According to ENISA, the general spending on cybersecurity is 41 % lower by organisations in the EU than by their US counterparts. With the arrival of NIS2, this ratio is expected to shift to cover this enormous gap at least partially. Conservative estimates are that NIS2 entry in force will translate into a ~22% increase in ICT spending over a 3–4-year period.

NIS2 was published just before year-end, and EU Member States now have 21 months to transpose requirements and mechanisms described into national laws. The 2016 NIS Directive – despite shortcomings – served as a cornerstone for increasing Member States’ cybersecurity capabilities. Now, NIS2 will expand the scope and the list of impacted organizations. It is expected that as many as 160 000 organizations will be subject to this new legislation, including digital services providers (platforms and data centre services), electronic communications networks and services providers, manufacturing, food, and the public sector.


NIS2 aims to strengthen cybersecurity postures by, amongst other: improving cybersecurity governance, addressing the security of supply chains, streamlining reporting obligations (early warnings/shortened notification periods), and introducing more stringent supervisory measures and stricter enforcement requirements.

What can you do right now?

  • First, try to understand which obligations will apply to your organization and in which compliance bucket your organization will fall into: “Essential Entity,” “Important Entity,” or maybe “other.”
  • Next, see if you can create synergies and leverage existing technical and organizational measures implemented during preceding compliance efforts (e.g., GDPR, NIS1, etc.)
  • Start looking for the right partners that can adequately support your compliance efforts. Engage your vendors in discussing the approach that best fits your organization.
  • Last but not least, initiate planning for increased spending to address any remaining gaps. In compliance could result in administrative fines of up to 10 million euros or up to 2% of the total annual worldwide turnover of the organization.


DORA

DORA aims to achieve “a high common level of digital operational resilience,” mitigating cyber threats and ensuring resilient operations across the EU financial sector. It will become directly applicable from Jan 17th, 2025. It will impact the financial sector (banks, insurance companies, investment firms) and its ICT providers (i.e., cloud platforms) – roughly around 22 000 organizations.

New requirements imposed by DORA will effectively boil down to reviewing and updating risk management practices. Financial sector customers will need to transfer as many regulatory risks as possible to ICT providers or apply different risk-mitigating strategies. In any case, ICT providers will need to be able to assure adherence to DORA’s requirements. The whole industry will also need to reassess contractual relations with vendors. DORA will incorporate requirements for contracts between financial companies and their critical ICT providers, including the location where data is processed, service level agreement descriptions, reporting requirements, rights of access, and circumstances that would lead to terminating the contract.

In a separate post – Commvault’s Product Team will perform a more technical deep-dive into DORA’s requirements related to detection (art. 10), response and recovery (art. 11), and backup (art. 12).


US data privacy laws – CPRA/CCPA, CPA, CDPA, UCPA, VCDPA, ADPPA

As of January 1st, 2023, California Privacy Rights Act (CPRA) amendments to the California Consumer Privacy Act 2018 went into effect. Many temporary exemptions in place expire, imposing additional obligations on companies dealing with California residents’ personal information, e.g., regarding employment-related personal data, opt-out from selling personal information.

2023 is also the year when the Colorado Privacy Act (CPA), The Connecticut Data Privacy Act (CDPA), The Utah Consumer Privacy Act (UCPA), and The Virginia Consumer Data Privacy Act (VCDPA) will become effective. Legislative fragmentation risk is imminent and substantial, and this is the kind of risk that caused the European Union to harmonize the regulatory approach. Let us see whether the same will be true in 2023 in the case of the American Data Privacy and Protection Act (‘ADPPA’) – a proposal for a federal and general data privacy law.

India – DPDPB

Indian legislators plan to introduce a very ambitious Digital Personal Data Protection Bill (DPDPB) this year. When enacted, long-awaited legislation will undoubtedly impact all kinds of organizations due to India’s role as a tech powerhouse and a global outsourcing hub.

Australia – Privacy Penalty Bill & overhaul of the Privacy Act

Australian authorities announced yet another complete overhaul of the Privacy Act dated 1988. The current legislation was summarized as “out of date and not fit for purpose in the digital age.”

In the meantime, still in 2022, Australia passed the Privacy Penalty Bill that increased privacy-related sanctions to levels comparable with trends introduced by GDPR (up to 50m AUD) and expanded regulatory powers of the Office of the Australian Information Commissioner (OAIC) and the Australian Communications and Media Authority (ACMA).

Summary

The relentless compliance clock just started ticking again. Cross-functional teams consisting of IT, compliance, privacy, legal professionals, and business analysts will spend considerable amounts of time analysing the impact of the cloudburst of legislative developments that emerged at the end of last year and will materialize throughout 2023.

Be aware that the legislative developments presented here could be more comprehensive. You can be sure, however, that they will become standard talking points not only in 2023 but also for the years to come.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

As part of a set of three articles to mark Data Privacy Day 2023 (see accompanying articles by Jakub Lewandowski and Thomas Bryant ), Bill Mew argues that there is a real enforcement problem – it’s like the ‘Wild West’ out there.

Policies, frameworks, and rules are only helpful if adhered to, just as regulations and laws are meaningless without enforcement. The problem with the data privacy and cybersecurity arena is that where rules should be applied, they are frequently ignored, and where laws have been introduced, there needs to be more enforcement.

CISOs (Chief Information Security Officers) have a thankless task. Staff is usually reluctant to abide by the cyber hygiene measures that a CISO seeks to enforce, but when their lack of discipline results in a breach, these colleagues are too quick to pin the blame on the CISO. On top of this, while there are costly and complex regulations to abide by and strict rules on breach reporting, the authorities, far from helping to deal with any incident or catch the actual criminals, simply use the reporting to assess the allocation of fines.

Functional, Cultural Mismatch

If asked, most staff would agree that cyber threats are a significant issue, but in their day job, they focus on revenue or profit-centric ROI (return on investment) metrics. These are the metrics on which their individual and unit performance are measured and what company-wide incentive policies are structured to support.

The CISO is instead focused on return on risk (ROR). Based on the allocated budget and the organisation’s risk appetite, the CISO focuses on maximising security and minimising risk.

The mismatch between the CISO’s ROR orientation and just about everyone else’s ROI orientation can put the CISO at odds with the rest of the management team. They may not only become isolated (what I term CISOlation) but can also be a scapegoat when things go wrong – even when warnings are ignored.

Perverse regulatory incentives

In an accompanying article, Jakub Lewandowski [LINK] has explored the raft of new privacy and cybersecurity laws expected to add to a considerable regulatory burden. The problem is that regulation without enforcement is not just pointless but counter-productive. After all, only responsible companies will comply with these regulations, and for them, it represents a cost or compliance tax. Meanwhile, irresponsible ones often choose not to abide by the rules. If they believe that there is little or no risk of enforcement, then this is a cost-saving and risk-free source of competitive advantage.

Lack of compliance is widespread and comes from the top, with frequent headlines about BigTech suffering data incidents or incurring fines. Such fines appear not to be working as a deterrent but are instead being viewed as an additional cost of business by BigTech firms and many others unfortunate enough to have suffered a data incident.

Again, responsible firms that did their best to take reasonable measures but were unfortunately unable to prevent mistakes or attacks run the risk of being fined once they notify the local regulator. Meanwhile, irresponsible ones who choose not to comply will simply avoid reporting incidents and attempt to cover them up instead to avoid fines. Fines have, therefore, become more of a lagging indicator of misfortune for responsible firms rather than of misbehaviour by irresponsible ones.

Record of Regulatory Inaction

Most BigTech firms, attracted by a favourable tax regime, have opted to base their European headquarters in Ireland. The local regulator, DPC Ireland, is therefore responsible for ensuring that they comply with GDPR and other such regulations. Whether down to inadequate funding, reluctance to rock the boat, or simply out-gunned and out-lobbied by the BigTech firms, DPC Ireland has been seen as ineffective in holding them to account.

In one notable case, measures it failed to take against Facebook were eventually resolved in the European High Court under the Schrems I and Schrems II rulings. When it still failed to take action and apply these rulings, DPC Ireland was sanctioned by the European Parliament in a vote of 451 to 1. When further lobbying by regulators across the rest of Europe forced it to take action after a two-year delay eventually, the fine that it levied against Facebook was so low that it had to be increased (tenfold) at the insistence of the other regulators.

The EU Ombudsman Emily O’Reilly eventually opened an inquiry into the European Commission’s monitoring of how data protection rules are applied in Ireland. Eight months later, the Irish Council of Civil Liberties (ICCL) criticised the EU for its continued failure to properly monitor Ireland’s GDPR enforcement while “the fundamental rights of all Europeans hang in the balance.” There are now moves afoot to strip Ireland of its responsibility for regulating the BigTech firms and centralise such enforcement instead.

Ineffective Global Policing

Meanwhile, the number and sophistication of cyber-attacks are increasing exponentially, as is the cost of remediation. The World Economic Forum (WEF) has recently not only called for more widespread use of cybersecurity ‘fire drills’ to test cybersecurity and incident response capabilities but is also championing the need for global rules to crack down on cybercrime.

The damages incurred by all forms of cybercrime, including the cost of recovery and remediation, are thought to have totaled $3 trillion in 2015 and $6 trillion in 2021 and could reach as much as $10.5 trillion annually by 2025.

Cyber insurance isn’t the answer. Rapidly increasing premiums mean that it is out of reach to most buyers, but even those who can afford it often find it’s not worth it. At the same time, cyber insurance cannot be expected to cover systemic problems, and in any case, it has the perverse effect of potentially making bad problems even worse.

While almost all nations have signed up for United Nations agreements on combatting crime, including cybercrime, some nations turn a blind eye and instead provide safe havens for cybercriminals to operate from. While most cybercrime originates from countries like Russia, Iran, or North Korea, such activities are not confined to these rogue nations and continue closer to home. In addition, countries like China have significant espionage operations, and the United States is responsible for a great deal of global mass surveillance – all of which contravenes GDPR and a host of other laws.

We need to start with mandatory data breaches and cyber theft reporting. This has begun in the US with 2022’s Cyber Incident Reporting for Critical Infrastructure Act and in the EU with 2018’s Directive on Security Network and Information Systems. Still, there are also a host of other regulations that mandate telecom payment services, medical device manufacturers, and critical infrastructure providers to report breaches.

Once we have better data on the problem, we can focus on improving international investigation, prosecution, and adjudication efficiency and effectiveness. The United Nations Office on Drugs and Crime is promoting a Cybercrime Programme which has the following aims:

  • Increased efficiency and effectiveness in the investigation, prosecution, and adjudication of cybercrime, especially online child sexual exploitation, and abuse, within a strong human rights framework.
  • Efficient and effective long-term whole-of-government response to cybercrime, including national coordination, data collection, and effective legal frameworks, leading to a sustainable response and greater deterrence.
  • Strengthened national and international communication between government, law enforcement, and the private sector with increased public knowledge of cybercrime risks.

These are laudable goals. However, we are a long way from victims of crime being able to pick up the phone to police at the local, national, or international level with any expectation of getting either practical assistance or justice. The reality is that when it comes to cybercrime, aside from private sector incident response specialists, you’re on your own.

  • Staff are rarely adequately disciplined about cyber hygiene
  • Regulators are not proactive in tracking down and countering non-compliance
  • Criminals are growing in confidence, intensity, and sophistication
  • Police are unable to act against criminals operating from safe havens
  • And CISOs are the default scapegoat when things go wrong

In this ‘Wild West’ environment, there isn’t any cavalry going to the rescue, so you are expected to be adequately armed and ready to defend yourself. Take hints from Thomas Bryant’s article and learn how to deal with it best. There is no substitute for getting your cybersecurity and incident response right.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

As part of our “Get to know your customers day” series, we’re taking a deeper look at Swinerton Inc, a large national construction company who is pursuing a cloud data management program to drive versatility, sustainability and to free up company resources.

IT Manager, Brandon Marrott gives an insight into Swinerton’s data modernization journey which includes cloud transformation and embracing SaaS flexibility.  He also describes operating a hybrid cloud environment through the need to retain a number of company data assets on prem and how Swinerton manages their entire data estate, including SaaS, with Commvault.

https://play.vidyard.com/U5fZTkcgxdb7v9we3WJghp

What does it mean to go to the cloud?

Selecting the right cloud transformation partner

https://play.vidyard.com/oUYbtkBhyzYRoVibhsaWGm
https://play.vidyard.com/zwLtwiwBcsPG15DN2u5L8L

Overcoming challenges and flexibly managing a growing SaaS Data Estate


Faced with increased pressures, including an uncertain economic environment, IT teams are constantly finding ways to reduce costs or increase overall efficiency – all while supporting an evolving data environment.

Explore more examples of how Commvault customers use modern, innovative data protection services, including our DPaaS portfolio Metallic, to achieve their digital transformation goals https://www.commvault.com/digital-transformation-changes-everything-when-it-comes-to-data.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide