Skip to content

For years, cyber resilience has been defined by technology – security controls, sophisticated detection capabilities, and increasingly robust backup strategies designed to prevent attacks or recover more quickly. Those investments remain essential, but they are no longer enough. 

AI has fundamentally changed the nature of cyberattacks, which now move at a speed that challenges even mature organizations. As the window between compromise and business disruption continues to shrink, resilience is becoming less about preventing every attack and more about keeping the enterprise running when prevention inevitably falls short. 

That shift is at the heart of IDC’s new report, Resilience Operations: The Discipline that Makes Readiness Provable. Based on a survey of more than 500 North American organizations, the report argues that resilience is evolving into a cross-functional operating discipline that connects business priorities with cybersecurity, ITOps, and disaster recovery. More importantly, it reveals several gaps that suggest many organizations are still preparing for a threat landscape that no longer exists. 

Here are the insights that stood out. 

Recovery should begin with business outcomes – not technical ones.

Historically, recovery planning has focused on restoring infrastructure as quickly as possible, with success judged by recovery time objectives, backup completion rates, and application availability. While those measures remain valuable, they don’t necessarily answer the question executives care about most: When can we get the business back online? 

IDC argues that resilience should be anchored to business outcomes rather than technical milestones – restoring the capabilities that allow the organization to serve customers, generate revenue, and meet its obligations. That may sound like semantics, but it changes how recovery priorities are established. Technology becomes the means to an end rather than the end itself. 

Most organizations still haven’t defined what matters most.

Nearly 6 in 10 organizations have not fully defined their minimum viable business (MVB) – the smallest set of functions, systems, processes, and data required to continue operating after a disruption. 

Without a shared understanding of what the business truly depends on, every movement during recovery becomes reactive. By defining your MVB before a crisis, you’ll enable faster decisions, better coordination during recovery, and ultimately a more resilient organization. 

Automation is becoming the dividing line between resilience and recovery debt.

While attackers increasingly automate reconnaissance, exploitation, and lateral movement, many organizations still rely on manual recovery processes. 

That imbalance is becoming increasingly difficult to ignore. AI is compressing attack timelines, but recovery timelines have not kept pace. Organizations that fail to automate these recovery tasks may find themselves spending days assembling and executing plans while the damage has already been done. 

Automated recovery orchestration, clean recovery point identification, and coordinated validation are becoming foundational capabilities for recovering at the speed modern attacks demand. 

Technology isn’t the biggest resilience challenge – organizational alignment is.

Security teams focus on containment, infrastructure teams focus on restoration, business leaders focus on customer impact, and compliance teams focus on regulatory obligations. None of these priorities are inherently wrong, but when they evolve independently, organizations enter a crisis without a shared operating model. 

Enter ResOps. Rather than positioning resilience as an IT responsibility, the report frames it as a discipline that deliberately brings together business, security, infrastructure, and recovery planning. The message is clear: Resilience depends less on individual tools than on creating shared priorities before an incident forces you to make difficult decisions. 

Testing remains one of the strongest indicators of resilience.

IDC found that relatively few organizations conduct frequent tabletop exercises or cyber-range simulations, despite decades of evidence showing that rehearsal consistently improves performance during real incidents. 

Exercises reveal hidden dependencies, expose communication gaps, and allow teams to make decisions without the real consequences. Organizations that repeatedly validate their recovery processes develop a level of confidence beyond planning alone. 

Tomorrow’s resilience challenges are already taking shape.

Ransomware still dominates headlines, but the next resilience challenges have already emerged – from agentic AI and machine identities to post-quantum cryptography. 

These threats remind us that resilience planning can’t focus exclusively on today’s infrastructure. Recovery increasingly involves cloud services, SaaS applications, AI models, machine identities, third-party providers, and distributed digital ecosystems that didn’t exist a decade ago. 

Resilience is becoming measurable.

IDC’s ResOps Maturity Model is invaluable for assessing your organization’s current posture. Rather than treating resilience as something organizations either possess or lack, the framework describes a progression from reactive, siloed operations to mature, adaptive resilience built on governance, automation, and continuous improvement. 

To me, that progression acknowledges an important reality: Resilience is never finished. It’s not about purchasing a platform or completing a project. Organizations become resilient by continually improving how technology, people, and business processes work together under pressure. 

Viewed through that lens, resilience becomes less like insurance and more like operational excellence – a capability that can be assessed, strengthened, and demonstrated over time. 

We’re undergoing a broader shift in how organizations think about resilience.

Resilience conversations are evolving from protecting infrastructure to protecting the business itself. That means recovery planning starts with customers instead of servers, governance becomes as important as technology, and confidence comes from proving capabilities rather than documenting intentions. 

ResOps isn’t really a new framework; rather, it’s a broader recognition that cyber resilience has become an operational discipline. As attacks become faster and more complex, resilience will be measured not by the absence of incidents, but by an organization’s ability to continue serving customers, supporting employees, and maintaining trust despite disruption. 

That’s ultimately what ResOps is designed to prove. 

Rajiv Kottomtharayil is Chief Products Officer at Commvault. 

More related posts


Cyber Resilience

Read more about Cyber Resilience

Key Takeaways

  • Trust in the age of AI isn’t disappearing – it’s evolving.
  • Organizations need to verify AI continuously rather than trust it by default.
  • AI adoption should empower employees, not push them toward shadow AI.
  • Zero trust isn’t about distrusting people. It’s about continuously validating identities, devices, and actions.
  • Responsible AI adoption requires technology, governance, and people working together.

When we launched Ready. Or Not., we wanted to create a series that made some of today’s biggest AI conversations easier to understand. By pairing comedian Nathan Macintosh with industry experts, we’re exploring everything from agentic AI and cyber resilience to data management – and adding a little humor along the way.

If you caught our first episode on the opportunities and risks of agentic AI, I think you’ll enjoy this one as well. This time, we’re tackling a topic that’s at the center of every AI conversation: trust.

Nathan sits down with Diana Kelley, Chief Information Security Officer at Protect AI, for a conversation about what it means to trust technology when AI can generate convincing fake content, make decisions, and even imitate people. From deepfakes and hallucinations to zero trust and shadow AI, they explore how organizations can embrace AI without losing confidence in their people and systems.

Watch the full episode on Readiverse.

I walked away from this episode feeling more optimistic than I expected. Not because AI is suddenly more trustworthy, but because Diana shows us that trust grows when organizations put the right policies, guardrails, and technology in place. Here are some themes from the conversation that put AI in a new perspective.

Trust and Technology Can Co-Exist

Diana believes trust is possible in the AI era, but it’s going to look different. We’ve always built trust through relationships with people. Now, we’re learning how to extend that trust to systems.

That doesn’t mean trusting technology blindly. It means understanding how AI works, recognizing its limitations, and putting the right safeguards in place so people and technology can work together with confidence.

“Trust has to evolve for the new world.”

– Diana Kelley

What resonated with me was the idea that trust and technology don’t have to be at odds with one another. With the right approach, they can strengthen each other.

We’re Getting Smarter About AI

Deepfakes have become one of the most talked about AI risks, and it’s easy to understand why. AI can now generate convincing voices, images, and videos that make us question what’s real. But Diana pointed out that while AI is getting more sophisticated, people are getting smarter. We’re more likely to question an unexpected phone call, take a closer look at a social media post, or pause at something that doesn’t feel quite right.

Organizations are becoming savvier, too. As AI gets better at impersonation, businesses are investing in new ways to continuously verify identities and validate information. My takeaway is this: Technology will continue to improve, but so will our ability to recognize it and respond responsibly.

“Is today a good day to start a deepfake?”

– Nathan Macintosh

Responsible AI is Good for Business

Diana shared an example that will probably sound familiar to many organizations. An employee she calls “Karen in Finance” starts using AI because it helps her complete a task in minutes instead of hours. Karen isn’t trying to work around company policy – she’s trying to be more productive.

Employees use AI because they see real value in it, and that’s an opportunity for organizations. When employees have access to approved AI tools, supported by clear policies and practical guidance, they can work more efficiently while helping protect company data and systems.

Sneak Peek: Smarter AI Adoption

The goal isn’t to stop employees from using AI. It’s to make sure they’re using it the right way. Diana explains how organizations can encourage AI adoption without creating unnecessary risk.

Zero Trust Matters More Than Ever

“When you understand how things work, then you can start to understand how to manage them.”

– Diana Kelley

Zero trust is one of those concepts that’s much easier to understand with an analogy. Diana has a great one. She describes it as moving through a building. Just because you’ve been allowed through the front door doesn’t mean every other door automatically opens for you. Each time you access a new room, there’s another quick check to confirm you’re supposed to be there.

That’s essentially how zero trust works. Instead of assuming a person or device is trustworthy after a single login, organizations continuously verify identities, devices, and actions as technology becomes more connected. Most of those checks happen quietly behind the scenes.

One of the things I appreciated about Diana’s explanation is that zero trust doesn’t feel like another security buzzword. It feels like a practical way to think about trust in a world where AI and digital identities are becoming part of everyday business.

Trust Is About People

At the end of the day, technology doesn’t create trust – people do. People define the policies, processes, and ethical boundaries that guide how AI is used, while technology helps verify that those guardrails are working as intended. It’s that partnership between people and technology that makes responsible AI possible.

Trust extends beyond our own organizations. Businesses need confidence in the partners they work with, the systems they connect to, and the technologies they adopt. That’s why transparency, shared standards, and continuous verification are becoming just as important as innovation itself. The more AI becomes part of everyday business, the more trust becomes everyone’s responsibility.

Looking Ahead

AI will continue to evolve, and so will the way we interact with it. The organizations that succeed won’t be the ones that trust AI blindly or avoid it altogether. They’ll be the ones that build strong policies, adopt the right technologies, and continuously verify the systems they rely on.

Trust isn’t something we lose as technology advances. It’s something we intentionally build and evolve. That’s exactly the kind of conversation we hope to continue with every episode of Ready. Or Not.

Watch the full episode on Readiverse.

FAQs

Q: What is digital trust?

A: Digital trust is the confidence that people, systems, and organizations are who they claim to be and are acting in expected, secure ways. It combines technology, governance, and verification to help organizations interact safely.

Q: What are deepfakes?

A: Deepfakes are AI-generated images, videos, or audio recordings designed to closely imitate real people. While they have legitimate uses, they can also be used to impersonate individuals or commit fraud.

Q: What is zero trust?

A: Zero trust is a security model based on continuous verification rather than automatic trust. Instead of assuming a user or device is trustworthy after one login, organizations continuously validate identities and actions.

Q: What is shadow AI?

A: Shadow AI refers to employees using AI tools that haven’t been approved or governed by their organization. While often well-intentioned, it can introduce security, privacy, and compliance risks.

Q: Why shouldn’t organizations simply block AI tools?

A: Employees typically adopt AI because it helps them work more efficiently. Rather than banning AI outright, organizations should provide approved tools, establish clear policies, and educate employees on responsible use.

Q: What’s the biggest takeaway from this episode?

A: Trust isn’t disappearing because of AI – it’s evolving. Organizations that combine people, policies, and technology with continuous verification will be better positioned to adopt AI confidently and responsibly.

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Our Chief Products Officer, Rajiv Kottomtharayil, recently wrote about a big shift that is taking place across industries. Frontier AI models are compressing the time between vulnerability discovery and exploitation.  

This shift is prompting organizations everywhere to re-examine their vulnerability management processes. We’re doing the same at Commvault. That’s why, starting August 11, we’re changing the rhythm of how we disclose vulnerabilities.  

What’s Changing

We are raising the bar for security, transparency, and customer trust. On August 11, and on the second Tuesday of each month after that, we’re introducing Patch Tuesdays: a scheduled monthly release where we share security advisories and vulnerability patches.  

Patch Tuesdays are a hallmark of leading technology companies, because they provide customers with a predictable security rhythm.  This matters even more as the pace of vulnerability discovery accelerates. Of course, if there is an urgent vulnerability that must be reported off cycle, we will not hesitate to follow our well-established processes.  

Where You Can Find Up-to-Date Resources  

On the second Tuesday of each month, you’ll find new information pertaining to CVEs on our Security Advisories page. You also can find the official publications at MITRE’s CVE site. 

On the Commvault Security Center, you’ll find our vulnerability management program and other security-by-design thought leadership.   

For compliance certifications, audit reports, and documentation on how Commvault protects customer data, visit the Commvault Trust Center. You can subscribe to updates from the Trust Center at the link in the upper righthand corner of the page. 

Bill O’Connell is Chief  Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

For decades, technology leaders have been trying to eliminate silos. Entire modernization programs have been built around connecting applications, consolidating platforms, and giving organizations a more complete view of their data.

Those efforts have delivered enormous value, but they also have shaped the way we think about resilience. When something goes wrong, we instinctively look for technical fragmentation. However, we’ve found the greater challenge lies elsewhere.

The most significant silos affecting cyber resilience today aren’t found in databases or applications but in organizational structures. They exist between security and infrastructure teams, between IT and the business, and between the people responsible for responding to an attack and those responsible for keeping the organization operating.

IDC’s latest research on ResOps, Resilience Operations: The Discipline that Makes Readiness Provable, suggests these organizational boundaries have become one of the defining obstacles to effective recovery. That’s a timely observation because cyberattacks have evolved in ways that can make those boundaries increasingly difficult to maintain.

Modern Attacks Don’t Follow Your Org Chart

A modern cyberattack rarely affects a single technology domain. A ransomware incident might begin with compromised identities, spread through cloud infrastructure, encrypt critical workloads, disrupt customer-facing applications, impact third-party services, and trigger regulatory reporting requirements – all within a matter of hours. Every stage involves different teams, different tools, and different priorities.

Yet many organizations still prepare for recovery as though these responsibilities can be managed independently.

Security teams naturally focus on containing threats and preserving evidence. Infrastructure teams prioritize restoring systems and minimizing downtime. Business leaders concentrate on customers, revenue, and operational continuity. Communications teams think about reputation, while legal and compliance teams focus on regulatory obligations.

Each perspective is entirely reasonable. The problem arises when those priorities have never been reconciled before an incident occurs.

In the middle of a crisis, recovery requires decision-making under pressure. Which applications should return first? Which data can safely be restored? How much risk is acceptable before customer services resume? Who has the authority to make those decisions?

Without alignment, organizations often discover that the greatest delays aren’t caused by technology but by uncertainty – the kind that could be mitigated by better preparation.

Resilience Begins with a Shared Definition of What Matters

The report places emphasis on establishing your minimum viable business (MVB). At first glance, it appears to be another recovery planning exercise, but its real value lies in the conversations it forces organizations to have.

Defining an MVB requires business leaders, security teams, infrastructure specialists, and application owners to agree on a deceptively simple question: What absolutely must continue operating if everything else stops?

That discussion changes the nature of resilience planning. Recovery priorities are no longer determined by whichever application owner argues most convincingly during an incident. Instead, they are established in advance, grounded in business outcomes, and supported by technical dependencies that everyone understands.

Perhaps more importantly, MVB creates a common language. Business leaders begin talking about critical capabilities rather than individual systems. Technology teams begin mapping infrastructure to customer outcomes rather than technical architectures. Security teams gain greater clarity about which assets deserve the highest levels of protection during recovery.

That shared understanding is precisely what many organizations have been missing.

Technology Can Automate Recovery – But it Can’t Create Alignment

The report doesn’t argue that organizations need yet another platform. It argues they need a way of working that aligns people, processes, and technology around a single operational objective. This is where ResOps – a cross-functional discipline – proves its mettle.

Technology can help automate recovery, but it cannot resolve disagreements about business priorities. It cannot decide which customer services matter most. And it cannot replace the governance needed to coordinate multiple teams during a high-pressure event.

Those are leadership challenges, and they are best addressed by investing time in answering the difficult questions together, long before an attack forces your hand.

The Strongest Organizations Don’t Eliminate Silos – They Connect Them

Cyberattacks will continue evolving. AI will continue compressing attack timelines. New technologies will introduce new dependencies, and new threats will emerge alongside them. None of that changes the fundamental requirement for resilience.

Organizations don’t recover because individual teams perform brilliantly in isolation, but because those teams already know how to work together.

That may ultimately be the most important insight from IDC’s research. Resilience isn’t simply the product of better technology or more sophisticated security controls. It is the result of shared priorities, clear governance, and a tested operating model that brings the right people together before an incident occurs.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Learn about our advances through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

By Sustainability Team

As AI adoption accelerates, cyber threats are becoming more sophisticated, and data regulations are expanding. Resilience is no longer simply a defensive posture – it is a business imperative and competitive advantage.

That belief is at the center of Commvault’s FY26 Sustainability Report, which is now available. This year’s report reflects the progress we’ve made across the areas that matter most to our business, our customers, our people, and the communities where we live and work.

Anchored by our updated materiality assessment, the report highlights how we are advancing sustainability through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

Cyber resilience remains foundational to our work. As organizations rethink what it means to be ready for disruption, Commvault continues to unify data security, identity resilience, and cyber recovery to help customers detect threats faster, operate more efficiently, and recover with greater confidence. We also are integrating AI and automation designed to support smarter, more secure, and more resilient operations.

That same focus on resilience extends to our environmental commitments. Our solutions help customers optimize data storage and movement, which can help reduce energy expenditure in data centers. For Commvault, responsible innovation means building solutions that support both operational strength and more efficient use of resources.

The report also reflects the people and principles behind our progress. Strong governance, a modern Code of Ethics, and continued investment in our talent help create the foundation for trusted partnerships and long-term value. These commitments are deeply connected: Strong governance enables responsible innovation, responsible innovation helps strengthen the security and efficiency our customers depend on, and that trust is sustained by the people who bring our mission to life every day.

We invite you to read Commvault’s FY26 Sustainability Report as both a record of our progress and a look forward to the priorities that will shape our next chapter.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

A few years ago, digital sovereignty was largely viewed as a compliance conversation. If you stored data in the right geography, met the right regulatory requirements, and satisfied a handful of audit questions, you could generally move on.

That’s no longer the case.

Today, sovereignty has become a board-level discussion. Governments are rewriting policies. Regulators are increasing scrutiny. And business leaders are starting to recognize that sovereignty isn’t just about where data resides – it’s about how organizations continue operating when geopolitical, legal, or operational assumptions suddenly change.

In the first episode of our STRIVE series on digital sovereignty, I sat down with Max Mortillaro, co-founder and Chief Research Officer at Osmium Data Group. Together, we unpack what sovereignty actually means, why the conversation has accelerated so quickly, and where organizations are most likely to get it wrong.

Watch the full episode.

Key Takeaways

  • Digital sovereignty is no longer just a compliance issue – it has become a resilience and business continuity concern.
  • Data location is only one piece of the puzzle. Jurisdiction, operations, technology dependencies, and governance all matter.
  • Many organizations focus on technical controls before understanding the business problem they’re trying to solve.
  • Geopolitical uncertainty is accelerating sovereignty initiatives, particularly across Europe.
  • There is no such thing as a perfectly sovereign environment. Every organization must make informed trade-offs between risk, cost, and operational requirements.

Why Data Location Isn’t the Whole Story

One of the most common misconceptions around digital sovereignty is that it begins and ends with geography. If data is stored in a local data center, the thinking goes, the sovereignty problem has been solved.

It’s an understandable assumption. After all, many of the early conversations around sovereignty focused heavily on data residency requirements and where information could legally be stored.

But as Max points out during our discussion, that’s only one dimension of a much larger challenge. Sovereignty isn’t simply about where a data center sits. It’s also about who operates it, which laws apply to it, who has access to it, and what dependencies exist behind the scenes.

A cloud service may be physically located within a specific country, but that doesn’t necessarily mean it’s insulated from legal, operational, or technological influence originating elsewhere.

That’s where the conversation becomes significantly more complex.

The Hidden Dependencies Most Organizations Overlook

When organizations first begin exploring sovereignty, they often approach it as a technology project. They evaluate hosting locations. They assess replication strategies. They examine where workloads should run.

Those conversations are important, but they can also create a false sense of confidence.

As Max explains, modern technology environments are built on layers of dependencies that aren’t always visible. A service may appear local on the surface but it may be relying on infrastructure, management systems, telemetry services, or operational controls that exist elsewhere.

That’s why sovereignty isn’t simply a question of location. It’s a question of influence.

Who ultimately controls the service? Which legal jurisdiction applies when disputes arise? What happens if geopolitical tensions introduce new restrictions, regulations, or limitations on access?

These aren’t hypothetical questions anymore. They’re becoming part of real-world risk assessments.

Sneak Peek: Sovereignty Is More Than a Technical Problem

In this segment from the conversation, Max explains why organizations often start sovereignty discussions in the wrong place – and why understanding the legal, operational, and business objectives must come before any technology decisions.

Why Europe Is Driving the Conversation

One of the most interesting parts of our discussion focuses on why sovereignty has become such a dominant topic across Europe.

The answer isn’t just regulation; it’s dependency.

European organizations have become increasingly aware that many of the technologies they rely on every day are owned, operated, or governed outside of their direct control. For years, that reality was largely accepted as part of the global technology ecosystem.

Today, that assumption is being reevaluated.

Geopolitical tensions, evolving regulations, and increasing concern around strategic autonomy have pushed sovereignty higher on the priority list for governments and enterprises alike. What was once considered an edge case has become a mainstream business concern.

The result is a growing recognition that resilience isn’t only about recovering from technical failures. It’s also about understanding and managing external dependencies before they become business disruptions.

Sovereignty and Resilience Are the Same Conversation

One of the themes that you’ll see repeatedly surfacing throughout the discussion is how closely sovereignty and resilience are connected.

At first glance, they may seem like separate disciplines. One focuses on governance, regulation, and control. The other focuses on recovery, continuity, and operational readiness.

In practice, they’re deeply intertwined.

If a business cannot access critical systems because of a geopolitical event, regulatory restriction, or third-party dependency, the outcome isn’t very different from other disruptions organizations spend years preparing for.

The business still needs to operate. Customers still need to be served. Recovery still needs to happen.

That’s why I increasingly view sovereignty through the same lens as cyber resilience. Both are fundamentally about reducing exposure to events that could disrupt operations and preparing the organization to continue functioning when those events occur.

Start With the Business Problem

Perhaps the most practical advice Max shares is also the simplest.

Before evaluating sovereign cloud offerings, before engaging vendors, and before debating technical architectures, organizations should first understand what problem they’re trying to solve.

That means understanding:

  • Which business processes are most critical.
  • Which data assets matter most.
  • Which regulatory requirements apply.
  • Which risks are truly being mitigated.

Only after those questions are answered does it make sense to evaluate technology options.

Too often, organizations start with solutions and work backward toward the problem. Sovereignty requires the opposite approach. The strategy should come first.

The architecture follows.

Why There Is No Perfect Answer

One of the realities leaders need to accept is that there is no such thing as a perfectly sovereign environment.

Every organization operates within a network of dependencies. Every technology choice introduces trade-offs. Every risk decision involves balancing operational requirements, compliance obligations, cost considerations, and business outcomes.

The goal isn’t perfection. The goal is understanding those trade-offs well enough to make informed decisions.

Organizations that approach sovereignty as a binary yes-or-no question often find themselves frustrated. Organizations that approach it as a risk-management exercise tend to make better progress.

Why This Conversation Matters

Digital sovereignty is moving quickly from a niche compliance topic to a strategic business issue.

Boards are asking questions. Regulators are increasing scrutiny. Customers are becoming more aware of where their data lives and who controls it.

At the same time, geopolitical uncertainty continues to reshape how organizations think about risk.

That doesn’t mean every company needs a radical sovereignty transformation tomorrow.

But it does mean that the organizations that start building a clear strategy today will be in a much stronger position than those who wait until the conversation becomes unavoidable.

Sovereignty isn’t a technology decision masquerading as a business problem. It’s a business problem that requires legal, operational, and technical decisions working together.

Watch the Full Episode

In this installment, Max and I explore:

  • What digital sovereignty actually means.
  • Why data location alone isn’t enough.
  • The legal and operational dimensions organizations often overlook.
  • How geopolitical developments are influencing sovereignty strategies.
  • Why sovereignty and resilience are becoming inseparable.

Watch now.

FAQs

Q: What is digital sovereignty? 

A: Digital sovereignty refers to an organization’s ability to maintain control over its data, technology, operations, and governance within specific legal and jurisdictional boundaries.

Q: Is digital sovereignty the same as data residency? 

A: No. Data residency is one component of sovereignty, but sovereignty also includes legal jurisdiction, operational control, technology dependencies, and governance.

Q: Why has digital sovereignty become more important recently? 

A: Growing geopolitical uncertainty, evolving regulations, and increasing concern about technology dependencies have accelerated interest in sovereignty initiatives.

Q: What is the biggest mistake organizations make? 

A: Treating sovereignty as a purely technical challenge instead of a broader business risk and resilience issue.

Q: How does sovereignty relate to cyber resilience? 

A: Both disciplines focus on maintaining operational continuity in the face of disruptions, whether those disruptions are technical, legal, geopolitical, or regulatory.

Q: Where should organizations begin? 

A: Start by understanding the business outcomes you’re trying to protect, the risks you’re trying to mitigate, and the data and processes that are most critical to your operations.

Alex Zinin is VP/GM of Managed Service Providers at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • The role of the backup administrator is evolving from managing infrastructure to delivering business resilience and recovery confidence.
  • Modern ResOps (resilience operations) focus on recovery readiness, continuous validation, governance, and business outcomes – not just successful backup jobs.
  • Autonomous Resilience is Commvault’s vision for the next evolution of ResOps, where AI helps resilience teams reduce operational overhead through intent-driven, governed workflows while maintaining human oversight, approvals, and auditability.
  • By helping reduce repetitive operational work, AI enables resilience teams to spend more time improving cyber recovery, governance, and recovery readiness.
  • The future of resilience will be measured by confidence in recovery – not simply the successful completion of protection activities.

The Operational Shift at 8 a.m.

For an enterprise backup administrator, the morning routine has long followed a predictable, high-stress pattern. You log in at 8 a.m. to face a wall of dashboards. There are thousands of completed protection activities, but your eyes naturally scan for the exceptions – a handful of failed workloads, replication delays, and capacity alerts warning that critical storage resources are nearing their thresholds.

As you begin sorting through the day’s priorities, the reality of modern infrastructure closes in. A virtualization administrator submits a request: Dozens of new workloads were provisioned overnight, and leadership needs to know whether they are automatically covered by existing protection policies.

Moments later, the compliance team requests a detailed history of protection success and retention validation to prepare for an upcoming audit. Then, the security operations center (SOC) calls. An anomaly has been detected on a critical system, and they need confirmation that recovery copies remain isolated, immutable, and uncompromised.

Before you can finish your first cup of coffee, leadership asks a simple but devastating question: “If we were hit by ransomware right now, how consistently and confidently could we recover?”

Ten years ago, a successful backup administrator was an infrastructure gatekeeper. Success was binary and infrastructure-centric: Did the jobs finish within the required time window? Was the data successfully protected? If the dashboard was green, the job was done.

Today, that paradigm is entirely broken. The modern enterprise does not care whether data protection jobs completed successfully. It cares whether the business can survive a catastrophic disruption.

Success is no longer measured by the completion of a background data protection process. It is measured by an organization’s ability to withstand ransomware, infrastructure failures, cloud outages, insider threats, and compliance events without losing data or operational momentum.

The role has fundamentally evolved from infrastructure management to enterprise resilience. Yet many organizations still force administrators to spend their days managing operational tasks instead of architecting recovery confidence.

Commvault is working to redesign the administrator experience to help break this cycle, enabling a shift from reactive backup management toward comprehensive ResOps.

The Drag of the Modern Administrator’s Daily Reality

To understand why this shift is necessary, one must first recognize the enormous operational burden carried by administrators every day. Consider the volume of tactical work required to maintain a modern enterprise protection environment:

  • Job and infrastructure monitoring: Reviewing overnight activities, distinguishing transient issues from legitimate failures, and validating infrastructure health across a rapidly changing hybrid environment.
  • Troubleshooting and issue resolution: Spending hours reviewing diagnostic information and operational telemetry to determine why processes stalled, services became unavailable, or critical workloads failed unexpectedly.
  • Resource optimization and performance management: Continuously identifying storage constraints, network bottlenecks, or infrastructure limitations that impact protection and recovery objectives, then manually expanding capacity as requirements grow.
  • Workload discovery and lifecycle management: Automatically discovering, classifying, and assigning appropriate protection policies to newly deployed applications, cloud services, databases, and infrastructure resources.
  • Capacity and storage management: Monitoring consumption trends, forecasting growth, and responding to unexpected increases before they threaten recovery objectives.
  • Audit and compliance support: Collecting reports, validation records, and historical evidence across multiple systems to demonstrate compliance with retention and governance requirements.

Every hour spent troubleshooting an operational issue or assembling compliance evidence is an hour taken away from strategic resilience planning. This is where resilience teams lose time. The challenge is the operational overhead required to keep protection systems synchronized with a constantly evolving hybrid cloud environment.

The Structural Shift: From Backup Operations to ResOps

As organizational risk profiles increasingly center around cyber resilience and business continuity, the very mindset of data protection must evolve.

Old Mindset: Backup Operations

“I need my protection jobs to finish successfully.” 

New Mindset: ResOps

“I need confidence that we can recover immediately.” 

This evolution fundamentally changes the questions administrators must answer.

Backup Operations  ResOps
Did the workload complete protection last night? Are our critical applications verified as recoverable?
How much storage capacity remains? What is our verified recovery readiness posture?
Are recovery copies synchronized? Are our recovery environments protected and isolated?
Can we restore a single file? Can we recover an entire business service during a cyber event?

In this new model, recovery – not backup – becomes the primary operational metric. 

An organization can achieve near-perfect protection success rates while remaining dangerously unprepared for a ransomware attack due to compromised credentials, hidden dependencies, configuration drift, or unverified recovery processes.

ResOps assumes disruption is inevitable. The focus shifts toward continuous validation, proactive risk identification, threat awareness, and deterministic recovery orchestration.

At Commvault, we see this evolution leading toward Autonomous Resilience, where AI helps resilience teams move from manual operations toward intent-driven, governed outcomes.

How Commvault is Redesigning the Experience Around Outcomes

Commvault is addressing these realities by working to redesign the administrator experience. Rather than requiring users to organize their work around infrastructure configurations, protection policies, storage resources, and system assignments, Commvault is shifting the experience toward outcomes that matter to the business.

  • Unified management and risk-driven visibility: Rather than navigating multiple interfaces to manage different environments, administrators gain visibility into their entire estate through a unified resilience experience.

    The focus extends beyond operational status. The platform highlights risk exposure, protection gaps, emerging threats, unprotected workloads, and configuration drift that could impact recovery readiness.

  • Policy simplification and intelligent automation: Traditional environments often require administrators to manage hundreds of static schedules and policies. Commvault is designed to replace this complexity with intent-based protection plans.

    Administrators define business outcomes, while the platform can automatically orchestrate the infrastructure, optimize workflows, and manage protection activities behind the scenes.

  • Continuous validation and clean recovery environments: True resilience requires confidence not only in protected data but also in the ability to restore it safely.

    Commvault can integrate automated recovery validation directly into operations. This includes the ability to orchestrate isolated recovery environments where systems can be restored, validated, and inspected before production restoration occurs.

  • Threat-aware operations and intelligent detection: Modern resilience requires more than monitoring activity counts. By applying advanced analytics and machine learning to operational telemetry, the platform establishes historical baselines and detects abnormal behavior.

    When suspicious activity occurs, administrators receive contextual explanations, probable causes, impact assessments, and recommended actions – not just generic alerts.

A Day in the Life: The Outcome-Driven Workflow

To understand the potential impact of this transformation, consider an illustrative day for an administrator within an outcome-focused resilience platform. The scenario below shows how these capabilities are intended to work together.

8 a.m. – Establishing Recovery Readiness

Instead of searching through thousands of activities and alerts, you open a resilience dashboard displaying a comprehensive Recovery Readiness Score across the environment. The platform highlights a scaling concern. Recently deployed workloads have increased demand beyond recommended operational limits.

Rather than manually expanding infrastructure and coordinating resources, the platform automatically recommends a corrective action: “Additional infrastructure capacity is recommended to maintain recovery objectives. Approve?” 

A single approval initiates the adjustment.

11:30 a.m. – Automated Audit Resolution

The compliance team requests evidence of protection activity and policy compliance for a previous reporting period. Rather than manually compiling reports and spreadsheets, the administrator generates a compliance package containing validation records, policy compliance evidence, and supporting documentation within minutes.

Time is spent improving resilience – not producing paperwork.

2 p.m. – Threat Detection and Autonomous Response

A critical anomaly is detected. A workload exhibits behavior that significantly deviates from normal historical patterns.

Instead of issuing a generic warning, the platform automatically correlates the event with known behaviors, evaluates potential causes, assesses business impact, and identifies clean recovery points.

If a cyberattack is suspected, the platform highlights affected recovery data, isolates impacted assets, validates clean recovery options, and prepares recommended recovery actions.

The administrator is no longer investigating what happened. The platform is helping determine what to do next.

The Power of Intent: Why Embedded Intelligence Changes Everything

The engine powering this transformation is the move from manual task execution to autonomous, intent-driven operations.

Commvault’s conversational and AI-driven capabilities are designed to support the operational model that this transformation requires:

  1. An administrator expresses intent.
  2. The platform gathers context.
  3. Recommendations are generated.
  4. Actions are executed with appropriate oversight.
  5. Outcomes are validated.
  6. Activities are documented automatically for governance and audit purposes.

This fundamentally changes the relationship between administrators and the underlying technology. The goal is no longer to manage systems. The goal is to direct outcomes.

From Diagnostics to Actionable Root Cause

When infrastructure issues occur, administrators traditionally have spent hours reviewing diagnostic information, searching for symptoms, and piecing together dependencies. Embedded intelligence continuously monitors infrastructure health, operational telemetry, and service activity patterns. When an issue arises, diagnostic information can be analyzed automatically, probable causes identified, and remediation recommendations generated without requiring manual investigation.

Multi-Workload Dependency Correlation

Modern environments are interconnected ecosystems. A single infrastructure issue can generate hundreds of downstream failures. Rather than forcing administrators to investigate each event individually, the platform automatically correlates failures and identifies shared infrastructure dependencies, common services, or connectivity issues contributing to broader disruption.

Proactive Resource Forecasting

Instead of waiting for operational failures, the platform continuously analyzes historical workload patterns, growth trends, and infrastructure utilization. Expected changes are separated from abnormal behavior, allowing resilience teams to proactively address capacity and performance concerns before they impact recovery readiness.

The Rise of the Resilience Engineer

The data protection industry is undergoing a profound transformation. The title of backup administrator is rapidly becoming an artifact of a previous era – one in which data protection was viewed primarily as an operational task supported by infrastructure checklists.

Tomorrow’s successful professional is a resilience engineer. They collaborate with security teams to design cyber recovery strategies. They work alongside compliance leaders to automate governance requirements. They provide executives with measurable confidence in the organization’s ability to recover from disruption. Their value is no longer defined by how effectively they manage operational complexity, but by how effectively they reduce business risk and accelerate recovery.

Commvault is not simply enhancing an existing backup platform. It is helping build the operational framework for the next generation of resilience leadership. By helping reduce administrative overhead, simplify operations, and align the experience around recovery readiness and continuous validation, Commvault is enabling administrators to focus on what matters most: helping the business remain resilient. 

The future of enterprise availability is no longer about managing backups. It is about delivering autonomous resilience. 

Continue the Conversation

The conversation around Autonomous Resilience is just beginning. At SHIFT 2026 in Nashville this November, we’ll explore how AI is reshaping ResOps and what it means for the next generation of resilience engineers. Register here.

FAQs

Q: Why is the role of the backup administrator changing?

A: Enterprise resilience is no longer measured by successful backup jobs alone. Organizations increasingly judge resilience by their ability to recover confidently from ransomware, cloud outages, infrastructure failures, and other disruptions. As a result, backup administrators are taking on a broader role that spans cyber resilience, governance, recovery readiness, and business continuity.

Q: What is ResOps (resilience operations)?

A: ResOps reflects the shift from managing backup infrastructure to managing recovery readiness. It brings together data protection, cyber recovery, governance, continuous validation, and operational visibility into a single discipline focused on helping organizations recover with confidence.

Q: What is Autonomous Resilience?

A: Autonomous Resilience is Commvault’s vision for the next evolution of ResOps. It applies AI to help resilience teams reduce operational overhead through intent-driven, governed workflows that gather context, recommend actions, execute approved tasks, validate outcomes, and maintain auditability throughout the recovery process.

Q: How will AI change the day-to-day work of resilience teams?

A: AI can help reduce repetitive operational work such as reviewing backup activity, investigating failed workloads, collecting compliance evidence, assessing recovery readiness, identifying clean recovery points, and recommending recovery actions – all while operating within established governance controls. This allows administrators to spend more time improving resilience strategy and less time performing routine operational tasks.

Q: Does Autonomous Resilience replace backup administrators?

A: No. Autonomous Resilience is designed to augment resilience professionals, not replace them. Administrators remain responsible for oversight, approvals, governance, and decision-making while AI helps reduce operational overhead and supports day-to-day resilience operations.

Q: Why is this important now?

A: Hybrid infrastructure, cyber threats, AI adoption, and increasing operational complexity are changing what organizations expect from backup and recovery teams. The role is evolving from managing infrastructure to delivering resilience, making recovery readiness, governance, and operational confidence more important than ever.

Rajiv Kottomtharayil is Chief Products Officer at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • A CVE is a globally unique identifier for a publicly disclosed software vulnerability, enabling vendors, researchers, and defenders to reference the same consistently.
  • An organization’s approach to vulnerability disclosure – including coordinated fixes, researcher engagement, and accurate software inventory – is a strong indicator of overall security maturity.
  • Commvault protects its customers with a CVE program of transparency, cadence, and clarity. CVE disclosure says a great deal about the maturity of a security and engineering program.

Why This Matters

Many breaches that reach the boardroom trace back to vulnerability in software. The mechanism the entire industry uses to name and describe those vulnerabilities is the CVE, Common Vulnerabilities and Exposures.

How a vendor, or your own organization, handles CVEs is one of the clearest signals of security maturity.

A company that discloses and credits researchers fairly is usually a company that takes underlying engineering seriously. This blog explains how a CVE is built, who runs the system, and what separates an exemplary disclosure from a poor one.

Beyond the CVE: Why Disclosure Philosophy Matters

Publishing a CVE is table stakes. The differentiators are: transparency of the vulnerability and patch, regular scans and patching, and clear communication.

Commvault treats disclosure as an engineering and security discipline rather than a compliance checkbox: Establish a cadence for code review and remediation, communicate the fix in plain language, and protect our customers. That consistency, more than any single score, is what CVE disclosure says about security maturity.

What a CVE Actually Is

A CVE is not a patch, a score, or a piece of malware. It is a dictionary entry that gives one specific, publicly known vulnerability a permanent, unique name so that everyone can refer to it.

The identifier itself follows a simple, durable format: the letters CVE, the year the ID was assigned, and a sequence number, for example, CVE-2021-44228.

The scale of the program is enormous, and still growing: 48,000 CVEs were published in 2025, on the order of 132 per day, up more than 260% since 2020.

The Anatomy of a Single Record

CVE publications require a consistent set of elements. Reading one is straightforward once you know what each part is for:

  • Identifier, the unique CVE-YYYY-NNNNN
  • Description, a concise explanation of the vulnerability: what it is and how a threat actor could exploit it.
  • Affected products and versions, which software, hardware, or firmware (and which versions) are impacted, and which versions contain the fix.
  • Criticality, the underlying category of criticality.
  • References, links to the vendor advisory, the patch, and technical write-ups.

The Supporting Cast: CVSS, CWE, EPSS, and KEV

Four companion systems turn a CVE into something a business can prioritize. They are easy to confuse, so the distinction is worth holding onto:

  • CVSS (Common Vulnerability Scoring System) answers “How severe is it?” CVSS is the severity rating (1–10, 10 being the most severe) of the flaw, not a measurement of your specific exposure.
  • EPSS (Exploit Prediction Scoring System) answers “How likely is this to be exploited soon?” EPSS produces a probability score, from zero to 100 percent, estimating the likelihood that a vulnerability will be exploited in the next 30 days.
  • CWE (Common Weakness Enumeration) answers “What kind of mistake caused it?” The CWE classifies the underlying coding weakness.
  • KEV (Known Exploited Vulnerabilities) answers “Is it being used against people right now?” The KEV catalog is a curated list of CVEs with confirmed real-world exploitation.

A high CVSS score tells you how serious a vulnerability could be, a high EPSS score tells you how soon it is likely to be exploited, and a listing in the KEV catalog confirms exploitation is already happening. The best vulnerability programs weigh all three.

FAQs

Q: What is a CVE, and why is it important?
A: A Common Vulnerability and Exposure (CVE) is a standardized identifier assigned to a publicly disclosed software vulnerability. It enables everyone – from vendors and researchers to regulators and customers – to refer to the same vulnerability without ambiguity.

Q: What information should a well-formed CVE record contain?
A: A complete CVE record requires a unique identifier, a description of the vulnerability, affected products and versions, the criticality type, and references to vendor advisories or patches. These elements enable organizations to understand their exposure and respond efficiently.

Q: How do CVSS, CWE, EPSS, and KEV differ from a CVE?
A: A CVE identifies a specific vulnerability, while CVSS measures its severity, EPSS estimates the likelihood of near-term exploitation, CWE classifies the underlying coding weakness, and KEV identifies vulnerabilities that are actively exploited in the real world. Together, these frameworks help provide the context needed to prioritize remediation.

Q: What does Commvault look for in its own disclosure practices?
A: Commvault holds its own disclosures to the same standard it expects of others: transparency, cadence and clarity. That is how Commvault protects its customers.

Q: What should business leaders evaluate when assessing vendors’ vulnerability management practices?
A: Leaders should look for coordinated disclosure timelines, comprehensive and accurate CVE records, clear remediation guidance, robust reporting programs, and the ability to quickly determine whether products are affected by newly disclosed vulnerabilities. These characteristics reflect a strong security culture and improve organizational resilience.

Werner Nel is Principal Product Experience Manager at Commvault.

More related posts


Cyber Resilience

Read more about Cyber Resilience

Key Takeaways

  • JadePuffer is the name security researchers at Sysdig gave to what they assessed as the first documented ransomware operation driven end-to-end by an autonomous AI agent, not a human working through a toolkit.
  • The individual techniques weren’t new. What changed was orchestration speed: The agent chained reconnaissance, credential theft, lateral movement, and destructive encryption, correcting a failed login attempt in 31 seconds.
  • The agent generated its own encryption key, then never stored or transmitted it. Paying the ransom would not have restored the data.
  • The real damage targeted configuration state and control-plane systems, not just files, which is exactly the layer most recovery plans don’t cover.
  • Recovering from an attack like this means proving the business can safely resume operations, not just restoring a backup.

What Happened

In mid-2026, security researchers at Sysdig documented an extortion campaign they believe is the first of its kind: a ransomware operation carried out end-to-end by a large language model agent, with minimal human hands-on-keyboard involvement. They named it JadePuffer.

The entry point was familiar. The attacker exploited CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow, an open source framework for building AI agent workflows, running a version older than 1.3.0. From there, the agent enumerated the host, searched for credentials across cloud providers, AI model vendors, and databases, and quietly dumped the platform’s own backing database.

What happened next is the part worth paying attention to. The agent scanned the internal network, found an exposed object store, and pulled Terraform state and configuration files. It set up a scheduled task to call home every 30 minutes. Then it pivoted to a separate production system running MySQL and Alibaba Nacos, a configuration and service-discovery platform common in microservice architectures.

Once inside, the agent tried to create an administrator account in Nacos. It failed. Thirty-one seconds later, it had diagnosed the failure and succeeded with a different approach. It then used MySQL’s file-handling functions to probe whether it could escalate further, before encrypting more than 1,300 configuration records, dropping the original tables, and leaving a ransom note behind.

The encryption key was generated on the fly, displayed once, and never stored anywhere the attacker could retrieve it again. Whether or not that was intentional, the outcome for the victim is the same: There was no path back through the attacker or a decryption key, ransom paid or not. Recovery would depend on clean backups, rebuild, or validated recovery points.

Why Researchers Are Calling This “Agentic”

None of the individual techniques here are new. Exploiting an unpatched CVE, harvesting credentials, scanning for lateral movement, encrypting data for extortion: Security teams have seen every one of these before. What made Sysdig classify the operator as agentic rather than a conventional attacker is how the steps fit together.

The agent didn’t run a fixed script. It observed results and adjusted. When it expected a JSON response and got XML back, it changed its approach and kept going. When its first attempt to create an admin account failed, it diagnosed the specific failure and tried something different, in under a minute.

Researchers also found comments embedded in the payloads, explaining targets and next steps in simple language, a pattern more consistent with an LLM reasoning through a task than a human copying and pasting a known exploit kit.

Public reporting hasn’t confirmed which model or platform powered the attack. What’s confirmed is the behavior: Something reasoned, acted, hit a wall, and corrected course faster than most human-paced incident response can move.

The Recovery Problem Too Many Frameworks Still Miss

Most ransomware playbooks are built around a specific assumption: something encrypted your files, and the question is whether you can restore a clean backup or need to negotiate a decryption key.

JadePuffer breaks that assumption in two ways. First, there was no decryption key to negotiate for. Second, the damage wasn’t only in the data. It was in the configuration and control-plane layer underneath the data: the service-discovery platform, the secrets it held, the Terraform state describing how the infrastructure fit together, and the credentials scattered across every system the agent touched on the way there.

That’s a harder recovery problem than “restore the database.” A clean file restore into an environment with rotated-but-not-verified credentials, unreviewed configuration drift, and an identity layer nobody has re-audited isn’t really a clean recovery. It’s a fresh copy of the data sitting inside a system that still can’t be trusted.

What This Means for Your Resilience Strategy

JadePuffer is a preview of the question every recovery plan will eventually have to answer: Can you resume operations when an attacker has touched not just your data, but the identity, configuration, and control-plane systems that data depends on?

A few places to start:

Treat configuration and control-plane systems as recovery-critical, not just applications. Service discovery platforms, secrets stores, and infrastructure-as-code state are as business-critical as the databases they configure. If they aren’t in your recovery plan today, that’s the first gap to close.

Build credential hygiene into recovery, not after it. Restoring a workload that reintroduces compromised secrets doesn’t end the incident; it resets the clock on it. This is the same discipline Commvault applies to identity infrastructure today: vulnerability assessment to see exposure before an attacker does, real-time auditing to catch changes as they happen, and rollback to undo unauthorized changes without rebuilding from scratch.

Validate before you restore, not after. A restore point is only useful if you know it’s clean. That’s the logic behind Commvault® Cleanroom™: testing and validating data in an isolated environment before it ever touches production again, rather than finding out after reinfection.

Plan for a control-plane compromise, not just a file-encryption event. A recovery journey map built only for “encrypted files, restore from backup” won’t hold up against an incident like this. The more useful question, and the one at the center of ResOps (resilience operations) as an operating discipline, is what it takes to reach minimum viable operations when the systems underneath your applications are the ones that got hit.

None of this requires treating agentic AI as an unprecedented threat that demands starting from zero. It requires extending the same resilience discipline that already applies to identity and data, down into the configuration and control-plane layer that agentic attacks are now targeting directly.

Learn more about how Commvault approaches identity resilience and clean recovery validation.

FAQs

Q: What is JadePuffer?

A: JadePuffer is the name Sysdig gave to what it assessed as the first documented ransomware campaign driven end-to-end by an autonomous AI agent, rather than a human attacker manually operating a toolkit.

Q: Did the attackers use a specific AI model, like ChatGPT or Claude?

A: Public reporting hasn’t confirmed which model or platform was used. The agent searched for API keys from multiple AI providers, which shows interest in that kind of access, but doesn’t identify what powered the attack itself.

Q: How did the attack start?

A: Through CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, an open-source AI agent framework, affecting versions before 1.3.0.

Q: Could the victim have paid the ransom to recover their data?

A: No. The encryption key was generated on the fly and never stored or transmitted, so there was no key available to recover, regardless of payment.

Q: What makes this different from typical ransomware?

A: The individual techniques weren’t new. What stood out was the speed and adaptability: the agent diagnosed a failed login attempt and corrected it in 31 seconds, a pace closer to machine speed than typical human-paced attacker behavior.

Q: What should security and recovery teams take away from this?

A: That recovery planning needs to extend beyond application data to configuration stores, service-discovery platforms, secrets, and identity systems, the layer JadePuffer actually targeted for maximum damage.

Chris Bevil is Principal Portfolio Marketing Manager at Commvault.

More related posts


Cyber Resilience

Read more about Cyber Resilience

Key Takeaways

  • Advanced AI models escaped a restricted evaluation environment by exploiting previously unknown vulnerabilities.
  • OpenAI says the models were pursuing an assigned objective, not acting with malicious intent, yet still caused a real security incident.
  • Traditional controls like sandboxing and segmentation are insufficient if AI can discover unexpected paths around them.
  • Cyber resilience is becoming as important as prevention.

It began as an internal evaluation of advanced AI cyber capabilities.

While attempting to solve a narrowly defined benchmark, OpenAI models discovered a zero-day vulnerability, escaped the intended restrictions of their test environment, escalated privileges, reached the internet, and compromised Hugging Face infrastructure.

They treated the technical boundaries around them as problems to solve.

This Was Not a Traditional Cyberattack

Hugging Face first reported that an autonomous AI-agent framework had compromised part of its production infrastructure. A malicious dataset exploited two code-execution paths in its dataset-processing pipeline, escalated to node-level access, harvested credentials, and moved laterally across internal clusters.

The models involved, including GPT-5.6 Sol and a more capable pre-release model, were operating with reduced cyber refusals and without the normal production classifiers. They went far beyond the assignment, exploiting a proxy vulnerability to reach the internet, then using stolen credentials and zero-day vulnerabilities to find a remote-code-execution path on Hugging Face servers.

Malicious Intent Was Not Required

There is no public indication that the models developed criminal intent or chose to harm Hugging Face. They did not need to. Give a capable system an objective, tools, time, and feedback, and it will route around obstacles.

The conversation has moved past prompts and bad answers. These are systems that can investigate, test assumptions, discover previously unknown vulnerabilities, use stolen credentials, escalate privileges, and continue operating when the first approach fails.

A Sandbox Is Not a Force Field

We call environments isolated, segmented, and sandboxed as though the label itself creates security. It does not. In this case, the obvious path to the internet was blocked, but a reachable software-package proxy was not, and the models used its vulnerability to escape. Policies and expected behavior are not enough. The technical environment itself must enforce the boundaries.

Why This Is a Resilience Story

The activity moved from an evaluation environment, through OpenAI’s research infrastructure, onto the internet, and into Hugging Face’s production environment. That is a rapidly expanding blast radius. When AI can explore and act at machine speed, the time between initial access and broader compromise may continue to shrink.

Hugging Face did not simply block the original access path and declare the incident over. It closed the vulnerable code-execution paths, rebuilt compromised nodes, rotated credentials and tokens, and tightened cluster controls. The objective is not merely to restore a system. It is to restore confidence.

The question is no longer only: Are our AI systems secure? It is: When a powerful AI system finds a path we did not know existed, can we contain the blast radius, continue critical operations, rebuild what we no longer trust, and prove it is safe to move forward?

Chris Bevil is Principal Portfolio Marketing Manager at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • The rapid growth in vulnerabilities and AI-enabled discovery is shrinking the time between vulnerability disclosure and active exploitation.
  • Regular, disciplined patching cycles help reduce overall exposure and prepare for new CVEs.
  • Recovery is essential for resilience, but it must be paired with timely patching to remediate vulnerabilities.
  • Organizations should use AI to accelerate vulnerability detection and remediation rather than allowing issues to accumulate in backlogs.
  • Vendors who play a critical role provide fast, transparent vulnerability disclosures and clear remediation guidance for customers.

Last year, industry reporting put annual CVE volume in the tens of thousands, with NIST later noting record CVE growth and a 263% increase in submissions between 2020 and 2025.

I hear what that does to a security team in real time, because I am on the calls when it happens. The old questions – what is our exposure, and how fast can we close it? – used to have room to breathe. Now they arrive faster than most teams can staff for them.

Most organizations have vulnerability response processes. Fewer have processes designed for this speed.

For years, the industry organized its response around individual vulnerabilities. A CVE would publish, severity scores would follow, enrichment would catch up, and teams would triage with some margin for judgment. That rhythm assumed a human pace of discovery, but that assumption no longer holds.

That volume is already outrunning the infrastructure built to track it. NIST has said the National Vulnerability Database is moving to a risk-based enrichment model because CVE submissions have grown faster than the program can fully process them.

AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. The window between when a vulnerability is discovered and when it is exploited is closing, and working exploit code can appear before a patch is widely deployed.

That breaks the old model. Structured vulnerability management still matters, but many programs are calibrated for a slower era: gather signal, rank risk, assign owners, then remediate. When discovery accelerates this sharply, even disciplined teams fall behind because the operating model cannot absorb the volume fast enough.

So, the unit of work must change. It no longer matters whether you patched a specific vulnerability but whether your organization can apply, verify, and recover at the speed the threat environment now demands.

Patch on a Clock

Start with cadence. The most resilient operations I see have stopped treating patching as an interruption and started treating it as routine maintenance: scheduled weekly, visibly owned, and measured like any other operational commitment.

A predictable cadence helps shrink the standing window of exposure across the estate and remove the panic premium from any single disclosure. When patching happens every week, organizations are prepared for CVEs.

Cadence does not mean treating everything alike. A vulnerability under active exploitation, the kind that lands in CISA’s Known Exploited Vulnerabilities Catalog, still earns an immediate, out-of-band response. The weekly schedule handles the flood as routine, so true emergencies receive proper attention instead of competing with noise.

Close the Vulnerability, Not Just the Gap

Here is the part recovery cannot fix by itself. If a vulnerability puts an asset at risk, restoring that asset without closing the vulnerability just resets the clock. The vulnerability is still there, waiting for the next attempt. Recovery matters, but it is not a substitute for closing the hole that let the threat actor in.

That means the real work needs to happen earlier, at the point where vulnerabilities are found and fixed. AI is changing that math on both sides. The same models that help an threat actor spot an exploitation can help a vendor find it first.

Commvault Engineering runs AI against our own codebase to scan for vulnerabilities before they ship, and we apply AI to help resolve what we find instead of routing it into a backlog. A vulnerability that sits in queue for weeks because a team ran out of bandwidth is still a vulnerability. Speed to detection means nothing without speed to resolution.

Ask More of Your Vendors

When the window between discovery and exploit is measured in hours, customers cannot afford to learn about a vulnerability in their vendor’s product from a third party.

They need to hear it from the vendor, early, in plain language, with a direct answer to “Am I affected?” and “What do I do first?” Ask every critical vendor how quickly they disclose, how they notify affected customers, what evidence they provide for remediation, and how customers can validate that the exposure is closed. Vulnerability transparency is part of resilience.

The frontier AI era will not be won by whoever ships the fewest vulnerabilities. Every serious software company will disclose more. The advantage goes to whoever treats patching as a standing discipline and treats recovery as the discipline that makes a missed window survivable.

FAQs

Q: Why is the window between vulnerability discovery and exploitation getting shorter?
A: AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. As a result, exploit code can become available before many organizations have had time to deploy patches.

Q: Why are weekly patching cycles becoming more important?
A: A consistent weekly patching schedule helps reduce the organization’s exposure to known vulnerabilities. It also allows security teams to focus immediate attention on actively exploited threats and prepare new CVEs.

Q: Is disaster recovery enough to protect against cyberattacks?
A: No. Recovery helps organizations restore operations after an incident, but restoring systems without addressing the underlying vulnerability leaves them exposed to future attacks. Effective resilience requires both rapid remediation and reliable recovery.

Q: How can AI help improve vulnerability management?
A: AI can help identify vulnerabilities earlier, prioritize remediation efforts, and accelerate the resolution process. This helps security and engineering teams respond more quickly instead of allowing vulnerabilities to remain unresolved in lengthy backlogs.

Q: What should organizations ask their software vendors about vulnerability management?
A: Organizations should ask how quickly vendors disclose vulnerabilities, how affected customers are notified, what remediation guidance is provided, and how customers can verify that the issue has been fully addressed. Transparent communication is an important part of cyber resilience.


Rajiv Kottomtharayil is Chief Products Officer at Commvault.

 

More related posts


AI Data Resilience

Read more about AI Data Resilience

Cyber Resilience

Read more about Cyber Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Security does not end at the edge of an organization’s own systems. Modern businesses connect a growing web of third-party applications to their core platforms to support sales, service, and collaboration. Each of these connections adds value. Each one also introduces exposure the organization does not fully control.

That risk is not hypothetical. In June 2026, a threat actor compromised OAuth tokens tied to Klue, a competitive intelligence platform used to sync sales and marketing data with Salesforce. The attacker used those tokens to reach the Salesforce environments of the many organizations that had authorized the integration, including Commvault’s.

As soon as we were notified of potential impact, our Security team activated our incident response process to determine what had occurred, contain the exposure, and assess whether customer information or Commvault services were affected.

Our investigation found that the activity was limited to certain business relationship and sales information maintained within our Salesforce environment. The investigation found no indication that any customer backup data, product data, product metadata, operational logs, or Commvault services were impacted.

Acting Quickly When It Matters

Our response followed established security incident response procedures built to contain risk quickly while supporting a thorough investigation. Once we were notified of the incident, we disabled the Klue integration, revoked the associated access, and worked with the appropriate parties to conduct a full assessment of what happened.

Throughout the investigation, our teams worked to determine what information had been accessed, validate the integrity of our environment, and confirm the incident stayed within the scope we had already contained.

A Pattern Worth Noting

This incident is one recent example of a pattern security teams have watched grow for several years: attackers targeting third-party applications connected to core business systems rather than attacking those systems directly. A single compromised integration can offer a trusted path into the environments of many downstream organizations at once, often with less resistance than a direct attack on any one of them.

This shifts where an organization’s defense actually has to live. Strong internal controls remain necessary, but they are no longer sufficient by themselves. They have to be paired with active oversight of every application an organization connects, and a response capability that is ready before an incident, not built during one.

Building Resilience Beyond Our Own Environment

At Commvault, our security program includes ongoing assessment of the third-party applications connected to our environment. We review connected applications on a regular basis, evaluate the access each one holds, monitor for emerging risk, and reassess those integrations as business needs and the threat landscape change. When circumstances warrant, we act to reduce exposure and strengthen our posture, including disconnecting integrations that no longer meet our standards.

Our Commitment to Transparency

Trust is built through openness and accountability. When an event affects our stakeholders, we believe it is important to communicate what we know, explain how we responded, and share the outcome of our investigation, even when the event originated outside our own systems.

We will continue to evaluate our security controls, refine our incident response processes, and strengthen our approach to third-party risk as part of our broader commitment to protecting our customers and partners.

For the official details of this incident, including the scope of the investigation and customer guidance, please refer to our Trust Center Updates.

Will Galway is Deputy CISO at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

How to Architect Unified Data Protection: A Single Platform for Modern Workloads

Unified data protection consolidates security, recovery, governance, and AI automation into a single platform, enabling consistent protection and reliable recovery across hybrid and multi-cloud environments

Key Takeaways

Unified data protection consolidates security, recovery, governance, and AI automation into one platform, helping reduce complexity while strengthening cyber resilience.

  • Unified data protection replaces fragmented tools with a single control plane that spans on-premises, hybrid, and multi-cloud environments for optimized TCO.
  • Siloed protection strategies increase operational complexity, weaken visibility, and reduce confidence in enterprise-wide recoverability.
  • A unified platform connects data security, cyber recovery, and identity resilience to help strengthen overall cyber resilience.
  • A dedicated instance delivers isolated resources, streamlined compliance and data localization, along with SaaS-driven innovation – helping enable secure, compliant operations without infrastructure management overhead.
  • Embedded AI capabilities help support automated discovery, intelligent policy enforcement, and faster, cleaner recovery outcomes.

Most enterprise data protection strategies were designed for a world that no longer exists — before cloud sprawl, AI-generated data growth, and hybrid infrastructure became the norm. Commvault Cloud addresses this architectural gap with a unified platform that connects data security, cyber recovery, identity resilience, and AI-enabled governance across every environment from a single control plane.

Why Do Modern Enterprises Need Unified Data Protection?

According to IBM’s Cost of a Data Breach Report 2025, the average cost of a data breach stands at a staggering $4.4 million globally, with costs rising significantly when recovery is delayed or incomplete.

At the same time, the World Economic Forum notes that as organizations confront AI threats, geopolitical volatility, and supply chain vulnerabilities, the need for resilience has never been clearer.

Enterprise data protection is rapidly entering a new period of drastic modernization. Data no longer lives in predictable locations, and it certainly does not remain still. Critical workloads exist across on-premises infrastructures, multiple public clouds, SaaS platforms, containers, and emerging AI pipelines. Each environment brings its own operational model, its own tooling, and its own risks.

For security and IT teams, the pressure is intensifying. Many organizations are now confronting three critical structural challenges simultaneously:

  • AI is generating exponential volumes of distributed data, which expands the potential attack surface.
  • Many enterprises still rely on siloed products to secure, protect, manage, and recover data, even though those tools were never designed to operate together.
  • There is no one-size-fits-all approach. Modern enterprises run across on-premises, cloud, and hybrid environments, and require resilience that spans all of them.

This complexity did not emerge overnight. It developed as cloud adoption accelerated and application teams moved faster than protection strategies could evolve, resulting in fragmented visibility, inconsistent operations, and uncertainty around recovery readiness.

In this landscape, unified data protection has emerged as the architectural response – establishing a single control plane that helps protect workloads consistently across environments, reduce complexity, and strengthen confidence in enterprise-wide recoverability.


How Does Unified Data Protection Eliminate Fragmentation?

A recent study by IBM and Palo Alto Networks highlighted that the average organization has 83 different security solutions from 29 vendors. In this unhappy new norm, 52% of executives believe complexity is the biggest impediment to security operations.

The fragmentation of protection causes inefficiencies while actively increasing operational and security risks. What often happens is that each new workload category introduces another protection tool. Cloud-native backups operate separately from virtual machine protection. SaaS data sits in its own silo. Compliance reporting pulls from multiple disconnected systems. Over time, this complexity multiplies, with coverage becoming uneven and difficult to verify.

The operational burden grows quickly. Teams are forced to manage multiple consoles, increasing costs and technical challenges. Security leaders lack a unified view of protected vs. exposed data. Compliance teams spend cycles reconciling evidence. Finance teams struggle to understand true protection costs. And the biggest obstacle: Recovery confidence becomes inconsistent, and uncertainty reigns supreme.

Finally, leaders are left asking a fundamental question: Are we truly recoverable across our entire data estate?

Overcoming the obstacle of fragmentation now has become essential to long-term organizational success. Unified data protection is designed to address this by helping eliminate silos and establishing a consistent operational model across environments.

Why Do Modern Businesses Need a Unified Architectural Reset?

Unified data protection represents a change in how protection platforms are built and operated. Instead of layering tools around individual environments, modern architectures establish a single policy and intelligence layer that spans the entire data estate. Unified protection is about creating a cohesive cyber resilience foundation that brings together data security, cyber recovery, and identity resilience within a single operational model.

A unified platform supports:

  • Consistent protection across the full workload spectrum.
  • Centralized visibility into protection posture and cost.
  • Unified policy and governance enforcement.
  • Flexible deployment models that respect data residency needs.
  • AI-enabled automation that scales with data growth.
  • A single operational experience for backup, recovery, and mobility.

The Commvault Cloud platform positions unified protection as foundational to modern cyber resilience.


How Does Unified Protection Support Regulated and Sovereign Environments?

For heavily regulated industries and critical workloads, unified protectiohn must go beyond visibility and efficiency. It shoudl also help deliver provable isolation, geographic control, and audit readiness. Digital sovereignty requires demonstratable, auditable control over where data resides, who can access and operate the environment, and how recovery is executed. It is not achieved simply by chooisng a cloud region or provider; it depends on how the entire system is architected, governed, and operated.

Commvault Geo Shield helps address these requirements by helping enabling configurable controls across data while adapting to evolving customer sovereign needs in modern hybrid cloud environments. Built for real-world regulation, this solution helps keep data, metadata, and access within your region, limiting extraterritorial exposure.

Similarly, Commvault Cloud Dedicated Instance provides a fully isolated SaaS environment designed for organizations with strict compliance, privacy, or data residency mandates. Customers receive their own dedicated compute, storage, and management resources, and this solution is designed so that infrastructure is never shared across unrelated tenants.

Dedicated Private Instance provides several advantages for modern enterprises. It helps:

  • Simplify audits for frameworks such as HIPAA, FedRAMP, and GDPR.
  • Support data residency requirements through geographic deployment choice.
  • Support continuous SaaS innovation velocity while preserving isolation.
  • Exercise greater control over upgrade timing and feature rollout.
  • Reduce friction when transitioning regulated workloads to SaaS.

Dedicated Private Instance operates within the same unified platform experience. Organizations are designed to maintain feature parity and innovation speed when choosing a more controlled deployment model.


How Does AI Strengthen Unified Cyber Resilience?

AI is reshaping both the threat landscape and the opportunity for smarter protection. However, AI capabilities deliver the most value when they are embedded across the entire data protection lifecycle rather than applied as isolated features.

Within the unified platform, AI-enabled capabilities help support:
Automated data discovery and classification. 

  • Intelligent protection policy recommendations.
  • Continuous monitoring and enforcement.
  • Optimization insights that improve cost and resilience posture.

These capabilities are part of Commvault’s broader data security vision, which was strengthened through the acquisition of Satori Cyber. The acquisition was particularly important in an environment where data growth is outpacing traditional defenses.

Through this acquisition, Commvault Cloud now delivers Commvault Data & AI Security — a cloud-native capability that helps address the needs of modern enterprises adopting AI and managing sensitive data across structured and unstructured environments.

The unified platform also advances cyber recovery through AI-enabled workflows such as Synthetic Recovery, which helps surgically remove compromised data while restoring clean business operations. In parallel, expanding identity resilience capabilities helps organizations detect, audit, and respond to threats targeting identity systems such as Active Directory.

What Is the Strategic Impact of Unified Data Protection?

Unified data protection allows organizations to rethink how they operationalize cyber resilience. By bringing together data security, cyber recovery, and identity resilience within one architecture, organizations gain access to a coordinated set of capabilities that work consistenly across diverse ecosystems.

This unified foundation helps deliver extended benefits:

  • Unified protection across workloads, clouds, and locations designed to improve availability of trusted data.
  • Unified governance that connects security, identity, and recovery operations.
  • Unified intelligence that correlates signals across previously disconnected systems.
  • Faster, cleaner recovery outcomes when cyber incidents occur.
  • Reduced operational complexity at enterprise scale.

Industry observers have noted that while elements of this convergence have appeared before, meaningful unification across these disciplines has been limited. Platforms such as Commvault Cloud advance this vision by operationalizing resilience across the full enterprise data estate.

To learn more, visit the Commvault Cloud platform page.

Conclusion: How Does Unified Data Protection Define the Next Era of Cyber Resilience?

The shift toward unified data protection reflects a broader reality. Enterprises can no longer afford fragmented resilience strategies in a world defined by AI-enabled data growth, distributed infrastructure, and increasingly sophisticated cyber threats.

Now, architectures that unify visibility, governance, intelligence, and recovery are becoming foundational to IT and security operations.

Platforms designed around this principle help organizations modernize their approach to protection. By covering the broadest range of workloads, supporting flexible deployment models, and embedding AI-enabled intelligence across the lifecycle, such platforms enable organizations to improve recovery confidence without adding complexity.

For security and IT leaders, the path forward is becoming clear. Resilience must be unified, intelligent, and adaptable to wherever data lives.

Frequently Asked Questions

What is unified data protection, and why does it matter now?

Unified data protection is an architectural approach that uses a single platform to protect all workloads across hybrid and multi-cloud environments. It matters now because fragmented tools cannot address AI-enabled complexity, distributed infrastructure, and sophisticated cyber threats at enterprise scale. Commvault Cloud o designed to deliver this through a single control plane that spans data security, cyber recovery, and identity resilience.

How does fragmentation increase enterprise risk?

Fragmented protection creates visibility gaps, inconsistent policies, and uneven recovery capabilities — making it difficult to verify coverage or confidently recover at scale. Commvault Cloud is designed to address this by replacing siloed tools with a unified control plane that provides consistent visibility, governance, and recovery confidence across on-premises, hybrid, and multi-cloud environments.

How does Commvault Cloud support multi-cloud environments without vendor lock-in?

Commvault Cloud unifies protection across AWS, Azure, Google Cloud, and on-premises environments through a single interface. This approach helps organizations manage policies, monitor risk, and optimize costs across clouds without being tied to a single infrastructure provider.

What role does Dedicated Instance play in regulated industries?

Dedicated Instance provides a fully isolated SaaS environment with dedicated compute, storage, and management resources. It helps organizations meet compliance, privacy, and sovereignty requirements while maintaining access to the same unified platform capabilities.

How does AI enhance unified data protection?

Commvault Cloud embeds AI-enabled capabilities across the full protection lifecycle — supporting automated data discovery, intelligent classification, policy recommendations, and continuous monitoring. Strengthened through the acquisition of Satori Cyber, these capabilities help reduce exposure windows, optimize protection strategies, and accelerate clean recovery after incidents without adding operational complexity.

How does unified protection improve cyber recovery outcomes?

Commvault Cloud integrates data security, cyber recovery workflows, and identity resilience signals within a single platform — helping organizations detect threats earlier and execute faster, more precise recoveries. Capabilities like Synthetic Recovery and anomaly detection work together to help strengthen resilience and reduce operational disruption during incidents.

Explore Related Resources

Commvault’s Complete Cloud Platform

Solution

Commvault Cloud Geo Shield

Learn how Geo Shield helps organizations align cyber resilience with sovereignty, regulatory, and operational requirements across hybrid and multi-cloud environments.
Explore the solution about Commvault Cloud Geo Shield
Solution

Commvault Cloud Unity Dedicated Instance

Explore how Dedicated Private Instance combines infrastructure isolation with simplified SaaS-style operations for organizations with strict compliance, privacy, or data residency requirements.
Explore the solution about Commvault Cloud Unity Dedicated Instance

The conversation around AI is changing quickly. That’s why I’m so excited to share our podcast series Ready. Or Not. We’ve paired comedian Nathan Macintosh with expert guests to talk about AI agents, cyber resilience, trust, data management, and more.

In our first episode, Nathan sits down with Dr. Reid Blackman, founder and CEO of Virtue Consultants, to tackle one of the biggest topics in AI today: agentic AI. From ethical challenges to security risks, their conversation explores what happens when AI moves beyond making content to making decisions – and taking action.

One thing is clear: Agentic AI isn’t just another technology trend. It’s changing how we think about decision-making and the role AI will play in our organizations. If you’re wondering what agentic AI means for your business, this podcast is a great place to start.

Watch the full episode on Readiverse.

Blog Key Takeaways

  • Most AI failures are caused by unintended consequences, not malicious intent.
  • Agentic AI can access systems, tools, and data to get work done, making it both incredibly useful and inherently risky.
  • AI agents can create new security challenges, from prompt attacks to expanded attack surfaces.
  • Multi-agent systems can increase efficiency, but they can also amplify mistakes when systems are connected.
  • Organizations need practical frameworks for managing AI risks before they become real-world problems.

First, Do No Harm

One takeaway from the episode is that most AI failures don’t start with bad intentions. Many begin with organizations trying to solve legitimate business problems.

Dr. Blackman uses a failed Amazon AI recruiting tool as an example. The algorithm was trained on past resumes and hiring data to inform future hiring decisions. AI ultimately learned patterns that favored male candidates because those patterns existed in the data.

The result wasn’t what Amazon intended, but that’s exactly the point. AI systems can learn lessons we never meant to teach them.

What happened next was encouraging: Amazon tested the system, identified the issue, tried to correct it, and ultimately discontinued the project when the problem couldn’t be resolved.

We tend to treat AI failures as proof that technology can’t be trusted, but Dr. Blackman makes a different point. Responsible AI isn’t about pretending mistakes won’t happen. It’s about testing, learning, and being willing to stop when something isn’t working the way you intended.

When AI Becomes Your Coworker

The Amazon example also highlights something bigger. AI is capable of delivering value, but it can also produce unintended outcomes when we don’t fully understand how it’s learning or making decisions. Generative AI showed us what AI can create. Agentic AI is showing us what AI can actually do when it’s connected to business systems.

One comparison that stood out to me was that agentic systems are, in some ways, starting to look like employees. To be useful, they need access to the same tools, databases, and software that people use. Give an AI agent access to one system, and it can do one job. Give it access to dozens of systems, and it becomes more powerful.

“More access means more capability, but it also increases risk dramatically.”

– Dr. Reid Blackman

Sneak Peek: Keeping AI in Check

What happens when your AI agent starts interacting with other people’s agents? In this clip, Dr. Blackman explains why monitoring multi-agent systems will become one of our biggest challenges.

A New Kind of Security Challenge

Agentic AI changes more than the way work gets done. It also changes the way we think about security. Instead of following predefined workflows, users interact with AI through natural language. That makes these systems more intuitive – but it also creates new challenges that traditional software doesn’t have.

As Dr. Blackman explained, attackers don’t necessarily have to break into an AI system the way they might traditional software. Instead, they may try to manipulate it through carefully crafted prompts that influence its behavior, bypass safeguards, or expose information it shouldn’t access. It’s a reminder that as AI becomes more capable, security has to evolve right alongside it.

“Do we need AI watching AI?”

– Nathan Macintosh

The Risks of Multi-Agent Systems

If one AI agent can make a mistake, imagine what happens when multiple AI agents start working together. While it may be more efficient for systems to be connected, it also creates more opportunities for failure.

If one agent makes a mistake, it can create a ripple effect. A small issue can become a much larger one if organizations don’t understand how those interactions work. This doesn’t mean multi-agent systems are inherently risky. It simply means they require the same level of planning and oversight that organizations would apply to any complex business process.

“I learned about agentic AI today and I’m already scared. Now you’re telling me AI agents talk to other AI agents?”

– Nathan Macintosh

Do You Know Who Your AI is Talking To?

If managing your own AI agents sounds challenging, consider what happens when they start interacting with someone else’s AI. You may know your own guardrails and policies, but external AI systems may be different. You may not know how they were trained, what they can access, and if they have the same safeguards in place.

Get Ready

Agentic AI is moving quickly, and the technology will keep evolving. The organizations that succeed may not necessarily be the ones that adopt AI first. They’ll be the ones that understand how to govern it, test it, and build trust around it.

One of the goals of Ready. Or Not. is to move beyond the hype and examine what responsible technology adoption actually looks like.

Dr. Blackman’s perspective is a reminder that successful AI adoption isn’t about choosing between innovation and caution. It’s about balancing both. That’s exactly the kind of conversation we’re excited to continue throughout our series.

Watch the full episode on Readiverse.

FAQs

Q: What is agentic AI?

A: Agentic AI refers to AI systems that can take actions, access tools, interact with applications, and complete multi-step tasks with varying levels of autonomy. Rather than simply generating responses, they can actively perform work across connected systems.

Q: Why does agentic AI introduce new risks?

A: Agentic AI often requires access to multiple systems, applications, and data sources. While that access increases usefulness, it can also expand the potential impact of mistakes, misuse, or security compromises.

Q: What are prompt attacks?

A: Prompt attacks involve using carefully crafted inputs to manipulate an AI system’s behavior, bypass safeguards, or expose information that should remain protected.

Q: Why is monitoring becoming more important?

A: As AI agents become more autonomous and connect to more systems, they are also becoming less predictable. Monitoring helps organizations identify unexpected behavior early and understand how AI systems are interacting with people, data, and other AI agents.

Q: What are multi-agent systems?

A: Multi-agent systems consist of multiple AI agents communicating and collaborating with one another to complete tasks. While they can improve efficiency, they can also introduce additional complexity that organizations must manage carefully.

Q: What’s the biggest takeaway from this episode?

A: AI risk isn’t just about what technology can do. It’s about understanding how systems behave when they interact with people, data, applications, and each other – and putting the right safeguards in place before problems arise.

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

For years, the working assumption in enterprise security was that a mature prevention stack could hold the line long enough for defenders to respond. Frontier AI is shaking that premise, as the latest models shrink the timeline for discovering and exploiting vulnerabilities from days or weeks down to almost real time.

Launched to assess the potential security risks posed by its own Mythos model, Anthropic’s Project Glasswing initiative has already grown to nearly 200 companies and surfaced approximately 10,000 critical or high-severity vulnerabilities. Meanwhile, OpenAI’s GPT-5.5 is showing comparable capabilities.

In a recent webinar, Commvault Chief Technology and AI Officer Pranay Ahlawat and Field CTO Vidya Shankaran joined me to explore the new timeline for vulnerability management, the rising importance of recovery validation, and how teams should be thinking about resilience today.

Register for the on-demand webinar.

Key takeaways

  • As frontier AI capability doubles on an accelerating schedule, advanced capabilities that help compress the time between vulnerability discovery and exploitation will reach adversaries within six to nine months.
  • Recovering an agentic AI system requires synchronizing data sources, agent configurations, and non-human identities simultaneously; restoring any single element in isolation can create gaps that surface only when something downstream breaks.
  • Backup and recovery solve different problems: Backup confirms that data exists somewhere safe, while recovery confirms that an organization can actually return to a clean, working state.
  • ResOps™ (resilience operations) frames recovery as a cross-functional discipline. It brings security, operations, and technology teams together around a shared definition of what clean actually means.
  • A four-step framework – defining a minimum viable company, isolating and testing crown jewel workloads, evaluating recovery for risk, and running full recovery drills – gives organizations a practical starting point.

Frontier AI Changes the Math on Vulnerability Management

The power of frontier AI now doubles approximately every four months, much faster than even a few years ago. Although Mythos-type models have yet to be released publicly, adversaries may soon gain open-source access to Mythos-like capabilities, including:

  • An effectively unlimited context window.
  • The ability to construct an attack harness by reverse-compiling code and building containers to find attack vectors.
  • Vulnerability chaining, which is the linking of individually minor weaknesses into a serious exploit.

This has serious implications. Two out of three organizations currently carry more than 100,000 unpatched vulnerabilities, with an average fix life of approximately 240 days. In the past, security teams have dismissed many vulnerabilities as too difficult for an average adversary to chain together, but automation has rendered that viewpoint nearly obsolete.

At the same time, the use of AI for code creation – roughly 41% of new code is now AI-generated, and GitHub saw a 25% year-over-year increase in commits – is expanding the vulnerability surface faster than remediation can address it. The ability to uncover new zero-day vulnerabilities at scale compounds the problem.

When the time from discovery to exploitation approaches zero, the window for defensive action effectively closes.

Sneak Peek: The Rapidly Changing Future of AI

This clip highlights a critical reality: Advanced AI capabilities rarely remain exclusive for long. As frontier AI innovations diffuse into broader ecosystems, organizations must prepare for a future where increasingly sophisticated offensive capabilities become more widely available.

The New Metric for Resilience: Mean Time to Clean Recovery

Backup and recovery solve fundamentally different problems. Backup only confirms that data has been copied somewhere safe, but it says nothing about whether the organization can actually return to a working state. And that’s where things can get complicated.

Two challenges often come between a successful backup and a successful recovery.

  1. Restoring a complex environment means recovering the application, virtual machines, network configuration, Active Directory, and transactional databases that support it, all in the correct sequence.
  2. You have to make sure that the data you’re restoring is free of malware or backdoors – something seven out of 10 organizations recovering from a cyber incident are currently unable to validate.

A recovery that meets its time target while reintroducing an active threat can be worse than no recovery at all.

To get clearer visibility into their resilience, organizations have begun using the mean time to clean recovery (MTCR) metric, which combines recovery time objective (RTO), the time required to validate that recovered data is actually clean, and a final human validation step before systems return to production. The recovery target for MTCR is the minimum viable company: the roughly 30% of an environment, sequenced by dependency, that has to come back online for the organization to keep functioning.

Cleanroom as a Testing Tool

Recovery testing, the final human validation step in MTCR, typically means standing up a separate environment from live production systems – a time-consuming task when every minute counts. While cleanrooms are sometimes seen as an element of backup, a cloud-based cleanroom can also play a proactive role in recovery by providing an isolated environment to orchestrate and test complex recoveries before they are restored to production.

The same isolated environment can also help serve as a forensic tool, letting teams stand up two versions of a backup side-by-side to better understand what changed during an incident. And because it’s cloud-native and consumption-based, organizations can avoid standing up dedicated infrastructure just to test recovery.

Four Steps to Operational Resilience

Commvault’s four-step framework for building measurable operational resilience builds on these ideas.

  • Step 1: Define the minimum viable company: A business-oriented view of what has to come back, in what sequence, and with what dependencies, for the organization to function again, rather than a flat inventory of databases and virtual machines.
  • Step 2: Make sure the systems supporting that minimum viable company sit in an air-gapped, immutable, network-segmented environment that can be spun up and down quickly. For crown jewel workloads, this should be tested on a 45-day cadence.
  • Step 3: Evaluate recovery for risk before declaring it complete, since reintroducing a backdoor or piece of malware during recovery defeats the purpose of the exercise and leaves little time for a second attempt.
  • Step 4: Treat recovery as more than a tabletop exercise. Perform recoveries with the same people and processes that would be involved in a real incident, alongside the automation behind them.

When AI Becomes the Recovery Problem

A large share of enterprises are already running AI systems in production, but only about 20% of them have actually tested their recoverability, leaving them vulnerable in the event of an incident. This is especially significant in light of the three ways AI changes resilience architecture.

First, AI expands the surface area that needs protection, from vector databases and model weights to agent configurations and the endpoints, such as Claude Cowork or Google Antigravity, where employees actually interact with agents.

It also introduces a fan-out problem, where a single update from an agent can cascade through a mesh of connected systems in ways that are far less predictable than a traditional three-tier application.

Finally, AI makes recovery itself more complex, since restoring an agentic system means synchronizing memory, state, transactional data, and non-human identities (NHIs) – the credentials and permissions assigned to AI agents rather than people – all at once.

The customers furthest along on agentic deployments have already made these systems part of their minimum viable company. At every stage of maturity, the emphasis is on restoring data sources, agent configurations, and supporting elements like weights and biases together, rather than as separate efforts, since misalignment between any of those pieces can introduce risk that a single point of recovery wouldn’t catch.

Taking Action on Post-Mythos Resilience

As a starting point to reduce risk from frontier AI, map your organization’s crown jewel systems and confirm that they sit in an air-gapped environment. With your minimum viable company defined, run cleanroom drills to establish a recoverability and MTCR baseline across tier-one workloads. This should be your anchor, board-level metric for resilience, showing clearly how quickly your business can resume essential operations following an incident.

Testing is critical for surfacing gaps in business, technology, and process understanding. Often, some of the biggest problems are organizational. ResOps™ (resilience operations), can address these.

A framework rather than a product, ResOps brings security, operations, and technology teams together around a shared view of what resilient design and recovery validation should look like. ResOps formalizes the growing industry recognition that cyber recovery is a cross-functional problem that requires stakeholders from across the business who each have a stake in the outcome.

In the post-Mythos era, that coordination is critical to both support ongoing readiness and enable a fast, effective response to an incident. Frontier AI makes a tested, well-defined clean recovery process a baseline requirement.

See the Full Webinar

Watch the full Resilience Over Panic session on demand to explore our four-step framework in more detail, including the requirements for agentic AI recovery.

Register here for the webinar.

FAQs

Q: What is mean time to clean recovery (MTCR)?

A: Mean time to clean recovery (MTCR) measures how long it takes an organization to return to a verified, clean operating state after an incident. It’s a broader measure than simply how long it takes to restore data. It combines the traditional recovery time objective (RTO) with the additional time needed to confirm recovered data is free of malware or backdoors, plus a final human validation step before systems return to production.

Organizations are increasingly treating MTCR, rather than recovery speed alone, as the board-level metric for resilience, since a fast recovery that reintroduces an active threat can cause more damage than a slower, verified one.

Q: How is MTCR different from RTO?

A: RTO measures how quickly systems and data can be restored after a disruption. MTCR includes RTO as one component, but adds the time needed to confirm that restored data is clean and the time spent on human validation before systems go back into production. In a cyber incident specifically, a system can meet its RTO and still fall short of true resilience if the restored environment is reinfected shortly afterward.

Q: What is a minimum viable company, and how is it different from a full disaster recovery plan?

A: A minimum viable company, sometimes called a minimum viable business, is the smaller, business-prioritized subset of systems, data, and dependencies an organization needs back online to keep functioning after an incident, rather than its entire IT estate.

A full disaster recovery plan typically aims to restore everything, in time; a minimum viable company definition forces an organization to decide in advance what truly has to come back first, and in what sequence, to avoid an operational shutdown.

Q: What’s the difference between a tabletop exercise and a live recovery drill?

A: A tabletop exercise is a paper-based walkthrough of an incident response plan, typically used to test decision-making and communication among stakeholders without actually executing any technical recovery steps.

A live recovery drill goes further by actually performing a recovery, using the real tools, automation, and people involved, to confirm the process works in practice, beyond what a paper exercise can show. Organizations that rely only on tabletop exercises may have a resilience plan that looks sound on review but hasn’t been tested against the operational details that tend to make real incidents take longer than expected.

Q: What are non-human identities (NHIs), and why do they complicate AI recovery?

A: NHIs are the credentials, permissions, and access rights assigned to software components, such as AI agents, rather than to individual people. As organizations deploy more agentic AI, the number of NHIs in an environment grows, and each one needs to be accounted for during a recovery alongside more familiar elements like databases and transactional systems.

Recovering an agentic AI system typically requires synchronizing NHIs with the rest of the AI stack, since restoring data or configurations without restoring the correct agent permissions can leave gaps that are difficult to detect until something breaks downstream.

Q: How should an organization get started with ResOps™ (resilience operations)?

A: ResOps is a cross-functional framework that brings security, operations, and technology teams together around a shared definition of resilient design, distinct from any single product.

Organizations can begin by identifying a small number of core applications and running an initial recovery test to establish a baseline MTCR, rather than trying to formalize the entire discipline at once. That early baseline gives security, operations, and governance teams a concrete reference point for tracking improvement. It also helps build the cross-team habits that ResOps depends on over time.

Michael Thelander is Senior Director of Product Marketing at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

At Commvault, caring is not just something we say. It is something we act on every day.

Over the years, we have been so proud to have partnered with TeenTech, a UK-based educational charity for students aged 11–19. Teams of up to three students design and build tech products that solve real-world problems, then present them to a panel of industry judges.

We recently had the honor of attending the TeenTech Awards in London, where students from across the UK showcased the kind of creativity and problem-solving that gives us real hope for the future.

What made the day so meaningful was watching our people show up for each other. Vaulters from across the UK have supported TeenTech throughout our partnership – from building educational games and reviewing dozens of student projects, to volunteering their time on the big finals day.

This kind of commitment brings together Vaulters from different parts of our business and creates new connections along the way.

The innovation on display at the TeenTech Awards this year was unmatched. Here are a few of the standout ideas from the finalists:

  • A path toward treating Parkinson’s disease. One team proposed an approach for supporting patients earlier in the disease’s progression and explained the science behind it with real clarity.
  • A safer way to get from A to B. Another team rebuilt a navigation app around a “safest route” option, prioritizing personal safety alongside speed and distance.
  • A smart bandage that watches wounds heal. One finalist team designed a bandage that produces a hydrogel to support recovery and pairs with an app to track healing progress.
  • A fencing panel built to cut emissions. A fourth team proposed attaching zeolite panels to farm fencing as a simple way to help reduce agricultural emissions.

TeenTech gives young people a runway into STEM careers they might never have considered. Continuing to invest in the next generation of innovators matters, and we’re honored that Commvault gets to play a part in this journey.

Martha Delehanty is Chief People Officer at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

For years, post-quantum cryptography (PQC) sat comfortably in the category of “important, but not urgent.”

Security leaders knew it was coming. Researchers talked about it. Standards bodies worked on it. Most organizations acknowledged that it would eventually require attention. But I would argue that the time to start preparing is now.

In this episode of STRIVE, I sat down with Sr. Director of Portfolio Marketing Michael Fasulo to discuss why the conversation around PQC is changing so quickly – and why the organizations that wait for certainty may find themselves running out of time.

Watch the full episode.

Key Takeaways

  • Harvest Now, Decrypt Later attacks mean sensitive data is already at risk, even if quantum capabilities aren’t stable or commercially viable yet.
  • Most organizations do not have a complete view of their cryptographic inventory, making discovery the first major hurdle.
  • PQC is just as much a technology challenge to solve for and as much as it is about risk prioritization.
  • The organizations that start preparing now will have more options to course correct on prioritizations than those forced to react later.

The Problem Isn’t the Technology

Most discussions about post-quantum cryptography start with technology.

  • How quickly is quantum computing advancing?
  • When will cryptographically-relevant quantum systems become practical?
  • Which algorithms are likely to survive long term?

Those are important questions. But they’re not the questions I would prioritize asking. Michael wrote a blog last year about PQC and we discussed today how several things have changed since then.

Over the past several years, estimates have consistently moved in one direction: what once felt distant now feels increasingly close. At the same time, standards are evolving; regulatory expectations are increasing, and organizations are beginning to recognize how much cryptographic debt they’ve accumulated over the decades.

The exact date of Q-Day may remain uncertain. The direction of travel is not.

The Risk Is Here And Now

One reason this conversation has become more urgent is the growing attention around Harvest Now, Decrypt Later attacks. The concept is straightforward: An adversary gains access to encrypted information today, stores it, and waits for future capabilities to make that information readable.

What’s important here is that the risk doesn’t begin when quantum computing arrives. The risk begins when even encrypted data is exfiltrated and stored.

For organizations protecting intellectual property, healthcare records, government information, or other sensitive long term retention data, that distinction changes everything.

Organizations need to know whether data being retained today will still matter when that future arrives.

For many,esp. the highly regulated industries and critical infrastructure, the answer is yes.

Sneak Peek: Why Crypto Agility Matters

Embed clip here: https://www.youtube.com/watch?v=A3YWU5rlmGA

In this clip, Michael explains why PQC isn’t a one-time fix or switch. The real goal is crypto agility – building the flexibility to adapt cryptographic algorithms as standards, and threats evolve. Because in cybersecurity, the challenge isn’t just preparing for what’s next. It’s being ready for what comes after that.

Discovery Is the Real Project

One misconception about PQC is that it’s primarily an encryption upgrade. In reality, most organizations haven’t reached the stage where replacement is the biggest concern.

They’re still trying to understand the scope of the problem. Cryptography exists everywhere.

  • Applications
  • Certificates
  • Cloud services
  • APIs
  • Code signing
  • Third-party platforms

Many organizations struggle with the creation of the cryptographic inventory or its scope. That makes discovery one of the most important – and often underestimated – parts of the journey.

And for many enterprises, that’s a much larger endeavor than expected.

The Supply Chain Challenge

Another reason PQC has become a priority is that no organization will navigate this transition alone. Modern enterprises depend on vendors, cloud providers, software partners, and countless third parties, all of whom use cryptography.

That means quantum readiness extends beyond internal systems. It becomes a question of ecosystem readiness.

  • Are suppliers preparing?
  • Are critical vendors planning migrations?
  • Are third-party platforms aligned with emerging standards?

These questions will increasingly become part of risk conversations, procurement discussions, and long-term technology planning. Because cryptography doesn’t stop at organizational boundaries. Neither does risk.

Why This Conversation Matters

The most important takeaway from this discussion is that post-quantum cryptography is no longer a future technology challenge.

It’s becoming a present-day resilience conversation.

Organizations don’t need to panic and they don’t need to overhaul every system overnight. But they do need to begin, to make the best use of the time at their disposal for prepartion.

The organizations that navigate this transition successfully won’t necessarily be the ones with the most sophisticated cryptography. They’ll be the ones that started building understanding before certainty arrived.

And that’s often how resilience works.

Watch the Full Episode

There is plenty more that Michael and I explore in the episode that I didn’t capture above. Be sure to watch now for insights to:

  • The biggest challenges organizations face when starting their PQC journey.
  • What leaders should prioritize today including some best practices.
  • Understanding MLKEM algorithms and crypto agility.
  • Infrastructure considerations for PQC.
  • How Commvault is preparing for this future.

FAQs

Q: What is post-quantum cryptography (PQC)?
A: PQC refers to cryptographic algorithms designed to help remain secure against attacks from future quantum computers.

Q: What is Harvest Now, Decrypt Later?
A: It’s a strategy where attackers collect encrypted data today with the intention of decrypting it later when more advanced computing capabilities become available.

Q: Why are organizations focusing on PQC now?
A: Because preparation takes years, and sensitive data collected today may still be valuable when quantum threats become practical.

Q: What is the biggest challenge organizations face?
A: Discovery. Most organizations do not have complete visibility into where cryptography is used across their environments.

Q: Do organizations need to replace all cryptography immediately?
A: No. Most experts recommend starting with inventory, discovery, and prioritization before planning broader migrations.

Q: What should leaders do first?
A: Identify long-lived sensitive data, understand cryptographic dependencies, and begin building a roadmap for future transition.

 

Vidya Shankaran is Field CTO at Commvault.

More related posts


Cyber Resilience

Read more about Cyber Resilience

How Does ResOps Drive the Next Evolution of Enterprise Resilience?

Resilience operations (ResOps) is an operational discipline that unifies security, IT infrastructure, and recovery to give organizations the ability to prove end-to-end recoverability.

Key Takeaways

ResOps shifts organizations from a reliance on passive tools and assumptions to adoption of a proactive operational discipline that proves recoverability across systems, teams, and processes.

  • ResOps is a practice and discipline that can be adopted, not a product that can be bought. It is a unified operational model that brings together people, process, and technology to address digital fragility and the existential risk facing modern organizations.
  • The rapid adoption of AI has accelerated data growth, increased system interdependencies, and introduced new risks across pipelines, identities, and models. This ecosystem needs an overarching model to achieve resilience.
  • 97% of organizations have had a security incident in the past 12 months, according to Microsoft’s 2026 Secure Access Report — split fairly evenly between malicious attacks and accidental errors.
  • Traditional metrics such as uptime and recovery time objective (RTO) fail to capture the complexities and risks of cyber recovery, where data integrity and system dependencies play a critical role.
  • Detection and containment alone are not sufficient: organizations must build recovery processes that helps restore clean, trusted, and fully functional data.
  • Increasing regulatory pressure has forced organizations to move beyond policy-based compliance toward demonstrable, evidence-based resilience.

Most enterprises have backup, disaster recovery, and security tools in place — yet few can prove the recoverability of critical services. Especially under real-world, active attack conditions. Commvault enables ResOps by connecting protection, detection, and recovery into a continuous operational model, helping organizations move from assumption-based resilience to evidence-based, measurable, and predictable recoverability.


Why do traditional B&R and disaster recovery solutions fall short?

Disruption is a constant threat in today’s hybrid, multi-cloud world. That’s why most businesses already have backup and disaster recovery in place. Many also invest heavily in cybersecurity tools designed to detect and respond to threats. On paper, it looks like organizations have already built a cyber resilience program.

In practice, however, this is rarely the case.

The challenge is not the lack of tools, but the increasing complexity of the environments they are expected to protect, combined with virility of new attacks and the fragmentation that exists within modern security architectures.

According to Microsoft’s recent Secure Access report, 97% of organizations have had a security incident in the past 12 months. These attacks are happening in enterprises that now operate across fragmented systems spanning clouds, applications, endpoints, and data platforms. At the same time, AI adoption is accelerating this complexity. With 88% of organizations using AI in at least one function, data is growing exponentially faster, the threats embedded in that data are stealthily increasing, dependencies have become harder to track, and recovery paths are no longer predictable.

Traditional backup and disaster recovery processes start when something breaks. These tools are also designed for stable, static systems: they confirm that data copies exist and recovery plans are documented, but don’t validate whether entire services, including all dependencies, can be restored under real-world conditions.

This creates a resilience gap, leading to real-world problems:

  • Data may be recoverable but not usable or trusted.
  • Systems may be restored but not fully functional.
  • Recovery plans may exist but fail under real-world conditions.

Resilience now requires more than isolated tools. It requires an operational model that continuously connects protection, detection, and recovery.

This is where ResOps changes the equation. It effectively unites data protection, detection, and recovery into one continuous and validated operational model.


What is ResOps, and why does it matter?

ResOps is an operational discipline designed to confirm that recovery is comprehensive and can be demonstrated on demand, with proof.

It brings together people, processes, and technology across security, IT, and infrastructure into a single operating model. By collectively planning and implementing critical services, resilient design, and continuous validation, organizations can better withstand disruption, recover within defined impact tolerances, and prove it with evidence.

The biggest advantage of a high-functioning ResOps practice is that it’s been structured directly to addressing enterprise fragility and existential risk. Some of the model’s key capabilities include:

  • Operationalizing the “safe recovery” process
  • Defining measurable service resilience indicators (SRIs) and evidence-based scoring
  • Assuming (and optimizing for) recovery under stress
  • Assuming total disruption and validating rebuild pathways
  • Continuously identifying and helping reduce resilience gaps as systems evolve
  • Relying on evidence from realistic tests
  • Spanning the entire enterprise
  • Managing the boundary between normal operations and crisis-state operations

The key difference is focus. Traditional approaches prioritize capability, ResOps prioritizes outcomes. It gives organizations the ability to demonstrate that critical services can be restored, not just that tools are in place.


Why does cyber resilience demand an operating discipline?

Adding more tools isn’t the answer for resilience. In fact, 40% of organizations say they have too many vendors.

Modern systems are tightly coupled and highly automated. Failures in one area can cascade across services, especially in environments with shared infrastructure and interdependent workloads.

Without a unifying operational model, teams must coordinate across disconnected tools and workflows during incidents – while the salvos are flying and communication is at its worst. This slows response and increases risk. IT teams and engineers are left figuring out a plethora of tools instead of actually focusing on what matters.

ResOps introduces structure and accountability. It defines ownership of recovery outcomes, establishes service-level expectations, and verifies that recovery processes are regularly tested.


How should organizations measure cyber resilience today?

Traditional metrics such as uptime and RTO do not reflect the realities of cyber recovery. They assume that systems can be restored quickly and cleanly, which is rarely the case in complex, interdependent ecosystems.

A new metric is required for true cyber recovery success: Mean Time to Clean Recovery (MTCR) MTCR addresses this need by precisely measuring how long it takes to restore verified, uncompromised and fully usable data. This metric is based on the belief that cyber recovery can only be complete when data integrity and trustworthiness have been restored. “Time to reastore,” without any context for safety or cleanliness or completeness, is wholly insufficient to provide confidence in addresses this by measuring how long it takes to restore verified, uncompromised data. This metric is based on the belief that cyber recovery must be measured by data integrity and trustworthiness. Only considering the restoration time is insufficient for the complete picture.

SRIs further this trust by measuring whether critical services can operate within defined tolerances during disruption. In totality, these metrics help allow organizations to move from assumption to evidence, identify gaps in recovery capabilities, and align resilience with business outcomes.


What does zero trust miss when it comes to recovery?

Zero trust is a cybersecurity paradigm that assumes no user or device is inherently trusted, that elevated permissions are policed, and that a breach has already occurred or is inevitable.

Zero Trust has done wonders in increasing our overall security posture across industry segments.

Where zero trust falls short is Tenet 3: an actual breach or security failure. Most organizations will nod in agreement but are not operationally prepared for these scenarios.

Organizations may detect and isolate threats quickly, yet still struggle to restore systems in a way that validates continuity and trust. Detection does not guarantee recoverability. This created an evident gap between response and actual recovery.

ResOps fills this gap by serving as the operational layer that extends the zero-trust model all the way through its “assume the breach” mandate and fulfilling its original promise. With ResOps enhancing zero trust through a practice of operational resilience, organizations are better prepared to respond to threats and recover from them effectively.



How are regulators redefining resilience expectations?

Regulatory expectations are rapidly shifting toward demonstrable resilience, especially with AI-generated, poorly tracked data. Governance frameworks now increasingly call for structured protection and oversight of AI systems and AI-generated data. Aspects such as transparency, traceability, human oversight, data quality controls, and lifecycle risk management are of paramount importance.

Frameworks such as NIS2 and the Digital Operational Resilience Act (DORA) require organizations to prove that they can withstand and recover from disruption.

This includes:

  • Defining acceptable levels of disruption
  • Testing recovery processes regularly
  • Providing evidence of recovery performance

These frameworks and regulations emphasize that compliance is no longer based on policies alone. It requires measurable outcomes.

ResOps support this shift by embedding validation and measurement into cross-functional operations and enabling teams to demonstrate resilience through continuous testing and reporting.

 

Conclusion: How businesses close the resilience gap with ResOps

The gap between perceived resilience and actual, seamless recoverability from disruptions is prominent. It’s visible in how often organizations struggle to restore operations despite having the right tools in place. As environments grow more complex and AI accelerates the pace of change, this gap can only widen. When resilience is treated as a set of disconnected capabilities rather than a cross-functional discipline, the expected “bad days” can be unrecoverable.

ResOps helps close this gap by shifting the focus from preparation to proof. It helps bring together protection, detection, and recovery into a continuous operational loop, so that recovery is not just planned, but validated under real-world conditions.

What’s more, approach transforms resilience from a reactive function into a measurable discipline. It helps teams gain clarity on ownership, visibility into dependencies, and confidence that critical services can be restored when it matters most.

By embracing ResOps, businesses enter a new era of evidence-driven resilience. Breaches and exploits are inevitable. But a ResOps approach can help organizations recover fast, safely, and completely.

 

Frequently Asked Questions

What is ResOps in cyber resilience?

ResOps is an operational discipline that unifies security, IT, and recovery teams to continuously validate and prove recoverability. It focuses on measurable outcomes, not just tools. Commvault Cloud supports the ResOps model by connecting anomaly detection, clean recovery, and Cleanroom validation into a single operational platform — enabling businesses to restore critical services reliably under real-world disruption

Why do traditional backup and disaster recovery models fail?

Traditional backup and disaster recovery focus on data availability and documented plans, but do not validate whether full services and dependencies can be restored — leaving gaps where data exists but systems are not functional or trusted. Commvault products addresses this with evidence-driven recovery capabilities including anomaly detection, Cleanroom Recovery, and Synthetic Recovery that validate clean restore points before production cutover.

How does ResOps improve cyber resilience?

ResOps improves resilience by connecting detection, protection, and recovery into a continuous closed-loop model. Commvault Cloud operationalizes this across five integrated functions: automated discovery and protection, continuous detection, clean recovery, continuous validation and improvement, and continuous compliant business — giving teams a single platform to execute the full ResOps discipline.

What metrics measure cyber resilience effectively?

Metrics like Mean Time to Clean Recovery (MTCR) and Service Resilience Indicators (SRIs) provide better insight than RTO alone — measuring how quickly organizations can restore trusted, fully functional systems. Commvault introduced MTCR as a cyber recovery metric, shifting the measurement conversation from speed to data integrity and verified service continuity.

How does ResOps extend zero trust?

Zero trust focuses on prevention and access control but does not address recovery after a breach. Commvault Cloud fills this gap by connecting threat detection with clean recovery workflows — helping organizations restore trusted systems after compromise and close the gap between detection and operational continuity. In this way, ResOps extends and enables true zero trust by operationalizing restoration.

Why is regulatory pressure increasing for resilience?

Regulations such as NIS2 and DORA now require organizations to demonstrate resilience through testing, measurement, and evidence — not just documented policies. Commvault supports this shift through ResOps-aligned capabilities including continuous validation, Cleanroom-based recovery testing, and MTCR measurement — providing the audit-ready evidence of recoverability that modern regulatory frameworks require.

Explore Related Resources

Analyst Report

GigaOm Minimum Viable Recovery Report

Define exactly what recovery performance your organization must achieve – and benchmark your readiness against industry standards.
Read the report about GigaOm Minimum Viable Recovery Report
On-Demand Webinar

AI Resilience and ResOps: SHIFT Keynote

Watch Commvault’s CEO introduce ResOps and demonstrate how AI-enabled automation transforms enterprise cyber recovery in real time.
Watch on-demand about AI Resilience and ResOps: SHIFT Keynote