Skip to content

Award recognition is a team sport at Commvault and when the recipient is a member of your team, the news is even sweeter, which is why I am proud to share that CRN®, a brand of The Channel Company, has named Kalesha Wiley, Partner Business Manager, to its 2021 list of Rising Female Stars. This list honors up-and-coming, talented women in the IT channel for whose contributions are shaping the future of the IT channel through their leadership, tireless dedication and innovative ideas.

Selected by the CRN editorial team, the 2nd annual Rising Female Stars list is made up of exceptional channel leadership candidates. Honorees are selected for their unique experience, expertise, impact on their partners and dedication to the IT channel. These women are playing key roles in helping their organizations maintain and grow their channel partner programs across a multitude of disciplines, including marketing, program management and partner engagement.

With over 12 years of channel management experience working with National, VAR, GSI, and Distributor partners, Kalesha is an integral part of our Channel Sales team. She is the Team Lead on building Commvault’s overall go-to-market strategy with CDW and for the last two years, has been responsible for the growth, engagement, and enablement of more than 3,000 CDW partner sellers across the U.S. and Canada.

“CRN’s 2021 Rising Female Stars list recognizes professionals displaying an unwavering commitment toward channel growth and excellence. These future leaders are driving tomorrow’s innovations for today’s organizations,” said Blaine Raddon, CEO of The Channel Company. “On behalf of The Channel Company, we congratulate all the honorees. What these women are accomplishing today will define the IT channel for many years to come.”

One of Kalesha’s shining moments came during a monumental occasion for Commvault – the launch of Metallic in October 2019. With CDW as a launch partner, Kalesha worked tirelessly leading up to the announcement, leveraging her dedication to Commvault’s business, attention to detail, and focused execution to identify growth opportunities at CDW and amplify Metallic’s portfolio of SaaS solutions.

Her success has not gone unnoticed and Kalesha is no stranger to accomplishments. In FY21, she was named, along with a group of her colleagues, Commvault’s Channel Team of the Year, and earned a much sought-after place in Commvault’s Infinity Club. Suffice it to say, Kalesha’s induction in CRN’s list of Rising Female Stars is self-explanatory.

To learn more about Kalesha and see the full 2021 list of Rising Female Stars, visit www.CRN.com/risingstars.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Why Do You Need an IT Business Continuity Plan?

It’s no secret that data and network infrastructure are at the heart of operations for modern businesses. An IT business continuity plan is crucial to keep an organization operating during a disaster event such as a cloud outage or a malicious cyber attack like ransomware. This is essentially a plan within the larger plan, as it accounts for all things IT-related, ranging from keeping servers online to recovering and restoring lost or stolen data. And during a potentially crippling disaster event, the speed at which you can recover and restore data makes all the difference.

How to Enable Rapid Data Recovery in an IT Business Continuity Plan

While all data is important to an organization, not all data is necessarily equal or mission-critical to maintaining business operations. When disaster recovery is underway, it’s important to be equipped with a way to identify and prioritize restoring specific data sets and workloads over others.

If your organization has migrated to the cloud, know that your recovery abilities ultimately depend on your choice of cloud backup platform.

Restoring whole data and workload instances via cloud backup can be time-consuming and may slow down the speed of recovery, potentially jeopardizing an organization’s Recovery Time Objective and Recovery Point Objective parameters and creating a break in business continuity. Rapid data recovery can be achieved with capabilities such as granular recovery, which lets you choose and prioritize specific data and instances for restoration while a full recovery commences, rather than waiting for all enterprise data to be restored, regardless of importance.

Achieve Rapid Restore with Clumio

Clumio’s industry-leading cloud backup-as-a-service provides enterprises with all the tools necessary to ensure rapid data restores during a disaster event. With capabilities such as granular recovery, flexible recovery, and global search, Clumio allows users to pinpoint specific mission-critical data and workloads to restore first, along with the ability to instantly restore from any regions that are unaffected by the outage or disaster.

Other features include:

  • Instant backups of AWS data across your entire organization
  • Air-gapped backup storage to provide protection from ransomware and other malicious attacks
  • Simplified data compliance with global policies
  • Optimized backups and insights into potential cost-savings

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Why Do You Need an IT Business Continuity Plan?

It’s no secret that data and network infrastructure are at the heart of operations for modern businesses. An IT business continuity plan is crucial to keep an organization operating during a disaster event such as a cloud outage or a malicious cyber attack like ransomware. This is essentially a plan within the larger plan, as it accounts for all things IT-related, ranging from keeping servers online to recovering and restoring lost or stolen data. And during a potentially crippling disaster event, the speed at which you can recover and restore data makes all the difference.

How to Enable Rapid Data Recovery in an IT Business Continuity Plan

While all data is important to an organization, not all data is necessarily equal or mission-critical to maintaining business operations. When disaster recovery is underway, it’s important to be equipped with a way to identify and prioritize restoring specific data sets and workloads over others.

If your organization has migrated to the cloud, know that your recovery abilities ultimately depend on your choice of cloud backup platform.

Restoring whole data and workload instances via cloud backup can be time-consuming and may slow down the speed of recovery, potentially jeopardizing an organization’s Recovery Time Objective and Recovery Point Objective parameters and creating a break in business continuity. Rapid data recovery can be achieved with capabilities such as granular recovery, which lets you choose and prioritize specific data and instances for restoration while a full recovery commences, rather than waiting for all enterprise data to be restored, regardless of importance.

Achieve Rapid Restore with Clumio

Clumio’s industry-leading cloud backup-as-a-service provides enterprises with the tools necessary for rapid data restores during a disaster event. With capabilities such as granular recovery, flexible recovery, and global search, Clumio allows users to pinpoint specific mission-critical data and workloads to restore first, along with the ability to instantly restore from any regions that are unaffected by the outage or disaster.

Other features include:

  • Instant backups of AWS data across your entire organization
  • Air-gapped backup storage to provide protection from ransomware and other malicious attacks
  • Simplified data compliance with global policies
  • Optimized backups and insights into potential cost-savings

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Ransomware attacks are becoming more frequent and sophisticated as time goes on, so it is important to know the actions to recovery. “70% of ransomware attacks involved the threat to leak exfiltrated data”.1

It is the worst-case scenario constantly re-defined. It costs companies hundreds of thousands of dollars to pay the ransom, typically. “The average ransomware payment is $154,108”.1

The recovery process is important because organizations want to focus on getting back to business. It is hard to understand the process unless you or your organization have experienced it. These steps will help you understand what ransomware recovery entails and how to approach it.

  1. Contact Customer support
  2. Update and deploy antivirus and ransomware protection software
  3. Recover the Commvault CommServe
  4. Recover Commvault MediaAgents
  5. Create a Client recovery priority list
  6. Initiate recoveries

The first step to ransomware recovery is contacting Commvault Customer Support. This will help determine the level of impact that the attack had and jointly establish a plan.

Step two is to update and deploy antivirus and ransomware software. This step is to prevent the re-spread of ransomware viruses.

Recovering the Commvault CommServe and disabling backup schedules is step three in the process. The company will also need to disable all backup plans and scheduled backups temporarily to keep further damage from happening.  

Step four is for recovering Commvault MediaAgents and access to libraries. It is crucial to make sure that the MediaAgents are accessible and functional.

The fifth step is the client recovery priority list. This is where your organization will generate a list of critical systems and applications and determine what is most important for getting back to business.

The final and sixth step is to initiate the recoveries. The organization must pay attention to the point-in-time to ensure it is pre-infection. This way, you are not recovering from a point-in-time that includes the ransomware files.    

It is important to emphasize starting your preparation today because every little bit will help. Within Commvault Command CenterTM, there are valuable tools and dashboards to understand your data and your data protection and recovery capabilities. A great resource is the Commvault Recovery Readiness Report to evaluate your RPO and RTO service levels.

These six steps will help you better prepare and recover from cyber-attacks that have become more sophisticated with time.

Sources

1 Coveware Quarterly Ransomware Report, Feb 1, 2021

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

When your company consistently receives broad ranging recognition of leadership – from the data center to the cloud – you know you are meeting your customers’ needs all along their digital transformation. That’s why I’m excited to share that we’re the proud recipients of two Gold Globee awards in this year’s 16th Annual IT World Awards – Commvault in the “Data Center Backup and Recovery” category and Metallic in the “Cloud Computing/SaaS category” – exemplifying the “The Power of And” that our portfolio brings to our customers!

For me, these awards highlight the trust that our customers place in using our technology leadership to solve their most complicated data management challenges. Just ask Arvest Bank, the oldest and largest bank in Arkansas, about Commvault’s data backup and protection. Josh Kimes, Network Systems Engineer at Arvest said, “The backup tools that I’ve administered in the past were definitely far behind the curve compared to Commvault. Other products that I’ve used don’t seem to innovate and update their software in order to support backups for new technologies nearly as quickly as Commvault does.” This is why, as a longtime Commvault customer, when Arvest looked to implement Microsoft Teams to drive its remote collaboration, Metallic SaaS was the clear choice to safeguard that data. It’s stories like this that show our true commitment to staying one step ahead of our customers’ needs.

Leading in both Disaster Recovery and SaaS data protection

This year’s IT World Awards are yet another perfect example of how we continue to lead the data protection industry by offering futureproof solutions. Open to all worldwide Information Technology and Cyber Security organizations and their end-users of products and services, the IT World Awards is one of eleven premier business awards programs and ranking lists organized by the Globee Awards, and is judged by more than 65 industry experts from around the world.

In the Data Center Backup and Recovery category, Commvault Disaster Recovery has bagged the Golden Globee for ensuring business continuity and verifying recoverability across our customers’ data center, cloud, and other environments, with streamlined, automated disaster recovery orchestration, flexible replication, and verified recovery readiness – support our customers are seeking now more than ever.

For example, to contend with the rise in ransomware attacks in the healthcare industry, Sang-seok Park, Department Head of Information Strategy at SAM Medical Center turned to Commvault to upgrade the facility’s backup infrastructure and prevent data loss. Park said, “Commvault is the only vendor we found that offers an all-in-one solution for backup and disaster recovery. Commvault gives us the confidence that we can respond immediately to unexpected events, such as a ransomware attack or data loss caused by user mistakes.”

And, in the Cloud Computing/ SaaS category, we have won the Golden Globee for our Metallic Backup as a Service (BaaS) portfolio. Since launching in October 2019, Metallic has seen strong growth – we are available in 24 countries and counting, with unmatched flexibility and breadth of coverage across workloads including VMs, endpoints, Office 365, Salesforce, and Microsoft Dynamics. Most recently, we launched Metallic Government Cloud with FedRAMP High In Process – In PMO Review – making Metallic the only comprehensive SaaS data protection solution to currently meet the highest confidentiality, integrity, and availability standards recognized by the U.S. government. It has certainly been a whirlwind and an exciting journey to be part of.

Leadership that comes at a time when our customers need it most

As we have seen, especially over the last year, disaster recovery and ransomware are on the rise, with cybersecurity one of the top priorities for organizations of all sizes. According to San Madan, co-President of Globee Awards, “The information technology industry continues to show its resilience. The tech sector is robust and innovative. And the pandemic has changed the way people live, work, shop, and socialize thereby accelerating demand for newer technologies and innovations everywhere.”

I am happy to say that with our portfolio of Intelligent Data Services, including Commvault Disaster Recovery and Metallic BaaS, our customers have options – simple, flexible, and scalable enterprise-grade solutions for quickly and reliably recovering data center and other workloads that have been locked or lost due to a disaster, whether on-prem or in the cloud. I am proud of the work we have done this year, and continue to do, in giving our customers and partners peace of mind.

To learn more about the winners of the 2021 IT World Awards, visit: https://globeeawards.com/it-world-awards/winners/

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

As I hope you’ve seen by now, today we announced Commvault has achieved “High Ready” status from the Federal Risk and Authorization Management Program (FedRAMP) for our Metallic Backup-as-a-Service (BaaS) portfolio and Metallic Cloud Storage Service (MCSS) offerings, and introduced our new Metallic Government Cloud offerings for federal agencies. As the only SaaS data protection solution to currently meet FedRAMP Class D (High) Certified In Process – In PMO Review standards – we are thrilled to be able to bring the gold standard in SaaS-delivered data protection to federal customers by meeting the most stringent protocols set forth by the US government.

I’m happy to say that the days of unending wait times in front of government offices to obtain services might be coming to an end. Government agencies responsible for regional, state, or local services are slowly following the pathways of private companies by focusing on migrating to the cloud to offer robust citizen services to “customers.”

Our FedRAMP Class D (High) Certified In Process – In PMO Review status is a testament to Commvault’s and Metallic’s sharp focus on ensuring the highest security for all of our customers at a time when risk is at an all-time high – and while ransomware protection and data recoverability is critical for any industry – there is heightened urgency for our federal customers. Commvault is dedicated to providing our government agencies with the industry’s leading data management technology in the face of critical threats against unwanted access and data loss due to bad actors. And with cyberattacks on the rise – ransomware attacks, for example, are predicted to happen every 11 seconds in 2021 – it’s clear that government agencies need top technology to help mitigate the risk.

Commvault has always made security a priority, and this is just further proof of our commitment to lead the way for our customers across all sectors. As governmental agencies continue to drive digital transformation, SaaS data protection must be an integral part of this strategy. We’re thrilled to be able to bring the best of data protection and the best of SaaS together – to help our government customers have peace of mind as they reap the benefits of cloud adoption.

So, what are those benefits? Let’s first talk procurement of technology solutions, as it’s a big problem within the Public Sector. Often bogged down by red tape and budget cycles, buying industry-leading data protection technologies to keep governmental data safe from loss, attack, or deletion is a thankless and difficult job. But there are ways to make the transition smoother.

Importance of investing in the right solution. The migration to cloud computing is definitely the logical next step for forward-looking government agencies. This also means that the deluge of critical data that is being stored on the cloud has brought renewed focus on high-level security. Network breaches, ransomware, and other cyberattacks threaten everything from government operations to national security.

It all begins with how you make the purchase decision. In the government sector, sometimes the hardest challenge to overcome is figuring out how to make an IT purchase. With well-defined requirements and budget dollars in hand, the government buyer still faces that last, sometimes elusive hurdle of how to buy a solution from a contract perspective.

Metallic has been designed to address this exact concern – making the buying process as easy and flexible as possible for any customer to effortlessly, confidently, and securely migrate to the cloud. Our Metallic solutions are secure, and offered as enterprise-grade data protection in an easy, light-touch, subscription-based model. Just like a phone contract, you can use a simple pay-as-you-go model to acquire tech that is tried, true, and compliant with the necessary security and governmental regulations, as demonstrated by our FedRAMP Class D (High) Certified In Process – In PMO Review status. You can even request a trial, use a government credit card for management, and easily cancel at any time.

A well-planned purchasing strategy is the first step for government agencies toward achieving their goals and providing secure operational efficiency. This is where partnering with a FedRAMP Class D (High) Certified In Process – In PMO Review technology provider is most helpful. Once that is complete, the next time someone asks  if your cloud infrastructure is secure, scalable, and reliable, you can say “YES!”

And with today’s announcement, that solution can be Metallic Office 365 Backup for Government Cloud, Commvault’s first FedRAMP Class D (High) Certified In Process – In PMO Review Ready SaaS data protection offering in support of federal, state, and local agencies running Office 365 GCC High environments on Azure Government Cloud. In the weeks and months to come, we intend to continue adding additional workloads, as well as Metallic Cloud Storage, delivering government customers a true portfolio of solutions that support their needs and meets stringent security standards.

Also in the coming weeks, we’ll be diving deeper into how Metallic SaaS can make your life easier, budget more stable, and your concerns over cloud data protection a thing of the past.

You can find more information about the ways in which Metallic and MCSS SaaS and cloud technologies are helping local, state, and regional governments provide secure operations and better citizen services by visiting the Metallic Government Cloud page on our website.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

For the Clumio Protect Backup Service, we use Amazon Elastic Kubernetes Service (EKS) to manage our Kubernetes clusters. The main benefit of using a managed Kubernetes is that you have tight integration with other services from your cloud provider. Specifically, when you create a new Kubernetes Service, a service controller, which is provided by AWS and installed in the cluster, it creates a new instance of Elastic Load Balancer (ELB) and configures it to forward traffic to the service. At the same time, that controller manages the whole life cycle of the corresponding load balancer: it provides a correct configuration for its health checks and keeps the load balancer target group up to date when you add or remove nodes from the cluster. Finally, it deletes the load balancer when you delete your Kubernetes Service from the cluster.

While it is very convenient to use Kubernetes Services backed by AWS load balancers, there are several considerations that we should be aware of.

The Clumio Cloud-Native Architecture

Our architecture is based on microservices, and each of our Kubernetes clusters has several dozens of these services. The number of services is especially noticeable for our development clusters, where we host as many isolated development environments as we can in a single cluster. In some development clusters, we have more than 300 services and counting. Needless to say, each AWS load balancer is not free and it would be unreasonable for us to have 300+ AWS load balancers just for a single development cluster. Another issue is the limit of load balancers each EKS cluster can support. This limit is related to the maximal number of the rules in EC2 Security Group. Specifically, our average EKS cluster could have no more than 60 classic load balancers. To solve that issue, we decided to use Kubernetes Ingress for most of our services. The Ingress mechanism gives us a way to share one ELB across multiple Services in an EKS cluster, which reduces resource utilization and cost.

Why Add Kubernetes Ingress

The creation of a new AWS load balancer typically takes some time. This delay is acceptable for most operations, however for certain changes, for example deploying multiple microservices at the same time, we wanted to minimize time required for their readiness. To address this use case, adding a new Kubernetes Ingress provides instant operation. Depending on the specific implementation, an Ingress controller needs to reload the new configuration similar to ingress Nginx controllers or apply the new configuration at runtime, similar to Envoy-based ingress controllers.

When working with services, you expect that each service has a DNS name, potentially an external one. With the ELB-per-service approach, you cannot create a DNS name until the ELB is created. With a single pre-allocated ELB for the ingress controller, it is possible to assign as many DNS aliases to that ELB in advance, so all our services become available as soon as we create Ingress definitions for them.

Some of our services expose REST API, but the vast majority of our services have gRPC endpoints. We needed an Ingress controller that supports both HTTPS and gRPC at the same time, and we wanted to terminate TLS on the Ingress controller. The latter was not a strict requirement, and we considered using Istio sidecars to terminate TLS directly in a microservice pod. However, we decided to use the Ingress controller to terminate TLS because it is simpler to manage and requires in general less overhead for the cluster. Another requirement we had is to be able to deploy several instances of the Ingress controller to the same cluster. A specific Ingress definition can have an annotation kubernetes.io/ingress.class to specify which ingress controller should be used.

We have tested several Ingress controllers and found it was surprisingly hard to find the one that works with all the requirements. Some controllers did not work correctly with gRPC, some did not support multiple controller instances in the same clusters. Finally, we found that NGINX Ingress controller works for us. We had to make only a small adjustment for its configuration to increase gRPC buffer size to make it work with our gRPC stack.

We constantly improve our infrastructure-level services to scale our infrastructure and optimize maintenance costs. Initially, we used a dedicated load balancer per service but very soon we hit the limit of load balancers per cluster. At that moment we updated our infrastructure to use hosted Ingress controllers for external connectivity for our services and we significantly reduced the number of AWS classic load balancers required for the product. Using AWS Application Load Balancer (ALB) was not an option at that moment, because ALB did not support gRPC. At the end of 2020, AWS announced that they have added support for end-to-end HTTP/2 and gRPC for Application Load Balancer. Now we can use the AWS Load Balancer controller, formerly known as “AWS ALB Ingress Controller”, which was donated to Kubernetes AWS Special Interest Group (SIG-AWS) to allow AWS and other SIG-AWS contributors to officially maintain the project. We are looking forward to using this Ingress controller for our infrastructure. Another focus of our interest is Kubernetes Gateway API, a new Kubernetes API that is in the process of development by Network Special Interest Group (SIG-Network). Compared to Ingress API, Gateway API exposes a more general API for proxying that can be used for more protocols than just HTTP, and models more infrastructure components to provide better deployment and management options for cluster operators. We are looking forward to trying future Kubernetes controllers implementing Gateway API.

Reducing Resource Utilization and Cost

The Kubernetes Ingress mechanism helps us to reduce resource utilization and cost. We are no longer constrained by EC2 and EKS limits with respect to the number of services deployed to a single managed Kubernetes cluster. Some of the open source Ingress controllers work with gRPC services out of the box but require additional verification if they work for a specific use case. Kubernetes community provides and constantly improves Kubernetes APIs, such as Ingress API or Gateway API, while commercial and open source vendors provide various implementations of such APIs. This allows choosing the right implementation for a specific use case and replacing implementations without major changes to the application level.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Ransomware attacks, malware, human error, and cloud outages are just a few of the threats that can instantly take an organization offline—thereby risking the integrity and availability of its data.

Disaster recovery is the collective response to such events. Part of this response includes the restoring of the data and applications needed to maintain business continuity. When planned and executed successfully, a disaster recovery plan can minimize or fully avoid downtime that would threaten permanent data loss, disabling internal processes, and the disruption of customers and end users.

During a disaster event and subsequent recovery, speed is of the utmost importance—just a few minutes can be the difference between an organization’s vital infrastructure going offline or remaining operational with little to no effect on processes and end users.

Key Requirements for Faster Disaster Recovery in the Cloud

With many of today’s organizations now hosting their applications and workloads in the cloud, most have also turned to cloud native backup solutions to protect their data—leaving legacy solutions like physical, on-premises backup in the past. If an incident occurs that leads to data being lost, corrupted, or compromised, the cloud backup solution can initiate data recovery and restore the most recent copy of the data from any location.

However, not all cloud backup solutions are the same in terms of features and capabilities. Using a cloud backup solution does not automatically guarantee the data will be safe, uncorrupted, or restorable at a speed that ensures business continuity.

Here is the truth: your organization’s disaster recovery abilities are only as good as the tools it uses. For a cloud backup solution to facilitate fast and effective IT disaster recovery, it must be able to:

  • Back up and store data efficiently
  • Ensure the security of the backups from threats like ransomware and malware by air-gapping them
  • Rapidly restore mission-critical data and workloads required for business continuity

You need a way to not only keep the backup data secured from threats, you also need a way to quickly restore the specific data required to keep your operations going rather than waiting on all the data to be restored. Here’s how Clumio addresses these needs directly.

Achieve Faster Disaster Recovery with Clumio

Developed natively in the cloud, Clumio is an industry-pioneering cloud backup-as-a-service platform that provides organizations with a wide range of innovative data backup, protection, and restore features.

Clumio delivers optimized cloud disaster recovery by creating instant data backups across your organization and storing the data in an encrypted, air-gapped environment outside of the primary account to safeguard it from being compromised by threats like ransomware. This ensures that you always have a valid backup copy to restore data from.

If data recovery is needed, Clumio utilizes granular, flexible file recovery features that quickly restores the specific mission-critical files and workloads, speeding up the disaster recovery process and ensuring you meet RTO (recovery time objective) to maintain business continuity.

Faster disaster recovery can be the difference between costly downtime and seamless business continuity. Schedule a demo today and learn how your business can get started with Clumio in under 15 minutes and lower your (RTO), without the need to install new infrastructure or software or conduct any pre-planning beforehand.

More Information on Disaster Recovery

Three Cloud Disaster Recovery Best Practices

Cloud-based disaster recovery is now the best choice for any entity that hosts its data and workloads in the cloud. Discover three best practices to ensure an optimal disaster recovery plan that fully leverages what the cloud offers.

Leveraging Cloud Backup in an IT Disaster Recovery Plan

A specific IT disaster recovery plan is essential for organizations wishing to ensure the viability and functionality of mission-critical IT infrastructure during a disaster event. Learn about the crucial role cloud backup plays in a robust IT disaster recovery plan.

Examining the Role of Cloud Backup in a Disaster Recovery Plan Template

Disaster recovery is indeed a complex process, which is why a disaster recovery plan template can help in the creation of a plan that doesn’t leave anything out. Find out why cloud backup should be at the heart of every disaster recovery plan—and the template used to create one.

Can a Disaster Recovery Plan Protect Against the Effects of Ransomware Attacks?

Ransomware is just one of many potential threats that can risk the integrity of an organization’s data at a moment’s notice, creating a domino effect that can result in costly downtime and disruption to both internal processes and end users.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

In 1996, Commvault became an independent, incorporated company, as a spin-off of AT&T Bell labs. A little over a year later, Bob Hammer and Al Bunte took a chance and joined that small company—Bob as Chairman and CEO, and Al as COO. They placed their bets on one primary premise: Data will continue to grow.

“Our thesis was, that if data keeps growing like crazy, this is going to be a good space,” Al said.

It turns out, they were right. They went on to build a company focused on delivering customers the best technology for their data needs, taking that company through IPO and building a loyal customer base over the past 25 years.

Today’s Commvault propels that vision. We give our customers the peace of mind that liberates them to do amazing things with data. We simplify and manage the complexity of our customers’ data, uncovering insights, accelerating their growth, and helping ensure the fundamental integrity of their business. With technology excellence at our core, we continue to lead the market with our Intelligent Data Services Platform.

Under the direction of CEO Sanjay Mirchandani, who joined the company in February 2019, Commvault has continued to transform to meet our customers’ growing and evolving data environments. We built an enterprise grade software as a service portfolio, Metallic, which is growing rapidly. In fact, in the recently announced fiscal year 2021, Metallic doubled its number of customers each quarter. We acquired software-defined storage leader, Hedvig, and most recently, delivered on the company’s best financial year ever in FY21. The market is taking notice—Commvault is here!

We’ve been at the forefront of innovation for our rich 25-year history and recognize that customers need flexibility and choice. Today, we deliver our Intelligent Data Services as software on-premises; in the cloud; as a managed service through partners; or as SaaS—a critical differentiator in the market. The opportunity for us to help our customers has never been greater.

We do all of this, driven by our core values—Connect, Inspire, Care and Deliver— and we provide the peace of mind that liberates people to do amazing things with data.

On this 25th anniversary, we want to say thank you to our entire community of trailblazers who have helped Commvault build the amazing company we are today. We could not have done any of this without you.

Explore our history:

Early days: Commvault founders Bob Hammer and Al Bunte.
  • Check out our 25-year anniversary video here.
In 2013 we broke ground on a new
company headquarters in Tinton Falls, NJ.
  • Enjoy stories from customers who have relied on Commvault for decades:

Norfolk Southern

State of Oregon

Olymp

University of Leicester

  • Our own Don Foster chats with Coca-Cola.
  • Hear from industry analysts Steve Duplessie and Christophe Bertrand, ESG, and Phil Goodwin IDC.

  • Check out Sanjay and team at Bloomberg on the day we announced the acquisition of Hedvig.
  • Learn how we celebrate our long time employees and embrace new ideas to power innovation, diversity and a culture of caring.

  • Speaking of caring, we achieve all of this by truly living our values each and every day. Hear how our employees live our values everyday.
  • In line with our values, environmental, social and corporate governance is important to us. Take a look at some of our efforts here.
  • On our 25-year anniversary, our diverse group of global employees, share our rally cry for our future, which is fueled by our incredible past.
  • Our own fearless leader, Sanjay Mirchandani talks about how we continue to invest in innovation to deliver the most robust portfolio to our customers, and ultimately, give them the peace of mind they need.

The future has never been brighter and the opportunity has never been greater. 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Understanding Amazon EC2

One analogy to understand Amazon EC2 is to think of it as a rental car service. Just like how you rent a car for a specific period, choose the size and type of car based on your needs, and return it after use, Amazon EC2 lets you lease servers as needed. It’s almost like paying for what you use, and nothing more.

Moreover, since Amazon EC2 is integrated with most AWS services, it provides developers with an extensive range of options for computing resources. The services include running big data processing jobs such as Hadoop clusters, launching scalable microservices with load balancers from Elastic Load Balancing (ELB), to setting up infrastructure-free databases using Amazon Aurora.

For instance, let’s say a company needs additional servers to handle traffic surge during holiday sales. Instead of investing in physical hardware that will remain unused throughout the rest of the year, this business can use Amazon EC2 to automatically launch servers during peak traffic times, ensuring that customers receive the best shopping experience.

Additionally, when you create an instance in Amazon EC2, you have complete control over it – meaning that you can manage its performance directly while simultaneously taking advantage of the Amazon Web Services ecosystem. This customized control allows developers flexibility in choosing their own security measures like disabling root access or automatically shutting down under-utilized instances.

To further emphasize user’s control over performance management on Amazon EC2 instances let me tell you an example; when Houseparty made headlines last spring as everyone’s go-to video-chat app during lockdown, the app’s servers did not hold up very well under high traffic. Their engineers had to adjust the number of instances they were using on Amazon EC2 and make other changes to infrastructure. This is just one example of how Amazon EC2 can provide users with complete control over their performance.

Now that we’ve established a basic understanding of what Amazon EC2 is all about, it’s time to dive into another critical aspect of the service: Virtual Computing Environments.

  • According to a 2020 survey by Flexera, Amazon Web Services (AWS) dominates the cloud computing market with a share of 67%, where Amazon EC2 plays an integral role.
  • A study by Synergy Research Group in 2021 found that AWS holds a 32% share in the public Infrastructure as a Service (IaaS) market segment, with Amazon EC2 being one of the core IaaS services offered by AWS.
  • In a 2018 study published by Stratoscale, it was reported that companies of all sizes, from startups to large enterprises, are using Amazon EC2 instances, with 77% choosing on-demand instances while the remaining opt for reserved instances or spot instances.

Virtual Computing Environments

One of the most intriguing advantages of Amazon EC2 is that it allows users to create and configure virtual computing environments similar to physical computers, but instead used virtually within the cloud. These virtual machines are called instances and use pre-configured applications and operating systems compatible with a vast majority of existing server-based applications making it user-friendly.

For example, your virtual computing environment could be Windows or Linux operating system and installed on any type of instance matching the required server resources for your application. You can also add additional volumes for storage needs, attach an elastic IP address for easy connectivity and set up security groups to manage incoming traffic rules.

These virtual machines offer users a range of performance-based options, including multiple instance types such as memory-optimized or CPU-optimized configurations that cater towards businesses’ workloads like data analytics or processing localized transactions. Users can choose precisely which resources they require while creating new instances, so they never have too much or too little capacity available in line with business needs.

However, let’s not forget that configuring these virtual computing environments comes with responsibility on users’ end. While Amazon Web Services provides ready-to-be-used templates from which you can start from scratch; it’s essential to keep them always updated as well as maintain application patch updates because having outdated software could cause security risks for your business operations.

This also reminds me of when you rent an apartment versus buying one. While renting comes with flexibility and the ability to move around easily, it does have its downsides like limited freedom on customization compared to if you own the place. Likewise, while using EC2 instances gives you complete control over performance management and scalability, you are still subject in some way to complying with Amazon’s updates on templates.

With virtual computing environments covered, it is now time to see how we can further leverage our EC2 instances through integrating them with other AWS services in the market.

Scalable and Flexible Resources

As businesses grow, their cloud computing needs tend to scale up too. Fortunately, Amazon EC2 provides a scalable service that can expand or contract computing capacity with ease. For instance, if you have an e-commerce site that experiences peak traffic during certain times of the day or year, you may need additional server capacity to handle the increased traffic volume. With Amazon EC2, you can quickly create new instances when needed and terminate them when you’re done. This level of scalability allows your business to adjust its resources based on real-time demand.

Imagine you are a small business owner who runs an online art store. During the holiday season, consumer demand for your unique artwork spikes. Your website’s current infrastructure is not enough to keep up with this increased demand, causing operational delays and lost revenue. By integrating Amazon EC2, you can easily launch a new server with higher capabilities to handle the extra web traffic during the holidays.

Amazon EC2 provides many flexible features that enable users to customize and configure their virtual servers according to their needs. Developers have a selection of multiple operating systems, software packages, CPU configurations, memory types, and storage options to choose from. Additionally, if new resources are required on short notice, users can quickly launch virtual servers in a matter of minutes using pre-configured templates.

However, some users might argue that scaling up quickly at times of excessive web traffic can become an expensive and inefficient process. Executing quick adjustments to virtual servers requires significant investment in hardware capabilities upfront. These introductions could go unused for long periods after the demand dies down. However, with Amazon EC2’s surface-level scalability feature, reducing computing power is always as easy as increasing it.

The flexibility offered by Amazon EC2 does not stop there. To learn more about Amazon’s advanced security features, including Amazon RDS, ECS, and CloudWatch, keep reading.

Integrating EC2 with AWS Services

One of the significant advantages of Amazon EC2 is its ability to integrate with other AWS services. This means that when you migrate to Amazon’s EC2 cloud computing service, you are gaining access to an array of powerful tools that can enhance your business operations. Here are three services that integrate seamlessly into Amazon EC2.

Think about using a shopping cart: it usually comes with a range of compartments and spaces specifically designed to hold different items for functionality convenience. Similarly, by integrating multiple services within the same platform, users can get more efficiency out of different tools necessary for various tasks without the need for constant system hopping.

Amazon Relational Database Service (Amazon RDS) works in partnership with Amazon EC2 to provide access to relational databases like SQL servers or Oracle Databases on the cloud. With RDS, users no longer have to worry about managing complex database infrastructures manually. Instead, they can focus their attention on their application development which creates value systems for their businesses.

Amazon Elastic Container Service (Amazon ECS) is another tool that simplifies running applications on a public cloud network. ECS enables developers to build high-performance containerized applications and run them on Amazon’s secure and robust infrastructure at scale.

Amazon CloudWatch is another integral component available for integration within EC2, providing users with comprehensive monitoring metrics for their applications and resources running within an AWS ecosystem.

For instance, let’s say that you have hosted an e-commerce website through Amazon EC2 hosted in the US West region and have experienced performance issues due to website traffic from around the world logging in at the same time. AWS offers extra resources such as Elastic Load Balancing services in different regions worldwide capable of directing traffic amongst different locations ensuring users enjoy fast navigation speeds from a local server.

However, although there are multiple tools available for seamless integration with Amazon EC2, users could argue that migrating to an unfamiliar cloud environment can lead to complications or high costs. While this could potentially be true, AWS offers multiple resources and highly reliable migration options for users new to the cloud environment, making the transition as seamless as possible.

Overall, it’s essential to consider how the changes and learnings we’ve discussed throughout this blog post can empower businesses of any size towards more efficient operations by utilizing Amazon EC2 services alongside other AWS tools.

Amazon RDS, ECS, and CloudWatch

Amazon EC2 is a powerful web service that allows users to access scalable and flexible computing resources in the cloud. But EC2 is not an isolated service; it can be integrated with a wide variety of other AWS services to create even more complex and powerful solutions.

One of these services is Amazon RDS (Relational Database Service), which provides managed database instances in the cloud. With RDS, you can select from various popular database engines like MySQL, PostgreSQL, Oracle, SQL Server, and MariaDB. RDS takes care of all the backend management tasks such as patching, backup, replication, scalability without user intervention. By integrating EC2 with RDS, you can create a multi-tier application environment where your applications on EC2 instances interact with databases on RDS instances. This integration creates a high-performance solution for scaling applications, ensuring reliable performance and resilience.

Another essential service that integrates well with Amazon EC2 is Amazon Elastic Container Service (ECS). ECS is an advanced container management service that makes it easy to run and scale Docker containers in the cloud securely. With ECS, you can launch and stop Docker-enabled applications running on clusters of EC2 instances. You manage your cluster using the ECS console or API if you want to automate infrastructure management using AWS CloudFormation templates. Thus by integrating ECS into your architecture on top of Amazon-EC2 containers instead of VMs become smaller and starts faster enabling higher speed deployment cycle.

CloudWatch is a monitoring service that helps in collecting logs and metrics across multiple AWS resources. It gives system-wide visibility into resource utilization across compute power but also for storage capacity for example volumes or S3 buckets as well as of network traffic. When you couple this with Amazon EC2 instances running applications accessing Amazon RDS databases through Amazon Elastic Load Balancing As you can see, integrating EC2 with other AWS services enables you to create even more powerful solutions suited to your organization’s needs. Amazon RDS, ECS, and CloudWatch are just some examples of the many services that can be used together with EC2 to create a robust cloud computing solution. But what about pricing?

Amazon EC2 Pricing Options

When it comes to cost structures available in Amazon EC2, customers have two primary choices: On-Demand Instances and Savings Plans.

On-Demand pricing is well-suited for users who require flexibility and do not want to enter into any long-term commitments. With on-demand instances, users pay only for the resources they use, by the hour or per-second billing without any pre-commitment. This model enables you to grow your infrastructure on an as-needed basis instantly.

For those willing to sign up for longer-term commitments/contracts, however, Savings Plans may offer better value. Savings Plans operate like buying reserved instances but without purchasing any specific instance type or sizing instead customer make a commitment for specific regions within their geographical area. And receive discounted rates according to the previous month’s resource usage.

Other factors impacting pricing configuration include availability zone and location, instance type (compute capacity), software licensing options, and more.

Think about an electric utility bill – most users know that if they leave the lights on overnight, electricity costs will be higher than if they turn them off completely when they leave a room. In a sense, On-Demand pricing could be interpreted like paying for every light bulb switched on and off throughout the day. Many customers will prefer to turn off certain ‘lights’ periodically but keep key ones running all night, purchase reserved hours in bulk in a predictable manner and price.

While cost is undoubtedly a critical factor to consider, users should not just choose AWS purely based on pricing alone. On-demand instances offer the benefit of flexibility and the capability of scaling according to customer needs. Since workloads are unpredictable, customers may prefer the dynamic allocation of resources offered by on-demand instances. However, users looking to keep their costs low may choose extra advanced options like Spot Instances or EC2 Reserved instances. Reserved Instances optimizes for consistency and predictability, making it an excellent choice for applications with stable usage patterns that can forecast upcoming traffic correctly.

Moreover, AWS services like Elastic Load Balancing (ELB) support both types of instance classes On-Demand and Reserved Instances, which can be auto-scaling as per requirements. It also provides Auto-Scaling functions to handle large-scale traffic bursts or excess demand traffic while minimizing costs. It is essential to analyze the workload and determine the most efficient instance class while balancing flexibility versus consistency.

Amazon EC2 pricing provides flexible models that can cater to any budget or business requirement, including On-Demand instances, saving plans with various payment schemes across regions. By evaluating your workload requirements and usage trends in detail, you can select the best mix that meets your organization’s required functionality.

On-Demand and Savings Plans

One of the most significant benefits of Amazon EC2 is its flexible pricing options that make it accessible to users with varying budgets and usage requirements. Two popular AWS pricing models are On-Demand Instances and Savings Plans.

On-Demand Instances are best suited for short-term workloads or computing needs that vary a lot, like testing and development environments. They have no upfront costs or long-term obligations, so users only pay for what they use. On-Demand pricing allows users to launch instances when needed and terminate them when the task is complete, minimizing costs.

Savings Plans, on the other hand, cater to users who run consistent workloads regularly. They provide up to 72% savings compared to On-Demand pricing and offer a way for users to save money while making a commitment to AWS usage. With Savings Plans, users commit to a certain amount of compute usage over one or three years in exchange for significantly lower hourly rates.

For instance, let’s assume an organization needs 2000 hours’ worth of t2.micro instances per year. It can opt for either On-Demand pricing ($0.0116 per hour) or a one-year savings plan commitment ($0.0031 per hour). If the company chose On-Demand pricing for the entire year, it would result in an annual cost of $23,200, while a one-year savings plan would reduce it down to $6,200.

While Savings Plans result in significant cost savings in the long term, their rigid commitments may not suit cloud environments with highly unpredictable needs or those that require scale-in/outsourcing frequently.

However, as we move toward more agile cloud structures that diversify IT resources across multiple providers simultaneously eliminating vendor lock-ins, committing to one provider’s services (including Saving Plans) for a few years may become less appealing.

Buying an AWS Savings Plan is akin to signing up for a gym membership. While it may seem like a smart investment, requiring the member to commit to a certain amount of usage, it can be difficult to follow through if the individual’s circumstances or needs change.

Now that we’ve explored the pricing model offered by Amazon EC2 let’s take a closer look at the security and reliability of the service.

  • Amazon EC2 offers flexible pricing options that cater to a range of budgets and usage requirements. On-Demand Instances are suitable for short-term workloads, while Savings Plans are ideal for users with consistent workloads. While Savings Plans provide significant cost savings over time, they come with rigid commitments that may not suit all cloud environments. It’s essential to consider the benefits and limitations of each pricing model before committing to a plan.

Security and Reliability in EC2

Security and reliability are critical factors for businesses operating on the cloud, with even minor disruptions or data breaches leading to significant financial and reputational damage. Amazon EC2 has several features that ensure user data remains private, secured, and accessible only to authorized parties.

AWS takes a shared responsibility approach when it comes to security. They operate, controls, maintains, and secures the infrastructure that runs their services while providing users with tools to help protect their data according to their specific requirements.

For instance, AWS Identity and Access Management (IAM) helps secure user credentials while Elastic Load Balancers distribute traffic across instances in different availability zones for higher fault tolerance.

Despite having vast resources at its disposal, AWS is never immune from security breaches. Organizations migrating or relying primarily on cloud services must continuously monitor developments on cloud-specific security threats.

To provide maximum transparency, AWS undergoes rigorous third-party certifications and reports as part of its compliance programs. Its audits include PCI DSS Level 1 Certification, SOC 1/2/3 reports, HIPAA Compliance, among others.

Amazon EC2 offers network-level protection via security groups that act as virtual firewalls controlling incoming and outgoing traffic of instances connected with them based on predefined rules.

Securing data on the cloud is like protecting valuable items in a high-security vault. It requires multiple security layers, integrated systems, and organization-wide commitment to attain maximum safety.

As you can see, Amazon EC2 provides flexible pricing options and ensures reliable infrastructure and security for its users. In the next section, we will look at AWS integrations with other services such as Amazon RDS, ECS, and CloudWatch.

Cloud Security and High Availability

When it comes to cloud computing, security and reliability are two of the most crucial concerns for businesses. Amazon EC2 takes these concerns seriously and offers a number of features designed to ensure that your data is always protected and accessible.

Cloud security at AWS is among the highest priorities, with ongoing investments in this area. The Nitro System, AWS’s new server architecture, was built using hardware and software dedicated to security, providing enhanced protection against potential threats. Additionally, the Nitro Hypervisor is optimized specifically for hosting workloads in the cloud, with a smaller attack surface than traditional hypervisors.

Amazon EC2 also offers granular controls over access to your resources through Identity and Access Management (IAM). Using IAM, you can manage individual users or groups of users and grant them access only to the resources they need to perform their job functions. Furthermore, EC2 supports network isolation through Virtual Private Cloud (VPC) that allows you to create a logically isolated portion of the AWS Cloud where you can launch resources in a virtual network that you define.

While EC2 provides a robust set of security tools and features, ultimately it is up to the user to ensure that their applications are secure and properly configured. Misconfiguration can be responsible for many security breaches in cloud environments, so it’s critical that users remain vigilant when setting up their infrastructure on Amazon EC2. It is also important in software development today to use DevSecOps practices such as Security by design and automated testing along with AWS security technologies.

Additionally, while EC2 offers high availability commitments for each Amazon EC2 Region, outages do still happen. While rare, being aware of this possibility should be factored into your planning process when considering any cloud computing service.

To help mitigate risk and protect against possible data loss or disruption in the event of an outage, EC2 offers the ability to store and synchronize data across multiple Availability Zones (AZs). This helps ensure that if one AZ experiences an outage, your data remains available in another region within minutes.

Think of it like a skydiver packing a backup parachute. While the likelihood of needing to deploy that backup is low, having it there provides peace of mind and a contingency plan in case of a failure with the main chute.

In conclusion, Amazon EC2 takes cloud security and reliability very seriously, investing heavily in the Nitro System and offering a range of tools to help ensure that your data remains accessible and secure. However, it’s important for users to remain mindful of the need for proper configuration and to consider contingencies for potential system outages. Ultimately, by properly utilizing the tools provided by Amazon EC2 and remaining aware of best practices for cloud computing, businesses can confidently migrate their infrastructure to the cloud while ensuring their applications’ security and high availability.

Answers to Frequently Asked Questions with Explanations

What are some alternatives to Amazon EC2 for cloud computing?

As the demand for cloud computing services continues to grow, many competitors have emerged offering alternatives to Amazon EC2. Some of the most popular alternatives include:

1. Microsoft Azure – with an estimated market share of 16% as of 2019, this cloud computing platform offers a wide range of services and is often considered the closest competitor to Amazon Web Services (AWS).

2. Google Cloud Platform – although it has a smaller market share compared to AWS and Azure, Google’s cloud computing platform has been rapidly growing with innovative features and competitive pricing.

3. IBM Cloud – this platform provides a wide range of services that cater to specific industries such as healthcare and finance.

4. Alibaba Cloud – catering mainly to China’s domestic market, Alibaba Cloud is quickly expanding its reach globally with extensive infrastructure and competitive pricing.

It is worth noting that while these alternative platforms may offer comparable services to Amazon EC2, each has its unique strengths and weaknesses depending on the user’s needs. Ultimately, the choice among these alternatives should be made based on factors such as cost, scalability, reliability, security, and support.

How secure is Amazon EC2?

When it comes to security, Amazon EC2 is highly secure. It uses a variety of techniques to protect the confidentiality, integrity, and availability of your resources. Let’s dig into some of the ways Amazon EC2 is designed to keep your data safe.

First, Amazon EC2 allows you to control access to your instances using an extensive set of security features, including security groups, network ACLs, and identity and access management (IAM). Combined with encryption options for data at rest and in transit, you can achieve a high level of security for your applications running in EC2.

Additionally, Amazon EC2 offers features like AWS Shield and AWS WAF that help protect against Distributed Denial of Service (DDoS) attacks and web application attacks. In fact, according to AWS’s 2021 Cloud Security Report, customers using AWS Shield saw a 37% reduction in DDoS attack frequency compared to those who did not use the service.

Furthermore, Amazon EC2 complies with several industry-recognized certifications and standards such as PCI DSS Level 1, HIPAA, ISO 27001, SOC 1/2/3, and more. This means that the infrastructure running EC2 has been audited by third-party organizations for compliance with strict security requirements.

Overall, based on the measures implemented by Amazon EC2 and its adherence to various compliance standards, it is safe to say that Amazon EC2 offers highly secure cloud computing services.

How does Amazon EC2 work?

Amazon Elastic Compute Cloud (EC2) is a web service that provides secure, resizable compute capacity in the cloud. Basically, EC2 allows you to rent virtual machines of different sizes and specifications according to your needs.

When you launch an instance using EC2, it creates a virtual server in the cloud that can be accessed from anywhere with an internet connection. Amazon EC2 instances are highly customizable and come with operating systems and application software pre-installed. Additionally, you can add more software packages according to your project requirements.

One of the major advantages of using Amazon EC2 is that you only pay for what you use. You can easily scale up or down your compute capacity based on demand without having to worry about physical infrastructure or maintenance costs. This is not only cost-effective but also ensures that you have the computing power instantly available whenever you need it.

Moreover, Amazon EC2 also provides several features such as auto-scaling, load balancing, and security groups, which ensure that your applications run smoothly and securely at all times.

In conclusion, Amazon EC2 works by providing virtual machines on-demand with custom specifications to meet user needs. It offers flexibility and scalability at low costs while maintaining high levels of reliability and security.

References:

– “What is Amazon EC2?” Amazon Web Services. https://aws.amazon.com/ec2/

– “Compute Instances – Amazon Elastic Compute Cloud (EC2).” AWS Documentation. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Instances.html

What are the benefits of using Amazon EC2 for businesses?

Amazon Elastic Compute Cloud (EC2) is a leading example of cloud computing, offering businesses the ability to access secure, scalable, and cost-efficient computer resources on demand. One of the significant advantages of using Amazon EC2 for businesses is the flexibility it provides in terms of computing resources. With EC2, companies can quickly expand or shrink their computing infrastructure to meet changing demands without worrying about infrastructure investments. This means that they only pay for what they use, which is far more cost-effective than traditional IT infrastructure.

Moreover, using Amazon EC2 ensures high availability and reliability since Amazon guarantees an uptime of 99.99%. AWS also has multiple data centers distributed across different locations around the globe, ensuring excellent latency performance and disaster recovery capabilities.

Another benefit of EC2 is that it allows businesses to focus on their core competencies rather than managing IT infrastructure. By leveraging AWS’s managed services such as Auto Scaling, Elastic Load Balancing, and Amazon RDS, businesses can automate many operational tasks and free up IT teams’ time for more strategic work.

Statistics show that using AWS has helped businesses cut down their costs significantly. A recent survey conducted by IDC revealed that organizations leveraging AWS saved an average of $1.6 million per year per application while increasing revenue by 44%. Additionally, AWS was ranked as the most widely-used cloud provider among internet retailers in North America in 2021, with over 50% market share according to Statista.

In conclusion, leveraging Amazon EC2 enables businesses to access a wide range of benefits such as cost-efficiency, flexibility, high availability and reliability, disaster recovery capabilities and freeing up IT resources for more critical tasks. Therefore, every business aiming to enhance its operational efficiency should consider utilizing Amazon EC2 for its computing infrastructure needs.

Can Amazon EC2 be used for data analytics and machine learning?

Absolutely! Amazon EC2 is one of the most popular cloud computing platforms used for data analytics and machine learning tasks. With a plethora of data storage and processing services offered through Amazon Web Services (AWS), EC2 instances can be easily integrated with a range of machine learning frameworks such as TensorFlow, PyTorch, and Scikit-learn.

In fact, according to a study conducted by Synergy Research Group in 2021, AWS holds a staggering 33% share of the global cloud infrastructure market, largely due to its wide range of offerings in artificial intelligence and machine learning domains.

Moreover, EC2 instances offer unmatched scalability and performance for handling large datasets, thanks to their ability to auto-scale on demand. This allows data scientists and engineers to quickly turn around experiments without having to worry about infrastructure management or bottlenecks.

So whether you’re training deep neural networks or performing complex statistical analysis on terabytes of data, Amazon EC2 remains an excellent choice for all your data analytics and machine learning needs.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

What happened?

We changed the name of the Hedvig product from the Hedvig Distributed Storage Platform™ to Commvault® Distributed Storage.

Please note that we no longer include the word ‘Platform’ in the description and there is no longer a ™ at the end of the name. The ® is after the word Commvault, like with the other products (e.g., Commvault® Backup & Recovery, Commvault® Disaster Recovery).

When did this happen?

The change happened on March 15, 2021, aligned to FR 11.23/Hedvig 4.3 release.

There was no formal press activity around this name change, we simply updated the Partner Portal and the core assets to reflect the name change.

Why did we do this?

We made this change to fully incorporate Hedvig into the Commvault master brand. It’s been ~18 months since the acquisition and we wanted to wait to change the name until after Hedvig technology had been fully integrated into the Commvault Grid portfolio. This integration initially happened with the appliance in July 2020 and then with the reference designs in November. These integrations not only significantly improved the product’s performance, resilience, and scalability, but they also served as a logical time to make the name change.

Are there any other changes happening along with this?

While the product capabilities are not changing, we’re tweaking how we position Commvault Distributed Storage. Up to this point, we have targeted four use cases across primary and secondary storage: virtualization and containers for primary storage, and backup and object storage for secondary storage.

Given the Hedvig technology integration with Commvault Grid and that Commvault Grid is our flagship product for backup, we will lead with Commvault Grid for the backup use case. This simplifies our story.

The other use cases remain unchanged. Moving forward, we will look to increase our mindshare for primary storage, and more specifically virtualization and containers storage, which will allow us to be more targeted in our messaging for personas like DevOps.

For additional information, please check out the Commvault Distributed Storage page on the partner portal or on commvault.com.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

HIPAA, PCI, the California Consumer Privacy Act (CCPA), and Europe’s Global Data Protection Regulation (GDPR) all pose their own challenges when it comes to regulatory compliance and data retention due to the complexity and variance across state and international lines. For example, there is a minimum six-year federal retention period for HIPAA-protected records, but state-level requirements range anywhere from five to ten years.

Regardless of the complexities (and seeming inconsistencies) with compliance regulations, the burden is always on the organization to meet them.

The Shared Responsibility Model of Regulatory Compliance

Most cloud providers—including AWS—operate with what’s known as a shared responsibility model. This means that while the cloud provider is responsible for complying with regulations regarding their infrastructure and platform, the entity using the cloud provider is on the hook for satisfying regulations related to how they use cloud services, host applications, and data storage.

This model also applies to security. The cloud provider is responsible for the security of the cloud (i.e., cloud service infrastructure), while the organization is responsible for security in the cloud (i.e., applications, software or utilities installed by the customer on the instances, access to the endpoints used to store and retrieve data, and management of data).

And that’s not all. The user also has to classify assets and use identity and access management (IAM) tools to apply any appropriate permissions and adhere to service-level agreements (SLAs) with customers.

Hidden Costs And Outdated Manual Compliance Methods

Inefficient methods of maintaining regulatory compliance can result in hidden costs that snowball over time and lead to an unsustainable amount of overhead—especially when using snapshots as a backup strategy. This approach creates the need to store several snapshots volumes, increasing storage costs incrementally as more time passes.

Some may opt for a manual policy for compliance management, which typically relies on multiple tools or manually-written scripts to create and maintain a set of policies. But this method can grow increasingly complex and burdensome to maintain. It also leaves ample room for human error, which may eventually derail an organization’s compliance and expose it to severe ramifications.

The Right Cloud Backup Can Remove the Complexity and Risks of Compliance

There’s certainly a lot at stake with compliance. If your organization experiences compliance failure for any reason—such as via cyber attack, like ransomware—you could be hit with fines, lose customer trust, and sustain long-term damage to your reputation.

Fortunately, maintaining compliance doesn’t have to be complex, even as data retention laws continue to change and evolve.

Clumio is a fully secure, cloud backup-as-a-service solution that delivers compliance-driven data retention via hands-off automation. By leveraging industry-leading innovation, the platform defines backup policies and monitors compliance in real-time across your organization’s entire AWS environment.

Clumio’s features include:

  • A simple interface that offers a single, cohesive view of all your AWS assets
  • The ability to automatically discover AWS accounts and index existing and future resources with the same uniform policies
  • Instant alerts when compliance is at risk
  • ISO 27001, ISO 27701, SOC 2 Type 2, HIPAA, and PCI DSS certifications
  • Air-gapped storage of backups outside of production environments, ensuring protection against threats such as ransomware and bad-actor attacks
  • Predictable cloud backup and data storage costs coupled with a Pay-As-You-Go consumption model that allows rollover credits

Remove the complexity and overspending that often comes with maintaining compliance for your organization. See for yourself why Clumio is the industry’s leading innovator for AWS cloud backup. Schedule a demo today to learn how your organization can be fully protected by Clumio in less than 15 minutes—without the need to install any new infrastructure or software.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

As we experienced this past year, it is nearly impossible to fully predict what challenges we might face. However, one thing at Commvault that has always been a constant is our sheer dedication to building intelligent data services that bring change in our customers and make them digitally ready to future-proof their business. For example, just take a look at Metallic – within a year and a half, we have launched a continuously growing SaaS portfolio of solutions in 24 countries and counting. As our customers’ needs change, so too do our offerings to best support them on their cloud journey. As The Walt Disney Company’s Bob Iger famously stated, “Innovate or die.” We truly follow this mantra and in fact, it is this exact vision that has already gained us strong industry-wide recognition for both Commvault and Metallic, only four months into 2021.

We kicked off the year with some big award wins for Commvault and Metallic, including features in the TrustRadius Best of Awards for Security, CRN’s Top 20 Coolest Cloud Storage Companies of 2021, DCIG TOP 5 Office 365 Online SaaS Backup Solutions, and CRN’s 2021 Channel Chiefs listing, where three of our Global Partner Organization leaders were honored for their contributions to the channel. We followed that up with recognition for our Backup and Recovery Solutions in IT Central Station’s Peer Award for 2021 and a five star rating in CRN’s Partner Program Guide, and now, I am proud to share our latest win as one of CRN’s Top 20 Coolest Data Management Companies of 2021 within the Storage 100 list.

Chosen by a panel of respected CRN editors, the companies included in the 2021 Storage 100 list were selected for their perseverance in pushing the boundaries of innovation through cutting-edge technology and strategic partnerships. The list itself is a valuable resource for solution providers looking to find vendors that can support them in a complex storage market with industry-leading storage offerings in areas such as software-defined storage, data protection, data management, and storage components.

The award is presented annually to companies by their own customers, based on their experience and satisfaction during the prior calendar year. Commvault’s recognition as one of the “Top 20 Coolest Data Management Companies of 2021” truly showcases our determination toward customer satisfaction.

Customer Satisfaction is Preeminent for our Business

Customer experience is arguably one of the most important topics in the IT landscape. In fact, across our 25+ years in business, there are two valuable lessons we have learned – “change is the only constant” and “to remain relevant, you must be customer-obsessed and partner-focused.” Our customers are more than buyers, they are our partners and our relationship is a team sport. Through our relentless focus on customer satisfaction, we’re architecting our foundation around building cutting-edge solutions that make virtualized infrastructures highly scalable, fast, and easy to manage in the best possible way.

Like our CEO Sanjay Mirchandani recently said, “Never has data been more valuable nor more vulnerable,” and as the shift to the cloud has become a prerequisite for organizations to sustain the constant change that fuels the data deluge and usage, there is major demand for data management like never before.

Customers are looking at partnering with a more versatile and durable technological partner that will enable them to scale without limits. For example, understanding this specific pain point, Commvault launched the latest generation of our on-prem technology last year, Commvault Grid, a fully integrated storage data management technology that optimizes scalability, flexibility and simplicity for all workloads, including containers, virtual machines, databases, and more. With built-in ransomware protection, Commvault Grid is the perfect solution that simplifies and accelerates hybrid cloud adoption.

Simply put, the combination of excellent products like Commvault Grid, team support, and terrific partner engagement have helped us achieve incredible results in what has been a very challenging year. We know though, that this is not the end, and there are miles ahead and more to achieve in providing the best intelligent data services to our customers.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Your disaster recovery plan ready for cloud, on-premises and hybrid data demands? The uncontrollable events of the past year have prompted many questions about disaster recovery. 

In fact, 89% of surveyed Commvault cloud data protection customers said that disaster recovery was a top priority through the global pandemic.1

As the global pandemic pushed organizations to shift rapidly to the cloud, teams worked quickly to ensure data was available to serve customers, protect employees, and keep companies running. Sometimes in the rush to the cloud, disaster recovery plans weren’t updated.

Huge ransomware attacks, natural disasters, and unexpected crises stretched disaster recovery plans like never before.

Now is the time to develop a disaster recovery plan that includes all of your data – cloud, on-premises and that hybrid data that may be moving between locations today or tomorrow.

What is disaster recovery?

Today disaster recovery can mean the ability to recover applications, databases, entire virtual machine environments or entire IT environments. It can be failing over one application, one manufacturing plant, or all of your IT operations in one country.

Disaster recovery can be to the cloud, from the cloud, across clouds, or across cloud regions. Cloud workloads can be recovered on-premises, on-premises workloads can be recovered from the cloud.

With rapidly changing business needs, it’s important to work with a software vendor that supports your cloud disaster recovery requirements – today and in the future.

Thinking through a comprehensive disaster recovery plan

There are several steps to developing a comprehensive disaster recovery plan. Some organizations choose to work with a solution provider, systems integrator, or other services partner to develop the disaster recovery plan. Other enterprises manage cloud disaster recovery internally, coordinating with line of business owners to support new DBaaS or SaaS applications as they are adopted. 

Commvault offers specialized consulting services to help customers establish and maintain a state of recovery readiness. Click here to learn more about Commvault recovery readiness services.

How can your organization save time and money with a comprehensive cloud disaster recovery strategy? 

Developing a cloud disaster recovery plan checklist

Ready to get started with a cloud disaster recovery plan?

First, think through the workloads that need to be included in the disaster recovery plan.  What workloads are currently on-premises, in the cloud, or at the edge? Where should those workloads be recovered?

Start with essentials – the cloud-based applications and databases that run your business. If you haven’t updated your disaster recovery plan in a year, think through the new cloud-based applications and databases that have been added to the organization.

Disaster Recovery Plan Updates Questions to Ask Examples
What line of business applications recently changed? Are there overlooked applications missing from the plan? • Marketing SaaS-based applications
• Customer service applications like chatbots
• A move from on-premises to SaaS-based CRM or ERP
Who has implemented databases-as-a service? What database-as-a-service implementations run critical data? • Azure Cosmos DB, Azure Database for MariaDB
• AWS Redshift, Amazon Aurora, Amazon Dynamo DB
• Google Cloud SQL for MySQL, Google Cloud SQL for PostgreSQL

Now, consider your cloud storage environment, on-premises storage, and hybrid plan. For many organizations, today’s data estate is spread across on-premises, edge, private cloud, and public cloud locations.

With 76% of organizations adopting multi-cloud strategies (ESG, 2019), cloud-based disaster recovery is more important than ever. With these emergencies, time is critical, so automation, flexibility and scalability are big requirements.

What are the locations you might choose for cloud disaster recovery?

Hybrid – on- premises and multi-cloud:

Prepare for today’s cloud environment – and the technologies you’ll need tomorrow. Commvault supports more than 40 cloud storage options and multiple hypervisors. See the full list of supported technologies.

Why multi-cloud or hybrid cloud works for disaster recovery

As we saw in recent emergencies, having a geographically diverse team that can failover essential applications and databases is important.

In the February 2021 Texas ice storm and power outage, some bank customers were unable to access their online banking application. The bank and the infrastructure for the application were both based in locations with no power. Without their app, Texas-based customers couldn’t pay bills or use their debit card for essentials like food or transportation. Even customers outside the state were unable to use the online banking application.  Customer satisfaction was an issue with vocal customers using social media to voice their unhappiness.

In March 2021, the OHV cloud data center fire in France highlighted the need for multi-region or multi-cloud disaster recovery strategies. The fire destroyed one of the Strasbourg data centers, damaged another and caused two additional data centers to be shut down as a precautionary measure. Business and government organizations lost access to data, email, and applications for multiple days. Many reported complete data loss.

Many organizations are opting for cloud-based services that can be moved to another cloud or another cloud region. On-premises or edge applications could be failed over to public cloud – or public cloud regions in other geographic zones.

Disaster Recovery Plan Updates Questions to Ask Examples
Include options for moving data to, from, across and between clouds When does data need to move from one cloud location – or one cloud vendor – to another? How expensive will it be to recover data? Recover data and workloads across hypervisors and clouds
• Microsoft Azure
• AWS
• Google Cloud
Platform
Ensure edge devices have a backup Do we have a backup for data on hybrid cloud or edge devices? • Microsoft Azure Stack and Azure Stack HCI
• AWS Outposts

Be sure to consider cloud disaster recovery RTO and RPO

Disaster recovery planning includes thinking ahead for recovery exercises. Be sure to test your recovery time objectives (RTO) and recovery point objectives (RPO). Can you prove that you can recover critical services in the required timeframes?

Commvault customers are working with multiple RTO and RPO goals for virtualized workloads, applications, databases, file systems and more. Flexibility to manage RTO and RPO by multiple factors means scalable, custom disaster recovery options for changing business needs.

What’s next for cloud disaster recovery?

2021 has already started as a mixed year. On one hand, we already see the need to pay attention to natural disasters, accidents, and human caused data emergencies like cyberattacks.  On the other hand, organizations that were resilient through 2020 have accelerated their digital transformation initiatives. 

With digital transformation rapidly changing everything, more enterprises are looking at cloud disaster recovery options.

Consider starting with a 2-minute demo video of Commvault cloud disaster recovery. See how orchestration, automation and verifiable recoverability work across on-premises and cloud environments.

https://play.vidyard.com/yFCP4XA5m1essCJFZ8bGwe
Commvault offers an easy-to-use disaster recovery software solution with orchestration, automation and verifiable recoverability for business continuity across on-premises and cloud environments.

Commvault disaster recovery products

Reference
TechValidate, October 2020

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

With every step echoing, you realize this isn’t just a vault; it’s HIPAA-compliant data backup, offering rock-solid security to the crown jewels of healthcare providers — patient data. Now envision that without the need for physical keys or elaborate codes, this vault is as virtual as the air we breathe but sturdy as steel. Welcome to the frontier of our discussion today: HIPAA compliant backup solutions that ensure not just the protection of sensitive health information but also the safety and trust of patients.

Just like a compass shows north, let’s point straight towards a less discussed yet vital aspect of healthcare tech – HIPAA Compliant Backup Solutions. Remember, one small lapse in securing data could lead to a catastrophic landslide in public trust and hefty penalties. So buckle up as we illuminate your path towards safer, more secure healthcare management!

HIPAA compliant backup refers to a data backup solution that meets the rigorous requirements of the Health Insurance Portability and Accountability Act (HIPAA), which mandates strict security and privacy standards for healthcare organizations. It is important because it ensures protection and confidentiality of electronic protected health information (ePHI) in the event of a disaster or emergency, as well as compliance with federal regulations. A HIPAA-compliant backup solution must include encryption, regular testing and revision of contingency plans, secure transmission protocols, and signed Business Associate Agreements with cloud backup vendors to ensure the highest levels of data security.

Understanding HIPAA Compliance

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that sets national standards for protecting sensitive patient health information. Covered entities like healthcare providers, insurance companies, and their business associates are required to comply with the regulations to ensure the confidentiality, integrity, and availability of protected health information (PHI).

One analogy that can be used to understand HIPAA compliance is a lockbox. Just as a lockbox secures sensitive documents and valuables, HIPAA compliance measures are put in place to secure patients’ medical information. This includes physical, administrative, and technical safeguards such as monitoring and controlling access to PHI, encrypting electronic devices containing PHI, conducting risk assessments, and providing training for workforce members.

To illustrate why HIPAA compliance is important, consider a scenario where a healthcare provider’s unencrypted laptop containing patient data was stolen. If the data was not properly secured or backed up, it could be lost forever or fall into the wrong hands. This could result in serious consequences for both the provider and their patients, ranging from legal penalties to reputational damage.

Non-compliance with HIPAA regulations can have severe financial and legal implications. Healthcare providers who violate patient privacy laws may face civil or criminal penalties imposed by the Office for Civil Rights (OCR), which can impose fines of up to $1.5 million per violation category during an investigation.

With that in mind, let’s take a closer look at critical requirements and regulations mandated by HIPAA.

Critical Requirements and Regulations

HIPAA compliance requires covered entities and their business associates to adhere to specific rules regarding the collection, use, disclosure, storage, and disposal of PHI.

One of the most important components of HIPAA compliance is maintaining the confidentiality of PHI. This means that healthcare organizations must restrict access to PHI on a need-to-know basis and implement secure access controls to protect against unauthorized access.

Another critical HIPAA requirement is data backup and disaster recovery planning. Covered entities must have a data backup plan in place that enables them to maintain retrievable exact copies of electronic PHI, ensuring that data can be recovered in the event of a disaster or cyberattack.

In addition to these measures, covered entities are required to conduct regular risk analyses to identify vulnerabilities and potential threats to PHI. Based on the results of the analysis, they must implement appropriate safeguards to protect against those risks.

Some healthcare organizations may argue that HIPAA compliance places an undue burden on their operations or limits their ability to use patient data for research purposes. However, protecting patient privacy and security should always be given priority over business interests. Moreover, HIPAA mandates only minimally necessary uses or disclosures of PHI for treatment, payment, and healthcare operations.

Now that we have gained a deeper understanding of HIPAA compliance and its critical requirements and regulations, let’s explore how organizations can construct a HIPAA-compliant backup strategy.

Constructing a HIPAA-Compliant Backup Strategy

In the healthcare industry, data breaches are not uncommon. Encrypting and protecting sensitive patient information is essential for every organization dealing with Protected Health Information (PHI). While HIPAA compliance regulations are in place, many organizations still suffer from data breaches or loss of critical health data due to inappropriate backup strategies.

To prevent such risks, healthcare organizations must create a well-constructed HIPAA-compliant backup strategy. Such a plan should not only ensure the availability of protected health information but also ensure that PHI complies with all current security standards and regulations.

A hospital had their entire network knocked offline for 24 hours due to ransomware. The hospital staff relied on paper charts to keep track of patient care while their IT team struggled to recover data. The IT team restored the backups after paying an enormous amount of money to hackers. As a result, many patients incurred severe health consequences as their care was delayed or compromised during those 24 hours.

To avoid such scenarios, healthcare organizations must invest in a robust backup and recovery plan that aligns with HIPAA compliance. This requires thoughtful consideration of essential components and considerations for such a plan.

First and foremost, any HIPAA-compliant backup strategy must have reliable and secure encryption methods along with sophisticated access controls to protect sensitive health information effectively.

Secondly, it is vital to develop policies around backup frequency, storage location, and system restoration processes. This may involve the use of redundant backup regimes or various types of backup technology solutions that will mitigate risk in case of failed hardware.

Thirdly, developing a proper incident response plan is crucial for responding quickly when unforeseen events like ransomware attacks occur.

Fourthly, it is highly advisable to test the entire backup process regularly. This includes running tests for both automation and manual steps within the backup and recovery processes. It is best to make testing an imperative part of your strategy so that you can catch any vulnerabilities before they impact the organization.

Each component mentioned above is critical for developing a comprehensive HIPAA-compliant backup plan. However, to ensure an effective backup system, every healthcare organization must also consider several fundamental considerations.

  • The healthcare industry must prioritize the development of a robust HIPAA-compliant backup strategy to prevent data breaches or loss of critical health data. This includes reliable encryption methods, policies around backup frequency and storage location, developing an incident response plan, and regular testing of the backup process. By implementing such a plan, organizations can ensure patient care is not compromised or delayed during unforeseen events and align with all current security standards and regulations.

Essential Components and Considerations

Developing appropriate components for a HIPAA-compliant backup plan requires more than simply implementing encryption and following standard regulations. Here are additional essential considerations:

Think of backup solutions as a weapon in your arsenal, a firing squad if you will. A successful outcome requires several steady hands aiming at precisely the same target. Each hand must perform their role flawlessly, from executing proper data backups to ensuring safe storage – only then can the final outcome be successful.

To begin with, identifying all necessary backups and disaster recovery requirements before selecting a solution is crucial. Backup frequency, security protocols, and access control measures are core considerations that need proper analysis during this step.

Secondly, choosing between hardware-based or virtual-based servers is another key consideration for a HIPAA-compliant backup system. While both are HIPAA compliant options, some healthcare organizations might find that their unique IT infrastructure makes one solution more suitable than the other.

Thirdly, selecting the right vendor is fundamental while making decisions around technology and services required for secure backups. Vendors should be HIPAA compliant, have experience dealing with PHI protection strategies, be able to help customers define their backup needs thoroughly and identify potential gaps.

Fourthly, accessibility is another critical area when developing a strong backup strategy for PHI data. Cloud-based backup solutions offer numerous benefits over traditional off-site storage methods. By allowing authorized personnel easy access to encrypted data at any time from anywhere in the world through secure channels such SSL VPN connections or proxy services or similar technologies-based solutions like Zero Trust Network Access (ZTNA).

A common debate regarding HIPAA-compliant backup strategies is around data retention. While it is true that maintaining older backups can be costly and require more storage, doing so can be beneficial if something goes wrong, and the healthcare organization needs to refer back to earlier versions of their data. Conversely, there is no clear consensus on how long backups should be kept. The best solution here is customizing the retention period based on your specific industry regulations or legal requirements.

With continuously evolving technology and cloud advancements, it’s a smart move for healthcare organizations to get the support they need from trustworthy vendors and IT teams who can provide them with exclusive expertise of Backup for HIPPA Compliance.

Appropriate Backup Solutions for HIPAA Compliance

When it comes to backup solutions for HIPAA compliance, there are several options available in the market. However, not all backup solutions are created equal, and some may not meet the stringent requirements set by HIPAA. It is essential to find a solution that is both efficient and compliant with all relevant regulations.

One of the best backup solutions for HIPAA compliance is cloud-based backup. Cloud-based backup is a simple, secure way to store and protect medical data. When choosing a cloud-based backup solution for your organization, it is critical to ensure that the provider meets all necessary regulatory requirements.

Another option for backup solutions is local backups. Local backups refer to backing up data on servers located within an organization’s premises. Local backups can be cheaper than cloud-based backups, but they come with their limitations. Businesses must have adequate systems in place to maintain the integrity and security of their local backups.

For businesses that require more control over their backups, hybrid backups are another suitable option. Hybrid backups allow businesses to combine both cloud and local backups, resulting in more robust protection against any disasters or data breaches.

It is essential to note that not all backup solutions will meet all requirements mandated by HIPAA regulations but finding one that supports encryption of files will strengthen your overall data security. Moreover, as part of HIPAA regulations, companies must get a signed Business Associate Agreement with their cloud back vendor.

To comply fully with HIPAA standards surrounding data handling and storage, vendors like MSP360 Backup have been developed explicitly for healthcare providers or managed service providers (MSPs) dealing with health information’s storage and protection. The software makes sure that patient information transmission complies with HIPAA regulations, meeting the requirements for encryption of electronic protected health information (ePHI).

On-premises inventories are frequently underutilized because of the expense and hassle involved in maintaining them. Unfortunately, local storage solutions may cause security issues owing to practices such as making backups in unprotected locales or refraining from encrypting files appropriately.

While cloud-based backup solutions are an increasingly popular option for medical institutions, on-premises backups still have their place in HIPAA compliance. Medical organizations receive the added benefit of being able to verify that backup procedures are safe and manageable when they occur locally, rather than relying on third-party support. With local backups, businesses can keep track of who maintains access to sensitive data from within the organization.

  • Surveys have shown that around 60% of healthcare organizations have transitioned to using HIPAA compliant cloud backup solutions as an integral part of their data management strategy by 2023.
  • A report by the Office for Civil Rights (OCR) in 2021 shows that there has been a 22% increase in investigations related to non-compliance with HIPAA backup requirements, emphasizing the increasing importance of secure and compliant data backup procedures.
  • According to research firm Markets and Markets, the market for global healthcare cloud computing, including HIPAA-compliant cloud backup services is expected to grow at a CAGR of approximately 17.2% from 2020 to 2025, reflecting an increased demand for such services by healthcare providers.

Preferred Cloud-Based Options

Cloud-based backup is becoming a popular choice for healthcare providers to store patient information without investing heavily in infrastructure or personnel. It also enables quick data recovery and exceptional scalability. When it comes to selecting the best cloud-based backup solution, you must look for several specific features.

One crucial aspect of an appropriate cloud-based backup is that it should be encrypted. All stored information should have secure encryption mechanisms such that only authorized parties with an encryption key can access it securely. Some standards include AES-256 encryption as well as end-to-end SSL/TLS encryption across all data transfer points.

A robust orchestration system is another essential feature. A good backup solution should have a comprehensive dashboard suite capable of streamlining administrative processes such as scheduling backups, define retention policies and implement restores effortlessly.

Additionally, Choose a cloud vendor with adequate transparency controls that provides actionable insights into your organization’s ePHI and meets strict regulations such as HIPAA compliance. The storage provider needs to be reliable and rigorous enough to prevent other clients from overburdening their servers.

Investing in HIPAA compliant backup solutions is like building a fortress around your institution’s critical data against cyber-threats analogous to locking up your valuables inside a safe under lock and key—much like a secure backup solution. Cloud-based backup options give the additional benefit of creating a copy of the sensitive data that is easily accessible in case of data loss or other emergencies.

Having understood what HIPAA compliance entails and various backup solution choices available, it is time to look at some common pitfalls that healthcare providers may overlook when implementing their HIPAA-compliant backup strategies.

Avoiding Common HIPAA Backup Mistakes

When it comes to protecting patients’ sensitive information, it’s important to take every measure possible. That’s why it’s crucial to avoid making common backup mistakes that could lead to breaches and other compliance issues. Here are some of the most common HIPAA backup mistakes and how to avoid them.

Using Unsecured Devices for Backup

One of the biggest HIPAA backup mistakes is using unprotected devices to back up data. This includes using personal phones, laptops or tablets without appropriate security measures in place. These devices often lack encryption, enabling unauthorized individuals to access sensitive data. A better solution is to use a dedicated and secure backup device with robust encryption methods.

Failing to Test Backups Regularly

Another mistake that healthcare organizations make is failing to test their backups regularly. Some organizations assume that their backups are functioning as intended, only discovering otherwise when disaster strikes. Regular testing can identify any issues and ensure that everything is working as intended. Testing should also include a restoration process to check whether recovered files match their original state.

Unclear Access Control Methods

Another common error is maintaining unclear access control methods. This essentially means that there aren’t clear guidelines for who has permission to access certain medical information, including backup files. Organizations need to take a proactive approach by setting up strong authentication mechanisms and restricting access privileges based on job roles and responsibilities.

Inadequate Training of Staff Members

Training staff members on best practices in regards to data security and regular backups is essential, but oftentimes overlooked by organizations. Employees must understand the risks involved with HIPAA compliance mistakes, especially with regard to backups. It can be helpful to provide examples of successful attacks on healthcare systems in recent times, vividly driving home the severity of shortcomings in HIPAA compliance.

Not Keeping Business Associate Agreements Up-to-Date

As we mentioned earlier in this article, HIPAA regulations stipulate that companies must have a signed Business Associate Agreement with their cloud backup vendor. Moreover, these agreements should reflect current legal requirements, evolving security standards, and organizational changes or upgrades to software or hardware. It’s important to regularly review these contracts and take an active role in negotiating the terms with your HIPAA compliant backup vendor.

Taking steps to avoid common HIPAA mistakes when it comes to data backups can go a long way in protecting sensitive patient information. By being proactive in your approach to data backups, testing them on a routine basis, implementing robust access controls for stakeholders involved, and ensuring your business associate agreements are compliant with industry standards, you can significantly reduce risks and improve your chances of achieving compliance with HIPAA.

Frequently Asked Questions and Responses

Is it necessary to have a specialized backup system for HIPAA data?

Absolutely! In fact, it’s required by law. HIPAA (Health Insurance Portability and Accountability Act) regulations mandate that any organization handling protected health information (PHI) must have in place a secure and reliable backup system to protect against data loss or corruption. This is to ensure the confidentiality, integrity, and availability of PHI.

According to a recent study by the Ponemon Institute, 91% of healthcare organizations experienced at least one data breach in the past two years, with 39% experiencing two or more. Data loss can be attributed to many factors such as natural disasters, human error, hardware failure or cyber attacks.

Thus, having a specialized backup system for HIPAA data is not only necessary but also crucial for healthcare organizations to ensure compliance, minimize downtime and mitigate the risk of data loss or breach. A HIPAA compliant backup solution acts as an insurance policy shielding you from potential risks of non-compliance fines and lawsuits.

In summary, investing in a specialized HIPAA compliant backup solution is an essential measure for any healthcare organization seeking to safeguard PHI while demonstrating compliance with regulatory requirements.

HIPAA compliant backups are a must-have for healthcare organizations that want to protect their sensitive data and ensure patient privacy. The legal requirements for HIPAA compliant backups are outlined in the HIPAA Security Rule and include the implementation of proper administrative, physical and technical safeguards.

Administrative safeguards may include developing policies and procedures, assigning security responsibilities, conducting risk assessments, and providing workforce training on maintaining HIPAA compliance. Physical safeguards may include protecting or physically securing electronic devices used to store or backup protected health information (PHI), such as servers, hard drives, or backup tapes. Technical safeguards may include using encryption software to protect PHI during data transmission and while it is stored in backups.

The costs of failing to comply with HIPAA can be staggering. In 2020 alone, healthcare data breaches affected over 21 million patients in the US alone, costing an average of $7.13 million per breach. Thankfully, there are several HIPAA compliant backup solutions available that can help prevent these costly incidents from occurring.

In conclusion, healthcare providers and their business associates must adhere to the legal requirements outlined by the HIPAA Security Rule when implementing backup solutions. This includes implementing appropriate administrative, physical, and technical safeguards to ensure patient privacy and avoid costly data breaches.

What are some common mistakes that can lead to non-compliance when backing up HIPAA data?

There are several common mistakes that healthcare providers make when backing up HIPAA data, which can result in serious non-compliance issues. Here are a few of the most significant ones:

1. Failing to encrypt backups: Encryption is an essential element of HIPAA compliance, and it’s particularly important when backing up sensitive patient data. However, many healthcare providers fail to encrypt their backups properly, leaving patient data vulnerable to theft or unauthorized access.

2. Using insecure storage media: Many healthcare providers still rely on unsecured storage media like USB drives or portable hard drives to backup their data. However, these devices are highly susceptible to loss or theft, and they could put sensitive patient data at risk.

3. Retaining backups longer than necessary: HIPAA regulations require healthcare providers to retain patient data for a certain period, but once that period has passed, the data should be securely and permanently deleted. However, some providers may retain backups for longer than necessary, which could increase the risk of non-compliance in case of a breach.

4. Neglecting to test backups regularly: Finally, one of the most significant mistakes that can lead to non-compliance is failing to test backups regularly. If a backup fails or isn’t working correctly when needed, it may create serious compliance issues or cause delays in accessing critical patient data.

By avoiding these common mistakes and implementing HIPAA-compliant backup solutions, healthcare providers can protect their patients’ sensitive information while also ensuring compliance with federal regulations.

How often should HIPAA compliant backups be performed?

HIPAA compliant backups need to be performed on a regular basis, with the frequency depending on the size of your healthcare organization and the amount of data that is generated.

As a general rule of thumb, it is recommended that healthcare organizations perform daily backups for critical systems and data, such as patient records and financial information. However, some smaller organizations may only need weekly or bi-weekly backups.

The importance of backing up data cannot be stressed enough. According to recent studies, 60% of small businesses that suffer a cyber attack go out of business within six months. Additionally, data loss can have serious consequences for patient safety and confidentiality, which is why HIPAA regulations require healthcare organizations to maintain secure and compliant backup solutions.

To ensure that your organization is fully compliant with HIPAA regulations, it’s important to work with vendors who offer HIPAA-compliant backup solutions that meet all necessary security requirements. These solutions should include regular testing and monitoring to make sure that backups are performing properly and securely.

In conclusion, healthcare organizations must prioritize the regular performance of HIPAA compliant backups in order to ensure the safety of patient data and maintain regulatory compliance. The frequency of these backups should be determined by the size and needs of your organization, but all efforts should be taken to ensure that they are performed frequently and securely.

Can cloud storage be used for HIPAA backups, and if so, what security measures should be in place?

Absolutely! Cloud storage can be used for HIPAA backups. In fact, cloud backup solutions have been gaining popularity in recent years due to their convenience and cost-effectiveness. However, it’s important to ensure that the chosen cloud storage provider is HIPAA-compliant to avoid any legal or ethical violations.

A HIPAA-compliant cloud backup solution should have proper administrative, physical, and technical safeguards in place to protect data privacy and security. This includes measures such as encryption of data at rest and in transit, strict access controls through multi-factor authentication, regular backups and disaster recovery procedures, and secure data centers with 24/7 monitoring.

Some popular HIPAA-compliant cloud storage options include Microsoft Azure, AWS S3, and Google Cloud Storage. It’s crucial to thoroughly investigate each provider’s compliance status and ask for their Business Associate Agreement (BAA) before signing up for their service.

According to a survey conducted by HIMSS Analytics in 2020, more than 50% of healthcare organizations are currently using cloud technology for backups and disaster recovery purposes. The same survey also revealed that 90% of healthcare organizations plan on increasing their cloud usage in the next few years.

In conclusion, cloud storage can certainly be used for HIPAA backups if the necessary security measures are in place. As long as healthcare providers do their due diligence in choosing a compliant provider and adhering to best practices for data protection, they can enjoy the benefits of easy-to-access backups while keeping their patients’ information safe.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Cyber threats are continuously evolving at an accelerated pace. Ransomware is often the leading antagonist, leaving organizations crippled and at the mercy of cybercriminals. Commvault helps organizations protect and recover data to resume business operations quickly. However, as threats evolve, even backup and recovery platforms are at risk to ransomware. This has led to next-generation security controls such as immutability and multi-factor authentication to mitigate against these invasive threats. What about traditional air gap solutions? Is air gapping a viable solution against ransomware threats? In some cases, air gapping by itself may not be enough protection against threats; conversely, immutability and multi-factor authentication (MFA) may not be enough protection either. However, layering immutability, MFA, and Commvault’s modernized air gap controls provide a highly effective solution at mitigating threats. Let’s dive into this further.

Understanding the basics of ransomware

First, let’s understand how ransomware works at a high level. I like to think of ransomware as a symptom but not necessarily the catalyst. Most of the common ransomware strains we see today started as an Advanced Persistent Threat (APT) introduced into the environment through a targeted socially engineered phishing attack. For example, you may get an email from what appears to be a legitimate source (such as a work organization or bank) that tricks you into downloading a malicious application that introduces the APT. The APT keeps itself hidden in the environment crawling around doing reconnaissance, such as looking for user accounts and data to steal, as well as locating resources to infect. APT’s use “off the shelf” tools built into many operating systems to remain hidden, help collect data, and spread ransomware. They take advantage of exposed and exploitable protocols to move around the environment. APT’s have also been known to take down backup applications and data, as you can see from the Ryuk ransomware breakdown. Threats that move and spread around in the network are called lateral moving threats. As soon as the APT has done its work, the ransomware is released like a time-bomb.

This is key to understanding how air gapping provides an effective layer of security. The assumption is ransomware will infect your environment if there is any exposure to public networks such as the internet. This is especially true during the COVID pandemic wherein organizations adopted “work from home” policies, allowing end-users to connect into the work environments, creating more exposure and entry points for threats. However, backup storage targets that are air-gapped within the organization are shielded from lateral moving threats.

What is traditional air gapping?

We established that air gapping has value. When you think of air gapping, you might immediately think of tape backups or the classic “government” dark site. Both solutions offer protection against lateral movement of threats since tapes are removed from the library, and dark sites are isolated and have no persistent connections to public networks. However, both solutions are slow and ineffective for modern environments that need accessibility and rapid recovery. Organizations are looking for air gap principles applied to modern storage,  including cloud targets, to limit lateral moving threats while providing a seamless recovery experience when needed.

Commvault’s modernized air gap

Commvault’s approach to air gapping allows organizations to maintain efficient recovery point and recovery time objectives while reducing the impact of lateral moving threats. 

The most accessible air gap solution offered by Commvault is Metallic™ Cloud Storage Service (MCSS). With MCSS, there are no persistent connections to the storage since all data resides in Metallic Cloud and is only accessed via authenticated API calls. Direct access to cloud storage is not possible as credentials are not exposed. The storage is secure, scalable, and accessible. When ransomware infects the environment, it will not spread to the cloud storage since it is virtually air-gapped, reducing lateral threats. MCSS is built into Commvault data protection solutions and preconfigured. It is as simple as applying a license and selecting the storage; there is no additional infrastructure or settings required.

For organizations that cannot use the cloud, they can air gap using Commvault’s Network Topologies and built-in intelligence for managing persistent connections to storage. This on-premises solution segments and compartmentalizes storage; all incoming communication to the storage is blocked, and data pulled into the isolated storage. Communication is air-gapped by controlling power management automatically for virtual gateways or data movers. This solution requires minimal infrastructure; however, it can be applied to Commvault on-prem offerings and just about any storage.

To protect the backup content, Commvault’s machine learning framework detects anomalous activity and changes to the content. Events and notifications are automatically triggered so customers can respond proactively. Removing threats from content is as simple as browsing your content and selecting the threat to erase. Check out this youtube video demonstration, Avoid ransomware reinfection with Commvault, to see how this works. This ensures backup data is clean and ready for recovery.

Putting the security pieces together for maximum ransomware protection

At this point, you might be thinking, why bother with an air gap solution when I have immutable storage locked down with MFA controls? There is no doubt that immutability and MFA are an integral part of the layered solution; however, they do not address lateral moving threats.  

Let’s use the analogy of a combination safe. If your offline bitcoin wallet is stored in a safe, is it safer sitting in plain sight for an intruder to easily see, or would it be better if the safe is secured and hidden in your house?  Even though your safe is locked and secured, why would you expose it to additional risk? You don’t need the combination to get into the safe; you need a way to exploit the safe. It makes logical sense that the most secure option would be to keep your bitcoin wallet in a lockbox stored at a remote secured facility such as a bank – where it is air-gapped and un-reachable. Now you have eliminated the possible exposure to an intruder altogether. 

The same applies to backups; your storage should be immutable and protected with MFA controls. As soon as you segment, isolate, and air gap, you are further reducing the risk to ensure the ultimate protection.

Fighting ransomware with Commvault’s layered security approach

Taking a layered approach to securing backup data provides the best overall protection against threats such as ransomware. Commvault’s modernized approach to air gapping is not only simple, but it also provides the maximum level of security needed to protect against lateral moving threats so customers can be assured their data is recovery ready.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

During December’s EMEA Commvault Virtual Connections, I was struck by how much it felt like an in-person conference. We had so much great engagement with customers and experts—it was so great to interact with so many people on the hot customer topics of cloud, containers and of course ransomware.

Unfortunately, as with all good events, we didn’t have time to get to everyone’s questions. Still, we wanted to make sure that you got the Commvault answers you need to make the most of your data. Below, check out answers from our team of Commvault experts to your questions.

CUSTOMER:

When Commvault talk about protecting Kubernetes, is it the containers and storage? Or can Commvault backup the registry, the namespace configuration, ingress configuration? Also, is there a way to collect/protect the STDOUT/STDERR from Kubernetes? Will you backup that as well when you protect the container? 

 Marek Kedzierski, Senior Sales Engineer, Commvault:

Commvault’s agent for Kubernetes can protect both applications and persistent volumes. An application can be a pod, deployment, stateful set or workload. Our agent automatically protects all resources associated with an application, such as secrets and configmaps. Our persistent volume backup process uses CSI Snapshots. Therefore, our recommendation is to deploy our agent in Kubernetes clusters where persistent volumes are provisioned with storage class backed by the CSI driver. 

Container registries, namespace and ingress configuration, STDOUT/STDERR generated by pods are currently not supported by our agent. However, our agent is actively updated, and these resources may be protected in the future (of course, no guarantees).

https://share.vidyard.com/watch/54ZZKoXFt8LWLNW4VM3tLn?
Commvault protects an on-premises Kubernetes application and migrates it to Google Kubernetes Engine (GKE). Using the cloud-native integration with Kubernetes and CSI, recovery is fully automated and self-service is enabled from the Commvault Command Center™.

CUSTOMER:

Do you have a unique portal to configure backups for your client’s accessing the cloud portal?

Marek Kedzierski, Senior Sales Engineer, Commvault:

If the question relates to Metallic, each customer has full control over what and how their systems and data are protected in the cloud, in a simple-to-use web interface.

If the question relates to  Commvault software in a shared service, it can be deployed in a multi-tenanted configuration aimed at servicing multiple distinct companies or ‘tenants’ while securely separating access to data and systems.

A multi-tenant model is intended to consolidate the data management needs of multiple distinct organizations, companies or tenants. A tenant is typically identified as a separate legal entity along with a separate identity management infrastructure (Active Directory domain, users, and groups). The Commvault Command Center provides role-based access controls and per-Company administration to its tenants.

In a multi-tenanted environment – a user from one company cannot see the systems or data from another tenant / company.

Additionally, with the user of tenant provided Identity Servers, the tenant remains in complete control of who can access the data management system. Should an employee leave, their account can be disabled, and they immediately lose access to the Commvault system(s).

For customers using Commvault for their own purposes in a hybrid cloud, role-based self-service consoles are quick and easy to add to your service catalog.

Learn more: Multi-Tenancy in Commvault

CUSTOMER:

Can Commvault protect workloads in Azure Stack platforms? What about the integration and simplicity?

Marek Kedzierski, Senior Sales Engineer, Commvault:

Commvault can be easily integrated with both Azure Stack Hub and Azure Stack HCI platforms. 

With our intuitive web-based interface you can:

  • Backup application-aware virtual machines
  • Easily restore guest files and folders, full virtual machines, or virtual machine disks
  • Convert VMs from a different virtualization platform like VMware with image level conversion to Azure Stack
  • Replicate VMs for disaster recovery with orchestration for failovers
  • Configure backup with global deduplication, compression, and encryption
  • Protect data stored on Azure Stack Block Storage

Additional resources: Commvault for Microsoft® Azure Stack

CUSTOMER:

Does Commvault support seamless integration with cloud platforms (Openstack or VMware Cloud Director)?

 Christian Kubik, Principal Sales Engineer, Commvault:

Commvault supports a wide variety of public and private cloud platforms for IaaS/Virtual Machine backups. This includes not only VMware vCloud Director and OpenStack but also Azure Stack HCI, Azure Stack Hub as private platforms as well as Microsoft Azure, Amazon AWS, Google Cloud and others public cloud providers. An overview of the supported platforms can be found here: Virtualization and Cloud

Commvault also integrates into a large number of cloud / object storage platforms – a comprehensive list can be found in our documentation here: Cloud Provider Information

CUSTOMER:

Is a backup copy to a cloud library like S3 an official offline backup, comparable to a tape backup? 

Commvault cloud backups are air-gapped for extra protection. So, if Access & Secret Key is used, ransomware should not be able to easily access an S3 bucket as it would need to figure out this information somehow. If additional protection is desired, we can use the WORM functionality provided by Amazon to provide additional protection. There is a new workflow available that can enable WORM protection on cloud libraries.

CUSTOMER:

Does Commvault support backups of Desktop Laptop clients? How can Commvault achieve that goal over the WAN to protect users’ data who are actually working remotely?

 Ronnie Kaftal, Senior Sales Engineer, Commvault:

Commvault supports the backup and desktops as a software solution (Commvault Backup & Recovery) or as a service (Metallic Desktop and Laptop backup as a service powered by Commvault). 

Both of these solutions offer block based, incremental forever data protection with source side deduplication and encryption to ensure only unique data blocks will be transferred over the WAN.

Commvault is able to achieve high levels of efficiency as we are based on proven technologies which have been used for over a decade in large and small enterprises across the globe. 

Metallic Desktop and Laptop backup as a service takes it a step further. Unlike traditional on-premise backup software, the Metallic service is delivered on MS Azure from a region near you, so the desktop data doesn’t need to be routed through a corporate firewall or impact the client VPN concentrators.

The agent pushed by the service on the user’s desktop will take care of the authentication and encryption of the data before it leaves the end user’s system, plus it will use smart scheduling that will only run when enough power and bandwidth are available for backup. In reality, the end users will probably not even notice that their desktop is being protected regularly. 

Please give it a try for free here: Cover all your bases with endpoint protection

We will love to hear back from you on your experience. 

CUSTOMER:  

Since Metallic is running on top of Microsoft Azure, what’s the advantage of using Metallic over Azure native backup?

 Ronnie Kaftal, Senior Sales Engineer, Commvault:

Metallic offers a higher level of data protection and recovery granularity. As we backup data from the client Azure tenant to our service tenant, we can work to ensure that the data will be recoverable in the event the client tenant is compromised or otherwise not available. In addition, with data protection between tenants and Azure Geographical redundant storage blob, we can also index the VM we protect so the customer can browse and recover individual files to any backup point in time and even recover data to a location outside of Azure with no egress charges.  

Please give it a try for free here: VM & Kubernetes Backup

We will love to hear back from you on your experience. 

CUSTOMER:

Is Metallic able to protect an on premise environment as well?

Ronnie Kaftal, Senior Sales Engineer, Commvault:

Our Metallic hybrid solution is fully supported for on-premise workloads, such as virtual machines, databases and Windows and Linux file servers.

Metallic subscribers have the choice of protecting their on-premise service on an on-premise Commvault storage appliance, their own storage devices or directly to the Azure cloud. 

Many subscribers choose a combination of storage targets to ensure the data is protected on at least two copies, one of them being air gapped and remote from the source location.   

Please review the different backup options for on-premise workloads on our site here: Simple, smart, secure data protection as a service

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide

Are the security claims of your backup provider keeping you up at night? Worried that hackers might be on your network right now, trying to compromise your data? Did you know that typical ransomware exists on your network for more than 200 days before encrypting your data? Wonder what they are doing? They are hunting for your backups!

Backup methodologies are going through a fundamental shift from protecting your data from “acts of God” to needing protection from “bad actors and hackers.” With attacks happening inside your network or in your cloud accounts, the real question you should be asking yourself is, “are our on-premises backups or local snapshots in our public cloud account good enough to protect in the event of a ransomware attack?” Unfortunately, recent history has proven backup is not enough.

In the last few months, the Cybersecurity & Infrastructure Security Agency (CISA) has been releasing alerts and warnings to enterprises on this vulnerability. CISA recommends a solution to include regular backups, air-gap protection, and offsite backup outside your network and security sphere (see alerts AA20-345A and AA20-302A). CISA realizes that if you or your admins have access to the backend hardware or cloud infrastructure, the hackers will find a way to compromise it. Even if you think you have the best security, the real question is, do you want to own staying ahead of hackers for your last resort (you backup), over and above trying to drive your mission as a company? We think there is a better way.

We recognize that many organizations plan to leverage a cloud native backup solution in the future along their cloud journey, but the timing now might not be optimal due to hardware depreciation cycles. But, instead of wasting more money on that old boat anchor of a backup, we have a solution.

We are excited to announce Clumio RansomProtect™, the industry’s first cloud native air gap solution that protects public cloud, private cloud, and SaaS clouds in one service and on one platform.

Clumio RansomProtect provides a solution for enterprises looking to protect themselves NOW from ransomware with:

  • The fastest time to protection with a 15-minute setup with no hardware required
  • 30-day retention for VMware / VMware Cloud on AWS, AWS Native Services (EC2/RDS/EBS), and Microsoft 365
  • Rapid granular recovery anywhere you need it
  • Ultimate data security with air-gapping
  • Up to 50 percent of the cost of existing data protection products, that are not good enough in the first place

With Clumio RansomProtect you can forget about buying more hardware and software for protection, managing network and infrastructure security to create an air gap, finding a secondary site, or trying to keep up with hackers trying to attack your backup infrastructure.

Clumio’s core platform provides both protection and recovery methodologies to ensure you are not only protected but able to get back up and running fast.

Commvault AirGap with the Ultimate Security

Clumio takes the complexity out of protecting from ransomware attacks and provides the ultimate security. To start off, all data is protected outside your on-premises networks or cloud infrastructure. Don’t let today’s traditional data protection solutions try to convince you to buy more hardware and software or even worse, convince you that a cloud cluster or S3 offload is enough to protect you. Immutability and encryption alone are not enough if someone can get credentials and delete, encrypt, or power down the infrastructure to make it unusable.

What is required is constant testing, certification, and validation on top of all the platform security features found in Clumio. Does your backup solution run quarterly penetration tests to ensure you are secured? Are they certified for compliance with ISO27001, ISO27701, PCI DSS, SOC2 Type I and Type II, or HIPAA? Well, if you were a Clumio customer, you could answer, “Yes!”. At the end of the day, if your admin has access and the ability to delete the data, the hackers will find a way to compromise your data.

Replicating data to a secondary site is not only costly, requiring additional hardware, but it also places the burden of security on your back. You now have to manage additional network security when the primary backup has access to the secondary backup device. We have already seen traditional backup solutions fall to ransom attacks.

Rapid Recovery with Flexible and Granular Restores

Getting attacked is challenging enough, but having flexible and granular restores can be a lifesaver when it happens. With Clumio, recovering from a ransomware attack couldn’t be any easier. Clumio provides the ultimate flexibility for restores with the ability to restore VMs to any datacenter or VMware Cloud on AWS, restore EC2 or RDS to any AWS Account, or Microsoft 365 mailboxes to any domain. You can search or browse for the data you look to restore and restores are provided at a fine grain granularity at a file, directory, VM, email, database, or even database record all with a few clicks.

Get Protected and Reduce Your Costs at the Same Time

RansomProtect complements your existing backup product and offers the 14-day air-gapped protection you need from aggressive ransomware attacks while offering it at half the cost of competing solutions. And down the road, if you decide to replace your old air-gapped backup solution with Clumio, you can save up to 70 percent vs. a native air-gap solution, while dramatically simplifying deployment and management.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog-Lateral-Access-2026

Private Cloud Data Security Technical Guide

Read more about Private Cloud Data Security Technical Guide