Skip to content

Key Takeaways

  • Deepfake extortion transforms ransomware from a data access threat into a trust crisis by using stolen data to fabricate believable forgeries.
  • The success of deepfake attacks stems from easy access to generative AI tools, limited detection capabilities, and the burden of proof shifting to victims.
  • True defense lies in protecting and proving the authenticity of data – not chasing every fake artifact.
  • Immutable storage and trusted recovery points enable organizations to demonstrate what is real when under pressure.
  • Commvault can help strengthen resilience by securing data integrity across backup and recovery workflows, allowing organizations to restore credibility quickly.

Ransomware has evolved from disrupting operations to undermining truth itself. Today’s attackers steal sensitive data and use generative AI to fabricate emails, audio, and video that appear authentic enough to deceive customers, partners, regulators, and internal teams. The challenge is no longer just restoring systems. It is proving what is real under pressure.

When Data Theft Becomes Identity Theft

Traditional ransomware denies access to data. Deepfake extortion attacks trust itself. Attackers exfiltrate sensitive corporate information, including executive communications, meeting recordings, and internal documents, and then use generative AI to create convincing forgeries. Fabricated audio or video can appear authentic enough to mislead customers, partners, regulators, and even internal teams.

In these attacks, identity and authenticity are no longer assumed. Perception becomes the weapon.

Why Deepfake Extortion Works

Deepfake extortion succeeds because three structural realities converge at once.

  • Generative tools are widely accessible: High-quality AI tools are readily available and require little expertise to operate.
  • Detection lags creation: Even experienced analysts struggle to distinguish sophisticated deepfakes from authentic content in real time.
  • The burden of proof shifts to the victim: Organizations must demonstrate that content is fabricated, often under extreme time pressure and public scrutiny.

Without trusted data foundations and provable data lineage, truth becomes negotiable.

Defense: Make Data Protected, Private, and Provably Real

Deepfake extortion is effective only when attackers have access to authentic source data. When that data is protected and provable, fabricated content loses credibility and leverage.

Effective defense begins with the recognition that deepfake extortion is not a content problem. It is a data integrity problem. The goal is not to chase every fabricated artifact, but to enable organizations to prove what is authentic when it matters most.

Defense therefore must focus on three architectural principles:

  • Protect the source data: Sensitive information must be secured before it can be exfiltrated. Executive communications, recordings, and internal documents should be tightly controlled so they cannot be repurposed for manipulation.
  • Preserve data integrity: Authentic data must remain provably unchanged. Immutable storage helps prevent backups and historical records from being altered, even by attackers with privileged access. This immutability provides a trusted reference point when authenticity is challenged.
  • Recover from a position of trust: When incidents occur, recovery must be based on verified, clean data. Restoring systems and records from trusted sources allows organizations to reestablish credibility quickly, rather than amplifying doubt through contaminated recovery points.

Together, these principles shift the balance of power. Instead of reacting defensively to fabricated content, organizations can retain the ability to prove authenticity, restore trust, and remove the attacker’s leverage.

How Commvault Supports Truth and Resilience

Commvault helps organizations strengthen resilience against deepfake extortion by protecting data integrity across backup, recovery, and restoration workflows.

By maintaining trusted recovery points and isolating clean data from manipulation, Commvault enables organizations to respond to extortion attempts with evidence rather than uncertainty.

Commvault helps organizations:

  • Protect authoritative data sources so authentic records remain available when credibility is challenged.
  • Isolate trusted recovery points to prevent manipulation from spreading across environments.
  • Restore systems and data from verified sources without reintroducing uncertainty.
  • Re-establish operational and reputational trust as AI-enabled attacks scale.

This positions organizations to respond decisively under scrutiny, using trusted data to guide action rather than reacting defensively to fabricated narratives.

Final Thought

Deepfake extortion is not just a cybersecurity problem. It is a challenge to truth itself. Organizations that cannot prove the authenticity of their own data risk losing trust when scrutiny is highest. In those moments, doubt spreads faster than facts.

By designing cyber resilience around protected, provable data and trusted recovery, organizations can help retain the ability to demonstrate what is real and respond decisively under pressure.

FAQs

Q: What is deepfake extortion, and how does it differ from traditional ransomware?
A: Traditional ransomware denies access to data, while deepfake extortion manipulates trust. Attackers steal sensitive information and use generative AI to create fake but convincing content, such as videos or emails, that exploit public perception.

Q: Why are deepfake attacks so effective?
A: They work because advanced generative AI tools are widely available, detection technologies lag behind creation, and organizations must prove that fabricated content is false – often under intense time pressure.

Q: How can organizations defend against deepfake extortion?
A: Defense should focus on protecting the integrity and authenticity of source data. This includes securing sensitive data, maintaining immutable backups, and verifying that recovery processes rely only on verified, clean data.

Q: What role does Commvault play in combating deepfake extortion?
A: Commvault helps maintain trusted recovery points, isolate clean data from manipulation, and enable organizations to respond confidently with verified information instead of speculation.

Q: Why is data integrity critical during a deepfake crisis?
A: When false content circulates, organizations quickly must prove what is real. Immutable and verifiable data provides the evidence needed to restore trust, counter manipulation, and maintain credibility under scrutiny.

Q: What’s the key takeaway for business leaders?
A: Deepfake extortion isn’t just a cybersecurity issue – it’s a truth crisis. Building cyber resilience around protected, provable data allows organizations to respond decisively and maintain trust when it matters most.

Chris DiRado is Principal, Product Experience, at Commvault.

Related Blogs

A Multi-Layered Approach to Cyber Resilience

Mastering Immutability, Air-Gapping, and Zero Trust for Unrivaled Cloud App Recovery

Dealing with Ransomware at a Global Level

Why Cleanroom Recovery and Cyber Testing are Critical for Cyber Resilience

More related posts


Cyber Resilience

Read more about Cyber Resilience

Cyber Recovery

Read more about Cyber Recovery
CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Key Takeaways

  • Data leakage loops emerge when sensitive information introduced into AI interactions is retained, retrieved, and reinforced over time.
  • These loops are difficult to detect because each step appears as normal system behavior rather than a traditional security breach.
  • Prompt injection, over-broad retrieval, and excessive retention are the three core mechanisms that enable AI-driven data leakage.
  • Effective AI security requires embedding containment, least privilege, and continuous verification directly into interaction design.
  • Protection, isolation, and rapid recovery capabilities help organizations limit the blast radius when unintended exposure occurs.

The biggest AI risk is not what large language models say. It is what they remember.

A single copied API key, customer record, or internal document pasted into a prompt can quietly persist, reappear, and spread well beyond its original context.

Every prompt, retrieval, and response in an AI system creates the potential for unintended data exposure. Credentials, intellectual property, personally identifiable information, and customer data can all be introduced into AI workflows without malicious intent. Over time, these exposures compound, forming invisible feedback loops of risk until exposure is widespread.

Unlike a traditional breach, data leakage loops rarely announce themselves. They grow incrementally, interaction by interaction, until sensitive information is dispersed across systems, users, and outputs that were never meant to see it.

Data leakage loops follow a simple pattern. Sensitive data is introduced into an AI interaction, stored or embedded by the system, retrieved later in an unintended context, and reinforced with each subsequent use. Because each step looks like normal system behavior, the loop often goes unnoticed until exposure is widespread.

When Intelligence Creates Leakage

Organizations adopt generative AI to accelerate productivity, automate decisions, and improve customer experiences. The challenge lies not in intent, but in architecture.

AI systems are designed to ingest, retrieve, and contextualize information. When safeguards are insufficient, fragments of sensitive data introduced during one interaction can surface in unrelated responses later. Each use reinforces the next, creating a self-sustaining cycle of exposure.

The Architecture of Data Leakage Loops

Data leakage in AI systems typically emerges through three interconnected mechanisms:

  • Prompt injection (intentional or accidental): Users knowingly or unknowingly include sensitive data in prompts, such as passwords, customer records, or proprietary information, which the system processes and may retain.
  • Over-broad retrieval: AI systems retrieve information from data sources they should not access due to weak permissions or insufficient context filtering.
  • Excessive retention: Interaction histories, embeddings, and logs are stored longer or more broadly than necessary, allowing sensitive data to persist and resurface.

Together, these mechanisms form feedback loops where each interaction increases cumulative exposure.

Defense in AI Interaction Design

The safest design assumption is that anything provided to an AI system may be retained, reused, or disclosed.

That mindset fundamentally changes how AI systems should be secured. Protection must be embedded into interaction design rather than applied after exposure occurs. Security in AI systems begins with the assumption that exposure is possible, which makes containment, least privilege, and continuous verification core design requirements.

In practice, this means:

  • Applying zero-trust principles to every AI interaction.
  • Verifying and limiting data access at each stage of prompt handling, retrieval, and response generation.
  • Minimizing permissions across prompts, retrieval sources, and storage layers.
  • Enforcing context aware authorization within retrieval pipelines at query time, rather than relying on static permissions defined outside the AI workflow.
  • Designing systems to contain exposure rather than assuming prevention alone is sufficient.

This approach transforms AI security from reactive cleanup into proactive resilience.

The Role of Commvault

Commvault helps organizations protect the data that fuels AI systems, including training data, retrieval sources, and recovery paths, before, during, and after interaction.

By providing protection, isolation, and rapid recovery capabilities, Commvault enables organizations to limit the blast radius of unintended exposure and restore AI environments from trusted data sources.

With Commvault, enterprises can help:

When combined with fine-grained data access controls, organizations can innovate with AI without creating compounding loops of risk.

Final Thought

Data leakage loops represent one of the most subtle and dangerous risks in AI adoption. They do not look like attacks, but they weaken security continuously. By treating every AI interaction as a potential exposure and embedding protection, isolation, and recovery into AI architectures, organizations can scale AI while helping preserve trust.

FAQs

Q: What is a data leakage loop in AI systems?
A: A data leakage loop occurs when sensitive data is introduced into an AI interaction, stored or embedded, later retrieved in an unintended context, and reinforced through repeated use. Over time, this creates a self-sustaining cycle of exposure that can spread across systems and users.

Q: Why are data leakage loops harder to detect than traditional breaches?
A: Unlike conventional breaches, data leakage loops do not trigger clear alerts or single points of failure. They grow gradually through normal-looking interactions, making exposure visible only after it has already spread widely.

Q: How does prompt injection contribute to data leakage?
A: Prompt injection occurs when users accidentally or intentionally include sensitive information in prompts. If safeguards are weak, that data can be processed, retained, or reused by the system beyond its original context.

Q: What role does AI system architecture play in preventing leakage?
A: Architecture determines how data is ingested, retrieved, stored, and reused. Designing AI systems with zero-trust principles, least-privilege, and context-aware authorization helps contain exposure instead of relying solely on prevention.

Q: How can organizations reduce risk without slowing AI adoption?
A: Organizations can reduce risk by embedding security directly into AI interaction design and planning for containment and recovery. This approach enables innovation while limiting cumulative exposure as AI usage scales.

Q: How does Commvault support protection against data leakage loops?
A: Commvault helps protect the data that fuels AI systems by providing immutable backups, isolation, and rapid recovery. These capabilities help enable organizations to limit the impact of unintended exposure and restore trusted AI environments quickly.

Chris DiRado is Principal, Product Experience, at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The board meeting started with a simple question: “Are we ready for the next disruption?”

I gave them an honest answer: “That depends on which disruption we’re talking about.”

Because here’s the reality every CIO knows but doesn’t always say out loud: Readiness isn’t a checkbox. It’s not something you achieve once with a great recovery plan or a perfectly executed disaster recovery test. Readiness is a muscle you build, test, and rebuild constantly as the threat landscape shifts beneath your feet.

That’s why we created the Readiverse. Not another content library. Not another vendor resource hub. It’s a space where CIOs, CISOs, and technology leaders can get the intelligence they need to help them stay ready – whether that means anticipating the next ransomware variant, navigating AI governance challenges, or simply having a straight answer when the board asks, “Are we protected?”

Two Kinds of Readiness

In my role, I need two things that rarely live in the same place:

Strategic insight for the boardroom: Intelligence briefs that analyze emerging threats through a business impact lens. Quick-hit perspectives from executives who’ve been in your chair – 60-second Bold Takes on what matters now. Peer conversations with other CIOs who’ve navigated market disruptions and transformation challenges.

Practical guidance for implementation: Readiness assessments to benchmark your maturity. Regulatory compliance guides that help map requirements to capabilities. Recovery workshops and hands-on experience that sharpen your team’s ability to respond when it matters most.

The Readiverse brings both together. Because you can’t lead from the boardroom without understanding implementation realities. And you can’t build resilient systems without connecting them to business outcomes.

Ready. Or Not.

That’s the choice we face every day as technology leaders. We can be ready – with tested plans, trained teams, and intelligent defenses. Or we can be caught off-guard when disruption arrives.

That’s why we’re launching our new, six-part podcast series, Ready. Or Not., on the Readiverse. Our host, comedian Nathan Macintosh, and his guests cut through the AI hype and cybersecurity complexity with humor and straight talk. Check out our first episode – AI: Agents of Good, Meet Agents of Evil – with guest Reid Blackman, founder and CEO of AI risk consultancy Virtue.

Beyond the Noise

The Readiverse exists to give you the intelligence, perspective, and practical guidance you need to build resilience that works – not just resilience that sounds good in a slide deck.

Because the board will keep asking if we’re ready. And we owe them – and ourselves – an honest, confident answer. Explore the Readiverse, and we’ll stay ready together.

Ha Hoang is Chief Information Officer at Commvault.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Belgium-based xyzt.ai was founded to help customers gain insight from their location data. Read on to hear why the company chose Clumio, a Commvault company following its acquisition in 2024, to reduce AWS backup costs and significantly improve recovery times.


Q: Lida, can you start by telling us what xyzt.ai does?

Lida: We are a cloud-based, no-code analytics platform that helps customers turn massive volumes of sensor, IoT, and mobility data into meaningful insights. We process billions of records and make it easy for users to visualize patterns, identify anomalies, and make data-driven decisions. Our customers span maritime, mobility, smart cities, and connectivity – anyone who needs to understand location-based behavior at scale.

Q: As a growing startup, how did backups fit into your early strategy?

Lida: In the beginning, AWS-native backups worked well for us. They were simple, integrated, and aligned with our cloud-first architecture. Unfortunately, over time, as our data grew, our AWS backup bill grew with it. It wasn’t dramatic at first, but every year the cost kept climbing.

Q: At what point did rising AWS backup costs become something you needed to solve?

Lida: After about five years of steady growth, the trend was impossible to ignore. Our costs were increasing year over year simply because we were scaling our data footprint. That’s when we realized we needed a more sustainable, predictable option.

Q: What led you to evaluate Clumio?

Lida: Initially, we were looking purely for cost reduction. Once we saw the Clumio demo, we realized the value was much broader. Compliance, recovery, data isolation, pricing predictability – those were all important features Clumio provided.

Q: How would you describe your onboarding experience?

Lida: Surprisingly fast. We expected a time-consuming migration, but it was incredibly smooth. We had our first backup running within 30 minutes. That’s not something you expect when switching a core infrastructure component.

Q: Many organizations worry not just about backup costs but also how quickly they can recover. How has recovery performance changed since moving to Clumio?

Lida: Recovery speed is one of the areas where we saw the biggest improvement. With AWS-native tools, restoring large datasets could take hours – sometimes longer – because recoveries were tied to the time it took to fully rehydrate data back into our AWS environment. That lag was a real challenge when we needed fast access for troubleshooting or when customers required immediate data validation.

With Clumio, the experience is dramatically different. The Instant Access feature lets us mount backups in minutes without waiting for full restores. That means our team can start working with the data almost immediately, whether it’s for verification, investigation, or full-scale recovery.

The time savings are enormous – it’s not just faster, it fundamentally changes how quickly we can respond to issues. For a real-time analytics platform like ours, that makes Clumio far more effective than AWS-native options.

Q: Let’s talk results. What impact did Clumio have once you were up and running?

Lida: The most immediate impact with Clumio was cost savings. Using AWS Storage Lens, we confirmed that backups through Clumio were 66.7% cheaper than what we were paying previously. That validation came quickly, and it accelerated our internal approval to move forward.

We also gained stronger resilience by storing backups outside our main AWS environment, which improved our security and compliance posture.

Q: What advice would you share with other AWS-native startups evaluating their backup strategy, and how does Clumio fit into your long-term plans?

Lida: I would tell other startups not to be intimidated by the idea of switching backup providers. The migration was much easier than we expected, and the payoff was immediate.

If your AWS costs are climbing or your compliance requirements are evolving, it’s absolutely worth exploring alternatives. Data protection is central to our business, so we need solutions that scale with us without introducing unpredictable cost spikes – and Clumio gives us that confidence.

Cara Peterson is Voice of the Customer Manager at Commvault.

More related posts


GSI

The Importance of Cyber Resilience in a Cloud-First World

Read more about The Importance of Cyber Resilience in a Cloud-First World
Thumbnail_Blog_Clumio-Tech-2025

Restore only what matters: Clumio Backtrack for DynamoDB

Read more about Restore only what matters: Clumio Backtrack for DynamoDB

Clumio

Read more about Clumio

New Yorkers don’t settle. They expect the fastest service, the toughest infrastructure, and the boldest ideas. So it’s no shock that when it comes to data security, their expectations soar.

But here’s the twist: According to a recent Commvault-commissioned survey of more than 1,000 New Yorkers, consumers hold businesses to uncompromising security standards, even as many admit they don’t follow those same practices themselves.

This isn’t just an interesting quirk. It’s a signal about the future of trust, resilience, and loyalty.

Two Standards, One City

The survey makes one thing clear: In New York, trust isn’t given – it’s earned. And it’s earned through action.

Most respondents said they would stop using, or seriously consider leaving, a company after a breach. Many already have. They reward businesses that prove they take data protection seriously, not just talk about it.

Yet, while they demand resilience from brands, their own habits tell a different story. Password reuse? Still common. Public Wi-Fi? Still tempting. Even with rising awareness and firsthand experience of cyber incidents, inconsistent behaviors persist.

Is that hypocrisy? No. It’s human nature.

People want safety, but they also want convenience, speed, and simplicity. And when those collide, personal cyber hygiene often slips.

Businesses don’t have that luxury.

Why This Gap Is a Leadership Mandate

The takeaway isn’t to judge consumers; it’s to understand them. Consumers can take steps to protect themselves (and many do), but they can’t single-handedly defend against sophisticated, AI-enabled threats. Nor should they have to.

That’s where the expectation gap becomes a leadership mandate. Cyber resilience is a shared responsibility, but businesses must lead. And leadership shows up in three ways:

  • Protect before the breach: Build strong defenses, zero-trust controls, and unified resilience platforms that keep pace with evolving threats.
  • Respond fast when things go wrong: Consumers judge a breach not just by its occurrence, but by how quickly and effectively you recover.
  • Communicate with transparency: Silence erodes trust faster than bad news. Honesty wins.

The alignment of these elements strengthens consumer trust.

New York as a National Signal

Trends start in New York. Expectations crystallize here. Sentiment swings hard here. If New Yorkers are signaling that trust is a primary factor in brand choice, companies nationwide should pay attention. What starts in a major market rarely stays there.

Security expectations are only intensifying. And in the AI era, the cost of losing trust is steeper than ever.

Resilience Is the New Loyalty Program

For years, brands have poured billions into personalization and convenience. But today’s research suggests something different is rising to the top: Consumers stay loyal to businesses they believe will protect and recover their data, not just collect it.

Security, resilience, and trustworthiness aren’t just back-office concerns anymore. They’re front-of-brand differentiators that shape purchasing decisions, referrals, and long-term relationships.

And in a season when people are traveling, shopping, and accessing sensitive information on the go, often across unsecured networks, the stakes couldn’t be higher.

The Moment to Lead

Consumers have clear demands: People know what they expect, what they’ll tolerate, and what they won’t. And they’re watching you closely.

For businesses, the opportunity is profound: Invest in resilience today and earn loyalty tomorrow. Because when it comes to cybersecurity, consumers don’t just want to feel protected, they want to be protected.

The companies that deliver on that promise will define the next era of trust.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • Arlie Data Sense helps turn sprawling grid data (logs, audits, job histories) into clear, actionable summaries with suggested follow-ups and free-form querying.
  • New root-cause analysis helps scan failures, spots anomalies, and delivers plain-language diagnostics with recommended next steps – no manual log-diving required.
  • Video Bytes in Arlie Responses jumps you to the exact timestamp in long-form videos that answer your question, helping speed up problem-solving.
  • Behind the scenes, Arlie orchestrates ETL, PII masking, and analysis agents to help generate contextual insights you can act on quickly.
  • Arlie and its agent library are available in Commvault SaaS with phased rollout, bringing parity with Commvault software deployments.

IT teams are under pressure to do more with less. You’re expected to spot risks early and optimize performance while juggling growing infrastructure and managing thousands of daily backup events. Generating insights from this constant stream of activity across platforms can be incredibly difficult.

This allows vulnerabilities to quietly creep in, waiting to expand into a major issue. Your dashboard says green. Backups seem to be running. But behind the scenes, something’s building: a silent timeout, a log full of subtle warnings, a spike in retries you didn’t notice. By the time a backup admin spots it, it’s already an incident.

The fact is, modern IT environments don’t fail loudly – they fail subtly. And most of the time, the data that could have warned you is already there. It’s just buried in audit trails, scattered across consoles, or trapped in a 40-minute training video.

This is where Arlie really shines. Arlie isn’t just an AI assistant – it’s the intelligent, unified interface designed to help find, understand, and resolve issues faster. Arlie orchestrates advanced backend workflows (agents) that help interpret data, identify anomalies, and generate insights – and then communicates the findings to you through a simple, conversational experience.

With Arlie Data Sense and Video Bytes in Responses, Arlie brings context, clarity, and speed to every interaction – without the hunting. Let’s take a look at what’s new.

Grid Data Analysis: From Data Overload to Data Insight

Modern environments generate an overwhelming amount of data‌: ‌logs, alerts, warnings, and more. On the Commvault platform, these manifest as audit trails and job histories, with hundreds or even thousands of events occurring every day.

Businesses often don’t know where to begin when analyzing their environments. Backup admins are tasked with making sense of this flood, manually scanning through sprawling rows of data across multiple consoles just to understand what’s happening. And with so many actions being logged every minute, it’s easy to miss early warning signs that could escalate into larger issues.

That’s where Arlie Data Sense and its grid data analysis capability come in. It ingests your platform data and distills it into clear, actionable summaries. Instead of forcing teams to scroll through thousands of rows, Arlie Data Sense identifies the most relevant information, delivers those summaries, and highlights what’s actionable in a clear, conversational way. Users can expect:

  • A highlighted executive summary tailored to the user’s environment.
  • Suggested follow-up questions to help explore emerging issues.
  • The ability to ask free-form questions for deeper analysis.

What’s more, Arlie Data Sense highlights ransomware protection-related events and major changes, proactively surfacing insights that help users stay ahead of potential risks.

However, behind the scenes is where the magic truly happens. Arlie orchestrates multiple backend workflows – retrieving data from Commvault, performing ETL and PII masking, and leveraging analysis agents to generate insights. Arlie’s reasoning and knowledge augmentation capabilities then transform this into actionable intelligence for the user.

With a simple click of a button, backup admins can derive key insights that highlight the exact points needed. Essentially, this allows you to converse with your platform’s data and gain a much clearer understanding of where the system stands in real time.

It’s not just alerting; ‌it’s contextual understanding. No more digging through logs. No more endless tab-hopping. It’s a smarter, faster way to help you monitor system health, troubleshoot issues, and understand your risk landscape. This kind of insight drastically improves efficiency, especially for lean teams managing complex environments‌, ‌allowing them to focus on what truly moves the needle.

Root-Cause Analysis: Turning Raw Logs into Real-Time Answers

Reading logs is no one’s idea of fun. Yet buried in those logs are critical clues: ‌why something failed, where the system is strained, and what’s likely to break next. Given the monotonous nature of scouring through large volumes of log data for answers, many teams struggle to diagnose job failures.

Arlie Data Sense and its root-cause analysis capability do the detective work. It scans job failures, identifies root causes, spots anomalies, and generates clear, human-readable explanations – all without manual log interpretation.

Integrated directly into the Send Log Files workflow and Command Center, the agent processes log files to deliver detailed diagnostics along with potential resolutions. Arlie then communicates those findings and recommendations to users, providing clarity and saving valuable troubleshooting time.

Let’s say a job has failed intermittently over the past week. Instead of manually combing through five different logs, Arlie Data Sense can help flag recurring timeouts linked to a specific virtual machine (VM). Or, if backups are running slower than usual, it can help identify the underlying issue.

So, whether you’re managing a handful of backup jobs or orchestrating across hundreds of environments, Arlie helps you cut through the noise and act faster by presenting the right insights at the right time.

Ever found the perfect video that promises to answer your question‌, only to realize it’s 30 minutes long? The exact answer you’re looking for could be 20 seconds or 20 whole minutes into the video, and you have no idea where it’s actually buried. Even after finding this video, locating your answer could be a tedious, time-consuming endeavor.

With Video Bytes in Arlie Responses, that frustration is gone.

Now, when Arlie knows there’s helpful information available within documentation or the Readiverse, it doesn’t just share the link‌ – ‌it pinpoints the exact moment in the video that answers your question. Just ask something like “How can I reduce my VM costs?” and Arlie will jump straight to the timestamp where that topic is addressed‌ – ‌say, Minute 12 of a 30-minute walkthrough.

This enhancement means that you don’t have to rely strictly on documentation or lengthy videos to resolve your issues. It’s a smarter, more efficient, and highly focused approach that gives you exactly what you need.

From Answers to Actions: Arlie, Evolved for You

These exciting new capabilities mark a new chapter in Arlie’s journey, transforming it from being an AI assistant that helps to one that understands. Whether it’s generating key summaries or diagnosing failures through Arlie Data Sense or jumping to exactly what you need with Video Bytes, Arlie is AI designed specifically for you.

In a world where IT complexity is only growing, the real edge lies in proactive, contextual intelligence. With Arlie, you don’t just fix issues faster – you prevent them from happening. With minimal user input, Arlie allows you to see more, do more, and be more.

Now Available in Commvault SaaS

Commvault’s AI capabilities – including Arlie and its agent library – are now available in Commvault SaaS. This brings feature parity with Commvault software deployments, giving SaaS customers the same intelligent, AI-enabled experience. This brings feature parity with Commvault software deployments, giving SaaS customers the same intelligent, AI-enabled experience.

These capabilities are rolling out in phases, and you’ll begin seeing them appear in your SaaS environment in the coming weeks.

With these enhancements, Arlie brings the future of intelligent, contextual resilience directly into your hands – across both Commvault software and SaaS. Get ready for faster insights, fewer surprises, and a more connected, proactive experience – all with Arlie at the center.

If you’re using Commvault software, you can enable Arlie today by following the instructions in our documentation.

If you’re using Commvault SaaS and would like to enable these features early, please contact your Commvault representative.

FAQs

Q: What exactly is Arlie, and how is it different from a typical chatbot?
A: Arlie is a unified, conversational interface that orchestrates backend workflows –ingesting platform data, running analyses, and returning concise, actionable guidance – so you can move from “searching” to “solving.”

Q: How does the grid data analysis feature help me day to day?
A: Instead of sifting through thousands of rows across consoles, Arlie Data Sense highlights the most relevant signals, summarizes them for your environment, and proposes next questions to dig deeper, reducing noise and accelerating decisions.

Q: What problems does the root-cause analysis feature tackle?
A: It analyzes failures and anomalies across logs to pinpoint likely causes – like recurring timeouts tied to a specific VM – and offers human-readable explanations with potential resolutions, saving significant troubleshooting time.

Q: How do Video Bytes in Arlie Responses speed up learning and support?
A: When a relevant video exists, Arlie links directly to the precise timestamp that answers your query, eliminating the need to scrub through lengthy recordings to find the right segment.

Q: Where can I access these capabilities, and when will I see them?
A: Arlie and its agents are available in Commvault SaaS with feature parity to software deployments, and the enhancements are rolling out in phases over the coming weeks; contact Commvault to enable early access.

Q: How does this tie into resilience and business continuity efforts?
A: Proactive insight and faster root-cause analysis complement disaster recovery programs by helping teams act before minor issues escalate – supporting broader goals of resilience and continuity highlighted in industry cyber and disaster recovery practices.


Teja Medasani is Principal Product Manager, AI, and Mrityunjay Upadhyay is Director, Development, at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The threat of disruption – from ransomware attacks to natural disasters – has never been greater. For businesses, downtime isn’t just an inconvenience; it’s a direct hit to revenue, reputation, and customer trust. This reality has pushed cyber resilience to the forefront of IT strategy, demanding solutions that not only protect data but also maintain its continuous availability.

HPE and Commvault are deepening their longstanding collaboration to help address this critical need. By offering HPE Zerto Software with the Commvault Cloud platform, these two industry leaders are delivering a powerful, unified solution for providing advanced cyber resilience, data protection, and disaster recovery across enterprise hybrid cloud environments.

A Leader in Continuous Data Protection 

We’re proud to announce that the HPE Zerto Software from Commvault solution is now generally available (GA) – ready for organizations everywhere. HPE Zerto Software from Commvault is a leading solution for data resilience and disaster recovery, designed to protect data and applications across multiple on-premises and cloud environments. By providing continuous data protection, HPE Zerto Software delivers near-zero data loss and downtime, enabling rapid recovery from ransomware attacks, disasters, and other disruptions.

Key features:

  • Real-time encryption to enable ransomware resilience.
  • Disaster recovery for virtualized infrastructures and cloud environments, including on-premises, public clouds (AWS, Azure), and hybrid environments. Protect workloads across different environments and cloud providers, creating a comprehensive disaster recovery solution.
  • Workload mobility delivered by simple automation and orchestration of failover, failover tests, and recovery, making it suited for cloud migrations and workload mobility.
  • Cyber resilience with a combination of regular data protection, real-time encryption detection, and immutable data recovery data.
  • Scalability and reliability with features like near-synchronous replication that can reduce recovery times significantly.

Why Commvault and HPE Zerto?

Each customer has different needs and requirements, and there is no one-size-fits-all solution. Among the factors to consider are the workload types, the size and scale of the environment, the desired recovery point objective and recovery time objective, and the cost of the solution.

Commvault is focused on delivering end-to-end solutions that not only address the operational resilience and disaster recovery needs of our customers, but also enable cyber readiness and recovery, governance and compliance, and rapid rebuilding of cloud native applications.

HPE Zerto Software from Commvault is a direct reflection of this commitment. HPE Zerto fits well within Commvault’s Autonomous Recovery offering, providing customers regular replication and operational resilience for most critical virtualized workloads that cannot afford any downtime.

Amplifying Our Strengths

This offering is a testament to the deep, strategic relationship between HPE and Commvault. We amplify each other’s portfolio strengths, creating a synergy that enhances the overall value and effectiveness of our solutions. And what we jointly offer to our customers goes beyond just data protection; it’s the confidence that comes from knowing your operations are set up to be resilient and ready to face the uncertainties of the digital age.

To learn more about early access to HPE Zerto offering from Commvault, please reach out to your account team.

Ready to Get Started?

The GA launch of HPE Zerto Software from Commvault means now is the time to act – don’t wait. Schedule a demo with your Commvault account team.

More related posts


Thumbnail_Blog_HPE-Zerta-Software-2025

HPE Zerto Software from Commvault: Enhancing Data Resilience and Disaster Recovery

Read more about HPE Zerto Software from Commvault: Enhancing Data Resilience and Disaster Recovery

Key Takeaways

  • Ransomware mirrors a hurricane lifecycle: Early warnings are often ignored, impact is paralyzing, and coordinated recovery is vital.
  • Identity systems (Active Directory and Entra ID) are frequent first casualties; without them, data recovery and access stall.
  • The cost of unpreparedness is high – weeks of downtime and seven-figure losses – making identity-centric resilience a business imperative.
  • Preparation should include clean, immutable, and air-gapped backups of AD/Entra ID plus regular full-forest recovery drills.
  • A practical blueprint – assess, protect, isolate, recover, evolve – enables faster, cleaner restoration of data, identity, and trust.

Ransomware has become the digital equivalent of a hurricane – powerful, unpredictable, and capable of wiping out years of progress in a single strike. Like natural disasters, cyber disasters are no longer if events, but when events. The question every organization must answer is not “Can we prevent the storm?” but “Will we survive and recover when it hits?”

This paper explores the parallels between ransomware and hurricanes, with a special focus on identity resilience – including Active Directory (AD) and Microsoft Entra ID. These identity systems are often the first casualties of a ransomware event. When identity is compromised, recovery stalls – just as losing your address and keys after a hurricane leaves you locked out of your own home.

1. The Parallel Between Storms and Cyberattacks

Hurricane Lifecycle
Ransomware Lifecycle
Shared Lesson
Formation: Warm waters and unstable air pressure form the perfect storm. Exposure: Unpatched systems, weak credentials, and flat networks create ideal attack conditions. Weak foundations invite disaster.
Warning: Meteorologists issue alerts days in advance. Alerts: Security Information and Event Management, Endpoint Detection and Response, and threat intelligence show early warning signs – often ignored. Detection without action is denial.
Landfall: The hurricane makes impact – power lines fall, flooding begins, and communications fail. Detonation: Malware encrypts systems, disables security tools, and shuts down AD. Both result in complete operational paralysis.
Response: First responders triage, reroute power, and rescue survivors. Response: Incident response teams isolate affected systems, assess backups, and begin recovery procedures . Speed, coordination, and clarity define success.
Recovery: Homes are rebuilt, infrastructure restored, and new defenses added. Recovery: Clean data and identity are restored, enabling business continuity. Recovery must include identity – not just data.

2. The Hidden Cost of Identity Loss

When a hurricane destroys your home, you can’t just rebuild walls – you need new keys, insurance, and documents to reclaim ownership. In a ransomware event, the same is true: Without AD or Entra ID, you can’t re-enter your own network.

Identity is the “address” of your digital home – lose it, and you’re stranded outside your own infrastructure.

3. The Cost of Unpreparedness

When hurricanes strike, unprepared communities face catastrophic loss. When ransomware strikes unprotected environments, the results are equally devastating:

Unprepared organizations struggle not only to restore data but also to rebuild trust chains between systems, domains, and users – often forcing a complete forest rebuild that takes weeks or months.

4. Lessons from the Storm: Building Cyber and Identity Resilience

A. Preparation is Prevention

  • Regularly export and validate AD system state backups and Entra ID configurations.
  • Implement role-based access and privileged identity management to limit blast radius.
  • Store clean, immutable copies of both on-prem AD and Entra ID schemas in a secure, air-gapped vault.
  • Conduct forest recovery drills that simulate full AD rebuilds.

B. Withstand the Impact

  • Segment identity infrastructure and limit replication paths.
  • Use Conditional Access and Authentication Strength policies in Entra ID to enforce adaptive protection.
  • Employ zero-trust principles to contain lateral movement and privilege escalation.

C. Recover with Confidence

  • Commvault full forest recovery helps automate the end-to-end rebuild of AD forests – restoring DCs, trusts, and configurations from clean, immutable backups.
  • Entra ID Protection integrates with recovery workflows so that cloud identities, multi-factor authentication policies, and Conditional Access settings are restored in sync.
  • Automated validation helps verify there’s no reinfection and no cross-contamination of credentials.

5. The Resilience Blueprint: From Disaster to Continuity

  • Assess: Identify your “digital coastline” – the systems and identities that define business continuity.
  • Protect: Harden your identity and data perimeter through zero trust and ongoing validation.
  • Isolate: Maintain immutable, air-gapped copies of AD, Entra ID, and critical data.
  • Recover: Use orchestrated tools like Commvault’s full forest recovery to restore identity and access rapidly.
  • Evolve: Update and retest your plan with every new patch, policy, or platform integration.

6. Commvault Perspective: Recover Faster. Recover Clean. Recover Identity.

With full forest recovery for AD and integrated Entra ID protection, Commvault helps enable organizations to restore on-prem and cloud data and identities with integrity, speed, and confidence after a ransomware incident.

A hurricane tests the strength of your walls. Ransomware tests the strength of your resilience. You cannot stop every storm – natural or digital – but you can decide whether it destroys or defines you.

FAQs

Q: What makes identity loss so disruptive during ransomware recovery?
A: If AD or Entra ID is compromised, organizations can’t authenticate, authorize, or re-establish trust across systems – effectively locking themselves out of their own environment. Attackers often target domain controllers and trust relationships, so recovery must start with clean identity restoration before broader services can come back online.

Q: How big is the downtime and cost risk?
A: The paper cites typical ransomware downtime measured in weeks and total incident costs in the seven-figure range, with identity systems among top targets. These impacts compound when teams lack forest-level recovery capabilities or clean, immutable backups of identity configurations.

Q: What preparation steps most effectively reduce impact?
A: Regularly export and validate AD system-state and Entra ID configurations; apply role-based access and privileged identity management; keep immutable, air-gapped copies of identity schemas; and run full-forest recovery exercises to validate speed and coordination under pressure.

Q: How should recovery be orchestrated after an attack?
A: Start by isolating affected systems and pivot immediately to identity restoration from clean, immutable backups, then rebuild domain controllers, trusts, and policies in sync with cloud identity settings. Automated validation helps confirm a clean state and prevents credential cross-contamination during bring-up.

Q: What does a resilience blueprint look like in practice?
A: Follow five steps: Assess critical “digital coastline,” protect with Zero Trust and continuous validation, isolate with immutable air-gapped copies, recover with orchestrated full-forest workflows, and evolve by testing after every change in patches, policies, or platform integrations.

Jerry Carlson is Field CTO at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Ransomware-and-Hurricane-2025

Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

Read more about Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

Key Takeaways

  • Ransomware mirrors a hurricane lifecycle: Early warnings are often ignored, impact is paralyzing, and coordinated recovery is vital.
  • Identity systems (Active Directory and Entra ID) are frequent first casualties; without them, data recovery and access stall.
  • The cost of unpreparedness is high – weeks of downtime and seven-figure losses – making identity-centric resilience a business imperative.
  • Preparation should include clean, immutable, and air-gapped backups of AD/Entra ID plus regular full-forest recovery drills.
  • A practical blueprint – assess, protect, isolate, recover, evolve – enables faster, cleaner restoration of data, identity, and trust.

Ransomware has become the digital equivalent of a hurricane – powerful, unpredictable, and capable of wiping out years of progress in a single strike. Like natural disasters, cyber disasters are no longer if events, but when events. The question every organization must answer is not “Can we prevent the storm?” but “Will we survive and recover when it hits?”

This paper explores the parallels between ransomware and hurricanes, with a special focus on identity resilience – including Active Directory (AD) and Microsoft Entra ID. These identity systems are often the first casualties of a ransomware event. When identity is compromised, recovery stalls – just as losing your address and keys after a hurricane leaves you locked out of your own home.

1. The Parallel Between Storms and Cyberattacks

Hurricane Lifecycle
Ransomware Lifecycle
Shared Lesson
Formation: Warm waters and unstable air pressure form the perfect storm. Exposure: Unpatched systems, weak credentials, and flat networks create ideal attack conditions. Weak foundations invite disaster.
Warning: Meteorologists issue alerts days in advance. Alerts: Security Information and Event Management, Endpoint Detection and Response, and threat intelligence show early warning signs – often ignored. Detection without action is denial.
Landfall: The hurricane makes impact – power lines fall, flooding begins, and communications fail. Detonation: Malware encrypts systems, disables security tools, and shuts down AD. Both result in complete operational paralysis.
Response: First responders triage, reroute power, and rescue survivors. Response: Incident response teams isolate affected systems, assess backups, and begin recovery procedures . Speed, coordination, and clarity define success.
Recovery: Homes are rebuilt, infrastructure restored, and new defenses added. Recovery: Clean data and identity are restored, enabling business continuity. Recovery must include identity – not just data.

2. The Hidden Cost of Identity Loss

When a hurricane destroys your home, you can’t just rebuild walls – you need new keys, insurance, and documents to reclaim ownership. In a ransomware event, the same is true: Without AD or Entra ID, you can’t re-enter your own network.

Identity is the “address” of your digital home – lose it, and you’re stranded outside your own infrastructure.

3. The Cost of Unpreparedness

When hurricanes strike, unprepared communities face catastrophic loss. When ransomware strikes unprotected environments, the results are equally devastating:

Unprepared organizations struggle not only to restore data but also to rebuild trust chains between systems, domains, and users – often forcing a complete forest rebuild that takes weeks or months.

4. Lessons from the Storm: Building Cyber and Identity Resilience

A. Preparation is Prevention

  • Regularly export and validate AD system state backups and Entra ID configurations.
  • Implement role-based access and privileged identity management to limit blast radius.
  • Store clean, immutable copies of both on-prem AD and Entra ID schemas in a secure, air-gapped vault.
  • Conduct forest recovery drills that simulate full AD rebuilds.

B. Withstand the Impact

  • Segment identity infrastructure and limit replication paths.
  • Use Conditional Access and Authentication Strength policies in Entra ID to enforce adaptive protection.
  • Employ zero-trust principles to contain lateral movement and privilege escalation.

C. Recover with Confidence

  • Commvault full forest recovery helps automate the end-to-end rebuild of AD forests – restoring DCs, trusts, and configurations from clean, immutable backups.
  • Entra ID Protection integrates with recovery workflows so that cloud identities, multi-factor authentication policies, and Conditional Access settings are restored in sync.
  • Automated validation helps verify there’s no reinfection and no cross-contamination of credentials.

5. The Resilience Blueprint: From Disaster to Continuity

  • Assess: Identify your “digital coastline” – the systems and identities that define business continuity.
  • Protect: Harden your identity and data perimeter through zero trust and ongoing validation.
  • Isolate: Maintain immutable, air-gapped copies of AD, Entra ID, and critical data.
  • Recover: Use orchestrated tools like Commvault’s full forest recovery to restore identity and access rapidly.
  • Evolve: Update and retest your plan with every new patch, policy, or platform integration.

6. Commvault Perspective: Recover Faster. Recover Clean. Recover Identity.

With full forest recovery for AD and integrated Entra ID protection, Commvault helps enable organizations to restore on-prem and cloud data and identities with integrity, speed, and confidence after a ransomware incident.

A hurricane tests the strength of your walls. Ransomware tests the strength of your resilience. You cannot stop every storm – natural or digital – but you can decide whether it destroys or defines you.

FAQs

Q: What makes identity loss so disruptive during ransomware recovery?
A: If AD or Entra ID is compromised, organizations can’t authenticate, authorize, or re-establish trust across systems – effectively locking themselves out of their own environment. Attackers often target domain controllers and trust relationships, so recovery must start with clean identity restoration before broader services can come back online.

Q: How big is the downtime and cost risk?
A: The paper cites typical ransomware downtime measured in weeks and total incident costs in the seven-figure range, with identity systems among top targets. These impacts compound when teams lack forest-level recovery capabilities or clean, immutable backups of identity configurations.

Q: What preparation steps most effectively reduce impact?
A: Regularly export and validate AD system-state and Entra ID configurations; apply role-based access and privileged identity management; keep immutable, air-gapped copies of identity schemas; and run full-forest recovery exercises to validate speed and coordination under pressure.

Q: How should recovery be orchestrated after an attack?
A: Start by isolating affected systems and pivot immediately to identity restoration from clean, immutable backups, then rebuild domain controllers, trusts, and policies in sync with cloud identity settings. Automated validation helps confirm a clean state and prevents credential cross-contamination during bring-up.

Q: What does a resilience blueprint look like in practice?
A: Follow five steps: Assess critical “digital coastline,” protect with Zero Trust and continuous validation, isolate with immutable air-gapped copies, recover with orchestrated full-forest workflows, and evolve by testing after every change in patches, policies, or platform integrations.

Jerry Carlson is Field CTO at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Ransomware-and-Hurricane-2025

Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

Read more about Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

University of Illinois Chicago (UIC) is home to more than 34,000 students and 13,000 faculty and staff. Technology Solutions, UIC’s central IT organization, is responsible for ensuring the resilience of research, clinical, and administrative systems.

We spoke with Dean Dang, Director of Enterprise Applications and Services, about UIC’s data protection journey and how Commvault helps the university safeguard mission-critical operations.

 

Q: Can you start by introducing yourself and giving us a sense of UIC’s mission and what drives your IT strategy?

Dean: My name is Dean Dang, and I serve as the Director of Enterprise Applications and Services within Technology Solutions. We support the university’s administrative and academic functions, aligning IT with UIC’s mission: to provide the broadest access to the highest levels of educational, research, and clinical excellence. Our commitment to access, vitality, empowerment, and creativity is our strength.

 

Q: Before onboarding Commvault, what were the biggest data protection and resilience challenges UIC was up against?

Dean: Our legacy backup system, Spectrum Protect, had accumulated years of technical debt. Recovery was painfully slow — restoring large file servers could take weeks. We also dealt with decentralized IT management across 20+ departments, inconsistent backup policies, inefficient tape storage, and no cloud options. The risks of data loss and downtime were too high for a university of our size.

 

Q: When it came time to modernize, what stood out about Commvault that made it the right fit for UIC?

Dean: We’d known Commvault for over a decade and trusted it for Active Directory and Exchange backups. When we evaluated options, Commvault stood out. The ability to take VM snapshots without server agents was huge. Even more important was the multi-tenant model. It let us provide departmental autonomy while maintaining centralized governance and support — exactly what higher ed needs.

 

Q: What changes have you seen since implementing Commvault, and how has it elevated UIC’s cyber resilience?

Dean: With Commvault, we do nightly backups with deduplication and synthetic fulls. That reduces storage demand and speeds up restores. Departments get their own “tenants” to manage backups, but we still enforce policies and provide support. All backups are encrypted and can be stored on-prem or in the cloud.

We also use Air Gap Protect for immutable copies and Cleanroom Recovery for safe recovery testing. This setup means we can recover mission-critical systems in under 8 hours — compared to days or weeks before.

 

Q: If you were talking to other higher-ed IT leaders, what top lessons or best practices would you share about building cyber resilience?

Dean:

  1. Enforce multifactor authentication everywhere, especially admin accounts. Everyone can be phished.
  2. Build a pragmatic, team-driven DR plan. Don’t try to solve everything at once — build consensus and clarity.
  3. Test nightly backups. Make them immutable, air-gapped, and validated so you know you can restore when it matters.

 

Q: How do you communicate cyber risks to non-technical leaders?

Dean: We translate risk into business terms. How many hours of downtime? What does that cost in productivity, reputation, and compliance? We use “what if” scenarios, dashboards, and regular updates on metrics like backup health and restore times. When leaders see the financial and mission impact, the case for resilience is clear.

 

Q: Looking ahead, how does Commvault fit into UIC’s long-term strategy?

Dean: UIC is hybrid — on-campus, cloud, and SaaS. Commvault covers all of it, from VMs and databases to M365 and even emerging AI workloads. With 95%+ deduplication and tiered storage, we keep costs under control. And with anomaly detection, automation, and cleanroom testing, we’re preparing for a future where downtime is measured in hours, not days.

Read more about the University of Illinois of Chicago’s data protection journey here.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

University of Illinois Chicago (UIC) is home to more than 34,000 students and 13,000 faculty and staff. Technology Solutions, UIC’s central IT organization, is responsible for ensuring the resilience of research, clinical, and administrative systems.

We spoke with Dean Dang, Director of Enterprise Applications and Services, about UIC’s data protection journey and how Commvault helps the university safeguard mission-critical operations.

 

Q: Can you start by introducing yourself and giving us a sense of UIC’s mission and what drives your IT strategy?

Dean: My name is Dean Dang, and I serve as the Director of Enterprise Applications and Services within Technology Solutions. We support the university’s administrative and academic functions, aligning IT with UIC’s mission: to provide the broadest access to the highest levels of educational, research, and clinical excellence. Our commitment to access, vitality, empowerment, and creativity is our strength.

 

Q: Before onboarding Commvault, what were the biggest data protection and resilience challenges UIC was up against?

Dean: Our legacy backup system, Spectrum Protect, had accumulated years of technical debt. Recovery was painfully slow — restoring large file servers could take weeks. We also dealt with decentralized IT management across 20+ departments, inconsistent backup policies, inefficient tape storage, and no cloud options. The risks of data loss and downtime were too high for a university of our size.

 

Q: When it came time to modernize, what stood out about Commvault that made it the right fit for UIC?

Dean: We’d known Commvault for over a decade and trusted it for Active Directory and Exchange backups. When we evaluated options, Commvault stood out. The ability to take VM snapshots without server agents was huge. Even more important was the multi-tenant model. It let us provide departmental autonomy while maintaining centralized governance and support — exactly what higher ed needs.

 

Q: What changes have you seen since implementing Commvault, and how has it elevated UIC’s cyber resilience?

Dean: With Commvault, we do nightly backups with deduplication and synthetic fulls. That reduces storage demand and speeds up restores. Departments get their own “tenants” to manage backups, but we still enforce policies and provide support. All backups are encrypted and can be stored on-prem or in the cloud.

We also use Commvault Air Gap for immutable copies and Commvault Cleanroom for safe recovery testing. This setup means we can recover mission-critical systems in under 8 hours — compared to days or weeks before.

 

Q: If you were talking to other higher-ed IT leaders, what top lessons or best practices would you share about building cyber resilience?

Dean:

  1. Enforce multifactor authentication everywhere, especially admin accounts. Everyone can be phished.
  2. Build a pragmatic, team-driven DR plan. Don’t try to solve everything at once — build consensus and clarity.
  3. Test nightly backups. Make them immutable, air-gapped, and validated so you know you can restore when it matters.

 

Q: How do you communicate cyber risks to non-technical leaders?

Dean: We translate risk into business terms. How many hours of downtime? What does that cost in productivity, reputation, and compliance? We use “what if” scenarios, dashboards, and regular updates on metrics like backup health and restore times. When leaders see the financial and mission impact, the case for resilience is clear.

 

Q: Looking ahead, how does Commvault fit into UIC’s long-term strategy?

Dean: UIC is hybrid — on-campus, cloud, and SaaS. Commvault covers all of it, from VMs and databases to M365 and even emerging AI workloads. With 95%+ deduplication and tiered storage, we keep costs under control. And with anomaly detection, automation, and cleanroom testing, we’re preparing for a future where downtime is measured in hours, not days.

Read more about the University of Illinois of Chicago’s data protection journey here.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The psychologist Abraham Maslow famously said that if the only tool you have is a hammer, you tend to see every problem as a nail. And everywhere you look these days, companies are wielding AI like a hammer, hoping it can solve all their pressing business problems: “How can we use AI? How can we sell AI? How can we make money on AI?”

But here’s the thing – if you’re starting with those questions, you’re starting with a broken assumption. The right question isn’t “How do we use/sell/make a fortune with AI?” The right question is “What problems are we trying to solve?”

What Problem Are You Solving?

Technology should make us more capable of doing uniquely human work, not replace our capacity to think, create, and connect with each other. The approach of starting with the tool instead of the problem is why we’re seeing many AI implementations stall. Companies are throwing technology at problems they haven’t properly defined or understood.

The approach I recommend to any leader considering AI: Start by listing your actual problems. Not theoretical problems, not problems you think you should have, but the real pain points keeping your teams from working fast. Then ask: What tools do I have that can help solve these problems? AI might be one of those tools. It makes sense to explore AI solutions for tedious, repeatable, manual tasks. You likely can identify those opportunities in your organization easily.

But let’s say your employee engagement is suffering, and people have expressed needing better support during difficult times. You want human connection and emotional intelligence here, not algorithmic responses. Starting with the problem helps reveal the appropriate solution.

Should We Engineer Out the Human Element?

Today, AI excels at automating repetitive tasks – the digital equivalent of assembly line work. If your backup administrators are turning the same widgets over and over, or your data entry teams are focused on purely laborious spreadsheet work, AI absolutely can help. But I believe relationship building, creative problem-solving, and complex decision-making require human judgment, intuition, and contextual understanding that no algorithm today can yet replicate.

At Commvault, we’re committed to the ethical development and deployment of AI. We’ve employed it for tasks like turning complex regulatory documents into succinct summaries or helping create targeted versions of content. Saving this time for employees to focus on more value-added activities. None of this work happens without careful human oversight.

The companies I see succeeding understand this distinction. They use AI to eliminate tedious tasks so workers can focus on what humans do best: nuanced decision-making, building trust, navigating complex stakeholder relationships, and thinking through problems that don’t have clear precedents.

A Framework for Smart AI Adoption

Before implementing any AI solution, leadership teams should ask themselves these questions:

  1. What specific problem are we solving? Be concrete. “We want to be more efficient” isn’t specific enough.
    Try: “We want to automate X.”
  2. Why is this problem worth solving? What’s the real business impact?
  3. Where do we need human judgment to remain in the loop? Identify the decision points, beyond just high-risk scenarios, that demand wisdom, not just intelligence.
  4. How will we measure success? Not just adoption rates, but actual problem resolution.
  5. Revisit the conversation. Successful AI adoption is not a point-in-time measurement.

Read more in Guiding Principles for Responsible AI.

The Path Forward

Make time to establish procedures for data handling, privacy protection, and decision-making authority. Who controls what information gets fed into AI systems? What data absolutely cannot be uploaded to external AI platforms? How do you prevent customer data from being used to train models?

When you put information into an AI system, you may be sharing it not only with that vendor, but also with its cloud providers, sub-processors, and others in its data supply chain. A secret known by more than three people isn’t a secret anymore – so be careful before you hand yours to dozens of entities.

Learn more about Commvault’s approach at Principles for Responsible Artificial Intelligence.

Danielle Sheer is Chief Trust Officer at Commvault.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We are in the most consequential moment of change in our industry, with the widespread adoption of AI reshaping how enterprises operate, how data flows, and how decisions are made.

This introduces new challenges and vulnerabilities for you to manage. Like the explosive growth of data; the evolving governance requirements for human and non-human identities; and new threats to AI-oriented identities, supply chains, and models.

To make matters worse, the pressure is on you and your teams to enable your business to embrace AI with data that’s distributed and fragmented across clouds, applications, and endpoints. All of which introduces business risk while increasing the fragility of your AI systems.

In anticipation of this evolution, Commvault has been broadening its industry-leading resilience focus to help you to secure data at source; to control identity access; and predictably and cleanly recover following an inevitable cyberattack or disruption.

We call it ResOps, or resilience operations. It’s not a product – it’s a new operational approach that enables you to actively manage resilience across increasingly complex emerging AI environments.

As you know, Commvault always has been obsessed with solving our customers’ most significant resilience challenges with elegant and innovative solutions. And today, we are taking it even further with the introduction of Commvault Cloud Unity – our next-gen platform to enable ResOps.

The platform was built from the ground up to help unify previously disparate data security, identity, and recovery processes across today’s workloads and tomorrow’s emerging AI stacks. It no longer matters where your data lives – if it’s on-prem, cloud-bound, cloud-borne, or an emerging AI workload.

In fact, Commvault has the broadest workload support. Across the multi-cloud alone, we cover more than 160 regions and over 200 public cloud services. And we simply manage it all through a single policy engine and a unified pane of glass.

None of this would have been possible without our team’s foresight, engineering prowess, and commitment to continuously innovating to solve our customers’ hardest challenges.

Want to learn more about ResOps and Commvault Cloud Unity? Click here to watch Commvault’s SHIFT event on demand, and read our whitepaper ResOps: The Future of Resilient Business in the Era of AI.


Sanjay Mirchandani is President & Chief Executive Officer of Commvault.

More related posts


Thumbnail_Blog-SHIFT-Sanjay-2025-Linkedin

Re-envisioning Resilience for the Age of AI

Read more about Re-envisioning Resilience for the Age of AI

Key Takeaways

  • Streamlined process: Simplifies recovery through enhanced threat detection and validation.
  • Integrated experience: One simple process from threat identification to production recovery.
  • Readiness: Configure, plan, and test cyber recovery plans to uncover gaps.
  • Rapid detection and validation: Quickly identify clean points and validate recovery.
  • Confident recovery: Helps organizations confidently recover clean data, apps, and infrastructure.

In today’s landscape of relentless cyber threats, organizations are grappling with an unprecedented challenge: maintaining business continuity in the face of potential data loss and system compromise. The recent surge in sophisticated ransomware attacks has underscored the critical need for robust cyber resilience strategies that go beyond traditional backup and recovery methods.

Commvault Cloud Cleanroom Recovery introduces an innovative approach to this challenge. By creating an on-demand, secure, and isolated environment, organizations can test their recovery plans, conduct thorough forensic investigations, and execute production recoveries without risking further disruption to their operations.

Cyber Recovery Readiness/Testing + Forensics = Optimal Recovery

Ransomware threats targeting backup systems have become increasingly common, highlighting the vulnerabilities in conventional recovery processes. It’s no longer sufficient to simply have a recovery plan in place; organizations must rigorously test and validate their strategies to prepare to withstand real-world cyberattacks.

Cleanroom Recovery can help organizations seeking to maintain uninterrupted operations amid disruption. Testing your cyber recovery plans is a huge part of achieving true cyber resilience. By facilitating rapid and reliable recovery, minimizing downtime, and streamlining processes, testing plays a vital role to strengthen business continuity.

As organizations continue to prioritize robust cyber recovery plans, the importance of rigorous testing cannot be overstated. With effective testing protocols in place, organizations can identify vulnerabilities and verify their recovery strategies remain aligned with evolving cyber threats.

Once an organization has set up regular malware scanning of all backups and tested its plans, it can conduct forensics analysis to identify the root cause of an attack and investigate any affected systems. These two use cases increase confidence in executing an optimal recovery.

What’s New in Cleanroom Recovery?

Building on its foundation, the latest Cleanroom Recovery innovations are introducing significant enhancements that further strengthen cyber recovery capabilities. These advancements deliver new capabilities that help organizations protect their critical infrastructure and data.

Recent and upcoming developments have bolstered Cleanroom Recovery’s capabilities in orchestration, security, and scalability, including early access to:

  • Cleanroom creation automation: Automate cleanroom deployment, cross hypervisor recovery and threat scanning inside the cleanroom to remove manual intervention​. (Generally Available)
  • Runbook experience: Ability to create multiple runbooks for critical assets for different use cases. Runbooks provide step-by-step execution playbooks with optional manual steps.​ (Early Access)
  • Expanded workload support: You can recover Active Directory forest along with VMs and files into a cleanroom for end-to-end application validation. ​(Early Access)
  • On-premises deployment capabilities: You now can use Cleanroom Recovery to recover critical application into an isolated recovery environment in an on-premises data center using air-gapped Hyperscale X (Early Access)

These advancements illustrate a continued focus on expanding the features, capabilities, and scale of Cleanroom Recovery. This is the next phase in Cleanroom Recovery’s evolution. The solution helps provide customers with enhanced efficiency, scalability, and adaptability, with the flexibility to deploy isolated cleanroom in cloud and on-premises.

Cleanroom Recovery helps enable customers to effortlessly spin up automated cleanrooms with streamlined runbooks and features threat scanning capabilities for comprehensive threat detection and recovery.

With this new evolution, organizations will be enabled to quickly and safely test their cyber recovery plans, validate applications, and execute a confident cyber recovery. Commvault is delivering one integrated experience from identifying threats to production recovery.

FAQs

Q: What is Cleanroom Recovery, and why is it important?
A: Cleanroom Recovery is a secure, isolated environment that enables organizations to test recovery plans and conduct forensic analysis without risking production systems. This helps organizations maintain continuous business operations and improve cyber resilience against modern ransomware threats.

Q: How does Cleanroom Recovery enhance cyber recovery readiness?
A: By automating cleanroom creation to conduct recovery testing and enabling forensic investigation, it helps organizations validate their recovery strategies, uncover vulnerabilities, and execute faster, more confident recoveries after cyber incidents.

Q: What are the main new features in the Cleanroom Recovery release?
A: Key innovations include automated cleanroom deployment, new runbook capabilities for multiple recovery scenarios, support for Active Directory recovery, and the ability to deploy in on-premises data centers with air-gapped Hyperscale X.

Q: How does Cleanroom Recovery improve security during recovery operations?
A: It isolates the recovery environment, scans for threats pre-/post-recovery, provides controlled orchestration, and helps reduce the risk of reinfection or unauthorized access during recovery.

Q: Can Cleanroom Recovery be deployed both on-premises and in the cloud?
A: Yes, organizations now can deploy Cleanroom Recovery in both cloud and on-premises environments, providing flexibility for hybrid infrastructures and diverse security requirements.

Q: Who benefits most from Cleanroom Recovery?
A: Enterprises seeking to strengthen their cyber resilience, particularly those facing ransomware risks or complex recovery needs, gain value from its automation, scalability, and integrated testing capabilities.

Toussaint Brock is a Product Marketing Manager at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We are in the most consequential moment of change in our industry, with the widespread adoption of AI reshaping how enterprises operate, how data flows, and how decisions are made.

This introduces new challenges and vulnerabilities for you to manage. Like the explosive growth of data; the evolving governance requirements for human and non-human identities; and new threats to AI-oriented identities, supply chains, and models.

To make matters worse, the pressure is on you and your teams to enable your business to embrace AI with data that’s distributed and fragmented across clouds, applications, and endpoints. All of which introduces business risk while increasing the fragility of your AI systems.

In anticipation of this evolution, Commvault has been broadening its industry-leading resilience focus to help you to secure data at source; to control identity access; and predictably and cleanly recover following an inevitable cyberattack or disruption.

We call it ResOps, or resilience operations. It’s not a product – it’s a new operational approach that enables you to actively manage resilience across increasingly complex emerging AI environments.

As you know, Commvault always has been obsessed with solving our customers’ most significant resilience challenges with elegant and innovative solutions. And today, we are taking it even further with the introduction of Commvault Cloud Unity – our next-gen platform to enable ResOps.

The platform was built from the ground up to help unify previously disparate data security, identity, and recovery processes across today’s workloads and tomorrow’s emerging AI stacks. It no longer matters where your data lives – if it’s on-prem, cloud-bound, cloud-borne, or an emerging AI workload.

In fact, Commvault has the broadest workload support. Across the multi-cloud alone, we cover more than 160 regions and over 200 public cloud services. And we simply manage it all through a single policy engine and a unified pane of glass.

None of this would have been possible without our team’s foresight, engineering prowess, and commitment to continuously innovating to solve our customers’ hardest challenges.

Want to learn more about ResOps and Commvault Cloud Unity? Click here to watch Commvault’s SHIFT event on demand, and read our whitepaper ResOps: The Future of Resilient Business in the Era of AI.


Sanjay Mirchandani is President & Chief Executive Officer of Commvault.

More related posts


Thumbnail_Blog-SHIFT-Sanjay-2025-Linkedin

Re-envisioning Resilience for the Age of AI

Read more about Re-envisioning Resilience for the Age of AI

Key Takeaways

  • Streamlined process: Simplifies recovery through enhanced threat detection and validation.
  • Integrated experience: One simple process from threat identification to production recovery.
  • Readiness: Configure, plan, and test cyber recovery plans to uncover gaps.
  • Rapid detection and validation: Quickly identify clean points and validate recovery.
  • Confident recovery: Helps organizations confidently recover clean data, apps, and infrastructure.

In today’s landscape of relentless cyber threats, organizations are grappling with an unprecedented challenge: maintaining business continuity in the face of potential data loss and system compromise. The recent surge in sophisticated ransomware attacks has underscored the critical need for robust cyber resilience strategies that go beyond traditional backup and recovery methods.

Commvault Cloud Cleanroom Recovery introduces an innovative approach to this challenge. By creating an on-demand, secure, and isolated environment, organizations can test their recovery plans, conduct thorough forensic investigations, and execute production recoveries without risking further disruption to their operations.

Cyber Recovery Readiness/Testing + Forensics = Optimal Recovery

Ransomware threats targeting backup systems have become increasingly common, highlighting the vulnerabilities in conventional recovery processes. It’s no longer sufficient to simply have a recovery plan in place; organizations must rigorously test and validate their strategies to prepare to withstand real-world cyberattacks.

Cleanroom Recovery can help organizations seeking to maintain uninterrupted operations amid disruption. Testing your cyber recovery plans is a huge part of achieving true cyber resilience. By facilitating rapid and reliable recovery, minimizing downtime, and streamlining processes, testing plays a vital role to strengthen business continuity.

As organizations continue to prioritize robust cyber recovery plans, the importance of rigorous testing cannot be overstated. With effective testing protocols in place, organizations can identify vulnerabilities and verify their recovery strategies remain aligned with evolving cyber threats.

Once an organization has set up regular malware scanning of all backups and tested its plans, it can conduct forensics analysis to identify the root cause of an attack and investigate any affected systems. These two use cases increase confidence in executing an optimal recovery.

What’s New in Cleanroom Recovery?

Building on its foundation, the latest Cleanroom Recovery innovations are introducing significant enhancements that further strengthen cyber recovery capabilities. These advancements deliver new capabilities that help organizations protect their critical infrastructure and data.

Recent and upcoming developments have bolstered Cleanroom Recovery’s capabilities in orchestration, security, and scalability, including early access to:

  • Cleanroom creation automation: Automate cleanroom deployment, cross hypervisor recovery and threat scanning inside the cleanroom to remove manual intervention​. (Generally Available)
  • Runbook experience: Ability to create multiple runbooks for critical assets for different use cases. Runbooks provide step-by-step execution playbooks with optional manual steps.​ (Early Access)
  • Expanded workload support: You can recover Active Directory forest along with VMs and files into a cleanroom for end-to-end application validation. ​(Early Access)
  • On-premises deployment capabilities: You now can use Cleanroom Recovery to recover critical application into an isolated recovery environment in an on-premises data center using air-gapped Commvault Grid (Early Access)

These advancements illustrate a continued focus on expanding the features, capabilities, and scale of Cleanroom Recovery. This is the next phase in Cleanroom Recovery’s evolution. The solution helps provide customers with enhanced efficiency, scalability, and adaptability, with the flexibility to deploy isolated cleanroom in cloud and on-premises.

Cleanroom Recovery helps enable customers to effortlessly spin up automated cleanrooms with streamlined runbooks and features threat scanning capabilities for comprehensive threat detection and recovery.

With this new evolution, organizations will be enabled to quickly and safely test their cyber recovery plans, validate applications, and execute a confident cyber recovery. Commvault is delivering one integrated experience from identifying threats to production recovery.

FAQs

Q: What is Cleanroom Recovery, and why is it important?
A: Cleanroom Recovery is a secure, isolated environment that enables organizations to test recovery plans and conduct forensic analysis without risking production systems. This helps organizations maintain continuous business operations and improve cyber resilience against modern ransomware threats.

Q: How does Cleanroom Recovery enhance cyber recovery readiness?
A: By automating cleanroom creation to conduct recovery testing and enabling forensic investigation, it helps organizations validate their recovery strategies, uncover vulnerabilities, and execute faster, more confident recoveries after cyber incidents.

Q: What are the main new features in the Cleanroom Recovery release?
A: Key innovations include automated cleanroom deployment, new runbook capabilities for multiple recovery scenarios, support for Active Directory recovery, and the ability to deploy in on-premises data centers with air-gapped Commvault Grid.

Q: How does Cleanroom Recovery improve security during recovery operations?
A: It isolates the recovery environment, scans for threats pre-/post-recovery, provides controlled orchestration, and helps reduce the risk of reinfection or unauthorized access during recovery.

Q: Can Cleanroom Recovery be deployed both on-premises and in the cloud?
A: Yes, organizations now can deploy Cleanroom Recovery in both cloud and on-premises environments, providing flexibility for hybrid infrastructures and diverse security requirements.

Q: Who benefits most from Cleanroom Recovery?
A: Enterprises seeking to strengthen their cyber resilience, particularly those facing ransomware risks or complex recovery needs, gain value from its automation, scalability, and integrated testing capabilities.

Toussaint Brock is a Product Marketing Manager at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • The Commvault Cloud Unity platform release is an AI-enabled platform that unifies data security, cyber recovery, and identity resilience across all environments – from cloud to on-premises.
  • It helps eliminate silos between security, identity, and recovery tools, enabling faster, smarter, and more reliable protection.
  • Commvault’s Synthetic Recovery™ uses AI to surgically remove compromised data and restore clean data quickly.
  • Integrated Identity Resilience detects and rolls back malicious changes to critical systems like Active Directory.
  • With built-in intelligence, Commvault Cloud continuously learns from threats, making enterprise resilience proactive and adaptive.

Today, we’re thrilled to announce the Commvault Cloud Unity platform release, our next-generation, AI-enabled platform designed to unify data security, cyber recovery, and identity resilience across every environment your business runs on – cloud, SaaS, on-premises, and hybrid.

For years, IT and security teams have been fighting an uphill battle. Data is growing faster than ever, AI is generating it at lightning speed, and bad actors are taking full advantage. Meanwhile, enterprises are forced to stitch together countless security tools and recovery solutions that don’t talk to each other. The result? More silos, more risk, and slower recoveries when time matters most.

The Commvault Cloud Unity platform release helps change that.

This isn’t just another platform release. It’s a redefinition of what resilience means in the AI era.

Why We Built the Commvault Cloud Unity Platform Release

Every business today faces a perfect storm of challenges:

  • Explosive data growth fueled by AI and distributed work.
  • Disjointed tools for data protection, security, and identity management.
  • Complex environments that span cloud, SaaS, edge, and on-prem.

These are problems we’ve seen firsthand – and we knew the answer wasn’t another tool. It was a unified platform that could simplify and strengthen resilience at its core.

So, we created the Commvault Cloud Unity platform release: the first truly unified resilience platform that brings together data security, cyber recovery, and identity protection – all under one intelligent control plane.

“Today enterprises are facing the perfect storm: non-stop cyber threats, exacerbated by AI; attacks on identity systems that paralyze organizations; and recovery challenges that impact revenues and reputations,” said Pranay Ahlawat, Chief Technology and AI Officer at Commvault. “Commvault brought together the best engineering minds in the business and is debuting a transformative platform release that not only unifies resilience across disciplines and environments but helps drive business outcomes that can redefine new benchmarks in the industry.”

What Makes Commvault Cloud … Unified

Let’s break down what makes this next generation of Commvault Cloud so different – and so powerful.

  1. Data Security That Sees Everything

Commvault Cloud helps you stay a step ahead of risk with AI-enabled discovery, classification, and protection across all your data. It learns what’s sensitive, recommends protection policies, and enforces them automatically.

With our recent integration of Satori Cyber, Commvault Cloud now brings data and AI access governance into the fold – adding even more visibility and control over how your data is used, shared, and protected.

  1. Cyber Recovery That’s Redefined

Traditional recovery methods can take hours or days – time your business can’t afford during an attack. Commvault introduces Synthetic Recovery, an AI-enabled approach that surgically removes compromised data and helps recover everything else cleanly.

This means you’re not just restoring data – you’re restoring trust. Fast.

  1. Identity Resilience Built In

When identity systems like Active Directory go down, entire organizations can grind to a halt. Commvault Cloud’s Identity Resilience capabilities detect hidden threats in those systems and can rapidly roll back malicious changes, restoring access and productivity quickly.

Commvault makes identity protection part of your overall resilience strategy – not an afterthought.

  1. Unified Governance for a Unified World

Security, identity, and recovery teams have long operated in silos – each with their own tools, dashboards, and processes. The Commvault Cloud Unity platform release brings them together.

Now, you can monitor, enforce, and respond to threats across your entire ecosystem from one place. That means faster response times, cleaner recoveries, and a single version of the truth for all your resilience data.

  1. Intelligence That Gets Smarter Every Day

By combining insights from data security, identity behavior, and recovery operations, the Commvault Cloud Unity platform release delivers AI-enabled intelligence that helps you not just react to threats – but predict and prevent them.

This unified intelligence layer drives automation across the platform, helping enterprises achieve the cleanest, fastest, and most complete recoveries possible.

Built for Every Environment – and Every Team

One of Commvault Cloud’s biggest strengths is its flexibility. Whether your business runs entirely in the cloud, stays on-prem, or operates in a hybrid model, Commvault Cloud fits right in.

From protecting Microsoft 365 and Google Workspace to securing DevOps environments like GitHub, GitLab, and Azure DevOps, the Commvault Cloud Unity platform release brings resilience to the tools your teams already rely on.

We’re even extending protection to CRM systems like Salesforce and Dynamics 365 – and expanding across platforms like Atlassian, Jira, Slack, and Power Apps.

This is what we mean when we say Commvault Cloud helps deliver one of the most comprehensive SaaS protection portfolios in the industry – unified and built to grow with you.

Designed for the AI Era

AI isn’t just part of Commvault Cloud – it’s at the heart of it.

From intelligent threat detection and automated policy enforcement to recovery workflows that optimize themselves, Commvault Cloud uses AI to make resilience proactive, adaptive, and continuous.

That’s what we call AI-enabled unified resilience – the ability to not just bounce back from disruption, but to get smarter every time it happens.

The Future Is Unified

The Commvault Cloud Unity platform release isn’t just about solving today’s problems – it’s about preparing for tomorrow’s.

By unifying data security, cyber recovery, and identity resilience under one intelligent platform, we’re giving enterprises a new way to protect what matters most – their data, their operations, and their future.

In short: Commvault Cloud simplifies resilience. And more importantly, it redefines it.

FAQs

Q: What is the Commvault Cloud Unity platform release?
A: The Commvault Cloud Unity platform release is a next-generation resilience platform that unifies data security, cyber recovery, and identity protection into a single AI-enabled solution. It allows organizations to protect, recover, and manage data across cloud, SaaS, hybrid, and on-prem environments.

Q: How does Synthetic Recovery™ work?
A: Synthetic Recovery™ uses AI to analyze affected systems, isolate compromised data, and restore only verified clean data. This shortens recovery time and helps organizations rebuild trust after a cyberattack faster than traditional methods.

Q: What makes the Commvault Cloud Unity platform release different from other resilience or backup platforms?
A: Unlike siloed tools that manage data protection, security, and identity separately, the Commvault Cloud Unity platform release combines them into one intelligent control plane. This unified governance enables real-time visibility, faster response, and stronger compliance across the enterprise.

Q: How does Commvault Cloud enhance identity resilience?
A: Commvault Cloud Identity Resilience actively monitors identity systems like Active Directory for malicious changes, detects potential threats, and can rapidly roll back compromised accounts or configurations – letting employees regain safe access quickly.

Q: Is the Commvault Cloud Unity platform release compatible with existing business tools and cloud platforms?
A: Yes. Commvault Cloud integrates with platforms like Microsoft 365, Google Workspace, Salesforce, GitHub, Jira, and more, providing broad SaaS and hybrid protection that grows with your organization’s needs.

Kristin Flandreau is Senior Director, Product & Customer Marketing, at Commvault.

More related posts


Thumbnail_Blog-SHIFT-Announcement-Recover-Clean-2025-Linkedin

Recover Clean, Recover Fast

Read more about Recover Clean, Recover Fast
Thumbnail_Blog-SHIFT-Announcement-Next-Evolution-2025-Linkedin

The Next Evolution in Cloud Data Protection

Read more about The Next Evolution in Cloud Data Protection
Readiverse_ShareImage_1200x630

The Conversations That Inspired the Readiverse

Read more about The Conversations That Inspired the Readiverse

Key Takeaways

  • Synthetic Recovery™ automates finding a clean recovery point and assembling only the most recent uncorrupted versions, enabling clean, fast restores across your backup estate.
  • By excluding encrypted or malicious files before recovery begins, it helps prevent reinfection and minimizes unnecessary rollback.
  • AI-enabled, multi-engine threat detection (behavioral analytics, signatures, machine learning, heuristics, YARA/Hash, and partner signals) powers precise identification of good data.
  • The approach transforms recovery from reactive triage to a strategic, automated resilience capability within the Commvault Cloud Unity platform.

When cyberattacks strike, recovery confidence is everything. The ability to restore operations quickly ­– and know that the data you’re bringing back is clean – separates the resilient from the vulnerable.

With exclusive Synthetic Recovery™, Commvault announced a breakthrough innovation as part of the Commvault Cloud Unity platform release. Enabled by AI and Commvault’s industry-leading multi-engine threat detection capability, Threat Scan, Synthetic Recovery helps organizations achieve one of the most elusive goals in cyber resilience: clean, fast, and complete recovery.

The Confidence Gap in Cyber Recovery

Even the best-protected environments can harbor hidden threats. Ransomware and other malware can remain dormant for days or weeks before activating, compromising systems and even backups.

When that happens, traditional recovery approaches – manual scans, isolated recovery environments, and trial-and-error restore – can waste valuable time, drive unnecessary data rollback, and risk reintroducing malware into production systems.

Enter Synthetic Recovery, designed to close this confidence gap in cyber recovery.

Clean Data, Fast: The Power of Synthetic Recovery

Synthetic Recovery automates the process of Cleanpoint™ identification, assembly, and restore of only the most recent uncorrupted file versions across entire backup data estates.

By drawing on AI-enabled  insights across multiple backups, Commvault can assemble a curated recovery point that can help:

  • Speed up restoration by automating clean data assembly, reducing downtime from hours to minutes.
  • Prevent reinfection by excluding encrypted or malicious files before recovery begins.
  • Minimize rollback by keeping the most current, validated file versions of good data.
  • Simplify recovery across workloads, clouds, and storage environments.

The result? Faster recoveries, cleaner outcomes, and unified operations that strengthen enterprise resilience from the inside out.

AI Precision at Work

Synthetic Recovery is powered by Commvault’s AI-enabled  multi-engine threat detection and response – a system that combines behavioral analytics, static signatures, machine learning, heuristic detection, YARA-rule and Hash scanning, and security partner signals to spot both known and zero-day threats with exceptional accuracy.

This intelligent automation helps Commvault customers build assurance that every recovery is validated, clean, and secure – not only restoring your data, but also your confidence in it.

Unified Resilience for Modern Operations

For today’s IT and security teams, Synthetic Recovery represents more than a feature – it’s a mindset shift. It transforms recovery from a reactive process into a strategic, automated resilience capability.

By bringing together cloud-native protection, advanced detection, and identity resilience in one platform, Commvault empowers enterprises to move faster, recover smarter, and operate with certainty – even in the face of the unexpected.


FAQs

Q: What is Synthetic Recovery?

A: Synthetic Recovery™ is a new Commvault capability within the Threat Scan offering that automates clean and verifiable data recovery after a cyberattack. It identifies and assembles the most recent uncorrupted file versions from entire backup estates across multiple virtual machines and files, creating a single, curated recovery point. This helps organizations restore operations faster, cleaner, and with confidence, while minimizing rollback and reinfection risk.

Q: Why is Synthetic Recovery important now?

A: Modern ransomware and malware threats are increasingly stealthy, often lying dormant for days or weeks before activation. During that time, malicious data can silently enter backup sets. When that happens, traditional recovery methods risk restoring infected data. Synthetic Recovery helps solve this by combining AI-enabled threat detection, Cleanpoint™ identification, and automated clean data assembly to enable that only verified, healthy data is brought back online.

Q: How does Synthetic Recovery differ from traditional recovery methods?

A: Traditional clean recovery workflows rely on manual steps such as creating isolated recovery environments, manually restoring data for external scanning, and guessing at the “last known good” recovery point.

Synthetic Recovery removes that guesswork. Using Commvault’s indexed backup data and AI-enabled threat detection, it automatically identifies and replaces compromised files, generating a dataset ready for immediate recovery – no manual validation required.

Q: What role does AI play in Synthetic Recovery?

A: Synthetic Recovery leverages Commvault’s AI-enabled multi-engine threat detection and response framework. This includes:

  • Behavioral analysis to detect unusual file activity.
  • Machine-learning models that recognize encryption and ransomware patterns.
  • Static and signature-based scanning for known threats.

For a complete list of Commvault Threat Scan detection techniques, request a demo.

Q: How does Synthetic Recovery help reduce reinfection risk?

A: Because Synthetic Recovery excludes files identified as malicious or encrypted, it helps validate that compromised data never re-enters production environments. This can break the reinfection cycle, giving teams confidence that every restored file has been validated as safe – based on AI analysis and Commvault’s multi-engine threat intelligence.

Pauline List is a Product Marketing Specialist at Commvault.

More related posts


Thumbnail_Blog-SHIFT-Announcement-Recover-Clean-2025-Linkedin

Recover Clean, Recover Fast

Read more about Recover Clean, Recover Fast
Thumbnail_Blog-SHIFT-Announcement-Commvault-Cloud-Unity-2025-Linkedin

A New Era of Enterprise Resilience

Read more about A New Era of Enterprise Resilience
Thumbnail_Blog-SHIFT-Announcement-Next-Evolution-2025-Linkedin

The Next Evolution in Cloud Data Protection

Read more about The Next Evolution in Cloud Data Protection
Thumbnail_Blog_Modern-Playbook-2025

Your Modern Playbook for Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Rapid Response and Clean Recovery