Skip to content

The International Day of Women and Girls in Science 2023 takes place on Saturday 11th February and is an opportunity to promote the full and equal access and participation of females in Science, Technology, Engineering and Mathematics (STEM) fields.

We caught up with two amazing and inspirational Commvault leaders, Field CTO Vidya Shankaran and Director of User Experience Parisa Bazl to get their views on a range of topics including;

  • Why a minority of women pursue careers in STEM,
  • How bringing diverse perspectives can be a huge positive in their roles and
  • What advice would they give their 18 year old selves.
  • Personal Heroes

Why is marking the International Day of Women and Girls in Science important?

Vidya

As a mother of a daughter who is in science and engineering magnet high school, I know how important it is to raise awareness of the need for gender equality and promote the empowerment and advancement of women and girls in science, technology, engineering, and mathematics (STEM) fields.

By celebrating this day, it serves as a constant reminder for all to work towards removing the barriers that prevent women and girls from participating – this helps foster a more inclusive and innovative scientific community and a better future for all.

The day recognizes the important contributions of women and girls to these fields, and it encourages more girls and women to pursue careers in STEM.

Parisa

Celebrating this day is a way to remind ourselves of how far we’ve come and the distance we still need to go. While achieving gender equality in the STEM field is an uphill battle, our progress is evidence that it is possible and we will get there. This day is also a reminder of the benefits of having diversity in technology since so many critical, fun, and interesting things — from WiFi to dating apps – had their groundwork laid by women.

Why do you think women earn STEM degrees at half the rate of men – how can we help address this?

Vidya

Despite the fact that women have had a significant role to play in the progress of science and technology, they have not received the same levels of recognition as their male colleagues is an issue that transcends centuries. 

I would not necessarily to ascribe it to lack of female role models in STEM – there are many unsung “heroes” – but rather to the gender stereotypes and societal expectations that science is a “male” field. This manifests in the form of insufficient support for work-life balance that women and girls encounter compared to their male counterparts.

Thankfully, it is not irreparable or beyond redemption yet – there are many things we are already doing today and should continue doing and maybe even accelerate.

Promoting female role models in STEM through media coverage and highlighting the achievements of successful women in science is key as this has the power to encourage girls to take up science from an early age.

Most importantly, it is imperative that we continue providing supportive environments in education and the workplace, such as mentorship programs and outreach activities. Providing flexible work arrangements ensures that women continue to remain motivated to pursue their careers in STEM. Finally, fostering a culture of diversity and inclusivity in STEM, and promoting equity and equal opportunities in hiring, promotion, and compensation are critical to improving induction and retention of women and girls in STEM careers.

Parisa

Many women grow up with the incorrect perception that STEM is a field that plays to stereotypically masculine strengths, and we do not always have the proper social support systems to address these feelings of inadequacy and lack of confidence. Technology is often equated with software, but it much more about people. By highlighting the human aspects of the discipline, we can encourage more women to see how their unique backgrounds, perspectives, and skills will serve as a strength while pursuing degrees and careers in STEM.

What can being a woman bring to your roles of field Chief Technology Officer (Vidya) and Director of User Experience (Parisa)

Vidya

In my role, which is technology evangelism with our customers and partners, in order deliver this role successfully, it requires empathy, emotional intelligence, respect for all cultures and obviously, understanding of technology. As a woman it does require a lot more effort and perseverance to get to and keep my “seat at the table”, but it is not without the support of all men and women around me.

I am also seeing an increase in the number of men who are allies, who have been instrumental in driving acceptance, encouragement, and support for women in technology. These men are invariably fathers or brothers of women and girls in STEM and are aware of the challenges that women/girls face and are happy to do their bit in removing these roadblocks. This is definitely a change in the right direction.

Parisa

Working in a field where I’ve historically been at a disadvantage means that I’ve cultivated skills which not only help me navigate the field, but also do my job very well. I have had to pay attention to the smallest details, ask incisive questions, and listen extremely closely in order to best position myself for success. These are skills that make me a better advocate for users, since great UX is built on our ability to pay attention to what their users are saying in order to piece together the optimal solutions. In addition, being an outsider within the field of technology also makes me much more conscientious of inclusivity, and how everything from the way in which my team operates down to the interface that is designed needs to be intentional about creating equitable access and success.

What advice would you give to your 18-year-old self, moving into technology?

Vidya

I would say – Hang in there for it does get better .

But again, the kind of pressure we put on ourselves to deliver our best day after day, I would only say to take slow down and “smell the roses” – that we are not expected to know everything or have all the answers and it is okay to say, “I don’t know”.  After graduating with a degree in Chemical Engineering when I moved into Information technology, it felt like a personal failure, but I would tell me 18-yo self that it is okay to fail – “Failure” is a verb not a noun.

Parisa

I would advise my 18 year old self, who never planned on getting into technology, to think about it beyond just engineering. As I mentioned earlier, technology is way more about people than it is about software. If we focus on our ability to connect with people and cultivate understanding, it makes us that much more valuable and our impact that much more positive.

Personal Heroes – Who do you admire?

Vidya

I have a lot of respect for Indra Nooyi, former CEO of Pepsico and look for every opportunity to learn from her experiences.

Parisa

I’m a big fan of Barack Obama. He is someone who also had to navigate a system that was not predisposed to his success, and he leveraged his unique skillset, background, and point of view to inspire and connect with millions of people.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

It sometimes feels like we are living in the age of the reboot.  If you’re a fan of the hit TV show “That 70’s Show,” you know that it’s all about a group of friends navigating the challenges of adolescence in the 1970s and that it’s been rebooted (and updated to the 90s) on a popular streaming service. 

And it’s not alone.  From the good (Cobra Kai anyone?) to the not so popular (did anyone actually see the Knight Rider remake??) there is always an appetite for an update which reflects the current environment and challenges.

That sentiment can also be applied to your organization’s data management and protection strategy – to ensure it stays current and effective in an ever-changing world of emerging technologies and cyber threats.

With a new year and a fresh perspective, see if any of the below signs resonate with you. If so, you may be in a great place to put together a plan to reboot your approach to data in the Modern Cloud Era:

  • Outdated & mismatched technologies: Just like the characters on the show were stuck in the 1970s, your data management and protection strategy may be relying on a “frakenstack” of mismatched and outdated technologies that sprawled organically but are now stuck in time and are no longer effective in today’s modern multi-cloud world. It’s important to regularly review and update your technology strategy to ensure that your approach to data growth and retention is not only purposeful and effective, but also provides you powerful protection and controls from the best tools available.
  • Uncertainty around shared responsibility obligations with Cloud Providers and SaaS Applications: If you don’t have a solid understanding of what your obligations are to protect your data under the shared responsibility model, you could end up losing days, weeks, or even months of valuable insights in the event of a disaster situation. In the show, the characters often found themselves in sticky situations that could have been avoided with proper situational awareness & planning. The same is true for your organization’s off-prem data.
  • Insufficient access controls: Whether resulting from innocent human error, or malicious bad actors, your data management and protection measures can often be wide open to catastrophic incident if users have too large a sandbox to play in. Our crew of misfits in “That 70’s Show” often found themselves in trouble due to a lack of boundaries and rules. The same is true for your organization’s data. With proper access controls in place, your data is more protected, your risk profiler is smaller, and you can rest easy knowing that it’s that much harder to have a major incident due to unauthorized individual actions.
  • Lack of employee & org leader education: Just like the characters on the show needed guidance and direction, your employees and cross-functional partners need to be educated on best practices for data protection. Without proper education, your organization is at risk of data breaches and other cybersecurity threats. Do all of your cross-functional partners (HR, Sales, Operations, Dev Ops, etc.) understand the implications and limitations of native SaaS applications and cloud services? Do they have a trusted partner in the IT function to ensure that their workloads are secure and backed up to cover any gaps in the service provider’s shared responsibility model while simultaneously providing upline leadership a single view of all of their distributed corporate data across all platforms and form-factors?

If any of these signs apply to your organization, it’s time to think about giving your data protection strategy a refresh.

Just like “That 70’s Show” has stood the test of time, a solid data protection strategy can help your organization stay current and protect its sensitive information. Don’t get stuck in the past – take action to ensure your data is safe and secure.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Zero trust architecture is central to an organization’s security posture to mitigate cyberattacks, and the Defense Department recently released its Zero Trust Strategy and Roadmap1 on its plan to get the DOD to a Zero Trust architecture by 2027.2

A zero trust architecture provides the foundations for micro-segmentation of the IT landscape, access limited with the Least Privilege principle, and all communication to and between the micro-segments being authenticated, audited, and verified3. The underlying philosophy for zero trust is never assume trust, but continuously validate trust, so bad actors don’t get in. Companies, organizations and government agencies need to make sure that even users inside a network can’t do serious damage.

Flag Unusual Behavior

Zero trust principles ensure user access is continuously validated and monitored for Authentication and Authorization while constantly Auditing. Commvault leverages security controls such as multi-factor authentication for everyday administrative tasks, privacy locks, and data encryption. User access can be compartmentalized, explicitly denying CommCell level access, while applying roles to micro-segmented groups of resources through multi-tenant configurations. Zero trust controls help limit internal lateral movement to prevent data loss and unauthorized access to data.

Apply Zero Trust Controls

Commvault makes it simple to apply zero trust AAA controls by using the Security Health Assessment Dashboard. The dashboard provides a single pane of glass for identifying controls, highlighting potential risks within the backup environment, and recommending interactive actions to apply controls.

Add Layers of Security

To help strengthen the resilience of your data infrastructure, the NIST Cybersecurity Framework focuses on five primary pillars for a successful and holistic cybersecurity program. Attention to these pillars can help your organization in developing a comprehensive risk management strategy. Commvault has built these security pillars into our data protection software and policies without the incremental management overhead. The Commvault data protection and management platform include five security layers:

Identify

Protect

Monitor

Respond

Recover

Our multi-layered security consists of feature sets, guidelines, and best practices to manage cybersecurity risk and ensure data is readily available. We help protect and isolate your data, provide proactive monitoring and alerts, and enable fast restores. Advanced technologies powered by artificial intelligence and machine learning, including honeypots, make it possible to detect and provide alerts on potential attacks as they happen so you can respond quickly. By keeping your backups out of danger and making it possible to restore them within your Service Level Agreements, you can minimize the impact of a ransomware attack so you can get back to business right away (and avoid paying expensive ransoms).

Immutability

Protecting and isolating your backup copies is critical for data integrity and security. Therefore, we have taken an agnostic approach to immutability. With Commvault, you do not need special hardware or cloud storage accounts to lock backup data against ransomware threats. If you happen to have Write-Once, Read Many (WORM)-, object lock- or snapshot-supported hardware (which Commvault fully supports), you can still use Commvault’s built-in locking capabilities to complement and layer on top of existing security controls. Commvault’s ability to support layered defenses for securing data sets against ransomware ensures that your organization benefits from a sound cyber recovery-ready architecture. Here are some elements to include in your immutability architecture:

  •  Access locks to isolate copy store against ransomware
  • Immutability with lifecycle locks to reduce risks, balanced with consumption impact
  • Air-gap isolation network and controls
  • Configuration governance to protect against intentional or accidental changes
  • Concurrent Recovery performance – reduce latency with due importance to speed and cost impact
  • Automatic patching to stay current, simplifying management and maintenance of data protection infrastructure
  • Alignment with the 3-2-1 data protection philosophy  (3 copies of data, 2 different media, 1 vaulted copy)

Learn more about Commvault’s immutable infrastructure architecture here.

Cyber Deception Technology

While delivering business continuity is a critical element of any multi-layered strategy, a strong security posture also includes proactive defense technology that actively surfaces and engages unknown and zero-day threats. Metallic® ThreatWiseTM changes the game in ransomware protection, combining sophisticated early warning and early action with comprehensive data protection. It enables businesses of every size to neutralize silent attacks before they cause harm, detecting and diverting the stealthiest of zero-day attacks, which evade conventional detection technology and circumvent security controls.

A Ransomware Strategy

You need a plan to remain steadfast against ransomware. Beyond simply adhering to zero trust principles and hoping for the best, the ultimate solution can manage and substantially reduce the impact of a ransomware attack. It can reduce costs for your organization by utilizing one centralized management platform, so security teams don’t have multiple product points to log in and out of. It can increase the visibility of your data through a single landscape to minimize complexity for your teams. And finally, it can protect what matters most by providing the broadest workload coverage and rapid recovery capabilities through a unified approach. For all of this to happen, a solution must embrace Zero Loss Strategy.

Become Less Vulnerable

The reality is your organization needs to be prepared and take proactive steps to protect your data and work with a provider who offers ransomware protection and recovery solutions. How prepared are you? Take our free risk assessment to find out. Also, read our eBook on Understanding Team Roles and Responsibilities in Fighting Ransomware.

References
1. US DOD, Department of Defense Releases Zero Trust Strategy and Roadmap, November 2022
2. C. Todd Lopez , DOD News, DOD Releases Path to Cyber Security Through Zero Trust Architecture, November 2022
3.Commvault, Vidya Shankaran, Ransomware Defense in Depth – Best Practices for Security and Backup Data Immutability, October 2021

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

I’m so proud to announce the inspiring Vaulters who just won our FY’23 Q3 CEO Living Our Values Awards. 

Here at Commvault, our four values – we connect, we inspire, we care, we deliver – are always top of mind! 

This week we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work as they live our values every day. 

I’m so proud to announce our FY’23 Q3 CEO Living Our Values Award winners:

Christina Manning
Director, Finance Operations

Mathew Ericson
Principal Product Manager

Jason Gerrard
Director, Sales Engineering

Parisa Bazl
Director, Development UX

Sam Hernandez
Director, Facilities Management


All these winners set an inspiring example and embody what it truly means to be a Vaulter!

To learn more about what it’s like to work at Commvault, check out our careers site.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The challenge with audit logs today

One major challenge customers face with audit logs is that they’re not aggregated in a central location that is fully immutable. SaaS applications specifically tend to have their audit logs kept within the SaaS application itself, oftentimes with only a 90-day history.

This leads to complicated scripting or the periodic export of logs from each application to place in a centralized location to meet corporate compliance and security goals.

This is a heavy lift on IT departments, and with hundreds of applications under management in any environment, it’s oftentimes not feasible to accomplish this completely. 

Consolidating audit logs with AWS CloudTrail Lake

With the release of CloudTrail Lake, AWS has made it simpler to manage audit logs from disparate sources. CloudTrail Lake is a managed security and audit data lake that lets organizations aggregate, immutably store, and query events recorded by AWS CloudTrail.

This can be done across different regions and accounts – and is backed by a 7-year default retention policy to help you meet compliance requirements.

Customers can ingest and analyze events in an AWS CloudTrail compatible schemafrom Clumio, as well as other third-party and non-AWS sources to streamline auditing, security investigation, and operational troubleshooting.

Simpler data security with Clumio and AWS CloudTrail Lake

AWS and Clumio teamed to deliver this integration for CloudTrail Lake thatallows you to simplify and streamline the process of consolidating activity data.

Through the newly launchedPutAuditEvents API for AWS CloudTrail Lake, Clumio has created a simple integration to capture user activity information and events from your Clumio environment alongside the AWS systems you are protecting with Clumio.

Once the integration is enabled, you’ll be able to capture and store audit activity across various categories. This will allow you to easily answer many security and compliance-related questions across various categories such as:

  • Authentication– Was there a high volume of unsuccessful logins to the Clumio console, indicating a brute force entry attempt or an issue with your Single Sign On provider? 
  • User Management– When was a user added to the Development Organization in Clumio, and when were they given the backup Admin role?
  • Backups– When was a backup policy accidentally changed? This will help you quickly determine when a backup policy was changed or created to ensure you’re always meeting both long-term compliance requirements and maintaining any minimum required RPO’s (recovery point objectives).
  • Restores– Is someone browsing the CEO’s email history, or trying to recover Payroll information from a system backup? This activity is tracked even if a restore hasn’t been initiated.
  • S3 Protection Groups– When was a new S3 production bucket added to a protection group? Why was a bucket removed? 

Setup and Architecture of Clumio logs on AWS CloudTrail Lake

First, in Clumio, navigate directly to the Audit Report page. You’ll see a link to set up the integration in the upper right corner. You must have the Super Admin role to set up the integration.

AWS CloudTrail Integration

On the next screen, you will see an external ID unique to your integration with CloudTrail. Copy this value, and we will then setup the next portion of the integration in AWS directly.

After logging into the AWS Console, navigate to CloudTrail, where you will find a new Integrations section under Lake.Click on the Add Integration button to configure the Clumio integration.

You’ll first need to give a name to channel that Clumio will use to send the audit logs data through, and then selectClumioas the source.

Next, we will need a place to deliver the Clumio audit logs and determine how long you would like to get the logs. You can either use an existing event data store or create a new one for this integration.

Next, we’ll configure the resource policy which is what will provide Clumio with a secure way to send the audit log data across the channel. This is where we will paste in the external ID we copied from the Clumio interface.

Lastly, apply any tags you may want to add to the resource and select Add Integration.

The integration is now set up; however, we have one final step. We need to copy the Channel ARN value and bring it back to Clumio, so we can complete the setup.

Once you add the Channel ARN value, click on Connect to CloudTrail

An initial event will be sent to the CloudTrail Lake event data store, allowing you to verify connectivity. From there, your Clumio audit events will be regularly sent to the CloudTrail Lake data store.

Additionally, you’ll be able to monitor the health of the integration at any time through the Audit Log report.

Below is a list of all audit event categories that are sent to CloudTrail as part of this integration:

  • Authentication
  • Datasource
  • Policy
  • S3 Protection
  • Restore
  • Backup
  • Users
  • Organizational Unit
  • KMS Config
  • SSO/MFA
  • CloudFormation template

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

In the handful of months since I became Commvault’s first Chief Partner Officer, I’ve been reading the terrain, talking with our partners, and figuring out how we can better help them in the year to come. I’ve analyzed everything from program incentives to partner enablement and everything in between to plot our course. There is, however, one thing I didn’t consider. The intangible effect of being one of the coolest kids on the block.

For the 7th year in a row, Commvault has been named to CRN’s annual Cloud 100 list! Honoring the 100 Coolest Cloud Companies for 2023 across five key categories: infrastructure, monitoring and management, storage, software, and security, we rated among the Top 20 in the storage category based on CRN’s analysis.

To make the list, which is considered by most in the partner world as the trusted resource for solution providers looking for technology vendors best positioned to support their cloud product and services needs, Commvault had to prove its commitment to channel partners as well as demonstrate our innovation in the development of cloud-based technologies.

This wasn’t difficult for Commvault, as we’re a leader in data management, protecting data wherever it lives – whether on-prem, in the cloud, or in a hybrid cloud environment. We support the broadest range of workloads in the industry and most recently expanded our cloud protection for Kubernetes, positioning us as an Outperformer and Leader in GigaOm’s Radar for Kubernetes Data Protection.

“In today’s remote-facing enterprise environment, cloud services have become the critical component needed to build comprehensive and secure IT solutions,” said Blaine Raddon, CEO, The Channel Company. “The companies selected for this year’s Cloud 100 list have shown time and again that they support partners in the ever-evolving cloud computing business with state-of-the-art products and services. Our team commends those on this year’s list and looks forward to watching them drive positive change in the cloud domain throughout the year.”

CRN’s Cloud 100 list will be featured in the February 2023 issue of CRN magazine and online at www.crn.com/cloud100.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Data Privacy Week is an annual event that aims to raise awareness about the importance of data privacy and security. The goal of Data Privacy Week is to educate individuals and organizations about the importance of protecting personal data and to provide them with the tools and resources they need to do so effectively.

We’ve brought together three opinion leaders to discuss the key data privacy challenges that face businesses around the world and how to overcome them.

Bill Mew, Data Privacy Champion and CEO of the Crisis Team is joined by Jakub Lewandowski – Global Data Governance Officer, Commvault and Thomas Bryant – Product Marketing Director, Commvault as they discuss;

  • Current trends and challenges in Data Privacy and Security
  • Laws and regulations related to data privacy, such as the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States as well as DORA and NIS2
  • Best Practices for protecting data – including a modern (and tested) data protection strategy and conducting regular risk assessments
  • The current state of Data Privacy policy and legislation compliance/ enforcement  

Learn more about these topics in our Data Privacy Week Blog Series available now

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

World Privacy Day, observed annually on January 28th, serves as a reminder of the importance of protecting personal data in today’s digital age. As technology advances and more personal information is shared online, individuals and organizations must take steps to safeguard their data.

New regulations, such as DORA (Digital Operational Resiliency ACT), mandate that organizations create plans for risk management, incident reporting, and resilience testing. These regulations outline policies for data management, including encryption, data locality, and data lifecycles. Gartner projects, “by 2023, 65% of the world’s population will have its personal data covered under various privacy regulations, and companies need flexible solutions that can adapt to the multitude of legislation.” Navigating this complex environment can be challenging for both individuals and companies.

Data Privacy is protecting personal information and giving individuals control over how their data is collected, used, and stored.  On the other hand, data protection refers to the technical and organizational measures put in place to protect data (including personal data) from unauthorized access, use, alteration, or destruction. Data protection encompasses Data Privacy and other areas, including backup & recovery, disaster recovery, data security, and a host of other areas.

To help address that complexity, let’s spend some time reviewing the Top 10 topics to consider when managing Data Privacy and Data Protection.


1. Data Protection Strategy
2. Encryption
3. Multi-Person Authentication
4. Immutable Storage
5. Data Sovereignty
6. Data Governance & Discovery
7. Classification of data
8. Data Retention
9. Resilience plan testing & incident response
10. Risk Assessment

1. Data Protection Strategy

Organizations should start by creating or updating a Data Privacy, Backup & Recovery, and Disaster Recovery plan as part of an overall data protection strategy. There are many facets to a reliable data protection plan and how it specifically relates to protecting the private data your customers have shared with your organization.

2. Encryption

Encryption is a crucial feature of data protection and protecting private data. Allowing for data encryption at rest and in transit helps prevent unauthorized access to personal information. This is especially important for organizations that handle large amounts of private data, such as healthcare providers and financial institutions. Data no longer resides just in our corporate data centers, as most organizations have one or multiple public clouds with workloads and data stored in them. Securing, with encryption, for the life of the data helps mitigate potential attackers.

3. Multi-person authentication

Beyond protecting data with encryption, organizations must safeguard their systems from malicious attacks. Leveraging multi-person authentication (MPA) for your data protection systems ensures critical tasks require multiple approvals from pre-approved users. Often overlooked, this is one of the simplest ways to prevent tasks like data exfiltration or deletion.

4. Immutable Storage

Immutable storage allows for data, private or otherwise, to be written and unable to be further modified or deleted. Data that cannot be tampered with or altered ensures data integrity is maintained. Immutable storage requirements are quickly becoming a standard part of data governance regulations like GDPR, HIPAA, and others. When paired with MPA, you can create highly secure data storage tiers that are a perfect fit for storing confidential and private data.

5. Data Sovereignty

Organizations should consider regulations surrounding private data storage when developing a data protection strategy. This includes the location of data storage and compliance with regulations regarding data sovereignty. For example, a cloud-based workload on GCP in Europe or containing EU citizens’ data must comply with EU regulations. Anywhere that private data may reside, even if temporary, may be required to be in a specific region under regulatory requirements. Commvault helps to address this concern in its latest release, allowing customers to select which specific region they will leverage for snapshot & data protection storage vs. multiple regions that cost more and may have different regulatory requirements.

6. Data Governance & Discovery

In a recent survey, 57% of CISOs admit they don’t know where some or all their data is or how it is protected! As this amount of private data continues to grow, the sheer number of regulations expands exponentially, and we are confused about what and how we should protect our data.  As a result, organizations need to understand their data, where it is, and what is at risk.  Being able to prioritize data based on your organization’s policies, priorities, and applicable regulations is critical to protecting the data. You cannot protect what you don’t know about!

7. Classification of data

Knowing what data exists and where it resides is only part of the solution. Organizations must consider what data is private customer data, business-critical, etc., in terms of its importance to your business and your customers. Protecting only on-prem data may miss some critical customer data living in your SaaS-based CRM solution. Speaking of which, you must rely on something other than your SaaS vendor or even your IaaS cloud providers to provide data protection for your data. They may provide some SLAs and a level of redundancy, but that is not a replacement for a solid data protection plan. Managing data classification is no point in time operation, with data growing each year exponentially.

8. Retention

It is paramount to know what data exists and how important it is, but how long does it stay relevant? This is a hard question to answer for most organizations and one that can be seen every year when buying ever-increasing storage systems to house corporate data. The ability to assign an expected lifespan to data can significantly impact your organization’s bottom line AND protect your customers’ private data. Having systems in place to automatically find, classify, and set retention will reduce the likelihood of data sprawl, reduce the amount of time to recover unused data, and reduce costs. If you are looking for a great place to start efficiently managing your governance, risk, and compliance, read through Commvault’s unique approach to Unified Data Management.

9. Resilience plan testing & incident response

Resilience plan testing often referred to as a runbook, is an often-overlooked area of a data protection strategy. Creating or updating an outdated plan can take time and effort. Partnering with solution providers or strategic data protection companies with experience in creating a plan can significantly reduce the time it takes to get current. While it may be trivial to think runbooks are passe, I’ve found that when an actual DR event or ransomware attack hits, they are the GO-TO asset you want in your arsenal of tools. A regular cadence of updates creates an organizational posture that is ready to face data security threats head-on.

10.  Risk Assessment

As mentioned with runbook, consider working with strategic vendors to perform a risk assessment semi-annually or annually. Scheduled reviews can help build the muscle memory for a solid data protection and data privacy mindset. The benefit of working with well establish data protection & data privacy vendors is they are up to date on the latest security threats and mitigation strategies.

By implementing this list of considerations and routinely refreshing your resilience plan, you can be confident that personal information is secure and compliant with the latest privacy regulations. If you aren’t sure where to start but need help from a company that can answer all these questions.

Commvault is here to help! We continually add new capabilities, including our latest enhancements to regional data sovereignty for backup snapshots, industry certifications, immutable storage capabilities, and more.

Head over to our community to learn more or take a test drive today https://www.commvault.com/request-demo

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Happy 2023 Data Privacy Week!

Just as everyone started to get more or less cozy with the regulatory landscape in data privacy/protection and individuals and businesses learned to navigate the shallow waters of data subject requests, risk management, and impact assessments – BOOM – another tidal wave of regulatory requirements and new challenges rushed in!

2023 is the perfect moment to start internalizing new acronyms (get ready for #NIS2, #DORA, #DPDPB, #CPRA, #CCPA, #CPA, #CDPA, #UCPA, #VCDPA, #ADPPA, #PrivacyPenaltyBill) and legislative acts they stand for.

The underlying motive of the upcoming changes is to boost and enhance the cybersecurity postures of various organizations and manage evolving cyber risks more effectively.

Here is a helicopter view of selected legal developments around the world:

  • EU – Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2)
  • EU – Regulation on digital operational resilience for the financial sector (DORA)
  • US – State & Federal privacy laws
  • India – Digital Personal Data Protection Bill (DPDPB)
  • Australia – Privacy Penalty Bill & overhaul of the Privacy Act 1988

NIS2

According to ENISA, the general spending on cybersecurity is 41 % lower by organisations in the EU than by their US counterparts. With the arrival of NIS2, this ratio is expected to shift to cover this enormous gap at least partially. Conservative estimates are that NIS2 entry in force will translate into a ~22% increase in ICT spending over a 3–4-year period.

NIS2 was published just before year-end, and EU Member States now have 21 months to transpose requirements and mechanisms described into national laws. The 2016 NIS Directive – despite shortcomings – served as a cornerstone for increasing Member States’ cybersecurity capabilities. Now, NIS2 will expand the scope and the list of impacted organizations. It is expected that as many as 160 000 organizations will be subject to this new legislation, including digital services providers (platforms and data centre services), electronic communications networks and services providers, manufacturing, food, and the public sector.


NIS2 aims to strengthen cybersecurity postures by, amongst other: improving cybersecurity governance, addressing the security of supply chains, streamlining reporting obligations (early warnings/shortened notification periods), and introducing more stringent supervisory measures and stricter enforcement requirements.

What can you do right now?

  • First, try to understand which obligations will apply to your organization and in which compliance bucket your organization will fall into: “Essential Entity,” “Important Entity,” or maybe “other.”
  • Next, see if you can create synergies and leverage existing technical and organizational measures implemented during preceding compliance efforts (e.g., GDPR, NIS1, etc.)
  • Start looking for the right partners that can adequately support your compliance efforts. Engage your vendors in discussing the approach that best fits your organization.
  • Last but not least, initiate planning for increased spending to address any remaining gaps. In compliance could result in administrative fines of up to 10 million euros or up to 2% of the total annual worldwide turnover of the organization.


DORA

DORA aims to achieve “a high common level of digital operational resilience,” mitigating cyber threats and ensuring resilient operations across the EU financial sector. It will become directly applicable from Jan 17th, 2025. It will impact the financial sector (banks, insurance companies, investment firms) and its ICT providers (i.e., cloud platforms) – roughly around 22 000 organizations.

New requirements imposed by DORA will effectively boil down to reviewing and updating risk management practices. Financial sector customers will need to transfer as many regulatory risks as possible to ICT providers or apply different risk-mitigating strategies. In any case, ICT providers will need to be able to assure adherence to DORA’s requirements. The whole industry will also need to reassess contractual relations with vendors. DORA will incorporate requirements for contracts between financial companies and their critical ICT providers, including the location where data is processed, service level agreement descriptions, reporting requirements, rights of access, and circumstances that would lead to terminating the contract.

In a separate post – Commvault’s Product Team will perform a more technical deep-dive into DORA’s requirements related to detection (art. 10), response and recovery (art. 11), and backup (art. 12).


US data privacy laws – CPRA/CCPA, CPA, CDPA, UCPA, VCDPA, ADPPA

As of January 1st, 2023, California Privacy Rights Act (CPRA) amendments to the California Consumer Privacy Act 2018 went into effect. Many temporary exemptions in place expire, imposing additional obligations on companies dealing with California residents’ personal information, e.g., regarding employment-related personal data, opt-out from selling personal information.

2023 is also the year when the Colorado Privacy Act (CPA), The Connecticut Data Privacy Act (CDPA), The Utah Consumer Privacy Act (UCPA), and The Virginia Consumer Data Privacy Act (VCDPA) will become effective. Legislative fragmentation risk is imminent and substantial, and this is the kind of risk that caused the European Union to harmonize the regulatory approach. Let us see whether the same will be true in 2023 in the case of the American Data Privacy and Protection Act (‘ADPPA’) – a proposal for a federal and general data privacy law.

India – DPDPB

Indian legislators plan to introduce a very ambitious Digital Personal Data Protection Bill (DPDPB) this year. When enacted, long-awaited legislation will undoubtedly impact all kinds of organizations due to India’s role as a tech powerhouse and a global outsourcing hub.

Australia – Privacy Penalty Bill & overhaul of the Privacy Act

Australian authorities announced yet another complete overhaul of the Privacy Act dated 1988. The current legislation was summarized as “out of date and not fit for purpose in the digital age.”

In the meantime, still in 2022, Australia passed the Privacy Penalty Bill that increased privacy-related sanctions to levels comparable with trends introduced by GDPR (up to 50m AUD) and expanded regulatory powers of the Office of the Australian Information Commissioner (OAIC) and the Australian Communications and Media Authority (ACMA).

Summary

The relentless compliance clock just started ticking again. Cross-functional teams consisting of IT, compliance, privacy, legal professionals, and business analysts will spend considerable amounts of time analysing the impact of the cloudburst of legislative developments that emerged at the end of last year and will materialize throughout 2023.

Be aware that the legislative developments presented here could be more comprehensive. You can be sure, however, that they will become standard talking points not only in 2023 but also for the years to come.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

As part of a set of three articles to mark Data Privacy Day 2023 (see accompanying articles by Jakub Lewandowski and Thomas Bryant ), Bill Mew argues that there is a real enforcement problem – it’s like the ‘Wild West’ out there.

Policies, frameworks, and rules are only helpful if adhered to, just as regulations and laws are meaningless without enforcement. The problem with the data privacy and cybersecurity arena is that where rules should be applied, they are frequently ignored, and where laws have been introduced, there needs to be more enforcement.

CISOs (Chief Information Security Officers) have a thankless task. Staff is usually reluctant to abide by the cyber hygiene measures that a CISO seeks to enforce, but when their lack of discipline results in a breach, these colleagues are too quick to pin the blame on the CISO. On top of this, while there are costly and complex regulations to abide by and strict rules on breach reporting, the authorities, far from helping to deal with any incident or catch the actual criminals, simply use the reporting to assess the allocation of fines.

Functional, Cultural Mismatch

If asked, most staff would agree that cyber threats are a significant issue, but in their day job, they focus on revenue or profit-centric ROI (return on investment) metrics. These are the metrics on which their individual and unit performance are measured and what company-wide incentive policies are structured to support.

The CISO is instead focused on return on risk (ROR). Based on the allocated budget and the organisation’s risk appetite, the CISO focuses on maximising security and minimising risk.

The mismatch between the CISO’s ROR orientation and just about everyone else’s ROI orientation can put the CISO at odds with the rest of the management team. They may not only become isolated (what I term CISOlation) but can also be a scapegoat when things go wrong – even when warnings are ignored.

Perverse regulatory incentives

In an accompanying article, Jakub Lewandowski [LINK] has explored the raft of new privacy and cybersecurity laws expected to add to a considerable regulatory burden. The problem is that regulation without enforcement is not just pointless but counter-productive. After all, only responsible companies will comply with these regulations, and for them, it represents a cost or compliance tax. Meanwhile, irresponsible ones often choose not to abide by the rules. If they believe that there is little or no risk of enforcement, then this is a cost-saving and risk-free source of competitive advantage.

Lack of compliance is widespread and comes from the top, with frequent headlines about BigTech suffering data incidents or incurring fines. Such fines appear not to be working as a deterrent but are instead being viewed as an additional cost of business by BigTech firms and many others unfortunate enough to have suffered a data incident.

Again, responsible firms that did their best to take reasonable measures but were unfortunately unable to prevent mistakes or attacks run the risk of being fined once they notify the local regulator. Meanwhile, irresponsible ones who choose not to comply will simply avoid reporting incidents and attempt to cover them up instead to avoid fines. Fines have, therefore, become more of a lagging indicator of misfortune for responsible firms rather than of misbehaviour by irresponsible ones.

Record of Regulatory Inaction

Most BigTech firms, attracted by a favourable tax regime, have opted to base their European headquarters in Ireland. The local regulator, DPC Ireland, is therefore responsible for ensuring that they comply with GDPR and other such regulations. Whether down to inadequate funding, reluctance to rock the boat, or simply out-gunned and out-lobbied by the BigTech firms, DPC Ireland has been seen as ineffective in holding them to account.

In one notable case, measures it failed to take against Facebook were eventually resolved in the European High Court under the Schrems I and Schrems II rulings. When it still failed to take action and apply these rulings, DPC Ireland was sanctioned by the European Parliament in a vote of 451 to 1. When further lobbying by regulators across the rest of Europe forced it to take action after a two-year delay eventually, the fine that it levied against Facebook was so low that it had to be increased (tenfold) at the insistence of the other regulators.

The EU Ombudsman Emily O’Reilly eventually opened an inquiry into the European Commission’s monitoring of how data protection rules are applied in Ireland. Eight months later, the Irish Council of Civil Liberties (ICCL) criticised the EU for its continued failure to properly monitor Ireland’s GDPR enforcement while “the fundamental rights of all Europeans hang in the balance.” There are now moves afoot to strip Ireland of its responsibility for regulating the BigTech firms and centralise such enforcement instead.

Ineffective Global Policing

Meanwhile, the number and sophistication of cyber-attacks are increasing exponentially, as is the cost of remediation. The World Economic Forum (WEF) has recently not only called for more widespread use of cybersecurity ‘fire drills’ to test cybersecurity and incident response capabilities but is also championing the need for global rules to crack down on cybercrime.

The damages incurred by all forms of cybercrime, including the cost of recovery and remediation, are thought to have totaled $3 trillion in 2015 and $6 trillion in 2021 and could reach as much as $10.5 trillion annually by 2025.

Cyber insurance isn’t the answer. Rapidly increasing premiums mean that it is out of reach to most buyers, but even those who can afford it often find it’s not worth it. At the same time, cyber insurance cannot be expected to cover systemic problems, and in any case, it has the perverse effect of potentially making bad problems even worse.

While almost all nations have signed up for United Nations agreements on combatting crime, including cybercrime, some nations turn a blind eye and instead provide safe havens for cybercriminals to operate from. While most cybercrime originates from countries like Russia, Iran, or North Korea, such activities are not confined to these rogue nations and continue closer to home. In addition, countries like China have significant espionage operations, and the United States is responsible for a great deal of global mass surveillance – all of which contravenes GDPR and a host of other laws.

We need to start with mandatory data breaches and cyber theft reporting. This has begun in the US with 2022’s Cyber Incident Reporting for Critical Infrastructure Act and in the EU with 2018’s Directive on Security Network and Information Systems. Still, there are also a host of other regulations that mandate telecom payment services, medical device manufacturers, and critical infrastructure providers to report breaches.

Once we have better data on the problem, we can focus on improving international investigation, prosecution, and adjudication efficiency and effectiveness. The United Nations Office on Drugs and Crime is promoting a Cybercrime Programme which has the following aims:

  • Increased efficiency and effectiveness in the investigation, prosecution, and adjudication of cybercrime, especially online child sexual exploitation, and abuse, within a strong human rights framework.
  • Efficient and effective long-term whole-of-government response to cybercrime, including national coordination, data collection, and effective legal frameworks, leading to a sustainable response and greater deterrence.
  • Strengthened national and international communication between government, law enforcement, and the private sector with increased public knowledge of cybercrime risks.

These are laudable goals. However, we are a long way from victims of crime being able to pick up the phone to police at the local, national, or international level with any expectation of getting either practical assistance or justice. The reality is that when it comes to cybercrime, aside from private sector incident response specialists, you’re on your own.

  • Staff are rarely adequately disciplined about cyber hygiene
  • Regulators are not proactive in tracking down and countering non-compliance
  • Criminals are growing in confidence, intensity, and sophistication
  • Police are unable to act against criminals operating from safe havens
  • And CISOs are the default scapegoat when things go wrong

In this ‘Wild West’ environment, there isn’t any cavalry going to the rescue, so you are expected to be adequately armed and ready to defend yourself. Take hints from Thomas Bryant’s article and learn how to deal with it best. There is no substitute for getting your cybersecurity and incident response right.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

As part of our “Get to know your customers day” series, we’re taking a deeper look at Swinerton Inc, a large national construction company who is pursuing a cloud data management program to drive versatility, sustainability and to free up company resources.

IT Manager, Brandon Marrott gives an insight into Swinerton’s data modernization journey which includes cloud transformation and embracing SaaS flexibility.  He also describes operating a hybrid cloud environment through the need to retain a number of company data assets on prem and how Swinerton manages their entire data estate, including SaaS, with Commvault.

https://play.vidyard.com/U5fZTkcgxdb7v9we3WJghp

What does it mean to go to the cloud?

Selecting the right cloud transformation partner

https://play.vidyard.com/oUYbtkBhyzYRoVibhsaWGm
https://play.vidyard.com/zwLtwiwBcsPG15DN2u5L8L

Overcoming challenges and flexibly managing a growing SaaS Data Estate


Faced with increased pressures, including an uncertain economic environment, IT teams are constantly finding ways to reduce costs or increase overall efficiency – all while supporting an evolving data environment.

Explore more examples of how Commvault customers use modern, innovative data protection services, including our DPaaS portfolio Metallic, to achieve their digital transformation goals https://www.commvault.com/digital-transformation-changes-everything-when-it-comes-to-data.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

From achieving sustainability targets to finding efficiencies, all while supporting innovation, IT teams have big contributions to make in 2023.

Check out our collection of 2023 Partner and Customer IT Priorities and let us know what you think via Social Media.

Alan Atkinson, Chief Partner Officer – Concentration on highest value projects


2023 will continue to be challenging for companies from an economic perspective, especially those that are neither profitable nor public – leading many organizations to seek opportunities for cost reductions.

There will inevitably be cutbacks and ultimately some failures, and partners and customers will be reticent to adopt solutions from vendors that do not have a clear path forward. This, combined with various inflationary pressures, will require partners to drill down on enabling the very highest value projects. Ransomware, cloud migration, and digital transformation will remain priorities that get funded, while other areas of business will likely be deprioritized. Consolidation will be key in addressing these needs. Partners and customers will not be looking for more providers, but rather providers that offer more solutions. They will make bigger bets with more concentration, aligning with vendors that offer a wider breadth of coverage and support in cost-effective delivery models.

Darren Yablonski, Sr. Director, Sales Engineering, Canada, U.S. SLED, LATAM – Cyber Security, AI and Regulation


A top, if not the top IT priority for organizations in 2023 will most certainly be cybersecurity. Significant amounts of IT budget spend will be allocated and invested in technologies to prevent, detect and recover from inevitable cyberattacks not if, but when they occur. As cloud adoption in a SaaS (Software as a Service) model continues to proliferate the market, organizations will leverage solutions that provide proven piece of mind knowing their data is safe and recoverable in a timely fashion. Trust will be given to organizations that can clearly articulate cybersecurity best practices that align to a customer specific use case and objectives.

Continuing on the theme of cybersecurity, emerging technologies and trends will be inclusive of both AI (artificial intelligence) and automation. Organizations typically have predictable network and data usage patterns. As data continues to grow exponentially within the realm of the “internet of things” and those patterns deviate within a network or data repository, humans simply cannot keep track of anomalies in real time. As such, Security Information and Event Management (SIEM) solutions that collect, process, analyze and report threats in an expedited and accurate manner will continue to become more ubiquitous. Integration and adoption of such technologies within a zero-trust architecture will be of greater top of mind for CISO’s and security specialists as the years progress.

As mentioned earlier, data consumption will continue to flow from on premise to cloud applications using a SaaS model depending on use case. Hybrid solutions, both on-prem and cloud-based will continue to exist for a number of years as companies look to both balance and ensure data immutability and speed of recovery in the most cost effective manner. As new regulations continue to evolve specific to data security practices, data management solutions that provide a complete and comprehensive set of tools addressing those practices will also evolve. In summary, as the threat landscape in IT continues to grow and increase in complexity, organizations attempting to address this complexity for customers will focus on developing more diverse and broad software solutions that simplify recoverability and accurate reporting regardless of where that data resides.

Katharine Colucci, Associate Solutions Marketing Manager – Corporate Sustainability


The IT organization will take steps to lower the carbon footprint of its data to support corporate sustainability goals. Adopting more sustainable business practices has become a strategic priority of organizations worldwide as they become increasingly aware of how important sustainability efforts are to the success of the business. In fact, Gartner predicts that by 2025, 50% of CIOs will have performance metrics tied to the sustainability of the IT organization. IT teams will need to take steps to reduce the carbon footprint of their data through responsible data management practices, to support overall corporate sustainability goals. Responsible data management practices make it possible to control the total amount of data produced, thereby reducing the energy needed to create, store, manage and protect it.

Commvault supports our customers wherever they are on their sustainability journey, providing opportunities to mitigate their carbon footprint while reducing costs and maximizing the efficiency and security of their data management practices. To learn more about how Commvault is helping customers take a sustainable approach to intelligently manage data, visit Commvault.com/ corporate-sustainability.

Gartner, Are You Thinking Too Small About Sustainable Technology?, September 2022

Jason Gerrard, Director, International Sales Engineering – AI/ML and Automation


As the population progressively gets older, it becomes increasingly difficult for companies to recruit new and fresh talent into the IT industry. As a result, the skills gap is widening and businesses are having to rely less on people to drive innovation, growth, and stability, and move towards a more automated world, where technology can bridge the gap.

This transformation is already well underway, and many organisations are taking advantage of environments, such as the public cloud, to help them automate many of the processes that historically required human beings. Orchestration and automation technologies can go a long way towards helping with this transition by integrating artificial intelligence and machine learning into their solutions. This has been adopted widely throughout the past year to help plug the skills gap, but with costs set to rise to unprecedented levels, it will continue to grow in 2023 as a solution to reducing costs whilst keeping systems running.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

As the world enters the post pandemic period of heightened digital transformation, new challenges have emerged which businesses (and their data) will have to navigate.  In the face of increased economic pressure, digital transformation and cloud initiatives are set to focus on creating efficiencies through costs and resources.

To help organizations steer through these (potentially) choppy waters, we’ve gathered thoughts from some Commvault key opinion leaders.  

Param Kumarasamy, VP, Product Management
– Resilience and Cloud Native Technologies

In 2023, the economic uncertainty will continue to grow in the midst of massive data growth and increasingly constrained IT resources. This will result in moving the enterprises from transformation initiatives into a resiliency. We expect the executives to take defensive posture to address known issues and doing more with constrained resources. IT resiliency initiatives will increase the adoption of AI/ML technologies such as self-monitoring and management of IT assets and automation and orchestration of IT activities across on-premises and cloud.

In last few years we have seen tremendous growth in Hybrid-cloud and multi-cloud initiatives across the enterprises. In 2023, we expect organizations to double down on cloud native technologies. Similar to the physical to virtualization shift, we will see enterprises moving from virtualization technologies to adopt more and more Kubernetes, containers, and DevOps across on-premise and cloud deployments.

Reza Morakabati, Chief Information Officer –
CIOs need a holistic approach to data protection

As we enter 2023, CIOs will need to take a holistic, situational approach when assessing their data storage target map. Companies may blindly adopt cloud or on-prem based on general recommendations, but the decision should be highly dependent upon how the data will be used.

CIOs need to focus on five main areas – scalability, flexibility, agility, security, and cost. Cloud for instance checks off many of these boxes, but could account for a significant portion of a CIO’s operating budget, whereas data center investments are mostly allocated to capital budgets. It is critical for CIOs to look at the full picture.

Matt Tyrer, Senior Solutions Marketing Manager
and Head of Competitive Intelligence – Data Diversification and Mobility 

The number of applications, clouds, platforms, utilities, tools, and various other data workloads and locations to run them is multiplying. Just to frame this a little let’s just look at one of the bigger providers out there, AWS.  Prior to AWS reInvent in late November 2022, they had over 200 applications and services within their catalog for customers to leverage and build on. They then introduced at their annual event another 50+ including many highly specialized databases and tools.

That’s a lot, and that’s just one vendor. With this growing diversification is my prediction, and one seconded by Gartner at their recent IT Infrastructure, Operations, and Cloud Strategies Conference in Las Vegas just a few weeks ago: 

The applications and workloads you are running today, and where you are running them, will not be the applications and workloads or places where you will be running them in tomorrow. 

The impact here is equally diverse.  

  • Skills Shortages: The constant shifting of data workloads will mean that most organizations will not have the in-house skills to keep up with the changing platforms and services they are depending on to drive their business forward and remain competitive. 
  • Data Protection/Management Challenges: It is already a daunting task ensuring that all of your data sources are not only protected but secured from the growing threats to them. Many businesses are stuck relying on multiple niche or point product solutions in order to tackle this challenge because there simply are not many options out there that can cover it ALL. Now imagine all of those data sources and applications moving and changing on a regular basis, most tools today just can’t keep up and this will lead to overlapping siloes adding complexity, cost, and overall risk to the business. 

To address this, businesses will be turning more and more to partners who provide the broadest possible spectrum of support for data protection and data management to ensure that as their data platforms change, their solutions not only can keep pace, but already provide the needed coverage. This will enable organizations to adapt and transform with significantly less friction as they don’t need to revisit data protection and management with each step. This also supports a number of other initiatives such as sustainability and ESG as it enables the consolidation of tools and reduction of infrastructure and consumption of other resources such as the power and water that fuel that infrastructure. 

Hope D’Amore, Solutions Marketing Manager
– Cloud-Native will become the norm

Digital transformation is needed to maintain a level of innovation and competitiveness within the market. Add in a turbulent and uncertain economy and businesses will need to focus on cloud cost management to strike a balance between the two. Some may think a cloud-native adoption would take the back burner during these uncertain times, but a recent survey from Forrester reports that forty percent of firms will take a cloud-native-first strategy in 2023. Organizations will invest more in cloud-native technologies, such as Kubernetes, to realize greater efficiencies instead of continuing to invest in legacy infrastructure.

As the shift to cloud-native environments becomes the norm, security will continue to be top of mind and Commvault is here to help. We provide the most comprehensive and flexible portfolio of solutions for containers. Store, protect, and migrate your Kubernetes applications wherever they live across hybrid multi-cloud environments. To learn more about how Commvault data protection can increase efficiencies within your cloud-native environment, visit Commvault.com/containers.

Forrester, Predictions 2023: Cloud Computing, October 27, 2022

What do you think? What plans does your business have in the digital transformation and cloud areas? Are you planning on investing more in containerization this year?

Let us know on social media.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

As we celebrate Dr. Martin Luther King, Jr. on January 16, his life and legacy as a Civil Rights Leader remains so important to highlight as we start 2023. With so many things that have been accomplished in racial and social justice movements, there is still a global journey towards equality for all.

This day is a meaningful opportunity to reflect on what it means to drive positive change through the power of connection – whether it’s in our local communities, with family and friends or in our workplaces. For Dr. King, and all those who worked alongside him, their commitment to equality and human rights became another moment in the world in how individuals can empower the collective.

At Commvault, we’re striving for a balance in what it means to connect meaningfully whether it is in person or remotely. The global pandemic helped us navigate how to extend those connections around the world in virtual spaces and do it successfully to have “courageous conversations” around various topics.

In my role, my goal is focused on empowering everyone to be a change agent towards moving the Commvault community forward– especially driving lasting and impactful change for all dimensions of diversity. In various workplaces, there are diversity, equity and inclusion (DE&I) efforts focused on improving the recruitment, retention, advancement and sense of belonging for those from diverse, unique backgrounds and cultures. Within Commvault, we have the Multi-Culture Employee Resource Group (ERG) focused on helping to create connections, education and awareness of our global cultures.

The Commvault Multi-Culture ERG is committed to providing a space of refuge, celebration, and reflection for Vaulters that hail from underrepresented racial backgrounds and allies at Commvault. We strive to bring awareness to the beauty, value, and contributions of all racial and ethnic backgrounds.

As a company, we’re working towards that meaningful change and creating a sustainable foundation to support future efforts where all feel like they belong and can thrive. In honor of Dr. Martin Luther King, Jr., let’s continue to make a commitment to ourselves, others, and our broader global community that we will create space for positive change, more connections, and making our places in the world a more welcoming environment -– we’re in this together!

Click here to learn more about our DE&I efforts at Commvault.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

To be successful in our roles as IT professionals, we frequently need to juggle a variety of responsibilities or “wear a lot of hats” – especially when it comes to the important matter of protecting a company’s great asset, its data. 

Let’s pause to explore the characteristics of each hat and how it relates to the data protection responsibilities of a IT Professional:

The baseball cap – Readiness

Foreseeing and thwarting potential dangers to information security. As IT leaders, it is our responsibility to protect data and foresee any weaknesses. This entails continuously scanning for potential dangers and preventing them before they become an issue. Utilizing solutions like cyber-deception allow for an early warning system and provide that shade needed before you get blinded by an attack.

The fedora – Flexibility

Modifying data protection tactics to fit the organization’s evolving needs. As IT executives, we must be ready to modify our approach to data protection to match the shifting requirements of our organization. The digital landscape is always changing. To remain ahead of potential dangers, this can entail putting new security processes into place or modifying current ones. Additionally, an IT leader must consider the latest technologies from cloud to containers and even possibly consider older tech when involved in mergers and acquisitions.  These scenarios all require a robust data protection solution that is scalable and flexible.  

The beret – Creativity

Inventing innovative ways to safeguard data in an increasingly complex digital environment. As IT executives, we must be able to think creatively and develop novel ways to safeguard data in a complicated digital environment. The cybercriminals are often a few steps ahead and might have more resources than your internal IT staff, the only way to combat this is to have elegant solutions to complex problems.  Nothing is more elegant than a beret…

The top hat – Decision Making

Making decisions that secure data and shield the organization from potential dangers while also ensuring that data protection and security are top organizational priorities. As the “top hat” of the company, it is our duty to make sure that data security and protection come first, to make choices that secure data, and to defend the company against any dangers. Our customers, employees, shareholders and even our peace of mind rely on knowing that IT leaders are securing the data and information of our company.  

In conclusion, IT leaders have a lot on their plates and need to be knowledgeable in a variety of fields.

On National Hat Day, let’s take that extra moment to recognize the various hats they wear and the crucial role they play in ensuring the smooth and effective operation of our companies.

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

2022 was a BIG year for Cyber Security.  According to Cyber Security Hub, more than 4100 data breaches were publicly exposed with a number of high-profile attacks including Twitter, Optus and WhatsApp.

In today’s world, bad actors are well organized, informed and also persistent with the volume and speed of attacks increasing.  Their motives are changing, with data leakage, exfiltration, theft and restructure being top objectives causing data damage to now be the top concern of IT decision makers.

So what does 2023 hold? We’ve gathered thoughts from experts across Commvault to answer that very question. 

Industry-Wide Shift to Proactive, Early Threat Prevention 
– Matt Tyrer

In short, businesses will need and begin to implement proactive solutions to constantly monitor their environment to catch threats and enable early warning/response.  Bad guys are getting in, and we aren’t knowing about it early enough. 

From a cyber security and threat defence perspective, the industry today could be essentially divided in two approaches: 

  1. Preventative Measures: These vendors are your perimeter defence vendors like firewalls, anti-virus, SIEM/SOAR tools, along with other data loss prevention (DLP) and intrusion detection/prevention solutions. Even the newer identity access management (IAM) security vendors, who are adding key security functionality to control who can see what in your environment, can be grouped in here. They are all the locks on your doors and windows actively working to keep the bad guys out of the house so that they can’t even start the fire. 
  2. Reactive Measures: These tend to be the storage and most conventional backup vendors who are focused on protecting the data itself. Aiming to ensure it is available for recovery via table stakes features like immutability and anomaly detection (threat hunting) in the backups. These solutions are the sprinkler system and fire alarm – by the time they are triggered your house is already on fire and your only response is triage and disaster recovery. 

Don’t get me wrong, both of these are critical parts of a layered security posture and strategy but there is a gap which where early warning lives.  It’s the abilities to better respond when a breach occurs, while not waiting for data damage to be done before recovery is kickstarted.

This is why my prediction is an industry wide shift to more PROACTIVE warning systems, helping companies fill gaps between their preventive and reactionary toolsets.    

Thankfully, Commvault is ahead of this game with our ThreatWise cyber deception technology. Get started NOW on proactively defending your data. 

Rise in Managed Services Provider Spending
– Donna Namorato

The Institute of International Finance is predicting a global economic growth rate of just 1.2% in 2023, a level on par with 2009 when the world was only beginning its emergence from the from the financial crisis.1 Even with economic uncertainty looming, expect that cybersecurity spending will continue to rise but don’t be surprised if there is a decline in product and service spending.

And even while cybersecurity spending increases, according to a Jefferies CIO survey, 53% noted they would cut ITSM spending. If this happens, I would expect to see a rise in spending on Managed Service Providers (MSP). MSPs specialize in specific IT segments and can offer expert IT experience as they attract and retain talent, whereas organizations have difficulty doing so.

To remain vigilant against ransomware and data security, organizations must adopt a ransomware strategy and develop an incident response plan against bad actors. Incorporating a multilayered security framework is also vital to safeguard your data and reduce cybersecurity risk. And, when you need help, Commvault Ransomware Readiness Solutions is available to assist you.

Industry and Platform Consolidation
– Brian Brockway, Global Chief Technology Officer


Currently, the security space is very convoluted. There are so many tools out there and lots of businesses have multiple solutions to make sure that they are fully protected. However, we have seen the industry start to consolidate and this should continue into 2023. All of the components need to work together in order to operate at maximum efficiency and stand the best chance of being protected. Consolidating them into one platform will be essential to ensure that you are getting the best out of your solutions and having a single pane of glass is key to managing them. Especially as costs continue to rise, organizations must ensure that they are spending every penny wisely and getting optimal output from every purchase.

Yet, due to the sheer amount of threats facing businesses, there is also a growing understanding that not everything can be stopped, no matter how great your solutions are or how effectively you manage them. Organizations should turn their focus to resilience. It is almost inevitable now that businesses will be attacked at some point, but what really counts is how quickly you can recover from it. Regular backups should be taking place so that, even if the worst does happen, downtime is kept to a minimum and normal business operations can be restored as quickly as possible with little lasting damage.

“Inside-out” CyberSecurity, Tiger Teams and Managed Services
– Zack Brigman, Sr Product Marketing Manager

Cyberthreats continue to reach record highs, both in the number of successful breaches, as well as the damage incurred as a result of these attacks. As we look ahead to 2023, experts project these trends to continue to move in the wrong direction as adversaries employ new sophisticated tactics, hackers-for-hire networks continue to expand, and the security/IT skills gap widens. And while these negative forces present difficult challenges to navigate, organizations will take a big leap in the coming year to better plan, invest, and mature their cybersecurity disciplines.

Prioritization

Breaches happen. But not all assets, systems, and data are created equal. Given that a small percentage of information assets carry the majority of business risk, progressive companies will begin employing an “inside-out” cybersecurity strategy. One that starts with hardening and securing their most critical assets first – then working toward the perimeter. While perimeter defences and preventing intrusion will (and should) remain a paramount focus, this risk-aligned approach enables the prioritization of defence strategies to mitigate risk for high-value assets and functions. This reshapes conventional “outside-in” approaches, making security investments more accessible and operational.

Tiger Teams

To better manage emerging threats and respond to risk, we will continue to see a rise in fusion teams (thanks Gartner for the term!) – merging IT, security, and operational stakeholders together to drive change. These blended teams help create new synergies by pairing complementary (but often siloed) groups and capacities to achieve common goals. These cross-functional teams increase visibility across the organization, discover and eliminate blind spots, and optimize investments in existing and new tools. While many mature organizations already leverage fusion teams today, 2023 will see a more widespread adoption of these functions to better identify risks, implement cyber response strategies, and manage threats.

Managed Services

As threats mount, businesses will continue to adopt managed service (MSP) and managed security service (MSSP) offerings to augment existing tools and tactics. This is particularly true of lean IT departments and those looking to enhance their security operations centers. Leveraging these managed providers will enable organizations to close the cyber security skills gap, tap into a consortium of specialized solutions, and scale their cyber practice without managing additional headcount or disparate solutions. 

Thanks to all our contributors! Stay tuned to see if their predictions come true by following Commvault and our DPaaS portfolio Metallic on Social Media. 

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

The trend toward remote employment, coupled with inconsistencies in data security, access, and control across multiple environments, is leading to an increased risk of data breaches, data leakage, and unauthorized data access. This, combined with constantly evolving data types and distributed workloads, leads to multigenerational data sprawl that further compounds business risks. One in three organizations report having been successfully hit more than once by a ransomware attack, making ransomware both a significant and recurring source of business disruption.1

A Cybersecurity Framework

Organizations are adopting multilayered security frameworks to deal with these vulnerabilities – an approach that offers the best blueprint for protecting against and recovering from ransomware attacks. Commvault’s multilayered security framework is built on zero trust principles and follows the National Institute of Standards and Technology (NIST) Cybersecurity Framework standards and best practices to address these five areas: Identify, Protect, Monitor, Respond, and Recover. Attention to these pillars can aid your organization in developing a comprehensive risk management strategy.

Identify

Protect

Monitor

Respond

 Recover

Essential Security Layers of Protection and Recovery with Commvault

A multilayered security framework is important for data security because it provides several defenses to cover data security gaps that may exist within your infrastructure. It is the best approach to protect and recover from ransomware attacks.  Commvault has built these security capabilities into data protection software and policies.

Map your current ransomware protection and recovery capabilities through our Aligning Ransomware Protection and Recovery Plans with Critical Capabilities eBook.

Safeguard your data and reduce cybersecurity risk through our secure backup framework. Learn more through our Multilayered Security Approach to Ransomware Protection and Recovery infographic.

Protect and recover your data across your hybrid, cloud, or SaaS workload environments.  Read our blog and watch our lightboard video on Identify, Protect, Monitor, Respond and Recover.  

At Commvault, we believe a multilayered framework is a way to prepare you for anything your data is facing. Please take our free risk assessment to learn how prepared your organization is to protect and recover from ransomware.

1ESG: The Long Road Ahead to Ransomware Preparedness, June 2022

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Good tidings for 2023! The new year affords us the opportunity for a fresh start and perspective. It is also a time to reflect on changes you need and want to make so you don’t repeat them in 2023.

Recipes for Data Protection Success

To make 2023 an impactful year, follow this four-step recipe to escape the high cost of data protection.

  • Prep Time: Contact Commvault today to get started
  • Bake Time: Throughout 2023
  • Makes: Efficient data protection across your infrastructure

Ingredients

  • 1 cup centralized management
  • 2 tablespoons broadest workload protection
  • 3 cups automation

Directions

1. Preheat infrastructure to a 360-degree view of your data

With today’s evolving IT environment, you need a way to view your data in its entirety. Often organizations try to manage the complexity of a diverse IT environment with multiple backup tools that add complexity and drive up costs. Additionally, managing multiple interfaces reduces visibility to data, leading to lower productivity and greater risk. Using a single, unified interface to control your entire data environment reduces complexity and simplifies daily operations, freeing your staff to focus on higher-value, more strategic activities.

Commvault helps streamline the management of all your workloads – physical, virtual, on-premises, cloud, and even across multiple clouds – through a single unified interface, the Commvault Command Center™. The centralized management console is a highly customizable web-based user interface for managing all your data protection and disaster recovery initiatives – streamlining your daily data management tasks and saving you precious time.

2. Get out a mixing bowl large enough to fit all your workloads

Protecting your organization’s data is like baking a cake—leave out an ingredient, and the entire recipe can be ruined. But securing today’s diverse technology stack across modern SaaS applications and Kubernetes, and workloads from prior generations doesn’t have to be stressful.

Keep up with an ever-evolving tech stack and ensure no workload is left behind with Commvault. We cover the broadest workload protection from on-premises to the cloud to SaaS applications and provide support for native cloud integration, helping to minimize complexity. With Commvault, customers have peace of mind that as they change and evolve, the data and applications they leverage, old and new, are protected.

Read more about Commvault supported technologies.

3. Measure and add automation

For baking, precise measurements are essential to a successful end product. The same is true for data protection – automation can ensure the accuracy of your processes and eliminate human error from entering the equation. Plus, it reduces the time it takes to complete complex data management tasks, adding more time back on your IT team’s calendar.

Commvault software uses built-in automation, orchestration, and policy-based management to improve your overall IT productivity. Through auto-tiering, automated power management systems and intelligent pattern recognition, and numerous other capabilities, you can maximize productivity and minimize overall IT spend.

4. Bake time: The duration of 2023

The key to a successful recipe, and successful data protection is consistency. With Commvault’s quick prep time, you can easily digest the three ingredients needed to make efficient and cost-effective data protection across your infrastructure.

Nutritional Facts:

The icing on the cake is Commvault data management. We provide a comprehensive solution that covers all data protection ingredients – the depth, breadth, scale, and scope of data management to help reduce operating costs while also meeting data protection SLAs.

For more cost-saving recipes, visit Commvault.com/cut-it-costs

More related posts


888×500-blog.8

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements
Thumbnail_Blog-What-is-Resops-2026

What Is ResOps – and Why Cyber Resilience Needs It

Read more about What Is ResOps – and Why Cyber Resilience Needs It
Thumbnail_Blog-Playbook-2026

Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago

Read more about Prove It Before You Need It: The Playbook I Wish I’d Had 10 Years Ago