Skip to content

The RSA Conference, held from March 23 – 26 in San Francisco, is one of the premier events in the cybersecurity industry, bringing together experts, thought leaders, and innovators to discuss the latest trends and solutions in cyber resilience and data protection.

The energy was palpable, the learning top-notch, and the city buzzing. With so much to see, including our ResOps Rumble and The Rumble After Party on Monday evening, we wanted to make sure you didn’t miss these exciting announcements from Commvault.

Key Takeaways

  • Commvault earned major industry recognition with a Global InfoSec Award for innovation in cyber resilience.
  • Expanded threat hunting capabilities help organizations detect risks in backups and recover clean data faster.
  • New data and AI security enhancements help extend visibility, classification, and governance across structured and unstructured data.
  • Integration with Microsoft Security helps enable faster, coordinated threat detection and recovery workflows.
  • Strategic partnerships and industry initiatives highlight a shift toward unified resilience operations as a core security discipline

  1. Commvault wins the 2026 Market Disruptor Cyber Resilience Global InfoSec Award.

After being named Outstanding in the Cyber Resilience category at the 2025 Global InfoSec Awards, we have accelerated our innovation roadmap, redefining cyber resilience beyond traditional backup and recovery to help address the realities of today’s AI-driven threat landscape.

This year, Global InfoSec has recognized Commvault as Market Disruptor in the cyber resilience category. We provide a unified cyber resilience platform designed to deliver AI-enabled data protection, proactive threat detection, advanced ransomware recovery, and a single operational view across enterprise environments.

Unlike other solutions, Commvault® Cloud helps empower customers to protect, recover, and manage their data, applications, and production workloads – across on-premises, public, private, hybrid, SaaS, and multi-cloud environments.

On the topic of market disruption and innovation, we have made a few major announcements leading up to the conference.

  1. Commvault Announces Expanded Threat Hunting Capabilities

We recently announced expanded threat hunting capabilities within Commvault Cloud Threat Scan. The enhancements help organizations rapidly identify risks within backup environments and recover validated clean data, helping reduce reinfection risks and prolonged downtime.

To address this challenge, Commvault now delivers two complementary scanning modes within Commvault Cloud Threat Scan:

  • Hyper Threat Hunting helps enable targeted searches across backup data using threat hunting artifacts such as hashes and YARA rules to identify known indicators of compromise at scale. Hash-based hunting helps provide fast, index-based detection, while YARA-based analysis helps support more targeted pattern matching for deeper investigation.
  • Deep Inspection provides layered file-level analysis using malware signatures, machine learning, heuristic analysis, and AI-enabled encryption detection to help uncover known threats, suspicious variants, and ransomware related activity that may evade exact-match indicators alone.

Together, these detection modes allow close collaboration across incident response and recovery teams to isolate affected data and help make informed recovery decisions. They can schedule recurring scans for continuous monitoring or conduct targeted searches during active incident response scenarios, helping provide flexibility for both ongoing protection and time-sensitive response.

  1. Commvault Announces an Expansion of Data and AI Security Capabilities

On the same day, we announced an expansion of data and AI security capabilities within Commvault Cloud, enabled via our recent acquisition of Satori. The advancements extend data discovery, classification, and risk assessment into structured data environments and introduce real-time access governance for structured databases, including vector databases used in AI applications. These innovations expand Commvault’s existing data security posture management functionality for unstructured data, while data access governance adds real-time control of structured data access.

These advancements also unify visibility by identifying sensitive data, surfacing exposure and policy violations, and consolidating risk insights to help organizations prioritize remediation based on impact. This helps yield improved resilience, prioritized risk remediation, support for compliance, and reduced data exposure to help strengthen resilience across both production and backup data.

  1. Commvault Announces an Expanded Integration with Microsoft Security

On the first morning of the conference, we announced an expanded integration with Microsoft Security to better connect threat detection with trusted recovery. The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the Commvault Cloud platform to streamline resilience operations (ResOps) and enable real-time data insights, helping organizations move quickly from identifying a threat to validating and restoring clean data faster and with greater confidence.

This new integration helps enable coordinated workflows between security and recovery teams. Security alerts from Commvault Cloud are ingested into Microsoft Sentinel data lake where security operations center analysts can enrich these incidents with partner intelligence to access impact and validate scope. In the coming quarters, these insights can help drive automated, policy-based recovery workflows to accelerate and orchestrate clean recovery. You can learn more from our blog here.

  1. NetApp and Commvault Advance Cyber Resilience with Strategic Alliance 

On the topic of alliances, we also announced a strategic alliance with NetApp® to deliver a powerful, integrated solution for enterprise data protection and cyber resilience. The unified solution enables resilience, security, and rapid recovery for customers across on-premises and cloud environments, helping give organizations confidence that their data is available, immutable, and recoverable.

This alliance addresses a critical need for scaling resilience via unified cyber detection and ransomware recovery. By combining Commvault’s leading resilience, protection, and recovery capabilities with NetApp’s enterprise-grade data platform with built-in intelligence and AI-enable ransomware detection, together we’re creating a highly differentiated, end-to-end cyber resilience solution.

  1. TIME + Commvault CISO of the Year

Last but not least in a newsworthy few weeks, we are very excited to announce the launch of the inaugural TIME and Commvault CISO of the Year Award. The branded award, selected by Commvault and a panel of industry experts, recognizes enterprise security leaders who are not only defending against cyber threats but also redefining resilience in an increasingly complex threat landscape.

The CISO of the Year Award recognizes leaders who are transforming cybersecurity into a driver of trust, operational strength, and long-term resilience. They embrace critical practices and emerging disciplines, including ResOps, which is rapidly becoming a core discipline for modern enterprise security.

Nominations for the CISO of the Year Award will be accepted by Commvault from March 23 through June 20, 2026. Submissions will be reviewed by a panel of industry experts. The panel and Commvault will choose finalists and the winning CISO of the Year based on pre-defined criteria. You can read more about the criteria on the nominations page.

Commvault Cyber Resilience a Highlight of RSAC

RSAC 2026 made one thing clear: Cyber resilience is no longer a future aspiration – it’s a present-day mandate. From industry recognition to expanded threat hunting, deeper data and AI security, and stronger ecosystem integrations, Commvault continues to push the boundaries of what organizations can expect from a modern resilience platform.

These announcements reflect a broader shift toward unifying security, data protection, and recovery into a cohesive strategy that helps organizations act faster, respond smarter, and recover with confidence in the face of evolving threats.

As the threat landscape grows more complex, the ability to not only detect and defend but also recover with great confidence is becoming a defining competitive advantage. The innovations highlighted at RSAC – alongside strategic partnerships and recognition of industry leaders – underscore Commvault’s commitment to enabling that outcome.

If RSAC is any indication of where the industry is headed, ResOps will continue to take center stage, and organizations that embrace this approach will be well positioned to navigate whatever comes next.


FAQs

Q: What are the new threat hunting capabilities Commvault introduced?
A: Commvault introduced Hyper Threat Hunting and Deep Inspection within its Threat Scan solution. These features combine fast detection with advanced analysis to help identify both known and emerging threats in backup data.

Q: How do Commvault’s new data and AI security capabilities benefit organizations?
A: The enhancements to Commvault’s data and AI security capabilities expand visibility into sensitive data across structured and unstructured environments. They also add real-time access governance, helping organizations reduce risk and improve compliance.

Q: What is the significance of the Microsoft Security integration with Commvault Cloud?
A: The integration helps connect threat detection with recovery by linking Commvault Cloud with Microsoft Sentinel and Security Copilot. This is designed to enable faster decision-making and more automated recovery processes.

Q: What does the Commvault and NetApp alliance bring to customers?
A: The alliance combines Commvault’s resilience platform with NetApp’s data infrastructure and AI-enabled ransomware detection. This creates a unified solution designed to deliver stronger data protection and faster recovery across environments.

Q: What is the TIME and Commvault CISO of the Year Award?
A: The TIME + Commvault CISO of the Year award recognizes a security leader who exemplifies modern resilience leadership through a ResOps approach.

This program celebrates CISOs who treat resilience as a core business capability not just a technical function, those bridging security, IT, and operations to enable their organizations to recover quickly, operate confidently, and innovate without increasing risk​​.

​​​The honoree selected ​by Commvault ​will be featured in a TIME​ ​branded​ ​article and video, with additional recognition across TIME and Commvault channels​. The honoree will also be invited to Commvault’s annual SHIFT event. ​

More related posts


Threat Scan

Read more about Threat Scan

Key Takeaways

  • Security must scale like Agent Smith: In The Matrix, Agent Smith multiplied rapidly to overwhelm Neo. Security teams face a similar challenge today as threats and signals grow faster than analyst capacity. AI-enabled security agents help teams scale investigations without needing to scale headcount.
  • Correlating signals improves investigation confidence: The Commvault Security Investigation Agent correlates backup intelligence with security signals from platforms like Netskope, CrowdStrike, and Palo Alto Networks to determine whether threats discovered in backup data also impacted production systems.
  • Cyber resilience will become agent-driven: The Commvault Security Investigation Agent is the first step toward a future where specialized AI agents assist security teams with investigations, recovery decisions, and faster restore workflows.

Introduction

In The Matrix, there’s a moment that feels surprisingly relevant to today’s technology landscape. Agent Smith discovers he can duplicate himself. One becomes many, and suddenly Neo is surrounded by an army of identical agents operating simultaneously.

In many ways, that scene mirrors the world we’re entering today with agentic AI. Across industries, and especially in cybersecurity, we’re beginning to see the rise of specialized AI agents that can work independently, scale rapidly, and assist humans in ways that were previously impossible. But unlike Agent Smith’s relentless takeover, the goal of these agents isn’t domination. It’s defense.

Scaling while Breaking Down Silos

Security operations today face a fundamental scaling problem. The number of systems, signals, and security tools continues to grow, but the number of analysts does not.

Organizations now ingest telemetry from endpoint security platforms, network defenses, cloud monitoring tools, and identity protection systems. Each of these tools generates its own alerts and dashboards, often operating in isolation from one another. The result is an overwhelming amount of data spread across disconnected silos.

It’s tempting to assume the solution is simply hiring more analysts, but anyone who has managed large teams knows that adding people introduces its own challenges. As teams grow, communication becomes more complex, coordination slows down, and the efficiency of investigations often decreases.

What security teams really need is not just more people, but more intelligence and automation to help analysts move faster and see the bigger picture.

One of the most persistent silos in security operations has been the divide between backup systems and security tools. Traditionally, security teams monitor production environments through their security information and event management tools while backup environments operate in a separate console.

Backup data is often only examined after an incident occurs, when organizations are already deep in recovery mode. Yet attackers increasingly target backup systems precisely because they know they are critical to recovery.

Ransomware operators frequently encrypt production systems, attempt to corrupt backups, or leave malicious artifacts hidden inside protected datasets. This means that backup environments often contain valuable evidence of an attack, but that intelligence has historically been difficult for security teams to access and correlate with other signals.

The New Security Investigation Agent

Commvault’s new integration with Microsoft Sentinel and Microsoft Security Copilot is designed to close that gap. Through this integration, Commvault Cloud events can be streamed directly into the Sentinel Data Lake, bringing backup telemetry into the same analytical environment as endpoint, network, and cloud security signals.

Instead of existing in isolation, backup activity now can be analyzed alongside the broader security ecosystem. But the real power of this integration comes from the introduction of the Commvault Security Investigation Agent.

The Security Investigation Agent helps analysts investigate potential threats by correlating signals discovered in backup environments with signals coming from other security platforms. When an analyst provides the hostname of a server, the agent gathers security events generated by Commvault Threat Scan and Risk Analysis, including backup anomalies, encryption events that may indicate ransomware activity, malware detected inside protected datasets, and backups that contain sensitive data.

The agent then correlates those events with telemetry from other security tools organizations already rely on, such as Netskope, CrowdStrike, and Palo Alto Networks. By analyzing activity across these platforms together, the agent can help determine whether suspicious behavior identified in backup data also appears in production environments.

How Do You Get the Agent?

Let’s first walk you through how you can start with our first agent focused on security investigations. Then we’ll share how we plan to rapidly spawn new agents – just like Agent Smith – so customers can take control of investigations, recovery decisions, and restore operations, giving security and operations teams the intelligence they need to respond faster and recover with confidence.

Configure the Connector

Before we can enable the Commvault Security Investigation Agent, you will need to install and configure the Commvault Cloud connector.

  1. Installation: Instructions for how to install the Commvault Cloud Solution, along with permissions and pre-requisites, is here.

Screenshot: Installation details for the Commvault Cloud Data Connector in the Microsoft Sentinel Content Hub.

  1. Configuration: Once installed, configuration details are here.
 Use Commvault Security Investigation Agent

Once the Commvault Cloud connector is installed for you, you can use the new Security Investigation Agent.

  1. Go to https://securitycopilot.microsoft.com/agents.
  2. Search for “Commvault Security Investigation Agent.”
  3. Click on “Set up” Agent.
  4. Click on “Go to Agent.”
  5. Click on “Run” => “One time.”
  6. Provide the “Hostname” for the host you’d like help investigating, and click “Submit.”
    1. Note: Hostname is the name of the server that we want to check for events of Commvault and partners like Netskope, CrowdStrike and Palo Alto.
  7. The agent will run and you will get a detailed analysis and recommendations as a result.

Screenshot: The detailed analysis of the Commvault Security Investigation Agent being run on a host that is part of an investigation.

Conclusion

The Matrix may have dramatized the idea of multiplying agents, but it captured an important truth about scale. When Agent Smith multiplied, the dynamics of the fight changed entirely.

Cybersecurity is undergoing a similar shift. Attackers are increasingly leveraging automation and AI to scale their operations. The only way defenders can keep pace is by scaling their own capabilities through intelligent systems that augment human expertise.

With the integration between Commvault, Microsoft Sentinel, and Microsoft Security Copilot – and with the introduction of the Commvault Security Investigation Agent – we are beginning to see what that future looks like. It’s a world where security operations are no longer constrained by silos, where investigations move faster, and where AI-enabled agents work alongside analysts to strengthen cyber resilience across the entire environment.

Over the coming year, Commvault plans to introduce additional agents – just like Agent Smith multiplying in The Matrix – that can help security teams run Commvault Threat Scan, spin up Cleanroom environments for SOC analysts to safely investigate incidents, and accelerate recovery by identifying the safest data to restore.

We’re also excited to collaborate with Microsoft to enable customers to use Microsoft Foundry to build and extend their own agents, allowing them to tailor automation and investigations to their unique environments.

By combining Commvault’s deep cyber resilience capabilities with Microsoft’s AI and security ecosystem, we’re helping organizations move toward a future where intelligent agents help analysts investigate faster, break down silos, and strengthen resilience across the entire environment.


FAQs

Q: What are AI agents in security operations (SecOps/ResOps)?
A: AI agents are specialized, autonomous tools that assist security teams by analyzing data, correlating signals, and supporting investigations. They operate alongside human analysts to help accelerate decision-making and improve response times across complex environments.

Q: Why is scaling security operations such a challenge today?
A: Security teams face an explosion of alerts and data from multiple tools, while analyst headcount grows slowly. This imbalance creates bottlenecks, making it difficult to investigate threats efficiently without automation and intelligent assistance.

Q: How does the Commvault Security Investigation Agent improve threat investigations?
A: The agent correlates backup data with signals from security platforms like CrowdStrike, Netskope, and Palo Alto Networks. This combined view helps enable analysts to determine whether threats detected in backups also impacted production systems, increasing confidence in investigations.

Q: What problem does integrating backup data into security workflows solve?
A: Backup environments often contain critical evidence of attacks but have historically been siloed from security tools. Integrating this data helps enable teams to analyze threats holistically, uncover hidden risks, and make more informed recovery decisions.

Q: How can organizations start using the Commvault Security Investigation Agent?
A: Organizations need to install and configure the Commvault Cloud connector within Microsoft Sentinel. Once set up, the agent can be accessed through Microsoft Security Copilot to run investigations by simply providing a hostname.

Q: What does the future of AI agents in cyber resilience look like?
A: The future points toward multiple specialized agents helping handle investigations, recovery planning, and restore operations. These agents will help break down silos, accelerate response, and enable more resilient security operations across the entire environment.

Ritu Singh is Senior Product Manager and Rich Vorwaller is Director, Product Management, at Commvault.


Related Blogs

MCP 2.0 Explained: Securing AI Agents Before They Secure Themselves

Why AI Is Breaking Your Resilience Strategy (And What to Do About It)

Staying Resilient Against Lateral Access Exploits

Are You Ready for Data Leakage Loops?

Ransomware Trends for 2026: AI, Resilience, and MTCR

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • AI is accelerating data creation and distributed workflows, making traditional reactive approaches inadequate for enabling resilience.
  • Resilience operations (ResOps) help teams shift from reactive troubleshooting to coordinated action, with Commvault applying AI across three areas: protecting AI data, models, and pipelines; leveraging AI to guide and accelerate response; and extending AI across the broader resilience ecosystem.
  • Practical AI agents are designed to surface operational issues (Arlie Data Sense), guide protection decisions (Arlie Advisor), and enable conversational workflows (MCP server).
  • Data security and governance remain foundational. AI must be trained to respect access controls, maintain auditability, and operate within policy boundaries.
  • Organizations can start small with targeted agents and scale toward coordinated, intelligent operations.

AI introduces both new challenges and potential breakthroughs for enterprise resilience. On one hand, traditional siloed tools for protection, recovery, and governance weren’t designed to operate across constantly evolving AI environments that span multiple platforms.

On the other hand, AI-enabled resilience tools can deliver a transformative impact by helping teams maintain visibility, enforce policy, and recover cleanly. For IT and security teams, the question is how best to leverage the benefits of AI while mitigating the operational risks it can pose.

In a recent webinar, I sat down with Teja Medasani, Principal Product Manager, AI, at Commvault, to explore real-world use cases that put AI agents to work in resilience workflows across cloud, SaaS, on-premises, and AI-native platforms.

Why AI Is Redefining Resilience Operations

The rapid growth and dynamic nature of AI-native environments have put operational workflows under pressure. Manual tagging, spreadsheets, and logic quickly drift out of sync. Sprawling job history tables and audit trails slow manual troubleshooting and make subtle warning signs easy to miss. Recovery processes that assume centralized data and isolated failures are poorly suited for exponential data growth and fragmented workloads across platforms.

When data, workloads, and environments span platforms, resilience can’t remain siloed in separate teams, tools, and policies. A new operating model is needed: resilience operations, or ResOps.

What ResOps Looks Like in Practice

The ResOps framework addresses these challenges across three dimensions:

  • Protect AI: Safeguarding AI data, models, and pipelines across environments so they remain recoverable and compliant.
  • Leverage AI: Using AI to help reduce manual effort, surface operational insight, and guide response and recovery decisions.
  • Extend AI: Connecting ResOps across tools and teams to help protect conversational interactions and integrated workflows.

In the webinar, we focused primarily on leveraging and extending AI, highlighting key roles AI agents can play in day-to-day operations. These examples center on Arlie, Commvault’s AI assistant. Designed to help users interpret data, understand issues, and move toward action more efficiently, Arlie includes a library of agents purpose-built to help address specific resilience workflows.

By helping reduce repetitive analysis, surfacing meaningful signals, and guiding decisions around security-aware recovery, these agents can help teams take actions more quickly and confidently. Arlie Data Sense, Arlie Advisor, and Commvault’s MCP server illustrate a few of the possibilities unlocked by AI-enabled ResOps.

Surfacing Operational Issues with Arlie Data Sense

Arlie Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find patterns or diagnose failures, users can trigger Arlie to help analyze the data and generate an executive summary highlighting anomalies and emerging issues.

Teams can ask follow-up questions in natural language and explore data further through interactive summaries or visualizations. When a job fails, Arlie can help analyze logs, summarize the failure, identify the possible cause, and provide next steps for resolution.

Guiding Response Decisions with Arlie Advisor

As workloads are added, ownership changes, and requirements shift, maintaining protection coverage across environments becomes increasingly difficult. Arlie Advisor is designed to help teams create and validate protection plans at scale by evaluating the characteristics and current protection coverage for each resource, and then highlighting where adjustments may be needed.

Recommendations are presented clearly with reasoning explained, so teams can evaluate them and decide how to apply them within existing governance processes. This helps teams maintain consistency across dynamic environments.

Extending Resilience Workflows with MCP Server

Resilience workflows often need to connect with ticketing systems, collaboration tools, and security platforms outside the Commvault platform, and they need to be accessible to users who aren’t resilience experts. Commvault’s MCP server makes it possible to extend workflows without custom integrations or significant training by allowing conversational interaction.

Users can ask questions or request actions in natural language, with their prompts translated into governed API calls behind the scenes – for example, to automatically create tickets in ServiceNow for failed jobs.

Coordination and Clarity Across Teams and Platforms

The examples above share a common theme: coordination. Effective resilience requires visibility, policy enforcement, and clean recovery across environments. AI can help strengthen these capabilities by helping teams identify what matters and act more quickly.

While the evolution of resilience from reactive recovery to continuous insight and guided action has become essential, it doesn’t need to happen all at once. Teams can start with targeted agents that address specific operational pain points and then build toward more coordinated operations as capabilities mature and teams gain confidence.

The key is to begin the ResOps journey now – because the challenges posed by evolving resilience requirements will only keep growing.

Watch the full webinar on-demand to see detailed demos of Arlie Data Sense, Arlie Advisor, and conversational resilience in action, and explore how AI-enabled ResOps can help support your operational workflows.

FAQs

Q: What is resilience operations?

A: ResOps is an operating model that unifies data security, identity resilience, and cyber recovery into a continuous, automated discipline rather than treating them as separate IT functions. ResOps helps transform resilience from a reactive response to incidents into an active practice that helps continuously understand data access patterns, detect threats and anomalies, and enable fast, intelligent recovery at scale.

Q: What is Arlie and how has it evolved?

A: Arlie, short for autonomous resilience, was first introduced in 2023 as an AI assistant to help users navigate the Commvault platform more easily. As AI capabilities have evolved, Arlie has evolved as well.

In addition to answering questions and guiding configuration, Arlie now also includes a library of purpose-built agents to address specific resilience workflows, such as surfacing operational insights, recommending protection strategies, and guiding security-aware recovery decisions. Arlie has become an entry point into operational insight rather than just a how-to assistant.

Q: How does Arlie Data Sense help with operational troubleshooting?

A: Arlie Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find subtle warning signs or diagnose issues, users can trigger Arlie to analyze the full data set and generate an executive summary highlighting patterns, anomalies, and emerging issues.

Teams can ask follow-up questions in natural language and explore data through interactive summaries or visualizations. For failed jobs, Arlie provides root-cause analysis by analyzing logs, summarizing failures, identifying possible causes, and providing personalized next steps for resolution.

Q: What does “guided action” mean in the context of AI-enabled resilience?

A: Guided action refers to AI helping teams move from insight to response more efficiently by recommending specific actions based on analysis of operational data and protection coverage. Rather than simply surfacing information, AI agents like Arlie Advisor help evaluate resource characteristics, identify gaps between current protection and policy expectations, and present clear recommendations with reasoning.

Teams retain decision-making authority and can evaluate recommendations within their existing governance processes, but the agent helps reduce the manual effort required to identify what needs attention and what actions may be appropriate.

Q: How does MCP server enable conversational resilience workflows?

A: MCP server uses Model Context Protocol technology to enable conversational interaction with resilience workflows through natural language. Users can ask questions or request actions in everyday language, and those requests are translated into governed API calls behind the scenes.

Identity, role-based access control, and audit logging remain in place, so the conversational interface doesn’t bypass security requirements. This approach helps reduce friction for experienced teams, lower barriers for new users, and enable resilience workflows to integrate more easily with other enterprise systems like ticketing platforms through standardized interfaces.

Q: How does Commvault enable AI to respect security and governance requirements?

A: In Commvault Cloud, AI interactions inherit the same identity and role-based access controls that govern the rest of the platform. When AI surfaces insights or recommends actions, it operates within the governance framework customers already rely on.

This means AI respects existing access controls, maintains auditability through standard logging, and operates within clearly defined policy boundaries. The architecture is designed to prevent natural language interactions or agent recommendations from bypassing the security and governance requirements already in place for the platform.

Q: Can organizations adopt AI-enabled ResOps incrementally?

A: Yes. Organizations can start with targeted AI agents that address specific operational pain points rather than transforming their entire resilience practice at once. For example, teams might begin by using Arlie Data Sense to help surface insights from operational data, then add Arlie Advisor to help maintain protection coverage at scale, and later enable conversational workflows through MCP server for easier integration with other systems.

This incremental approach allows teams to build confidence with AI-enabled capabilities, demonstrate value in specific workflows, and scale toward more coordinated, intelligent operations over time as the organization’s needs and capabilities evolve.

Vir Choksi is Principal Product Marketing Manager at Commvault.

Related Blogs

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Note: “MCP 2.0” is used here as a colloquial reference to the next-generation evolution of the Model Context Protocol. MCP itself uses date-based versioning (e.g., the latest release being 2025-11-25 at the time of this document’s release) and does not officially define a 2.0 release.

AI agents are no longer just answering questions – they’re taking action. They’re reading files. They’re modifying systems. And in some cases, they’re making decisions that ripple across an entire enterprise.

That’s why Model Context Protocol (MCP) 2.0 matters.

In a recent episode of STRIVE, Commvault’s thought leadership series on cyber readiness, I sat down with Werner Nel, Principal, Security and AI Intelligence, at Commvault, to unpack what MCP 2.0 really changes – and why security leaders can’t afford to treat it as a minor spec update.

This isn’t a theoretical conversation. It’s a practical look at how enterprises can enable AI innovation without widening their blast radius.

Key Takeaways: What MCP 2.0 Really Changes

  • MCP 2.0 marks a shift from AI adoption to accountability.
  • OAuth can enable least-privilege access for AI agents.
  • Structured schemas may help mitigate prompt injection and abuse.
  • Elicitation flows can add critical pause points for high-risk actions.
  • MCP 2.0 may help improve security – but doesn’t eliminate risk.
  • Understanding agent authority and blast radius is essential.

Why MCP 2.0 Is a Turning Point

MCP 1.x was about adoption.

It gave enterprises a way to connect AI models to real tools and real data. But as Werner explains, that first wave was never designed to answer the hardest question: How do we let AI agents execute real work inside the enterprise – without turning them into a security liability?

MCP 2.0 is the industry’s first serious attempt to answer that question.

Instead of focusing purely on connectivity, it shifts attention to authorization, control, and visibility – three things security teams care deeply about, especially as agents move from read-only assistants to actors with real power.

The Three Security Shifts That Matter Most

  1. OAuth comes to MCP. MCP 2.0 introduces OAuth support, giving enterprises a standardized way to assign permissions and enforce least privilege. Instead of relying on vague trust assumptions, agents can be scoped to exactly what they’re allowed to do—and nothing more.
  2. Structured schemas help reduce prompt injection risk. Structured schemas act like an allowlist for agent actions. If a tool isn’t explicitly defined in the schema, it won’t execute. This can help reduce prompt injection risk and other manipulation techniques that were easier to exploit in earlier implementations.
  3. Elicitation flows add a “pause button.” Elicitation flows can enable workflows to pause mid-execution so a high-risk step may trigger confirmation, validation, or even credential escalation. This can help shift teams from “log and hope” to more deliberate control over sensitive actions.

Sneak Peek: MCP 2.0 in Action

This preview highlights why authority, blast radius, and reversibility are the three most important questions enterprises should be asking as they deploy AI agents.

The Gaps MCP 2.0 Doesn’t Solve (And Why That’s Important)

MCP 2.0 is a big step forward – but it’s not the finish line. As Werner highlights in STRIVE, there are still meaningful gaps enterprises need to account for in real-world deployments.

For example, enterprises still can’t fully cryptographically prove that an MCP server is the authentic original (vs. a clone or modified copy). Similarly, even if the protocol improves authorization and input discipline, organizations still need to think about signing tools and binaries, and about the environment where MCP servers and models run – because a compromise can translate into broad access depending on how it’s deployed.

The takeaway: MCP 2.0 improves the protocol, but organizations still have to make smart decisions about trust, containment, monitoring, and oversight.

A Simple Framework for Evaluating AI Agent Risk

One of the most practical moments in the episode is Werner’s three-question risk lens – something CISOs and architects can apply immediately:

  • What authority does my agent have?
  • How big is the blast radius?
  • How reversible is the action being taken?

These questions help teams move from generic “AI risk” discussions to concrete decisions about permissions, containment, and how to handle high-impact actions that may not be easy to roll back.

Watch the Full STRIVE Episode

This blog only scratches the surface. In the full 20-minute STRIVE podcast, you’ll hear:

  • Why MCP 2.0 evolved so quickly.
  • What CISOs should prioritize right now.
  • Where MCP 3.0 is likely headed.
  • How security teams can keep pace as agents become more autonomous.

Watch the full STRIVE episode on the Readiverse.

Go deeper and assess your own readiness.

FAQs

Q: What is MCP 2.0?

A: MCP 2.0 is an updated protocol that governs how AI models interact with enterprise tools and data, with a strong focus on security, authorization, and control.

Q: How is MCP 2.0 different from MCP 1.x?

A: MCP 1.x focused on connectivity and onboarding. MCP 2.0 prioritizes securing those interactions.

Q: Does MCP 2.0 eliminate AI security risk?

A: No. It can help improve security hygiene but must be paired with strong architecture and governance.

Q: What is an elicitation flow?

A: An elicitation flow allows AI workflows to pause for confirmation before executing high-risk actions.

Chris Mierzwa is Senior Director, Portfolio Marketing, at Commvault.


Related Blogs

 

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

When you’re responsible for powering communities across southern Minnesota, cybersecurity isn’t just about protecting data. It’s about making sure the lights stay on. For Southern Minnesota Municipal Power Agency (SMMPA), implementing Commvault® Cleanroom Recovery was a strategic decision that transformed their approach to cyber resilience.

Meeting the Challenge Head On

SMMPA serves as an electric wholesaler to 17 municipal utilities. With approximately 50 employees supporting critical power infrastructure, the organization must maintain constant resilience against increasingly sophisticated cyber threats, where even a short disruption could have widespread impact.

After more than a decade as a Commvault customer, SMMPA faced a new wave of cyber readiness requirements. Cyber insurance providers introduced stricter mandates, including air-gapped backups and malware scanning at rest.

At the same time, the team needed confidence that it could rapidly recover mission-critical systems such as domain controllers, SQL databases, and application servers, without risking the restoration of compromised data.

“As our cyber readiness requirements evolved, we started evaluating Cleanroom Recovery more seriously,” says Alan Wagner, Manager of IT & Corporate Cybersecurity at SMMPA. “We were thinking about additional ways to safeguard and protect ourselves. Cleanroom sounded like it would be a good solution for that.”

Having relied on Commvault for more than a decade and recently expanding into Commvault Cloud SaaS protection for Microsoft 365, SMMPA viewed Cleanroom Recovery as a natural next step in strengthening its cyber resilience strategy and helping it meet new compliance expectations.

A Collaborative Implementation Journey

SMMPA’s Cleanroom Recovery deployment in March 2025 showcased the power of collaboration between its team and Commvault. Sam Mack, IT/OT and Cybersecurity Specialist at SMMPA, appreciated the responsive partnership: “The Commvault team was quick to address any questions we had during setup.”

The team worked together to optimize its VMware virtual machine configuration for the Azure environment. “We discovered we needed to install some additional tools on the virtual machines to get them running smoothly within Cleanroom Recovery,” Sam explains. This fine-tuning meant its recovery solution was calibrated for its specific infrastructure.

The result? A successful implementation that met all SMMPA’s requirements and positioned it for robust cyber resilience.

Protecting What Matters Most

SMMPA uses Cleanroom Recovery to protect its critical infrastructure, including file servers, application servers, SQL servers, virtual domain controllers, and print servers.

“We’re an Office 365 shop, and we use Commvault Cloud to back up that infrastructure,” Sam says. “In the event of a compromise, getting those domain controllers, file servers, and SQL servers is going to be our priority.”

The solution was particularly well suited to SMMPA’s environment. “I have to give Commvault and their teams a lot of credit for bringing Cleanroom Recovery to our attention,” Sam says. “Our cyber insurance policy is really big on pushing for air-gapped backups and malware scanning at rest, so Cleanroom Recovery was the perfect fit.”

The Value of Confidence

While SMMPA has been fortunate not to face a real-world cyberattack requiring Cleanroom Recovery, the solution provides valuable peace of mind to the team.

“It gives me a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time,” Alan says. “Cleanroom Recovery gives us confidence that we can restore our systems without worrying that something malicious is being brought back with the data. Nothing is ever 100% guaranteed, but since implementing Cleanroom Recovery, I’ve had far fewer concerns.”

The organization conducts annual testing of its Cleanroom Recovery capabilities, with plans to potentially increase the frequency to biannual testing. This regular validation helps keep the team familiar with the recovery process and maintain confidence in its ability to respond effectively to any incident.

“Cleanroom Recovery gives us a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time – without the concern, or with a minimal concern, that there’s something malicious in the data being restored.”

– Alan Wagner, Manager of IT & Corporate Cybersecurity, SMMPA

As SMMPA continues to refine its cybersecurity strategy, Cleanroom Recovery remains a cornerstone of its defense. The straightforward integration with its existing Commvault infrastructure, combined with the specific capabilities that meet its cyber insurance requirements, made it an obvious choice.

Cara Peterson is Voice of the Customer Manager at Commvault.


Related Blogs

More related posts


CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Key Takeaways

  • Commvault is expanding its identity resilience portfolio to support Okta, with Early Access expected to begin in April 2026.
  • Identity has become a primary attack vector, with 107 billion identity records exposed in 2024 and 57% of cyberattacks starting with compromised credentials.
  • The new capabilities can help provide automated, policy-driven protection and granular, point-in-time recovery for critical Okta objects and configurations.
  • Backup data is stored in immutable, air-gapped storage to help safeguard identity environments from ransomware and unauthorized changes.
  • The solution extends Commvault’s unified identity resilience platform across hybrid environments and will be priced on a per-user basis.

Identity has become the new frontline of cyber defense – and the stakes have never been higher.

Today, Commvault is announcing the expansion of its identity resilience portfolio to include support for Okta, delivering automated protection and rapid recovery for one of the enterprise’s most critical control planes. Early Access is expected to begin in April 2026.

As credential theft accelerates and identity exposures surge worldwide, organizations can no longer treat identity systems as simply another application. Identity is the gateway to everything – users, applications, APIs, automation, and increasingly, AI agents. When identity fails, the business stops.

Why Identity Resilience Matters Now

The numbers tell a stark story:

The rapid growth of non-human, agentic, and API-based identities has dramatically expanded the attack surface. Meanwhile, hybrid cloud adoption, SaaS sprawl, and AI-enabled automation have elevated identity providers like Okta to mission-critical infrastructure.

While Okta is built on a resilient platform, when an identity provider is disrupted – whether due to human error, misconfiguration, ransomware, or malicious tampering – the consequences are rapid:

  • Users are locked out.
  • Applications fail to authenticate.
  • Revenue-generating systems stall.
  • Customer-facing services go offline.

And yet, many enterprises still rely on manual scripts and ad hoc processes to restore identity environments – increasing downtime, operational complexity, and risk.

That’s the gap Commvault is helping to close.

Bringing Automated Identity Recovery to Okta

Commvault’s expanded identity resilience capabilities can help provide automated protection and granular recovery for critical Okta objects and configurations.

Rather than rebuilding entire environments after an incident, organizations can precisely restore what was impacted – quickly and confidently.

“Identity is the new cyber battleground, with most modern attacks targeting identity systems,” said Pranay Ahlawat, Chief Technology and AI Officer at Commvault. “By extending our identity resilience capabilities to Okta, we’re helping customers protect one of their most critical control planes and helping ensusre they can rapidly recover access and maintain business continuity even in the face of disruption.”

Key Capabilities

Accelerated recovery from identity disruptions: Automated, policy-driven protection of critical Okta objects – including users, groups, applications, and policies – can help organizations to restore access quickly following outages, operational mistakes, or cyber incidents.

Granular, point-in-time recovery: Can help precisely restore only deleted, misconfigured, or compromised objects and settings. No full-environment rebuilds required.

Ransomware-resistant protection: Backup data is stored in Commvault-managed immutable, air-gapped storage isolated from production environments, helping safeguard identity data from ransomware and unauthorized changes.

Streamlined, integrated recovery: Recover complex, interconnected identity systems through a unified workflow – helping reduce operational overhead and save valuable time during incidents.

Unified identity resilience platform: Support for Okta extends Commvault’s single-platform approach across hybrid identity environments, helping maintain consistent policy enforcement, governance, and recovery across providers.

Early Access Coming April 2026

Commvault’s identity resilience support for Okta is expected to be available through public Early Access in April 2026, with general availability planned for Summer 2026.

The solution will be offered globally as part of the Commvault Cloud Identity Resilience suite and priced on a per-user basis.

If identity is now the enterprise control plane, resilience must extend to identity itself. With support for Okta, Commvault continues advancing unified resilience at enterprise scale – helping organizations recover faster, minimize disruption, and stay operational in the face of escalating identity-driven cyber risk.

Learn more about identity resilience here. Register now for our webinar Identity Under Attack: Take Back Control with Commvault Identity Resilience, Now Supporting Okta.

FAQs

Q: Why is identity resilience becoming a top priority for enterprises?
A: Identity systems now function as the enterprise control plane, governing access for users, applications, APIs, and AI agents. As credential theft and identity-based attacks increase, disruptions to identity providers can immediately halt business operations. Protecting and recovering identity infrastructure has become mission-critical.

Q: What does Commvault’s support for Okta include?
A: The expanded capabilities help provide automated protection and granular recovery for essential Okta objects such as users, groups, applications, and policies. This will help organizations restore specific items impacted by outages, misconfigurations, or cyber incidents without rebuilding entire environments.

Q: How does granular, point-in-time recovery benefit security teams?
A: Instead of performing full-environment restores, teams can precisely recover only deleted or compromised objects and settings. This approach helps reduce downtime, lower operational risk, and accelerate restoration of normal access.

Q: How does Commvault protect identity data from ransomware?
A: Backup data is stored in immutable, air-gapped storage managed by Commvault and isolated from production environments. This architecture helps safeguard identity configurations from ransomware and unauthorized modifications.

Q: When will Okta support be available?
A: Public Early Access is expected to begin in April 2026, with general availability planned for Summer 2026. The offering will be available globally as part of the Commvault Cloud Identity Resilience suite.

Q: How does this expansion fit into Commvault’s broader resilience strategy?
A: Adding Okta support helps strengthen Commvault’s unified, single-platform approach to identity resilience across hybrid environments. It enables consistent governance, policy enforcement, and recovery workflows, helping organizations maintain business continuity even during identity-driven disruptions.

Katharine Colucci is a Product Marketing Manager at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Periods of geopolitical instability, including the current conflict in the Middle East, can lead to an increase in cyber activity from both state‑linked groups and opportunistic threat actors. Government agencies and industry organizations have encouraged businesses to maintain a heightened security posture during this time.

At Commvault, we’re doing exactly that. We’ve elevated our internal awareness, tightened our operational discipline, and reinforced our resilience measures. Commvault also works with a trusted threat intelligence partner, CloudSEK, to help monitor evolving risks and inform our security posture. We encourage our customers, partners, and peers across the industry to take similar steps to stay informed and reinforce core cyber controls.

What organizations should focus on right now

1. Know when to shift into “heightened alert” mode

Have clear internal criteria for when to increase monitoring, limit non-essential changes on critical systems, or accelerate incident‑response readiness. These moves don’t need to be dramatic – they just need to be deliberate and well‑coordinated.

2. Strengthen identity and access discipline

During periods of heightened regional tensions, many threat actor campaigns rely on compromising user accounts. Reinforce good hygiene: regular credential rotation, strong authentication, careful review of unusual login behavior, and prompt investigation of anything that looks out of place. For practical steps to reduce identity-related risk, see Commvault’s recent blog on Security Best Practices.

3. Pay closer attention to your internet-facing perimeter and remote access

Threat actors often take advantage of internet‑facing systems or remote access tools during global flare‑ups. Ensure these systems are well‑maintained, updated, and monitored.

4. Be prepared for potential availability disruptions

DDoS and hacktivism activity often spikes during regional conflicts. Talk with your service providers, understand your mitigation options, and rehearse your internal escalation and communications plan so you’re ready if availability becomes a target.

5. Validate your ability to recover quickly

In times of uncertainty, resilience matters as much as prevention. Ensure your critical data is backed up securely, stored in multiple forms and locations, and restorable on short notice. Practicing recovery is just as important as having the backups themselves.

6. Watch for misinformation, social engineering, and false noise

Periods of conflict tend to bring surges in defacements, false breach or shutdown claims, and social‑media‑driven narratives. Treat sensational claims cautiously, verify impacts through trusted channels, report suspicious communications quickly, and maintain steady communication practices.

7. Stay aligned with trusted advisories

Follow alerts and guidance from reputable government and industry bodies. These sources regularly highlight shifts in regional threat activity and recommend practical steps organizations can take to prepare. A few resources include: CISA Cybersecurity AdvisoriesUK NCSC Reports & AdvisoriesCERT-EU Security Advisories; and NIST National Vulnerability Database.


Stay ready, stay resilient

Cybersecurity during global instability is not about panic, it’s about posture. By staying informed, tightening foundational practices, and strengthening resilience, organizations can navigate turbulent periods with confidence.

If you’d like help reviewing your preparation or refining your approach, our team is here to support you.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • Traditional resilience strategies are breaking down under the scale, speed, and autonomy of AI-enabled systems.
  • Industrialized ransomware and AI-powered attacks now target backup systems, undermining the foundation of recovery.
  • Organizations must shift from siloed security and recovery teams to a unified, continuous model called resilience operations.
  • AI resilience requires real-time data visibility, continuous threat detection, and intelligent, clean recovery at scale.
  • Modern platforms enable fast and verified recovery, helping organizations avoid the tradeoff between restoring quickly and restoring safely.

As organizations race to adopt AI, CISOs and CIOs are coming to a stark realization: The resilience strategies that worked for traditional infrastructure are breaking down. Systems that could recover from attacks in hours may now take days. Backup approaches designed for centralized data may struggle with workloads distributed across clouds and AI platforms. Meanwhile, threats and potential vulnerabilities grow by the day.

In a recent webinar, Tim Zonca, vice president of portfolio marketing at Commvault, addressed an urgent question facing security leaders: How do you maintain resilience when AI fundamentally changes the rules?

What Industrialized Ransomware and AI Mean for Resilience

CISOs and CIOs are under pressure. In spite of billions spent on cyber defense, nation-states and professional crime rings continue to reap ever larger payoffs from their victims. Ransomware-as-a-service has become widespread, and advanced AI automation is accelerating the industrialization of malware. By including backup systems in their attacks, adversaries are undermining the very foundation of resilience.

As attacks become more sophisticated, targets are becoming more vulnerable. AI is scaling faster than organizations can secure, with exponential data growth, fragmentation across environments, more complex supply chains, and autonomous systems operating with minimal oversight. AI agents and non-human identities now outnumber humans 80 to 1. When these systems make mistakes or expose vulnerabilities, the impact can cascade across interconnected business processes.

Breaches and failures are now almost inevitable; the only question is whether you can recover fast enough to keep your business running. For organizations using legacy systems that assume human-controlled systems, centralized data, and isolated failures, the answer may well be no.

Making Resilience Operational

As AI agents make decisions across the environment, including a significant number of errors, it’s no longer enough to focus on protecting infrastructure. Security leaders must now broaden their operational focus across three critical areas:

  • Continuously securing data at the source and monitoring for anomalies.
  • Controlling the identities of individuals, non-human identities, and devices that access and use data autonomously.
  • Achieving predictable recovery of data at massive scale without compromise or corruption.

Traditionally, data security, identity resilience, and cyber recovery have functioned as independent disciplines, each with its own team, tools, policies, and requirements. These silos leave vulnerabilities for attackers to exploit and slow recovery when AI systems fail. To close those gaps, organizations must unify these capabilities into a continuous, automated loop. We call this approach resilience operations (ResOps).

ResOps encompasses three essential requirements for AI resilience:

  • Understanding your data landscape: Knowing where data lives, its sensitivity, who’s accessing it (including AI agents and non-human identities), and what policies govern that access in real time. For AI workloads, this extends to protections like LLM prompt governance to control how models access data.
  • Continuous threat detection: Automated systems that constantly monitor for anomalies, compromised identities, and data corruption. When AI systems are making thousands of autonomous decisions, you can’t wait for periodic security reviews.
  • Intelligent recovery: Automated, comprehensive restoration for entire cloud-native applications and their dependencies. To prevent re-infection, teams must validate data integrity and conduct forensic analysis in an isolated cleanroom before moving trusted data back to production.

Enabling ResOps in practice

To help companies make the move to ResOps, Commvault has introduced Commvault Cloud Unity, the most significant platform release in our history. It is designed to bring together all three dimensions of resilience:

  • Bringing together data security, identity resilience, and cyber recovery under one operational model.
  • Protecting all workloads, from both today’s production systems to tomorrow’s emerging AI stacks.
  • Safeguarding data regardless of location, whether in clouds, regions, data centers, or edge locations.

A next-generation architecture brings AI automation to all facets of data protection, data security, identity resilience, and recovery. For security and IT teams, the platform provides simplicity at scale with one experience, one policy engine, and one interface designed to protect data, predict threats, and accelerate clean recoveries.

As security leaders know all too well, recovering from the most recent backup minimizes data loss but risks restoring compromised data. Rolling back to a verified clean state may eliminate threats but means losing hours or days of business-critical transactions or AI model training.

With Commvault Cloud, continuous threat monitoring and verified clean recovery points help eliminate this forced choice. The platform architecture automatically maps dependencies across distributed systems, helps maintain immutable backups, and helps enable one-click restoration of entire environments. Recovery can be both fast and clean, helping minimize loss as well as risk.

See ResOps in action

Watch the full webinar on-demand to learn more about ResOps, explore the architecture and services of Commvault Cloud, and rethink your resilience strategy for the AI age.


FAQs

 Q: What is Resilience Operations (Res Ops)?

A: ResOps is an operating model that unifies data security, identity resilience, and cyber recovery into a continuous, automated discipline rather than treating them as separate IT functions. ResOps transforms resilience from a reactive response to incidents into an active practice that continuously understands data access patterns, helps detect threats and anomalies, and enables fast, intelligent recovery at scale.

Q: Why can’t traditional backup and recovery handle AI workloads?

A: Traditional backup tools were designed for centralized, human-controlled systems with isolated failures. AI workloads involve autonomous agents accessing distributed data across clouds and complex dependencies between microservices and containers, and they operate at a scale that manual processes can’t match.

When AI systems fail or are attacked, you need to recover not just data but entire application infrastructures with all their configurations, policies, and relationships – capabilities traditional backup tools lack.

Q: What does “unified resilience” mean in practice?

A: Unified resilience means bringing data security, identity management, and cyber recovery together under a single platform, policy engine, and operational model rather than managing them as separate functions with different teams and tools.

In practice, this provides a consistent approach to protect all workloads and data locations, automatically correlate security events with access patterns, and orchestrate comprehensive recovery that restores both data and the complete application infrastructure needed to use it.

Q: What’s the difference between cyber resilience and AI resilience?

A: Cyber resilience focuses on protecting infrastructure and recovering from security incidents, treating resilience as an operational state for confronting threats. AI resilience expands this to address challenges unique to AI-driven systems: autonomous agents making decisions with minimal oversight, exponential growth of data and non-human identities across environments, and cascading failures where problems in interconnected AI systems impact entire business operations rather than staying isolated.

Q: How does ransomware target backup systems?

A: Ransomware increasingly targets backup systems by exploiting compromised credentials with privileged access, moving laterally from production systems to connected backup repositories, or exploiting vulnerabilities in backup software itself. Modern ransomware families specifically hunt for backup infrastructure to encrypt or delete recovery points, preventing organizations from restoring clean data and maximizing pressure to pay ransom. This makes offline, immutable, or air-gapped backups essential for resilience.

Q: What is the clean vs. complete recovery dilemma?

A: The clean vs. complete recovery dilemma is the forced choice organizations face during incident response. You can recover from the most recent backup to minimize data loss but risk restoring compromised or corrupted data; or you can roll back to a verified clean state before the incident to eliminate threats but lose significant business-critical data. Traditional backup tools make organizations choose between completeness and safety, while modern resilience platforms aim to provide both simultaneously through continuous threat monitoring and verified recovery points.

Q: What is a cleanroom in cyber recovery?

A: A cleanroom in cyber recovery is an isolated, secure environment completely separated from production systems to help organizations safely test, validate, and analyze recovered data before restoring it to active use. Cleanrooms help enable forensic investigation of compromised systems, testing of recovery procedures, and verification that restored data is free from malware or corruption – all without risking reinfection of production environments or exposing sensitive data during analysis.

Sam Curcuruto is Director of Product Marketing at Commvault.


Related Blogs

Re-envisioning Resilience for the Age of AI

A CIO’s Perspective: Strengthening Business Resilience in the AI Era

Resilient Against the AI Machine

Cleanroom Recovery Innovations Enable a New Era in Cyber Resilience

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • “Instant restore” claims often break down at scale due to real-world I/O operations per second (IOPS), rehydration, and infrastructure constraints.
  • Mass live mounts on deduplicated backup storage can cause performance collapse, forcing slow rehydration back to primary storage.
  • Cleanrooms help enables parallel forensic investigation and business recovery instead of serial, delay-driven downtime.
  • Identity compromise expands the blast radius, making isolated recovery and Active Directory (AD) restoration critical to secure operations.
  • Automated cleanroom runbooks and repeatable testing help organizations validate real recovery metrics before a crisis occurs.

Let’s start with a quick story about a “ransomware‑proof” environment that took 72 hours to recover, way beyond the organization’s expectations for recovery time objective. It is exactly the kind of situation where Commvault’s Cleanroom Recovery could have helped turn a painful, three‑day outage into a faster, more controlled recovery with less risk.

War Story: Physics vs. Marketing

On Reddit, a user shared how the financial services firm they work for was hit by a breach. They assumed they had a “dream stack” for quick recovery (but can you really have a “dream stack” without Cleanroom Recovery?): immutable backups, secure storage snapshots, and a modern hypervisor. The datasheets promised “instant mass restore,” yet the business sat offline for three days while everyone tried to drag their environment back to life.

The root cause was not that backups failed, but that the real‑world physics of rehydration, forensics, and identity were never tested at scale. The original poster mentioned that having access to a cleanroom environment would have sped up the process. Let’s dig into this further and address why.

Commvault’s Cleanroom Recovery is designed to address exactly these weak points: It helps automate clean, isolated recovery into the cloud, validates data, and orchestrates recovery in a way that aligns with how incidents actually unfold, not just how diagrams look on slides.

Problem 1: The Rehydration Trap

In the story, “live mounting” a handful of virtual machines (VMs) worked fine, but trying to live mount hundreds crushed the backup appliance. The random I/O running directly on deduplicated, compressed backup storage collapsed the IOPS, forcing the team to rehydrate everything back to primary Non-Volatile Memory Express at about 3 TB/hour for roughly 100 TB of data.

Commvault Cleanroom Recovery helps recover workloads into an isolated Azure‑based cleanroom built on scalable cloud compute and storage instead of trying to run production at scale off a backup appliance.

This allows you to restore critical VMs into a purpose‑built recovery environment, use cloud elasticity to absorb I/O, and automate the recovery sequence so the right systems (identity, core apps, critical data) come up first without bottlenecking on a single backup target.

Problem 2: The Forensic Drag

In the audit, the tech stack was ready in about four hours, but legal delayed touching anything for 72 hours because they had no pre‑provisioned cleanroom. Without an isolated environment with zero routes back to production, the forensics team could not safely investigate while the business recovered, so everyone waited for the all-clear before starting any real restore.

Cleanroom Recovery provides an on-demand, isolated recovery environment explicitly built for simultaneous recovery and forensic analysis. You can spin up a fenced cleanroom in Azure in hours, recover systems into it, and let security and legal teams perform read‑only forensics and threat scanning while operations validates applications and prepares for cutover – dramatically shrinking “forensic drag” as a contributor to downtime.

Problem 3: Identity Blast Radius

The environment in the story had a single admin account with access to both the hypervisor and backup console, which meant if attackers pivoted that far, immutability could become just another setting they flipped off. Identity, not just data, was the real blast radius problem.

Cleanroom Recovery is designed to help reduce dependency on the compromised production identity plane during recovery, allowing isolated access and planned support for AD restoration in the cleanroom.

By recovering identity services into an isolated cleanroom and using separate, least‑privilege access paths, you can help validate AD, help enforce proper authorizations, and help protect backup control planes from being trivially compromised by the same credentials that were used in production.

How Cleanroom Recovery Would Change This Story

If this customer had used Cleanroom Recovery, their recovery story could have been very different.

For organizations that already invest in “ransomware‑proof” stacks, the missing piece is often not more features but a cleanroom strategy that respects physics, identity, and legal reality. Commvault Cleanroom Recovery is designed to close that gap and help turn recovery from a three‑day war story into a controlled, provable, and much faster operation.

FAQs

Q: Why did the “instant mass restore” approach fail in the ransomware scenario?
A: While live mounting a few VMs worked, scaling to hundreds overwhelmed the backup appliance due to I/O constraints. Deduplicated and compressed backup storage is not designed to handle full production workloads at scale, leading to performance collapse and delayed recovery.

Q: What is the “rehydration trap” in disaster recovery?
A: The rehydration trap occurs when organizations must restore large volumes of compressed backup data back to primary storage before systems can operate normally. This process is limited by throughput rates, which can dramatically extend recovery times when dealing with tens or hundreds of terabytes.

Q: How does a cleanroom help reduce forensic-related downtime?
A: A cleanroom provides an isolated environment where forensic teams can safely investigate while IT simultaneously restores systems. This parallel approach helps eliminate long waiting periods for legal or security approval before beginning recovery efforts.

Q: Why is identity such a critical factor in ransomware recovery?
A: If attackers compromise administrative credentials tied to both production and backup systems, immutability controls may no longer provide protection. Isolated identity recovery and least-privilege access can help limit blast radius and support a safer restoration process.

Q: How does Cleanroom Recovery help improve recovery orchestration?
A: Cleanroom Recovery helps automates workload sequencing, cleanpoint validation, and cloud-based recovery infrastructure provisioning. This structured approach aligns recovery with how incidents actually unfold, helping organizations regain control faster and with greater confidence.

Q: What is the strategic lesson for organizations with “ransomware-proof” stacks?
A: Advanced features alone do not guarantee fast recovery. A cleanroom strategy that accounts for infrastructure physics, identity isolation, and legal realities helps enable organizations to turn theoretical resilience into measurable, repeatable recovery performance.

Nico Guerrera is Senior Solutions Marketing Manager at Commvault.

Related Blogs

Active Directory Forest Recovery: Why Manual Methods Are No Longer Viable

Recovery Testing: The Missing Piece in Most Cyber Resilience Programs

Your Modern Playbook for Rapid Response and Clean Recovery

Unlocking Cyber Resilience: The Power of Cleanrooms

Why Cleanroom Recovery and Cyber Testing are Critical for Cyber Resilience

More related posts


Cyber Resilience

Read more about Cyber Resilience

In the current cybersecurity landscape, we are drowning in data but starving for insight. Traditional AI excels at pattern recognition (correlation), but in high-stakes security environments, correlation is a liability.

Causal AI provides the “reasoning” (the why), while agentic AI provides the “execution” (the how). To build truly resilient systems, we must move beyond predicting threats to understanding the causal mechanisms that allow them to flourish.

1. The Problem Statement: The Crisis of Trust

Modern Security Operations Centers (SOCs) face a fundamental trust gap. Legacy predictive models often flag “anomalies” that are merely noise, leading to alert fatigue.

  • The problem: Data is noisy, correlated, and lacks labels.
  • The consequence: Analysts struggle to distinguish between a “correlated event” (a user logging in from a new IP) and a “causal event” (that login directly initiating unauthorized data egress).
  • The solution: Integrating causal AI to provide an auditable, human-readable logic chain for every automated action.

2. Causal AI in Action: Cybersecurity Use Cases

By applying structural causal models, organizations can shift from reactive patching to proactive resilience.

  • Causal chain of breach formation: Instead of viewing a breach as a single event, causal AI maps the “butterfly effect” of minor configuration changes and how they chain together to create a critical vulnerability.
  • Optimal control selection: If a budget only allows for one upgrade, causal AI can simulate the “do-calculus”: If we implement micro-segmentation instead of endpoint detection and response, how does the causal probability of lateral movement change?
  • Vulnerability prioritization via causal risk: Move beyond the static Common Vulnerability Scoring System. Use causal AI to prioritize vulnerabilities based on their actual “causal reachability” within your specific network topology.
  • Digital twins for posture simulation: Create a “security digital twin” to run “what-if” interventions. This allows CISOs to stress-test resilience strategies in a virtual environment before deploying them to production.

3. The Resilience Framework: Reasoning + Execution

True resilience is the ability of a system to maintain state and purpose during an attack. We propose a two-tier architecture:

Component Role Analog
Causal AI Reasoning & decisioning The brain
Agentic AI Execution & recovery The hands
The Feedback Loop:

When an agentic AI performs a task (e.g., isolating a compromised server), causal AI monitors the logs (Step 4: State Recovery). If the agent fails, causal AI analyzes the telemetry to determine if it was a systemic failure or an external cause (e.g., “The agent didn’t fail; the inventory API returned a null value”).

4. Graceful Degradation and Fallback Tiers

Resilience requires knowing when to stop. We implement “causal fallbacks” so that if the AI reasoning becomes uncertain, the system degrades safely rather than failing catastrophically.

Tier 1: Full autonomy: Causal AI confirms high confidence in the root cause; agentic AI remediates.

Tier 2: Augmented human-in-the-loop: Causal AI provides the “reasoning path” to a human analyst for rapid approval.

Tier 3: Rules-based mode: The system reverts to “causal Six Sigma” logic – a strict, pre-defined safety protocol that prioritizes uptime over optimization.

Tier 4: Fail-closed: If causal integrity is lost, the system isolates critical segments to prevent the butterfly effect of a spreading breach.

5. Industry Impact: Beyond the SOC

  • Healthcare & Internet of Medical Things: Causal AI can distinguish between a malfunctioning heart monitor (systemic noise) and a targeted attack on medical telemetry.
  • Telecommunications & 5G: Managing the complex causal dependencies of network slicing to verify that a breach in a low-security slice cannot causally impact emergency services.

6. Measuring Success: The New KPIs

Success in a causal AI–enabled environment is measured by the quality of decisions, not just the quantity of blocked threats:

  • Mean time to causal discovery: The speed at which the true root cause is identified vs. the initial symptom.
  • Intervention efficacy: The percentage of security changes that resulted in the predicted reduction of risk.
  • Counterfactual accuracy: How closely the digital twin simulations match real-world incident outcomes.

What’s Next

The future of cyber resilience is not just smarter AI but more logical AI. By combining the execution power of agentic systems with the reasoning depth of causal AI, we can build security architectures that don’t just survive attacks – they understand them.

Vidya Shankaran is Field CTO at Commvault.

© 2025 Commvault. See www.commvault.com/IP for trademarks and patents.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • Commvault Cloud Backup & Recovery for DevOps now includes support for Atlassian Jira, extending enterprise-grade data protection to mission-critical project workflows.
  • Automated, policy-based backups and granular recovery options help teams quickly restore Jira spaces, work items, and configurations.
  • Built-in cyber resilience features such as immutable backups and isolated cloud storage help safeguard Jira data from ransomware and unauthorized changes.
  • Unified protection across Jira, Azure DevOps, GitHub, and GitLab reduces tool sprawl and simplifies DevOps data resilience.
  • Jira protection is available through Early Adopter access, with general availability planned for March 2026.

We are excited to announce the extension of Commvault® Cloud Backup & Recovery for DevOps to include support for Atlassian Jira. This update brings enterprise-grade protection, recovery, and cyber resilience to Jira, helping organizations safeguard mission-critical project data against data loss and cyber incidents.

With this release, teams now have a unified way to protect critical sprint plans, work items, and configurations alongside their code, pipelines, and repositories in Azure DevOps, GitHub, or GitLab, all with a single solution.

Why Protecting Jira Data Matters

Jira has become a cornerstone for many organizations, supporting everything from agile software development and product releases to IT service management. It houses the plans, workflows, and task data that teams depend on to help execute mission-critical work.

Despite its importance, Jira is not immune to data loss. Accidental deletions, misconfiguration, and malicious activity can quickly erase valuable project history and disrupt active work.

When Jira data is lost or becomes unavailable, teams lose visibility, sprints stall, releases are delayed, service commitments are missed, and productivity suffers as teams attempt to recreate lost information.

A reliable backup and recovery strategy for Jira is critical to help maintain continuous business and help minimize the risk of downtime, operational disruption, and potential failure to meet data retention or regulatory compliance requirements.

Enterprise-Grade Protection for Jira

Commvault Cloud delivers enterprise-scale protection and recovery for Jira, helping organizations safeguard mission-critical Jira data against cyber incidents, disasters, and operational mistakes.

Key features:

  • Automated, policy-based backups of Jira spaces, work items, and configurations, including attachments, custom fields, and board settings.
  • Granular recovery of individual spaces or work items, as well as full-site recovery to a specific point in time.
  • Simplified compliance through centralized control, audit logging, and extended retention to help support regulatory and internal requirements.
  • Cyber resilience with immutable backups, isolated cloud storage, and zero-trust design to help safeguard data from ransomware and unauthorized changes.
  • Unified protection for Jira, Azure DevOps, GitHub, GitLab, and other enterprise workloads from a single platform.

Unifying DevOps Data Resilience with Commvault

By unifying Jira protection with other DevOps platforms in Commvault Cloud Backup & Recovery for DevOps, enterprises can gain a holistic approach to data resilience across the full DevOps lifecycle – from planning and issue tracking to code and delivery. The result is fewer tools, reduced complexity, and confidence that sprint plans and backlog items are rapidly recoverable when it matters most.

Early Availability

Atlassian Jira protection is now available through Early Adopter access with general availability planned for March 2026.

Learn more about Commvault’s support for Atlassian Jira, here.

To learn more about how to get access to getting access to Jira protection or schedule a demo, contact your Commvault account team.

FAQs

Q: Why is backing up Atlassian Jira important?
A: Jira houses critical sprint plans, workflows, and issue data that many teams rely on to deliver projects and services. Data loss from accidental deletion, misconfiguration, or malicious activity can disrupt releases and impact productivity, making a reliable backup and recovery strategy essential.

Q: What Jira data can Commvault Cloud protect?
A: Commvault Cloud helps protect Jira spaces, work items, configurations, attachments, custom fields, and board settings. This comprehensive coverage helps organizations maintain full visibility and recover both detailed items and entire sites when needed.

Q: How does recovery work with Commvault Cloud for Jira?
A: The solution helps support granular recovery of individual spaces or work items, as well as full-site recovery to a specific point in time. This flexibility enables teams to restore exactly what they need without unnecessary disruption.

Q: How does this solution support compliance and cyber resilience?
A: Centralized control, audit logging, and extended retention help organizations meet regulatory and internal requirements. Immutable backups, isolated cloud storage, and a zero-trust design help strengthen protection against ransomware and unauthorized changes.

Q: Can Jira protection be managed alongside other DevOps platforms?
A: Yes. Commvault Cloud unifies protection for Jira with Azure DevOps, GitHub, GitLab, and other enterprise workloads within a single platform, helping reduce complexity and enable a holistic approach to DevOps data resilience.

Q: When will Jira protection be generally available?
A: Atlassian Jira protection is currently available through Early Adopter access, with general availability planned for March 2026. Organizations can contact their Commvault account team to learn more or schedule a demo.

Katharine Colucci is a Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog_DevOps_2025

Enhance Resilience with Backup & Recovery for DevOps

Read more about Enhance Resilience with Backup & Recovery for DevOps
Zz05MThhZTc3NmU0MTQxMWVmYTYwZWJlYTg2ZTllNjQ5Yw

A Blueprint for Effective Cloud Recovery

Read more about A Blueprint for Effective Cloud Recovery
Commvault-cloud-availability-LinkedIn

Experience True, Cloud Cyber Resilience – Available now in Commvault Cloud

Read more about Experience True, Cloud Cyber Resilience – Available now in Commvault Cloud
Thumbnail_Blog-SHIFT-Announcement-Recover-Clean-2025-Linkedin

Recover Clean, Recover Fast

Read more about Recover Clean, Recover Fast
Thumbnail_Blog–CloudRewind2025–Linkedin

Built for Resilience, Optimized for Scale: The Cloud Rewind Architecture

Read more about Built for Resilience, Optimized for Scale: The Cloud Rewind Architecture
Thumbnail_Blog-SHIFT-Announcement-Commvault-Cloud-Unity-2025-Linkedin

A New Era of Enterprise Resilience

Read more about A New Era of Enterprise Resilience

Key Takeaways

  • GigaOm recognized Satori as the only mature, platform-centric leader in data access governance.
  • Traditional security tools can fail to handle the rapid scale and complexity of modern data usage.
  • Data access governance platforms can provide real-time visibility, enforcement, and compliance evidence for data access.
  • Satori was founded to empower security teams with control over data access without slowing down analytics or AI innovation.
  • Integrating data access governance with recovery capabilities enables a proactive, resilient data security strategy.

The independent analyst firm GigaOm published its latest and placed Satori, a Commvault company, as the only mature, platform-centric leader in the category.

That recognition matters. Not because of the badge itself, but because it validates something many security and data leaders are feeling right now but don’t always have language for: In today’s AI era, data has become the foundation of modern business. At the same time, it has become a moving target. Governing data in this environment is increasingly impractical without a dedicated data access governance platform like Satori.

But let’s step back and look at the data security problem first.

The Real Problem with Data Security Today

The most prominent challenge organizations face today is not a lack of data. On the contrary, storing data is cheap, collecting it is easy, and acquiring external data is often straightforward. In recent years, even processing and extracting value from that data has become significantly more accessible.

It used to be that only specialized teams could analyze data. But today’s analytics tools and AI make it possible for almost anyone to do so, using more data than ever before. Analytics, self-service business intelligence, automation, and AI mean data is accessed more frequently, by more systems, and by more identities than ever before.

This transformation can deliver tremendous value for businesses. But without proper governance, it also can introduce significant risk. In most enterprises:

  • Data lives across many platforms and in thousands of different locations.
  • Access decisions are owned by engineering or data teams.
  • Security teams depend on others for answers and for applying security policies.

Add to this external pressure: compliance. There is growing regulatory pressure to continuously answer questions such as who accessed what data, when, and why. Organizations must also know where sensitive data such as personally identifiable information or protected health information resides, how access to production data is provisioned, and whether controls are consistently enforced.

Data and security teams are expected to answer these questions and place controls over the data, but they often lack the visibility, control, and evidence to do so confidently.

Why Is This Happening Now?

This situation didn’t develop overnight; several forces converged at the same time.

First, data usage scaled faster than governance. Access models that worked when data was accessed occasionally break down when access is continuous, automated, and embedded in everyday workflows. And in many cases, this can even happen by an AI agent that may or may not follow data use guidelines. These changes are similar to those in software when organizations moved to CI/CD and could no longer “freeze and wait” for version releases.

Second, security teams were pushed out of the data path. Controls were implemented at the infrastructure, schema, or application level, often owned by engineering or data teams. Security teams became dependent on others to understand how data was being accessed and to enforce policies. Let’s face it, we can’t expect security teams to know every SQL command used to protect or reveal sensitive data.

Third, compliance expectations increased. It is no longer enough to say that controls exist. Organizations are expected to continuously demonstrate that sensitive data is governed correctly and that access aligns with policy.

Together, these forces may have created a gap that traditional security and data tools were never designed to fill.

What Data Access Governance Actually Solves

Despite its name, data access governance is not about documentation or policy paperwork.

It is about giving organizations direct visibility and control over how data is accessed, without slowing the business down.

A data access governance platform allows teams to:

A data access governance platform does not replace identity systems, data catalogs, or data protection tools. Instead, it fills the gap between them by governing access where it matters most: when data is used.

Why We Built Satori

Satori was built on a simple observation: Security teams are accountable for data risk but often lack direct control over data access.

We set out to change that.

From the beginning, Satori was designed to:

  • Enforce policies at query time, close to the data.
  • Apply controls consistently across modern data platforms.
  • Support fine-grained access without requiring code changes.
  • Provide clear visibility into who accessed what data, and why.

This approach allows organizations to govern data access without becoming a bottleneck for analytics, AI, or innovation. It is also the model recognized by GigaOm in its latest report.

From Governing Data to Resilience

Recovery remains a cornerstone of resilience.

Backups, clean recovery, and testing recoverability enable organizations to continue operating when incidents occur. They help support availability, integrity, and the ability to restore systems quickly and confidently.

Data access governance builds on that foundation by addressing a different but complementary set of questions:

  • How is data being accessed on an ongoing basis?
  • Are access policies consistently enforced?
  • Can we demonstrate compliance continuously, not just after an incident?

While recovery focuses on restoring data to a known good state, governance focuses on preventing misuse, reducing exposure, and providing ongoing assurance. Together, they enable a more thorough and proactive approach to resilience.

By combining real-time data governance with proven recovery capabilities, organizations can gain both control and resilience: control over how data is used every day and the ability to bounce back when things go wrong.

What Comes Next: Integrated Data Security

The future of data security is not about adding more isolated tools.

It is about creating an integrated approach that helps keeps data governed at all times, while enabling the organization to bounce back when things go south.

That means:

  • Continuous visibility into data usage.
  • Real-time control over access.
  • Ongoing evidence for compliance.
  • And resilient recovery when incidents occur.

By bringing together real-time data access governance with data protection and recovery, organizations can move from a reactive security posture to a more proactive, defensible one. This is where we see the industry heading, and it is the direction we are building toward.

Modern Data Security

Data is being used more than ever, by more people and systems, in more ways than before.

Security teams are expected to govern that usage, demonstrate compliance, and keep the business running during incidents. Doing that requires more than traditional data protection alone – it requires visibility into data usage, control over access, and proof that governance is working continuously.

That is what data access governance enables, and why it is becoming a foundational part of modern data security. To learn more about how Commvault can help your organization, book a demo.

FAQs

Q: Why did GigaOm recognize Satori as a leader in data access governance?
A: GigaOm highlighted Satori’s platform-centric approach that provides mature, unified capabilities for governing data access in real time. This recognition underscores Satori’s ability to give organizations visibility and control without impeding business agility.

Q: What is the main problem with data security today?
A: The biggest challenge isn’t data scarcity but uncontrolled data access. Data now lives across multiple platforms, is accessed by countless systems, and lacks unified oversight. This creates compliance gaps and security risks that traditional tools can’t manage effectively.

Q: How does data access governance solve these challenges?
A: A data access governance platform helps organizations monitor how data is used, enforce access policies at runtime, and maintain ongoing compliance documentation. It bridges the gap between identity management and data protection tools by focusing on real-time data use.

Q: What makes Satori’s approach unique?
A: Satori is designed to enforce security policies directly at query time, close to the data, helping provide granular control without requiring code changes. It offers ongoing visibility into who accessed what and why, helping empower security teams with actionable insights.

Q: How does data access governance relate to resilience and recovery?
A: While recovery focuses on restoring data after incidents, governance helps prevent misuse and minimize exposure beforehand. Together, they enable ongoing compliance and faster, more confident recovery – helping strengthen overall business resilience.

Q: What’s next for modern data security?
A: The future lies in integrated security – combining ongoing visibility, real-time control, and resilient recovery. This holistic approach helps enable organizations to move from reactive data protection to proactive, defensible governance.

Ben Herzberg is Senior Director, Solutions Marketing, at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Your organization just got hit with a ransomware attack. Your cyber and IT departments are scrambling to get your incident response plan started and operational. All of a sudden, everyone realizes that they cannot log in to anything. Active Directory (AD) must be offline!? Your organization’s authentication and authorization tools are impacted.

After hours of triage and assessing the size of this problem, your cyber incident response team reports that restoring foundational AD and authentication and authorization services will take over a week, if everything goes well.

You thought your resiliency plan with AD backups and a SaaS identity platform was sufficient. But even with SaaS in the mix, recovery is complex and manual, delaying the path back to minimum viable operations when time matters most.

Resilience means you can restore authentication and authorization quickly and predictably in a trusted way, whether the disruption is malicious activity, an outage, or an accidental misconfiguration.

Understanding the Threat

Attackers target AD because it’s the identity control plane. Once they get a foothold, they’ll often establish persistence by creating shadow or backdoor accounts, then harvest credentials, and escalate privileges. With elevated access, they laterally move across systems and applications, sometimes staying quiet long enough that the first clear signal is when authentication starts failing.

They gain a wealth of knowledge of the organizations network, people, and applications. And when they’re ready to maximize impact, they can encrypt or corrupt the AD forest, disrupting logins and complicating recovery across the environment.

Why Identity (and Why AD First)?

It’s common for an organization’s identity stack, especially AD and Entra ID, to become complex over time. Forests expand, permissions sprawl, legacy policies accumulate, and “good enough” processes often turn into long-term security drift. That complexity creates blind spots, and defenders lose crisp visibility into how roles, privileges, and policies evolve.

And it’s never “just AD.” Identity is an ecosystem: identity governance and access solutions (IGA), privileged access, customer identity, identity providers, authentication databases, and single sign-on all connect back to the same truth. That’s why identity incidents (and even everyday misconfigurations) can cause outsized disruption compared to many other infrastructure failures.

The recovery challenge is where most plans get exposed. Even with backups, forest recovery is a multi-step, high-stakes process, where guidance for manual recovery can involve 50 to 100 (or more) individual steps and can take days to weeks, depending on environment complexity and preparedness.

The real question isn’t “do we have backups?” it’s “can the teams leverage the backups to cleanly execute under pressure, and have runbooks been tested and verified so recovery doesn’t become an error‑prone scramble at the worst possible time?”

The Solution

The need to have a recovery plan is great. It needs to be tested and verified. Organizations need to know and understand that your identity management platform is the No. 1 target for cyber criminals and attacks. It needs to be protected as such. It needs to be backed up, tested, and verified it can be recovered. This includes:

  • Backups of AD, Entra ID, and IGA platforms.
  • Tested and verified recovery plans.
  • Isolated recovery environments and Cleanroom Recovery.
  • AD recovery workflow and automation.

Strong identity governance and monitoring are still critical, but they’re only part of the equation. You want the ability to detect suspicious identity behavior early, contain it fast, and recover with confidence when something changes that shouldn’t (whether it’s malicious activity or an accidental modification that breaks authentication).

That also means you need to integrate identity account and user activity into SecOps and continuously watch for signals like unauthorized account creation, privilege changes, and abnormal authentication patterns, and have a recovery path that’s proven, repeatable, and clean.

Commvault and Deloitte: A Partnership for Identity Resilience

Identity resilience is a business challenge that requires strong governance, processes, controls, and enabling technology. That’s why Deloitte and Commvault have partnered to deliver comprehensive identity protection, recovery, and resilience programs that organizations can trust when it matters most. 

Deloitte brings deep expertise in cyber risk, enterprise resilience, and identity and access management to help Fortune 100 to 1000 organizations design, implement, and operationalize identity resilience programs.

These programs help clients assess security posture, improve detection and response capabilities, and define minimum viable company requirements, and then build tested, verified recovery plans with clear timelines and accountability across business and IT stakeholders. Deloitte turns identity resilience into an executable program with runbooks, testing, and readiness, so teams know what “prepared” looks like under pressure.

Commvault makes resilience programs operational with integrated protection and automated recovery workflows across identity systems, plus Commvault AirGap and Cleanroom Recovery to support repeatable, clean, validated recovery when it matters most. Commvault provides the technology foundation with identity resilience capabilities that include:

  • Protection for critical identity systems, including AD and Entra ID, point-in-time comparison and rollback support for unwanted or accidental changes.
  • Auditing and detection to surface suspicious modifications early (who changed what, and when), helping reduce the window for attackers to spread or persist.
  • Automated recovery workflows, including forest-level recovery automation, to help reduce the manual burden and error risk during identity restoration.
  • Commvault Cleanroom to help validate identity recovery in isolation before reintroducing trust back into production.
  • Commvault AirGap to help maintain immutable, air-gapped backup copies, creating a protected foundation that supports clean recovery and cleanroom testing when identity (or the environment around it) can’t be trusted.

Take Action

If you want to pressure-test your cyber recovery readiness, start with a Deloitte Active Directory Workshop to map dependencies and produce a clear, actionable plan to recover AD and workloads to production. Then validate it the right way: using Commvault to rehearse recovery in a cleanroom before you ever need it in a real event.

For organizations ready to take the next step, we can extend this into a 30-day pilot that puts clean recovery and testing into motion with real artifacts and measurable outcomes. Contact your Deloitte representative at commvaultsalesteam@deloitte.com or your Commvault representative at deloittealliance@commvault.com for more information.

Dave Nowak is Cyber Defense & Resilience Principal at Deloitte, and Michael Fasulo is Senior Director, Portfolio Marketing, at Commvault.

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • IT and Security misalignment increases cyber risk.
  • Commvault Cloud enables unified response and recovery.
  • Arlie AI delivers shared intelligence and guided action.
  • Secure by Design principles underpin trust and compliance.
  • A shared mindset is foundational to cyber resilience.

In today’s enterprise environment, cyber resilience depends on more than tools. It depends on whether IT and Security teams operate with shared intent. With Commvault Cloud, organizations gain a unified platform that connects detection, response, and recovery – helping CIOs and CISOs move forward together without compromise.

Understanding the IT and Security Divide

IT and Security teams share a common mission: enable the business to succeed. Yet their paths often diverge through opposing objectives, siloed tools, and disjointed workstreams.

IT Operations prioritize speed, scalability, automation, and uptime.

Security Operations focus on protecting data, reducing risk, and maintaining compliance through the CIA triad – confidentiality, integrity, and availability.

When these perspectives collide without coordination, silos form. Communication slows. Risk increases.

Why Misalignment Undermines Cyber Resilience

Lack of alignment creates tangible consequences:

  • Slower incident detection and response.
  • Inefficient and error-prone recovery.
  • Expanded blast radius during cyberattacks.
  • Increased operational friction during crises.

Cyber resilience demands coordinated action across detection, investigation, and recovery.

Bridging the Gap with Commvault Cloud

Commvault demonstrates how technology can align teams instead of fragmenting them.

  • Faster, cleaner recoveries: Commvault provides threat insights, scanning against indicators of compromise and sharing insights with security tooling while enabling rapid, reliable recovery. Together, teams can identify affected systems and restore operations with confidence.
  • Targeted risk mitigation: Capabilities such as cyber resilience assessments, scenario simulations, and isolated testing in cleanrooms allow organizations to prepare without impacting production environments.
  • Unified incident management: Integrated workflows connect detection, investigation, and recovery, minimizing room for miscommunication, and helping to accelerate resolution.
  • Scalable, tailored services: Commvault incident response recovery services adapt to organizational needs, supporting resilience without overextending resources.
  • Shared expertise: Customers can benefit from combined guidance across architecture planning, process optimization, and operational readiness.

Arlie AI: Shared Intelligence in Action

Arlie AI, Commvault’s Autonomous Resilience copilot, strengthens collaboration by delivering real-time insights and guided workflows.

Arlie helps:

  • Surface anomalies and critical data.
  • Guide users step by step during incidents.
  • Reduce reliance on deep technical expertise.
  • Standardize response across IT and security.

With no-code integrations and platform-aware intelligence, Arlie removes guesswork and reinforces shared execution.

Secure by Design, Not by Accident

Commvault embeds security at the code level through Secure by Design principles. This approach is validated through initiatives such as and the adoption of post-quantum cryptographic capabilities that align to the new NIST standards.

These measures reduce compliance burden and support regulated industries. Additional certifications are available in the Commvault Trust Center.

Steps to a Shared Mindset

Q: Why do IT and Security teams struggle to align?

A: They operate under different priorities, KPIs, and tools, which can create silos.

Q: How does Commvault help improve cyber resilience?

A: By unifying detection, response, and recovery within Commvault Cloud.

Q: What role do security integrations play?

A: Commvault security integrations allow sharing threat insights cross-functionally and help inform faster recovery.

Q: What is Arlie AI?

A: Arlie is Commvault’s AI copilot that delivers guided, real-time resilience insights.

Q: Why is Secure by Design important?

A: It helps reduce risk at the code level and helps support compliance from the start.

Q: How can organizations measure alignment success?

A: Through shared KPIs like time to detection, recovery speed, and readiness testing

Pauline List is a Product Marketing Specialist at Commvault.


Related Blogs

Building Stakeholder Alignment for Cyber Resilience

The Urgent Need for Cyber Resilience

A Multi‑Layered Approach to Cyber Resilience

Conversational Resilience: A New Way to Manage and Protect Enterprise Data

The Next Evolution in Cloud Data Protection

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • Lateral access in AI environments enables attackers to move across connected systems by exploiting shared trust and excessive permissions.
  • AI workflows can obscure lateral movement because attacks often mimic normal system behavior.
  • Defense in depth – including identity isolation, segmentation, and dynamic access control – helps reduce the spread of compromise.
  • Recovery planning must be treated as a core control, not an afterthought, to restore trust after lateral breaches.
  • Commvault supports resilience by helping enable trusted, isolated recovery and rapid containment when lateral access incidents occur.

Modern AI systems are built for speed and connectivity. That same design also makes lateral access one of the most dangerous and least visible failure modes in AI-enabled environments.

Large language models, retrieval pipelines, orchestration layers, and downstream services continuously interact to generate value. When those interactions rely on shared trust and overly broad permissions, a single compromise can spread far beyond its original scope.

What Is Lateral Access in AI Environments?

Lateral access occurs when an attacker compromises one component and then moves horizontally across connected systems by exploiting trust relationships, shared identities, or overly broad permissions.

In modern AI environments, this type of movement is especially dangerous. Models, retrieval services, orchestration layers, and data stores are designed to communicate continuously, often using shared credentials and implicit trust. Once a single component is compromised, attackers can move quickly across the environment without triggering obvious alerts.

Because AI workflows generate large volumes of legitimate activity, lateral movement often blends into normal system behavior until the blast radius already has expanded.

Why Lateral Access Is Especially Dangerous

Lateral access undermines security assumptions that many organizations still rely on. Traditional defenses focus on preventing initial compromise or vertical privilege escalation. Lateral movement bypasses those controls by abusing legitimate access paths that already exist.

In AI-enabled environments, the impact compounds rapidly. Compromised services may continue to generate valid outputs while attackers move across models, data sources, and tenants at machine speed. What begins as a single breach quickly can expand into a systemic incident.

Recovery is also more complex. When identities, orchestration layers, or shared data stores are involved, organizations must assume broader contamination and restore trust across multiple systems rather than a single endpoint.

Common Causes of Lateral Movement

Most lateral access exploits are enabled by architectural decisions rather than novel vulnerabilities. In modern AI environments, speed and integration are often prioritized before identity discipline and segmentation are fully enforced.

The most common causes include:

  • Excessive permissions granted to AI services, agents, or automation accounts.
  • Shared identities across ingestion, retrieval, inference, and orchestration functions.
  • Weak enforcement of role-based and attribute-based access controls.
  • Insufficient segmentation between tenants, environments, or workloads.
  • Lack of immutable backups and isolated recovery workflows.

Addressing these issues requires architectural discipline and recovery planning, not reactive controls applied after compromise.

Reducing Lateral Risk with Defense in Depth

Reducing lateral access risk in AI environments requires more than perimeter controls or isolated fixes. It requires defense in depth that assumes compromise and limits how far attackers can move once inside.

Effective design focuses on four core principles:

  • Enforce identity isolation: Each AI function should operate with its own narrowly scoped identity. Ingestion services, retrieval components, orchestration layers, and inference engines should never share credentials. When identities are isolated, a single compromise cannot automatically spread across systems.
  • Apply context-aware access controls: Permissions should be evaluated dynamically based on role, environment, tenant, and operation. Combining role-based and attribute-based access controls limits abuse of legitimate access paths and reduces the opportunity for lateral movement.
  • Segment data paths and execution environments: AI components should be isolated from one another and from core business systems. Segmented networks, service boundaries, and controlled data paths help restrict how far attackers can move and contain the blast radius when compromise occurs.
  • Plan for recovery as a control: Prevention alone is insufficient. Organizations must assume lateral movement will occur and design recovery workflows that help them isolate compromised components, restore trusted systems, and reestablish control without reintroducing risk.

Together, these principles shift lateral access from an uncontrolled cascade into a contained and recoverable event.

Detecting and Responding to Lateral Behavior

Early detection is critical in limiting the impact of lateral access. Because lateral movement often mimics legitimate system behavior, traditional alerting focused on perimeter breaches or privilege escalation is frequently insufficient.

Effective detection focuses on behavioral signals rather than individual events. Unexpected interactions between services, sudden expansion of access scope, and anomalous identity usage patterns can indicate lateral movement even when individual actions appear valid.

When suspicious behavior is identified, response must prioritize containment and trust restoration. Compromised identities should be revoked quickly, affected components isolated, and recovery initiated using trusted data in controlled environments. The goal is not only to stop movement, but to reestablish confidence in system integrity.

Why Commvault Matters for AI Resilience

AI systems increase speed and scale across the enterprise. Attackers benefit from that same speed when lateral access is left unchecked.

Commvault helps organizations reduce the impact of lateral access by providing trusted recovery foundations that support containment, isolation, and restoration at scale. When compromise occurs, the ability to recover from known good data becomes a critical control.

Commvault can help organizations:

  • Preserve trusted recovery points that remain available even during widespread compromise.
  • Restore systems and data into isolated environments for validation before reintroduction.
  • Recover identity-dependent services without amplifying lateral contamination.
  • Reduce downtime and reestablish operational trust faster.

Resilience against lateral access is not about eliminating connectivity. It is about controlling it, monitoring it, and making sure that recovery remains possible.

Final Thought

Lateral access is not a failure of individual controls. It is a consequence of how modern AI systems are designed to connect and trust one another.

As AI environments continue to scale, resilience depends on disciplined identity design, intentional segmentation, and the ability to recover quickly from trusted data. Organizations that plan for containment and recovery alongside innovation are best positioned to limit blast radius and preserve trust when compromise occurs.

Learn how Commvault helps organizations strengthen AI resilience and accelerate recovery when it matters most. The Commvault Cloud Unity platform release lets you unify data security, identity resilience, and cyber recovery at enterprise scale.


FAQs

Q: What does “lateral access” mean in AI-enabled environments?
A: Lateral access refers to an attacker’s ability to move horizontally between interconnected systems after compromising one component. In AI environments where models, retrieval layers, and data sources share trust, this movement can go unnoticed and expand quickly.

Q: Why is lateral access particularly dangerous for AI systems?
A: Because AI ecosystems are highly interconnected, a single compromise can cascade across multiple components. Attackers can maintain legitimate-looking activity while accessing sensitive data or systems, making detection difficult and recovery complex.

Q: What are the most common causes of lateral movement?
A: Excessive permissions, shared identities across AI services, weak access control enforcement, lack of segmentation, and missing immutable backups all create opportunities for lateral exploitation.

Q: How can organizations reduce lateral access risk?
A: Implementing identity isolation, dynamic (context-aware) access control, and segmentation across AI components limits how far attackers can move. Recovery strategies should be built into architecture to enable containment and safe system restoration.

Q: What role can Commvault play in defending against lateral access?
A: Commvault strengthens resilience by enabling organizations to maintain trusted recovery points and isolate restoration. Its tools are designed to validate, recover, and reestablish trust quickly, helping reduce downtime after compromise.

Q: How should teams detect and respond to lateral movement?
A: Commvault recommends focusing on behavioral anomalies – such as unexpected service interactions or expanded access scopes – rather than traditional alerts. Once detected, revoke compromised credentials, isolate affected systems, and recover from verified data backups.

Chris DiRado is Principal, Product Experience, at Commvault.

More related posts


Thumbnail_-Blog_Hyperscale-2025-1

Commvault On-Prem Solutions: Ransomware Resilience to AI-Ready Data Protection

Read more about Commvault On-Prem Solutions: Ransomware Resilience to AI-Ready Data Protection
Thumbnail_Blog_Resilient-Against-the-AI-Machine

Resilient Against the AI Machine

Read more about Resilient Against the AI Machine

At Commvault, support exists for one reason: to solve customer challenges as quickly and confidently as possible. Every process we refine, every tool we introduce, and every investment we make is guided by that goal – helping customers feel supported when it matters most.

Over the years, we’ve learned that great support isn’t just about resolving tickets. It’s about clarity during high-pressure moments, honest communication, and building trust that lasts beyond a single interaction. Those lessons have shaped a support ecosystem designed to move fast without losing the human connection.

Human Expertise, Amplified by AI

Speed and empathy don’t have to compete. That’s why our approach to AI is built around partnership, not replacement. AI helps us move faster; people are dedicated to making sure we move wisely.

Arlie, our AI-enabled support assistant, analyzes logs, recognizes patterns, and surfaces insights early – often before issues escalate. Customers can use Arlie directly to find answers in real time, while our engineers use those same insights to focus less on data gathering and more on understanding each customer’s unique environment.

This balance matters. Support interactions often happen during moments of risk or stress, when customers want reassurance that a real person is invested in their success. By handling the repetitive and time-consuming tasks, AI creates space for meaningful conversations – the kind that build confidence and trust.

The Team Behind Every Resolution

Behind every fast resolution is a global team of highly skilled engineers who continuously learn, collaborate, and share knowledge. Our Center of Excellence model allows expertise gained in one region to strengthen support everywhere, ensuring customers benefit from collective experience – not just individual cases.

Training, certifications, case reviews, and simulations are part of everyday life for our support teams. This preparation means that when a ticket arrives, engineers respond with clarity, purpose, and deep technical understanding across cloud, storage, backup, databases, and security.

AI strengthens this model even further by capturing insights from past cases and making them instantly accessible, so knowledge never stays siloed.

A Support Experience That Keeps Evolving

The result is a support experience that feels both efficient and personal – one where customers can self-serve when they need speed, connect with experts when they need guidance, and trust that every interaction is backed by experience, empathy, and continuous learning.

We’re continuing to invest in proactive monitoring, smarter self-service, and learning paths that help customers and engineers grow together. Progress is ongoing, but the direction is clear: faster resolutions, stronger partnerships, and support that customers can truly rely on.

If you’ve interacted with Commvault Support recently, we’d love to hear your feedback. Thank you for being a Commvault customer and for providing insights that help us keep improving – for every customer, every day.

 

 

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Backup and recovery integrations depend on secure workload credentials. A single compromised credential can open access far beyond one system, and threat actors know it.

The best static credential is the one you don’t have. Where feasible, move from secret-based authentication to managed identities or other “secretless” approaches, so credentials are issued, protected, and rotated by the platform rather than stored and handled manually. However, we realize this is not always possible for some legacy systems and configurations.

The good news: Even when using long-lived secrets, hygiene can reduce your risk and blast radius.

This post outlines a practical routine that can help ensure your business remains cyber resilient: Rotate credentials, minimize scope, and enforce Conditional Access where possible.

The Baseline: Three Key Controls

Strong credential hygiene comes down to three pillars: rotation, least privilege, and Conditional Access. While you won’t always be able to implement all three for every credential type, these are the right places to start for any environment:

  1. Rotation and monitoring: Rotate credentials regularly and review authentication activity for anomalies.
  2. Least privilege: Scope permissions so credentials can perform only the required backup/restore actions. Practical steps include:
    • Separate credentials by workload.
    • Scope permission to the minimum dataset/site/mailbox/database needed.
    • Avoid broad admin roles unless absolutely required.
  3. Conditional Access: Where supported, set policies to limit when and where credentials can be used, such as:
    • Trusted locations and IP ranges
    • Risk signals
    • Device/session controls

When Conditional Access Isn’t Feasible, Rotation is the Compensating Control

Not every credential type meets Conditional Access requirements. In those cases, rotation limits how long a stolen credential remains useful, and monitoring helps you detect misuse quickly.

Commvault guidance emphasizes rotating passwords, secrets, and credentials regularly across all environments. For single-tenant Azure app registrations protecting M365/D365/Entra ID workloads, Commvault recommends 90-day rotation cycles. Many common security and compliance frameworks (PCI DSS, ISO 27001, SOC 2, NIST) also expect disciplined credentials management, including periodic rotation and review of access.

Consult Your Security Team

Credential hygiene is most effective when it’s consistent. Align with your security team on:

  • Rotation intervals (by credential type and risk tier).
  • Conditional Access policy design (what’s enforceable without breaking automation).
  • Privileged access rules, logging requirements, and review cycles.

Resource Guide

The resources below offer additional context and environment-based guidance on credential protection and access controls.

Commvault
Microsoft
AWS
Google Cloud (GCP)

Will Galway is Deputy Chief Security Officer at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Key Takeaways

  • Commvault is expanding Google Workspace protection with advanced eDiscovery search capabilities to support compliance, investigations, and litigation.
  • The new capabilities allow faster, more precise discovery across Gmail and Google Drive using keyword, phrase, and metadata filters.
  • Flexible export options help legal teams streamline reviews and reuse standardized export sets for recurring cases.
  • A centralized discovery interface enables organizations to manage eDiscovery across Google Workspace, Microsoft 365, and endpoints from one platform.
  • The solution aligns with Electronic Discovery Reference Model (EDRM) standards and is available in early access, with general availability targeted for the first half of 2026.

Google Workspace is central to how many organizations communicate and collaborate, containing business-critical emails, files, and messages that are often essential for compliance, investigations, and litigation.

As a key source of discoverable data, organizations need efficient eDiscovery processes to help quickly locate, manage, and export pertinent electronically stored information (ESI) across Google Workspace services to help meet modern legal and regulatory requirements. Delayed responses and incomplete or inaccurate ESI collection can drive up legal costs, increase regulatory risk, and lead to fines or failed compliance obligations.

To help address this need, we are expanding existing Google Workspace protection by adding advanced compliance search capabilities for our eDiscovery offering. These eDiscovery capabilities for Google Workspace join existing eDiscovery support for Microsoft 365 and endpoints, making it easier to unify compliance across multiple workloads from a single platform.

Simplifying Compliance Search for Google Workspace Environments

With this release, customers can locate, filter, and export relevant data, such as email messages and files, across their Google Workspace backups faster for audits, litigation, or investigations. This expanded support is designed to help organizations reduce the time and costs associated with eDiscovery and support their legal and regulatory obligations.

Key features and benefits:
  • Advanced search: Quickly find relevant emails and files using keyword, phrase, and metadata searches with granular filtering controls. Run centralized searches across Gmail and Google Drive or target a specific service to narrow the scope for focused investigations.
  • Flexible export options: Export all search results or select items for legal review or external production. Utilize standardized export sets for recurring investigations to help minimize manual effort and expedite response times for future requests.
  • Centralized discovery experience: Perform discovery across Google Workspace today, with the flexibility to extend searches to Microsoft 365 and endpoint data – all from a single, centralized interface.
  • EDRM-compliant solution: Helps maintain EDRM compliance, adhering to identification, collection, and processing protocols.

Compliance search capabilities for Google Workspace are currently available in early access and are targeted for general availability in the first half of 2026.

Ready to Learn More?

Explore Commvault Backup & Recovery for Google Workspace, or request a personalized demo to see the new compliance search capabilities in action.

FAQs

Q: Why is eDiscovery important for Google Workspace data?
A: Google Workspace contains critical emails, files, and communications that are often required for legal, regulatory, and compliance matters. Efficient eDiscovery helps organizations quickly locate and produce accurate ESI while controlling costs and risk.

Q: What types of data can be searched with Commvault eDiscovery for Google Workspace?
A: The solution supports searches across Gmail and Google Drive, allowing organizations to locate relevant emails and files. Searches can be centralized across services or scoped to a specific workload for focused investigations.

Q: How do advanced search capabilities improve compliance response times?
A: Keyword, phrase, and metadata-based searches with granular filters help teams quickly narrow large data sets. This helps reduce manual effort and enable faster responses to audits, litigation, and investigations.

Q: What export options are available for legal and compliance teams?
A: Users can export all search results or select specific items for review or external production. Standardized export sets can be reused for recurring matters, enabling more consistent and efficient workflows.

Q: How does this fit into a broader, multi-platform compliance strategy?
A: Commvault provides a centralized discovery experience that spans Google Workspace, Microsoft 365, and endpoint data. This unified approach helps enable organizations to manage compliance across multiple workloads from a single interface.

Q6: When will compliance search for Google Workspace be generally available?
A: The capabilities are currently available in early access and are targeted for general availability in the first half of 2026.

Katharine Colucci is a Product Marketing Manager at Commvault.


Related Blogs

More related posts


Abstract-city-in-the-clouds-Crocus_PPT

Commvault Expands Collaboration with Google Cloud to Help Strengthen Enterprise Protection and Cyber Resilience

Read more about Commvault Expands Collaboration with Google Cloud to Help Strengthen Enterprise Protection and Cyber Resilience