Skip to content

What Is Recovery Point Objective (RPO)? A Complete Guide

Recovery point objective (RPO) defines how much data your organization can afford to lose after a disruption – and it shapes every backup, replication, and recovery decision you make.

Recovery point objective (RPO) is the maximum amount of data – measured in time – that your organization can lose after an unplanned disruption and still operate within acceptable limits.

Think of RPO as a data-loss clock: It starts ticking backward from the moment an outage, cyberattack, or human error strikes, and it stops at your last usable backup or replication point. Every second between those two points is data you may never get back.

NISTdefines RPO as “the point in time to which data must be recovered after an outage.” That definition is deceptively simple. In practice, setting the right RPO raises important questions about which workloads matter most, how often you back up, and how much you invest in replication infrastructure.

Cyberattacks, cloud outages, and accidental deletions happen on schedules you do not control. Organizations that define clear RPO targets – and enforce them with automated, policy-driven backup – position themselves to recover within business tolerance instead of scrambling after the fact.

This guide walks you through how RPO works, how it differs from recovery time objective (RTO), what are some real-world examples, calculating RPO, and RPO’s critical role in cyber resilience.

How RPO Works in Business Continuity Planning

RPO is the “data-loss clock” that shapes your backup frequency. If your RPO for a database is one hour, backups should run at least every 60 minutes. Miss that cadence and you may have already exceeded your tolerance before anything goes wrong.

In a business continuity plan, RPO sits alongside RTO as one of two recovery pillars. While RTO answers “How fast can we get systems running again?” RPO answers “How current will the recovered data be?” Both feed into the broader disaster recovery strategy – and both should be validated through regular testing, not just documented in a binder.

RPO can also have a compliance dimension:

  • Regulations like HIPAA generally expect healthcare organizations to maintain recoverable copies of electronic patient health information.
  • SOX includes provisions around keeping financial records auditable and intact.
  • GDPR contemplates that personal data processing should be restorable in a timely manner after a technical incident.

When an attack encrypts production data, the gap between your last clean backup and the encryption timestamp is the data you lose. That gap is your RPO in action – and it helps determine whether recovery takes hours or becomes a crisis.

The practical takeaway: RPO is not a number you set once and forget. It should reflect current data-change rates, compliance mandates, and threat landscape realities – and it should be enforced through automated backup policies.

RPO vs. RTO: What’s the Difference?

RPO and RTO are two sides of the same recovery coin, but they measure different things.

RPO looks backward from the moment of failure. It asks: “How much data can we afford to lose?” The answer is expressed in time – minutes, hours, or days – representing the gap between the last good backup and the disruption.

RTO looks forward from the moment of failure. It asks: “How quickly must systems be back online?” The answer is also expressed in time, but it measures downtime tolerance rather than data-loss tolerance.

Dimension RPO RTO
 Focus Data-loss tolerance Downtime tolerance
Measures Time since last usable backup Time to restore service
Direction Backward-looking (before failure) Forward-looking (after failure)
Key Question How much data can we lose? How long can we be down?
Ejemplo 1-hour RPO = Backups every hour 4-hour RTO = Systems restored in four hours

 

Both metrics should be defined together. An organization with a 15-minute RPO but a 24-hour RTO has recent data that sits idle for a full day. Conversely, a four-hour RTO paired with a 24-hour RPO means systems come back quickly – but with stale data.

Aligning RPO and RTO targets before an incident – and validating them through regular disaster recovery testing – can be the difference between a measured response and a scramble.

RPO Tiers and Real-World Examples

Not every workload deserves the same RPO. Tiering your RPOs by business criticality helps keep protection tight where it matters and costs manageable where it does not.

Tier 0: Near-Zero RPO (Seconds to Minutes): Financial transaction databases, electronic patient health records, and real-time trading platforms typically call for continuous data protection (CDP) or synchronous replication. These workloads generate revenue or carry regulatory weight every second, so even minutes of data loss can be difficult to absorb. Organizations implementing near-zero RPO typically use CDP or synchronous replication to help minimize the data loss window.

Tier 1: 1–4 Hours: Customer relationship management (CRM) systems, email platforms, and order processing systems often fall here. Frequent incremental backups – every 15 to 60 minutes – help keep data loss within tolerance. The cost is moderate, and the business impact of losing a few hours of email or CRM updates is generally manageable with manual re-entry.

Tier 2: 4–12 Hours: Internal collaboration tools, development environments, and project management platforms commonly operate in this range. Scheduled backups every 4 to 6 hours can strike a balance between protection and storage costs.

Tier 3: 12– 24 Hours: Marketing analytics archives, historical logs, and reference documentation often tolerate daily cloud backups. Data changes slowly and reconstruction is feasible, making daily backup cadences cost-effective.

Tiering helps organizations invest the most in protecting the workloads where each minute of data loss carries the highest cost, while avoiding overspending on archives that change once a week.

How to Calculate RPO for Your Organization

Calculating RPO is a business exercise first and a technical exercise second.  These steps can help set RPOs that reflect reality, not aspiration.


Identify critical data.

Catalog your workloads and classify them by business impact. Ask: If this system were to lose data, what happens to revenue, compliance, and customer trust? The answers help drive your tier assignments.


Assess data change rates.

A database that processes 10,000 transactions per hour typically calls for a tighter RPO than a document repository updated twice a day. Measure actual change rates, not estimates.


Check compliance requirements.

Map each workload to applicable regulatory obligations. HIPAA, SOX, PCI DSS, and GDPR can each include data retention and recoverability requirements that inform RPO.


Evaluate budget and infrastructure.

Near-zero RPO typically involves CDP, synchronous replication, or both – and that infrastructure has a cost. Align your RPO targets with what your budget can sustain.


Set tiered RPOs and automate enforcement.

Assign each workload to an RPO tier, configure backup policies to match, and automate compliance monitoring. An RPO that exists only in a spreadsheet offers limited protection – enforcement should be continuous and policy-driven.

Reviewing and recalibrating quarterly is good practice. Data volumes grow, workloads shift, and threat landscapes evolve – your RPOs should keep pace.

RPO and Cyber Resilience

Ransomware does not care about your backup schedule – but your RPO determines how much leverage attackers have. A tight RPO means less data sits between your last immutable backup and the encryption event, helping reduce the blast radius of an attack.

Cyber resilience depends on more than backup frequency alone. Air-gapped, immutable backup copies help protect against attackers who compromise production environments so that they cannot reach or alter recovery data. When those backups are stored outside the primary cloud account, you add isolation that ransomware simply cannot cross.

This is where Clumio by Commvault fits into your RPO strategy. WithClumio, you store backup data in an isolated, fully managed environment outside your primary AWS account. Granular point-in-time recovery helps you restore to a precise moment before the attack – helping minimize data loss to the RPO you defined. Designed to help you maintain control of your recovery without depending on the same infrastructure the attacker compromised.

Organizations that maintain tight RPOs with immutable, isolated backups can avoid paying ransom because they can recover clean data independently.

The formula is straightforward: Tighter RPO plus immutable, isolated backups generally translates to a smaller attack surface and faster, cleaner recovery. That is the foundation of cyber resilience.

 

Preguntas frecuentes

What does RPO stand for?

RPO stands for recovery point objective. It defines the maximum acceptable amount of data loss, measured in time, after an unplanned disruption such as a cyberattack, hardware failure, or human error.

What is a good RPO?

A good RPO depends on the workload. Financial and healthcare systems often require near-zero RPOs, while internal tools may tolerate 4 to 12 hours. The right RPO balances business impact, compliance requirements, and budget allowances.

What is the difference between RPO and recovery time objective (RTO)?

RPO measures how much data you can lose, expressed as time since the last backup. RTO measures how long systems can remain offline. RPO looks backward from a failure; RTO looks forward. Both must be defined together in a disaster recovery plan.

Can RPO be zero?

A zero RPO means no data loss whatsoever. Achieving it requires synchronous replication where every write is confirmed on a secondary system before being acknowledged. This is technically possible but can be expensive, so most organizations reserve it for their most critical workloads.

How does RPO affect backup frequency?

RPO directly dictates backup frequency. A one-hour RPO requires backups at least every 60 minutes. A 24-hour RPO allows daily backups. The tighter the RPO, the more frequent the backup or replication cadence must be.

What factors determine RPO?

Key factors include the business criticality of the data, the rate at which data generally changes, applicable regulatory and compliance requirements, available budget for backup infrastructure, and the organization’s overall risk tolerance. Most organizations tier their RPOs based on these factors.

Planificación de la continuidad empresarial para la era Cloud

A modern business continuity plan starts with protecting your cloud data. Learn the key components, benefits, and best practices for cloud-native business continuity.

Why Continuity Matters

Cloud complexity multiplies the challenge. Most enterprises now operate across multiple cloud providers, each with different security models, backup mechanisms, andshared responsibilityboundaries. Data sprawl across Amazon S3 buckets, DynamoDB tables, and data lakehouse environments creates blind spots. The shared responsibility model means your cloud provider secures the infrastructure, but you own the protection and recoverability of your data.

The business impact of an unplanned disruption goes far beyond downtime. Revenue loss compounds by the minute. Customer trust, once broken, takes months or years to rebuild. Regulatory penalties under frameworks like GDPR, HIPAA, and SOX can reach millions. And reputational damage often outlasts the incident itself.

A well-structured business continuity plan transforms your organization from reactive to resilient. It defines exactly how you will protect critical data, recover operations, and communicate with stakeholders when disruption strikes. Without one, recovery becomes improvisation — and improvisation under pressure rarely ends well.

For a deeper look at recovery capabilities that support business continuity, seeessential disaster recovery capabilities for business continuity management.

Plan Components

A strong cloud business continuity plan is built on interconnected components that work together before, during, and after an incident.


Business Impact Analysis and Risk Assessment

Start with a business impact analysis (BIA) to identify your most critical workloads and quantify the cost of downtime for each. Pair this with a risk assessment that maps threats — ransomware, cloud provider outages, insider errors, compliance failures — to specific data assets. This analysis drives every decision that follows.


RTO/RPO Targets per Workload

Not all data is created equal. Define recovery time objectives (RTO) andrecovery point objectives (RPO)for each workload based on its business criticality. A customer-facing database may need an RPO of minutes, while archived logs may tolerate hours. Tiered targets prevent over-spending on low-priority assets and under-investing in high-priority ones.


Cloud Backup Strategy

Your backup strategy must be automated and policy-driven. Manual processes introduce human error and cannot scale. Define policies that capture changes continuously, store backups in isolated environments, and support granular recovery at the object, prefix, bucket, table, or partition level. Explore yourcloud backup optionsbefore committing to a single approach.


Communication and Escalation Protocols

Document who is responsible for what during an incident. Define escalation paths, notification timelines, and communication channels for internal teams, executives, customers, and regulators. A recovery plan that no one can execute is not a plan at all.


Testing and Maintenance

The most dangerous business continuity plan is one that has never been tested. Schedule recovery drills at least quarterly to validate that your RTO/RPO targets are achievable and your team knows the playbook.

Cloud-Native Benefits

Shifting your business continuity strategy to cloud-native solutions delivers measurable advantages over legacy on-premises approaches.

Scalability without infrastructure overhead. Cloud-native backup scales automatically with your data growth. You do not need to provision additional servers, storage arrays, or backup appliances. As your S3 buckets and databases expand, your protection expands with them.

Cost efficiency. A serverless, SaaS-based approach eliminates capital expenditure on dedicated backup hardware. You pay for the protection you use, and operational costs stay predictable as data volumes increase.

Enhanced security through isolation. Air-gapped, immutable backups stored outside your primary cloud account create a critical layer of defense. If ransomware compromises your production environment, your backup data remains untouched in an isolated vault. This separation is the difference between paying a ransom and restoring your data on your terms.

Rapid, granular recovery. Cloud-native solutions enable targeted recovery — restoring specific objects, prefixes, buckets, tables, or partitions rather than entire environments. This precision reduces recovery time dramatically and minimizes disruption to unaffected workloads.

Multi-cloud resilience. Organizations increasingly operate across AWS, Azure, and Google Cloud. Cloud-native backup solutions support cross-region and cross-account recovery, giving you flexibility to restore data wherever you need it.

The cloud data protection market continues to grow as organizations recognize these advantages. With cloud workloads expanding and threats intensifying, investment in resilience infrastructure is accelerating across industries.For more on howClumio’s cloud-native protection supportsransomware recovery,Exploraourdedicated solution page.

Continuity Best Practices

Effective business continuity planning is not a one-time project — it is an ongoing discipline. These practices help you build and maintain a plan that holds up under real-world pressure.


Conduct regular risk assessments.

The threat landscape shifts constantly. Review your risk profile at least quarterly and update your BIA whenever you add new cloud workloads, change providers, or enter new regulatory jurisdictions.


Define and test your RTO/RPO targets.

Setting targets on paper is step one. Validating them through actual recovery drills is where readiness is built. Test restores against your defined objectives and document gaps. Revisit these targets as business needs evolve.


Adopt a multi-cloud backup strategy.

Do not rely on a single provider’s native tools for backup and recovery. Cross-account and cross-region backup capabilities protect you against account-level compromise and regional outages alike.


Automate backup policies.

Manual backup processes are fragile. Implement policy-driven automation that captures data changes continuously, without relying on scheduled snapshots that can miss critical updates between intervals.


Integrate security into your backup strategy.

Air-gapped storage, immutable backups, role-based access controls, and threat scanning should be standard features of your backup solution — not afterthoughts. Your backup data is a high-value target; protect it accordingly.


Test at least quarterly.

Recovery drills should simulate realistic scenarios, including ransomware events and accidental bulk deletions.  Testing reveals where your plan falls short before an actual incident occurs.

Cloud Backup Support

A modern business continuity plan requires purpose-built cloud backup — not legacy tools adapted for cloud environments. Traditional backup solutions were designed for on-premises infrastructure and struggle with the scale, speed, and architecture of cloud-native workloads.

Clumio de Commvaultwas built from the ground up for cloud environments. As a serverless, SaaS-based platform designed for AWS and Google Cloud, Clumio delivers the recovery capabilities that business continuity demands without adding customer-managed infrastructureooperational complexity.

Air-gapped backups. Clumio stores backup data in an immutable, isolated environment completely separate from your production cloud account. This air-gapped architecture means that even if ransomwareoan account compromise affects your primary environment, your backup data stays protected and recoverable.

Granular recovery at scale. Rather than forcing full-environment restores, Clumio enables targeted recovery at the object, prefix, bucket, partition,otable level. When a bad code push corrupts specific data, you recover exactly what was affected — nothing more, nothing less.

Cross-region and cross-account restore. Clumio supports flexible recovery paths, including restoring data to different regionsoaccounts. This capability is critical for disaster scenarios where an entire regionoaccount is compromised.

Clumio Backtrack for point-in-time rollback. Clumio Backtrack allows in-place rollback ofAmazon S3oDynamoDB data to a precise point in time. This is invaluable to help recover data corruptionoaccidental deletion without the delay of traditional restore workflows.

The speed of recovery matters. Purpose-built cloud backup compresses that timeline from weeks to hours —ominutes — transforming business continuity from aspiration into operational reality.

Preguntas frecuentes

What Is a Business Continuity Plan?

A business continuity plan is a documented strategy that outlines how an organization will maintain critical operations during and after a disruption. It covers everything from data protection and recovery procedures to communication protocols and escalation paths. In cloud-first organizations, the plan centers on protecting cloud workloads, defining RTO/RPO targets, and validating recovery through regular testing.

What Is the Difference Between BCP and DRP?

Business continuity planning (BCP) is the broader discipline focused on keeping all critical business functions running during a disruption. Disaster recovery planning (DRP) is a subset of BCP focused specifically on restoring IT systems, applications, and data after an incident. A strong BCP includes a DRP, but also addresses communication, personnel, and operational procedures beyond IT.

What Are Key Components of a Cloud BC Plan?

A cloud business continuity plan includes a business impact analysis, defined RTO/RPO targets per workload, automated cloud backup strategy, communication and escalation protocols, and a regular testing cadence. Each component must account for the unique characteristics of cloud environments, including shared responsibility models, multi-cloud architectures, and data sprawl.

Why Is Cloud-Native Backup Important?

Cloud-native backup is purpose-built for the scale and architecture of cloud workloads. Unlike legacy tools adapted for cloud, cloud-native solutions offer automated policy-driven protection, air-gapped storage, granular recovery, and serverless operation. These capabilities directly support faster recovery times and stronger business continuity outcomes.

How Often Should You Test Your Plan?

Test your business continuity plan at least quarterly. Each test should simulate realistic disruption scenarios — including ransomware, accidental deletions, and cloud provider outages — and validate that your defined RTO/RPO targets are achievable. Document the results, identify gaps, and update the plan accordingly.

What Is an Air-Gapped Backup?

An air-gapped backup is stored in an isolated environment that is not directly accessible from the production network or cloud account. This isolation protects backup data from ransomware, insider threats, and account-level compromise. Air-gapped backups are a critical component of a resilient business continuity strategy because they provide a clean, recoverable copy of data even when production systems are fully compromised.

SOC 2 Compliance Requirements: What They Are and How Data Protection Fits In

SOC 2 compliance requirements define how service organizations prove they protect customerdata and meetingthem hinges on more than firewalls and access controls. 

SOC 2 Overview

SOC 2 is a voluntary auditing framework created by the AICPA that evaluates how service organizations manage customer data. Unlike regulatory mandates such as HIPAA or PCI DSS, SOC 2 is not a law. It is an audit report issued by an independent CPA firm that assesses your organization’s controls against the AICPA’s Trust Services Criteria.

The framework applies to any technology company or service organization that stores, processes, or transmits customer data. In practice, that means SaaS providers, cloud hosting companies, data analytics firms, and managed service providers are the most common candidates. But the audience has broadened significantly.

Enterprise procurement teams now routinely request SOC 2 reports during vendor evaluations, making the audit a de facto requirement for doing business with large organizations. What makes SOC 2 distinct is its flexibility. You do not check boxes on a fixed compliance list.

Instead, you define the scope of your audit by selecting which of the five Trust Services Criteria apply to your services. Your auditor then evaluates whether your controls meet those criteria effectively.

SOC 2 compliance requirements push you toward exactly that kind of structured, documented approach to security and data protection, one that can lower both risk and cost. The AICPA’s Trust Services Criteria framework provides the structure, and the audit report gives your customers the evidence they need.

Trust Services Criteria

The five Trust Services Criteria form the backbone of every SOC 2 audit. Each criterion addresses a specific dimension of how you protect and manage data. Security is the only mandatory criterion, but most organizations include at least one or two additional criteria based on their services and customer expectations.

 Security (Common Criteria) – Security is the foundation of every SOC 2 report. The Common Criteria covers logical and physical access controls, system operations monitoring, change management, and risk mitigation.

Controls like CC6.4 (restricting physical and logical access to information assets) and CC6.7 (restricting the transmission, movement, and removal of information) are central to demonstrating that you protect systems from unauthorized access and threats. Every SOC 2 audit includes Security, regardless of which other criteria you select.

 Availability – Availability addresses whether your systems are operational and accessible as committed in your service-level agreements. This is where data protection becomes critical. Control A1.2 requires you to maintain backup processes and recovery infrastructure. Control A1.3 requires you to test your recovery plan, not just document one.

Auditors want to see that you can restore systems and data within defined recovery time objectives and recovery point objectives.Clumio’s operational recovery capabilitiesare purpose-built for this: policy-driven backup with automated scheduling and air-gapped storage that satisfies both A1.2 and A1.3.

Confidentiality – Confidentiality criteria (C1.1 and C1.2) focus on protecting information designated as confidential. This includes encryption of data at rest and in transit, retention policies that define how long confidential data is kept, and secure destruction processes when retention periods expire.

Processing integrity – Processing integrity evaluates whether your systems process data completely, accurately, and in a timely manner. This criterion is most relevant for organizations whose core service involves data transformation, calculation, or transaction processing.

 Privacy – Privacy addresses how you collect, use, retain, disclose, and dispose of personal information. It overlaps significantly with GDPR and CCPA requirements, making it a common addition for organizations that handle PII across jurisdictions.

SOC 2 Types

SOC 2 audits come in two forms, and the distinction matters. A SOC 2 Type 1 report evaluates whether your controls are properly designed at a specific point in time. Think of it as a snapshot: the auditor confirms your policies and controls exist and are appropriately structured on the date of the assessment.

A SOC 2 Type 2 report goes further. It evaluates whether those controls actually operate effectively over a defined period, typically six to 12 months. Auditors review evidence of consistent execution, including logs, change records, backup verification reports, and incident response documentation.

Type 2 is the standard that enterprise buyers expect. A Type 1 report can serve as an interim step while you build your audit history, but most procurement teams will require a SOC 2 Type 2 report before signing a contract.

The extended observation period is what gives the report its credibility: It proves your controls work in practice, not just on paper.

Control Mapping

Data protection is not a peripheral concern in a SOC 2 audit. It maps directly to multiple controls across the Security and Availability criteria. Yet many organizations overlook backup and recovery when preparing for their audit, focusing instead on access controls and network security.

Here is how specific SOC 2 controls align with data protection capabilities:


CC6.4

Restrict access to information assets

Clumio stores backups in an isolated, air-gapped environment with dedicated encryption, separate from your primary cloud account. This administrative isolation helps satisfy the control requirement to restrict logical access to protected information.


CC7.5

Identify and respond to security incidents

Clumio enables cross-account and cross-region recovery, helping support incident response testing and rapid restoration when production environments are compromised.


CC9.1

Identify and manage risk

Policy-driven backup with automated scheduling helps eliminate manual processes and custom scripts, which also helps reduce operational risk. Clumio’s serverless architecture scales automatically without infrastructure overhead.


A1.2

Maintain backup and recovery infrastructure

Clumio’s policy-based asset selection and offsite, air-gapped storage help deliver the backup processes and recovery infrastructure that auditors evaluate.


A1.3

Probar los planes de recuperación

Clumio supports restore testing through both its management console and API, helping enable you to demonstrate documented, repeatable recovery testing to your auditor.

Compliance Checklist

A structured approach to SOC 2 compliance requirements helps keep your audit on track and reduce the likelihood of gaps. Follow these steps:


Define your scope and select Trust Services Criteria.

Determine which criteria apply based on your services and customer commitments. Security is mandatory; add Availability, Confidentiality, Processing Integrity, or Privacy as needed.


Conduct a readiness assessment.

Identify where your current controls meet the criteria and where gaps exist. This is your roadmap.


Implement controls and document policies.

Build the technical and administrative controls required by each criterion. Document everything: policies, procedures, configurations, and responsibilities.


Perform internal testing, including backup and recovery validation.

Verify that your controls work as intended. For Availability, this means testing backup integrity, restore procedures, and failover processes.


Engage your auditor.

Select an independent CPA firm with SOC 2 experience. The auditor will define the observation period for a Type 2 report and outline evidence requirements.


Address gaps and obtain your report.

Remediate any findings from the audit and receive your final SOC 2 report. Starting with a clear checklist helps you move from preparation to audit with fewer surprises.

Preguntas frecuentes

What are the 5 SOC 2 criteria?

The five SOC 2 Trust Services Criteria are Security, Availability, Confidentiality, Processing Integrity, and Privacy. Security, also known as the Common Criteria, is mandatory for every SOC 2 audit. Your organization selects additional criteria based on the services you provide and your contractual commitments to customers.

What is SOC 2 Type 1 vs. Type 2?

A SOC 2 Type 1 report evaluates whether your controls are properly designed at a single point in time. A SOC 2 Type 2 report assesses whether those controls operate effectively over a period of six to 12 months. Type 2 is more rigorous and is the standard that most enterprise buyers require.

How long does SOC 2 compliance take?

For a first-time audit, expect the full process to take six to 12 months. That includes readiness assessment, control implementation, the observation period, and the audit itself.

How often is SOC 2 compliance required?

A SOC 2 Type 2 report covers a specific observation period, typically 12 months. Most organizations renew annually to maintain an unbroken audit history and help satisfy ongoing customer and procurement requirements.

Is SOC 2 compliance mandatory?

SOC 2 is a voluntary framework, not a legal requirement. However, enterprise customers, partners, and procurement teams increasingly require a current SOC 2 Type 2 report before signing contracts. In practice, it has become a baseline expectation for any service organization handling customer data.


Puntos Clave

  • ResOps is not a technology product. It’s a cross-functional operating discipline that helps drive organizational cyber resilience.
  • It complements backup, la Recovery, cybersecurity, business continuity, and incident response by aligning these functions around end-to-end recovery outcomes.
  • ResOps focuses on critical services and business-defined impact tolerances, rather than isolated infrastructure components.
  • It relies on the continuous production of evidence, including tested recovery results, service resilience indicators, and an owned backlog of gaps.
  • ResOps is a continuous process. Neither making a plan nor running a successful one-time exercise are enough to establish lasting recovery capability.

The New Resilience Challenge

Most organizations invest in cybersecurity, backup,la Recovery, and business continuity. Yet many executives still face three critical questions: Can we recover? How long will recovery take? And can we prove it?

Part of the challenge is that responsibility for resilience is spread across teams that often operate in silos. Security manages threats. IT maintains systems. Backup and la Recovery teams restore data and infrastructure. Business continuity teams focus on keeping the organization running. Each plays an important role, but responsibility for recovery can remain fragmented.

ResOps brings these functions together around shared priorities, recovery goals, and evidence. The result is a more practical way to approach resilience: know what matters most, understand what it takes to recover it, test whether recovery works, and act on the gaps you find.

P: ¿Qué es ResOps?

ResOpsis the operational discipline that brings security, infrastructure, IT operations,business continuity, and business owners together around critical services, resilient design, and continuous validation. Put simply, ResOps helps teams prepare for disruption, recover critical services within business-defined impact tolerances, and demonstrate in an evidence-based way that recovery works.

Four characteristics define ResOps. It is:

  1. Cross-functional by design. ResOps connects distributed responsibilities through a shared operating model, named ownership, and executive governance.
  2. Centered on critical services. It prioritizes the services the organization must restore to deliver core value, serve customers, and generate revenue; as well as helping meet urgent legal, regulatory, safety, and mission obligations.
  3. Continuously validated. Resilience is a posture that teams must exercise and improve – not a state established by an annual test.
  4. Measured through evidence. ResOps produces a resilience posture score (RPS): a per-service, evidence-backed score that measures how recoverable a single critical service is based on validation results, dependency health, and clean-recovery confidence.

What Isn’t ResOps?

It’s not a product category.

No platform can create ResOps on its own. Data protection, cyber recovery, automation, observability, and testing technologies can support the discipline, but ResOps is organizational. It depends on governance, shared accountability, business priorities, operational practices, and a common standard of evidence.

It’s not a replacement for backup and recovery or la Recovery.

ResOps does not replace strong backup and la Recovery capabilities: it depends on them. Backup establishes whether recoverable copies exist. Disaster recovery provides the procedures and technical capabilities to help restore systems and infrastructure.

But then ResOps asks a broader question: Can the critical service return completely, cleanly, and within tolerance, including its identities, applications, data, infrastructure, cloud services, third parties, people, and decision paths?

It’s not another name for business continuity or incident response.

Business continuity defines how the business operates through disruption. Incident response detects, contains, and manages the event. ResOps connects those disciplines to the recovery outcome. It creates an operating rhythm for teams to agree on what matters, validate recovery under realistic conditions, measure results, and address the gaps that testing reveals.

It’s not a compliance exercise or one-time project.

A mature ResOps program can help generate evidence for boards, regulators, insurers, customers, and auditors. But documentation is a byproduct, not the objective. The objective is demonstrated recoverability.

And because systems, dependencies, threats, and business priorities keep changing, ResOps is never “finished.” It operates continuously, much like financial planning or security operations.

What Changes With ResOps?

ResOps shifts the focus from whether individual systems and processes are working to whether the critical service as a whole can recover. That changes the questions leaders can ask.

A successful backup is important. So is having a recovery plan. But neither one tells you whether a critical service can actually be restored when you need it. ResOps looks at the bigger picture:

  • Did we recover from a verified clean recovery point?
  • How long did it take?
  • Did we recover within the limits the business set?
  • And what still needs attention?

That’s why ResOps matters. It gives organizations a way to move beyond assumptions of resilience to programmatic, reliable demonstrations of their ability to recover. And they do it with continuous production of evidence and traceability. So when disruption happens, the question isn’t whether every team did its part or who failed at which task. It’s whether the business can restore the critical services its customers depend on.

Saber Más

Commvault has publishedResOps: An Executive Guide to give CISOs, CIOs, IT, security, resilience, and risk leaders a practical framework for implementing ResOps in their organizations.

Leaders will learn how to identify the services that matter most, validate recovery readiness with real evidence, and continuously test resilience. As a result, organizations can establish a single operating model that unites security, infrastructure, IT operations, and business leaders around evidence-based recoverability.

Get the guide here. 

Preguntas frecuentes

Q: Is ResOps simply a new name for la Recovery?

A: No. Disaster recovery is an essential part of ResOps, but ResOps looks at the entire critical service – including technical, third-party, human, and decision dependencies – and whether it can recover within a business-defined impact tolerance.

Q: Does ResOps require buying a new platform?

A: No. Technology can support mapping, testing, recovery, and evidence collection, but ResOps starts with ownership, governance, business priorities, and operating practices.

Q: Who owns ResOps?

A: ResOps needs a named leader with cross-functional authority and executive sponsorship. Individual service owners remain accountable for their services, while security, IT, business continuity, and business teams contribute to the shared recovery outcome.

Q: How is ResOps success measured?

A: Success comes from current evidence that critical services can recover cleanly within their defined impact tolerances – not simply from completing a plan or running a successful backup job.

A resilience posture score (RPS) is also a useful measurement tool. As a per-service, evidence-backed score, RPS helps demonstrate how recoverable a single critical service is based on validation results, dependency health, and clean-recovery confidence.

Q: How do organizations get started with ResOps?

A: Start by identifying the critical services the business depends on, who owns them, what they depend on, and how quickly they need to recover. From there, teams can validate recovery, identify gaps, and prioritize the work needed to strengthen resilience.

Michael Thelander is Senior Director of Product Marketing at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave

  • Resilience depends on how quickly and confidently the business can recover – not solely on keeping every threat out.
  • Turn recovery plans into evidence – tested results are more credible to boards, regulators, and insurers than targets or assumptions.
  • Make ResOps a shared operating model for security, infrastructure, business continuity, and service owners.
  • Measure what matters: Teams should know whether critical services can be restored, how long recovery actually takes, and whether they can prove it.
  • Select one or two critical services, define successful recovery, run an honest exercise, and document the results.
  • Twenty years in security leadership teaches you one thing early: The attack you stopped never makes the board meeting. The one you didn’t is the only story anyone remembers. Somewaquí along the way I stopped measuring my team by how many hits we absorbed alone and started also measuring us by how fast we got back up.
  • That’s the reason I want every CISO, CIO, and board member I know to read this new book, ResOps: una guía para ejecutivos. Commvault sponsored it, but I’d be recommending it either way.

The Wall Was Never the Whole Plan

For most of my career, the job was building higher walls. Better detection, tighter controls, faster response. That work still matters, and it always will. But a wall only answers one question, and it’s not the one your board is asking anymore.

Last September, ransomware forced Jaguar Land Rover to halt global manufacturing. Assembly lines stopped. Supply chains froze. The UK’s Cyber Monitoring Centre put the cost to the broader economy at roughly £1.9 billion, and JLR posted its lowest monthly production output in 73 years. JLR had defenses. What the incident tested wasn’t whether the wall held. It was whether the business could get back up once it didn’t.

I’ve said this before and I’ll keep saying it: Disruption isn’t an if, it’s a when. The CISOs who sleep at night aren’t those who believe they can keep everything out; they’re those who’ve practiced getting back up so many times that the practice itself is the confidence.

Three Questions I Ask My Own Team

The book organizes the whole problem into three questions, and I’ve started opening every resilience review with them:

  • If we were hit tonight, could we recover?
  • How long would it actually take?
  • Can we prove it, with evidence, to the board?

Most organizations answer the first two with a plan and the third with silence. That silence is the resilience gap, and it’s bigger and more expensive than most executives realize.

Proof, Not Promises

Here’s a distinction the book makes better than I’ve heard it made anywaquí else: A recovery time objective is a target. It tells you what you’re aiming for – but it doesn’t tell you whether you’ll hit it.

Compare “we believe we can recover the payments service in four hours” to “we restored it in 3.2 hours last quarter, from a verified clean recovery point, against a four-hour tolerance.” The first sentence is a plan. The second is evidence. Only one of them holds up when your board, your regulator, or your cyber insurer starts asking harder questions, which they will.

We calls this discipline ResOps, short for resilience operations. It’s not a product you buy or a binder you file. It’s an operating model that connects security, infrastructure, business continuity, and the business owners who depend on these services, all working from the same evidence instead of separate plans.

The Part That Should Worry Every CISO

The book also names something I’ve felt for a while and finally have language for: the AI paradox. The same AI capability helping us find vulnerabilities faster is helping attackers close the gap between discovery and exploitation just as fast, maybe faster. Finding more problems doesn’t make you safer if you can’t recover from the ones that get through. Detection speed was never the finish line. Recovery capability is.

Start with One Service

None of this requires boiling the ocean, and I’d be lying if I said my own team got it right on the first try. The book lays out a 90-day path: Pick one or two of your most critical services, define what “recovered” really means for each, run one honest recovery exercise, and produce your first piece of real evidence. That’s a project any team can start this quarter, mine included.

Proof over promises. Readiness over perfection. That’s the standard I hold my team to, and it’s the standard this book gives you a real path toward.

Get your copy of ResOps: una guía para ejecutivos aquí.

Preguntas frecuentes

Q: What is ResOps?

A: ResOps, short for resilience operations, is an operating model that connects security, infrastructure, business continuity, and service owners around shared, evidence-based recovery practices.

Q: How is ResOps different from traditional disaster recovery?

A: Traditional disaster recovery often centers on plans and technical targets. ResOps emphasizes continuous validation, cross-functional ownership, and measurable proof that critical services can be restored within business tolerances.

Q: Why is recovery evidence important?

A: Recovery evidence shows what an organization has actually tested and achieved. It helps give boards, regulators, insurers, and business leaders greater confidence than plans or recovery targets alone.

Q: What should organizations measure in a ResOps program?

A: Organizations should measure whether critical services can be restored, how long recovery actually takes, whether recovery points are clean and verified, and whether results meet defined business tolerances.

Q: Who should be involved in ResOps?

A: ResOps should bring together security, infrastructure, business continuity, application and service owners, and executive stakeholders so that recovery priorities and evidence reflect business needs.

Q: How can an organization get started with ResOps?

A: Start with one or two critical services. Define what successful recovery means, run an honest recovery exercise, document the results, and use that evidence to improve the next test.

Bill O’Connell is Chief Security Officer at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave 

  • El informe federal actualizado recoge las nuevas tácticas y técnicas de Medusa, así como más de 500 víctimas en sectores de infraestructuras críticas. 
  • Attackers target more than production data; they also disrupt backups, identity, virtualization, and other systems organizations depend on for recovery. 
  • La fase deadvisory calls on organizations to prove their resilience through testing and validation against observed attacker behaviors, not assume it from plans or successful backup jobs alone.  

La fase delatest federal advisory on Medusa ransomware was updated for a reason:La fase deadversary changed. 

La fase deupdated federal advisory, issued August 18, 2026, by the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS), describes an adversary that recruits new access brokers, moves faster once inside, and has gotten better at making sure the damage it causes cannot be undone.  

La fase deAttack Is Not Just Against Your Data

Medusa actors move quickly. Investigators report that Medusa actors have leveraged newly announced exploits within 24 hours and, in some cases, have used exploits up to a week before public vulnerability disclosure. 

Once inside, they blend in using legitimate remote management tools, credential theft, and living-off-the-land techniques. 

But the advisory’s most significant finding is that Medusa attacks the recovery path itself. 

La fase deadvisory maps this activity to MITRE ATT&CK technique T1490, Inhibit System Recovery. It documents the ransomware terminating services associated with backups, security, databases, communications, file sharing, and websites. It also deletes shadow copies, and remotely shuts down and encrypts virtual machines. 

If an attacker is deliberately targeting the systems, identities, and infrastructure an organization may need to recover, the problem extends beyond data protection into cyber resilience and cyber recovery. 

Where ResOps (Resilience Operations) Comes In

ResOps is not another name for backup. It is an operating discipline that brings security, IT, infrastructure, applications, operations, and the business together around one outcome: keeping critical services running and recovering them within the time the business can tolerate. 

La fase deMedusa advisory never uses the word ResOps, but the thinking is there. It recommends organizations exercise, test, and validate their security programs against observed attacker behaviors, align security technologies to attack techniques, test them at scale, measure performance, and tune people, processes, and technologies based on the evidence. 

A backup does not prove it is clean. A recovery-time objective in a spreadsheet does not prove the business will be operating within that window. Resilience has to move from assumption to evidence. 

Start With the Business, Not La fase deServer

La fase deaddition of HHS in the advisory makes this especially relevant for healthcare, a sector the FBI says has been a frequent Medusa target. La fase derecovery conversation starts with three questions: 

  • What has to keep running, and what does minimum viable operation look like? 
  • Which identities, applications, infrastructure, and data support those services? 
  • Which recovery points we can trust, and what comes back first? 

In a hospital, leaving any one of those unanswered may mean a delayed surgery, a pharmacist who can’t verify a dosage, or a diagnostic system a clinician can’t trust. No single team can answer them alone, which is the gap ResOps is designed to close. 

Use Medusa to Test Your Assumptions

Use Medusa as a test case for recovery assumptions. Can an attacker reach the systems supporting recovery? What happens if Active Directory is compromised? Can you identify a clean recovery point, restore critical services in the correct order, and prove how long that will take? 

Threat actors adapt when defenders adapt. Resilience programs need to operate the same way: continuously tested, continuously validated, and continuously improved.  

Because the middle of an incident is a terrible time to discover that the recovery plan looked better on paper than it works in real life. 

Preguntas frecuentes

Q: What is Medusa ransomware? 

R:Medusa is a ransomware-as-a-service operation first identified in 2021. Its developers and affiliates use a double-extortion model, encrypting systems while threatening to publish stolen data if a ransom is not paid. 

Q: Why was the federal Medusa advisory updated? 

R: La fase deAugust 2026 update incorporates findings from FBI investigations as recent as April 2026. It expands the documented tactics, techniques, procedures, exploited vulnerabilities, affiliate activity, and indicators of compromise, while adding HHS insights on attacks against healthcare. 

Q: How does Medusa threaten an organization’s recovery capabilities? 

R:Medusa can terminate services associated with backups, security, databases, communications, and other critical functions. It also can delete shadow copies, alter identity-related policies, and shut down or encrypt virtual machines, putting the recovery path itself at risk. 

Q: What should organizations do to help reduce Medusa risk? 

R:Organizations should patch known vulnerabilities promptly, segment networks, restrict access to remote services, strengthen authentication, monitor lateral movement, and apply least privilege. They also should maintain separate, offline, encrypted, and immutable recovery copies and regularly test restoration workflows. 

Q: What is ResOps, and how is it different from backup? 

R: ResOps, or resilience operations, is a cross-functional operating discipline – not a backup product. It aligns security, IT, infrastructure, applications, operations, business continuity, and business owners around restoring critical services within the amount of disruption the business can tolerate. 

Q: How can an organization help prove it is ready to recover? 

R:Start with critical business services, map the identities, applications, infrastructure, data, people, and third parties they depend on, and define successful recovery. Then run realistic exercises that identify clean recovery points, restore services in the correct order, measure actual recovery time, and turn any gaps into an owned improvement backlog. 

Chris Bevilis Principal Portfolio Marketing Manager at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience

Key Takeaways 
  • Roughly 1,200 supposedly isolated agents communicated through an unauthorized message board, and about 700 participated in Hugging Face-related activity. 
  • Agents exchanged over 70,000 messages and files, combining discoveries across sessions meant to remain separate. 
  • Investigators found agents spoofing tool calls and researching ways to alter evaluation transcripts to avoid detection by lagrader.  
  • Immutable, isolated backups alone are insufficient: Organizations need a validated, trustworthy recovery point before restoring to production. 
La fase deforensic reports are finally here, and they changed laway I think about this incident. 

About a month ago,I wrote aboutlaOpenAI and Hugging Face security incident because I thought it was something anyone responsible for cybersecurity, AI or business resilience should be watching.  

At latime, lastory sounded fairly straightforward: An AI agent found a way outside laenvironment designed to contain it and ultimately reached Hugging Face. 

That is not really what happened. 

La fase deStory Is Bigger Than One Rogue Agent 

La fase deforensic reports reveal that about 1,200 agents, supposed to be operating in isolation, discovered a way to communicate through an unauthorized message board. They exchanged more than 70,000 messages and files, and roughly 700 agents participated in activity associated with Hugging Face. 

None of that was prompted or intended. La fase deagents were persistent, they could share what they found, and they could combine effort across sessions that were supposed to have no contact with each other.  

Among lanew details: GPT-5.6 Sol agents reproduced an exploit and copied private evaluation data into a public Hugging Face dataset, a concrete escalation beyond what initial reports described. 

La fase deReward-Hacking Problem 

La fase deindependent investigation conducted by METR and Redwood Research, published alongside OpenAI’s own report on August 26, found that agents researched ways to spoof, edit or delete portions of their own evaluation transcripts because they incorrectly believed lagrader would inspect how they completed latask. Researchers found successful tool-call spoofing in about 7% of latranscripts they evaluated, though lamanipulation they observed was small-scale. 

La fase definding is not that agents are “deceptive” in a human sense. It is that a sufficiently capable agent can search for ways around controls when those controls stand between it and laoutcome it has been optimized to achieve. 

OpenAI calls laincident a “warning shot.” I think that is a fair description. 

What Happens When Containment Fails 

Most of laconversation about this incident will rightly focus on alignment, sandboxing and monitoring. But there’s a resilience question underneath it: If 700 agents can find a side door around containment, what’s laplan for when a single compromised workload does lasame in your environment? 

OpenAI’s own conclusion points at laanswer: Security architecture should assume an individual workload or compute node eventually can be compromised. That means air-gapped, immutable recovery data, and a way to validate what you’re restoring before it touches production again. 

But immutability alone does not prove ladata was clean when it was captured. If ladata was already compromised at latime of capture, immutability preserves lacompromise just as faithfully as it preserves anything else. 

La fase depractical version of that question is simple to ask and hard to answer: If this happened to us, could we prove which recovery point predates lacompromise? 

We cover this operating model underResOps (resilience operations) on laReadiverse. 

La fase deLesson for Every Organization 

OpenAI has since tightened workload and network isolation, expanded monitoring, and revised its model-development practices. La fase delesson applies beyond OpenAI: Contain laimpact, preserve what you can trust, and prove you can recover before you need to. 


Preguntas frecuentes 

Q: What was laOpenAI-Hugging Face incident? 

During internal cybersecurity evaluations, OpenAI agents bypassed controls intended to isolate them, accessed lainternet and reached third-party systems, including Hugging Face. La fase deactivity was driven primarily by an internal research model operating with reduced safeguards. 

Q: How did supposedly isolated agents communicate? 

R:They discovered an unauthorized message board in shared infrastructure. About 1,200 agents used it to exchange more than 70,000 messages and files, allowing information and tactics to carry across sessions that were designed to remain independent. 

Q: Were laagents instructed to attack Hugging Face? 

R: No. They were attempting to complete a difficult cybersecurity benchmark. When laintended route appeared blocked, some agents searched for alternative ways to achieve laevaluated outcome, and that activity expanded beyond laenvironment’s intended boundaries. 

Q: What does “reward hacking” mean in this context? 

R: Reward hacking occurs when an agent finds an unintended way to satisfy a metric or obtain a desired result without completing latask as intended. Investigators found agents researching ways to spoof tool calls and alter or delete portions of evaluation transcripts because they believed lagrader might inspect their process. 

Q: Why are immutable backups not enough on their own? 

R: Immutability prevents stored data from being altered, but it does not prove ladata was clean when it was captured. If a backup already contains compromised data, immutability preserves that compromise. Organizations therefore need isolated copies, trustworthy recovery points and validation before restoration. 

Q: What should organizations do differently after this incident? 

R:Strengthen workload and network isolation, restrict unnecessary internet and credential access, monitor agent behavior and escalation signals, and assume that prevention may fail. Pair those controls with air-gapped, immutable recovery data and a tested process for identifying and validating a clean recovery point. 

Chris Bevilis Principal Portfolio Marketing Manager at Commvault. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave

  • Certificate lifespans will shrink from 398 to 47 days by March 2029 with “domain validation reuse” shrinking to just 10 days, making manual renewal obsolete and automatic Certificate Lifecycle Management (CLM) necessary.
  • Harvest Now, Decrypt Later operations are already underway to store data with long lifespans for future decryption using quantum computers, which means there is an immediate threat to encrypted, sensitive data that have longer term retention.
  • Certificate/Crypto Inventory is most crucial for companies to start building now, as continuous and automated inventory is the first step toward long-term cyber-resilience and crypto-agility.

The Problem Hiding in the Background

Most modern enterprise networks rely on a hidden layer comprised of digital certificates and cryptography that most people never see. This layer verifies machine trust and secures data flows, but with machine identities now outnumbering human identities bymore than 80 to 1 in the average enterprise according to CyberArk’s machine identity research, it can be easy to underestimate the cryptographic and certificate layer’s importance.

A helpful way to think about a digital certificate is an ID badge for a machine. If the badge is valid, the doors open automatically and no one thinks about it, but the moment that badge expires or is misconfigured, the door stops opening, regardless of how legitimate the machine behind it is. A single expired certificate can take down websites, break the APIs that let applications talk to each other, interrupt transactions, and create compliance violations, all while eroding user trust.

For years, organizations have managed certificates manually, but two changes are going to make it impossible to keep up by hand. First, the maximum lifespan of public Transport Layer Security (TLS) certificates, the protocol securing your browser, is being compressed to just 47 days by 2029. Second, the eventual arrival of quantum computers powerful enough to break today’s encryption is forcing a transition to Post-Quantum Cryptography. These two issues both point to the same solution – a governed, automated, and crypto-agile approach to CLM.

The Roadmap Behind Shrinking Certificate Lifespans

The operational window for public TLS certificates has been narrowing for a decade. In early 2023, Google first published its“Moving Forward, Together”roadmap, which proposed reducing certificate validity from 398 days to 90 days in hopes to push the industry toward automation. Apple accelerated that timeline in October 2024 byintroducing a draft ballot to the CA/Browser Forum, the industry body where certificate authorities and browser makers set shared rules. Apple’s proposal, endorsed by Sectigo, Google Chrome, and Mozilla, was approved in April 2025 as Ballot SC-081v3.

This reduction happens in phases. The past 398-day maximum has already dropped to 200 days as of March 2026, with the maximum being reduced to 100 days in March 2027, and finally to 47 days in March 2029. In practical terms, an organization that currently renews each certificate about once a year will soon berenewing every certificate roughly every month and a half; by the final stage, any process that depends on a person manually requesting and installing certificates will fail.

Browser makers are pushing for these shorter lifespans to force automation, which removes the human error that causes most certificate outages in the first place. They also let the entire web adopt new cryptographic standards in weeks rather than years, since old certificates cycle out quickly. Additionally, they help reduce reliance on legacy revocation systems which suffer from performance and privacy problems. Lastly, if a Certificate Transparency log (a public record of issued certificates) is ever disqualified, short-lived certificates dramatically shrink the number that must be replaced on short notice.

The Validation Crunch

While the 47-day limit gets headlines and attention, the more disruptive change may be what happens to Domain Control Validation (DCV). DCV is the process of proving to a Certificate Authority (CA) that you control the domain you are requesting a certificate for. Historically, once an organization proved ownership, the CA could reuse that proof for up to 398 days, but under SC-081v3, the reuse window shrinks to 200 days in 2026 and to just 10 days by March 2029.

This creates a real imbalance, as even an organization that fully automates certificate installation will stall if it cannot re-prove domain ownership every 10 days. Any delay in validation halts the entire issuance pipeline and leads directly to outages.

The practical answer to this problem is adopting the Automatic Certificate Management Environment (ACME) protocol withautomated DNS-01 API validation, so that proving ownership happens programmatically rather than waiting on a person.

The Quantum Threat and Timeline

While certificate lifespans shrink, the algorithms inside those certificates face a quantum threat. Traditional Public Key Infrastructure (PKI) rely on asymmetric cryptography to secure digital signatures, key exchanges, and TLS connections. A sufficiently powerful quantum computer running Shor’s algorithm could break these systems completely. Waiting until quantum computing is powerful enough to decrypt is not a viable option; as Commvault Field CTO Vidya Shankaran has written, “the exact date of Q-Day may remain uncertain. The direction of travel is not.” Estimates place Q-Day, the point at which a quantum computer can break public-key encryption, somewhere in the next 5 to 10 years. However, it would be a mistake to treat this as a future problem. Threat actors are already conducting Harvest Now, Decrypt Later (HNDL) operations, intercepting and storing encrypted traffic today with the intention of decrypting it once quantum computing matures. Data that must stay confidential for years, such as health records, intellectual property, and financial information, is effectively exposed the moment it is harvested.

The U.S. Federal Government has responded accordingly: In June 2026, the White House issuedExecutive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, which sets deadlines well ahead of NIST’s original 2035 target: Federal high-value systems must adopt post-quantum key establishment by the end of 2030 and post-quantum digital signatures by the end of 2031.

Despite this urgency, actual progress toward enterprise-level crypto-agility has been slow. The DigiCert Quantum Readiness Outlookfound that more than half of surveyed organizations expect classical asymmetric encryption to be broken within five years, yet only 7% have deployed quantum-safe or hybrid cryptography across their certificate estates, and overall readiness improved by just 2 percentage points in the past year.

Why Does Crypto-Agility Matter?

The most practical bridge between classical and post-quantum cryptography is the hybrid composite certificate, which combines a classical algorithm (RSA or ECC) with a post-quantum algorithm (ML-DSA, the standardized lattice-based signature scheme) inside a single X.509 certificate. Combining both into a single certificate is designed so that the certificate will hold up as long as either algorithm does, which is essential, as post-quantum algorithms are new and haven’t yet survived countless attempted attacks like RSA has.

However, post-quantum keys and signatures are several kilobytes rather than a few hundred bytes, which increases network latency, risks packet fragmentation during the TLS handshake, and adds computational overhead that may require hardware upgrades for constrained devices. This is exactly why crypto-agility matters; organizations need the ability to test, deploy, and rotate algorithms without rewiring their underlying infrastructure each time standards evolve.

Automated Certificate Lifecycle Management

Manual certificate management is not just inefficient; it is a genuine operational liability. When certificates live in spreadsheets out of sight, organizations lose visibility, and the result is expired credentials, weak key sizes, outdated signature algorithms, and noncompliant configurations that no one notices until something breaks. The resulting outages can confuse users, interrupt revenue, and land on whichever team is least prepared to explain them.A complete CLM platformaddresses this across the full life of a certificate:

  • Discovery: continuous scanning of cloud environments, datacenters, containers, and external domains to find all certificates in use.
  • Monitoring: tracking expiration dates, algorithms, key strengths, and compliance with security policy in real time.
  • Validation: Utilize direct API integration with public and private CAs, while automating domain validation and approvals
  • Installation: Deploy renewed certificates and keys programmatically through ACME or secure APIs, with no manual handoffs.
  • Revocation: Executing fast, policy-driven revocation is necessary so a compromised certificate can be rotated or revoked everywhere at once rather than hunted down machine by machine.

There is also a payoff hiding in the discovery step: The certificate inventory a CLM platform maintains is, in effect, the beginning of the cryptographic inventory that post-quantum migration planning requires, which can turn a compliance chore into a head start.

Non-Human Identities and Agentic AI

The scale problem is compounded by how modern applications are built. Containers, Kubernetes pods, virtual machines, Internet of Things (IoT) devices, and APIs all need their own credentials, and many of these workloads exist for only minutes or hours before terminating. No team of humans can issue and retire certificates at that velocity.

To keep up with this breakneck pace, AI agents can be utilized to discover, issue, renew, and manage certificates on their own, while remaining inside existing guardrails such as security policies, role-based access control (RBAC), and centralized audit trails. The result is automation at machine speed without giving up enterprise governance.

Where To Start

  1. The first step toward company-wide crypto-agility and resilience is organizational rather than technical. Followingguidance from NIST, enterprises should establish a central machine identity services team that owns the CLM platform, standardizes certificate templates, and maintains integrations with public and private CAs. Individual application owners and DevOps teams, in turn, should be responsible for wiring automated renewals into their own deployment pipelines, using the central platform as a shared service. This split keeps governance consistent while eliminating the manual handoffs that cause outages.
  2. Organizations should replace manual validation techniques and workflows with ACME and automated DNS-01 validation now, well before the 10-day DCV window arrives, while deprecating every manual renewal and validation process along the way.
      1. In parallel, organizations should conduct a full inventory of their cryptographic assets to surface hardcoded keys, legacy algorithms, and long-lived trust paths protecting sensitive data.
      2. Post-quantum preparation should start in a controlled environment rather than in production. A dedicated testing lab should be established to allow teams to test hybrid composite certificates and crypto-agile upgrades in a sandbox. By building applications on modular cryptographic libraries connected to a dynamic CLM platform, enterprises can gain true crypto-agility: the ability to rotate keys, ciphers, and algorithms across their infrastructure as standards change, without a rebuild.

The thread that connects all recommendations is inventory. A CLM platform’s discovery step is not busywork before the real fix; it is the same discipline organizations will need across every layer of quantum readiness. Certificates are non-human identities, and the same questions apply to service accounts, AI agents, open source dependencies, and the algorithms buried in application code: What do we have, what does it protect, and which of it matters most to the business?

Organizations that build that inventory muscle now, starting with certificates, will find the rest of the transition far less daunting, because prioritization becomes a calculation rather than a guess. Treating the next few years as a planning window rather than a grace period will help organizations make this transition on their own terms, instead of letting an outage make the decision for them.

Caitlin Dodson is a Summer 2026 Intern for FCTO – Americas at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave

  • Clumio Chat offers a faster, self-service way to evaluate Clumio’s cloud-native data protection capabilities.
  • El asistente de IA proporciona respuestas sobre copias de seguridad, Recovery, ciberresiliencia, implementación, escalabilidad y protección de cargas de trabajo en la nube.
  • Explora cuestiones técnicas sobre cargas de trabajo en la nube, permisos necesarios, opciones de Recovery y costes de protección de datos.
  • Clumio Chat ayuda a los arquitectos de la nube, ingenieros de plataformas, ingenieros de DevOps, SRE y responsables de compras técnicas a evaluar, a su propio ritmo, si Clumio se adapta a su entorno.
  • Cuando estén listos, los usuarios pueden pasar directamente del descubrimiento del producto a la evaluación práctica creando una cuenta e iniciando una prueba gratuita.

Una forma más rápida de evaluar la protección de datos nativa de la nube

If you’re evaluating cloud-native data protection, you probably want answers before you schedule a demo or talk to Sales.

Clumio by Commvault provides cloud-native backup, recovery,ycyber resilience for AWSyGoogle Cloud workloads. With Clumio Chat, you can ask productytechnical questions, explore how Clumio works,ydecide whether it’s the right fit for your environment – all at your own pace.

 

Click “Ask Clumio” in the navigation bar on clumio.com to start a conversation with Clumio Chat.

Presentamos Clumio Chat

Clumio Chat is an AI assistant designed to help you learn about Clumio’s cloud-native data protectionyrecovery capabilities. Whether you’re exploring key features, understanding how Clumio helps protect las cargas de trabajo en la nubeo te estás preparando para iniciar una prueba gratuita, Clumio Chat te ofrece respuestas sin necesidad de mantener una conversación comercial.

 

Obtén respuestas a retos reales de protección de datos en la nube

En lugar de buscar en la documentación o esperar a una reunión, puedes plantear el tipo de preguntas técnicas que normalmente le harías a un ingeniero de soluciones:

  • ¿Qué opciones de Recovery ofrece Clumio para Amazon S3?
  • ¿Qué permisos requiere Clumio? ¿Tengo que implementar alguna infraestructura de copia de seguridad en mi cuenta de AWS?
  • ¿Qué escala admite Clumio para Amazon S3?
  • ¿Cómo ayuda Clumio a reducir el coste de la protección de datos en la nube a largo plazo?

 

Pruébalo ahora

Clumio Chat helps you move from product discovery to hands-on evaluation with less friction. Learn how Clumio works, explore the capabilities that matter most to you,ywhen you’re ready, crea una cuentaycomienza una prueba gratuita.

PruebaClumio Chat todayyexperience a faster, more self-service approach to evaluating cloud-native data protection.

Preguntas frecuentes

Q: What is Clumio Chat?

A: Clumio Chat is an AI assistant that helps you learn about Clumio’s cloud-native backup, recovery,ycyber resilience capabilities before starting a free trial.

Q: Who is Clumio Chat for?

A: Clumio Chat is designed for cloud architects, platform engineers, DevOps, SREs,ytechnical buyers evaluating cloud-native data protection.

Q: What kinds of questions can I ask?

A: You can ask questions about Clumio’s capabilities, deployment model, cloud workload protection, recovery options, scalability,yother technical topics related to evaluating the platform.

Q: Do I need to talk to Sales before trying Clumio?

A: No. Clumio Chat is designed to help you explore the product on your . If you decide you’d like additional guidance, you can always ponerte en contacto con nuestro equipo.

Q: Where can I try Clumio Chat?

A: Visitchat.clumio.com, or click Ask Clumio in the navigation bar onclumio.com.

Vir Choksies director principal de marketing de producto en Commvault.

More related posts


Backup and Recovery

Read more about Backup and Recovery

Cyber Resilience

Read more about Cyber Resilience

Cyber Resilience for Cloud Apps

Read more about Cyber Resilience for Cloud Apps

Puntos Clave

  • Clumio by Commvault has achieved FedRAMP® Class C (Moderate) Ready statusy ya figura en elFedRAMP Marketplace as Legacy FedRAMP Ready.
  • Este nuevo hito permite a las agencias y organizaciones reguladas evaluar Clumio mientras esta empresa sigue avanzando hacia una futura certificación FedRAMP de Clase C.
  • Clumio ofrece soluciones de Backup and Recovery nativas de la nube, diseñadas específicamente para entornos de nube pública.
  • The announcement expands Commvault’s public sector cyber resilience portfolio, complementing Commvault Cloud for Government, which addresses organizations requiring FedRAMP Class D (High).
  • Government agencies, contractors, technology partners, and regulated commercial organizations can all benefit from additional cloud-native cyber resilience options.
    As more government agencies and regulated organizations embrace the cloud, they need data protection that’s built for modern environments and aligned with evolving federal security requirements.

Clumioby Commvault, que ofrece soluciones de Backup and Recovery nativas de la nube diseñadas específicamente para entornos de nube pública, ha obtenidola calificación «FedRAMP Clase C (Moderada) Readiness»y ya figura en elFedRAMP Marketplace. Este importante paso amplía las opciones de ciberresiliencia nativas de la nube para agencias federales, contratistas gubernamentales y organizaciones reguladas, al tiempo que acerca a Clumio a una futura certificación FedRAMP Clase C.

Nuevas oportunidades

FedRAMP is the U.S. government’s standardized approach to assessing the security of cloud services used by federal agencies. While an Authorization to Operate (ATO) is the ultimate goal, FedRAMP Class C Ready is the first major public step in that process.

After successfully completing its Readiness Assessment Report (RAR), Clumio is now listed in the FedRAMP Marketplace as Legacy FedRAMP Ready. This makes it easier for agencies, partners, and regulated organizations to discover and evaluate Clumio as it continues through the FedRAMP certification process.

Diseñado para Modern Cloud

A medida que las organizaciones siguen actualizando sus entornos de TI, los enfoques tradicionales de copia de seguridad suelen tener dificultades para seguir el ritmo de las aplicaciones y servicios nativos de la nube. Clumio se ha diseñado específicamente para la nube, lo que ayuda a proteger los datos, simplificar la Recovery y reforzar la ciberresiliencia sin añadir una complejidad innecesaria.

Para las organizaciones que operan en entornos FedRAMP de nivel «Moderado», esto supone el acceso a una solución de Backup and Recovery nativa de la nube, diseñada para cumplir con los requisitos de seguridad federales y, al mismo tiempo, favorecer la eficiencia operativa.

Por qué es importante para los clientes

The demand for guarded, cloud-native data protection continues to grow across both the public and private sectors. Federal agencies, government contractors, and regulated commercial organizations all face increasing pressure to protect critical workloads while meeting evolving compliance expectations.

Clumio’s FedRAMP Class C Ready status helps address those needs by helping:

  • Ampliar las opciones de Backup and Recovery nativas de la nube para las agencias federales y las organizaciones que operan en entornos FedRAMP de nivel «Moderado».
  • Ofrecer una mayor visibilidad a través del proceso de contratación del FedRAMP Marketplace.
  • Apoyar a los clientes que desean ampliar la protección de datos nativa de la nube a entornos regulados.

Para los clientes actuales, incluidas las organizaciones con entornos en la nube tanto comerciales como Government Cloud, este hito también genera nuevas oportunidades para estandarizar la protección de datos nativa de la nube en todas sus operaciones.

Strengthening Commvault’s Government Portfolio

Clumio’s FedRAMP Class C Ready status complements Commvault® Cloud for Government, que da servicio a organizaciones que requieren la certificación FedRAMP Clase D (Alta).

En conjunto, estas ofertas proporcionan a los clientes mayor flexibilidad para proteger los datos en entornos de nube, híbridos y nativos de la nube, al tiempo que cumplen con los distintos requisitos de seguridad federales. Las organizaciones con cargas de trabajo nativas de la nube pueden evaluar Clumio para entornos FedRAMP «Moderate», mientras que Commvault Cloud for Government se dirige a las organizaciones que requieren FedRAMP «High».

Mirando hacia el futuro

Clumio’s FedRAMP Class C Ready status reflects Commvault’s ongoing investment in cloud-native cyber resilience for the public sector. As Clumio advances toward a future FedRAMP Class C certification, customers can begin evaluating the offering while Commvault continues expanding its public sector cyber resilience portfolio.

Preguntas frecuentes

Q: What is la calificación «FedRAMP Clase C (Moderada) Readiness»?

A: la calificación «FedRAMP Clase C (Moderada) Readiness» means Clumio has successfully completed its RAR and has been approved by the FedRAMP Program Management Office (PMO) for listing in the FedRAMP Marketplace as Legacy FedRAMP Ready. This allows federal agencies and other regulated organizations to evaluate the offering while Clumio continues through the FedRAMP process toward a potential future Class C FedRAMP certification ATO.

Q: Is FedRAMP Class C (Moderate) Ready the same as an Authorization to Operate (ATO)?

A: No. FedRAMP Class C Ready is an early milestone in the FedRAMP process. It is not equivalent to a full ATO.

Q: What is the FedRAMP Marketplace?

A: The FedRAMP Marketplace is the federal government’s official catalog of cloud service offerings participating in the FedRAMP program. It provides agencies and procurement teams with visibility into each offering’s status in the FedRAMP lifecycle.

Q: Who benefits from Clumio’s FedRAMP Class C Ready status?

A: The milestone can be valuable for federal agencies, government contractors, government-focused partners, and regulated commercial organizations that operate in FedRAMP Class C environments or use FedRAMP as a security benchmark.

Q: How does Clumio fit into Commvault’s government portfolio?

A: Clumio provides cloud-native backup and recovery for organizations with cloud-native workloads operating in FedRAMP Class C (Moderate) environments, while Commvault Cloud for Government can serve customers requiring FedRAMP Class D (High). Together, the offerings provide organizations with more flexibility based on their federal security requirements.

Poojan Kumar is Chief Product Innovation Officer at Commvault; and President & CEO of Clumio, a Commvault Company.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Throughout the«Ready. Or Not». series,we’ve explored topics like la IA agencial,digital trust,the human factor,and vibe coding. In this fifth and final episode of season one,the conversation shifts to the one constant behind every AI conversation: data. 

Nathan Macintosh sits down with Ben Lorica,former chief data scientist at O’Reilly Media and founder of Gradient Flow,to discuss what AI readiness really looks like. Their conversation moves beyond algorithms and applications to the work organizations need to do before AI can succeed.  

They explore why AI is changing the way we think about governance,why collecting more data isn’t always the answer,and why preparation matters just as much as adoption. 

Mira el episodio completo en Readiverse. 

Puntos Clave 

  • AI readiness starts with understanding and organizing the data you already have.  
  • Governance now applies to AI systems,not just people.  
  • More data isn’t always better. Strive for better data. 
  • AI introduces new risks that require new processes,not just new technology.  
  • The organizations best prepared for AI are building strong data foundations today. 

Organizations are generating and managing more data than ever before. It’s easy to assume the next step is simply collecting more data. Ben explains why preparing and governing the data you already have may be a much stronger foundation for AI. 

One thing I appreciated about Ben’s perspective is that he never presents AI readiness as a technology problem alone. It’s an organizational challenge that starts long before teams begin putting AI to work. 

Here are a few ideas that stayed with me. 

AI Is Only as Good as the Data Behind It 

“Focus on the data you have … and get that ready for AI.”– Ben Lorica 

One of Ben’s first points challenged a common assumption. When organizations talk about becoming “AI ready,” the instinct is often to collect more data. Ben sees it differently. Instead of prioritizing quantity,he encourages organizations to focus on quality and prepare their existing data for AI. 

That starts with understanding what data you have,organizing it,and making sure it’s accurate and well governed. As AI becomes part of more business processes,organizations will rely on many different types of information,from spreadsheets to text,images,audio,and video. If that data isn’t reliable,AI won’t fix the problem – and it can make it even more difficult to spot. 

There’s understandable pressure to move quickly with AI. This conversation reminded me that taking the time to build a solid data foundation may be one of the smartest investments we can make. Clean,well-governed data helps organizations make better decisions today while preparing them for whatever comes next. 

AI Changes the Role of Governance  

Ben points out that governance has a broader job to do. It’s no longer just about managing how people access and use information. Organizations also need to think about how AI interacts with that information and the actions it takes. 

As AI becomes part of everyday work,it can access,analyze,and act on information at a scale and speed that’s difficult for people to match. That means organizations need to understand what AI can access,how it’s using that information,and what safeguards should be in place to protect sensitive data. 

What’s interesting is that the fundamentals of governance haven’t changed. Clear policies around access,security,and accountability are just as important as they’ve always been. What is changing is the number of systems interacting with organizational data and the pace at which information moves across the business. 

To me,that’s one of the most important takeaways from this episode. AI doesn’t replace good governance. It makes it even more important. 

Sneak Peek: When Data Starts to Multiply

 

What happens when AI allows five people to do the work of 100? Ben explains why the real challenge isn’t productivity. It’s the explosion of data that comes with it. 

Responsible AI Starts With Responsible People 

One thing Ben emphasizes throughout the conversation is that organizations can’t rely on technology alone to make AI responsible. The people using AI play an important role,too.  

Whether employees are entering prompts,uploading documents,or fine-tuning models,they need to understand what information they’re sharing and how it could be used. Guardrails aren’t just about restricting access. They’re also about helping people make informed decisions when working with AI. 

Ben points out that organizations should think beyond what goes into an AI system. They should also pay attention to what comes out. AI can unintentionally generate sensitive information,making review and oversight of the outputs just as important as the prompts that started the interaction. 

It’s another reminder that responsible AI isn’t just a technology challenge. It’s a shared responsibility between the people using AI and the policies that guide them. 

Plan for the Unknown 

There’s understandable pressure to adopt AI quickly. New tools are emerging almost daily,and organizations don’t want to fall behind. But Ben makes the case that readiness isn’t just about moving fast. It’s about having the right processes in place before they’re needed. 

Toward the end of the conversation,Ben points out that many AI teams haven’t fully considered what they’ll do when things go wrong. I love Nathan’s response because it was exactly what I was thinking: 

“Why wouldn’t they think of that? That’s all I think about.”

– Nathan Macintosh 

In cybersecurity,resilient organizations don’t wait for an incident before deciding how they’ll respond. They establish roles,define processes,and prepare for different scenarios long before they’re needed. Ben argues that AI deserves the same level of preparation. 

That means asking questions many organizations haven’t fully considered yet,like: 

  • What data should AI have access to?  
  • Who should be involved if an AI-generated output creates a problem?  
  • How will decisions be made if something unexpected happens?  

These conversations may not be as exciting as launching an AI initiative,but they’re just as important. 

One Final Takeaway 

As this season of«Ready. Or Not». comes to a close,one thing has become clear to me. Every episode explored a different AI concept or trend,yet they all reinforced the same idea: successful AI adoption isn’t just about the technology. It’s about the people,processes,and preparation that make it possible. 

Organizations don’t have to have every answer before embracing AI. But the more intentional they are about building strong foundations today,the more prepared they’ll be for whatever comes next. 

Mira el episodio completo en Readiverse. 

Preguntas frecuentes 

Q: What does AI readiness mean? 
R: AI readiness begins with understanding,organizing,governing,and protecting the data your organization already has. Strong data practices create the foundation AI depends on. 
Q: Should organizations collect more data for AI? 
R:Not necessarily. Ben recommends focusing first on improving the quality and organization of existing data before expanding data collection efforts. 
Q: What’s the role of employees in responsible AI use? 
R: Employees play an important role in AI governance. They need to understand what information is appropriate to share with AI,review AI-generated outputs carefully,and follow organizational policies for using AI responsibly. 
Q: Why does AI change data governance? 
R: AI systems increasingly access,analyze,and act on organizational data. That means governance policies need to apply to machines as well as people. 
Q: Why should organizations prepare for unexpected AI issues? 
R: AI can introduce new risks,from exposing sensitive information to producing unintended results. Preparing in advance by defining responsibilities and response processes helps organizations address those situations with greater confidence. 
Q: What’s the biggest takeaway from this episode? 
R: AI readiness isn’t just about adopting new technology. It’s about building solid governance,good data practices,and resilient organizational processes that help allow AI to be used responsibly and effectively. 

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Por qué el riesgo cibernético actual exige una resiliencia cibernética integral

Ransomware attacks target the full data lifecyclefrom backups to production systems. See how Commvaults A-to-Z cyber resilience approach unifies protection, detection, and recovery togestionar risk and restore operations fast. 

Puntos Clave 

Modern cyber risk demands unified resilience across the entire una protección de datoslifecycle, from prevention to recovery, as fragmented toolsfail to address today’s complex threat landscape. 

  • Cyber risk now affects customer trust, with breaches often leading to lost business and reputational damage. 
  • A-to-Z resilience brings protection, monitoring, governance, and recovery into a unified, more effective strategy. 
  • Leadership is essential in driving proactive defense, rapid response, and clear communication across the organization. 
  • Fragmenteduna protección de datossecurity tools leave gaps in hybrid environments that attackers can exploit more easily. 
  • An end-to-end approachLa integración con SaaS acelera la implementación:improve visibility, speed recovery, andmaintainbusiness continuity. 

Modern cyber risk spans the entire una protección de datoslifecycle – from vulnerabilities and threats to recovery and compliance – making fragmented, reactive tools insufficient. Organizations need A-to-Z cyber resilience that unifies protection, monitoring, governance, and recovery. This approach La integración con SaaS acelera la implementación:gestionar risk, strengthen security posture, and enable faster, more reliable recovery across complex hybrid environments. 

Una sola filtración puede costarte la confianza de tus clientes

Cyber risk is no longer just an IT issue – it is a direct threat to customer trust and revenue.  

El 64 % de los consumidores would stop doing business with a company after a significant data breach, highlighting how quickly loyalty erodes when data is compromised.  

Este cambio eleva lo que está en juego: la resiliencia ya no es opcional, sino que se da por sentada. 

Al mismo tiempo, existe una desconexión entre las expectativas y el comportamiento. Los consumidores exigen una protección sólida de los datos, pero persisten hábitos de riesgo como la reutilización de contraseñas o el uso de redes no seguras. Esa incoherencia puede aumentar la exposición y hace recaer una mayor responsabilidad en las organizaciones a la hora de proteger los datos en todos los puntos de contacto. 

Trust is earned through consistent action – especially in cybersecurity. 

Commvault Cloud,con tecnología deMetallic AI,ayuda a las organizaciones a llevar a cabo esa acción unificando la protección, la supervisión y la Recovery a lo largo de todo el ciclo de vida de los datos, lo que refuerza la confianza mediante una ejecución coherente. La infografía refleja este enfoque integral, que abarca la alerta temprana, la supervisión de amenazas y la Recovery rápida. 

Para las organizaciones, la conclusión es clara: la resiliencia no consiste solo en prevenir los ataques. Se trata de mantener la confianza cuando la prevención falla. 

 

La resiliencia cibernética empieza por el liderazgo

A medida que las amenazas se vuelven cada vez más sofisticadas, la resiliencia cibernética se ha convertido en una prioridad empresarial que va más allá de los equipos de TI. El liderazgo desempeña un papel fundamental a la hora de armonizar la estrategia, la inversión y la rendición de cuentas en toda la organización. 

Este mandato se manifiesta de tres formas: 

  1. Proteger antes de que se produzca una brecha de seguridad.
    Reforzar las defensas con principios de «confianza cero», supervisión periódica y plataformas unificadas que se adapten a las amenazas en constante evolución. 
  2. Responder con rapidez cuando se producen incidentes.
    Customers and stakeholders judge organizations not just on whether a breach happens – but how quickly and effectively they recover. 
  3. Comunicarse con transparencia
    . 

 Según datos del sector, elcoste medio de una violación de seguridad ha alcanzado los 4,88 millones de dólares 

 Commvault Cloud respalda este mandato de liderazgo al reunir la gobernanza, la detección de amenazas y la recuperación coordinada en – helping organizations align teams and respond with greater speed and coordination.  

La resiliencia integral ayuda a gestionar el riesgo

Modern environments are too complex for fragmented tools to keep up. Data spans hybrid cloud, on-prem systems, and SaaS applications – creating a broad and dynamic attack surface. Point solutions leave gaps that attackers exploit. 

An end-to-end approach helps close those gaps by integrating capabilities across the lifecycle: vulnerability management, threat detection, immutability,air-gapped protection, and orchestrated recovery. This unified model helps improve visibility and enable faster, more reliable response. 

Commvault Cloud brings these capabilities togetherwith AI-enabled insights, regular monitoring, and automated recovery workflows, helping organizations manage risk and maintain operational continuity across hybrid environments. 

Organizations should plan for cyber incidents as an expected event and prioritize resilience and recovery readiness. The difference lies in readiness – and having a unified approach to protection, detection, and recovery across the data lifecycle. 

<. Elija tecnologías de copia de seguridadection id="FAQ. Elija tecnologías de copia de seguridad" cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="blade t-fog blade-pt-md blade-pb-md " >

Pregunta. Elija tecnologías de copia de seguridad frecuente. Elija tecnologías de copia de seguridad

<. Elija tecnologías de copia de seguridadummary>
What i. Elija tecnologías de copia de seguridad A-to-Z cyber re. Elija tecnologías de copia de seguridadilience?

<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TextRun SCXW67173536 BCX0" lang="EN-US" xml:lang="EN-US" data-contra. Elija tecnologías de copia de seguridadt="none"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">A-to-Z cyber re. Elija tecnologías de copia de seguridadilience i. Elija tecnologías de copia de seguridad a unified approach that cover. Elija tecnologías de copia de seguridad the entire data lifecycle<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">–<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">from protection and monitoring through governance and recovery. CommvaultCloud<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">help. Elija tecnologías de copia de seguridad you<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">implement<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TrackChangeTextDeletionMarker TrackedChange SCXW67173536 BCX0"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TextRun SCXW67173536 BCX0" lang="EN-US" xml:lang="EN-US" data-contra. Elija tecnologías de copia de seguridadt="none"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun TrackChangeTextDeletion SCXW67173536 BCX0">. Elija tecnologías de copia de seguridad<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TextRun SCXW67173536 BCX0" lang="EN-US" xml:lang="EN-US" data-contra. Elija tecnologías de copia de seguridadt="none"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0"> thi. Elija tecnologías de copia de seguridad through it. Elija tecnologías de copia de seguridad <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">re. Elija tecnologías de copia de seguridadilience operation. Elija tecnologías de copia de seguridad (<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SpellingErrorV2Themed SCXW67173536 BCX0">Re. Elija tecnologías de copia de seguridadOp. Elija tecnologías de copia de seguridad<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">)<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0"> framework, replacing fragmented tool. Elija tecnologías de copia de seguridad with an integrated . Elija tecnologías de copia de seguridadtrategy that u. Elija tecnologías de copia de seguridade. Elija tecnologías de copia de seguridad AI-enabled threat detection, immutable . Elija tecnologías de copia de seguridadtorage, and orche. Elija tecnologías de copia de seguridadtrated recovery to <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">gestionar <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW67173536 BCX0">ri. Elija tecnologías de copia de seguridadk and improve re. Elija tecnologías de copia de seguridadpon. Elija tecnologías de copia de seguridade time. Elija tecnologías de copia de seguridad acro. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad hybrid environment. Elija tecnologías de copia de seguridad.<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="EOP SCXW67173536 BCX0" data-ccp-prop. Elija tecnologías de copia de seguridad="{}"> 

<. Elija tecnologías de copia de seguridadummary>
Why i. Elija tecnologías de copia de seguridad cyber re. Elija tecnologías de copia de seguridadilience a bu. Elija tecnologías de copia de seguridadine. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad priority, not ju. Elija tecnologías de copia de seguridadt an IT concern?

<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TextRun SCXW17604337 BCX0" lang="EN-US" xml:lang="EN-US" data-contra. Elija tecnologías de copia de seguridadt="auto"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0">Cyber incident. Elija tecnologías de copia de seguridad <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0">can<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0">directly<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0">impact<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0"> cu. Elija tecnologías de copia de seguridadtomer tru. Elija tecnologías de copia de seguridadt, revenue, and brand reputation. CommvaultCloud help. Elija tecnologías de copia de seguridad organization. Elija tecnologías de copia de seguridad addre. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad thi. Elija tecnologías de copia de seguridad ri. Elija tecnologías de copia de seguridadk with unified data protection and threat monitoring, giving bu. Elija tecnologías de copia de seguridadine. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad leader. Elija tecnologías de copia de seguridad vi. Elija tecnologías de copia de seguridadibility and control to <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0">be able to<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0">re. Elija tecnologías de copia de seguridadpond quickly and <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0">maintain<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW17604337 BCX0"> tru. Elija tecnologías de copia de seguridadt acro. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad critical operation. Elija tecnologías de copia de seguridad.<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="EOP SCXW17604337 BCX0" data-ccp-prop. Elija tecnologías de copia de seguridad="{}"> 

<. Elija tecnologías de copia de seguridadummary>
How doe. Elija tecnologías de copia de seguridad a data breach affect cu. Elija tecnologías de copia de seguridadtomer tru. Elija tecnologías de copia de seguridadt?

<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TextRun SCXW153074622 BCX0" lang="EN-US" xml:lang="EN-US" data-contra. Elija tecnologías de copia de seguridadt="auto"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW153074622 BCX0">A . Elija tecnologías de copia de seguridadingle breach canquickly erode cu. Elija tecnologías de copia de seguridadtomer confidence, e. Elija tecnologías de copia de seguridadpecially when . Elija tecnologías de copia de seguridaden. Elija tecnologías de copia de seguridaditive data i. Elija tecnologías de copia de seguridad expo. Elija tecnologías de copia de seguridaded. CommvaultCloud Threat Scanhelp. Elija tecnologías de copia de seguridad <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW153074622 BCX0">identify<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW153074622 BCX0"> hidden threat. Elija tecnologías de copia de seguridad in backup data, enabling . Elija tecnologías de copia de seguridadafer recovery and helping organization. Elija tecnologías de copia de seguridad <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW153074622 BCX0">maintain<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW153074622 BCX0"> tru. Elija tecnologías de copia de seguridadt through more reliable, clean re. Elija tecnologías de copia de seguridadtore proce. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridade. Elija tecnologías de copia de seguridad.<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="EOP SCXW153074622 BCX0" data-ccp-prop. Elija tecnologías de copia de seguridad="{}"> 

<. Elija tecnologías de copia de seguridadummary>
What role doe. Elija tecnologías de copia de seguridad leader. Elija tecnologías de copia de seguridadhip play in cyber re. Elija tecnologías de copia de seguridadilience?

<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TextRun SCXW45144074 BCX0" lang="EN-US" xml:lang="EN-US" data-contra. Elija tecnologías de copia de seguridadt="auto"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW45144074 BCX0">Leader. Elija tecnologías de copia de seguridadhip align. Elija tecnologías de copia de seguridad . Elija tecnologías de copia de seguridadtrategy, inve. Elija tecnologías de copia de seguridadtment, and accountability acro. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad the organization. With CommvaultCloud and it. Elija tecnologías de copia de seguridad <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SpellingErrorV2Themed SCXW45144074 BCX0">Re. Elija tecnologías de copia de seguridadOp. Elija tecnologías de copia de seguridad<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW45144074 BCX0"> framework, leader. Elija tecnologías de copia de seguridad canunify protection, detection, and recovery effort. Elija tecnologías de copia de seguridad, helping team. Elija tecnologías de copia de seguridad act fa. Elija tecnologías de copia de seguridadter, coordinate re. Elija tecnologías de copia de seguridadpon. Elija tecnologías de copia de seguridade, and communicate effectively during cyber incident. Elija tecnologías de copia de seguridad.<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="EOP Selected SCXW45144074 BCX0" data-ccp-prop. Elija tecnologías de copia de seguridad="{"335559738":240,"335559739":240}"> 

<. Elija tecnologías de copia de seguridadummary>
Why are fragmented cyber. Elija tecnologías de copia de seguridadecurity tool. Elija tecnologías de copia de seguridad no longer effective?

<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TextRun SCXW66027038 BCX0" lang="EN-US" xml:lang="EN-US" data-contra. Elija tecnologías de copia de seguridadt="auto"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW66027038 BCX0">Modern environment. Elija tecnologías de copia de seguridad . Elija tecnologías de copia de seguridadpan hybrid cloud, SaaS, and on-prem . Elija tecnologías de copia de seguridady. Elija tecnologías de copia de seguridadtem. Elija tecnologías de copia de seguridad, creating a broad attack . Elija tecnologías de copia de seguridadurface. CommvaultCloud unifie. Elija tecnologías de copia de seguridad capabilitie. Elija tecnologías de copia de seguridad like air-gapped protection, <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW66027038 BCX0">regular <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW66027038 BCX0">monitoring, and automated recovery, helping<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW66027038 BCX0">eliminate<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW66027038 BCX0"> gap. Elija tecnologías de copia de seguridad and enabl<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW66027038 BCX0">e<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW66027038 BCX0"> more coordinated, efficient re. Elija tecnologías de copia de seguridadpon. Elija tecnologías de copia de seguridade. Elija tecnologías de copia de seguridad to threat. Elija tecnologías de copia de seguridad.<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="EOP SCXW66027038 BCX0" data-ccp-prop. Elija tecnologías de copia de seguridad="{}"> 

<. Elija tecnologías de copia de seguridadummary>
How doe. Elija tecnologías de copia de seguridad CommvaultCloud . Elija tecnologías de copia de seguridadupport cyber re. Elija tecnologías de copia de seguridadilience?

<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="TextRun SCXW253710022 BCX0" lang="EN-US" xml:lang="EN-US" data-contra. Elija tecnologías de copia de seguridadt="auto"><. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW253710022 BCX0">CommvaultCloud integrate. Elija tecnologías de copia de seguridad protection, threat detection, and recovery into a . Elija tecnologías de copia de seguridadingle platform. With capabilitie. Elija tecnologías de copia de seguridad like <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW253710022 BCX0">Commvault<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW253710022 BCX0">Cleanroom™ and automated workflow. Elija tecnologías de copia de seguridad, it help. Elija tecnologías de copia de seguridad organization. Elija tecnologías de copia de seguridad <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW253710022 BCX0">gestionar <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW253710022 BCX0">ri. Elija tecnologías de copia de seguridadk, accelerate recovery, and <. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW253710022 BCX0">maintain<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="NormalTextRun SCXW253710022 BCX0"> bu. Elija tecnologías de copia de seguridadine. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad continuity acro. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad the data lifecycle.<. Elija tecnologías de copia de seguridadpan cla. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad="EOP SCXW253710022 BCX0" data-ccp-prop. Elija tecnologías de copia de seguridad="{}"> 

<. Elija tecnologías de copia de seguridadcript tran. Elija tecnologías de copia de seguridadlate="no" type="application/ld+j. Elija tecnologías de copia de seguridadon">{ “@context”: “http. Elija tecnologías de copia de seguridad://. Elija tecnologías de copia de seguridadchema.org”, “@type”: “FAQPage”, “mainEntity”: [ { “@type”: “Que. Elija tecnologías de copia de seguridadtion”, “name”: “What i. Elija tecnologías de copia de seguridad A-to-Z cyber re. Elija tecnologías de copia de seguridadilience? “, “acceptedAn. Elija tecnologías de copia de seguridadwer”: { “@type”: “An. Elija tecnologías de copia de seguridadwer”, “text”: “A-to-Z cyber re. Elija tecnologías de copia de seguridadilience i. Elija tecnologías de copia de seguridad a unified approach that cover. Elija tecnologías de copia de seguridad the entire data lifecycle-from protection and monitoring through governance and recovery. CommvaultCloudhelp. Elija tecnologías de copia de seguridad youimplement. Elija tecnologías de copia de seguridad thi. Elija tecnologías de copia de seguridad through it. Elija tecnologías de copia de seguridad re. Elija tecnologías de copia de seguridadilience operation. Elija tecnologías de copia de seguridad (Re. Elija tecnologías de copia de seguridadOp. Elija tecnologías de copia de seguridad) framework, replacing fragmented tool. Elija tecnologías de copia de seguridad with an integrated . Elija tecnologías de copia de seguridadtrategy that u. Elija tecnologías de copia de seguridade. Elija tecnologías de copia de seguridad AI-enabled threat detection, immutable . Elija tecnologías de copia de seguridadtorage, and orche. Elija tecnologías de copia de seguridadtrated recovery to gestionar ri. Elija tecnologías de copia de seguridadk and improve re. Elija tecnologías de copia de seguridadpon. Elija tecnologías de copia de seguridade time. Elija tecnologías de copia de seguridad acro. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad hybrid environment. Elija tecnologías de copia de seguridad.” } }, { “@type”: “Que. Elija tecnologías de copia de seguridadtion”, “name”: “Why i. Elija tecnologías de copia de seguridad cyber re. Elija tecnologías de copia de seguridadilience a bu. Elija tecnologías de copia de seguridadine. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad priority, not ju. Elija tecnologías de copia de seguridadt an IT concern? “, “acceptedAn. Elija tecnologías de copia de seguridadwer”: { “@type”: “An. Elija tecnologías de copia de seguridadwer”, “text”: “Cyber incident. Elija tecnologías de copia de seguridad candirectlyimpact cu. Elija tecnologías de copia de seguridadtomer tru. Elija tecnologías de copia de seguridadt, revenue, and brand reputation. CommvaultCloud help. Elija tecnologías de copia de seguridad organization. Elija tecnologías de copia de seguridad addre. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad thi. Elija tecnologías de copia de seguridad ri. Elija tecnologías de copia de seguridadk with unified data protection and threat monitoring, giving bu. Elija tecnologías de copia de seguridadine. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad leader. Elija tecnologías de copia de seguridad vi. Elija tecnologías de copia de seguridadibility and control to be able tore. Elija tecnologías de copia de seguridadpond quickly and maintain tru. Elija tecnologías de copia de seguridadt acro. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad critical operation. Elija tecnologías de copia de seguridad.” } }, { “@type”: “Que. Elija tecnologías de copia de seguridadtion”, “name”: “How doe. Elija tecnologías de copia de seguridad a data breach affect cu. Elija tecnologías de copia de seguridadtomer tru. Elija tecnologías de copia de seguridadt? “, “acceptedAn. Elija tecnologías de copia de seguridadwer”: { “@type”: “An. Elija tecnologías de copia de seguridadwer”, “text”: “A . Elija tecnologías de copia de seguridadingle breach canquickly erode cu. Elija tecnologías de copia de seguridadtomer confidence, e. Elija tecnologías de copia de seguridadpecially when . Elija tecnologías de copia de seguridaden. Elija tecnologías de copia de seguridaditive data i. Elija tecnologías de copia de seguridad expo. Elija tecnologías de copia de seguridaded. CommvaultCloud Threat Scanhelp. Elija tecnologías de copia de seguridad identify hidden threat. Elija tecnologías de copia de seguridad in backup data, enabling . Elija tecnologías de copia de seguridadafer recovery and helping organization. Elija tecnologías de copia de seguridad maintain tru. Elija tecnologías de copia de seguridadt through more reliable, clean re. Elija tecnologías de copia de seguridadtore proce. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridade. Elija tecnologías de copia de seguridad.” } }, { “@type”: “Que. Elija tecnologías de copia de seguridadtion”, “name”: “What role doe. Elija tecnologías de copia de seguridad leader. Elija tecnologías de copia de seguridadhip play in cyber re. Elija tecnologías de copia de seguridadilience? “, “acceptedAn. Elija tecnologías de copia de seguridadwer”: { “@type”: “An. Elija tecnologías de copia de seguridadwer”, “text”: “Leader. Elija tecnologías de copia de seguridadhip align. Elija tecnologías de copia de seguridad . Elija tecnologías de copia de seguridadtrategy, inve. Elija tecnologías de copia de seguridadtment, and accountability acro. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad the organization. With CommvaultCloud and it. Elija tecnologías de copia de seguridad Re. Elija tecnologías de copia de seguridadOp. Elija tecnologías de copia de seguridad framework, leader. Elija tecnologías de copia de seguridad canunify protection, detection, and recovery effort. Elija tecnologías de copia de seguridad, helping team. Elija tecnologías de copia de seguridad act fa. Elija tecnologías de copia de seguridadter, coordinate re. Elija tecnologías de copia de seguridadpon. Elija tecnologías de copia de seguridade, and communicate effectively during cyber incident. Elija tecnologías de copia de seguridad.” } }, { “@type”: “Que. Elija tecnologías de copia de seguridadtion”, “name”: “Why are fragmented cyber. Elija tecnologías de copia de seguridadecurity tool. Elija tecnologías de copia de seguridad no longer effective? “, “acceptedAn. Elija tecnologías de copia de seguridadwer”: { “@type”: “An. Elija tecnologías de copia de seguridadwer”, “text”: “Modern environment. Elija tecnologías de copia de seguridad . Elija tecnologías de copia de seguridadpan hybrid cloud, SaaS, and on-prem . Elija tecnologías de copia de seguridady. Elija tecnologías de copia de seguridadtem. Elija tecnologías de copia de seguridad, creating a broad attack . Elija tecnologías de copia de seguridadurface. CommvaultCloud unifie. Elija tecnologías de copia de seguridad capabilitie. Elija tecnologías de copia de seguridad like air-gapped protection, regular monitoring, and automated recovery, helpingeliminate gap. Elija tecnologías de copia de seguridad and enable more coordinated, efficient re. Elija tecnologías de copia de seguridadpon. Elija tecnologías de copia de seguridade. Elija tecnologías de copia de seguridad to threat. Elija tecnologías de copia de seguridad.” } }, { “@type”: “Que. Elija tecnologías de copia de seguridadtion”, “name”: “How doe. Elija tecnologías de copia de seguridad CommvaultCloud . Elija tecnologías de copia de seguridadupport cyber re. Elija tecnologías de copia de seguridadilience? “, “acceptedAn. Elija tecnologías de copia de seguridadwer”: { “@type”: “An. Elija tecnologías de copia de seguridadwer”, “text”: “CommvaultCloud integrate. Elija tecnologías de copia de seguridad protection, threat detection, and recovery into a . Elija tecnologías de copia de seguridadingle platform. With capabilitie. Elija tecnologías de copia de seguridad like CommvaultCleanroom\u2122 and automated workflow. Elija tecnologías de copia de seguridad, it help. Elija tecnologías de copia de seguridad organization. Elija tecnologías de copia de seguridad gestionar ri. Elija tecnologías de copia de seguridadk, accelerate recovery, and maintain bu. Elija tecnologías de copia de seguridadine. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad continuity acro. Elija tecnologías de copia de seguridad. Elija tecnologías de copia de seguridad the data lifecycle.” } } ] }

Explora recursos relacionados

Explora

Protección de datos unificada

Descubre en qué consiste una estrategia de protección unificada de datos y conoce consejos que pueden seguir las grandes empresas para alcanzar una verdadera ciberresiliencia.
Más informaciónabout Protección de datos unificada
Resumen de la solución

Racionalizar la protección y gestión de datos para la empresa híbrida

Learn why Commvault’s solution can help organizations streamline their data management processes, manage risk, and enable the resilience of their critical data.
Lea el resumenabout Racionalizar la protección y gestión de datos para la empresa híbrida

Every episode of Ready. Or Not. has challenged me to think about AI a little differently. The conversations have moved from understanding agentic AI to building trust and preparing organizations for responsible adoption. This episode turns its attention to vibe coding and why it’s becoming one of AI’s most talked-about ways of working.

Comedian Nathan Macintosh sits down with Microsoft engineer and open-source leader Harald Kirschner to discuss what vibe coding really means, why it’s gaining momentum, and where it can go wrong if speed outpaces oversight.

Watch the episodio completoen Readiverse.

Puntos Clave

  • La IA está facilitando a las organizaciones la tarea de probar ideas, resolver problemas e innovar más rápidamente.
  • La programación intuitiva ayuda a los equipos a explorar y validar ideas rápidamente antes de realizar inversiones más importantes.
  • AI delivers more value when it’s used to challenge assumptions – not just generate content.
  • El criterio humano, la revisión minuciosa y unas directrices claras siguen siendo esenciales en un mundo impulsado por la IA.
  • Las organizaciones que aprendan más rápido estarán mejor posicionadas para innovar.

I was already familiar with the term vibe coding, but after listening to this episode, I walked away with a much better understanding of why people – not just developers, but also nontechnical teams – are embracing it.

By the end of the conversation, I realized vibe coding isn’t really about coding at all. It’s about learning faster and knowing where AI fits into the creative process. The conversation also makes something else clear: AI may accelerate the work, but people are still responsible for guiding it. That’s why guardrails matter more than ever. Here are some of the themes that resonated with me.

De la idea a la realidad

One thing I learned about vibe coding is that it’s changing how organizations explore ideas. Instead of spending weeks building something before finding out whether it works, teams can quickly create a prototype, gather feedback, and decide whether it’s worth pursuing.

“AI can be a really good critical thought partner if it’s applied properly.”

– Harald Kirschner

Harald explica que el «vibe coding» utiliza el lenguaje natural para convertir las ideas en software funcional. Pone como ejemplo el desarrollo de software, pero el concepto va más allá de los equipos de ingeniería. Tanto para un gestor de producto que prueba una nueva función, como para un diseñador que explora una interfaz o un directivo que valida un concepto, la IA facilita enormemente la transformación de una idea en algo que la gente pueda experimentar de verdad.

That ability to experiment may be one of AI’s greatest strengths. Organizations can learn what resonates, refine ideas earlier, and invest time and resources only after they’ve gained confidence that they’re solving the right problem.

Avanzar rápido sigue requiriendo supervisión

One thing Harald emphasizes throughout the conversation is that speed shouldn’t come at the expense of a thorough review.

Again, he uses software development as an example. AI can quickly generate working code, but that doesn’t automatically make it secure, reliable, or ready for production. Developers still need to review it, test it, and make sure it meets the same standards they would apply to anything else they build.

Harald’s lesson extends well beyond engineering. As AI becomes part of business processes, organizations will need the same mindset whether they’re generating software, creating content, analyzing data, or automating workflows. Vibe coding can help the work move faster, but people are still responsible for validating the results.

That’s one of the most important lessons from the episode. While AI can make it easier to create something quickly, human expertise is what turns a good idea into something people can trust.

Los comentarios sinceros dan mejores resultados

A memorable moment in this episode starts with an unexpected prompt. Instead of asking AI to write code, Harald asks it to critique his work by prompting it to “Roast my code.”

It’s funny, but it’s also an effective way to get more honest feedback from AI. Instead of acting like an assistant that simply completes a task, AI becomes more like a trusted colleague offering another perspective. Used this way, it can challenge assumptions, uncover blind spots, and improve the quality of the final result.

AI’s constructive criticism can help us improve our work, but it also becomes more useful when we continue teaching and refining it. Anyone who’s spent time working with AI knows it could use a little feedback, too.

Sneak Peek: Checking the Vibe

¿Qué ocurre cuando la IA sigue cometiendo los mismos errores? Nathan lo compara con un invitado revoltoso a una fiesta al que, al final, dejan de invitar. Escucha a Harald explicar cómo entrenar a la IA para que resulte más útil con el tiempo.

La innovación se vuelve más accesible

Algo que va surgiendo una y otra vez a lo largo de la conversación es que la IA está cambiando quién puede participar en la innovación.

La IA está reduciendo las barreras para que las personas de toda una organización exploren ideas, experimenten con nuevos enfoques y den vida rápidamente a los conceptos. En lugar de depender de especialistas técnicos para validar cada idea, más personas pueden crear algo tangible, recabar opiniones y perfeccionar sus ideas antes de invertir una cantidad significativa de tiempo y recursos.

“… you can actually build it and hand it to some people and see like, oh, this is flying, or this is really falling flat.”

– Harald Kirschner

To me, that’s one of AI’s most exciting opportunities. By making experimentation faster and more accessible, AI gives organizations the confidence to test more ideas, learn from them sooner, and involve more people into the creative process.

Ready for What’s Next

Vibe coding may be the workflow everyone’s talking about today, but the bigger story is how AI continues to change the way we learn, experiment, and solve problems. Every episode of Ready. Or Not. reminds me that the organizations willing to explore new technology will be the ones best prepared for what’s next.

Watch the episodio completoen Readiverse.

Preguntas frecuentes

Q: What is vibe coding?

A: Vibe coding is an emerging way of working with AI that uses natural language to quickly turn ideas into something tangible. Instead of starting from scratch, people can use AI to prototype concepts, explore solutions, gather feedback, and iterate much more quickly.

Q: Why is vibe coding generating so much interest?

A: Vibe coding lowers the barrier to experimentation. It allows more people – not just technical specialists – to test ideas, validate concepts, and learn what works before investing significant time and resources.

Q: Does vibe coding replace human expertise?

A: No. The conversation makes it clear that AI works best as a collaborator, not a replacement. People are still responsible for applying judgment, reviewing results, and deciding what should move forward.

Q: Why do organizations still need guardrails when using AI?

A: AI can accelerate work, but it doesn’t eliminate the need for thoughtful oversight. Clear policies, review processes, and human expertise help organizations validate AI-generated work and reduce unnecessary risk.

Q: How can AI improve the way organizations work?

A: Beyond generating content or prototypes, AI can help challenge assumptions, identify blind spots, suggest improvements, and accelerate learning. Used thoughtfully, it becomes another perspective that helps teams make better decisions.

Q: What’s the biggest takeaway from this episode?

A: The greatest value of AI isn’t simply helping organizations move faster. It’s helping them experiment more freely, learn more quickly, and involve more people in the innovation process – while continuing to rely on human judgment to guide the final decisions.

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave

  • Commvault has joined the Open Secure AI Alliance to help advance open, secure, and collaborative approaches to AI.  
  • Open source AI tools give organizations greater visibility and control, allowing experts to inspect, adapt, and strengthen systems as threats and requirements evolve.  
  • Effective AI security extends beyond models to include identity, permissions, guardrails, logging, evaluation, and the broader environment in which AI agents operate.  
  • Cross-industry collaboration and shared research can help organizations respond more quickly to the rapidly changing challenges created by increasingly capable agentic AI.  
  • Commvault will share its cyber resilience and data expertise with the Alliance, grounded in the principle that organizations can better protect systems and data they fully understand.  

Collaboration has long been one of the most effective ways the technology industry meets new challenges. The past few months have brought that lesson into sharper focus for AI. Agentic systems are becoming more capable, more independent, and more deeply connected to the technology we use every day.  

Recent events also have shown how quickly this landscape can change. When an advanced AI system created an unexpected security challenge forHugging Face, the organization used an open-weight model on its own infrastructure to understand and contain the situation. The experience demonstrated the value of open source AI tools that organizations can inspect, adapt, and control when needed.  

Moments like this should not diminish our optimism about AI. They should deepen our commitment to shaping its future together.  

That is why Commvault is proud to join the  Open Secure AI Alliance, a community of leading organizations advancing AI through open research, shared knowledge, and practical tools.  

AI will keep evolving, and no single organization will have every answer. Bringing together deep expertise from across the industry gives the community a better chance to understand what is changing and respond with the speed this new era demands.  

Open source is central to that effort. It gives experts the ability to examine how systems work and improve what others have started. For defenders, it also provides something essential: the freedom to choose and adapt the right technology for the situation rather than depending on a single system or provider.  

NVIDIA describes this as an open defense foundation built on models, harnesses, and tools that the community can study and strengthen.  

The Alliance also recognizes that AI security extends well beyond the model. Identity, permissions, guardrails, logs, and evaluation all shape how an agent behaves. Understanding that complete environment will take new research and a willingness to share what the industry learns along the way.  

Commvault’s perspective is grounded in years of solving complex cyber resilience challenges – helping organizations understand their data, keep it trustworthy, and recover with confidence when disruption strikes.  

Much of that work comes down to the same idea the Alliance is pursuing: You can only protect what you fully understand. That’s the experience we hope to bring, alongside an eagerness to learn from others tackling these challenges from different angles. 

The opportunity ahead for AI is enormous. Realizing it will depend not only on how quickly the technology advances, but on how openly the industry works together as it does. Commvault is glad to be part of that work, and excited to help build what comes next.  

Read NVIDIA’s announcement here: Industry Leaders Join the Open Secure AI Alliance.  

Preguntas frecuentes

Q: What is the Open Secure AI Alliance?R:The Open Secure AI Alliance is a community of organizations working to advance AI security through open research, shared knowledge, models, harnesses, and practical tools. Its collaborative approach gives participants opportunities to study emerging challenges and strengthen AI defenses together. 
Q: Why has Commvault joined the Open Secure AI Alliance?R:Commvault joined the Alliance to contribute its experience in cyber resilience, data understanding, trust, and recovery. It also provides an opportunity for Commvault to learn from other industry leaders approaching AI security from different perspectives. 
Q: Why is open source important for AI security?R:Open source allows experts to examine how AI systems work, build on existing technologies, and adapt tools to specific security situations. It also gives defenders greater freedom to select and modify technologies rather than relying on a single system or provider. 
Q: What does AI security involve beyond protecting the model?R:AI security encompasses the broader environment in which an AI system operates, including identity, permissions, guardrails, logs, and evaluation. Understanding these interconnected elements can help organizations better assess and manage how AI agents behave. 
Q: How does Commvault’s cyber resilience experience relate to AI security?R: Commvault’s cyber resilience work focuses on helping organizations understand their data, maintain its trustworthiness, and recover confidently after disruption. That perspective fits naturally with the Alliance’s focus on open, inspectable approaches to AI security.  
Q: Why is industry collaboration important for the future of AI?R:AI is evolving too quickly and broadly for any single organization to have every answer. Combining expertise, research, and practical insights across the industry can help the community understand emerging challenges and respond at the speed AI development demands. 

Alexander Coombesis AVP, Strategic Partner Development, at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Guía sobre el Backup and Recovery en la nube: desde la detección de amenazas hasta la Recovery completa

Descubre cómo funcionan las copias de seguridad y la Recovery en la nube para ayudar a proteger los datos sanos, comprobar la Readiness para la Recovery y restablecer las operaciones empresariales tras un ataque de ransomware o un incidente cibernético.


El proceso ideal de Backup and Recovery en la nube comienza con la detección de amenazas como el ransomware, los accesos sospechosos o la actividad anómala de los datos. A continuación, las organizaciones pueden obtener copias de seguridad limpias e inmutables; validar los puntos de recuperación no afectados; y aislar los sistemas comprometidos. Una vez verificadas, las aplicaciones y los datos críticos pueden restaurarse mediante procesos de Recovery automatizados, lo que ayuda a minimizar el tiempo de inactividad, reducir la pérdida de datos y restablecer las operaciones empresariales de forma rápida y segura.


Cyber resilience is increasingly measured by what happens after attackers get in. Organizations have invested heavily in prevention, detection, and response, but ransomware, vulnerability exploitation, credential abuse, cloud misconfigurations, and third-party compromise continue to disrupt operations.

For many teams, the recovery challenge is no longer simply whether backups exist. It is whether those backups are clean, protected, validated, and ready to restore critical services when production systems can no longer be trusted.

That distinction matters because cyberattacks continue to create both data risk and operational disruption. According to the Verizon2026 Data Breach Investigations Report, ransomware was involved in 48% of breaches, up from 44% the previous year. The report also found that exploitation of vulnerabilities became the most common initial access vector for breaches, rising to 31% while credential abuse fell to 13%.

Cloud backup and recovery efforts need to support the full path from detection to restoration. That starts with identifying suspicious activity before compromised data is restored. It continues with protected, immutable recovery points that give teams usable recovery options when production systems are no longer trusted.

From there, organizations need a way to validate which recovery points are clean and restore critical workloads in the right order. The result is a recovery strategy that helps teams move from incident response to operational restoration with more confidence.

 


¿Por qué Backup and Recovery en la nube constituyen una estrategia de ciberresiliencia?

Traditional backup strategies were designed to help organizations recover from hardware failures, accidental deletion, and localized outages. Those use cases still matter, but today’s recovery requirements are broader.

Los ciberataques pueden afectar al mismo tiempo a las cargas de trabajo de producción, los sistemas de identidad, las configuraciones en la nube, las aplicaciones SaaS y los entornos de copia de seguridad. Cuando eso ocurre, la recuperación no consiste solo en restaurar una copia de los datos. Se trata de determinar en qué sistemas se puede confiar, qué puntos de recuperación siguen intactos y qué servicios deben restablecerse en primer lugar.

Por eso,Backup and Recovery en la nubese han convertido en una parte fundamental de la ciberresiliencia. Una estrategia moderna debe ayudar a los equipos a detectar actividades sospechosas, proteger los datos de Recovery, validar la integridad de las copias de seguridad y restaurar las operaciones críticas siguiendo una secuencia controlada. También debe facilitar la realización de pruebas periódicas, ya que un plan de Recovery que no se haya puesto a prueba puede no funcionar como se espera durante un incidente real.

Esto marca un cambio: se pasa de considerar la copia de seguridad como una póliza de seguro a verla como una capacidad operativa de Recovery. Las copias almacenadas siguen siendo importantes, pero solo son una parte de la ecuación de Recovery. Los equipos también necesitan tener la seguridad de que los datos de Recovery no han sido alterados, de que se han probado los flujos de trabajo de restauración y de que la empresa sabe qué servicios deben restablecerse primero.

Backup and Recovery resulta más fácil de entender cuando se considera como un ciclo de vida. Las cinco etapas que se indican a continuación muestran cómo las organizaciones pueden pasar de la detección temprana de amenazas a una Recovery validada y a la mejora de la resiliencia a largo plazo.


Fase 1: Detectar las amenazas antes de que se extienda el riesgo de Recovery

Recovery comienza antes de que se restablezcan los sistemas. En un incidente cibernético, la primera prioridad es determinar si la actividad sospechosa ha afectado a los datos de producción, a los datos de copia de seguridad o a ambos.

Si los equipos realizan la restauración desde un punto de recuperación comprometido, podrían reintroducir en el entorno archivos dañados, rastros de malware o cambios no autorizados. Ese riesgo convierte la detección de amenazas en una parte importante de Backup and Recovery en la nube, y no solo en una cuestión de operaciones de seguridad.

Las estrategias de Recovery modernas deben incluir visibilidad de la actividad anómala en todas las cargas de trabajo, entornos de copia de seguridad y puntos de Recovery. Es posible que los equipos tengan que investigar señales como:

  • Comportamiento inusual en el cifrado
  • Picos repentinos de eliminaciones
  • Cambios inesperados en los privilegios
  • Patrones de copia de seguridad anómalos
  • Indicadores de malware

Estas señales pueden ayudar a los equipos a comprender hasta dónde puede haberse extendido un ataque y qué datos pueden requerir una revisión adicional antes de su restauración.

Timing is another essential factor. Microsoft’s El Informe de Defensa Digital 2025de Microsoft reveló que la mayoría de los ataques investigados por su Equipo de Detección y Respuesta (DART) tenían tiempos de permanencia cortos, lo que significa que los equipos de recuperación podrían no disponer de semanas para comprender el alcance total de la intrusión antes de que los atacantes se desplacen lateralmente, accedan a datos confidenciales, interfieran en los servicios o intenten afectar a los sistemas de copia de seguridad. El contexto de la detección puede ayudar a los equipos a evitar tratar todos los puntos de recuperación como igualmente fiables.

El 59 % de los ataques investigados por Microsoft DART tuvieron una duración de siete días o menos, lo que hace que la detección temprana sea fundamental para las decisiones de Recovery.
Source:Informe de Defensa Digital de Microsoft 2025

Threat detection doesn’t eliminate recovery risk on its own. It helps create a more informed recovery process. When suspicious activity is identified early, organizations can isolate affected systems, investigate impacted data, and avoid restoring recovery points that may reintroduce the same threat.

Esto proporciona a los equipos de seguridad, TI y Recovery un punto de partida más claro para la siguiente fase: proteger los puntos de recuperación no infectados antes de que los atacantes puedan alterarlos o eliminarlos.


Stage 2: Protect clean recovery points from attack

In a cyber incident, backups are not just stored copies. They are part of the recovery path, which means attackers may try to disrupt them. If backup data is altered, encrypted, deleted, or made inaccessible, the organization may lose one of its best options for restoring operations without relying on compromised production systems.

That’s why clean recovery pointsneed layered protection. Immutable and indelible backup storage can help preserve data for a defined retention period. Offsite or isolated copies help add separation from the production environment. Encryption, access controls, and role-based permissions help limit who can access or change backup settings. Together, these safeguards make it harder for attackers to interfere with the data teams may need most during recovery.

The goal is to preserve recovery choice. The 2026 Verizon report found that69% of ransomware victimsin its dataset did not pay the ransom, up from 65% the prior year. The report also notes that median ransom payments continued to decline, which it links in part to improved defensive adaptations and increased victim resilience. Teams need clean backups they can actually use, so paying a ransom is not the only path back to business.

The familiar 3-2-1 backup rule still provides a useful foundation: Keep three copies of data, on two different media or platforms, with at least one copy stored offsite or isolated. Modern cloud backup and recovery strategies often extend that model with immutable storage, air-gapped patterns, policy-based retention, and replicated copies across cloud or hybrid environments.

With protected recovery points in place, teams can pare down their restore options and move into validation with a clearer view of what is ready to bring back.


Etapa 3: Comprobar qué copias de seguridad están listas para restaurarse

Disponer de copias de seguridad no es lo mismo que estar preparado para la recuperación. Antes de que los equipos restauren los sistemas de producción, deben saber qué puntos de recuperación son utilizables, qué cargas de trabajo se han visto afectadas y qué dependencias deben recuperarse junto con ellas.

Una copia de seguridad reciente puede contener los datos empresariales más actuales, pero también puede incluir archivos dañados, cambios no autorizados o rastros de malware. Una copia de seguridad más antigua puede estar más limpia, pero puede provocar una mayor pérdida de datos. La validación ayuda a los equipos a tomar esa decisión basándose en pruebas, en lugar de en conjeturas.

Esa labor comienza con la delimitación del alcance del incidente. Los equipos de seguridad y de TI deben comprender cuándo comenzó la actividad sospechosa, qué sistemas se vieron afectados y si se vieron afectados los servicios de identidad, las bases de datos, los recursos compartidos de archivos, las aplicaciones SaaS o las configuraciones en la nube.

También deben confirmar si el punto de recuperación es compatible con la aplicación en su conjunto, y no solo con los datos que la sustentan. La restauración de una base de datos, por ejemplo, puede depender de que los servidores de aplicaciones, los permisos, las claves de cifrado, las rutas de red y los servicios de identidad estén disponibles en el estado adecuado.

Los entornos de Recovery aislados pueden ayudar a los equipos a comprobar esas condiciones antes de restaurar el entorno de producción. En un entorno controlado, los equipos pueden, de forma segura:

  • Analizar los puntos de Recovery seleccionados.
  • Revisar los cambios en los archivos.
  • Confirmar el inicio de la aplicación.
  • Probar el acceso de los usuarios.
  • Comprobar si los sistemas dependientes se comportan según lo previsto.

Validacióntambién debe servir de base para la secuencia de Recovery. Es posible que los equipos tengan que restaurar primero los servicios de identidad, luego la infraestructura básica, a continuación las aplicaciones críticas para la misión y, por último, las cargas de trabajo de apoyo.

Al probar los puntos de recuperación antes de la restauración, pueden reducir sus opciones y decidir qué sistemas están listos para volver a ponerse en marcha, cuáles necesitan una revisión más detallada y cuáles deben permanecer aislados hasta que se comprenda mejor el riesgo.

La siguiente etapa es aquella en la que esa decisión se traduce en acción: restaurar los sistemas, las aplicaciones y los datos que la empresa necesita en primer lugar.


Fase 4: Restablecer las operaciones críticas en el orden adecuado

A restore plan starts with the organization’s minimum viable operating state. That means identifying the people, systems, applications, data, and communication channels the business needs to function at a basic level during a disruption.

Para algunas organizaciones, esto puede empezar por los servicios de identidad y las comunicaciones con los empleados. Para otras, puede dar prioridad a las aplicaciones de atención al cliente, los sistemas de pago, los sistemas clínicos, las operaciones de fabricación o las plataformas logísticas. El orden debe reflejar el impacto en el negocio, no solo la conveniencia técnica.

Dependencies are where many recovery plans become more complicated. An application may be listed as “critical,” but it still depends on identity, DNS, network connectivity, databases, storage, encryption keys, APIs, and monitoring. If those pieces are not restored in the right state, the application may come back online but remain unusable. That is why recovery teams need dependency mapping before an incident, not during one.

Los manuales de procedimientos y los flujos de trabajo orquestados ayudan a convertir esas decisiones en pasos repetibles. Permiten definir quién aprueba la restauración, qué entorno debe utilizarse, qué comprobaciones deben realizarse antes de restablecer el acceso a producción y cuándo puede volver a estar operativo el siguiente nivel de sistemas. Esto es importante cuando los equipos de seguridad, infraestructura, aplicaciones, nube y de negocio trabajan todos al mismo tiempo.

La restauración también necesita puntos de control. Tras el restablecimiento de cada carga de trabajo importante, los equipos deben confirmar que los usuarios pueden autenticarse, que los datos están disponibles, que las integraciones funcionan y que la supervisión está activa. Esas comprobaciones ayudan a detectar problemas antes de que Recovery se extienda al siguiente nivel de sistemas.

La rapidez sigue siendo importante, pero el control lo es igual de importante. Una restauración rápida puede generar más trabajo si se recuperan datos erróneos, si faltan controles de acceso o si una aplicación vuelve a estar operativa sin los sistemas que necesita para funcionar. El enfoque más sólido consiste en restaurar por fases, confirmar que cada servicio crítico funciona y, a continuación, seguir ampliando Recovery a medida que el entorno se estabiliza.


Etapa 5: Convertir las lecciones aprendidas de Recovery en una mayor continuidad

Una vez restablecidos los servicios críticos, los equipos aún deben comprender qué funcionó, qué les ralentizó y en qué aspectos el plan de Recovery no se ajustó a la realidad. Ese seguimiento es lo que convierte la Backup and Recovery en la nube en una actividad de respuesta en una práctica de resiliencia continua.

El primer paso es revisar el proceso de Recovery en sí. Los equipos deben plantearse preguntas como:

  • ¿Con qué rapidez detectaron los equipos la actividad sospechosa?
  • ¿Resultó fácil identificar los puntos de recuperación válidos?
  • ¿Qué pasos de validación llevaron más tiempo del esperado?
  • ¿En qué puntos se ralentizaron los flujos de trabajo de restauración?
  • ¿Participaron las personas adecuadas en el momento oportuno?

Estas respuestas pueden revelar deficiencias que no siempre son de carácter técnico. Una Recovery puede tener éxito y, aun así, poner de manifiesto problemas relacionados con la toma de decisiones, la comunicación, las aprobaciones o los traspasos entre equipos.

Esos hallazgos deben incorporarse directamente a la próxima versión del plan de Recovery. Si una aplicación crítica dependía de un sistema que no estaba documentado, actualiza el mapa de dependencias. Si los controles de acceso ralentizaron la restauración, aclara el proceso de aprobación. Si en las pruebas de Recovery se pasó por alto una carga de trabajo clave, añádela al próximo ejercicio. Si los responsables de la empresa carecían de visibilidad sobre lo que se había restaurado y lo que seguía fuera de línea, mejora los informes y las vías de escalado.

Las pruebas periódicas son lo que da solidez a este trabajo. Los ejercicios de simulación, las restauraciones aisladas, las pruebas de Recovery en entorno controlado y la validación de Recovery entre nubes ayudan a los equipos a detectar problemas antes de que un incidente real les obligue a aprender bajo presión. También ayudan a proporcionar a los responsables una mejor evidencia de en qué aspectos la organización está preparada y en cuáles aún le queda trabajo por hacer.

Con el tiempo, el objetivo es contar con un programa de Recovery que se perfeccione tras cada prueba y cada incidente. Los equipos estarán mejor preparados, se comprenderán mejor los pasos de Recovery y la organización dispondrá de una hoja de ruta más clara para mantener en funcionamiento las operaciones esenciales durante las interrupciones.


Cómo convertir la recuperación en la nube en resiliencia empresarial

 Cloud backup and recovery now plays a larger role than traditional data protection alone. It is the connected process of detecting recovery risk, protecting backup data, validating clean restore options, and restoring critical services when production environments can no longer be trusted.

En caso de incidente cibernético, estas actividades no pueden llevarse a cabo como etapas independientes. El contexto de la amenaza debe determinar qué copias de seguridad se revisan. La protección de las copias de seguridad debe preservar las opciones de Recovery que los equipos puedan necesitar. La validación debe determinar qué está listo para restaurarse. La restauración debe restablecer los servicios de los que depende la empresa siguiendo un orden controlado.

Una copia de seguridad en la que no se pueda confiar, que no se haya probado o que no se pueda restaurar en el momento adecuado puede no proporcionar a la empresa el resultado que necesita. Un proceso de restauración que ignore la identidad, las dependencias de las aplicaciones o las prioridades empresariales puede dejar los sistemas técnicamente recuperados, pero operativamente incompletos.

La mayor oportunidad radica en tratar la recuperación como una práctica de resiliencia continua. Eso significa probar los planes antes de que se produzca un incidente, actualizar los mapas de dependencias a medida que cambian los entornos y aprovechar cada ejercicio o evento de recuperación para mejorar la siguiente respuesta.

Las organizaciones que se recuperan más rápido no son necesariamente aquellas que cuentan con el mayor número de copias de los datos. Es imprescindible saber qué datos son utilizables, qué servicios son los más importantes y cómo restaurarlos bajo presión.

El reto consiste en que la Readiness para la recuperación sea tan operativa como la detección y la respuesta. Backup and Recovery en la nube proporciona una base práctica para esa labor cuando se abordan como un proceso continuo que va desde la detección de riesgos hasta la restauración del negocio.

Las organizaciones deben desarrollar esa capacidad para estar mejor preparadas a la hora de restaurar datos limpios, recuperar servicios críticos y mantener el negocio en marcha cuando se produzca una interrupción.

 

Acelerar una Recovery segura tras los ciberataques

Learn more about how Commvault’s data backup and recovery solutions can help organizations detect threats, recover clean data, and reduce downtime.

Preguntas frecuentes

¿Cuál es la diferencia entre la copia de seguridad en la nube y la recuperación ante desastres?

La copia de seguridad en la nube se centra en crear copias seguras de los datos para su restauración, mientras que la recuperación ante desastres se centra en restaurar aplicaciones, sistemas y operaciones empresariales tras una interrupción del servicio o un ciberataque. Juntas, contribuyen a garantizar la continuidad y la resiliencia del negocio.

¿Por qué son importantes las copias de seguridad inmutables para la resiliencia cibernética?

Immutable and indelible backups are designed to help prevent backup data from being altered, encrypted, or deleted within defined retention settings. Combined with Commvault AirGap and automated Cleanpoint identification, Commvault’s immutable backup capabilities help keep organizations ready with a verified, clean recovery source available when production systems are compromised.

¿Qué debo buscar en una solución de Backup and Recovery en la nube?

Busque una plataforma que unifique entornos híbridos y multinube, almacenamiento inmutable, coordinación automatizada de la Recovery y gestión centralizada. Commvault Cloud está diseñada teniendo en cuenta estos requisitos, lo que ayuda a las organizaciones a proteger una infraestructura diversa al tiempo que minimiza el tiempo de inactividad durante la Recovery y la complejidad operativa.

¿Ofrece la solución de copias de seguridad de Commvault protección contra el ransomware y copias de seguridad con aislamiento físico?

Sí. Commvault ayuda a las organizaciones a reforzar su ciberresiliencia con copias de seguridad inmutables, opciones de recuperación «air-gapped», detección de amenazas, capacidades de recuperación limpia y protección contra el ransomware en varias capas, diseñadas para ayudar a reducir el riesgo de Recovery y el tiempo de inactividad.

¿Ofrece Commvault pruebas automatizadas de copias de seguridad e informes de cumplimiento normativo?

Sí. Commvault proporciona pruebas de Recovery automatizadas, validación de copias de seguridad, informes de cumplimiento normativo y visibilidad preparada para auditorías, con el fin de ayudar a las organizaciones a verificar la capacidad de Recovery, demostrar el cumplimiento normativo y mejorar la Readiness para la Recovery.

Recursos relacionados

Video

Recuperación de Ciberataques: Cómo lograr una viabilidad mínima en minutos, no en días

Cuando se producen ciberataques, cada minuto cuesta 14 000 dólares y la Recovery total lleva una media de 24 días. Pero, ¿y si pudieras alcanzar la viabilidad mínima en cuestión de minutos en lugar de días?
Vea el vídeo sobreabout Recuperación de Ciberataques: Cómo lograr una viabilidad mínima en minutos, no en días
Solución

Commvault AirGap

Ciberprotección mejorada con almacenamiento inmutable en la nube y air-gapped.
Explora la solución Acerca deCommvault AirGap

Puntos Clave 

  • AI adoption is accelerating, helping make employees more efficient, productive, and competitive. 
  • Organizations need governance and guardrails to adopt AI responsibly and at scale. 
  • Security and productivity don’t have to compete – they can reinforce one another.  
  • AI will become one of security’s most valuable tools for managing cyber risks.  
  • AI adoption works best when innovation and security move together. 

One of the things I’ve enjoyed about the «Ready. Or Not».series is that each conversation builds on the last. We started by exploring the opportunities and risks of agentic AI. Then we looked at how organizations can build trust as AI becomes part of everyday business. This episode addresses the next logical question: How do we actually use AI safely? 

Comedian Nathan Macintosh sits down with Rinki Sethi, CISO and CSO at Upwind Security, for a conversation about what responsible AI adoption actually looks like. They cover everything from AI governance and guardrails to user experience and the growing role AI will play in cybersecurity.  

Nathan continues to ask the questions many of us are wondering. Should we be worried? How much more productive do we need to be? And can AI actually make security better?  

Mira el episodio completoen Readiverse. 

What I appreciated most about this conversation is that Rinki is genuinely excited about new technology and protecting it. She didn’t frame AI as something organizations need to worry about. Instead, she focused on encouraging businesses to move forward with confidence by putting the right guardrails in place. Here are the ideas that stayed with me. 

The push for AI adoption 

One thing that becomes clear from the conversation is that many organizations aren’t only encouraging their employees to adopt AI – they’re mandating it. These companies recognize that using AI helps people solve problems more efficiently, which is essential for staying competitive. 

“Every single company has a mandate … we’ve got to use AI everywhere in the company.”

– Rinki Sethi 

The question is no longer if AI belongs in the workplace, but do employees have the right guardrails to use it responsibly? As AI adoption accelerates, organizations need clear standards around which AI tools employees can use and how company data is protected. 

Sneak Peek: AI Governance

Rinki explains that governance isn’t just about protecting against new risks. It’s about creating a framework that helps employees use AI responsibly while keeping pace with evolving regulations and industry standards. 

The Hidden Benefit of Productivity 

Here’s something I never thought about before. Rinki explains that AI isn’t simply helping people work faster. In many cases, it’s leaving room for the highest-performing employees to excel.  

She used software developers as an example. When AI-powered coding assistants became available, many assumed they’d only help less experienced developers. Instead, some of the best engineers began using them to move faster. They were able to solve more complex problems and spend more time on creative work rather than repetitive tasks. 

That kind of productivity is exactly why organizations are mandating AI. It doesn’t limit what people can do – it helps give them more space to focus on higher-value work. 

“You can be way more creative with how you’re doing things … cause you’re creating the space for that.”

– Rinki Sethi 

AI’s Role in Cybersecurity 

“How can AI be used to help with security and not be just looked at as a demon thing that’s here to take us out?”

– Nathan Macintosh 

When we talk about AI and security, the conversation is often focused on risk. But Rinki believes that AI will become one of cybersecurity’s greatest advantages. 

Security teams are already overwhelmed by the volume of alerts, logs, and data they need to investigate every day. Human analysts simply can’t keep up. Rather than replacing security professionals, AI assists them by filtering through massive amounts of data in seconds. This helps analysts identify false positives so they can focus on investigating real threats. 

My takeaway is that the future of cybersecurity isn’t about people versus AI – it’s about people working alongside AI to help make better decisions, respond faster, and scale their operations in ways that weren’t possible before. 

Ready for What’s Next? 

Every episode of«Ready. Or Not». has reminded me that the biggest AI conversations are often about people – how we adapt, how we learn, and how we build the confidence to use new technology responsibly. The real opportunity for organizations isn’t just adopting AI. It’s creating an environment where employees can use AI to work smarter, become more creative, and deliver better outcomes for the business. 

Mira el episodio completoen Readiverse. 

Preguntas frecuentes 

Q: Why are organizations adopting AI so quickly? 
R:Many organizations see AI as a way to help improve productivity, increase efficiency, and give employees more time to spend on higher-value work. 
Q: What is AI governance? 
R:AI governance is the combination of policies, processes, and oversight that helps organizations adopt AI responsibly while managing security, privacy, and compliance risks. 
Q: Why is user experience important for security? 
R:Security controls that create unnecessary friction often encourage people to find workarounds. Designing secure systems that are also easy to use helps improve both adoption and protection. 
Q: Can AI help improve cybersecurity? 
R:AI can help security teams analyze large amounts of data, which helps reduce false positives. This in turn helps teams prioritize threats and respond more efficiently to security events. 
Q: Should people be afraid of AI? 
R: Rinki’s perspective is that a healthy sense of skepticism is valuable, but fear shouldn’t prevent organizations from adopting technology responsibly. Education, governance, and strong security practices can help organizations use AI with confidence. 
Q: What’s the biggest takeaway from this episode? 
R: AI adoption isn’t about choosing between innovation and security. Organizations that combine strong governance with practical security measures will be better positioned to take advantage of AI’s benefits while managing its risks. 

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Cómo Mythos y GPT-5.5-Cyber podrían cambiar la seguridad de los datos en la nube

Los modelos especializados de IA cibernética podrían acelerar la detección de vulnerabilidades y los flujos de trabajo de ataques en varias etapas. Más allá de la prevención, los equipos de seguridad de los datos en la nube necesitan mayor visibilidad, gobernanza y una Readiness sólida para la Recovery. 

Key Takeaways

Frontier cyber AI compresses the time between discovery and action, exposing why organizations need resilience-aware cloud data security built around clean recovery and ResOps. 

  • Claude Mythos and GPT-5.5-Cyber remain limited-access models, but they preview a future where AI can reason across complex cyber workflows and accelerate both defense and, potentially, attacker operations.
  • As the time between vulnerability discovery and exploitation shrinks, organizations need better visibility into cloud dependencies, identity risk, and interconnected attack paths before disruption occurs.
  • Recovery is no longer just about restoring backups. Organizations need to define their minimum viable company, validate trusted recovery points, and restore critical systems in the right sequence.
  • Resilience operations align security, IT, and business teams around measurable recovery outcomes, helping organizations govern data, prioritize recovery, and restore trusted operations with greater confidence.

 Claude Mythos and GPT-5.5-Cyber could affect cloud data security by speeding up how risks are discovered, tested, and acted on. Their impact is still uncertain, but they point to a need for stronger data visibility, access governance, and clean recovery across cloud environments. 

Claude Mythos and GPT-5.5-Cyber are giving security teams an early look at what more specialized cyber AI could mean for cloud data security. 

Neither model is widely available, and their long-term impact is still uncertain. But their existence matters because cloud environments are already difficult to defend. Sensitive data, identity systems, SaaS applications, development pipelines, AI workloads, and recovery infrastructure often depend on one another in ways that are hard to see until something goes wrong. 

The UK AI Security Institute’s April 2026 evaluation of Claude Mythos Preview found significant improvement on multi-step cyber-attack simulations, including the ability to execute multi-stage attacks on vulnerable networks when explicitly directed in a controlled environment.  

The same evaluation cautioned that its ranges differ from real-world environments and do not prove whether Mythos could attack well-defended systems. Still, it shows why cloud data security teams should pay attention to the direction of travel. 

As cyber AI capabilities mature, the question is not only whether attacks get faster. It’s whether the window between discovering a weakness and exploiting it continues to shrink. When that clock compresses, cloud data security is no longer just about preventing compromise. Instead, the question shifts to whether organizations can understand risk quickly enough, govern access consistently, and recover trusted operations before disruption spreads. 

Por qué son importantes Mythos y GPT-5.5-Cyber 

La importancia de Mythos y GPT-5.5-Cyber no radica en que todas las organizaciones vayan a tener acceso a ellos de repente. Según la información pública disponible actualmente, se trata de modelos controlados y de acceso limitado. Para los equipos de seguridad de datos en la nube, su importancia radica en lo que sugieren sobre la dirección que está tomando la IA cibernética: sistemas más especializados diseñados para dar soporte a flujos de trabajo de seguridad complejos. 

Esa distinción es importante. Un asistente de IA de uso general puede ayudar a resumir alertas o a redactar un informe de incidentes. Un modelo especializado de IA cibernética es diferente. Puede estar diseñado para analizar de forma integrada vulnerabilidades, infraestructura, vías de ataque, controles defensivos y pasos de validación. En entornos autorizados, eso podría ayudar a los equipos de seguridad a probar entornos, priorizar exposiciones y reforzar la planificación de Recovery antes de que se produzca un incidente. 

Para los equipos de seguridad de datos en la nube, el impacto práctico no radica tanto en los nombres de los modelos como en el flujo de trabajo que representan. El riesgo en la nube suele provenir de las conexiones entre sistemas: una carga de trabajo mal configurada, un conjunto de datos expuesto, una identidad con permisos excesivos, una dependencia de copias de seguridad o una ruta de recuperación no probada. La IA cibernética especializada podría facilitar una evaluación más rápida de esas relaciones, especialmente en entornos de gran tamaño donde la revisión manual puede pasar por alto cómo un problema afecta a otro. 

That shift mirrors a broader change happening across cybersecurity. The challenge is becoming less about identifying individual vulnerabilities and more about understanding how interconnected systems behave under pressure. AI may soon help defenders reason across identities, cloud workloads, backups, SaaS applications, AI pipelines, and business dependencies simultaneously — revealing not just isolated risks, but how those risks combine into operational failure. 

También cambia la forma en que las organizaciones deben plantearse sureadiness. Si la IA puede ayudar a los defensores a abordar tareas cibernéticas complejas de manera más eficiente, es posible que, con el tiempo, técnicas similares influyan también en los flujos de trabajo de los atacantes. La preocupación no es solo que los ataques se vuelvan más rápidos, sino que la brecha entre encontrar una vulnerabilidad, probarla y actuar en consecuencia podría reducirse. 

Cloud data security teams now have to plan for a harder question: what happens when the same types of AI-assisted workflows that help defenders validate risk also make weak points easier to find, test, and chain together? That’s where the cloud environment itself becomes the issue. 

AI Is Raising the Stakes for Cloud Data Security 

Most organizations don’t have one neat cloud environment. They have multiple clouds, SaaS platforms, data lakes, identity systems, development pipelines, backup repositories, and AI workloads that all depend on each other.  

That complexity already creates gaps: sensitive data can be overexposed, access permissions can drift, and recovery plans may not reflect how the business actually runs.  

In practice, those gaps rarely stay isolated. A storage bucket with sensitive data may not look urgent on its own. An over-permissive service account may look like a routine configuration issue. An untested recovery dependency may sit unnoticed because the system is still running. But when those issues connect, they can create a path from exposure to disruption. 

Attackers are well aware of these vulnerabilities. Mandiant’s2026 M-Trends reportnotes that ransomware operators are increasingly targeting backup infrastructure, identity services, and virtualization management planes. It also highlights how attackers are using long-lived OAuth tokens, session cookies, hard-coded keys, and personal access tokens to pivot across environments. 

Now add more capable cyber AI to the picture: If models can helpfind vulnerabilities faster, test exploitability more effectively, or connect weak signals across systems, defenders could benefit. However, attackers may eventually benefit, too—especially if similar capabilities become more accessible or are recreated elsewhere. 

22 seconds 
Median time between an initial access event and hand-off to a secondary threat group  

Source: Mandiant’s 2026 M-Trends report 

That’swhy the conversationcan’t stop at “AI makes attacks faster.” Frontier cyber AIchanges the tempo of security. As the time between discovery, validation, and exploitation compresses, every delay in understanding cloud dependencies or preparing recovery becomes more expensive. 

¿Cómo podría la IA cibernética de última generación cambiar la defensa en la nube? 

While the full impact of Mythos and GPT-5.5-Cyber is still unknown, they point to three practical shifts cloud data security teams should be watching. Each one comes back to the same issue: cloud data security now depends on how quickly organizations can understand risk, act on it, and recover when something goes wrong. 

Los defensores cibernéticos deben estar atentos a:

  • Rapidez:las herramientas asistidas por IA pueden ayudar a los defensores autorizados a revisar el código, clasificar las vulnerabilidades, analizar el malware, validar los parches y probar los controles más rápido de lo que permiten los flujos de trabajo tradicionales. 
  • Escala:el riesgo en la nube rara vez se limita a un solo lugar. Una vulnerabilidad en una aplicación, una identidad con permisos excesivos, un depósito de almacenamiento mal configurado y una ruta de Recovery no probada pueden convertirse en una cadena de ataque. 
  • Presión sobre la recuperación: If AI helps attackers move faster, organizations need to recover faster and cleaner. Backups alone aren’t enough if teams don’t know which data is clean, which identity systems can be trusted, or whether recovery will reintroduce compromised assets.

Para los defensores, el mayor cambio puede ser la forma en que se secuencia el trabajo. Hoy en día, muchos equipos pasan de la alerta a la investigación, de la corrección a la planificación de Recovery en pasos separados, a menudo entre equipos distintos. La IA cibernética podría comprimir ese flujo de trabajo ayudando a los equipos a pasar más rápidamente de una señal a un conjunto de acciones recomendadas para el siguiente paso. 

That doesn’t mean decisions should become automatic. It means teams may need clearer rules for when to trust a recommendation, when to escalate to a human reviewer, and when to move from investigation into recovery preparation. A model may help identify a possible attack path, but people still need to decide whether to close access, isolate a workload, preserve evidence, notify stakeholders, or prepare a clean recovery path. 

Aquí es donde el proceso cobra tanta importancia como las herramientas. La IA cibernética de última generación podría ayudar a los defensores a actuar con mayor rapidez, pero solo si los equipos cuentan con pasos de validación y planes de Recovery bien definidos. Sin esa estructura, la rapidez puede generar confusión. Con ella, los flujos de trabajo asistidos por IA podrían ayudar a los equipos a actuar antes, al tiempo que mantienen el control sobre cómo se evalúa el riesgo y cómo se toman las decisiones de Recovery. 

Por qué la Recovery limpia cobra mayor importancia a medida que los riesgos se aceleran 

When cloud risk moves faster, recovery planning has to become more precise. It’s not enough to know that backup copies exist. Teams need confidence that the data they restore is trustworthy, the recovery environment is isolated, and the systems coming back online won’t reintroduce the same threat that caused the disruption. 

Esto es importante porque los entornos en la nube estánmuy interconectados.Una identidad comprometida, un conjunto de datos dañado, una máquina virtual afectada o una carga de trabajo mal configurada pueden generar incertidumbre en múltiples servicios. Durante un incidente, es posible que los equipos tengan que determinar qué puntos de recuperación están limpios, qué dependencias deben restablecerse primero y si los datos restaurados pueden respaldar de forma segura las operaciones empresariales. 

Recovery limpia also changes the way teams think about priority. The goal isn’t necessarily restoring everything immediately. It’s restoring enough of the business to operate safely. 

Many organizations know which applications they consider “critical,” but far fewer have defined their minimum viable company: the smallest combination of identities, cloud services, data, applications, and infrastructure required to keep the business functioning during disruption. Those dependencies often become visible only when recovery is tested under realistic conditions. 

En un panorama de amenazas dominado por la IA, determinar la «empresa mínima viable» es crucial. Una detección más rápida de vulnerabilidades y un desarrollo más eficiente de las cadenas de ataque podrían ejercer mayor presión sobre los equipos de Recovery para que tomen decisiones con un alto grado de confianza en plazos muy ajustados. 

What’s more, identity systems, cloud configurations, business communications, customer-facing applications, and the data they depend on may all need to come back in a deliberate sequence — not simply according to technical priority, but according to what the business needs first to operate. 

Las organizaciones necesitan procesos de recuperación que ayuden a validar datos limpios, a llevar a cabo la recuperación de forma escalonada en entornos aislados, a proteger las dependencias críticas de identidad y a probar los planes de recuperación antes de que un incidente lo haga imprescindible. A medida que maduran las capacidades de la IA cibernética, los equipos de seguridad de datos en la nube deberían tratar la recuperación limpia como parte de la estrategia de seguridad, y no como un paso posterior a la acción. 

Desarrollar una seguridad de datos orientada a la resiliencia 

La seguridad de los datos en la nube se ha centrado a menudo en evitar la exposición: localizar datos confidenciales, clasificarlos, gestionar el acceso y reducir el riesgo. Esa labor sigue siendo importante. De hecho, cobra aún más relevancia a medida que los sistemas de IA consumen datos empresariales a través de indicaciones, sistemas de recuperación, procesos de entrenamiento, flujos de trabajo analíticos y apoyo automatizado a la toma de decisiones. 

That’s because data may move into new contexts without moving into a new system of record. A sensitive dataset might support a retrieval workflow, shape a model response, or appear in a prompt log. That makes governance less about one location and more about how data is accessed, reused, and recovered across workflows. 

Pero la prevención por sí sola no basta para la siguiente fase de la seguridad de los datos en la nube. Si la IA cibernética especializada puede ayudar a los equipos de seguridad a descubrir vulnerabilidades, probar vías de ataque y conectar señales débiles más rápidamente, entonces los programas de seguridad de datos deben tener en cuenta lo que ocurre después de que se detecte o se aproveche una exposición. La visibilidad y los controles de acceso son solo una parte del panorama. Los equipos también necesitan una vía clara hacia una Recovery fiable. 

Descubrir esa vía requiere algo más que mejores herramientas de seguridad. Requiere un modelo operativo de Recovery que alinee a los responsables de seguridad, TI y del negocio en torno a prioridades de Recovery compartidas antes de que se produzca un incidente. Cada vez más, las organizaciones describen esta disciplina como ResOps, u operaciones de resiliencia: un enfoque estructurado para hacer que la Recovery sea medible, repetible y vinculada a los resultados empresariales, en lugar de limitarse únicamente al éxito de las copias de seguridad. 

En ResOps, las organizaciones deben comprender: 

  • ¿Qué conjuntos de datos son los más críticos para las operaciones empresariales? 
  • ¿Qué identidades, servicios en la nube y flujos de trabajo de IA dependen de conjuntos de datos críticos para el negocio? 
  • ¿Están las políticas de gobernanza y acceso alineadas con el riesgo empresarial? 
  • ¿Cuál es el estado operativo mínimo viable que la organización debe restablecer en primer lugar? 
  • ¿Pueden validarse esas decisiones de Recovery antes de que se produzca un incidente, en lugar de durante el mismo? 

That’s the shift Mythos and GPT-5.5-Cyber point toward. The future of cloud data security won’t be defined by prevention alone. As cyber AI compresses the time between discovery and action, organizations will need equal confidence in how they recover. That means understanding cloud dependencies before an incident, defining the minimum viable business they need to restore, and treating recovery as an operational discipline rather than a technical afterthought. 

Mythos and GPT-5.5-Cyber matter not because every organization will use these models tomorrow, but because they reveal where cybersecurity is heading. As AI accelerates both defense and attack, the organizations that perform best won’t simply be the ones with the strongest preventive controls. They’ll be the ones that can prove they know what to recover, in what order, and how to restore trusted operations before uncertainty becomes business disruption. 

Preguntas frecuentes

When will these specialized models become public?

There’s no confirmed timeline for broad public access. Current reporting indicates Claude Mythos is being limited to select organizations through controlled programs, while OpenAI describes GPT-5.5-Cyber as available only to vetted defenders through its Trusted Access for Cyber framework.

Are AI attacks likely to increase?

Not necessarily. But they do show that advanced AI can support more complex cyber workflows, which means organizations should prepare for faster discovery, testing, and exploitation cycles.

Which risks should teams prioritize first?

Start with visibility into sensitive data, access paths, cloud misconfigurations, identity dependencies, and recovery readiness. Commvault’s Data & AI Security capabilities can help teams classify data, govern access, and identifyrisks across cloud environments. 

Why does recovery matter for cloud data security?

Because prevention can fail.Commvault cyber resilience capabilities can help organizationsidentifyclean recovery points,validaterecovery in isolated environments, and restore data and critical services without reintroducing compromised assets. 

Does Commvault offer AI-supported threat detection?

Yes. Commvault can use AI-enabled capabilities to help identify threats, detect anomalous activity, prioritize risk, and accelerate incident response. Combined with cyber resilience and recovery workflows, we can help teams improve response workflows and recover critical data with greater confidence.