Skip to content

This codification of privacy is transforming how businesses are expected to operate. There is no more question of what happens when a business doesn’t invest in a cyber program and who’s responsible. Let’s take a quick look at what will shape this year.

Normativa sobre privacidad en EE. UU.: la CCPA, el NYDFS y la SEC actualizan sus requisitos

CCPA may be amended. Currently the CCPA has an open request for comment on how audits fit with CCPA. In addition, we will start seeing rulings in cases around CCPA showing what we can expect for the reality of losses from not complying. For those who want to keep track with us, Perkins Coie has a great seguimiento.

NYDFS will likely be amended. Industry comments are under review. Once DFS makes its recommendations it will move through the legislation process. Notable takes:

    • “The CISO and the highest-ranking officer of the covered entities are both required to sign a certificate of compliance, and notice of compliance must be delivered annually to the NYDFS.” – Morgan Lewis.
    • Esto es más que una ley de protección de datos; abarca también la resiliencia empresarial y la seguridad de las operaciones.

The SEC wants their new rules in place ASAP. This includes provisions for Cyber Security reporting requirements alongside considering rules requiring adoption of standard practices. As with all federal rules, this one may take some time. Other provisions, notably around carbon footprint reporting, seem to be causing friction. We will see if the SEC makes their timeline.

$100 Million penalty for BIPA violations. In 2022, we saw cases relating to the Louisiana BIPA come to a close with significant penalties being doled out. The rubber is meeting the road, and liabilities are a reality. Read more at Data Protection Report.

Por qué los directivos deben dar prioridad a los conocimientos especializados en ciberseguridad

Con este fuerte impulso legislativo, las responsabilidades legales en el mundo real ya son una realidad. Los directivos ya no pueden ignorar los consejos de los equipos de seguridad. La realidad es que la mayoría de las empresas no están preparadas. Un breve extracto de Forbes lo ilustra a la perfección:

“Our analysis showed that only 51% of Fortune 100 companies have a director on their boards with relevant cybersecurity experience. The situation in the Fortune 200 and 500 is more concerning: only 9% have cyber-savvy directors. Worse still are the companies in the Russell 3000 smaller than those in the Fortune 500: only 8% have cyber directors. There is a total shortage of 2,724 directors with cybersecurity expertise across all Russell 3000 companies.” –Forbes

To be successful in filling these positions, security leaders will need to have an opinion on what’s changing from a legal perspective, how that impacts business strategy, and how the business creates opportunity in markets with changing regulations.

En resumen, los CISO deben formar parte de todas las conversaciones estratégicas a nivel directivo. Un CISO activo puede suponer, de hecho, una ventaja competitiva. Estos líderes activos comprenderán los datos de la empresa, sabrán cómo utilizarlos para obtener ventajas en el mercado y harán frente a los nuevos retos normativos. Las empresas que sean capaces de adelantarse a los cambios en el entorno normativo obtendrán una mayor rentabilidad. Las empresas que consideren el cumplimiento normativo como un mero trámite se quedarán atrás.

Adherence to compliance regulations is critical to your business’s operations, but it doesn’t have to consume an outsized portion of your resources. Let Clumio help automate compliance and simplify management while reducing your data protection costs. Contact us for a customized consultation.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The past year has been amazing – our data protection portfolio has won many accolades of technology leadership from industry analysts like Gartner, Forrester and GigaOm. These wins are no doubt driven by our relentless passion to protect our customers’ data in a difficult world and our fundamental belief that continuous customer collaboration is key to pragmatic innovation.

The next chapter of our 26-year journey of customer-driven innovation is now here – we are excited to announce the General Availability of Commvault Platform Release 2023! Commvault PR 2023 introduces several new features and additions to strengthen our customers’ security posture, deepen our rich integration with all major hyperscalers and introduce more smart savings through operational efficiencies.
Cientos de clientes ya se han beneficiado de estas nuevas capacidades durante la fase de vista previa tecnológica, que comenzó el 15 de diciembre de 2022.

Harnessing the power of multi-cloud

What differentiates our approach to the ecosystem – and yes, we continue to support the broadest ecosystem when it comes to data protection – is how our integrations are seamlessly built-in and not just clumsily bolted on for a quick mention. Deeper the integrations, greater the synergies enjoyed by our customers.

Commvault PR 2023 incorpora nuevas integraciones avanzadas para facilitar a nuestros clientes la protección de sus datos en Microsoft Azure, AWS Cloud, Google Cloud y Oracle Cloud Infrastructure.

Take, for instance, our new integration with Microsoft Azure Restore Points. We worked closely with Microsoft to be the first data protection platform to support Azure Restore Points. While Azure has had incremental snapshot capabilities, this new integration allows for application consistency across disks, while reducing costs with the option to use more cost-efficient storage tiers for backups. Commvault PR 2023 also introduces integration with Amazon FSx for NetApp which brings the same on-premises NetApp ONTAP policy-based protection to AWS. The new release also introduces support for Oracle Cloud Infrastructure (OCI) infrequent access & combined storage tiers to help reduce costs for protecting your cloud data.

Enhancing data security

Our trusted approach to data protection is shaped by the fundamental customer direction that data security is an integral and inseparable component of data protection. Building on our robust multi-layered ransomware detection, protection and recovery framework, Commvault PR 2023 introduces new integrations to drive data protection insights into the broader security ecosystem.

An important aspect of data protection is to leverage data awareness to proactively alert IT teams when threats arise. Commvault PR 2023 introduces a new Security Information and Event Management (SIEM) connector that makes it easy to feed alerts, events, and audit data to other platforms through webhooks APIs or even Syslog. Leveraging standard protocols ensures we can work with virtually any SIEM or event management system giving security teams better visibility to anomalies and threats in their data. 

Driving smart savings

With the uncertainty of a global recession looming, customers in every industry are looking to optimize costs in their budgets to make up for the increased spending for security and mission-critical areas. We are continuing to help provide options to lower the cost for data

Las nuevas funciones que permiten utilizar instantáneas de una sola región en lugar de instantáneas multirregionales en GCP pueden suponer un ahorro del 30 % en los costes de los recursos de copia de seguridad. A veces, reducir los costes es tan sencillo como acortar el tiempo que se tarda en proteger las aplicaciones.

Nuestras optimizaciones para Hadoop, que aprovechan snapdiff, permiten reducir a solo unos minutos los escaneos de copias de seguridad que antes duraban horas, gracias a las mejoras introducidas en la forma en que se buscan los bloques modificados.

These are just a few of the amazing features we have in Platform Release 2023. You can learn about more of the latest features in our What’s New page for Platform Releases. Conecta with our product management team and others in our comunidades for all the latest news and release information. 

Join us live on March 8th, 2023 at our Platform Release 2023 customer webinar.  Register here

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

El Día Internacional de las Mujeres y las Niñas en la Ciencia 2023 se celebra el sábado 11 de febrero y supone una oportunidad para promover el acceso y la participación plenos y en igualdad de condiciones de las mujeres en los ámbitos de la ciencia, la tecnología, la ingeniería y las matemáticas (STEM).

Nos hemos reunido con dos líderes extraordinarias e inspiradoras de Commvault, la directora técnica de campo, Vidya Shankaran, y la directora de experiencia de usuario, Parisa Bazl, para conocer sus opiniones sobre diversos temas, entre los que se incluyen:

  • ¿Por qué solo una minoría de mujeres opta por desarrollar su carrera profesional en el ámbito de las ciencias, la tecnología, la ingeniería y las matemáticas (STEM),
  • cómo la aportación de perspectivas diversas puede suponer una gran ventaja en sus puestos de trabajo y
  • qué consejos les darían a sus yo de 18 años.
  • Héroes personales

Why is marking the International Day of Women and Girls in Science important?

Vidya

Como madre de una hija que estudia en un instituto especializado en ciencias e ingeniería, soy consciente de lo importante que es sensibilizar sobre la necesidad de la igualdad de género y promover el empoderamiento y el avance de las mujeres y las niñas en los campos de la ciencia, la tecnología, la ingeniería y las matemáticas (STEM).

By celebrating this day, it serves as a constant reminder for all to work towards removing the barriers that prevent women and girls from participating – this helps foster a more inclusive and innovative scientific community and a better future for all.

Este día reconoce las importantes contribuciones de las mujeres y las niñas en estos ámbitos, y anima a más niñas y mujeres a seguir una carrera profesional en el ámbito de las ciencias, la tecnología, la ingeniería y las matemáticas (STEM).

Parisa

Celebrating this day is a way to remind ourselves of how far we’ve come and the distance we still need to go. While achieving gender equality in the STEM field is an uphill battle, our progress is evidence that it is possible and we will get there. This day is also a reminder of the benefits of having diversity in technology since so many critical, fun, and interesting things — from WiFi to dating apps – had their groundwork laid by women.

Why do you think women earn STEM degrees at half the rate of men – how can we help address this?

Vidya

Despite the fact that women have had a significant role to play in the progress of science and technology, they have not received the same levels of recognition as their male colleagues is an issue that transcends centuries. 

I would not necessarily to ascribe it to lack of female role models in STEM – there are many unsung “heroes” – but rather to the gender stereotypes and societal expectations that science is a “male” field. This manifests in the form of insufficient support for work-life balance that women and girls encounter compared to their male counterparts.

Thankfully, it is not irreparable or beyond redemption yet – there are many things we are already doing today and should continue doing and maybe even accelerate.

Es fundamental promover modelos femeninos a seguir en el ámbito de las ciencias, la tecnología, la ingeniería y las matemáticas (STEM) a través de la cobertura mediática y destacar los logros de las mujeres que han triunfado en el ámbito científico, ya que esto tiene el poder de animar a las niñas a interesarse por las ciencias desde una edad temprana.

Y lo que es más importante, es imprescindible que sigamos ofreciendo entornos propicios tanto en el ámbito educativo como en el laboral, como programas de tutoría y actividades de divulgación. Ofrecer condiciones laborales flexibles garantiza que las mujeres sigan motivadas para desarrollar sus carreras en el ámbito de las STEM. Por último, fomentar una cultura de diversidad e inclusión en las STEM, así como promover la equidad y la igualdad de oportunidades en la contratación, la promoción y la remuneración, es fundamental para mejorar la incorporación y la retención de mujeres y niñas en las carreras relacionadas con las STEM.

Parisa

Muchas mujeres crecen con la percepción errónea de que las disciplinas STEM son un ámbito que favorece las fortalezas estereotípicamente masculinas, y no siempre contamos con los sistemas de apoyo social adecuados para hacer frente a estos sentimientos de insuficiencia y falta de confianza. A menudo se equipara la tecnología con el software, pero se trata, en realidad, de personas. Al destacar los aspectos humanos de esta disciplina, podemos animar a más mujeres a darse cuenta de que sus experiencias, perspectivas y habilidades únicas serán una ventaja a la hora de cursar estudios y desarrollar carreras profesionales en el ámbito de las disciplinas STEM.

What can being a woman bring to your roles of field Chief Technology Officer (Vidya) and Director of User Experience (Parisa)

Vidya

In my role, which is technology evangelism with our customers and partners, in order deliver this role successfully, it requires empathy, emotional intelligence, respect for all cultures and obviously, understanding of technology. As a woman it does require a lot more effort and perseverance to get to and keep my “seat at the table”, but it is not without the support of all men and women around me.

También estoy observando un aumento en el número de hombres que actúan como aliados y que han desempeñado un papel fundamental a la hora de fomentar la aceptación, el ánimo y el apoyo hacia las mujeres en el ámbito de la tecnología. Estos hombres son, sin excepción, padres o hermanos de mujeres y niñas que se dedican a las disciplinas STEM, son conscientes de los retos a los que se enfrentan las mujeres y las niñas, y están encantados de aportar su granito de arena para eliminar esos obstáculos. Sin duda, se trata de un cambio en la dirección correcta.

Parisa

Working in a field where I’ve historically been at a disadvantage means that I’ve cultivated skills which not only help me navigate the field, but also do my job very well. I have had to pay attention to the smallest details, ask incisive questions, and listen extremely closely in order to best position myself for success. These are skills that make me a better advocate for users, since great UX is built on our ability to pay attention to what their users are saying in order to piece together the optimal solutions. In addition, being an outsider within the field of technology also makes me much more conscientious of inclusivity, and how everything from the way in which my team operates down to the interface that is designed needs to be intentional about creating equitable access and success.

What advice would you give to your 18-year-old self, moving into technology?

Vidya

Yo diría: «Ánimo, que las cosas mejoran».

But again, the kind of pressure we put on ourselves to deliver our best day after day, I would only say to take slow down and “smell the roses” – that we are not expected to know everything or have all the answers and it is okay to say, “I don’t know”.  After graduating with a degree in Chemical Engineering when I moved into Information technology, it felt like a personal failure, but I would tell me 18-yo self that it is okay to fail – “Failure” is a verb not a noun.

Parisa

A mi yo de 18 años, que nunca se planteó dedicarse a la tecnología, le aconsejaría que pensara en ella más allá de la mera ingeniería. Como he mencionado antes, la tecnología tiene mucho más que ver con las personas que con el software. Si nos centramos en nuestra capacidad para conectar con la gente y fomentar el entendimiento, eso nos hace mucho más valiosos y nuestro impacto es mucho más positivo.

Personal Heroes – Who do you admire?

Vidya

Siento un gran respeto por Indra Nooyi, antigua directora general de PepsiCo, y aprovecho cualquier oportunidad para aprender de sus experiencias.

Parisa

I’m a big fan of Barack Obama. He is someone who also had to navigate a system that was not predisposed to his success, and he leveraged his unique skillset, background, and point of view to inspire and connect with millions of people.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

It sometimes feels like we are living in the age of the reboot.  If you’re a fan of the hit TV show “That 70’s Show,” you know that it’s all about a group of friends navigating the challenges of adolescence in the 1970s and that it’s been rebooted (and updated to the 90s) on a popular streaming service. 

And it’s not alone.  From the good (Cobra Kai anyone?) to the not so popular (did anyone actually see the Knight Rider remake??) there is always an appetite for an update which reflects the current environment and challenges.

That sentiment can also be applied to your organization’s data management and protection strategy – to ensure it stays current and effective in an ever-changing world of emerging technologies and cyber threats.

Con el nuevo año y una nueva perspectiva, fíjate si alguna de las señales que se indican a continuación te resulta familiar. Si es así, puede que estés en el momento ideal para elaborar un plan que te permita renovar tu enfoque respecto a los datos en la era de la nube moderna:

  • Outdated & mismatched technologies: Just like the characters on the show were stuck in the 1970s, your data management and protection strategy may be relying on a “frakenstack” of mismatched and outdated technologies that sprawled organically but are now stuck in time and are no longer effective in today’s modern multi-cloud world. It’s important to regularly review and update your technology strategy to ensure that your approach to data growth and retention is not only purposeful and effective, but also provides you powerful protection and controls from the best tools available.
  • Uncertainty around shared responsibility obligations with Cloud Providers and SaaS Applications: If you don’t have a solid understanding of what your obligations are to protect your data under the shared responsibility model, you could end up losing days, weeks, or even months of valuable insights in the event of a disaster situation. In the show, the characters often found themselves in sticky situations that could have been avoided with proper situational awareness & planning. The same is true for your organization’s off-prem data.
  • Insufficient access controls: Whether resulting from innocent human error, or malicious bad actors, your data management and protection measures can often be wide open to catastrophic incident if users have too large a sandbox to play in. Our crew of misfits in “That 70’s Show” often found themselves in trouble due to a lack of boundaries and rules. The same is true for your organization’s data. With proper access controls in place, your data is more protected, your risk profiler is smaller, and you can rest easy knowing that it’s that much harder to have a major incident due to unauthorized individual actions.
  • Lack of employee & org leader education: Just like the characters on the show needed guidance and direction, your employees and cross-functional partners need to be educated on best practices for data protection. Without proper education, your organization is at risk of data breaches and other cybersecurity threats. Do all of your cross-functional partners (HR, Sales, Operations, Dev Ops, etc.) understand the implications and limitations of native SaaS applications and cloud services? Do they have a trusted partner in the IT function to ensure that their workloads are secure and backed up to cover any gaps in the service provider’s shared responsibility model while simultaneously providing upline leadership a single view of all of their distributed corporate data across all platforms and form-factors?

Si tu organización presenta alguno de estos indicios, es hora de plantearte actualizar tu estrategia de protección de datos.

Just like “That 70’s Show” has stood the test of time, a solid data protection strategy can help your organization stay current and protect its sensitive information. Don’t get stuck in the past – take action to ensure your data is safe and secure.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Zero trust architecture is central to an organization’s security posture to mitigate cyberattacks, and the Defense Department recently released its Zero Trust Strategy and Roadmap1 on its plan to get the DOD to a Zero Trust architecture by 2027.2

A zero trust architecture provides the foundations for micro-segmentation of the IT landscape, access limited with the Least Privilege principle, and all communication to and between the micro-segments being authenticated, audited, and verified3. The underlying philosophy for zero trust is never assume trust, but continuously validate trust, so bad actors don’t get in. Companies, organizations and government agencies need to make sure that even users inside a network can’t do serious damage.

Flag Unusual Behavior

Los principios de «cero confianza» garantizan que el acceso de los usuarios se valide y supervise de forma continua en lo que respecta a la autenticación y la autorización, al tiempo que se lleva a cabo una auditoría constante. Commvault aprovecha controles de seguridad como la autenticación multifactorial para las tareas administrativas cotidianas, los bloqueos de privacidad y el cifrado de datos. El acceso de los usuarios se puede compartimentar, denegando explícitamente el acceso a nivel de CommCell, al tiempo que se aplican roles a grupos de recursos microsegmentados mediante configuraciones multitenant. Los controles de «cero confianza» ayudan a limitar el movimiento lateral interno para evitar la pérdida de datos y el acceso no autorizado a los mismos.

Apply Zero Trust Controls

Commvault makes it simple to apply zero trust AAA controls by using thePanel de control de evaluación de la seguridad y la salud. The dashboard provides a single pane of glass for identifying controls, highlighting potential risks within the backup environment, and recommending interactive actions to apply controls.

Add Layers of Security

Para contribuir a reforzar la resiliencia de su infraestructura de datos, elMarco de Ciberseguridad del NISTse centra en cinco pilares fundamentales para un programa de ciberseguridad eficaz e integral. Prestar atención a estos pilares puede ayudar a su organización a desarrollar una estrategia global de gestión de riesgos. Commvault ha integrado estos pilares de seguridad en nuestro software y nuestras políticas de protección de datos sin que ello suponga una carga administrativa adicional. La plataforma de protección y gestión de datos de Commvault incluye cinco capas de seguridad:

Identificar

«Protección»

Supervisar

Responder

Recuperar

Nuestro sistema de seguridad multicapa se compone de conjuntos de funciones, directrices y prácticas recomendadas para gestionar los riesgos de ciberseguridad y garantizar que los datos estén siempre disponibles. Ayudamos a proteger y aislar sus datos, ofrecemos supervisión proactiva y alertas, y facilitamos restauraciones rápidas. Las tecnologías avanzadas basadas en la inteligencia artificial y el aprendizaje automático, incluidos los honeypots, permiten detectar y alertar de posibles ataques en el momento en que se producen, para que puedas responder con rapidez. Al mantener tus copias de seguridad a salvo y garantizar su restauración dentro de los plazos establecidos en tus acuerdos de nivel de servicio, puedes minimizar el impacto de un ataque de ransomware y reanudar tu actividad de inmediato (además de evitar el pago de costosos rescates).

Immutability

Protecting and isolating your backup copies is critical for data integrity and security. Therefore, we have taken an agnostic approach to immutability. With Commvault, you do not need special hardware or cloud storage accounts to lock backup data against ransomware threats. If you happen to have Write-Once, Read Many (WORM)-, object lock- or snapshot-supported hardware (which Commvault fully supports), you can still use Commvault’s built-in locking capabilities to complement and layer on top of existing security controls. Commvault’s ability to support layered defenses for securing data sets against ransomware ensures that your organization benefits from a sound cyber recovery-ready architecture. Here are some elements to include in your immutability architecture:

  •  Access locks to isolate copy store against ransomware
  • Inmutabilidad con bloqueos a lo largo del ciclo de vida para reducir los riesgos, equilibrando el impacto en el consumo
  • Red de aislamiento con espacio de aire y controles
  • Control de la configuración para protegerla frente a cambios intencionados o accidentales
  • Concurrent Recovery performance – reduce latency with due importance to speed and cost impact
  • Aplicación automática de parches para mantenerse al día, lo que simplifica la gestión y el mantenimiento de la infraestructura de protección de datos
  • Alignment with the 3-2-1 data protection philosophy  (3 copies of data, 2 different media, 1 vaulted copy)

Learn more about Commvault’s immutable infrastructure architecture aquí.

Cyber Deception Technology

Si bien garantizar la continuidad del negocio es un elemento fundamental de cualquier estrategia en múltiples niveles, una sólida postura de seguridad también incluye tecnología de defensa proactiva que detecta y combate de forma activa las amenazas desconocidas y de «día cero».Metallic® ThreatWiseTMsupone un punto de inflexión en la protección contra el ransomware, al combinar un sofisticado sistema de alerta temprana y actuación precoz con una protección integral de los datos. Permite a las empresas de cualquier tamaño neutralizar los ataques silenciosos antes de que causen daños, detectando y desviando los ataques de día cero más sigilosos, que eluden la tecnología de detección convencional y burlan los controles de seguridad.

A Ransomware Strategy

You need a plan to remain steadfast against ransomware. Beyond simply adhering to zero trust principles and hoping for the best, the ultimate solution can manage and substantially reduce the impact of a ransomware attack. It can reduce costs for your organization by utilizing one centralized management platform, so security teams don’t have multiple product points to log in and out of. It can increase the visibility of your data through a single landscape to minimize complexity for your teams. And finally, it can protect what matters most by providing the broadest workload coverage and rapid recovery capabilities through a unified approach. For all of this to happen, a solution must embrace Zero Loss Strategy.

Become Less Vulnerable

La realidad es que tu organización debe estar preparada y tomar medidas proactivas para proteger tus datos y colaborar con un proveedor que ofrezca soluciones de protección y Recovery frente al ransomware. ¿Estás preparado? Realiza nuestraevaluación de riesgos gratuitapara averiguarlo. Además, lee nuestroeBooktitulado «Comprender las funciones y responsabilidades del equipo en la lucha contra el ransomware».

References
1. Departamento de Defensa de EE. UU. (DOD), «El Departamento de Defensa publica su estrategia y hoja de ruta sobre el modelo Zero Trust», noviembre de 2022
. 2. C. Todd López, DOD News, «El DOD presenta una hoja de ruta hacia la ciberseguridad a través de la arquitectura Zero Trust», noviembre de 2022
3.Commvault, Vidya Shankaran, Ransomware Defense in Depth – Best Practices for Security and Backup Data Immutability, October 2021

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

I’m so proud to announce the inspiring Vaulters who just won our FY’23 Q3 CEO Living Our Values Awards. 

Here at Commvault, our four values – we connect, we inspire, we care, we deliver – are always top of mind! 

This week we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work as they live our values every day. 

I’m so proud to announce our FY’23 Q3 CEO Living Our Values Award winners:

Christina Manning
, directora de Operaciones Financieras

Mathew Ericson
director de producto

Jason Gerrard
, director de ingeniería de ventas

Parisa Bazl
, directora de Desarrollo de la Experiencia de Usuario (UX)

Sam Hernandez
, director de Gestión de Instalaciones


¡Todos estos ganadores son un ejemplo inspirador y encarnan lo que realmente significa ser un «Vaulter»!

To learn more about what it’s like to work at Commvault, check out our sitio de empleo.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

El reto que plantean hoy en día los registros de auditoría

One major challenge customers face with audit logs is that they’re not aggregated in a central location that is fully immutable. SaaS applications specifically tend to have their audit logs kept within the SaaS application itself, oftentimes with only a 90-day history.

Esto da lugar a scripts complejos o a la exportación periódica de los registros de cada aplicación para almacenarlos en una ubicación centralizada, con el fin de cumplir los objetivos corporativos en materia de cumplimiento normativo y seguridad.

This is a heavy lift on IT departments, and with hundreds of applications under management in any environment, it’s oftentimes not feasible to accomplish this completely. 

Consolidación de registros de auditoría con AWS CloudTrail Lake

Con el lanzamiento de CloudTrail Lake, AWS ha simplificado la gestión de los registros de auditoría procedentes de fuentes diversas. CloudTrail Lake es un lago de datos gestionado dedicado a la seguridad y la auditoría que permite a las organizaciones agregar, almacenar de forma inmutable y consultar los eventos registrados por AWS CloudTrail.

This can be done across different regions and accounts – and is backed by a 7-year default retention policy to help you meet compliance requirements.

Los clientes pueden importar y analizar eventos en un esquema compatible con AWS CloudTraildesde Clumio, así como desde otras fuentes de terceros y ajenas a AWS, para optimizar las auditorías, las investigaciones de seguridad y la resolución de problemas operativos.

Seguridad de datos más sencilla con Clumio y AWS CloudTrail Lake

AWS y Clumio se han asociado para ofrecer esta integración para CloudTrail Lake, que te permite simplificar y agilizar el proceso de consolidación de los datos de actividad.

Through the newly launchedPutAuditEvents API for AWS CloudTrail Lake, Clumio has created a simple integration to capture user activity information and events from your Clumio environment alongside the AWS systems you are protecting with Clumio.

Once the integration is enabled, you’ll be able to capture and store audit activity across various categories. This will allow you to easily answer many security and compliance-related questions across various categories such as:

  • Authentication– Was there a high volume of unsuccessful logins to the Clumio console, indicating a brute force entry attempt or an issue with your Single Sign On provider? 
  • User Management– When was a user added to the Development Organization in Clumio, and when were they given the backup Admin role?
  • Backups– When was a backup policy accidentally changed? This will help you quickly determine when a backup policy was changed or created to ensure you’re always meeting both long-term compliance requirements and maintaining any minimum required RPO’s (recovery point objectives).
  • Restores– Is someone browsing the CEO’s email history, or trying to recover Payroll information from a system backup? This activity is tracked even if a restore hasn’t been initiated.
  • S3 Protection Groups– When was a new S3 production bucket added to a protection group? Why was a bucket removed? 

Configuración y arquitectura de los registros de Clumio en AWS CloudTrail Lake

First, in Clumio, navigate directly to the Audit Report page. You’ll see a link to set up the integration in the upper right corner. You must have the Super Admin role to set up the integration.

Integración con AWS CloudTrail

En la siguiente pantalla, verás un ID externo exclusivo de tu integración con CloudTrail. Copia este valor y, a continuación, configuraremos directamente en AWS la siguiente parte de la integración.

After logging into the AWS Console, navigate to CloudTrail, where you will find a new Integrations section under Lake.Click on the Add Integration button to configure the Clumio integration.

You’ll first need to give a name to channel that Clumio will use to send the audit logs data through, and then selectClumioas the source.

Next, we will need a place to deliver the Clumio audit logs and determine how long you would like to get the logs. You can either use an existing event data store or create a new one for this integration.

Next, we’ll configure the resource policy which is what will provide Clumio with a secure way to send the audit log data across the channel. This is where we will paste in the external ID we copied from the Clumio interface.

Lastly, apply any tags you may want to add to the resource and select Add Integration.

The integration is now set up; however, we have one final step. We need to copy the Channel ARN value and bring it back to Clumio, so we can complete the setup.

Once you add the Channel ARN value, click on Connect to CloudTrail

Se enviará un evento inicial al almacén de datos de eventos de CloudTrail Lake, lo que te permitirá comprobar la conectividad. A partir de ahí, tus eventos de auditoría de Clumio se enviarán periódicamente al almacén de datos de CloudTrail Lake.

Additionally, you’ll be able to monitor the health of the integration at any time through the Audit Log report.

A continuación se muestra una lista de todas las categorías de eventos de auditoría que se envían a CloudTrail como parte de esta integración:

  • Autenticación
  • Fuente de datos
  • Las políticas
  • Protección S3
  • Restaurar
  • Backup
  • Usuarios
  • Unidad organizativa
  • Configuración de KMS
  • SSO/MFA
  • Plantilla de CloudFormation

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In the handful of months since I became Commvault’s first Chief Partner Officer, I’ve been reading the terrain, talking with our partners, and figuring out how we can better help them in the year to come. I’ve analyzed everything from program incentives to partner enablement and everything in between to plot our course. There is, however, one thing I didn’t consider. The intangible effect of being one of the coolest kids on the block.

For the 7th year in a row, Commvault has been named to CRN’s annual Cloud 100 list! Honoring the 100 Coolest Cloud Companies for 2023 across five key categories: infrastructure, monitoring and management, storage, software, and security, we rated among the Top 20 in the storage category based on CRN’s analysis.

To make the list, which is considered by most in the partner world as the trusted resource for solution providers looking for technology vendors best positioned to support their cloud product and services needs, Commvault had to prove its commitment to channel partners as well as demonstrate our innovation in the development of cloud-based technologies.

This wasn’t difficult for Commvault, as we’re a leader in data management, protecting data wherever it lives – whether on-prem, in the cloud, or in a hybrid cloud environment. We support the broadest range of workloads in the industry and most recently hemos ampliado nuestra protección en la nube para Kubernetes, lo que nos ha posicionado como «Outperformer» y «Líder» enGigaOm’s Radar for Kubernetes Data Protection.

“In today’s remote-facing enterprise environment, cloud services have become the critical component needed to build comprehensive and secure IT solutions,” said Blaine Raddon, CEO, The Channel Company. “The companies selected for this year’s Cloud 100 list have shown time and again that they support partners in the ever-evolving cloud computing business with state-of-the-art products and services. Our team commends those on this year’s list and looks forward to watching them drive positive change in the cloud domain throughout the year.”

CRN’s Cloud 100 list will be featured in the February 2023 issue of CRN magazine and online at www.crn.com/cloud100.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

La Semana de la Privacidad de los Datos es un evento anual cuyo objetivo es sensibilizar sobre la importancia de la privacidad y la seguridad de los datos. El objetivo de la Semana de la Privacidad de los Datos es concienciar a las personas y a las organizaciones sobre la importancia de proteger los datos personales y proporcionarles las herramientas y los recursos que necesitan para hacerlo de forma eficaz.

We’ve brought together three opinion leaders to discuss the key data privacy challenges that face businesses around the world and how to overcome them.

Bill Mew, Data Privacy Champion and CEO of the Crisis Team is joined by Jakub Lewandowski – Global Data Governance Officer, Commvault and Thomas Bryant – Product Marketing Director, Commvault as they discuss;

  • Tendencias y retos actuales en materia de privacidad y seguridad de los datos
  • Leyes y normativas relacionadas con la privacidad de los datos, como el Reglamento General de Protección de Datos (RGPD) de la Unión Europea y la Ley de Privacidad del Consumidor de California (CCPA) de Estados Unidos, así como la DORA y la NIS2
  • Best Practices for protecting data – including a modern (and tested) data protection strategy and conducting regular risk assessments
  • The current state of Data Privacy policy and legislation compliance/ enforcement  

Descubre más sobre estos temas en nuestra serie de entradas de blog sobre la Semana de la Privacidad de los Datos, ya disponible.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

El Día Mundial de la Privacidad, que se celebra cada año el 28 de enero, sirve para recordar la importancia de proteger los datos personales en la era digital actual. A medida que avanza la tecnología y se comparte cada vez más información personal en Internet, tanto las personas como las organizaciones deben tomar medidas para proteger sus datos.

New regulations, such as DORA (Digital Operational Resiliency ACT), mandate that organizations create plans for risk management, incident reporting, and resilience testing. These regulations outline policies for data management, including encryption, data locality, and data lifecycles. Gartner prevé, “by 2023, 65% of the world’s population will have its personal data covered under various privacy regulations, and companies need flexible solutions that can adapt to the multitude of legislation.” Navigating this complex environment can be challenging for both individuals and companies.

Data Privacy is protecting personal information and giving individuals control over how their data is collected, used, and stored.  On the other hand, data protection refers to the technical and organizational measures put in place to protect data (including personal data) from unauthorized access, use, alteration, or destruction. Data protection encompasses Data Privacy and other areas, including backup & recovery, disaster recovery, data security, and a host of other areas.

To help address that complexity, let’s spend some time reviewing the Top 10 topics to consider when managing Data Privacy and Data Protection.


1.Data Protection Strategy
2.Cifrado
3.Multi-Person Authentication
4.Almacenamiento inmutable
5.Soberanía de los datos
6.Data Governance & Discovery
7.Classification of data
8.Conservación de datos
9.Resilience plan testing & incident response
10.Risk Assessment

1. Data Protection Strategy

Organizations should start by creating or updating a Data Privacy, Backup & Recovery, and Disaster Recovery plan as part of an overall data protection strategy. There are many facets to a reliable data protection plan and how it specifically relates to protecting the private data your customers have shared with your organization.

2. Encryption

El cifrado es una característica fundamental para la protección de datos y la protección de la información privada. Permitir el cifrado de los datos en reposo y en tránsito ayuda a evitar el acceso no autorizado a la información personal. Esto es especialmente importante para las organizaciones que gestionan grandes cantidades de datos privados, como los proveedores de asistencia sanitaria y las entidades financieras. Los datos ya no residen únicamente en nuestros centros de datos corporativos, ya que la mayoría de las organizaciones cuentan con una o varias nubes públicas en las que se almacenan cargas de trabajo y datos. Proteger los datos mediante cifrado durante todo su ciclo de vida ayuda a mitigar las posibles amenazas de los atacantes.

3. Multi-person authentication

Además de proteger los datos mediante cifrado, las organizaciones deben proteger sus sistemas frente a ataques maliciosos. El uso de la autenticación multipersona (MPA) en los sistemas de protección de datos garantiza que las tareas críticas requieran varias aprobaciones por parte de usuarios previamente autorizados. Aunque a menudo se pasa por alto, esta es una de las formas más sencillas de evitar tareas como la filtración o la eliminación de datos.

4. Immutable Storage

El almacenamiento inmutable permite que los datos, ya sean privados o de otro tipo, se escriban y no puedan modificarse ni eliminarse posteriormente. El hecho de que los datos no puedan ser manipulados ni alterados garantiza el mantenimiento de la integridad de los mismos. Los requisitos de almacenamiento inmutable se están convirtiendo rápidamente en un elemento estándar de las normativas de gobernanza de datos, como el RGPD, la HIPAA y otras. Al combinarlo con la MPA, se pueden crear niveles de almacenamiento de datos de alta seguridad que resultan perfectos para almacenar datos confidenciales y privados.

5. Data Sovereignty

Organizations should consider regulations surrounding private data storage when developing a data protection strategy. This includes the location of data storage and compliance with regulations regarding data sovereignty. For example, a cloud-based workload on GCP in Europe or containing EU citizens’ data must comply with EU regulations. Anywhere that private data may reside, even if temporary, may be required to be in a specific region under regulatory requirements. Commvault helps to address this concern in its latest release, allowing customers to select which specific region they will leverage for snapshot & data protection storage vs. multiple regions that cost more and may have different regulatory requirements.

6. Data Governance & Discovery

In a recent survey, el 57 % de los CISO admit they don’t know where some or all their data is or how it is protected! As this amount of private data continues to grow, the sheer number of regulations expands exponentially, and we are confused about what and how we should protect our data.  As a result, organizations need to understand their data, where it is, and what is at risk.  Being able to prioritize data based on your organization’s policies, priorities, and applicable regulations is critical to protecting the data. You cannot protect what you don’t know about!

7. Classification of data

Saber qué datos existen y dónde se encuentran es solo una parte de la solución. Las organizaciones deben tener en cuenta qué datos son datos privados de los clientes, cuáles son críticos para el negocio, etc., en función de su importancia para tu empresa y tus clientes. Proteger únicamente los datos locales puede suponer pasar por alto algunos datos críticos de los clientes que se encuentran en su solución de CRM basada en SaaS. Hablando de ello, debe confiar en algo más que en su proveedor de SaaS o incluso en sus proveedores de nube IaaS para garantizar la protección de sus datos. Es posible que ofrezcan algunos acuerdos de nivel de servicio (SLA) y un cierto nivel de redundancia, pero eso no sustituye a un plan sólido de protección de datos. La gestión de la clasificación de datos no es una operación puntual, ya que los datos crecen exponencialmente cada año.

8. Retention

It is paramount to know what data exists and how important it is, but how long does it stay relevant? This is a hard question to answer for most organizations and one that can be seen every year when buying ever-increasing storage systems to house corporate data. The ability to assign an expected lifespan to data can significantly impact your organization’s bottom line AND protect your customers’ private data. Having systems in place to automatically find, classify, and set retention will reduce the likelihood of data sprawl, reduce the amount of time to recover unused data, and reduce costs. If you are looking for a great place to start efficiently managing your governance, risk, and compliance, read through Commvault’s unique approach to la gestión unificada de datos.

9. Resilience plan testing & incident response

Resilience plan testing often referred to as a runbook, is an often-overlooked area of a data protection strategy. Creating or updating an outdated plan can take time and effort. Partnering with solution providers or strategic data protection companies with experience in creating a plan can significantly reduce the time it takes to get current. While it may be trivial to think runbooks are passe, I’ve found that when an actual DR event or ransomware attack hits, they are the GO-TO asset you want in your arsenal of tools. A regular cadence of updates creates an organizational posture that is ready to face data security threats head-on.

10.  Risk Assessment

As mentioned with runbook, consider working with strategic vendors to perform a risk assessment semi-annually or annually. Scheduled reviews can help build the muscle memory for a solid data protection and data privacy mindset. The benefit of working with well establish data protection & data privacy vendors is they are up to date on the latest security threats and mitigation strategies.

By implementing this list of considerations and routinely refreshing your resilience plan, you can be confident that personal information is secure and compliant with the latest privacy regulations. If you aren’t sure where to start but need help from a company that can answer all these questions.

¡Commvault está aquí para ayudarte! Incorporamos continuamente nuevas funcionalidades, entre las que se incluyen nuestras últimas mejoras en materia de soberanía de datos regional para instantáneas de copia de seguridad, certificaciones del sector, capacidades de almacenamiento inmutable y mucho más.

Head over to our community to Saber más or take a test drive today https://www.commvault.com/request-demo

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Happy 2023 Data Privacy Week!

Just as everyone started to get more or less cozy with the regulatory landscape in data privacy/protection and individuals and businesses learned to navigate the shallow waters of data subject requests, risk management, and impact assessments – BOOM – another tidal wave of regulatory requirements and new challenges rushed in!

2023 is the perfect moment to start internalizing new acronyms (get ready for #NIS2, #DORA, #DPDPB, #CPRA, #CCPA, #CPA, #CDPA, #UCPA, #VCDPA, #ADPPA, #PrivacyPenaltyBill) and legislative acts they stand for.

El objetivo fundamental de los próximos cambios es impulsar y mejorar las medidas de ciberseguridad de diversas organizaciones, así como gestionar de forma más eficaz los riesgos cibernéticos en constante evolución.

A continuación se ofrece una visión general de una selección de novedades jurídicas en todo el mundo:

  • EU – Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2)
  • EU – Regulation on digital operational resilience for the financial sector (DORA)
  • US – State & Federal privacy laws
  • India – Digital Personal Data Protection Bill (DPDPB)
  • Australia – Privacy Penalty Bill & overhaul of the Privacy Act 1988

NIS2

According to ENISA, the general spending on cybersecurity is 41 % lower by organisations in the EU than by their US counterparts. With the arrival of NIS2, this ratio is expected to shift to cover this enormous gap at least partially. Conservative estimates are that NIS2 entry in force will translate into a ~22% increase in ICT spending over a 3–4-year period.

La NIS2 se publicó justo antes de que finalizara el año, y los Estados miembros de la UE disponen ahora de 21 meses para transponer a sus legislaciones nacionales los requisitos y mecanismos descritos. La Directiva NIS de 2016 —a pesar de sus deficiencias— sirvió de piedra angular para aumentar las capacidades de ciberseguridad de los Estados miembros. Ahora, la NIS 2 ampliará el ámbito de aplicación y la lista de organizaciones afectadas. Se prevé que hasta 160 000 organizaciones queden sujetas a esta nueva legislación, entre ellas los proveedores de servicios digitales (plataformas y servicios de centros de datos), los proveedores de redes y servicios de comunicaciones electrónicas, así como los sectores manufacturero, alimentario y el sector público.


NIS2 aims to strengthen cybersecurity postures by, amongst other: improving cybersecurity governance, addressing the security of supply chains, streamlining reporting obligations (early warnings/shortened notification periods), and introducing more stringent supervisory measures and stricter enforcement requirements.

¿Qué puedes hacer ahora mismo?

  • First, try to understand which obligations will apply to your organization and in which compliance bucket your organization will fall into: “Essential Entity,” “Important Entity,” or maybe “other.”
  • A continuación, comprueba si puedes crear sinergias y aprovechar las medidas técnicas y organizativas ya implantadas durante iniciativas de cumplimiento anteriores (por ejemplo, el RGPD, la Directiva NIS1, etc.).
  • Empieza a buscar los socios adecuados que puedan respaldar adecuadamente tus iniciativas de cumplimiento normativo. Involucra a tus proveedores en el debate sobre el enfoque que mejor se adapte a tu organización.
  • Por último, pero no por ello menos importante, empieza a planificar un aumento del gasto para subsanar cualquier deficiencia restante. El incumplimiento de la normativa podría acarrear multas administrativas de hasta 10 millones de euros o de hasta el 2 % de la facturación anual total a nivel mundial de la organización.


DORA

DORA aims to achieve “a high common level of digital operational resilience,” mitigating cyber threats and ensuring resilient operations across the EU financial sector. It will become directly applicable from Jan 17th, 2025. It will impact the financial sector (banks, insurance companies, investment firms) and its ICT providers (i.e., cloud platforms) – roughly around 22 000 organizations.

Los nuevos requisitos impuestos por la DORA se traducirán, en la práctica, en una revisión y actualización de las prácticas de gestión de riesgos. Los clientes del sector financiero deberán transferir el mayor número posible de riesgos normativos a los proveedores de TIC o aplicar diferentes estrategias de mitigación de riesgos. En cualquier caso, los proveedores de TIC deberán poder garantizar el cumplimiento de los requisitos de la DORA. Además, todo el sector deberá reevaluar las relaciones contractuales con los proveedores. La DORA incorporará requisitos para los contratos entre las entidades financieras y sus proveedores de TIC críticos, incluyendo la ubicación donde se procesan los datos, las descripciones de los acuerdos de nivel de servicio, los requisitos de información, los derechos de acceso y las circunstancias que darían lugar a la rescisión del contrato.

In a separate post – Commvault’s Product Team will perform a more technical deep-dive into DORA’s requirements related to detection (art. 10), response and recovery (art. 11), and backup (art. 12).


US data privacy laws – CPRA/CCPA, CPA, CDPA, UCPA, VCDPA, ADPPA

As of January 1st, 2023, California Privacy Rights Act (CPRA) amendments to the California Consumer Privacy Act 2018 went into effect. Many temporary exemptions in place expire, imposing additional obligations on companies dealing with California residents’ personal information, e.g., regarding employment-related personal data, opt-out from selling personal information.

2023 is also the year when the Colorado Privacy Act (CPA), The Connecticut Data Privacy Act (CDPA), The Utah Consumer Privacy Act (UCPA), and The Virginia Consumer Data Privacy Act (VCDPA) will become effective. Legislative fragmentation risk is imminent and substantial, and this is the kind of risk that caused the European Union to harmonize the regulatory approach. Let us see whether the same will be true in 2023 in the case of the American Data Privacy and Protection Act (‘ADPPA’) – a proposal for a federal and general data privacy law.

India – DPDPB

Indian legislators plan to introduce a very ambitious Digital Personal Data Protection Bill (DPDPB) this year. When enacted, long-awaited legislation will undoubtedly impact all kinds of organizations due to India’s role as a tech powerhouse and a global outsourcing hub.

Australia – Privacy Penalty Bill & overhaul of the Privacy Act

Australian authorities announced yet another complete overhaul of the Privacy Act dated 1988. The current legislation was summarized as “out of date and not fit for purpose in the digital age.”

Mientras tanto, todavía en 2022, Australia aprobó la Ley de Sanciones en materia de Privacidad, que aumentó las sanciones relacionadas con la privacidad hasta niveles comparables a los establecidos por el RGPD (hasta 50 millones de AUD) y amplió las competencias reguladoras de la Oficina del Comisionado de Información de Australia (OAIC) y de la Autoridad Australiana de Comunicaciones y Medios de Comunicación (ACMA).

Summary

El implacable reloj del cumplimiento normativo acaba de volver a ponerse en marcha. Los equipos multifuncionales, formados por profesionales de TI, cumplimiento normativo, protección de datos, el ámbito jurídico y analistas de negocio, dedicarán una cantidad considerable de tiempo a analizar el impacto de la avalancha de novedades legislativas que surgieron a finales del año pasado y que se materializarán a lo largo de 2023.

Ten en cuenta que los avances legislativos que aquí se presentan podrían ser más exhaustivos. No obstante, puedes estar seguro de que se convertirán en temas de debate habituales no solo en 2023, sino también en los próximos años.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Como parte de una serie de tres artículos con motivo del Día de la Protección de Datos de 2023 (véanse los artículos adjuntos deJakub LewandowskiyThomas Bryant ), Bill Mew argues that there is a real enforcement problem – it’s like the ‘Wild West’ out there.

Las políticas, los marcos normativos y las normas solo resultan útiles si se cumplen, del mismo modo que las normativas y las leyes carecen de sentido si no se hacen cumplir. El problema en el ámbito de la protección de datos y la ciberseguridad es que, allí donde deberían aplicarse las normas, a menudo se ignoran, y allí donde se han promulgado leyes, es necesario reforzar su cumplimiento.

Los CISO (directores de seguridad de la información) tienen una tarea ingrata. El personal suele mostrarse reacio a cumplir las medidas de ciberhigiene que el CISO intenta imponer, pero cuando su falta de disciplina da lugar a una filtración, estos compañeros se apresuran a echarle la culpa al CISO. Además, aunque hay que cumplir normativas costosas y complejas, así como normas estrictas sobre la notificación de filtraciones, las autoridades, lejos de ayudar a gestionar cualquier incidente o a capturar a los verdaderos delincuentes, se limitan a utilizar los informes para determinar la imposición de multas.

Functional, Cultural Mismatch

Si se les preguntara, la mayoría de los empleados estarían de acuerdo en que las amenazas cibernéticas son un problema importante, pero en su trabajo diario se centran en indicadores de rendimiento centrados en los ingresos o en el beneficio, como el ROI (retorno de la inversión). Estos son los indicadores con los que se mide su rendimiento individual y el de su unidad, y en los que se basan las políticas de incentivos de toda la empresa.

The CISO is instead focused on return on risk (ROR). Based on the allocated budget and the organisation’s risk appetite, the CISO focuses on maximising security and minimising risk.

The mismatch between the CISO’s ROR orientation and just about everyone else’s ROI orientation can put the CISO at odds with the rest of the management team. They may not only become isolated (what I term CISOlation) but can also be a scapegoat when things go wrong – even when warnings are ignored.

Perverse regulatory incentives

In an accompanying article, Jakub Lewandowski [LINK] has explored the raft of new privacy and cybersecurity laws expected to add to a considerable regulatory burden. The problem is that una normativa sin aplicación no solo carece de sentido, sino que resulta contraproducente. Al fin y al cabo, solo las empresas responsables cumplirán estas normas y, para ellas, esto supone un coste o un «impuesto de cumplimiento». Por su parte, las empresas irresponsables suelen optar por no respetar las normas. Si creen que el riesgo de que se apliquen las sanciones es escaso o nulo, esto se convierte en una fuente de ventaja competitiva que les permite ahorrar costes y está libre de riesgos.

El incumplimiento de la normativa está muy extendido y proviene de las altas esferas, como demuestran los frecuentes titulares sobre incidentes relacionados con los datos que sufren las grandes empresas tecnológicas o las multas que se les imponen. Dichas multas no parecen surtir efecto disuasorio, sino que las grandes empresas tecnológicas y muchas otras que han tenido la mala suerte de sufrir un incidente relacionado con los datos las consideran un coste adicional de su actividad empresarial.

Again, responsible firms that did their best to take reasonable measures but were unfortunately unable to prevent mistakes or attacks run the risk of being fined once they notify the local regulator. Meanwhile, irresponsible ones who choose not to comply will simply avoid reporting incidents and attempt to cover them up instead to avoid fines. Fines have, therefore, become more of a indicador rezagado de la mala suerte de las empresas responsables rather than of misbehaviour by irresponsible ones.

Record of Regulatory Inaction

Most BigTech firms, attracted by a favourable tax regime, have opted to base their European headquarters in Ireland. The local regulator, DPC Ireland, is therefore responsible for ensuring that they comply with GDPR and other such regulations. Whether down to inadequate funding, reluctance to rock the boat, or simply out-gunned and out-lobbied by the BigTech firms, DPC Ireland has been seen as ineffective in holding them to account.

In one notable case, measures it failed to take against Facebook were eventually resolved in the European High Court under the Schrems I and Schrems II rulings. When it still failed to take action and apply these rulings, DPC Ireland was sanctioned by the European Parliament in a votación de 451 a 1. Cuando nuevas presiones por parte de los reguladores del resto de Europa la obligaron a actuar tras un retraso de dos años, la multa que impuso a Facebook fue tan baja que tuvo que ser incrementada (diez veces) ante la insistencia de los demás reguladores.

The EU Ombudsman Emily O’Reilly eventually abriendo una investigación into the European Commission’s monitoring of how data protection rules are applied in Ireland. Eight months later, the Consejo Irlandés de Libertades Civiles (ICCL) criticó a la UE for its continued failure to properly monitor Ireland’s GDPR enforcement while “the fundamental rights of all Europeans hang in the balance.” There are now moves afoot to strip Ireland of its responsibility for regulating the BigTech firms and centralise such enforcement instead.

Ineffective Global Policing

Meanwhile, the number and sophistication of cyber-attacks are increasing exponentially, as is the cost of remediation. The World Economic Forum (WEF) has recently not only called for more widespread use of cybersecurity ‘fire drills’ to test cybersecurity and incident response capabilities but is also championing the need for global rules to crack down on cybercrime.

Se estima que los daños causados por todas las formas de ciberdelincuencia, incluidos los costes de Recovery y reparación, ascendieron a 3 billones de dólares en 2015 y a 6 billones de dólares en 2021, y podrían alcanzar los 10,5 billones de dólares anuales para 2025.

Cyber insurance isn’t the answer. Rapidly increasing premiums mean that it is out of reach to most buyers, but even those who can afford it often find it’s not worth it. At the same time, cyber insurance cannot be expected to cover systemic problems, and in any case, it has the perverse effect of potentially making bad problems even worse.

While almost all nations have signed up for United Nations agreements on combatting crime, including la ciberdelincuencia, some nations turn a blind eye and instead provide safe havens for cybercriminals to operate from. While most la ciberdelincuencia originates from countries like Russia, Iran, or North Korea, such activities are not confined to these rogue nations and continue closer to home. In addition, countries like China have significant espionage operations, and the United States is responsible for a great deal of global mass surveillance – all of which contravenes GDPR and a host of other laws.

We need to start with mandatory data breaches and cyber theft reporting. This has begun in the US with 2022’s Cyber Incident Reporting for Critical Infrastructure Act and in the EU with 2018’s Directive on Security Network and Information Systems. Still, there are also a host of other regulations that mandate telecom payment services, medical device manufacturers, and critical infrastructure providers to report breaches.

Once we have better data on the problem, we can focus on improving international investigation, prosecution, and adjudication efficiency and effectiveness. The Oficina de las Naciones Unidas contra la Droga y el Delito is promoting a Cybercrime Programme which has the following aims:

  • Mayor eficiencia y eficacia en la investigación, el enjuiciamiento y la resolución judicial de los delitos informáticos, especialmente la explotación y el abuso sexual de menores en Internet, dentro de un marco sólido de derechos humanos.
  • Una respuesta eficiente y eficaz a largo plazo por parte de todo el Gobierno frente a la ciberdelincuencia, que incluya la coordinación nacional, la recopilación de datos y marcos jurídicos eficaces, y que conduzca a una respuesta sostenible y a una mayor disuasión.
  • Se ha reforzado la comunicación a nivel nacional e internacional entre el Gobierno, las fuerzas del orden y el sector privado, al tiempo que se ha incrementado la concienciación de la ciudadanía sobre los riesgos de la ciberdelincuencia.

These are laudable goals. However, we are a long way from victims of crime being able to pick up the phone to police at the local, national, or international level with any expectation of getting either practical assistance or justice. The reality is that when it comes to cybercrime, aside from private sector incident response specialists, you’re on your own.

  • El personal rara vez aplica las medidas de higiene cibernética de forma adecuada
  • Las autoridades reguladoras no actúan de forma proactiva a la hora de detectar y combatir los incumplimientos.
  • Los delincuentes están ganando en confianza, intensidad y sofisticación.
  • La policía no puede actuar contra los delincuentes que operan desde refugios seguros
  • Y los CISO son el chivo expiatorio por defecto cuando las cosas salen mal

In this ‘Wild West’ environment, there isn’t any cavalry going to the rescue, so you are expected to be adequately armed and ready to defend yourself. Take hints from Thomas Bryant’s article and learn how to deal with it best. There is no substitute for getting your cybersecurity and incident response right.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

As part of our “Get to know your customers day” series, we’re taking a deeper look at Swinerton Inc, a large national construction company who is pursuing a cloud data management program to drive versatility, sustainability and to free up company resources.

IT Manager, Brandon Marrott gives an insight into Swinerton’s data modernization journey which includes cloud transformation and embracing SaaS flexibility.  He also describes operating a hybrid cloud environment through the need to retain a number of company data assets on prem and how Swinerton manages their entire data estate, including SaaS, with Commvault.

https://play.vidyard.com/U5fZTkcgxdb7v9we3WJghp

What does it mean to go to the cloud?

Selecting the right cloud transformation partner

https://play.vidyard.com/oUYbtkBhyzYRoVibhsaWGm
https://play.vidyard.com/zwLtwiwBcsPG15DN2u5L8L

Superar retos y gestionar con flexibilidad un conjunto de datos SaaS en crecimiento


Faced with increased pressures, including an uncertain economic environment, IT teams are constantly finding ways to reduce costs or increase overall efficiency – all while supporting an evolving data environment.

Descubre más ejemplos de cómo los clientes de Commvault utilizan servicios modernos e innovadores de protección de datos, incluida nuestra cartera de DPaaS Metallic, para alcanzar sus objetivos de transformación digital:https://www.commvault.com/digital-transformation-changes-everything-when-it-comes-to-data.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Desde alcanzar los objetivos de sostenibilidad hasta mejorar la eficiencia, todo ello sin dejar de apoyar la innovación, los equipos de TI tienen mucho que aportar en 2023.

Echa un vistazo a nuestra recopilación de las prioridades de TI de nuestros socios y clientes para 2023 y dinos qué te parece a través de las redes sociales.

Alan Atkinson, Chief Partner Officer – Concentration on highest value projects


2023 will continue to be challenging for companies from an economic perspective, especially those that are neither profitable nor public – leading many organizations to seek opportunities for cost reductions.

Inevitablemente habrá recortes y, en última instancia, algunos fracasos, y los socios y clientes se mostrarán reticentes a adoptar soluciones de proveedores que no tengan una trayectoria clara de futuro. Esto, junto con diversas presiones inflacionistas, obligará a los socios a centrarse en hacer realidad los proyectos de mayor valor. El ransomware, la migración a la nube y la transformación digital seguirán siendo prioridades que recibirán financiación, mientras que es probable que otras áreas de negocio pierdan prioridad. La consolidación será clave para abordar estas necesidades. Los socios y los clientes no buscarán más proveedores, sino proveedores que ofrezcan más soluciones. Realizarán apuestas más importantes y concentradas, alineándose con proveedores que ofrezcan una mayor amplitud de cobertura y soporte en modelos de prestación rentables.

Darren Yablonski, Sr. Director, Sales Engineering, Canada, U.S. SLED, LATAM – Cyber Security, AI and Regulation


A top, if not the top IT priority for organizations in 2023 will most certainly be cybersecurity. Significant amounts of IT budget spend will be allocated and invested in technologies to prevent, detect and recover from inevitable cyberattacks not if, but when they occur. As cloud adoption in a SaaS (Software as a Service) model continues to proliferate the market, organizations will leverage solutions that provide proven piece of mind knowing their data is safe and recoverable in a timely fashion. Trust will be given to organizations that can clearly articulate cybersecurity best practices that align to a customer specific use case and objectives.

Continuing on the theme of cybersecurity, emerging technologies and trends will be inclusive of both AI (artificial intelligence) and automation. Organizations typically have predictable network and data usage patterns. As data continues to grow exponentially within the realm of the “internet of things” and those patterns deviate within a network or data repository, humans simply cannot keep track of anomalies in real time. As such, Security Information and Event Management (SIEM) solutions that collect, process, analyze and report threats in an expedited and accurate manner will continue to become more ubiquitous. Integration and adoption of such technologies within a zero-trust architecture will be of greater top of mind for CISO’s and security specialists as the years progress.

Como se ha mencionado anteriormente, el consumo de datos seguirá fluyendo desde las instalaciones locales hacia las aplicaciones en la nube mediante un modelo SaaS, en función del caso de uso. Las soluciones híbridas, tanto locales como basadas en la nube, seguirán existiendo durante varios años, ya que las empresas buscan equilibrar y garantizar la inmutabilidad de los datos y la rapidez de Recovery de la forma más rentable posible. A medida que sigan evolucionando las nuevas normativas específicas sobre prácticas de seguridad de los datos, también evolucionarán las soluciones de gestión de datos que ofrezcan un conjunto completo y exhaustivo de herramientas que aborden dichas prácticas. En resumen, a medida que el panorama de amenazas en el ámbito de las tecnologías de la información siga creciendo y aumentando en complejidad, las organizaciones que intenten abordar esta complejidad para sus clientes se centrarán en desarrollar soluciones de software más diversas y amplias que simplifiquen la capacidad de recuperación y la elaboración de informes precisos, independientemente de dónde residan los datos.

Katharine Colucci, Associate Solutions Marketing Manager – Corporate Sustainability


The IT organization will take steps to lower the carbon footprint of its data to support corporate sustainability goals. Adopting more sustainable business practices has become a strategic priority of organizations worldwide as they become increasingly aware of how important sustainability efforts are to the success of the business. In fact, Gartner predicts that by 2025, 50% of CIOs will have performance metrics tied to the sustainability of the IT organization. IT teams will need to take steps to reduce the carbon footprint of their data through responsible data management practices, to support overall corporate sustainability goals. Responsible data management practices make it possible to control the total amount of data produced, thereby reducing the energy needed to create, store, manage and protect it.

Commvault supports our customers wherever they are on their sustainability journey, providing opportunities to mitigate their carbon footprint while reducing costs and maximizing the efficiency and security of their data management practices. To learn more about how Commvault is helping customers take a sustainable approach to intelligently manage data, visit Commvault.com/corporate-sustainability.

Gartner, ¿estás pensando a pequeña escala en lo que respecta a la tecnología sostenible?, septiembre de 2022

Jason Gerrard, Director, International Sales Engineering – AI/ML and Automation


A medida que la población envejece progresivamente, a las empresas les resulta cada vez más difícil atraer talento nuevo y fresco al sector de las tecnologías de la información. Como resultado, la brecha de competencias se está ampliando y las empresas se ven obligadas a depender menos de las personas para impulsar la innovación, el crecimiento y la estabilidad, y a avanzar hacia un mundo más automatizado, en el que la tecnología pueda salvar esa brecha.

Esta transformación ya está muy avanzada, y muchas organizaciones están aprovechando entornos, como la nube pública, para automatizar muchos de los procesos que históricamente requerían la intervención humana. Las tecnologías de orquestación y automatización pueden contribuir en gran medida a facilitar esta transición mediante la integración de la inteligencia artificial y el aprendizaje automático en sus soluciones. Estas tecnologías se han adoptado ampliamente a lo largo del último año para ayudar a cubrir la brecha de competencias, pero, dado que se prevé que los costes alcancen niveles sin precedentes, seguirán creciendo en 2023 como solución para reducir costes y, al mismo tiempo, mantener los sistemas en funcionamiento.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

As the world enters the post pandemic period of heightened digital transformation, new challenges have emerged which businesses (and their data) will have to navigate.  In the face of increased economic pressure, digital transformation and cloud initiatives are set to focus on creating efficiencies through costs and resources.

To help organizations steer through these (potentially) choppy waters, we’ve gathered thoughts from some Commvault key opinion leaders.  

Param Kumarasamy, VP, Product Management
– Resilience and Cloud Native Technologies

En 2023, la incertidumbre económica seguirá aumentando en un contexto de crecimiento masivo de datos y de recursos de TI cada vez más limitados. Esto hará que las empresas pasen de centrarse en iniciativas de transformación a centrarse en la resiliencia. Esperamos que los ejecutivos adopten una postura defensiva para abordar los problemas conocidos y sacar más partido a unos recursos limitados. Las iniciativas de resiliencia de TI impulsarán la adopción de tecnologías de IA y aprendizaje automático (ML), como la autosupervisión y la gestión de activos de TI, así como la automatización y la orquestación de actividades de TI tanto en entornos locales como en la nube.

En los últimos años hemos sido testigos de un enorme crecimiento de las iniciativas de nube híbrida y multinube en las empresas. En 2023, prevemos que las organizaciones redoblen su apuesta por las tecnologías nativas de la nube. Al igual que ocurrió con el cambio de los entornos físicos a la virtualización, veremos cómo las empresas pasan de las tecnologías de virtualización a adoptar cada vez más Kubernetes, contenedores y DevOps, tanto en entornos locales como en la nube.

Reza Morakabati, Chief Information Officer –
CIOs need a holistic approach to data protection

Al entrar en 2023, los directores de sistemas de información (CIO) deberán adoptar un enfoque integral y adaptado a cada situación a la hora de evaluar su mapa de destinos de almacenamiento de datos. Es posible que las empresas adopten de forma indiscriminada la nube o las soluciones locales basándose en recomendaciones generales, pero la decisión debería depender en gran medida del uso que se vaya a dar a los datos.

CIOs need to focus on five main areas – scalability, flexibility, agility, security, and cost. Cloud for instance checks off many of these boxes, but could account for a significant portion of a CIO’s operating budget, whereas data center investments are mostly allocated to capital budgets. It is critical for CIOs to look at the full picture.

Matt Tyrer, Senior Solutions Marketing Manager
and Head of Competitive Intelligence – Data Diversification and Mobility 

The number of applications, clouds, platforms, utilities, tools, and various other data workloads and locations to run them is multiplying. Just to frame this a little let’s just look at one of the bigger providers out there, AWS.  Prior to AWS reInvent in late November 2022, they had over 200 applications and services within their catalog for customers to leverage and build on. They then introduced at their annual event another 50+ including many highly specialized databases and tools.

That’s a lot, and that’s just one vendor. With this growing diversification is my prediction, and one seconded by Gartner at their recent IT Infrastructure, Operations, and Cloud Strategies Conference in Las Vegas just a few weeks ago: 

The applications and workloads you are running today, and where you are running them, will not be the applications and workloads or places where you will be running them in tomorrow. 

The impact here is equally diverse.  

  • Skills Shortages: The constant shifting of data workloads will mean that most organizations will not have the in-house skills to keep up with the changing platforms and services they are depending on to drive their business forward and remain competitive. 
  • Data Protection/Management Challenges: It is already a daunting task ensuring that all of your data sources are not only protected but secured from the growing threats to them. Many businesses are stuck relying on multiple niche or point product solutions in order to tackle this challenge because there simply are not many options out there that can cover it ALL. Now imagine all of those data sources and applications moving and changing on a regular basis, most tools today just can’t keep up and this will lead to overlapping siloes adding complexity, cost, and overall risk to the business. 

To address this, businesses will be turning more and more to partners who provide the broadest possible spectrum of support for data protection and data management to ensure that as their data platforms change, their solutions not only can keep pace, but already provide the needed coverage. This will enable organizations to adapt and transform with significantly less friction as they don’t need to revisit data protection and management with each step. This also supports a number of other initiatives such as sustainability and ESG as it enables the consolidation of tools and reduction of infrastructure and consumption of other resources such as the power and water that fuel that infrastructure. 

Hope D’Amore, Solutions Marketing Manager
– Cloud-Native will become the norm

La transformación digital es necesaria para mantener un nivel de innovación y competitividad en el mercado. Si a esto le sumamos una economía turbulenta e incierta, las empresas tendrán que centrarse en la gestión de los costes de la nube para lograr un equilibrio entre ambos aspectos. Puede que algunos piensen que la adopción de soluciones nativas de la nube pasaría a un segundo plano en estos tiempos de incertidumbre, pero una encuesta reciente de Forrester revela que el 40 % de las empresas adoptarán una estrategia que dé prioridad a las soluciones nativas de la nube en 2023. Las organizaciones invertirán más en tecnologías nativas de la nube, como Kubernetes, para lograr una mayor eficiencia en lugar de seguir invirtiendo en infraestructuras heredadas.

As the shift to cloud-native environments becomes the norm, security will continue to be top of mind and Commvault is here to help. We provide the most comprehensive and flexible portfolio of solutions for containers. Store, protect, and migrate your Kubernetes applications wherever they live across hybrid multi-cloud environments. To learn more about how Commvault data protection can increase efficiencies within your cloud-native environment, visit Commvault.com/containers.

Forrester, Previsiones para 2023: Computación en la nube, 27 de octubre de 2022

¿Qué opinas? ¿Qué planes tiene tu empresa en materia de transformación digital y en la nube? ¿Tienes previsto invertir más en contenedorización este año?

Cuéntanoslo en las redes sociales.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Al conmemorar al Dr. Martin Luther King, Jr. el 16 de enero, sigue siendo muy importante destacar su vida y su legado como líder de los derechos civiles ahora que comenzamos el año 2023. A pesar de todos los logros alcanzados en los movimientos por la justicia racial y social, aún queda un largo camino por recorrer a nivel mundial hacia la igualdad para todos.

This day is a meaningful opportunity to reflect on what it means to drive positive change through the power of connection – whether it’s in our local communities, with family and friends or in our workplaces. For Dr. King, and all those who worked alongside him, their commitment to equality and human rights became another moment in the world in how individuals can empower the collective.

At Commvault, we’re striving for a balance in what it means to connect meaningfully whether it is in person or remotely. The global pandemic helped us navigate how to extend those connections around the world in virtual spaces and do it successfully to have “courageous conversations” around various topics.

In my role, my goal is focused on empowering everyone to be a change agent towards moving the Commvault community forward– especially driving lasting and impactful change for all dimensions of diversity. In various workplaces, there are diversity, equity and inclusion (DE&I) efforts focused on improving the recruitment, retention, advancement and sense of belonging for those from diverse, unique backgrounds and cultures. Within Commvault, we have the Multi-Culture Employee Resource Group (ERG) focused on helping to create connections, education and awareness of our global cultures.

El grupo de empleados (ERG) «Multi-Culture» de Commvault se compromete a ofrecer un espacio de refugio, celebración y reflexión para los «Vaulters» procedentes de grupos raciales infrarrepresentados y para sus aliados en Commvault. Nos esforzamos por dar a conocer la belleza, el valor y las contribuciones de todos los orígenes raciales y étnicos.

As a company, we’re working towards that meaningful change and creating a sustainable foundation to support future efforts where all feel like they belong and can thrive. In honor of Dr. Martin Luther King, Jr., let’s continue to make a commitment to ourselves, others, and our broader global community that we will create space for positive change, more connections, and making our places in the world a more welcoming environment -– we’re in this together!

Haz clic aquí to learn more about our DE&I efforts at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

To be successful in our roles as IT professionals, we frequently need to juggle a variety of responsibilities or “wear a lot of hats” – especially when it comes to the important matter of protecting a company’s great asset, its data. 

Hagamos una pausa para analizar las características de cada función y cómo se relacionan con las responsabilidades en materia de protección de datos de un profesional de las tecnologías de la información:

The baseball cap – Readiness

Prever y frustrar los posibles riesgos para la seguridad de la información. Como responsables de TI, es nuestra responsabilidad proteger los datos y prever cualquier punto débil. Esto implica buscar continuamente posibles riesgos y prevenirlos antes de que se conviertan en un problema. El uso de soluciones como el «cyber-deception» permite disponer de un sistema de alerta temprana y proporciona esa protección necesaria antes de que un ataque te deje ciego.

The fedora – Flexibility

Modifying data protection tactics to fit the organization’s evolving needs. As IT executives, we must be ready to modify our approach to data protection to match the shifting requirements of our organization. The digital landscape is always changing. To remain ahead of potential dangers, this can entail putting new security processes into place or modifying current ones. Additionally, an IT leader must consider the latest technologies from cloud to containers and even possibly consider older tech when involved in mergers and acquisitions.  These scenarios all require a robust data protection solution that is scalable and flexible.  

The beret – Creativity

Inventing innovative ways to safeguard data in an increasingly complex digital environment. As IT executives, we must be able to think creatively and develop novel ways to safeguard data in a complicated digital environment. The cybercriminals are often a few steps ahead and might have more resources than your internal IT staff, the only way to combat this is to have elegant solutions to complex problems.  Nothing is more elegant than a beret…

The top hat – Decision Making

Making decisions that secure data and shield the organization from potential dangers while also ensuring that data protection and security are top organizational priorities. As the “top hat” of the company, it is our duty to make sure that data security and protection come first, to make choices that secure data, and to defend the company against any dangers. Our customers, employees, shareholders and even our peace of mind rely on knowing that IT leaders are securing the data and information of our company.  

En conclusión, los responsables de TI tienen mucho trabajo y deben tener conocimientos en diversos ámbitos.

En el Día Nacional del Sombrero, dediquemos un momento a reconocer las distintas funciones que desempeñan y el papel fundamental que tienen a la hora de garantizar el buen funcionamiento y la eficacia de nuestras empresas.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

2022 was a BIG year for Cyber Security.  According to Cyber Security Hub, more than 4100 data breaches were publicly exposed with a number of high-profile attacks including Twitter, Optus and WhatsApp.

In today’s world, bad actors are well organized, informed and also persistent with the volume and speed of attacks increasing.  Their motives are changing, with data leakage, exfiltration, theft and restructure being top objectives causing data damage to now be the top concern of IT decision makers.

So what does 2023 hold? We’ve gathered thoughts from experts across Commvault to answer that very question. 

Industry-Wide Shift to Proactive, Early Threat Prevention 
– Matt Tyrer

In short, businesses will need and begin to implement proactive solutions to constantly monitor their environment to catch threats and enable early warning/response.  Bad guys are getting in, and we aren’t knowing about it early enough. 

From a cyber security and threat defence perspective, the industry today could be essentially divided in two approaches: 

  1. Preventative Measures: These vendors are your perimeter defence vendors like firewalls, anti-virus, SIEM/SOAR tools, along with other data loss prevention (DLP) and intrusion detection/prevention solutions. Even the newer identity access management (IAM) security vendors, who are adding key security functionality to control who can see what in your environment, can be grouped in here. They are all the locks on your doors and windows actively working to keep the bad guys out of the house so that they can’t even start the fire. 
  2. Reactive Measures: These tend to be the storage and most conventional backup vendors who are focused on protecting the data itself. Aiming to ensure it is available for recovery via table stakes features like immutability and anomaly detection (threat hunting) in the backups. These solutions are the sprinkler system and fire alarm – by the time they are triggered your house is already on fire and your only response is triage and disaster recovery. 

Don’t get me wrong, both of these are critical parts of a layered security posture and strategy but there is a gap which where early warning lives.  It’s the abilities to better respond when a breach occurs, while not waiting for data damage to be done before recovery is kickstarted.

This is why my prediction is an industry wide shift to more PROACTIVE warning systems, helping companies fill gaps between their preventive and reactionary toolsets.    

Thankfully, Commvault is ahead of this game with our ThreatWise cyber deception technology. Get started NOW on proactively defending your data. 

Rise in Managed Services Provider Spending
– Donna Namorato

The Institute of International Finance is predicting a global economic growth rate of just 1.2% in 2023, a level on par with 2009 when the world was only beginning its emergence from the from the financial crisis.1 Even with economic uncertainty looming, expect that cybersecurity spending will continue to rise but don’t be surprised if there is a decline in product and service spending.

Y aunque el gasto en ciberseguridad aumenta, según una encuesta de Jefferies a directores de sistemas de información (CIO), el 53 % señaló que recortaría el gasto en gestión de servicios de TI (ITSM). Si esto ocurre, cabría esperar un aumento del gasto en proveedores de servicios gestionados (MSP). Los MSP se especializan en segmentos específicos de las TI y pueden ofrecer experiencia especializada en este ámbito, ya que atraen y retienen talento, algo que a las organizaciones les resulta difícil lograr.

To remain vigilant against ransomware and data security, organizations must adopt a ransomware strategy and develop an plan de respuesta ante incidentes against bad actors. Incorporating a multilayered security framework is also vital to safeguard your data and reduce cybersecurity risk. And, when you need help, las soluciones de Readiness frente al ransomware de Commvault is available to assist you.

Industry and Platform Consolidation
– Brian Brockway, Global Chief Technology Officer


En la actualidad, el sector de la seguridad es muy complejo. Existen muchísimas herramientas en el mercado y muchas empresas cuentan con múltiples soluciones para garantizar una protección total. Sin embargo, hemos observado que el sector ha comenzado a consolidarse, una tendencia que debería continuar en 2023. Todos los componentes deben trabajar de forma conjunta para funcionar con la máxima eficiencia y ofrecer las mejores garantías de protección. Consolidarlos en una única plataforma será esencial para garantizar que se saca el máximo partido a las soluciones, y disponer de un único panel de control es clave para gestionarlas. Especialmente ahora que los costes siguen aumentando, las organizaciones deben asegurarse de que gastan cada céntimo de forma inteligente y obtienen el máximo rendimiento de cada adquisición.

Sin embargo, debido a la enorme cantidad de amenazas a las que se enfrentan las empresas, también existe una creciente conciencia de que no todo se puede detener, por muy buenas que sean las soluciones o por muy eficazmente que se gestionen. Las organizaciones deben centrar su atención en la resiliencia. Hoy en día es casi inevitable que las empresas sufran un ataque en algún momento, pero lo que realmente importa es la rapidez con la que se pueda recuperar. Deben realizarse copias de seguridad periódicas para que, incluso si ocurre lo peor, el tiempo de inactividad se reduzca al mínimo y las operaciones comerciales normales puedan restablecerse lo antes posible con un daño duradero mínimo.

“Inside-out” CyberSecurity, Tiger Teams and Managed Services
– Zack Brigman, Sr Product Marketing Manager

Las ciberamenazas siguen alcanzando máximos históricos, tanto en el número de ataques que tienen éxito como en los daños causados por ellos. De cara al año 2023, los expertos prevén que estas tendencias sigan avanzando en la dirección equivocada, ya que los adversarios emplean nuevas tácticas sofisticadas, las redes de hackers a sueldo siguen expandiéndose y la brecha de competencias en seguridad y TI se amplía. Y aunque estas fuerzas negativas plantean retos difíciles de superar, las organizaciones darán un gran paso adelante durante el próximo año para planificar mejor, invertir y madurar sus disciplinas de ciberseguridad.

Prioritization

Breaches happen. But not all assets, systems, and data are created equal. Given that a small percentage of information assets carry the majority of business risk, progressive companies will begin employing an “inside-out” cybersecurity strategy. One that starts with hardening and securing their most critical assets first – then working toward the perimeter. While perimeter defences and preventing intrusion will (and should) remain a paramount focus, this risk-aligned approach enables the prioritization of defence strategies to mitigate risk for high-value assets and functions. This reshapes conventional “outside-in” approaches, making security investments more accessible and operational.

Tiger Teams

To better manage emerging threats and respond to risk, we will continue to see a rise in fusion teams (thanks Gartner for the term!) – merging IT, security, and operational stakeholders together to drive change. These blended teams help create new synergies by pairing complementary (but often siloed) groups and capacities to achieve common goals. These cross-functional teams increase visibility across the organization, discover and eliminate blind spots, and optimize investments in existing and new tools. While many mature organizations already leverage fusion teams today, 2023 will see a more widespread adoption of these functions to better identify risks, implement cyber response strategies, and manage threats.

Managed Services

As threats mount, businesses will continue to adopt managed service (MSP) and managed security service (MSSP) offerings to augment existing tools and tactics. This is particularly true of lean IT departments and those looking to enhance their security operations centers. Leveraging these managed providers will enable organizations to close the cyber security skills gap, tap into a consortium of specialized solutions, and scale their cyber practice without managing additional headcount or disparate solutions. 

Thanks to all our contributors! Stay tuned to see if their predictions come true by following Commvault and our DPaaS portfolio Metallic on Social Media. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements