Skip to content

Your organization just got hit with a ransomware attack. Your cyber yIT departments are scrambling to get your incident response plan started yoperational. All of a sudden, everyone realizes that they cannot log in to anything.Active Directory (AD) must be offline!? Your organization’s authentication yauthorization tools are impacted.

After hours of triage yassessing the size of this problem, your cyber incident response team reports that restoring foundational AD yauthentication yauthorization services will take over a week, if everything goes well.

You thought your resiliency plan with AD backups ya SaaS identity platform was sufficient. But even with SaaS in the mix, recovery is complex ymanual, delaying the path back to minimum viable operationswhen time matters most.Resilienciameans you can restore authentication yauthorization quickly ypredictably in a trusted way, whether the disruption is malicious activity, an outage, or an accidental misconfiguration.

Understanding the Threat

Attackers target AD because it’s the identity control plane. Once they get a foothold, they’ll often establish persistence by creating shadow or backdoor accounts, then harvest credentials, yescalate privileges. With elevated access, they laterally move across systems yapplications, sometimes staying quiet long enough that the first clear signal is when authentication starts failing.

They gain a wealth of knowledge of the organizations network, people, yapplications. And when they’re ready to maximize impact, they can encrypt or corrupt the AD forest, disrupting logins ycomplicating recovery across the environment.

Why Identity (yWhy AD First)?

It’s common for an organization’s identity stack, especially AD yEntra ID, to become complex over time. Forests expand, permissions sprawl, legacy policies accumulate, y“good enough” processes often turn into long-term security drift. That complexity creates blind spots, ydefenders lose crisp visibility into how roles, privileges, ypolicies evolve.

And it’s never “just AD.” Identity is an ecosystem: identity governance yaccess solutions (IGA), privileged access, customer identity, identity providers, authentication databases, ysingle sign-on all connect back to the same truth. That’s why identity incidents (yeven everyday misconfigurations) can cause outsized disruption compared to many other infrastructure failures.

The recovery challenge is where most plans get exposed. Even with backups, forest recovery is a multi-step, high-stakes process, where guidance for manual recovery can involve 50 to 100 (or more) individual steps ycan take days to weeks, depending on environment complexity ypreparedness.

The real question isn’t “do we have backups?” it’s “can the teams leverage the backups to cleanly execute under pressure, yhave runbooks been tested yverified so recovery doesn’t become an error‑prone scramble at the worst possible time?”

La solución

The need to have a recovery plan is great. It needs to be tested yverified. Organizations need to know yunderstythat your identity management platform is the No. 1 target for cyber criminals yattacks. It needs to be protected as such. It needs to be backed up, tested, yverified it can be recovered. This includes:

  • Backups of AD, Entra ID, yIGA platforms.
  • Tested yverified recovery plans.
  • Isolated recovery environments yCleanroom.
  • AD recovery workflow yautomation.

Strong identity governance ymonitoring are still critical, but they’re only part of the equation. You want the ability to detect suspicious identity behavior early, contain it fast, yrecover with confidence when something changes that shouldn’t (whether it’s malicious activity or an accidental modification that breaks authentication).

That also means you need to integrate identity account yuser activity into SecOps ycontinuously watch for signals like unauthorized account creation, privilege changes, yabnormal authentication patterns, yhave a recovery path that’s proven, repeatable, yclean.

Commvault yDeloitte: A Partnership for Identity Resiliencia

La resiliencia de la identidad is a business challenge that requires strong governance, processes, controls, yenabling technology. That’s why Deloitte yCommvault have partnered to deliver comprehensive identity protection, recovery, yresilience programs that organizations can trust when it matters most. 

Deloitte brings deep expertise in cyber risk, enterprise resilience, yidentity yaccess management to help Fortune 100 to 1000 organizations design, implement, yoperationalize identity resilience programs.

These programs help clients assess security posture, improve detection yresponse capabilities, ydefine minimum viable company requirements, ythen build tested, verified recovery plans with clear timelines yaccountability across business yIT stakeholders. Deloitte turns identity resilience into an executable program with runbooks, testing, yreadiness, so teams know what “prepared” looks like under pressure.

Commvault makes resilience programs operational with integrated protection yautomated recovery workflows across identity systems, plus Commvault AirGapyCleanroomto support repeatable, clean, validated recovery when it matters most. Commvault provides the technology foundation with identity resilience capabilities that include:

  • Protection for critical identity systems, including AD yEntra ID, point-in-time comparison yrollback support for unwanted or accidental changes.
  • Auditing ydetection to surface suspicious modifications early (who changed what, ywhen), helping reduce the window for attackers to spread or persist.
  • Automated recovery workflows, including forest-level recovery automation, to help reduce the manual burden yerror risk during identity restoration.
  • Commvault Cleanroom to help validate identity recovery in isolation before reintroducing trust back into production.
  • Commvault AirGapto help maintain immutable, air-gapped backup copies, creating a protected foundation that supports clean recovery ycleanroom testing when identity (or the environment around it) can’t be trusted.

Take Action

If you want to pressure-test your cyber recovery readiness, start with a Deloitte Active Directory Workshop to map dependencies yproduce a clear, actionable plan to recover AD yworkloads to production. Then validate it the right way: using Commvault to rehearse recovery in a cleanroom before you ever need it in a real event.

For organizations ready to take the next step, we can extend this into a 30-day pilot that puts clean recovery ytesting into motion with real artifacts ymeasurable outcomes. Contact your Deloitte representative at commvaultsalesteam@deloitte.comor your Commvault representative atdeloittealliance@commvault.compara obtener más información.Dave Nowak is Cyber Defense & Resiliencia Principal at Deloitte, yMichael Fasulo is Senior Director, Portfolio Marketing, at Commvault.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave

  • La falta de coordinación entre las áreas de TI y seguridad aumenta el riesgo cibernético.
  • Commvault Cloud permite una respuesta y una Recovery unificadas.
  • Arlie AI ofrece inteligencia compartida y acciones guiadas.
  • Los principios de «seguridad desde el diseño» sustentan la confianza y el cumplimiento normativo.
  • Una mentalidad compartida es fundamental para la ciberresiliencia.

In today’s enterprise environment, cyber resilience depends on more than tools. It depends on whether IT and Security teams operate with shared intent. With Commvault Cloud, organizations gain a unified platform that connects detection, response, and recovery – helping CIOs and CISOs move forward together without compromise.

Comprender la brecha entre TI y seguridad

IT and Security teams share a common mission: enable the business to succeed. Yet their paths often diverge through opposing objectives, siloed tools, and disjointed workstreams.
IT Operations prioritize speed, scalability, automation, and uptime.
Security Operations focus on protecting data, reducing risk, and maintaining compliance through the CIA triad – confidentiality, integrity, and availability.
When these perspectives collide without coordination, silos form. Communication slows. Risk increases.

Por qué la falta de alineación socava la ciberresiliencia

La falta de alineación tiene consecuencias tangibles:

  • Detección y respuesta más lentas ante incidentes.
  • Recovery that is inefficient and prone to errors.
  • Mayor alcance de los ciberataques.
  • Mayor fricción operativa durante las crisis.

La resiliencia cibernética exige una acción coordinada en las fases de detección, investigación y Recovery.

Superar las barreras con Commvault Cloud

Commvault demonstrates how technology can align teams instead of fragmenting them.

  • Faster, cleaner recoveries: Commvault provides threat insights, scanning against indicators of compromise and sharing insights with security tooling while enabling rapid, reliable recovery. Together, teams can identify affected systems and restore operations with confidence.
  • Targeted risk mitigation: Capabilities such as cyber resilience assessments, scenario simulations, and isolated testing in cleanrooms allow organizations to prepare without impacting production environments.
  • Unified incident management: Integrated workflows connect detection, investigation, and recovery, minimizing room for miscommunication, and helping to accelerate resolution.
  • Scalable, tailored services: Commvault incident response recovery services adapt to organizational needs, supporting resilience without overextending resources.
  • Shared expertise: Customers can benefit from combined guidance across architecture planning, process optimization, and operational readiness.

Arlie AI: inteligencia compartida en acción

Arlie AI, Commvault’s Autonomous Resilience copilot, strengthens collaboration by delivering real-time insights and guided workflows.
Arlie helps:

  • Detectar anomalías y datos críticos.
  • Guiar a los usuarios paso a paso durante los incidentes.
  • Reducir la dependencia de conocimientos técnicos especializados.
  • Estandarizar la respuesta entre los equipos de TI y seguridad.

Gracias a las integraciones sin código y a la inteligencia adaptada a la plataforma, Arlie elimina las conjeturas y refuerza la ejecución compartida.

Seguridad por diseño, no por casualidad

Commvault integra la seguridad a nivel de código mediante los principiosde«seguridad desde el diseño». Este enfoque queda validado a través de iniciativas como la adopción decapacidades criptográficas poscuánticasCentro de confianza de Commvault.

se pueden consultar certificaciones adicionales.

Q: Why do IT and Security teams struggle to align?

A: They operate under different priorities, KPIs, and tools, which can create silos.
Q: How does Commvault help improve cyber resilience?

A: By unifying detection, response, and recovery within Commvault Cloud.
Q: What role do security integrations play?

A: Commvault security integrations allow sharing threat insights cross-functionally and help inform faster recovery.
Q: What is Arlie AI?

A: Arlie is Commvault’s AI copilot that delivers guided, real-time resilience insights.
Q: Why is de important?

A: It helps reduce risk at the code level and helps support compliance from the start.
Q: How can organizations measure alignment success?

A: Through shared KPIs like time to detection, recovery speed, and readiness testing

Pauline List is a Product Marketing Specialist at Commvault.


Blogs relacionados

Alineación de las partes interesadas para la ciberresiliencia

La urgente necesidad de ciberresiliencia

A Multi‑Layered Approach to Cyber Resilience

Un enfoque multicapa para la ciberresiliencia

La próxima evolución en la protección Cloud

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave

  • El acceso lateral en entornos de IA permite a los atacantes desplazarse por los sistemas conectados aprovechando la confianza compartida y los permisos excesivos.
  • Los flujos de trabajo de IA pueden ocultar el movimiento lateral, ya que los ataques suelen imitar el comportamiento normal del sistema.
  • Defense in depth – including identity isolation, segmentation, and dynamic access control – helps reduce the spread of compromise.
  • La planificación de la Recovery debe considerarse un control fundamental, y no una medida secundaria, para restablecer la confianza tras las brechas de seguridad laterales.
  • Commvault fomenta la resiliencia al facilitar una Recovery fiable y aislada, así como una contención rápida cuando se producen incidentes de acceso lateral.

Modern AI systems are built for speed and connectivity. That same design also makes lateral access one of the most dangerous and least visible failure modes in AI-enabled environments.

Large language models, retrieval pipelines, orchestration layers, and downstream services continuously interact to generate value. When those interactions rely on shared trust and overly broad permissions, a single compromise can spread far beyond its original scope.

What Is Lateral Access in AI Environments?

Lateral access occurs when an attacker compromises one component and then moves horizontally across connected systems by exploiting trust relationships, shared identities, or overly broad permissions.

In modern AI environments, this type of movement is especially dangerous. Models, retrieval services, orchestration layers, and data stores are designed to communicate continuously, often using shared credentials and implicit trust. Once a single component is compromised, attackers can move quickly across the environment without triggering obvious alerts.

Because AI workflows generate large volumes of legitimate activity, lateral movement often blends into normal system behavior until the blast radius already has expanded.

Why Lateral Access Is Especially Dangerous

Lateral access undermines security assumptions that many organizations still rely on. Traditional defenses focus on preventing initial compromise or vertical privilege escalation. Lateral movement bypasses those controls by abusing legitimate access paths that already exist.

In AI-enabled environments, the impact compounds rapidly. Compromised services may continue to generate valid outputs while attackers move across models, data sources, and tenants at machine speed. What begins as a single breach quickly can expand into a systemic incident.

Recovery is also more complex. When identities, orchestration layers, or shared data stores are involved, organizations must assume broader contamination and restore trust across multiple systems rather than a single endpoint.

Common Causes of Lateral Movement

Most lateral access exploits are enabled by architectural decisions rather than novel vulnerabilities. In modern AI environments, speed and integration are often prioritized before identity discipline and segmentation are fully enforced.

The most common causes include:

  • Permisos excesivos concedidos a servicios de IA, agentes o cuentas de automatización.
  • Identidades compartidas entre las funciones de ingestión, recuperación, inferencia y orquestación.
  • Aplicación deficiente de los controles de acceso basados en roles y en atributos.
  • Segmentación insuficiente entre inquilinos, entornos o cargas de trabajo.
  • Falta de copias de seguridad inmutables y flujos de trabajo de Recovery aislados.

Addressing these issues requires architectural discipline and recovery planning, not reactive controls applied after compromise.

Reducing Lateral Risk with Defense in Depth

Reducing lateral access risk in AI environments requires more than perimeter controls or isolated fixes. It requires defense in depth that assumes compromise and limits how far attackers can move once inside.

Effective design focuses on four core principles:

  • Enforce identity isolation: Each AI function should operate with its own narrowly scoped identity. Ingestion services, retrieval components, orchestration layers, and inference engines should never share credentials. When identities are isolated, a single compromise cannot automatically spread across systems.
  • Apply context-aware access controls: Permissions should be evaluated dynamically based on role, environment, tenant, and operation. Combining role-based and attribute-based access controls limits abuse of legitimate access paths and reduces the opportunity for lateral movement.
  • Segment data paths and execution environments: AI components should be isolated from one another and from core business systems. Segmented networks, service boundaries, and controlled data paths help restrict how far attackers can move and contain the blast radius when compromise occurs.
  • Plan for recovery as a control: Prevention alone is insufficient. Organizations must assume lateral movement will occur and design recovery workflows that help them isolate compromised components, restore trusted systems, and reestablish control without reintroducing risk.

Together, these principles shift lateral access from an uncontrolled cascade into a contained and recoverable event.

Detecting and Responding to Lateral Behavior

Early detection is critical in limiting the impact of lateral access. Because lateral movement often mimics legitimate system behavior, traditional alerting focused on perimeter breaches or privilege escalation is frequently insufficient.

Effective detection focuses on behavioral signals rather than individual events. Unexpected interactions between services, sudden expansion of access scope, and anomalous identity usage patterns can indicate lateral movement even when individual actions appear valid.

When suspicious behavior is identified, response must prioritize containment and trust restoration. Compromised identities should be revoked quickly, affected components isolated, and recovery initiated using trusted data in controlled environments. The goal is not only to stop movement, but to reestablish confidence in system integrity.

Why Commvault Matters for AI Resilience

AI systems increase speed and scale across the enterprise. Attackers benefit from that same speed when lateral access is left unchecked.

Commvault helps organizations reduce the impact of lateral access by providingbases de Recovery fiablesque permiten la contención, el aislamiento y la restauración a gran escala. Cuando se produce una violación de seguridad, la capacidad de recuperarse a partir de datos conocidos como fiables se convierte en un control crítico. Commvault ayuda a las organizaciones a:

  • Conservar puntos de recuperación fiables que permanezcan disponibles incluso durante una compromisión generalizada.
  • Restaurar sistemas y datos en entornos aislados para su validación antes de su reintroducción.
  • Recuperar servicios dependientes de la identidad sin amplificar la contaminación lateral.
  • Reducir el tiempo de inactividad y restablecer la confianza operativa más rápidamente.

Resilience against lateral access is not about eliminating connectivity. It is about controlling it, monitoring it, and making sure that recovery remains possible.

Final Thought

Lateral access is not a failure of individual controls. It is a consequence of how modern AI systems are designed to connect and trust one another.

As AI environments continue to scale, resilience depends on disciplined identity design, intentional segmentation, and the ability to recover quickly from trusted data. Organizations that plan for containment and recovery alongside innovation are best positioned to limit blast radius and preserve trust when compromise occurs.

Learn how Commvault helps organizations strengthen AI resilience and accelerate recovery when it matters most.La nueva versión de la plataforma Commvault Cloud Unityte permite unificar la seguridad de los datos, la resiliencia de las identidades y la recuperación cibernética a escala empresarial.


Preguntas frecuentes

Q: What does “lateral access” mean in AI-enabled environments?
A: Lateral access refers to an attacker’s ability to move horizontally between interconnected systems after compromising one component. In AI environments where models, retrieval layers, and data sources share trust, this movement can go unnoticed and expand quickly.

Q: Why is lateral access particularly dangerous for AI systems?
A: Because AI ecosystems are highly interconnected, a single compromise can cascade across multiple components. Attackers can maintain legitimate-looking activity while accessing sensitive data or systems, making detection difficult and recovery complex.

Q: What are the most common causes of lateral movement?
A: Excessive permissions, shared identities across AI services, weak access control enforcement, lack of segmentation, and missing immutable backups all create opportunities for lateral exploitation.

Q: How can organizations reduce lateral access risk?
A: Implementing identity isolation, dynamic (context-aware) access control, and segmentation across AI components limits how far attackers can move. Recovery strategies should be built into architecture to enable containment and safe system restoration.

Q: What role can Commvault play in defending against lateral access?
A: Commvault strengthens resilience by enabling organizations to maintain trusted recovery points and isolate restoration. Its tools are designed to validate, recover, and reestablish trust quickly, helping reduce downtime after compromise.

Q: How should teams detect and respond to lateral movement?
A: Commvault recommends focusing on behavioral anomalies – such as unexpected service interactions or expanded access scopes – rather than traditional alerts. Once detected, revoke compromised credentials, isolate affected systems, and recover from verified data backups.

Chris DiRado is Principal, Product Experience, at Commvault.

More related posts


Thumbnail_-Blog_Hyperscale-2025-1

Commvault On-Prem Solutions: Ransomware Resilience to AI-Ready Data Protection

Read more about Commvault On-Prem Solutions: Ransomware Resilience to AI-Ready Data Protection
Thumbnail_Blog_Resilient-Against-the-AI-Machine

Resilient Against the AI Machine

Read more about Resilient Against the AI Machine

At Commvault, support exists for one reason: to solve customer challenges as quickly and confidently as possible. Every process we refine, every tool we introduce, and every investment we make is guided by that goal – helping customers feel supported when it matters most.

Over the years, we’ve learned that great support isn’t just about resolving tickets. It’s about clarity during high-pressure moments, honest communication, and building trust that lasts beyond a single interaction. Those lessons have shaped a support ecosystem designed to move fast without losing the human connection.

La experiencia humana, potenciada por la IA

Speed and empathy don’t have to compete. That’s why our approach to AI is built around partnership, not replacement. AI helps us move faster; people are dedicated to making sure we move wisely.

Arlie, our AI-enabled support assistant, analyzes logs, recognizes patterns, and surfaces insights early – often before issues escalate. Customers can use Arlie directly to find answers in real time, while our engineers use those same insights to focus less on data gathering and more on understanding each customer’s unique environment.

This balance matters. Support interactions often happen during moments of risk or stress, when customers want reassurance that a real person is invested in their success. By handling the repetitive and time-consuming tasks, AI creates space for meaningful conversations – the kind that build confidence and trust.

El equipo que hay detrás de cada resolución

Behind every fast resolution is a global team of highly skilled engineers who continuously learn, collaborate, and share knowledge. Our Center of Excellence model allows expertise gained in one region to strengthen support everywhere, ensuring customers benefit from collective experience – not just individual cases.

Training, certifications, case reviews, and simulations are part of everyday life for our support teams. This preparation means that when a ticket arrives, engineers respond with clarity, purpose, and deep technical understanding across cloud, storage, backup, databases, and security.

AI strengthens this model even further by capturing insights from past cases and making them instantly accessible, so knowledge never stays siloed.

Una experiencia de asistencia que no deja de evolucionar

The result is a support experience that feels both efficient and personal – one where customers can self-serve when they need speed, connect with experts when they need guidance, and trust that every interaction is backed by experience, empathy, and continuous learning.

We’re continuing to invest in proactive monitoring, smarter self-service, and learning paths that help customers and engineers grow together. Progress is ongoing, but the direction is clear: faster resolutions, stronger partnerships, and support that customers can truly rely on.

If you’ve interacted with Commvault Support recently, we’d love to hear your feedback. Thank you for being a Commvault customer and for providing insights that help us keep improving – for every customer, every day.

 

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Backup and recovery integrations depend on secure workload credentials. A single compromised credential can open access far beyond one system, and threat actors know it.

The best static credential is the one you don’t have. Where feasible, move from secret-based authentication to managed identities or other “secretless” approaches, so credentials are issued, protected, and rotated by the platform rather than stored and handled manually. However, we realize this is not always possible for some legacy systems and configurations.

The good news: Even when using long-lived secrets, hygiene can reduce your risk and blast radius.

This post outlines a practical routine that can help ensure your business remains cyber resilient: Rotate credentials, minimize scope, and enforce Conditional Access where possible.

La base: tres controles clave

Strong credential hygiene comes down to three pillars: rotation, least privilege, and Conditional Access. While you won’t always be able to implement all three for every credential type, these are the right places to start for any environment:

  1. Rotation and monitoring: Rotate credentials regularly and review authentication activity for anomalies.
  2. Least privilege: Scope permissions so credentials can perform only the required backup/restore actions. Practical steps include:
    • Separar las credenciales por carga de trabajo.
    • Limitar los permisos al mínimo necesario en cuanto a conjuntos de datos, sitios, buzones de correo o bases de datos.
    • Evitar los roles de administrador de amplio alcance, salvo que sea absolutamente necesario.
  3. Conditional Access: Where supported, set policies to limit when and where credentials can be used, such as:
    • Ubicaciones de confianza y rangos de IP
    • Señales de riesgo
    • Controles de dispositivos y sesiones

When Conditional Access Isn’t Feasible, Rotation is the Compensating Control

No todos los tipos de credenciales cumplen los requisitos del acceso condicional. En esos casos, la rotación limita el tiempo durante el que una credencial robada sigue siendo útil, y la supervisión ayuda a detectar rápidamente cualquier uso indebido.Las directrices de Commvaulthacen hincapié en la rotación periódica de contraseñas, claves secretas y credenciales en todos los entornos. Para los registros de aplicaciones de Azure de un único inquilino que protegen cargas de trabajo de M365/D365/Entra ID,Commvault recomienda90-day rotation cycles. Many common security and compliance frameworks (PCI DSS, ISO 27001, SOC 2, NIST) also expect disciplined credentials management, including periodic rotation and review of access.

Consulte a su equipo de seguridad

Credential hygiene is most effective when it’s consistent. Align with your security team on:

  • Los intervalos de rotación (por tipo de credencial y nivel de riesgo).
  • Conditional Access policy design (what’s enforceable without breaking automation).
  • Las normas de acceso privilegiado, los requisitos de registro y los ciclos de revisión.

Guía de recursos

Los recursos que se indican a continuación ofrecen información adicional y orientación específica para cada entorno sobre la protección de credenciales y los controles de acceso.

Commvault
Microsoft
AWS
Google Cloud (GCP)

Will Galway is Deputy Chief Security Officer at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave

  • Commvault amplía la protección de Google Workspace con funciones avanzadas de búsqueda eDiscovery para facilitar el cumplimiento normativo, las investigaciones y los litigios.
  • The new capabilities allow faster, more precise discovery across Gmail and Google Drive using keyword, phrase, and metadata filters.
  • Flexible export options help legal teams streamline reviews and reuse standardized export sets for recurring cases.
  • A centralized discovery interface enables organizations to manage eDiscovery across Google Workspace, Microsoft 365, and endpoints from one platform.
  • The solution aligns with Electronic Discovery Reference Model (EDRM) standards and is available in early access, with general availability targeted for the first half of 2026.

Google Workspace is central to how many organizations communicate and collaborate, containing business-critical emails, files, and messages that are often essential forcompliance, investigations, and litigation.

As a key source of discoverable data, organizations needefficient eDiscovery processesto help quickly locate, manage, and export pertinent electronically stored information (ESI) across Google Workspace services to help meet modern legal and regulatory requirements. Delayed responses and incomplete or inaccurate ESI collection can drive up legal costs, increase regulatory risk, and lead to fines or failed compliance obligations.

To help address this need, we are expandingexisting Google Workspace protectionbyadding advanced compliance search capabilities for our eDiscovery offering. These eDiscovery capabilities for Google Workspace join existing eDiscovery support for Microsoft 365 and endpoints, making it easier to unify compliance across multiple workloads from a single platform.

Simplifying Compliance Search for Google Workspace Environments

With this release, customers can locate, filter, and export relevant data, such as email messages and files, across their Google Workspace backups faster for audits, litigationoinvestigations. This expanded support is designed to help organizations reduce the time and costs associated with eDiscovery and support their legal and regulatory obligations.

Key features and benefits:
  • Advanced search: Quickly find relevant emails and files using keyword, phrase, and metadata searches with granular filtering controls. Run centralized searches across Gmail and Google Drive or target a specific service to narrow the scope for focused investigations.
  • Flexible export options: Export all search results or select items for legal review or external production. Utilize standardized export sets for recurring investigations to help minimize manual effort and expedite response times for future requests.
  • Centralized discovery experience: Perform discovery across Google Workspace today, with the flexibility to extend searches to Microsoft 365 and endpoint data – all from a single, centralized interface.
  • EDRM-compliant solution: Helps maintain EDRM compliance, adhering to identification, collection, and processing protocols.

Compliance search capabilities for Google Workspace are currently available in early access and are targeted for general availability in the first half of 2026.

Ready to Learn More?

ExploraCommvault Backup & Recovery for Google Workspaceorequest a personalized demoto see the new compliance search capabilities in action.

Preguntas frecuentes

Q: Why is eDiscovery important for Google Workspace data?
A: Google Workspace contains critical emails, files, and communications that are often required for legal, regulatory, and compliance matters. Efficient eDiscovery helps organizations quickly locate and produce accurate ESI while controlling costs and risk.

Q: What types of data can be searched with Commvault eDiscovery for Google Workspace?
A: The solution supports searches across Gmail and Google Drive, allowing organizations to locate relevant emails and files. Searches can be centralized across services or scoped to a specific workload for focused investigations.

Q: How do advanced search capabilities improve compliance response times?
A: Keyword, phrase, and metadata-based searches with granular filters help teams quickly narrow large data sets. This helps reduce manual effort and enable faster responses to audits, litigation, and investigations.

Q: What export options are available for legal and compliance teams?
A: Users can export all search results or select specific items for review or external production. Standardized export sets can be reused for recurring matters, enabling more consistent and efficient workflows.

Q: How does this fit into a broader, multi-platform compliance strategy?
A: Commvault provides a centralized discovery experience that spans Google Workspace, Microsoft 365, and endpoint data. This unified approach helps enable organizations to manage compliance across multiple workloads from a single interface.

Q6: When will compliance search for Google Workspace be generally available?
A: The capabilities are currently available in early access and are targeted for general availability in the first half of 2026.Katharine Colucci is a Product Marketing Manager at Commvault.


Blogs relacionados

More related posts


Abstract-city-in-the-clouds-Crocus_PPT

Commvault Expands Collaboration with Google Cloud to Help Strengthen Enterprise Protection and Cyber Resilience

Read more about Commvault Expands Collaboration with Google Cloud to Help Strengthen Enterprise Protection and Cyber Resilience

Puntos Clave

  • La extorsión mediante deepfakes transforma el ransomware de una amenaza al acceso a los datos en una crisis de confianza, al utilizar datos robados para fabricar falsificaciones creíbles.
  • El éxito de los ataques deepfake se debe al fácil acceso a las herramientas de IA generativa, a las limitadas capacidades de detección y al hecho de que la carga de la prueba recae sobre las víctimas.
  • True defense lies in protecting and proving the authenticity of data – not chasing every fake artifact.
  • El almacenamiento inmutable y los puntos de recuperación fiables permiten a las organizaciones demostrar lo que es real cuando se encuentran bajo presión.
  • Commvault puede ayudar a reforzar la resiliencia al garantizar la integridad de los datos en los flujos de trabajo backup recuperación, lo que permite a las organizaciones recuperar rápidamente su credibilidad.

Ransomware has evolved from disrupting operations to undermining truth itself. Today’s attackers steal sensitive data and use generative AI to fabricate emails, audio, and video that appear authentic enough to deceive customers, partners, regulators, and internal teams. The challenge is no longer just restoring systems. It is proving what is real under pressure.

Cuando el robo de datos se convierte en robo de identidad

El ransomware tradicional niega el acceso a los datos.La extorsión mediante deepfakes atacala confianza en sí misma.Los atacantes sustraen información corporativa confidencial—incluidas comunicaciones de ejecutivos, grabaciones de reuniones y documentos internos— y, a continuación, utilizan IA generativa para crear falsificaciones convincentes. El audio o el vídeo falsificados pueden parecer lo suficientemente auténticos como para engañar a clientes, socios, organismos reguladores e incluso a los propios equipos internos. En estos ataques, la identidad y la autenticidad ya no se dan por sentadas. La percepción se convierte en el arma.

Por qué funciona la extorsión con deepfakes

La extorsión mediante deepfakes tiene éxito porque convergen tres realidades estructurales a la vez.

  • Generative tools are widely accessible: High-quality AI tools are readily available and require little expertise to operate.
  • Detection lags creation: Even experienced analysts struggle to distinguish sophisticated deepfakes from authentic content in real time.
  • The burden of proof shifts to the victim: Organizations must demonstrate that content is fabricated, often under extreme time pressure and public scrutiny.

Sin bases de datos fiables y un linaje de datos demostrable, la verdad se vuelve negociable.

Defensa: Proteger los datos, garantizar su privacidad y demostrar su autenticidad

La extorsión mediante deepfakes solo es eficaz cuando los atacantes tienen acceso a datos originales auténticos. Cuando esos datos están protegidos y son verificables, el contenido falsificado pierde credibilidad e influencia.

Una defensa eficaz comienza por reconocer que la extorsión mediante deepfakes no es un problema de contenido. Es unproblema de integridad de los datos. El objetivo no es perseguir cada elemento falsificado, sino permitir que las organizaciones demuestren qué es auténtico cuando más importa. Por lo tanto, la defensa debe centrarse en tres principios arquitectónicos:

  • Protect the source data: Sensitive information must be secured before it can be exfiltrated. Executive communications, recordings, and internal documents should be tightly controlled so they cannot be repurposed for manipulation.
  • Preserve data integrity: Authentic data must remain provably unchanged.El almacenamiento inmutable ayuda a evitar que las copias de seguridad y los registros históricos sean alterados, incluso por atacantes con acceso privilegiado. Esta inmutabilidad proporciona un punto de referencia fiable cuando se cuestiona la autenticidad.
  • Recover from a position of trust: When incidents occur, recovery must be based on verified, clean data. Restoring systems and records from trusted sources allows organizations to reestablish credibility quickly, rather than amplifying doubt through contaminated recovery points.

Together, these principles shift the balance of power. Instead of reacting defensively to fabricated content, organizations can retain the ability to prove authenticity, restore trust, and remove the attacker’s leverage.

Cómo Commvault respalda la veracidad y la resiliencia

Commvault ayuda a las organizaciones a reforzar su resiliencia frente a la extorsión mediante deepfakes, protegiendo la integridad de los datos en los flujos de trabajo backup, recuperación y restauración. Al mantenerpuntos de recuperación fiablesy aislar los datos limpios de cualquier manipulación, Commvault permite a las organizaciones responder a los intentos de extorsión con pruebas en lugar de incertidumbre. Commvault ayuda a las organizaciones a:

  • Protect authoritative data sources so authentic records remain available when credibility is challenged.
  • Isolate puntos de recuperación fiablespara evitar que la manipulación se extienda por todos los entornos.
  • Restore systems and data from verified sources without reintroducing uncertainty.
  • Re-establish operational and reputational trust as AI-enabled attacks scale.

Esto permite a las organizaciones responder con decisión ante el escrutinio público, utilizando datos fiables para orientar sus acciones en lugar de reaccionar a la defensiva ante narrativas inventadas.

Reflexión final

La extorsión mediante deepfakes no es solo un problema de ciberseguridad. Es un desafío a la propia verdad. Las organizaciones que no pueden demostrar la autenticidad de sus propios datos corren el riesgo de perder la confianza cuando el escrutinio es mayor. En esos momentos, la duda se propaga más rápido que los hechos. Al diseñar la ciberresiliencia en torno a datos protegidos y verificables y una recuperación fiable, las organizaciones pueden ayudar a conservar la capacidad de demostrar lo que es real y responder con decisión bajo presión.

Preguntas frecuentes

Q: What is deepfake extortion, and how does it differ from traditional ransomware?
A: Traditional ransomware denies access to data, while deepfake extortion manipulates trust. Attackers steal sensitive information and use generative AI to create fake but convincing content, such as videos or emails, that exploit public perception.

Q: Why are deepfake attacks so effective?
A: They work because advanced generative AI tools are widely available, detection technologies lag behind creation, and organizations must prove that fabricated content is false – often under intense time pressure.

Q: How can organizations defend against deepfake extortion?
A: Defense should focus on protecting the integrity and authenticity of source data. This includes securing sensitive data, maintaining immutable backups, and verifying that recovery processes rely only on verified, clean data.

Q: What role does Commvault play in combating deepfake extortion?
A: Commvault helps maintain puntos de recuperación fiables, isolate clean data from manipulation, and enable organizations to respond confidently with verified information instead of speculation.

Q: Why is data integrity critical during a deepfake crisis?
A: When false content circulates, organizations quickly must prove what is real. Immutable and verifiable data provides the evidence needed to restore trust, counter manipulation, and maintain credibility under scrutiny.

Q: What’s the key takeaway for business leaders?
A: Deepfake extortion isn’t just a cybersecurity issue – it’s a truth crisis. Building cyber resilience around protected, provable data allows organizations to respond decisively and maintain trust when it matters most.

Chris DiRado is Principal, Product Experience, at Commvault.

Blogs relacionados

Un enfoque multicapa de la ciberresiliencia

Dominar la inmutabilidad, el Air-Gapping y la confianza cero para una recuperación de aplicaciones Cloud sin rival

Hacer frente al ransomware a escala mundial

Por qué la Cleanroom Recovery y las pruebas cibernéticas son fundamentales para la ciberresiliencia

More related posts


Cyber Resilience

Read more about Cyber Resilience

Cyber Recovery

Read more about Cyber Recovery
CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Puntos Clave

  • Los bucles de fuga de datos surgen cuando la información confidencial introducida en las interacciones con la IA se conserva, recupera y refuerza con el tiempo.
  • Estos bucles son difíciles de detectar porque cada paso parece un comportamiento normal del sistema en lugar de una violación de seguridad tradicional.
  • La inyección rápida, la recuperación excesiva y la retención excesiva son los tres mecanismos principales que permiten la fuga de datos impulsada por la IA.
  • Una seguridad eficaz basada en la IA requiere integrar la contención, el privilegio mínimo y la verificación continua directamente en el diseño de la interacción.
  • Las capacidades de protección, aislamiento y recuperación rápida ayudan a las organizaciones a limitar el alcance de los daños cuando se produce una exposición no deseada.

El mayor riesgo de la IA no es lo que dicen los grandes modelos lingüísticos, sino lo que recuerdan. Una sola clave API copiada, un registro de cliente o un documento interno pegado en un indicador pueden persistir silenciosamente, reaparecer y propagarse mucho más allá de su contexto original. Cada indicación, recuperación y respuesta en un sistema de IA crea la posibilidad de una exposición involuntaria de datos. Cada solicitud, recuperación y respuesta en un sistema de IA crea la posibilidad de una exposición involuntaria de datos. Las credenciales, la propiedad intelectual, la información de identificación personal y los datos de los clientes pueden introducirse en los flujos de trabajo de IA sin intención maliciosa. Con el tiempo, estas exposiciones se acumulan, formando bucles de retroalimentación invisibles de riesgo hasta que la exposición se generaliza. A diferencia de una violación tradicional, los bucles de fuga de datos rara vez se manifiestan. Crecen de forma gradual, interacción tras interacción, hasta que la información confidencial se dispersa por sistemas, usuarios y salidas que nunca debían haberla visto.

Los bucles de fuga de datos siguen un patrón sencillo. Los datos confidenciales se introducen en una interacción con la IA, se almacenan o se integran en el sistema, se recuperan posteriormente en un contexto no deseado y se refuerzan con cada uso posterior. Dado que cada paso parece un comportamiento normal del sistema, el bucle suele pasar desapercibido hasta que la exposición se generaliza.

Cuando la inteligencia genera filtraciones

Las organizaciones adoptan la IA generativa para acelerar la productividad, automatizar las decisiones y mejorar la experiencia de los clientes. El reto no radica en la intención, sino en la arquitectura. Los sistemas de IA están diseñados para recopilar, recuperar y contextualizar información. Cuando las medidas de seguridad son insuficientes, fragmentos de datos confidenciales introducidos durante una interacción pueden aparecer más tarde en respuestas que no guardan relación con ella. Cada uso refuerza el siguiente, creando un ciclo autosostenido de exposición.

La arquitectura de los bucles de fuga de datos

La fuga de datos en los sistemas de IA suele producirse a través de tres mecanismos interconectados:

  • Prompt injection (intentional or accidental): Users knowingly or unknowingly include sensitive data in prompts, such as passwords, customer records, or proprietary information, which the system processes and may retain.
  • Over-broad retrieval: AI systems retrieve information from data sources they should not access due to weak permissions or insufficient context filtering.
  • Excessive retention: Interaction histories, embeddings, and logs are stored longer or more broadly than necessary, allowing sensitive data to persist and resurface.

En conjunto, estos mecanismos forman bucles de retroalimentación en los que cada interacción aumenta la exposición acumulativa.

Defensa en el diseño de interacción con IA

La hipótesis de diseño más segura es que cualquier información proporcionada a un sistema de IA puede ser conservada, reutilizada o divulgada. Esta mentalidad cambia radicalmente la forma en que deben protegerse los sistemas de IA. La protección debe integrarse en el diseño de la interacción, en lugar de aplicarse después de que se produzca la exposición. La seguridad en los sistemas de IA parte de la premisa de que la exposición es posible, lo que convierte la contención, el privilegio mínimo y la verificación continua en requisitos fundamentales del diseño. En la práctica, esto significa:

  • Aplicación delos principios de «confianza ceroa todas las interacciones con la IA.
  • Verificar y limitar el acceso a los datos en cada etapa del manejo rápido, la recuperación y la generación de respuestas.
  • Minimizar los permisos en las solicitudes, las fuentes de recuperación y las capas de almacenamiento.
  • Aplicar la autorización sensible al contexto en los procesos de recuperación en el momento de la consulta, en lugar de basarse en permisos estáticos definidos fuera del flujo de trabajo de IA.
  • Diseñar sistemas para contener la exposición en lugar de asumir que la prevención por sí sola es suficiente.

Este enfoque transforma la seguridad de la IA, pasando de una limpieza reactiva a una resiliencia proactiva.

El papel de Commvault

Commvault ayuda a las organizaciones a proteger los datos que alimentan los sistemas de IA, incluidos los datos de entrenamiento, las fuentes de recuperación y las rutas de recuperación, antes, durante y después de la interacción. Al proporcionar protección, aislamiento y capacidades de recuperación rápida, Commvault permite a las organizacioneslimitar el alcancede la exposición no deseada y restaurar entornos de IA a partir de fuentes de datos fiables. Con Commvault, las empresas pueden ayudar a:

Cuando se combina con controles de acceso a datos muy precisos, las organizaciones pueden innovar con la IA sin crear bucles de riesgo compuestos.

Reflexión final

Los ciclos de fuga de datos representan uno de los riesgos más sutiles y peligrosos en la adopción de la IA. No parecen ataques, pero debilitan la seguridad de forma continua. Al tratar cada interacción con la IA como una posible exposición e integrar la protección, el aislamiento y Recovery en las arquitecturas de IA, las organizaciones pueden ampliar el uso de la IA al tiempo que ayudan a preservar la confianza.

Preguntas frecuentes

Q: What is a data leakage loop in AI systems?
A: A data leakage loop occurs when sensitive data is introduced into an AI interaction, stored or embedded, later retrieved in an unintended context, and reinforced through repeated use. Over time, this creates a self-sustaining cycle of exposure that can spread across systems and users.

Q: Why are data leakage loops harder to detect than traditional breaches?
A: Unlike conventional breaches, data leakage loops do not trigger clear alerts or single points of failure. They grow gradually through normal-looking interactions, making exposure visible only after it has already spread widely.

Q: How does prompt injection contribute to data leakage?
A: Prompt injection occurs when users accidentally or intentionally include sensitive information in prompts. If safeguards are weak, that data can be processed, retained, or reused by the system beyond its original context.

Q: What role does AI system architecture play in preventing leakage?
A: Architecture determines how data is ingested, retrieved, stored, and reused. Designing AI systems with los principios de «confianza cero, least-privilege, and context-aware authorization helps contain exposure instead of relying solely on prevention.

Q: How can organizations reduce risk without slowing AI adoption?
A: Organizations can reduce risk by embedding security directly into AI interaction design and planning for containment and recovery. This approach enables innovation while limiting cumulative exposure as AI usage scales.

Q: How does Commvault support protection against data leakage loops?
A: Commvault helps protect the data that fuels AI systems by providing copias de seguridad inmutables, isolation, and rapid recovery. These capabilities help enable organizations to limit the impact of unintended exposure and restore trusted AI environments quickly.

Chris DiRado is Principal, Product Experience, at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The board meeting started with a simple question: “Are we ready for the next disruption?”

I gave them an honest answer: “That depends on which disruption we’re talking about.”

Because here’s the reality every CIO knows but doesn’t always say out loud: Readiness isn’t a checkbox. It’s not something you achieve once with a great recovery plan or a perfectly executed disaster recovery test. Readiness is a muscle you build, test, and rebuild constantly as the threat landscape shifts beneath your feet.

That’s why we created the Readiverse. Not another content library. Not another vendor resource hub. It’s a space where CIOs, CISOs, and technology leaders can get the intelligence they need to help them stay ready – whether that means anticipating the next ransomware variant, navigating AI governance challenges, or simply having a straight answer when the board asks, “Are we protected?”

Dos tipos de preparación

In my role, I need two things that rarely live in the same place:

Strategic insight for the boardroom: Intelligence briefs that analyze emerging threats through a business impact lens. Quick-hit perspectives from executives who’ve been in your chair – 60-second Bold Takes on what matters now. Conversaciones entre pares with other CIOs who’ve navigated market disruptions and transformation challenges.

Practical guidance for implementation: evaluaciones de Readinesspara comparar su nivel de madurez. Guías de cumplimiento normativo que ayudan a relacionar los requisitos con las capacidades.Talleres de Recovery y experiencia práctica that sharpen your team’s ability to respond when it matters most.

The Readiverse brings both together. Because you can’t lead from the boardroom without understanding implementation realities. And you can’t build resilient systems without connecting them to business outcomes.

«Ready. Or Not».

That’s the choice we face every day as technology leaders. We can be ready – with tested plans, trained teams, and intelligent defenses. Or we can be caught off-guard when disruption arrives.

That’s why we’re launching our new, six-part podcast series, «Ready. Or Not»., on the Readiverse. Our host, comedian Nathan Macintosh, and his guests cut through the AI hype and cybersecurity complexity with humor and straight talk. Check out our first episode – —«IA: los agentes del bien se enfrentan a los agentes del mal – with guest Reid Blackman, founder and CEO of AI risk consultancy Virtue.

Más allá del ruido

The Readiverse exists to give you the intelligence, perspective, and practical guidance you need to build resilience that works – not just resilience that sounds good in a slide deck.

Because the board will keep asking if we’re ready. And we owe them – and ourselves – an honest, confident answer. Explore the Readiverse, and we’ll stay ready together.

Ha Hoang is Chief Information Officer at Commvault.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Belgium-based xyzt.ai was founded to help customers gain insight from their location data. Read on to hear why the company chose Clumio, a Commvault company following its acquisition in 2024, to reduce AWS backup costs and significantly improve recovery times.


Q: Lida, can you start by telling us what xyzt.ai does?

Lida: We are a cloud-based, no-code analytics platform that helps customers turn massive volumes of sensor, IoT, and mobility data into meaningful insights. We process billions of records and make it easy for users to visualize patterns, identify anomalies, and make data-driven decisions. Our customers span maritime, mobility, smart cities, and connectivity – anyone who needs to understand location-based behavior at scale.

Q: As a growing startup, how did backups fit into your early strategy?

Lida: In the beginning, AWS-native backups worked well for us. They were simple, integrated, and aligned with our cloud-first architecture. Unfortunately, over time, as our data grew, our AWS backup bill grew with it. It wasn’t dramatic at first, but every year the cost kept climbing.

Q: At what point did rising AWS backup costs become something you needed to solve?

Lida: After about five years of steady growth, the trend was impossible to ignore. Our costs were increasing year over year simply because we were scaling our data footprint. That’s when we realized we needed a more sustainable, predictable option.

Q: What led you to evaluate Clumio?

Lida: Initially, we were looking purely for cost reduction. Once we saw theClumio demo, we realized the value was much broader. Compliance, recovery, data isolation, pricing predictability – those were all important features Clumio provided.

Q: How would you describe your onboarding experience?

Lida: Surprisingly fast. We expected a time-consuming migration, but it was incredibly smooth. We had our first backup running within 30 minutes. That’s not something you expect when switching a core infrastructure component.

Q: Many organizations worry not just about backup costs but also how quickly they can recover. How has recovery performance changed since moving to Clumio?

Lida: Recovery speed is one of the areas where we saw the biggest improvement. With AWS-native tools, restoring large datasets could take hours – sometimes longer – because recoveries were tied to the time it took to fully rehydrate data back into our AWS environment. That lag was a real challenge when we needed fast access for troubleshooting or when customers required immediate data validation.

With Clumio, the experience is dramatically different. The Instant Access feature lets us mount backups in minutes without waiting for full restores. That means our team can start working with the data almost immediately, whether it’s for verification, investigation, or full-scale recovery.

The time savings are enormous – it’s not just faster, it fundamentally changes how quickly we can respond to issues. For a real-time analytics platform like ours, that makes Clumio far more effective than AWS-native options.

Q: Let’s talk results. What impact did Clumio have once you were up and running?

Lida: The most immediate impact with Clumio was cost savings. Using AWS Storage Lens, we confirmed that backups through Clumio were 66.7% cheaper than what we were paying previously. That validation came quickly, and it accelerated our internal approval to move forward.

We also gained stronger resilience by storing backups outside our main AWS environment, which improved our security and compliance posture.

Q: What advice would you share with other AWS-native startups evaluating their backup strategy, and how does Clumio fit into your long-term plans?

Lida: I would tell other startups not to be intimidated by the idea of switching backup providers. The migration was much easier than we expected, and the payoff was immediate.

If your AWS costs are climbing or your compliance requirements are evolving, it’s absolutely worth exploring alternatives. Data protection is central to our business, so we need solutions that scale with us without introducing unpredictable cost spikes – and Clumiogives us that confidence.

Cara Peterson is Voice of the Customer Manager at Commvault.

More related posts


GSI

The Importance of Cyber Resilience in a Cloud-First World

Read more about The Importance of Cyber Resilience in a Cloud-First World
Thumbnail_Blog_Clumio-Tech-2025

Restore only what matters: Clumio Backtrack for DynamoDB

Read more about Restore only what matters: Clumio Backtrack for DynamoDB

Clumio

Read more about Clumio

New Yorkers don’t settle. They expect the fastest service, the toughest infrastructure, and the boldest ideas. So it’s no shock that when it comes to data security, their expectations soar.

But here’s the twist: según una reciente encuesta encargada por Commvault of more than 1,000 New Yorkers, consumers hold businesses to uncompromising security standards, even as many admit they don’t follow those same practices themselves.

This isn’t just an interesting quirk. It’s a signal about the future of trust, resilience, and loyalty.

Dos normas, una ciudad

The survey makes one thing clear: In New York, trust isn’t given – it’s earned. And it’s earned through action.

Most respondents said they would stop using, or seriously consider leaving, a company after a breach. Many already have. They reward businesses that prove they take data protection seriously, not just talk about it.

Yet, while they demand resilience from brands, their own habits tell a different story. Password reuse? Still common. Public Wi-Fi? Still tempting. Even with rising awareness and firsthand experience of cyber incidents, inconsistent behaviors persist.

Is that hypocrisy? No. It’s human nature.

People want safety, but they also want convenience, speed, and simplicity. And when those collide, personal cyber hygiene often slips.

Businesses don’t have that luxury.

Por qué esta brecha es un mandato de liderazgo

The takeaway isn’t to judge consumers; it’s to understand them. Consumers can take steps to protect themselves (and many do), but they can’t single-handedly defend against sophisticated, AI-enabled threats. Nor should they have to.

That’s where the expectation gap becomes a leadership mandate. Cyber resilience is a shared responsibility, but businesses must lead. And leadership shows up in three ways:

  • Protect before the breach: Build strong defenses, zero-trust controls, and unified resilience platforms that keep pace with evolving threats.
  • Respond fast when things go wrong: Consumers judge a breach not just by its occurrence, but by how quickly and effectively yourecuperarte.
  • Communicate with transparency: Silence erodes trust faster than bad news. Honesty wins.

La alineación de estos elementos refuerza la confianza de los consumidores.

Nueva York como señal nacional

Las tendencias comienzan en Nueva York. Las expectativas se cristalizan aquí. La opinión pública oscila con fuerza aquí. Si los neoyorquinos indican que la confianza es un factor primordial a la hora de elegir una marca, las empresas de todo el país deberían prestar atención. Lo que comienza en un mercado importante rara vez se queda ahí. Las expectativas en materia de seguridad no hacen más que intensificarse. Y en la era de la IA, el coste de perder la confianza es más elevado que nunca.

La resiliencia es el nuevo programa de fidelización

For years, brands have poured billions into personalization and convenience. But today’s research suggests something different is rising to the top: Consumers stay loyal to businesses they believe will protect and recuperarte their data, not just collect it.

Seguridad, resilience, and trustworthiness aren’t just back-office concerns anymore. They’re front-of-brand differentiators that shape purchasing decisions, referrals, and long-term relationships.

And in a season when people are traveling, shopping, and accessing sensitive information on the go, often across unsecured networks, the stakes couldn’t be higher.

El momento de liderar

Consumers have clear demands: People know what they expect, what they’ll tolerate, and what they won’t. And they’re watching you closely.

For businesses, the opportunity is profound: Invest in resilience today and earn loyalty tomorrow. Because when it comes to cybersecurity, consumers don’t just want to feel protected, they want to be protected.

The companies that deliver on that promise will define the next era of trust.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Puntos Clave

  • Arlie Data Sense ayuda a convertir datos de red dispersos (registros, auditorías, historiales de trabajos) en resúmenes claros y prácticos con sugerencias de seguimiento y consultas de formato libre.
  • New root-cause analysis helps scan failures, spots anomalies, and delivers plain-language diagnostics with recommended next steps – no manual log-diving required.
  • Los Video Bytes en Arlie Responses te llevan al momento exacto de los vídeos largos que responden a tu pregunta, lo que te ayuda a resolver los problemas más rápidamente.
  • Entre bastidores, Arlie coordina ETL, el enmascaramiento de PII y los agentes de análisis para ayudar a generar información contextual sobre la que puedes actuar rápidamente.
  • Arlie y su biblioteca de agentes están disponibles en Commvault SaaS una implementación por fases, lo que te permite estar a la par con las implementaciones de software de Commvault.

IT teams are under pressure to do more with less. You’re expected to spot risks early and optimize performance while juggling growing infrastructure and managing thousands of daily backup events. Generating insights from this constant stream of activity across platforms can be incredibly difficult.

This allows vulnerabilities to quietly creep in, waiting to expand into a major issue. Your dashboard says green. Backups seem to be running. But behind the scenes, something’s building: a silent timeout, a log full of subtle warnings, a spike in retries you didn’t notice. By the time a backup admin spots it, it’s already an incident.

The fact is, modern IT environments don’t fail loudly – they fail subtly. And most of the time, the data that could have warned you is already there. It’s just buried in audit trails, scattered across consoles, or trapped in a 40-minute training video.

This is where Arlie really shines. Arlie isn’t just an AI assistant – it’s the intelligent, unified interface designed to help find, understand, and resolve issues faster. Arlie orchestrates advanced backend workflows (agents) that help interpret data, identify anomalies, and generate insights – and then communicates the findings to you through a simple, conversational experience.

With Arlie Data Sense and Video Bytes in Responses, Arlie brings context, clarity, and speed to every interaction – without the hunting. Let’s take a look at what’s new.

Análisis de datos de red: de la sobrecarga de datos a la comprensión de los datos

Modern environments generate an overwhelming amount of data‌: ‌logs, alerts, warnings, and more. On the Commvault platform, these manifest as audit trails and job histories, with hundreds or even thousands of events occurring every day.

Businesses often don’t know where to begin when analyzing their environments. Backup admins are tasked with making sense of this flood, manually scanning through sprawling rows of data across multiple consoles just to understand what’s happening. And with so many actions being logged every minute, it’s easy to miss early warning signs that could escalate into larger issues.

That’s where Arlie Data Sense and its grid data analysis capability come in. It ingests your platform data and distills it into clear, actionable summaries. Instead of forcing teams to scroll through thousands of rows, Arlie Data Sense identifies the most relevant information, delivers those summaries, and highlights what’s actionable in a clear, conversational way. Users can expect:

  • A highlighted executive summary tailored to the user’s environment.
  • Preguntas de seguimiento sugeridas para ayudar a explorar cuestiones emergentes.
  • La capacidad de formular preguntas abiertas para realizar un análisis más profundo.

What’s more, Arlie Data Sense highlights ransomware protection-related events and major changes, proactively surfacing insights that help users stay ahead of potential risks.

However, behind the scenes is where the magic truly happens. Arlie orchestrates multiple backend workflows – retrieving data from Commvault, performing ETL and PII masking, and leveraging analysis agents to generate insights. Arlie’s reasoning and knowledge augmentation capabilities then transform this into actionable intelligence for the user.

With a simple click of a button, backup admins can derive key insights that highlight the exact points needed. Essentially, this allows you to converse with your platform’s data and gain a much clearer understanding of where the system stands in real time.

It’s not just alerting; ‌it’s contextual understanding. No more digging through logs. No more endless tab-hopping. It’s a smarter, faster way to help you monitor system health, troubleshoot issues, and understand your risk landscape. This kind of insight drastically improves efficiency, especially for lean teams managing complex environments‌, ‌allowing them to focus on what truly moves the needle.

Análisis de causas raíz: convertir registros sin procesar en respuestas en tiempo real

Reading logs is no one’s idea of fun. Yet buried in those logs are critical clues: ‌why something failed, where the system is strained, and what’s likely to break next. Given the monotonous nature of scouring through large volumes of log data for answers, many teams struggle to diagnose job failures.

Arlie Data Sense and its root-cause analysis capability do the detective work. It scans job failures, identifies root causes, spots anomalies, and generates clear, human-readable explanations – all without manual log interpretation.

Integrated directly into the Send Log Files workflow and Command Center, the agent processes log files to deliver detailed diagnostics along with potential resolutions. Arlie then communicates those findings and recommendations to users, providing clarity and saving valuable troubleshooting time.

Let’s say a job has failed intermittently over the past week. Instead of manually combing through five different logs, Arlie Data Sense can help flag recurring timeouts linked to a specific virtual machine (VM). Or, if backups are running slower than usual, it can help identify the underlying issue.

So, whether you’re managing a handful of backup jobs or orchestrating across hundreds of environments, Arlie helps you cut through the noise and act faster by presenting the right insights at the right time.

Ever found the perfect video that promises to answer your question‌, only to realize it’s 30 minutes long? The exact answer you’re looking for could be 20 seconds or 20 whole minutes into the video, and you have no idea where it’s actually buried. Even after finding this video, locating your answer could be a tedious, time-consuming endeavor.

With Video Bytes in Arlie Responses, that frustration is gone.

Now, when Arlie knows there’s helpful information available within Documentación or the Readiverse, it doesn’t just share the link‌ – ‌it pinpoints the exact moment in the video that answers your question. Just ask something like “How can I reduce my VM costs?” and Arlie will jump straight to the timestamp where that topic is addressed‌ – ‌say, Minute 12 of a 30-minute walkthrough.

This enhancement means that you don’t have to rely strictly on Documentación or lengthy videos to resolve your issues. It’s a smarter, more efficient, and highly focused approach that gives you exactly what you need.

De respuestas a acciones: Arlie, evolucionado para ti

These exciting new capabilities mark a new chapter in Arlie’s journey, transforming it from being an AI assistant that helps to one that understands. Whether it’s generating key summaries or diagnosing failures through Arlie Data Sense or jumping to exactly what you need with Video Bytes, Arlie is AI designed specifically for you.

In a world where IT complexity is only growing, the real edge lies in proactive, contextual intelligence. With Arlie, you don’t just fix issues faster – you prevent them from happening. With minimal user input, Arlie allows you to see more, do more, and be more.

Ahora disponible en Commvault SaaS

Commvault’s AI capabilities – including Arlie and its biblioteca de agentes – are now available in Commvault SaaS. This brings feature parity with Commvault software deployments, giving SaaS customers the same intelligent, AI-enabled experience. This brings feature parity with Commvault software deployments, giving SaaS customers the same intelligent, AI-enabled experience.

These capabilities are rolling out in phases, and you’ll begin seeing them appear in your SaaS environment in the coming weeks.

With these enhancements, Arlie brings the future of intelligent, contextual resilience directly into your hands – across both Commvault software and SaaS. Get ready for faster insights, fewer surprises, and a more connected, proactive experience – all with Arlie at the center.

If you’re using Commvault software, you can enable Arlie today by following the instructions in our Documentación.

If you’re using Commvault SaaS and would like to enable these features early, please contact your Commvault representative.

FAQs

Q: What exactly is Arlie, and how is it different from a typical chatbot?
A: Arlie is a unified, conversational interface that orchestrates backend workflows –ingesting platform data, running analyses, and returning concise, actionable guidance – so you can move from “searching” to “solving.”

Q: How does the grid data analysis feature help me day to day?
A: Instead of sifting through thousands of rows across consoles, Arlie Data Sense highlights the most relevant signals, summarizes them for your environment, and proposes next questions to dig deeper, reducing noise and accelerating decisions.

Q: What problems does the root-cause analysis feature tackle?
A: It analyzes failures and anomalies across logs to pinpoint likely causes – like recurring timeouts tied to a specific VM – and offers human-readable explanations with potential resolutions, saving significant troubleshooting time.

Q: How do Video Bytes in Arlie Responses speed up learning and support?
A: When a relevant video exists, Arlie links directly to the precise timestamp that answers your query, eliminating the need to scrub through lengthy recordings to find the right segment.

Q: Where can I access these capabilities, and when will I see them?
A: Arlie and its agents are available in Commvault SaaS with feature parity to software deployments, and the enhancements are rolling out in phases over the coming weeks; contact Commvault to enable early access.

Q: How does this tie into resilience and business continuity efforts?
A: Proactive insight and faster root-cause analysis complement disaster recovery programs by helping teams act before minor issues escalate – supporting broader goals of resilience and continuity highlighted in industry cyber and disaster recovery practices.


Teja Medasani is Principal Product Manager, AI, and Mrityunjay Upadhyay is Director, Development, at Commvault.


Blogs relacionados

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The threat of disruption – from ransomware attacks to natural disasters – has never been greater. For businesses, downtime isn’t just an inconvenience; it’s a direct hit to revenue, reputation, and customer trust. This reality has pushed cyber la resiliencia to the forefront of IT strategy, demanding solutions that not only protect data but also maintain its continuous availability.

HPE and Commvaultare deepening their longstanding collaboration to help address this critical need. By offering HPE Zerto Software with the Commvault Cloud platform, these two industry leaders are delivering a powerful, unified solution for providing advanced cyber la resiliencia, data protection, and disaster recovery across enterprise hybrid cloud environments.

A Leader in Continuous Data Protection 

We’re proud to announce that the HPE Zerto Software from Commvault solution is now generally available (GA) – ready for organizations everywhere. HPE Zerto Software from Commvault is a leading solution for data la resilienciaand disaster recovery, designed to protect data and applications across multiple on-premises and cloud environments. By providing continuous data protection, HPE Zerto Software delivers near-zero data loss and downtime, enabling rapid recovery from ransomware attacks, disasters, and other disruptions.

Key features:

  • Real-time encryption to enable ransomware la resiliencia.
  • Disaster recovery for virtualized infrastructures and cloud environments, including on-premises, public clouds (AWS, Azure), and hybrid environments. Protect workloads across different environments and cloud providers, creating a comprehensive disaster recovery solution.
  • Workload mobility delivered by simple automation and orchestration of failover, failover tests, and recovery, making it suited for cloud migrations and workload mobility.
  • Cyber la resiliencia with a combination of regular data protection, real-time encryption detection, and immutable data recovery data.
  • Scalability and reliability with features like near-synchronous replication that can reduce recovery times significantly.

Why Commvault and HPE Zerto?

Each customer has different needs and requirements, and there is no one-size-fits-all solution. Among the factors to consider are the workload types, the size and scale of the environment, the desired recovery point objective and recovery time objective, and the cost of the solution.

Commvault is focused on delivering end-to-end solutions that not only address the operational la resiliencia and disaster recovery needs of our customers, but also enable cyber readiness and recovery, governance and compliance, and rapid rebuilding of cloud native applications.

HPE Zerto Software from Commvault is a direct reflection of this commitment. HPE Zerto fits well within Commvault’s Autonomous Recovery offering, providing customers regular replication and operational la resiliencia for most critical virtualized workloads that cannot afford any downtime.

Amplifying Our Strengths

This offering is a testament to the deep, strategic relationship between HPE and Commvault. We amplify each other’s portfolio strengths, creating a synergy that enhances the overall value and effectiveness of our solutions. And what we jointly offer to our customers goes beyond just data protection; it’s the confidence that comes from knowing your operations are set up to be resilient and ready to face the uncertainties of the digital age.

To learn more about early access to HPE Zerto offering from Commvault, please reach out to your account team.

Ready to Get Started?

The GA launch of HPE Zerto Software from Commvault means now is the time to act – don’t wait. Schedule a demo with your Commvault account team.

More related posts


Thumbnail_Blog_HPE-Zerta-Software-2025

HPE Zerto Software from Commvault: Enhancing Data Resilience and Disaster Recovery

Read more about HPE Zerto Software from Commvault: Enhancing Data Resilience and Disaster Recovery

Puntos Clave

  • El ransomware refleja el ciclo de vida de un huracán: las primeras alertas suelen ignorarse, el impacto es paralizante y la recuperación coordinada es vital.
  • Los sistemas de identidad (Directorio Activo y Entra ID) suelen ser las primeras víctimas; sin ellos, la recuperación de datos y el acceso se paralizan.
  • The cost of unpreparedness is high – weeks of downtime and seven-figure losses – making identity-centric resilience a business imperative.
  • La preparación debe incluir copias de seguridad limpias, inmutables y aisladas de AD/Entra ID, además de simulacros periódicos de recuperación completa del bosque.
  • A practical blueprint – assess, protect, isolate, recover, evolve – enables faster, cleaner restoration of data, identity, and trust.

Ransomware has become the digital equivalent of a hurricane – powerful, unpredictable, and capable of wiping out years of progress in a single strike. Like natural disasters, cyber disasters are no longer if events, but when events. The question every organization must answer is not “Can we prevent the storm?” but “Will we survive and recover when it hits?”

This paper explores the parallels between ransomware and hurricanes, with a special focus on la resiliencia de la identidad – including Directorio Activo(AD) yMicrosoft Entra ID. These identity systems are often the first casualties of a ransomware event. When identity is compromised, recovery stalls – just as losing your address and keys after a hurricane leaves you locked out of your own home.

1. El paralelismo entre las tormentas y los ciberataques

Hurricane Lifecycle
Ransomware Lifecycle
Shared Lesson
Formation: Warm waters and unstable air pressure form the perfect storm. Exposure: Unpatched systems, weak credentials, and flat networks create ideal attack conditions. Los cimientos débiles invitan al desastre.
Warning: Meteorologists issue alerts days in advance. Alerts: Security Information and Event Management, Endpoint Detection and Response, and threat intelligence show early warning signs – often ignored. Detectar sin actuar es negar.
Landfall: The hurricane makes impact – power lines fall, flooding begins, and communications fail. Detonation: Malware encrypts systems, disables security tools, and shuts down AD. Ambos provocan una parálisis operativa total.
Response: First responders triage, reroute power, and rescue survivors. Response: Incident response teams isolate affected systems, assess backups, and begin recovery procedures . La velocidad, la coordinación y la claridad definen el éxito.
Recovery: Homes are rebuilt, infrastructure restored, and new defenses added. Recovery: Clean data and identity are restored, enabling business continuity. Recovery must include identity – not just data.

2. El costo oculto de la pérdida de identidad

When a hurricane destroys your home, you can’t just rebuild walls – you need new keys, insurance, and documents to reclaim ownership. In a ransomware event, the same is true: Without AD or Entra ID, you can’t re-enter your own network.

Identity is the “address” of your digital home – lose it, and you’re stranded outside your own infrastructure.

3. El costo de la falta de preparación

Cuando llegan los huracanes, las comunidades que no están preparadas se enfrentan a pérdidas catastróficas. Cuando el ransomware ataca entornos desprotegidos, los resultados son igualmente devastadores:

Unprepared organizations struggle not only to restore data but also to rebuild trust chains between systems, domains, and users – often forcing a complete forest rebuild that takes weeks or months.

4. Lecciones aprendidas de la tormenta: cómo desarrollar la resiliencia cibernética y de identidad

A. La preparación es prevención

  • Exporta y valida periódicamente las copias de seguridad del estado del sistema AD y las configuraciones de Entra ID.
  • Implementa el acceso basado en roles y la gestión de identidades privilegiadas para limitar el radio de acción.
  • Almacena copias limpias e inmutables de los esquemas AD locales y Entra ID en una bóveda segura y aislada.
  • Realizarsimulacros de recuperación forestalque simulen reconstrucciones completas mediante compostaje aeróbico.

B. Resistir el impacto

  • Segmentar la infraestructura de identidad y limitar las rutas de replicación.
  • Utiliza las directivas de acceso condicional y fuerza de autenticación en Entra ID para aplicar la protección adaptativa.
  • Aplica los principios de confianza cero para contener el movimiento lateral y la escalada de privilegios.

C. Recupera con confianza

  • Commvault full forest recovery helps automate the end-to-end rebuild of AD forests – restoring DCs, trusts, and configurations from clean, immutable backups.
  • Entra ID Protection se integra con los flujos de trabajo de recuperación para que cloud , las políticas de autenticación multifactor y la configuración de acceso condicional se restauren de forma sincronizada.
  • Automated validation helps verify there’s no reinfection and no cross-contamination of credentials.

5. El plan de resiliencia: del desastre a la continuidad

  • Assess: Identify your “digital coastline” – the systems and identities that define business continuity.
  • Protect: Harden your identity and data perimeter through zero trust and ongoing validation.
  • Isolate: Maintain immutable, air-gapped copies of AD, Entra ID, and critical data.
  • Recover: Use orchestrated tools like Commvault’s full forest recovery to restore identity and access rapidly.
  • Evolve: Update and retest your plan with every new patch, policy, or platform integration.

6. Perspectiva de Commvault: Recuperación más rápida. Recuperación limpia. Recuperación de la identidad.

Conla recuperación completa del bosque para AD y la protección integrada Entra ID, Commvault helps enable organizations to restore on-prem and cloud data and identities with integrity, speed, and confidence after a ransomware incident.

A hurricane tests the strength of your walls. Ransomware tests the strength of your resilience. You cannot stop every storm – natural or digital – but you can decide whether it destroys or defines you.

Preguntas frecuentes

Q: What makes identity loss so disruptive during ransomware recovery?
A: If AD or Entra ID is compromised, organizations can’t authenticate, authorize, or re-establish trust across systems – effectively locking themselves out of their own environment. Attackers often target domain controllers and trust relationships, so recovery must start with clean identity restoration before broader services can come back online.

Q: How big is the downtime and cost risk?
A: The paper cites typical ransomware downtime measured in weeks and total incident costs in the seven-figure range, with identity systems among top targets. These impacts compound when teams lack forest-level recovery capabilities or clean, immutable backups of identity configurations.

Q: What preparation steps most effectively reduce impact?
A: Regularly export and validate AD system-state and Entra ID configurations; apply role-based access and privileged identity management; keep immutable, air-gapped copies of identity schemas; and run full-forest recovery exercises to validate speed and coordination under pressure.

Q: How should recovery be orchestrated after an attack?
A: Start by isolating affected systems and pivot immediately to identity restoration from clean, immutable backups, then rebuild domain controllers, trusts, and policies in sync with cloud identity settings. Automated validation helps confirm a clean state and prevents credential cross-contamination during bring-up.

Q: What does a resilience blueprint look like in practice?
A: Follow five steps: Assess critical “digital coastline,” protect with Zero Trust and continuous validation, isolate with immutable air-gapped copies, recover with orchestrated full-forest workflows, and evolve by testing after every change in patches, policies, or platform integrations.

Jerry Carlson is Field CTO at Commvault.


Blogs relacionados

More related posts


Thumbnail_Blog-Ransomware-and-Hurricane-2025

Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

Read more about Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

University of Illinois Chicago (UIC) is home to more than 34,000 studentsy13,000 facultyystaff. Technology Solutions, UIC’s central IT organization, is responsible for ensuring the resilience of research, clinical,yadministrative systems.

We spoke with Dean Dang, Director of Enterprise ApplicationsyServices, about UIC’s data protection journeyyhow Commvault helps the university safeguard mission-critical operations.

 

Q: Can you start by introducing yourselfygiving us a sense of UIC’s missionywhat drives your IT strategy?

Dean: My name is Dean Dang,yI serve as the Director of Enterprise ApplicationsyServices within Technology Solutions. We support the university’s administrativeyacademic functions, aligning IT with UIC’s mission: to provide the broadest access to the highest levels of educational, research,yclinical excellence. Our commitment to access, vitality, empowerment,ycreativity is our strength.

 

Q: Before onboarding Commvault, what were the biggest data protectionyresilience challenges UIC was up against?

Dean: Our legacy backup system, Spectrum Protect, had accumulated years of technical debt. Recovery was painfully slow — restoring large file servers could take weeks. We also dealt with decentralized IT management across 20+ departments, inconsistent backup policies, inefficient tape storage,yno cloud options. The risks of data lossydowntime were too high for a university of our size.

 

Q: When it came time to modernize, what stood out about Commvault that made it the right fit for UIC?

Dean: We’d known Commvault for over a decadeytrusted it for Directorio ActivoyExchange backups. When we evaluated options, Commvault stood out. The ability to takeVM snapshots without server agents was huge. Even more important was the multi-tenant model. It let us provide departmental autonomy while maintaining centralized governanceysupport — exactly what higher ed needs.

 

Q: What changes have you seen since implementing Commvault,yhow has it elevated UIC’s cyber resilience?

Dean: With Commvault, we do nightly backups with deduplicationysynthetic fulls. That reduces storage demandyspeeds up restores. Departments get their own “tenants” to manage backups, but we still enforce policiesyprovide support. All backups are encryptedycan be stored on-prem or in the cloud.

We also use Air Gap Protect for immutable copiesyCleanroom Recovery for safe recovery testing. This setup means we can recover mission-critical systems in under 8 hours — compared to days or weeks before.

 

Q: If you were talking to other higher-ed IT leaders, what top lessons or best practices would you share about building cyber resilience?

Dean:

  1. Enforce multifactor authentication everywhere, especially admin accounts. Everyone can be phished.
  2. Build a pragmatic, team-driven DR plan. Don’t try to solve everything at once — build consensusyclarity.
  3. Test nightly backups. Make them immutable, air-gapped,yvalidated so you know you can restore when it matters.

 

Q: How do you communicate cyber risks to non-technical leaders?

Dean: We translate risk into business terms. How many hours of downtime? What does that cost in productivity, reputation,ycompliance? We use “what if” scenarios, dashboards,yregular updates on metrics like backup healthyrestore times. When leaders see the financialymission impact, the case for resilience is clear.

 

Q: Looking ahead, how does Commvault fit into UIC’s long-term strategy?

Dean: UIC is hybrid — on-campus, cloud,ySaaS. Commvault covers all of it, from VMsydatabases to M365yeven emerging AI workloads. With 95%+ deduplicationytiered storage, we keep costs under control. And with anomaly detection, automation,ycleanroom testing, we’re preparing for a future where downtime is measured in hours, not days.

Read more about the University of Illinois of Chicago’s data protection journey here.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The psychologist Abraham Maslow famously said that if the only tool you have is a hammer, you tend to see every problem as a nail. And everywhere you look these days, companies are wielding AI like a hammer, hoping it can solve all their pressing business problems: “How can we use AI? How can we sell AI? How can we make money on AI?”

But here’s the thing – if you’re starting with those questions, you’re starting with a broken assumption. The right question isn’t “How do we use/sell/make a fortune with AI?” The right question is “What problems are we trying to solve?”

¿Qué problema estás resolviendo?

Technology should make us more capable of doing uniquely human work, not replace our capacity to think, create, and connect with each other. The approach of starting with the tool instead of the problem is why we’re seeing many AI implementations stall. Companies are throwing technology at problems they haven’t properly defined or understood.
The approach I recommend to any leader considering AI: Start by listing your actual problems. Not theoretical problems, not problems you think you should have, but the real pain points keeping your teams from working fast. Then ask: What tools do I have that can help solve these problems? AI might be one of those tools. It makes sense to explore AI solutions for tedious, repeatable, manual tasks. You likely can identify those opportunities in your organization easily.
But let’s say your employee engagement is suffering, and people have expressed needing better support during difficult times. You want human connection and emotional intelligence here, not algorithmic responses. Starting with the problem helps reveal the appropriate solution.

¿Deberíamos eliminar el elemento humano?

Today, AI excels at automating repetitive tasks – the digital equivalent of assembly line work. If your backup administrators are turning the same widgets over and over, or your data entry teams are focused on purely laborious spreadsheet work, AI absolutely can help. But I believe relationship building, creative problem-solving, and complex decision-making require human judgment, intuition, and contextual understanding that no algorithm today can yet replicate.
At Commvault, we’re committed to the desarrollo y la implementación éticos de la IA. We’ve employed it for tasks like turning complex regulatory documents into succinct summaries or helping create targeted versions of content. Saving this time for employees to focus on more value-added activities. None of this work happens without careful human oversight.
The companies I see succeeding understand this distinction. They use AI to eliminate tedious tasks so workers can focus on what humans do best: nuanced decision-making, building trust, navigating complex stakeholder relationships, and thinking through problems that don’t have clear precedents.

Un marco para la adopción inteligente de la IA

Antes de implementar cualquier solución de IA, los equipos directivos deben plantearse las siguientes preguntas:

  1. What specific problem are we solving? Be concrete. “We want to be more efficient” isn’t specific enough.Try: “We want to automate X.”
  2. Why is this problem worth solving? What’s the real business impact?
  3. Where do we need human judgment to remain in the loop? Identify the decision points, beyond just high-risk scenarios, that demand wisdom, not just intelligence.
  4. How will we measure success? Not just adoption rates, but actual problem resolution.
  5. Revisit the conversation. Successful AI adoption is not a point-in-time measurement.

Más información enPrincipios rectores de la IA responsable.

El camino a seguir

Dedica tiempo a establecer procedimientos para el tratamiento de datos, la protección de la privacidad y la autoridad en la toma de decisiones.¿Quién controla qué información se introduce en los sistemas de IA? What data absolutely cannot be uploaded to external AI platforms? How do you prevent customer data from being used to train models?

When you put information into an AI system, you may be sharing it not only with that vendor, but also with its cloud providers, sub-processors, and others in its data supply chain. A secret known by more than three people isn’t a secret anymore – so be careful before you hand yours to dozens of entities.
Learn more about Commvault’s approach at Principios de la Inteligencia Artificial responsable.
Danielle Sheer is Chief Trust Officer at Commvault.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

We are in the most consequential moment of change in our industry, with the widespread adoption of AI reshaping how enterprises operate, how data flows, and how decisions are made.This introduces new challenges and vulnerabilities for you to manage. Like the explosive growth of data; the evolving governance requirements for human and non-human identities; and new threats to AI-oriented identities, supply chains, and models.To make matters worse, the pressure is on you and your teams to enable your business to embrace AI with data that’s distributed and fragmented across clouds, applications, and endpoints. All of which introduces business risk while increasing the fragility of your AI systems.In anticipation of this evolution, Commvault has been broadening its industry-leading resilience focus to help you to secure data at source; to control identity access; and predictably and cleanly recover following an inevitable cyberattack or disruption.We call it ResOps, or resilience operations. It’s not a product – it’s a new operational approach that enables you to actively manage resilience across increasingly complex emerging AI environments.As you know, Commvault always has been obsessed with solving our customers’ most significant resilience challenges with elegant and innovative solutions. And today, we are taking it even further with the introduction of Commvault Cloud Unity – our next-gen platform to enable ResOps.The platform was built from the ground up to help unify previously disparate data security, identity, and recovery processes across today’s workloads and tomorrow’s emerging AI stacks. It no longer matters where your data lives – if it’s on-prem, cloud-bound, cloud-borne, or an emerging AI workload.In fact, Commvault has the broadest workload support. Across the multi-cloud alone, we cover more than 160 regions and over 200 public cloud services. And we simply manage it all through a single policy engine and a unified pane of glass.None of this would have been possible without our team’s foresight, engineering prowess, and commitment to continuously innovating to solve our customers’ hardest challenges.Want to learn more about ResOps and Commvault Cloud Unity? Haz clic aquí para ver Commvault’s SHIFT event on demand, and read our whitepaper ResOps: el futuro de los negocios resilientes en la era de la IA.


Sanjay Mirchandani is President & Chief Executive Officer of Commvault.

More related posts


Thumbnail_Blog-SHIFT-Sanjay-2025-Linkedin

Re-envisioning Resilience for the Age of AI

Read more about Re-envisioning Resilience for the Age of AI

Puntos Clave

  • Streamlined process: Simplifies recovery through enhanced threat detection and validation.
  • Integrated experience: One simple process from threat identification to production recovery.
  • Readiness: Configure, plan, and test cyber recovery plans to uncover gaps.
  • Rapid detection and validation: Quickly identify clean points and validate recovery.
  • Confident recovery: Helps organizations confidently recover clean data, apps, and infrastructure.

In today’s landscape of relentless cyber threats, organizations are grappling with an unprecedented challenge: maintaining business continuity in the face of potential data loss and system compromise. The recent surge in sophisticated ransomware attacks has underscored the critical need for estrategias sólidas de ciberresilienciaque vayan más allá de los métodos tradicionales backup recuperación.Commvault Cloud Cleanroom Recoveryintroduce un enfoque innovador para este desafío. Al crear un entorno bajo demanda, seguro y aislado, las organizaciones pueden probar sus planes de recuperación, llevar a cabo investigaciones forenses exhaustivas y ejecutar recuperaciones de producción sin correr el riesgo de interrumpir aún más sus operaciones.

Cyber Recovery + análisis forense = recuperación óptima

Ransomware threats targeting backup systems have become increasingly common, highlighting the vulnerabilities in conventional recovery processes. It’s no longer sufficient to simply have a recovery plan in place; organizations must rigorously test and validate their strategies to prepare to withstand real-world cyberattacks.

Cleanroom Recovery can help organizations seeking to maintain uninterrupted operations amid disruption. Probar los planes de recuperación cibernéticaes una parte fundamental para lograr una verdadera resiliencia cibernética. Al facilitar una recuperación rápida y fiable, minimizar el tiempo de inactividad y agilizar los procesos, las pruebas desempeñan un papel vital para reforzar la continuidad del negocio.

A medida que las organizaciones siguen dando prioridad a los planes sólidos de recuperación cibernética, no se puede subestimar la importancia de realizar pruebas rigurosas. Con protocolos de prueba eficaces, las organizaciones pueden identificar vulnerabilidades y verificar que sus estrategias de recuperación sigan estando en consonancia con las amenazas cibernéticas en constante evolución. Una vez que una organización ha configurado el análisis periódico de malware de todas las copias de seguridad y ha probado sus planes, puede realizar análisis forenses para identificar la causa raíz de un ataque e investigar los sistemas afectados. Estos dos casos de uso aumentan la confianza en la ejecución de una recuperación óptima.

What’s New in Cleanroom Recovery?

Building on its foundation, the latest Cleanroom Recovery innovations are introducing significant enhancements that further strengthen cyber recovery capabilities. These advancements deliver new capabilities that help organizations protect their critical infrastructure and data.

Recent and upcoming developments have bolstered Cleanroom Recovery’s capabilities in orchestration, security, and scalability, including early access to:

  • Cleanroom creation automation: Automate cleanroom deployment, cross hypervisor recovery and threat scanning inside the cleanroom to remove manual intervention​. (Generally Available)
  • Runbook experience: Ability to create multiple runbooks for critical assets for different use cases. Runbooks provide step-by-step execution playbooks with optional manual steps.​ (Early Access)
  • Expanded workload support: You can recover Active Directory forest along with VMs and files into a cleanroom for end-to-end application validation. ​(Early Access)
  • On-premises deployment capabilities: You now can use Cleanroom Recovery to recover critical application into an isolated recovery environment in an on-premises data center using air-gapped Hyperscale X (Early Access)

These advancements illustrate a continued focus on expanding the features, capabilities, and scale of Cleanroom Recovery. This is the next phase in Cleanroom Recovery’s evolution. The solution helps provide customers with enhanced efficiency, scalability, and adaptability, with the flexibility to deploy isolated cleanroom in cloud and on-premises.

Cleanroom Recovery helps enable customers to effortlessly spin up automated cleanrooms with streamlined runbooks and features threat scanning capabilities for comprehensive threat detection and recovery.

With this new evolution, organizations will be enabled to quickly and safely test their cyber recovery plans, validate applications, and execute a confident cyber recovery. Commvault is delivering one integrated experience from identifying threats to production recovery.

Preguntas frecuentes

Q: What is Cleanroom Recovery, and why is it important?
A: Cleanroom Recovery is a secure, isolated environment that enables organizations to test recovery plans and conduct forensic analysis without risking production systems. This helps organizations maintain continuous business operations and improve cyber resilience against modern ransomware threats.

Q: How does Cleanroom Recovery enhance cyber recovery readiness?
A: By automating cleanroom creation to conduct recovery testing and enabling forensic investigation, it helps organizations validate their recovery strategies, uncover vulnerabilities, and execute faster, more confident recoveries after cyber incidents.

Q: What are the main new features in the Cleanroom Recovery release?
A: Key innovations include automated cleanroom deployment, new runbook capabilities for multiple recovery scenarios, support for Active Directory recovery, and the ability to deploy in on-premises data centers with air-gapped Hyperscale X.

Q: How does Cleanroom Recovery improve security during recovery operations?
A: It isolates the recovery environment, scans for threats pre-/post-recovery, provides controlled orchestration, and helps reduce the risk of reinfection or unauthorized access during recovery.

Q: Can Cleanroom Recovery be deployed both on-premises and in the cloud?
A: Yes, organizations now can deploy Cleanroom Recovery in both cloud and on-premises environments, providing flexibility for hybrid infrastructures and diverse security requirements.

Q: Who benefits most from Cleanroom Recovery?
A: Enterprises seeking to strengthen their cyber resilience, particularly those facing ransomware risks or complex recovery needs, gain value from its automation, scalability, and integrated testing capabilities.Toussaint Brock is a Product Marketing Manager at Commvault.


Blogs relacionados

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements