Skip to content

Guía sobre el Backup and Recovery en la nube: desde la detección de amenazas hasta la Recovery completa

Descubre cómo funcionan las copias de seguridad y la Recovery en la nube para ayudar a proteger los datos sanos, comprobar la Readiness para la Recovery y restablecer las operaciones empresariales tras un ataque de ransomware o un incidente cibernético.


El proceso ideal de Backup and Recovery en la nube comienza con la detección de amenazas como el ransomware, los accesos sospechosos o la actividad anómala de los datos. A continuación, las organizaciones pueden obtener copias de seguridad limpias e inmutables; validar los puntos de recuperación no afectados; y aislar los sistemas comprometidos. Una vez verificadas, las aplicaciones y los datos críticos pueden restaurarse mediante procesos de Recovery automatizados, lo que ayuda a minimizar el tiempo de inactividad, reducir la pérdida de datos y restablecer las operaciones empresariales de forma rápida y segura.


La resiliencia cibernética se mide cada vez más en función de lo que ocurre una vez que los atacantes logran acceder al sistema. Las organizaciones han realizado importantes inversiones en prevención, detección y respuesta, pero el ransomware, el aprovechamiento de vulnerabilidades, el uso indebido de credenciales, las configuraciones erróneas en la nube y las brechas de seguridad en terceros siguen afectando a las operaciones.

Para muchos equipos, el reto de la recuperación ya no se limita a saber si existen copias de seguridad. Se trata de saber si esas copias de seguridad están en buen estado, protegidas, validadas y listas para restaurar los servicios críticos cuando ya no se pueda confiar en los sistemas de producción.

Esa distinción es importante porque los ciberataques siguen generando tanto riesgos para los datos como interrupciones operativas. Según el informe de VerizonInforme sobre investigaciones de filtraciones de datos de 2026, el ransomware estuvo presente en el 48 % de las filtraciones, lo que supone un aumento respecto al 44 % del año anterior. El informe también reveló que la explotación de vulnerabilidades se convirtió en el vector de acceso inicial más habitual para las filtraciones, con un aumento hasta el 31 %, mientras que el uso indebido de credenciales descendió al 13 %.

Las medidas de Backup and Recovery en la nube deben abarcar todo el proceso, desde la detección hasta la restauración. Esto comienza con la identificación de actividades sospechosas antes de que se restauren los datos comprometidos. Continúa con puntos de Recovery protegidos e inmutables que ofrecen a los equipos opciones de Recovery viables cuando ya no se puede confiar en los sistemas de producción.

A partir de ahí, las organizaciones necesitan una forma de comprobar qué puntos de recuperación están en buen estado y restaurar las cargas de trabajo críticas en el orden correcto. El resultado es una estrategia de Recovery que ayuda a los equipos a pasar de la respuesta ante incidentes a la restauración operativa con mayor confianza.

 


¿Por qué Backup and Recovery en la nube constituyen una estrategia de ciberresiliencia?

Traditional backup strategies were designed to help organizations recover from hardware failures, accidental deletion, and localized outages. Those use cases still matter, but today’s recovery requirements are broader.

Los ciberataques pueden afectar al mismo tiempo a las cargas de trabajo de producción, los sistemas de identidad, las configuraciones en la nube, las aplicaciones SaaS y los entornos de copia de seguridad. Cuando eso ocurre, la recuperación no consiste solo en restaurar una copia de los datos. Se trata de determinar en qué sistemas se puede confiar, qué puntos de recuperación siguen intactos y qué servicios deben restablecerse en primer lugar.

Por eso,Backup and Recovery en la nubese han convertido en una parte fundamental de la ciberresiliencia. Una estrategia moderna debe ayudar a los equipos a detectar actividades sospechosas, proteger los datos de Recovery, validar la integridad de las copias de seguridad y restaurar las operaciones críticas siguiendo una secuencia controlada. También debe facilitar la realización de pruebas periódicas, ya que un plan de Recovery que no se haya puesto a prueba puede no funcionar como se espera durante un incidente real.

Esto marca un cambio: se pasa de considerar la copia de seguridad como una póliza de seguro a verla como una capacidad operativa de Recovery. Las copias almacenadas siguen siendo importantes, pero solo son una parte de la ecuación de Recovery. Los equipos también necesitan tener la seguridad de que los datos de Recovery no han sido alterados, de que se han probado los flujos de trabajo de restauración y de que la empresa sabe qué servicios deben restablecerse primero.

Backup and Recovery resulta más fácil de entender cuando se considera como un ciclo de vida. Las cinco etapas que se indican a continuación muestran cómo las organizaciones pueden pasar de la detección temprana de amenazas a una Recovery validada y a la mejora de la resiliencia a largo plazo.


Fase 1: Detectar las amenazas antes de que se extienda el riesgo de Recovery

Recovery comienza antes de que se restablezcan los sistemas. En un incidente cibernético, la primera prioridad es determinar si la actividad sospechosa ha afectado a los datos de producción, a los datos de copia de seguridad o a ambos.

Si los equipos realizan la restauración desde un punto de recuperación comprometido, podrían reintroducir en el entorno archivos dañados, rastros de malware o cambios no autorizados. Ese riesgo convierte la detección de amenazas en una parte importante de Backup and Recovery en la nube, y no solo en una cuestión de operaciones de seguridad.

Las estrategias de Recovery modernas deben incluir visibilidad de la actividad anómala en todas las cargas de trabajo, entornos de copia de seguridad y puntos de Recovery. Es posible que los equipos tengan que investigar señales como:

  • Comportamiento inusual en el cifrado
  • Picos repentinos de eliminaciones
  • Cambios inesperados en los privilegios
  • Patrones de copia de seguridad anómalos
  • Indicadores de malware

Estas señales pueden ayudar a los equipos a comprender hasta dónde puede haberse extendido un ataque y qué datos pueden requerir una revisión adicional antes de su restauración.

Timing is another essential factor. Microsoft’s El Informe de Defensa Digital 2025de Microsoft reveló que la mayoría de los ataques investigados por su Equipo de Detección y Respuesta (DART) tenían tiempos de permanencia cortos, lo que significa que los equipos de recuperación podrían no disponer de semanas para comprender el alcance total de la intrusión antes de que los atacantes se desplacen lateralmente, accedan a datos confidenciales, interfieran en los servicios o intenten afectar a los sistemas de copia de seguridad. El contexto de la detección puede ayudar a los equipos a evitar tratar todos los puntos de recuperación como igualmente fiables.

El 59 % de los ataques investigados por Microsoft DART tuvieron una duración de siete días o menos, lo que hace que la detección temprana sea fundamental para las decisiones de Recovery.
Fuente:Informe de Defensa Digital de Microsoft 2025

Threat detection doesn’t eliminate recovery risk on its own. It helps create a more informed recovery process. When suspicious activity is identified early, organizations can isolate affected systems, investigate impacted data, and avoid restoring recovery points that may reintroduce the same threat.

Esto proporciona a los equipos de seguridad, TI y Recovery un punto de partida más claro para la siguiente fase: proteger los puntos de recuperación no infectados antes de que los atacantes puedan alterarlos o eliminarlos.


Fase 2: Proteger los puntos de recuperación limpios frente a los ataques

En un incidente cibernético, las copias de seguridad no son solo copias almacenadas. Forman parte del proceso de Recovery, lo que significa que los atacantes pueden intentar alterarlas. Si los datos de las copias de seguridad se modifican, se cifran, se borran o se hace imposible acceder a ellos, la organización podría perder una de sus mejores opciones para restablecer las operaciones sin tener que depender de sistemas de producción comprometidos.

That’s why borrar puntos de recuperaciónSe necesita una protección por capas. Un almacenamiento de copias de seguridad inmutable e indeleble puede ayudar a conservar los datos durante un periodo de retención definido. Las copias externas o aisladas contribuyen a establecer una separación con respecto al entorno de producción. El cifrado, los controles de acceso y los permisos basados en roles ayudan a limitar quién puede acceder o modificar la configuración de las copias de seguridad. En conjunto, estas medidas de seguridad dificultan que los atacantes puedan interferir en los datos que los equipos pueden necesitar más durante la Recovery.

El objetivo es preservar la libertad de elección en materia de Recovery. El informe de Verizon de 2026 reveló queEl 69 % de las víctimas de ransomwarede su base de datos no pagaron el rescate, lo que supone un aumento respecto al 65 % del año anterior. El informe también señala que la mediana de los pagos de rescate siguió disminuyendo, lo que atribuye, en parte, a la mejora de las medidas defensivas y al aumento de la resiliencia de las víctimas. Los equipos necesitan copias de seguridad limpias que puedan utilizar realmente, por lo que pagar un rescate no es la única forma de reanudar la actividad empresarial.

La conocida regla de copia de seguridad «3-2-1» sigue constituyendo una base útil: conservar tres copias de los datos, en dos soportes o plataformas diferentes, con al menos una copia almacenada fuera de las instalaciones o aislada. Las estrategias modernas de Backup and Recovery en la nube suelen ampliar ese modelo con almacenamiento inmutable, patrones de aislamiento físico, retención basada en políticas y copias replicadas en entornos en la nube o híbridos.

Al contar con puntos de recuperación protegidos, los equipos pueden reducir sus opciones de restauración y pasar a la fase de validación con una visión más clara de lo que está listo para recuperarse.


Etapa 3: Comprobar qué copias de seguridad están listas para restaurarse

Disponer de copias de seguridad no es lo mismo que estar preparado para la recuperación. Antes de que los equipos restauren los sistemas de producción, deben saber qué puntos de recuperación son utilizables, qué cargas de trabajo se han visto afectadas y qué dependencias deben recuperarse junto con ellas.

Una copia de seguridad reciente puede contener los datos empresariales más actuales, pero también puede incluir archivos dañados, cambios no autorizados o rastros de malware. Una copia de seguridad más antigua puede estar más limpia, pero puede provocar una mayor pérdida de datos. La validación ayuda a los equipos a tomar esa decisión basándose en pruebas, en lugar de en conjeturas.

Esa labor comienza con la delimitación del alcance del incidente. Los equipos de seguridad y de TI deben comprender cuándo comenzó la actividad sospechosa, qué sistemas se vieron afectados y si se vieron afectados los servicios de identidad, las bases de datos, los recursos compartidos de archivos, las aplicaciones SaaS o las configuraciones en la nube.

También deben confirmar si el punto de recuperación es compatible con la aplicación en su conjunto, y no solo con los datos que la sustentan. La restauración de una base de datos, por ejemplo, puede depender de que los servidores de aplicaciones, los permisos, las claves de cifrado, las rutas de red y los servicios de identidad estén disponibles en el estado adecuado.

Los entornos de Recovery aislados pueden ayudar a los equipos a comprobar esas condiciones antes de restaurar el entorno de producción. En un entorno controlado, los equipos pueden, de forma segura:

  • Analizar los puntos de Recovery seleccionados.
  • Revisar los cambios en los archivos.
  • Confirmar el inicio de la aplicación.
  • Probar el acceso de los usuarios.
  • Comprobar si los sistemas dependientes se comportan según lo previsto.

Validacióntambién debe servir de base para la secuencia de Recovery. Es posible que los equipos tengan que restaurar primero los servicios de identidad, luego la infraestructura básica, a continuación las aplicaciones críticas para la misión y, por último, las cargas de trabajo de apoyo.

Al probar los puntos de recuperación antes de la restauración, pueden reducir sus opciones y decidir qué sistemas están listos para volver a ponerse en marcha, cuáles necesitan una revisión más detallada y cuáles deben permanecer aislados hasta que se comprenda mejor el riesgo.

La siguiente etapa es aquella en la que esa decisión se traduce en acción: restaurar los sistemas, las aplicaciones y los datos que la empresa necesita en primer lugar.


Fase 4: Restablecer las operaciones críticas en el orden adecuado

A restore plan starts with the organization’s minimum viable operating state. That means identifying the people, systems, applications, data, and communication channels the business needs to function at a basic level during a disruption.

Para algunas organizaciones, esto puede empezar por los servicios de identidad y las comunicaciones con los empleados. Para otras, puede dar prioridad a las aplicaciones de atención al cliente, los sistemas de pago, los sistemas clínicos, las operaciones de fabricación o las plataformas logísticas. El orden debe reflejar el impacto en el negocio, no solo la conveniencia técnica.

Dependencies are where many recovery plans become more complicated. An application may be listed as “critical,” but it still depends on identity, DNS, network connectivity, databases, storage, encryption keys, APIs, and monitoring. If those pieces are not restored in the right state, the application may come back online but remain unusable. That is why recovery teams need dependency mapping before an incident, not during one.

Los manuales de procedimientos y los flujos de trabajo orquestados ayudan a convertir esas decisiones en pasos repetibles. Permiten definir quién aprueba la restauración, qué entorno debe utilizarse, qué comprobaciones deben realizarse antes de restablecer el acceso a producción y cuándo puede volver a estar operativo el siguiente nivel de sistemas. Esto es importante cuando los equipos de seguridad, infraestructura, aplicaciones, nube y de negocio trabajan todos al mismo tiempo.

La restauración también necesita puntos de control. Tras el restablecimiento de cada carga de trabajo importante, los equipos deben confirmar que los usuarios pueden autenticarse, que los datos están disponibles, que las integraciones funcionan y que la supervisión está activa. Esas comprobaciones ayudan a detectar problemas antes de que Recovery se extienda al siguiente nivel de sistemas.

La rapidez sigue siendo importante, pero el control lo es igual de importante. Una restauración rápida puede generar más trabajo si se recuperan datos erróneos, si faltan controles de acceso o si una aplicación vuelve a estar operativa sin los sistemas que necesita para funcionar. El enfoque más sólido consiste en restaurar por fases, confirmar que cada servicio crítico funciona y, a continuación, seguir ampliando Recovery a medida que el entorno se estabiliza.


Etapa 5: Convertir las lecciones aprendidas de Recovery en una mayor continuidad

Una vez restablecidos los servicios críticos, los equipos aún deben comprender qué funcionó, qué les ralentizó y en qué aspectos el plan de Recovery no se ajustó a la realidad. Ese seguimiento es lo que convierte la Backup and Recovery en la nube en una actividad de respuesta en una práctica de resiliencia continua.

El primer paso es revisar el proceso de Recovery en sí. Los equipos deben plantearse preguntas como:

  • ¿Con qué rapidez detectaron los equipos la actividad sospechosa?
  • ¿Resultó fácil identificar los puntos de recuperación válidos?
  • ¿Qué pasos de validación llevaron más tiempo del esperado?
  • ¿En qué puntos se ralentizaron los flujos de trabajo de restauración?
  • ¿Participaron las personas adecuadas en el momento oportuno?

Estas respuestas pueden revelar deficiencias que no siempre son de carácter técnico. Una Recovery puede tener éxito y, aun así, poner de manifiesto problemas relacionados con la toma de decisiones, la comunicación, las aprobaciones o los traspasos entre equipos.

Esos hallazgos deben incorporarse directamente a la próxima versión del plan de Recovery. Si una aplicación crítica dependía de un sistema que no estaba documentado, actualiza el mapa de dependencias. Si los controles de acceso ralentizaron la restauración, aclara el proceso de aprobación. Si en las pruebas de Recovery se pasó por alto una carga de trabajo clave, añádela al próximo ejercicio. Si los responsables de la empresa carecían de visibilidad sobre lo que se había restaurado y lo que seguía fuera de línea, mejora los informes y las vías de escalado.

Las pruebas periódicas son lo que da solidez a este trabajo. Los ejercicios de simulación, las restauraciones aisladas, las pruebas de Recovery en entorno controlado y la validación de Recovery entre nubes ayudan a los equipos a detectar problemas antes de que un incidente real les obligue a aprender bajo presión. También ayudan a proporcionar a los responsables una mejor evidencia de en qué aspectos la organización está preparada y en cuáles aún le queda trabajo por hacer.

Con el tiempo, el objetivo es contar con un programa de Recovery que se perfeccione tras cada prueba y cada incidente. Los equipos estarán mejor preparados, se comprenderán mejor los pasos de Recovery y la organización dispondrá de una hoja de ruta más clara para mantener en funcionamiento las operaciones esenciales durante las interrupciones.


Cómo convertir la recuperación en la nube en resiliencia empresarial

 Cloud backup and recovery now plays a larger role than traditional data protection alone. It is the connected process of detecting recovery risk, protecting backup data, validating clean restore options, and restoring critical services when production environments can no longer be trusted.

En caso de incidente cibernético, estas actividades no pueden llevarse a cabo como etapas independientes. El contexto de la amenaza debe determinar qué copias de seguridad se revisan. La protección de las copias de seguridad debe preservar las opciones de Recovery que los equipos puedan necesitar. La validación debe determinar qué está listo para restaurarse. La restauración debe restablecer los servicios de los que depende la empresa siguiendo un orden controlado.

Una copia de seguridad en la que no se pueda confiar, que no se haya probado o que no se pueda restaurar en el momento adecuado puede no proporcionar a la empresa el resultado que necesita. Un proceso de restauración que ignore la identidad, las dependencias de las aplicaciones o las prioridades empresariales puede dejar los sistemas técnicamente recuperados, pero operativamente incompletos.

La mayor oportunidad radica en tratar la recuperación como una práctica de resiliencia continua. Eso significa probar los planes antes de que se produzca un incidente, actualizar los mapas de dependencias a medida que cambian los entornos y aprovechar cada ejercicio o evento de recuperación para mejorar la siguiente respuesta.

Las organizaciones que se recuperan más rápido no son necesariamente aquellas que cuentan con el mayor número de copias de los datos. Es imprescindible saber qué datos son utilizables, qué servicios son los más importantes y cómo restaurarlos bajo presión.

El reto consiste en que la Readiness para la recuperación sea tan operativa como la detección y la respuesta. Backup and Recovery en la nube proporciona una base práctica para esa labor cuando se abordan como un proceso continuo que va desde la detección de riesgos hasta la restauración del negocio.

Las organizaciones deben desarrollar esa capacidad para estar mejor preparadas a la hora de restaurar datos limpios, recuperar servicios críticos y mantener el negocio en marcha cuando se produzca una interrupción.

 

Acelerar una Recovery segura tras los ciberataques

Learn more about how Commvault’s data backup and recovery solutions can help organizations detect threats, recover clean data, and reduce downtime.

Preguntas frecuentes

¿Cuál es la diferencia entre la copia de seguridad en la nube y la recuperación ante desastres?

La copia de seguridad en la nube se centra en crear copias seguras de los datos para su restauración, mientras que la recuperación ante desastres se centra en restaurar aplicaciones, sistemas y operaciones empresariales tras una interrupción del servicio o un ciberataque. Juntas, contribuyen a garantizar la continuidad y la resiliencia del negocio.

¿Por qué son importantes las copias de seguridad inmutables para la resiliencia cibernética?

Las copias de seguridad inmutables e indelebles están diseñadas para evitar que los datos de las copias de seguridad sean alterados, cifrados o eliminados dentro de los parámetros de retención definidos. En combinación con Commvault AirGap y la identificación automatizada de Cleanpoint, las capacidades de copia de seguridad inmutable de Commvault ayudan a las organizaciones a estar preparadas con una fuente de recuperación verificada y limpia disponible en caso de que los sistemas de producción se vean comprometidos.

¿Qué debo buscar en una solución de Backup and Recovery en la nube?

Busca una plataforma que unifique entornos híbridos y multinube, almacenamiento inmutable, coordinación automatizada de la Recovery y gestión centralizada. Commvault Cloud está diseñada teniendo en cuenta estos requisitos, lo que ayuda a las organizaciones a proteger infraestructuras diversas al tiempo que minimiza el tiempo de inactividad durante la Recovery y la complejidad operativa.

¿Ofrece la solución de copias de seguridad de Commvault protección contra el ransomware y copias de seguridad con aislamiento físico?

Sí. Commvault ayuda a las organizaciones a reforzar su resiliencia cibernética mediante copias de seguridad inmutables, opciones de recuperación en entornos aislados, detección de amenazas, capacidades de recuperación limpia y protección contra el ransomware en varias capas, diseñadas para ayudar a reducir el riesgo de Recovery y el tiempo de inactividad.

¿Ofrece Commvault pruebas automatizadas de copias de seguridad e informes de cumplimiento normativo?

Sí. Commvault ofrece pruebas de recuperación automatizadas, validación de copias de seguridad, informes de cumplimiento normativo y una visibilidad preparada para auditorías, con el fin de ayudar a las organizaciones a verificar la capacidad de recuperación, demostrar el cumplimiento normativo y mejorar su Readiness para la recuperación.

Recursos relacionados

Vídeo

Recuperación de Ciberataques: Cómo lograr una viabilidad mínima en minutos, no en días

Cuando se producen ciberataques, cada minuto cuesta 14 000 dólares y la Recovery total lleva una media de 24 días. Pero, ¿y si pudieras alcanzar la viabilidad mínima en cuestión de minutos en lugar de días?
Vea el vídeo sobreabout Recuperación de Ciberataques: Cómo lograr una viabilidad mínima en minutos, no en días
Solución

Commvault AirGap

Ciberprotección mejorada con almacenamiento inmutable en la nube y air-gapped.
Explora la solución Acerca deCommvault AirGap

Puntos Clave 

  • La adopción de la inteligencia artificial se está acelerando, lo que contribuye a que los empleados sean más eficientes, productivos y competitivos. 
  • Las organizaciones necesitan mecanismos de gobernanza y medidas de protección para adoptar la IA de forma responsable y a gran escala. 
  • Security and productivity don’t have to compete – they can reinforce one another.  
  • AI will become one of security’s most valuable tools for managing cyber risks.  
  • La implantación de la IA funciona mejor cuando la innovación y la seguridad avanzan de la mano. 

One of the things I’ve enjoyed about the «Ready. Or Not».Lo que caracteriza a esta serie es que cada conversación se basa en la anterior. Empezamos analizando las oportunidades y los riesgos de la IA autónoma. A continuación, examinamos cómo las organizaciones pueden generar confianza a medida que la IA se va integrando en el día a día de la empresa. Este episodio aborda la siguiente pregunta lógica: ¿cómo podemos utilizar la IA de forma segura en la práctica? 

Comedian Nathan Macintosh sits down with Rinki Sethi, CISO and CSO at Upwind Security, for a conversation about what responsible AI adoption actually looks like. They cover everything from AI governance and guardrails to user experience and the growing role AI will play in cybersecurity.  

Nathan continues to ask the questions many of us are wondering. Should we be worried? How much more productive do we need to be? And can AI actually make security better?  

Mira el episodio completoen Readiverse. 

What I appreciated most about this conversation is that Rinki is genuinely excited about new technology and protecting it. She didn’t frame AI as something organizations need to worry about. Instead, she focused on encouraging businesses to move forward with confidence by putting the right guardrails in place. Here are the ideas that stayed with me. 

El impulso a la adopción de la inteligencia artificial 

One thing that becomes clear from the conversation is that many organizations aren’t only encouraging their employees to adopt AI – they’re mandating it. These companies recognize that using AI helps people solve problems more efficiently, which is essential for staying competitive. 

“Every single company has a mandate … we’ve got to use AI everywhere in the company.”

– Rinki Sethi 

La cuestión ya no es si la IA tiene cabida en el lugar de trabajo, sino si los empleados cuentan con las medidas de seguridad adecuadas para utilizarla de forma responsable. A medida que se acelera la adopción de la IA, las organizaciones necesitan normas claras sobre qué herramientas de IA pueden utilizar los empleados y cómo se protegen los datos de la empresa. 

Avance: La gobernanza de la IA

Rinki explains that governance isn’t just about protecting against new risks. It’s about creating a framework that helps employees use AI responsibly while keeping pace with evolving regulations and industry standards. 

El beneficio oculto de la productividad 

Here’s something I never thought about before. Rinki explains that AI isn’t simply helping people work faster. In many cases, it’s leaving room for the highest-performing employees to excel.  

She used software developers as an example. When AI-powered coding assistants became available, many assumed they’d only help less experienced developers. Instead, some of the best engineers began using them to move faster. They were able to solve more complex problems and spend more time on creative work rather than repetitive tasks. 

That kind of productivity is exactly why organizations are mandating AI. It doesn’t limit what people can do – it helps give them more space to focus on higher-value work. 

“You can be way more creative with how you’re doing things … cause you’re creating the space for that.”

– Rinki Sethi 

AI’s Role in Cybersecurity 

“How can AI be used to help with security and not be just looked at as a demon thing that’s here to take us out?”

– Nathan Macintosh 

When we talk about AI and security, the conversation is often focused on risk. But Rinki believes that AI will become one of cybersecurity’s greatest advantages. 

Security teams are already overwhelmed by the volume of alerts, logs, and data they need to investigate every day. Human analysts simply can’t keep up. Rather than replacing security professionals, AI assists them by filtering through massive amounts of data in seconds. This helps analysts identify false positives so they can focus on investigating real threats. 

My takeaway is that the future of cybersecurity isn’t about people versus AI – it’s about people working alongside AI to help make better decisions, respond faster, and scale their operations in ways that weren’t possible before. 

Ready for What’s Next? 

Cada episodio de«Ready. Or Not». has reminded me that the biggest AI conversations are often about people – how we adapt, how we learn, and how we build the confidence to use new technology responsibly. The real opportunity for organizations isn’t just adopting AI. It’s creating an environment where employees can use AI to work smarter, become more creative, and deliver better outcomes for the business. 

Mira el episodio completoen Readiverse. 

Preguntas frecuentes 

P: ¿Por qué las organizaciones están adoptando la IA tan rápidamente? 
R:Muchas organizaciones consideran que la inteligencia artificial es una forma de ayudar a mejorar la productividad, aumentar la eficiencia y proporcionar a los empleados más tiempo para dedicarse a tareas de mayor valor. 
P: ¿Qué es la gobernanza de la IA? 
R:La gobernanza de la IA es el conjunto de políticas, procesos y mecanismos de supervisión que ayuda a las organizaciones a adoptar la IA de forma responsable, al tiempo que gestionan los riesgos relacionados con la seguridad, la privacidad y el cumplimiento normativo. 
P: ¿Por qué es importante la experiencia del usuario para la seguridad? 
R:Los controles de seguridad que generan dificultades innecesarias suelen incitar a los usuarios a buscar soluciones alternativas. Diseñar sistemas seguros que, al mismo tiempo, sean fáciles de usar contribuye a mejorar tanto su aceptación como la protección que ofrecen. 
P: ¿Puede la IA contribuir a mejorar la ciberseguridad? 
R:La inteligencia artificial puede ayudar a los equipos de seguridad a analizar grandes cantidades de datos, lo que contribuye a reducir los falsos positivos. Esto, a su vez, ayuda a los equipos a priorizar las amenazas y a responder de forma más eficaz ante los incidentes de seguridad. 
P: ¿Debería la gente tener miedo a la IA? 
R: Rinki’s perspective is that a healthy sense of skepticism is valuable, but fear shouldn’t prevent organizations from adopting technology responsibly. Education, governance, and strong security practices can help organizations use AI with confidence. 
Q: What’s the biggest takeaway from this episode? 
R: AI adoption isn’t about choosing between innovation and security. Organizations that combine strong governance with practical security measures will be better positioned to take advantage of AI’s benefits while managing its risks. 

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Cómo Mythos y GPT-5.5-Cyber podrían cambiar la seguridad de los datos en la nube

Los modelos especializados de IA cibernética podrían acelerar la detección de vulnerabilidades y los flujos de trabajo de ataques en varias etapas. Más allá de la prevención, los equipos de seguridad de los datos en la nube necesitan mayor visibilidad, gobernanza y una Readiness sólida para la Recovery. 

Puntos clave

La IA cibernética de vanguardia reduce el tiempo que transcurre entre el descubrimiento y la actuación, lo que pone de manifiesto por qué las organizaciones necesitan una seguridad de datos en la nube que tenga en cuenta la resiliencia y se base en una Recovery limpia y en las operaciones de respuesta (ResOps). 

  • Claude Mythos y GPT-5.5-Cyber siguen siendo modelos de acceso restringido, pero ofrecen un adelanto de un futuro en el que la inteligencia artificial podrá razonar en el marco de flujos de trabajo cibernéticos complejos y acelerar tanto las operaciones de defensa como, potencialmente, las de los atacantes.
  • A medida que se reduce el tiempo que transcurre entre el descubrimiento de una vulnerabilidad y su explotación, las organizaciones necesitan una mayor visibilidad de las dependencias en la nube, los riesgos relacionados con la identidad y las vías de ataque interconectadas antes de que se produzca una interrupción.
  • Recovery ya no consiste únicamente en restaurar copias de seguridad. Las organizaciones deben definir su «empresa mínima viable», validar puntos de recuperación fiables y restaurar los sistemas críticos en el orden adecuado.
  • Las operaciones de resiliencia coordinan a los equipos de seguridad, TI y de negocio en torno a resultados de Recovery cuantificables, lo que ayuda a las organizaciones a gestionar los datos, priorizar la Recovery y restablecer operaciones fiables con mayor seguridad.

 Claude Mythos y GPT-5.5-Cyber podrían afectar a la seguridad de los datos en la nube al acelerar la detección, la comprobación y la gestión de los riesgos. Aunque su impacto aún es incierto, ponen de manifiesto la necesidad de una mayor visibilidad de los datos, una mejor gestión del acceso y una Recovery eficaz en todos los entornos de nube. 

Claude Mythos y GPT-5.5-Cyber están ofreciendo a los equipos de seguridad un avance de lo que podría suponer una IA cibernética más especializada para la seguridad de los datos en la nube. 

Ninguno de los dos modelos está ampliamente disponible, y su impacto a largo plazo sigue siendo incierto. Pero su existencia es importante porque los entornos en la nube ya son difíciles de proteger. Los datos confidenciales, los sistemas de identidad, las aplicaciones SaaS, los procesos de desarrollo, las cargas de trabajo de IA y la infraestructura de Recovery suelen depender unos de otros de formas que resultan difíciles de percibir hasta que surge algún problema. 

The UK AI Security Institute’s Evaluación de abril de 2026 of Claude Mythos Preview found significant improvement on multi-step cyber-attack simulations, including the ability to execute multi-stage attacks on vulnerable networks when explicitly directed in a controlled environment.  

La misma evaluación advertía de que sus resultados difieren de los entornos reales y no demuestran si Mythos podría atacar sistemas bien protegidos. Aun así, pone de manifiesto por qué los equipos de seguridad de datos en la nube deberían prestar atención a la tendencia actual. 

As cyber AI capabilities mature, the question is not only whether attacks get faster. It’s whether the window between discovering a weakness and exploiting it continues to shrink. When that clock compresses, cloud data security is no longer just about preventing compromise. Instead, the question shifts to whether organizations can understand risk quickly enough, govern access consistently, and recover trusted operations before disruption spreads. 

Por qué son importantes Mythos y GPT-5.5-Cyber 

La importancia de Mythos y GPT-5.5-Cyber no radica en que todas las organizaciones vayan a tener acceso a ellos de repente. Según la información pública disponible actualmente, se trata de modelos controlados y de acceso limitado. Para los equipos de seguridad de datos en la nube, su importancia radica en lo que sugieren sobre la dirección que está tomando la IA cibernética: sistemas más especializados diseñados para dar soporte a flujos de trabajo de seguridad complejos. 

Esa distinción es importante. Un asistente de IA de uso general puede ayudar a resumir alertas o a redactar un informe de incidentes. Un modelo especializado de IA cibernética es diferente. Puede estar diseñado para analizar de forma integrada vulnerabilidades, infraestructura, vías de ataque, controles defensivos y pasos de validación. En entornos autorizados, eso podría ayudar a los equipos de seguridad a probar entornos, priorizar exposiciones y reforzar la planificación de Recovery antes de que se produzca un incidente. 

Para los equipos de seguridad de datos en la nube, el impacto práctico no radica tanto en los nombres de los modelos como en el flujo de trabajo que representan. El riesgo en la nube suele provenir de las conexiones entre sistemas: una carga de trabajo mal configurada, un conjunto de datos expuesto, una identidad con permisos excesivos, una dependencia de copias de seguridad o una ruta de recuperación no probada. La IA cibernética especializada podría facilitar una evaluación más rápida de esas relaciones, especialmente en entornos de gran tamaño donde la revisión manual puede pasar por alto cómo un problema afecta a otro. 

That shift mirrors a broader change happening across cybersecurity. The challenge is becoming less about identifying individual vulnerabilities and more about understanding how interconnected systems behave under pressure. AI may soon help defenders reason across identities, cloud workloads, backups, SaaS applications, AI pipelines, and business dependencies simultaneously — revealing not just isolated risks, but how those risks combine into operational failure. 

También cambia la forma en que las organizaciones deben plantearse suPreparación. Si la IA puede ayudar a los defensores a abordar tareas cibernéticas complejas de manera más eficiente, es posible que, con el tiempo, técnicas similares influyan también en los flujos de trabajo de los atacantes. La preocupación no es solo que los ataques se vuelvan más rápidos, sino que la brecha entre encontrar una vulnerabilidad, probarla y actuar en consecuencia podría reducirse. 

Cloud data security teams now have to plan for a harder question: what happens when the same types of AI-assisted workflows that help defenders validate risk also make weak points easier to find, test, and chain together? That’s where the cloud environment itself becomes the issue. 

La IA está elevando el listón de la seguridad de los datos en la nube 

Most organizations don’t have one neat cloud environment. They have multiple clouds, SaaS platforms, data lakes, identity systems, development pipelines, backup repositories, and AI workloads that all depend on each other.  

That complexity already creates gaps: sensitive data can be overexposed, access permissions can drift, and recovery plans may not reflect how the business actually runs.  

En la práctica, esas brechas rara vez se mantienen aisladas. Un depósito de almacenamiento con datos confidenciales puede no parecer urgente por sí solo. Una cuenta de servicio con permisos excesivos puede parecer un problema de configuración rutinario. Una dependencia de Recovery no probada puede pasar desapercibida porque el sistema sigue funcionando. Pero cuando esos problemas se relacionan entre sí, pueden crear una vía que va desde la exposición hasta la interrupción del servicio. 

Attackers are well aware of these vulnerabilities. Mandiant’sInforme «M-Trends» de 2026señala que los autores de ataques de ransomware se están centrando cada vez más en la infraestructura de copias de seguridad, los servicios de identidad y los planos de gestión de la virtualización. Además, destaca cómo los atacantes utilizan tokens OAuth de larga duración, cookies de sesión, claves codificadas de forma fija y tokens de acceso personales para desplazarse entre distintos entornos. 

Ahora añadamos al panorama una IA cibernética más avanzada: si los modelos pueden ayudar…detectar vulnerabilidades más rápido, test exploitability more effectively, or connect weak signals across systems, defenders could benefit. However, attackers may eventually benefit, too—especially if similar capabilities become more accessible or are recreated elsewhere. 

22 seconds 
Median time between an initial access event and hand-off to a secondary threat group  

Source: Mandiant’s Informe «M-Trends» de 2026 

That’s¿Por qué esta conversación?can’t stop at “AI makes attacks faster.” Frontier ciber-IAcambia el ritmo de la seguridad. A medida que se reduce el tiempo que transcurre entre el descubrimiento, la validación y la explotación, cada retraso a la hora de comprender las dependencias de la nube o de preparar Recovery resulta cada vez más costoso. 

¿Cómo podría la IA cibernética de última generación cambiar la defensa en la nube? 

While the full impact of Mythos and GPT-5.5-Cyber is still unknown, they point to three practical shifts cloud data security teams should be watching. Each one comes back to the same issue: cloud data security now depends on how quickly organizations can understand risk, act on it, and recover when something goes wrong. 

Los defensores cibernéticos deben estar atentos a:

  • Rapidez:las herramientas asistidas por IA pueden ayudar a los defensores autorizados a revisar el código, clasificar las vulnerabilidades, analizar el malware, validar los parches y probar los controles más rápido de lo que permiten los flujos de trabajo tradicionales. 
  • Escala:el riesgo en la nube rara vez se limita a un solo lugar. Una vulnerabilidad en una aplicación, una identidad con permisos excesivos, un depósito de almacenamiento mal configurado y una ruta de Recovery no probada pueden convertirse en una cadena de ataque. 
  • Presión sobre la recuperación: If AI helps attackers move faster, organizations need to recover faster and cleaner. Backups alone aren’t enough if teams don’t know which data is clean, which identity systems can be trusted, or whether recovery will reintroduce compromised assets.

Para los defensores, el mayor cambio puede ser la forma en que se secuencia el trabajo. Hoy en día, muchos equipos pasan de la alerta a la investigación, de la corrección a la planificación de Recovery en pasos separados, a menudo entre equipos distintos. La IA cibernética podría comprimir ese flujo de trabajo ayudando a los equipos a pasar más rápidamente de una señal a un conjunto de acciones recomendadas para el siguiente paso. 

That doesn’t mean decisions should become automatic. It means teams may need clearer rules for when to trust a recommendation, when to escalate to a human reviewer, and when to move from investigation into recovery preparation. A model may help identify a possible attack path, but people still need to decide whether to close access, isolate a workload, preserve evidence, notify stakeholders, or prepare a clean recovery path. 

Aquí es donde el proceso cobra tanta importancia como las herramientas. La IA cibernética de última generación podría ayudar a los defensores a actuar con mayor rapidez, pero solo si los equipos cuentan con pasos de validación y planes de Recovery bien definidos. Sin esa estructura, la rapidez puede generar confusión. Con ella, los flujos de trabajo asistidos por IA podrían ayudar a los equipos a actuar antes, al tiempo que mantienen el control sobre cómo se evalúa el riesgo y cómo se toman las decisiones de Recovery. 

Por qué la Recovery limpia cobra mayor importancia a medida que los riesgos se aceleran 

When cloud risk moves faster, recovery planning has to become more precise. It’s not enough to know that backup copies exist. Teams need confidence that the data they restore is trustworthy, the recovery environment is isolated, and the systems coming back online won’t reintroduce the same threat that caused the disruption. 

Esto es importante porque los entornos en la nube estánmuy interconectados.Una identidad comprometida, un conjunto de datos dañado, una máquina virtual afectada o una carga de trabajo mal configurada pueden generar incertidumbre en múltiples servicios. Durante un incidente, es posible que los equipos tengan que determinar qué puntos de recuperación están limpios, qué dependencias deben restablecerse primero y si los datos restaurados pueden respaldar de forma segura las operaciones empresariales. 

Recovery limpia also changes the way teams think about priority. The goal isn’t necessarily restoring everything immediately. It’s restoring enough of the business to operate safely. 

Many organizations know which applications they consider “critical,” but far fewer have defined their minimum viable company: the smallest combination of identities, cloud services, data, applications, and infrastructure required to keep the business functioning during disruption. Those dependencies often become visible only when recovery is tested under realistic conditions. 

En un panorama de amenazas dominado por la IA, determinar la «empresa mínima viable» es crucial. Una detección más rápida de vulnerabilidades y un desarrollo más eficiente de las cadenas de ataque podrían ejercer mayor presión sobre los equipos de Recovery para que tomen decisiones con un alto grado de confianza en plazos muy ajustados. 

What’s more, identity systems, cloud configurations, business communications, customer-facing applications, and the data they depend on may all need to come back in a deliberate sequence — not simply according to technical priority, but according to what the business needs first to operate. 

Las organizaciones necesitan procesos de recuperación que ayuden a validar datos limpios, a llevar a cabo la recuperación de forma escalonada en entornos aislados, a proteger las dependencias críticas de identidad y a probar los planes de recuperación antes de que un incidente lo haga imprescindible. A medida que maduran las capacidades de la IA cibernética, los equipos de seguridad de datos en la nube deberían tratar la recuperación limpia como parte de la estrategia de seguridad, y no como un paso posterior a la acción. 

Desarrollar una seguridad de datos orientada a la resiliencia 

La seguridad de los datos en la nube se ha centrado a menudo en evitar la exposición: localizar datos confidenciales, clasificarlos, gestionar el acceso y reducir el riesgo. Esa labor sigue siendo importante. De hecho, cobra aún más relevancia a medida que los sistemas de IA consumen datos empresariales a través de indicaciones, sistemas de recuperación, procesos de entrenamiento, flujos de trabajo analíticos y apoyo automatizado a la toma de decisiones. 

That’s because data may move into new contexts without moving into a new system of record. A sensitive dataset might support a retrieval workflow, shape a model response, or appear in a prompt log. That makes governance less about one location and more about how data is accessed, reused, and recovered across workflows. 

Pero la prevención por sí sola no basta para la siguiente fase de la seguridad de los datos en la nube. Si la IA cibernética especializada puede ayudar a los equipos de seguridad a descubrir vulnerabilidades, probar vías de ataque y conectar señales débiles más rápidamente, entonces los programas de seguridad de datos deben tener en cuenta lo que ocurre después de que se detecte o se aproveche una exposición. La visibilidad y los controles de acceso son solo una parte del panorama. Los equipos también necesitan una vía clara hacia una Recovery fiable. 

Descubrir esa vía requiere algo más que mejores herramientas de seguridad. Requiere un modelo operativo de Recovery que alinee a los responsables de seguridad, TI y del negocio en torno a prioridades de Recovery compartidas antes de que se produzca un incidente. Cada vez más, las organizaciones describen esta disciplina como ResOps, u operaciones de resiliencia: un enfoque estructurado para hacer que la Recovery sea medible, repetible y vinculada a los resultados empresariales, en lugar de limitarse únicamente al éxito de las copias de seguridad. 

En ResOps, las organizaciones deben comprender: 

  • ¿Qué conjuntos de datos son los más críticos para las operaciones empresariales? 
  • ¿Qué identidades, servicios en la nube y flujos de trabajo de IA dependen de conjuntos de datos críticos para el negocio? 
  • ¿Están las políticas de gobernanza y acceso alineadas con el riesgo empresarial? 
  • ¿Cuál es el estado operativo mínimo viable que la organización debe restablecer en primer lugar? 
  • ¿Pueden validarse esas decisiones de Recovery antes de que se produzca un incidente, en lugar de durante el mismo? 

That’s the shift Mythos and GPT-5.5-Cyber point toward. The future of cloud data security won’t be defined by prevention alone. As cyber AI compresses the time between discovery and action, organizations will need equal confidence in how they recover. That means understanding cloud dependencies before an incident, defining the minimum viable business they need to restore, and treating recovery as an operational discipline rather than a technical afterthought. 

Mythos and GPT-5.5-Cyber matter not because every organization will use these models tomorrow, but because they reveal where cybersecurity is heading. As AI accelerates both defense and attack, the organizations that perform best won’t simply be the ones with the strongest preventive controls. They’ll be the ones that can prove they know what to recover, in what order, and how to restore trusted operations before uncertainty becomes business disruption. 

Preguntas frecuentes

¿Cuándo se pondrán a la venta estos modelos especializados?

No hay un calendario confirmado para su acceso general al público. Según la información disponible actualmente, Claude Mythos se está limitando a determinadas organizaciones a través de programas controlados, mientras que OpenAI describe GPT-5.5-Cyber como una herramienta disponible únicamente para profesionales de la seguridad que hayan superado un proceso de verificación a través de su marco «Trusted Access for Cyber».

¿Es probable que aumenten los ataques de IA?

No necesariamente. Pero sí demuestran que la IA avanzada puede dar soporte a flujos de trabajo cibernéticos más complejos, lo que significa que las organizaciones deben prepararse para ciclos más rápidos de detección, prueba y explotación.

¿Qué riesgos deberían priorizar los equipos en primer lugar?

Empieza por obtener visibilidad sobre los datos confidenciales, las rutas de acceso, las configuraciones erróneas en la nube, las dependencias de identidad y el grado de Readiness para la recuperación. Las capacidades de seguridad de datos e inteligencia artificial de Commvault pueden ayudar a los equipos a clasificar los datos, gestionar el acceso e identificar riesgos en todos los entornos en la nube. 

¿Por qué es importante Recovery para la seguridad de los datos en la nube?

Porque la prevención puede fallar. Las capacidades de ciberresiliencia de Commvault pueden ayudar a las organizaciones a identificar puntos de Recovery no afectados, validar la Recovery en entornos aislados y restaurar datos y servicios críticos sin reintroducir activos comprometidos. 

¿Ofrece Commvault detección de amenazas basada en inteligencia artificial?

Sí. Commvault puede utilizar funciones basadas en inteligencia artificial para ayudar a identificar amenazas, detectar actividades anómalas, priorizar los riesgos y acelerar la respuesta ante incidentes. En combinación con la ciberresiliencia y los flujos de trabajo de Recovery, podemos ayudar a los equipos a mejorar sus flujos de trabajo de respuesta y a recuperar datos críticos con mayor confianza.


At Commvault, we talk a lot about cyber resilience, the ability to recover from whatever challenges come your way. But for one engineer at Australian technology services provider Perfekt, it is his personal resilience that helps him succeed.

Viktor Trokhin left Ukraine when the war began, traveling through five countries before eventually reuniting with his family in Australia. He brought more than six years of ICT experience, deep technical expertise, and a determination to continue his career in tech.

Like many skilled professionals starting over in a new country, Viktor wasn’t just adapting to a new workplace. He was building expertise in new technologies, communicating in a second language, and finding his place in a different professional environment.

Marcus Rolim, Managed Services General Manager at Perfekt and Viktor’s manager, saw his potential immediately.

“Our engineering development program is built around people,” Marcus says. “We invest heavily in mentoring and creating opportunities for engineers from different backgrounds.”

Over the years, Perfekt has welcomed engineers from around 10 different countries. Rather than following a standard training path, the company focuses on each person’s strengths, providing mentoring, practical experience, and support where it’s needed most.

For Viktor, that meant building on his existing expertise while gaining experience with Commvault Cloud and cyber resilience.

As he worked with customers, Arlie – the AI assistant in Commvault Cloud – became a natural part of his daily workflow. Whether he was exploring product capabilities, troubleshooting an issue, or looking for guidance, Arlie helped him quickly find trusted information without interrupting his work.

Then came an unexpected benefit.

Because Arlie supports multiple languages, Viktor could work through complex concepts in his native language before switching to English when speaking with customers or colleagues. While this wasn’t the use case Perfekt originally envisioned, it quickly became a valuable learning advantage.

“When an engineer can explore a complex question in their own language, understand the reasoning behind the answer, and then communicate it clearly in English, it changes the learning experience,” Marcus says. “It allows their technical ability to come through without language becoming a barrier.”

Today, Viktor is an Infrastructure & Data Protection Engineer at Perfekt, supporting customers while continuing to deepen his expertise in cyber resilience.

When Viktor left Ukraine, he carried with him years of experience, deep technical expertise, and an unwavering determination to continue the career he had worked so hard to build. Today, he helps organizations strengthen their cyber resilience, drawing on the same resilience that helped him rebuild his own life.

Maybe that’s why this story resonates. Viktor’s resilience shaped his own future. Today, it helps him make a difference for others.

That’s what putting people first looks like: organizations like Perfekt investing in people, and technology like Commvault Cloud helping them thrive.

Chris DiRadoes director de Experiencia de Producto en Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

¿Cómo pueden los responsables de seguridad proteger sus datos más confidenciales?

La seguridad de los datos y de la IA permite a las organizaciones detectar, clasificar y gestionar el acceso a los datos confidenciales entre usuarios, sistemas y soluciones de IA.

Puntos Clave

Los datos son el motor de las empresas modernas, ya que ayudan a orientar las decisiones clave e impulsan las iniciativas de inteligencia artificial. Dado su valor, es fundamental conocer y proteger tus datos.

  • El 90 % de las organizaciones mantengamosdatos confidenciales almacenados en la nube que pueden ser detectados por la inteligencia artificial. Esto hace que la visibilidad de los activos de datos sea el primer paso, y el más importante, para reducir el riesgo empresarial. 
  • El 40 % de los archivos subidoen herramientas de IA generativa compartidascontieneInformación de identificación personal (PII) o datos del sector de las tarjetas de pago (PCI). Este uso indebido de datos sensibles supone un riesgo considerable para las organizaciones en lo que respecta a la privacidad y al incumplimiento de la normativa. 
  • La detección y la clasificación de datos constituyen la base de una seguridad eficaz, ya que permiten a las organizaciones identificar datos confidenciales en entornos estructurados, semiestructurados y no estructurados.
  • Overpermissive access is one of the most persistent data risks for modern businesses. With users, applications, and service accounts often retaining unnecessary access to sensitive data, the “attack surface” is expanded.
  • Para contribuir a la protección de la IA es necesario regular tanto los datos de entrenamiento como las interacciones en tiempo de ejecución. Las organizaciones deben asegurarse de que los datos sensibles no queden expuestos a través de las entradas, las salidas o el comportamiento del modelo.
  • El cumplimiento normativo depende de una base sólida de datos. Una gestión rigurosa de la clasificación y el acceso permite a las organizaciones aplicar las políticas y demostrar que ejercen control.

Sensitive data now moves across clouds, applications, and AI workflows without clear visibility — creating exposure risks that traditional security controls cannot address alone. Commvault Data and AI Security helps organizations discover and classify sensitive data, govern access for both human and machine identities, and maintain compliance with GDPR, HIPAA, and PCI DSS across the full data lifecycle.


¿Por qué la exposición de datos sensibles es la mayor brecha de seguridad?

Los datos son el combustible inestimable que impulsa a las empresas modernas. Por ello, las organizaciones han dado prioridad a realizar importantes inversiones en herramientas de seguridad sofisticadas.

However, according to Varonis’ Informe sobre el estado de la seguridad de los datos de 2025, el 90 % de las organizaciones sigue teniendo datos confidenciales expuestos en la nube. Del mismo modo, el 88 % de las organizaciones cuenta con usuarios fantasma inactivos pero con acceso habilitado.

Perothat’sNo todos.According to IBM’s Informe sobre el coste de una filtración de datos 2025, El 53 % de las organizaciones afectadas por una filtración informaron de que los datos de sus clientes se habían visto comprometidosDatos personales. EstosLas estadísticas ofrecen una imagen muy clara: aunque los datos son fundamentales para las empresas, la visibilidad y la seguridad general siguen siendo cuestiones cruciales. 

Los datos ya no se limitan a las bases de datos estructuradas. Se encuentran en archivos, correos electrónicos, plataformas en la nube, aplicaciones SaaS y dispositivos finales. Gran parte de ellos son datos no estructurados, duplicados o no gestionados, lo que dificulta su seguimiento y protección.

La IA está agravando este problema. Acerca deEl 40 % de los archivos subidos a herramientas de IA generativa contiene información confidencial, a menudo sin control ni supervisión. A medida que aumenta la adopción de la IA, también lo hace el número de sistemas e identidades que interactúan con los datos.

Sin saber qué datos existen y dónde se encuentran, las organizaciones no pueden protegerlos de forma eficaz. Esta falta de visibilidad es la raíz del problema actual de la seguridad de los datos.


¿Cuáles son los pilares de la seguridad de los datos y la IA?

Para hacer frente al reto que supone la exposición de los datos,las organizaciones necesitan un enfoque estructurado que aporte coherencia y control a la gestión de los datos. La seguridad de los datos y la IA se sustenta en tres pilares fundamentales:Descubrimiento de datos,Clasificación de datos,and Data & AI Access Governance.

Cada pilar aborda una carencia importante:

  • Discovery provides visibility into where data resides across environments. This includes structured systems such as databases,as well as semi-structured and unstructured sources that are often overlooked.
  • Classification adds context by identifying the type and sensitivity of data. It enables organizations to distinguish between operational data,sensitive personal information,financial records,intellectual property,and other high-risk categories.
  • Access governance enables organizations to verify that data is used appropriately. It defines who or what can access data,under what conditions,and with what level of control.

These three pillars do not exist independently. They create a connected system that fully covers data and AI security. Discovery identifies the complete data landscape,classification defines the appropriate sensitivity,and access governance enforces control based on that context.

This model even extends beyond human users to include machine identities such as AI models. In modern environments,these non-human identities often represent a significant portion of data access activity. Bringing these pillars together can help organizations move from fragmented security controls to a unified,policy-driven approach.


¿Cómo pueden las organizaciones detectar y clasificar los datos confidenciales?

La detección y la clasificación son fundamentales para un modelo de seguridad de datos eficaz. Sin embargo, a menudo son los aspectos más difíciles de implementar de forma eficaz.

Esto se debe a que los entornos de datos actuales están muy fragmentados. La información confidencial se encuentra dispersa en múltiples plataformas en la nube, sistemas locales, aplicaciones SaaS y dispositivos finales. Una parte significativa de estos datos es no estructurada, lo que dificulta su identificación y categorización.

Algunos de los retos más destacados son:

  • Datos ocultos que existen sin que se tenga conocimiento de ellos, sin autorización ni supervisión de seguridad.
  • Formatos inconsistentes entre datos estructurados y no estructurados.
  • El rápido crecimiento de los datos debido a la adopción de la IA, que supera el ritmo de los esfuerzos de clasificación manual.

Para hacer frente a esto, las organizaciones necesitan capacidades de detección escalables y marcos de clasificación. Una clasificación adecuada puede dar sentido a las enormes cantidades de datos existentes. Esto suele incluir categorías como la información de identificación personal (PII), la información sanitaria protegida (PHI), la normativa PCI, la propiedad intelectual y las claves y secretos.

El valor de la clasificación radica en cómo se utiliza. Una vez clasificados los datos, las organizaciones pueden aplicar de forma eficaz políticas de retención y eliminación, restringir o supervisar el acceso y habilitar el enmascaramiento o la censura de campos sensibles.

A gran escala, un enfoque maduro de detección y clasificación no solo garantiza la cobertura, sino que también ayuda a generar resultados significativos. Esto puede incluir una menor exposición, una mejor aplicación de las políticas y una reducción cuantificable del riesgo.


¿Cuáles son los principales riesgos de un acceso con privilegios excesivos?

Según un estudio deReliaQuest, el 99 % de las identidades en la nube cuentan con privilegios excesivos. En la misma línea, unestudio de 2025 del Ponemon Institutedestaca que el 61 % de las empresas estadounidenses han sufrido filtraciones de datos por parte de personal interno en los últimos dos años, con un coste medio de estos incidentes que asciende a la asombrosa cifra de 2,7 millones de dólares.

Esto demuestra que, incluso cuando las organizaciones conocen bien sus datos, el acceso sigue siendo uno de los puntos más débiles en materia de seguridad.

El acceso excesivamente permisivo se produce cuando los usuarios, las aplicaciones o las cuentas de servicio tienen más acceso a los datos del que necesitan. Este problema está muy extendido porque los controles de acceso suelen concederse de forma amplia por comodidad y rara vez se revisan.

El impacto es significativo. Un acceso excesivo aumenta la probabilidad de exposición accidental, de riesgo interno y de explotación durante una filtración.

Para abordar esto, las organizaciones deben, en primer lugar, inspeccionar minuciosamente los patrones de acceso. Esto incluye averiguar quién accede a datos confidenciales, qué sistemas o identidades están implicados y si dicho acceso se ajusta a las necesidades empresariales.

Debe prestarse especial atención a las cuentas con privilegios y a las identidades de servicio. Estas suelen tener permisos amplios y pueden acceder a grandes volúmenes de datos confidenciales en distintos sistemas.

En este contexto, una gestión eficaz de los accesos es fundamental. Para ello es necesario:

  • Alinear las políticas de acceso con la clasificación de datos.
  • Supervisar continuamente los patrones de uso.
  • Identificar y corregir las desviaciones en el acceso a lo largo del tiempo.

Al reducir los accesos innecesarios, las organizaciones contribuyen a limitar su superficie de ataque y a mejorar la protección general de los datos.


¿Cómo deberían las organizaciones gestionar los datos que utilizan los sistemas de IA?

La adopción de la IA se está extendiendo rápidamente por todas las facetas de las empresas modernas. Esto introduce un nuevo nivel de complejidad en la forma en que se accede a los datos, se procesan y se divulgan.

Los conjuntos de datos de entrenamiento suelen incluir grandes volúmenes de datos procedentes de toda la organización. Sin una clasificación y una gestión adecuadas, estos conjuntos de datos pueden contener información sensible o sujeta a normativa.

Esto genera riesgos en varias etapas:

  • Durante la preparación de los datos y el entrenamiento.
  • Cuando los modelos interactúan con datos en tiempo real.
  • A través de los resultados, que pueden revelar involuntariamente información confidencial.

Por lo tanto, la clasificación debe preceder al entrenamiento de los modelos. Esto implica validar y clasificar todos los datos utilizados en los conjuntos de datos y eliminar la información confidencial cuando sea necesario.

Del mismo modo, tras la implantación de herramientas de IA, los equipos de datos deben evaluar continuamente cómo los modelos utilizan y exponen los datos. También deben aplicar mecanismos de control adecuados, como el enmascaramiento o la supresión, cuando sea necesario.

Los sistemas de IA no deben tratarse como algo ajeno a la seguridad de los datos. Son una extensión de cómo se utilizan los datos y deben gestionarse en consecuencia. Al integrar estas capacidades de seguridad de datos e IA en el ciclo de vida más amplio del desarrollo de la IA, las organizaciones pueden contribuir a reducir el riesgo sin dejar de fomentar la innovación.


¿Cómo contribuye la clasificación de datos al cumplimiento normativo?

El cumplimiento normativo depende de la capacidad de identificar y controlar los datos sensibles. Marcos normativos como el RGPD, la HIPAA y el PCI DSS establecen requisitos específicos sobre cómo deben tratarse los datos. Sin embargo, estos requisitos no pueden aplicarse sin saber primero dónde se encuentran los datos sujetos a regulación.

Por eso fracasan los programas de cumplimiento sin una base de datos adecuada.

En tales casos, la clasificación de datos actúa como columna vertebral del cumplimiento normativo, asignando los datos a categorías reglamentarias. Permite a las organizaciones aplicar controles específicos en función de la sensibilidad de los datos y hacer cumplir políticas críticas sobre el ciclo de vida de los datos.

Esto abre un sinfín de capacidades esenciales:

  • Aplicación de políticas de conservación y supresión
  • Restricción del acceso a los datos regulados
  • Implementación de controles de privacidad cruciales

Además, simplifica los procesos de auditoría. Las organizaciones pueden demostrar dónde se encuentran los datos sensibles, cómo están protegidos y quién tiene acceso a ellos. La gobernanza del acceso refuerza aún más el cumplimiento normativo al garantizar que solo las identidades autorizadas puedan interactuar con los datos regulados.

En conjunto, la clasificación de datos y los controles de acceso redefinen el cumplimiento normativo para la era moderna, impulsada por la inteligencia artificial.


Conclusión: ¿Qué se necesita hoy en día para garantizar una seguridad eficaz de los datos y la IA?

La seguridad moderna de los datos y la IA ya no se define por defensas perimetrales o controles aislados. Requiere un enfoque continuo y unificado que conecte la visibilidad, la clasificación y la gestión del acceso a lo largo de todo el ciclo de vida de los datos.

Para hacer realidad este enfoque, las organizaciones deben, en primer lugar, comprender sus datos y localizar con exactitud dónde se encuentran. A continuación, deben controlar cómo se accede a ellos. Por último, deben asegurarse de que los sistemas de IA los utilicen de forma responsable. Estas capacidades deben funcionar de forma conjunta, no de manera independiente, para ayudar a reducir la exposición y mantener la confianza.

A medida que crecen los volúmenes de datos y se acelera la adopción de la IA, el reto no consistirá únicamente en proteger los datos, sino en demostrar dónde se encuentran los datos confidenciales, quién puede acceder a ellos y cómo están protegidos en todos los sistemas. Aquellas organizaciones que desarrollen un enfoque estructurado y basado en políticas estarán mejor posicionadas para ayudar a reducir el riesgo, cumplir con las exigencias normativas y potenciar la innovación con confianza.

Preguntas frecuentes

¿Qué es la seguridad de los datos y la IA?

La seguridad de los datos y la IA consiste en identificar, clasificar y gestionar el acceso a los datos confidenciales en todos los sistemas, usuarios y modelos de IA. La solución de seguridad de datos e IA de Commvault ofrece estas capacidades en entornos híbridos, lo que permite a las organizaciones garantizar que los datos permanezcan visibles, controlados y protegidos a lo largo de todo su ciclo de vida, incluyendo su uso en el entrenamiento de la IA y en los resultados obtenidos.

¿Por qué supone un riesgo importante la exposición de datos sensibles?

La exposición de datos sensibles supone un riesgo importante, ya que las organizaciones suelen carecer de visibilidad sobre dónde se almacenan los datos y quién puede acceder a ellos, lo que aumenta la probabilidad de que se produzcan filtraciones, usos indebidos e incumplimientos normativos. Commvault ayuda a mitigar este riesgo mediante un enfoque unificado que combina la detección de datos, la clasificación y la gestión del acceso en entornos híbridos.

¿Cuáles son los pilares fundamentales de la seguridad de los datos?

Los tres pilares fundamentales de la seguridad de los datos son la detección, la clasificación y la gestión del acceso. Commvault ofrece todas estas funciones: la detección de datos identifica dónde se encuentran los datos confidenciales en todos los entornos; la clasificación de datos define su nivel de confidencialidad y su tipo; y la gestión del acceso a los datos y a la IA garantiza un control de acceso acorde con las políticas empresariales y normativas.

¿Por qué es peligroso un acceso excesivamente permisivo?

Un acceso excesivamente permisivo permite a los usuarios, las aplicaciones y las cuentas de servicio acceder a más datos de los necesarios, lo que aumenta el riesgo de exposición accidental, amenazas internas y abuso. La solución de gobernanza del acceso a los datos y la IA de Commvault aborda este problema mediante la supervisión continua de los patrones de acceso, la adaptación de los permisos a la clasificación de los datos y la identificación y corrección de las desviaciones en el acceso en entornos híbridos.

¿Cómo deben las organizaciones ayudar a proteger los datos utilizados por la IA?

Las organizaciones pueden proteger los datos de IA clasificando los conjuntos de datos antes del entrenamiento y supervisando de forma continua cómo los modelos acceden a los datos y los exponen. Commvault Data and AI Security facilita esta tarea mediante controles de detección, clasificación y gobernanza, que incluyen el enmascaramiento, la censura y las restricciones de acceso, lo que ayuda a garantizar que los datos sensibles no queden expuestos a través del entrenamiento de la IA, el comportamiento de los modelos o sus resultados.

¿Cómo contribuye la clasificación de datos al cumplimiento normativo?

La clasificación de datos facilita el cumplimiento normativo al identificar los datos regulados, como la información de carácter personal (PII), y asignarles los controles adecuados. La clasificación de datos de Commvault ayuda a las organizaciones a aplicar políticas de conservación y eliminación que se ajustan al RGPD, la HIPAA y la norma PCI DSS, y proporciona las pruebas necesarias para una auditoría, con el fin de demostrar cómo se identifican, protegen y gestionan los datos sensibles.

Explora recursos relacionados

Explora

What are the Key Risks of Data & AI Security?

Explore how AI introduces new data vulnerabilities – from model training to exposure to runtime risks – and the layered practices organizations use to govern workloads responsibly.
Lea el artículo sobreabout What are the Key Risks of Data & AI Security?
Libro blanco

Análisis de los riesgos de seguridad de la IA

Un informe de Readiness para que su CISO y su CIO vean qué ha cambiado con MCP 2.0 y qué deben hacer para que su organización esté preparada.
Lee el libro blanco sobre elabout Análisis de los riesgos de seguridad de la IA


Puntos Clave

  • Replace subjective claims about “ease of use” with a measurable data protection gearing ratio: protected capacity divided by the number of full-time administrators.
  • Medir la capacidad protegida por ETC ofrece una visión más significativa de la eficiencia operativa que las métricas tradicionales, como los trabajos de copia de seguridad por administrador.
  • El índice de protección de datos debe utilizarse como referencia antes de una migración de plataforma y medirse de nuevo después para validar las mejoras operativas.
  • Factores como los entornos multinube, los requisitos de Recovery tras ciberataques y las obligaciones de cumplimiento normativo pueden influir en el índice, por lo que debe evaluarse en el contexto de cada entorno.
  • Las organizaciones deberían pedir a los proveedores que se comprometan a alcanzar resultados operativos cuantificables, en lugar de basarse en afirmaciones cualitativas sobre la simplicidad.

Every vendor evaluation I have sat in eventually reaches the same dead end. One side says the platform is simple to run. The other side says their platform is simpler.

Nobody can prove either claim, so the conversation drifts to the demo, the reference call, the gut feeling in the room. That is not how you should be making a decision that determines how your team will spend the next five years.

I have run production data protection environments. I have watched teams get buried under fragmented tooling that promised automation and delivered tickets instead.

“Reduced complexity” is not a feeling you should have to take on faith. It is something you should be able to calculate.

La métrica que le faltaba al sector

We have started using a simple ratio internally and with customers: total protected capacity divided by the number of full-time staff required to run it. We call it the data protection gearing ratio.

Protected Capacity (PB) / FTEs = Data Protection Gearing Ratio

That’s it. No survey questions about satisfaction. No adjectives. A number, calculated from data you already have.

Here is why it matters more than the metrics it replaces. Calculating the number of backup jobs per person made sense a decade ago, when a job represented a discrete unit of manual effort. It does not reflect how modern platforms operate today, where automation absorbs the routine work and a single administrator can be accountable for petabytes, not job counts.

Measuring jobs per person in an automated environment tells you nothing about whether the automation is actually working.

Cómo se aplica en la práctica

One clarification before the number, because it trips people up. Protected capacity means the full, uncompressed, undeduplicated size of the applications being protected, not the physical disk behind them.

That distinction matters because it is the whole point. Commvault’s own production environment protects 42,39 PB of application data on 9,26 PB of physical disk, an 81,91 % space savings from deduplication and compression.

The ratio is not just a measure of how many petabytes a person can watch over. It is a measure of how much architecture is doing the work before headcount ever enters the picture.

With that in mind: Commvault runs its own production backup environment on 42,39 PB of protected capacity with two FTEs. That is a gearing ratio of 21.20 PB per FTE. Industry benchmarks for modern platforms typically land between 5 and 25 PB per FTE, depending on environment complexity, so that number sits at the high end of what is achievable today.

Métrico  Valor  Definición 
Capacidad protegida (front-end)  42,39 PB  Full, uncompressed, undeduplicated application size protected in our environment 
Capacidad total de disco  9,26 PB  Almacenamiento físico de destino 
Espacio total utilizado  7,89 PB  Current utilization 
Datos escritos en total  7,67 PB  Datos lógicos grabados en el disco 
Ahorro de espacio  81,91 %  Eficiencia de la deduplicación y la compresión 
Empleados a tiempo completo dedicados a la protección de datos  2  Number of full-time admins managing Commvault’s own production backup estate 

Data Protection Gearing Ratio = 42,39 PB / 2 FTEs = 21.20 PB per FTE

I want to be direct about what this number does not do. It does not account for a multi-cloud footprint, cyber recovery requirements, or a compliance-heavy application mix, all of which will pull the ratio down for reasons that have nothing to do with how good the platform is.

A ratio in isolation is not a verdict. A ratio measured before and after a migration is.

That is the actual use case. Baseline your current environment on your current tools. Set a target ratio based on your growth projections and your team’s capacity. Then hold your vendor to it after the implementation is done, not just during the sales cycle.

Las implicaciones a nivel de la junta directiva

Si eres tú quien da el visto bueno a la migración a una nueva plataforma, no solo se te pide que confíes en que la nueva plataforma sea más fácil de gestionar. Se te pide que financies un resultado operativo específico. Un objetivo de ratio de protección de datos te ofrece una forma de incluir ese resultado en el análisis de viabilidad y comprobarlo 12 meses después.

Esta es la misma disciplina que aplicamos al tiempo medio de recuperación tras una limpieza (MTCR). La capacidad de recuperación no es algo que se afirme, sino algo que se mide y se vuelve a medir hasta que la cifra refleje la realidad. La eficiencia operativa merece el mismo nivel de exigencia.

El reto

Ask your current vendor for the gearing ratio of your own environment today. If they cannot produce it, that tells you something about how well they understand what “simple to manage” means for your team.

And if you are evaluating a new platform, do not accept “easier to use” as an answer. Ask what ratio they will commit to, and ask again after year one.

Preguntas frecuentes

Q: What is the data protection gearing ratio?

A: The data protection gearing ratio measures the amount of protected data capacity managed by each full-time administrator. It provides an objective way to evaluate operational efficiency rather than relying on subjective impressions of platform usability.

Q: Why is this metric more useful than backup jobs per administrator?

A: Modern data protection platforms automate much of the routine work that previously required manual effort. As a result, counting backup jobs no longer reflects the true workload or efficiency of an operations team.

Q: What does “protected capacity” mean in this calculation?

A: Protected capacity refers to the full, uncompressed, and undeduplicated size of the application data being protected. This measurement reflects the actual workload managed by the platform rather than the physical storage consumed after optimization.

Q: Does a higher gearing ratio always indicate a better platform?

A: Not necessarily. Environmental complexity, including multi-cloud deployments, cyber resilience requirements, and regulatory obligations, can reduce the ratio even when the platform performs well. The metric is most valuable when comparing the same environment before and after a migration.

Q: How should organizations use the data protection gearing ratio during vendor evaluations?

A: Organizations should establish a baseline using their current environment, define a target ratio aligned with future growth, and ask vendors to commit to achieving measurable improvements after implementation. This approach shifts the conversation from marketing claims to verifiable business outcomes.

Q: What is the broader business value of this metric?

A: The data protection gearing ratio enables executives to quantify expected operational efficiency gains and include them in the business case for a platform investment. It also provides a benchmark that can be reviewed after deployment to confirm the promised results were achieved.

Rajiv Kottomtharayiles director de productos de Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

En elprimer episodio de nuestra serie STRIVE sobre soberanía digital, Commvault’s Alex Zinin and Osmium Data Group’s Max Mortillaro challenged one of the biggest misconceptions in the industry: Digital sovereignty isn’t a feature you buy – it’s a business problem you have to understand before you can solve.

This conversation picks up where that one left off. This time, I sat down with Thomas Maurer, EMEA Global Black Belt for Sovereign Cloud at Microsoft, to explore what happens after an organization decides sovereignty matters. How do executive teams move from broad concerns about regulation, jurisdiction, or geopolitical uncertainty into practical architectural decisions?

The answer, it turns out, is rarely as straightforward as choosing a cloud provider or selecting the right deployment model. It’s about asking better questions before making technical decisions.

Watch the episodio completo.

Puntos Clave

  • Every organization defines digital sovereignty differently – and that’s exactly where the conversation should begin.
  • Sovereignty isn’t solved by technology alone. Legal, operational, architectural, and business considerations all shape the outcome.
  • Cloud and on-premises aren’t competing strategies. For many organizations, the future is a carefully designed combination of both.
  • Risk management – not fear – should drive sovereignty decisions.
  • Una buena arquitectura empieza por entender las necesidades del negocio, no por elegir la infraestructura.

El concepto de soberanía tiene diferentes significados para cada organización

One of the first observations Thomas made was also one of the most important.

There is no universal definition for digital sovereignty. For one organization, it may simply mean meeting regulatory requirements or keeping data within a specific geography. For another, it may involve operational independence, business continuity, or preparing for geopolitical disruption. That difference matters because it changes the conversation entirely.

Too often, organizations assume there’s a standard sovereignty blueprint waiting to be implemented. In reality, the first challenge isn’t selecting technology – it’s understanding what problem the organization is actually trying to solve.

Only then does architecture begin to make sense.

La tecnología debe seguir a la estrategia

One theme that kept surfacing throughout our discussion was the temptation to jump straight into technical design.

It’s understandable. Architects naturally think about infrastructure, workloads, connectivity, and deployment models. But Thomas emphasized that the most successful projects begin somewhere else.

They begin by listening.

What concerns are driving the initiative? Is the objective regulatory compliance? Business continuity? Data residency? Operational control? Protection against geopolitical disruption?

Different answers lead to different architectures.

That may sound obvious, but it’s surprising how often organizations begin evaluating solutions before they’ve aligned on the business outcome they’re trying to achieve.

Avance: Empieza por el riesgo, no por las suposiciones

One of the most practical moments in our conversation comes when Thomas and I discuss why sovereignty initiatives should begin with a risk assessment – not an architectural diagram.

Every organization has a different risk appetite. A Formula 1 team, a government agency, and a global manufacturer won’t make the same decisions, nor should they. The key is understanding which risks matter most to your business, what trade-offs you’re willing to make, and then designing an architecture that supports those decisions.

As Thomas points out, there is no perfect solution – only informed trade-offs. The earlier organizations adopt that mindset, the stronger their sovereignty strategy will be.

‘Cloud or On-Premises?’ Is the Wrong Question to Ask

One of the more interesting parts of the conversation challenged another common assumption – that organizations must choose between public cloud and private infrastructure.

Thomas described a very different reality.

Many organizations aren’t replacing one with the other. They’re designing environments where workloads can move between them based on business need, regulatory requirements, or resilience considerations.

That flexibility changes how we should think about architecture. Instead of asking whether cloud or on-premises is better, the more useful question becomes:

“Where does this workload belong today – and could that answer change tomorrow?”

When sovereignty becomes part of the design process, workload mobility becomes just as important as workload placement.

La arquitectura es solo una parte de la ecuación

Another takeaway I appreciate is Thomas’s reminder that architecture alone doesn’t solve sovereignty.

  • Los contratos son importantes.
  • Los marcos legales son importantes.
  • Los procesos operativos son importantes.
  • Las personas que se encargan de gestionar el medio ambiente son importantes.

None of those disciplines can operate in isolation. Sovereignty requires legal, security, compliance, and infrastructure teams to work together from the beginning – not hand projects off to one another after decisions have already been made.

That’s a familiar pattern for anyone working in cyber resilience. The strongest outcomes rarely come from individual teams. They come from coordinated ones.

El riesgo debería guiar cada decisión

Toward the end of our discussion, the conversation naturally shifted toward risk. For me, this is where sovereignty starts to feel much more familiar. Every resilience project begins by asking what the organization is trying to protect, what threats matter most, and how much risk it’s willing to accept.

Digital sovereignty is no different.

Rather than searching for a perfect solution, organizations need to identify the specific sovereignty scenarios they’re concerned about and then determine which architectural, operational, or contractual controls best address those risks.

That shift – from feature comparison to risk management – is what ultimately leads to better decisions.

Estas preguntas formarán parte cada vez más de las conversaciones sobre riesgos, los debates sobre adquisiciones y la planificación tecnológica a largo plazo. Porque la criptografía no se detiene en los límites de la organización. Tampoco lo hace el riesgo.

Digital sovereignty continues to evolve rapidly. New regulations will emerge. Technology will change. Geopolitical realities will continue to shift.

That means sovereignty isn’t something organizations solve once. It’s something they regularly evaluate as business priorities and external risks evolve.

The organizations that succeed won’t necessarily have the most restrictive architectures. They’ll have the clearest understanding of their business objectives, the discipline to assess risk thoughtfully, and the flexibility to adapt as those risks change.

Ultimately, digital sovereignty isn’t something organizations can buy off a shelf. It’s an exercise in understanding risk, managing dependencies, and making informed trade-offs long before those decisions are tested.

La conclusión más importante de este debate es que la criptografía poscuántica ya no es un reto tecnológico del futuro.

Se está convirtiendo en un debate sobre la resiliencia en el presente.

Las organizaciones no tienen por qué entrar en pánico ni necesitan renovar todos los sistemas de la noche a la mañana. Pero sí deben empezar a actuar, para aprovechar al máximo el tiempo del que disponen para prepararse.

Las organizaciones que superen con éxito esta transición no serán necesariamente aquellas que cuenten con la criptografía más sofisticada. Serán aquellas que hayan empezado a formarse una idea del tema antes de que llegara la certeza.

Y así es, a menudo, como funciona la resiliencia.

En este episodio de STRIVE, Thomas y yo hablamos de:

  • Por qué el concepto de soberanía tiene significados distintos para cada organización.
  • Cómo deberían abordar los directivos la estrategia de soberanía.
  • Public cloud versus private cloud – and why it’s often not an either/or decision.
  • Por qué la gestión de riesgos debería guiar las decisiones arquitectónicas.
  • El papel de la resiliencia en la planificación de la soberanía moderna.

Ver ahora.

Preguntas frecuentes

Q: Does digital sovereignty mean keeping everything on-premises?

A: No. Many organizations adopt hybrid approaches that balance cloud capabilities with specific sovereignty requirements.

Q: Where should sovereignty projects begin?

A: Start by defining the business problem and understanding the risks you’re trying to mitigate before evaluating technology.

Q: Is sovereignty purely a technical issue?

A: No. It requires collaboration between legal, compliance, security, operations, and architecture teams.

Q: How does sovereignty relate to resilience?

A: Both disciplines focus on maintaining operational continuity by reducing exposure to risks that could disrupt the business.

Q: What’s one big mistake organizations make in regard to digital sovereignty?

A: Jumping into architectural decisions before agreeing on what sovereignty means for their organization.

Q: What should executives ask first in terms of planning for digital sovereignty?

A: “What problem are we trying to solve?” Everything else follows from that answer.

Darren Thomsones vicepresidente y director de tecnología para la región de EMEA en Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave

  • Terraform manages desired state – it provisions and configures infrastructure from code.
  • Cloud Rewind captures actual deployed state – it helps restore environments to a known-good point in time.
  • Los archivos de estado de Terraform y el historial de Git no son herramientas de recuperación; no recogen lo que realmente se estaba ejecutando.
  • Cloud Rewind Ayuda a recuperar la infraestructura, tanto si los cambios se han realizado mediante IaC, a través de la consola o mediante intervención manual.
  • Juntos, Terraform y Cloud Rewind ayudan a los equipos a contar con una estrategia completa de operaciones de « cloud »: crear rápido, recuperarse aún más rápido.

If your team runs Terraform, you already know how powerful IaC can be. You define what you want, apply it, and your cloud environment materializes. Change management becomes repeatable. Provisioning becomes predictable.

But there is a gap between provisioning infrastructure and recovering it – and it matters most when something goes wrong at 2 a.m.

Terraform and Cloud Rewind address different parts of the cloud lifecycle. Understanding the difference helps you avoid a dangerous assumption: that your IaC tooling doubles as a recovery plan.

En qué se diferencian Terraform y Cloud Rewind

Terraform is a provisioning tool. It defines and manages desired state. When you revert a Terraform change, you are re-applying a previous desired configuration – not restoring the actual deployed environment that was running before the incident.

That distinction matters. Terraform state is not a historical recovery snapshot.

Cloud Rewind captures actual cloud configuration state and stores point-in-time snapshots. When something breaks, you do not rebuild from code and hope the environment comes back intact. You restore a known-good environment – the one that was actually running – regardless of how the change that caused the problem was introduced.

Terraform Design  Cloud Rewind Design 
Gestión del estado deseado  Recuperación del estado real 
Aprovisionamiento de infraestructura  Recuperación de la infraestructura 
Aplica los cambios  Deshace los cambios 
Fuente de verdad = código  Fuente de verdad = entorno implementado 
Con visión de futuro  Retrospectivo 
Compilar y actualizar  Recuperar y reconstruir 
Ayuda a recuperar la configuración deseada  Ayuda a restaurar el estado de implementación a partir de un momento concreto 

Dónde llega Terraform a sus límites

Incluso en los entornos de IaC más maduros se dan situaciones de recuperación en las que reconstruir a partir del código no es suficiente. Piensa en esto:

  • Un cambio en la infraestructura que ha fallado y que ya se ha implementado en producción.
  • Borrado accidental de recursos de « cloud ».
  • Desviaciones en la infraestructura causadas por cambios manuales o fuera de banda.
  • Cambios realizados fuera de Terraform que no se reflejan en el código ni en el estado.
  • La necesidad de restaurar la infraestructura para que quede exactamente como estaba en un momento concreto.
Terraform does not maintain historical cloud state. It re-applies a desired configuration – it does not restore what was actually deployed and running. “Rewind to 2:15 PM yesterday” is not a Terraform feature. It is a Cloud Rewind feature.

Una recuperación que dependa de que el código de Terraform, los archivos de estado y el historial de versiones estén disponibles, sean precisos y estén completos conlleva un riesgo real. En un incidente real, esas condiciones no están garantizadas.

Dos herramientas, una estrategia completa

Terraform helps you automate infrastructure creation and change management. Cloud Rewind helps you recover infrastructure quickly and consistently when deployments fail, resources are deleted, infrastructure drifts, or your team needs to restore a known-good environment.

They complement each other. Terraform is designed to make your cloud environment repeatable. Cloud Rewind is designed to make it recoverable.

Build with Terraform.Recupera con Cloud Rewind.

Preguntas frecuentes

Q: Does Terraform provide point-in-time recovery?

A: No. Terraform re-applies a desired configuration from code. It does not maintain historical snapshots of your deployed cloud environment. If the change that caused an incident is not captured in your Terraform state or Git history – for example, a console change or infrastructure drift – Terraform cannot help you restore it.

Q: What happens when changes are made outside Terraform?

A: Console changes, manual interventions, and out-of-band configurations are common in real environments. Terraform does not track them. Cloud Rewind captures actual deployed state – regardless of how a change was introduced – so you can restore a known-good environment even when your IaC does not reflect what was running.

Q: Is Cloud Rewind a replacement for Terraform?

A: No. They solve different problems. Terraform is your provisioning and change management tool. Cloud Rewind is your recovery tool. Most teams that use one can benefit from both – they cover different parts of the cloud operations lifecycle.

Q: What kinds of incidents does Cloud Rewind address?

A: Cloud Rewind is designed for scenarios where rebuilding from code is not enough: failed deployments already in production, accidental resource deletion, infrastructure drift, and cases where teams need to restore an environment to a specific historical point in time.

Q: Does Cloud Rewind require teams to stop using Terraform?

A: No. Cloud Rewind works alongside your existing IaC workflows. Teams continue to use Terraform for provisioning and change management and use Cloud Rewind when they need to recover from a real incident.

Cailin Pitcheres directora sénior de marketing de cartera en Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave 
  • Commvault integrates frontier AI vulnerability discovery into its risk-based security program rather than relying on AI as a standalone solution.
  • Every AI-generated finding is reviewed and validated by humans before remediation decisions are made.
  • Frontier AI complements established security practices such as static analysis, dynamic analysis, and penetration testing by expanding code coverage and identifying more complex exploit scenarios.
  • Commvault maintains strict governance over source code, vendor access, and vulnerability handling.
  • Commvault is investing in scalable vulnerability management processes in order to respond efficiently as AI increases the volume of potential security findings.

Across the security industry, AI and large language models are being applied to vulnerability discovery – helping teams evaluate more code, explore more attack paths, and identify exploitable conditions faster than manual review alone.  

This is not a niche experiment. It is a shift in how thorough a security evaluation can be, and it is changing what customers reasonably expect from their software vendors. 

Customers are regularly asking their software vendors: Do you test your own products against the same methods a threat actor might use? Are the processes behind that testing rigorous enough to keep pace? These are the right questions to ask. 

Our Approach: Strong Processes, no Single Tool

Commvault’s security posture is built on strong, repeatable processes rather than dependence on any single tool, model, or vendor.  

Vulnerability management follows an established, risk-based framework: Findings are assessed for practical exploitability, prioritized by severity and exposure, and remediated through our standard development lifecycle. That framework applies the same way regardless of whether a finding comes from a penetration test, an external researcher, or AI. 

AI vulnerability discovery is integrated into this framework as an additional capability, not a separate program running on its own rules. Candidate findings generated through AI methods are treated as inputs that require human confirmation of exploitability before any remediation action is taken. That step helps prevent two failure modes at once: under-prioritizing genuine risk and burning cycles on false positives. 

AI Alongside Established Security Practices

AI methods do not replace the disciplines that have always defined responsible vulnerability management. Static analysis, dynamic analysis, penetration testing, and established scanning tools remain essential parts of our program.  

What AI adds is coverage depth: the ability to evaluate a broader set of code paths, model more complex exploit conditions, and surface findings that require contextual understanding rather than simple pattern matching. 

Our vulnerability program is tool-agnostic and model-agnostic by design. We are not dependent on any single vendor or model, and new approaches can be added as they prove out, without re-architecting how findings are governed or remediated. The advantage isn’t which model we use but whether the process behind it is disciplined enough to act on what that model finds. 

Governance and Controls

Every AI scan we run operates under the same governance principles: 

  • AI models are vetted before used. Any vendor and tooling access is governed by formal NDA and engagement terms.
  • Findings are processed through the same security engineering review pipeline used for every other vulnerability source.
  • No AI-generated finding is acted upon without human triage and exploitability confirmation.
From Candidate Finding to Confirmed Fix

Findings generated through AI are treated as candidates, not confirmed vulnerabilities. Each one is assessed by engineers and product security experts for practical exploitability in realistic customer environments.  

Severity ratings are assigned based on exposure, exploitability, and impact – not on how the finding was discovered. Confirmed vulnerabilities move through the same remediation timelines and escalation paths as any other source, with priority set by severity and exposure. 

First Patch Tuesday Disclosures – August 2026

Our inaugural Patch Tuesday, published August 11, 2026, includes the following disclosures: 

CVE ID  Severity  Resumen 
CVE-2026-13737  Crítico  CommServe contained an allowlist bypass affecting command execution authorization.  
CVE-2026-13738  Crítico  CommServe contained an authorization bypass affecting a limited set of command execution operations.  
CVE-2026-13739  Alto  A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) related to the handling of arbitrary target URLs. 

 

Full technical advisories, including affected versions and remediation guidance, are available on our Security Advisories page. Read more about the move to a monthly cadence in Bringing  Trust to CVE Disclosures.  

Why Operational Readiness Matters More Than Any Single Tool

As AI vulnerability discovery becomes standard practice across the industry, the volume of potential findings that security teams need to evaluate will keep rising. The question that matters for any enterprise software vendor isn’t which AI model they use. It’s whether their vulnerability management process is mature enough, and scalable enough, to handle that throughput without creating a backlog that increases customer exposure. 

We pair our investment in AI with an equal investment in the process infrastructure needed to act on what it finds: triage capacity, severity prioritization, remediation tracking, and coordinated disclosure practices. Our investment is only as valuable as the response capability behind it. 

Preguntas frecuentes

Q: What is Commvault doing with frontier AI security testing? 
A: We actively evaluate our products using AI methods as part of our structured security engineering program. We are being thoughtful about testing different models and harnesses so that we find any potential vulnerabilities previously undiscovered by humans and or existing testing. That work follows the same vulnerability management process as every other form of testing. This is underway today – it isn’t a roadmap item. 
Q: How is Commvault preparing for AI vulnerability discovery? 
A: We built a program that is model-agnostic and tool-agnostic by design. Our goal is to make sure our security engineering practice can incorporate the best available methods across a range of AI tooling, inside one consistent governance and risk management framework. 
Q: Is Commvault using these models safely? 
A: Yes. All AI scans are thoroughly vetted. Any vendor and tool access is governed by formal NDA and engagement terms, and every AI-generated finding requires human confirmation of exploitability before any remediation action is taken. 
Q: How is Commvault scaling vulnerability management for the AI era? 
A: Our focus is on making sure the response process scales with discovery volume and discovery pace. As AI increases the number of potential findings our teams need to review, we’re investing in risk-based triage, consistent remediation service level agreements, and the operational infrastructure needed to act on higher discovery throughput within accelerated timeframes to decrease exposure for customers. 

Bill O’Connell is Chief Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

When frontier AI models started making headlines, most of the discussion centered on one question: What happens when attackers gain access to them? 

It’s a fair question.  

Models capable of discovering vulnerabilities faster, chaining exploits together, and operating at unprecedented speed naturally raise concerns for every CISO.  

But after spending time talking with customers over the past several months – and in my conversation with Tim Zonca, Commvault’s VP of Portfolio Marketing, in this episode of STRIVE – I think there’s an even more important question emerging. 

What happens to resilience itself? 

Because while frontier AI will undoubtedly accelerate cyber threats, it’s also accelerating something else: Enterprise complexity. 

Watch the episodio completo. 

 Puntos Clave 

  • Frontier AI isn’t just accelerating cyberattacks – it’s accelerating enterprise complexity.  
  • Vulnerability management isn’t disappearing, but the speed and scale of discovery are changing dramatically.  
  • AI systems introduce entirely new recovery dependencies, including agents, vector databases, embeddings, and distributed state.  
  • Organizations need a coherent understanding of their environments before they can recover them.  
  • The next generation of resilience will depend on trusted systems of record that explain what happened, why it happened, and how to recover confidently.  
The Conversation Has Changed 

One thing Tim and I discuss early in the episode is how differently organizations are reacting to frontier AI. 

  • Some see an entirely new class of cybersecurity challenge. 
  • Others view it as simply the next evolution of vulnerability management. 

What’s interesting is that neither perspective is necessarily wrong. 

The processes organizations use to identify, prioritize, and remediate vulnerabilities remain familiar. But the pace at which AI can discover those vulnerabilities – and uncover entirely new chains of attack – is unlike anything we’ve seen before.  

That’s the shift. 

The work isn’t fundamentally different. The speed is. 

When AI Changes the Shape of Recovery 

Most conversations about AI focus on security and prevention: 

  • How do we secure models? 
  • How do we protect prompts? 
  • How do we defend against AI-assisted attacks? 

Those are important questions. But resilience introduces a different one: What exactly are we recovering? 

Traditional enterprise applications already involve complicated relationships between infrastructure, applications, and data. AI expands that picture considerably. Now there are agents operating across multiple systems. Vector databases. Embeddings. Models interacting with different data sources simultaneously. It’s become far more than a traditional application stack.  

Recovery is no longer about restoring an application. It’s about restoring an ecosystem. 

Sneak Peek: Check This Out 

In this moment from our STRIVE discussion, Tim and I discuss the growing complexity of AI stacks, what coherent recovery is (and why it matters), and how Commvault is helping our customers with full AI-stack recovery. 

Why Coherency Matters 

One idea that keeps surfacing throughout our conversation is coherence. 

For years, organizations have worked to map application dependencies, understand infrastructure relationships, and identify critical services. AI makes that challenge significantly more difficult. 

Applications no longer interact with a single database or service. They may depend on multiple models, agents, data stores, and orchestration layers – all changing dynamically. 

Understanding those relationships isn’t just an architectural exercise anymore. 

It’s a recovery requirement. 

Because if you don’t understand what makes up the system, it’s difficult to know whether you’ve actually recovered it. 

A New System of Record 

Another concept from Tim that I found compelling is the idea of a system of record for the AI era. Historically, systems of record gave organizations confidence in business data. Customer records lived in CRM platforms. Financial records lived in ERP systems. 

AI changes that expectation. 

Organizations increasingly need trusted visibility into how data is used, what agents interact with it, why decisions are made, and whether restored environments represent a known-good state.  

That doesn’t replace resilience. It strengthens it. Because confidence in recovery depends on confidence in what you’re recovering. 

AI Can Also Help Solve the Problem 

As organizations struggle to understand increasingly distributed environments, AI becomes a powerful tool for discovery, classification, and policy recommendation.  

Rather than manually identifying relationships across sprawling environments, organizations can use AI to help identify dependencies, recommend protection policies, and continuously update those relationships as environments evolve. 

That’s an important shift. 

The same technology that’s adding to organizational complexity may also become one of the best tools for managing it. 

Estas preguntas formarán parte cada vez más de las conversaciones sobre riesgos, los debates sobre adquisiciones y la planificación tecnológica a largo plazo. Porque la criptografía no se detiene en los límites de la organización. Tampoco lo hace el riesgo. 

Frontier AI isn’t simply introducing another cybersecurity challenge. It’s forcing organizations to rethink resilience itself. 

Recovery is becoming less about individual systems and more about restoring trusted business operations across increasingly intelligent environments. That means resilience strategies must evolve alongside the technologies they’re protecting. 

Organizations that prepare for that shift won’t just recover faster. They’ll recover with greater confidence. 

La conclusión más importante de este debate es que la criptografía poscuántica ya no es un reto tecnológico del futuro.

Se está convirtiendo en un debate sobre la resiliencia en el presente.

Las organizaciones no tienen por qué entrar en pánico ni necesitan renovar todos los sistemas de la noche a la mañana. Pero sí deben empezar a actuar, para aprovechar al máximo el tiempo del que disponen para prepararse.

Las organizaciones que superen con éxito esta transición no serán necesariamente aquellas que cuenten con la criptografía más sofisticada. Serán aquellas que hayan empezado a formarse una idea del tema antes de que llegara la certeza.

Y así es, a menudo, como funciona la resiliencia. 

In this conversation, Tim and I explore: 

  • How frontier AI is changing enterprise risk.  
  • Why vulnerability management is entering a new phase.  
  • What AI means for modern recovery architectures.  
  • The role of coherent recovery across AI-enabled environments.  
  • Why trusted systems of record will become increasingly important.  

Ver ahora. 


Preguntas frecuentes 

Q: What are frontier AI models? 
A: Frontier AI models are the latest generation of highly capable AI systems designed to solve increasingly complex reasoning and cybersecurity tasks. 
Q: Why are organizations concerned about them? 
A: They dramatically accelerate vulnerability discovery, exploit chaining, and security research, increasing both defensive and offensive capabilities. 
Q: How does AI change cyber resilience? 
A: AI introduces new dependencies – including agents, models, vector databases, and distributed states – that make recovery more complex. 
Q: What is a coherent recovery strategy? 
A: It’s an approach that restores not only data, but also the applications, infrastructure, dependencies, and AI components required for trusted business operations. 
Q: What is a system of record in the AI era? 
A: It’s a trusted source that helps organizations understand what happened, why it happened, and whether recovered systems represent a known-good state. 
Q: What should organizations do now? 
A: Begin mapping AI dependencies, understand how AI changes recovery requirements, and develop resilience strategies that account for increasingly intelligent application environments. 

Chris Mierzwa is Senior Director of Portfolio Marketing at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Protección unificada de datos | Recuperación tras ataques de ransomware | Cleanroom Recovery | Cargas de trabajo híbridas

Cómo unificar la protección de datos en todas las cargas de trabajo híbridas

Commvault® Cloud helps organizations discover, govern, and unify workload protection, allowing teams to rebuild critical services quickly after a cyber incident.


You’re the VP of IT Operations. It’s 2:00 a.m. on a Saturday. Your SecOps team just confirmed ransomware has encrypted files across three regions. Your last backup job completed successfully – but when your team attempts to restore the ERP system, the application fails to start.

The backup was marked successful. The data was present. But the dependencies, transaction logs, and service relationships were never captured in a consistent, recoverable state. Recovery isn’t just about data – it’s about rebuilding services.

This scenario plays out across hybrid environments every day. Modern enterprises run on interconnected cloud-native services, Kubernetes clusters, hybrid databases, and SaaS platforms – none of which recover cleanly from a simple file restore. Fragmented protection strategies designed for a simpler era leave organizations exposed at exactly the moment resilience matters most.

Commvault Cloud is an AI-enabled platform designed to help organizations discover, govern, and unify data protection across cloud-native, hybrid, and on-premises workloads – from a single control plane. Capabilities such as AI-enabled workload discovery, Cleanroom Recovery, Cleanpoint Identification, Threat Scan, and Command Center orchestration help teams validar recovery readiness and rebuild critical services in a controlled sequence after a cyber incident. 

El 45 %

of organizations are repeat ransomware victims – meaning fast recovery without clean validation reinfects as often as it restores. 
ESG Research — Zero Trust and Ransomware Protection Report 

What Is Unified Data Protection – and Why Does It Matter? 

Unified data protection is a backup and recovery approach that helps organizations govern the broadest range of workloads – including cloud databases, Kubernetes, SaaS, hypervisors, and on-premises systems – from a single control plane, rather than managing separate tools and policies for each environment.Commvault Cloud Unityestá diseñado para respaldar este enfoque, ayudando a los equipos a reducir la complejidad operativa y a mantener una protección coherente en entornos híbridos y multicloud.

Fragmented data protection strategies can create invisible gaps: inconsistent policies across environments, coverage blind spots that surface only during recovery, and manual overhead that scales poorly as workloads diversify. When ransomware strikes or an outage occurs, teams may discover too late that critical workloads were not protected consistently. A unified approach is designed to help address this by bringing all workloads under a centralized policy engine – so protection status, retention schedules, and recovery workflows are governed from one place.

  • Commvault Cloud workload coverage: Unified protection across cloud databases (AWS RDS, Azure SQL, SAP HANA, Oracle), hypervisors (VMware, Hyper-V), Kubernetes (AKS, EKS, GKE), SaaS (Microsoft 365, Salesforce, Google Workspace), and on-premises infrastructure.
  • Unified control plane: All workloads managed from a single AI-enabled Command Center –helping reduce fragmented policy sets and manual operational overhead.
  • AI-enabled discovery and tagging: Automated workload inventory and classification can help teams identify coverage gaps and bring unprotected resources under policy.
  • TCO analysis: Real-time visibility into protected status and cost drivers can support budget governance across cloud, hybrid, and on-premises environments.

¿Cómo te ayuda Commvault Cloud a identificar y gestionar la protección de las cargas de trabajo?

Effective data protection depends on knowing what you have before an incident occurs – not discovering gaps during recovery. Commvault Cloud is designed to help organizations continuously discover, classify, and apply backup policies across hybrid and multi-cloud assets, so coverage stays current as environments change.

Commvault Cloud begins with AI-enabled discovery –automatically inventorying cloud-native and hybrid assets, identifying resources without policy coverage, and bringing workloads under centralized governance in Command Center. Policies can be applied consistently across accounts, regions, and clouds, with real-time visibility into protected status and cost. Because environments change continuously – new workloads deployed, configurations updated, cloud resources spun up – discovery is designed to run as an ongoing process rather than a one-time assessment, helping teams maintain accurate coverage without manual audits.

  • AI-enabled discovery: Continuously inventories cloud-native and hybrid assets, identifies coverage gaps, and brings new workloads under centralized policies.
  • Centralized policy engine: Command Center applies consistent retention schedules, backup frequency, and copy policies across multi-cloud, hybrid, and on-premises workloads from a single interface.
  • Commvault Threat Scan: Continuously monitors backup data for anomalies, encryption activity, and malware indicators so security teams can act before recovery begins.
  • Cross-region and cross-cloud copies: Backup copies can be created across regions and cloud providers to support compliance, data residency requirements, and resilience posture.

¿Por qué fallan las herramientas fragmentadas a la hora de la Recovery?

El 89 % de las organizaciones operate in environments environments with more than one cloud, including hybrid cloud and multi-cloud set ups, yet most recovery failures don’t stem from a lack of backup jobs – they stem from protection that wasn’t built for the environment being recovered. Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.

Recovery failures surface the gap between a backup that ran and a service that actually restarts. Crash-consistent snapshots may restore raw data while leaving transaction logs, service dependencies, and cluster configurations in an inconsistent state – meaning the application cannot start even when the data is present. Unified data protection can help address this by ensuring workloads are protected in a way that reflects how they operate, and by validating recovery readiness before an incident forces the question.

Commvault Cloud presta apoyo a los responsables de seguridad que requieren una capacidad de recuperación lista para auditorías, a los equipos de TI que gestionan entornos híbridos y multinube, y a las partes interesadas en la nube y el cumplimiento normativo responsables de proteger y validar las cargas de trabajo críticas. Commvault fue reconocida en el informe «IDC MarketScape: Worldwide Cyber-Recovery 2025 Vendor Assessment» por sus puntos fuertes en la arquitectura de ciberrecuperación, la integración del ecosistema de seguridad y la amplitud de las cargas de trabajo.

  • Continuous backup monitoring: Threat Scan monitors backup data for malware indicators, encryption activity, and anomalous behavior –with alerts integrated into SIEM and SOC tools for coordinated incident response.
  • Commvault Cleanroom: Designed to stage restoration in an isolated environment so teams can validate data integrity and confirm systems are threat-free before returning to production – reducing reinfection risk.
  • Cleanpoint Identification: Designed to help pinpoint when data may have become compromised, providing more precise selection of a verified recovery point and supporting minimization of data loss.
  • Orchestrated service recovery: Command Center workflows can restore dependent services in sequence – helping reduce the manual coordination burden during high-pressure recovery events.
  • Scalable on-premises protection: HyperScale supports on-premises protection for hybrid environments, with streamlined onboarding and management through Command Center.

Microsoft Azure (nube)

Detección, clasificación y copias de seguridad adaptadas a las aplicaciones en Azure SQL, máquinas virtuales de Azure, Azure Blob y cargas de trabajo alojadas en Azure.

Microsoft Entra ID (Identidad)

Identity-based access governance integration – connects classification-based controls to Entra ID-managed users and AI service principals for policy enforcement.

AWS (nube)

Application-aware protection across AWS-hosted workloads including RDS, EC2, and EKS – via native API integrations.

Okta (Identidad)

Identity-based access policy integration –connects Commvault access governance to Okta-managed identities for role-based enforcement.

Cloud Google (nube)

Detección y copias de seguridad específicas para cada aplicación en Google Cloud Storage, GKE (Google Kubernetes Engine) y las cargas de trabajo conectadas.

ServiceNow (ITSM)

Integration for incident and audit workflows – connects Commvault threat scan events and recovery actions to ServiceNow ticketing for compliance reporting.

Cómo Funciona


Discover and protect

AI-enabled discovery inventories cloud-native, hybrid, and on-premises assets to identificar unprotected workloads. Command Center applies centralized policies – including backup frequency and retention – across environments, with cross-region and cross-cloud copies to support resilience and compliance. 


Monitor and detect

Threat Scan monitors backup data for anomalies, encryption activity, and malware indicators. Alerts integrate with SIEM and SOC tools, helping teams isolate affected data and plan a response before recovery begins. 


Validate and recover

Cleanpoint Identification helps pinpoint when data may have been compromised and surfaces viable recovery points. Cleanroom Recovery stages restoration in an isolated environment for validation before production restore, while Command Center orchestrates service recovery in the correct sequence to support controlled, reinfection-resistant recovery.


Before unified data protection, the most dangerous moment in incident response was often the restore itself – when teams discovered coverage gaps they didn’t know existed. With Commvault Cloud, teams can move from reactive gap discovery to proactive governance: understanding which workloads are protected, at what policy level, and whether recovery points have been validated. That shift – from hoping a backup worked to demonstrating that it can – can make the difference between a measured recovery and an extended outage.

¿Estás listo para unificar la protección en todas tus cargas de trabajo híbridas?

Descubre cómo Commvault Cloud puede ayudar a tu equipo a detectar, gestionar y recuperar todas las cargas de trabajo de forma eficaz.

Preguntas frecuentes

¿Qué es la protección unificada de datos?

Unified data protection is an approach to managing backup and recovery across cloud-native, multi-cloud, and on-premises workloads from a single control plane. Commvault Cloud supports this by applying consistent policies and coverage across environments – helping teams reduce operational complexity and maintain visibility into protection status.

¿Por qué fallan las estrategias de copia de seguridad fragmentadas a la hora de la Recovery?

Las estrategias de copia de seguridad fragmentadas pueden dar lugar a políticas incoherentes, lagunas de cobertura ocultas y una sobrecarga de trabajo manual que no se adapta bien a los entornos híbridos.

Commvault® Cloud addresses this with a unified control plane, centralized policies, and AI-enabled discovery – helping organizations identify and close gaps before they impact recovery.

¿Cómo respalda Commvault Cloud la protección de datos para cargas de trabajo híbridas?

Commvault Cloud delivers unified data protection across cloud, SaaS, Kubernetes, and on-premises environments through a single AI-enabled platform. The Command Center, AI-enabled discovery, and Cleanroom Recovery work together to centralize policies, identify coverage gaps, and help validate data before production restoration –supporting a more controlled recovery process.

¿Qué es Cleanroom Recovery y cómo funciona?

Cleanroom Recovery ofrece un entorno aislado para restaurar y validar datos de forma segura antes de su uso en producción. Al combinar Threat Scan con la validación a nivel de aplicación, ayuda a su equipo a reducir el riesgo de reinfección y a recuperar los datos con mayor control tras un ciberincidente.

¿Cómo respalda la protección de datos unificada los requisitos de RTO y RPO?

Commvault Cloud ayuda a alinear la protección de datos con las prioridades empresariales y respalda los objetivos de RTO y RPO. Los flujos de trabajo de recuperación orquestados en Command Center y Cleanpoint Identification, combinados con un plano de control unificado, ayudan a reducir el tiempo de inactividad, mejoran la coherencia y permiten a los equipos supervisar el estado de la protección y abordar las deficiencias de forma proactiva.

¿Qué integraciones admite Commvault Cloud para la respuesta ante amenazas?

Commvault Cloud se integra de forma nativa con Microsoft Azure, Entra ID, AWS, Google Cloud, Okta y ServiceNow. Las señales de Threat Scan se envían a las herramientas SIEM y SOC, y las acciones de recuperación se conectan a plataformas ITSM como ServiceNow para el seguimiento de incidentes y la elaboración de informes de auditoría.

Recursos relacionados

Resumen de la Solución

Protección de datos segura y resiliente

Descubre cómo la protección de datos moderna combina copias de seguridad inmutables, resistencia ante el ransomware y Recovery rápida para las operaciones empresariales.
Lea el resumenabout Protección de datos segura y resiliente
eBook

5 Questions Most Data Protection Providers Won’t Answer

Descubre las preguntas clave que debes plantear durante la evaluación de proveedores para descubrir costes ocultos y validar las capacidades reales de Recovery.
Consigue el libro electrónicoabout 5 Questions Most Data Protection Providers Won’t Answer

For years, cyber resilience has been defined by technology – security controls, sophisticated detection capabilities, and increasingly robust backup strategies designed to prevent attacks or recover more quickly. Those investments remain essential, but they are no longer enough. 

AI has fundamentally changed the nature of cyberattacks, which now move at a speed that challenges even mature organizations. As the window between compromise and business disruption continues to shrink, resilience is becoming less about preventing every attack and more about keeping the enterprise running when prevention inevitably falls short. 

That shift is at the heart of IDC’s new report, Resilience Operations: The Discipline that Makes Readiness Provable. Based on a survey of more than 500 North American organizations, the report argues that resilience is evolving into a cross-functional operating discipline that connects business priorities with cybersecurity, ITOps, and disaster recovery. More importantly, it reveals several gaps that suggest many organizations are still preparing for a threat landscape that no longer exists. 

Here are the insights that stood out. 

Recovery should begin with business outcomes – not technical ones.

Historically, recovery planning has focused on restoring infrastructure as quickly as possible, with success judged by recovery time objectives, backup completion rates, and application availability. While those measures remain valuable, they don’t necessarily answer the question executives care about most: When can we get the business back online? 

IDC argues that resilience should be anchored to business outcomes rather than technical milestones – restoring the capabilities that allow the organization to serve customers, generate revenue, and meet its obligations. That may sound like semantics, but it changes how recovery priorities are established. Technology becomes the means to an end rather than the end itself. 

Most organizations still haven’t defined what matters most.

Nearly 6 in 10 organizations have not fully defined their minimum viable business (MVB) – the smallest set of functions, systems, processes, and data required to continue operating after a disruption. 

Without a shared understanding of what the business truly depends on, every movement during recovery becomes reactive. By defining your MVB before a crisis, you’ll enable faster decisions, better coordination during recovery, and ultimately a more resilient organization. 

Automation is becoming the dividing line between resilience and recovery debt.

While attackers increasingly automate reconnaissance, exploitation, and lateral movement, many organizations still rely on manual recovery processes. 

That imbalance is becoming increasingly difficult to ignore. AI is compressing attack timelines, but recovery timelines have not kept pace. Organizations that fail to automate these recovery tasks may find themselves spending days assembling and executing plans while the damage has already been done. 

Automated recovery orchestration, clean recovery point identification, and coordinated validation are becoming foundational capabilities for recovering at the speed modern attacks demand. 

Technology isn’t the biggest resilience challenge – organizational alignment is.

Security teams focus on containment, infrastructure teams focus on restoration, business leaders focus on customer impact, and compliance teams focus on regulatory obligations. None of these priorities are inherently wrong, but when they evolve independently, organizations enter a crisis without a shared operating model. 

Enter ResOps. Rather than positioning resilience as an IT responsibility, the report frames it as a discipline that deliberately brings together business, security, infrastructure, and recovery planning. The message is clear: Resilience depends less on individual tools than on creating shared priorities before an incident forces you to make difficult decisions. 

Testing remains one of the strongest indicators of resilience.

IDC found that relatively few organizations conduct frequent tabletop exercises or cyber-range simulations, despite decades of evidence showing that rehearsal consistently improves performance during real incidents. 

Exercises reveal hidden dependencies, expose communication gaps, and allow teams to make decisions without the real consequences. Organizations that repeatedly validate their recovery processes develop a level of confidence beyond planning alone. 

Tomorrow’s resilience challenges are already taking shape.

Ransomware still dominates headlines, but the next resilience challenges have already emerged – from agentic AI and machine identities to post-quantum cryptography. 

These threats remind us that resilience planning can’t focus exclusively on today’s infrastructure. Recovery increasingly involves cloud services, SaaS applications, AI models, machine identities, third-party providers, and distributed digital ecosystems that didn’t exist a decade ago. 

Resilience is becoming measurable.

IDC’s ResOps Maturity Model is invaluable for assessing your organization’s current posture. Rather than treating resilience as something organizations either possess or lack, the framework describes a progression from reactive, siloed operations to mature, adaptive resilience built on governance, automation, and continuous improvement. 

To me, that progression acknowledges an important reality: Resilience is never finished. It’s not about purchasing a platform or completing a project. Organizations become resilient by continually improving how technology, people, and business processes work together under pressure. 

Viewed through that lens, resilience becomes less like insurance and more like operational excellence – a capability that can be assessed, strengthened, and demonstrated over time. 

We’re undergoing a broader shift in how organizations think about resilience.

Resilience conversations are evolving from protecting infrastructure to protecting the business itself. That means recovery planning starts with customers instead of servers, governance becomes as important as technology, and confidence comes from proving capabilities rather than documenting intentions. 

ResOps isn’t really a new framework; rather, it’s a broader recognition that cyber resilience has become an operational discipline. As attacks become faster and more complex, resilience will be measured not by the absence of incidents, but by an organization’s ability to continue serving customers, supporting employees, and maintaining trust despite disruption. 

That’s ultimately what ResOps is designed to prove. 

Rajiv Kottomtharayiles director de productos de Commvault. 

More related posts


Cyber Resilience

Read more about Cyber Resilience

Puntos Clave

  • Trust in the age of AI isn’t disappearing – it’s evolving.
  • Las organizaciones deben verificar la IA de forma continua, en lugar de confiar en ella por defecto.
  • La adopción de la IA debería empoderar a los empleados, no empujarlos hacia la «IA en la sombra».
  • Zero trust isn’t about distrusting people. It’s about continuously validating identities, devices, and actions.
  • Para que la IA se implemente de forma responsable, hace falta que la tecnología, la gobernanza y las personas trabajen juntas.

When we launched Ready. Or Not., we wanted to create a series that made some of today’s biggest AI conversations easier to understand. By pairing comedian Nathan Macintosh with industry experts, we’re exploring everything from agentic AI and cyber resilience to data management – and adding a little humor along the way.

If you caught our first episode on the oportunidades y los riesgos de la IA agente, I think you’ll enjoy this one as well. This time, we’re tackling a topic that’s at the center of every AI conversation: trust.

Nathan sits down with Diana Kelley, Chief Information Security Officer at Protect AI, for a conversation about what it means to trust technology when AI can generate convincing fake content, make decisions, and even imitate people. From deepfakes and hallucinations to zero trust and shadow AI, they explore how organizations can embrace AI without losing confidence in their people and systems.

Mira el episodio completo en Readiverse.Este episodio me ha dejado con una sensación de optimismo mayor de lo que esperaba. No porque la IA sea de repente más fiable, sino porque Diana nos muestra que la confianza crece cuando las organizaciones ponen en marcha las políticas, las medidas de seguridad y la tecnología adecuadas. Aquí tienes algunos temas de la conversación que te harán ver la IA desde una nueva perspectiva.

La confianza y la tecnología pueden coexistir

Diana believes trust is possible in the AI era, but it’s going to look different. We’ve always built trust through relationships with people. Now, we’re learning how to extend that trust to systems.

That doesn’t mean trusting technology blindly. It means understanding how AI works, recognizing its limitations, and putting the right safeguards in place so people and technology can work together with confidence.

“Trust has to evolve for the new world.”

– Diana Kelley

What resonated with me was the idea that trust and technology don’t have to be at odds with one another. With the right approach, they can strengthen each other.

We’re Getting Smarter About AI

Deepfakes have become one of the most talked about AI risks, and it’s easy to understand why. AI can now generate convincing voices, images, and videos that make us question what’s real. But Diana pointed out that while AI is getting more sophisticated, people are getting smarter. We’re more likely to question an unexpected phone call, take a closer look at a social media post, or pause at something that doesn’t feel quite right.

Organizations are becoming savvier, too. As AI gets better at impersonation, businesses are investing in new ways to continuously verify identities and validate information. My takeaway is this: Technology will continue to improve, but so will our ability to recognize it and respond responsibly.

“Is today a good day to start a deepfake?”

– Nathan Macintosh

Una IA responsable es buena para los negocios

Diana shared an example that will probably sound familiar to many organizations. An employee she calls “Karen in Finance” starts using AI because it helps her complete a task in minutes instead of hours. Karen isn’t trying to work around company policy – she’s trying to be more productive.

Employees use AI because they see real value in it, and that’s an opportunity for organizations. When employees have access to approved AI tools, supported by clear policies and practical guidance, they can work more efficiently while helping protect company data and systems.

Avance: Una adopción más inteligente de la IA

The goal isn’t to stop employees from using AI. It’s to make sure they’re using it the right way. Diana explains how organizations can encourage AI adoption without creating unnecessary risk.

El modelo «Zero Trust» es más importante que nunca

“When you understand how things work, then you can start to understand how to manage them.”

– Diana Kelley

Zero trust is one of those concepts that’s much easier to understand with an analogy. Diana has a great one. She describes it as moving through a building. Just because you’ve been allowed through the front door doesn’t mean every other door automatically opens for you. Each time you access a new room, there’s another quick check to confirm you’re supposed to be there.

That’s essentially how zero trust works. Instead of assuming a person or device is trustworthy after a single login, organizations continuously verify identities, devices, and actions as technology becomes more connected. Most of those checks happen quietly behind the scenes.

One of the things I appreciated about Diana’s explanation is that zero trust doesn’t feel like another security buzzword. It feels like a practical way to think about trust in a world where AI and digital identities are becoming part of everyday business.

La confianza tiene que ver con las personas

At the end of the day, technology doesn’t create trust – people do. People define the policies, processes, and ethical boundaries that guide how AI is used, while technology helps verify that those guardrails are working as intended. It’s that partnership between people and technology that makes responsible AI possible.

Trust extends beyond our own organizations. Businesses need confidence in the partners they work with, the systems they connect to, and the technologies they adopt. That’s why transparency, shared standards, and continuous verification are becoming just as important as innovation itself. The more AI becomes part of everyday business, the more trust becomes everyone’s responsibility.

Mirando hacia el futuro

AI will continue to evolve, and so will the way we interact with it. The organizations that succeed won’t be the ones that trust AI blindly or avoid it altogether. They’ll be the ones that build strong policies, adopt the right technologies, and continuously verify the systems they rely on.

Trust isn’t something we lose as technology advances. It’s something we intentionally build and evolve. That’s exactly the kind of conversation we hope to continue with every episode of Ready. Or Not.

Mira el episodio completo en Readiverse.

Preguntas frecuentes

Q: What is digital trust?

A: Digital trust is the confidence that people, systems, and organizations are who they claim to be and are acting in expected, secure ways. It combines technology, governance, and verification to help organizations interact safely.

Q: What are deepfakes?

A: Deepfakes are AI-generated images, videos, or audio recordings designed to closely imitate real people. While they have legitimate uses, they can also be used to impersonate individuals or commit fraud.

Q: What is zero trust?

A: Zero trust is a security model based on continuous verification rather than automatic trust. Instead of assuming a user or device is trustworthy after one login, organizations continuously validate identities and actions.

Q: What is shadow AI?

A: Shadow AI refers to employees using AI tools that haven’t been approved or governed by their organization. While often well-intentioned, it can introduce security, privacy, and compliance risks.

Q: Why shouldn’t organizations simply block AI tools?

A: Employees typically adopt AI because it helps them work more efficiently. Rather than banning AI outright, organizations should provide approved tools, establish clear policies, and educate employees on responsible use.

Q: What’s the biggest takeaway from this episode?

A: Trust isn’t disappearing because of AI – it’s evolving. Organizations that combine people, policies, and technology with continuous verification will be better positioned to adopt AI confidently and responsibly.

Katherine Demacopouloses directora sénior de Estrategia y Programas de Contenidos Globales en Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Our Chief Products Officer, Rajiv Kottomtharayil, recently wrote about a big shift that is taking place across industries. Frontier AI models are compressing the time between vulnerability discovery and exploitation.  

This shift is prompting organizations everywhere to re-examine their vulnerability management processes. We’re doing the same at Commvault. That’s why, starting August 11, we’re changing the rhythm of how we disclose vulnerabilities.  What’s ChangingWe are raising the bar for security, transparency, and customer trust. On August 11, and on the second Tuesday of each month after that, we’re introducing Patch Tuesdays: a scheduled monthly release where we share security advisories and vulnerability patches.  

Patch Tuesdays are a hallmark of leading technology companies, because they provide customers with a predictable security rhythm.  This matters even more as the pace of vulnerability discovery accelerates. Of course, if there is an urgent vulnerability that must be reported off cycle, we will not hesitate to follow our well-established processes.  

Where You Can Find Up-to-Date Resources  

On the second Tuesday of each month, you’ll find new information pertaining to CVEs on our Security Advisories page. You also can find the official publications at MITRE’s CVE site. 

On the Commvault Security Center, you’ll find our vulnerability management program and other security-by-design thought leadership.   

For compliance certifications, audit reports, and documentation on how Commvault protects customer data, visit the Centro de confianza de Commvault. You can subscribe to updates from the Trust Center at the link in the upper righthand corner of the page. 

Bill O’Connell is Chief  Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

For decades, technology leaders have been trying to eliminate silos. Entire modernization programs have been built around connecting applications, consolidating platforms, and giving organizations a more complete view of their data.

Those efforts have delivered enormous value, but they also have shaped the way we think about resilience. When something goes wrong, we instinctively look for technical fragmentation. However, we’ve found the greater challenge lies elsewhere.

The most significant silos affecting cyber resilience today aren’t found in databases or applications but in organizational structures. They exist between security and infrastructure teams, between IT and the business, and between the people responsible for responding to an attack and those responsible for keeping the organization operating.

IDC’s latest research on ResOps, Resilience Operations: The Discipline that Makes Readiness Provable, suggests these organizational boundaries have become one of the defining obstacles to effective recovery. That’s a timely observation because cyberattacks have evolved in ways that can make those boundaries increasingly difficult to maintain.

Modern Attacks Don’t Follow Your Org Chart

A modern cyberattack rarely affects a single technology domain. A ransomware incident might begin with compromised identities, spread through cloud infrastructure, encrypt critical workloads, disrupt customer-facing applications, impact third-party services, and trigger regulatory Informeing requirements – all within a matter of hours. Every stage involves different teams, different tools, and different priorities.

Yet many organizations still prepare for recovery as though these responsibilities can be managed independently.

Security teams naturally focus on containing threats and preserving evidence. Infrastructure teams prioritize restoring systems and minimizing downtime. Business leaders concentrate on customers, revenue, and operational continuity. Communications teams think about reputation, while legal and compliance teams focus on regulatory obligations.

Each perspective is entirely reasonable. The problem arises when those priorities have never been reconciled before an incident occurs.

In the middle of a crisis, recovery requires decision-making under pressure. Which applications should return first? Which data can safely be restored? How much risk is acceptable before customer services resume? Who has the authority to make those decisions?

Without alignment, organizations often discover that the greatest delays aren’t caused by technology but by uncertainty – the kind that could be mitigated by better preparation.

Resilience Begins with a Shared Definition of What Matters

The Informe places emphasis on establishing your minimum viable business (MVB). At first glance, it appears to be another recovery planning exercise, but its real value lies in the conversations it forces organizations to have.

Defining an MVB requires business leaders, security teams, infrastructure specialists, and application owners to agree on a deceptively simple question: What absolutely must continue operating if everything else stops?

That discussion changes the nature of resilience planning. Recovery priorities are no longer determined by whichever application owner argues most convincingly during an incident. Instead, they are established in advance, grounded in business outcomes, and supported by technical dependencies that everyone understands.

Perhaps more importantly, MVB creates a common language. Business leaders begin talking about critical capabilities rather than individual systems. Technology teams begin mapping infrastructure to customer outcomes rather than technical architectures. Security teams gain greater clarity about which assets deserve the highest levels of protection during recovery.

That shared understanding is precisely what many organizations have been missing.

Technology Can Automate Recovery – But it Can’t Create Alignment

The Informe doesn’t argue that organizations need yet another platform. It argues they need a way of working that aligns people, processes, and technology around a single operational objective. This is where ResOps – a cross-functional discipline – proves its mettle.

Technology can help automate recovery, but it cannot resolve disagreements about business priorities. It cannot decide which customer services matter most. And it cannot replace the governance needed to coordinate multiple teams during a high-pressure event.

Those are leadership challenges, and they are best addressed by investing time in answering the difficult questions together, long before an attack forces your hand.

The Strongest Organizations Don’t Eliminate Silos – They Connect Them

Cyberattacks will continue evolving. AI will continue compressing attack timelines. New technologies will introduce new dependencies, and new threats will emerge alongside them. None of that changes the fundamental requirement for resilience.

Organizations don’t recover because individual teams perform brilliantly in isolation, but because those teams already know how to work together.

That may ultimately be the most important insight from IDC’s research. Resilience isn’t simply the product of better technology or more sophisticated security controls. It is the result of shared priorities, clear governance, and a tested operating model that brings the right people together before an incident occurs.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Learn about our advances through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

By Sustainability Team

As AI adoption accelerates, cyber threats are becoming more sophisticated, and data regulations are expanding. Resilience is no longer simply a defensive posture – it is a business imperative and competitive advantage.

That belief is at the center of Commvault’s FY26 Sustainability Report, which is now available. This year’s report reflects the progress we’ve made across the areas that matter most to our business, our customers, our people, and the communities where we live and work.

Anchored by our updated materiality assessment, the report highlights how we are advancing sustainability through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

Cyber resilience remains foundational to our work. As organizations rethink what it means to be ready for disruption, Commvault continues to unify data security, identity resilience, and cyber recovery to help customers detect threats faster, operate more efficiently, and recover with greater confidence. We also are integrating AI and automation designed to support smarter, more secure, and more resilient operations.

That same focus on resilience extends to our environmental commitments. Our solutions help customers optimize data storage and movement, which can help reduce energy expenditure in data centers. For Commvault, responsible innovation means building solutions that support both operational strength and more efficient use of resources.

The report also reflects the people and principles behind our progress. Strong governance, a modern Code of Ethics, and continued investment in our talent help create the foundation for trusted partnerships and long-term value. These commitments are deeply connected: Strong governance enables responsible innovation, responsible innovation helps strengthen the security and efficiency our customers depend on, and that trust is sustained by the people who bring our mission to life every day.

We invite you to read Commvault’s FY26 Sustainability Report as both a record of our progress and a look forward to the priorities that will shape our next chapter.

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

A few years ago, digital sovereignty was largely viewed as a compliance conversation. If you stored data in the right geography, met the right regulatory requirements, and satisfied a handful of audit questions, you could generally move on.

That’s no longer the case.

Today, sovereignty has become a board-level discussion. Governments are rewriting policies. Regulators are increasing scrutiny. And business leaders are starting to recognize that sovereignty isn’t just about where data resides – it’s about how organizations continue operating when geopolitical, legal, or operational assumptions suddenly change.

In the first episode of our STRIVE series on digital sovereignty, I sat down with Max Mortillaro, co-founder and Chief Research Officer at Osmium Data Group. Together, we unpack what sovereignty actually means, why the conversation has accelerated so quickly, and where organizations are most likely to get it wrong.

Watch the episodio completo.

Puntos Clave

  • Digital sovereignty is no longer just a compliance issue – it has become a resilience and business continuity concern.
  • Data location is only one piece of the puzzle. Jurisdiction, operations, technology dependencies, and governance all matter.
  • Many organizations focus on technical controls before understanding the business problem they’re trying to solve.
  • Geopolitical uncertainty is accelerating sovereignty initiatives, particularly across Europe.
  • There is no such thing as a perfectly sovereign environment. Every organization must make informed trade-offs between risk, cost, and operational requirements.

Why Data Location Isn’t the Whole Story

One of the most common misconceptions around digital sovereignty is that it begins and ends with geography. If data is stored in a local data center, the thinking goes, the sovereignty problem has been solved.

It’s an understandable assumption. After all, many of the early conversations around sovereignty focused heavily on data residency requirements and where information could legally be stored.

But as Max points out during our discussion, that’s only one dimension of a much larger challenge. Sovereignty isn’t simply about where a data center sits. It’s also about who operates it, which laws apply to it, who has access to it, and what dependencies exist behind the scenes.

A cloud service may be physically located within a specific country, but that doesn’t necessarily mean it’s insulated from legal, operational, or technological influence originating elsewhere.

That’s where the conversation becomes significantly more complex.

The Hidden Dependencies Most Organizations Overlook

When organizations first begin exploring sovereignty, they often approach it as a technology project. They evaluate hosting locations. They assess replication strategies. They examine where workloads should run.

Those conversations are important, but they can also create a false sense of confidence.

As Max explains, modern technology environments are built on layers of dependencies that aren’t always visible. A service may appear local on the surface but it may be relying on infrastructure, management systems, telemetry services, or operational controls that exist elsewhere.

That’s why sovereignty isn’t simply a question of location. It’s a question of influence.

Who ultimately controls the service? Which legal jurisdiction applies when disputes arise? What happens if geopolitical tensions introduce new restrictions, regulations, or limitations on access?

These aren’t hypothetical questions anymore. They’re becoming part of real-world risk assessments.

Sneak Peek: Sovereignty Is More Than a Technical Problem

In this segment from the conversation, Max explains why organizations often start sovereignty discussions in the wrong place – and why understanding the legal, operational, and business objectives must come before any technology decisions.

Why Europe Is Driving the Conversation

One of the most interesting parts of our discussion focuses on why sovereignty has become such a dominant topic across Europe.

The answer isn’t just regulation; it’s dependency.

European organizations have become increasingly aware that many of the technologies they rely on every day are owned, operated, or governed outside of their direct control. For years, that reality was largely accepted as part of the global technology ecosystem.

Today, that assumption is being reevaluated.

Geopolitical tensions, evolving regulations, and increasing concern around strategic autonomy have pushed sovereignty higher on the priority list for governments and enterprises alike. What was once considered an edge case has become a mainstream business concern.

The result is a growing recognition that resilience isn’t only about recovering from technical failures. It’s also about understanding and managing external dependencies before they become business disruptions.

Sovereignty and Resilience Are the Same Conversation

One of the themes that you’ll see repeatedly surfacing throughout the discussion is how closely sovereignty and resilience are connected.

At first glance, they may seem like separate disciplines. One focuses on governance, regulation, and control. The other focuses on recovery, continuity, and operational readiness.

In practice, they’re deeply intertwined.

If a business cannot access critical systems because of a geopolitical event, regulatory restriction, or third-party dependency, the outcome isn’t very different from other disruptions organizations spend years preparing for.

The business still needs to operate. Customers still need to be served. Recovery still needs to happen.

That’s why I increasingly view sovereignty through the same lens as cyber resilience. Both are fundamentally about reducing exposure to events that could disrupt operations and preparing the organization to continue functioning when those events occur.

Start With the Business Problem

Perhaps the most practical advice Max shares is also the simplest.

Before evaluating sovereign cloud offerings, before engaging vendors, and before debating technical architectures, organizations should first understand what problem they’re trying to solve.

That means understanding:

  • Which business processes are most critical.
  • Which data assets matter most.
  • Which regulatory requirements apply.
  • Which risks are truly being mitigated.

Only after those questions are answered does it make sense to evaluate technology options.

Too often, organizations start with solutions and work backward toward the problem. Sovereignty requires the opposite approach. The strategy should come first.

The architecture follows.

Why There Is No Perfect Answer

One of the realities leaders need to accept is that there is no such thing as a perfectly sovereign environment.

Every organization operates within a network of dependencies. Every technology choice introduces trade-offs. Every risk decision involves balancing operational requirements, compliance obligations, cost considerations, and business outcomes.

The goal isn’t perfection. The goal is understanding those trade-offs well enough to make informed decisions.

Organizations that approach sovereignty as a binary yes-or-no question often find themselves frustrated. Organizations that approach it as a risk-management exercise tend to make better progress.

Estas preguntas formarán parte cada vez más de las conversaciones sobre riesgos, los debates sobre adquisiciones y la planificación tecnológica a largo plazo. Porque la criptografía no se detiene en los límites de la organización. Tampoco lo hace el riesgo.

Digital sovereignty is moving quickly from a niche compliance topic to a strategic business issue.

Boards are asking questions. Regulators are increasing scrutiny. Customers are becoming more aware of where their data lives and who controls it.

At the same time, geopolitical uncertainty continues to reshape how organizations think about risk.

That doesn’t mean every company needs a radical sovereignty transformation tomorrow.

But it does mean that the organizations that start building a clear strategy today will be in a much stronger position than those who wait until the conversation becomes unavoidable.

Sovereignty isn’t a technology decision masquerading as a business problem. It’s a business problem that requires legal, operational, and technical decisions working together.

La conclusión más importante de este debate es que la criptografía poscuántica ya no es un reto tecnológico del futuro.

Se está convirtiendo en un debate sobre la resiliencia en el presente.

Las organizaciones no tienen por qué entrar en pánico ni necesitan renovar todos los sistemas de la noche a la mañana. Pero sí deben empezar a actuar, para aprovechar al máximo el tiempo del que disponen para prepararse.

Las organizaciones que superen con éxito esta transición no serán necesariamente aquellas que cuenten con la criptografía más sofisticada. Serán aquellas que hayan empezado a formarse una idea del tema antes de que llegara la certeza.

Y así es, a menudo, como funciona la resiliencia.

In this installment, Max and I explore:

  • What digital sovereignty actually means.
  • Why data location alone isn’t enough.
  • The legal and operational dimensions organizations often overlook.
  • How geopolitical developments are influencing sovereignty strategies.
  • Why sovereignty and resilience are becoming inseparable.

Ver ahora.

Preguntas frecuentes

Q: What is digital sovereignty? 

A: Digital sovereignty refers to an organization’s ability to maintain control over its data, technology, operations, and governance within specific legal and jurisdictional boundaries.

Q: Is digital sovereignty the same as data residency? 

A: No. Data residency is one component of sovereignty, but sovereignty also includes legal jurisdiction, operational control, technology dependencies, and governance.

Q: Why has digital sovereignty become more important recently? 

A: Growing geopolitical uncertainty, evolving regulations, and increasing concern about technology dependencies have accelerated interest in sovereignty initiatives.

Q: What is the biggest mistake organizations make? 

A: Treating sovereignty as a purely technical challenge instead of a broader business risk and resilience issue.

Q: How does sovereignty relate to cyber resilience? 

A: Both disciplines focus on maintaining operational continuity in the face of disruptions, whether those disruptions are technical, legal, geopolitical, or regulatory.

Q: Where should organizations begin? 

A: Start by understanding the business outcomes you’re trying to protect, the risks you’re trying to mitigate, and the data and processes that are most critical to your operations.

Alex Zinin is VP/GM of Managed Service Providers at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave

  • The role of the backup administrator is evolving from managing infrastructure to delivering business resilience and recovery confidence.
  • Modern ResOps (resilience operations) focus on recovery readiness, continuous validation, governance, and business outcomes – not just successful backup jobs.
  • Autonomous Resilience is Commvault’s vision for the next evolution of ResOps, waquí AI helps resilience teams reduce operational overhead through intent-driven, governed workflows while maintaining human oversight, approvals, and auditability.
  • By helping reduce repetitive operational work, AI enables resilience teams to spend more time improving cyber recovery, governance, and recovery readiness.
  • The future of resilience will be measured by confidence in recovery – not simply the successful completion of protection activities.

The Operational Shift at 8 a.m.

For an enterprise backup administrator, the morning routine has long followed a predictable, high-stress pattern. You log in at 8 a.m. to face a wall of dashboards. Taquí are thousands of completed protection activities, but your eyes naturally scan for the exceptions – a handful of failed workloads, replication delays, and capacity alerts warning that critical storage resources are nearing their thresholds.As you begin sorting through the day’s priorities, the reality of modern infrastructure closes in. A virtualization administrator submits a request: Dozens of new workloads were provisioned overnight, and leadership needs to know whether they are automatically covered by existing protection policies.Moments later, the compliance team requests a detailed history of protection success and retention validation to prepare for an upcoming audit. Then, the security operations center (SOC) calls. An anomaly has been detected on a critical system, and they need confirmation that recovery copies remain isolated, immutable, and uncompromised.Before you can finish your first cup of coffee, leadership asks a simple but devastating question: “If we were hit by ransomware right now, how consistently and confidently could we recover?”

Ten years ago, a successful backup administrator was an infrastructure gatekeeper. Success was binary and infrastructure-centric: Did the jobs finish within the required time window? Was the data successfully protected? If the dashboard was green, the job was done.Today, that paradigm is entirely broken. The modern enterprise does not care whether data protection jobs completed successfully. It cares whether the business can survive a catastrophic disruption.Success is no longer measured by the completion of a background data protection process. It is measured by an organization’s ability to withstand ransomware, infrastructure failures, cloud outages, insider threats, and compliance events without losing data or operational momentum.The role has fundamentally evolved from infrastructure management to enterprise resilience. Yet many organizations still force administrators to spend their days managing operational tasks instead of architecting recovery confidence.Commvault is working to redesign the administrator experience to help break this cycle, enabling a shift from reactive backup management toward comprehensive ResOps.

The Drag of the Modern Administrator’s Daily Reality

To understand why this shift is necessary, one must first recognize the enormous operational burden carried by administrators every day. Consider the volume of tactical work required to maintain a modern enterprise protection environment:

  • Job and infrastructure monitoring: Reviewing overnight activities, distinguishing transient issues from legitimate failures, and validating infrastructure health across a rapidly changing hybrid environment.
  • Troubleshooting and issue resolution: Spending hours reviewing diagnostic information and operational telemetry to determine why processes stalled, services became unavailable, or critical workloads failed unexpectedly.
  • Resource optimization and performance management: Continuously identifying storage constraints, network bottlenecks, or infrastructure limitations that impact protection and recovery objectives, then manually expanding capacity as requirements grow.
  • Workload discovery and lifecycle management: Automatically discovering, classifying, and assigning appropriate protection policies to newly deployed applications, cloud services, databases, and infrastructure resources.
  • Capacity and storage management: Monitoring consumption trends, forecasting growth, and responding to unexpected increases before they threaten recovery objectives.
  • Audit and compliance support: Collecting reports, validation records, and historical evidence across multiple systems to demonstrate compliance with retention and governance requirements.

Every hour spent troubleshooting an operational issue or assembling compliance evidence is an hour taken away from strategic resilience planning. This is waquí resilience teams lose time. The challenge is the operational overhead required to keep protection systems synchronized with a constantly evolving hybrid cloud environment.

The Structural Shift: From Backup Operations to ResOps

As organizational risk profiles increasingly center around cyber resilience and business continuity, the very mindset of data protection must evolve.

Old Mindset: Backup Operations

“I need my protection jobs to finish successfully.” 

New Mindset: ResOps

“I need confidence that we can recover immediately.” 

This evolution fundamentally changes the questions administrators must answer.

Backup Operations  ResOps
Did the workload complete protection last night? Are our critical applications verified as recoverable?
How much storage capacity remains? What is our verified recovery readiness posture?
Are recovery copies synchronized? Are our recovery environments protected and isolated?
Can we restore a single file? Can we recover an entire business service during a cyber event?

In this new model, recovery – not backup – becomes the primary operational metric. 

An organization can achieve near-perfect protection success rates while remaining dangerously unprepared for a ransomware attack due to compromised credentials, hidden dependencies, configuration drift, or unverified recovery processes.ResOps assumes disruption is inevitable. The focus shifts toward continuous validation, proactive risk identification, threat awareness, and deterministic recovery orchestration.At Commvault, we see this evolution leading toward Autonomous Resilience, waquí AI helps resilience teams move from manual operations toward intent-driven, governed outcomes.

How Commvault is Redesigning the Experience Around Outcomes

Commvault is addressing these realities by working to redesign the administrator experience. Rather than requiring users to organize their work around infrastructure configurations, protection policies, storage resources, and system assignments, Commvault is shifting the experience toward outcomes that matter to the business.

  • Unified management and risk-driven visibility: Rather than navigating multiple interfaces to manage different environments, administrators gain visibility into their entire estate through a unified resilience experience.The focus extends beyond operational status. The platform highlights risk exposure, protection gaps, emerging threats, unprotected workloads, and configuration drift that could impact recovery readiness.
  • Policy simplification and intelligent automation: Traditional environments often require administrators to manage hundreds of static schedules and policies. Commvault is designed to replace this complexity with intent-based protection plans.

    Administrators define business outcomes, while the platform can automatically orchestrate the infrastructure, optimize workflows, and manage protection activities behind the scenes.

  • Continuous validation and clean recovery environments: True resilience requires confidence not only in protected data but also in the ability to restore it safely.

    Commvault can integrate automated recovery validation directly into operations. This includes the ability to orchestrate isolated recovery environments waquí systems can be restored, validated, and inspected before production restoration occurs.

  • Threat-aware operations and intelligent detection: Modern resilience requires more than monitoring activity counts. By applying advanced analytics and machine learning to operational telemetry, the platform establishes historical baselines and detects abnormal behavior.

    When suspicious activity occurs, administrators receive contextual explanations, probable causes, impact assessments, and recommended actions – not just generic alerts.

A Day in the Life: The Outcome-Driven Workflow

To understand the potential impact of this transformation, consider an illustrative day for an administrator within an outcome-focused resilience platform. The scenario below shows how these capabilities are intended to work together.

8 a.m. – Establishing Recovery Readiness

Instead of searching through thousands of activities and alerts, you open a resilience dashboard displaying a comprehensive Recovery Readiness Score across the environment. The platform highlights a scaling concern. Recently deployed workloads have increased demand beyond recommended operational limits.Rather than manually expanding infrastructure and coordinating resources, the platform automatically recommends a corrective action: “Additional infrastructure capacity is recommended to maintain recovery objectives. Approve?” 

A single approval initiates the adjustment.

11:30 a.m. – Automated Audit Resolution

The compliance team requests evidence of protection activity and policy compliance for a previous reporting period. Rather than manually compiling reports and spreadsheets, the administrator generates a compliance package containing validation records, policy compliance evidence, and supporting documentation within minutes.Time is spent improving resilience – not producing paperwork.

2 p.m. – Threat Detection and Autonomous Response

A critical anomaly is detected. A workload exhibits behavior that significantly deviates from normal historical patterns.Instead of issuing a generic warning, the platform automatically correlates the event with known behaviors, evaluates potential causes, assesses business impact, and identifies clean recovery points.If a cyberattack is suspected, the platform highlights affected recovery data, isolates impacted assets, validates clean recovery options, and prepares recommended recovery actions.The administrator is no longer investigating what happened. The platform is helping determine what to do next.

The Power of Intent: Why Embedded Intelligence Changes Everything

The engine powering this transformation is the move from manual task execution to autonomous, intent-driven operations.Commvault’s conversational and AI-driven capabilities are designed to support the operational model that this transformation requires:

  1. An administrator expresses intent.
  2. The platform gathers context.
  3. Recommendations are generated.
  4. Actions are executed with appropriate oversight.
  5. Outcomes are validated.
  6. Activities are documented automatically for governance and audit purposes.

This fundamentally changes the relationship between administrators and the underlying technology. The goal is no longer to manage systems. The goal is to direct outcomes.

From Diagnostics to Actionable Root Cause

When infrastructure issues occur, administrators traditionally have spent hours reviewing diagnostic information, searching for symptoms, and piecing together dependencies. Embedded intelligence continuously monitors infrastructure health, operational telemetry, and service activity patterns. When an issue arises, diagnostic information can be analyzed automatically, probable causes identified, and remediation recommendations generated without requiring manual investigation.

Multi-Workload Dependency Correlation

Modern environments are interconnected ecosystems. A single infrastructure issue can generate hundreds of downstream failures. Rather than forcing administrators to investigate each event individually, the platform automatically correlates failures and identifies shared infrastructure dependencies, common services, or connectivity issues contributing to broader disruption.

Proactive Resource Forecasting

Instead of waiting for operational failures, the platform continuously analyzes historical workload patterns, growth trends, and infrastructure utilization. Expected changes are separated from abnormal behavior, allowing resilience teams to proactively address capacity and performance concerns before they impact recovery readiness.

The Rise of the Resilience Engineer

The data protection industry is undergoing a profound transformation. The title of backup administrator is rapidly becoming an artifact of a previous era – one in which data protection was viewed primarily as an operational task supported by infrastructure checklists.Tomorrow’s successful professional is a resilience engineer. They collaborate with security teams to design cyber recovery strategies. They work alongside compliance leaders to automate governance requirements. They provide executives with measurable confidence in the organization’s ability to recover from disruption. Their value is no longer defined by how effectively they manage operational complexity, but by how effectively they reduce business risk and accelerate recovery.Commvault is not simply enhancing an existing backup platform. It is helping build the operational framework for the next generation of resilience leadership. By helping reduce administrative overhead, simplify operations, and align the experience around recovery readiness and continuous validation, Commvault is enabling administrators to focus on what matters most: helping the business remain resilient. 

The future of enterprise availability is no longer about managing backups. It is about delivering autonomous resilience. 

Continue the Conversation

The conversation around Autonomous Resilience is just beginning. At SHIFT 2026 in Nashville this November, we’ll explore how AI is reshaping ResOps and what it means for the next generation of resilience engineers. Register aquí.

Preguntas frecuentes

Q: Why is the role of the backup administrator changing?

A: Enterprise resilience is no longer measured by successful backup jobs alone. Organizations increasingly judge resilience by their ability to recover confidently from ransomware, cloud outages, infrastructure failures, and other disruptions. As a result, backup administrators are taking on a broader role that spans cyber resilience, governance, recovery readiness, and business continuity.

Q: What is ResOps (resilience operations)?

A: ResOps reflects the shift from managing backup infrastructure to managing recovery readiness. It brings together data protection, cyber recovery, governance, continuous validation, and operational visibility into a single discipline focused on helping organizations recover with confidence.

Q: What is Autonomous Resilience?

A: Autonomous Resilience is Commvault’s vision for the next evolution of ResOps. It applies AI to help resilience teams reduce operational overhead through intent-driven, governed workflows that gather context, recommend actions, execute approved tasks, validate outcomes, and maintain auditability throughout the recovery process.

Q: How will AI change the day-to-day work of resilience teams?

A: AI can help reduce repetitive operational work such as reviewing backup activity, investigating failed workloads, collecting compliance evidence, assessing recovery readiness, identifying clean recovery points, and recommending recovery actions – all while operating within established governance controls. This allows administrators to spend more time improving resilience strategy and less time performing routine operational tasks.

Q: Does Autonomous Resilience replace backup administrators?

A: No. Autonomous Resilience is designed to augment resilience professionals, not replace them. Administrators remain responsible for oversight, approvals, governance, and decision-making while AI helps reduce operational overhead and supports day-to-day resilience operations.

Q: Why is this important now?

A: Hybrid infrastructure, cyber threats, AI adoption, and increasing operational complexity are changing what organizations expect from backup and recovery teams. The role is evolving from managing infrastructure to delivering resilience, making recovery readiness, governance, and operational confidence more important than ever.

Rajiv Kottomtharayiles director de productos de Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience