Skip to content

Puntos Clave

  • Advanced AI models like Claude Mythos Preview could dramatically accelerate vulnerability discovery, reshaping the cybersecurity landscape.
  • Mythos highlights growing concerns about managing AI-enabled security risks at scale.
  • ResOps helps shift organizations from reactive defense to proactive resilience and recovery.
  • Cybersecurity tools focus heavily on prevention, while recovery capabilities remain underdeveloped.
  • In an AI-enabled world, the ability to recover quickly from disruption will define operational success.

Anthropic’s new Claude Mythos Preview modelis reportedly powerful enough to identify vulnerabilities in software systems in seconds. In early testing, the company claims the model was able to break out of its containment environment and email an engineer about the event.
Given these potential risks, Anthropic is limiting access to a small group of large organizations throughMythos. The goal: stay ahead of the security implications of a world where vulnerability discovery and exploitation may become trivial.
This shift strengthens the case for resilience operations (ResOps™). It could fundamentally change how organizations approach cybersecurity.
In a recent LinkedIn post, “The Beginning of the End of Cybersecurity,” Jen Easterly, CEO of RSAC and former director of CISA, argues that today’s cybersecurity industry is built to identify, defend against, and respond to software defects.
In effect, it compensates for gaps in software quality and secure development practices. If models like Claude Mythos Preview perform as described, their ability to surface vulnerabilities at scale could significantly disrupt today’s security tooling landscape.
A recent STRIVE episode – Evidence Over Hope: Will Your Recovery Plan Hold Up Under Pressure? – echoes this concern. Organizations have invested heavily in tools to prevent attacks, yet relatively little innovation exists “right of boom” – the capabilities required to recover the business when disruption inevitably occurs.

Why ResOps?

ResOps is an organizational discipline that embeds resilience into daily operations. It shifts organizations from passive, reactive backup strategies to an active, continuous model.
Traditional IT operations focus on efficiency. ResOps focuses on surviving failure. It brings together security, infrastructure, and operations teams around a common goal: Identify the organization’s minimum viable business – the critical systems, data, and processes required to operate – and enable those services to be restored quickly and cleanly after a disruption.
Most operational disciplines optimize for when systems work as expected. ResOps is designed for when they don’t. Its core question is simple: Can you recover each critical service right now – with confidence and evidence?

What Does the Future Hold?

If Easterly’s perspective proves accurate – that cybersecurity largely compensates for software defects – then technologies like Claude Mythos Preview represent more than incremental progress. They signal a structural shift in enterprise risk.
AI may help reduce the time between vulnerability discovery and remediation. It may even eliminate certain classes of software flaws. But it does not remove the risk of outages, misconfigurations, identity compromise, or cascading failures in complex systems. And it does not replace the operational discipline required to respond and recover.
Failure will still happen. That reality makes ResOps more important – not less. As prevention becomes more automated, resilience becomes the differentiator. Organizations will no longer be measured solely by their ability to block attacks. They will be measured by how effectively they recover – restoring critical services and trusted data under real-world conditions.
Cybersecurity aims to keep threats out. ResOps prepares you for when they get in. In an AI-accelerated world, the ability to survive and recover from failure may be the most important operational capability an organization can build.
Read more in our Readiness Report, Evidence Over Hope: The Executive Case for Resilience Operations, and learn more about theResOps disciplineen elReadiverse.

Preguntas frecuentes

Q: What is Mythos, and why does it matter?

A: Mythos is an initiative by Anthropic to limit and study access to powerful AI models capable of identifying software vulnerabilities. It matters because it signals a future where vulnerability discovery becomes fast and widespread, increasing both defensive and offensive risks.

Q: What is ResOps, and how is it different from traditional IT operations?

A: ResOps is a discipline focused on enabling organizations to survive and recover from disruptions. Unlike traditional IT operations that prioritize efficiency, ResOps prioritizes continuity and rapid recovery of critical services.

Q: How could AI impact the future of cybersecurity?

A: AI may significantly reduce the time needed to detect and fix vulnerabilities, potentially disrupting existing security tools. However, it does not eliminate risks like outages or misconfigurations, making recovery capabilities even more important.

Q: Why is recovery becoming more important than prevention?

A: Despite heavy investment in preventive tools, disruptions still occur. As threats evolve and automation increases, organizations will be judged more on how quickly and effectively they can restore operations after an incident.

Q: What does “right of boom” mean in this context?

A: “Right of boom” refers to the phase after an incident has occurred, focusing on response and recovery. It highlights the gap in innovation around restoring business operations compared to preventing attacks.

Q: How can organizations start adopting ResOps?

A: Organizations can begin by identifying their minimum viable business – critical systems and data – and building processes to restore them quickly. This involves aligning security, IT, and operations teams around resilience-focused goals.

Jason Meserve is Director of Social Marketing at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave

  • Rising operational disruption makes scalable resilience essential, but organizations commonly fall into traps like seeking “silver bullet” technology or relying on “hero worship” of individual experts.
  • ResOps ofrece un marco escalable que integra a las personas, los procesos y la tecnología en ITOps, SecOps y DevOps.
  • El apoyo de la alta dirección, a nivel de director general, ayuda a fomentar la responsabilidad y a dar prioridad a la resiliencia como disciplina estratégica.

Cyberattacks, cloud complexity, and AI-enabled threats are creating constant operational challenges for enterprises. To help meet business requirements in this increasingly disruptive environment, organizations need to move beyond separate recovery tools, teams, and plans to resilience as an integrated operating model.

In a recent webinar, Phil Goodwin, research vice president for IDC’s worldwide infrastructure programs, joined me for a fireside chat to explore how organizations can move beyond fragmented approaches to build resilience that scales.

Por qué las organizaciones necesitan un nuevo marco de resiliencia

As organizations engage in daily firefighting while keeping up with new technologies and addressing new initiatives, they rarely have time to step back and reassess whether their approaches still meet requirements. But as isolated incidents become systemic disruption, this conversation has become essential.

In a simpler era, organizations focused primarily on backup and recovery. Large-scale disruptions such as Hurricane Sandy brought disaster recovery onto the agenda. Intensifying cyberthreats like ransomware added cyber resilience and business continuity to the list. Each evolution brought new capabilities, but many organizations simply bolted new approaches onto what they were already doing rather than addressing these expanding requirements holistically.

When separate teams manage different pieces with different tools and policies, gaps may emerge that can slow recovery. Despite years of investment in cybersecurity, organizations are still struggling with recovery.

More recently, AI has accelerated the urgency for a more integrated approach by reshaping both threats and defenses. Despite increasing AI investments, many businesses are delaying AI rollouts due to ongoing concerns about governance and security vulnerabilities.

On the other side of the cyber front, bad actors are using AI to create deepfakes, target users with more sophisticated and convincing phishing, and exploit vulnerabilities at scale.

Resilience operations – ResOps – treats resilience as a continuous operating discipline rather than a collection of separate tools and teams. By bringing together ITOps, SecOps, and DevOps under a unified framework, ResOps helps transform resilience to keep pace with systemic disruption.

Cómo evitar los errores más comunes en la planificación de la resiliencia

Even organizations that recognize the need for change often fall into traps. One is the “silver bullet” problem, which focuses on technology as the solution. Leaders want to believe that buying the right tools will solve everything, but technology alone can’t deliver positive business outcomes without proper integration and process.

“Hero worship” is another common pitfall – relying on talented staff members with expertise residing in their heads rather than in documented processes. Heroism can’t scale, and reliance on specific individuals creates vulnerability when people leave or responsibilities shift.

To move past these traps, you have to think differently about your operating model. Instead of focusing primarily on technology and people, consider the team you’ll need to build, including executive sponsorship, IT operations and security leadership, and senior leaders from the business side.

The team’s charter should focus on defining business outcomes first: What does resilience need to achieve for the organization? What KPIs, SLAs, and processes should be established to meet these requirements?

Desarrollar operaciones de resiliencia de arriba abajo

Como prioridad a nivel de la junta directiva, la resiliencia requiere el apoyo de los más altos cargos. Las operaciones de resiliencia (ResOps) cobran mayor impulso cuando el director general se implica, ayudando a establecer las prioridades en materia de recursos e impulsando la rendición de cuentas en toda la organización. Con el respaldo de la dirección, los altos directivos —como el director de sistemas de información (CIO), el director técnico (CTO), el director de seguridad de la información (CISO) y los directores generales— pueden encargar a su personal la puesta en marcha.

Este enfoque se puede adaptar a organizaciones de cualquier tamaño. Incluso las empresas pequeñas y medianas pueden formar equipos multifuncionales que incluyan a las partes interesadas del negocio, a los equipos de TI y al personal encargado de la seguridad de los datos y de la red. A medida que crecen, esta estructura puede adaptarse a sus necesidades, incorporando personal en disciplinas específicas relacionadas con la resiliencia, al tiempo que se mantiene un enfoque integrado en toda la cadena de operaciones de resiliencia. ResOps refleja la forma en que los equipos de operaciones de TI, SecOps y DevOps deben trabajar juntos dentro de las organizaciones. La recuperación de datos y la seguridad de los datos se han alineado tan estrechamente que, en IDC, los investigadores de estas disciplinas colaboran ahora con frecuencia en proyectos con clientes. Ahora hay que diseñar las aplicaciones teniendo en cuenta a los atacantes, incorporando arquitecturas de «confianza cero» y partiendo de la base de que algo va a salir mal. ResOps ofrece el marco necesario para esta convergencia, uniendo las herramientas de seguridad y de operaciones en un modelo unificado para hacer frente a amenazas e interrupciones de todo tipo.

ResOps como marco común para el sector

ResOps is an operating model, not a product, and can benefit companies regardless of the specific tools they use. As Phil observed during our chat, “It really requires that community involvement where people pitch in from different perspectives, different vendors, different organizations, and different teams, just like DevOps or SecOps.”

For organizations struggling with constant disruption and the growing complexity of AI-enabled threats and defenses, ResOps offers a path beyond fragmented resilience approaches. By bringing together people, processes, and technology in a unified operating model, ResOps turns fragmented recovery efforts into enterprise-wide readiness.

Watch my charla informal completa con Philpara ver cómo ResOps puede ayudarte a desarrollar una resiliencia empresarial que se adapte a tus necesidades.

Preguntas frecuentes

P: ¿Qué son las operaciones de resiliencia (ResOps)?

R: ResOps es un modelo operativo que integra las operaciones de TI, las operaciones de seguridad y DevOps en una disciplina continua. En lugar de tratar la recuperación ante desastres, la ciberresiliencia y la continuidad del negocio como capacidades independientes, ResOps aúna a las personas, los procesos y la tecnología bajo un marco unificado para ayudar a crear una resiliencia empresarial escalable.

P: ¿Por qué es importante el apoyo de la dirección para la resiliencia cibernética?

A: Executive sponsorship – ideally at the CEO level – helps drive accountability and priority for resilience initiatives across the organization. This top-down support is essential for organizations trying to move beyond fragmented approaches to integrated resilience operations.

P: ¿Pueden las pequeñas y medianas empresas implementar ResOps?

R: Sí. ResOps se puede aplicar a organizaciones de cualquier tamaño. El marco se adapta en complejidad a medida que las organizaciones crecen, lo que lo hace accesible para las empresas medianas sin dejar de ser eficaz para las grandes empresas.

P: ¿Por qué tienen que colaborar los equipos de TI y de seguridad para garantizar la resiliencia?

R: Cuando los equipos de operaciones de TI, de seguridad y de DevOps colaboran en lugar de trabajar de forma aislada, las organizaciones pueden contribuir a crear una infraestructura más resistente para hacer frente a las amenazas en constante evolución.

P: ¿Cómo deberían empezar las organizaciones con las operaciones de resiliencia?

R: Empieza por lo más alto, consiguiendo el respaldo de la dirección al nivel del director general. A continuación, forma un equipo multifuncional que incluya a miembros de operaciones de TI, SecOps y partes interesadas del negocio, y pídeles que definan los resultados empresariales que la resiliencia debe aportar a tu empresa. Realiza una evaluación de amenazas para comprender los riesgos que debes abordar. Solo tras dar estos pasos fundamentales deben las organizaciones centrarse en seleccionar tecnologías y desarrollar procesos detallados.

Chris Mierzwa es director sénior de marketing de cartera en Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Nota: Esta entrada del blog se publicó originalmente en octubre de 2025, cuando se presentó Data Rooms. Se ha actualizado para reflejar la siguiente evolución: Data Activate.

Puntos Clave

  • Data Activate is part of Commvault’s next-generation AI capabilities – alongside AI ProtectyAI Studio – anunciado to help organizations activate AI safely, govern AI agents,ybuild agentic workflows from Commvault Cloud.
  • Data Activate está diseñado para que puedas transformar backup en activos fiables y preparados para la IA, a la vez que te ayuda a mantener el control y el cumplimiento normativo.
  • La oferta une la protección de datos y la activación de la IA sin crear nuevos riesgos de seguridad ni requerir otra platform.
  • Se integra con ecosistemas de IA existentes, como Microsoft Azure y Snowflake, utilizando estándares abiertos como Apache Parquet e Iceberg.
  • La gobernanza integrada permite la gestión, clasificación y el intercambio de datos protegidos dentro de una arquitectura de confianza cero.
  • Al activar los datos históricos, las organizaciones pueden ayudar a acelerar la innovación en IA, el análisis y los flujos de trabajo de cumplimiento normativo de forma segura.

AI innovation depends on data – but not just any data. It depends on trusted, governed,yaccessible data. Yet for most enterprises, the data that could fuel AI lives deep within backups, scattered across environments,ywrapped in compliance constraints. That’s where Commvault’s Data Activate offering, previously known as Data Rooms, comes in.

Acelerar la IA de forma segura

Data Activate es una de las tres funciones de IA que Commvaultanunciado as part of its next-generation AI platform – alongside AI ProtectyAI Studio. As organizations race to adopt AI, many are running into a fundamental challenge: their data is fragmentedydifficult to use. According to a recent survey, el 68 % de las empresas cite data silos as their top concern.

Commvault’s Data Activate offering helps transform backup data – one of the most completeytrusted datasets an organization owns – into AI-ready assets. Data Activate helps enterprises safely connect their data to AIyanalytics platforms, without creating new risks or complexity.

Unlike earlier bulk export approaches, Data Activate can regularly publish updated datasets, making it easier to keep AI pipelines in sync with the most current trusted data. Teams also can identifyyexclude sensitive data – such as personally identifiable information – before activating datasets for analytics or model development.

The Data Activate offering is not another AI platform. It’s the bridge between data protectionydata activation, designed to make your existing AI investments work fasterysafer. It does this by creating governed, policy-controlled “rooms” inside Commvault Cloud – spaces where data can be classified, curated,yshared with AIyanalytics tools without leaving the protection boundary.

Escuchar a los clientes: se acabó Platform

We heard customers loudyclear: You don’t need another AI platform. You need a protected, simple way to use the data you already maintain – across the AI toolsyecosystems you’ve already chosen.

That’s why Commvault built Data Activate to integrate with partners like Microsoft AzureySnowflake using open-standard formats such as Apache ParquetyIceberg. This helps you keep your data portable, policy-compliant,yready for activation – wherever your AI strategy takes you.

Convertir la protección de datos en activación de datos

With Data Activate, authorized users can discover, classify,yprepare data directly from backup repositories – across on-premisesycloud environments. Built-in governance helps maintain control, allowing only approved datasets to be shared, with automated classification, sensitivity tagging, redaction,yaudit trails applied every step of the way.

Data Activate acts as a governed, policy-controlled workspace inside Commvault Cloud – where data can be curatedymade available to AI or analytics tools without leaving the protection boundary. This governed design provides a protected bridge between backup datayactivation workflows, helping organizations unlock their information for innovation while being able to maintain complianceycontrol.

Data Activate puede ayudarte a:

  • Accelerate insights: Quickly findyexport historical data in AI-friendly formats to train models or power analytics.
  • Simplify operations: Eliminate brittle ETL pipelines with automated data discoveryycuration.
  • Maintain compliance: Keep governance intact with policy-based controlsytraceability from backup to activation.

La confianza como base para una IA responsable

En la prisa por adoptar la IA, la confianza suele convertirse en daño colateral. Según unestudio, roughly three-quarters of surveyed IT leaders said that using AI could make their organizations more vulnerable to cyberattacks. That’s why Commvault built Data Activate within Commvault Cloud’s zero-trust architecture, complete with encryption, RBAC,ycompliance support.

By combining data protection, governance,yactivation in one platform, Commvault enables enterprises to accelerate AI innovation without compromising data security, compliance, or control.

Acelera la innovación sin añadir riesgos

Commvault’s Data Activate offering helps organizations move faster by making data safely accessible to the tools that drive their business forward – from AI model training to analytics, eDiscovery,ycompliance support automation. Because when backup data becomes usable data, enterprises unlock years of historical intelligenceycontext that most AI models simply don’t have.

As Pranay Ahlawat, Commvault’s Chief TechnologyyAI Officer, said: “Organizations are beginning to realize that their historical data is more than just insurance – it’s a powerful, untapped strategic asset. With Commvault Data Activate, enterprises can confidently export their secondary datayharness it with the AI platform of their choice to unlock new opportunities for intelligence, innovation,ybusiness growth.”

Por qué es importante ahora

Commvault’s Data Activate offering redefines what’s possible for enterprises that want to innovate responsibly. They make it possible to move from protecting data to activating data – safely, flexibly,yat scale.

In short: Commvault isn’t building another AI platform. We’re building the foundation that lets every AI platform work better – because when data is protected, trusted,yready for activation, innovation happens faster.


Preguntas frecuentes

Q: What is Commvault’s Data Activate offering?
A: Commvault Data Activate is a capability within Commvault Cloud that helps enterprises safely discover, classify,yactivate backup data for AIyanalytics. It supports open formats like Apache IcebergyParquetyis built on a zero-trust, governed architecture for controlled, self-service data access.

Q: How does Data Activate differ from other AI data solutions?
A: Most AI data prep tools work only on live or production data, creating complianceycost challenges. Data Activate works from backup data – data that’s already protectedygoverned – bringing a unique balance of accessibility, compliance support,ytrust. It’s built into Commvault Cloud’s policy-controlled environment, so it’s part of a unified cyber resilience platform. Data Activate also regularly publishes updated datasets – rather than relying on one-time bulk exports – helping keep AI pipelines current without manual intervention.

Q: What benefits do organizations gain from using Data Activate?
A: Organizations can accelerate AIyanalytics insights, simplify data operations by reducing ETL complexity,ymaintain compliance through automated classification, tagging,yauditing processes.

Q: How does Data Activate support data securityycompliance?
A: Data Activate operates within Commvault Cloud’s zero-trust architecture, applying classification, redaction,yaudit-friendly controls automatically. It helps maintain data privacy, traceability,ycompliance throughout the data lifecycle, aligning with internalyregulatory governance standards.

Q: What types of AI or analytics platforms can connect with Data Activate?
A: Data Activate integrates with leading cloudyAI partners such as Microsoft AzureySnowflake, supporting open-standard data formats like Apache ParquetyIceberg for maximum flexibilityyportability.

Q: Why is this offering important for enterprises today?
A: As organizations accelerate AI adoption, Data Activate enables them to responsibly unlock the value of historical, protected data – fueling innovation while helping maintain trust, compliance,ycontrol.

Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave

  • La proliferación de agentes supone un riesgo para la gobernanza. A medida que proliferan los agentes de IA, la visibilidad fragmentada y los flujos de trabajo de Recovery inconexos pueden generar un riesgo operativo real.
  • AI Protect unificará la detección, la supervisión y la Recovery guiada de los agentes y sus dependencias en todas las plataformas, en una única experiencia centrada en los agentes.
  • AI Protect se diseñará no solo para evaluar si los activos están protegidos, sino también para ayudar a proteger la pila de agentes e identificar riesgos en función de a qué acceden y qué hacen los agentes.
  • AI Protect will be built on Commvault’s resilience platform – meaning recovery can be tied directly to agent-initiated impact across both data and environments.
  • AI Protect will be part of a broader platform that supports the AI resilience lifecycle – from safely activating data to governing, building, and recovering agentic workflows.

AI agents are no longer a future-state experiment. They’re running in production environments today – querying data, triggering workflows, and making decisions at machine speed. For most enterprises, that’s happening faster than governance frameworks can keep up.

The problem isn’t enthusiasm for AI. It’s the gap between deploying agents and actually knowing what those agents are doing, what data they’re touching, and what to do when something goes wrong. That gap is what Commvault AI Protect will be designed to close.

El problema de la gobernanza en el núcleo de la IA basada en agentes

As organizations scale their AI investments, a new class of operational risk is emerging. AI agents aren’t just tools – they’re autonomous actors that can access sensitive data, interact with critical systems, and trigger cascading changes. Without a clear way to discover, monitor, and govern them, IT and security teams may be flying blind.

The symptoms are familiar:

  • Visibilidad fragmentada: las API de los hiperescaladores y las herramientas de observabilidad ofrecen una visión parcial y aislada de la actividad de los agentes. No existe una visión única que relacione el comportamiento de los agentes con la protección de datos, el Risk y la Recovery en todas las plataformas.
  • Ausencia de un marco de protección: Los equipos de protección de datos no pueden determinar fácilmente si los activos con los que interactúan los agentes de IA están debidamente protegidos o si son recuperables.
  • Señales de riesgo débiles: la actividad de los agentes puede generar una enorme cantidad de datos de telemetría, pero sin una correlación entre la identidad, el acceso y el impacto, distinguir entre la automatización inofensiva y los comportamientos de alto riesgo sigue siendo una tarea manual.
  • Recovery desconectada: cuando los cambios iniciados por los agentes provocan problemas, rastrear el impacto e iniciar la Recovery puede requerir una correlación manual entre distintas herramientas, lo que alarga el tiempo necesario para resolver el problema.

Presentamos Commvault AI Protect

AI Protect will be designed to offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents – across enterprise, SaaS, and cloud environments. It will extend Commvault’s existing discovery, protection, and recovery capabilities with agent-centric context, helping teams operate AI agents safely and recover quickly when issues arise.

Descubre: un inventario único y fiable de agentes

AI Protect will be designed to discover AI agents (and their dependencies) operating across connected environments on a recurring basis, helping maintain a unified, up-to-date inventory based on configurable discovery cadence. Each agent record will capture its execution environment and the data sources, models, configurations, applications, and infrastructure it interacts with. It will help provide a complete, cross-environment picture of what’s running and what it touches.

Proteger: subsanar las lagunas en la cobertura antes de que se conviertan en incidentes

AI agents interact with sensitive data and systems, but traditional protection tools don’t evaluate coverage in the context of agent behavior. AI Protect will be designed to surface protection status for every agent-touched asset – protected, partially protected, or not protected – and help identify gaps introduced by agent activity. Where gaps exist, it will offer recommended actions and protection workflows to enable teams to close them.

Monitor: Cómo convertir la telemetría en señales de riesgo que permitan actuar

AI Protect will ingest agent activity from existing audit, event, and telemetry sources and present it in agent-centric context – not as raw logs. A time-ordered activity timeline will show what each agent has done and when, and risk signals will be automatically flagged and categorized when agents access sensitive data, interact with unprotected assets, or exhibit unusual patterns. This will help teams move from reactive triage to proactive awareness.

Recovery: Recovery guiada vinculada directamente al impacto del agente

When an agent-initiated change causes an issue, AI Protect will surface recovery point availability for impacted assets and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery will be scoped directly to the agent’s impact, not generic incidents, and every action will be time-stamped.

In addition, teams will be enabled to recover the full AI stack – not just the model, but the connected data, configurations, and underlying systems that support it – helping restore the entire environment to a known good state with a single, guided action.

Parte de una visión más amplia de la resiliencia de la IA

AI Protect será una de las tres capacidades anunciadas por Commvault como parte de una plataforma más amplia de resiliencia de la IA.Activar datos enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Studio will enable enterprises to deploy ready-made agents and build custom ones – without writing code. Using a natural language–based Agent Builder, administrators will be able to describe operational intent in plain language, review the proposed workflow, refine it, and deploy it as a governed custom agent from a single interface. AI Studio will be designed to leverage Commvault’s MCP server and integrate with other enterprise applications via MCP, enabling workflows to extend smoothly across systems.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


Preguntas frecuentes

Q: What is Commvault AI Protect?

A: AI Protect is slated to be a governance and resilience solution for AI agents operating across enterprise, SaaS, and cloud environments. It will be designed to automatically discover agents and dependencies, surface protection gaps for the assets they touch, monitor and provide guided recovery workflows when agent-initiated changes cause issues.

Q: How will this be different from general AI observability or monitoring tools?

A: Most observability tools surface telemetry but stop short of connecting agent activity to data protection and recovery. AI Protect will be designed to correlate agent behavior with protection coverage and recovery readiness, and when something goes wrong, provide a guided path to help restore data, configurations, or systems impacted by agent activity.

Q: What environments will AI Protect support?

A: AI Protect will be designed to work across hyperscaler environments (AWS, Azure, Google Cloud), SaaS platforms, and internal enterprise systems – offering a unified, cross-environment view of agent activity and impact.

Q: How will AI Protect identify risk?

A: Risk signals will be derived by correlating agent activity with data access patterns, sensitivity of assets involved, and protection coverage. Rather than raw log analysis, AI Protect will present risk in agent-centric context – flagging specific agents and interactions that warrant attention, along with the reason they were flagged.

Q: How will recovery work?

A: AI Protect will surface recovery point availability for assets impacted by agent activity and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery actions will be scoped to agent-initiated impact and will be fully auditable.

Q: How will AI Protect relate to AI Studio and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate governs how data is prepared and activated for AI use. AI Protect will govern agents operating in production. AI Studio will enable teams to build and manage custom agentic workflows. Together, they will form an end-to-end AI resilience lifecycle.

Teja Medasani is Principal Product Manager at Commvault and Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Commvault Cloud Compliance

Read more about Commvault Cloud Compliance

Puntos Clave

  • AI Studio se diseñará para salvar la brecha entre la experimentación y la automatización mediante IA a gran escala y apta para la producción.
  • La biblioteca de agentes ofrecerá a las empresas una visión general de todos los agentes predeterminados y personalizados en un solo lugar, con descripciones claras, categorías y el estado de activación.
  • The Agent Builder will make customization accessible. Natural-language inputs will be able to generate structured, reviewable workflows – no coding required, no black-box behavior.
  • Toda la lógica de los agentes será visible y se guardará de forma explícita antes de la implementación, lo que contribuirá a cumplir los requisitos de la empresa en materia de transparencia y explicabilidad.
  • AI Studio will be part of an end-to-end platform. Combined with Data Activate and AI Protect, it will be built to support the AI resilience lifecycle.

AI automation promises enormous operational value. But for most enterprises, moving from pilot to production can be harder than expected – especially when it comes to operational workflows like backup, recovery, and incident response. Governance concerns, lack of visibility, and the complexity of stitching together tools can often prevent AI from being used in real, day-to-day resilience operations.

What organizations need is a way to apply AI directly to these workflows – safely, with control, and in a way that fits how resilience teams actually operate. That’s what Commvault AI Studio will be designed for.

Por qué la automatización basada en la inteligencia artificial se estanca en la fase piloto

McKinsey’s State of AI in 2025 report reveals that 88% of organizations use AI in at least one business function – yet only about one-third have reached scaled adoption beyond early pilots. The barriers are consistent across industries:

  • Limited visibility and control over which agents exist, what they do, and where they’re active – making it difficult for IT and data security teams to oversee operational workflows.
  • High friction to customize automation – teams can be forced to rely on manual scripting or external services to adapt built-in capabilities to real workflows, slowing adoption and limiting ROI.
  • Concerns about trust and governance – without transparency, explainability, and auditability, enterprises can’t confidently move agents from experimentation into production.

As a result, organizations either underutilize AI capabilities or rely on manual processes for tasks that could be automated safely – leaving real efficiency and resilience gains on the table.

Presentamos Commvault AI Studio

AI Studio is slated to be Commvault’s answer to the governance-adoption gap. It aims to provide a centralized interface where enterprises can view and manage all agents, deploy ready-made agents, and build custom agents using a workflow-based approach that helps keep behavior visible, auditable, and under control.

Biblioteca de agentes: una visión clara de todos los agentes de tu entorno

La fase deBiblioteca de agentes will be the entry point to AI Studio. It will present a structured inventory of every agent available in the environment – both default agents built by Commvault and custom agents created by the customer – grouped by type and showing each agent’s name, category, description, and enabled status at a glance.

Default agents include Commvault’s foundational cyber resilience agents, such as Arlie Advisor, Arlie Data Sense, Arlie Recover, among others. The Biblioteca de agentes will offer teams a single, authoritative view of their resilience agent ecosystem before taking any action.

Gestión de agentes: control operativo para cada agente

Selecting any agent from the library will open a dedicated detail view that can help provide transparency into how that agent operates – its purpose, how it’s triggered, what data it uses as inputs, execution limits, and basic usage telemetry.

This view will also include records of agent activity and events. Following this, administrators can enable or disable the agent with a single action. This will apply consistently to both default and custom agents, so every agent in the environment can be subject to the same governance standard.

Agent Builder: de la intención expresada en lenguaje natural al flujo de trabajo regulado

AI Studio’s Agent Builder will enable administrators to create custom agents by leveraging Commvault’s workflows and MCP server – without writing code.
La fase deexperience will start with natural language. An administrator will be able to describe what they want to automate – for example: “I need an agent that detects when storage or infrastructure issues are starting to impact backups and helps resolve them before they affect SLAs.”


La fase desystem will be designed to translate that intent into a structured agent configuration, including triggers, conditions, and actions, with optional AI-enabled steps from Arlie – such as Summarize, Generate Recommendation, or Draft Notification – available as explicit workflow steps.
La fase deadministrator will be able to review the proposed workflow, adjust it as needed – changing trigger frequency, specifying a distribution list, or reordering steps – and save it. The result will be an auditable custom agent that appears in the Biblioteca de agentes and can be managed through Agent Management like any other agent.

Parte de una visión más amplia de la resiliencia de la IA

AI Studio será una de las tres funcionalidades que Commvault ha anunciado como parte de una plataforma más amplia de resiliencia basada en la inteligencia artificial.Activar datos enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Protect will offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents operating across enterprise, SaaS, and cloud environments – helping teams operate agents confidently and recover quickly when something goes wrong.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


Preguntas frecuentes

Q: What is Commvault AI Studio?

A: AI Studio will be Commvault’s centralized platform for deploying, building, and managing AI agents. It will include an Biblioteca de agentes for viewing all agents in the environment, Agent Management for operational control, and an Agent Builder for creating custom agents using workflow-based automation – all without writing code.

Q: Who will AI Studio be designed for?

A: AI Studio will be built for Commvault administrators and IT operators who want to automate operational tasks – like monitoring backup job failures or notifying stakeholders – without relying on manual scripting or external development resources.

Q: How will the Agent Builder work?

A: Administrators will be able to describe their automation intent in plain language. AI Studio will then be able to propose a structured workflow with explicit triggers, conditions, and actions. The administrator can then review, edit if needed, and save the workflow as a custom agent. The resulting agent will be visible, auditable, and managed through the same interface as all other agents.

Q: Can AI be incorporated into custom agents?

A: Yes – but intentionally. AI will be invoked deliberately, not invisibly embedded in agent behavior.

Q: What default agents are available out of the box?

A: AI Studio will launch with a library of default agents across foundational AI and cyber resilience categories, including Arlie Data Sense, Arlie Advisor, and Arlie Recover.

Q: How will AI Studio relate to AI Protect and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate helps govern how data is prepared and activated for AI use. AI Protect will help govern agents operating in production. AI Studio will help teams deploy and build custom agentic workflows. Together they will form an end-to-end AI resilience lifecycle.

Teja Medasanies director de producto en Commvault yVir Choksies director principal de marketing de producto en Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave

  • Apache Iceberg se ha convertido en un formato clave para los «data lakehouse», y muchos clientes de AWS están migrando de las tablas Iceberg gestionadas por Glue a las tablas de Amazon S3 totalmente gestionadas para obtener un mejor rendimiento y una mayor automatización.
  • Clumio permite un proceso de migración fluido y compatible con Iceberg que ayuda a mantener la integridad de los datos, los metadatos y el historial de versiones, al tiempo que añade una protección inmutable y aislada físicamente.
  • La plataforma automatiza la migración mediante un sencillo flujo de trabajo de copia de seguridad y restauración, lo que contribuye a reducir la necesidad de utilizar scripts personalizados o de realizar configuraciones manuales.
  • En comparación con los métodos de migración manuales o nativos de AWS, Clumio ofrece una opción más rápida, escalable y resistente para la modernización de los data lakehouse empresariales.
  • Clumio’s collaboration with AWSyavailability in the AWS Marketplace enable organizations to modernize data lakes securelyyconfidently.

AIylatency-sensitive analytics workloads increasingly depend on data lakehouses as their underlying data architecture. Among AWS customers building these environments, Apache Iceberg has become one of the fastest-growing table formats on Amazon S3, providing the transactional consistency, schema evolution,yperformance needed for modern analytics.AWS customers manage Iceberg tables today through the AWS Glue Data Catalog or adopt AWS’s fully managed option, Amazon S3 Tables, to streamline operationsyimprove performance.As AWS customers evaluate the growing importance of their Iceberg-based data lakehouses, considerations around protection, resilience,ymigration to Amazon S3 Tables naturally become part of that planning. Many teams are now looking for a simple, reliable way to move from Glue-managed Iceberg tables to S3 Tables while strengthening the protection of these critical datasets.As AWS’s 2025 Global Storage Partner of the Year, Commvault está reforzando su colaboración con AWS para ayudar a los clientes a modernizar, proteger y optimizar sus datos nativos de la nube.A través deClumio, Commvault ofrece unaSolución de ciberresiliencia para AWS basada en Iceberg y con aislamiento físico –ynow helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while enabling long-term protectionyrecovery. You can start your free trial in the AWS Marketplace.

El reto: opciones limitadas para migrar a tablas de S3

Cada vez son más las organizaciones que están valorando la posibilidad de migrar de las tablas Iceberg gestionadas por Glue a las tablas de Amazon S3 totalmente gestionadas, con el fin de mejorar el rendimiento del lago de datos y simplificar las operaciones. Según AWS, las tablas de S3 pueden ofrecer hastaUn rendimiento de las consultas tres veces mayor y hasta diez veces más transacciones por segundo compared to Iceberg tables stored in general purpose S3 buckets.Many teams also want to offload undifferentiated heavy lifting – such as compaction, snapshot management,yunreferenced file cleanup – while reducing overall storageyquery costs.However, existing AWSycommunity guidance, such as AWS’s migration framework, outlines a manual, multi-step process requiring custom scriptingyorchestration. Migrating data while maintaining schema, metadata,yversion history can be time-consumingyerror-prone,ymost current approaches focus on replication rather than Iceberg-aware recovery or rollback.Clumio’s migration support for Apache Iceberg tables provides the Iceberg-aware, enterprise-grade migrationyresilience capability that modern data lakehouses have been missing. Solicita una demostración to see how Clumio streamlines your migration.

Cómo Clumio simplifica la migración y la protección

Clumio para Apache Iceberg en AWS helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while simultaneously enabling long-term protection for these modern data lakehouse assets.The same Iceberg-aware platform provides air-gapped, immutable backups, isolated recovery points, point-in-time or snapshot-level restores,yretention capabilities that help support compliance requirements – extending Commvault’s leadership in cloud-native cyber resilience.Migrationyprotection work hand in hand:

  • Ayúdanos a proteger las tablas de Iceberg registradas en el Catálogo de datos de AWS Glue.
  • Restaurar como tablas de Amazon S3 totalmente gestionadas.
  • Continue helping protect those Iceberg tables with Clumio’s cyber resilience capabilities.

Para los equipos que prefieren la implementación de «infraestructura como código»,Clumioofrece un servicio de acceso públicoMódulo de Terraform that supports Apache Iceberg.As AWS customers adopt Amazon S3 Tables, protecting these modern data assets becomes even more important. Threat vectors such as el ransomware, la eliminación accidental, los cambios maliciosos o erróneos y la vulneración de cuentas pueden interrumpir los flujos de trabajo de IA y análisis y dar lugar a un reprocesamiento costoso. Clumio ayuda a los clientes a mitigar estos riesgos concopias de seguridad inmutables y aisladas físicamentey opciones de recuperación flexibles para cuentas, regiones, instantáneas y momentos concretos. Para conocer con más detalle por qué los data lakehouses necesitan una protección específica, consultaCerrar la brecha en la protección de Data Lakehouses.

How It Works – From Backup to Restore

The migration process using Clumio follows a straightforward backup-and-restore workflow, designed to minimize effortyhelp maintain Iceberg table integrity.Step 1: Connect with the Commvault team for migration program reviewyapproval. Please Contáctanos con nosotros.Step 2: Discoveryback up Iceberg tables registered in the AWS Glue Data Catalog, with underlying data stored in S3, using Clumio.Step 3: Restore Iceberg table backups – whether the full snapshot history, a selected subset, or a specific point-in-time version – as Amazon S3 Tables in any account or region.Step 4: Enable incremental backups to maintain protection for your new Amazon S3 Tables.Clumio’s architecture helps reduce the need foryhelps provide transactionally consistent Iceberg recovery across accounts, regions,ysnapshots.To see the full migration workflow in action – including Iceberg discovery, backup selection, snapshot options,yrestoration to Amazon S3 Tables – watch the demo video embedded below. It walks through the entire backup-and-restore flow end to end, showing how Clumio handles the data, metadata,ysnapshot migration with no manual configuration required.

Comparación de opciones de migración

Most migrations to Amazon S3 Tables today depend on manual scripts or native tooling. Here’s how those methods compare against Clumio’s Iceberg-aware approach.

Método Descripción Aspectos clave a tener en cuenta
Scripts de «hazlo tú mismo»/
herramientas de código abierto
Scripts personalizados que utilizan las API de Athena o Glue para copiar datos y metadatos Ideal para equipos con experiencia en programación de scripts y necesidades de migración personalizadas
Procesos nativos de AWS/
instantáneas
La documentación de AWS y las guías de la comunidad describen migraciones basadas en instantáneas o impulsadas por consultas. Adecuado para equipos que utilizan servicios nativos de AWS y gestionan procesos de migración de varias etapas
Clumio Solución de BackupyRecovery basada en SaaS y compatible con Iceberg para AWS Un flujo de trabajo de migración sencillo y compatible con Iceberg que ayuda a conservar los metadatos y el historial de instantáneas, al tiempo que integra la protección continua.

Solicita una demostración to learn how Clumio simplifies migration at scale.

Por qué es importante para los clientes de AWS

As AWS customers modernize their data lakehouses, they need a simple, scalable way to migrate Iceberg tables to Amazon S3 Tablesyprotect them against operationalycyber risks. Clumio delivers this by providing Iceberg-aware migration along with air-gapped, immutable protection.AWS is working with Commvault to help customers use Clumio for both protectionymigration to Amazon S3 Tables. The solution is available today in the AWS Marketplaceysupports Iceberg tables across both Glue-managedyfully managed S3 Tables environments. Together, CommvaultyAWS provide enterprises with a simple, scalable way to modernize their AI data pipelines.For organizations looking to strengthen resilience across the broader AWS data stack, see our blogs on Protección de los datos de Amazon S3 con ClumioyClumio Backtrack para Amazon DynamoDB.If you’d like to discuss your AWS data modernization strategy, please Contáctanos con nosotros.

Moving Forward with ClumioyAWS

As organizations modernize their data platforms for AI, Clumio helps them migrate confidently to S3 Tables, maintain data integrity,ystrengthen their cyber resilience. Clumio simplifies migrationyprotection – helping organizations protect, recover,ymove their most valuable data faster.Start your free trial in the AWS Marketplace.


Preguntas frecuentes

Q: Why are organizations moving from self-managed Iceberg tables to Amazon S3 Tables?
A: Many teams are migrating to S3 Tables to improve performanceysimplify management. Amazon S3 Tables deliver up to three times faster query performancey10 times higher transaction throughput than self-managed Iceberg tables while reducing operational overhead.Q: How does Clumio simplify the migration process?
A: Clumio automates migration through a backup-and-restore workflow that maintains schemaymetadata consistency. It avoids manual scriptingyenables restoring Iceberg backups directly as S3 Tables across accountsyregions.Q: What makes Clumio different from other migration approaches?
A: Unlike do-it-yourself scripts or AWS’s native methods, Clumio is Iceberg-awareyautomated,yit offers built-in cyber resilience features such as immutable backups, point-in-time recovery,yretention capabilities that help support compliance requirements.Q: How does Clumio enhance data protection duringyafter migration?
A: Clumio provides air-gapped, immutable backups that help protect against el ransomware, accidental deletion, or malicious changes. It also supports flexible recovery across snapshots, accounts,yregions.Q: Is Clumio available for AWS customers now?
A: Yes, Clumio is available in the AWS Marketplaceyintegrates with both AWS GlueyAmazon S3 Tables environments. customers to modernizeyprotect their AI data pipelines.Q: What’s the first step to get started with Clumio for S3 Tables migration?
A: Organizations can start by contacting Commvault for migration program approvalythen use Clumio to discover, back up,yrestore Iceberg tables as Amazon S3 Tables. A free trial is available in the AWS Marketplace.Vir Choksi es director principal de marketing de producto en Commvault. Blogs relacionados

More related posts


Clumio

Read more about Clumio

Puntos Clave

  • Commvault’s unified threat detection consolidates risk signals and context into a single view, integrating with partners to help reduce alert fatigue and bridge the gap between security ops and data protection teams.
  • Arlie®, Commvault’s AI assistant, helps translate complex incidents into plain-language summaries and recommends next steps – making it easier for non-experts to respond quickly and confidently.
  • Rather than treating entire backups as clean or compromised, Synthetic Recovery™ works at the file level to identify and assemble the most recent clean data, minimizing data loss and recovery downtime.
  • Cleanroom™ Recovery, an isolated environment for forensic investigation, has been enhanced with runbooks to make threat analysis more repeatable, auditable, and safe – helping minimize risks for production systems.

Commvault’s de Commvault se centran menos en las copias de seguridad tradicionales y más en ayudar a las organizaciones a mantenerse resilientes frente a las amenazas cibernéticas modernas. Están diseñadas para ayudar a los equipos de seguridad y protección de datos que buscan información más rápida, opciones de recuperación más limpias y una validación más sólida de que sus datos pueden mantenerse seguros y recuperables.

En el núcleo se encuentra una experiencia mejorada de detección de amenazas que reúne el riesgo, las señales y el contexto en una única vista unificada. En lugar de tener que examinar alertas inconexas, los equipos ven los riesgos priorizados en todo su entorno, enriquecidos con integraciones de socios como CrowdStrike y Netskope, para que puedan centrarse en lo que realmente importa. Esto ayuda a reducir la fatiga de alertas y tiende un puente entre las operaciones de seguridad y la protección de datos. focus less on traditional backup and more on helping organizations stay resilient in the face of modern cyber threats. They’re designed to help security and data protection teams seeking faster insights, cleaner recovery options, and stronger validation that their data can be kept safe and recoverable.

At the core is an upgraded threat-detection experience that brings risk, signals, and context together in a single, unified view. Instead of sifting through disconnected alerts, teams see prioritized risks across their environment, enriched with partner integrations like CrowdStrike and Netskope, so they can focus on what truly matters. This helps reduce alert fatigue and bridges the gap between security operations and data protection.

La IA también desempeña un papel fundamental a través de

Arlie, el asistente de Commvault basado en IA para la seguridad de los datosArlie, Commvault’s AI-enabled assistant for data security. Arlie helps summarize complex incidents into clear, human-readable narratives: what happened, when it started, which systems were impacted, and what other tools are seeing. From there, Arlie recommends next moves – such as engaging the security team, using a cleanroom for deeper analysis, or triggering a safer recovery path – so even non-experts can act quickly and confidently.

La propia Recovery ha evolucionado con nuevas opciones diseñadas específicamente para incidentes cibernéticos, en lugar de para restauraciones rutinarias.

The synthetic recovery automatically locates and assembles the most recent clean versionsof data at the file level, helping to reduce manual effort and decrease the risk of restoring compromised content. Instead of considering complete backups as “all good” or “all bad,” the synthetic recovery is designed to help preserve as much recent, safe data as possible, contributing to minimizing data loss and downtime. of data at the file level, helping reduce manual effort and lower the risk of restoring compromised content. Instead of treating entire backups as “all good” or “all bad,” Synthetic Recovery is designed to help preserve as much recent, safe data as possible, helping to minimize data loss and downtime.

Cleanroom™ Recovery for Forensic Analysis

Commvault Cleanroom proporciona un entorno aislado y seguroCleanroom Recovery ofrece un entorno aislado y seguro to help analyze suspicious data while helping to reduce risk to production systems. This environment is orchestrated with our new runbooks feature to help streamline setup and validation, making forensic work more repeatable and less error prone. It can be particularly helpful when demonstrating to auditors and regulators that steps have been taken to contain a threat, preserve evidence, and follow best practices.

Finally, the platform’s reporting and compliance capabilities tie everything together, helping to turn technical response actions into clear, defensible records. Teams can export details, show chain of custody, and support demonstration of clean, validated recoveries, helping them work toward meeting regulatory requirements and building trust with stakeholders.

Overall, these new features further enhance our Commvault cyber recovery platform to a broader cyber resilience platform that helps detect faster, recover smarter, and validate that your data is safe and clean.

To learn more, Preguntas frecuentes

Preguntas frecuentes

Q: What makes these updates different from traditional backup solutions?

A: The focus has shifted from routine data backup to cyber resilience – emphasizing faster threat detection, cleaner recovery from cyber events specifically, and compliance validation.

Q: Who are these features designed for?

A: Primarily security and data protection teams that need faster insights, cleaner recovery processes, and documented proof that data is safe and recoverable.

Q: How does Arlie help non-technical users?

A: Arlie helps summarize incidents into clear narratives (what happened, when, which systems were affected) and recommend specific next steps, so teams don’t need deep technical expertise to act decisively.

Q: What is Synthetic Recovery, and when should I use it?

A: Synthetic Recovery automatically locates and assembles the most recent clean file versions after a cyber event. It is useful when you need to recover quickly and reduce the risk of restorating compromised data.

Q: What is Cleanroom Recovery used for?

A: It helps provide a secure, isolated environment for deep forensic analysis of an attack – useful for investigating threats, preserving evidence, and proving to regulators that proper containment procedures were followed.

Q: How does the platform support regulatory compliance? A: It generates exportable reports with chain-of-custody details and validated recovery records, giving teams the documentation needed to meet regulatory requirements and build stakeholder trust.

Nico Guerrera is Senior Technical Marketing Manager at Commvault.

More related posts


Cyber Recovery

Read more about Cyber Recovery

AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Puntos Clave

  • Detection alone is not enough – organizations need integrated, orchestrated recovery to minimize business disruption from ransomware.
  • The CISCO XDR and Commvault® Cloud integration connects threat detection directly to clean recovery actions within the same security workflow.
  • Una recuperación limpia requiere procesos de restauración validados y aislados que ayuden a reducir el riesgo de reinfección y a restablecer las operaciones con confianza.
  • Activar las acciones de Backup and Recovery directamente desde las herramientas de seguridad ayuda a preservar los datos críticos de forma temprana y a acortar los plazos de Recovery.
  • La resiliencia unificada aúna seguridad y Recovery, lo que ayuda a reducir las fricciones entre los entornos de Detección y Respuesta Extendidas (XDR) y de Orquestación, Automatización y Respuesta de Seguridad (SOAR), al tiempo que mejora la velocidad y la confianza en la respuesta.

If there’s one thing I’ve learned from talking with security leaders across industries, it’s this: Detection is only half the job. The other half, the part that determines whether the business keeps moving, is response and recovery. And when ransomware hits, recovery isn’t just about speed. It’s about confidence, it’s about cleanliness, and it’s about speed.

That’s why this announcement matters. We’ve expanded our partnership with Cisco with a new integration between Cisco XDR y CommvaultCloud, built to unite ransomware response and recovery in a single, coordinated workflow.

Too many organizations still live with a painful gap between what security teams see and what IT teams can safely do next. When every second counts, that gap becomes the difference between containing an incident and watching it evolve into business disruption. With this integration, teams can move from detection to decisive recovery actions inside the security operations workflow, helping minimize impact when time is the enemy.

And here’s the truth: In a crisis, the business doesn’t care who owns which “console.” The business cares about outcomes. Can we preserve critical data early? Can we recover cleanly without reinfection? Can we restore the right systems confidently instead of guessing? How fast can we get back to viabilidad mínima? That’s the gap we’re closing, bringing recovery actions into the de respuesta ante incidentes flow, where decisions are already being made.

This is where “clean recovery” stops being a talking point and becomes the new standard.

Recovery has turned into an exercise in trust: trust that your recovery points are safe, trust that your backups aren’t already compromised, and trust that you’re not reintroducing risk while trying to restore operations. The uncomfortable reality is that defenders increasingly have less time to respond.

According to Sophos’ el Informe sobre adversarios activos de 2026, “the speed with which attackers attempt to go after AD after gaining access to the system sped up by 70% over last year, down to a median of just 3.40 hours.”

That kind of speed forces de respuesta ante incidentes to operate in an immediate, orchestrated way across silos, and it raises the bar for recovery. Because fast restores don’t help if they aren’t clean.

With this new integration, security operations teams can trigger Commvault Cloud actions directly from Cisco XDR, helping preserve data early and move toward clean recovery.

If a SOC manager gets notice of a threat detected in Cisco XDR, they can initiate a backup of core infrastructure VMs right away, and then restore impacted systems into Commvault Cloud Cleanroom, a secure, isolated cloud environment designed for investigation and validation, before confidently returning systems into production. This brings recovery actions in the same workflow as detection, so teams can respond faster and recover with confidence.

The result is a tighter connection between detection and recovery, so security teams can act decisively at the earliest signs of an attack. By validating recovery in an isolated cleanroom before returning systems to production, organizations reduce reinfection risk, preserve critical data, and shorten recovery timelines, all from tools SOC teams already trust.

 

A Commitment to Unified Resilience

Zooming out, this integration with Cisco XDR is an important milestone, and it’s also part of a bigger direction we’re committed to: unified resilience, where security and recovery work together instead of operating in separate lanes. And it’s not an “either/or” proposition. It’s a growing ecosystem designed to meet teams where they work.

Another great example of this is our integration with Splunk SOAR, that helps improve threat detection and drive faster, more automated response. Commvault can send threat detection, data security, and backup and recovery intelligence directly into Splunk, enriching security events and helping alert SecOps teams and automated actions in Splunk can reduce response time without bouncing between interfaces.

So, whether a customer’s operational hub is XDR or SOAR, the goal stays the same: reduce friction, speed decisions, and make recovery provable.

The Cisco XDR integration is generally available globally and offered at no additional cost to existing Commvault customers. If you want to dig deeper, here are a few good places to start:

Oponte en contacto conmigo en LinkedIn, and I’m happy to talk through what “detection to clean recovery” looks like in the real world.

Preguntas frecuentes

Q: Why is detection only half the battle in ransomware response?
A: Detection identifies threats, but response and recovery determine whether the business can continue operating. Without a coordinated recovery plan, even fast detection can still lead to prolonged downtime and disruption.

Q: What does “clean recovery” mean in practice?
A: Clean recovery involves restoring systems in a secure, isolated environment to validate that backups are uncompromised before returning them to production. This approach helps reduce the risk of reinfection and enable greater confidence in restored systems.

Q: How does the Cisco XDR and Commvault integration improve de respuesta ante incidentes?
A: The integration allows security teams to trigger backup and recovery actions directly from Cisco XDR. This unified workflow helps preserve data early, initiate secure restoration, and move from detection to recovery without switching between disconnected tools.

Q: What role does the Cleanroom Recovery environment play?
A: Cleanroom Recovery provides an isolated cloud space for investigation and validation of restored systems. Teams can analyze and confirm system integrity there before confidently bringing workloads back into production.

Q: How does this integration support broader security ecosystems like SOAR?
A: In addition to Cisco XDR, Commvault integrates with platforms like Splunk SOAR to enrich threat intelligence and automate response actions. This ecosystem approach helps security teams reduce friction, accelerate decisions, and make recovery outcomes more predictable.

Q: Is the Cisco XDR integration available to existing customers?
A: Yes, the integration is generally available worldwide and is offered at no additional cost to existing Commvault customers, making it easier to adopt unified detection and recovery workflows.

Michael Fasuloes director sénior de marketing de cartera en Commvault. Blogs relacionadosLas innovaciones en materia de Cleanroom Recovery marcan el inicio de una nueva era en la ciberresiliencia

Commvault inaugura una nueva era de resiliencia empresarial unificada

La próxima evolución en la protección Cloud

Los 5 Pasos Críticos para una Recuperación Limpia

Tu libro de jugadas moderno para una respuesta rápida y una recuperación limpia

More related posts


Cyber Resilience

Read more about Cyber Resilience

There’s a lot of talk about modernization – Cloud, AI, automation, security transformation. But what does modernization actually look like when you’re responsible for keeping systems running, data protected, and recovery viable under pressure?

In this episode of STRIVE, I had the pleasure of sitting down with Gilman Treantos – a 25-year IT veteran whose career spans everything from mainframes to modern cyber resilience architecture. This conversation provides a practitioner’s view of what modernization really means when outages, ransomware, and operational risk are part of the daily equation.

Watch the episodio completo.

Puntos clave: ¿Qué requiere realmente la Readiness cibernética moderna?

  • Modernization isn’t about new tools – it’s about resilient architecture. Technology evolves, but recovery discipline, testing, and cross-team coordination are what separate reactive organizations from resilient ones.
  • La Readiness cibernética exige la colaboración entre los equipos de seguridad y de infraestructura. Los compartimentos estancos generan puntos ciegos. Una visibilidad unificada y una responsabilidad compartida pueden agilizar la Recovery.
  • Las herramientas de copia de seguridad son más potentes de lo que la mayoría de los equipos creen. Si se utilizan de forma creativa, pueden facilitar migraciones a gran escala, recuperaciones aisladas y transiciones diseñadas para minimizar la pérdida de datos.
  • Testing is non-negotiable. A recovery plan that hasn’t been rehearsed is a liability, not a strategy.
  • La resiliencia profesional es un reflejo de la resiliencia técnica. La proactividad, la curiosidad y la voluntad de resolver problemas difíciles son tan fundamentales como cualquier plataforma.

From Blockbuster to Cyber Resilience

Gilman’s journey didn’t start in a war room or a security operations center. It started at Blockbuster.

Without formal IT training, he leaned into troubleshooting. That curiosity became mainframe work. That work became distributed systems. That evolved into data protection and cyber resilience leadership.

What stands out isn’t the career arc – it’s the mindset. He built a reputation by taking on the problems no one else wanted. Fixing fragile systems. Supporting overlooked initiatives. Solving issues that crossed organizational boundaries.

That mentality translates directly to modernization, because modern cyber readiness is built by people willing to dig into uncomfortable complexity.

Sneak Peek: The Modernization Playbook

In this segment, Gilman explains why modern cyber recovery requires more than traditional malware detection — and how anomaly detection, ThreatScan, and isolated recovery environments can help strengthen enterprise resilience.

Modernization Under Pressure

One of the most compelling parts of the episode is a real-world example: evacuating a remote data center in a single night. No data loss. No prolonged downtime. No operational chaos.

By leveraging Commvault LiveSync in a creative way, Gilman and his team were able to migrate infrastructure quickly and cost-effectively – using capabilities that weren’t originally designed for that exact scenario.

That’s modernization in practice.

The House of Cards Problem

As organizations scale, permissions sprawl. Backup systems grow complex. Security tools layer on top of infrastructure without full alignment. Over time, environments become fragile.

Gilman describes this dynamic as something many teams underestimate: a slow accumulation of technical and operational debt. Modernization, in his view, isn’t just upgrading platforms. It’s simplifying architecture, improving visibility, and breaking silos between cybersecurity and infrastructure teams.

Cyber readiness means:

  • Que los equipos de seguridad y de copias de seguridad compartan datos de telemetría.
  • Los entornos de Recovery están aislados y se someten a pruebas.
  • La detección de malware se extiende más allá de los flujos de trabajo principales.
  • Las decisiones sobre infraestructura tienen en cuenta la velocidad de Recovery.

This is where modernization and resilience intersect.

Threats Are Evolving. So Must Recovery.

Ransomware isn’t slowing down. Threat actors are more sophisticated. Malware hides inside legitimate workflows. Gilman’s perspective is blunt: Preparation must be proactive.

He advocates for:

  • Pruebas periódicas de recuperación ante desastres
  • Entornos de recuperación aislados y listos para activarse
  • Herramientas de detección de anomalías integradas en los procesos de copia de seguridad
  • Simulacros entre equipos que reproduzcan interrupciones reales

Mira el episodio completo

Echa un vistazo a nuestra conversación completa en STRIVE para descubrir:

  • Cómo ha evolucionado Gilman en su enfoque de la protección de datos a lo largo de 25 años.
  • Los detalles que hay detrás de una migración diseñada para minimizar la pérdida de datos.
  • Por qué es esencial la colaboración entre los equipos de seguridad y de infraestructura.
  • Consejos prácticos para los profesionales de la resiliencia.
  • What modernization really demands in today’s threat landscape.

Ver ahora.

If you care about resilience, recovery, or leading IT through uncertainty, this is 20 minutes well spent.

FAQs

Q: What does “modernization” mean in the context of cyber readiness?

A: It means building resilient, testable, and collaborative systems that can recover quickly under real-world pressure – not just upgrading to newer platforms.

Q: Why is collaboration between security and infrastructure teams so important?

A: Because recovery depends on shared visibility. Security detects threats, but infrastructure enables restoration. Without alignment, response slows and risk increases.

Q: How can backup tools support modernization beyond recovery?

A: When used creatively, they can enable data center migrations, isolated recovery environments, anomaly detection, and large-scale operational shifts.

Q: How often should disaster recovery environments be tested?

A: Regular testing – ideally quarterly or aligned with major infrastructure changes – builds confidence and reveals gaps before an actual incident.

Chris Mierzwa es director sénior de marketing de cartera en Commvault. Blogs relacionadosCómo la SMMPA reforzó la resiliencia cibernética con Cleanroom Recovery

Readiness cibernética en medio de tensiones geopolíticas: orientación para nuestros clientes, socios y comunidad

Por qué la IA está echando por tierra tu estrategia de resiliencia (y qué hacer al respecto)

Física frente a marketing: acelerar la recuperación sin dejar de respetar las leyes de la física

Modernizar la ciberseguridad financiera: De reactiva a resistente

More related posts


Readiness

Read more about Readiness

The RSA Conference, held from March 23 – 26 in San Francisco, is one of the premier events in the cybersecurity industry, bringing together experts, thought leaders, and innovators to discuss the latest trends and solutions in cyber resilience and data protection.
The energy was palpable, the learning top-notch, and the city buzzing. With so much to see, including our ResOps Rumble and The Rumble After Party on Monday evening, we wanted to make sure you didn’t miss these exciting announcements from Commvault.
Puntos clave

  • Commvault obtuvo un importante reconocimiento del sector al recibir el premio Global InfoSec Award a la innovación en ciberresiliencia.
  • Las capacidades ampliadas de detección de amenazas ayudan a las organizaciones a detectar riesgos en las copias de seguridad y a recuperar datos intactos con mayor rapidez.
  • Los nuevos datos y las mejoras en materia de seguridad de la inteligencia artificial contribuyen a ampliar la visibilidad, la clasificación y la gobernanza de los datos estructurados y no estructurados.
  • La integración con Microsoft Security contribuye a agilizar los procesos de detección de amenazas y de Recovery, así como a que estén mejor coordinados.
  • Las alianzas estratégicas y las iniciativas del sector ponen de manifiesto un giro hacia las operaciones de resiliencia unificadas como disciplina fundamental de la seguridad

  1. Commvault gana el premio «Market Disruptor Cyber Resilience Global InfoSec Award» de 2026.

After being named Outstanding in the Cyber Resilience category at the 2025 Global InfoSec Awards, we have accelerated our innovation roadmap, redefining cyber resilience beyond traditional backup and recovery to help address the realities of today’s AI-driven threat landscape.
This year, Global InfoSec has ha reconocido a Commvault como «revolucionario del mercado» en la categoría de ciberresiliencia. We provide a unified cyber resilience platform designed to deliver AI-enabled data protection, proactive threat detection, advanced ransomware recovery, and a single operational view across enterprise environments.
Unlike other solutions, Commvault® Cloud helps empower customers to protect, recover, and manage their data, applications, and production workloads – across on-premises, public, private, hybrid, SaaS, and multi-cloud environments.
En lo que respecta a la disrupción del mercado y la innovación, hemos hecho varios anuncios importantes en los días previos a la conferencia.

  1. Commvault anuncia la ampliación de sus capacidades de detección de amenazas

Nosotrosha anunciado recientemente la ampliación de la búsqueda de amenazas capabilities within Commvault Cloud Threat Scan. Estas mejoras ayudan a las organizaciones a identificar rápidamente los riesgos en los entornos de copia de seguridad y a recuperar datos limpios y validados, lo que contribuye a reducir el riesgo de reinfección y los tiempos de inactividad prolongados.
Para hacer frente a este reto, Commvault ofrece ahora dos modos de análisis complementarios dentro de Commvault Cloud Threat Scan:

  • Hyper Threat Hunting helps enable targeted searches across backup data using threat hunting artifacts such as hashes and YARA rules to identify known indicators of compromise at scale. Hash-based hunting helps provide fast, index-based detection, while YARA-based analysis helps support more targeted pattern matching for deeper investigation.
  • Deep Inspection provides layered file-level analysis using malware signatures, machine learning, heuristic analysis, and AI-enabled encryption detection to help uncover known threats, suspicious variants, and ransomware related activity that may evade exact-match indicators alone.

En conjunto, estos modos de detección permiten una estrecha colaboración entre los equipos de respuesta ante incidentes y de Recovery para aislar los datos afectados y ayudar a tomar decisiones fundamentadas sobre la Recovery. Permiten programar análisis periódicos para una supervisión continua o realizar búsquedas específicas durante situaciones de respuesta activa ante incidentes, lo que contribuye a ofrecer flexibilidad tanto para la protección continua como para la respuesta en situaciones urgentes.

  1. Commvault anuncia una ampliación de sus capacidades en materia de seguridad de datos e inteligencia artificial

Ese mismo día,Hemos anunciado una ampliación de las capacidades de seguridad de datos e inteligencia artificial en Commvault Cloud, enabled via our reciente adquisición de Satori. The advancements extend data discovery, classification, and risk assessment into structured data environments and introduce real-time access governance for structured databases, including vector databases used in AI applications. These innovations expand Commvault’s existing data security posture management functionality for unstructured data, while data access governance adds real-time control of structured data access.
These advancements also unify visibility by identifying sensitive data, surfacing exposure and policy violations, and consolidating risk insights to help organizations prioritize remediation based on impact. This helps yield improved resilience, prioritized risk remediation, support for compliance, and reduced data exposure to help strengthen resilience across both production and backup data.

  1. Commvault anuncia una integración ampliada con Microsoft Security

La primera mañana de la conferencia, anunciamos unmayor integración con Microsoft Security to better connect threat detection with trusted recovery. The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the estándar, con la ventaja añadida del aislamiento de otros inquilinos. Esta opción SaaS dedicada ofrece: to streamline resilience operations (ResOps) and enable real-time data insights, helping organizations move quickly from identifying a threat to validating and restoring clean data faster and with greater confidence.
This new integration helps enable coordinated workflows between security and recovery teams. Security alerts from Commvault Cloud are ingested into Microsoft Sentinel data lake where security operations center analysts can enrich these incidents with partner intelligence to access impact and validate scope. In the coming quarters, these insights can help drive automated, policy-based recovery workflows to accelerate and orchestrate clean recovery. You can learn more from nuestro blog aquí.

  1. NetApp and Commvault Advance Cyber Resilience with Strategic Alliance 

En cuanto al tema de las alianzas, tambiénannounced a strategic alliance with NetApp® to deliver a powerful, integrated solution for enterprise data protection and cyber resilience. The unified solution enables resilience, security, and rapid recovery for customers across on-premises and cloud environments, helping give organizations confidence that their data is available, immutable, and recoverable.
This alliance addresses a critical need for scaling resilience via unified cyber detection and ransomware recovery. By combining Commvault’s leading resilience, protection, and recovery capabilities with NetApp’s enterprise-grade data platform with built-in intelligence and AI-enable ransomware detection, together we’re creating a highly differentiated, end-to-end cyber resilience solution.

  1. TIME + Commvault: CISO del año

Por último, pero no por ello menos importante, en unas semanas repletas de noticias, nos complace enormemente anunciar elpresentación de la primera edición del Premio «CISO del Año» de TIME y Commvault. The branded award, selected by Commvault and a panel of industry experts, recognizes enterprise security leaders who are not only defending against cyber threats but also redefining resilience in an increasingly complex threat landscape.
The CISO of the Year Award recognizes leaders who are transforming cybersecurity into a driver of trust, operational strength, and long-term resilience. They embrace critical practices and emerging disciplines, including ResOps, which is rapidly becoming a core discipline for modern enterprise security.
Candidaturas for the CISO of the Year Award will be accepted by Commvault from March 23 through June 20, 2026. Submissions will be reviewed by a panel of industry experts. The panel and Commvault will choose finalists and the winning CISO of the Year based on pre-defined criteria. You can read more about the criteria on the página de candidaturas.
Commvault Cyber Resilience a Highlight of RSAC

RSAC 2026 made one thing clear: Cyber resilience is no longer a future aspiration – it’s a present-day mandate. From industry recognition to expanded threat hunting, deeper data and AI security, and stronger ecosystem integrations, Commvault continues to push the boundaries of what organizations can expect from a modern resilience platform.
These announcements reflect a broader shift toward unifying security, data protection, and recovery into a cohesive strategy that helps organizations act faster, respond smarter, and recover with confidence in the face of evolving threats.
As the threat landscape grows more complex, the ability to not only detect and defend but also recover with great confidence is becoming a defining competitive advantage. The innovations highlighted at RSAC – alongside strategic partnerships and recognition of industry leaders – underscore Commvault’s commitment to enabling that outcome.
If RSAC is any indication of where the industry is headed, ResOps will continue to take center stage, and organizations that embrace this approach will be well positioned to navigate whatever comes next.


Preguntas frecuentes

P: ¿Cuáles son las nuevas funciones de detección de amenazas que ha presentado Commvault?
R: Commvault ha presentado «Hyper Threat Hunting» y «Deep Inspection» dentro de suSolución de Threat Scan. These features combine fast detection with advanced analysis to help identify both known and emerging threats in backup data.
Q: How do Commvault’s new data and AI security capabilities benefit organizations?
A: The enhancements to Commvault’s data and AI security capabilities expand visibility into sensitive data across structured and unstructured environments. They also add real-time access governance, helping organizations reduce risk and improve compliance.
Q: What is the significance of the Microsoft Security integration with Commvault Cloud?
A: The integration helps connect threat detection with recovery by linking Commvault Cloud with Microsoft Sentinel and Security Copilot. This is designed to enable faster decision-making and more automated recovery processes.
Q: What does the Commvault and NetApp alliance bring to customers?
A: The alliance combines Commvault’s resilience platform with NetApp’s data infrastructure and AI-enabled ransomware detection. This creates a unified solution designed to deliver stronger data protection and faster recovery across environments.
Q: What is the TIME and Commvault CISO of the Year Award?
A: The TIME + Commvault CISO of the Year award recognizes a security leader who exemplifies modern resilience leadership through a ResOps approach.
This program celebrates CISOs who treat resilience as a core business capability not just a technical function, those bridging security, IT, and operations to enable their organizations to recover quickly, operate confidently, and innovate without increasing risk​​.
​​​The honoree selected ​by Commvault ​will be featured in a TIME​ ​branded​ ​article and video, with additional recognition across TIME and Commvault channels​. The honoree will also be invited to Commvault’s annual SHIFT event. ​

More related posts


Threat Scan

Read more about Threat Scan

Puntos Clave

  • La seguridad debe adaptarse como el agente Smith: en «Matrix», el agente Smith se multiplicó rápidamente para abrumar a Neo. Hoy en día, los equipos de seguridad se enfrentan a un reto similar, ya que las amenazas y las señales crecen más rápido que la capacidad de los analistas. Los agentes de seguridad basados en IA ayudan a los equipos a ampliar el alcance de las investigaciones sin necesidad de aumentar la plantilla.
  • La correlación de señales mejora la fiabilidad de las investigaciones: El Commvault Security Investigation Agent correlaciona la información de las copias de seguridad con las señales de seguridad procedentes de plataformas como Netskope, CrowdStrike y Palo Alto Networks para determinar si las amenazas detectadas en los datos de las copias de seguridad también han afectado a los sistemas de producción.
  • La ciberresiliencia pasará a estar impulsada por agentes: el Commvault Security Investigation Agent es el primer paso hacia un futuro en el que agentes especializados de inteligencia artificial ayuden a los equipos de seguridad en las investigaciones, las decisiones de Recovery y la agilización de los flujos de trabajo de restauración.

Introducción

In The Matrix, there’s a moment that feels surprisingly relevant to today’s technology landscape. Agent Smith discovers he can duplicate himself. One becomes many, and suddenly Neo is surrounded by an army of identical agents operating simultaneously.

In many ways, that scene mirrors the world we’re entering today with agentic AI. Across industries, and especially in cybersecurity, we’re beginning to see the rise of specialized AI agents that can work independently, scale rapidly, and assist humans in ways that were previously impossible. But unlike Agent Smith’s relentless takeover, the goal of these agents isn’t domination. It’s defense.

Crecer y acabar con los silos

Security operations today face a fundamental scaling problem. The number of systems, signals, and security tools continues to grow, but the number of analysts does not.

Organizations now ingest telemetry from endpoint security platforms, network defenses, cloud monitoring tools, and identity protection systems. Each of these tools generates its own alerts and dashboards, often operating in isolation from one another. The result is an overwhelming amount of data spread across disconnected silos.

It’s tempting to assume the solution is simply hiring more analysts, but anyone who has managed large teams knows that adding people introduces its own challenges. As teams grow, communication becomes more complex, coordination slows down, and the efficiency of investigations often decreases.

What security teams really need is not just more people, but more intelligence and automation to help analysts move faster and see the bigger picture.

One of the most persistent silos in security operations has been the divide between backup systems and security tools. Traditionally, security teams monitor production environments through their security information and event management tools while backup environments operate in a separate console.

Backup data is often only examined after an incident occurs, when organizations are already deep in recovery mode. Yet attackers increasingly target backup systems precisely because they know they are critical to recovery.

Ransomware operators frequently encrypt production systems, attempt to corrupt backups, or leave malicious artifacts hidden inside protected datasets. This means that backup environments often contain valuable evidence of an attack, but that intelligence has historically been difficult for security teams to access and correlate with other signals.

El nuevo agente de investigación de seguridad

Commvault’s new integration with Microsoft Sentinel and Microsoft Security Copilotestá diseñado para cubrir esa laguna. Gracias a esta integración, los eventos de Commvault Cloud pueden transmitirse directamente al Sentinel Data Lake, lo que permite incorporar la telemetría de las copias de seguridad al mismo entorno analítico que las señales de seguridad de los terminales, la red y la nube.

En lugar de permanecer aislada, la actividad de las copias de seguridad ahora puede analizarse junto con el ecosistema de seguridad más amplio. Pero el verdadero potencial de esta integración radica en la introducción del Commvault Security Investigation Agent.

El Security Investigation Agent ayuda a los analistas a investigar posibles amenazas correlacionando las señales detectadas en los entornos de copia de seguridad con las procedentes de otras plataformas de seguridad. Cuando un analista introduce el nombre de host de un servidor, el agente recopila los eventos de seguridad generados por Commvault Threat Scan y Risk Analysis, incluyendo anomalías en las copias de seguridad, eventos de cifrado que puedan indicar actividad de ransomware, malware detectado en conjuntos de datos protegidos y copias de seguridad que contengan datos confidenciales.

A continuación, el agente correlaciona esos eventos con la telemetría de otras herramientas de seguridad en las que las organizaciones ya confían, como Netskope, CrowdStrike y Palo Alto Networks. Al analizar conjuntamente la actividad en todas estas plataformas, el agente puede ayudar a determinar si el comportamiento sospechoso identificado en los datos de copia de seguridad también aparece en los entornos de producción.

¿Cómo se consigue un agente?

Let’s first walk you through how you can start with our first agent focused on security investigations. Then we’ll share how we plan to rapidly spawn new agents – just like Agent Smith – so customers can take control of investigations, recovery decisions, and restore operations, giving security and operations teams the intelligence they need to respond faster and recover with confidence.

Configurar el conector

Antes de poder habilitar el agente de investigación de seguridad de Commvault, deberá instalar y configurar el conector de Commvault Cloud.

  1. Instalación: Las instrucciones para instalar Commvault Cloud Solution, junto con los permisos y los requisitos previos, se encuentran enaquí.

Captura de pantalla: Detalles de la instalación del Commvault Cloud Data Connector en el Centro de contenido de Microsoft Sentinel.

  1. Configuración: Una vez instalado, los detalles de configuración sonaquí.
 Use Commvault Security Investigation Agent

Una vez que se haya instalado el conector de Commvault Cloud, podrás utilizar el nuevo Security Investigation Agent.

  1. Ir ahttps://securitycopilot.microsoft.com/agents.
  2. Search for “Commvault Security Investigation Agent.”
  3. Click on “Set up” Agent.
  4. Click on “Ir aAgent.”
  5. Click on “Run” => “One time.”
  6. Provide the “Hostname” for the host you’d like help investigating, and click “Submit.”
    1. Nota: El nombre de host es el nombre del servidor en el que queremos comprobar si hay eventos de Commvault y de socios como Netskope, CrowdStrike y Palo Alto.
  7. El agente se ejecutará y, como resultado, obtendrás un análisis detallado y una serie de recomendaciones.

Captura de pantalla: Análisis detallado del Commvault Security Investigation Agent ejecutándose en un host que forma parte de una investigación.

Conclusión

The Matrix may have dramatized the idea of multiplying agents, but it captured an important truth about scale. When Agent Smith multiplied, the dynamics of the fight changed entirely.

Cybersecurity is undergoing a similar shift. Attackers are increasingly leveraging automation and AI to scale their operations. The only way defenders can keep pace is by scaling their own capabilities through intelligent systems that augment human expertise.

With the integration between Commvault, Microsoft Sentinel, and Microsoft Security Copilot – and with the introduction of the Commvault Security Investigation Agent – we are beginning to see what that future looks like. It’s a world where security operations are no longer constrained by silos, where investigations move faster, and where AI-enabled agents work alongside analysts to strengthen cyber resilience across the entire environment.

Over the coming year, Commvault plans to introduce additional agents – just like Agent Smith multiplying in The Matrix – that can help security teams run Commvault Threat Scan, spin up Cleanroom environments for SOC analysts to safely investigate incidents, and accelerate recovery by identifying the safest data to restore.

We’re also excited to collaborate with Microsoft to enable customers to use Microsoft Foundry to build and extend their own agents, allowing them to tailor automation and investigations to their unique environments.

By combining Commvault’s deep cyber resilience capabilities with Microsoft’s AI and security ecosystem, we’re helping organizations move toward a future where intelligent agents help analysts investigate faster, break down silos, and strengthen resilience across the entire environment.


Preguntas frecuentes

P: ¿Qué son los agentes de IA en las operaciones de seguridad (SecOps/ResOps)?
R: Los agentes de IA son herramientas especializadas y autónomas que ayudan a los equipos de seguridad analizando datos, correlacionando señales y apoyando las investigaciones. Operan junto a los analistas humanos para ayudar a acelerar la toma de decisiones y mejorar los tiempos de respuesta en entornos complejos.

P: ¿Por qué resulta tan complicado hoy en día ampliar las operaciones de seguridad?
R: Los equipos de seguridad se enfrentan a una avalancha de alertas y datos procedentes de múltiples herramientas, mientras que el número de analistas crece lentamente. Este desequilibrio genera cuellos de botella, lo que dificulta investigar las amenazas de manera eficiente sin automatización ni asistencia inteligente.

P: ¿Cómo mejora el Commvault Security Investigation Agent las investigaciones de amenazas?
R: El agente correlaciona los datos de copia de seguridad con las señales procedentes de plataformas de seguridad como CrowdStrike, Netskope y Palo Alto Networks. Esta visión combinada permite a los analistas determinar si las amenazas detectadas en las copias de seguridad también han afectado a los sistemas de producción, lo que aumenta la fiabilidad de las investigaciones.

P: ¿Qué problema resuelve la integración de los datos de copia de seguridad en los flujos de trabajo de seguridad?
R: Los entornos de copia de seguridad suelen contener pruebas cruciales de los ataques, pero históricamente han estado aislados de las herramientas de seguridad. La integración de estos datos permite a los equipos analizar las amenazas de forma integral, descubrir riesgos ocultos y tomar decisiones de Recovery más fundamentadas.

P: ¿Cómo pueden las organizaciones empezar a utilizar el Commvault Security Investigation Agent?
R: Las organizaciones deben instalar y configurar el conector Commvault Cloud en Microsoft Sentinel. Una vez configurado, se puede acceder al agente a través de Microsoft Security Copilot para llevar a cabo investigaciones con solo indicar un nombre de host.

P: ¿Cómo se perfila el futuro de los agentes de IA en la ciberresiliencia?
R: El futuro apunta hacia múltiples agentes especializados que ayuden a gestionar las investigaciones, la planificación de la Recovery y las operaciones de restauración. Estos agentes contribuirán a romper los silos, acelerar la respuesta y permitir operaciones de seguridad más resilientes en todo el entorno.Ritu Singh es director sénior de producto y Rich Vorwaller es director de Gestión de Productos en Commvault.


Blogs relacionados

Explicación de MCP 2.0: cómo proteger a los agentes de IA antes de que se protejan a sí mismos

Por qué la IA está echando por tierra tu estrategia de resiliencia (y qué hacer al respecto)

Cómo mantener la resiliencia frente a los ataques de acceso lateral

¿Estás preparado para los bucles de fuga de datos?

Tendencias del ransomware para 2026: IA, resiliencia y MTCR

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave

  • La IA está acelerando la creación de datos y los flujos de trabajo distribuidos, lo que hace que los enfoques reactivos tradicionales resulten insuficientes para garantizar la resiliencia.
  • Las operaciones de resiliencia (ResOps) ayudan a los equipos a pasar de la resolución reactiva de problemas a la acción coordinada, y Commvault aplica la IA en tres áreas: la protección de los datos, los modelos y los flujos de trabajo de IA; el aprovechamiento de la IA para orientar y acelerar la respuesta; y la extensión de la IA a todo el ecosistema de resiliencia en general.
  • Los agentes prácticos de IA están diseñados para detectar problemas operativos (Arlie Data Sense), orientar las decisiones de protección (Asesor de Arlie) y habilitar flujos de trabajo conversacionales (servidor MCP).
  • La seguridad y la gobernanza de los datos siguen siendo fundamentales. La IA debe entrenarse para respetar los controles de acceso, mantener la auditabilidad y operar dentro de los límites establecidos por las políticas.
  • Las organizaciones pueden empezar poco a poco con agentes específicos e ir ampliando hacia operaciones coordinadas e inteligentes.

AI introduces both new challenges and potential breakthroughs for enterprise resilience. On one hand, traditional siloed tools for protection, recovery, and governance weren’t designed to operate across constantly evolving AI environments that span multiple platforms.
On the other hand, AI-enabled resilience tools can deliver a transformative impact by helping teams maintain visibility, enforce policy, and recover cleanly. For IT and security teams, the question is how best to leverage the benefits of AI while mitigating the operational risks it can pose.
En un seminario web reciente, me reuní conTeja Medasani, director principal de producto de IA en Commvault, para explorar casos de uso reales en los que los agentes de IA se emplean en flujos de trabajo de resiliencia en la nube, SaaS, entornos locales y plataformas nativas de IA.

Por qué la IA está redefiniendo las operaciones de resiliencia

The rapid growth and dynamic nature of AI-native environments have put operational workflows under pressure. Manual tagging, spreadsheets, and logic quickly drift out of sync. Sprawling job history tables and audit trails slow manual troubleshooting and make subtle warning signs easy to miss. Recovery processes that assume centralized data and isolated failures are poorly suited for exponential data growth and fragmented workloads across platforms.
When data, workloads, and environments span platforms, resilience can’t remain siloed in separate teams, tools, and policies. A new operating model is needed: las operaciones de resiliencia, o ResOps.

Cómo se aplica ResOps en la práctica

El marco de ResOps aborda estos retos en tres dimensiones:

  • Proteger la IA: Proteger los datos, los modelos y los flujos de trabajo de la IA en todos los entornos para que sigan siendo recuperables y cumplan con la normativa.
  • Aprovechar la IA: utilizar la IA para reducir el esfuerzo manual, obtener información operativa y orientar las decisiones sobre respuesta y Recovery.
  • Ampliar la IA: conectar las operaciones de respuesta (ResOps) entre herramientas y equipos para ayudar a proteger las interacciones conversacionales y los flujos de trabajo integrados.

En el seminario web, nos centramos principalmente en el aprovechamiento y la ampliación de la IA, destacando las funciones clave que los agentes de IA pueden desempeñar en las operaciones diarias. Estos ejemplos se centran enArlie, Commvault’s AI assistant. Designed to help users interpret data, understand issues, and move toward action more efficiently, Arlie includes a biblioteca de agentes purpose-built to help address specific resilience workflows.
By helping reduce repetitive analysis, surfacing meaningful signals, and guiding decisions around security-aware recovery, these agents can help teams take actions more quickly and confidently. Arlie Data Sense, Asesor de Arlie, and Commvault’s el servidor MCP illustrate a few of the possibilities unlocked by AI-enabled ResOps.

Detección de problemas operativos con Arlie Data Sense

Arlie Data Sense ayuda a los equipos a dar sentido a datos operativos densos, como tablas de historial de tareas y registros de auditoría. En lugar de examinar manualmente cientos de filas para encontrar patrones o diagnosticar fallos, los usuarios pueden activarArlie to help analyze the data and generate an executive summary highlighting anomalies and emerging issues.
Teams can ask follow-up questions in natural language and explore data further through interactive summaries or visualizations. When a job fails, Arlie can help analyze logs, summarize the failure, identify the possible cause, and provide next steps for resolution.

Orientación en la toma de decisiones de respuesta con Asesor de Arlie

A medida que se añaden cargas de trabajo, cambian los responsables y varían los requisitos, mantener la cobertura de protección en todos los entornos se vuelve cada vez más difícil.Asesor de Arlie is designed to help teams create and validate protection plans at scale by evaluating the characteristics and current protection coverage for each resource, and then highlighting where adjustments may be needed.
Recommendations are presented clearly with reasoning explained, so teams can evaluate them and decide how to apply them within existing governance processes. This helps teams maintain consistency across dynamic environments.

Ampliación de los flujos de trabajo de resiliencia con el servidor MCP

Resilience workflows often need to connect with ticketing systems, collaboration tools, and security platforms outside the Commvault platform, and they need to be accessible to users who aren’t resilience experts. Commvault’s el servidor MCP makes it possible to extend workflows without custom integrations or significant training by allowing conversational interaction.
Users can ask questions or request actions in natural language, with their prompts translated into governed API calls behind the scenes – for example, to automatically create tickets in ServiceNow for failed jobs.

Coordinación y claridad entre equipos y plataformas

The examples above share a common theme: coordination. Effective resilience requires visibility, policy enforcement, and clean recovery across environments. AI can help strengthen these capabilities by helping teams identify what matters and act more quickly.
While the evolution of resilience from reactive recovery to continuous insight and guided action has become essential, it doesn’t need to happen all at once. Teams can start with targeted agents that address specific operational pain points and then build toward more coordinated operations as capabilities mature and teams gain confidence.
The key is to begin the ResOps journey now – because the challenges posed by evolving resilience requirements will only keep growing.
Vea el seminario web completo bajo demanda to see detailed demos of Arlie Data Sense, Asesor de Arlie, and conversational resilience in action, and explore how AI-enabled ResOps can help support your operational workflows.

Preguntas frecuentes

Q: What is resilience operations?

A: ResOps is an operating model that unifies data security, identity resilience, and cyber recovery into a continuous, automated discipline rather than treating them as separate IT functions. ResOps helps transform resilience from a reactive response to incidents into an active practice that helps continuously understand data access patterns, detect threats and anomalies, and enable fast, intelligent recovery at scale.
Q: What is Arlie and how has it evolved?

A: Arlie, short for autonomous resilience, was first introduced in 2023 as an AI assistant to help users navigate the Commvault platform more easily. As AI capabilities have evolved, Arlie has evolved as well.
In addition to answering questions and guiding configuration, Arlie now also includes a library of purpose-built agents to address specific resilience workflows, such as surfacing operational insights, recommending protection strategies, and guiding security-aware recovery decisions. Arlie has become an entry point into operational insight rather than just a how-to assistant.
Q: How does Arlie Data Sense help with operational troubleshooting?

A: Arlie Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find subtle warning signs or diagnose issues, users can trigger Arlie to analyze the full data set and generate an executive summary highlighting patterns, anomalies, and emerging issues.
Teams can ask follow-up questions in natural language and explore data through interactive summaries or visualizations. For failed jobs, Arlie provides root-cause analysis by analyzing logs, summarizing failures, identifying possible causes, and providing personalized next steps for resolution.
Q: What does “guided action” mean in the context of AI-enabled resilience?

A: Guided action refers to AI helping teams move from insight to response more efficiently by recommending specific actions based on analysis of operational data and protection coverage. Rather than simply surfacing information, AI agents like Asesor de Arlie help evaluate resource characteristics, identify gaps between current protection and policy expectations, and present clear recommendations with reasoning.
Teams retain decision-making authority and can evaluate recommendations within their existing governance processes, but the agent helps reduce the manual effort required to identify what needs attention and what actions may be appropriate.
Q: How does el servidor MCP enable conversational resilience workflows?

A: el servidor MCP uses Model Context Protocol technology to enable conversational interaction with resilience workflows through natural language. Users can ask questions or request actions in everyday language, and those requests are translated into governed API calls behind the scenes.
Identity, role-based access control, and audit logging remain in place, so the conversational interface doesn’t bypass security requirements. This approach helps reduce friction for experienced teams, lower barriers for new users, and enable resilience workflows to integrate more easily with other enterprise systems like ticketing platforms through standardized interfaces.
Q: How does Commvault enable AI to respect security and governance requirements?

A: In Commvault Cloud, AI interactions inherit the same identity and role-based access controls that govern the rest of the platform. When AI surfaces insights or recommends actions, it operates within the governance framework customers already rely on.
This means AI respects existing access controls, maintains auditability through standard logging, and operates within clearly defined policy boundaries. The architecture is designed to prevent natural language interactions or agent recommendations from bypassing the security and governance requirements already in place for the platform.
Q: Can organizations adopt AI-enabled ResOps incrementally?

A: Yes. Organizations can start with targeted AI agents that address specific operational pain points rather than transforming their entire resilience practice at once. For example, teams might begin by using Arlie Data Sense to help surface insights from operational data, then add Asesor de Arlie to help maintain protection coverage at scale, and later enable conversational workflows through el servidor MCP for easier integration with other systems.
This incremental approach allows teams to build confidence with AI-enabled capabilities, demonstrate value in specific workflows, and scale toward more coordinated, intelligent operations over time as the organization’s needs and capabilities evolve.
Vir Choksi es director principal de marketing de productos en Commvault.

Blogs relacionados

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Note: “MCP 2.0” is used here as a colloquial reference to the next-generation evolution of the Model Context Protocol. MCP itself uses date-based versioning (e.g., the latest release being 2025-11-25 at the time of this document’s release) and does not officially define a 2.0 release.

AI agents are no longer just answering questions – they’re taking action. They’re reading files. They’re modifying systems. And in some cases, they’re making decisions that ripple across an entire enterprise.That’s why Model Context Protocol (MCP) 2.0 matters.In a episodio reciente de STRIVE, Commvault’s thought leadership series on cyber readiness, I sat down with Werner Nel, Principal, Security and AI Intelligence, at Commvault, to unpack what MCP 2.0 really changes – and why security leaders can’t afford to treat it as a minor spec update.This isn’t a theoretical conversation. It’s a practical look at how enterprises can enable AI innovation without widening their blast radius.

Puntos clave: lo que realmente cambia con MCP 2.0

  • MCP 2.0 marca un cambio de la mera adopción de la IA hacia la rendición de cuentas.
  • OAuth puede permitir un acceso con privilegios mínimos para los agentes de IA.
  • Los esquemas estructurados pueden ayudar a mitigar la inyección de comandos y el uso indebido.
  • Los flujos de elicitación pueden añadir puntos de pausa críticos para las acciones de alto riesgo.
  • MCP 2.0 may help improve security – but doesn’t eliminate risk.
  • Es esencial comprender la autoridad de los agentes y su radio de impacto.

Por qué MCP 2.0 es un punto de inflexión

MCP 1.x was about adoption.It gave enterprises a way to connect AI models to real tools and real data. But as Werner explains, that first wave was never designed to answer the hardest question: How do we let AI agents execute real work inside the enterprise – without turning them into a security liability?

MCP 2.0 is the industry’s first serious attempt to answer that question.Instead of focusing purely on connectivity, it shifts attention to authorization, control, and visibility – three things security teams care deeply about, especially as agents move from read-only assistants to actors with real power.

Los tres cambios de seguridad más importantes

  1. OAuth comes to MCP. MCP 2.0 introduces OAuth support, giving enterprises a standardized way to assign permissions and enforce least privilege. Instead of relying on vague trust assumptions, agents can be scoped to exactly what they’re allowed to do—and nothing more.
  2. Structured schemas help reduce prompt injection risk. Structured schemas act like an allowlist for agent actions. If a tool isn’t explicitly defined in the schema, it won’t execute. This can help reduce prompt injection risk and other manipulation techniques that were easier to exploit in earlier implementations.
  3. Elicitation flows add a “pause button.” Elicitation flows can enable workflows to pause mid-execution so a high-risk step may trigger confirmation, validation, or even credential escalation. This can help shift teams from “log and hope” to more deliberate control over sensitive actions.

Avance: MCP 2.0 en acción

Esta vista previa destaca por qué la autoridad, el radio de impacto y la reversibilidad son las tres cuestiones más importantes que las empresas deberían plantearse al implementar agentes de IA.

The Gaps MCP 2.0 Doesn’t Solve (And Why That’s Important)

MCP 2.0 is a big step forward – but it’s not the finish line. As Werner highlights in STRIVE, there are still meaningful gaps enterprises need to account for in real-world deployments.For example, enterprises still can’t fully cryptographically prove that an MCP server is the authentic original (vs. a clone or modified copy). Similarly, even if the protocol improves authorization and input discipline, organizations still need to think about signing tools and binaries, and about the environment where MCP servers and models run – because a compromise can translate into broad access depending on how it’s deployed.The takeaway: MCP 2.0 improves the protocol, but organizations still have to make smart decisions about trust, containment, monitoring, and oversight.

Un marco sencillo para evaluar el riesgo de los agentes de IA

One of the most practical moments in the episode is Werner’s three-question risk lens – something CISOs and architects can apply immediately:

  • ¿Qué autoridad tiene mi agente?
  • ¿Cuál es el alcance del impacto?
  • ¿Hasta qué punto es reversible la acción que se está llevando a cabo?

These questions help teams move from generic “AI risk” discussions to concrete decisions about permissions, containment, and how to handle high-impact actions that may not be easy to roll back.

Mira el episodio completo de STRIVE

This blog only scratches the surface. In the full 20-minute STRIVE podcast, you’ll hear:

  • Por qué MCP 2.0 ha evolucionado tan rápidamente.
  • Qué deben priorizar los CISO en este momento.
  • Hacia dónde se dirige probablemente MCP 3.0.
  • Cómo pueden los equipos de seguridad mantenerse al día a medida que los agentes ganan en autonomía.

Mira el episodio completo de STRIVE en Readiverse.Profundiza en el tema y evalúa tu propia Readiness.

Preguntas frecuentes

Q: What is MCP 2.0?

A: MCP 2.0 is an updated protocol that governs how AI models interact with enterprise tools and data, with a strong focus on security, authorization, and control.Q: How is MCP 2.0 different from MCP 1.x?

A: MCP 1.x focused on connectivity and onboarding. MCP 2.0 prioritizes securing those interactions.Q: Does MCP 2.0 eliminate AI security risk?

A: No. It can help improve security hygiene but must be paired with strong architecture and governance.Q: What is an elicitation flow?

A: An elicitation flow allows AI workflows to pause for confirmation before executing high-risk actions.Chris Mierzwa es director sénior de marketing de cartera en Commvault.


Blogs relacionados

 

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

When you’re responsible for powering communities across southern Minnesota, cybersecurity isn’t just about protecting data. It’s about making sure the lights stay on. For Southern Minnesota Municipal Power Agency (SMMPA), implementing Commvault® Cleanroomfue una decisión estratégica que transformó su enfoque en materia de ciberresiliencia.

Afrontar el reto de frente

SMMPA serves as an electric wholesaler to 17 municipal utilities. With approximately 50 employees supporting critical power infrastructure, the organization must maintain constant resilience against increasingly sophisticated cyber threats, where even a short disruption could have widespread impact.

After more than a decade as a Commvault customer, SMMPA faced a new wave of cyber readiness requirements. Cyber insurance providers introduced stricter mandates, including copias de seguridad aisladas and malware scanning at rest.

At the same time, the team needed confidence that it could rapidly recover mission-critical systems such as domain controllers, SQL databases, and application servers, without risking the restoration of compromised data.

“As our cyber readiness requirements evolved, we started evaluating Cleanroom more seriously,” says Alan Wagner, Manager of IT & Corporate Cybersecurity at SMMPA. “We were thinking about additional ways to safeguard and protect ourselves. Cleanroom sounded like it would be a good solution for that.”

Having relied on Commvault for more than a decade and recently expanding into Commvault Cloud SaaS protection for Microsoft 365, SMMPA viewed Cleanroom as a natural next step in strengthening its cyber resilience strategy and helping it meet new compliance expectations.

Un proceso de implementación colaborativo

SMMPA’s Cleanroom deployment in March 2025 showcased the power of collaboration between its team and Commvault. Sam Mack, IT/OT and Cybersecurity Specialist at SMMPA, appreciated the responsive partnership: “The Commvault team was quick to address any questions we had during setup.”

The team worked together to optimize its VMware virtual machine configuration for the Azure environment. “We discovered we needed to install some additional tools on the virtual machines to get them running smoothly within Cleanroom,” Sam explains. This fine-tuning meant its recovery solution was calibrated for its specific infrastructure.

The result? A successful implementation that met all SMMPA’s requirements and positioned it for robust cyber resilience.

Proteger lo que más importa

SMMPA uses Cleanroom to protect its critical infrastructure, including file servers, application servers, SQL servers, virtual domain controllers, and print servers.

“We’re an Office 365 shop, and we use Commvault Cloud to back up that infrastructure,” Sam says. “In the event of a compromise, getting those domain controllers, file servers, and SQL servers is going to be our priority.”

The solution was particularly well suited to SMMPA’s environment. “I have to give Commvault and their teams a lot of credit for bringing Cleanroom to our attention,” Sam says. “Our cyber insurance policy is really big on pushing for copias de seguridad aisladas and malware scanning at rest, so Cleanroom was the perfect fit.”

El valor de la confianza

While SMMPA has been fortunate not to face a real-world cyberattack requiring Cleanroom, the solution provides valuable peace of mind to the team.

“It gives me a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time,” Alan says. “Cleanroom gives us confidence that we can restore our systems without worrying that something malicious is being brought back with the data. Nothing is ever 100% guaranteed, but since implementing Cleanroom, I’ve had far fewer concerns.”

The organization conducts annual testing of its Cleanroom capabilities, with plans to potentially increase the frequency to biannual testing. This regular validation helps keep the team familiar with the recovery process and maintain confidence in its ability to respond effectively to any incident.

“Cleanroom gives us a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time – without the concern, or with a minimal concern, that there’s something malicious in the data being restored.”

– Alan Wagner, Manager of IT & Corporate Cybersecurity, SMMPA

As SMMPA continues to refine its cybersecurity strategy, Cleanroom remains a cornerstone of its defense. The straightforward integration with its existing Commvault infrastructure, combined with the specific capabilities that meet its cyber insurance requirements, made it an obvious choice.

Cara Peterson es responsable de «La voz del cliente» en Commvault.


Blogs relacionados

More related posts


CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Puntos Clave

  • Commvault está ampliando su cartera de soluciones de resiliencia de identidades para dar soporte a Okta, y se prevé que el acceso anticipado comience en abril de 2026.
  • La identidad se ha convertido en un vector de ataque principal, con107 000 millones de registros de identidad expuestos en 2024yEl 57 % de los ciberataques comienzan con credenciales comprometidas.
  • The new capabilities can help provide automated, policy-driven protectionygranular, point-in-time recovery for critical Okta objectsyconfigurations.
  • Backup data is stored in immutable, air-gapped storage to help safeguard identity environments from ransomwareyunauthorized changes.
  • The solution extends Commvault’s unified la resiliencia de la identidad platform across hybrid environmentsywill be priced on a per-user basis.

Identity has become the new frontline of cyber defense –ythe stakes have never been higher.

Today, Commvault is announcing the expansion of its la resiliencia de la identidad portfolio to include support for Okta, delivering automated protectionyrapid recovery for one of the enterprise’s most critical control planes.Early Access is expected to begin in April 2026.

As credential theft acceleratesyidentity exposures surge worldwide, organizations can no longer treat identity systems as simply another application.Identity is the gateway to everything – users, applications, APIs, automation,yincreasingly, AI agents.When identity fails, the business stops.

Por qué es tan importante ahora la resiliencia de la identidad

Las cifras reflejan una realidad cruda:

The rapid growth of non-human, agentic,yAPI-based identities has dramatically expanded the attack surface.Meanwhile, hybrid cloud adoption, SaaS sprawl,yAI-enabled automation have elevated identity providers like Okta to mission-critical infrastructure.

While Okta is built on a resilient platform, when an identity provider is disrupted – whether due to human error, misconfiguration, ransomware, or malicious tampering – the consequences are rapid:

  • Los usuarios no pueden acceder.
  • Las aplicaciones no logran autenticarse.
  • Los sistemas generadores de ingresos se estancan.
  • Los servicios de atención al cliente dejan de estar disponibles.

And yet, many enterprises still rely on manual scriptsyad hoc processes to restore identity environments – increasing downtime, operational complexity,yrisk.

That’s the gap Commvault is helping to close.

Incorporación de la recuperación automática de identidades a Okta

Commvault’s expanded la resiliencia de la identidad capabilities can help provide automated protectionygranular recovery for critical Okta objectsyconfigurations.

Rather than rebuilding entire environments after an incident, organizations can precisely restore what was impacted – quicklyyconfidently.

“Identity is the new cyber battleground, with most modern attacks targeting identity systems,” said Pranay Ahlawat, Chief TechnologyyAI Officer at Commvault.“By extending our la resiliencia de la identidad capabilities to Okta, we’re helping customers protect one of their most critical control planesyhelping ensusre they can rapidly recover accessymaintain business continuity even in the face of disruption.”

Capacidades clave

Accelerated recovery from identity disruptions: Automated, policy-driven protection of critical Okta objects – including users, groups, applications,ypolicies – can help organizations to restore access quickly following outages, operational mistakes, or cyber incidents.

Granular, point-in-time recovery: Can help precisely restore only deleted, misconfigured, or compromised objectsysettings.No full-environment rebuilds required.

Ransomware-resistant protection: Backup data is stored in Commvault-managed immutable, air-gapped storage isolated from production environments, helping safeguard identity data from ransomwareyunauthorized changes.

Streamlined, integrated recovery: Recover complex, interconnected identity systems through a unified workflow – helping reduce operational overheadysave valuable time during incidents.

Unified la resiliencia de la identidad platform: Support for Okta extends Commvault’s single-platform approachen entornos de identidad híbridos, lo que contribuye a garantizar una aplicación coaquínte de las políticas,Gobernanza,yrecovery across providers.

Acceso anticipado a partir de abril de 2026

Commvault’s la resiliencia de la identidad support for Okta is expected to be available through public Early Access in April 2026, with general availability planned for Summer 2026.

The solution will be offered globally as part of the Commvault Cloud Identity Resilience suiteypriced on a per-user basis.

If identity is now the enterprise control plane, resilience must extend to identity itself.With support for Okta, Commvault continues advancing unified resilience at enterprise scale – helping organizations recover faster, minimize disruption,ystay operational in the face of escalating identity-driven cyber risk.

Learn more about la resiliencia de la identidad aquí.Regístrate ahorapara nuestro seminario web «Identidad bajo ataque: recupera el control con Commvault Identity Resilience, ahora compatible con Okta».

Preguntas frecuentes

Q: Why is la resiliencia de la identidad becoming a top priority for enterprises?
A: Identity systems now function as the enterprise control plane, governing access for users, applications, APIs,yAI agents.As credential theftyidentity-based attacks increase, disruptions to identity providers can immediately halt business operations.Protectingyrecovering identity infrastructure has become mission-critical.

Q: What does Commvault’s support for Okta include?
A: The expanded capabilities help provide automated protectionygranular recovery for essential Okta objects such as users, groups, applications,ypolicies.This will help organizations restore specific items impacted by outages, misconfigurations, or cyber incidents without rebuilding entire environments.

Q: How does granular, point-in-time recovery benefit security teams?
A: Instead of performing full-environment restores, teams can precisely recover only deleted or compromised objectsysettings.This approach helps reduce downtime, lower operational risk,yaccelerate restoration of normal access.

Q: How does Commvault protect identity data from ransomware?
A: Backup data is stored in immutable, air-gapped storage managed by Commvaultyisolated from production environments.This architecture helps safeguard identity configurations from ransomwareyunauthorized modifications.

Q: When will Okta support be available?
A: Public Early Access is expected to begin in April 2026, with general availability planned for Summer 2026.The offering will be available globally as part of the Commvault Cloud Identity Resilience suite.

Q: How does this expansion fit into Commvault’s broader resilience strategy?
A: Adding Okta support helps strengthen Commvault’s unified, single-platform approach to la resiliencia de la identidad across hybrid environments.It enables consistent Gobernanza, policy enforcement,yrecovery workflows, helping organizations maintain business continuity even during identity-driven disruptions.

Katharine Colucci es responsable de marketing de productos en Commvault.


Blogs relacionados

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Periods of geopolitical instability, including the current conflict in the Middle East, can lead to an increase in cyber activity from both state‑linked groups and opportunistic threat actors. Government agencies and industry organizations have encouraged businesses to maintain a heightened security posture during this time.
At Commvault, we’re doing exactly that. We’ve elevated our internal awareness, tightened our operational discipline, and reinforced our resilience measures. Commvault also works with a trusted threat intelligence partner, CloudSEK, para ayudarnos a supervisar los riesgos en constante evolución y ajustar nuestra estrategia de seguridad. Animamos a nuestros clientes, socios y compañeros del sector a que adopten medidas similares para mantenerse informados y reforzar los controles cibernéticos fundamentales.

En qué deben centrarse las organizaciones en este momento

1. Know when to shift into “heightened alert” mode

Have clear internal criteria for when to increase monitoring, limit non-essential changes on critical systems, or accelerate incident‑response readiness. These moves don’t need to be dramatic – they just need to be deliberate and well‑coordinated.

2. Reforzar la disciplina en materia de identidad y acceso

During periods of heightened regional tensions, many threat actor campaigns rely on compromising user accounts. Reinforce good hygiene: regular credential rotation, strong authentication, careful review of unusual login behavior, and prompt investigation of anything that looks out of place. For practical steps to reduce identity-related risk, see Commvault’s recent blog on Buenas prácticas de seguridad.

3. Presta más atención a tu perímetro expuesto a Internet y al acceso remoto

Threat actors often take advantage of internet‑facing systems or remote access tools during global flare‑ups. Ensure these systems are well‑maintained, updated, and monitored.

4. Prepárate para posibles interrupciones en la disponibilidad

DDoS and hacktivism activity often spikes during regional conflicts. Talk with your service providers, understand your mitigation options, and rehearse your internal escalation and communications plan so you’re ready if availability becomes a target.

5. Demuestra tu capacidad para recuperarte rápidamente

In times of uncertainty, resilience matters as much as prevention. Ensure your critical data is backed up securely, stored in multiple forms and locations, and restorable on short notice. Practicing recovery is just as important as having the backups themselves.

6. Mantente alerta ante la desinformación, la ingeniería social y las noticias falsas

Periods of conflict tend to bring surges in defacements, false breach or shutdown claims, and social‑media‑driven narratives. Treat sensational claims cautiously, verify impacts through trusted channels, report suspicious communications quickly, and maintain steady communication practices.

7. Mantente al día de las recomendaciones de fuentes fiables

Follow alerts and guidance from reputable government and industry bodies. These sources regularly highlight shifts in regional threat activity and recommend practical steps organizations can take to prepare. A few resources include: los avisos de ciberseguridad de la CISA; UK NCSC Reports & Advisories; los avisos de seguridad del CERT-EU; and la Base de Datos Nacional de Vulnerabilidades del NIST.


Stay ready, stay resilient

Cybersecurity during global instability is not about panic, it’s about posture. By staying informed, tightening foundational practices, and strengthening resilience, organizations can navigate turbulent periods with confidence.
If you’d like help reviewing your preparation or refining your approach, our team is here to support you.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave

  • Las estrategias tradicionales de resiliencia están fallando ante la escala,la velocidad y la autonomía de los sistemas basados en IA.
  • El ransomware industrializado y los ataques impulsados por la IA ahora se dirigen a los sistemas de copia de seguridad,lo que socava los cimientos de la recuperación.
  • Las organizaciones deben pasar de contar con equipos de seguridad y Recovery aislados entre sí a adoptar un modelo unificado y continuo denominado «operaciones de resiliencia».
  • La resiliencia basada en la IA requiere visibilidad de los datos en tiempo real,detección continua de amenazas y una Recovery inteligente y limpia a gran escala.
  • Las plataformas modernas permiten una Recovery rápida y verificada,lo que ayuda a las organizaciones a evitar el dilema entre restaurar rápidamente y restaurar de forma segura.

A medida que las organizaciones se apresuran a adoptar la IA,los CISO y los CIO se están dando cuenta de una cruda realidad: las estrategias de resiliencia que funcionaban para la infraestructura tradicional están fallando. Los sistemas que antes podían recuperarse de los ataques en cuestión de horas ahora pueden tardar días. Los enfoques de copia de seguridad diseñados para datos centralizados pueden tener dificultades con cargas de trabajo distribuidas entre nubes y plataformas de IA. Mientras tanto,las amenazas y las posibles vulnerabilidades aumentan día a día.En un seminario web reciente,Tim Zonca,vicepresidente de marketing de cartera de Commvault,abordó una cuestión urgente a la que se enfrentan los responsables de seguridad: ¿cómo se mantiene la resiliencia cuando la IA cambia radicalmente las reglas del juego?

What Industrialized Ransomware and AI Mean for Resilience

CISOs and CIOs are under pressure. In spite of billions spent on cyber defense,nation-states and professional crime rings continue to reap ever larger payoffs from their victims. Ransomware-as-a-service has become widespread,and advanced AI automation is accelerating the industrialization of malware. By including backup systems in their attacks,adversaries are undermining the very foundation of resilience.

As attacks become more sophisticated,targets are becoming more vulnerable. AI is scaling faster than organizations can secure,with exponential data growth,fragmentation across environments,more complex supply chains,and autonomous systems operating with minimal oversight. AI agents and non-human identities now outnumber humans 80 to 1. When these systems make mistakes or expose vulnerabilities,the impact can cascade across interconnected business processes.

Breaches and failures are now almost inevitable; the only question is whether you can recover fast enough to keep your business running. For organizations using legacy systems that assume human-controlled systems,centralized data,and isolated failures,the answer may well be no.

Making Resilience Operational

As AI agents make decisions across the environment,including a significant number of errors,it’s no longer enough to focus on protecting infrastructure. Security leaders must now broaden their operational focus across three critical areas:

  • Proteger continuamente los datos en su origen y supervisar la presencia de anomalías.
  • Controlar las identidades de las personas,las identidades no humanas y los dispositivos que acceden a los datos y los utilizan de forma autónoma.
  • Lograr una recuperación predecible de los datos a gran escala sin comprometer su integridad ni corromperlos.

Tradicionalmente,la seguridad de los datos,la resiliencia de las identidades y la recuperación cibernética han funcionado como disciplinas independientes,cada una con su propio equipo,herramientas,políticas y requisitos. Estos silos dejan vulnerabilidades que los atacantes pueden aprovechar y ralentizan la recuperación cuando fallan los sistemas de IA. Para cerrar esas brechas,las organizaciones deben unificar estas capacidades en un ciclo continuo y automatizado. A este enfoque lo denominamoslas operaciones de resiliencia (ResOps).

ResOps abarca tres requisitos esenciales para la resiliencia de la IA:

  • Understanding your data landscape: Knowing where data lives,its sensitivity,who’s accessing it (including AI agents and non-human identities),and what policies govern that access in real time. For AI workloads,this extends to protections like LLM prompt governance to control how models access data.
  • Continuous threat detection: Automated systems that constantly monitor for anomalies,compromised identities,and data corruption. When AI systems are making thousands of autonomous decisions,you can’t wait for periodic security reviews.
  • Recovery inteligente: restauración automatizada y completa de aplicaciones nativas de la nube en su totalidad y de sus dependencias. Para evitar una nueva infección,los equipos deben validar la integridad de los datos y llevar a cabo un análisis forense en un entorno aislado y seguro antes de volver a trasladar los datos fiables al entorno de producción.

La implantación de ResOps en la práctica

Para ayudar a las empresas a dar el salto a ResOps,Commvault ha presentadoCommvault Cloud Unity,el lanzamiento de plataforma más importante de nuestra historia. Está diseñado para aunar las tres dimensiones de la resiliencia:

A next-generation architecture brings AI automation to all facets of data protection,la seguridad de los datos,la resiliencia de la identidad,and recovery. For security and IT teams,the platform provides simplicity at scale with one experience,one policy engine,and one interface designed to protect data,predict threats,and accelerate clean recoveries.

As security leaders know all too well,recovering from the most recent backup minimizes data loss but risks restoring compromised data. Rolling back to a verified clean state may eliminate threats but means losing hours or days of business-critical transactions or AI model training.

With Commvault Cloud,la supervisión continua de amenazas and verified clean recovery points help eliminate this forced choice. The platform architecture automatically maps dependencies across distributed systems,helps maintain immutable backups,and helps enable one-click restoration of entire environments. Recovery can be both fast and clean,helping minimize loss as well as risk.

See ResOps in action

Vea el seminario web completo bajo demanda to learn more about ResOps,explore the architecture and services of Commvault Cloud,and rethink your resilience strategy for the AI age.


FAQs

 Q: What is Resilience Operations (Res Ops)?

A: ResOps is an operating model that unifies la seguridad de los datos,la resiliencia de la identidad,and la Recovery cibernética into a continuous,automated discipline rather than treating them as separate IT functions. ResOps transforms resilience from a reactive response to incidents into an active practice that continuously understands data access patterns,helps detect threats and anomalies,and enables fast,intelligent recovery at scale.

Q: Why can’t traditional backup and recovery handle AI workloads?

A: Traditional backup tools were designed for centralized,human-controlled systems with isolated failures. AI workloads involve autonomous agents accessing distributed data across clouds and complex dependencies between microservices and containers,and they operate at a scale that manual processes can’t match.

When AI systems fail or are attacked,you need to recover not just data but entire application infrastructures with all their configurations,policies,and relationships – capabilities traditional backup tools lack.

Q: What does “unified resilience” mean in practice?

A: Unified resilience means bringing la seguridad de los datos,identity management,and la Recovery cibernética together under a single platform,policy engine,and operational model rather than managing them as separate functions with different teams and tools.

In practice,this provides a consistent approach to protect all workloads and data locations,automatically correlate security events with access patterns,and orchestrate comprehensive recovery that restores both data and the complete application infrastructure needed to use it.

Q: What’s the difference between cyber resilience and AI resilience?

A: Cyber resilience focuses on protecting infrastructure and recovering from security incidents,treating resilience as an operational state for confronting threats. AI resilience expands this to address challenges unique to AI-driven systems: autonomous agents making decisions with minimal oversight,exponential growth of data and non-human identities across environments,and cascading failures where problems in interconnected AI systems impact entire business operations rather than staying isolated.

Q: How does ransomware target backup systems?

A: Ransomware increasingly targets backup systems by exploiting compromised credentials with privileged access,moving laterally from production systems to connected backup repositories,or exploiting vulnerabilities in backup software itself. Modern ransomware families specifically hunt for backup infrastructure to encrypt or delete recovery points,preventing organizations from restoring clean data and maximizing pressure to pay ransom. This makes offline,immutable,or air-gapped backups essential for resilience.

Q: What is the clean vs. complete recovery dilemma?

A: The clean vs. complete recovery dilemma is the forced choice organizations face during incident response. You can recover from the most recent backup to minimize data loss but risk restoring compromised or corrupted data; or you can roll back to a verified clean state before the incident to eliminate threats but lose significant business-critical data. Traditional backup tools make organizations choose between completeness and safety,while modern resilience platforms aim to provide both simultaneously through la supervisión continua de amenazas and verified recovery points.

Q: What is a cleanroom in la Recovery cibernética?

A: A cleanroom in la Recovery cibernética is an isolated,secure environment completely separated from production systems to help organizations safely test,validate,and analyze recovered data before restoring it to active use. Cleanrooms help enable forensic investigation of compromised systems,testing of recovery procedures,and verification that restored data is free from malware or corruption – all without risking reinfection of production environments or exposing sensitive data during analysis.

Sam Curcuruto es director de marketing de productos en Commvault.


Blogs relacionadosReplanteamiento de la resiliencia para la era de la IA

A CIO’s Perspective: Strengthening Business Resilience in the AI Era

Resistente contra la máquina de IA

Las innovaciones en materia de Cleanroom Recovery marcan el inicio de una nueva era en la ciberresiliencia

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Puntos Clave

  • “Instant restore” claims often break down at scale due to real-world I/O operations per second (IOPS), rehydration, and infrastructure constraints.
  • Las conexiones masivas en tiempo real al almacenamiento de copias de seguridad deduplicado pueden provocar un colapso del rendimiento, lo que obliga a una lenta rehidratación de vuelta al almacenamiento primario.
  • Las salas blancas permiten llevar a cabo simultáneamente la investigación forense y la recuperación de la actividad empresarial, en lugar de tener que hacerlo de forma secuencial, lo que provocaría tiempos de inactividad y retrasos.
  • La filtración de datos de identidad amplía el alcance del impacto, por lo que la recuperación aislada y la restauración de Active Directory (AD) resultan fundamentales para garantizar la seguridad de las operaciones.
  • Los manuales de procedimientos automatizados para salas blancas y las pruebas repetibles ayudan a las organizaciones a validar métricas de recuperación reales antes de que se produzca una crisis.

Let’s start with a quick story about a “ransomware‑proof” environment that took 72 hours to recover, way beyond the organization’s expectations for recovery time objective. It is exactly the kind of situation where Commvault’s Cleanroom could have helped turn a painful, three‑day outage into a faster, more controlled recovery with less risk.

Historia de guerra: la física contra el marketing

On Reddit, a user shared how the financial services firm they work for was hit by a breach. They assumed they had a “dream stack” for quick recovery (but can you really have a “dream stack” without Cleanroom?): immutable backups, secure storage snapshots, and a modern hypervisor. The datasheets promised “instant mass restore,” yet the business sat offline for three days while everyone tried to drag their environment back to life.

The root cause was not that backups failed, but that the real‑world physics of rehydration, forensics, and identity were never tested at scale. The original poster mentioned that having access to a cleanroom environment would have sped up the process. Let’s dig into this further and address why.

Commvault’s Cleanroom is designed to address exactly these weak points: It helps automate clean, isolated recovery into the cloud, validates data, and coordina la Recovery de manera que se adapte al desarrollo real de los incidentes, not just how diagrams look on slides.

Problem 1: The Rehydration Trap

In the story, “live mounting” a handful of virtual machines (VMs) worked fine, but trying to live mount hundreds crushed the backup appliance. The random I/O running directly on deduplicated, compressed backup storage collapsed the IOPS, forcing the team to rehydrate everything back to primary Non-Volatile Memory Express at about 3 TB/hour for roughly 100 TB of data.

Commvault Cleanroom helps recover workloads into an isolated Azure‑based cleanroom built on scalable cloud compute and storage instead of trying to run production at scale off a backup appliance.

This allows you to restore critical VMs into a purpose‑built recovery environment, use cloud elasticity to absorb I/O, and automate the recovery sequence so the right systems (identity, core apps, critical data) come up first without bottlenecking on a single backup target.

Problem 2: The Forensic Drag

In the audit, the tech stack was ready in about four hours, but legal delayed touching anything for 72 hours because they had no pre‑provisioned cleanroom. Without an isolated environment with zero routes back to production, the forensics team could not safely investigate while the business recovered, so everyone waited for the all-clear before starting any real restore.

Cleanroom provides an on-demand, isolated recovery environment explicitly built for simultaneous recovery and forensic analysis. Puedes poner en marcha una sala limpia aislada en Azure en cuestión de horas, recover systems into it, and let security and legal teams perform read‑only forensics and threat scanning while operations validates applications and prepares for cutover – dramatically shrinking “forensic drag” as a contributor to downtime.

Problem 3: Identity Blast Radius

The environment in the story had a single admin account with access to both the hypervisor and backup console, which meant if attackers pivoted that far, immutability could become just another setting they flipped off. Identity, not just data, was the real blast radius problem.

Cleanroom is designed to help reduce dependency on the compromised production identity plane during recovery, allowing isolated access and planned support for AD restoration in the cleanroom.

Mediante la reincorporación de los servicios de identidad a una sala limpia aislada and using separate, least‑privilege access paths, you can help validate AD, help enforce proper authorizations, and help protect backup control planes from being trivially compromised by the same credentials that were used in production.

How Cleanroom Would Change This Story

If this customer had used Cleanroom, their recovery story could have been very different.

For organizations that already invest in “ransomware‑proof” stacks, the missing piece is often not more features but a estrategia de salas blancas that respects physics, identity, and legal reality. Commvault Cleanroom is designed to close that gap and help turn recovery from a three‑day war story into a controlled, provable, and much faster operation.

Preguntas frecuentes

Q: Why did the “instant mass restore” approach fail in the ransomware scenario?
A: While live mounting a few VMs worked, scaling to hundreds overwhelmed the backup appliance due to I/O constraints. Deduplicated and compressed backup storage is not designed to handle full production workloads at scale, leading to performance collapse and delayed recovery.

Q: What is the “rehydration trap” in disaster recovery?
A: The rehydration trap occurs when organizations must restore large volumes of compressed backup data back to primary storage before systems can operate normally. This process is limited by throughput rates, which can dramatically extend recovery times when dealing with tens or hundreds of terabytes.

Q: How does a cleanroom help reduce forensic-related downtime?
A: A cleanroom provides an isolated environment where forensic teams can safely investigate while IT simultaneously restores systems. This parallel approach helps eliminate long waiting periods for legal or security approval before beginning recovery efforts.

Q: Why is identity such a critical factor in ransomware recovery?
A: If attackers compromise administrative credentials tied to both production and backup systems, immutability controls may no longer provide protection. Isolated identity recovery and least-privilege access can help limit blast radius and support a safer restoration process.

Q: How does Cleanroom help improve recovery orchestration?
A: Cleanroom helps automates workload sequencing, cleanpoint validation, and cloud-based recovery infrastructure provisioning. This structured approach aligns recovery with how incidents actually unfold, helping organizations regain control faster and with greater confidence.

Q: What is the strategic lesson for organizations with “ransomware-proof” stacks?
A: Advanced features alone do not guarantee fast recovery. A estrategia de salas blancas that accounts for infrastructure physics, identity isolation, and legal realities helps enable organizations to turn theoretical resilience into measurable, repeatable recovery performance.

Nico Guerrera es directora sénior de marketing de soluciones en Commvault.

Blogs relacionados

Recuperación de bosques de Active Directory: Por qué los métodos manuales ya no son viables

Pruebas de Recuperación: La pieza que falta en la mayoría de los programas de ciberresiliencia

Tu libro de jugadas moderno para una respuesta rápida y una recuperación limpia

Desbloquear la ciberresiliencia: El poder de las salas blancas

Why Cleanroom and Cyber Testing are Critical for Cyber Resilience

More related posts


Cyber Resilience

Read more about Cyber Resilience