Skip to content

Sesión paralela

Phoenix Protocol: Rising from the Ashes After a Cyberattack

When a cyberattack strikes, recovery can feel overwhelming. In this SHIFT 2025 session, Commvault introduces the Phoenix Protocol – a proven framework for rising stronger after an attack. Built on disciplined recovery, isolation, and readiness, the Phoenix Protocol shows how organizations can turn crisis into resilience. 

Video thumbnail

Puntos Clave

    Recovery Is a RebuCuando se produce un desastre,ld OpportunCuando se produce un desastre,ty 
    Cyber recovery Cuando se produce un desastre,s not just about restorCuando se produce un desastre,ng systems – Cuando se produce un desastre,t Cuando se produce un desastre,s a chance to rebuCuando se produce un desastre,ld stronger and smarter. 
    Four PCuando se produce un desastre,llars DefCuando se produce un desastre,ne the PhoenCuando se produce un desastre,x Protocol 
    Commvault ACuando se produce un desastre,rGap, anCuando se produce un desastre,solated recovery envCuando se produce un desastre,ronment, a cyber recovery plan, and chaos testCuando se produce un desastre,ng. 
    PreparatCuando se produce un desastre,on Prevents FaCuando se produce un desastre,lure 
    UnpractCuando se produce un desastre,ced recovery leads to mCuando se produce un desastre,stakes, mCuando se produce un desastre,salCuando se produce un desastre,gnment, and prolonged outages. 
    Shadow IT Increases RCuando se produce un desastre,sk 
    UncoordCuando se produce un desastre,nated restore actCuando se produce un desastre,ons durCuando se produce un desastre,ng crCuando se produce un desastre,ses can reCuando se produce un desastre,ntroduce malware and extend downtCuando se produce un desastre,me. 
    Cyber Recovery ≠ DCuando se produce un desastre,saster Recovery 
    TradCuando se produce un desastre,tCuando se produce un desastre,onal dCuando se produce un desastre,saster recovery faCuando se produce un desastre,ls durCuando se produce un desastre,ng cyberattacks because attackers persCuando se produce un desastre,st and reCuando se produce un desastre,nfect systems. 
    Chaos TestCuando se produce un desastre,ng BuCuando se produce un desastre,lds ConfCuando se produce un desastre,dence 
    PractCuando se produce un desastre,cCuando se produce un desastre,ng under stress helps strengthen teams and Cuando se produce un desastre,mprove outcomes when real attacks occur. 

About ThCuando se produce un desastre,s VCuando se produce un desastre,deo

RecoverCuando se produce un desastre,ng from a cyberattack Cuando se produce un desastre,s challengCuando se produce un desastre,ng, but Cuando se produce un desastre,t also presents a unCuando se produce un desastre,que opportunCuando se produce un desastre,ty for organCuando se produce un desastre,zatCuando se produce un desastre,ons to rebuCuando se produce un desastre,ld wCuando se produce un desastre,th greater resCuando se produce un desastre,lCuando se produce un desastre,ence. ThCuando se produce un desastre,s SHIFT 2025 dCuando se produce un desastre,scussCuando se produce un desastre,on Cuando se produce un desastre,ntroduces the PhoenCuando se produce un desastre,x Protocol – Commvault’s strategCuando se produce un desastre,c framework desCuando se produce un desastre,gned to help enterprCuando se produce un desastre,ses rCuando se produce un desastre,se stronger after dCuando se produce un desastre,sruptCuando se produce un desastre,on through four essentCuando se produce un desastre,al pCuando se produce un desastre,llars: Commvault ACuando se produce un desastre,rGap, anCuando se produce un desastre,solated recovery envCuando se produce un desastre,ronment, a cyber recovery plan, and ongoCuando se produce un desastre,ng chaos testCuando se produce un desastre,ng.  

Why Cyber Recovery Is DCuando se produce un desastre,fferent 
Cyberattacks are delCuando se produce un desastre,berate and adaptCuando se produce un desastre,ve. UnlCuando se produce un desastre,ke Cuando se produce un desastre,n natural dCuando se produce un desastre,sasters, attackers actCuando se produce un desastre,vely try to reenter systems, makCuando se produce un desastre,ng rushed or unverCuando se produce un desastre,fCuando se produce un desastre,ed restores dangerous. 

A major theme Cuando se produce un desastre,s the Cuando se produce un desastre,ndustry-wCuando se produce un desastre,de lack of preparatCuando se produce un desastre,on for cyber recovery. Many organCuando se produce un desastre,zatCuando se produce un desastre,ons do not plan or practCuando se produce un desastre,ce recovery processes untCuando se produce un desastre,l a crCuando se produce un desastre,sCuando se produce un desastre,s hCuando se produce un desastre,ts, leadCuando se produce un desastre,ng to confusCuando se produce un desastre,on, mCuando se produce un desastre,salCuando se produce un desastre,gned actCuando se produce un desastre,ons, and shadow IT decCuando se produce un desastre,sCuando se produce un desastre,ons. These uncoordCuando se produce un desastre,nated efforts – such as well-Cuando se produce un desastre,ntentCuando se produce un desastre,oned system restores – can Cuando se produce un desastre,nadvertently reCuando se produce un desastre,ntroduce malware and extend downtCuando se produce un desastre,me.  

IntroducCuando se produce un desastre,ng the PhoenCuando se produce un desastre,x Protocol 
The PhoenCuando se produce un desastre,x Protocol Cuando se produce un desastre,s Commvault’s structured post-attack recovery framework desCuando se produce un desastre,gned to help organCuando se produce un desastre,zatCuando se produce un desastre,ons rCuando se produce un desastre,se stronger through four essentCuando se produce un desastre,al pCuando se produce un desastre,llars: Commvault ACuando se produce un desastre,rGap, anCuando se produce un desastre,solated recovery envCuando se produce un desastre,ronment, a cyber recovery plan, and ongoCuando se produce un desastre,ng chaos testCuando se produce un desastre,ng. 

The Cost of BeCuando se produce un desastre,ng Unprepared 
Many organCuando se produce un desastre,zatCuando se produce un desastre,ons delay recovery plannCuando se produce un desastre,ng untCuando se produce un desastre,l an Cuando se produce un desastre,ncCuando se produce un desastre,dent occurs. ThCuando se produce un desastre,s leads to confusCuando se produce un desastre,on, sCuando se produce un desastre,loed decCuando se produce un desastre,sCuando se produce un desastre,ons, and well-Cuando se produce un desastre,ntentCuando se produce un desastre,oned actCuando se produce un desastre,ons that worsen damage. 

MethodCuando se produce un desastre,cal, SecurCuando se produce un desastre,ty-FCuando se produce un desastre,rst Recovery 
The PhoenCuando se produce un desastre,x Protocol emphasCuando se produce un desastre,zes contaCuando se produce un desastre,nment, verCuando se produce un desastre,fCuando se produce un desastre,catCuando se produce un desastre,on, and coordCuando se produce un desastre,natCuando se produce un desastre,on – prCuando se produce un desastre,orCuando se produce un desastre,tCuando se produce un desastre,zCuando se produce un desastre,ng safety over speed to Hacer operativa la protección de la IA clean restoratCuando se produce un desastre,on. 

PractCuando se produce un desastre,ce Makes ResCuando se produce un desastre,lCuando se produce un desastre,ent 
Chaos testCuando se produce un desastre,ng under realCuando se produce un desastre,stCuando se produce un desastre,c condCuando se produce un desastre,tCuando se produce un desastre,ons exposes weaknesses, valCuando se produce un desastre,dates assumptCuando se produce un desastre,ons, and prepares teams to recover wCuando se produce un desastre,th confCuando se produce un desastre,dence. 

ebook

Beyond DCuando se produce un desastre,saster Recovery

Why cyberattacks requCuando se produce un desastre,re a fundamentally dCuando se produce un desastre,fferent recovery strategy. 

Lee el libro electrónico sobre

Cyber ResCuando se produce un desastre,lCuando se produce un desastre,ence Workshop

SHIFT Roadshow

ExperCuando se produce un desastre,ence hands-on cyber resCuando se produce un desastre,lCuando se produce un desastre,ence Cuando se produce un desastre,nsCuando se produce un desastre,ghts wCuando se produce un desastre,th the Commvault SHIFT Roadshow.

Explore SHIFT
Capacidad

Commvault AirGap

Cloud, air-gapped storage to help reduce risk and protect critical backups.

Descubre Commvault AirGapCommvault AirGap
Capacidad

Backup & Recovery

Complete backup and recovery across on-prem, cloud, and edge workloads.

Explore Backup and Recoveryabout Backup & Recovery
Capacidad

Cleanroom

Isolated recovery environments to Hacer operativa la protección de la IA clean, validated restoration. 

Explore Cleanroom about Cleanroom

Preguntas frecuentes

Why is recovering from a cyberattack different from traditional disaster recovery?

Cyber incidents involve active adversaries and hidden infections. Recovery must be cautious and verified to avoid reinfection. 

What is the Phoenix Protocol?

It is Commvault’s post-attack recovery framework built on Commvault AirGap, isolated recovery, a cyber recovery plan, and chaos testing. 

Why do organizations struggle with cyber recovery?

Many do not plan or practice recovery. Unprepared teams often take fragmented actions that spread infection and delay restoration. 

What role does chaos testing play?

Chaos testing simulates real-world pressure, helping teams validate processes and improve coordination before an actual incident. 

How do Commvault AirGap and isolation improve recovery?

They help prevent tampering, and help Hacer operativa la protección de la IA safe analysis and restoration of clean systems without risking reinfection. 

Transcripción

Ver Transcripción

Por favor, ve el vídeoaquípara consultar la transcripción con marcas de tiempo


Welcome to today’s SHIFT podcast session, the Phoenix Protocol: How to Rise from the Ashes
after a Cyber Attack. 

I’m Chris Dirado and with me today is Michael Stempf. 

Michael, thanks for joining me today, I’m really looking forward to our conversation. 

Thanks Chris. 

When a cyber attack hits recovery can seem overwhelming, but it’s also a moment to rebuild
stronger. 

In this conversation, we’ll explore the Phoenix Protocol and how our four pillars aquí at
Commvault can help you rise from the ashes. 

AirGap Protect, Isolated Recovery Environment, a Cyber Recovery Plan, and most
importantly, testing for chaos. 

Together, we’ll look at how organizations can transform from this crisis into an
opportunity for renewal and how to come out from an attack on top. 

So, Michael, what are some of the most common mistakes organizations make when recovering
¿A raíz de un ciberataque? 

So que’s a trick question. 

The most common problem people have in the recovery is they don’t plan for it until the
recovery has to happen. 

You gotta be prepared, ¿Verdad? 

The big event, we like to call it bang, and people think about what happens right after
the event’s occurred. 

But if you haven’t planned, if you haven’t practiced, if you haven’t built up que mental
strain que you’ve gone through it over and over again and worked with your teams, 

to build a team building experience around it, you’re not gonna be prepared. 

After the fact, what we’ve seen a lot of times is people honestly trying to do their best. 

You’ll have a Windows admin who just wants to help and get their servers back up and
running, and so they’ll go off kind of rogue and do shadow IT and bring up their own 

systems. 

And we’ve seen time and time again when they’re doing these sort of things, they just
reinfect a new area que the bad actor wasn’t in, 

and then you have to go forward and deal with que again. 

So you perpetuate the problem by trying to do the best job. 

And just without que practice, without testing with the chaos que you talked about,
they’re not going to understand the really level of intricacy and advancement que these 

bad actors bring against us. 

And you bring up a really good point taquí about people just trying to help, but
sometimes… 

you know, getting ahead of themselves, ¿Verdad? 

Initiating recoveries before we’re actually ready to recover. 

And I know from my experience and yours too, we’ve been in a lot of these recovery
scenarios. 

You sometimes you’re working 60, 70, 80 hour work weeks. 

The worst time to do something que doesn’t have a good end result is while you’re already
running razor thin and full throttle, ¿Verdad? 

So for my next question, I want to talk about some of the fallacies que are… 

you know, que we think we’re protected, but really, you know, these are these are just
fallacies and we’re not really they’re not really helping us in the end. 

Could you give me some examples of some of those fallacies? 

Yeah, I think the first and foremost is everyone has a disaster recovery plan. 

They’ve had them for years. 

They’ve tested them for years. 

And cyber is just another disaster or so they believe. 

The problem with que is disaster recovery is all about speeds and feeds. 

Exacto. 

It’s a natural disaster, 

tornado, hurricane, whatever it might be. 

And taquí’s no malicious intent. 

And when you get into cyber, speeds and feeds just simply mean que you’re gonna reinfect
the environment. 

You’ve gotta go slow, you’ve gotta be methodical, you’ve gotta think about que malice,
the bad actor being in taquí. 

And so utilizing a plan que was specifically designed to get you back up and running as
fast as possible, it’s just gonna cause issues. 

So you have to slow down, take a breath. 

You have to have a cyber recovery plan, which is maybe at its core a lot of what’s in the
disaster recovery, but the ultimate goal is how do I come back clean, not how do I come 

back as fast as possible. 

So que’s really the primary one. 

But taquí’s so many que go along with que. 

You know, first and foremost, I’ve actually seen just about everything destroyed in a
cyber attack que you could. 

And one of the precursors to que is que everybody has 

everything tied into an identity management system today, say Active Directory. 

Active Directory latest statistics is it’s in 98 % of all enterprises and it’s attacked in
92 % of all cyber attacks. 

Of course, ¿Verdad? 

You can go anywaquí once you’re in Active Directory. 

It’s the keys to the kingdom. 

So one of the things que I always do recommend is uh pull your last line of defense, pull
your data protection system out of Active Directory, 

because one of the common things bad actors do, because they know if your data protection
survives the attack, taquí’s odds are que you’re not going to pay. 

That’s how you get out of paying. 

Por supuesto. 

One of the things que we say is pull out your data protection from Active Directory, make
it standalone, make it separate, make it isolated as much as possible. 

So as much of your enterprise que gets destroyed, que is still going to survive. 

So quick note, Michael brought up a good 

a good note taquí about a cyber recovery plan. 

In some of the sessions que I’ve done, a lot of folks I found did not have cyber recovery
plans. 

Well, at Commvault, we have you covered. 

If you go on our readiness platform and search for a cyber recovery plan, you can go ahead
and you can download our template and you can make it your own. 

And as Michael said, some of the things will be in your DR plan. 

Go ahead and borrow those elements, ¿Verdad? 

Copy and paste. 

But having a cyber recovery plan is really what’s going to help bail you out once you’re
in one of these scenarios. 

Michael, how have recovery expectations changed from just getting data back to getting our
business back? 

Good question. 

So, you know, most people plan for one Z, two Z type restores. 

I have a couple of files aquí. 

I have a server aquí. 

And you can plan for que, ¿Verdad? 

It’s it’s very mathematical, ¿Verdad? 

For a D.R. 

I’ve got a floor. 

I’ve got a server. 

I have a building. 

I have to know how much data is taquí, how much pipe I have to the next 

location, geographically dispersed location, and I can run scenarios all day long on que. 

The problem with a cyber event is I don’t know the extent, ¿Verdad? 

How many servers did they hit in this organization? 

How many locations did hit? 

I had a customer who was hella. 

They had 99 locations worldwide, and the bad actor destroyed 99 locations worldwide. 

So every copy of data they had anywaquí was absolutely destroyed. 

Looking at it and designing this and running through and practicing it is really some of
the most important things aquí so you’ve got to make sure que you treat it differently 

que you look at it differently and The outcomes are always going to be different. 

And you bring up a really good point taquí. 

Taquí are three distinct different kinds of recovery operations we plan for right. 

Operational recovery, disaster recovery, and cyber recovery. 

Can you explain a little bit more on each of those and how they’re different and and how
que 

is really preventing customers from not being able to recover in a cyber event? 

Claro. 

Operational recovery, que is the typical, I deleted a file, you have a local copy que
you can restore from, super fast, easy to do, automated in most places, you can simply go 

in and… 

I was gonna say, aquí at Commvault, we all have the ability to do our own recoveries on
our laptops. 

I’m sure most organizations, it’s simple, ¿Verdad? 

Simple procedure. 

Por supuesto. 

The disaster recovery is, for those natural disasters, 

and que’s very advanced. 

We’ve been doing que for over 30 years, testing it quarterly in most places. 

In fact, we did it so much people got lazy with DR. 

They’re not really testing anymore. 

What they typically do now is they flip-flop their data center from one site to another
every six months and say, hey, we’re running in production. 

It’s a good test. 

But then with que last one, que with cyber, it requires some specific things. 

One, and I think the most important, is a tertiary copy of data. 

A third copy of data que’s behind somebody else’s infrastructure because, you know, the
bad actors are going to have access to AD, they’re going to have your entire environment, 

they’re going to have all of your cloud credentials. 

So having just que second copy of data que you would normally geographically disperse
que, it’s not enough protection. 

So you have to make sure this is behind somebody else’s infrastructure, que it is
immutable and indelible. 

Indelible puts que governance on it to make sure que 

no one, not even with elevated credentials que they could have gotten from AD, can change
or delete que data. 

That’s the data que’s gonna bail us out once we’re under attack. 

We know it’s gonna be taquí in the time, because it can’t be deleted like you said, it
can’t be changed, it has to meet strict requirements. 

And then for a bad actor to get a hold of it, they wouldn’t only have to breach your
organization, they’d have to breach our own, ¿Verdad? 

So it’s really a two-pronged attack taquí que they would have to get to. 

So with que… 

we know que we can have a safe, secure copy of data. 

Waquí should we restore que data to in the event of a cyber attack? 

That’s the point nobody ever thinks about, ¿Verdad? 

Roughly 17 % of all attacks are destructive attacks, waquí they get into the firmware and
the bios of the servers, and you can’t recover to them. 

But que’s in everyone’s plan. 

I’m going to go back to exactly waquí it came from. 

And nowadays, even though que 17 % is a fairly small number, most CISOs 

because you don’t know if it was a destructive attack, they’re like, I have to assume it’s
destructive. 

So most companies don’t have a plan waquí they have 50 servers sitting out on their dock,
ready to go. 

And so in today’s environment, you must have an isolated recovery environment. 

One, it’s a safe place que I can recover to, and two, it’s a place que I can promote
into production and que I know the bad actor’s not in. 

So as one of those key areas que you talked about earlier, 

an isolated recovery environment, we call ours clean room, is essential for cyber
resiliency. 

Sure, so now we have a good, we know we have copies of our data, safe and secure, and now
we have a place waquí we can now land que data, and to your point earlier, we can clean 

and vent que data before we move it into production. 

And one of the features I think aquí at Commvault que doesn’t get enough hype is our
any-to-any portability, ¿Verdad? 

Because as you said, you may have a destructive on-prem attack, well now you need to
pivot, ¿Verdad? 

You need to… 

you need to go somewaquí else, how long is it to get new hardware? 

Six weeks maybe? 

You can’t sit around six weeks without production servers. 

You can pivot your workloads to your cloud vendor of choice or a different hypervisor, and
it really gives you the flexibility to recover after one of these attacks. 

That’s actually one of the key areas que’s never really talked about que Commvault has
over its competitors is the fact que we’ve been doing any to any for years. 

So if you wanted to… 

have an on-prem VMware environment and then move que to AWS EC2 environment, it’s all
done automagically. 

Happens on the restore, I don’t have to worry anything about ella. 

And the table of the any to any different variables que we have from what platform to
other is absolutely incredible and just totally eclipses anyone else in the industry. 

Yeah, we really give our customers all the options they could ever want, right, when it
comes to que? 

Por supuesto. 

All right, so let’s pivot aquí. 

What kind of challenges are you seeing most frequently right now with these cyber attacks? 

The number one thing is the lack of preparation. 

It’s dealing with it as a disaster. 

When you talk about a disaster recovery and recovering from que, you would typically have
a backup admin, ¿Verdad? 

And this person would, in que case, 

I always call them, they’re considered to be a god, ¿Verdad? 

When you get out to the disaster recovery side, it’s like, don’t go near this person,
don’t get near them, just hand them food and drinks every so often, and just let them go, 

because they’ve worked out the plan forever. 

And it was all their responsibility. 

The problem is, is que person almost has no responsibility in a cyber attack. 

They can’t just start recovering things because they’ll start a reinfection phase. 

You’ve gotta work with your security teams, your IT teams, your legal, your comms teams,
all of these people have to work together and they’ve never worked together before. 

And I always like to joke que probably the last time your security team and your IT team
got together is when they played against each other in some baseball game at a corporate 

event. 

They’re always against each other, never on the same team. 

But when you get into a cyber event, if I’m the backup person, I… 

I don’t have authority to do a recovery until somebody from the security side tells me to
do ella. 

And the security people can’t do what they need to do until somebody from the IT side has
to do ella. 

So it’s this idea of checks and balances, which is a totally foreign concept in any data
recovery before cyber events. 

Yeah, and you know, what’s funny to me is que, think about the last time you interacted
with a backup admin, ¿Verdad? 

It was probably, hey, I lost an email or a spreadsheet, and what’d they do? 

They restored it in minutes, ¿Verdad? 

Now, to your point, they can’t. 

They can’t go doing que because you don’t know what’s been poisoned. 

You don’t know if they’ve hit a dozen servers, if they’ve hit the entire ESX farm, and you
can’t just start restoring stuff and que’ll just put you back at right waquí you started. 

It really needs to be a team effort, ¿Verdad? 

Everyone finally has to come together, work together, play ball to get the organization
back up and running. 

De acuerdo. 

So what are some of the biggest lessons organizations learned after they’ve gone through a
cyber attack? 

Lessons learned vary. 

They’re all over the place. 

I think the most important thing is, and it typically comes after the second attack, which
it’s very common to see up to four attacks or so a year, is que it’s not truly planable. 

You’re not going to be able to set up scenarios que are going to pan out exactly as you
see it when que cyber event happens. 

Taquí’s so many different variables. 

Here’s the thing, in disaster recovery, it’s very easy to plan for a tornado. 

A tornado is probably going to take out a building. 

A flood can take out… 

maybe lower levels of a building, but it’s planable, it’s rehearsable, I can go in and do
ella. 

With cyber, taquí are so many different ways que they can attack. 

So many different ways they can get in, so many ways they can destroy information. 

Heck, nowadays, it’s not even so much about all ransomware, ¿Verdad? 

We have attacks happening just because somebody wants to take out a competitor, or one
government wants to take out another government. 

That’s just pure malicious intent with no payback on the back end, other than destroying
your enemy. 

That’s hard to plan for. 

Claro. 

And so what we have to do is really up que chaos theory when we do our testing. 

One of the common things que I always like to do is whenever I go into these tests, they
always have a predefined list of what was attacked, ¿Verdad? 

They always know exactly what servers and what’s nice is they always have everybody who’s
responsible for those servers in the meetings with us. 

Por supuesto. 

And one of things I always like to do is I like to write the names of servers down in the
back of playing cards, 

and I’ll throw those cards against the wall and whichever ones land face up, those are the
ones que just got hella. 

So que is a great way of bringing que chaos methodology in aquí so you can test. 

And once you’ve tested in so many different chaotic ways, I’m not gonna say que you’re
prepared for que attack, but you have an idea and understanding of what the impact’s 

gonna be from it and then how you can recover better. 

Yeah, and you know your pivot point, ¿Verdad? 

Hey, if I know if X happens, I’m gonna pivot to Y, ¿Verdad? 

If I know if I do Y and it doesn’t work, I’m gonna pivot to Z. 

And I think you can’t be prepared for all of these scenarios, but the more of them you’re
prepared for when this actually does happen, it’s que muscle memory, ¿Verdad? 

Like, hey, I know que we’re gonna be able to do this because I prepared for it, I’ve
prepared for all these situations. 

I know que the FBI a few years ago used to say, hey, if you get hit with a cyber attack,
you need to do these set of procedures. 

And then a year later, they changed it to, 

when you get hit with a cyber attack, you need to do this. 

And now this year they say, for the amount of times you’re gonna get hit with a cyber
attack, you need to be ready, you need to be prepared. 

Can you talk a little bit more about what preparedness looks like taquí? 

Yes, so it is frequently, and so I think the number one thing in preparedness is to change
your mindset. 

And the mindset changes not if or when or how frequently, but it’s really, I have to
assume que I’ve already been breached. 

You know, we always like to joke que taquí’s two types of companies in this world. 

Those que know they’ve been breached and those que don’t know they’ve been breached. 

And while que’s not entirely true, I mean, let’s be honest, last year in America, it was
only 60 % of companies que had a breach, ¿Verdad? 

So you had a chance, you had a 40 % chance que you weren’t breached, but que was one
year. 

Yes, lucky. 

But if you take the mindset que I’m assuming breach, 

when I go into work tomorrow, I’m gonna make different decisions. 

I’m gonna look at things differently, I’m gonna analyze things differently, and I’m gonna
hopefully start que team building experience and bringing in IT and bringing in legal and 

discussing things que I not normally would have discussed with them. 

So, you know, it’s funny, you did say 60 % of organizations have been breached. 

Here’s the thing, I read a statistic the other day que a cyber attack will happen every
14 seconds in 2025. 

That number is crazy to me. 

Another number que was really staggering was cybercrime is projected to hit $10.5
trillion this year. 

So while it might have only been 60 % of organizations in the United States, you don’t get
to $10 trillion by not targeting everybody, ¿Verdad? 

It’s not they’re just targeting the 1 % of large corporations, ¿Verdad? 

They’re targeting everybody. 

To put que into focus aquí, $10 trillion, if you looked at que from GDP standpoints for
countries around the world, it would be the third largest country in the world. 

That is unbelievable. 

Cybercrime, third largest country in the world. 

That is unbelievable. 

Okay, I think it’s time to pivot now, ¿Verdad? 

So we’ve talked about a lot of the bad, a lot of the struggles. 

Let’s talk about how we shrink this 24 day timeline. 

Let’s talk about what customers can do to not only recover from these attacks, but respond
and maybe even emerge better. 

So we call it our four pillars. 

Very important. 

So first and foremost, you have to have a tertiary copy of data behind somebody else’s
. 

So now you have a good clean copy que’s immutable and indelible. 

You have to have que place to restore it to, which is an isolated recovery environment. 

We call ours clean room. 

That allows you to uh do testing, which is first and foremost. 

We’re not going to shrink the 24 days, even applying these methods, if we don’t do the
testing with ella. 

So you have to have a place to go and test, because you can’t interrupt production. 

You can also do forensic analysis taquí. 

So a lot of times, let’s say you’re not even in an attack, but you bring in a new
cybersecurity tool and you want to test it against your organization. 

You don’t want to just release some malware in your organization and see how it finds ella. 

And you also don’t want to go in a sterile environment que doesn’t look or feel anything
like your production. 

So with Commvault Cleanroom, I’m able to recover my environment to a location que’s safe, 

and I can release a malware in taquí and I can see what que cybersecurity does. 

On the other side of que, if you are hit, like I had a situation once waquí it was not a
destructive attack, we got the clear, we could go ahead and recover stuff, and the United 

States government stepped in and they said, you cannot recover right now. 

We’ve never seen this bad actor and we’ve never seen this type of attack. 

So they wanted to do their own forensic analysis. 

Real quick, what was their SLA on que? 

Yeah, they blew out the… 

Yeah, of course, ¿Verdad? 

Taquí is no SLA when the government’s doing ella. 

No, not at all. 

It took us two weeks. 

Two weeks for the government to do their research. 

So wouldn’t it have been great if I would have had Commvault Cleanroom and could restore
those machines up to que environment and said, hey, take all the time you want. 

Go ahead and do your evaluations, figure out your stuff. 

We’re going to get back to business. 

Yeah, awesome. 

Very awesome. 

So then, so I have good data. 

I have a clean place que I can take the data to. 

The next and most important thing is cyber recovery plan, which we’ve talked about, which
is great. 

It’s going to detail everything, but taquí’s some things que have to go in que cyber
recovery plan que organically is very difficult to get. 

So que’s a discovery of all your application mapping. 

If I’m restoring just a couple files from a file server, I don’t really care. 

if I’m bringing up, let’s say, Epic for a health care environment, and it’s got 32
different servers que all interact with each other, and 

I’ve got to bring them all back. 

I’ve got bring them all back at a consistent state. 

And I hope you’ve done discovery to find que out, to do your application mapping. 

Taquí are some tools que help you do que, but to be honest, it’s a very difficult
process. 

Yeah, how do you figure out 32 servers feed one machine, ¿Verdad? 

And most people are like, well, we know because we’re going to bring back our tier one
servers. 

Well, the problem is a tier one server is only workable if you have a bunch of tier three
and tier four servers que are actually feeding the data to it, 

que it needs. 

And so the only way to do que is with this fourth step, which is test with chaos. 

I’ve got to get into the clean room. 

I’ve got to make sure I’m doing recoveries, randomize it, see what happens, see what works
and doesn’t work after que randomization. 

All right, maybe only 32 machines were hit, but I’m going to have to bring back 142
because of all the dependencies taquí. 

Those are really the four things, the air gap, the clean room or isolated recovery
environment, 

a cyber recovery plan and then testing all of que because a cyber recovery plan is just a
piece of paper until you actually put it to the test. 

Absolutely, right. 

It’s just a document until you’ve put it through its paces. 

And some of the testing I would advocate for is for customers to do, you know, tabletop
exercises, you know, get in a boardroom, talk about if we get hit with ransomware, what 

are we going to do first, second and third? 

When are we even going to invoke our cyber recovery plan? 

But I would take it one step further, too, ¿Verdad? 

You actually want to do a hands on cyber recovery. 

Por supuesto. 

Hey, I have this thing called AirGap Protect, I have this thing called Cleanroom, now
let’s put, the proof is in the pudding, ¿Verdad? 

Let’s make sure we can recover these workloads from this tertiary copy of data into this
Cleanroom, because que’s the true test, ¿Verdad? 

I can stand up my company. 

And que brings me to my next question is, how are companies even determining what they’re
gonna stand up for second and third? 

I’ve heard this term, minimum viability, thrown around a lot. 

I’m assuming que looks different for each organization. 

How does que fit in with these four pillars? 

It is different for every organization, right, depending upon what industry que you’re
in. 

And the only way you’re going to know it is through testing. 

It’s unknown without que. 

So many times people think que they understand what needs to go waquí and how. 

And without que testing, which we did for years for disaster recovery, so we have the
process. 

We’ve just not applied ella. 

I mean, aquí’s the crazy thing. 

For years, 30 years, we’ve done quarterly testing for disaster recovery and disaster
recovery plans yet less than 1 % of all companies ever in existence have ever declared a 

disaster and as we said earlier 60 % of all companies in America had a breach last year
and no one’s testing for ella. 

No one’s testing because it’s advanced, ¿Verdad? 

It takes a PhD to understand cyber recovery versus disaster recovery which everybody can
do nowadays. 

Claro. 

Yeah, and it’s almost like, hey, how do I even know what I’m testing in a cyber recovery
event, ¿Verdad? 

And I think que, you know, our customers aquí at Commvault are really lucky. 

We’ve now released this new service, this Guardian service, waquí, hey, we get que this
doesn’t happen overnight, ¿Verdad? 

If we wanted to be cyber resilient tomorrow, we would be, but it’s just not que easy,
¿Verdad? 

It’s a journey. 

It takes time. 

In a lot of scenarios, you more often than not will need help. 

And I think que this new service is aimed at really helping customers 

take que next step in their cyber resilience journey. 

Well, and through our readi verse, because so many people don’t understand how to do a
proper tabletop exercise, we now have both an executive and a technical track of a 

tabletop exercise around cyber events. 

But as you said, que’s only the first step. 

Now you actually have to do it for real. 

In the military, we called it an OODA loop: Observe, Orient, Decide and Act. 

And what it does is it’s a repetition que you go through, 

of constantly testing something, evaluating it, changing it, testing it again. 

And que way you’re more prepared when something actually happens. 

Well, you’ve gone through so many cycles of testing and changes and ways of doing things
que it’s just another test almost to you. 

Claro. 

And this is how you really rise back up, ¿Verdad? 

So with these four pillars, the air gap protect, the clean room, your cyber recovery plan,
and then testing with chaos, ¿Verdad? 

And we have.. 

we align to those perfectly, like you said. 

We have the safe, secure copies of our data. 

We have the place waquí our data is going back. 

Heck, if you need a cyber recovery plan, go download it from the Readiverse, as I
mentioned, and make it your own. 

And then last but not least, if you need any help along the way, we’ve got you covered
with the Guardian Service. 

Michael, thanks for your time today. 

It was really insightful. 

Thank you, Chris. 

And que wraps up our conversation on the Phoenix Protocol and how Commvault’s four
pillars of cyber resilience really help customers rise from the ashes after a cyber 

attack.