Skip to content

Tout savoir sur le Backup and Recovery dans le cloud : de la détection des menaces à la Recovery complète

Découvrez comment fonctionnent la Backup and Recovery dans le cloud pour vous aider à protéger vos données saines, à vérifier la Readiness de votre système pour la Recovery et à rétablir vos activités après une attaque par ransomware ou un incident informatique.


Le processus idéal de Backup and Recovery dans le cloud commence par la détection de menaces telles que les ransomwares, les accès suspects ou les activités inhabituelles sur les données. Les entreprises peuvent alors obtenir des copies de sauvegarde saines et immuables, valider les points de restauration non affectés et isoler les systèmes compromis. Une fois ces éléments vérifiés, les applications et les données critiques peuvent être restaurées grâce à des processus de Recovery automatisés, ce qui permet de minimiser les temps d’arrêt, de réduire les pertes de données et de rétablir les opérations métier rapidement et en toute sécurité.


La cyber-résilience se mesure de plus en plus à l’aune de ce qui se passe une fois que les attaquants ont réussi à s’introduire dans le système. Les entreprises ont investi massivement dans la prévention, la détection et la réaction, mais les ransomwares, l’exploitation des vulnérabilités, l’usurpation d’identifiants, les erreurs de configuration du cloud et la compromission de tiers continuent de perturber leurs opérations.

Pour de nombreuses équipes, le défi de la Recovery ne se résume plus à savoir si des sauvegardes existent. Il s’agit de savoir si ces sauvegardes sont intactes, protégées, validées et prêtes à restaurer les services critiques lorsque l’on ne peut plus se fier aux systèmes de production.

Cette distinction est importante car les cyberattaques continuent de générer à la fois des risques liés aux données et des perturbations opérationnelles. Selon le rapport« 2026 Data Breach Investigations Report» de Verizon, les rançongiciels étaient impliqués dans 48 % des violations de données, contre 44 % l’année précédente. Le rapport a également révélé que l’exploitation des vulnérabilités était devenue le vecteur d’accès initial le plus courant pour les violations, atteignant 31 %, tandis que l’utilisation abusive des identifiants est tombée à 13 %.

Les efforts de Backup and Recovery dans le cloud doivent couvrir l’ensemble du processus, de la détection à la restauration. Cela commence par l’identification des activités suspectes avant que les données compromises ne soient restaurées. Cela se poursuit avec des points de Recovery protégés et immuables qui offrent aux équipes des options de Recovery exploitables lorsque les systèmes de production ne sont plus fiables.

À partir de là, les entreprises doivent disposer d’un moyen de vérifier quels points de restauration sont sains et de restaurer les charges de travail critiques dans le bon ordre. Il en résulte une stratégie de Recovery qui aide les équipes à passer de la réponse aux incidents à la Recovery opérationnelle avec davantage de confiance.

 


Pourquoi la Backup and Recovery dans le cloud constituent-elles une stratégie de cyber-résilience ?

Traditional backup strategies were designed to help organizations recover from hardware failures, accidental deletion, and localized outages. Those use cases still matter, but today’s recovery requirements are broader.

Les cyberattaques peuvent affecter simultanément les charges de travail de production, les systèmes d’identité, les configurations cloud, les applications SaaS et les environnements de sauvegarde. Dans ce cas, la reprise ne se résume pas à restaurer une copie des données. Il s’agit de déterminer quels systèmes sont fiables, quels points de reprise restent intacts et quels services doivent être rétablis en priorité.

C’est pourquoila Backup and Recovery dans le cloudsont devenues un élément essentiel de la cyber-résilience. Une stratégie moderne doit aider les équipes à détecter les activités suspectes, à protéger les données de reprise, à valider l’intégrité des sauvegardes et à restaurer les opérations critiques selon une séquence contrôlée. Elle doit également faciliter la réalisation de tests réguliers, car un plan de Recovery qui n’a pas été mis en pratique risque de ne pas fonctionner comme prévu lors d’un incident réel.

Cela marque un changement de perspective : la sauvegarde n’est plus une simple police d’assurance, mais la capacité opérationnelle de reprise. Les copies stockées restent importantes, mais elles ne constituent qu’une partie de l’équation de la reprise. Les équipes doivent également avoir l’assurance que les données de reprise n’ont pas été altérées, que les workflows de restauration ont été testés et que l’entreprise sait quels services doivent être rétablis en priorité.

Backup and Recovery dans le cloud deviennent plus faciles à comprendre lorsqu’on les envisage comme un cycle de vie. Les cinq étapes ci-dessous montrent comment les organisations peuvent passer de la détection précoce des menaces à une Recovery validée, puis à l’amélioration de la résilience à long terme.


Étape 1 : Détecter les menaces avant que le risque lié à la Recovery ne se propage

Recovery commence avant même que les systèmes ne soient remis en service. En cas de cyberincident, la première priorité est de déterminer si une activité suspecte a affecté les données de production, les données de sauvegarde, ou les deux.

Si les équipes effectuent une restauration à partir d’un point de reprise compromis, elles risquent de réintroduire dans l’environnement des fichiers corrompus, des artefacts de logiciels malveillants ou des modifications non autorisées. Ce risque fait de la détection des menaces un élément essentiel de Backup and Recovery dans le cloud, et pas seulement une préoccupation des opérations de sécurité.

Les stratégies de reprise modernes doivent inclure une visibilité sur les activités anormales au sein des charges de travail, des environnements de sauvegarde et des points de reprise. Les équipes peuvent être amenées à examiner des signaux tels que :

  • Un comportement de chiffrement inhabituel
  • Des pics soudains de suppressions
  • Des modifications inattendues des privilèges
  • Des schémas de sauvegarde anormaux
  • Indicateurs de logiciels malveillants

Ces signaux peuvent aider les équipes à comprendre où une attaque a pu se propager et quelles données peuvent nécessiter un examen supplémentaire avant leur restauration.

Timing is another essential factor. Microsoft’s Le rapport 2025 Digital DefenseReport de Microsoft a révélé que la plupart des attaques examinées par son équipe DART (Detection and Response Team) présentaient des temps de persistance courts, ce qui signifie que les équipes de reprise après sinistre n’ont pas forcément plusieurs semaines pour cerner l’étendue totale de la compromission avant que les attaquants ne se déplacent latéralement, n’accèdent à des données sensibles, n’interfèrent avec les services ou ne tentent de compromettre les systèmes de sauvegarde. Le contexte de détection peut aider les équipes à éviter de considérer tous les points de restauration comme étant également fiables.

59 % des attaques examinées par Microsoft DART ont duré sept jours ou moins, ce qui rend la détection précoce essentielle pour les décisions relatives à la Recovery.
Source :Rapport Microsoft Digital Defense 2025

Threat detection doesn’t eliminate recovery risk on its own. It helps create a more informed recovery process. When suspicious activity is identified early, organizations can isolate affected systems, investigate impacted data, and avoid restoring recovery points that may reintroduce the same threat.

Cela offre aux équipes de sécurité, informatiques et de Recovery un point de départ plus clair pour l’étape suivante : protéger les points de reprise sains avant que les attaquants ne puissent les altérer ou les supprimer.


Étape 2 : Protéger les points de Recovery intacts contre les attaques

En cas de cyberincident, les sauvegardes ne sont pas de simples copies stockées. Elles font partie intégrante du processus de Recovery, ce qui signifie que les attaquants peuvent tenter de les perturber. Si les données de sauvegarde sont altérées, chiffrées, supprimées ou rendues inaccessibles, l’entreprise risque de perdre l’un de ses meilleurs moyens de rétablir ses opérations sans avoir à recourir à des systèmes de production compromis.

That’s why les points de restauration intactsnécessitent une protection à plusieurs niveaux. Un stockage de sauvegarde immuable et indélébile peut contribuer à préserver les données pendant une durée de conservation définie. Des copies hors site ou isolées permettent de renforcer la séparation par rapport à l’environnement de production. Le chiffrement, les contrôles d’accès et les autorisations basées sur les rôles contribuent à limiter le nombre de personnes pouvant accéder aux paramètres de sauvegarde ou les modifier. Ensemble, ces mesures de sécurité compliquent la tâche des attaquants qui chercheraient à interférer avec les données dont les équipes pourraient avoir le plus besoin lors de la restauration.

L’objectif est de préserver les options de Recovery. Le rapport Verizon de 2026 a révélé que69 % des victimes de ransomwarefigurant dans son échantillon n’avaient pas payé la rançon, contre 65 % l’année précédente. Le rapport note également que le montant médian des rançons versées a continué de baisser, ce qu’il attribue en partie à l’amélioration des mesures défensives et à la résilience accrue des victimes. Les équipes ont besoin de sauvegardes intactes qu’elles peuvent réellement utiliser, de sorte que le paiement d’une rançon ne soit pas la seule voie pour reprendre leurs activités.

La règle de sauvegarde bien connue « 3-2-1 » constitue toujours une base utile : conserver trois copies des données, sur deux supports ou plateformes différents, dont au moins une copie stockée hors site ou isolée. Les stratégies modernes de Backup and Recovery dans le cloud étendent souvent ce modèle avec un stockage immuable, des modèles « air-gapped », une conservation basée sur des politiques et des copies répliquées dans des environnements cloud ou hybrides.

Grâce à la mise en place de points de restauration protégés, les équipes peuvent réduire leurs options de restauration et passer à la phase de validation en ayant une vision plus claire de ce qui est prêt à être restauré.


Étape 3 : Vérifier quelles sauvegardes sont prêtes à être restaurées

Disposer de sauvegardes ne signifie pas pour autant être prêt à effectuer une restauration. Avant de restaurer les systèmes de production, les équipes doivent savoir quels points de Recovery sont exploitables, quelles charges de travail ont été affectées et quelles dépendances doivent être rétablies en même temps.

Une sauvegarde récente peut contenir les données métier les plus récentes, mais elle peut également inclure des fichiers corrompus, des modifications non autorisées ou des traces de logiciels malveillants. Une sauvegarde plus ancienne peut être plus «propre», mais elle peut entraîner davantage de pertes de données. La validation aide les équipes à faire ce compromis en s’appuyant sur des preuves plutôt que sur des conjectures.

Ce travail commence par la délimitation de l’incident. Les équipes de sécurité et informatiques doivent comprendre quand l’activité suspecte a commencé, quels systèmes ont été touchés et si les services d’identité, les bases de données, les partages de fichiers, les applications SaaS ou les configurations cloud ont été affectés.

Elles doivent également vérifier si le point de Recovery prend en charge l’application dans son ensemble, et pas seulement les données qui la sous-tendent. Une restauration de base de données, par exemple, peut dépendre de la disponibilité et du bon état des serveurs d’applications, des autorisations, des clés de chiffrement, des routes réseau et des services d’identité.

Des environnements de Recovery isolés peuvent aider les équipes à tester ces conditions avant de procéder à la restauration en production. Dans un environnement contrôlé, les équipes peuvent en toute sécurité :

  • Analyser les points de Recovery sélectionnés.
  • Examiner les modifications apportées aux fichiers.
  • Vérifier le démarrage de l’application.
  • Tester l’accès des utilisateurs.
  • Vérifier si les systèmes dépendants se comportent comme prévu.

La validationdoit également orienter la séquence de Recovery. Les équipes devront peut-être restaurer d’abord les services d’identité, puis l’infrastructure de base, ensuite les applications critiques, et enfin les charges de travail associées.

En testant les points de reprise avant la restauration, elles peuvent affiner leurs options et déterminer quels systèmes sont prêts à être remis en service, lesquels nécessitent un examen plus approfondi et lesquels doivent rester isolés jusqu’à ce que le Risk soit mieux cerné.

L’étape suivante consiste à mettre cette décision en pratique : restaurer en priorité les systèmes, les applications et les données dont l’entreprise a besoin.


Étape 4 : Rétablir les opérations essentielles dans le bon ordre

A restore plan starts with the organization’s minimum viable operating state. That means identifying the people, systems, applications, data, and communication channels the business needs to function at a basic level during a disruption.

Pour certaines organisations, cela peut commencer par les services d’identité et la communication avec les collaborateurs. Pour d’autres, la priorité peut être donnée aux applications en contact avec la clientèle, aux systèmes de paiement, aux systèmes cliniques, aux opérations de fabrication ou aux plateformes logistiques. L’ordre doit refléter l’impact sur l’activité, et non pas seulement la commodité technique.

Dependencies are where many recovery plans become more complicated. An application may be listed as “critical,” but it still depends on identity, DNS, network connectivity, databases, storage, encryption keys, APIs, and monitoring. If those pieces are not restored in the right state, the application may come back online but remain unusable. That is why recovery teams need dependency mapping before an incident, not during one.

Les runbooks et les workflows orchestrés permettent de transformer ces décisions en étapes reproductibles. Ils permettent de définir qui approuve la restauration, quel environnement doit être utilisé, quelles vérifications doivent être effectuées avant que l’accès à la production ne soit rétabli, et à quel moment le niveau suivant de systèmes peut être remis en ligne. Cela revêt une importance particulière lorsque les équipes chargées de la sécurité, de l’infrastructure, des applications, du cloud et des activités opérationnelles travaillent toutes simultanément.

La restauration nécessite également des points de contrôle. Après le retour de chaque charge de travail majeure, les équipes doivent vérifier que les utilisateurs peuvent s’authentifier, que les données sont disponibles, que les intégrations fonctionnent et que la surveillance est en place. Ces vérifications permettent de détecter les problèmes avant que Recovery ne s’étende au niveau suivant des systèmes.

La rapidité reste importante, mais le contrôle l’est tout autant. Une restauration rapide peut générer davantage de travail si les mauvaises données sont rétablies, si des contrôles d’accès font défaut ou si une application est rétablie sans les systèmes dont elle a besoin pour fonctionner. L’approche la plus efficace consiste à procéder à une restauration par phases, à vérifier que chaque service critique fonctionne, puis à poursuivre l’extension de la restauration à mesure que l’environnement se stabilise.


Étape 5 : Tirer les leçons de la reprise pour renforcer la continuité

Une fois les services essentiels rétablis, les équipes doivent encore comprendre ce qui a fonctionné, ce qui les a ralenties et en quoi le plan de Recovery ne correspondait pas à la réalité. C’est ce suivi qui transforme la Backup and Recovery dans le cloud d’une simple intervention ponctuelle en une pratique de résilience continue.

La première étape consiste à analyser la Recovery elle-même. Les équipes doivent se poser des questions telles que :

  • À quelle vitesse les équipes ont-elles détecté une activité suspecte ?
  • Les points de Recovery valides ont-ils été faciles à identifier ?
  • Quelles étapes de validation ont pris plus de temps que prévu ?
  • À quel moment les workflows de restauration ont-ils ralenti ?
  • Les bonnes personnes ont-elles été impliquées au bon moment ?

Ces réponses peuvent révéler des lacunes qui ne sont pas toujours d’ordre technique. Recovery peut aboutir tout en mettant en évidence des problèmes liés à la prise de décision, à la communication, aux validations ou aux relais entre les équipes.

Ces conclusions doivent être directement intégrées à la prochaine version du plan de Recovery. Si une application critique dépendait d’un système non documenté, mettez à jour la cartographie des dépendances. Si les contrôles d’accès ont ralenti la restauration, clarifiez le processus de validation. Si les tests de Recovery ont omis une charge de travail clé, ajoutez-la au prochain exercice. Si les dirigeants n’avaient pas une visibilité suffisante sur ce qui avait été restauré et ce qui était encore hors ligne, améliorez les rapports et les procédures d’escalade.

La réalisation régulière de tests est ce qui assure la cohérence de ce travail. Les exercices sur table, les restaurations isolées, les tests de Recovery en conditions réelles et la validation de la Recovery inter-cloud aident les équipes à identifier les problèmes avant qu’un incident réel ne les oblige à apprendre sous pression. Ils permettent également de fournir aux dirigeants des indications plus précises sur les domaines dans lesquels l’organisation est prête et ceux où elle a encore du travail à accomplir.

À terme, l’objectif est de disposer d’un programme de Recovery qui gagne en efficacité après chaque test et chaque incident. Les équipes sont mieux préparées, les étapes de Recovery sont mieux comprises et l’organisation dispose d’une feuille de route plus claire pour maintenir les opérations essentielles en fonctionnement en cas de perturbation.


Faire de la Recovery dans le cloud un levier de résilience de l’entreprise

 Cloud backup and recovery now plays a larger role than traditional data protection alone. It is the connected process of detecting recovery risk, protecting backup data, validating clean restore options, and restoring critical services when production environments can no longer be trusted.

En cas de cyberincident, ces activités ne peuvent pas être traitées comme des étapes distinctes. Le contexte de la menace doit déterminer quelles sauvegardes doivent être examinées. La protection des sauvegardes doit préserver les options de restauration dont les équipes pourraient avoir besoin. La validation doit déterminer ce qui est prêt à être restauré. La restauration doit rétablir les services dont dépend l’entreprise selon un ordre contrôlé.

Une sauvegarde qui ne peut être considérée comme fiable, testée ou restaurée au bon moment risque de ne pas apporter à l’entreprise le résultat dont elle a besoin. Un processus de restauration qui ne tient pas compte des identités, des dépendances entre applications ou des priorités métier peut aboutir à des systèmes techniquement restaurés, mais incomplets sur le plan opérationnel.

La véritable opportunité consiste à considérer la reprise comme une pratique de résilience continue. Cela implique de tester les plans avant un incident, de mettre à jour les cartes de dépendances à mesure que les environnements évoluent, et de tirer parti de chaque exercice ou événement de Recovery pour améliorer la réponse suivante.

Les organisations qui se remettent plus rapidement ne sont pas nécessairement celles qui disposent du plus grand nombre de copies de données. Il est impératif de savoir quelles données sont exploitables, quels services sont les plus importants et comment les restaurer en situation de crise.

Le défi consiste à rendre la Readiness pour la reprise aussi opérationnelle que la détection et la réponse. Backup and Recovery dans le cloud constituent une base pratique pour ce travail lorsqu’elles sont considérées comme un processus continu, de la détection des risques à la restauration des activités.

Les organisations doivent renforcer cette capacité afin d’être mieux à même de restaurer des données intactes, de rétablir les services critiques et de maintenir l’activité en cas de perturbation.

 

Accélérer la Recovery sans perte de données après une cyberattaque

Learn more about how Commvault’s data backup and recovery solutions can help organizations detect threats, recover clean data, and reduce downtime.

Questions fréquemment posées:

Quelle est la différence entre la sauvegarde dans le cloud et la reprise après sinistre ?

La sauvegarde dans le cloud vise principalement à créer des copies sécurisées des données en vue de leur restauration, tandis que la reprise après sinistre vise à restaurer les applications, les systèmes et les opérations métier après une panne ou une cyberattaque. Ensemble, ces deux processus contribuent à assurer la continuité d’activité et la résilience de l’entreprise.

Pourquoi les sauvegardes immuables sont-elles importantes pour la cyber-résilience ?

Les sauvegardes immuables et indélébiles sont conçues pour empêcher que les données sauvegardées ne soient modifiées, chiffrées ou supprimées dans le cadre des paramètres de conservation définis. Associées à Commvault AirGap et à l’identification automatisée des points propres (Cleanpoint), les fonctionnalités de sauvegarde immuable de Commvault permettent aux entreprises de disposer d’une source de restauration vérifiée et intacte en cas de compromission des systèmes de production.

Que dois-je rechercher dans une solution de Backup and Recovery dans le cloud ?

Recherchez une plateforme qui unifie les environnements hybrides et multicloud, le stockage immuable, l’orchestration automatisée de la Recovery et la gestion centralisée. Commvault Cloud est conçu pour répondre à ces exigences, aidant ainsi les entreprises à protéger leurs infrastructures diversifiées tout en réduisant au minimum les temps d’arrêt liés à la Recovery et la complexité opérationnelle.

La solution de sauvegarde de Commvault offre-t-elle une protection contre les ransomwares et des sauvegardes en mode « air-gap » ?

Oui. Commvault aide les entreprises à renforcer leur cyber-résilience grâce à des sauvegardes immuables, des options de restauration en environnement isolé, la détection des menaces, des capacités de restauration « propre » et une protection multicouche contre les ransomwares, conçues pour réduire les risques liés à la restauration et les temps d’arrêt.

Commvault propose-t-il des tests de sauvegarde automatisés et des rapports de conformité ?

Oui. Commvault propose des tests de restauration automatisés, la validation des sauvegardes, des rapports de conformité et une visibilité adaptée aux audits afin d’aider les entreprises à vérifier la restaurabilité de leurs données, à démontrer leur conformité et à améliorer leur Readiness en matière de restauration.

Ressources connexes

Vidéo

Récupération après une cyberattaque : Comment parvenir à une viabilité minimale en quelques minutes et non en quelques jours ?

Lorsqu’une cyberattaque se produit, chaque minute coûte 14 000 dollars et la Recovery complète prend en moyenne 24 jours. Mais que se passerait-il si vous pouviez atteindre un niveau de viabilité minimale en quelques minutes plutôt qu’en plusieurs jours ?
Regardez la vidéo surabout Récupération après une cyberattaque : Comment parvenir à une viabilité minimale en quelques minutes et non en quelques jours ?
Solution

Commvault AirGap

Une cyberprotection renforcée grâce à un stockage immuable sur cloud .
Découvrez la solution à propos de «Commvault AirGap

Points clés à retenir 

  • L’adoption de l’IA s’accélère, ce qui contribue à rendre les employés plus efficaces, plus productifs et plus compétitifs. 
  • Les organisations ont besoin de mécanismes de gouvernance et de cadres de référence pour adopter l’IA de manière responsable et à grande échelle. 
  • Security and productivity don’t have to compete – they can reinforce one another.  
  • AI will become one of security’s most valuable tools for managing cyber risks.  
  • L’adoption de l’IA donne les meilleurs résultats lorsque l’innovation et la sécurité vont de pair. 

One of the things I’ve enjoyed about the Prêt. Ou pas.de cette série réside dans le fait que chaque conversation s’appuie sur la précédente. Nous avons commencé par explorer les opportunités et les risques liés à l’IA agentique. Nous avons ensuite examiné comment les organisations peuvent instaurer la confiance à mesure que l’IA s’intègre dans le quotidien de l’entreprise. Cet épisode aborde la question logique qui en découle : comment utiliser concrètement l’IA en toute sécurité ? 

Comedian Nathan Macintosh sits down with Rinki Sethi, CISO and CSO at Upwind Security, for a conversation about what responsible AI adoption actually looks like. They cover everything from AI governance and guardrails to user experience and the growing role AI will play in cybersecurity.  

Nathan continues to ask the questions many of us are wondering. Should we be worried? How much more productive do we need to be? And can AI actually make security better?  

Regardez l’épisode completsur Readiverse. 

What I appreciated most about this conversation is that Rinki is genuinely excited about new technology and protecting it. She didn’t frame AI as something organizations need to worry about. Instead, she focused on encouraging businesses to move forward with confidence by putting the right guardrails in place. Here are the ideas that stayed with me. 

La dynamique en faveur de l’adoption de l’IA 

One thing that becomes clear from the conversation is that many organizations aren’t only encouraging their employees to adopt AI – they’re mandating it. These companies recognize that using AI helps people solve problems more efficiently, which is essential for staying competitive. 

“Every single company has a mandate … we’ve got to use AI everywhere in the company.”

– Rinki Sethi 

La question n’est plus de savoir si l’IA a sa place dans le monde du travail, mais si les employés disposent des garde-fous nécessaires pour l’utiliser de manière responsable. À mesure que l’adoption de l’IA s’accélère, les entreprises doivent établir des normes claires concernant les outils d’IA que les employés sont autorisés à utiliser et la manière dont les données de l’entreprise sont protégées. 

Aperçu : la gouvernance de l’IA

Rinki explains that governance isn’t just about protecting against new risks. It’s about creating a framework that helps employees use AI responsibly while keeping pace with evolving regulations and industry standards. 

L’avantage insoupçonné de la productivité 

Here’s something I never thought about before. Rinki explains that AI isn’t simply helping people work faster. In many cases, it’s leaving room for the highest-performing employees to excel.  

She used software developers as an example. When AI-powered coding assistants became available, many assumed they’d only help less experienced developers. Instead, some of the best engineers began using them to move faster. They were able to solve more complex problems and spend more time on creative work rather than repetitive tasks. 

That kind of productivity is exactly why organizations are mandating AI. It doesn’t limit what people can do – it helps give them more space to focus on higher-value work. 

“You can be way more creative with how you’re doing things … cause you’re creating the space for that.”

– Rinki Sethi 

AI’s Role in Cybersecurity 

“How can AI be used to help with security and not be just looked at as a demon thing that’s here to take us out?”

– Nathan Macintosh 

When we talk about AI and security, the conversation is often focused on risk. But Rinki believes that AI will become one of cybersecurity’s greatest advantages. 

Security teams are already overwhelmed by the volume of alerts, logs, and data they need to investigate every day. Human analysts simply can’t keep up. Rather than replacing security professionals, AI assists them by filtering through massive amounts of data in seconds. This helps analysts identify false positives so they can focus on investigating real threats. 

My takeaway is that the future of cybersecurity isn’t about people versus AI – it’s about people working alongside AI to help make better decisions, respond faster, and scale their operations in ways that weren’t possible before. 

Ready for What’s Next? 

Chaque épisode dePrêt. Ou pas. has reminded me that the biggest AI conversations are often about people – how we adapt, how we learn, and how we build the confidence to use new technology responsibly. The real opportunity for organizations isn’t just adopting AI. It’s creating an environment where employees can use AI to work smarter, become more creative, and deliver better outcomes for the business. 

Regardez l’épisode completsur Readiverse. 

FAQ 

Q : Pourquoi les entreprises adoptent-elles l’IA aussi rapidement ? 
R :De nombreuses entreprises considèrent l’IA comme un moyen d’améliorer la productivité, d’accroître l’efficacité et de permettre aux employés de consacrer davantage de temps à des tâches à plus forte valeur ajoutée. 
Q : Qu’est-ce que la gouvernance de l’IA ? 
R :La gouvernance de l’IA désigne l’ensemble des politiques, des processus et des mécanismes de contrôle qui aident les organisations à adopter l’IA de manière responsable tout en gérant les risques liés à la sécurité, à la protection de la vie privée et à la conformité. 
Q : Pourquoi l’expérience utilisateur est-elle importante pour la sécurité ? 
R :Les mesures de sécurité qui créent des obstacles inutiles incitent souvent les utilisateurs à trouver des solutions de contournement. Concevoir des systèmes à la fois sécurisés et faciles à utiliser permet d’améliorer à la fois leur adoption et leur protection. 
Q : L’IA peut-elle contribuer à améliorer la cybersécurité ? 
R :L’IA peut aider les équipes de sécurité à analyser de grandes quantités de données, ce qui permet de réduire les faux positifs. Cela permet ensuite aux équipes de hiérarchiser les menaces et de réagir plus efficacement aux incidents de sécurité. 
Q : Faut-il avoir peur de l’IA ? 
R : Rinki’s perspective is that a healthy sense of skepticism is valuable, but fear shouldn’t prevent organizations from adopting technology responsibly. Education, governance, and strong security practices can help organizations use AI with confidence. 
Q: What’s the biggest takeaway from this episode? 
R : AI adoption isn’t about choosing between innovation and security. Organizations that combine strong governance with practical security measures will be better positioned to take advantage of AI’s benefits while managing its risks. 

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Comment Mythos et GPT-5.5-Cyber pourraient transformer la sécurité des données dans le cloud

Des modèles d’IA spécialisés dans la cybersécurité pourraient accélérer la détection des vulnérabilités et la mise en œuvre de scénarios d’attaques en plusieurs étapes. Au-delà de la prévention, les équipes chargées de la sécurité des données dans le cloud ont besoin d’une meilleure visibilité, d’une gouvernance renforcée et d’une capacité de Recovery sans faille. 

Points clés à retenir

L’IA cyber de pointe réduit le délai entre la détection et l’intervention, démontrant ainsi pourquoi les entreprises ont besoin d’une sécurité des données dans le cloud axée sur la résilience, articulée autour d’une Recovery sans faille et des ResOps. 

  • Claude Mythos et GPT-5.5-Cyber restent des modèles à accès restreint, mais ils laissent entrevoir un avenir où l’IA sera capable de raisonner au sein de flux de travail cybernétiques complexes et d’accélérer aussi bien les opérations de défense que, potentiellement, celles des attaquants.
  • Alors que le délai entre la découverte d’une vulnérabilité et son exploitation ne cesse de se réduire, les entreprises doivent disposer d’une meilleure visibilité sur les dépendances liées au cloud, les risques liés à l’identité et les voies d’attaque interconnectées avant que des perturbations ne surviennent.
  • Recovery ne se limite plus à la restauration de sauvegardes. Les entreprises doivent définir leur « entreprise minimale viable », valider des points de reprise fiables et restaurer les systèmes critiques dans le bon ordre.
  • Les opérations de résilience permettent d’aligner les équipes chargées de la sécurité, de l’informatique et des activités commerciales autour d’objectifs de Recovery mesurables, aidant ainsi les organisations à gérer leurs données, à hiérarchiser la Recovery et à rétablir des opérations fiables avec davantage d’assurance.

 Claude Mythos et GPT-5.5-Cyber pourraient avoir une incidence sur la sécurité des données dans le cloud en accélérant la détection, le test et la gestion des risques. Leur impact reste encore incertain, mais ils mettent en évidence la nécessité de renforcer la visibilité des données, la gouvernance des accès et la Recovery sans faille dans tous les environnements cloud. 

Claude Mythos et GPT-5.5-Cyber offrent aux équipes de sécurité un aperçu précoce de ce que pourrait apporter une IA cybernétique plus spécialisée en matière de sécurité des données dans le cloud. 

Aucun de ces deux modèles n’est encore largement répandu, et leur impact à long terme reste incertain. Mais leur existence est importante, car les environnements cloud sont déjà difficiles à sécuriser. Les données sensibles, les systèmes d’identité, les applications SaaS, les pipelines de développement, les charges de travail liées à l’IA et les infrastructures de Recovery dépendent souvent les uns des autres d’une manière qui n’est perceptible que lorsqu’un problème survient. 

The UK AI Security Institute’s Évaluation d’avril 2026 of Claude Mythos Preview found significant improvement on multi-step cyber-attack simulations, including the ability to execute multi-stage attacks on vulnerable networks when explicitly directed in a controlled environment.  

Cette même évaluation soulignait toutefois que ses résultats diffèrent des conditions réelles et ne permettent pas de déterminer si Mythos serait capable d’attaquer des systèmes bien protégés. Elle montre néanmoins pourquoi les équipes chargées de la sécurité des données dans le cloud devraient prêter attention à cette évolution. 

As cyber AI capabilities mature, the question is not only whether attacks get faster. It’s whether the window between discovering a weakness and exploiting it continues to shrink. When that clock compresses, cloud data security is no longer just about preventing compromise. Instead, the question shifts to whether organizations can understand risk quickly enough, govern access consistently, and recover trusted operations before disruption spreads. 

Pourquoi Mythos et GPT-5.5-Cyber sont importants 

L’importance de Mythos et de GPT-5.5-Cyber ne réside pas dans le fait que toutes les organisations y auront soudainement accès. D’après les informations publiques actuellement disponibles, il s’agit de modèles contrôlés à accès restreint. Pour les équipes chargées de la sécurité des données dans le cloud, leur importance tient à ce qu’ils laissent entrevoir quant à l’orientation de l’IA cybernétique : des systèmes plus spécialisés, conçus pour prendre en charge des workflows de sécurité complexes. 

Cette distinction est importante. Un assistant IA polyvalent peut aider à résumer des alertes ou à rédiger un rapport d’incident. Un modèle d’IA cybernétique spécialisé est différent. Il peut être conçu pour analyser de manière cohérente les vulnérabilités, l’infrastructure, les voies d’attaque, les contrôles défensifs et les étapes de validation. Dans des environnements autorisés, cela pourrait aider les équipes de sécurité à tester les environnements, à hiérarchiser les expositions et à renforcer la planification de la Recovery avant qu’un incident ne se produise. 

Pour les équipes chargées de la sécurité des données dans le cloud, l’impact pratique tient moins aux noms des modèles qu’aux workflows qu’ils représentent. Les risques liés au cloud proviennent souvent des interconnexions entre les systèmes : une charge de travail mal configurée, un ensemble de données exposé, une identité aux autorisations trop larges, une dépendance à la sauvegarde ou un chemin de Recovery non testé. Une IA spécialisée en cybersécurité pourrait faciliter et accélérer l’évaluation de ces relations, en particulier dans les grands environnements où un examen manuel peut passer à côté de la manière dont un problème en affecte un autre. 

That shift mirrors a broader change happening across cybersecurity. The challenge is becoming less about identifying individual vulnerabilities and more about understanding how interconnected systems behave under pressure. AI may soon help defenders reason across identities, cloud workloads, backups, SaaS applications, AI pipelines, and business dependencies simultaneously — revealing not just isolated risks, but how those risks combine into operational failure. 

Cela modifie également la manière dont les organisations doivent envisager leurPréparation. Si l’IA peut aider les défenseurs à mener à bien des tâches cybernétiques complexes plus efficacement, des techniques similaires pourraient à terme influencer également les méthodes des attaquants. La préoccupation ne réside pas seulement dans le fait que les attaques deviennent plus rapides, mais aussi dans le fait que le délai entre la découverte d’une faille, son test et la mise en œuvre d’une réponse pourrait se réduire. 

Cloud data security teams now have to plan for a harder question: what happens when the same types of AI-assisted workflows that help defenders validate risk also make weak points easier to find, test, and chain together? That’s where the cloud environment itself becomes the issue. 

L’IA rend la sécurité des données dans le cloud encore plus cruciale 

Most organizations don’t have one neat cloud environment. They have multiple clouds, SaaS platforms, data lakes, identity systems, development pipelines, backup repositories, and AI workloads that all depend on each other.  

That complexity already creates gaps: sensitive data can be overexposed, access permissions can drift, and recovery plans may not reflect how the business actually runs.  

Dans la pratique, ces failles restent rarement isolées. Un compartiment de stockage contenant des données sensibles peut ne pas sembler urgent en soi. Un compte de service aux autorisations trop larges peut passer pour un simple problème de configuration. Une dépendance de Recovery non testée peut passer inaperçue tant que le système fonctionne encore. Mais lorsque ces problèmes s’enchaînent, ils peuvent ouvrir la voie à une exposition aux risques, voire à une perturbation. 

Attackers are well aware of these vulnerabilities. Mandiant’sLe rapport « 2026 M-Trends »de Mandiant souligne que les opérateurs de ransomware ciblent de plus en plus les infrastructures de sauvegarde, les services d’identité et les plans de gestion de la virtualisation. Il met également en évidence la manière dont les attaquants utilisent des jetons OAuth à longue durée de vie, des cookies de session, des clés codées en dur et des jetons d’accès personnels pour se déplacer d’un environnement à l’autre. 

Ajoutons à cela une IA cybernétique plus performante : si les modèles peuvent aider àdétecter plus rapidement les vulnérabilités, test exploitability more effectively, or connect weak signals across systems, defenders could benefit. However, attackers may eventually benefit, too—especially if similar capabilities become more accessible or are recreated elsewhere. 

22 seconds 
Median time between an initial access event and hand-off to a secondary threat group  

Source: Mandiant’s Le rapport « 2026 M-Trends » 

That’sC’est pourquoi le débat ne peut se limiter à l’affirmation selon laquelle « l’IA accélère les attaques ».can’t stop at “AI makes attacks faster.” Frontier dans le domaine de la cybersécuritémodifie le rythme de la sécurité. À mesure que le délai entre la découverte, la validation et l’exploitation se réduit, tout retard dans la compréhension des dépendances du cloud ou dans la préparation de Recovery devient plus coûteux. 

Comment l’IA cybernétique de nouvelle génération pourrait-elle transformer la défense du cloud ? 

While the full impact of Mythos and GPT-5.5-Cyber is still unknown, they point to three practical shifts cloud data security teams should be watching. Each one comes back to the same issue: cloud data security now depends on how quickly organizations can understand risk, act on it, and recover when something goes wrong. 

Les cyberdéfenseurs doivent prêter attention aux éléments suivants :

  • Rapidité :les outils assistés par IA peuvent aider les défenseurs autorisés à examiner le code, à trier les vulnérabilités, à analyser les logiciels malveillants, à valider les correctifs et à tester les contrôles plus rapidement que ne le permettent les workflows traditionnels. 
  • L’échelle :les risques liés au cloud se concentrent rarement en un seul endroit. Une vulnérabilité dans une application, une identité dotée de droits trop étendus, un compartiment de stockage mal configuré et un chemin de Recovery non testé peuvent former une seule et même chaîne d’attaque. 
  • Pression sur la reprise : If AI helps attackers move faster, organizations need to recover faster and cleaner. Backups alone aren’t enough if teams don’t know which data is clean, which identity systems can be trusted, or whether recovery will reintroduce compromised assets.

Pour les défenseurs, le changement le plus important réside peut-être dans l’enchaînement des tâches. Aujourd’hui, de nombreuses équipes passent de l’alerte à l’enquête, puis à la correction et enfin à la planification de Recovery, en étapes distinctes, souvent entre différentes équipes. L’IA appliquée à la cybersécurité pourrait condenser ce flux de travail en aidant les équipes à passer plus rapidement d’un signal à un ensemble d’actions recommandées. 

That doesn’t mean decisions should become automatic. It means teams may need clearer rules for when to trust a recommendation, when to escalate to a human reviewer, and when to move from investigation into recovery preparation. A model may help identify a possible attack path, but people still need to decide whether to close access, isolate a workload, preserve evidence, notify stakeholders, or prepare a clean recovery path. 

C’est là que le processus devient aussi important que les outils. L’IA cyber de nouvelle génération pourrait aider les défenseurs à agir plus rapidement, mais uniquement si les équipes disposent d’étapes de validation et de plans de Recovery clairs. Sans cette structure, la rapidité peut être source de confusion. Avec elle, les workflows assistés par l’IA pourraient aider les équipes à agir plus tôt tout en conservant le contrôle sur la manière dont le Risk est évalué et dont les décisions de Recovery sont prises. 

Pourquoi une Recovery propre revêt une importance accrue à mesure que les risques évoluent plus rapidement 

When cloud risk moves faster, recovery planning has to become more precise. It’s not enough to know that backup copies exist. Teams need confidence that the data they restore is trustworthy, the recovery environment is isolated, and the systems coming back online won’t reintroduce the same threat that caused the disruption. 

Cela est essentiel car les environnements cloud sontfortement interconnectés.Une identité compromise, un ensemble de données corrompu, une machine virtuelle affectée ou une charge de travail mal configurée peuvent créer de l’incertitude au sein de plusieurs services. Lors d’un incident, les équipes peuvent avoir besoin de déterminer quels points de reprise sont « propres », quelles dépendances doivent être rétablies en priorité, et si les données restaurées peuvent soutenir les opérations métier en toute sécurité. 

Une Recovery « propre » also changes the way teams think about priority. The goal isn’t necessarily restoring everything immediately. It’s restoring enough of the business to operate safely. 

Many organizations know which applications they consider “critical,” but far fewer have defined their minimum viable company: the smallest combination of identities, cloud services, data, applications, and infrastructure required to keep the business functioning during disruption. Those dependencies often become visible only when recovery is tested under realistic conditions. 

Dans un paysage de menaces dominé par l’IA, il est crucial de déterminer la « société minimale viable ». Une détection plus rapide des vulnérabilités et un développement plus efficace des chaînes d’attaque pourraient exercer une pression accrue sur les équipes de Recovery, les obligeant à prendre des décisions hautement fiables dans des délais très serrés. 

What’s more, identity systems, cloud configurations, business communications, customer-facing applications, and the data they depend on may all need to come back in a deliberate sequence — not simply according to technical priority, but according to what the business needs first to operate. 

Les organisations ont besoin de processus de Recovery capables de valider des données saines, de mettre en place la Recovery dans des environnements isolés, de protéger les dépendances d’identité critiques et de tester les plans de Recovery avant qu’un incident ne les y oblige. À mesure que les capacités de l’IA cybernétique gagnent en maturité, les équipes chargées de la sécurité des données dans le cloud devraient considérer la Recovery sans faille comme faisant partie intégrante de la stratégie de sécurité, et non comme une étape post-incident. 

Mettre en place une sécurité des données axée sur la résilience 

La sécurité des données dans le cloud s’est souvent concentrée sur la prévention des fuites : identifier les données sensibles, les classer, en contrôler l’accès et réduire les risques. Ce travail reste essentiel. En réalité, il prend encore plus d’importance à mesure que les systèmes d’IA exploitent les données d’entreprise via des invites, des systèmes de recherche, des pipelines d’entraînement, des workflows d’analyse et des outils automatisés d’aide à la décision. 

That’s because data may move into new contexts without moving into a new system of record. A sensitive dataset might support a retrieval workflow, shape a model response, or appear in a prompt log. That makes governance less about one location and more about how data is accessed, reused, and recovered across workflows. 

Mais la prévention à elle seule ne suffit pas pour la prochaine étape de la sécurité des données dans le cloud. Si l’IA spécialisée en cybersécurité peut aider les équipes de sécurité à détecter les vulnérabilités, à tester les voies d’attaque et à relier plus rapidement les signaux faibles, les programmes de sécurité des données doivent alors prendre en compte ce qui se passe une fois qu’une exposition a été détectée ou exploitée. La visibilité et les contrôles d’accès ne constituent qu’une partie du tableau. Les équipes ont également besoin d’une voie claire vers une Recovery fiable. 

Définir cette voie nécessite plus que de simples outils de sécurité plus performants. Cela nécessite un modèle opérationnel de Recovery qui aligne les responsables de la sécurité, de l’informatique et de l’entreprise autour de priorités de Recovery communes avant même qu’un incident ne se produise. De plus en plus, les organisations qualifient cette discipline de « ResOps », ou opérations de résilience : une approche structurée visant à rendre la Recovery mesurable, reproductible et liée aux résultats commerciaux plutôt qu’à la seule réussite de la sauvegarde. 

Dans le cadre des ResOps, les organisations doivent comprendre : 

  • Quels ensembles de données sont les plus critiques pour les opérations métier ? 
  • Quelles identités, quels services cloud et quels workflows d’IA dépendent des ensembles de données critiques pour l’activité ? 
  • Les politiques de gouvernance et d’accès sont-elles alignées sur les risques métier ? 
  • Quel est l’état opérationnel minimum viable que l’entreprise doit rétablir en priorité ? 
  • Ces décisions de Recovery peuvent-elles être validées avant un incident plutôt que pendant celui-ci ? 

That’s the shift Mythos and GPT-5.5-Cyber point toward. The future of cloud data security won’t be defined by prevention alone. As cyber AI compresses the time between discovery and action, organizations will need equal confidence in how they recover. That means understanding cloud dependencies before an incident, defining the minimum viable business they need to restore, and treating recovery as an operational discipline rather than a technical afterthought. 

Mythos and GPT-5.5-Cyber matter not because every organization will use these models tomorrow, but because they reveal where cybersecurity is heading. As AI accelerates both defense and attack, the organizations that perform best won’t simply be the ones with the strongest preventive controls. They’ll be the ones that can prove they know what to recover, in what order, and how to restore trusted operations before uncertainty becomes business disruption. 

Questions fréquemment posées:

Quand ces modèles spécialisés seront-ils rendus publics ?

Il n’y a pas encore de calendrier confirmé pour une mise à disposition au grand public. Selon les informations actuelles, Claude Mythos serait réservé à certaines organisations dans le cadre de programmes contrôlés, tandis qu’OpenAI précise que GPT-5.5-Cyber n’est accessible qu’aux acteurs de la cybersécurité agréés via son programme « Trusted Access for Cyber ».

Les attaques liées à l’IA risquent-elles de se multiplier ?

Pas nécessairement. Mais cela montre bien qu’une IA avancée peut prendre en charge des flux de travail cybernétiques plus complexes, ce qui signifie que les organisations doivent se préparer à des cycles de détection, de test et d’exploitation plus rapides.

Quels risques les équipes devraient-elles traiter en priorité ?

Commencez par obtenir une visibilité sur les données sensibles, les chemins d’accès, les erreurs de configuration dans le cloud, les dépendances d’identité et l’état de Readiness à la reprise après sinistre. Les fonctionnalités de sécurité des données et de l’IA de Commvault peuvent aider les équipes à classer les données, à gérer les accès et à identifier les risques dans tous les environnements cloud. 

Pourquoi la Recovery est-elle importante pour la sécurité des données dans le cloud ?

Car la prévention peut échouer. Les fonctionnalités de cyber-résilience de Commvault permettent aux entreprises d’identifier des points de Recovery sains, de valider la Recovery dans des environnements isolés et de restaurer les données et les services critiques sans réintroduire d’actifs compromis. 

Commvault propose-t-il une fonctionnalité de détection des menaces basée sur l’IA ?

Oui. Commvault peut s’appuyer sur des fonctionnalités basées sur l’intelligence artificielle pour aider à identifier les menaces, détecter les activités anormales, hiérarchiser les risques et accélérer la réponse aux incidents. En associant ces fonctionnalités à des processus de cyber-résilience et de Recovery, nous pouvons aider les équipes à améliorer leurs processus d’intervention et à restaurer leurs données critiques en toute confiance.


At Commvault, we talk a lot about cyber resilience, the ability to recover from whatever challenges come your way. But for one engineer at Australian technology services provider Perfekt, it is his personal resilience that helps him succeed.

Viktor Trokhin left Ukraine when the war began, traveling through five countries before eventually reuniting with his family in Australia. He brought more than six years of ICT experience, deep technical expertise, and a determination to continue his career in tech.

Like many skilled professionals starting over in a new country, Viktor wasn’t just adapting to a new workplace. He was building expertise in new technologies, communicating in a second language, and finding his place in a different professional environment.

Marcus Rolim, Managed Services General Manager at Perfekt and Viktor’s manager, saw his potential immediately.

“Our engineering development program is built around people,” Marcus says. “We invest heavily in mentoring and creating opportunities for engineers from different backgrounds.”

Over the years, Perfekt has welcomed engineers from around 10 different countries. Rather than following a standard training path, the company focuses on each person’s strengths, providing mentoring, practical experience, and support where it’s needed most.

For Viktor, that meant building on his existing expertise while gaining experience with Commvault Cloud and cyber resilience.

As he worked with customers, Arlie – the AI assistant in Commvault Cloud – became a natural part of his daily workflow. Whether he was exploring product capabilities, troubleshooting an issue, or looking for guidance, Arlie helped him quickly find trusted information without interrupting his work.

Then came an unexpected benefit.

Because Arlie supports multiple languages, Viktor could work through complex concepts in his native language before switching to English when speaking with customers or colleagues. While this wasn’t the use case Perfekt originally envisioned, it quickly became a valuable learning advantage.

“When an engineer can explore a complex question in their own language, understand the reasoning behind the answer, and then communicate it clearly in English, it changes the learning experience,” Marcus says. “It allows their technical ability to come through without language becoming a barrier.”

Today, Viktor is an Infrastructure & Data Protection Engineer at Perfekt, supporting customers while continuing to deepen his expertise in cyber resilience.

When Viktor left Ukraine, he carried with him years of experience, deep technical expertise, and an unwavering determination to continue the career he had worked so hard to build. Today, he helps organizations strengthen their cyber resilience, drawing on the same resilience that helped him rebuild his own life.

Maybe that’s why this story resonates. Viktor’s resilience shaped his own future. Today, it helps him make a difference for others.

That’s what putting people first looks like: organizations like Perfekt investing in people, and technology like Commvault Cloud helping them thrive.

Chris DiRadoest directeur de l’expérience produit chez Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Comment les responsables de la sécurité peuvent-ils protéger leurs données les plus sensibles ?

La sécurité des données et de l’IA permet aux entreprises d’identifier, de classer et de contrôler l’accès aux données sensibles pour l’ensemble des utilisateurs, des systèmes et des solutions d’IA.

Points clés à retenir

Les données sont le moteur des entreprises modernes : elles contribuent à orienter les décisions clés et à alimenter les initiatives en matière d’intelligence artificielle. Compte tenu de leur valeur, il est essentiel de bien les connaître et de les protéger.

  • 90 % des organisations ontdes données sensibles stockées dans le cloud, susceptibles d’être mises en évidence par l’IA. La visibilité sur les ressources de données constitue donc la première étape, et la plus cruciale, pour réduire les risques au sein de l’entreprise. 
  • 40 % des fichiers mis en ligneintégré aux outils d’IA générativecontientInformations d’identification personnelle (PII) ou données relatives au secteur des cartes de paiement (PCI). Une telle utilisation abusive de données sensibles expose les organisations à des risques importants en matière de violation de la vie privée et de non-respect de la réglementation. 
  • La découverte et la classification des données constituent le fondement d’une sécurité efficace, en permettant aux organisations d’identifier les données sensibles dans des environnements structurés, semi-structurés et non structurés.
  • Overpermissive access is one of the most persistent data risks for modern businesses. With users, applications, and service accounts often retaining unnecessary access to sensitive data, the “attack surface” is expanded.
  • Pour contribuer à la protection de l’IA, il est nécessaire de réguler à la fois les données d’entraînement et les interactions lors de l’exécution. Les organisations doivent s’assurer que les données sensibles ne sont pas exposées par le biais des entrées, des sorties ou du comportement des modèles.
  • La conformité réglementaire repose sur des bases de données solides. Une gouvernance rigoureuse en matière de classification et d’accès permet aux organisations d’appliquer leurs politiques et de démontrer qu’elles exercent un contrôle.

Sensitive data now moves across clouds, applications, and AI workflows without clear visibility — creating exposure risks that traditional security controls cannot address alone. Commvault Data and AI Security helps organizations discover and classify sensitive data, govern access for both human and machine identities, and maintain compliance with GDPR, HIPAA, and PCI DSS across the full data lifecycle.


Pourquoi la divulgation de données sensibles constitue-t-elle la principale faille de sécurité ?

Les données constituent le moteur indispensable qui fait avancer les entreprises modernes. C’est pourquoi celles-ci se sont fixé comme priorité d’investir massivement dans des outils de sécurité sophistiqués.

However, according to Varonis’ Rapport 2025 sur l’état de la sécurité des données, 90 % des entreprises ont encore des données sensibles exposées dans le cloud. De même, 88 % des entreprises comptent des « utilisateurs fantômes », c’est-à-dire des comptes inactifs mais toujours activés.

Maisthat’spas tous.According to IBM’s Rapport sur le coût des fuites de données 2025, 53 % des entreprises victimes d’une violation de données ont signalé que les données de leurs clients avaient été compromisesDonnées à caractère personnel. CesLes statistiques en donnent une image très claire : bien que les données soient au cœur de l’activité des entreprises, leur visibilité et leur sécurité globale restent des enjeux cruciaux. 

Les données ne se limitent plus aux bases de données structurées. Elles se trouvent dans des fichiers, des e-mails, des plateformes cloud, des applications SaaS et des terminaux. Une grande partie de ces données est non structurée, dupliquée ou non gérée, ce qui rend leur suivi et leur protection difficiles.

L’IA aggrave ce problème. À propos de40 % des fichiers téléchargés vers des outils d’IA générative contiennent des informations sensibles, souvent sans cadre de gouvernance ni de contrôle. À mesure que l’IA se généralise, le nombre de systèmes et d’identités interagissant avec les données augmente également.

Sans savoir quelles données existent et où elles se trouvent, les entreprises ne peuvent pas les sécuriser efficacement. Ce manque de visibilité est à l’origine du problème actuel de sécurité des données.


Quels sont les piliers de la sécurité des données et de l’IA ?

Pour relever le défi de l’exposition des données,les organisations ont besoin d’une approche structurée qui apporte cohérence et contrôle à la gestion des données. La sécurité des données et de l’IA repose sur trois piliers fondamentaux :la découverte des données,Classification des données,and Data & AI Access Governance.

Chaque pilier comble une lacune majeure :

  • Discovery provides visibility into where data resides across environments. This includes structured systems such as databases,as well as semi-structured and unstructured sources that are often overlooked.
  • Classification adds context by identifying the type and sensitivity of data. It enables organizations to distinguish between operational data,sensitive personal information,financial records,intellectual property,and other high-risk categories.
  • Access governance enables organizations to verify that data is used appropriately. It defines who or what can access data,under what conditions,and with what level of control.

These three pillars do not exist independently. They create a connected system that fully covers data and AI security. Discovery identifies the complete data landscape,classification defines the appropriate sensitivity,and access governance enforces control based on that context.

This model even extends beyond human users to include machine identities such as AI models. In modern environments,these non-human identities often represent a significant portion of data access activity. Bringing these pillars together can help organizations move from fragmented security controls to a unified,policy-driven approach.


Comment les organisations peuvent-elles identifier et classer les données sensibles ?

La détection et la classification sont les fondements d’un modèle de sécurité des données efficace. Pourtant, ce sont souvent les aspects les plus difficiles à mettre en œuvre de manière efficace.

Cela s’explique par la forte fragmentation des environnements de données modernes. Les informations sensibles sont dispersées entre de multiples plateformes cloud, des systèmes sur site, des applications SaaS et des terminaux. Une part importante de ces données est non structurée, ce qui rend leur identification et leur catégorisation plus difficiles.

Parmi les défis les plus notables, on peut citer :

  • Les données « fantômes » qui existent à l’insu des responsables, sans autorisation et sans contrôle de sécurité.
  • Des formats incohérents entre les données structurées et non structurées.
  • Une croissance rapide des données due à l’adoption de l’IA, qui dépasse les efforts de classification manuelle.

Pour y remédier, les organisations ont besoin de capacités de découverte évolutives et de cadres de classification. Une classification adéquate permet de donner un sens aux vastes quantités de données existantes. Cela inclut généralement des catégories telles que les informations personnelles identifiables (PII), les informations de santé protégées (PHI), les données PCI, la propriété intellectuelle, ainsi que les clés et les secrets.

La valeur de la classification réside dans son utilisation. Une fois les données classifiées, les entreprises peuvent appliquer efficacement des politiques de conservation et de suppression, restreindre ou surveiller les accès, et mettre en place le masquage ou l’expurgation des champs sensibles.

À grande échelle, une approche aboutie de découverte et de classification ne se contente pas d’assurer une couverture complète, mais contribue également à produire des résultats significatifs. Cela peut se traduire par une exposition réduite, une meilleure application des politiques et une réduction mesurable des risques.


Quels sont les principaux risques liés à des droits d’accès trop larges ?

Selon une étude deReliaQuest, 99 % des identités dans le cloud disposent de privilèges excessifs. Dans le même ordre d’idées, uneétude réalisée en 2025 par le Ponemon Institutesouligne que 61 % des entreprises américaines ont été victimes de fuites de données commises par des initiés au cours des deux dernières années, le coût moyen de ces incidents s’élevant à la somme astronomique de 2,7 millions de dollars.

Cela prouve que même lorsque les organisations maîtrisent leurs données, l’accès reste l’un des maillons faibles de la sécurité.

On parle d’accès trop permissif lorsque des utilisateurs, des applications ou des comptes de service disposent d’un accès aux données plus étendu que nécessaire. Ce problème est très répandu, car les contrôles d’accès sont souvent accordés de manière trop large pour des raisons de commodité et rarement réexaminés.

Les conséquences sont importantes. Des accès excessifs augmentent le risque de divulgation accidentelle, de menaces internes et d’exploitation en cas de violation.

Pour y remédier, les organisations doivent tout d’abord examiner minutieusement les schémas d’accès. Cela implique notamment de déterminer qui accède aux données sensibles, quels systèmes ou identités sont concernés, et si cet accès correspond aux besoins de l’entreprise.

Une attention particulière doit être accordée aux comptes privilégiés et aux identités de service. Ceux-ci disposent souvent d’autorisations étendues et peuvent accéder à de grands volumes de données sensibles sur l’ensemble des systèmes.

Dans ce contexte, une gouvernance efficace des accès est essentielle. Cela nécessite :

  • d’aligner les politiques d’accès sur la classification des données ;
  • De surveiller en permanence les habitudes d’utilisation.
  • D’identifier et de corriger les dérives d’accès au fil du temps.

En réduisant les accès inutiles, les organisations contribuent à limiter leur surface d’attaque et à améliorer la protection globale des données.


Comment les organisations doivent-elles gérer les données utilisées par les systèmes d’IA ?

L’adoption de l’IA se généralise rapidement dans tous les domaines de l’entreprise moderne. Cela ajoute un nouveau niveau de complexité à la manière dont les données sont consultées, traitées et divulguées.

Les ensembles de données d’apprentissage comprennent souvent de grands volumes de données provenant de l’ensemble de l’organisation. Sans classification ni gouvernance adéquates, ces ensembles de données peuvent contenir des informations sensibles ou soumises à une réglementation.

Cela engendre des risques à plusieurs étapes :

  • lors de la préparation des données et de l’entraînement ;
  • Lorsque les modèles interagissent avec des données en temps réel.
  • Au travers de résultats susceptibles de divulguer involontairement des informations sensibles.

La classification doit donc précéder l’entraînement des modèles. Cela implique de valider et de classer toutes les données utilisées dans les ensembles de données, et de supprimer les informations sensibles lorsque cela est nécessaire.

De même, après le déploiement des outils d’IA, les équipes chargées des données doivent évaluer en permanence la manière dont les modèles utilisent et exposent les données. Elles doivent également mettre en œuvre des mécanismes de contrôle appropriés, tels que le masquage ou la caviardage, lorsque cela s’avère nécessaire.

Les systèmes d’IA ne doivent pas être considérés comme distincts de la sécurité des données. Ils constituent une extension de la manière dont les données sont utilisées et doivent être gérés en conséquence. En intégrant ces capacités de sécurité des données et de l’IA dans le cycle de vie plus large du développement de l’IA, les organisations peuvent contribuer à réduire les risques tout en favorisant l’innovation.


En quoi la classification des données favorise-t-elle la conformité réglementaire ?

La conformité réglementaire repose sur la capacité à identifier et à contrôler les données sensibles. Des cadres réglementaires tels que le RGPD, la loi HIPAA et la norme PCI DSS définissent des exigences spécifiques concernant le traitement des données. Cependant, ces exigences ne peuvent être respectées sans avoir préalablement identifié où se trouvent les données soumises à réglementation.

C’est pourquoi les programmes de conformité échouent en l’absence d’une base de données adéquate.

Dans ce cas, la classification des données sert de pilier à la conformité, en associant les données à des catégories réglementaires. Elle permet aux organisations d’appliquer des contrôles ciblés en fonction de la sensibilité des données et de faire respecter les politiques essentielles relatives au cycle de vie des données.

Cela ouvre la voie à une multitude de fonctionnalités essentielles :

  • Application des politiques de conservation et de suppression
  • Restriction de l’accès aux données réglementées
  • Mise en œuvre de contrôles essentiels en matière de confidentialité

Cela simplifie également les processus d’audit. Les organisations peuvent démontrer où se trouvent les données sensibles, comment elles sont protégées et qui y a accès. La gouvernance des accès renforce encore davantage la conformité en garantissant que seules les identités autorisées puissent interagir avec les données réglementées.

Ensemble, la classification des données et les contrôles d’accès redéfinissent la conformité à l’ère moderne, marquée par l’intelligence artificielle.


Conclusion : Quelles sont aujourd’hui les conditions indispensables à une sécurité efficace des données et de l’IA ?

La sécurité moderne des données et de l’IA ne se limite plus à des défenses périmétriques ou à des contrôles isolés. Elle nécessite une approche continue et unifiée qui associe visibilité, classification et gouvernance des accès tout au long du cycle de vie des données.

Pour mettre en œuvre une telle approche, les entreprises doivent d’abord comprendre leurs données et identifier précisément où elles se trouvent. Elles doivent ensuite contrôler les modes d’accès à ces données. Enfin, elles doivent s’assurer que les systèmes d’IA les utilisent de manière responsable. Ces capacités doivent fonctionner de concert, et non de manière indépendante, afin de réduire les risques d’exposition et de préserver la confiance.

À mesure que les volumes de données augmentent et que l’adoption de l’IA s’accélère, le défi ne consistera pas seulement à sécuriser les données, mais à démontrer où se trouvent les données sensibles, qui peut y accéder et comment elles sont protégées sur l’ensemble des systèmes. Les entreprises qui mettront en place une approche structurée et fondée sur des politiques seront mieux à même de réduire les risques, de répondre aux exigences réglementaires et de favoriser l’innovation en toute confiance.

Questions fréquemment posées:

Qu’est-ce que la sécurité des données et de l’IA ?

La sécurité des données et de l’IA consiste à identifier, classer et réguler l’accès aux données sensibles à travers les systèmes, les utilisateurs et les modèles d’IA. La solution Commvault Data and AI Security offre ces fonctionnalités dans les environnements hybrides, permettant ainsi aux entreprises de s’assurer que les données restent visibles, contrôlées et protégées tout au long de leur cycle de vie, y compris lors de leur utilisation dans le cadre de l’entraînement des modèles d’IA et de la génération de résultats.

Pourquoi l’exposition des données sensibles constitue-t-elle un risque majeur ?

L’exposition des données sensibles constitue un risque majeur, car les entreprises manquent souvent de visibilité sur l’emplacement de leurs données et sur les personnes qui y ont accès, ce qui augmente le risque de fuites, d’utilisation abusive et d’infractions réglementaires. Commvault contribue à atténuer ce risque grâce à une approche unifiée qui combine la découverte des données, leur classification et la gouvernance des accès dans les environnements hybrides.

Quels sont les piliers essentiels de la sécurité des données ?

Les trois piliers fondamentaux de la sécurité des données sont la découverte, la classification et la gouvernance des accès. Commvault répond à chacun d’entre eux : la découverte des données permet d’identifier où se trouvent les données sensibles dans l’ensemble des environnements ; la classification des données définit leur niveau de sensibilité et leur type ; enfin, la gouvernance des accès aux données et à l’IA assure un contrôle d’accès conforme aux politiques métier et réglementaires.

Pourquoi un accès trop permissif est-il dangereux ?

Un accès trop permissif permet aux utilisateurs, aux applications et aux comptes de service d’accéder à davantage de données que nécessaire, ce qui accroît le risque de divulgation accidentelle, de menaces internes et d’exploitation. La solution « Commvault Data & AI Access Governance » résout ce problème en surveillant en permanence les modèles d’accès, en alignant les autorisations sur la classification des données, ainsi qu’en identifiant et en corrigeant les dérives d’accès dans les environnements hybrides.

Comment les entreprises doivent-elles contribuer à protéger les données utilisées par l’IA ?

Les entreprises peuvent protéger les données utilisées pour l’IA en classifiant les ensembles de données avant l’entraînement et en surveillant en permanence la manière dont les modèles accèdent aux données et les divulguent. La solution « Commvault Data and AI Security » facilite cette démarche grâce à des contrôles de découverte, de classification et de gouvernance, notamment le masquage, la caviardage et les restrictions d’accès, ce qui permet de garantir que les données sensibles ne soient pas divulguées lors de l’entraînement de l’IA, par le comportement des modèles ou par leurs résultats.

Comment la classification des données contribue-t-elle à la conformité ?

La classification des données facilite la mise en conformité en identifiant les données soumises à une réglementation, telles que les informations à caractère personnel (PII), et en les associant aux contrôles appropriés. La solution Commvault Data Classification aide les organisations à appliquer des politiques de conservation et de suppression conformes au RGPD, à la loi HIPAA et à la norme PCI DSS. Elle fournit également les preuves nécessaires, prêtes à être présentées en cas d’audit, pour démontrer comment les données sensibles sont identifiées, protégées et gérées.

Découvrez les ressources associées

Explorer

What are the Key Risks of Data & AI Security?

Explore how AI introduces new data vulnerabilities – from model training to exposure to runtime risks – and the layered practices organizations use to govern workloads responsibly.
Lire l’articleabout What are the Key Risks of Data & AI Security?
Livre blanc

Risk Analysis for IA Security Risks

Un rapport de Readiness destiné à votre RSSI et à votre DSI pour comprendre ce qui a changé avec MCP 2.0 et ce qu’il faut faire pour que votre organisation soit prête.
Lire le livre blanc surabout Risk Analysis for IA Security Risks


Points clés à retenir

  • Replace subjective claims about “ease of use” with a measurable data protection gearing ratio: protected capacity divided by the number of full-time administrators.
  • La mesure de la capacité protégée par ETP offre une vision plus pertinente de l’efficacité opérationnelle que les indicateurs traditionnels, tels que le nombre de tâches de sauvegarde par administrateur.
  • Le ratio de protection des données doit servir de référence avant la migration vers une nouvelle plateforme, puis être mesuré à nouveau après celle-ci afin de valider les améliorations opérationnelles.
  • Des facteurs tels que les environnements multicloud, les exigences en matière de reprise après sinistre informatique et les obligations de conformité peuvent influencer ce ratio ; il convient donc de l’évaluer dans le contexte propre à chaque environnement.
  • Les entreprises devraient demander aux fournisseurs de s’engager à atteindre des résultats opérationnels mesurables plutôt que de se fier à des affirmations qualitatives concernant la simplicité.

Every vendor evaluation I have sat in eventually reaches the same dead end. One side says the platform is simple to run. The other side says their platform is simpler.

Nobody can prove either claim, so the conversation drifts to the demo, the reference call, the gut feeling in the room. That is not how you should be making a decision that determines how your team will spend the next five years.

I have run production data protection environments. I have watched teams get buried under fragmented tooling that promised automation and delivered tickets instead.

“Reduced complexity” is not a feeling you should have to take on faith. It is something you should be able to calculate.

L’indicateur qui manquait au secteur

We have started using a simple ratio internally and with customers: total protected capacity divided by the number of full-time staff required to run it. We call it the data protection gearing ratio.

Protected Capacity (PB) / FTEs = Data Protection Gearing Ratio

That’s it. No survey questions about satisfaction. No adjectives. A number, calculated from data you already have.

Here is why it matters more than the metrics it replaces. Calculating the number of backup jobs per person made sense a decade ago, when a job represented a discrete unit of manual effort. It does not reflect how modern platforms operate today, where automation absorbs the routine work and a single administrator can be accountable for petabytes, not job counts.

Measuring jobs per person in an automated environment tells you nothing about whether the automation is actually working.

Concrètement

One clarification before the number, because it trips people up. Protected capacity means the full, uncompressed, undeduplicated size of the applications being protected, not the physical disk behind them.

That distinction matters because it is the whole point. Commvault’s own production environment protects 42,39 PB of application data on 9,26 PB of physical disk, an 81,91 % space savings from deduplication and compression.

The ratio is not just a measure of how many petabytes a person can watch over. It is a measure of how much architecture is doing the work before headcount ever enters the picture.

With that in mind: Commvault runs its own production backup environment on 42,39 PB of protected capacity with two FTEs. That is a gearing ratio of 21.20 PB per FTE. Industry benchmarks for modern platforms typically land between 5 and 25 PB per FTE, depending on environment complexity, so that number sits at the high end of what is achievable today.

Système métrique  Valeur  Définition 
Capacité protégée (front-end)  42,39 PB  Full, uncompressed, undeduplicated application size protected in our environment 
Capacité totale des disques  9,26 PB  Stockage physique cible 
Espace total utilisé  7,89 PB  Current utilization 
Volume total de données écrites  7,67 PB  Données logiques écrites sur le disque 
Économies d’espace  81,91 %  Efficacité de la déduplication et de la compression 
Effectifs équivalents temps plein (ETP) dédiés à la protection des données  2  Number of full-time admins managing Commvault’s own production backup estate 

Data Protection Gearing Ratio = 42,39 PB / 2 FTEs = 21.20 PB per FTE

I want to be direct about what this number does not do. It does not account for a multi-cloud footprint, cyber recovery requirements, or a compliance-heavy application mix, all of which will pull the ratio down for reasons that have nothing to do with how good the platform is.

A ratio in isolation is not a verdict. A ratio measured before and after a migration is.

That is the actual use case. Baseline your current environment on your current tools. Set a target ratio based on your growth projections and your team’s capacity. Then hold your vendor to it after the implementation is done, not just during the sales cycle.

Les implications au niveau du conseil d’administration

Si vous êtes chargé de valider la migration vers une nouvelle plateforme, on ne vous demande pas simplement de croire que cette nouvelle plateforme est plus facile à gérer. On vous demande de financer un résultat opérationnel spécifique. Un objectif de ratio de protection des données vous permet d’intégrer ce résultat dans l’analyse de rentabilité et de le vérifier 12 mois plus tard.

C’est la même rigueur que nous appliquons au temps moyen de récupération après nettoyage (MTCR). La capacité de récupération ne se revendique pas, elle se mesure et se remet à l’épreuve jusqu’à ce que les chiffres reflètent la réalité. L’efficacité opérationnelle mérite d’être évaluée selon les mêmes critères.

Le défi

Ask your current vendor for the gearing ratio of your own environment today. If they cannot produce it, that tells you something about how well they understand what “simple to manage” means for your team.

And if you are evaluating a new platform, do not accept “easier to use” as an answer. Ask what ratio they will commit to, and ask again after year one.

FAQ

Q: What is the data protection gearing ratio?

A: The data protection gearing ratio measures the amount of protected data capacity managed by each full-time administrator. It provides an objective way to evaluate operational efficiency rather than relying on subjective impressions of platform usability.

Q: Why is this metric more useful than backup jobs per administrator?

A: Modern data protection platforms automate much of the routine work that previously required manual effort. As a result, counting backup jobs no longer reflects the true workload or efficiency of an operations team.

Q: What does “protected capacity” mean in this calculation?

A: Protected capacity refers to the full, uncompressed, and undeduplicated size of the application data being protected. This measurement reflects the actual workload managed by the platform rather than the physical storage consumed after optimization.

Q: Does a higher gearing ratio always indicate a better platform?

A: Not necessarily. Environmental complexity, including multi-cloud deployments, cyber resilience requirements, and regulatory obligations, can reduce the ratio even when the platform performs well. The metric is most valuable when comparing the same environment before and after a migration.

Q: How should organizations use the data protection gearing ratio during vendor evaluations?

A: Organizations should establish a baseline using their current environment, define a target ratio aligned with future growth, and ask vendors to commit to achieving measurable improvements after implementation. This approach shifts the conversation from marketing claims to verifiable business outcomes.

Q: What is the broader business value of this metric?

A: The data protection gearing ratio enables executives to quantify expected operational efficiency gains and include them in the business case for a platform investment. It also provides a benchmark that can be reviewed after deployment to confirm the promised results were achieved.

Rajiv Kottomtharayilest directeur des produits chez Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Dans lefirst episode of our STRIVE series on digital sovereignty, Commvault’s Alex Zinin and Osmium Data Group’s Max Mortillaro challenged one of the biggest misconceptions in the industry: Digital sovereignty isn’t a feature you buy – it’s a business problem you have to understand before you can solve.

This conversation picks up where that one left off. This time, I sat down with Thomas Maurer, EMEA Global Black Belt for Sovereign Cloud at Microsoft, to explore what happens after an organization decides sovereignty matters. How do executive teams move from broad concerns about regulation, jurisdiction, or geopolitical uncertainty into practical architectural decisions?

The answer, it turns out, is rarely as straightforward as choosing a cloud provider or selecting the right deployment model. It’s about asking better questions before making technical decisions.

Watch the full episode.

Points clés à retenir

  • Every organization defines digital sovereignty differently – and that’s exactly where the conversation should begin.
  • Sovereignty isn’t solved by technology alone. Legal, operational, architectural, and business considerations all shape the outcome.
  • Cloud and on-premises aren’t competing strategies. For many organizations, the future is a carefully designed combination of both.
  • Risk management – not fear – should drive sovereignty decisions.
  • Good architecture starts with understanding business requirements, not choosing infrastructure.

Sovereignty Means Different Things to Different Organizations

One of the first observations Thomas made was also one of the most important.

There is no universal definition for digital sovereignty. For one organization, it may simply mean meeting regulatory requirements or keeping data within a specific geography. For another, it may involve operational independence, business continuity, or preparing for geopolitical disruption. That difference matters because it changes the conversation entirely.

Too often, organizations assume there’s a standard sovereignty blueprint waiting to be implemented. In reality, the first challenge isn’t selecting technology – it’s understanding what problem the organization is actually trying to solve.

Only then does architecture begin to make sense.

Technology Should Follow Strategy

One theme that kept surfacing throughout our discussion was the temptation to jump straight into technical design.

It’s understandable. Architects naturally think about infrastructure, workloads, connectivity, and deployment models. But Thomas emphasized that the most successful projects begin somewhere else.

They begin by listening.

What concerns are driving the initiative? Is the objective regulatory compliance? Business continuity? Data residency? Operational control? Protection against geopolitical disruption?

Different answers lead to different architectures.

That may sound obvious, but it’s surprising how often organizations begin evaluating solutions before they’ve aligned on the business outcome they’re trying to achieve.

Sneak Peek: Start With Risk, Not Assumptions

One of the most practical moments in our conversation comes when Thomas and I discuss why sovereignty initiatives should begin with a risk assessment – not an architectural diagram.

Every organization has a different risk appetite. A Formula 1 team, a government agency, and a global manufacturer won’t make the same decisions, nor should they. The key is understanding which risks matter most to your business, what trade-offs you’re willing to make, and then designing an architecture that supports those decisions.

As Thomas points out, there is no perfect solution – only informed trade-offs. The earlier organizations adopt that mindset, the stronger their sovereignty strategy will be.

‘Cloud or On-Premises?’ Is the Wrong Question to Ask

One of the more interesting parts of the conversation challenged another common assumption – that organizations must choose between public cloud and private infrastructure.

Thomas described a very different reality.

Many organizations aren’t replacing one with the other. They’re designing environments where workloads can move between them based on business need, regulatory requirements, or resilience considerations.

That flexibility changes how we should think about architecture. Instead of asking whether cloud or on-premises is better, the more useful question becomes:

“Where does this workload belong today – and could that answer change tomorrow?”

When sovereignty becomes part of the design process, workload mobility becomes just as important as workload placement.

Architecture Is Only Part of the Equation

Another takeaway I appreciate is Thomas’s reminder that architecture alone doesn’t solve sovereignty.

  • Contracts matter.
  • Legal frameworks matter.
  • Operational processes matter.
  • The people responsible for running the environment matter.

None of those disciplines can operate in isolation. Sovereignty requires legal, security, compliance, and infrastructure teams to work together from the beginning – not hand projects off to one another after decisions have already been made.

That’s a familiar pattern for anyone working in cyber resilience. The strongest outcomes rarely come from individual teams. They come from coordinated ones.

Risk Should Drive Every Decision

Toward the end of our discussion, the conversation naturally shifted toward risk. For me, this is where sovereignty starts to feel much more familiar. Every resilience project begins by asking what the organization is trying to protect, what threats matter most, and how much risk it’s willing to accept.

Digital sovereignty is no different.

Rather than searching for a perfect solution, organizations need to identify the specific sovereignty scenarios they’re concerned about and then determine which architectural, operational, or contractual controls best address those risks.

That shift – from feature comparison to risk management – is what ultimately leads to better decisions.

Pourquoi cette discussion est importante

Digital sovereignty continues to evolve rapidly. New regulations will emerge. Technology will change. Geopolitical realities will continue to shift.

That means sovereignty isn’t something organizations solve once. It’s something they regularly evaluate as business priorities and external risks evolve.

The organizations that succeed won’t necessarily have the most restrictive architectures. They’ll have the clearest understanding of their business objectives, the discipline to assess risk thoughtfully, and the flexibility to adapt as those risks change.

Ultimately, digital sovereignty isn’t something organizations can buy off a shelf. It’s an exercise in understanding risk, managing dependencies, and making informed trade-offs long before those decisions are tested.

Regardez l’épisode dans son intégralité

In this STRIVE episode, Thomas and I discuss:

  • Why sovereignty means different things to different organizations.
  • How executives should approach sovereignty strategy.
  • Public cloud versus private cloud – and why it’s often not an either/or decision.
  • Why risk management should guide architectural choices.
  • The role of resilience in modern sovereignty planning.

Regardez-le dès maintenant.

FAQ

Q: Does digital sovereignty mean keeping everything on-premises?

A: No. Many organizations adopt hybrid approaches that balance cloud capabilities with specific sovereignty requirements.

Q: Where should sovereignty projects begin?

A: Start by defining the business problem and understanding the risks you’re trying to mitigate before evaluating technology.

Q: Is sovereignty purely a technical issue?

A: No. It requires collaboration between legal, compliance, security, operations, and architecture teams.

Q: How does sovereignty relate to resilience?

A: Both disciplines focus on maintaining operational continuity by reducing exposure to risks that could disrupt the business.

Q: What’s one big mistake organizations make in regard to digital sovereignty?

A: Jumping into architectural decisions before agreeing on what sovereignty means for their organization.

Q: What should executives ask first in terms of planning for digital sovereignty?

A: “What problem are we trying to solve?” Everything else follows from that answer.

Darren Thomsonis Vice President and Chief Technology Officer, EMEA, at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Points clés à retenir

  • Terraform manages desired state – it provisions and configures infrastructure from code.
  • Cloud Rewind captures actual deployed state – it helps restore environments to a known-good point in time.
  • Les fichiers d’état Terraform et l’historique Git ne sont pas des outils de restauration ; ils ne reflètent pas ce qui était réellement en cours d’exécution.
  • Cloud Rewind permet de restaurer l’infrastructure, que les modifications aient été effectuées via l’IaC, la console ou une intervention manuelle.
  • Ensemble, Terraform et Cloud Rewind permettent aux équipes de mettre en place une stratégie complète d’cloud -opérations : développer rapidement, se remettre encore plus vite.

If your team runs Terraform, you already know how powerful IaC can be. You define what you want, apply it, and your cloud environment materializes. Change management becomes repeatable. Provisioning becomes predictable.

But there is a gap between provisioning infrastructure and recovering it – and it matters most when something goes wrong at 2 a.m.

Terraform and Cloud Rewind address different parts of the cloud lifecycle. Understanding the difference helps you avoid a dangerous assumption: that your IaC tooling doubles as a recovery plan.

En quoi Terraform et Cloud Rewind diffèrent-ils ?

Terraform is a provisioning tool. It defines and manages desired state. When you revert a Terraform change, you are re-applying a previous desired configuration – not restoring the actual deployed environment that was running before the incident.

That distinction matters. Terraform state is not a historical recovery snapshot.

Cloud Rewind captures actual cloud configuration state and stores point-in-time snapshots. When something breaks, you do not rebuild from code and hope the environment comes back intact. You restore a known-good environment – the one that was actually running – regardless of how the change that caused the problem was introduced.

Terraform Design  Cloud Rewind Design 
Gestion de l’état souhaité  Restauration de l’état réel 
Provisionnement de l’infrastructure  Recovery de l’infrastructure 
Application des modifications  Annulation des modifications 
Source de vérité = code  Source de vérité = environnement déployé 
Orienté vers l’avenir  Rétrospective 
Créer et mettre à jour  Récupérer et reconstruire 
Permet de restaurer la configuration souhaitée  Permet de rétablir l’état de déploiement à partir d’un instant donné 

Les limites de Terraform

Même les environnements IaC les plus aboutis sont confrontés à des situations de reprise où la reconstruction à partir du code ne suffit pas. Prenons l’exemple suivant :

  • Une modification de l’infrastructure qui a échoué et qui a déjà été déployée en production.
  • Suppression accidentelle de ressources d’cloud .
  • Dérive de l’infrastructure due à des modifications manuelles ou hors bande.
  • Modifications apportées en dehors de Terraform et qui ne se reflètent ni dans le code ni dans l’état.
  • La nécessité de rétablir l’infrastructure exactement telle qu’elle était à un moment précis.
Terraform does not maintain historical cloud state. It re-applies a desired configuration – it does not restore what was actually deployed and running. “Rewind to 2:15 PM yesterday” is not a Terraform feature. It is a Cloud Rewind feature.

Une restauration qui repose sur la disponibilité, l’exactitude et l’exhaustivité du code Terraform, des fichiers d’état et de l’historique des versions comporte un risque réel. En cas d’incident réel, ces conditions ne sont pas garanties.

Deux outils, une stratégie complète

Terraform helps you automate infrastructure creation and change management. Cloud Rewind helps you recover infrastructure quickly and consistently when deployments fail, resources are deleted, infrastructure drifts, or your team needs to restore a known-good environment.

They complement each other. Terraform is designed to make your cloud environment repeatable. Cloud Rewind is designed to make it recoverable.

Build with Terraform.Récupérez vos données avec Cloud Rewind.

FAQ

Q: Does Terraform provide point-in-time recovery?

A: No. Terraform re-applies a desired configuration from code. It does not maintain historical snapshots of your deployed cloud environment. If the change that caused an incident is not captured in your Terraform state or Git history – for example, a console change or infrastructure drift – Terraform cannot help you restore it.

Q: What happens when changes are made outside Terraform?

A: Console changes, manual interventions, and out-of-band configurations are common in real environments. Terraform does not track them. Cloud Rewind captures actual deployed state – regardless of how a change was introduced – so you can restore a known-good environment even when your IaC does not reflect what was running.

Q: Is Cloud Rewind a replacement for Terraform?

A: No. They solve different problems. Terraform is your provisioning and change management tool. Cloud Rewind is your recovery tool. Most teams that use one can benefit from both – they cover different parts of the cloud operations lifecycle.

Q: What kinds of incidents does Cloud Rewind address?

A: Cloud Rewind is designed for scenarios where rebuilding from code is not enough: failed deployments already in production, accidental resource deletion, infrastructure drift, and cases where teams need to restore an environment to a specific historical point in time.

Q: Does Cloud Rewind require teams to stop using Terraform?

A: No. Cloud Rewind works alongside your existing IaC workflows. Teams continue to use Terraform for provisioning and change management and use Cloud Rewind when they need to recover from a real incident.

Cailin Pitcheroccupe le poste de responsable senior du marketing de portefeuille chez Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Points clés à retenir 
  • Commvault integrates frontier AI vulnerability discovery into its risk-based security program rather than relying on AI as a standalone solution.
  • Every AI-generated finding is reviewed and validated by humans before remediation decisions are made.
  • Frontier AI complements established security practices such as static analysis, dynamic analysis, and penetration testing by expanding code coverage and identifying more complex exploit scenarios.
  • Commvault maintains strict governance over source code, vendor access, and vulnerability handling.
  • Commvault is investing in scalable vulnerability management processes in order to respond efficiently as AI increases the volume of potential security findings.

Across the security industry, AI and large language models are being applied to vulnerability discovery – helping teams evaluate more code, explore more attack paths, and identify exploitable conditions faster than manual review alone.  

This is not a niche experiment. It is a shift in how thorough a security evaluation can be, and it is changing what customers reasonably expect from their software vendors. 

Customers are regularly asking their software vendors: Do you test your own products against the same methods a threat actor might use? Are the processes behind that testing rigorous enough to keep pace? These are the right questions to ask. 

Our Approach: Strong Processes, no Single Tool

Commvault’s security posture is built on strong, repeatable processes rather than dependence on any single tool, model, or vendor.  

Vulnerability management follows an established, risk-based framework: Findings are assessed for practical exploitability, prioritized by severity and exposure, and remediated through our standard development lifecycle. That framework applies the same way regardless of whether a finding comes from a penetration test, an external researcher, or AI. 

AI vulnerability discovery is integrated into this framework as an additional capability, not a separate program running on its own rules. Candidate findings generated through AI methods are treated as inputs that require human confirmation of exploitability before any remediation action is taken. That step helps prevent two failure modes at once: under-prioritizing genuine risk and burning cycles on false positives. 

AI Alongside Established Security Practices

AI methods do not replace the disciplines that have always defined responsible vulnerability management. Static analysis, dynamic analysis, penetration testing, and established scanning tools remain essential parts of our program.  

What AI adds is coverage depth: the ability to evaluate a broader set of code paths, model more complex exploit conditions, and surface findings that require contextual understanding rather than simple pattern matching. 

Our vulnerability program is tool-agnostic and model-agnostic by design. We are not dependent on any single vendor or model, and new approaches can be added as they prove out, without re-architecting how findings are governed or remediated. The advantage isn’t which model we use but whether the process behind it is disciplined enough to act on what that model finds. 

Governance and Controls

Every AI scan we run operates under the same governance principles: 

  • AI models are vetted before used. Any vendor and tooling access is governed by formal NDA and engagement terms.
  • Findings are processed through the same security engineering review pipeline used for every other vulnerability source.
  • No AI-generated finding is acted upon without human triage and exploitability confirmation.
From Candidate Finding to Confirmed Fix

Findings generated through AI are treated as candidates, not confirmed vulnerabilities. Each one is assessed by engineers and product security experts for practical exploitability in realistic customer environments.  

Severity ratings are assigned based on exposure, exploitability, and impact – not on how the finding was discovered. Confirmed vulnerabilities move through the same remediation timelines and escalation paths as any other source, with priority set by severity and exposure. 

First Patch Tuesday Disclosures – August 2026

Our inaugural Patch Tuesday, published August 11, 2026, includes the following disclosures: 

CVE ID  Severity  Résumé 
CVE-2026-13737  Critique  CommServe contained an allowlist bypass affecting command execution authorization.  
CVE-2026-13738  Critique  CommServe contained an authorization bypass affecting a limited set of command execution operations.  
CVE-2026-13739  Élevée  A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) related to the handling of arbitrary target URLs. 

 

Full technical advisories, including affected versions and remediation guidance, are available on our Chaque deuxième mardi du mois, vous trouverez de nouvelles informations concernant les CVE sur notre. Read more about the move to a monthly cadence in Bringing  Trust to CVE Disclosures.  

Why Operational Readiness Matters More Than Any Single Tool

As AI vulnerability discovery becomes standard practice across the industry, the volume of potential findings that security teams need to evaluate will keep rising. The question that matters for any enterprise software vendor isn’t which AI model they use. It’s whether their vulnerability management process is mature enough, and scalable enough, to handle that throughput without creating a backlog that increases customer exposure. 

We pair our investment in AI with an equal investment in the process infrastructure needed to act on what it finds: triage capacity, severity prioritization, remediation tracking, and coordinated disclosure practices. Our investment is only as valuable as the response capability behind it. 

FAQ

Q: What is Commvault doing with frontier AI security testing? 
A: We actively evaluate our products using AI methods as part of our structured security engineering program. We are being thoughtful about testing different models and harnesses so that we find any potential vulnerabilities previously undiscovered by humans and or existing testing. That work follows the same vulnerability management process as every other form of testing. This is underway today – it isn’t a roadmap item. 
Q: How is Commvault preparing for AI vulnerability discovery? 
A: We built a program that is model-agnostic and tool-agnostic by design. Our goal is to make sure our security engineering practice can incorporate the best available methods across a range of AI tooling, inside one consistent governance and risk management framework. 
Q: Is Commvault using these models safely? 
A: Yes. All AI scans are thoroughly vetted. Any vendor and tool access is governed by formal NDA and engagement terms, and every AI-generated finding requires human confirmation of exploitability before any remediation action is taken. 
Q: How is Commvault scaling vulnerability management for the AI era? 
A: Our focus is on making sure the response process scales with discovery volume and discovery pace. As AI increases the number of potential findings our teams need to review, we’re investing in risk-based triage, consistent remediation service level agreements, and the operational infrastructure needed to act on higher discovery throughput within accelerated timeframes to decrease exposure for customers. 

Bill O’Connell is Chief Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

When frontier AI models started making headlines, most of the discussion centered on one question: What happens when attackers gain access to them? 

It’s a fair question.  

Models capable of discovering vulnerabilities faster, chaining exploits together, and operating at unprecedented speed naturally raise concerns for every CISO.  

But after spending time talking with customers over the past several months – and in my conversation with Tim Zonca, Commvault’s VP of Portfolio Marketing, in this episode of STRIVE – I think there’s an even more important question emerging. 

What happens to resilience itself? 

Because while frontier AI will undoubtedly accelerate cyber threats, it’s also accelerating something else: Enterprise complexity. 

Watch the épisode. 

 Points clés à retenir 

  • Frontier AI isn’t just accelerating cyberattacks – it’s accelerating enterprise complexity.  
  • Vulnerability management isn’t disappearing, but the speed and scale of discovery are changing dramatically.  
  • AI systems introduce entirely new recovery dependencies, including agents, vector databases, embeddings, and distributed state.  
  • Organizations need a coherent understanding of their environments before they can recover them.  
  • The next generation of resilience will depend on trusted systems of record that explain what happened, why it happened, and how to recover confidently.  
The Conversation Has Changed 

One thing Tim and I discuss early in the episode is how differently organizations are reacting to frontier AI. 

  • Some see an entirely new class of cybersecurity challenge. 
  • Others view it as simply the next evolution of vulnerability management. 

What’s interesting is that neither perspective is necessarily wrong. 

The processes organizations use to identify, prioritize, and remediate vulnerabilities remain familiar. But the pace at which AI can discover those vulnerabilities – and uncover entirely new chains of attack – is unlike anything we’ve seen before.  

That’s the shift. 

The work isn’t fundamentally different. The speed is. 

When AI Changes the Shape of Recovery 

Most conversations about AI focus on security and prevention: 

  • How do we secure models? 
  • How do we protect prompts? 
  • How do we defend against AI-assisted attacks? 

Those are important questions. But resilience introduces a different one: What exactly are we recovering? 

Traditional enterprise applications already involve complicated relationships between infrastructure, applications, and data. AI expands that picture considerably. Now there are agents operating across multiple systems. Vector databases. Embeddings. Models interacting with different data sources simultaneously. It’s become far more than a traditional application stack.  

Recovery is no longer about restoring an application. It’s about restoring an ecosystem. 

Sneak Peek: Check This Out 

In this moment from our STRIVE discussion, Tim and I discuss the growing complexity of AI stacks, what coherent recovery is (and why it matters), and how Commvault is helping our customers with full AI-stack recovery. 

Why Coherency Matters 

One idea that keeps surfacing throughout our conversation is coherence. 

For years, organizations have worked to map application dependencies, understand infrastructure relationships, and identify critical services. AI makes that challenge significantly more difficult. 

Applications no longer interact with a single database or service. They may depend on multiple models, agents, data stores, and orchestration layers – all changing dynamically. 

Understanding those relationships isn’t just an architectural exercise anymore. 

It’s a recovery requirement. 

Because if you don’t understand what makes up the system, it’s difficult to know whether you’ve actually recovered it. 

A New System of Record 

Another concept from Tim that I found compelling is the idea of a system of record for the AI era. Historically, systems of record gave organizations confidence in business data. Customer records lived in CRM platforms. Financial records lived in ERP systems. 

AI changes that expectation. 

Organizations increasingly need trusted visibility into how data is used, what agents interact with it, why decisions are made, and whether restored environments represent a known-good state.  

That doesn’t replace resilience. It strengthens it. Because confidence in recovery depends on confidence in what you’re recovering. 

AI Can Also Help Solve the Problem 

As organizations struggle to understand increasingly distributed environments, AI becomes a powerful tool for discovery, classification, and policy recommendation.  

Rather than manually identifying relationships across sprawling environments, organizations can use AI to help identify dependencies, recommend protection policies, and continuously update those relationships as environments evolve. 

That’s an important shift. 

The same technology that’s adding to organizational complexity may also become one of the best tools for managing it. 

Pourquoi cette discussion est importante 

Frontier AI isn’t simply introducing another cybersecurity challenge. It’s forcing organizations to rethink resilience itself. 

Recovery is becoming less about individual systems and more about restoring trusted business operations across increasingly intelligent environments. That means resilience strategies must evolve alongside the technologies they’re protecting. 

Organizations that prepare for that shift won’t just recover faster. They’ll recover with greater confidence. 

Regardez l’épisode dans son intégralité 

In this conversation, Tim and I explore: 

  • How frontier AI is changing enterprise risk.  
  • Why vulnerability management is entering a new phase.  
  • What AI means for modern recovery architectures.  
  • The role of coherent recovery across AI-enabled environments.  
  • Why trusted systems of record will become increasingly important.  

Regardez-le dès maintenant. 


FAQ 

Q: What are frontier AI models? 
A: Frontier AI models are the latest generation of highly capable AI systems designed to solve increasingly complex reasoning and cybersecurity tasks. 
Q: Why are organizations concerned about them? 
A: They dramatically accelerate vulnerability discovery, exploit chaining, and security research, increasing both defensive and offensive capabilities. 
Q: How does AI change cyber resilience? 
A: AI introduces new dependencies – including agents, models, vector databases, and distributed states – that make recovery more complex. 
Q: What is a coherent recovery strategy? 
A: It’s an approach that restores not only data, but also the applications, infrastructure, dependencies, and AI components required for trusted business operations. 
Q: What is a system of record in the AI era? 
A: It’s a trusted source that helps organizations understand what happened, why it happened, and whether recovered systems represent a known-good state. 
Q: What should organizations do now? 
A: Begin mapping AI dependencies, understand how AI changes recovery requirements, and develop resilience strategies that account for increasingly intelligent application environments. 

Chris Mierzwa is Senior Director of Portfolio Marketing at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Protection unifiée des données | Recovery après une attaque par ransomware | Cleanroom Recovery | Charges de travail hybrides

Comment unifier la protection des données pour toutes les charges de travail hybrides

Commvault® Cloud helps organizations discover, govern, and unify workload protection, allowing teams to rebuild critical services quickly after a cyber incident.


You’re the VP of IT Operations. It’s 2:00 a.m. on a Saturday. Your SecOps team just confirmed ransomware has encrypted files across three regions. Your last backup job completed successfully – but when your team attempts to restore the ERP system, the application fails to start.

The backup was marked successful. The data was present. But the dependencies, transaction logs, and service relationships were never captured in a consistent, recoverable state. Recovery isn’t just about data – it’s about rebuilding services.

This scenario plays out across hybrid environments every day. Modern enterprises run on interconnected cloud-native services, Kubernetes clusters, hybrid databases, and SaaS platforms – none of which recover cleanly from a simple file restore. Fragmented protection strategies designed for a simpler era leave organizations exposed at exactly the moment resilience matters most.

Commvault Cloud is an AI-enabled platform designed to help organizations discover, govern, and unify data protection across cloud-native, hybrid, and on-premises workloads – from a single control plane. Capabilities such as AI-enabled workload discovery, Cleanroom Recovery, Cleanpoint Identification, Threat Scan, and Command Center orchestration help teams valider recovery readiness and rebuild critical services in a controlled sequence after a cyber incident. 

45 %

of organizations are repeat ransomware victims – meaning fast recovery without clean validation reinfects as often as it restores. 
ESG Research — Zero Trust and Ransomware Protection Report 

What Is Unified Data Protection – and Why Does It Matter? 

Unified data protection is a backup and recovery approach that helps organizations govern the broadest range of workloads – including cloud databases, Kubernetes, SaaS, hypervisors, and on-premises systems – from a single control plane, rather than managing separate tools and policies for each environment.Commvault Cloud Unityest conçu pour prendre en charge cette approche, aidant ainsi les équipes à réduire la complexité opérationnelle et à maintenir une protection cohérente dans les environnements hybrides et multicloud.

Fragmented data protection strategies can create invisible gaps: inconsistent policies across environments, coverage blind spots that surface only during recovery, and manual overhead that scales poorly as workloads diversify. When ransomware strikes or an outage occurs, teams may discover too late that critical workloads were not protected consistently. A unified approach is designed to help address this by bringing all workloads under a centralized policy engine – so protection status, retention schedules, and recovery workflows are governed from one place.

  • Commvault Cloud workload coverage: Unified protection across cloud databases (AWS RDS, Azure SQL, SAP HANA, Oracle), hypervisors (VMware, Hyper-V), Kubernetes (AKS, EKS, GKE), SaaS (Microsoft 365, Salesforce, Google Workspace), and on-premises infrastructure.
  • Unified control plane: All workloads managed from a single AI-enabled Command Center –helping reduce fragmented policy sets and manual operational overhead.
  • AI-enabled discovery and tagging: Automated workload inventory and classification can help teams identify coverage gaps and bring unprotected resources under policy.
  • TCO analysis: Real-time visibility into protected status and cost drivers can support budget governance across cloud, hybrid, and on-premises environments.

Comment Commvault Cloud vous aide-t-il à identifier et à gérer la protection des charges de travail ?

Effective data protection depends on knowing what you have before an incident occurs – not discovering gaps during recovery. Commvault Cloud is designed to help organizations continuously discover, classify, and apply backup policies across hybrid and multi-cloud assets, so coverage stays current as environments change.

Commvault Cloud begins with AI-enabled discovery –automatically inventorying cloud-native and hybrid assets, identifying resources without policy coverage, and bringing workloads under centralized governance in Command Center. Policies can be applied consistently across accounts, regions, and clouds, with real-time visibility into protected status and cost. Because environments change continuously – new workloads deployed, configurations updated, cloud resources spun up – discovery is designed to run as an ongoing process rather than a one-time assessment, helping teams maintain accurate coverage without manual audits.

  • AI-enabled discovery: Continuously inventories cloud-native and hybrid assets, identifies coverage gaps, and brings new workloads under centralized policies.
  • Centralized policy engine: Command Center applies consistent retention schedules, backup frequency, and copy policies across multi-cloud, hybrid, and on-premises workloads from a single interface.
  • Commvault Threat Scan: Continuously monitors backup data for anomalies, encryption activity, and malware indicators so security teams can act before recovery begins.
  • Cross-region and cross-cloud copies: Backup copies can be created across regions and cloud providers to support compliance, data residency requirements, and resilience posture.

Pourquoi les outils fragmentés échouent-ils au moment de la Recovery ?

89 % des entreprises operate in environments environments with more than one cloud, including hybrid cloud and multi-cloud set ups, yet most recovery failures don’t stem from a lack of backup jobs – they stem from protection that wasn’t built for the environment being recovered. Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.

Recovery failures surface the gap between a backup that ran and a service that actually restarts. Crash-consistent snapshots may restore raw data while leaving transaction logs, service dependencies, and cluster configurations in an inconsistent state – meaning the application cannot start even when the data is present. Unified data protection can help address this by ensuring workloads are protected in a way that reflects how they operate, and by validating recovery readiness before an incident forces the question.

Commvault Cloud accompagne les responsables de la sécurité qui ont besoin d’une capacité de récupération prête pour les audits, les équipes informatiques gérant des environnements hybrides et multicloud, ainsi que les parties prenantes du cloud et de la conformité chargées de protéger et de valider les charges de travail critiques. Commvault a été distingué dans le rapport IDC MarketScape: « Worldwide Cyber-Recovery 2025 Vendor Assessment » pour ses atouts en matière d’architecture de cyber-récupération, d’intégration dans l’écosystème de sécurité et d’étendue des charges de travail prises en charge.

  • Continuous backup monitoring: Threat Scan monitors backup data for malware indicators, encryption activity, and anomalous behavior –with alerts integrated into SIEM and SOC tools for coordinated incident response.
  • Commvault Cleanroom: Designed to stage restoration in an isolated environment so teams can validate data integrity and confirm systems are threat-free before returning to production – reducing reinfection risk.
  • Cleanpoint Identification: Designed to help pinpoint when data may have become compromised, providing more precise selection of a verified recovery point and supporting minimization of data loss.
  • Orchestrated service recovery: Command Center workflows can restore dependent services in sequence – helping reduce the manual coordination burden during high-pressure recovery events.
  • Scalable on-premises protection: HyperScale supports on-premises protection for hybrid environments, with streamlined onboarding and management through Command Center.

Microsoft Azure (Cloud)

Inventaire, classification et sauvegarde adaptée aux applications pour Azure SQL, les machines virtuelles Azure, Azure Blob et les charges de travail hébergées sur Azure.

Microsoft Entra ID (Identité)

Identity-based access governance integration – connects classification-based controls to Entra ID-managed users and AI service principals for policy enforcement.

AWS (Cloud)

Application-aware protection across AWS-hosted workloads including RDS, EC2, and EKS – via native API integrations.

Okta (Identité)

Identity-based access policy integration –connects Commvault access governance to Okta-managed identities for role-based enforcement.

Google Cloud (Cloud)

Découverte et sauvegarde adaptée aux applications sur Google Cloud Storage, GKE (Google Kubernetes Engine) et les charges de travail connectées.

ServiceNow (ITSM)

Integration for incident and audit workflows – connects Commvault threat scan events and recovery actions to ServiceNow ticketing for compliance reporting.

Comment Cela Fonctionne-t-il ?


Discover and protect

AI-enabled discovery inventories cloud-native, hybrid, and on-premises assets to identifier unprotected workloads. Command Center applies centralized policies – including backup frequency and retention – across environments, with cross-region and cross-cloud copies to support resilience and compliance. 


Monitor and detect

Threat Scan monitors backup data for anomalies, encryption activity, and malware indicators. Alerts integrate with SIEM and SOC tools, helping teams isolate affected data and plan a response before recovery begins. 


Validate and recover

Cleanpoint Identification helps pinpoint when data may have been compromised and surfaces viable recovery points. Cleanroom Recovery stages restoration in an isolated environment for validation before production restore, while Command Center orchestrates service recovery in the correct sequence to support controlled, reinfection-resistant recovery.


Before unified data protection, the most dangerous moment in incident response was often the restore itself – when teams discovered coverage gaps they didn’t know existed. With Commvault Cloud, teams can move from reactive gap discovery to proactive governance: understanding which workloads are protected, at what policy level, and whether recovery points have been validated. That shift – from hoping a backup worked to demonstrating that it can – can make the difference between a measured recovery and an extended outage.

Prêt à unifier la protection de toutes vos charges de travail hybrides ?

Découvrez comment Commvault Cloud peut aider votre équipe à identifier, gérer et restaurer chaque charge de travail en toute simplicité.

Questions fréquemment posées:

Qu’est-ce que la protection unifiée des données ?

La protection unifiée des données est une approche permettant de gérer le Backup and Recovery des charges de travail natives du cloud, multicloud et sur site à partir d’un seul plan de contrôle. Commvault Cloud prend en charge cette approche en appliquant des politiques et une couverture cohérentes dans tous les environnements, ce qui aide les équipes à réduire la complexité opérationnelle et à conserver une visibilité sur l’état de la protection.

Pourquoi les stratégies de sauvegarde fragmentées échouent-elles au moment de la restauration ?

Des stratégies de sauvegarde fragmentées peuvent entraîner des politiques incohérentes, des lacunes de couverture cachées et une charge de travail manuelle qui s’adapte mal aux environnements hybrides.

Commvault Cloud résout ce problème grâce à un plan de contrôle unifié, des politiques centralisées et une découverte basée sur l’IA, aidant ainsi les entreprises à identifier et à combler les lacunes avant qu’elles n’affectent Recovery.

Comment Commvault Cloud assure-t-il la protection des données pour les charges de travail hybrides ?

Commvault Cloud assure une protection unifiée des données dans les environnements cloud, SaaS, Kubernetes et sur site grâce à une plateforme unique dotée d’une intelligence artificielle. Le Command Center, la fonctionnalité de découverte basée sur l’IA et la fonctionnalité Cleanroom Recovery fonctionnent de concert pour centraliser les politiques, identifier les lacunes de couverture et faciliter la validation des données avant leur restauration en production, favorisant ainsi un processus de restauration mieux maîtrisé.

Qu’est-ce que Cleanroom Recovery et comment fonctionne-t-il ?

Cleanroom Recovery offre un environnement isolé permettant de restaurer et de valider les données en toute sécurité avant leur utilisation en production. En associant Threat Scan à une validation au niveau des applications, cette solution aide votre équipe à réduire le risque de réinfection et à assurer une reprise plus maîtrisée après un incident cybernétique.

Comment la protection unifiée des données répond-elle aux exigences en matière de RTO et de RPO ?

Commvault Cloud permet d’aligner la protection des données sur les priorités métier et contribue à la réalisation des objectifs RTO et RPO. Les workflows de restauration orchestrés dans Command Center et Cleanpoint Identification, associés à un plan de contrôle unifié, contribuent à réduire les temps d’arrêt, à améliorer la cohérence et permettent aux équipes de surveiller l’état de la protection et de combler les lacunes de manière proactive.

Quelles intégrations Commvault Cloud prend-il en charge pour la réponse aux menaces ?

Commvault Cloud s’intègre de manière native à Microsoft Azure, Entra ID, AWS, Google Cloud, Okta et ServiceNow. Les alertes générées par Threat Scan sont transmises aux outils SIEM et SOC, tandis que les actions de restauration s’intègrent aux plateformes ITSM telles que ServiceNow pour le suivi des incidents et la génération de rapports d’audit.

Ressources connexes

Solution Brief

Une protection des données sécurisée et résiliente

Découvrez comment la protection moderne des données combine sauvegardes immuables, résilience face aux ransomwares et Recovery rapide pour les opérations métier.
Read the briefabout Une protection des données sécurisée et résiliente
eBook

5 Questions Most Data Protection Providers Won’t Answer

Découvrez les questions essentielles à poser lors de l’évaluation des fournisseurs afin de mettre au jour les coûts cachés et de valider les capacités réelles de Recovery.
Obtenir le livre électroniqueabout 5 Questions Most Data Protection Providers Won’t Answer

For years, cyber resilience has been defined by technology – security controls, sophisticated detection capabilities, and increasingly robust backup strategies designed to prevent attacks or recover more quickly. Those investments remain essential, but they are no longer enough. 

AI has fundamentally changed the nature of cyberattacks, which now move at a speed that challenges even mature organizations. As the window between compromise and business disruption continues to shrink, resilience is becoming less about preventing every attack and more about keeping the enterprise running when prevention inevitably falls short. 

That shift is at the heart of IDC’s new report, Resilience Operations: The Discipline that Makes Readiness Provable. Based on a survey of more than 500 North American organizations, the report argues that resilience is evolving into a cross-functional operating discipline that connects business priorities with cybersecurity, ITOps, and disaster recovery. More importantly, it reveals several gaps that suggest many organizations are still preparing for a threat landscape that no longer exists. 

Here are the insights that stood out. 

Recovery should begin with business outcomes – not technical ones.

Historically, recovery planning has focused on restoring infrastructure as quickly as possible, with success judged by recovery time objectives, backup completion rates, and application availability. While those measures remain valuable, they don’t necessarily answer the question executives care about most: When can we get the business back online? 

IDC argues that resilience should be anchored to business outcomes rather than technical milestones – restoring the capabilities that allow the organization to serve customers, generate revenue, and meet its obligations. That may sound like semantics, but it changes how recovery priorities are established. Technology becomes the means to an end rather than the end itself. 

Most organizations still haven’t defined what matters most.

Nearly 6 in 10 organizations have not fully defined their minimum viable business (MVB) – the smallest set of functions, systems, processes, and data required to continue operating after a disruption. 

Without a shared understanding of what the business truly depends on, every movement during recovery becomes reactive. By defining your MVB before a crisis, you’ll enable faster decisions, better coordination during recovery, and ultimately a more resilient organization. 

Automation is becoming the dividing line between resilience and recovery debt.

While attackers increasingly automate reconnaissance, exploitation, and lateral movement, many organizations still rely on manual recovery processes. 

That imbalance is becoming increasingly difficult to ignore. AI is compressing attack timelines, but recovery timelines have not kept pace. Organizations that fail to automate these recovery tasks may find themselves spending days assembling and executing plans while the damage has already been done. 

Automated recovery orchestration, clean recovery point identification, and coordinated validation are becoming foundational capabilities for recovering at the speed modern attacks demand. 

Technology isn’t the biggest resilience challenge – organizational alignment is.

Security teams focus on containment, infrastructure teams focus on restoration, business leaders focus on customer impact, and compliance teams focus on regulatory obligations. None of these priorities are inherently wrong, but when they evolve independently, organizations enter a crisis without a shared operating model. 

Enter ResOps. Rather than positioning resilience as an IT responsibility, the report frames it as a discipline that deliberately brings together business, security, infrastructure, and recovery planning. The message is clear: Resilience depends less on individual tools than on creating shared priorities before an incident forces you to make difficult decisions. 

Testing remains one of the strongest indicators of resilience.

IDC found that relatively few organizations conduct frequent tabletop exercises or cyber-range simulations, despite decades of evidence showing that rehearsal consistently improves performance during real incidents. 

Exercises reveal hidden dependencies, expose communication gaps, and allow teams to make decisions without the real consequences. Organizations that repeatedly validate their recovery processes develop a level of confidence beyond planning alone. 

Tomorrow’s resilience challenges are already taking shape.

Ransomware still dominates headlines, but the next resilience challenges have already emerged – from agentic AI and machine identities to post-quantum cryptography. 

These threats remind us that resilience planning can’t focus exclusively on today’s infrastructure. Recovery increasingly involves cloud services, SaaS applications, AI models, machine identities, third-party providers, and distributed digital ecosystems that didn’t exist a decade ago. 

Resilience is becoming measurable.

IDC’s ResOps Maturity Model is invaluable for assessing your organization’s current posture. Rather than treating resilience as something organizations either possess or lack, the framework describes a progression from reactive, siloed operations to mature, adaptive resilience built on governance, automation, and continuous improvement. 

To me, that progression acknowledges an important reality: Resilience is never finished. It’s not about purchasing a platform or completing a project. Organizations become resilient by continually improving how technology, people, and business processes work together under pressure. 

Viewed through that lens, resilience becomes less like insurance and more like operational excellence – a capability that can be assessed, strengthened, and demonstrated over time. 

We’re undergoing a broader shift in how organizations think about resilience.

Resilience conversations are evolving from protecting infrastructure to protecting the business itself. That means recovery planning starts with customers instead of servers, governance becomes as important as technology, and confidence comes from proving capabilities rather than documenting intentions. 

ResOps isn’t really a new framework; rather, it’s a broader recognition that cyber resilience has become an operational discipline. As attacks become faster and more complex, resilience will be measured not by the absence of incidents, but by an organization’s ability to continue serving customers, supporting employees, and maintaining trust despite disruption. 

That’s ultimately what ResOps is designed to prove. 

Rajiv Kottomtharayilest directeur des produits chez Commvault. 

More related posts


Cyber Resilience

Read more about Cyber Resilience

Points clés à retenir

  • Trust in the age of AI isn’t disappearing – it’s evolving.
  • Les organisations doivent vérifier en permanence le fonctionnement de l’IA plutôt que de s’y fier aveuglément.
  • L’adoption de l’IA devrait donner plus d’autonomie aux employés, et non les pousser vers une « IA fantôme ».
  • Zero trust isn’t about distrusting people. It’s about continuously validating identities, devices, and actions.
  • Pour une adoption responsable de l’IA, il faut que la technologie, la gouvernance et les personnes travaillent main dans la main.

When we launched Ready. Or Not., we wanted to create a series that made some of today’s biggest AI conversations easier to understand. By pairing comedian Nathan Macintosh with industry experts, we’re exploring everything from agentic AI and cyber resilience to data management – and adding a little humor along the way.

If you caught our first episode on the opportunités et aux risques liés à l’IA agentique, I think you’ll enjoy this one as well. This time, we’re tackling a topic that’s at the center of every AI conversation: trust.

Nathan sits down with Diana Kelley, Chief Information Security Officer at Protect AI, for a conversation about what it means to trust technology when AI can generate convincing fake content, make decisions, and even imitate people. From deepfakes and hallucinations to zero trust and shadow AI, they explore how organizations can embrace AI without losing confidence in their people and systems.

Regardez l’épisode dans son intégralité sur Readiverse.À l’issue de cet épisode, je me suis senti plus optimiste que je ne l’aurais imaginé. Non pas parce que l’IA est soudainement devenue plus fiable, mais parce que Diana nous montre que la confiance s’installe lorsque les organisations mettent en place les politiques, les garde-fous et les technologies adéquats. Voici quelques thèmes abordés au cours de cette conversation qui jettent un nouvel éclairage sur l’IA.

La confiance et la technologie peuvent coexister

Diana believes trust is possible in the AI era, but it’s going to look different. We’ve always built trust through relationships with people. Now, we’re learning how to extend that trust to systems.

That doesn’t mean trusting technology blindly. It means understanding how AI works, recognizing its limitations, and putting the right safeguards in place so people and technology can work together with confidence.

“Trust has to evolve for the new world.”

– Diana Kelley

What resonated with me was the idea that trust and technology don’t have to be at odds with one another. With the right approach, they can strengthen each other.

We’re Getting Smarter About AI

Deepfakes have become one of the most talked about AI risks, and it’s easy to understand why. AI can now generate convincing voices, images, and videos that make us question what’s real. But Diana pointed out that while AI is getting more sophisticated, people are getting smarter. We’re more likely to question an unexpected phone call, take a closer look at a social media post, or pause at something that doesn’t feel quite right.

Organizations are becoming savvier, too. As AI gets better at impersonation, businesses are investing in new ways to continuously verify identities and validate information. My takeaway is this: Technology will continue to improve, but so will our ability to recognize it and respond responsibly.

“Is today a good day to start a deepfake?”

– Nathan Macintosh

Une IA responsable est bénéfique pour les entreprises

Diana shared an example that will probably sound familiar to many organizations. An employee she calls “Karen in Finance” starts using AI because it helps her complete a task in minutes instead of hours. Karen isn’t trying to work around company policy – she’s trying to be more productive.

Employees use AI because they see real value in it, and that’s an opportunity for organizations. When employees have access to approved AI tools, supported by clear policies and practical guidance, they can work more efficiently while helping protect company data and systems.

Aperçu : une adoption plus intelligente de l’IA

The goal isn’t to stop employees from using AI. It’s to make sure they’re using it the right way. Diana explains how organizations can encourage AI adoption without creating unnecessary risk.

Le modèle « Zero Trust » est plus important que jamais

“When you understand how things work, then you can start to understand how to manage them.”

– Diana Kelley

Zero trust is one of those concepts that’s much easier to understand with an analogy. Diana has a great one. She describes it as moving through a building. Just because you’ve been allowed through the front door doesn’t mean every other door automatically opens for you. Each time you access a new room, there’s another quick check to confirm you’re supposed to be there.

That’s essentially how zero trust works. Instead of assuming a person or device is trustworthy after a single login, organizations continuously verify identities, devices, and actions as technology becomes more connected. Most of those checks happen quietly behind the scenes.

One of the things I appreciated about Diana’s explanation is that zero trust doesn’t feel like another security buzzword. It feels like a practical way to think about trust in a world where AI and digital identities are becoming part of everyday business.

La confiance, c’est avant tout une question de personnes

At the end of the day, technology doesn’t create trust – people do. People define the policies, processes, and ethical boundaries that guide how AI is used, while technology helps verify that those guardrails are working as intended. It’s that partnership between people and technology that makes responsible AI possible.

Trust extends beyond our own organizations. Businesses need confidence in the partners they work with, the systems they connect to, and the technologies they adopt. That’s why transparency, shared standards, and continuous verification are becoming just as important as innovation itself. The more AI becomes part of everyday business, the more trust becomes everyone’s responsibility.

Perspectives d’avenir

AI will continue to evolve, and so will the way we interact with it. The organizations that succeed won’t be the ones that trust AI blindly or avoid it altogether. They’ll be the ones that build strong policies, adopt the right technologies, and continuously verify the systems they rely on.

Trust isn’t something we lose as technology advances. It’s something we intentionally build and evolve. That’s exactly the kind of conversation we hope to continue with every episode of Ready. Or Not.

Regardez l’épisode dans son intégralité sur Readiverse.

FAQ

Q: What is digital trust?

A: Digital trust is the confidence that people, systems, and organizations are who they claim to be and are acting in expected, secure ways. It combines technology, governance, and verification to help organizations interact safely.

Q: What are deepfakes?

A: Deepfakes are AI-generated images, videos, or audio recordings designed to closely imitate real people. While they have legitimate uses, they can also be used to impersonate individuals or commit fraud.

Q: What is zero trust?

A: Zero trust is a security model based on continuous verification rather than automatic trust. Instead of assuming a user or device is trustworthy after one login, organizations continuously validate identities and actions.

Q: What is shadow AI?

A: Shadow AI refers to employees using AI tools that haven’t been approved or governed by their organization. While often well-intentioned, it can introduce security, privacy, and compliance risks.

Q: Why shouldn’t organizations simply block AI tools?

A: Employees typically adopt AI because it helps them work more efficiently. Rather than banning AI outright, organizations should provide approved tools, establish clear policies, and educate employees on responsible use.

Q: What’s the biggest takeaway from this episode?

A: Trust isn’t disappearing because of AI – it’s evolving. Organizations that combine people, policies, and technology with continuous verification will be better positioned to adopt AI confidently and responsibly.

Katherine Demacopoulosest directrice principale de la stratégie et des programmes de contenu mondiaux chez Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Our Chief Products Officer, Rajiv Kottomtharayil, recently wrote about a big shift that is taking place across industries. Frontier AI models are compressing the time between vulnerability discovery and exploitation.  

This shift is prompting organizations everywhere to re-examine their vulnerability management processes. We’re doing the same at Commvault. That’s why, starting August 11, we’re changing the rhythm of how we disclose vulnerabilities.  What’s ChangingWe are raising the bar for security, transparency, and customer trust. On August 11, and on the second Tuesday of each month after that, we’re introducing Patch Tuesdays: a scheduled monthly release where we share security advisories and vulnerability patches.  

Patch Tuesdays are a hallmark of leading technology companies, because they provide customers with a predictable security rhythm.  This matters even more as the pace of vulnerability discovery accelerates. Of course, if there is an urgent vulnerability that must be reported off cycle, we will not hesitate to follow our well-established processes.  

Where You Can Find Up-to-Date Resources  

On the second Tuesday of each month, you’ll find new information pertaining to CVEs on our Chaque deuxième mardi du mois, vous trouverez de nouvelles informations concernant les CVE sur notre. You also can find the official publications at MITRE’s ». Vous pouvez également consulter les publications officielles sur le. 

On the Centre de sécurité Commvault, you’ll find our vulnerability management program and other security-by-design thought leadership.   

For compliance certifications, audit reports, and documentation on how Commvault protects customer data, visit the Commvault Trust Center. You can subscribe to updates from the Trust Center at the link in the upper righthand corner of the page. 

Bill O’Connell is Chief  Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

For decades, technology leaders have been trying to eliminate silos. Entire modernization programs have been built around connecting applications, consolidating platforms, and giving organizations a more complete view of their data.

Those efforts have delivered enormous value, but they also have shaped the way we think about resilience. When something goes wrong, we instinctively look for technical fragmentation. However, we’ve found the greater challenge lies elsewhere.

The most significant silos affecting cyber resilience today aren’t found in databases or applications but in organizational structures. They exist between security and infrastructure teams, between IT and the business, and between the people responsible for responding to an attack and those responsible for keeping the organization operating.

IDC’s latest research on ResOps, Resilience Operations: The Discipline that Makes Readiness Provable, suggests these organizational boundaries have become one of the defining obstacles to effective recovery. That’s a timely observation because cyberattacks have evolved in ways that can make those boundaries increasingly difficult to maintain.

Modern Attacks Don’t Follow Your Org Chart

A modern cyberattack rarely affects a single technology domain. A ransomware incident might begin with compromised identities, spread through cloud infrastructure, encrypt critical workloads, disrupt customer-facing applications, impact third-party services, and trigger regulatory Rapporting requirements – all within a matter of hours. Every stage involves different teams, different tools, and different priorities.

Yet many organizations still prepare for recovery as though these responsibilities can be managed independently.

Security teams naturally focus on containing threats and preserving evidence. Infrastructure teams prioritize restoring systems and minimizing downtime. Business leaders concentrate on customers, revenue, and operational continuity. Communications teams think about reputation, while legal and compliance teams focus on regulatory obligations.

Each perspective is entirely reasonable. The problem arises when those priorities have never been reconciled before an incident occurs.

In the middle of a crisis, recovery requires decision-making under pressure. Which applications should return first? Which data can safely be restored? How much risk is acceptable before customer services resume? Who has the authority to make those decisions?

Without alignment, organizations often discover that the greatest delays aren’t caused by technology but by uncertainty – the kind that could be mitigated by better preparation.

Resilience Begins with a Shared Definition of What Matters

The Rapport places emphasis on establishing your minimum viable business (MVB). At first glance, it appears to be another recovery planning exercise, but its real value lies in the conversations it forces organizations to have.

Defining an MVB requires business leaders, security teams, infrastructure specialists, and application owners to agree on a deceptively simple question: What absolutely must continue operating if everything else stops?

That discussion changes the nature of resilience planning. Recovery priorities are no longer determined by whichever application owner argues most convincingly during an incident. Instead, they are established in advance, grounded in business outcomes, and supported by technical dependencies that everyone understands.

Perhaps more importantly, MVB creates a common language. Business leaders begin talking about critical capabilities rather than individual systems. Technology teams begin mapping infrastructure to customer outcomes rather than technical architectures. Security teams gain greater clarity about which assets deserve the highest levels of protection during recovery.

That shared understanding is precisely what many organizations have been missing.

Technology Can Automate Recovery – But it Can’t Create Alignment

The Rapport doesn’t argue that organizations need yet another platform. It argues they need a way of working that aligns people, processes, and technology around a single operational objective. This is where ResOps – a cross-functional discipline – proves its mettle.

Technology can help automate recovery, but it cannot resolve disagreements about business priorities. It cannot decide which customer services matter most. And it cannot replace the governance needed to coordinate multiple teams during a high-pressure event.

Those are leadership challenges, and they are best addressed by investing time in answering the difficult questions together, long before an attack forces your hand.

The Strongest Organizations Don’t Eliminate Silos – They Connect Them

Cyberattacks will continue evolving. AI will continue compressing attack timelines. New technologies will introduce new dependencies, and new threats will emerge alongside them. None of that changes the fundamental requirement for resilience.

Organizations don’t recover because individual teams perform brilliantly in isolation, but because those teams already know how to work together.

That may ultimately be the most important insight from IDC’s research. Resilience isn’t simply the product of better technology or more sophisticated security controls. It is the result of shared priorities, clear governance, and a tested operating model that brings the right people together before an incident occurs.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Learn about our advances through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

By Sustainability Team

As AI adoption accelerates, cyber threats are becoming more sophisticated, and data regulations are expanding. Resilience is no longer simply a defensive posture – it is a business imperative and competitive advantage.

That belief is at the center of Commvault’s FY26 Sustainability Report, which is now available. This year’s report reflects the progress we’ve made across the areas that matter most to our business, our customers, our people, and the communities where we live and work.

Anchored by our updated materiality assessment, the report highlights how we are advancing sustainability through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

Cyber resilience remains foundational to our work. As organizations rethink what it means to be ready for disruption, Commvault continues to unify data security, identity resilience, and cyber recovery to help customers detect threats faster, operate more efficiently, and recover with greater confidence. We also are integrating AI and automation designed to support smarter, more secure, and more resilient operations.

That same focus on resilience extends to our environmental commitments. Our solutions help customers optimize data storage and movement, which can help reduce energy expenditure in data centers. For Commvault, responsible innovation means building solutions that support both operational strength and more efficient use of resources.

The report also reflects the people and principles behind our progress. Strong governance, a modern Code of Ethics, and continued investment in our talent help create the foundation for trusted partnerships and long-term value. These commitments are deeply connected: Strong governance enables responsible innovation, responsible innovation helps strengthen the security and efficiency our customers depend on, and that trust is sustained by the people who bring our mission to life every day.

We invite you to read Commvault’s FY26 Sustainability Report as both a record of our progress and a look forward to the priorities that will shape our next chapter.

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

A few years ago, digital sovereignty was largely viewed as a compliance conversation. If you stored data in the right geography, met the right regulatory requirements, and satisfied a handful of audit questions, you could generally move on.

That’s no longer the case.

Today, sovereignty has become a board-level discussion. Governments are rewriting policies. Regulators are increasing scrutiny. And business leaders are starting to recognize that sovereignty isn’t just about where data resides – it’s about how organizations continue operating when geopolitical, legal, or operational assumptions suddenly change.

In the first episode of our STRIVE series on digital sovereignty, I sat down with Max Mortillaro, co-founder and Chief Research Officer at Osmium Data Group. Together, we unpack what sovereignty actually means, why the conversation has accelerated so quickly, and where organizations are most likely to get it wrong.

Watch the full episode.

Points clés à retenir

  • Digital sovereignty is no longer just a compliance issue – it has become a resilience and business continuity concern.
  • Data location is only one piece of the puzzle. Jurisdiction, operations, technology dependencies, and governance all matter.
  • Many organizations focus on technical controls before understanding the business problem they’re trying to solve.
  • Geopolitical uncertainty is accelerating sovereignty initiatives, particularly across Europe.
  • There is no such thing as a perfectly sovereign environment. Every organization must make informed trade-offs between risk, cost, and operational requirements.

Why Data Location Isn’t the Whole Story

One of the most common misconceptions around digital sovereignty is that it begins and ends with geography. If data is stored in a local data center, the thinking goes, the sovereignty problem has been solved.

It’s an understandable assumption. After all, many of the early conversations around sovereignty focused heavily on data residency requirements and where information could legally be stored.

But as Max points out during our discussion, that’s only one dimension of a much larger challenge. Sovereignty isn’t simply about where a data center sits. It’s also about who operates it, which laws apply to it, who has access to it, and what dependencies exist behind the scenes.

A cloud service may be physically located within a specific country, but that doesn’t necessarily mean it’s insulated from legal, operational, or technological influence originating elsewhere.

That’s where the conversation becomes significantly more complex.

The Hidden Dependencies Most Organizations Overlook

When organizations first begin exploring sovereignty, they often approach it as a technology project. They evaluate hosting locations. They assess replication strategies. They examine where workloads should run.

Those conversations are important, but they can also create a false sense of confidence.

As Max explains, modern technology environments are built on layers of dependencies that aren’t always visible. A service may appear local on the surface but it may be relying on infrastructure, management systems, telemetry services, or operational controls that exist elsewhere.

That’s why sovereignty isn’t simply a question of location. It’s a question of influence.

Who ultimately controls the service? Which legal jurisdiction applies when disputes arise? What happens if geopolitical tensions introduce new restrictions, regulations, or limitations on access?

These aren’t hypothetical questions anymore. They’re becoming part of real-world risk assessments.

Sneak Peek: Sovereignty Is More Than a Technical Problem

In this segment from the conversation, Max explains why organizations often start sovereignty discussions in the wrong place – and why understanding the legal, operational, and business objectives must come before any technology decisions.

Why Europe Is Driving the Conversation

One of the most interesting parts of our discussion focuses on why sovereignty has become such a dominant topic across Europe.

The answer isn’t just regulation; it’s dependency.

European organizations have become increasingly aware that many of the technologies they rely on every day are owned, operated, or governed outside of their direct control. For years, that reality was largely accepted as part of the global technology ecosystem.

Today, that assumption is being reevaluated.

Geopolitical tensions, evolving regulations, and increasing concern around strategic autonomy have pushed sovereignty higher on the priority list for governments and enterprises alike. What was once considered an edge case has become a mainstream business concern.

The result is a growing recognition that resilience isn’t only about recovering from technical failures. It’s also about understanding and managing external dependencies before they become business disruptions.

Sovereignty and Resilience Are the Same Conversation

One of the themes that you’ll see repeatedly surfacing throughout the discussion is how closely sovereignty and resilience are connected.

At first glance, they may seem like separate disciplines. One focuses on governance, regulation, and control. The other focuses on recovery, continuity, and operational readiness.

In practice, they’re deeply intertwined.

If a business cannot access critical systems because of a geopolitical event, regulatory restriction, or third-party dependency, the outcome isn’t very different from other disruptions organizations spend years preparing for.

The business still needs to operate. Customers still need to be served. Recovery still needs to happen.

That’s why I increasingly view sovereignty through the same lens as cyber resilience. Both are fundamentally about reducing exposure to events that could disrupt operations and preparing the organization to continue functioning when those events occur.

Start With the Business Problem

Perhaps the most practical advice Max shares is also the simplest.

Before evaluating sovereign cloud offerings, before engaging vendors, and before debating technical architectures, organizations should first understand what problem they’re trying to solve.

That means understanding:

  • Which business processes are most critical.
  • Which data assets matter most.
  • Which regulatory requirements apply.
  • Which risks are truly being mitigated.

Only after those questions are answered does it make sense to evaluate technology options.

Too often, organizations start with solutions and work backward toward the problem. Sovereignty requires the opposite approach. The strategy should come first.

The architecture follows.

Why There Is No Perfect Answer

One of the realities leaders need to accept is that there is no such thing as a perfectly sovereign environment.

Every organization operates within a network of dependencies. Every technology choice introduces trade-offs. Every risk decision involves balancing operational requirements, compliance obligations, cost considerations, and business outcomes.

The goal isn’t perfection. The goal is understanding those trade-offs well enough to make informed decisions.

Organizations that approach sovereignty as a binary yes-or-no question often find themselves frustrated. Organizations that approach it as a risk-management exercise tend to make better progress.

Pourquoi cette discussion est importante

Digital sovereignty is moving quickly from a niche compliance topic to a strategic business issue.

Boards are asking questions. Regulators are increasing scrutiny. Customers are becoming more aware of where their data lives and who controls it.

At the same time, geopolitical uncertainty continues to reshape how organizations think about risk.

That doesn’t mean every company needs a radical sovereignty transformation tomorrow.

But it does mean that the organizations that start building a clear strategy today will be in a much stronger position than those who wait until the conversation becomes unavoidable.

Sovereignty isn’t a technology decision masquerading as a business problem. It’s a business problem that requires legal, operational, and technical decisions working together.

Regardez l’épisode dans son intégralité

In this installment, Max and I explore:

  • What digital sovereignty actually means.
  • Why data location alone isn’t enough.
  • The legal and operational dimensions organizations often overlook.
  • How geopolitical developments are influencing sovereignty strategies.
  • Why sovereignty and resilience are becoming inseparable.

Regardez-le dès maintenant.

FAQ

Q: What is digital sovereignty? 

A: Digital sovereignty refers to an organization’s ability to maintain control over its data, technology, operations, and governance within specific legal and jurisdictional boundaries.

Q: Is digital sovereignty the same as data residency? 

A: No. Data residency is one component of sovereignty, but sovereignty also includes legal jurisdiction, operational control, technology dependencies, and governance.

Q: Why has digital sovereignty become more important recently? 

A: Growing geopolitical uncertainty, evolving regulations, and increasing concern about technology dependencies have accelerated interest in sovereignty initiatives.

Q: What is the biggest mistake organizations make? 

A: Treating sovereignty as a purely technical challenge instead of a broader business risk and resilience issue.

Q: How does sovereignty relate to cyber resilience? 

A: Both disciplines focus on maintaining operational continuity in the face of disruptions, whether those disruptions are technical, legal, geopolitical, or regulatory.

Q: Where should organizations begin? 

A: Start by understanding the business outcomes you’re trying to protect, the risks you’re trying to mitigate, and the data and processes that are most critical to your operations.

Alex Zinin is VP/GM of Managed Service Providers at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Points clés à retenir

  • The role of the backup administrator is evolving from managing infrastructure to delivering business resilience and recovery confidence.
  • Modern ResOps (resilience operations) focus on recovery readiness, continuous validation, governance, and business outcomes – not just successful backup jobs.
  • Autonomous Resilience is Commvault’s vision for the next evolution of ResOps, wici AI helps resilience teams reduce operational overhead through intent-driven, governed workflows while maintaining human oversight, approvals, and auditability.
  • By helping reduce repetitive operational work, AI enables resilience teams to spend more time improving cyber recovery, governance, and recovery readiness.
  • The future of resilience will be measured by confidence in recovery – not simply the successful completion of protection activities.

The Operational Shift at 8 a.m.

For an enterprise backup administrator, the morning routine has long followed a predictable, high-stress pattern. You log in at 8 a.m. to face a wall of dashboards. Tici are thousands of completed protection activities, but your eyes naturally scan for the exceptions – a handful of failed workloads, replication delays, and capacity alerts warning that critical storage resources are nearing their thresholds.As you begin sorting through the day’s priorities, the reality of modern infrastructure closes in. A virtualization administrator submits a request: Dozens of new workloads were provisioned overnight, and leadership needs to know whether they are automatically covered by existing protection policies.Moments later, the compliance team requests a detailed history of protection success and retention validation to prepare for an upcoming audit. Then, the security operations center (SOC) calls. An anomaly has been detected on a critical system, and they need confirmation that recovery copies remain isolated, immutable, and uncompromised.Before you can finish your first cup of coffee, leadership asks a simple but devastating question: “If we were hit by ransomware right now, how consistently and confidently could we recover?”

Ten years ago, a successful backup administrator was an infrastructure gatekeeper. Success was binary and infrastructure-centric: Did the jobs finish within the required time window? Was the data successfully protected? If the dashboard was green, the job was done.Today, that paradigm is entirely broken. The modern enterprise does not care whether data protection jobs completed successfully. It cares whether the business can survive a catastrophic disruption.Success is no longer measured by the completion of a background data protection process. It is measured by an organization’s ability to withstand ransomware, infrastructure failures, cloud outages, insider threats, and compliance events without losing data or operational momentum.The role has fundamentally evolved from infrastructure management to enterprise resilience. Yet many organizations still force administrators to spend their days managing operational tasks instead of architecting recovery confidence.Commvault is working to redesign the administrator experience to help break this cycle, enabling a shift from reactive backup management toward comprehensive ResOps.

The Drag of the Modern Administrator’s Daily Reality

To understand why this shift is necessary, one must first recognize the enormous operational burden carried by administrators every day. Consider the volume of tactical work required to maintain a modern enterprise protection environment:

  • Job and infrastructure monitoring: Reviewing overnight activities, distinguishing transient issues from legitimate failures, and validating infrastructure health across a rapidly changing hybrid environment.
  • Troubleshooting and issue resolution: Spending hours reviewing diagnostic information and operational telemetry to determine why processes stalled, services became unavailable, or critical workloads failed unexpectedly.
  • Resource optimization and performance management: Continuously identifying storage constraints, network bottlenecks, or infrastructure limitations that impact protection and recovery objectives, then manually expanding capacity as requirements grow.
  • Workload discovery and lifecycle management: Automatically discovering, classifying, and assigning appropriate protection policies to newly deployed applications, cloud services, databases, and infrastructure resources.
  • Capacity and storage management: Monitoring consumption trends, forecasting growth, and responding to unexpected increases before they threaten recovery objectives.
  • Audit and compliance support: Collecting reports, validation records, and historical evidence across multiple systems to demonstrate compliance with retention and governance requirements.

Every hour spent troubleshooting an operational issue or assembling compliance evidence is an hour taken away from strategic resilience planning. This is wici resilience teams lose time. The challenge is the operational overhead required to keep protection systems synchronized with a constantly evolving hybrid cloud environment.

The Structural Shift: From Backup Operations to ResOps

As organizational risk profiles increasingly center around cyber resilience and business continuity, the very mindset of data protection must evolve.

Old Mindset: Backup Operations

“I need my protection jobs to finish successfully.” 

New Mindset: ResOps

“I need confidence that we can recover immediately.” 

This evolution fundamentally changes the questions administrators must answer.

Backup Operations  ResOps
Did the workload complete protection last night? Are our critical applications verified as recoverable?
How much storage capacity remains? What is our verified recovery readiness posture?
Are recovery copies synchronized? Are our recovery environments protected and isolated?
Can we restore a single file? Can we recover an entire business service during a cyber event?

In this new model, recovery – not backup – becomes the primary operational metric. 

An organization can achieve near-perfect protection success rates while remaining dangerously unprepared for a ransomware attack due to compromised credentials, hidden dependencies, configuration drift, or unverified recovery processes.ResOps assumes disruption is inevitable. The focus shifts toward continuous validation, proactive risk identification, threat awareness, and deterministic recovery orchestration.At Commvault, we see this evolution leading toward Autonomous Resilience, wici AI helps resilience teams move from manual operations toward intent-driven, governed outcomes.

How Commvault is Redesigning the Experience Around Outcomes

Commvault is addressing these realities by working to redesign the administrator experience. Rather than requiring users to organize their work around infrastructure configurations, protection policies, storage resources, and system assignments, Commvault is shifting the experience toward outcomes that matter to the business.

  • Unified management and risk-driven visibility: Rather than navigating multiple interfaces to manage different environments, administrators gain visibility into their entire estate through a unified resilience experience.The focus extends beyond operational status. The platform highlights risk exposure, protection gaps, emerging threats, unprotected workloads, and configuration drift that could impact recovery readiness.
  • Policy simplification and intelligent automation: Traditional environments often require administrators to manage hundreds of static schedules and policies. Commvault is designed to replace this complexity with intent-based protection plans.

    Administrators define business outcomes, while the platform can automatically orchestrate the infrastructure, optimize workflows, and manage protection activities behind the scenes.

  • Continuous validation and clean recovery environments: True resilience requires confidence not only in protected data but also in the ability to restore it safely.

    Commvault can integrate automated recovery validation directly into operations. This includes the ability to orchestrate isolated recovery environments wici systems can be restored, validated, and inspected before production restoration occurs.

  • Threat-aware operations and intelligent detection: Modern resilience requires more than monitoring activity counts. By applying advanced analytics and machine learning to operational telemetry, the platform establishes historical baselines and detects abnormal behavior.

    When suspicious activity occurs, administrators receive contextual explanations, probable causes, impact assessments, and recommended actions – not just generic alerts.

A Day in the Life: The Outcome-Driven Workflow

To understand the potential impact of this transformation, consider an illustrative day for an administrator within an outcome-focused resilience platform. The scenario below shows how these capabilities are intended to work together.

8 a.m. – Establishing Recovery Readiness

Instead of searching through thousands of activities and alerts, you open a resilience dashboard displaying a comprehensive Recovery Readiness Score across the environment. The platform highlights a scaling concern. Recently deployed workloads have increased demand beyond recommended operational limits.Rather than manually expanding infrastructure and coordinating resources, the platform automatically recommends a corrective action: “Additional infrastructure capacity is recommended to maintain recovery objectives. Approve?” 

A single approval initiates the adjustment.

11:30 a.m. – Automated Audit Resolution

The compliance team requests evidence of protection activity and policy compliance for a previous reporting period. Rather than manually compiling reports and spreadsheets, the administrator generates a compliance package containing validation records, policy compliance evidence, and supporting documentation within minutes.Time is spent improving resilience – not producing paperwork.

2 p.m. – Threat Detection and Autonomous Response

A critical anomaly is detected. A workload exhibits behavior that significantly deviates from normal historical patterns.Instead of issuing a generic warning, the platform automatically correlates the event with known behaviors, evaluates potential causes, assesses business impact, and identifies clean recovery points.If a cyberattack is suspected, the platform highlights affected recovery data, isolates impacted assets, validates clean recovery options, and prepares recommended recovery actions.The administrator is no longer investigating what happened. The platform is helping determine what to do next.

The Power of Intent: Why Embedded Intelligence Changes Everything

The engine powering this transformation is the move from manual task execution to autonomous, intent-driven operations.Commvault’s conversational and AI-driven capabilities are designed to support the operational model that this transformation requires:

  1. An administrator expresses intent.
  2. The platform gathers context.
  3. Recommendations are generated.
  4. Actions are executed with appropriate oversight.
  5. Outcomes are validated.
  6. Activities are documented automatically for governance and audit purposes.

This fundamentally changes the relationship between administrators and the underlying technology. The goal is no longer to manage systems. The goal is to direct outcomes.

From Diagnostics to Actionable Root Cause

When infrastructure issues occur, administrators traditionally have spent hours reviewing diagnostic information, searching for symptoms, and piecing together dependencies. Embedded intelligence continuously monitors infrastructure health, operational telemetry, and service activity patterns. When an issue arises, diagnostic information can be analyzed automatically, probable causes identified, and remediation recommendations generated without requiring manual investigation.

Multi-Workload Dependency Correlation

Modern environments are interconnected ecosystems. A single infrastructure issue can generate hundreds of downstream failures. Rather than forcing administrators to investigate each event individually, the platform automatically correlates failures and identifies shared infrastructure dependencies, common services, or connectivity issues contributing to broader disruption.

Proactive Resource Forecasting

Instead of waiting for operational failures, the platform continuously analyzes historical workload patterns, growth trends, and infrastructure utilization. Expected changes are separated from abnormal behavior, allowing resilience teams to proactively address capacity and performance concerns before they impact recovery readiness.

The Rise of the Resilience Engineer

The data protection industry is undergoing a profound transformation. The title of backup administrator is rapidly becoming an artifact of a previous era – one in which data protection was viewed primarily as an operational task supported by infrastructure checklists.Tomorrow’s successful professional is a resilience engineer. They collaborate with security teams to design cyber recovery strategies. They work alongside compliance leaders to automate governance requirements. They provide executives with measurable confidence in the organization’s ability to recover from disruption. Their value is no longer defined by how effectively they manage operational complexity, but by how effectively they reduce business risk and accelerate recovery.Commvault is not simply enhancing an existing backup platform. It is helping build the operational framework for the next generation of resilience leadership. By helping reduce administrative overhead, simplify operations, and align the experience around recovery readiness and continuous validation, Commvault is enabling administrators to focus on what matters most: helping the business remain resilient. 

The future of enterprise availability is no longer about managing backups. It is about delivering autonomous resilience. 

Continue the Conversation

The conversation around Autonomous Resilience is just beginning. At SHIFT 2026 in Nashville this November, we’ll explore how AI is reshaping ResOps and what it means for the next generation of resilience engineers. Register ici.

FAQ

Q: Why is the role of the backup administrator changing?

A: Enterprise resilience is no longer measured by successful backup jobs alone. Organizations increasingly judge resilience by their ability to recover confidently from ransomware, cloud outages, infrastructure failures, and other disruptions. As a result, backup administrators are taking on a broader role that spans cyber resilience, governance, recovery readiness, and business continuity.

Q: What is ResOps (resilience operations)?

A: ResOps reflects the shift from managing backup infrastructure to managing recovery readiness. It brings together data protection, cyber recovery, governance, continuous validation, and operational visibility into a single discipline focused on helping organizations recover with confidence.

Q: What is Autonomous Resilience?

A: Autonomous Resilience is Commvault’s vision for the next evolution of ResOps. It applies AI to help resilience teams reduce operational overhead through intent-driven, governed workflows that gather context, recommend actions, execute approved tasks, validate outcomes, and maintain auditability throughout the recovery process.

Q: How will AI change the day-to-day work of resilience teams?

A: AI can help reduce repetitive operational work such as reviewing backup activity, investigating failed workloads, collecting compliance evidence, assessing recovery readiness, identifying clean recovery points, and recommending recovery actions – all while operating within established governance controls. This allows administrators to spend more time improving resilience strategy and less time performing routine operational tasks.

Q: Does Autonomous Resilience replace backup administrators?

A: No. Autonomous Resilience is designed to augment resilience professionals, not replace them. Administrators remain responsible for oversight, approvals, governance, and decision-making while AI helps reduce operational overhead and supports day-to-day resilience operations.

Q: Why is this important now?

A: Hybrid infrastructure, cyber threats, AI adoption, and increasing operational complexity are changing what organizations expect from backup and recovery teams. The role is evolving from managing infrastructure to delivering resilience, making recovery readiness, governance, and operational confidence more important than ever.

Rajiv Kottomtharayilest directeur des produits chez Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience