Skip to content

This codification of privacy is transforming how businesses are expected to operate. There is no more question of what happens when a business doesn’t invest in a cyber program and who’s responsible. Let’s take a quick look at what will shape this year.

Réglementations américaines en matière de protection de la vie privée : mise à jour des exigences du CCPA, du NYDFS et de la SEC

CCPA may be amended. Currently the CCPA has an open request for comment on how audits fit with CCPA. In addition, we will start seeing rulings in cases around CCPA showing what we can expect for the reality of losses from not complying. For those who want to keep track with us, Perkins Coie has a great outil de suivi.

NYDFS will likely be amended. Industry comments are under review. Once DFS makes its recommendations it will move through the legislation process. Notable takes:

    • “The CISO and the highest-ranking officer of the covered entities are both required to sign a certificate of compliance, and notice of compliance must be delivered annually to the NYDFS.” – Morgan Lewis.
    • Il ne s’agit pas seulement d’une loi sur la protection de la vie privée, cela englobe également la résilience des entreprises et la sécurité des opérations.

The SEC wants their new rules in place ASAP. This includes provisions for Cyber Security reporting requirements alongside considering rules requiring adoption of standard practices. As with all federal rules, this one may take some time. Other provisions, notably around carbon footprint reporting, seem to be causing friction. We will see if the SEC makes their timeline.

$100 Million penalty for BIPA violations. In 2022, we saw cases relating to the Louisiana BIPA come to a close with significant penalties being doled out. The rubber is meeting the road, and liabilities are a reality. Read more at Data Protection Report.

Pourquoi les dirigeants doivent accorder la priorité à l’expertise en cybersécurité

Face à cette forte pression législative, les responsabilités concrètes sont désormais bien réelles. Les dirigeants ne peuvent plus ignorer les conseils des équipes de sécurité. La réalité est que la plupart des entreprises ne sont pas prêtes. Un bref extrait de Forbes illustre parfaitement cette situation :

“Our analysis showed that only 51% of Fortune 100 companies have a director on their boards with relevant cybersecurity experience. The situation in the Fortune 200 and 500 is more concerning: only 9% have cyber-savvy directors. Worse still are the companies in the Russell 3000 smaller than those in the Fortune 500: only 8% have cyber directors. There is a total shortage of 2,724 directors with cybersecurity expertise across all Russell 3000 companies.” –Forbes

To be successful in filling these positions, security leaders will need to have an opinion on what’s changing from a legal perspective, how that impacts business strategy, and how the business creates opportunity in markets with changing regulations.

En résumé, les RSSI doivent prendre part à toutes les discussions stratégiques au sein du conseil d’administration. Un RSSI proactif peut en effet constituer un avantage concurrentiel. Ces dirigeants proactifs sauront analyser les données de l’entreprise, les exploiter pour en tirer des avantages sur le marché et relever les nouveaux défis réglementaires. Les entreprises capables de garder une longueur d’avance sur l’évolution du cadre réglementaire obtiendront un meilleur retour sur investissement. Celles qui considèrent la conformité comme une simple formalité prendront du retard.

Adherence to compliance regulations is critical to your business’s operations, but it doesn’t have to consume an outsized portion of your resources. Let Clumio help automate compliance and simplify management while reducing your data protection costs. Contact us for a customized consultation.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The past year has been amazing – our data protection portfolio has won many accolades of technology leadership from industry analysts like Gartner, Forrester and GigaOm. These wins are no doubt driven by our relentless passion to protect our customers’ data in a difficult world and our fundamental belief that continuous customer collaboration is key to pragmatic innovation.

The next chapter of our 26-year journey of customer-driven innovation is now here – we are excited to announce the General Availability of Commvault Platform Release 2023! Commvault PR 2023 introduces several new features and additions to strengthen our customers’ security posture, deepen our rich integration with all major hyperscalers and introduce more smart savings through operational efficiencies.
Des centaines de clients ont déjà pu bénéficier de ces nouvelles fonctionnalités lors de la phase d’aperçu technologique, qui a débuté le 15 décembre 2022.

Harnessing the power of multi-cloud

What differentiates our approach to the ecosystem – and yes, we continue to support the broadest ecosystem when it comes to data protection – is how our integrations are seamlessly built-in and not just clumsily bolted on for a quick mention. Deeper the integrations, greater the synergies enjoyed by our customers.

La version 2023 de Commvault PR intègre de nouvelles intégrations avancées destinées à faciliter la protection des données de nos clients sur Microsoft Azure, AWS Cloud, Google Cloud Platform et Oracle Cloud Infrastructure.

Take, for instance, our new integration with Microsoft Azure Restore Points. We worked closely with Microsoft to be the first data protection platform to support Azure Restore Points. While Azure has had incremental snapshot capabilities, this new integration allows for application consistency across disks, while reducing costs with the option to use more cost-efficient storage tiers for backups. Commvault PR 2023 also introduces integration with Amazon FSx for NetApp which brings the same on-premises NetApp ONTAP policy-based protection to AWS. The new release also introduces support for Oracle Cloud Infrastructure (OCI) infrequent access & combined storage tiers to help reduce costs for protecting your cloud data.

Enhancing data security

Our trusted approach to data protection is shaped by the fundamental customer direction that data security is an integral and inseparable component of data protection. Building on our robust multi-layered ransomware detection, protection and recovery framework, Commvault PR 2023 introduces new integrations to drive data protection insights into the broader security ecosystem.

An important aspect of data protection is to leverage data awareness to proactively alert IT teams when threats arise. Commvault PR 2023 introduces a new Security Information and Event Management (SIEM) connector that makes it easy to feed alerts, events, and audit data to other platforms through webhooks APIs or even Syslog. Leveraging standard protocols ensures we can work with virtually any SIEM or event management system giving security teams better visibility to anomalies and threats in their data. 

Driving smart savings

With the uncertainty of a global recession looming, customers in every industry are looking to optimize costs in their budgets to make up for the increased spending for security and mission-critical areas. We are continuing to help provide options to lower the cost for data

Les nouvelles fonctionnalités permettant d’utiliser des instantanés mono-région par opposition aux instantanés multi-régions sur GCP peuvent permettre de réduire de 30 % le coût des ressources de sauvegarde. Parfois, optimiser les coûts revient simplement à réduire le temps nécessaire à la protection des applications.

Nos optimisations pour Hadoop, qui s’appuient sur snapdiff, permettent de réduire à quelques minutes seulement des analyses de sauvegarde qui prenaient auparavant plusieurs heures, grâce aux améliorations apportées à la manière dont nous recherchons les blocs modifiés.

These are just a few of the amazing features we have in Platform Release 2023. You can learn about more of the latest features in our What’s New page for Platform Releases. Rencontrez with our product management team and others in our communautés for all the latest news and release information. 

Join us live on March 8th, 2023 at our Platform Release 2023 customer webinar.  Register here

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

La Journée internationale des femmes et des filles dans les sciences 2023 aura lieu le samedi 11 février et constitue une occasion de promouvoir l’accès et la participation pleins et égaux des femmes dans les domaines des sciences, des technologies, de l’ingénierie et des mathématiques (STEM).

Nous avons rencontré deux dirigeantes exceptionnelles et inspirantes de Commvault, Vidya Shankaran, directrice technique sur le terrain, et Parisa Bazl, directrice de l’expérience utilisateur, afin de recueillir leur point de vue sur divers sujets, notamment :

  • Pourquoi une minorité de femmes se lancent dans une carrière dans les STEM,
  • en quoi la diversité des points de vue peut être un atout considérable dans leur travail et
  • Quels conseils donneraient-elles à elles-mêmes à l’âge de 18 ans ?
  • Leurs héros personnels

Why is marking the International Day of Women and Girls in Science important?

Vidya

En tant que mère d’une fille qui fréquente un lycée spécialisé en sciences et en ingénierie, je sais à quel point il est important de sensibiliser à la nécessité de l’égalité entre les sexes et de promouvoir l’autonomisation et l’avancement des femmes et des filles dans les domaines des sciences, de la technologie, de l’ingénierie et des mathématiques (STEM).

By celebrating this day, it serves as a constant reminder for all to work towards removing the barriers that prevent women and girls from participating – this helps foster a more inclusive and innovative scientific community and a better future for all.

Cette journée vise à mettre en avant les contributions importantes des femmes et des jeunes filles dans ces domaines, et à encourager davantage de jeunes filles et de femmes à se lancer dans une carrière dans les STEM.

Parisa

Celebrating this day is a way to remind ourselves of how far we’ve come and the distance we still need to go. While achieving gender equality in the STEM field is an uphill battle, our progress is evidence that it is possible and we will get there. This day is also a reminder of the benefits of having diversity in technology since so many critical, fun, and interesting things — from WiFi to dating apps – had their groundwork laid by women.

Why do you think women earn STEM degrees at half the rate of men – how can we help address this?

Vidya

Despite the fact that women have had a significant role to play in the progress of science and technology, they have not received the same levels of recognition as their male colleagues is an issue that transcends centuries. 

I would not necessarily to ascribe it to lack of female role models in STEM – there are many unsung “heroes” – but rather to the gender stereotypes and societal expectations that science is a “male” field. This manifests in the form of insufficient support for work-life balance that women and girls encounter compared to their male counterparts.

Thankfully, it is not irreparable or beyond redemption yet – there are many things we are already doing today and should continue doing and maybe even accelerate.

Il est essentiel de promouvoir des figures féminines de référence dans les STEM par le biais des médias et de mettre en avant les réalisations de femmes qui ont réussi dans le domaine scientifique, car cela permet d’encourager les filles à s’orienter vers les sciences dès leur plus jeune âge.

Avant tout, il est impératif de continuer à offrir des environnements favorables dans l’éducation et sur le lieu de travail, tels que des programmes de mentorat et des actions de sensibilisation. La mise en place d’aménagements de travail flexibles permet de garantir que les femmes restent motivées à poursuivre leur carrière dans les STEM. Enfin, favoriser une culture de diversité et d’inclusion dans les STEM, et promouvoir l’équité et l’égalité des chances en matière de recrutement, de promotion et de rémunération, sont essentiels pour améliorer l’intégration et la rétention des femmes et des filles dans les carrières des STEM.

Parisa

De nombreuses femmes grandissent avec l’idée erronée que les STEM constituent un domaine qui privilégie les atouts stéréotypiquement masculins, et nous ne disposons pas toujours des systèmes de soutien social adéquats pour remédier à ces sentiments d’inadéquation et de manque de confiance. La technologie est souvent assimilée aux logiciels, mais elle concerne bien davantage les personnes. En mettant en avant les aspects humains de cette discipline, nous pouvons encourager davantage de femmes à prendre conscience que leurs parcours, leurs points de vue et leurs compétences uniques constitueront un atout dans la poursuite de leurs études et de leur carrière dans les STEM.

What can being a woman bring to your roles of field Chief Technology Officer (Vidya) and Director of User Experience (Parisa)

Vidya

In my role, which is technology evangelism with our customers and partners, in order deliver this role successfully, it requires empathy, emotional intelligence, respect for all cultures and obviously, understanding of technology. As a woman it does require a lot more effort and perseverance to get to and keep my “seat at the table”, but it is not without the support of all men and women around me.

Je constate également une augmentation du nombre d’hommes qui se posent en alliés et qui ont joué un rôle déterminant pour favoriser l’acceptation, l’encouragement et le soutien des femmes dans le secteur des technologies. Ces hommes sont invariablement les pères ou les frères de femmes et de jeunes filles travaillant dans les domaines des sciences, des technologies, de l’ingénierie et des mathématiques (STEM) ; ils sont conscients des défis auxquels ces femmes et ces jeunes filles sont confrontées et sont heureux d’apporter leur contribution pour éliminer ces obstacles. Il s’agit sans aucun doute d’un changement dans la bonne direction.

Parisa

Working in a field where I’ve historically been at a disadvantage means that I’ve cultivated skills which not only help me navigate the field, but also do my job very well. I have had to pay attention to the smallest details, ask incisive questions, and listen extremely closely in order to best position myself for success. These are skills that make me a better advocate for users, since great UX is built on our ability to pay attention to what their users are saying in order to piece together the optimal solutions. In addition, being an outsider within the field of technology also makes me much more conscientious of inclusivity, and how everything from the way in which my team operates down to the interface that is designed needs to be intentional about creating equitable access and success.

What advice would you give to your 18-year-old self, moving into technology?

Vidya

Je dirais : « Tiens bon, ça va s’arranger. » .

But again, the kind of pressure we put on ourselves to deliver our best day after day, I would only say to take slow down and “smell the roses” – that we are not expected to know everything or have all the answers and it is okay to say, “I don’t know”.  After graduating with a degree in Chemical Engineering when I moved into Information technology, it felt like a personal failure, but I would tell me 18-yo self that it is okay to fail – “Failure” is a verb not a noun.

Parisa

Je conseillerais à celui que j’étais à 18 ans, qui n’avait jamais envisagé de se lancer dans la technologie, d’envisager ce domaine au-delà du simple génie technique. Comme je l’ai mentionné plus tôt, la technologie concerne bien plus les personnes que les logiciels. Si nous mettons l’accent sur notre capacité à créer des liens avec les autres et à favoriser la compréhension, cela nous rend d’autant plus précieux et notre impact d’autant plus positif.

Personal Heroes – Who do you admire?

Vidya

J’ai beaucoup de respect pour Indra Nooyi, ancienne PDG de PepsiCo, et je saisis toutes les occasions qui se présentent pour tirer des enseignements de son expérience.

Parisa

I’m a big fan of Barack Obama. He is someone who also had to navigate a system that was not predisposed to his success, and he leveraged his unique skillset, background, and point of view to inspire and connect with millions of people.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

It sometimes feels like we are living in the age of the reboot.  If you’re a fan of the hit TV show “That 70’s Show,” you know that it’s all about a group of friends navigating the challenges of adolescence in the 1970s and that it’s been rebooted (and updated to the 90s) on a popular streaming service. 

And it’s not alone.  From the good (Cobra Kai anyone?) to the not so popular (did anyone actually see the Knight Rider remake??) there is always an appetite for an update which reflects the current environment and challenges.

That sentiment can also be applied to your organization’s data management and protection strategy – to ensure it stays current and effective in an ever-changing world of emerging technologies and cyber threats.

Avec cette nouvelle année et un regard neuf, voyez si l’un des signes ci-dessous vous parle. Si c’est le cas, vous êtes peut-être dans une position idéale pour élaborer un plan visant à repenser votre approche des données à l’ère du cloud moderne :

  • Outdated & mismatched technologies: Just like the characters on the show were stuck in the 1970s, your data management and protection strategy may be relying on a “frakenstack” of mismatched and outdated technologies that sprawled organically but are now stuck in time and are no longer effective in today’s modern multi-cloud world. It’s important to regularly review and update your technology strategy to ensure that your approach to data growth and retention is not only purposeful and effective, but also provides you powerful protection and controls from the best tools available.
  • Uncertainty around shared responsibility obligations with Cloud Providers and SaaS Applications: If you don’t have a solid understanding of what your obligations are to protect your data under the shared responsibility model, you could end up losing days, weeks, or even months of valuable insights in the event of a disaster situation. In the show, the characters often found themselves in sticky situations that could have been avoided with proper situational awareness & planning. The same is true for your organization’s off-prem data.
  • Insufficient access controls: Whether resulting from innocent human error, or malicious bad actors, your data management and protection measures can often be wide open to catastrophic incident if users have too large a sandbox to play in. Our crew of misfits in “That 70’s Show” often found themselves in trouble due to a lack of boundaries and rules. The same is true for your organization’s data. With proper access controls in place, your data is more protected, your risk profiler is smaller, and you can rest easy knowing that it’s that much harder to have a major incident due to unauthorized individual actions.
  • Lack of employee & org leader education: Just like the characters on the show needed guidance and direction, your employees and cross-functional partners need to be educated on best practices for data protection. Without proper education, your organization is at risk of data breaches and other cybersecurity threats. Do all of your cross-functional partners (HR, Sales, Operations, Dev Ops, etc.) understand the implications and limitations of native SaaS applications and cloud services? Do they have a trusted partner in the IT function to ensure that their workloads are secure and backed up to cover any gaps in the service provider’s shared responsibility model while simultaneously providing upline leadership a single view of all of their distributed corporate data across all platforms and form-factors?

Si l’un de ces signes s’applique à votre organisation, il est temps d’envisager de réactualiser votre stratégie en matière de protection des données.

Just like “That 70’s Show” has stood the test of time, a solid data protection strategy can help your organization stay current and protect its sensitive information. Don’t get stuck in the past – take action to ensure your data is safe and secure.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Zero trust architecture is central to an organization’s security posture to mitigate cyberattacks, and the Defense Department recently released its Zero Trust Strategy and Roadmap1 on its plan to get the DOD to a Zero Trust architecture by 2027.2

A zero trust architecture provides the foundations for micro-segmentation of the IT landscape, access limited with the Least Privilege principle, and all communication to and between the micro-segments being authenticated, audited, and verified3. The underlying philosophy for zero trust is never assume trust, but continuously validate trust, so bad actors don’t get in. Companies, organizations and government agencies need to make sure that even users inside a network can’t do serious damage.

Flag Unusual Behavior

Les principes du « Zero Trust » garantissent que l’accès des utilisateurs est validé et surveillé en permanence en matière d’authentification et d’autorisation, tout en faisant l’objet d’un audit continu. Commvault s’appuie sur des contrôles de sécurité tels que l’authentification multifactorielle pour les tâches administratives quotidiennes, des verrous de confidentialité et le chiffrement des données. L’accès des utilisateurs peut être compartimenté, en refusant explicitement l’accès au niveau CommCell, tout en attribuant des rôles à des groupes de ressources micro-segmentés via des configurations multi-locataires. Les contrôles « Zero Trust » contribuent à limiter les mouvements latéraux internes afin de prévenir la perte de données et tout accès non autorisé à celles-ci.

Apply Zero Trust Controls

Commvault facilite la mise en œuvre des contrôles AAA « zero trust » grâce à sontableau de bord d’évaluation de la santé de la sécurité. Ce tableau de bord offre une vue d’ensemble unique permettant d’identifier les contrôles, de mettre en évidence les risques potentiels au sein de l’environnement de sauvegarde et de recommander des actions interactives pour appliquer ces contrôles.

Add Layers of Security

Afin de renforcer la résilience de votre infrastructure de données, lecadre de cybersécurité du NISTs’articule autour de cinq piliers fondamentaux pour un programme de cybersécurité efficace et global. La prise en compte de ces piliers peut aider votre organisation à élaborer une stratégie complète de gestion des risques. Commvault a intégré ces piliers de sécurité dans ses logiciels et politiques de protection des données, sans alourdir la charge administrative. La plateforme de protection et de gestion des données de Commvault comprend cinq couches de sécurité :

Identifiant

Protéger

Surveiller

Réagir

Récupérer

Notre système de sécurité à plusieurs niveaux repose sur un ensemble de fonctionnalités, de directives et de bonnes pratiques visant à gérer les risques liés à la cybersécurité et à garantir la disponibilité des données. Nous vous aidons à protéger et à isoler vos données, nous assurons une surveillance proactive et des alertes, et nous permettons des restaurations rapides. Des technologies de pointe basées sur l’intelligence artificielle et l’apprentissage automatique, notamment les « honeypots », permettent de détecter les attaques potentielles et de vous alerter dès qu’elles se produisent, afin que vous puissiez réagir rapidement. En mettant vos sauvegardes à l’abri et en garantissant leur restauration dans les délais prévus par vos accords de niveau de service, vous pouvez minimiser l’impact d’une attaque par ransomware et reprendre immédiatement vos activités (tout en évitant de payer des rançons exorbitantes).

Immutability

Protecting and isolating your backup copies is critical for data integrity and security. Therefore, we have taken an agnostic approach to immutability. With Commvault, you do not need special hardware or cloud storage accounts to lock backup data against ransomware threats. If you happen to have Write-Once, Read Many (WORM)-, object lock- or snapshot-supported hardware (which Commvault fully supports), you can still use Commvault’s built-in locking capabilities to complement and layer on top of existing security controls. Commvault’s ability to support layered defenses for securing data sets against ransomware ensures that your organization benefits from a sound cyber recovery-ready architecture. Here are some elements to include in your immutability architecture:

  •  Access locks to isolate copy store against ransomware
  • Immuabilité associée à des verrous de cycle de vie pour réduire les risques, en équilibre avec l’impact sur la consommation
  • Réseau d’isolation par entrefer et dispositifs de commande
  • Gouvernance de la configuration visant à protéger contre les modifications intentionnelles ou accidentelles
  • Concurrent Recovery performance – reduce latency with due importance to speed and cost impact
  • Application automatique des correctifs pour rester à jour, ce qui simplifie la gestion et la maintenance de l’infrastructure de protection des données
  • Alignment with the 3-2-1 data protection philosophy  (3 copies of data, 2 different media, 1 vaulted copy)

Learn more about Commvault’s immutable infrastructure architecture ici.

Cyber Deception Technology

Si la continuité des activités est un élément essentiel de toute stratégie à plusieurs niveaux, une posture de sécurité solide repose également sur une technologie de défense proactive capable de détecter et de contrer activement les menaces inconnues et de type « zero-day ».Metallic® ThreatWiseTMchange la donne en matière de protection contre les ransomwares, en combinant des mécanismes sophistiqués d’alerte précoce et d’intervention rapide avec une protection complète des données. Cette solution permet aux entreprises de toutes tailles de neutraliser les attaques silencieuses avant qu’elles ne causent des dommages, en détectant et en bloquant les attaques « zero-day » les plus furtives, qui échappent aux technologies de détection conventionnelles et contournent les contrôles de sécurité.

A Ransomware Strategy

You need a plan to remain steadfast against ransomware. Beyond simply adhering to zero trust principles and hoping for the best, the ultimate solution can manage and substantially reduce the impact of a ransomware attack. It can reduce costs for your organization by utilizing one centralized management platform, so security teams don’t have multiple product points to log in and out of. It can increase the visibility of your data through a single landscape to minimize complexity for your teams. And finally, it can protect what matters most by providing the broadest workload coverage and rapid recovery capabilities through a unified approach. For all of this to happen, a solution must embrace Zero Loss Strategy.

Become Less Vulnerable

En réalité, votre entreprise doit se préparer et prendre des mesures proactives pour protéger vos données, tout en collaborant avec un prestataire proposant des solutions de protection contre les ransomwares et de Recovery des données. Êtes-vous suffisamment préparé ? Répondez à notreévaluation gratuite des risquespour le découvrir. Nous vous invitons également à lire notreeBookintitulé « Comprendre les rôles et les responsabilités de chaque équipe dans la lutte contre les ransomwares ».

References
1. Département américain de la Défense (DOD), « Le Département de la Défense publie sa stratégie et sa feuille de route en matière de Zero Trust », novembre 2022
2. C. Todd Lopez, DOD News, « Le DOD présente sa feuille de route vers la cybersécurité grâce à l’architecture Zero Trust », novembre 2022
3.Commvault, Vidya Shankaran, Ransomware Defense in Depth – Best Practices for Security and Backup Data Immutability, October 2021

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

I’m so proud to announce the inspiring Vaulters who just won our FY’23 Q3 CEO Living Our Values Awards. 

Here at Commvault, our four values – we connect, we inspire, we care, we deliver – are always top of mind! 

This week we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work as they live our values every day. 

I’m so proud to announce our FY’23 Q3 CEO Living Our Values Award winners:

Christina Manning
, directrice des opérations financières

Mathew Ericson
chef de produit senior

Jason Gerrard
, directeur de l’ingénierie commerciale

Parisa Bazl
, directrice du développement UX

Sam Hernandez
, directeur de la gestion des installations


Tous ces lauréats constituent un exemple inspirant et incarnent ce que signifie véritablement être un « Vaulter » !

To learn more about what it’s like to work at Commvault, check out our site de carrières.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Le défi que posent aujourd’hui les journaux d’audit

One major challenge customers face with audit logs is that they’re not aggregated in a central location that is fully immutable. SaaS applications specifically tend to have their audit logs kept within the SaaS application itself, oftentimes with only a 90-day history.

Cela implique soit la mise en place de scripts complexes, soit l’exportation périodique des fichiers journaux de chaque application vers un emplacement centralisé, afin de respecter les objectifs de l’entreprise en matière de conformité et de sécurité.

This is a heavy lift on IT departments, and with hundreds of applications under management in any environment, it’s oftentimes not feasible to accomplish this completely. 

Consolidation des journaux d’audit avec AWS CloudTrail Lake

Avec le lancement de CloudTrail Lake, AWS a simplifié la gestion des journaux d’audit provenant de sources diverses. CloudTrail Lake est un « data lake » géré dédié à la sécurité et à l’audit qui permet aux entreprises d’agréger, de stocker de manière immuable et d’interroger les événements enregistrés par AWS CloudTrail.

This can be done across different regions and accounts – and is backed by a 7-year default retention policy to help you meet compliance requirements.

Les clients peuvent importer et analyser des événements selon un schéma compatible avec AWS CloudTrailà partir de Clumio, ainsi que d’autres sources tierces et non AWS, afin de rationaliser les audits, les enquêtes de sécurité et le dépannage opérationnel.

Une sécurité des données simplifiée grâce à Clumio et AWS CloudTrail Lake

AWS et Clumio se sont associés pour proposer cette intégration destinée à CloudTrail Lake, qui vous permet de simplifier et d’optimiser le processus de consolidation des données d’activité.

Through the newly launchedPutAuditEvents API for AWS CloudTrail Lake, Clumio has created a simple integration to capture user activity information and events from your Clumio environment alongside the AWS systems you are protecting with Clumio.

Once the integration is enabled, you’ll be able to capture and store audit activity across various categories. This will allow you to easily answer many security and compliance-related questions across various categories such as:

  • Authentication– Was there a high volume of unsuccessful logins to the Clumio console, indicating a brute force entry attempt or an issue with your Single Sign On provider? 
  • User Management– When was a user added to the Development Organization in Clumio, and when were they given the backup Admin role?
  • Backups– When was a backup policy accidentally changed? This will help you quickly determine when a backup policy was changed or created to ensure you’re always meeting both long-term compliance requirements and maintaining any minimum required RPO’s (recovery point objectives).
  • Restores– Is someone browsing the CEO’s email history, or trying to recover Payroll information from a system backup? This activity is tracked even if a restore hasn’t been initiated.
  • S3 Protection Groups– When was a new S3 production bucket added to a protection group? Why was a bucket removed? 

Configuration et architecture des journaux Clumio sur AWS CloudTrail Lake

First, in Clumio, navigate directly to the Audit Report page. You’ll see a link to set up the integration in the upper right corner. You must have the Super Admin role to set up the integration.

Intégration d’AWS CloudTrail

Sur l’écran suivant, vous verrez un identifiant externe propre à votre intégration avec CloudTrail. Copiez cette valeur ; nous allons ensuite configurer directement la suite de l’intégration dans AWS.

After logging into the AWS Console, navigate to CloudTrail, where you will find a new Integrations section under Lake.Click on the Add Integration button to configure the Clumio integration.

You’ll first need to give a name to channel that Clumio will use to send the audit logs data through, and then selectClumioas the source.

Next, we will need a place to deliver the Clumio audit logs and determine how long you would like to get the logs. You can either use an existing event data store or create a new one for this integration.

Next, we’ll configure the resource policy which is what will provide Clumio with a secure way to send the audit log data across the channel. This is where we will paste in the external ID we copied from the Clumio interface.

Lastly, apply any tags you may want to add to the resource and select Add Integration.

The integration is now set up; however, we have one final step. We need to copy the Channel ARN value and bring it back to Clumio, so we can complete the setup.

Once you add the Channel ARN value, click on Connect to CloudTrail

Un premier événement sera envoyé vers le magasin de données CloudTrail Lake, ce qui vous permettra de vérifier la connectivité. À partir de là, vos événements d’audit Clumio seront régulièrement envoyés vers le magasin de données CloudTrail Lake.

Additionally, you’ll be able to monitor the health of the integration at any time through the Audit Log report.

Vous trouverez ci-dessous la liste de toutes les catégories d’événements d’audit transmises à CloudTrail dans le cadre de cette intégration :

  • Authentification –
  • Source de données
  • Intégration automatisée des charges de travail, guidée par
  • Protection S3
  • Restauration
  • Backup
  • Utilisateurs
  • Unité organisationnelle
  • Configuration KMS
  • SSO/MFA
  • Modèle CloudFormation

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In the handful of months since I became Commvault’s first Chief Partner Officer, I’ve been reading the terrain, talking with our partners, and figuring out how we can better help them in the year to come. I’ve analyzed everything from program incentives to partner enablement and everything in between to plot our course. There is, however, one thing I didn’t consider. The intangible effect of being one of the coolest kids on the block.

For the 7th year in a row, Commvault has been named to CRN’s annual Cloud 100 list! Honoring the 100 Coolest Cloud Companies for 2023 across five key categories: infrastructure, monitoring and management, storage, software, and security, we rated among the Top 20 in the storage category based on CRN’s analysis.

To make the list, which is considered by most in the partner world as the trusted resource for solution providers looking for technology vendors best positioned to support their cloud product and services needs, Commvault had to prove its commitment to channel partners as well as demonstrate our innovation in the development of cloud-based technologies.

This wasn’t difficult for Commvault, as we’re a leader in data management, protecting data wherever it lives – whether on-prem, in the cloud, or in a hybrid cloud environment. We support the broadest range of workloads in the industry and most recently expanded our cloud protection for Kubernetes, positioning us as an Outperformer and Leader inGigaOm’s Radar for Kubernetes Data Protection.

“In today’s remote-facing enterprise environment, cloud services have become the critical component needed to build comprehensive and secure IT solutions,” said Blaine Raddon, CEO, The Channel Company. “The companies selected for this year’s Cloud 100 list have shown time and again that they support partners in the ever-evolving cloud computing business with state-of-the-art products and services. Our team commends those on this year’s list and looks forward to watching them drive positive change in the cloud domain throughout the year.”

CRN’s Cloud 100 list will be featured in the February 2023 issue of CRN magazine and online at www.crn.com/cloud100.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

La Semaine de la protection des données est un événement annuel qui vise à sensibiliser le public à l’importance de la protection et de la sécurité des données. L’objectif de cette semaine est d’informer les particuliers et les organisations sur l’importance de la protection des données à caractère personnel et de leur fournir les outils et les ressources nécessaires pour y parvenir efficacement.

We’ve brought together three opinion leaders to discuss the key data privacy challenges that face businesses around the world and how to overcome them.

Bill Mew, Data Privacy Champion and CEO of the Crisis Team is joined by Jakub Lewandowski – Global Data Governance Officer, Commvault and Thomas Bryant – Product Marketing Director, Commvault as they discuss;

  • Tendances et enjeux actuels en matière de confidentialité et de sécurité des données
  • Législations et réglementations relatives à la protection des données, telles que le Règlement général sur la protection des données (RGPD) dans l’Union européenne et la Loi californienne sur la protection de la vie privée des consommateurs (CCPA) aux États-Unis, ainsi que les directives DORA et NIS2
  • Best Practices for protecting data – including a modern (and tested) data protection strategy and conducting regular risk assessments
  • The current state of Data Privacy policy and legislation compliance/ enforcement  

Pour en savoir plus sur ces sujets, consultez notre série d’articles de blog consacrée à la Semaine de la protection des données, désormais disponible

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

La Journée mondiale de la protection de la vie privée, célébrée chaque année le 28 janvier, nous rappelle l’importance de la protection des données personnelles à l’ère numérique. À mesure que la technologie progresse et que de plus en plus d’informations personnelles sont partagées en ligne, les particuliers et les organisations doivent prendre des mesures pour protéger leurs données.

New regulations, such as DORA (Digital Operational Resiliency ACT), mandate that organizations create plans for risk management, incident reporting, and resilience testing. These regulations outline policies for data management, including encryption, data locality, and data lifecycles. Gartner prévoit, “by 2023, 65% of the world’s population will have its personal data covered under various privacy regulations, and companies need flexible solutions that can adapt to the multitude of legislation.” Navigating this complex environment can be challenging for both individuals and companies.

Data Privacy is protecting personal information and giving individuals control over how their data is collected, used, and stored.  On the other hand, data protection refers to the technical and organizational measures put in place to protect data (including personal data) from unauthorized access, use, alteration, or destruction. Data protection encompasses Data Privacy and other areas, including backup & recovery, disaster recovery, data security, and a host of other areas.

To help address that complexity, let’s spend some time reviewing the Top 10 topics to consider when managing Data Privacy and Data Protection.


1.Data Protection Strategy
2.Chiffrement
3.Multi-Person Authentication
4.Stockage immuable
5.Souveraineté des données
6.Data Governance & Discovery
7.Classification of data
8.Conservation des données
9.Resilience plan testing & incident response
10.Risk Assessment

1. Data Protection Strategy

Organizations should start by creating or updating a Data Privacy, Backup & Recovery, and Disaster Recovery plan as part of an overall data protection strategy. There are many facets to a reliable data protection plan and how it specifically relates to protecting the private data your customers have shared with your organization.

2. Encryption

Le chiffrement est un élément essentiel de la protection des données et de la protection des données à caractère personnel. Le chiffrement des données au repos et en transit permet d’empêcher tout accès non autorisé aux informations personnelles. Cela revêt une importance particulière pour les organisations qui traitent de grandes quantités de données à caractère personnel, telles que les prestataires de soins de santé et les établissements financiers. Les données ne résident plus uniquement dans nos centres de données d’entreprise, car la plupart des organisations disposent d’un ou plusieurs clouds publics dans lesquels sont stockées leurs charges de travail et leurs données. Sécuriser les données par le chiffrement tout au long de leur cycle de vie permet de limiter les risques liés à d’éventuels attaquants.

3. Multi-person authentication

Au-delà de la protection des données par cryptage, les organisations doivent protéger leurs systèmes contre les attaques malveillantes. Le recours à l’authentification à plusieurs niveaux (MPA) pour vos systèmes de protection des données garantit que les tâches critiques nécessitent plusieurs validations de la part d’utilisateurs préalablement autorisés. Souvent négligée, cette méthode constitue l’un des moyens les plus simples d’empêcher des actions telles que l’exfiltration ou la suppression de données.

4. Immutable Storage

Le stockage immuable permet d’enregistrer des données, qu’elles soient privées ou non, sans qu’il soit possible de les modifier ou de les supprimer par la suite. Le fait que ces données ne puissent être ni falsifiées ni altérées garantit le maintien de leur intégrité. Les exigences en matière de stockage immuable s’imposent rapidement comme une norme dans les réglementations relatives à la gouvernance des données, telles que le RGPD, la loi HIPAA et d’autres. Associé à la MPA, ce stockage permet de créer des niveaux de stockage hautement sécurisés, parfaitement adaptés à la conservation de données confidentielles et privées.

5. Data Sovereignty

Organizations should consider regulations surrounding private data storage when developing a data protection strategy. This includes the location of data storage and compliance with regulations regarding data sovereignty. For example, a cloud-based workload on GCP in Europe or containing EU citizens’ data must comply with EU regulations. Anywhere that private data may reside, even if temporary, may be required to be in a specific region under regulatory requirements. Commvault helps to address this concern in its latest release, allowing customers to select which specific region they will leverage for snapshot & data protection storage vs. multiple regions that cost more and may have different regulatory requirements.

6. Data Governance & Discovery

In a recent survey, 57 % des RSSI admit they don’t know where some or all their data is or how it is protected! As this amount of private data continues to grow, the sheer number of regulations expands exponentially, and we are confused about what and how we should protect our data.  As a result, organizations need to understand their data, where it is, and what is at risk.  Being able to prioritize data based on your organization’s policies, priorities, and applicable regulations is critical to protecting the data. You cannot protect what you don’t know about!

7. Classification of data

Savoir quelles données existent et où elles se trouvent ne constitue qu’une partie de la solution. Les entreprises doivent déterminer quelles données sont des données privées de clients, essentielles à l’activité, etc., en fonction de leur importance pour votre entreprise et vos clients. Se contenter de protéger les données sur site peut vous faire passer à côté de certaines données clients critiques hébergées dans votre solution CRM basée sur le SaaS. À ce propos, vous ne devez pas compter uniquement sur votre fournisseur SaaS, ni même sur vos fournisseurs de cloud IaaS, pour assurer la protection de vos données. Ceux-ci peuvent proposer des accords de niveau de service (SLA) et un certain niveau de redondance, mais cela ne remplace pas un plan de protection des données solide. La gestion de la classification des données n’est pas une opération ponctuelle, car le volume de données augmente de manière exponentielle chaque année.

8. Retention

It is paramount to know what data exists and how important it is, but how long does it stay relevant? This is a hard question to answer for most organizations and one that can be seen every year when buying ever-increasing storage systems to house corporate data. The ability to assign an expected lifespan to data can significantly impact your organization’s bottom line AND protect your customers’ private data. Having systems in place to automatically find, classify, and set retention will reduce the likelihood of data sprawl, reduce the amount of time to recover unused data, and reduce costs. If you are looking for a great place to start efficiently managing your governance, risk, and compliance, read through Commvault’s unique approach to gestion unifiée des données.

9. Resilience plan testing & incident response

Resilience plan testing often referred to as a runbook, is an often-overlooked area of a data protection strategy. Creating or updating an outdated plan can take time and effort. Partnering with solution providers or strategic data protection companies with experience in creating a plan can significantly reduce the time it takes to get current. While it may be trivial to think runbooks are passe, I’ve found that when an actual DR event or ransomware attack hits, they are the GO-TO asset you want in your arsenal of tools. A regular cadence of updates creates an organizational posture that is ready to face data security threats head-on.

10.  Risk Assessment

As mentioned with runbook, consider working with strategic vendors to perform a risk assessment semi-annually or annually. Scheduled reviews can help build the muscle memory for a solid data protection and data privacy mindset. The benefit of working with well establish data protection & data privacy vendors is they are up to date on the latest security threats and mitigation strategies.

By implementing this list of considerations and routinely refreshing your resilience plan, you can be confident that personal information is secure and compliant with the latest privacy regulations. If you aren’t sure where to start but need help from a company that can answer all these questions.

Commvault est là pour vous aider ! Nous ajoutons sans cesse de nouvelles fonctionnalités, notamment nos dernières améliorations en matière de souveraineté régionale des données pour les instantanés de sauvegarde, les certifications sectorielles, les capacités de stockage immuable, et bien plus encore.

Head over to our community to En savoir plus or take a test drive today https://www.commvault.com/request-demo

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Happy 2023 Data Privacy Week!

Just as everyone started to get more or less cozy with the regulatory landscape in data privacy/protection and individuals and businesses learned to navigate the shallow waters of data subject requests, risk management, and impact assessments – BOOM – another tidal wave of regulatory requirements and new challenges rushed in!

2023 is the perfect moment to start internalizing new acronyms (get ready for #NIS2, #DORA, #DPDPB, #CPRA, #CCPA, #CPA, #CDPA, #UCPA, #VCDPA, #ADPPA, #PrivacyPenaltyBill) and legislative acts they stand for.

L’objectif sous-jacent des changements à venir est de renforcer et d’améliorer les dispositifs de cybersécurité des différentes organisations et de gérer plus efficacement les cyberrisques en constante évolution.

Voici un aperçu général de certaines évolutions juridiques observées à travers le monde :

  • EU – Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2)
  • EU – Regulation on digital operational resilience for the financial sector (DORA)
  • US – State & Federal privacy laws
  • India – Digital Personal Data Protection Bill (DPDPB)
  • Australia – Privacy Penalty Bill & overhaul of the Privacy Act 1988

NIS2

According to ENISA, the general spending on cybersecurity is 41 % lower by organisations in the EU than by their US counterparts. With the arrival of NIS2, this ratio is expected to shift to cover this enormous gap at least partially. Conservative estimates are that NIS2 entry in force will translate into a ~22% increase in ICT spending over a 3–4-year period.

La directive NIS2 a été publiée juste avant la fin de l’année, et les États membres de l’UE disposent désormais de 21 mois pour transposer les exigences et les mécanismes qu’elle décrit dans leur législation nationale. La directive NIS de 2016, malgré ses lacunes, a constitué une pierre angulaire du renforcement des capacités des États membres en matière de cybersécurité. Désormais, la directive NIS 2 élargira le champ d’application et la liste des organisations concernées. On estime que jusqu’à 160 000 organisations seront soumises à cette nouvelle législation, notamment les fournisseurs de services numériques (plateformes et services de centres de données), les fournisseurs de réseaux et de services de communications électroniques, ainsi que les secteurs de l’industrie manufacturière, de l’agroalimentaire et du secteur public.


NIS2 aims to strengthen cybersecurity postures by, amongst other: improving cybersecurity governance, addressing the security of supply chains, streamlining reporting obligations (early warnings/shortened notification periods), and introducing more stringent supervisory measures and stricter enforcement requirements.

Que pouvez-vous faire dès maintenant ?

  • First, try to understand which obligations will apply to your organization and in which compliance bucket your organization will fall into: “Essential Entity,” “Important Entity,” or maybe “other.”
  • Ensuite, voyez si vous pouvez créer des synergies et tirer parti des mesures techniques et organisationnelles existantes mises en œuvre lors de précédentes initiatives de mise en conformité (par exemple, le RGPD, la directive NIS1, etc.)
  • Commencez à rechercher les partenaires adéquats, capables de soutenir efficacement vos efforts de mise en conformité. Discutez avec vos fournisseurs de l’approche la mieux adaptée à votre organisation.
  • Enfin, commencez à prévoir une augmentation des dépenses afin de combler les lacunes restantes. Le non-respect de la conformité pourrait entraîner des amendes administratives pouvant atteindre 10 millions d’euros ou 2 % du chiffre d’affaires annuel mondial total de l’organisation.


DORA

DORA aims to achieve “a high common level of digital operational resilience,” mitigating cyber threats and ensuring resilient operations across the EU financial sector. It will become directly applicable from Jan 17th, 2025. It will impact the financial sector (banks, insurance companies, investment firms) and its ICT providers (i.e., cloud platforms) – roughly around 22 000 organizations.

Les nouvelles exigences imposées par la DORA se traduiront concrètement par une révision et une mise à jour des pratiques de gestion des risques. Les clients du secteur financier devront transférer autant de risques réglementaires que possible à leurs prestataires TIC ou mettre en œuvre différentes stratégies d’atténuation des risques. Dans tous les cas, les prestataires TIC devront être en mesure de garantir le respect des exigences de la DORA. L’ensemble du secteur devra également réévaluer ses relations contractuelles avec ses fournisseurs. La DORA intégrera des exigences relatives aux contrats entre les entreprises financières et leurs prestataires TIC essentiels, notamment en ce qui concerne le lieu de traitement des données, la description des accords de niveau de service, les obligations de déclaration, les droits d’accès et les circonstances pouvant entraîner la résiliation du contrat.

In a separate post – Commvault’s Product Team will perform a more technical deep-dive into DORA’s requirements related to detection (art. 10), response and recovery (art. 11), and backup (art. 12).


US data privacy laws – CPRA/CCPA, CPA, CDPA, UCPA, VCDPA, ADPPA

As of January 1st, 2023, California Privacy Rights Act (CPRA) amendments to the California Consumer Privacy Act 2018 went into effect. Many temporary exemptions in place expire, imposing additional obligations on companies dealing with California residents’ personal information, e.g., regarding employment-related personal data, opt-out from selling personal information.

2023 is also the year when the Colorado Privacy Act (CPA), The Connecticut Data Privacy Act (CDPA), The Utah Consumer Privacy Act (UCPA), and The Virginia Consumer Data Privacy Act (VCDPA) will become effective. Legislative fragmentation risk is imminent and substantial, and this is the kind of risk that caused the European Union to harmonize the regulatory approach. Let us see whether the same will be true in 2023 in the case of the American Data Privacy and Protection Act (‘ADPPA’) – a proposal for a federal and general data privacy law.

India – DPDPB

Indian legislators plan to introduce a very ambitious Digital Personal Data Protection Bill (DPDPB) this year. When enacted, long-awaited legislation will undoubtedly impact all kinds of organizations due to India’s role as a tech powerhouse and a global outsourcing hub.

Australia – Privacy Penalty Bill & overhaul of the Privacy Act

Australian authorities announced yet another complete overhaul of the Privacy Act dated 1988. The current legislation was summarized as “out of date and not fit for purpose in the digital age.”

Entre-temps, toujours en 2022, l’Australie a adopté la loi sur les sanctions en matière de protection de la vie privée (Privacy Penalty Bill), qui a relevé les sanctions liées à la protection de la vie privée à des niveaux comparables à ceux instaurés par le RGPD (jusqu’à 50 millions de dollars australiens) et a élargi les pouvoirs réglementaires du Bureau du commissaire australien à l’information (OAIC) et de l’Autorité australienne des communications et des médias (ACMA).

Summary

Le compte à rebours incessant de la conformité vient de recommencer. Des équipes pluridisciplinaires, composées de professionnels de l’informatique, de la conformité, de la protection des données, du droit et d’analystes métier, consacreront un temps considérable à analyser l’impact de la vague de changements législatifs apparue à la fin de l’année dernière et qui se concrétisera tout au long de l’année 2023.

Sachez que les évolutions législatives présentées ici pourraient être plus complètes. Vous pouvez toutefois être certain qu’elles deviendront des thèmes de discussion incontournables, non seulement en 2023, mais aussi dans les années à venir.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Dans le cadre d’une série de trois articles publiés à l’occasion de la Journée de la protection des données 2023 (voir les articles deJakub LewandowskietThomas Bryant ), Bill Mew argues that there is a real enforcement problem – it’s like the ‘Wild West’ out there.

Les politiques, les cadres et les règles ne sont utiles que si elles sont respectées, tout comme les réglementations et les lois n’ont aucun sens si elles ne sont pas appliquées. Le problème dans le domaine de la protection des données et de la cybersécurité est que, là où des règles devraient être appliquées, elles sont souvent ignorées, et là où des lois ont été adoptées, leur application doit être renforcée.

Les RSSI (responsables de la sécurité des systèmes d’information) ont une tâche ingrate. Le personnel est généralement réticent à respecter les mesures de cyberhygiène que le RSSI cherche à mettre en place, mais lorsque leur manque de discipline entraîne une violation de sécurité, ces collègues s’empressent de rejeter la faute sur le RSSI. De plus, alors qu’il existe des réglementations coûteuses et complexes à respecter ainsi que des règles strictes en matière de signalement des violations, les autorités, loin d’aider à gérer les incidents ou à appréhender les véritables coupables, se contentent d’utiliser ces signalements pour déterminer le montant des amendes.

Functional, Cultural Mismatch

Si on leur posait la question, la plupart des collaborateurs s’accorderaient à dire que les cybermenaces constituent un enjeu majeur, mais dans leur travail quotidien, ils se concentrent sur des indicateurs axés sur le chiffre d’affaires ou le retour sur investissement (ROI). Ce sont ces indicateurs qui servent à évaluer leurs performances individuelles et celles de leur service, et sur lesquels s’appuient les politiques d’incitation mises en place à l’échelle de l’entreprise.

The CISO is instead focused on return on risk (ROR). Based on the allocated budget and the organisation’s risk appetite, the CISO focuses on maximising security and minimising risk.

The mismatch between the CISO’s ROR orientation and just about everyone else’s ROI orientation can put the CISO at odds with the rest of the management team. They may not only become isolated (what I term CISOlation) but can also be a scapegoat when things go wrong – even when warnings are ignored.

Perverse regulatory incentives

In an accompanying article, Jakub Lewandowski [LINK] has explored the raft of new privacy and cybersecurity laws expected to add to a considerable regulatory burden. The problem is that regulation without enforcement is not just pointless but counter-productive. After all, only responsible companies will comply with these regulations, and for them, it represents a cost or compliance tax. Meanwhile, irresponsible ones often choose not to abide by the rules. If they believe that there is little or no risk of enforcement, then this is a cost-saving and risk-free source of competitive advantage.

Le non-respect des réglementations est généralisé et émane des plus hautes sphères, comme en témoignent les nombreux articles de presse faisant état d’incidents liés aux données ou d’amendes infligées aux géants de la technologie. Ces amendes ne semblent pas avoir d’effet dissuasif ; elles sont au contraire considérées comme un coût supplémentaire par les géants de la technologie et par de nombreuses autres entreprises qui ont eu la malchance d’être victimes d’un incident lié aux données.

Again, responsible firms that did their best to take reasonable measures but were unfortunately unable to prevent mistakes or attacks run the risk of being fined once they notify the local regulator. Meanwhile, irresponsible ones who choose not to comply will simply avoid reporting incidents and attempt to cover them up instead to avoid fines. Fines have, therefore, become more of a indicateur tardif des déboires subis par les entreprises responsables rather than of misbehaviour by irresponsible ones.

Record of Regulatory Inaction

Most BigTech firms, attracted by a favourable tax regime, have opted to base their European headquarters in Ireland. The local regulator, DPC Ireland, is therefore responsible for ensuring that they comply with GDPR and other such regulations. Whether down to inadequate funding, reluctance to rock the boat, or simply out-gunned and out-lobbied by the BigTech firms, DPC Ireland has been seen as ineffective in holding them to account.

In one notable case, measures it failed to take against Facebook were eventually resolved in the European High Court under the Schrems I and Schrems II rulings. When it still failed to take action and apply these rulings, DPC Ireland was sanctioned by the European Parliament in a vote de 451 voix contre 1. Lorsque de nouvelles pressions exercées par les régulateurs du reste de l’Europe l’ont finalement contrainte à agir après deux ans de retard, l’amende qu’elle a infligée à Facebook était si faible qu’elle a dû être multipliée par dix sous la pression des autres régulateurs.

The EU Ombudsman Emily O’Reilly eventually opened an inquiry into the European Commission’s monitoring of how data protection rules are applied in Ireland. Eight months later, the Irish Council of Civil Liberties (ICCL) criticised the EU for its continued failure to properly monitor Ireland’s GDPR enforcement while “the fundamental rights of all Europeans hang in the balance.” There are now moves afoot to strip Ireland of its responsibility for regulating the BigTech firms and centralise such enforcement instead.

Ineffective Global Policing

Meanwhile, the number and sophistication of cyber-attacks are increasing exponentially, as is the cost of remediation. The World Economic Forum (WEF) has recently not only called for more widespread use of cybersecurity ‘fire drills’ to test cybersecurity and incident response capabilities but is also championing the need for global rules to crack down on cybercrime.

On estime que les pertes causées par toutes les formes de cybercriminalité, y compris les coûts de Recovery et de réparation, se sont élevées à 3 000 milliards de dollars en 2015 et à 6 000 milliards de dollars en 2021, et qu’elles pourraient atteindre jusqu’à 10 500 milliards de dollars par an d’ici 2025.

Cyber insurance isn’t the answer. Rapidly increasing premiums mean that it is out of reach to most buyers, but even those who can afford it often find it’s not worth it. At the same time, cyber insurance cannot be expected to cover systemic problems, and in any case, it has the perverse effect of potentially making bad problems even worse.

While almost all nations have signed up for United Nations agreements on combatting crime, including la cybercriminalité, some nations turn a blind eye and instead provide safe havens for cybercriminals to operate from. While most la cybercriminalité originates from countries like Russia, Iran, or North Korea, such activities are not confined to these rogue nations and continue closer to home. In addition, countries like China have significant espionage operations, and the United States is responsible for a great deal of global mass surveillance – all of which contravenes GDPR and a host of other laws.

We need to start with mandatory data breaches and cyber theft reporting. This has begun in the US with 2022’s Cyber Incident Reporting for Critical Infrastructure Act and in the EU with 2018’s Directive on Security Network and Information Systems. Still, there are also a host of other regulations that mandate telecom payment services, medical device manufacturers, and critical infrastructure providers to report breaches.

Once we have better data on the problem, we can focus on improving international investigation, prosecution, and adjudication efficiency and effectiveness. The United Nations Office on Drugs and Crime is promoting a Cybercrime Programme which has the following aims:

  • Renforcer l’efficacité et l’efficience des enquêtes, des poursuites et des procédures judiciaires relatives à la cybercriminalité, en particulier l’exploitation sexuelle des enfants en ligne et les abus sexuels à leur encontre, dans le respect d’un cadre solide en matière de droits de l’homme.
  • Une réponse efficace et performante à long terme de l’ensemble des pouvoirs publics face à la cybercriminalité, comprenant notamment une coordination nationale, la collecte de données et des cadres juridiques efficaces, débouchant sur une réponse durable et un renforcement de l’effet dissuasif.
  • Un renforcement de la communication, tant au niveau national qu’international, entre les pouvoirs publics, les forces de l’ordre et le secteur privé, ainsi qu’une meilleure sensibilisation du public aux risques liés à la cybercriminalité.

These are laudable goals. However, we are a long way from victims of crime being able to pick up the phone to police at the local, national, or international level with any expectation of getting either practical assistance or justice. The reality is that when it comes to cybercrime, aside from private sector incident response specialists, you’re on your own.

  • Le personnel fait rarement preuve d’une discipline suffisante en matière de cyberhygiène
  • Les autorités de régulation ne font pas preuve d’initiative pour repérer et lutter contre les cas de non-conformité
  • Les criminels gagnent en assurance, en agressivité et en sophistication
  • La police est dans l’impossibilité d’intervenir contre les criminels qui opèrent depuis des refuges sûrs
  • Et les RSSI sont systématiquement désignés comme boucs émissaires lorsque les choses tournent mal

In this ‘Wild West’ environment, there isn’t any cavalry going to the rescue, so you are expected to be adequately armed and ready to defend yourself. Take hints from Thomas Bryant’s article and learn how to deal with it best. There is no substitute for getting your cybersecurity and incident response right.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

As part of our “Get to know your customers day” series, we’re taking a deeper look at Swinerton Inc, a large national construction company who is pursuing a cloud data management program to drive versatility, sustainability and to free up company resources.

IT Manager, Brandon Marrott gives an insight into Swinerton’s data modernization journey which includes cloud transformation and embracing SaaS flexibility.  He also describes operating a hybrid cloud environment through the need to retain a number of company data assets on prem and how Swinerton manages their entire data estate, including SaaS, with Commvault.

https://play.vidyard.com/U5fZTkcgxdb7v9we3WJghp

What does it mean to go to the cloud?

Selecting the right cloud transformation partner

https://play.vidyard.com/oUYbtkBhyzYRoVibhsaWGm
https://play.vidyard.com/zwLtwiwBcsPG15DN2u5L8L

Relever les défis et gérer avec souplesse un parc de données SaaS en pleine expansion


Faced with increased pressures, including an uncertain economic environment, IT teams are constantly finding ways to reduce costs or increase overall efficiency – all while supporting an evolving data environment.

Découvrez d’autres exemples illustrant comment les clients de Commvault utilisent des services de protection des données modernes et innovants, notamment notre offre DPaaS Metallic, pour atteindre leurs objectifs de transformation numérique :https://www.commvault.com/digital-transformation-changes-everything-when-it-comes-to-data.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Qu’il s’agisse d’atteindre les objectifs de développement durable ou de gagner en efficacité, tout en soutenant l’innovation, les équipes informatiques auront un rôle majeur à jouer en 2023.

Découvrez notre sélection des priorités informatiques de nos partenaires et clients pour 2023 et donnez-nous votre avis sur les réseaux sociaux.

Alan Atkinson, Chief Partner Officer – Concentration on highest value projects


2023 will continue to be challenging for companies from an economic perspective, especially those that are neither profitable nor public – leading many organizations to seek opportunities for cost reductions.

Il y aura inévitablement des réductions budgétaires et, à terme, quelques échecs ; les partenaires et les clients se montreront réticents à adopter les solutions proposées par des fournisseurs dont la stratégie d’avenir n’est pas clairement définie. Cette situation, combinée à diverses pressions inflationnistes, obligera les partenaires à se concentrer sur la mise en œuvre des projets présentant la plus grande valeur ajoutée. Les ransomwares, la migration vers le cloud et la transformation numérique resteront des priorités bénéficiant d’un financement, tandis que d’autres domaines d’activité seront probablement relégués au second plan. La consolidation sera essentielle pour répondre à ces besoins. Les partenaires et les clients ne rechercheront pas davantage de fournisseurs, mais plutôt des fournisseurs proposant davantage de solutions. Ils miseront davantage sur des choix plus ciblés, en s’associant à des fournisseurs offrant une couverture et un support plus étendus, dans le cadre de modèles de prestation rentables.

Darren Yablonski, Sr. Director, Sales Engineering, Canada, U.S. SLED, LATAM – Cyber Security, AI and Regulation


A top, if not the top IT priority for organizations in 2023 will most certainly be cybersecurity. Significant amounts of IT budget spend will be allocated and invested in technologies to prevent, detect and recover from inevitable cyberattacks not if, but when they occur. As cloud adoption in a SaaS (Software as a Service) model continues to proliferate the market, organizations will leverage solutions that provide proven piece of mind knowing their data is safe and recoverable in a timely fashion. Trust will be given to organizations that can clearly articulate cybersecurity best practices that align to a customer specific use case and objectives.

Continuing on the theme of cybersecurity, emerging technologies and trends will be inclusive of both AI (artificial intelligence) and automation. Organizations typically have predictable network and data usage patterns. As data continues to grow exponentially within the realm of the “internet of things” and those patterns deviate within a network or data repository, humans simply cannot keep track of anomalies in real time. As such, Security Information and Event Management (SIEM) solutions that collect, process, analyze and report threats in an expedited and accurate manner will continue to become more ubiquitous. Integration and adoption of such technologies within a zero-trust architecture will be of greater top of mind for CISO’s and security specialists as the years progress.

Comme mentionné précédemment, la consommation de données continuera de s’orienter des infrastructures sur site vers les applications cloud utilisant un modèle SaaS, en fonction des cas d’utilisation. Les solutions hybrides, combinant environnements sur site et cloud, continueront d’exister pendant plusieurs années, les entreprises cherchant à concilier et à garantir à la fois l’immuabilité des données et la rapidité de Recovery de la manière la plus rentable possible. À mesure que de nouvelles réglementations spécifiques aux pratiques de sécurité des données continueront d’évoluer, les solutions de gestion des données offrant un ensemble complet et exhaustif d’outils répondant à ces pratiques évolueront elles aussi. En résumé, alors que le paysage des menaces informatiques ne cesse de s’étendre et de gagner en complexité, les organisations qui s’efforcent de répondre à cette complexité pour leurs clients se concentreront sur le développement de solutions logicielles plus diversifiées et plus étendues, capables de simplifier la récupérabilité et de garantir la précision des rapports, quel que soit l’emplacement des données.

Katharine Colucci, Associate Solutions Marketing Manager – Corporate Sustainability


The IT organization will take steps to lower the carbon footprint of its data to support corporate sustainability goals. Adopting more sustainable business practices has become a strategic priority of organizations worldwide as they become increasingly aware of how important sustainability efforts are to the success of the business. In fact, Gartner predicts that by 2025, 50% of CIOs will have performance metrics tied to the sustainability of the IT organization. IT teams will need to take steps to reduce the carbon footprint of their data through responsible data management practices, to support overall corporate sustainability goals. Responsible data management practices make it possible to control the total amount of data produced, thereby reducing the energy needed to create, store, manage and protect it.

Commvault supports our customers wherever they are on their sustainability journey, providing opportunities to mitigate their carbon footprint while reducing costs and maximizing the efficiency and security of their data management practices. To learn more about how Commvault is helping customers take a sustainable approach to intelligently manage data, visit Commvault.com/corporate-sustainability.

Gartner, votre vision des technologies durables est-elle trop restrictive ?, septembre 2022

Jason Gerrard, Director, International Sales Engineering – AI/ML and Automation


À mesure que la population vieillit, il devient de plus en plus difficile pour les entreprises de recruter de nouveaux talents dans le secteur des technologies de l’information. En conséquence, le déficit de compétences se creuse et les entreprises doivent de moins en moins compter sur les personnes pour stimuler l’innovation, la croissance et la stabilité, et s’orienter vers un monde plus automatisé, où la technologie peut combler ce déficit.

Cette transformation est déjà bien engagée, et de nombreuses organisations tirent parti d’environnements, tels que le cloud public, pour les aider à automatiser bon nombre de processus qui, historiquement, nécessitaient l’intervention humaine. Les technologies d’orchestration et d’automatisation peuvent grandement contribuer à cette transition en intégrant l’intelligence artificielle et l’apprentissage automatique dans leurs solutions. Ces technologies ont été largement adoptées au cours de l’année écoulée pour aider à combler le déficit de compétences, mais avec des coûts qui devraient atteindre des niveaux sans précédent, leur utilisation continuera de se développer en 2023 en tant que solution permettant de réduire les coûts tout en assurant le bon fonctionnement des systèmes.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

As the world enters the post pandemic period of heightened digital transformation, new challenges have emerged which businesses (and their data) will have to navigate.  In the face of increased economic pressure, digital transformation and cloud initiatives are set to focus on creating efficiencies through costs and resources.

To help organizations steer through these (potentially) choppy waters, we’ve gathered thoughts from some Commvault key opinion leaders.  

Param Kumarasamy, VP, Product Management
– Resilience and Cloud Native Technologies

En 2023, l’incertitude économique continuera de s’accentuer dans un contexte marqué par une croissance massive des données et des ressources informatiques de plus en plus limitées. Cela conduira les entreprises à privilégier la résilience au détriment des initiatives de transformation. Nous nous attendons à ce que les dirigeants adoptent une posture défensive pour résoudre les problèmes connus et tirer le meilleur parti de ressources limitées. Les initiatives de résilience informatique favoriseront l’adoption de technologies d’IA et d’apprentissage automatique, telles que l’autosurveillance et la gestion des actifs informatiques, ainsi que l’automatisation et l’orchestration des activités informatiques, tant sur site que dans le cloud.

Au cours des dernières années, nous avons assisté à une croissance spectaculaire des initiatives de cloud hybride et multicloud au sein des entreprises. En 2023, nous prévoyons que les organisations miseront davantage sur les technologies « cloud native ». À l’instar du passage de l’environnement physique à la virtualisation, nous verrons les entreprises passer des technologies de virtualisation à une adoption croissante de Kubernetes, des conteneurs et du DevOps, tant dans les déploiements sur site que dans le cloud.

Reza Morakabati, Chief Information Officer –
CIOs need a holistic approach to data protection

À l’aube de l’année 2023, les DSI devront adopter une approche globale et adaptée au contexte pour évaluer leur stratégie de stockage des données. Les entreprises pourraient être tentées d’opter aveuglément pour le cloud ou une solution sur site en se basant sur des recommandations générales, mais cette décision devrait dépendre en grande partie de l’utilisation qui sera faite des données.

CIOs need to focus on five main areas – scalability, flexibility, agility, security, and cost. Cloud for instance checks off many of these boxes, but could account for a significant portion of a CIO’s operating budget, whereas data center investments are mostly allocated to capital budgets. It is critical for CIOs to look at the full picture.

Matt Tyrer, Senior Solutions Marketing Manager
and Head of Competitive Intelligence – Data Diversification and Mobility 

The number of applications, clouds, platforms, utilities, tools, and various other data workloads and locations to run them is multiplying. Just to frame this a little let’s just look at one of the bigger providers out there, AWS.  Prior to AWS reInvent in late November 2022, they had over 200 applications and services within their catalog for customers to leverage and build on. They then introduced at their annual event another 50+ including many highly specialized databases and tools.

That’s a lot, and that’s just one vendor. With this growing diversification is my prediction, and one seconded by Gartner at their recent IT Infrastructure, Operations, and Cloud Strategies Conference in Las Vegas just a few weeks ago: 

The applications and workloads you are running today, and where you are running them, will not be the applications and workloads or places where you will be running them in tomorrow. 

The impact here is equally diverse.  

  • Skills Shortages: The constant shifting of data workloads will mean that most organizations will not have the in-house skills to keep up with the changing platforms and services they are depending on to drive their business forward and remain competitive. 
  • Data Protection/Management Challenges: It is already a daunting task ensuring that all of your data sources are not only protected but secured from the growing threats to them. Many businesses are stuck relying on multiple niche or point product solutions in order to tackle this challenge because there simply are not many options out there that can cover it ALL. Now imagine all of those data sources and applications moving and changing on a regular basis, most tools today just can’t keep up and this will lead to overlapping siloes adding complexity, cost, and overall risk to the business. 

To address this, businesses will be turning more and more to partners who provide the broadest possible spectrum of support for data protection and data management to ensure that as their data platforms change, their solutions not only can keep pace, but already provide the needed coverage. This will enable organizations to adapt and transform with significantly less friction as they don’t need to revisit data protection and management with each step. This also supports a number of other initiatives such as sustainability and ESG as it enables the consolidation of tools and reduction of infrastructure and consumption of other resources such as the power and water that fuel that infrastructure. 

Hope D’Amore, Solutions Marketing Manager
– Cloud-Native will become the norm

La transformation numérique est indispensable pour maintenir un niveau d’innovation et de compétitivité sur le marché. Si l’on ajoute à cela un contexte économique turbulent et incertain, les entreprises devront se concentrer sur la gestion des coûts liés au cloud afin de trouver un équilibre entre ces deux aspects. Certains pourraient penser que l’adoption d’une approche « cloud-native » passerait au second plan en ces temps d’incertitude, mais une récente enquête de Forrester révèle que 40 % des entreprises adopteront une stratégie privilégiant le « cloud-native » en 2023. Les entreprises investiront davantage dans les technologies cloud natives, telles que Kubernetes, afin de gagner en efficacité, plutôt que de continuer à investir dans des infrastructures héritées.

As the shift to cloud-native environments becomes the norm, security will continue to be top of mind and Commvault is here to help. We provide the most comprehensive and flexible portfolio of solutions for containers. Store, protect, and migrate your Kubernetes applications wherever they live across hybrid multi-cloud environments. To learn more about how Commvault data protection can increase efficiencies within your cloud-native environment, visit Commvault.com/containers.

Forrester, Prévisions 2023 : le cloud computing, 27 octobre 2022

Qu’en pensez-vous ? Quels sont les projets de votre entreprise en matière de transformation numérique et de cloud computing ? Envisagez-vous d’investir davantage dans la conteneurisation cette année ?

Faites-le-nous savoir sur les réseaux sociaux.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Alors que nous rendons hommage au Dr Martin Luther King, Jr. le 16 janvier, il est essentiel de mettre en avant sa vie et son héritage en tant que leader du mouvement des droits civiques en ce début d’année 2023. Malgré les nombreuses avancées réalisées dans le cadre des mouvements en faveur de la justice raciale et sociale, le chemin vers l’égalité pour tous reste encore long à parcourir à l’échelle mondiale.

This day is a meaningful opportunity to reflect on what it means to drive positive change through the power of connection – whether it’s in our local communities, with family and friends or in our workplaces. For Dr. King, and all those who worked alongside him, their commitment to equality and human rights became another moment in the world in how individuals can empower the collective.

At Commvault, we’re striving for a balance in what it means to connect meaningfully whether it is in person or remotely. The global pandemic helped us navigate how to extend those connections around the world in virtual spaces and do it successfully to have “courageous conversations” around various topics.

In my role, my goal is focused on empowering everyone to be a change agent towards moving the Commvault community forward– especially driving lasting and impactful change for all dimensions of diversity. In various workplaces, there are diversity, equity and inclusion (DE&I) efforts focused on improving the recruitment, retention, advancement and sense of belonging for those from diverse, unique backgrounds and cultures. Within Commvault, we have the Multi-Culture Employee Resource Group (ERG) focused on helping to create connections, education and awareness of our global cultures.

Le groupe ERG « Multi-Culture » de Commvault s’engage à offrir un espace de refuge, de célébration et de réflexion aux « Vaulters » issus de minorités ethniques et à leurs alliés au sein de Commvault. Nous nous efforçons de mettre en avant la beauté, la valeur et les contributions de toutes les origines raciales et ethniques.

As a company, we’re working towards that meaningful change and creating a sustainable foundation to support future efforts where all feel like they belong and can thrive. In honor of Dr. Martin Luther King, Jr., let’s continue to make a commitment to ourselves, others, and our broader global community that we will create space for positive change, more connections, and making our places in the world a more welcoming environment -– we’re in this together!

Cliquez ici to learn more about our DE&I efforts at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

To be successful in our roles as IT professionals, we frequently need to juggle a variety of responsibilities or “wear a lot of hats” – especially when it comes to the important matter of protecting a company’s great asset, its data. 

Prenons le temps d’examiner les caractéristiques de chaque rôle et leur lien avec les responsabilités d’un professionnel de l’informatique en matière de protection des données :

The baseball cap – Readiness

Anticiper et contrer les menaces potentielles pesant sur la sécurité de l’information. En tant que responsables informatiques, il est de notre devoir de protéger les données et d’anticiper toute faille. Cela implique de rechercher en permanence les menaces potentielles et de les prévenir avant qu’elles ne deviennent un problème. Le recours à des solutions telles que la cyber-déception permet de mettre en place un système d’alerte précoce et offre cette protection nécessaire avant que vous ne soyez pris au dépourvu par une attaque.

The fedora – Flexibility

Modifying data protection tactics to fit the organization’s evolving needs. As IT executives, we must be ready to modify our approach to data protection to match the shifting requirements of our organization. The digital landscape is always changing. To remain ahead of potential dangers, this can entail putting new security processes into place or modifying current ones. Additionally, an IT leader must consider the latest technologies from cloud to containers and even possibly consider older tech when involved in mergers and acquisitions.  These scenarios all require a robust data protection solution that is scalable and flexible.  

The beret – Creativity

Inventing innovative ways to safeguard data in an increasingly complex digital environment. As IT executives, we must be able to think creatively and develop novel ways to safeguard data in a complicated digital environment. The cybercriminals are often a few steps ahead and might have more resources than your internal IT staff, the only way to combat this is to have elegant solutions to complex problems.  Nothing is more elegant than a beret…

The top hat – Decision Making

Making decisions that secure data and shield the organization from potential dangers while also ensuring that data protection and security are top organizational priorities. As the “top hat” of the company, it is our duty to make sure that data security and protection come first, to make choices that secure data, and to defend the company against any dangers. Our customers, employees, shareholders and even our peace of mind rely on knowing that IT leaders are securing the data and information of our company.  

En conclusion, les responsables informatiques ont beaucoup à gérer et doivent posséder des connaissances dans divers domaines.

À l’occasion de la Journée nationale du chapeau, prenons un instant pour rendre hommage aux différentes casquettes qu’ils endossent et au rôle essentiel qu’ils jouent pour assurer le bon fonctionnement et l’efficacité de nos entreprises.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

2022 was a BIG year for Cyber Security.  According to Cyber Security Hub, more than 4100 data breaches were publicly exposed with a number of high-profile attacks including Twitter, Optus and WhatsApp.

In today’s world, bad actors are well organized, informed and also persistent with the volume and speed of attacks increasing.  Their motives are changing, with data leakage, exfiltration, theft and restructure being top objectives causing data damage to now be the top concern of IT decision makers.

So what does 2023 hold? We’ve gathered thoughts from experts across Commvault to answer that very question. 

Industry-Wide Shift to Proactive, Early Threat Prevention 
– Matt Tyrer

In short, businesses will need and begin to implement proactive solutions to constantly monitor their environment to catch threats and enable early warning/response.  Bad guys are getting in, and we aren’t knowing about it early enough. 

From a cyber security and threat defence perspective, the industry today could be essentially divided in two approaches: 

  1. Preventative Measures: These vendors are your perimeter defence vendors like firewalls, anti-virus, SIEM/SOAR tools, along with other data loss prevention (DLP) and intrusion detection/prevention solutions. Even the newer identity access management (IAM) security vendors, who are adding key security functionality to control who can see what in your environment, can be grouped in here. They are all the locks on your doors and windows actively working to keep the bad guys out of the house so that they can’t even start the fire. 
  2. Reactive Measures: These tend to be the storage and most conventional backup vendors who are focused on protecting the data itself. Aiming to ensure it is available for recovery via table stakes features like immutability and anomaly detection (threat hunting) in the backups. These solutions are the sprinkler system and fire alarm – by the time they are triggered your house is already on fire and your only response is triage and disaster recovery. 

Don’t get me wrong, both of these are critical parts of a layered security posture and strategy but there is a gap which where early warning lives.  It’s the abilities to better respond when a breach occurs, while not waiting for data damage to be done before recovery is kickstarted.

This is why my prediction is an industry wide shift to more PROACTIVE warning systems, helping companies fill gaps between their preventive and reactionary toolsets.    

Thankfully, Commvault is ahead of this game with our ThreatWise cyber deception technology. Get started NOW on proactively defending your data. 

Rise in Managed Services Provider Spending
– Donna Namorato

The Institute of International Finance is predicting a global economic growth rate of just 1.2% in 2023, a level on par with 2009 when the world was only beginning its emergence from the from the financial crisis.1 Even with economic uncertainty looming, expect that cybersecurity spending will continue to rise but don’t be surprised if there is a decline in product and service spending.

Et alors même que les dépenses en cybersécurité augmentent, selon une enquête menée par Jefferies auprès des DSI, 53 % d’entre eux ont indiqué qu’ils réduiraient leurs dépenses en matière de gestion des services informatiques (ITSM). Si cela se produit, je m’attendrais à voir une hausse des dépenses consacrées aux prestataires de services gérés (MSP). Les MSP sont spécialisés dans des segments informatiques spécifiques et peuvent offrir une expertise informatique de haut niveau, car ils parviennent à attirer et à fidéliser les talents, ce que les entreprises ont du mal à faire.

To remain vigilant against ransomware and data security, organizations must adopt a ransomware strategy and develop an incident response plan against bad actors. Incorporating a multilayered security framework is also vital to safeguard your data and reduce cybersecurity risk. And, when you need help, Commvault Ransomware Readiness Solutions is available to assist you.

Industry and Platform Consolidation
– Brian Brockway, Global Chief Technology Officer


À l’heure actuelle, le secteur de la sécurité est très complexe. Il existe une multitude d’outils et de nombreuses entreprises ont recours à plusieurs solutions pour s’assurer d’être pleinement protégées. Cependant, nous avons constaté que le secteur commence à se consolider, une tendance qui devrait se poursuivre en 2023. Tous les composants doivent fonctionner de concert afin d’atteindre une efficacité maximale et d’offrir les meilleures chances de protection. Leur regroupement au sein d’une plateforme unique sera essentiel pour tirer le meilleur parti de vos solutions, et disposer d’une vue d’ensemble unique est indispensable à leur gestion. D’autant plus que les coûts ne cessent d’augmenter, les organisations doivent s’assurer de dépenser chaque centime à bon escient et d’obtenir un rendement optimal de chaque achat.

Pourtant, face à la multitude de menaces qui pèsent sur les entreprises, on prend de plus en plus conscience qu’il est impossible de tout bloquer, quelle que soit la qualité de vos solutions ou l’efficacité avec laquelle vous les gérez. Les entreprises doivent désormais se concentrer sur la résilience. Il est aujourd’hui presque inévitable qu’une entreprise soit attaquée à un moment ou à un autre, mais ce qui compte vraiment, c’est la rapidité avec laquelle vous pouvez vous en remettre. Des sauvegardes régulières doivent être effectuées afin que, même si le pire devait arriver, les temps d’arrêt soient réduits au minimum et que les opérations commerciales normales puissent être rétablies aussi rapidement que possible, avec un minimum de dommages durables.

“Inside-out” CyberSecurity, Tiger Teams and Managed Services
– Zack Brigman, Sr Product Marketing Manager

Les cybermenaces continuent d’atteindre des niveaux records, tant en termes de nombre de violations réussies que de dommages causés par ces attaques. À l’horizon 2023, les experts prévoient que ces tendances continueront à évoluer dans la mauvaise direction, car les attaquants emploient de nouvelles tactiques sophistiquées, les réseaux de pirates à la solde de tiers ne cessent de s’étendre et le déficit de compétences en sécurité et en informatique se creuse. Et bien que ces forces négatives posent des défis difficiles à surmonter, les organisations feront un grand bond en avant au cours de l’année à venir pour mieux planifier, investir et faire évoluer leurs pratiques en matière de cybersécurité.

Prioritization

Breaches happen. But not all assets, systems, and data are created equal. Given that a small percentage of information assets carry the majority of business risk, progressive companies will begin employing an “inside-out” cybersecurity strategy. One that starts with hardening and securing their most critical assets first – then working toward the perimeter. While perimeter defences and preventing intrusion will (and should) remain a paramount focus, this risk-aligned approach enables the prioritization of defence strategies to mitigate risk for high-value assets and functions. This reshapes conventional “outside-in” approaches, making security investments more accessible and operational.

Tiger Teams

To better manage emerging threats and respond to risk, we will continue to see a rise in fusion teams (thanks Gartner for the term!) – merging IT, security, and operational stakeholders together to drive change. These blended teams help create new synergies by pairing complementary (but often siloed) groups and capacities to achieve common goals. These cross-functional teams increase visibility across the organization, discover and eliminate blind spots, and optimize investments in existing and new tools. While many mature organizations already leverage fusion teams today, 2023 will see a more widespread adoption of these functions to better identify risks, implement cyber response strategies, and manage threats.

Managed Services

As threats mount, businesses will continue to adopt managed service (MSP) and managed security service (MSSP) offerings to augment existing tools and tactics. This is particularly true of lean IT departments and those looking to enhance their security operations centers. Leveraging these managed providers will enable organizations to close the cyber security skills gap, tap into a consortium of specialized solutions, and scale their cyber practice without managing additional headcount or disparate solutions. 

Thanks to all our contributors! Stay tuned to see if their predictions come true by following Commvault and our DPaaS portfolio Metallic on Social Media. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements