Skip to content

Note: This blog was originally published in October 2025 when Data Rooms was introduced. It has been updated to reflect the next evolution, Data Activate.

Points clés à retenir

  • Data Activate is part of Commvault’s next-generation AI capabilities – alongside AI ProtectetAI Studio – annoncé to help organizations activate AI safely, govern AI agents,etbuild agentic workflows from Commvault Cloud.
  • Data Activate est conçu pour vous permettre de transformer vos données de sauvegarde en ressources fiables et prêtes pour l’IA, tout en vous aidant à garantir la gouvernance et la conformité.
  • Cette offre permet de concilier protection des données et activation de l’IA sans créer de nouveaux risques pour la sécurité ni nécessiter platform autre platform.
  • Il s’intègre aux écosystèmes d’IA existants tels que Microsoft Azure et Snowflake à l’aide de normes ouvertes telles qu’Apache Parquet et Iceberg.
  • La gouvernance intégrée permet la gestion, la classification et le partage sécurisés des données au sein d’une architecture « zero-trust ».
  • En activant les données historiques, les organisations peuvent contribuer à accélérer l’innovation en matière d’IA, l’analyse et les workflows de conformité en toute sécurité.

AI innovation depends on data – but not just any data. It depends on trusted, governed,etaccessible data. Yet for most enterprises, the data that could fuel AI lives deep within backups, scattered across environments,etwrapped in compliance constraints. That’s where Commvault’s Data Activate offering, previously known as Data Rooms, comes in.

Accélérer l’IA en toute sécurité

Data Activate est l’une des trois fonctionnalités d’IAannoncé as part of its next-generation AI platform – alongside AI ProtectetAI Studio. As organizations race to adopt AI, many are running into a fundamental challenge: their data is fragmentedetdifficult to use. According to a recent survey, 68 % des entreprises cite data silos as their top concern.

Commvault’s Data Activate offering helps transform backup data – one of the most completeettrusted datasets an organization owns – into AI-ready assets. Data Activate helps enterprises safely connect their data to AIetanalytics platforms, without creating new risks or complexity.

Unlike earlier bulk export approaches, Data Activate can regularly publish updated datasets, making it easier to keep AI pipelines in sync with the most current trusted data. Teams also can identifyetexclude sensitive data – such as personally identifiable information – before activating datasets for analytics or model development.

The Data Activate offering is not another AI platform. It’s the bridge between data protectionetdata activation, designed to make your existing AI investments work fasteretsafer. It does this by creating governed, policy-controlled “rooms” inside Commvault Cloud – spaces where data can be classified, curated,etshared with AIetanalytics tools without leaving the protection boundary.

À l’écoute des clients : finie Platform

We heard customers loudetclear: You don’t need another AI platform. You need a protected, simple way to use the data you already maintain – across the AI toolsetecosystems you’ve already chosen.

That’s why Commvault built Data Activate to integrate with partners like Microsoft AzureetSnowflake using open-standard formats such as Apache ParquetetIceberg. This helps you keep your data portable, policy-compliant,etready for activation – wherever your AI strategy takes you.

Transformer la protection des données en activation des données

With Data Activate, authorized users can discover, classify,etprepare data directly from backup repositories – across on-premisesetcloud environments. Built-in governance helps maintain control, allowing only approved datasets to be shared, with automated classification, sensitivity tagging, redaction,etaudit trails applied every step of the way.

Data Activate acts as a governed, policy-controlled workspace inside Commvault Cloud – where data can be curatedetmade available to AI or analytics tools without leaving the protection boundary. This governed design provides a protected bridge between backup dataetactivation workflows, helping organizations unlock their information for innovation while being able to maintain complianceetcontrol.

Data Activate peut vous aider à :

  • Accelerate insights: Quickly findetexport historical data in AI-friendly formats to train models or power analytics.
  • Simplify operations: Eliminate brittle ETL pipelines with automated data discoveryetcuration.
  • Maintain compliance: Keep governance intact with policy-based controlsettraceability from backup to activation.

La confiance comme fondement d’une IA responsable

Dans la course à l’adoption de l’IA, la confiance fait souvent les frais de cette évolution. Selon uneétude, roughly three-quarters of surveyed IT leaders said that using AI could make their organizations more vulnerable to cyberattacks. That’s why Commvault built Data Activate within Commvault Cloud’s zero-trust architecture, complete with encryption, RBAC,etcompliance support.

By combining data protection, governance,etactivation in one platform, Commvault enables enterprises to accelerate AI innovation without compromising data security, compliance, or control.

Accélérer l’innovation sans augmenter les risques

Commvault’s Data Activate offering helps organizations move faster by making data safely accessible to the tools that drive their business forward – from AI model training to analytics, eDiscovery,etcompliance support automation. Because when backup data becomes usable data, enterprises unlock years of historical intelligenceetcontext that most AI models simply don’t have.

As Pranay Ahlawat, Commvault’s Chief TechnologyetAI Officer, said: “Organizations are beginning to realize that their historical data is more than just insurance – it’s a powerful, untapped strategic asset. With Commvault Data Activate, enterprises can confidently export their secondary dataetharness it with the AI platform of their choice to unlock new opportunities for intelligence, innovation,etbusiness growth.”

Pourquoi est-ce important aujourd’hui ?

Commvault’s Data Activate offering redefines what’s possible for enterprises that want to innovate responsibly. They make it possible to move from protecting data to activating data – safely, flexibly,etat scale.

In short: Commvault isn’t building another AI platform. We’re building the foundation that lets every AI platform work better – because when data is protected, trusted,etready for activation, innovation happens faster.


FAQs

Q: What is Commvault’s Data Activate offering?
A: Commvault Data Activate is a capability within Commvault Cloud that helps enterprises safely discover, classify,etactivate backup data for AIetanalytics. It supports open formats like Apache IcebergetParquetetis built on a zero-trust, governed architecture for controlled, self-service data access.

Q: How does Data Activate differ from other AI data solutions?
A: Most AI data prep tools work only on live or production data, creating complianceetcost challenges. Data Activate works from backup data – data that’s already protectedetgoverned – bringing a unique balance of accessibility, compliance support,ettrust. It’s built into Commvault Cloud’s policy-controlled environment, so it’s part of a unified cyber resilience platform. Data Activate also regularly publishes updated datasets – rather than relying on one-time bulk exports – helping keep AI pipelines current without manual intervention.

Q: What benefits do organizations gain from using Data Activate?
A: Organizations can accelerate AIetanalytics insights, simplify data operations by reducing ETL complexity,etmaintain compliance through automated classification, tagging,etauditing processes.

Q: How does Data Activate support data securityetcompliance?
A: Data Activate operates within Commvault Cloud’s zero-trust architecture, applying classification, redaction,etaudit-friendly controls automatically. It helps maintain data privacy, traceability,etcompliance throughout the data lifecycle, aligning with internaletregulatory governance standards.

Q: What types of AI or analytics platforms can connect with Data Activate?
A: Data Activate integrates with leading cloudetAI partners such as Microsoft AzureetSnowflake, supporting open-standard data formats like Apache ParquetetIceberg for maximum flexibilityetportability.

Q: Why is this offering important for enterprises today?
A: As organizations accelerate AI adoption, Data Activate enables them to responsibly unlock the value of historical, protected data – fueling innovation while helping maintain trust, compliance,etcontrol.

Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • La prolifération des agents constitue un risque en matière de gouvernance. À mesure que les agents d’IA se multiplient, une visibilité fragmentée et des workflows de Recovery déconnectés peuvent créer une véritable exposition opérationnelle.
  • AI Protect unifiera la découverte, la surveillance et la Recovery guidée des agents et de leurs dépendances sur toutes les plateformes, au sein d’une expérience unique centrée sur les agents.
  • AI Protect sera conçu non seulement pour évaluer si les actifs sont protégés, mais aussi pour aider à protéger la pile d’agents et à identifier les risques en fonction de ce que les agents touchent et font.
  • AI Protect will be built on Commvault’s resilience platform – meaning recovery can be tied directly to agent-initiated impact across both data and environments.
  • AI Protect will be part of a broader platform that supports the AI resilience lifecycle – from safely activating data to governing, building, and recovering agentic workflows.

AI agents are no longer a future-state experiment. They’re running in production environments today – querying data, triggering workflows, and making decisions at machine speed. For most enterprises, that’s happening faster than governance frameworks can keep up.

The problem isn’t enthusiasm for AI. It’s the gap between deploying agents and actually knowing what those agents are doing, what data they’re touching, and what to do when something goes wrong. That gap is what Commvault AI Protect will be designed to close.

Le problème de gouvernance au cœur de l’IA agentique

As organizations scale their AI investments, a new class of operational risk is emerging. AI agents aren’t just tools – they’re autonomous actors that can access sensitive data, interact with critical systems, and trigger cascading changes. Without a clear way to discover, monitor, and govern them, IT and security teams may be flying blind.

The symptoms are familiar:

  • Fragmented visibility: Hyperscaler APIs and observability tools provide partial, siloed views of agent activity. No single view connects agent behavior to data protection, risk, and recovery across platforms.
  • No protection context: Data protection teams can’t easily determine whether assets touched by AI agents are adequately covered or recoverable.
  • Weak risk signals: Agent activity can generate enormous telemetry, but without correlation across identity, access, and impact, distinguishing benign automation from high-risk behavior remains a manual effort.
  • Disconnected recovery: When agent-initiated changes cause problems, tracing the impact and initiating recovery can require manual correlation across tools, increasing time to resolution.

Présentation de Commvault AI Protect

AI Protect will be designed to offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents – across enterprise, SaaS, and cloud environments. It will extend Commvault’s existing discovery, protection, and recovery capabilities with agent-centric context, helping teams operate AI agents safely and recover quickly when issues arise.

Discover: A Single, Authoritative Agent Inventory

AI Protect will be designed to discover AI agents (and their dependencies) operating across connected environments on a recurring basis, helping maintain a unified, up-to-date inventory based on configurable discovery cadence. Each agent record will capture its execution environment and the data sources, models, configurations, applications, and infrastructure it interacts with. It will help provide a complete, cross-environment picture of what’s running and what it touches.

Protect: Closing Coverage Gaps Before They Become Incidents

AI agents interact with sensitive data and systems, but traditional protection tools don’t evaluate coverage in the context of agent behavior. AI Protect will be designed to surface protection status for every agent-touched asset – protected, partially protected, or not protected – and help identify gaps introduced by agent activity. Where gaps exist, it will offer recommended actions and protection workflows to enable teams to close them.

Monitor: Turning Telemetry Into Actionable Risk Signals

AI Protect will ingest agent activity from existing audit, event, and telemetry sources and present it in agent-centric context – not as raw logs. A time-ordered activity timeline will show what each agent has done and when, and risk signals will be automatically flagged and categorized when agents access sensitive data, interact with unprotected assets, or exhibit unusual patterns. This will help teams move from reactive triage to proactive awareness.

Recover: Guided Recovery Tied Directly to Agent Impact

When an agent-initiated change causes an issue, AI Protect will surface recovery point availability for impacted assets and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery will be scoped directly to the agent’s impact, not generic incidents, and every action will be time-stamped.

In addition, teams will be enabled to recover the full AI stack – not just the model, but the connected data, configurations, and underlying systems that support it – helping restore the entire environment to a known good state with a single, guided action.

S’inscrit dans une vision plus large de la résilience de l’IA

AI Protect sera l’une des trois fonctionnalités annoncées par Commvault dans le cadre d’une plateforme plus large dédiée à la résilience de l’IA.Data Activate enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Studio will enable enterprises to deploy ready-made agents and build custom ones – without writing code. Using a natural language–based Agent Builder, administrators will be able to describe operational intent in plain language, review the proposed workflow, refine it, and deploy it as a governed custom agent from a single interface. AI Studio will be designed to leverage Commvault’s MCP server and integrate with other enterprise applications via MCP, enabling workflows to extend smoothly across systems.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


FAQs

Q: What is Commvault AI Protect?

A: AI Protect is slated to be a governance and resilience solution for AI agents operating across enterprise, SaaS, and cloud environments. It will be designed to automatically discover agents and dependencies, surface protection gaps for the assets they touch, monitor and provide guided recovery workflows when agent-initiated changes cause issues.

Q: How will this be different from general AI observability or monitoring tools?

A: Most observability tools surface telemetry but stop short of connecting agent activity to data protection and recovery. AI Protect will be designed to correlate agent behavior with protection coverage and recovery readiness, and when something goes wrong, provide a guided path to help restore data, configurations, or systems impacted by agent activity.

Q: What environments will AI Protect support?

A: AI Protect will be designed to work across hyperscaler environments (AWS, Azure, Google Cloud), SaaS platforms, and internal enterprise systems – offering a unified, cross-environment view of agent activity and impact.

Q: How will AI Protect identify risk?

A: Risk signals will be derived by correlating agent activity with data access patterns, sensitivity of assets involved, and protection coverage. Rather than raw log analysis, AI Protect will present risk in agent-centric context – flagging specific agents and interactions that warrant attention, along with the reason they were flagged.

Q: How will recovery work?

A: AI Protect will surface recovery point availability for assets impacted by agent activity and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery actions will be scoped to agent-initiated impact and will be fully auditable.

Q: How will AI Protect relate to AI Studio and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate governs how data is prepared and activated for AI use. AI Protect will govern agents operating in production. AI Studio will enable teams to build and manage custom agentic workflows. Together, they will form an end-to-end AI resilience lifecycle.

Teja Medasani is Principal Product Manager at Commvault and Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Commvault Cloud Compliance

Read more about Commvault Cloud Compliance

Points clés à retenir

  • AI Studio will be designed to bridge the gap between experimentation and scaled, production-grade AI automation.
  • The Agent Library will offer enterprises visibility of every default and custom agent in one place, with clear descriptions, categories, and enabled status.
  • The Agent Builder will make customization accessible. Natural-language inputs will be able to generate structured, reviewable workflows – no coding required, no black-box behavior.
  • All agent logic will be visible and explicitly saved before deployment, helping meet enterprise requirements for transparency and explainability.
  • AI Studio will be part of an end-to-end platform. Combined with Data Activate and AI Protect, it will be built to support the AI resilience lifecycle.

AI automation promises enormous operational value. But for most enterprises, moving from pilot to production can be harder than expected – especially when it comes to operational workflows like backup, recovery, and incident response. Governance concerns, lack of visibility, and the complexity of stitching together tools can often prevent AI from being used in real, day-to-day resilience operations.

What organizations need is a way to apply AI directly to these workflows – safely, with control, and in a way that fits how resilience teams actually operate. That’s what Commvault AI Studio will be designed for.

Why AI Automation Stalls at the Pilot Stage

McKinsey’s State of AI in 2025 report reveals that 88% of organizations use AI in at least one business function – yet only about one-third have reached scaled adoption beyond early pilots. The barriers are consistent across industries:

  • Limited visibility and control over which agents exist, what they do, and where they’re active – making it difficult for IT and data security teams to oversee operational workflows.
  • High friction to customize automation – teams can be forced to rely on manual scripting or external services to adapt built-in capabilities to real workflows, slowing adoption and limiting ROI.
  • Concerns about trust and governance – without transparency, explainability, and auditability, enterprises can’t confidently move agents from experimentation into production.

As a result, organizations either underutilize AI capabilities or rely on manual processes for tasks that could be automated safely – leaving real efficiency and resilience gains on the table.

Introducing Commvault AI Studio

AI Studio is slated to be Commvault’s answer to the governance-adoption gap. It aims to provide a centralized interface where enterprises can view and manage all agents, deploy ready-made agents, and build custom agents using a workflow-based approach that helps keep behavior visible, auditable, and under control.

Agent Library: A Clear View of Every Agent in Your Environment

LeAgent Library will be the entry point to AI Studio. It will present a structured inventory of every agent available in the environment – both default agents built by Commvault and custom agents created by the customer – grouped by type and showing each agent’s name, category, description, and enabled status at a glance.

Default agents include Commvault’s foundational cyber resilience agents, such as Arlie Advisor, Arlie Data Sense, Arlie Recover, among others. The Agent Library will offer teams a single, authoritative view of their resilience agent ecosystem before taking any action.

Agent Management: Operational Control for Every Agent

Selecting any agent from the library will open a dedicated detail view that can help provide transparency into how that agent operates – its purpose, how it’s triggered, what data it uses as inputs, execution limits, and basic usage telemetry.

This view will also include records of agent activity and events. Following this, administrators can enable or disable the agent with a single action. This will apply consistently to both default and custom agents, so every agent in the environment can be subject to the same governance standard.

Agent Builder: From Plain-Language Intent to Governed Workflow

AI Studio’s Agent Builder will enable administrators to create custom agents by leveraging Commvault’s workflows and MCP server – without writing code.
Leexperience will start with natural language. An administrator will be able to describe what they want to automate – for example: “I need an agent that detects when storage or infrastructure issues are starting to impact backups and helps resolve them before they affect SLAs.”


Lesystem will be designed to translate that intent into a structured agent configuration, including triggers, conditions, and actions, with optional AI-enabled steps from Arlie – such as Summarize, Generate Recommendation, or Draft Notification – available as explicit workflow steps.
Leadministrator will be able to review the proposed workflow, adjust it as needed – changing trigger frequency, specifying a distribution list, or reordering steps – and save it. The result will be an auditable custom agent that appears in the Agent Library and can be managed through Agent Management like any other agent.

S’inscrit dans une vision plus large de la résilience de l’IA

AI Studio will be one of three capabilities Commvault announced as part of a broader AI resilience platform.Data Activate enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Protect will offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents operating across enterprise, SaaS, and cloud environments – helping teams operate agents confidently and recover quickly when something goes wrong.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


FAQs

Q: What is Commvault AI Studio?

A: AI Studio will be Commvault’s centralized platform for deploying, building, and managing AI agents. It will include an Agent Library for viewing all agents in the environment, Agent Management for operational control, and an Agent Builder for creating custom agents using workflow-based automation – all without writing code.

Q: Who will AI Studio be designed for?

A: AI Studio will be built for Commvault administrators and IT operators who want to automate operational tasks – like monitoring backup job failures or notifying stakeholders – without relying on manual scripting or external development resources.

Q: How will the Agent Builder work?

A: Administrators will be able to describe their automation intent in plain language. AI Studio will then be able to propose a structured workflow with explicit triggers, conditions, and actions. The administrator can then review, edit if needed, and save the workflow as a custom agent. The resulting agent will be visible, auditable, and managed through the same interface as all other agents.

Q: Can AI be incorporated into custom agents?

A: Yes – but intentionally. AI will be invoked deliberately, not invisibly embedded in agent behavior.

Q: What default agents are available out of the box?

A: AI Studio will launch with a library of default agents across foundational AI and cyber resilience categories, including Arlie Data Sense, Arlie Advisor, and Arlie Recover.

Q: How will AI Studio relate to AI Protect and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate helps govern how data is prepared and activated for AI use. AI Protect will help govern agents operating in production. AI Studio will help teams deploy and build custom agentic workflows. Together they will form an end-to-end AI resilience lifecycle.

Teja Medasaniis Principal Product Manager at Commvault andVir Choksiest responsable principal du marketing produit chez Commvault.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • Apache Iceberg has become a key data lakehouse format,etmany AWS customers are migrating from Glue-managed Iceberg tables to fully managed Amazon S3 Tables for better performanceetautomation.
  • Clumio enables a smooth, Iceberg-aware migration process that helps maintain data integrity, metadata,etversion history while adding air-gapped, immutable protection.
  • The platform automates migration using a simple backup-and-restore workflow, helping reduce the need for custom scripts or manual configuration.
  • Compared to manual or native AWS migration methods, Clumio offers a faster, more scalable,etresilient option for enterprise data lakehouse modernization.
  • Clumio’s collaboration with AWSetavailability in the AWS Marketplace enable organizations to modernize data lakes securelyetconfidently.

AIetlatency-sensitive analytics workloads increasingly depend on data lakehouses as their underlying data architecture. Among AWS customers building these environments, Apache Iceberg has become one of the fastest-growing table formats on Amazon S3, providing the transactional consistency, schema evolution,etperformance needed for modern analytics.AWS customers manage Iceberg tables today through the AWS Glue Data Catalog or adopt AWS’s fully managed option, Amazon S3 Tables, to streamline operationsetimprove performance.As AWS customers evaluate the growing importance of their Iceberg-based data lakehouses, considerations around protection, resilience,etmigration to Amazon S3 Tables naturally become part of that planning. Many teams are now looking for a simple, reliable way to move from Glue-managed Iceberg tables to S3 Tables while strengthening the protection of these critical datasets.As AWS’s 2025 Global Storage Partner of the Year, Commvault is deepening its collaboration with AWS to help customers modernize, protect,etoptimize their cloud-native data.ThroughClumio, Commvault delivers anIceberg-aware, air-gapped cyber resilience solution for AWS –etnow helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while enabling long-term protectionetrecovery. You can start your free trial in the AWS Marketplace.

The Challenge: Limited Options for Moving to S3 Tables

Organizations are increasingly evaluating migrations from Glue-managed Iceberg tables to fully managed Amazon S3 Tables to improve data lake performanceetsimplify operations. According to AWS, S3 Tables can deliver up to3 times faster query performanceetup to 10 times higher transactions per second compared to Iceberg tables stored in general purpose S3 buckets.Many teams also want to offload undifferentiated heavy lifting – such as compaction, snapshot management,etunreferenced file cleanup – while reducing overall storageetquery costs.However, existing AWSetcommunity guidance, such as AWS’s migration framework, outlines a manual, multi-step process requiring custom scriptingetorchestration. Migrating data while maintaining schema, metadata,etversion history can be time-consumingeterror-prone,etmost current approaches focus on replication rather than Iceberg-aware recovery or rollback.Clumio’s migration support for Apache Iceberg tables provides the Iceberg-aware, enterprise-grade migrationetresilience capability that modern data lakehouses have been missing. Demander une démonstration to see how Clumio streamlines your migration.

How Clumio Simplifies MigrationetProtection

Clumio pour Apache Iceberg sur AWS helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while simultaneously enabling long-term protection for these modern data lakehouse assets.The same Iceberg-aware platform provides air-gapped, immutable backups, isolated recovery points, point-in-time or snapshot-level restores,etretention capabilities that help support compliance requirements – extending Commvault’s leadership in cloud-native cyber resilience.Migrationetprotection work hand in hand:

  • Help protect Iceberg tables registered in the AWS Glue Data Catalog.
  • Restore as fully managed Amazon S3 Tables.
  • Continue helping protect those Iceberg tables with Clumio’s cyber resilience capabilities.

For teams that prefer Infrastructure-as-Code deployment,Clumiooffers a publicly availableTerraform module that supports Apache Iceberg.As AWS customers adopt Amazon S3 Tables, protecting these modern data assets becomes even more important. Threat vectors such as ransomware, accidental deletion, malicious or mistaken changes,etaccount compromise can disrupt AIetanalytics pipelinesetlead to costly reprocessing. Clumio helps customers mitigate these risks withimmutable, air-gapped backupsand flexible recovery options across accounts, regions, snapshots,etpoints in time. For a deeper look at why data lakehouses need purpose-built protection, seeCombler les lacunes en matière de protection des entrepôts de données.

How It Works – From Backup to Restore

The migration process using Clumio follows a straightforward backup-and-restore workflow, designed to minimize effortethelp maintain Iceberg table integrity.Step 1: Connect with the Commvault team for migration program reviewetapproval. Please Nous contacter.Step 2: Discoveretback up Iceberg tables registered in the AWS Glue Data Catalog, with underlying data stored in S3, using Clumio.Step 3: Restore Iceberg table backups – whether the full snapshot history, a selected subset, or a specific point-in-time version – as Amazon S3 Tables in any account or region.Step 4: Enable incremental backups to maintain protection for your new Amazon S3 Tables.Clumio’s architecture helps reduce the need forethelps provide transactionally consistent Iceberg recovery across accounts, regions,etsnapshots.To see the full migration workflow in action – including Iceberg discovery, backup selection, snapshot options,etrestoration to Amazon S3 Tables – watch the demo video embedded below. It walks through the entire backup-and-restore flow end to end, showing how Clumio handles the data, metadata,etsnapshot migration with no manual configuration required.

Comparing Migration Options

Most migrations to Amazon S3 Tables today depend on manual scripts or native tooling. Here’s how those methods compare against Clumio’s Iceberg-aware approach.

Method Description Key Considerations
DIY scripts/
open source tools
Custom scripts using Athena or Glue APIs to copy dataetmetadata Best suited for teams with scripting expertiseetcustom migration requirements
Native AWS processes/
snapshots
AWS documentationetcommunity guides outline snapshot-based or query-driven migrations Suitable for teams using native AWS servicesetmanaging multi-step migration processes
Clumio SaaS-based, Iceberg-aware backupetrecovery solution for AWS Simple, Iceberg-aware migration workflow that helps preserve metadataetsnapshot lineage while integrating ongoing protection

Demander une démonstration to learn how Clumio simplifies migration at scale.

Why This Matters for AWS Customers

As AWS customers modernize their data lakehouses, they need a simple, scalable way to migrate Iceberg tables to Amazon S3 Tablesetprotect them against operationaletcyber risks. Clumio delivers this by providing Iceberg-aware migration along with air-gapped, immutable protection.AWS is working with Commvault to help customers use Clumio for both protectionetmigration to Amazon S3 Tables. The solution is available today in the AWS Marketplaceetsupports Iceberg tables across both Glue-managedetfully managed S3 Tables environments. Together, CommvaultetAWS provide enterprises with a simple, scalable way to modernize their AI data pipelines.For organizations looking to strengthen resilience across the broader AWS data stack, see our blogs on protecting Amazon S3 data with ClumioetClumio Backtrack for Amazon DynamoDB.If you’d like to discuss your AWS data modernization strategy, please Nous contacter.

Moving Forward with ClumioetAWS

As organizations modernize their data platforms for AI, Clumio helps them migrate confidently to S3 Tables, maintain data integrity,etstrengthen their cyber resilience. Clumio simplifies migrationetprotection – helping organizations protect, recover,etmove their most valuable data faster.Start your free trial in the AWS Marketplace.


FAQ

Q: Why are organizations moving from self-managed Iceberg tables to Amazon S3 Tables?
A: Many teams are migrating to S3 Tables to improve performanceetsimplify management. Amazon S3 Tables deliver up to three times faster query performanceet10 times higher transaction throughput than self-managed Iceberg tables while reducing operational overhead.Q: How does Clumio simplify the migration process?
A: Clumio automates migration through a backup-and-restore workflow that maintains schemaetmetadata consistency. It avoids manual scriptingetenables restoring Iceberg backups directly as S3 Tables across accountsetregions.Q: What makes Clumio different from other migration approaches?
A: Unlike do-it-yourself scripts or AWS’s native methods, Clumio is Iceberg-awareetautomated,etit offers built-in cyber resilience features such as immutable backups, point-in-time recovery,etretention capabilities that help support compliance requirements.Q: How does Clumio enhance data protection duringetafter migration?
A: Clumio provides air-gapped, immutable backups that help protect against ransomware, accidental deletion, or malicious changes. It also supports flexible recovery across snapshots, accounts,etregions.Q: Is Clumio available for AWS customers now?
A: Yes, Clumio is available in the AWS Marketplaceetintegrates with both AWS GlueetAmazon S3 Tables environments. customers to modernizeetprotect their AI data pipelines.Q: What’s the first step to get started with Clumio for S3 Tables migration?
A: Organizations can start by contacting Commvault for migration program approvaletthen use Clumio to discover, back up,etrestore Iceberg tables as Amazon S3 Tables. A free trial is available in the AWS Marketplace.Vir Choksi is Principal Product Marketing Manager at Commvault.

Related Blogs

More related posts


Clumio

Read more about Clumio

Points clés à retenir

  • Commvault’s unified threat detection consolidates risk signals and context into a single view, integrating with partners to help reduce alert fatigue and bridge the gap between security ops and data protection teams.
  • Arlie®, Commvault’s AI assistant, helps translate complex incidents into plain-language summaries and recommends next steps – making it easier for non-experts to respond quickly and confidently.
  • Rather than treating entire backups as clean or compromised, Synthetic Recovery™ works at the file level to identify and assemble the most recent clean data, minimizing data loss and recovery downtime.
  • Cleanroom™ Recovery, an isolated environment for forensic investigation, has been enhanced with runbooks to make threat analysis more repeatable, auditable, and safe – helping minimize risks for production systems.

Commvault’s enhanced cyber recovery capabilities focus less on traditional backup and more on helping organizations stay resilient in the face of modern cyber threats. They’re designed to help security and data protection teams seeking faster insights, cleaner recovery options, and stronger validation that their data can be kept safe and recoverable.

At the core is an upgraded threat-detection experience that brings risk, signals, and context together in a single, unified view. Instead of sifting through disconnected alerts, teams see prioritized risks across their environment, enriched with partner integrations like CrowdStrike and Netskope, so they can focus on what truly matters. This helps reduce alert fatigue and bridges the gap between security operations and data protection.

Arlie for the Assist

AI also plays a central role throughArlie, Commvault’s AI-enabled assistant for data security. Arlie helps summarize complex incidents into clear, human-readable narratives: what happened, when it started, which systems were impacted, and what other tools are seeing. From there, Arlie recommends next moves – such as engaging the security team, using a cleanroom for deeper analysis, or triggering a safer recovery path – so even non-experts can act quickly and confidently.

Synthetic Recovery Helps Restore Clean Data

Recovery itself has evolved with new options that are purpose-built for cyber events rather than routine restores.Synthetic Recovery automatically locates and assembles the most recent clean versions of data at the file level, helping reduce manual effort and lower the risk of restoring compromised content. Instead of treating entire backups as “all good” or “all bad,” Synthetic Recovery is designed to help preserve as much recent, safe data as possible, helping to minimize data loss and downtime.

Cleanroom™ Recovery for Forensic Analysis

For teams that need to investigate attacks in depth,Cleanroom Recovery provides an isolated, secure environment to help analyze suspicious data while helping to reduce risk to production systems. This environment is orchestrated with our new runbooks feature to help streamline setup and validation, making forensic work more repeatable and less error prone. It can be particularly helpful when demonstrating to auditors and regulators that steps have been taken to contain a threat, preserve evidence, and follow best practices.

Finally, the platform’s reporting and compliance capabilities tie everything together, helping to turn technical response actions into clear, defensible records. Teams can export details, show chain of custody, and support demonstration of clean, validated recoveries, helping them work toward meeting regulatory requirements and building trust with stakeholders.

Overall, these new features further enhance our Commvault cyber recovery platform to a broader cyber resilience platform that helps detect faster, recover smarter, and validate that your data is safe and clean.

To learn more, watch the Commvault Cyber Recovery demo.

FAQ

Q: What makes these updates different from traditional backup solutions?

A: The focus has shifted from routine data backup to cyber resilience – emphasizing faster threat detection, cleaner recovery from cyber events specifically, and compliance validation.

Q: Who are these features designed for?

A: Primarily security and data protection teams that need faster insights, cleaner recovery processes, and documented proof that data is safe and recoverable.

Q: How does Arlie help non-technical users?

A: Arlie helps summarize incidents into clear narratives (what happened, when, which systems were affected) and recommend specific next steps, so teams don’t need deep technical expertise to act decisively.

Q: What is Synthetic Recovery, and when should I use it?

A: Synthetic Recovery automatically locates and assembles the most recent clean file versions after a cyber event. It is useful when you need to recover quickly and reduce the risk of restorating compromised data.

Q: What is Cleanroom Recovery used for?

A: It helps provide a secure, isolated environment for deep forensic analysis of an attack – useful for investigating threats, preserving evidence, and proving to regulators that proper containment procedures were followed.

Q: How does the platform support regulatory compliance? A: It generates exportable reports with chain-of-custody details and validated recovery records, giving teams the documentation needed to meet regulatory requirements and build stakeholder trust.

Nico Guerrera is Senior Technical Marketing Manager at Commvault.

More related posts


Cyber Recovery

Read more about Cyber Recovery

AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Points clés à retenir

  • Detection alone is not enough – organizations need integrated, orchestrated recovery to minimize business disruption from ransomware.
  • The CISCO XDR and Commvault® Cloud integration connects threat detection directly to clean recovery actions within the same security workflow.
  • Une reprise sans risque nécessite des processus de restauration validés et isolés afin de réduire le risque de réinfection et de rétablir les opérations en toute confiance.
  • Le déclenchement des actions de Backup and Recovery directement à partir des outils de sécurité permet de préserver rapidement les données critiques et de raccourcir les délais de Recovery.
  • La résilience unifiée associe sécurité et Recovery, ce qui contribue à réduire les frictions entre les environnements de détection et de réponse étendues (XDR) et d’orchestration, d’automatisation et de réponse en matière de sécurité (SOAR), tout en améliorant la rapidité et la fiabilité des interventions.

If there’s one thing I’ve learned from talking with security leaders across industries, it’s this: Detection is only half the job. The other half, the part that determines whether the business keeps moving, is response and recovery. And when ransomware hits, recovery isn’t just about speed. It’s about confidence, it’s about cleanliness, and it’s about speed.

That’s why this announcement matters. We’ve expanded our partnership with Cisco with a new integration between Cisco XDR and Commvault Cloud, built to unite ransomware response and recovery in a single, coordinated workflow.

Too many organizations still live with a painful gap between what security teams see and what IT teams can safely do next. When every second counts, that gap becomes the difference between containing an incident and watching it evolve into business disruption. With this integration, teams can move from detection to decisive recovery actions inside the security operations workflow, helping minimize impact when time is the enemy.

And here’s the truth: In a crisis, the business doesn’t care who owns which “console.” The business cares about outcomes. Can we preserve critical data early? Can we recover cleanly without reinfection? Can we restore the right systems confidently instead of guessing? How fast can we get back to « viabilité minimale »? That’s the gap we’re closing, bringing recovery actions into the de réponse aux incidents flow, where decisions are already being made.

This is where “clean recovery” stops being a talking point and becomes the new standard.

Recovery has turned into an exercise in trust: trust that your recovery points are safe, trust that your backups aren’t already compromised, and trust that you’re not reintroducing risk while trying to restore operations. The uncomfortable reality is that defenders increasingly have less time to respond.

According to Sophos’ 2026 Active Adversary Report, “the speed with which attackers attempt to go after AD after gaining access to the system sped up by 70% over last year, down to a median of just 3.40 hours.”

That kind of speed forces de réponse aux incidents to operate in an immediate, orchestrated way across silos, and it raises the bar for recovery. Because fast restores don’t help if they aren’t clean.

With this new integration, security operations teams can trigger Commvault Cloud actions directly from Cisco XDR, helping preserve data early and move toward clean recovery.

If a SOC manager gets notice of a threat detected in Cisco XDR, they can initiate a backup of core infrastructure VMs right away, and then restore impacted systems into Commvault Cloud Cleanroom Recovery, a secure, isolated cloud environment designed for investigation and validation, before confidently returning systems into production. This brings recovery actions in the same workflow as detection, so teams can respond faster and recover with confidence.

The result is a tighter connection between detection and recovery, so security teams can act decisively at the earliest signs of an attack. By validating recovery in an isolated cleanroom before returning systems to production, organizations reduce reinfection risk, preserve critical data, and shorten recovery timelines, all from tools SOC teams already trust.

 

A Commitment to Unified Resilience

Zooming out, this integration with Cisco XDR is an important milestone, and it’s also part of a bigger direction we’re committed to: unified resilience, where security and recovery work together instead of operating in separate lanes. And it’s not an “either/or” proposition. It’s a growing ecosystem designed to meet teams where they work.

Another great example of this is our integration with Splunk SOAR, that helps improve threat detection and drive faster, more automated response. Commvault can send threat detection, data security, and backup and recovery intelligence directly into Splunk, enriching security events and helping alert SecOps teams and automated actions in Splunk can reduce response time without bouncing between interfaces.

So, whether a customer’s operational hub is XDR or SOAR, the goal stays the same: reduce friction, speed decisions, and make recovery provable.

The Cisco XDR integration is generally available globally and offered at no additional cost to existing Commvault customers. If you want to dig deeper, here are a few good places to start:

Oucontactez-moi sur LinkedIn, and I’m happy to talk through what “detection to clean recovery” looks like in the real world.

FAQs

Q: Why is detection only half the battle in ransomware response?
A: Detection identifies threats, but response and recovery determine whether the business can continue operating. Without a coordinated recovery plan, even fast detection can still lead to prolonged downtime and disruption.

Q: What does “clean recovery” mean in practice?
A: Clean recovery involves restoring systems in a secure, isolated environment to validate that backups are uncompromised before returning them to production. This approach helps reduce the risk of reinfection and enable greater confidence in restored systems.

Q: How does the Cisco XDR and Commvault integration improve de réponse aux incidents?
A: The integration allows security teams to trigger backup and recovery actions directly from Cisco XDR. This unified workflow helps preserve data early, initiate secure restoration, and move from detection to recovery without switching between disconnected tools.

Q: What role does the Cleanroom Recovery environment play?
A: Cleanroom Recovery provides an isolated cloud space for investigation and validation of restored systems. Teams can analyze and confirm system integrity there before confidently bringing workloads back into production.

Q: How does this integration support broader security ecosystems like SOAR?
A: In addition to Cisco XDR, Commvault integrates with platforms like Splunk SOAR to enrich threat intelligence and automate response actions. This ecosystem approach helps security teams reduce friction, accelerate decisions, and make recovery outcomes more predictable.

Q: Is the Cisco XDR integration available to existing customers?
A: Yes, the integration is generally available worldwide and is offered at no additional cost to existing Commvault customers, making it easier to adopt unified detection and recovery workflows.

Michael Fasulois Senior Director, Portfolio Marketing, at Commvault.

Related BlogsLes innovations en matière de Cleanroom Recovery ouvrent une nouvelle ère en matière de cyber-résilience

Commvault inaugure une nouvelle ère de résilience d’entreprise unifiée

La prochaine évolution dans la protection Cloud

Les 5 étapes essentielles d’une guérison propre

Votre manuel de jeu moderne pour une réponse rapide et une récupération propre

More related posts


Cyber Resilience

Read more about Cyber Resilience

There’s a lot of talk about modernization – Cloud, AI, automation, security transformation. But what does modernization actually look like when you’re responsible for keeping systems running, data protected, and recovery viable under pressure?

In this episode of STRIVE, I had the pleasure of sitting down with Gilman Treantos – a 25-year IT veteran whose career spans everything from mainframes to modern cyber resilience architecture. This conversation provides a practitioner’s view of what modernization really means when outages, ransomware, and operational risk are part of the daily equation.

Watch the épisode.

Key Takeaways: What Modern Cyber Readiness Actually Requires

  • Modernization isn’t about new tools – it’s about resilient architecture. Technology evolves, but recovery discipline, testing, and cross-team coordination are what separate reactive organizations from resilient ones.
  • Cyber readiness demands collaboration between security and infrastructure. Silos create blind spots. Unified visibility and shared responsibility can create speed in recovery.
  • Backup tools are more powerful than most teams realize. When used creatively, they can support large-scale migrations, isolated recovery, and transitions designed to minimize data loss.
  • Testing is non-negotiable. A recovery plan that hasn’t been rehearsed is a liability, not a strategy.
  • Career resilience mirrors technical resilience. Proactivity, curiosity, and willingness to solve hard problems are as critical as any platform.

From Blockbuster to Cyber Resilience

Gilman’s journey didn’t start in a war room or a security operations center. It started at Blockbuster.

Without formal IT training, he leaned into troubleshooting. That curiosity became mainframe work. That work became distributed systems. That evolved into data protection and cyber resilience leadership.

What stands out isn’t the career arc – it’s the mindset. He built a reputation by taking on the problems no one else wanted. Fixing fragile systems. Supporting overlooked initiatives. Solving issues that crossed organizational boundaries.

That mentality translates directly to modernization, because modern cyber readiness is built by people willing to dig into uncomfortable complexity.

Sneak Peek: The Modernization Playbook

In this segment, Gilman explains why modern cyber recovery requires more than traditional malware detection — and how anomaly detection, ThreatScan, and isolated recovery environments can help strengthen enterprise resilience.

Modernization Under Pressure

One of the most compelling parts of the episode is a real-world example: evacuating a remote data center in a single night. No data loss. No prolonged downtime. No operational chaos.

By leveraging Commvault LiveSync in a creative way, Gilman and his team were able to migrate infrastructure quickly and cost-effectively – using capabilities that weren’t originally designed for that exact scenario.

That’s modernization in practice.

The House of Cards Problem

As organizations scale, permissions sprawl. Backup systems grow complex. Security tools layer on top of infrastructure without full alignment. Over time, environments become fragile.

Gilman describes this dynamic as something many teams underestimate: a slow accumulation of technical and operational debt. Modernization, in his view, isn’t just upgrading platforms. It’s simplifying architecture, improving visibility, and breaking silos between cybersecurity and infrastructure teams.

Cyber readiness means:

  • Security and backup teams share telemetry.
  • Recovery environments are isolated and tested.
  • Malware detection extends beyond primary workflows.
  • Infrastructure decisions consider recovery speed.

This is where modernization and resilience intersect.

Threats Are Evolving. So Must Recovery.

Ransomware isn’t slowing down. Threat actors are more sophisticated. Malware hides inside legitimate workflows. Gilman’s perspective is blunt: Preparation must be proactive.

He advocates for:

  • Regular disaster recovery testing
  • Isolated recovery environments ready to activate
  • Anomaly detection tools layered into backup processes
  • Cross-team drills that simulate real-world disruption

Watch the Full Episode

Check out our full STRIVE conversation to learn:

  • How Gilman evolved his approach to data protection over 25 years.
  • The details behind migration designed to minimize data loss.
  • Why collaboration between security and infrastructure is essential.
  • Practical advice for resilience professionals.
  • What modernization really demands in today’s threat landscape.

Regardez-le dès maintenant.

If you care about resilience, recovery, or leading IT through uncertainty, this is 20 minutes well spent.

FAQs

Q: What does “modernization” mean in the context of cyber readiness?

A: It means building resilient, testable, and collaborative systems that can recover quickly under real-world pressure – not just upgrading to newer platforms.

Q: Why is collaboration between security and infrastructure teams so important?

A: Because recovery depends on shared visibility. Security detects threats, but infrastructure enables restoration. Without alignment, response slows and risk increases.

Q: How can backup tools support modernization beyond recovery?

A: When used creatively, they can enable data center migrations, isolated recovery environments, anomaly detection, and large-scale operational shifts.

Q: How often should disaster recovery environments be tested?

A: Regular testing – ideally quarterly or aligned with major infrastructure changes – builds confidence and reveals gaps before an actual incident.

Chris Mierzwa is Senior Director, Portfolio Marketing, at Commvault.

Related BlogsComment la SMMPA a renforcé sa cyber-résilience grâce à Cleanroom Recovery

Readiness à la cybersécurité dans un contexte de tensions géopolitiques : conseils à l’intention de nos clients, partenaires et de notre communauté

Pourquoi l’IA compromet votre stratégie de résilience (et comment y remédier)

Physique contre marketing : accélérer la Recovery tout en respectant les lois de la physique

Moderniser la cybersécurité financière : De la réactivité à la résilience

More related posts


Readiness

Read more about Readiness

The RSA Conference, held from March 23 – 26 in San Francisco, is one of the premier events in the cybersecurity industry, bringing together experts, thought leaders, and innovators to discuss the latest trends and solutions in cyber resilience and data protection.
The energy was palpable, the learning top-notch, and the city buzzing. With so much to see, including our ResOps Rumble and The Rumble After Party on Monday evening, we wanted to make sure you didn’t miss these exciting announcements from Commvault.
Key Takeaways

  • Commvault earned major industry recognition with a Global InfoSec Award for innovation in cyber resilience.
  • Expanded threat hunting capabilities help organizations detect risks in backups and recover clean data faster.
  • New data and AI security enhancements help extend visibility, classification, and governance across structured and unstructured data.
  • Integration with Microsoft Security helps enable faster, coordinated threat detection and recovery workflows.
  • Strategic partnerships and industry initiatives highlight a shift toward unified resilience operations as a core security discipline

  1. Commvault wins the 2026 Market Disruptor Cyber Resilience Global InfoSec Award.

After being named Outstanding in the Cyber Resilience category at the 2025 Global InfoSec Awards, we have accelerated our innovation roadmap, redefining cyber resilience beyond traditional backup and recovery to help address the realities of today’s AI-driven threat landscape.
This year, Global InfoSec has recognized Commvault as Market Disruptor in the cyber resilience category. We provide a unified cyber resilience platform designed to deliver AI-enabled data protection, proactive threat detection, advanced ransomware recovery, and a single operational view across enterprise environments.
Unlike other solutions, Commvault® Cloud helps empower customers to protect, recover, and manage their data, applications, and production workloads – across on-premises, public, private, hybrid, SaaS, and multi-cloud environments.
On the topic of market disruption and innovation, we have made a few major announcements leading up to the conference.

  1. Commvault Announces Expanded Threat Hunting Capabilities

Werecently announced expanded threat hunting capabilities within Commvault Cloud Threat Scan. The enhancements help organizations rapidly identify risks within backup environments and recover validated clean data, helping reduce reinfection risks and prolonged downtime.
To address this challenge, Commvault now delivers two complementary scanning modes within Commvault Cloud Threat Scan:

  • Hyper Threat Hunting helps enable targeted searches across backup data using threat hunting artifacts such as hashes and YARA rules to identify known indicators of compromise at scale. Hash-based hunting helps provide fast, index-based detection, while YARA-based analysis helps support more targeted pattern matching for deeper investigation.
  • Deep Inspection provides layered file-level analysis using malware signatures, machine learning, heuristic analysis, and AI-enabled encryption detection to help uncover known threats, suspicious variants, and ransomware related activity that may evade exact-match indicators alone.

Together, these detection modes allow close collaboration across incident response and recovery teams to isolate affected data and help make informed recovery decisions. They can schedule recurring scans for continuous monitoring or conduct targeted searches during active incident response scenarios, helping provide flexibility for both ongoing protection and time-sensitive response.

  1. Commvault Announces an Expansion of Data and AI Security Capabilities

On the same day,we announced an expansion of data and AI security capabilities within Commvault Cloud, enabled via our récente acquisition de Satori. The advancements extend data discovery, classification, and risk assessment into structured data environments and introduce real-time access governance for structured databases, including vector databases used in AI applications. These innovations expand Commvault’s existing data security posture management functionality for unstructured data, while data access governance adds real-time control of structured data access.
These advancements also unify visibility by identifying sensitive data, surfacing exposure and policy violations, and consolidating risk insights to help organizations prioritize remediation based on impact. This helps yield improved resilience, prioritized risk remediation, support for compliance, and reduced data exposure to help strengthen resilience across both production and backup data.

  1. Commvault Announces an Expanded Integration with Microsoft Security

On the first morning of the conference, we announced anexpanded integration with Microsoft Security to better connect threat detection with trusted recovery. The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the Commvault Cloud platform to streamline resilience operations (ResOps) and enable real-time data insights, helping organizations move quickly from identifying a threat to validating and restoring clean data faster and with greater confidence.
This new integration helps enable coordinated workflows between security and recovery teams. Security alerts from Commvault Cloud are ingested into Microsoft Sentinel data lake where security operations center analysts can enrich these incidents with partner intelligence to access impact and validate scope. In the coming quarters, these insights can help drive automated, policy-based recovery workflows to accelerate and orchestrate clean recovery. You can learn more from our blog here.

  1. NetApp and Commvault Advance Cyber Resilience with Strategic Alliance 

On the topic of alliances, we alsoannounced a strategic alliance with NetApp® to deliver a powerful, integrated solution for enterprise data protection and cyber resilience. The unified solution enables resilience, security, and rapid recovery for customers across on-premises and cloud environments, helping give organizations confidence that their data is available, immutable, and recoverable.
This alliance addresses a critical need for scaling resilience via unified cyber detection and ransomware recovery. By combining Commvault’s leading resilience, protection, and recovery capabilities with NetApp’s enterprise-grade data platform with built-in intelligence and AI-enable ransomware detection, together we’re creating a highly differentiated, end-to-end cyber resilience solution.

  1. TIME + Commvault CISO of the Year

Last but not least in a newsworthy few weeks, we are very excited to announce thelaunch of the inaugural TIME and Commvault CISO of the Year Award. The branded award, selected by Commvault and a panel of industry experts, recognizes enterprise security leaders who are not only defending against cyber threats but also redefining resilience in an increasingly complex threat landscape.
The CISO of the Year Award recognizes leaders who are transforming cybersecurity into a driver of trust, operational strength, and long-term resilience. They embrace critical practices and emerging disciplines, including ResOps, which is rapidly becoming a core discipline for modern enterprise security.
Les candidatures for the CISO of the Year Award will be accepted by Commvault from March 23 through June 20, 2026. Submissions will be reviewed by a panel of industry experts. The panel and Commvault will choose finalists and the winning CISO of the Year based on pre-defined criteria. You can read more about the criteria on the nominations page.
Commvault Cyber Resilience a Highlight of RSAC

RSAC 2026 made one thing clear: Cyber resilience is no longer a future aspiration – it’s a present-day mandate. From industry recognition to expanded threat hunting, deeper data and AI security, and stronger ecosystem integrations, Commvault continues to push the boundaries of what organizations can expect from a modern resilience platform.
These announcements reflect a broader shift toward unifying security, data protection, and recovery into a cohesive strategy that helps organizations act faster, respond smarter, and recover with confidence in the face of evolving threats.
As the threat landscape grows more complex, the ability to not only detect and defend but also recover with great confidence is becoming a defining competitive advantage. The innovations highlighted at RSAC – alongside strategic partnerships and recognition of industry leaders – underscore Commvault’s commitment to enabling that outcome.
If RSAC is any indication of where the industry is headed, ResOps will continue to take center stage, and organizations that embrace this approach will be well positioned to navigate whatever comes next.


FAQs

Q: What are the new threat hunting capabilities Commvault introduced?
A: Commvault introduced Hyper Threat Hunting and Deep Inspection within itsThreat Scan solution. These features combine fast detection with advanced analysis to help identify both known and emerging threats in backup data.
Q: How do Commvault’s new data and AI security capabilities benefit organizations?
A: The enhancements to Commvault’s data and AI security capabilities expand visibility into sensitive data across structured and unstructured environments. They also add real-time access governance, helping organizations reduce risk and improve compliance.
Q: What is the significance of the Microsoft Security integration with Commvault Cloud?
A: The integration helps connect threat detection with recovery by linking Commvault Cloud with Microsoft Sentinel and Security Copilot. This is designed to enable faster decision-making and more automated recovery processes.
Q: What does the Commvault and NetApp alliance bring to customers?
A: The alliance combines Commvault’s resilience platform with NetApp’s data infrastructure and AI-enabled ransomware detection. This creates a unified solution designed to deliver stronger data protection and faster recovery across environments.
Q: What is the TIME and Commvault CISO of the Year Award?
A: The TIME + Commvault CISO of the Year award recognizes a security leader who exemplifies modern resilience leadership through a ResOps approach.
This program celebrates CISOs who treat resilience as a core business capability not just a technical function, those bridging security, IT, and operations to enable their organizations to recover quickly, operate confidently, and innovate without increasing risk​​.
​​​The honoree selected ​by Commvault ​will be featured in a TIME​ ​branded​ ​article and video, with additional recognition across TIME and Commvault channels​. The honoree will also be invited to Commvault’s annual SHIFT event. ​

More related posts


Threat Scan

Read more about Threat Scan

Points clés à retenir

  • Security must scale like Agent Smith: In The Matrix, Agent Smith multiplied rapidly to overwhelm Neo. Security teams face a similar challenge today as threats and signals grow faster than analyst capacity. AI-enabled security agents help teams scale investigations without needing to scale headcount.
  • Correlating signals improves investigation confidence: The Commvault Security Investigation Agent correlates backup intelligence with security signals from platforms like Netskope, CrowdStrike, and Palo Alto Networks to determine whether threats discovered in backup data also impacted production systems.
  • Cyber resilience will become agent-driven: The Commvault Security Investigation Agent is the first step toward a future where specialized AI agents assist security teams with investigations, recovery decisions, and faster restore workflows.

Introduction

In The Matrix, there’s a moment that feels surprisingly relevant to today’s technology landscape. Agent Smith discovers he can duplicate himself. One becomes many, and suddenly Neo is surrounded by an army of identical agents operating simultaneously.

In many ways, that scene mirrors the world we’re entering today with agentic AI. Across industries, and especially in cybersecurity, we’re beginning to see the rise of specialized AI agents that can work independently, scale rapidly, and assist humans in ways that were previously impossible. But unlike Agent Smith’s relentless takeover, the goal of these agents isn’t domination. It’s defense.

Scaling while Breaking Down Silos

Security operations today face a fundamental scaling problem. The number of systems, signals, and security tools continues to grow, but the number of analysts does not.

Organizations now ingest telemetry from endpoint security platforms, network defenses, cloud monitoring tools, and identity protection systems. Each of these tools generates its own alerts and dashboards, often operating in isolation from one another. The result is an overwhelming amount of data spread across disconnected silos.

It’s tempting to assume the solution is simply hiring more analysts, but anyone who has managed large teams knows that adding people introduces its own challenges. As teams grow, communication becomes more complex, coordination slows down, and the efficiency of investigations often decreases.

What security teams really need is not just more people, but more intelligence and automation to help analysts move faster and see the bigger picture.

One of the most persistent silos in security operations has been the divide between backup systems and security tools. Traditionally, security teams monitor production environments through their security information and event management tools while backup environments operate in a separate console.

Backup data is often only examined after an incident occurs, when organizations are already deep in recovery mode. Yet attackers increasingly target backup systems precisely because they know they are critical to recovery.

Ransomware operators frequently encrypt production systems, attempt to corrupt backups, or leave malicious artifacts hidden inside protected datasets. This means that backup environments often contain valuable evidence of an attack, but that intelligence has historically been difficult for security teams to access and correlate with other signals.

The New Security Investigation Agent

Commvault’s new integration with Microsoft Sentinel and Microsoft Security Copilotis designed to close that gap. Through this integration, Commvault Cloud events can be streamed directly into the Sentinel Data Lake, bringing backup telemetry into the same analytical environment as endpoint, network, and cloud security signals.

Instead of existing in isolation, backup activity now can be analyzed alongside the broader security ecosystem. But the real power of this integration comes from the introduction of the Commvault Security Investigation Agent.

The Security Investigation Agent helps analysts investigate potential threats by correlating signals discovered in backup environments with signals coming from other security platforms. When an analyst provides the hostname of a server, the agent gathers security events generated by Commvault Threat Scan and Risk Analysis, including backup anomalies, encryption events that may indicate ransomware activity, malware detected inside protected datasets, and backups that contain sensitive data.

The agent then correlates those events with telemetry from other security tools organizations already rely on, such as Netskope, CrowdStrike, and Palo Alto Networks. By analyzing activity across these platforms together, the agent can help determine whether suspicious behavior identified in backup data also appears in production environments.

How Do You Get the Agent?

Let’s first walk you through how you can start with our first agent focused on security investigations. Then we’ll share how we plan to rapidly spawn new agents – just like Agent Smith – so customers can take control of investigations, recovery decisions, and restore operations, giving security and operations teams the intelligence they need to respond faster and recover with confidence.

Configure the Connector

Before we can enable the Commvault Security Investigation Agent, you will need to install and configure the Commvault Cloud connector.

  1. Installation: Instructions for how to install the Commvault Cloud Solution, along with permissions and pre-requisites, is, cliquez ici.

Screenshot: Installation details for the Commvault Cloud Data Connector in the Microsoft Sentinel Content Hub.

  1. Configuration: Once installed, configuration details are, cliquez ici.
 Use Commvault Security Investigation Agent

Once the Commvault Cloud connector is installed for you, you can use the new Security Investigation Agent.

  1. Go tohttps://securitycopilot.microsoft.com/agents.
  2. Search for “Commvault Security Investigation Agent.”
  3. Click on “Set up” Agent.
  4. Click on “Go toAgent.”
  5. Click on “Run” => “One time.”
  6. Provide the “Hostname” for the host you’d like help investigating, and click “Submit.”
    1. Note: Hostname is the name of the server that we want to check for events of Commvault and partners like Netskope, CrowdStrike and Palo Alto.
  7. The agent will run and you will get a detailed analysis and recommendations as a result.

Screenshot: The detailed analysis of the Commvault Security Investigation Agent being run on a host that is part of an investigation.

Conclusion

The Matrix may have dramatized the idea of multiplying agents, but it captured an important truth about scale. When Agent Smith multiplied, the dynamics of the fight changed entirely.

Cybersecurity is undergoing a similar shift. Attackers are increasingly leveraging automation and AI to scale their operations. The only way defenders can keep pace is by scaling their own capabilities through intelligent systems that augment human expertise.

With the integration between Commvault, Microsoft Sentinel, and Microsoft Security Copilot – and with the introduction of the Commvault Security Investigation Agent – we are beginning to see what that future looks like. It’s a world where security operations are no longer constrained by silos, where investigations move faster, and where AI-enabled agents work alongside analysts to strengthen cyber resilience across the entire environment.

Over the coming year, Commvault plans to introduce additional agents – just like Agent Smith multiplying in The Matrix – that can help security teams run Commvault Threat Scan, spin up Cleanroom environments for SOC analysts to safely investigate incidents, and accelerate recovery by identifying the safest data to restore.

We’re also excited to collaborate with Microsoft to enable customers to use Microsoft Foundry to build and extend their own agents, allowing them to tailor automation and investigations to their unique environments.

By combining Commvault’s deep cyber resilience capabilities with Microsoft’s AI and security ecosystem, we’re helping organizations move toward a future where intelligent agents help analysts investigate faster, break down silos, and strengthen resilience across the entire environment.


FAQs

Q: What are AI agents in security operations (SecOps/ResOps)?
A: AI agents are specialized, autonomous tools that assist security teams by analyzing data, correlating signals, and supporting investigations. They operate alongside human analysts to help accelerate decision-making and improve response times across complex environments.

Q: Why is scaling security operations such a challenge today?
A: Security teams face an explosion of alerts and data from multiple tools, while analyst headcount grows slowly. This imbalance creates bottlenecks, making it difficult to investigate threats efficiently without automation and intelligent assistance.

Q: How does the Commvault Security Investigation Agent improve threat investigations?
A: The agent correlates backup data with signals from security platforms like CrowdStrike, Netskope, and Palo Alto Networks. This combined view helps enable analysts to determine whether threats detected in backups also impacted production systems, increasing confidence in investigations.

Q: What problem does integrating backup data into security workflows solve?
A: Backup environments often contain critical evidence of attacks but have historically been siloed from security tools. Integrating this data helps enable teams to analyze threats holistically, uncover hidden risks, and make more informed recovery decisions.

Q: How can organizations start using the Commvault Security Investigation Agent?
A: Organizations need to install and configure the Commvault Cloud connector within Microsoft Sentinel. Once set up, the agent can be accessed through Microsoft Security Copilot to run investigations by simply providing a hostname.

Q: What does the future of AI agents in cyber resilience look like?
A: The future points toward multiple specialized agents helping handle investigations, recovery planning, and restore operations. These agents will help break down silos, accelerate response, and enable more resilient security operations across the entire environment.Ritu Singh is Senior Product Manager and Rich Vorwaller is Director, Product Management, at Commvault.


Blogs connexes

MCP 2.0 Explained: Securing AI Agents Before They Secure Themselves

Pourquoi l’IA compromet votre stratégie de résilience (et comment y remédier)

Rester résilient face aux attaques par accès latéral

Êtes-vous prêt à faire face aux boucles de fuite de données ?

Tendances en matière de ransomware pour 2026 : IA, résilience et MTCR

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • L’IA accélère la création de données et les flux de travail distribués, rendant les approches réactives traditionnelles insuffisantes pour garantir la résilience.
  • Les opérations de résilience (ResOps) aident les équipes à passer d’un dépannage réactif à une action coordonnée. Commvault applique l’IA dans trois domaines : la protection des données, des modèles et des pipelines d’IA ; l’utilisation de l’IA pour orienter et accélérer les interventions ; et l’extension de l’IA à l’ensemble de l’écosystème de résilience.
  • Des agents IA pratiques sont conçus pour mettre en évidence les problèmes opérationnels (Arlie Data Sense), orienter les décisions de protection (Arlie Advisor) et permettre des flux de travail conversationnels (serveur MCP).
  • La sécurité et la gouvernance des données restent fondamentales. L’IA doit être entraînée à respecter les contrôles d’accès, à garantir l’auditabilité et à fonctionner dans les limites des politiques définies.
  • Les organisations peuvent commencer modestement avec des agents ciblés, puis évoluer vers des opérations coordonnées et intelligentes.

AI introduces both new challenges and potential breakthroughs for enterprise resilience. On one hand, traditional siloed tools for protection, recovery, and governance weren’t designed to operate across constantly evolving AI environments that span multiple platforms.
On the other hand, AI-enabled resilience tools can deliver a transformative impact by helping teams maintain visibility, enforce policy, and recover cleanly. For IT and security teams, the question is how best to leverage the benefits of AI while mitigating the operational risks it can pose.
Lors d’un récent webinaire, j’ai rencontréTeja Medasani, chef de produit principal en IA chez Commvault, afin d’explorer des cas d’utilisation concrets où des agents IA sont mis à contribution dans des workflows de résilience sur des plateformes cloud, SaaS, sur site et natives de l’IA.

Pourquoi l’IA redéfinit les opérations de résilience

The rapid growth and dynamic nature of AI-native environments have put operational workflows under pressure. Manual tagging, spreadsheets, and logic quickly drift out of sync. Sprawling job history tables and audit trails slow manual troubleshooting and make subtle warning signs easy to miss. Recovery processes that assume centralized data and isolated failures are poorly suited for exponential data growth and fragmented workloads across platforms.
When data, workloads, and environments span platforms, resilience can’t remain siloed in separate teams, tools, and policies. A new operating model is needed: les opérations de résilience, ou ResOps.

À quoi ressemblent les ResOps dans la pratique ?

Le cadre ResOps répond à ces défis selon trois axes :

  • Protect AI: Safeguarding AI data, models, and pipelines across environments so they remain recoverable and compliant.
  • Leverage AI: Using AI to help reduce manual effort, surface operational insight, and guide response and recovery decisions.
  • Extend AI: Connecting ResOps across tools and teams to help protect conversational interactions and integrated workflows.

Au cours du webinaire, nous nous sommes principalement concentrés sur l’exploitation et l’extension de l’IA, en mettant en avant les rôles clés que les agents IA peuvent jouer dans les opérations quotidiennes. Ces exemples s’articulent autourArlie, Commvault’s AI assistant. Designed to help users interpret data, understand issues, and move toward action more efficiently, Arlie includes a bibliothèque d’agents purpose-built to help address specific resilience workflows.
By helping reduce repetitive analysis, surfacing meaningful signals, and guiding decisions around security-aware recovery, these agents can help teams take actions more quickly and confidently. Arlie Data Sense, Arlie Advisor, and Commvault’s le serveur MCP illustrate a few of the possibilities unlocked by AI-enabled ResOps.

Mise en évidence des problèmes opérationnels avec Arlie Data Sense

Arlie Data Sense aide les équipes à donner du sens à des données opérationnelles denses, telles que les tableaux d’historique des tâches et les pistes d’audit. Au lieu de parcourir manuellement des centaines de lignes pour repérer des tendances ou diagnostiquer des défaillances, les utilisateurs peuvent demander àArlie to help analyze the data and generate an executive summary highlighting anomalies and emerging issues.
Teams can ask follow-up questions in natural language and explore data further through interactive summaries or visualizations. When a job fails, Arlie can help analyze logs, summarize the failure, identify the possible cause, and provide next steps for resolution.

Orientez vos décisions d’intervention avec Arlie Advisor

À mesure que les charges de travail s’accumulent, que les responsabilités changent et que les exigences évoluent, il devient de plus en plus difficile de maintenir une couverture de protection cohérente dans tous les environnements.Arlie Advisor is designed to help teams create and validate protection plans at scale by evaluating the characteristics and current protection coverage for each resource, and then highlighting where adjustments may be needed.
Recommendations are presented clearly with reasoning explained, so teams can evaluate them and decide how to apply them within existing governance processes. This helps teams maintain consistency across dynamic environments.

Étendre les workflows de résilience avec le serveur MCP

Resilience workflows often need to connect with ticketing systems, collaboration tools, and security platforms outside the Commvault platform, and they need to be accessible to users who aren’t resilience experts. Commvault’s le serveur MCP makes it possible to extend workflows without custom integrations or significant training by allowing conversational interaction.
Users can ask questions or request actions in natural language, with their prompts translated into governed API calls behind the scenes – for example, to automatically create tickets in ServiceNow for failed jobs.

Coordination et clarté entre les équipes et les plateformes

The examples above share a common theme: coordination. Effective resilience requires visibility, policy enforcement, and clean recovery across environments. AI can help strengthen these capabilities by helping teams identify what matters and act more quickly.
While the evolution of resilience from reactive recovery to continuous insight and guided action has become essential, it doesn’t need to happen all at once. Teams can start with targeted agents that address specific operational pain points and then build toward more coordinated operations as capabilities mature and teams gain confidence.
The key is to begin the ResOps journey now – because the challenges posed by evolving resilience requirements will only keep growing.
Regardez l’intégralité du webinaire à la demande to see detailed demos of Arlie Data Sense, Arlie Advisor, and conversational resilience in action, and explore how AI-enabled ResOps can help support your operational workflows.

FAQ

Q: What is resilience operations?

A: ResOps is an operating model that unifies data security, identity resilience, and cyber recovery into a continuous, automated discipline rather than treating them as separate IT functions. ResOps helps transform resilience from a reactive response to incidents into an active practice that helps continuously understand data access patterns, detect threats and anomalies, and enable fast, intelligent recovery at scale.
Q: What is Arlie and how has it evolved?

A: Arlie, short for autonomous resilience, was first introduced in 2023 as an AI assistant to help users navigate the Commvault platform more easily. As AI capabilities have evolved, Arlie has evolved as well.
In addition to answering questions and guiding configuration, Arlie now also includes a library of purpose-built agents to address specific resilience workflows, such as surfacing operational insights, recommending protection strategies, and guiding security-aware recovery decisions. Arlie has become an entry point into operational insight rather than just a how-to assistant.
Q: How does Arlie Data Sense help with operational troubleshooting?

A: Arlie Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find subtle warning signs or diagnose issues, users can trigger Arlie to analyze the full data set and generate an executive summary highlighting patterns, anomalies, and emerging issues.
Teams can ask follow-up questions in natural language and explore data through interactive summaries or visualizations. For failed jobs, Arlie provides root-cause analysis by analyzing logs, summarizing failures, identifying possible causes, and providing personalized next steps for resolution.
Q: What does “guided action” mean in the context of AI-enabled resilience?

A: Guided action refers to AI helping teams move from insight to response more efficiently by recommending specific actions based on analysis of operational data and protection coverage. Rather than simply surfacing information, AI agents like Arlie Advisor help evaluate resource characteristics, identify gaps between current protection and policy expectations, and present clear recommendations with reasoning.
Teams retain decision-making authority and can evaluate recommendations within their existing governance processes, but the agent helps reduce the manual effort required to identify what needs attention and what actions may be appropriate.
Q: How does le serveur MCP enable conversational resilience workflows?

A: le serveur MCP uses Model Context Protocol technology to enable conversational interaction with resilience workflows through natural language. Users can ask questions or request actions in everyday language, and those requests are translated into governed API calls behind the scenes.
Identity, role-based access control, and audit logging remain in place, so the conversational interface doesn’t bypass security requirements. This approach helps reduce friction for experienced teams, lower barriers for new users, and enable resilience workflows to integrate more easily with other enterprise systems like ticketing platforms through standardized interfaces.
Q: How does Commvault enable AI to respect security and governance requirements?

A: In Commvault Cloud, AI interactions inherit the same identity and role-based access controls that govern the rest of the platform. When AI surfaces insights or recommends actions, it operates within the governance framework customers already rely on.
This means AI respects existing access controls, maintains auditability through standard logging, and operates within clearly defined policy boundaries. The architecture is designed to prevent natural language interactions or agent recommendations from bypassing the security and governance requirements already in place for the platform.
Q: Can organizations adopt AI-enabled ResOps incrementally?

A: Yes. Organizations can start with targeted AI agents that address specific operational pain points rather than transforming their entire resilience practice at once. For example, teams might begin by using Arlie Data Sense to help surface insights from operational data, then add Arlie Advisor to help maintain protection coverage at scale, and later enable conversational workflows through le serveur MCP for easier integration with other systems.
This incremental approach allows teams to build confidence with AI-enabled capabilities, demonstrate value in specific workflows, and scale toward more coordinated, intelligent operations over time as the organization’s needs and capabilities evolve.
Vir Choksi is Principal Product Marketing Manager at Commvault.

Blogs connexes

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Note: “MCP 2.0” is used here as a colloquial reference to the next-generation evolution of the Model Context Protocol. MCP itself uses date-based versioning (e.g., the latest release being 2025-11-25 at the time of this document’s release) and does not officially define a 2.0 release.

AI agents are no longer just answering questions – they’re taking action. They’re reading files. They’re modifying systems. And in some cases, they’re making decisions that ripple across an entire enterprise.That’s why Model Context Protocol (MCP) 2.0 matters.In a épisode récent de STRIVE, Commvault’s thought leadership series on cyber readiness, I sat down with Werner Nel, Principal, Security and AI Intelligence, at Commvault, to unpack what MCP 2.0 really changes – and why security leaders can’t afford to treat it as a minor spec update.This isn’t a theoretical conversation. It’s a practical look at how enterprises can enable AI innovation without widening their blast radius.

Points clés : ce que MCP 2.0 change réellement

  • Le MCP 2.0 marque un tournant : on passe de l’adoption de l’IA à la responsabilisation.
  • OAuth peut permettre un accès avec le moins de privilèges possible pour les agents d’IA.
  • Les schémas structurés peuvent contribuer à limiter l’injection de prompts et les abus.
  • Les flux d’interrogation peuvent ajouter des points de pause critiques pour les actions à haut risque.
  • MCP 2.0 may help improve security – but doesn’t eliminate risk.
  • Il est essentiel de bien comprendre les prérogatives des agents et leur rayon d’impact.

Pourquoi MCP 2.0 marque un tournant

MCP 1.x was about adoption.It gave enterprises a way to connect AI models to real tools and real data. But as Werner explains, that first wave was never designed to answer the hardest question: How do we let AI agents execute real work inside the enterprise – without turning them into a security liability?

MCP 2.0 is the industry’s first serious attempt to answer that question.Instead of focusing purely on connectivity, it shifts attention to authorization, control, and visibility – three things security teams care deeply about, especially as agents move from read-only assistants to actors with real power.

Les trois évolutions les plus importantes en matière de sécurité

  1. OAuth comes to MCP. MCP 2.0 introduces OAuth support, giving enterprises a standardized way to assign permissions and enforce least privilege. Instead of relying on vague trust assumptions, agents can be scoped to exactly what they’re allowed to do—and nothing more.
  2. Structured schemas help reduce prompt injection risk. Structured schemas act like an allowlist for agent actions. If a tool isn’t explicitly defined in the schema, it won’t execute. This can help reduce prompt injection risk and other manipulation techniques that were easier to exploit in earlier implementations.
  3. Elicitation flows add a “pause button.” Elicitation flows can enable workflows to pause mid-execution so a high-risk step may trigger confirmation, validation, or even credential escalation. This can help shift teams from “log and hope” to more deliberate control over sensitive actions.

Aperçu : MCP 2.0 en action

Cet aperçu met en évidence pourquoi l’autorité, la portée et la réversibilité sont les trois questions les plus importantes que les entreprises devraient se poser lors du déploiement d’agents d’IA.

The Gaps MCP 2.0 Doesn’t Solve (And Why That’s Important)

MCP 2.0 is a big step forward – but it’s not the finish line. As Werner highlights in STRIVE, there are still meaningful gaps enterprises need to account for in real-world deployments.For example, enterprises still can’t fully cryptographically prove that an MCP server is the authentic original (vs. a clone or modified copy). Similarly, even if the protocol improves authorization and input discipline, organizations still need to think about signing tools and binaries, and about the environment where MCP servers and models run – because a compromise can translate into broad access depending on how it’s deployed.The takeaway: MCP 2.0 improves the protocol, but organizations still have to make smart decisions about trust, containment, monitoring, and oversight.

Un cadre simple pour évaluer les risques liés aux agents IA

One of the most practical moments in the episode is Werner’s three-question risk lens – something CISOs and architects can apply immediately:

  • De quelles autorisations dispose mon agent ?
  • Quelle est l’ampleur du rayon d’impact ?
  • Dans quelle mesure l’action entreprise est-elle réversible ?

These questions help teams move from generic “AI risk” discussions to concrete decisions about permissions, containment, and how to handle high-impact actions that may not be easy to roll back.

Regardez l’épisode complet de STRIVE

This blog only scratches the surface. In the full 20-minute STRIVE podcast, you’ll hear:

  • Pourquoi le MCP 2.0 a évolué si rapidement.
  • Les priorités actuelles des RSSI.
  • Quelle direction MCP 3.0 est susceptible de prendre.
  • Comment les équipes de sécurité peuvent suivre le rythme alors que les agents gagnent en autonomie.

Regardez l’épisode STRIVE dans son intégralité sur Readiverse.Approfondissez le sujet et évaluez votre propre niveau de Readiness.

FAQ

Q: What is MCP 2.0?

A: MCP 2.0 is an updated protocol that governs how AI models interact with enterprise tools and data, with a strong focus on security, authorization, and control.Q: How is MCP 2.0 different from MCP 1.x?

A: MCP 1.x focused on connectivity and onboarding. MCP 2.0 prioritizes securing those interactions.Q: Does MCP 2.0 eliminate AI security risk?

A: No. It can help improve security hygiene but must be paired with strong architecture and governance.Q: What is an elicitation flow?

A: An elicitation flow allows AI workflows to pause for confirmation before executing high-risk actions.Chris Mierzwa is Senior Director, Portfolio Marketing, at Commvault.


Blogs connexes

 

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

When you’re responsible for powering communities across southern Minnesota, cybersecurity isn’t just about protecting data. It’s about making sure the lights stay on. For Southern Minnesota Municipal Power Agency (SMMPA), implementing Commvault® Cleanroomwas a strategic decision that transformed their approach to cyber resilience.

Meeting the Challenge Head On

SMMPA serves as an electric wholesaler to 17 municipal utilities. With approximately 50 employees supporting critical power infrastructure, the organization must maintain constant resilience against increasingly sophisticated cyber threats, where even a short disruption could have widespread impact.

After more than a decade as a Commvault customer, SMMPA faced a new wave of cyber readiness requirements. Cyber insurance providers introduced stricter mandates, including des sauvegardes «air-gapped» and malware scanning at rest.

At the same time, the team needed confidence that it could rapidly recover mission-critical systems such as domain controllers, SQL databases, and application servers, without risking the restoration of compromised data.

“As our cyber readiness requirements evolved, we started evaluating Cleanroom more seriously,” says Alan Wagner, Manager of IT & Corporate Cybersecurity at SMMPA. “We were thinking about additional ways to safeguard and protect ourselves. Cleanroom sounded like it would be a good solution for that.”

Having relied on Commvault for more than a decade and recently expanding into Commvault Cloud SaaS protection for Microsoft 365, SMMPA viewed Cleanroom as a natural next step in strengthening its cyber resilience strategy and helping it meet new compliance expectations.

A Collaborative Implementation Journey

SMMPA’s Cleanroom deployment in March 2025 showcased the power of collaboration between its team and Commvault. Sam Mack, IT/OT and Cybersecurity Specialist at SMMPA, appreciated the responsive partnership: “The Commvault team was quick to address any questions we had during setup.”

The team worked together to optimize its VMware virtual machine configuration for the Azure environment. “We discovered we needed to install some additional tools on the virtual machines to get them running smoothly within Cleanroom,” Sam explains. This fine-tuning meant its recovery solution was calibrated for its specific infrastructure.

The result? A successful implementation that met all SMMPA’s requirements and positioned it for robust cyber resilience.

Protecting What Matters Most

SMMPA uses Cleanroom to protect its critical infrastructure, including file servers, application servers, SQL servers, virtual domain controllers, and print servers.

“We’re an Office 365 shop, and we use Commvault Cloud to back up that infrastructure,” Sam says. “In the event of a compromise, getting those domain controllers, file servers, and SQL servers is going to be our priority.”

The solution was particularly well suited to SMMPA’s environment. “I have to give Commvault and their teams a lot of credit for bringing Cleanroom to our attention,” Sam says. “Our cyber insurance policy is really big on pushing for des sauvegardes «air-gapped» and malware scanning at rest, so Cleanroom was the perfect fit.”

The Value of Confidence

While SMMPA has been fortunate not to face a real-world cyberattack requiring Cleanroom, the solution provides valuable peace of mind to the team.

“It gives me a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time,” Alan says. “Cleanroom gives us confidence that we can restore our systems without worrying that something malicious is being brought back with the data. Nothing is ever 100% guaranteed, but since implementing Cleanroom, I’ve had far fewer concerns.”

The organization conducts annual testing of its Cleanroom capabilities, with plans to potentially increase the frequency to biannual testing. This regular validation helps keep the team familiar with the recovery process and maintain confidence in its ability to respond effectively to any incident.

“Cleanroom gives us a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time – without the concern, or with a minimal concern, that there’s something malicious in the data being restored.”

– Alan Wagner, Manager of IT & Corporate Cybersecurity, SMMPA

As SMMPA continues to refine its cybersecurity strategy, Cleanroom remains a cornerstone of its defense. The straightforward integration with its existing Commvault infrastructure, combined with the specific capabilities that meet its cyber insurance requirements, made it an obvious choice.

Cara Peterson is Voice of the Customer Manager at Commvault.


Blogs connexes

More related posts


CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Points clés à retenir

  • Commvault is expanding its résilience des identités portfolio to support Okta, with Early Access expected to begin in April 2026.
  • Identity has become a primary attack vector, with107 billion identity records exposed in 2024et57% of cyberattacks starting with compromised credentials.
  • The new capabilities can help provide automated, policy-driven protectionetgranular, point-in-time recovery for critical Okta objectsetconfigurations.
  • Backup data is stored in immutable, air-gapped storage to help safeguard identity environments from ransomwareetunauthorized changes.
  • The solution extends Commvault’s unified résilience des identités platform across hybrid environmentsetwill be priced on a per-user basis.

Identity has become the new frontline of cyber defense –etthe stakes have never been higher.

Today, Commvault is announcing the expansion of its résilience des identités portfolio to include support for Okta, delivering automated protectionetrapid recovery for one of the enterprise’s most critical control planes.Early Access is expected to begin in April 2026.

As credential theft acceleratesetidentity exposures surge worldwide, organizations can no longer treat identity systems as simply another application.Identity is the gateway to everything – users, applications, APIs, automation,etincreasingly, AI agents.When identity fails, the business stops.

Why Identity Resilience Matters Now

The numbers tell a stark story:

The rapid growth of non-human, agentic,etAPI-based identities has dramatically expanded the attack surface.Meanwhile, hybrid cloud adoption, SaaS sprawl,etAI-enabled automation have elevated identity providers like Okta to mission-critical infrastructure.

While Okta is built on a resilient platform, when an identity provider is disrupted – whether due to human error, misconfiguration, ransomware, or malicious tampering – the consequences are rapid:

  • Users are locked out.
  • Applications fail to authenticate.
  • Revenue-generating systems stall.
  • Customer-facing services go offline.

And yet, many enterprises still rely on manual scriptsetad hoc processes to restore identity environments – increasing downtime, operational complexity,etrisk.

That’s the gap Commvault is helping to close.

Bringing Automated Identity Recovery to Okta

Commvault’s expanded résilience des identités capabilities can help provide automated protectionetgranular recovery for critical Okta objectsetconfigurations.

Rather than rebuilding entire environments after an incident, organizations can precisely restore what was impacted – quicklyetconfidently.

“Identity is the new cyber battleground, with most modern attacks targeting identity systems,” said Pranay Ahlawat, Chief TechnologyetAI Officer at Commvault.“By extending our résilience des identités capabilities to Okta, we’re helping customers protect one of their most critical control planesethelping ensusre they can rapidly recover accessetmaintain business continuity even in the face of disruption.”

Capacités clés

Accelerated recovery from identity disruptions: Automated, policy-driven protection of critical Okta objects – including users, groups, applications,etpolicies – can help organizations to restore access quickly following outages, operational mistakes, or cyber incidents.

Granular, point-in-time recovery: Can help precisely restore only deleted, misconfigured, or compromised objectsetsettings.No full-environment rebuilds required.

Ransomware-resistant protection: Backup data is stored in Commvault-managed immutable, air-gapped storage isolated from production environments, helping safeguard identity data from ransomwareetunauthorized changes.

Streamlined, integrated recovery: Recover complex, interconnected identity systems through a unified workflow – helping reduce operational overheadetsave valuable time during incidents.

Unified résilience des identités platform: Support for Okta extends Commvault’s single-platform approachacross hybrid identity environments, helping maintain consistent policy enforcement,governance,etrecovery across providers.

Early Access Coming April 2026

Commvault’s résilience des identités support for Okta is expected to be available through public Early Access in April 2026, with general availability planned for Summer 2026.

The solution will be offered globally as part of the Commvault Cloud Identity Resilience suiteetpriced on a per-user basis.

If identity is now the enterprise control plane, resilience must extend to identity itself.With support for Okta, Commvault continues advancing unified resilience at enterprise scale – helping organizations recover faster, minimize disruption,etstay operational in the face of escalating identity-driven cyber risk.

Learn more about résilience des identités ici.S’inscrirefor our webinar Identity Under Attack: Take Back Control with Commvault Identity Resilience, Now Supporting Okta.

FAQ

Q: Why is résilience des identités becoming a top priority for enterprises?
A: Identity systems now function as the enterprise control plane, governing access for users, applications, APIs,etAI agents.As credential theftetidentity-based attacks increase, disruptions to identity providers can immediately halt business operations.Protectingetrecovering identity infrastructure has become mission-critical.

Q: What does Commvault’s support for Okta include?
A: The expanded capabilities help provide automated protectionetgranular recovery for essential Okta objects such as users, groups, applications,etpolicies.This will help organizations restore specific items impacted by outages, misconfigurations, or cyber incidents without rebuilding entire environments.

Q: How does granular, point-in-time recovery benefit security teams?
A: Instead of performing full-environment restores, teams can precisely recover only deleted or compromised objectsetsettings.This approach helps reduce downtime, lower operational risk,etaccelerate restoration of normal access.

Q: How does Commvault protect identity data from ransomware?
A: Backup data is stored in immutable, air-gapped storage managed by Commvaultetisolated from production environments.This architecture helps safeguard identity configurations from ransomwareetunauthorized modifications.

Q: When will Okta support be available?
A: Public Early Access is expected to begin in April 2026, with general availability planned for Summer 2026.The offering will be available globally as part of the Commvault Cloud Identity Resilience suite.

Q: How does this expansion fit into Commvault’s broader resilience strategy?
A: Adding Okta support helps strengthen Commvault’s unified, single-platform approach to résilience des identités across hybrid environments.It enables consistent governance, policy enforcement,etrecovery workflows, helping organizations maintain business continuity even during identity-driven disruptions.

Katharine Colucci is a Product Marketing Manager at Commvault.


Blogs connexes

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Periods of geopolitical instability, including the current conflict in the Middle East, can lead to an increase in cyber activity from both state‑linked groups and opportunistic threat actors. Government agencies and industry organizations have encouraged businesses to maintain a heightened security posture during this time.
At Commvault, we’re doing exactly that. We’ve elevated our internal awareness, tightened our operational discipline, and reinforced our resilience measures. Commvault also works with a trusted threat intelligence partner, CloudSEK, to help monitor evolving risks and inform our security posture. We encourage our customers, partners, and peers across the industry to take similar steps to stay informed and reinforce core cyber controls.

What organizations should focus on right now

1. Know when to shift into “heightened alert” mode

Have clear internal criteria for when to increase monitoring, limit non-essential changes on critical systems, or accelerate incident‑response readiness. These moves don’t need to be dramatic – they just need to be deliberate and well‑coordinated.

2. Strengthen identity and access discipline

During periods of heightened regional tensions, many threat actor campaigns rely on compromising user accounts. Reinforce good hygiene: regular credential rotation, strong authentication, careful review of unusual login behavior, and prompt investigation of anything that looks out of place. For practical steps to reduce identity-related risk, see Commvault’s recent blog on Bonnes pratiques en matière de sécurité.

3. Pay closer attention to your internet-facing perimeter and remote access

Threat actors often take advantage of internet‑facing systems or remote access tools during global flare‑ups. Ensure these systems are well‑maintained, updated, and monitored.

4. Be prepared for potential availability disruptions

DDoS and hacktivism activity often spikes during regional conflicts. Talk with your service providers, understand your mitigation options, and rehearse your internal escalation and communications plan so you’re ready if availability becomes a target.

5. Validate your ability to recover quickly

In times of uncertainty, resilience matters as much as prevention. Ensure your critical data is backed up securely, stored in multiple forms and locations, and restorable on short notice. Practicing recovery is just as important as having the backups themselves.

6. Watch for misinformation, social engineering, and false noise

Periods of conflict tend to bring surges in defacements, false breach or shutdown claims, and social‑media‑driven narratives. Treat sensational claims cautiously, verify impacts through trusted channels, report suspicious communications quickly, and maintain steady communication practices.

7. Stay aligned with trusted advisories

Follow alerts and guidance from reputable government and industry bodies. These sources regularly highlight shifts in regional threat activity and recommend practical steps organizations can take to prepare. A few resources include: CISA Cybersecurity Advisories; UK NCSC Reports & Advisories; CERT-EU Security Advisories; and NIST National Vulnerability Database.


Stay ready, stay resilient

Cybersecurity during global instability is not about panic, it’s about posture. By staying informed, tightening foundational practices, and strengthening resilience, organizations can navigate turbulent periods with confidence.
If you’d like help reviewing your preparation or refining your approach, our team is here to support you.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • Les stratégies de résilience traditionnelles s’effondrent face à l’ampleur,à la rapidité et à l’autonomie des systèmes basés sur l’IA.
  • Les ransomwares industrialisés et les attaques basées sur l’IA ciblent désormais les systèmes de sauvegarde,sapant ainsi les fondements mêmes de la Recovery.
  • Les organisations doivent passer d’une organisation en silos des équipes chargées de la sécurité et de la Recovery à un modèle unifié et continu appelé « opérations de résilience ».
  • La résilience basée sur l’IA nécessite une visibilité des données en temps réel,une détection continue des menaces et une Recovery intelligente et propre à grande échelle.
  • Les plateformes modernes permettent une Recovery rapide et vérifiée,aidant ainsi les entreprises à éviter le compromis entre une restauration rapide et une restauration sécurisée.

Alors que les entreprises se précipitent pour adopter l’IA,les RSSI et les DSI prennent conscience d’une réalité brutale : les stratégies de résilience qui fonctionnaient pour les infrastructures traditionnelles ne tiennent plus la route. Des systèmes qui pouvaient se remettre d’une attaque en quelques heures peuvent désormais mettre plusieurs jours. Les approches de sauvegarde conçues pour des données centralisées peuvent rencontrer des difficultés face à des charges de travail réparties entre les clouds et les plateformes d’IA. Parallèlement,les menaces et les vulnérabilités potentielles ne cessent de croître de jour en jour.Lors d’un récent webinaire,Tim Zonca,vice-président du marketing de portefeuille chez Commvault,a abordé une question urgente à laquelle sont confrontés les responsables de la sécurité : comment maintenir la résilience alors que l’IA bouleverse fondamentalement les règles du jeu ?

What Industrialized Ransomware and AI Mean for Resilience

CISOs and CIOs are under pressure. In spite of billions spent on cyber defense,nation-states and professional crime rings continue to reap ever larger payoffs from their victims. Ransomware-as-a-service has become widespread,and advanced AI automation is accelerating the industrialization of malware. By including backup systems in their attacks,adversaries are undermining the very foundation of resilience.

As attacks become more sophisticated,targets are becoming more vulnerable. AI is scaling faster than organizations can secure,with exponential data growth,fragmentation across environments,more complex supply chains,and autonomous systems operating with minimal oversight. AI agents and non-human identities now outnumber humans 80 to 1. When these systems make mistakes or expose vulnerabilities,the impact can cascade across interconnected business processes.

Breaches and failures are now almost inevitable; the only question is whether you can recover fast enough to keep your business running. For organizations using legacy systems that assume human-controlled systems,centralized data,and isolated failures,the answer may well be no.

Making Resilience Operational

As AI agents make decisions across the environment,including a significant number of errors,it’s no longer enough to focus on protecting infrastructure. Security leaders must now broaden their operational focus across three critical areas:

  • Sécuriser en permanence les données à la source et surveiller les anomalies.
  • Contrôler les identités des personnes,des entités non humaines et des appareils qui accèdent aux données et les utilisent de manière autonome.
  • Assurer une Recovery prévisible des données à très grande échelle,sans compromission ni corruption.

Traditionnellement,la sécurité des données,la résilience des identités et la cyber-Recovery fonctionnaient comme des disciplines indépendantes,chacune disposant de sa propre équipe,de ses propres outils,de ses propres politiques et de ses propres exigences. Ces silos laissent des failles que les attaquants peuvent exploiter et ralentissent la récupération en cas de défaillance des systèmes d’IA. Pour combler ces lacunes,les organisations doivent unifier ces capacités au sein d’une boucle continue et automatisée. Nous appelons cette approcheles « opérations de résilience » (ResOps).

Les ResOps englobent trois exigences essentielles pour la résilience de l’IA :

  • Understanding your data landscape: Knowing where data lives,its sensitivity,who’s accessing it (including AI agents and non-human identities),and what policies govern that access in real time. For AI workloads,this extends to protections like LLM prompt governance to control how models access data.
  • Continuous threat detection: Automated systems that constantly monitor for anomalies,compromised identities,and data corruption. When AI systems are making thousands of autonomous decisions,you can’t wait for periodic security reviews.
  • Intelligent recovery: Automated,comprehensive restoration for entire cloud-native applications and their dependencies. To prevent re-infection,teams must validate data integrity and conduct forensic analysis in an isolated cleanroom before moving trusted data back to production.

Enabling ResOps in practice

To help companies make the move to ResOps,Commvault has introducedCommvault Cloud Unity,la version la plus importante de notre plateforme à ce jour. Elle est conçue pour réunir les trois dimensions de la résilience :

A next-generation architecture brings AI automation to all facets of data protection,la sécurité des données,résilience des identités,and recovery. For security and IT teams,the platform provides simplicity at scale with one experience,one policy engine,and one interface designed to protect data,predict threats,and accelerate clean recoveries.

As security leaders know all too well,recovering from the most recent backup minimizes data loss but risks restoring compromised data. Rolling back to a verified clean state may eliminate threats but means losing hours or days of business-critical transactions or AI model training.

With Commvault Cloud,la surveillance continue des menaces and verified clean recovery points help eliminate this forced choice. The platform architecture automatically maps dependencies across distributed systems,helps maintain immutable backups,and helps enable one-click restoration of entire environments. Recovery can be both fast and clean,helping minimize loss as well as risk.

See ResOps in action

Regardez l’intégralité du webinaire à la demande to learn more about ResOps,explore the architecture and services of Commvault Cloud,and rethink your resilience strategy for the AI age.


FAQs

 Q: What is Resilience Operations (Res Ops)?

A: ResOps is an operating model that unifies la sécurité des données,résilience des identités,and cyber-récupération into a continuous,automated discipline rather than treating them as separate IT functions. ResOps transforms resilience from a reactive response to incidents into an active practice that continuously understands data access patterns,helps detect threats and anomalies,and enables fast,intelligent recovery at scale.

Q: Why can’t traditional backup and recovery handle AI workloads?

A: Traditional backup tools were designed for centralized,human-controlled systems with isolated failures. AI workloads involve autonomous agents accessing distributed data across clouds and complex dependencies between microservices and containers,and they operate at a scale that manual processes can’t match.

When AI systems fail or are attacked,you need to recover not just data but entire application infrastructures with all their configurations,policies,and relationships – capabilities traditional backup tools lack.

Q: What does “unified resilience” mean in practice?

A: Unified resilience means bringing la sécurité des données,identity management,and cyber-récupération together under a single platform,policy engine,and operational model rather than managing them as separate functions with different teams and tools.

In practice,this provides a consistent approach to protect all workloads and data locations,automatically correlate security events with access patterns,and orchestrate comprehensive recovery that restores both data and the complete application infrastructure needed to use it.

Q: What’s the difference between cyber resilience and AI resilience?

A: Cyber resilience focuses on protecting infrastructure and recovering from security incidents,treating resilience as an operational state for confronting threats. AI resilience expands this to address challenges unique to AI-driven systems: autonomous agents making decisions with minimal oversight,exponential growth of data and non-human identities across environments,and cascading failures where problems in interconnected AI systems impact entire business operations rather than staying isolated.

Q: How does ransomware target backup systems?

A: Ransomware increasingly targets backup systems by exploiting compromised credentials with privileged access,moving laterally from production systems to connected backup repositories,or exploiting vulnerabilities in backup software itself. Modern ransomware families specifically hunt for backup infrastructure to encrypt or delete recovery points,preventing organizations from restoring clean data and maximizing pressure to pay ransom. This makes offline,immutable,or air-gapped backups essential for resilience.

Q: What is the clean vs. complete recovery dilemma?

A: The clean vs. complete recovery dilemma is the forced choice organizations face during incident response. You can recover from the most recent backup to minimize data loss but risk restoring compromised or corrupted data; or you can roll back to a verified clean state before the incident to eliminate threats but lose significant business-critical data. Traditional backup tools make organizations choose between completeness and safety,while modern resilience platforms aim to provide both simultaneously through la surveillance continue des menaces and verified recovery points.

Q: What is a cleanroom in cyber-récupération?

A: A cleanroom in cyber-récupération is an isolated,secure environment completely separated from production systems to help organizations safely test,validate,and analyze recovered data before restoring it to active use. Cleanrooms help enable forensic investigation of compromised systems,testing of recovery procedures,and verification that restored data is free from malware or corruption – all without risking reinfection of production environments or exposing sensitive data during analysis.

Sam Curcuruto is Director of Product Marketing at Commvault.


Related BlogsRepenser la résilience à l’ère de l’IA

A CIO’s Perspective: Strengthening Business Resilience in the AI Era

Résilience face à la machine IA

Les innovations en matière de Cleanroom Recovery ouvrent une nouvelle ère en matière de cyber-résilience

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • “Instant restore” claims often break down at scale due to real-world I/O operations per second (IOPS), rehydration, and infrastructure constraints.
  • Mass live mounts on deduplicated backup storage can cause performance collapse, forcing slow rehydration back to primary storage.
  • Cleanrooms help enables parallel forensic investigation and business recovery instead of serial, delay-driven downtime.
  • Identity compromise expands the blast radius, making isolated recovery and Active Directory (AD) restoration critical to secure operations.
  • Automated cleanroom runbooks and repeatable testing help organizations validate real recovery metrics before a crisis occurs.

Let’s start with a quick story about a “ransomware‑proof” environment that took 72 hours to recover, way beyond the organization’s expectations for recovery time objective. It is exactly the kind of situation where Commvault’s Cleanroom could have helped turn a painful, three‑day outage into a faster, more controlled recovery with less risk.

War Story: Physics vs. Marketing

On Reddit, a user shared how the financial services firm they work for was hit by a breach. They assumed they had a “dream stack” for quick recovery (but can you really have a “dream stack” without Cleanroom?): immutable backups, secure storage snapshots, and a modern hypervisor. The datasheets promised “instant mass restore,” yet the business sat offline for three days while everyone tried to drag their environment back to life.

The root cause was not that backups failed, but that the real‑world physics of rehydration, forensics, and identity were never tested at scale. The original poster mentioned that having access to a cleanroom environment would have sped up the process. Let’s dig into this further and address why.

Commvault’s Cleanroom is designed to address exactly these weak points: It helps automate clean, isolated recovery into the cloud, validates data, and orchestrates recovery in a way that aligns with how incidents actually unfold, not just how diagrams look on slides.

Problem 1: The Rehydration Trap

In the story, “live mounting” a handful of virtual machines (VMs) worked fine, but trying to live mount hundreds crushed the backup appliance. The random I/O running directly on deduplicated, compressed backup storage collapsed the IOPS, forcing the team to rehydrate everything back to primary Non-Volatile Memory Express at about 3 TB/hour for roughly 100 TB of data.

Commvault Cleanroom helps recover workloads into an isolated Azure‑based cleanroom built on scalable cloud compute and storage instead of trying to run production at scale off a backup appliance.

This allows you to restore critical VMs into a purpose‑built recovery environment, use cloud elasticity to absorb I/O, and automate the recovery sequence so the right systems (identity, core apps, critical data) come up first without bottlenecking on a single backup target.

Problem 2: The Forensic Drag

In the audit, the tech stack was ready in about four hours, but legal delayed touching anything for 72 hours because they had no pre‑provisioned cleanroom. Without an isolated environment with zero routes back to production, the forensics team could not safely investigate while the business recovered, so everyone waited for the all-clear before starting any real restore.

Cleanroom provides an on-demand, isolated recovery environment explicitly built for simultaneous recovery and forensic analysis. You can spin up a fenced cleanroom in Azure in hours, recover systems into it, and let security and legal teams perform read‑only forensics and threat scanning while operations validates applications and prepares for cutover – dramatically shrinking “forensic drag” as a contributor to downtime.

Problem 3: Identity Blast Radius

The environment in the story had a single admin account with access to both the hypervisor and backup console, which meant if attackers pivoted that far, immutability could become just another setting they flipped off. Identity, not just data, was the real blast radius problem.

Cleanroom is designed to help reduce dependency on the compromised production identity plane during recovery, allowing isolated access and planned support for AD restoration in the cleanroom.

By recovering identity services into an isolated cleanroom and using separate, least‑privilege access paths, you can help validate AD, help enforce proper authorizations, and help protect backup control planes from being trivially compromised by the same credentials that were used in production.

How Cleanroom Would Change This Story

If this customer had used Cleanroom, their recovery story could have been very different.

For organizations that already invest in “ransomware‑proof” stacks, the missing piece is often not more features but a cleanroom strategy that respects physics, identity, and legal reality. Commvault Cleanroom is designed to close that gap and help turn recovery from a three‑day war story into a controlled, provable, and much faster operation.

FAQ

Q: Why did the “instant mass restore” approach fail in the ransomware scenario?
A: While live mounting a few VMs worked, scaling to hundreds overwhelmed the backup appliance due to I/O constraints. Deduplicated and compressed backup storage is not designed to handle full production workloads at scale, leading to performance collapse and delayed recovery.

Q: What is the “rehydration trap” in disaster recovery?
A: The rehydration trap occurs when organizations must restore large volumes of compressed backup data back to primary storage before systems can operate normally. This process is limited by throughput rates, which can dramatically extend recovery times when dealing with tens or hundreds of terabytes.

Q: How does a cleanroom help reduce forensic-related downtime?
A: A cleanroom provides an isolated environment where forensic teams can safely investigate while IT simultaneously restores systems. This parallel approach helps eliminate long waiting periods for legal or security approval before beginning recovery efforts.

Q: Why is identity such a critical factor in ransomware recovery?
A: If attackers compromise administrative credentials tied to both production and backup systems, immutability controls may no longer provide protection. Isolated identity recovery and least-privilege access can help limit blast radius and support a safer restoration process.

Q: How does Cleanroom help improve recovery orchestration?
A: Cleanroom helps automates workload sequencing, cleanpoint validation, and cloud-based recovery infrastructure provisioning. This structured approach aligns recovery with how incidents actually unfold, helping organizations regain control faster and with greater confidence.

Q: What is the strategic lesson for organizations with “ransomware-proof” stacks?
A: Advanced features alone do not guarantee fast recovery. A cleanroom strategy that accounts for infrastructure physics, identity isolation, and legal realities helps enable organizations to turn theoretical resilience into measurable, repeatable recovery performance.

Nico Guerrera is Senior Solutions Marketing Manager at Commvault.

Blogs connexes

Récupération de la forêt Active Directory : Pourquoi les méthodes manuelles ne sont plus viables

Tests de récupération : La pièce manquante dans la plupart des programmes de cyber-résilience

Votre manuel de jeu moderne pour une réponse rapide et une récupération propre

Débloquer la cyber-résilience : Le pouvoir des salles blanches

Why Cleanroom and Cyber Testing are Critical for Cyber Resilience

More related posts


Cyber Resilience

Read more about Cyber Resilience

In the current cybersecurity landscape, we are drowning in data but starving for insight. Traditional AI excels at pattern recognition (correlation), but in high-stakes security environments, correlation is a liability.

Causal AI provides the “reasoning” (the why), while agentic AI provides the “execution” (the how). To build truly resilient systems, we must move beyond predicting threats to understanding the causal mechanisms that allow them to flourish.

1. Énoncé du problème : la crise de confiance

Modern Security Operations Centers (SOCs) face a fundamental trust gap. Legacy predictive models often flag “anomalies” that are merely noise, leading to alert fatigue.

  • The problem: Data is noisy, correlated, and lacks labels.
  • The consequence: Analysts struggle to distinguish between a “correlated event” (a user logging in from a new IP) and a “causal event” (that login directly initiating unauthorized data egress).
  • The solution: Integrating causal AI to provide an auditable, human-readable logic chain for every automated action.

2. L’IA causale en action : cas d’utilisation en cybersécurité

En appliquant des modèles causaux structurels, les organisations peuvent passer d’une approche réactive de correction des failles à une résilience proactive.

  • Causal chain of breach formation: Instead of viewing a breach as a single event, causal AI maps the “butterfly effect” of minor configuration changes and how they chain together to create a critical vulnerability.
  • Optimal control selection: If a budget only allows for one upgrade, causal AI can simulate the “do-calculus”: If we implement micro-segmentation instead of endpoint detection and response, how does the causal probability of lateral movement change?
  • Vulnerability prioritization via causal risk: Move beyond the static Common Vulnerability Scoring System. Use causal AI to prioritize vulnerabilities based on their actual “causal reachability” within your specific network topology.
  • Digital twins for posture simulation: Create a “security digital twin” to run “what-if” interventions. This allows CISOs to stress-test resilience strategies in a virtual environment before deploying them to production.

:

créez un « jumeau numérique de sécurité » pour tester des scénarios d’intervention hypothétiques. Cela permet aux RSSI de soumettre les stratégies de résilience à des tests de résistance dans un environnement virtuel avant de les déployer en production.

Component Role Analog
Causal AI Reasoning & decisioning IA causale
Agentic AI Execution & recovery IA agentique
Exécution et Recovery

When an agentic AI performs a task (e.g., isolating a compromised server), causal AI monitors the logs (Step 4: State Recovery). If the agent fails, causal AI analyzes the telemetry to determine if it was a systemic failure or an external cause (e.g., “The agent didn’t fail; the inventory API returned a null value”).

La boucle de rétroaction :

Resilience requires knowing when to stop. We implement “causal fallbacks” so that if the AI reasoning becomes uncertain, the system degrades safely rather than failing catastrophically.

Tier 1: Full autonomy: Causal AI confirms high confidence in the root cause; agentic AI remediates.

Tier 2: Augmented human-in-the-loop: Causal AI provides the “reasoning path” to a human analyst for rapid approval.

Tier 3: Rules-based mode: The system reverts to “causal Six Sigma” logic – a strict, pre-defined safety protocol that prioritizes uptime over optimization.

Tier 4: Fail-closed: If causal integrity is lost, the system isolates critical segments to prevent the butterfly effect of a spreading breach.

Niveau 4 : Mode « fail-closed » :

  • Healthcare & Internet of Medical Things: Causal AI can distinguish between a malfunctioning heart monitor (systemic noise) and a targeted attack on medical telemetry.
  • Telecommunications & 5G: Managing the complex causal dependencies of network slicing to verify that a breach in a low-security slice cannot causally impact emergency services.

Télécommunications et 5G :

Success in a causal AI–enabled environment is measured by the quality of decisions, not just the quantity of blocked threats:

  • Mean time to causal discovery: The speed at which the true root cause is identified vs. the initial symptom.
  • Intervention efficacy: The percentage of security changes that resulted in the predicted reduction of risk.
  • Counterfactual accuracy: How closely the digital twin simulations match real-world incident outcomes.

What’s Next

The future of cyber resilience is not just smarter AI but more logical AI. By combining the execution power of agentic systems with the reasoning depth of causal AI, we can build security architectures that don’t just survive attacks – they understand them.

Vidya Shankaran is Field CTO at Commvault.

© 2025 Commvault. See est directrice technique sur le terrain chez Commvault.2025 Commvault. Consultez www.commvault.com/IP pour les marques déposées et les brevets.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Key Takeaways

  • Commvault Cloud Backup & Recovery for DevOps now includes support for Atlassian Jira,extending enterprise-grade data protection to mission-critical project workflows.
  • Des sauvegardes automatisées,basées sur des règles,ainsi que des options de restauration granulaire aident les équipes à restaurer rapidement les espaces Jira,les tâches et les configurations.
  • Des fonctionnalités intégrées de cyber-résilience,telles que les sauvegardes immuables et le stockage cloud isolé,contribuent à protéger les données Jira contre les ransomwares et les modifications non autorisées.
  • Une protection unifiée couvrant Jira,Azure DevOps,GitHub et GitLab réduit la prolifération des outils et simplifie la résilience des données DevOps.
  • La protection de Jira est disponible via l’accès « Early Adopter »,la disponibilité générale étant prévue pour mars 2026.

Nous sommes ravis d’annoncer l’extension deCommvault® Cloud Backup & Recovery for DevOpsafin d’inclure la prise en charge d’Atlassian Jira. Cette mise à jour apporte à Jiraune protection,une Recovery et une cyber-résilience de niveau entrepriseto Jira,helping organizations safeguard mission-critical project data against data loss and cyber incidents.

With this release,teams now have a unified way to protect critical sprint plans,work items,and configurations alongside their code,pipelines,and repositories in Azure DevOps,GitHub,or GitLab,all with a single solution.

Why Protecting Jira Data Matters

Jira has become a cornerstone for many organizations,supporting everything from agile software development and product releases to IT service management. It houses the plans,workflows,and task data that teams depend on to help execute mission-critical work.

Despite its importance,Jira is not immune to data loss. Accidental deletions,misconfiguration,and malicious activity can quickly erase valuable project history and disrupt active work.

When Jira data is lost or becomes unavailable,teams lose visibility,sprints stall,releases are delayed,service commitments are missed,and productivity suffers as teams attempt to recreate lost information.

A reliable backup and recovery strategy for Jira is critical to help maintain continuous business and help minimize the risk of downtime,operational disruption,and potential failure to meet data retention or regulatory compliance requirements.

Enterprise-Grade Protection for Jira Commvault Clouddelivers enterprise-scale protection and recovery for Jira,helping organizations safeguard mission-critical Jira data against cyber incidents,disasters,and operational mistakes.

Key features:

  • Automated,policy-based backups of Jira spaces,work items,and configurations,including attachments,custom fields,and board settings.
  • Granular recovery of individual spaces or work items,as well as full-site recovery to a specific point in time.
  • Simplified compliance through centralized control,audit logging,and extended retention to help support regulatory and internal requirements.
  • Cyber resilience withde sauvegardes immuables,un stockage cloud isolé,and une architecture « zero-trust »pour protéger les données contre les ransomwares et les modifications non autorisées.
  • Unified protection for Jira,Azure DevOps,GitHub,GitLab,and other enterprise workloads from a single platform.

Unifying DevOps Data Resilience with Commvault

By unifying Jira protection with other DevOps platforms in Commvault Cloud Backup & Recovery for DevOps,enterprises can gain a holistic approach to data resilience across the full DevOps lifecycle – from planning and issue tracking to code and delivery. The result is fewer tools,reduced complexity,and confidence that sprint plans and backlog items are rapidly recoverable when it matters most.

Early Availability

Atlassian Jira protection is now available through Early Adopter access with general availability planned for March 2026.

Learn more about Commvault’s support for Atlassian Jira,ici.

To learn more about how to get access to getting access to Jira protection or schedule a demo,contact your Commvault account team.

FAQs

Q: Why is backing up Atlassian Jira important?
A: Jira houses critical sprint plans,workflows,and issue data that many teams rely on to deliver projects and services. Data loss from accidental deletion,misconfiguration,or malicious activity can disrupt releases and impact productivity,making a reliable backup and recovery strategy essential.

Q: What Jira data can Commvault Cloud protect?
A: Commvault Cloud helps protect Jira spaces,work items,configurations,attachments,custom fields,and board settings. This comprehensive coverage helps organizations maintain full visibility and recover both detailed items and entire sites when needed.

Q: How does recovery work with Commvault Cloud for Jira?
A: The solution helps support granular recovery of individual spaces or work items,as well as full-site recovery to a specific point in time. This flexibility enables teams to restore exactly what they need without unnecessary disruption.

Q: How does this solution support compliance and cyber resilience?
A: Centralized control,audit logging,and extended retention help organizations meet regulatory and internal requirements. Immutable backups,un stockage cloud isolé,and a une architecture « zero-trust » help strengthen protection against ransomware and unauthorized changes.

Q: Can Jira protection be managed alongside other DevOps platforms?
A: Yes. Commvault Cloud unifies protection for Jira with Azure DevOps,GitHub,GitLab,and other enterprise workloads within a single platform,helping reduce complexity and enable a holistic approach to DevOps data resilience.

Q: When will Jira protection be generally available?
A: Atlassian Jira protection is currently available through Early Adopter access,with general availability planned for March 2026. Organizations can contact their Commvault account team to learn more or schedule a demo.

Katharine Colucci is a Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog_DevOps_2025

Enhance Resilience with Backup & Recovery for DevOps

Read more about Enhance Resilience with Backup & Recovery for DevOps
Zz05MThhZTc3NmU0MTQxMWVmYTYwZWJlYTg2ZTllNjQ5Yw

A Blueprint for Effective Cloud Recovery

Read more about A Blueprint for Effective Cloud Recovery
Commvault-cloud-availability-LinkedIn

Experience True, Cloud Cyber Resilience – Available now in Commvault Cloud

Read more about Experience True, Cloud Cyber Resilience – Available now in Commvault Cloud
Thumbnail_Blog-SHIFT-Announcement-Recover-Clean-2025-Linkedin

Recover Clean, Recover Fast

Read more about Recover Clean, Recover Fast
Thumbnail_Blog–CloudRewind2025–Linkedin

Built for Resilience, Optimized for Scale: The Cloud Rewind Architecture

Read more about Built for Resilience, Optimized for Scale: The Cloud Rewind Architecture
Thumbnail_Blog-SHIFT-Announcement-Commvault-Cloud-Unity-2025-Linkedin

A New Era of Enterprise Resilience

Read more about A New Era of Enterprise Resilience