Skip to content

Points clés à retenir

  • GigaOm recognized Satori as the only mature, platform-centric leader in data access governance.
  • Traditional security tools can fail to handle the rapid scale and complexity of modern data usage.
  • Data access governance platforms can provide real-time visibility, enforcement, and compliance evidence for data access.
  • Satori was founded to empower security teams with control over data access without slowing down analytics or AI innovation.
  • Integrating data access governance with recovery capabilities enables a proactive, resilient la sécurité des données strategy.

The independent analyst firm GigaOm published its latest and placedSatori, a Commvault company, as the only mature, platform-centric leader in the category.That recognition matters. Not because of the badge itself, but because it validates something many security and data leaders are feeling right now but don’t always have language for: In today’s AI era, data has become the foundation of modern business. At the same time, it has become a moving target. Governing data in this environment is increasingly impractical without a dedicated data access governance platform like Satori.But let’s step back and look at the la sécurité des donnéesproblem first.

The Real Problem with Data Security Today

The most prominent challenge organizations face today is not a lack of data. On the contrary, storing data is cheap, collecting it is easy, and acquiring external data is often straightforward. In recent years, even processing and extracting value from that data has become significantly more accessible.It used to be that only specialized teams could analyze data. But today’s analytics tools and AI make it possible for almost anyone to do so, using more data than ever before. Analytics, self-service business intelligence, automation, and AI mean data is accessed more frequently, by more systems, and by more identities than ever before.This transformation can deliver tremendous value for businesses. But without proper governance, it also can introduce significant risk. In most enterprises:

  • Data lives across many platforms and in thousands of different locations.
  • Access decisions are owned by engineering or data teams.
  • Security teams depend on others for answers and for applying security policies.

Add to this external pressure: compliance. There is growing regulatory pressure to continuously answer questions such as who accessed what data, when, and why. Organizations must also know where sensitive data such as personally identifiable information or protected health information resides, how access to production data is provisioned, and whether controls are consistently enforced.Data and security teams are expected to answer these questions and place controls over the data, but they often lack the visibility, control, and evidence to do so confidently.

Why Is This Happening Now?

This situation didn’t develop overnight; several forces converged at the same time.First, data usage scaled faster than governance. Access models that worked when data was accessed occasionally break down when access is continuous, automated, and embedded in everyday workflows. And in many cases, this can even happen by an AI agent that may or may not follow data use guidelines. These changes are similar to those in software when organizations moved to CI/CD and could no longer “freeze and wait” for version releases.Second, security teams were pushed out of the data path. Controls were implemented at the infrastructure, schema, or application level, often owned by engineering or data teams. Security teams became dependent on others to understand how data was being accessed and to enforce policies. Let’s face it, we can’t expect security teams to know every SQL command used to protect or reveal sensitive data.Third, compliance expectations increased. It is no longer enough to say that controls exist. Organizations are expected to continuously demonstrate that sensitive data is governed correctly and that access aligns with policy.Together, these forces may have created a gap that traditional security and data tools were never designed to fill.

What Data Access Governance Actually Solves

Despite its name, data access governance is not about documentation or policy paperwork.It is about giving organizations direct visibility and control over how data is accessed, without slowing the business down.A data access governance platform allows teams to:

A data access governance platform does not replace identity systems, data catalogs, or data protection tools. Instead, it fills the gap between them by governing access where it matters most: when data is used.

Why We Built Satori

Satori was built on a simple observation: Security teams are accountable for data risk but often lack direct control over data access.We set out to change that.From the beginning, Satori was designed to:

  • Enforce policies at query time, close to the data.
  • Apply controls consistently across modern data platforms.
  • Support fine-grained access without requiring code changes.
  • Provide clear visibility into who accessed what data, and why.

This approach allows organizations to govern data access without becoming a bottleneck for analytics, AI, or innovation. It is also the model recognized by GigaOm in its latestRapport.

From Governing Data to Resilience

Recovery remains a cornerstone of resilience.Backups, clean recovery, and testing recoverability enable organizations to continue operating when incidents occur. They help support availability, integrity, and the ability to restore systems quickly and confidently.Data access governance builds on that foundation by addressing a different but complementary set of questions:

  • How is data being accessed on an ongoing basis?
  • Are access policies consistently enforced?
  • Can we demonstrate compliance continuously, not just after an incident?

While recovery focuses on restoring data to a known good state, governance focuses on preventing misuse, reducing exposure, and providing ongoing assurance. Together, they enable a more thorough and proactive approach to resilience.By combining real-time data governance with proven recovery capabilities, organizations can gain both control and resilience: control over how data is used every day and the ability to bounce back when things go wrong.

What Comes Next: Integrated Data Security

The future of la sécurité des données is not about adding more isolated tools.It is about creating an integrated approach that helps keeps data governed at all times, while enabling the organization to bounce back when things go south.That means:

  • Continuous visibility into data usage.
  • Real-time control over access.
  • Ongoing evidence for compliance.
  • And resilient recovery when incidents occur.

By bringing together real-time data access governance with data protection and recovery, organizations can move from a reactive security posture to a more proactive, defensible one. This is where we see the industry heading, and it is the direction we are building toward.

Modern Data Security

Data is being used more than ever, by more people and systems, in more ways than before.Security teams are expected to govern that usage, demonstrate compliance, and keep the business running during incidents. Doing that requires more than traditional data protection alone – it requires visibility into data usage, control over access, and proof that governance is working continuously.That is what data access governance enables, and why it is becoming a foundational part of modern la sécurité des données. To learn more about how Commvault can help your organization, book a demo.

FAQ

Q: Why did GigaOm recognize Satori as a leader in data access governance?
A: GigaOm highlighted Satori’s platform-centric approach that provides mature, unified capabilities for governing data access in real time. This recognition underscores Satori’s ability to give organizations visibility and control without impeding business agility.Q: What is the main problem with la sécurité des données today?
A: The biggest challenge isn’t data scarcity but uncontrolled data access. Data now lives across multiple platforms, is accessed by countless systems, and lacks unified oversight. This creates compliance gaps and security risks that traditional tools can’t manage effectively.Q: How does data access governance solve these challenges?
A: A data access governance platform helps organizations monitor how data is used, enforce access policies at runtime, and maintain ongoing compliance documentation. It bridges the gap between identity management and data protection tools by focusing on real-time data use.Q: What makes Satori’s approach unique?
A: Satori is designed to enforce security policies directly at query time, close to the data, helping provide granular control without requiring code changes. It offers ongoing visibility into who accessed what and why, helping empower security teams with actionable insights.Q: How does data access governance relate to resilience and recovery?
A: While recovery focuses on restoring data after incidents, governance helps prevent misuse and minimize exposure beforehand. Together, they enable ongoing compliance and faster, more confident recovery – helping strengthen overall business resilience.Q: What’s next for modern la sécurité des données?
A: The future lies in integrated security – combining ongoing visibility, real-time control, and resilient recovery. This holistic approach helps enable organizations to move from reactive data protection to proactive, defensible governance.Ben Herzberg is Senior Director, Solutions Marketing, at Commvault.


Blogs connexes

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Your organization just got hit with a ransomware attack. Your cyber etIT departments are scrambling to get your incident response plan started etoperational. All of a sudden, everyone realizes that they cannot log in to anything.Active Directory (AD) must be offline!? Your organization’s authentication etauthorization tools are impacted.

After hours of triage etassessing the size of this problem, your cyber incident response team reports that restoring foundational AD etauthentication etauthorization services will take over a week, if everything goes well.

You thought your resiliency plan with AD backups eta SaaS identity platform was sufficient. But even with SaaS in the mix, recovery is complex etmanual, delaying the path back to minimum viable operationswhen time matters most.La résiliencemeans you can restore authentication etauthorization quickly etpredictably in a trusted way, whether the disruption is malicious activity, an outage, or an accidental misconfiguration.

Understanding the Threat

Attackers target AD because it’s the identity control plane. Once they get a foothold, they’ll often establish persistence by creating shadow or backdoor accounts, then harvest credentials, etescalate privileges. With elevated access, they laterally move across systems etapplications, sometimes staying quiet long enough that the first clear signal is when authentication starts failing.

They gain a wealth of knowledge of the organizations network, people, etapplications. And when they’re ready to maximize impact, they can encrypt or corrupt the AD forest, disrupting logins etcomplicating recovery across the environment.

Why Identity (etWhy AD First)?

It’s common for an organization’s identity stack, especially AD etEntra ID, to become complex over time. Forests expand, permissions sprawl, legacy policies accumulate, et“good enough” processes often turn into long-term security drift. That complexity creates blind spots, etdefenders lose crisp visibility into how roles, privileges, etpolicies evolve.

And it’s never “just AD.” Identity is an ecosystem: identity governance etaccess solutions (IGA), privileged access, customer identity, identity providers, authentication databases, etsingle sign-on all connect back to the same truth. That’s why identity incidents (eteven everyday misconfigurations) can cause outsized disruption compared to many other infrastructure failures.

The recovery challenge is where most plans get exposed. Even with backups, forest recovery is a multi-step, high-stakes process, where guidance for manual recovery can involve 50 to 100 (or more) individual steps etcan take days to weeks, depending on environment complexity etpreparedness.

The real question isn’t “do we have backups?” it’s “can the teams leverage the backups to cleanly execute under pressure, ethave runbooks been tested etverified so recovery doesn’t become an error‑prone scramble at the worst possible time?”

La solution

The need to have a recovery plan is great. It needs to be tested etverified. Organizations need to know etunderstetthat your identity management platform is the No. 1 target for cyber criminals etattacks. It needs to be protected as such. It needs to be backed up, tested, etverified it can be recovered. This includes:

  • Backups of AD, Entra ID, etIGA platforms.
  • Tested etverified recovery plans.
  • Isolated recovery environments etCleanroom.
  • AD recovery workflow etautomation.

Strong identity governance etmonitoring are still critical, but they’re only part of the equation. You want the ability to detect suspicious identity behavior early, contain it fast, etrecover with confidence when something changes that shouldn’t (whether it’s malicious activity or an accidental modification that breaks authentication).

That also means you need to integrate identity account etuser activity into SecOps etcontinuously watch for signals like unauthorized account creation, privilege changes, etabnormal authentication patterns, ethave a recovery path that’s proven, repeatable, etclean.

Commvault etDeloitte: A Partnership for Identity La résilience

La résilience des identités is a business challenge that requires strong governance, processes, controls, etenabling technology. That’s why Deloitte etCommvault have partnered to deliver comprehensive identity protection, recovery, etresilience programs that organizations can trust when it matters most. 

Deloitte brings deep expertise in cyber risk, enterprise resilience, etidentity etaccess management to help Fortune 100 to 1000 organizations design, implement, etoperationalize identity resilience programs.

These programs help clients assess security posture, improve detection etresponse capabilities, etdefine minimum viable company requirements, etthen build tested, verified recovery plans with clear timelines etaccountability across business etIT stakeholders. Deloitte turns identity resilience into an executable program with runbooks, testing, etreadiness, so teams know what “prepared” looks like under pressure.

Commvault makes resilience programs operational with integrated protection etautomated recovery workflows across identity systems, plus Commvault AirGapetCleanroomto support repeatable, clean, validated recovery when it matters most. Commvault provides the technology foundation with identity resilience capabilities that include:

  • Protection for critical identity systems, including AD etEntra ID, point-in-time comparison etrollback support for unwanted or accidental changes.
  • Auditing etdetection to surface suspicious modifications early (who changed what, etwhen), helping reduce the window for attackers to spread or persist.
  • Automated recovery workflows, including forest-level recovery automation, to help reduce the manual burden eterror risk during identity restoration.
  • Commvault Cleanroom to help validate identity recovery in isolation before reintroducing trust back into production.
  • Commvault AirGapto help maintain immutable, air-gapped backup copies, creating a protected foundation that supports clean recovery etcleanroom testing when identity (or the environment around it) can’t be trusted.

Take Action

If you want to pressure-test your cyber recovery readiness, start with a Deloitte Active Directory Workshop to map dependencies etproduce a clear, actionable plan to recover AD etworkloads to production. Then validate it the right way: using Commvault to rehearse recovery in a cleanroom before you ever need it in a real event.

For organizations ready to take the next step, we can extend this into a 30-day pilot that puts clean recovery ettesting into motion with real artifacts etmeasurable outcomes. Contact your Deloitte representative at commvaultsalesteam@deloitte.comor your Commvault representative atdeloittealliance@commvault.compour plus d’informations.Dave Nowak is Cyber Defense & La résilience Principal at Deloitte, etMichael Fasulo is Senior Director, Portfolio Marketing, at Commvault.

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • Le manque de coordination entre les services informatiques et de sécurité accroît les risques cybernétiques.
  • Commvault Cloud permet une réponse et une Recovery unifiées.
  • Arlie AI fournit des informations partagées et des actions guidées.
  • Les principes de « «Secure by Design » (sécurité dès la conception) sont le fondement de la confiance et de la conformité.
  • Une vision commune est fondamentale pour la cyber-résilience.

In today’s enterprise environment, cyber resilience depends on more than tools. It depends on whether IT and Security teams operate with shared intent. With Commvault Cloud, organizations gain a unified platform that connects detection, response, and recovery – helping CIOs and CISOs move forward together without compromise.

Comprendre le fossé entre l’informatique et la sécurité

IT and Security teams share a common mission: enable the business to succeed. Yet their paths often diverge through opposing objectives, siloed tools, and disjointed workstreams.
IT Operations prioritize speed, scalability, automation, and uptime.
Security Operations focus on protecting data, reducing risk, and maintaining compliance through the CIA triad – confidentiality, integrity, and availability.
When these perspectives collide without coordination, silos form. Communication slows. Risk increases.

Pourquoi un manque d’alignement sape la cyber-résilience

Le manque d’alignement entraîne des conséquences tangibles :

  • Une détection et une réponse aux incidents plus lentes.
  • Une reprise inefficace et source d’erreurs.
  • Une portée accrue des cyberattaques.
  • Des frictions opérationnelles accrues en cas de crise.

La cyber-résilience exige une action coordonnée entre la détection, l’investigation et Recovery.

Combler le fossé avec Commvault Cloud

Commvault demonstrates how technology can align teams instead of fragmenting them.

  • Faster, cleaner recoveries: Commvault provides threat insights, scanning against indicators of compromise and sharing insights with security tooling while enabling rapid, reliable recovery. Together, teams can identify affected systems and restore operations with confidence.
  • Targeted risk mitigation: Capabilities such as cyber resilience assessments, scenario simulations, and isolated testing in cleanrooms allow organizations to prepare without impacting production environments.
  • Unified incident management: Integrated workflows connect detection, investigation, and recovery, minimizing room for miscommunication, and helping to accelerate resolution.
  • Scalable, tailored services: Commvault incident response recovery services adapt to organizational needs, supporting resilience without overextending resources.
  • Shared expertise: Customers can benefit from combined guidance across architecture planning, process optimization, and operational readiness.

Arlie AI : l’intelligence partagée en action

Arlie AI, Commvault’s Autonomous Resilience copilot, strengthens collaboration by delivering real-time insights and guided workflows.
Arlie helps:

  • Mettre en évidence les anomalies et les données critiques.
  • De guider les utilisateurs étape par étape lors d’incidents.
  • De réduire la dépendance vis-à-vis d’une expertise technique approfondie.
  • Standardiser les réponses au sein des équipes informatiques et de sécurité.

Grâce à des intégrations sans code et à une intelligence adaptée à la plateforme, Arlie élimine les approximations et renforce la coordination des actions.

La sécurité par conception, et non par hasard

Commvault intègre la sécurité au niveau du code grâce aux principes«Secure by Design». Cette approche est validée par des initiatives telles que l’adoption decapacités cryptographiques post-quantiquesconformes aux nouvelles normes du NIST.

Ces mesures réduisent la charge liée à la conformité et soutiennent les secteurs réglementés. D’autres certifications sont disponibles dans leCommvault Trust Center.

Vers une vision commune

Q: Why do IT and Security teams struggle to align?

A: They operate under different priorities, KPIs, and tools, which can create silos.
Q: How does Commvault help improve cyber resilience?

A: By unifying detection, response, and recovery within Commvault Cloud.
Q: What role do security integrations play?

A: Commvault security integrations allow sharing threat insights cross-functionally and help inform faster recovery.
Q: What is Arlie AI?

A: Arlie is Commvault’s AI copilot that delivers guided, real-time resilience insights.
Q: Why is «Secure by Design important?

A: It helps reduce risk at the code level and helps support compliance from the start.
Q: How can organizations measure alignment success?

A: Through shared KPIs like time to detection, recovery speed, and readiness testing

Pauline List is a Product Marketing Specialist at Commvault.


Blogs connexes

Renforcer l’alignement des parties prenantes pour la cyber-résilience

L’urgence de la cyber-résilience

A Multi‑Layered Approach to Cyber Resilience

Une approche multicouche de la cyber-résilience

La prochaine évolution dans la protection Cloud

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • L’accès latéral dans les environnements d’IA permet aux attaquants de se déplacer d’un système connecté à l’autre en exploitant la confiance partagée et les autorisations excessives.
  • Les workflows d’IA peuvent masquer les mouvements latéraux, car les attaques imitent souvent le comportement normal du système.
  • Defense in depth – including identity isolation, segmentation, and dynamic access control – helps reduce the spread of compromise.
  • La planification de la Recovery doit être considérée comme un contrôle essentiel, et non comme une mesure secondaire, afin de rétablir la confiance après des violations latérales.
  • Commvault renforce la résilience en facilitant une Recovery fiable et isolée, ainsi qu’un confinement rapide en cas d’incidents d’accès latéral.

Modern AI systems are built for speed and connectivity. That same design also makes lateral access one of the most dangerous and least visible failure modes in AI-enabled environments.

Large language models, retrieval pipelines, orchestration layers, and downstream services continuously interact to generate value. When those interactions rely on shared trust and overly broad permissions, a single compromise can spread far beyond its original scope.

What Is Lateral Access in AI Environments?

Lateral access occurs when an attacker compromises one component and then moves horizontally across connected systems by exploiting trust relationships, shared identities, or overly broad permissions.

In modern AI environments, this type of movement is especially dangerous. Models, retrieval services, orchestration layers, and data stores are designed to communicate continuously, often using shared credentials and implicit trust. Once a single component is compromised, attackers can move quickly across the environment without triggering obvious alerts.

Because AI workflows generate large volumes of legitimate activity, lateral movement often blends into normal system behavior until the blast radius already has expanded.

Why Lateral Access Is Especially Dangerous

Lateral access undermines security assumptions that many organizations still rely on. Traditional defenses focus on preventing initial compromise or vertical privilege escalation. Lateral movement bypasses those controls by abusing legitimate access paths that already exist.

In AI-enabled environments, the impact compounds rapidly. Compromised services may continue to generate valid outputs while attackers move across models, data sources, and tenants at machine speed. What begins as a single breach quickly can expand into a systemic incident.

Recovery is also more complex. When identities, orchestration layers, or shared data stores are involved, organizations must assume broader contamination and restore trust across multiple systems rather than a single endpoint.

Common Causes of Lateral Movement

Most lateral access exploits are enabled by architectural decisions rather than novel vulnerabilities. In modern AI environments, speed and integration are often prioritized before identity discipline and segmentation are fully enforced.

The most common causes include:

  • Des autorisations excessives accordées aux services d’IA, aux agents ou aux comptes d’automatisation.
  • Des identités partagées entre les fonctions d’ingestion, de récupération, d’inférence et d’orchestration.
  • Une application insuffisante des contrôles d’accès basés sur les rôles et les attributs.
  • Une segmentation insuffisante entre les locataires, les environnements ou les charges de travail.
  • L’absence de sauvegardes immuables et de workflows de Recovery isolés.

Addressing these issues requires architectural discipline and recovery planning, not reactive controls applied after compromise.

Reducing Lateral Risk with Defense in Depth

Reducing lateral access risk in AI environments requires more than perimeter controls or isolated fixes. It requires defense in depth that assumes compromise and limits how far attackers can move once inside.

Effective design focuses on four core principles:

  • Enforce identity isolation: Each AI function should operate with its own narrowly scoped identity. Ingestion services, retrieval components, orchestration layers, and inference engines should never share credentials. When identities are isolated, a single compromise cannot automatically spread across systems.
  • Apply context-aware access controls: Permissions should be evaluated dynamically based on role, environment, tenant, and operation. Combining role-based and attribute-based access controls limits abuse of legitimate access paths and reduces the opportunity for lateral movement.
  • Segment data paths and execution environments: AI components should be isolated from one another and from core business systems. Segmented networks, service boundaries, and controlled data paths help restrict how far attackers can move and contain the blast radius when compromise occurs.
  • Plan for recovery as a control: Prevention alone is insufficient. Organizations must assume lateral movement will occur and design recovery workflows that help them isolate compromised components, restore trusted systems, and reestablish control without reintroducing risk.

Together, these principles shift lateral access from an uncontrolled cascade into a contained and recoverable event.

Detecting and Responding to Lateral Behavior

Early detection is critical in limiting the impact of lateral access. Because lateral movement often mimics legitimate system behavior, traditional alerting focused on perimeter breaches or privilege escalation is frequently insufficient.

Effective detection focuses on behavioral signals rather than individual events. Unexpected interactions between services, sudden expansion of access scope, and anomalous identity usage patterns can indicate lateral movement even when individual actions appear valid.

When suspicious behavior is identified, response must prioritize containment and trust restoration. Compromised identities should be revoked quickly, affected components isolated, and recovery initiated using trusted data in controlled environments. The goal is not only to stop movement, but to reestablish confidence in system integrity.

Why Commvault Matters for AI Resilience

AI systems increase speed and scale across the enterprise. Attackers benefit from that same speed when lateral access is left unchecked.

Commvault helps organizations reduce the impact of lateral access by providingdes bases de restauration fiablesqui prennent en charge le confinement, l’isolation et la restauration à grande échelle. En cas de compromission, la capacité à se restaurer à partir de données connues pour être fiables devient un contrôle essentiel.

Commvault peut aider les organisations à :

  • Conserver des points de Recovery fiables qui restent disponibles même en cas de compromission généralisée.
  • De restaurer les systèmes et les données dans des environnements isolés à des fins de validation avant leur réintroduction.
  • De restaurer les services dépendants de l’identité sans amplifier la contamination latérale.
  • Réduire les temps d’arrêt et rétablir plus rapidement la confiance opérationnelle.

Resilience against lateral access is not about eliminating connectivity. It is about controlling it, monitoring it, and making sure that recovery remains possible.

Final Thought

Lateral access is not a failure of individual controls. It is a consequence of how modern AI systems are designed to connect and trust one another.

As AI environments continue to scale, resilience depends on disciplined identity design, intentional segmentation, and the ability to recover quickly from trusted data. Organizations that plan for containment and recovery alongside innovation are best positioned to limit blast radius and preserve trust when compromise occurs.

Learn how Commvault helps organizations strengthen AI resilience and accelerate recovery when it matters most.La nouvelle version de la plateforme Commvault Cloud Unityvous permet d’unifier la sécurité des données, la résilience des identités et la reprise après sinistre informatique à l’échelle de l’entreprise.


FAQ

Q: What does “lateral access” mean in AI-enabled environments?
A: Lateral access refers to an attacker’s ability to move horizontally between interconnected systems after compromising one component. In AI environments where models, retrieval layers, and data sources share trust, this movement can go unnoticed and expand quickly.

Q: Why is lateral access particularly dangerous for AI systems?
A: Because AI ecosystems are highly interconnected, a single compromise can cascade across multiple components. Attackers can maintain legitimate-looking activity while accessing sensitive data or systems, making detection difficult and recovery complex.

Q: What are the most common causes of lateral movement?
A: Excessive permissions, shared identities across AI services, weak access control enforcement, lack of segmentation, and missing immutable backups all create opportunities for lateral exploitation.

Q: How can organizations reduce lateral access risk?
A: Implementing identity isolation, dynamic (context-aware) access control, and segmentation across AI components limits how far attackers can move. Recovery strategies should be built into architecture to enable containment and safe system restoration.

Q: What role can Commvault play in defending against lateral access?
A: Commvault strengthens resilience by enabling organizations to maintain trusted recovery points and isolate restoration. Its tools are designed to validate, recover, and reestablish trust quickly, helping reduce downtime after compromise.

Q: How should teams detect and respond to lateral movement?
A: Commvault recommends focusing on behavioral anomalies – such as unexpected service interactions or expanded access scopes – rather than traditional alerts. Once detected, revoke compromised credentials, isolate affected systems, and recover from verified data backups.

Chris DiRado is Principal, Product Experience, at Commvault.

More related posts


Thumbnail_-Blog_Hyperscale-2025-1

Commvault On-Prem Solutions: Ransomware Resilience to AI-Ready Data Protection

Read more about Commvault On-Prem Solutions: Ransomware Resilience to AI-Ready Data Protection
Thumbnail_Blog_Resilient-Against-the-AI-Machine

Resilient Against the AI Machine

Read more about Resilient Against the AI Machine

At Commvault, support exists for one reason: to solve customer challenges as quickly and confidently as possible. Every process we refine, every tool we introduce, and every investment we make is guided by that goal – helping customers feel supported when it matters most.

Over the years, we’ve learned that great support isn’t just about resolving tickets. It’s about clarity during high-pressure moments, honest communication, and building trust that lasts beyond a single interaction. Those lessons have shaped a support ecosystem designed to move fast without losing the human connection.

L’expertise humaine, renforcée par l’IA

Speed and empathy don’t have to compete. That’s why our approach to AI is built around partnership, not replacement. AI helps us move faster; people are dedicated to making sure we move wisely.

Arlie, our AI-enabled support assistant, analyzes logs, recognizes patterns, and surfaces insights early – often before issues escalate. Customers can use Arlie directly to find answers in real time, while our engineers use those same insights to focus less on data gathering and more on understanding each customer’s unique environment.

This balance matters. Support interactions often happen during moments of risk or stress, when customers want reassurance that a real person is invested in their success. By handling the repetitive and time-consuming tasks, AI creates space for meaningful conversations – the kind that build confidence and trust.

L’équipe derrière chaque résolution

Behind every fast resolution is a global team of highly skilled engineers who continuously learn, collaborate, and share knowledge. Our Center of Excellence model allows expertise gained in one region to strengthen support everywhere, ensuring customers benefit from collective experience – not just individual cases.

Training, certifications, case reviews, and simulations are part of everyday life for our support teams. This preparation means that when a ticket arrives, engineers respond with clarity, purpose, and deep technical understanding across cloud, storage, backup, databases, and security.

AI strengthens this model even further by capturing insights from past cases and making them instantly accessible, so knowledge never stays siloed.

Une expérience d’assistance en constante évolution

The result is a support experience that feels both efficient and personal – one where customers can self-serve when they need speed, connect with experts when they need guidance, and trust that every interaction is backed by experience, empathy, and continuous learning.

We’re continuing to invest in proactive monitoring, smarter self-service, and learning paths that help customers and engineers grow together. Progress is ongoing, but the direction is clear: faster resolutions, stronger partnerships, and support that customers can truly rely on.

If you’ve interacted with Commvault Support recently, we’d love to hear your feedback. Thank you for being a Commvault customer and for providing insights that help us keep improving – for every customer, every day.

 

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Backup and recovery integrations depend on secure workload credentials. A single compromised credential can open access far beyond one system, and threat actors know it.

The best static credential is the one you don’t have. Where feasible, move from secret-based authentication to managed identities or other “secretless” approaches, so credentials are issued, protected, and rotated by the platform rather than stored and handled manually. However, we realize this is not always possible for some legacy systems and configurations.

The good news: Even when using long-lived secrets, hygiene can reduce your risk and blast radius.

This post outlines a practical routine that can help ensure your business remains cyber resilient: Rotate credentials, minimize scope, and enforce Conditional Access where possible.

Les principes de base : trois contrôles clés

Strong credential hygiene comes down to three pillars: rotation, least privilege, and Conditional Access. While you won’t always be able to implement all three for every credential type, these are the right places to start for any environment:

  1. Rotation and monitoring: Rotate credentials regularly and review authentication activity for anomalies.
  2. Least privilege: Scope permissions so credentials can perform only the required backup/restore actions. Practical steps include:
    • Séparer les identifiants par charge de travail.
    • Limiter les autorisations au minimum nécessaire en termes de jeu de données, de site, de boîte aux lettres ou de base de données.
    • Évitez les rôles d’administrateur trop généraux, sauf en cas d’absolue nécessité.
  3. Conditional Access: Where supported, set policies to limit when and where credentials can be used, such as:
    • Emplacements et plages d’adresses IP de confiance
    • Signaux de risque
    • Contrôles des appareils et des sessions

When Conditional Access Isn’t Feasible, Rotation is the Compensating Control

Tous les types d’identifiants ne répondent pas aux exigences de l’accès conditionnel. Dans ces cas-là, la rotation limite la durée pendant laquelle un identifiant volé reste utilisable, et la surveillance vous aide à détecter rapidement toute utilisation abusive.Les recommandations de Commvaultmettent l’accent sur la rotation régulière des mots de passe, des secrets et des identifiants dans tous les environnements. Pour les enregistrements d’applications Azure à locataire unique protégeant les charges de travail M365/D365/Entra ID,Commvault recommande90-day rotation cycles. Many common security and compliance frameworks (PCI DSS, ISO 27001, SOC 2, NIST) also expect disciplined credentials management, including periodic rotation and review of access.

Consultez votre équipe de sécurité

Credential hygiene is most effective when it’s consistent. Align with your security team on:

  • Les intervalles de rotation (par type d’identifiants et par niveau de risque).
  • Conditional Access policy design (what’s enforceable without breaking automation).
  • Les règles d’accès privilégié, les exigences en matière de journalisation et les cycles de révision.

Guide de ressources

Les ressources ci-dessous fournissent des informations complémentaires et des conseils adaptés à votre environnement en matière de protection des identifiants et de contrôles d’accès.

Commvault
Microsoft
AWS
Google Cloud (GCP)

Will Galway is Deputy Chief Security Officer at Commvault.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • Commvault étend la protection de Google Workspace grâce à des fonctionnalités avancées de recherche eDiscovery destinées à faciliter la mise en conformité, les enquêtes et les procédures judiciaires.
  • Ces nouvelles fonctionnalités permettent une recherche plus rapide et plus précise dans Gmail et Google Drive grâce à des filtres par mots-clés, expressions et métadonnées.
  • Des options d’exportation flexibles aident les équipes juridiques à rationaliser les examens et à réutiliser des jeux d’exportation standardisés pour les dossiers récurrents.
  • Une interface de recherche centralisée permet aux organisations de gérer la recherche électronique sur Google Workspace, Microsoft 365 et les terminaux à partir d’une seule et même plateforme.
  • La solution est conforme aux normes du modèle de référence en matière de recherche électronique (EDRM) et est disponible en accès anticipé, sa mise à disposition générale étant prévue pour le premier semestre 2026.

Google Workspace est au cœur des modes de communication et de collaboration de nombreuses organisations ; il contient des e-mails, des fichiers et des messages critiques pour l’activité, qui sont souvent essentiels àla conformité, aux enquêtes et aux litiges.

En tant que source clé de données pouvant faire l’objet d’une recherche, les entreprises ont besoin deprocessus d’eDiscovery efficacespour localiser, gérer et exporter rapidement les informations stockées électroniquement (ESI) pertinentes dans l’ensemble des services Google Workspace, afin de répondre aux exigences légales et réglementaires actuelles. Des réponses tardives et une collecte d’ESI incomplète ou inexacte peuvent faire grimper les frais juridiques, accroître les risques réglementaires et entraîner des amendes ou le non-respect des obligations de conformité.

Pour répondre à ce besoin, nous étendonsla protection existante de Google Workspaceen suivant les étapes suivantes :ajoutant des fonctionnalités avancées de recherche de conformité à notre offre eDiscovery. Ces fonctionnalités eDiscovery pour Google Workspace viennent compléter la prise en charge eDiscovery existante pour Microsoft 365 et les terminaux, facilitant ainsi l’unification de la conformité sur plusieurs charges de travail à partir d’une seule et même plateforme.

Simplification de la recherche de conformité pour les environnements Google Workspace

Grâce à cette mise à jour, les clients peuvent localiser, filtrer et exporter plus rapidement les données pertinentes, telles que les e-mails et les fichiers, à partir de leurs sauvegardes Google Workspace, à des fins d’audits, de litiges ou d’enquêtes. Cette prise en charge étendue est conçue pour aider les organisations à réduire le temps et les coûts associés à l’eDiscovery et à respecter leurs obligations légales et réglementaires.

Principales caractéristiques et avantages :
  • Advanced search: Quickly find relevant emails and files using keyword, phrase, and metadata searches with granular filtering controls. Run centralized searches across Gmail and Google Drive or target a specific service to narrow the scope for focused investigations.
  • Flexible export options: Export all search results or select items for legal review or external production. Utilize standardized export sets for recurring investigations to help minimize manual effort and expedite response times for future requests.
  • Centralized discovery experience: Perform discovery across Google Workspace today, with the flexibility to extend searches to Microsoft 365 and endpoint data – all from a single, centralized interface.
  • EDRM-compliant solution: Helps maintain EDRM compliance, adhering to identification, collection, and processing protocols.

Les fonctionnalités de recherche de conformité pour Google Workspace sont actuellement disponibles en accès anticipé et leur mise à disposition générale est prévue pour le premier semestre 2026.

Envie d’en savoir plus ?

ExplorerCommvault Backup & Recovery for Google Workspaceoudemandez une démonstration personnaliséepour voir les nouvelles fonctionnalités de recherche de conformité en action.

FAQ

Q: Why is eDiscovery important for Google Workspace data?
A: Google Workspace contains critical emails, files, and communications that are often required for legal, regulatory, and compliance matters. Efficient eDiscovery helps organizations quickly locate and produce accurate ESI while controlling costs and risk.

Q: What types of data can be searched with Commvault eDiscovery for Google Workspace?
A: The solution supports searches across Gmail and Google Drive, allowing organizations to locate relevant emails and files. Searches can be centralized across services or scoped to a specific workload for focused investigations.

Q: How do advanced search capabilities improve compliance response times?
A: Keyword, phrase, and metadata-based searches with granular filters help teams quickly narrow large data sets. This helps reduce manual effort and enable faster responses to audits, litigation, and investigations.

Q: What export options are available for legal and compliance teams?
A: Users can export all search results or select specific items for review or external production. Standardized export sets can be reused for recurring matters, enabling more consistent and efficient workflows.

Q: How does this fit into a broader, multi-platform compliance strategy?
A: Commvault provides a centralized discovery experience that spans Google Workspace, Microsoft 365, and endpoint data. This unified approach helps enable organizations to manage compliance across multiple workloads from a single interface.

Q6: When will compliance search for Google Workspace be generally available?
A: The capabilities are currently available in early access and are targeted for general availability in the first half of 2026.Katharine Colucci is a Product Marketing Manager at Commvault.


Blogs connexes

More related posts


Abstract-city-in-the-clouds-Crocus_PPT

Commvault Expands Collaboration with Google Cloud to Help Strengthen Enterprise Protection and Cyber Resilience

Read more about Commvault Expands Collaboration with Google Cloud to Help Strengthen Enterprise Protection and Cyber Resilience

Points clés à retenir

  • Le chantage par « deepfake » transforme les ransomwares, qui ne constituent plus seulement une menace pour l’accès aux données, mais provoquent une crise de confiance en utilisant des données volées pour fabriquer des contrefaçons crédibles.
  • Le succès des attaques par deepfake tient à la facilité d’accès aux outils d’IA générative, aux capacités de détection limitées et au fait que la charge de la preuve incombe désormais aux victimes.
  • True defense lies in protecting and proving the authenticity of data – not chasing every fake artifact.
  • Un stockage immuable et des points de Recovery fiables permettent aux entreprises de démontrer ce qui est authentique lorsqu’elles sont sous pression.
  • Commvault peut contribuer à renforcer la résilience en garantissant l’intégrité des données tout au long des workflows de Backup and Recovery, permettant ainsi aux organisations de rétablir rapidement leur crédibilité.

Ransomware has evolved from disrupting operations to undermining truth itself. Today’s attackers steal sensitive data and use generative AI to fabricate emails, audio, and video that appear authentic enough to deceive customers, partners, regulators, and internal teams. The challenge is no longer just restoring systems. It is proving what is real under pressure.

Quand le vol de données devient un vol d’identité

Les ransomwares traditionnels bloquent l’accès aux données.Les attaques d’extorsion par deepfake s’attaquent àla confiance elle-même.Les attaquants exfiltrent des informations d’entreprise sensibles, notamment des communications de la direction, des enregistrements de réunions et des documents internes, puis utilisent l’IA générative pour créer des contrefaçons convaincantes. Les fichiers audio ou vidéo fabriqués de toutes pièces peuvent paraître suffisamment authentiques pour induire en erreur les clients, les partenaires, les autorités de régulation et même les équipes internes.

Dans ces attaques, l’identité et l’authenticité ne vont plus de soi. La perception devient une arme.

Pourquoi l’extorsion par deepfake fonctionne-t-elle ?

L’extorsion par deepfake réussit parce que trois réalités structurelles convergent simultanément.

  • Generative tools are widely accessible: High-quality AI tools are readily available and require little expertise to operate.
  • Detection lags creation: Even experienced analysts struggle to distinguish sophisticated deepfakes from authentic content in real time.
  • The burden of proof shifts to the victim: Organizations must demonstrate that content is fabricated, often under extreme time pressure and public scrutiny.

Sans bases de données fiables ni traçabilité vérifiable des données, la vérité devient négociable.

Défense : garantir la protection, la confidentialité et l’authenticité vérifiable des données

Le chantage par deepfake n’est efficace que lorsque les attaquants ont accès à des données sources authentiques. Lorsque ces données sont protégées et vérifiables, le contenu fabriqué perd toute crédibilité et tout moyen de pression.

Une défense efficace commence par la prise de conscience que l’extorsion par deepfake n’est pas un problème de contenu. Il s’agit d’unproblème d’intégrité des données. L’objectif n’est pas de traquer chaque artefact fabriqué de toutes pièces, mais de permettre aux organisations de prouver ce qui est authentique lorsque cela compte le plus.

La défense doit donc se concentrer sur trois principes architecturaux :

  • Protect the source data: Sensitive information must be secured before it can be exfiltrated. Executive communications, recordings, and internal documents should be tightly controlled so they cannot be repurposed for manipulation.
  • Preserve data integrity: Authentic data must remain provably unchanged.Un stockage immuable permet d’empêcher que les sauvegardes et les archives historiques ne soient altérées, même par des attaquants disposant d’un accès privilégié. Cette immuabilité fournit un point de référence fiable lorsque l’authenticité est remise en cause.
  • Recover from a position of trust: When incidents occur, recovery must be based on verified, clean data. Restoring systems and records from trusted sources allows organizations to reestablish credibility quickly, rather than amplifying doubt through contaminated recovery points.

Together, these principles shift the balance of power. Instead of reacting defensively to fabricated content, organizations can retain the ability to prove authenticity, restore trust, and remove the attacker’s leverage.

Comment Commvault soutient la vérité et la résilience

Commvault aide les organisations à renforcer leur résilience face au chantage par deepfake en protégeant l’intégrité des données tout au long des workflows de sauvegarde, de récupération et de restauration.

En conservantdes points de récupération fiableset en isolant les données saines de toute manipulation, Commvault permet aux organisations de répondre aux tentatives de chantage par des preuves plutôt que par l’incertitude.

Commvault aide les organisations à :

  • Protect authoritative data sources so authentic records remain available when credibility is challenged.
  • Isolate des points de récupération fiablespour empêcher la propagation de la manipulation à l’ensemble des environnements ;
  • Restore systems and data from verified sources without reintroducing uncertainty.
  • Re-establish operational and reputational trust as AI-enabled attacks scale.

Cela permet aux entreprises de réagir de manière décisive lorsqu’elles font l’objet d’une surveillance étroite, en s’appuyant sur des données fiables pour orienter leurs actions plutôt que de réagir de manière défensive face à des récits inventés de toutes pièces.

Conclusion

Le chantage par deepfake n’est pas seulement un problème de cybersécurité. C’est un défi lancé à la vérité elle-même. Les organisations qui ne peuvent pas prouver l’authenticité de leurs propres données risquent de perdre la confiance du public lorsque la pression est à son comble. Dans ces moments-là, le doute se propage plus vite que les faits.

En concevant leur cyber-résilience autour de données protégées et vérifiables ainsi que d’une Recovery fiable, les organisations peuvent conserver la capacité de démontrer ce qui est réel et de réagir de manière décisive sous pression.

FAQ

Q: What is deepfake extortion, and how does it differ from traditional ransomware?
A: Traditional ransomware denies access to data, while deepfake extortion manipulates trust. Attackers steal sensitive information and use generative AI to create fake but convincing content, such as videos or emails, that exploit public perception.

Q: Why are deepfake attacks so effective?
A: They work because advanced generative AI tools are widely available, detection technologies lag behind creation, and organizations must prove that fabricated content is false – often under intense time pressure.

Q: How can organizations defend against deepfake extortion?
A: Defense should focus on protecting the integrity and authenticity of source data. This includes securing sensitive data, maintaining immutable backups, and verifying that recovery processes rely only on verified, clean data.

Q: What role does Commvault play in combating deepfake extortion?
A: Commvault helps maintain des points de récupération fiables, isolate clean data from manipulation, and enable organizations to respond confidently with verified information instead of speculation.

Q: Why is data integrity critical during a deepfake crisis?
A: When false content circulates, organizations quickly must prove what is real. Immutable and verifiable data provides the evidence needed to restore trust, counter manipulation, and maintain credibility under scrutiny.

Q: What’s the key takeaway for business leaders?
A: Deepfake extortion isn’t just a cybersecurity issue – it’s a truth crisis. Building cyber resilience around protected, provable data allows organizations to respond decisively and maintain trust when it matters most.

Chris DiRado is Principal, Product Experience, at Commvault.

Blogs connexes

Une approche multicouche de la cyber-résilience

Maîtrise de l’immutabilité, de l’étanchéité et de la confiance zéro pour une récupération inégalée des applications Cloud

Traiter avec Ransomware au niveau mondial

Pourquoi la récupération en salle blanche et les cyber-tests sont essentiels à la cyber-résilience

More related posts


Cyber Resilience

Read more about Cyber Resilience

Cyber Recovery

Read more about Cyber Recovery
CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Points clés à retenir

  • Les boucles de fuite de données apparaissent lorsque des informations sensibles introduites dans les interactions avec l’IA sont conservées, récupérées et renforcées au fil du temps.
  • Ces boucles sont difficiles à détecter, car chaque étape apparaît comme un comportement normal du système plutôt que comme une violation de sécurité traditionnelle.
  • L’injection rapide, la récupération trop large et la conservation excessive sont les trois mécanismes principaux qui permettent les fuites de données liées à l’IA.
  • Une sécurité IA efficace nécessite d’intégrer directement dans la conception des interactions des mesures de confinement, le principe du moindre privilège et une vérification continue.
  • Les capacités de protection, d’isolation et de récupération rapide aident les organisations à limiter l’ampleur des dégâts en cas d’exposition involontaire.

Le plus grand risque lié à l’IA n’est pas ce que disent les grands modèles linguistiques. C’est ce dont ils se souviennent. Une seule clé API copiée, une fiche client ou un document interne collé dans une invite peut persister discrètement, réapparaître et se propager bien au-delà de son contexte d’origine. Chaque invite, chaque récupération et chaque réponse dans un système d’IA crée un risque d’exposition involontaire des données. Chaque invite, récupération et réponse dans un système d’IA crée un risque potentiel d’exposition involontaire des données. Les identifiants, la propriété intellectuelle, les informations personnelles identifiables et les données clients peuvent tous être introduits dans les flux de travail de l’IA sans intention malveillante. Au fil du temps, ces expositions s’accumulent, formant des boucles de rétroaction invisibles de risques jusqu’à ce que l’exposition soit généralisée. Contrairement aux violations traditionnelles, les boucles de fuite de données s’annoncent rarement. Elles se développent progressivement, interaction après interaction, jusqu’à ce que les informations sensibles soient dispersées à travers des systèmes, des utilisateurs et des sorties qui n’étaient pas censés les voir.

Les boucles de fuite de données suivent un schéma simple. Des données sensibles sont introduites dans une interaction IA, stockées ou intégrées par le système, récupérées ultérieurement dans un contexte non prévu, puis renforcées à chaque utilisation ultérieure. Chaque étape ressemblant à un comportement normal du système, la boucle passe souvent inaperçue jusqu’à ce que l’exposition soit généralisée.

Quand l’intelligence crée des fuites

Les organisations adoptent l’IA générative pour accélérer leur productivité, automatiser leurs décisions et améliorer l’expérience client. Le défi ne réside pas dans l’intention, mais dans l’architecture. Les systèmes d’IA sont conçus pour ingérer, récupérer et contextualiser des informations. Lorsque les mesures de protection sont insuffisantes, des fragments de données sensibles introduits lors d’une interaction peuvent refaire surface plus tard dans des réponses sans rapport. Chaque utilisation renforce la suivante, créant ainsi un cycle d’exposition qui s’autoalimente.

L’architecture des boucles de fuite de données

Les fuites de données dans les systèmes d’IA se produisent généralement par le biais de trois mécanismes interdépendants :

  • Prompt injection (intentional or accidental): Users knowingly or unknowingly include sensitive data in prompts, such as passwords, customer records, or proprietary information, which the system processes and may retain.
  • Over-broad retrieval: AI systems retrieve information from data sources they should not access due to weak permissions or insufficient context filtering.
  • Excessive retention: Interaction histories, embeddings, and logs are stored longer or more broadly than necessary, allowing sensitive data to persist and resurface.

Ensemble, ces mécanismes forment des boucles de rétroaction où chaque interaction augmente l’exposition cumulative.

Défense dans la conception d’interactions avec l’IA

L’hypothèse de conception la plus sûre est que tout ce qui est fourni à un système d’IA peut être conservé, réutilisé ou divulgué. Cette mentalité change fondamentalement la manière dont les systèmes d’IA doivent être sécurisés. La protection doit être intégrée dans la conception des interactions plutôt que d’être appliquée après l’exposition. La sécurité dans les systèmes d’IA part du principe que l’exposition est possible, ce qui fait du confinement, du moindre privilège et de la vérification continue des exigences fondamentales en matière de conception. En pratique, cela signifie :

  • Appliquerles principes du « zero trust »à chaque interaction avec l’IA.
  • Vérification et limitation de l’accès aux données à chaque étape du traitement rapide, de la récupération et de la génération de réponses.
  • Réduire au minimum les autorisations pour les invites, les sources de récupération et les couches de stockage.
  • Appliquer une autorisation contextuelle dans les pipelines de récupération au moment de la requête, plutôt que de s’appuyer sur des autorisations statiques définies en dehors du flux de travail de l’IA.
  • Concevoir des systèmes visant à limiter l’exposition plutôt que de supposer que la prévention seule est suffisante.

Cette approche transforme la sécurité de l’IA, qui passe d’un nettoyage réactif à une résilience proactive.

Le rôle de Commvault

Commvault aide les organisations à protéger les données qui alimentent les systèmes d’IA, notamment les données d’entraînement, les sources de récupération et les chemins de restauration, avant, pendant et après l’interaction. En offrant des capacités de protection, d’isolation et de récupération rapide, Commvault permet aux organisations delimiter l’ampleur des dommages causéspar une exposition involontaire et de restaurer les environnements d’IA à partir de sources de données fiables. Avec Commvault, les entreprises peuvent contribuer à :

En combinant cela avec des contrôles d’accès aux données très précis, les entreprises peuvent innover grâce à l’IA sans créer de boucles de risques cumulés.

Conclusion

Les boucles de fuite de données représentent l’un des risques les plus subtils et les plus dangereux liés à l’adoption de l’IA. Elles ne ressemblent pas à des attaques, mais elles affaiblissent la sécurité de manière continue. En traitant chaque interaction avec l’IA comme une exposition potentielle et en intégrant protection, isolation et Recovery dans les architectures d’IA, les entreprises peuvent faire évoluer l’IA tout en contribuant à préserver la confiance.

FAQ

Q: What is a data leakage loop in AI systems?
A: A data leakage loop occurs when sensitive data is introduced into an AI interaction, stored or embedded, later retrieved in an unintended context, and reinforced through repeated use. Over time, this creates a self-sustaining cycle of exposure that can spread across systems and users.

Q: Why are data leakage loops harder to detect than traditional breaches?
A: Unlike conventional breaches, data leakage loops do not trigger clear alerts or single points of failure. They grow gradually through normal-looking interactions, making exposure visible only after it has already spread widely.

Q: How does prompt injection contribute to data leakage?
A: Prompt injection occurs when users accidentally or intentionally include sensitive information in prompts. If safeguards are weak, that data can be processed, retained, or reused by the system beyond its original context.

Q: What role does AI system architecture play in preventing leakage?
A: Architecture determines how data is ingested, retrieved, stored, and reused. Designing AI systems with les principes du « zero trust », least-privilege, and context-aware authorization helps contain exposure instead of relying solely on prevention.

Q: How can organizations reduce risk without slowing AI adoption?
A: Organizations can reduce risk by embedding security directly into AI interaction design and planning for containment and recovery. This approach enables innovation while limiting cumulative exposure as AI usage scales.

Q: How does Commvault support protection against data leakage loops?
A: Commvault helps protect the data that fuels AI systems by providing de sauvegardes immuables, isolation, and rapid recovery. These capabilities help enable organizations to limit the impact of unintended exposure and restore trusted AI environments quickly.

Chris DiRado is Principal, Product Experience, at Commvault.


Related Blogs

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

The board meeting started with a simple question: “Are we ready for the next disruption?”

I gave them an honest answer: “That depends on which disruption we’re talking about.”

Because here’s the reality every CIO knows but doesn’t always say out loud: Readiness isn’t a checkbox. It’s not something you achieve once with a great recovery plan or a perfectly executed disaster recovery test. Readiness is a muscle you build, test, and rebuild constantly as the threat landscape shifts beneath your feet.

That’s why we created the Readiverse. Not another content library. Not another vendor resource hub. It’s a space where CIOs, CISOs, and technology leaders can get the intelligence they need to help them stay ready – whether that means anticipating the next ransomware variant, navigating AI governance challenges, or simply having a straight answer when the board asks, “Are we protected?”

Two Kinds of Readiness

In my role, I need two things that rarely live in the same place:

Strategic insight for the boardroom: Intelligence briefs that analyze emerging threats through a business impact lens. Quick-hit perspectives from executives who’ve been in your chair – 60-second Bold Takes on what matters now. Peer conversations with other CIOs who’ve navigated market disruptions and transformation challenges.

Practical guidance for implementation: Readiness assessmentsto benchmark your maturity. Regulatory compliance guides that help map requirements to capabilities.Recovery workshops and hands-on experience that sharpen your team’s ability to respond when it matters most.

The Readiverse brings both together. Because you can’t lead from the boardroom without understanding implementation realities. And you can’t build resilient systems without connecting them to business outcomes.

Ready. Or Not.

That’s the choice we face every day as technology leaders. We can be ready – with tested plans, trained teams, and intelligent defenses. Or we can be caught off-guard when disruption arrives.

That’s why we’re launching our new, six-part podcast series, Ready. Or Not., on the Readiverse. Our host, comedian Nathan Macintosh, and his guests cut through the AI hype and cybersecurity complexity with humor and straight talk. Check out our first episode – AI: Agents of Good, Meet Agents of Evil – with guest Reid Blackman, founder and CEO of AI risk consultancy Virtue.

Beyond the Noise

The Readiverse exists to give you the intelligence, perspective, and practical guidance you need to build resilience that works – not just resilience that sounds good in a slide deck.

Because the board will keep asking if we’re ready. And we owe them – and ourselves – an honest, confident answer. Explore the Readiverse, and we’ll stay ready together.

Ha Hoang is Chief Information Officer at Commvault.

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Belgium-based xyzt.ai was founded to help customers gain insight from their location data. Read on to hear why the company chose Clumio, a Commvault company following its acquisition in 2024, to reduce AWS backup costs and significantly improve recovery times.


Q: Lida, can you start by telling us what xyzt.ai does?

Lida: We are a cloud-based, no-code analytics platform that helps customers turn massive volumes of sensor, IoT, and mobility data into meaningful insights. We process billions of records and make it easy for users to visualize patterns, identify anomalies, and make data-driven decisions. Our customers span maritime, mobility, smart cities, and connectivity – anyone who needs to understand location-based behavior at scale.

Q: As a growing startup, how did backups fit into your early strategy?

Lida: In the beginning, AWS-native backups worked well for us. They were simple, integrated, and aligned with our cloud-first architecture. Unfortunately, over time, as our data grew, our AWS backup bill grew with it. It wasn’t dramatic at first, but every year the cost kept climbing.

Q: At what point did rising AWS backup costs become something you needed to solve?

Lida: After about five years of steady growth, the trend was impossible to ignore. Our costs were increasing year over year simply because we were scaling our data footprint. That’s when we realized we needed a more sustainable, predictable option.

Q: What led you to evaluate Clumio?

Lida: Initially, we were looking purely for cost reduction. Once we saw theClumio demo, we realized the value was much broader. Compliance, recovery, data isolation, pricing predictability – those were all important features Clumio provided.

Q: How would you describe your onboarding experience?

Lida: Surprisingly fast. We expected a time-consuming migration, but it was incredibly smooth. We had our first backup running within 30 minutes. That’s not something you expect when switching a core infrastructure component.

Q: Many organizations worry not just about backup costs but also how quickly they can recover. How has recovery performance changed since moving to Clumio?

Lida: Recovery speed is one of the areas where we saw the biggest improvement. With AWS-native tools, restoring large datasets could take hours – sometimes longer – because recoveries were tied to the time it took to fully rehydrate data back into our AWS environment. That lag was a real challenge when we needed fast access for troubleshooting or when customers required immediate data validation.

With Clumio, the experience is dramatically different. The Instant Access feature lets us mount backups in minutes without waiting for full restores. That means our team can start working with the data almost immediately, whether it’s for verification, investigation, or full-scale recovery.

The time savings are enormous – it’s not just faster, it fundamentally changes how quickly we can respond to issues. For a real-time analytics platform like ours, that makes Clumio far more effective than AWS-native options.

Q: Let’s talk results. What impact did Clumio have once you were up and running?

Lida: The most immediate impact with Clumio was cost savings. Using AWS Storage Lens, we confirmed that backups through Clumio were 66.7% cheaper than what we were paying previously. That validation came quickly, and it accelerated our internal approval to move forward.

We also gained stronger resilience by storing backups outside our main AWS environment, which improved our security and compliance posture.

Q: What advice would you share with other AWS-native startups evaluating their backup strategy, and how does Clumio fit into your long-term plans?

Lida: I would tell other startups not to be intimidated by the idea of switching backup providers. The migration was much easier than we expected, and the payoff was immediate.

If your AWS costs are climbing or your compliance requirements are evolving, it’s absolutely worth exploring alternatives. Data protection is central to our business, so we need solutions that scale with us without introducing unpredictable cost spikes – and Clumiogives us that confidence.

Cara Peterson is Voice of the Customer Manager at Commvault.

More related posts


GSI

The Importance of Cyber Resilience in a Cloud-First World

Read more about The Importance of Cyber Resilience in a Cloud-First World
Thumbnail_Blog_Clumio-Tech-2025

Restore only what matters: Clumio Backtrack for DynamoDB

Read more about Restore only what matters: Clumio Backtrack for DynamoDB

Clumio

Read more about Clumio

New Yorkers don’t settle. They expect the fastest service, the toughest infrastructure, and the boldest ideas. So it’s no shock that when it comes to data security, their expectations soar.

But here’s the twist: selon une récente enquête commandée par Commvault of more than 1,000 New Yorkers, consumers hold businesses to uncompromising security standards, even as many admit they don’t follow those same practices themselves.

This isn’t just an interesting quirk. It’s a signal about the future of trust, resilience, and loyalty.

Deux normes, une ville

The survey makes one thing clear: In New York, trust isn’t given – it’s earned. And it’s earned through action.

Most respondents said they would stop using, or seriously consider leaving, a company after a breach. Many already have. They reward businesses that prove they take data protection seriously, not just talk about it.

Yet, while they demand resilience from brands, their own habits tell a different story. Password reuse? Still common. Public Wi-Fi? Still tempting. Even with rising awareness and firsthand experience of cyber incidents, inconsistent behaviors persist.

Is that hypocrisy? No. It’s human nature.

People want safety, but they also want convenience, speed, and simplicity. And when those collide, personal cyber hygiene often slips.

Businesses don’t have that luxury.

Pourquoi cet écart est un impératif pour les dirigeants

The takeaway isn’t to judge consumers; it’s to understand them. Consumers can take steps to protect themselves (and many do), but they can’t single-handedly defend against sophisticated, AI-enabled threats. Nor should they have to.

That’s where the expectation gap becomes a leadership mandate. Cyber resilience is a shared responsibility, but businesses must lead. And leadership shows up in three ways:

  • Protect before the breach: Build strong defenses, zero-trust controls, and unified resilience platforms that keep pace with evolving threats.
  • Respond fast when things go wrong: Consumers judge a breach not just by its occurrence, but by how quickly and effectively youvous remettre sur pied.
  • Communicate with transparency: Silence erodes trust faster than bad news. Honesty wins.

L’alignement de ces éléments renforce la confiance des consommateurs.

New York, un signal national

Les tendances naissent à New York. C’est ici que les attentes se cristallisent. C’est ici que les opinions basculent le plus radicalement. Si les New-Yorkais indiquent que la confiance est un facteur primordial dans le choix d’une marque, les entreprises de tout le pays devraient en prendre bonne note. Ce qui commence sur un marché majeur s’étend rarement au-delà de celui-ci. Les attentes en matière de sécurité ne cessent de s’intensifier. Et à l’ère de l’IA, le coût de la perte de confiance est plus élevé que jamais.

La résilience est le nouveau programme de fidélisation

For years, brands have poured billions into personalization and convenience. But today’s research suggests something different is rising to the top: Consumers stay loyal to businesses they believe will protect and vous remettre sur pied their data, not just collect it.

Sécurité, resilience, and trustworthiness aren’t just back-office concerns anymore. They’re front-of-brand differentiators that shape purchasing decisions, referrals, and long-term relationships.

And in a season when people are traveling, shopping, and accessing sensitive information on the go, often across unsecured networks, the stakes couldn’t be higher.

Le moment de diriger

Consumers have clear demands: People know what they expect, what they’ll tolerate, and what they won’t. And they’re watching you closely.

For businesses, the opportunity is profound: Invest in resilience today and earn loyalty tomorrow. Because when it comes to cybersecurity, consumers don’t just want to feel protected, they want to be protected.

The companies that deliver on that promise will define the next era of trust.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Points clés à retenir

  • Arlie Data Sense aide à transformer des données réseau dispersées (journaux, audits, historiques des tâches) en résumés clairs et exploitables, accompagnés de suggestions de suivi et de requêtes libres.
  • New root-cause analysis helps scan failures, spots anomalies, and delivers plain-language diagnostics with recommended next steps – no manual log-diving required.
  • Les Video Bytes dans Arlie Responses vous permettent d’accéder directement au moment précis où votre question trouve une réponse dans les vidéos longues, ce qui accélère la résolution des problèmes.
  • En coulisses, Arlie orchestre les agents ETL, de masquage des informations personnelles identifiables et d’analyse afin de générer des informations contextuelles sur lesquelles vous pouvez agir rapidement.
  • Arlie et sa bibliothèque d’agents sont disponibles dans Commvault SaaS un déploiement progressif, ce qui permet d’atteindre la parité avec les déploiements logiciels Commvault.

IT teams are under pressure to do more with less. You’re expected to spot risks early and optimize performance while juggling growing infrastructure and managing thousands of daily backup events. Generating insights from this constant stream of activity across platforms can be incredibly difficult.

This allows vulnerabilities to quietly creep in, waiting to expand into a major issue. Your dashboard says green. Backups seem to be running. But behind the scenes, something’s building: a silent timeout, a log full of subtle warnings, a spike in retries you didn’t notice. By the time a backup admin spots it, it’s already an incident.

The fact is, modern IT environments don’t fail loudly – they fail subtly. And most of the time, the data that could have warned you is already there. It’s just buried in audit trails, scattered across consoles, or trapped in a 40-minute training video.

This is where Arlie really shines. Arlie isn’t just an AI assistant – it’s the intelligent, unified interface designed to help find, understand, and resolve issues faster. Arlie orchestrates advanced backend workflows (agents) that help interpret data, identify anomalies, and generate insights – and then communicates the findings to you through a simple, conversational experience.

With Arlie Data Sense and Video Bytes in Responses, Arlie brings context, clarity, and speed to every interaction – without the hunting. Let’s take a look at what’s new.

Analyse des données réseau : de la surcharge d’informations à la compréhension des données

Modern environments generate an overwhelming amount of data‌: ‌logs, alerts, warnings, and more. On the Commvault platform, these manifest as audit trails and job histories, with hundreds or even thousands of events occurring every day.

Businesses often don’t know where to begin when analyzing their environments. Backup admins are tasked with making sense of this flood, manually scanning through sprawling rows of data across multiple consoles just to understand what’s happening. And with so many actions being logged every minute, it’s easy to miss early warning signs that could escalate into larger issues.

That’s where Arlie Data Sense and its grid data analysis capability come in. It ingests your platform data and distills it into clear, actionable summaries. Instead of forcing teams to scroll through thousands of rows, Arlie Data Sense identifies the most relevant information, delivers those summaries, and highlights what’s actionable in a clear, conversational way. Users can expect:

  • A highlighted executive summary tailored to the user’s environment.
  • Questions complémentaires suggérées pour aider à explorer les questions émergentes.
  • La possibilité de poser des questions ouvertes pour une analyse plus approfondie.

What’s more, Arlie Data Sense highlights ransomware protection-related events and major changes, proactively surfacing insights that help users stay ahead of potential risks.

However, behind the scenes is where the magic truly happens. Arlie orchestrates multiple backend workflows – retrieving data from Commvault, performing ETL and PII masking, and leveraging analysis agents to generate insights. Arlie’s reasoning and knowledge augmentation capabilities then transform this into actionable intelligence for the user.

With a simple click of a button, backup admins can derive key insights that highlight the exact points needed. Essentially, this allows you to converse with your platform’s data and gain a much clearer understanding of where the system stands in real time.

It’s not just alerting; ‌it’s contextual understanding. No more digging through logs. No more endless tab-hopping. It’s a smarter, faster way to help you monitor system health, troubleshoot issues, and understand your risk landscape. This kind of insight drastically improves efficiency, especially for lean teams managing complex environments‌, ‌allowing them to focus on what truly moves the needle.

Analyse des causes profondes : transformer les journaux bruts en réponses en temps réel

Reading logs is no one’s idea of fun. Yet buried in those logs are critical clues: ‌why something failed, where the system is strained, and what’s likely to break next. Given the monotonous nature of scouring through large volumes of log data for answers, many teams struggle to diagnose job failures.

Arlie Data Sense and its root-cause analysis capability do the detective work. It scans job failures, identifies root causes, spots anomalies, and generates clear, human-readable explanations – all without manual log interpretation.

Integrated directly into the Send Log Files workflow and Command Center, the agent processes log files to deliver detailed diagnostics along with potential resolutions. Arlie then communicates those findings and recommendations to users, providing clarity and saving valuable troubleshooting time.

Let’s say a job has failed intermittently over the past week. Instead of manually combing through five different logs, Arlie Data Sense can help flag recurring timeouts linked to a specific virtual machine (VM). Or, if backups are running slower than usual, it can help identify the underlying issue.

So, whether you’re managing a handful of backup jobs or orchestrating across hundreds of environments, Arlie helps you cut through the noise and act faster by presenting the right insights at the right time.

Ever found the perfect video that promises to answer your question‌, only to realize it’s 30 minutes long? The exact answer you’re looking for could be 20 seconds or 20 whole minutes into the video, and you have no idea where it’s actually buried. Even after finding this video, locating your answer could be a tedious, time-consuming endeavor.

With Video Bytes in Arlie Responses, that frustration is gone.

Now, when Arlie knows there’s helpful information available within documentation or the Readiverse, it doesn’t just share the link‌ – ‌it pinpoints the exact moment in the video that answers your question. Just ask something like “How can I reduce my VM costs?” and Arlie will jump straight to the timestamp where that topic is addressed‌ – ‌say, Minute 12 of a 30-minute walkthrough.

This enhancement means that you don’t have to rely strictly on documentation or lengthy videos to resolve your issues. It’s a smarter, more efficient, and highly focused approach that gives you exactly what you need.

Des réponses aux actions : Arlie, évolué pour vous

These exciting new capabilities mark a new chapter in Arlie’s journey, transforming it from being an AI assistant that helps to one that understands. Whether it’s generating key summaries or diagnosing failures through Arlie Data Sense or jumping to exactly what you need with Video Bytes, Arlie is AI designed specifically for you.

In a world where IT complexity is only growing, the real edge lies in proactive, contextual intelligence. With Arlie, you don’t just fix issues faster – you prevent them from happening. With minimal user input, Arlie allows you to see more, do more, and be more.

Désormais disponible dans Commvault SaaS

Commvault’s AI capabilities – including Arlie and its bibliothèque d’agents – are now available in Commvault SaaS. This brings feature parity with Commvault software deployments, giving SaaS customers the same intelligent, AI-enabled experience. This brings feature parity with Commvault software deployments, giving SaaS customers the same intelligent, AI-enabled experience.

These capabilities are rolling out in phases, and you’ll begin seeing them appear in your SaaS environment in the coming weeks.

With these enhancements, Arlie brings the future of intelligent, contextual resilience directly into your hands – across both Commvault software and SaaS. Get ready for faster insights, fewer surprises, and a more connected, proactive experience – all with Arlie at the center.

If you’re using Commvault software, you can enable Arlie today by following the instructions in our documentation.

If you’re using Commvault SaaS and would like to enable these features early, please contact your Commvault representative.

FAQs

Q: What exactly is Arlie, and how is it different from a typical chatbot?
A: Arlie is a unified, conversational interface that orchestrates backend workflows –ingesting platform data, running analyses, and returning concise, actionable guidance – so you can move from “searching” to “solving.”

Q: How does the grid data analysis feature help me day to day?
A: Instead of sifting through thousands of rows across consoles, Arlie Data Sense highlights the most relevant signals, summarizes them for your environment, and proposes next questions to dig deeper, reducing noise and accelerating decisions.

Q: What problems does the root-cause analysis feature tackle?
A: It analyzes failures and anomalies across logs to pinpoint likely causes – like recurring timeouts tied to a specific VM – and offers human-readable explanations with potential resolutions, saving significant troubleshooting time.

Q: How do Video Bytes in Arlie Responses speed up learning and support?
A: When a relevant video exists, Arlie links directly to the precise timestamp that answers your query, eliminating the need to scrub through lengthy recordings to find the right segment.

Q: Where can I access these capabilities, and when will I see them?
A: Arlie and its agents are available in Commvault SaaS with feature parity to software deployments, and the enhancements are rolling out in phases over the coming weeks; contact Commvault to enable early access.

Q: How does this tie into resilience and business continuity efforts?
A: Proactive insight and faster root-cause analysis complement disaster recovery programs by helping teams act before minor issues escalate – supporting broader goals of resilience and continuity highlighted in industry cyber and disaster recovery practices.


Teja Medasani is Principal Product Manager, AI, and Mrityunjay Upadhyay is Director, Development, at Commvault.


Blogs connexes

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

The threat of disruption – from ransomware attacks to natural disasters – has never been greater. For businesses, downtime isn’t just an inconvenience; it’s a direct hit to revenue, reputation, and customer trust. This reality has pushed cyber des données et de reprise après sinistre, conçue pour protéger les données et les applications dans de multiples environnements sur site et dans le cloud. En assurant une protection continue des données, le logiciel HPE Zerto réduit à néant les pertes de données et les temps d’arrêt, permettant ainsi une reprise rapide après ransomware , une catastrophe ou toute autre perturbation. to the forefront of IT strategy, demanding solutions that not only protect data but also maintain its continuous availability.

HPE et Commvaultrenforcent leur collaboration de longue date afin de répondre à ce besoin crucial. En proposant le logiciel HPE Zerto avec laplatform Commvault Cloud , ces deux leaders du secteur offrent une solution puissante et unifiée qui garantit une cyber-résilience avancée, la protection des données et la reprise après sinistre dans cloud hybrides des entreprises.

A Leader in Continuous Data Protection 

We’re proud to announce that the HPE Zerto Software from Commvault solution is now generally available (GA) – ready for organizations everywhere. HPE Zerto Software from Commvault is a leading solution for data des données et de reprise après sinistre, conçue pour protéger les données et les applications dans de multiples environnements sur site et dans le cloud. En assurant une protection continue des données, le logiciel HPE Zerto réduit à néant les pertes de données et les temps d’arrêt, permettant ainsi une reprise rapide après ransomware , une catastrophe ou toute autre perturbation.Caractéristiques principales

Chiffrement en temps réel

  • Real-time encryption to enable ransomware des données et de reprise après sinistre, conçue pour protéger les données et les applications dans de multiples environnements sur site et dans le cloud. En assurant une protection continue des données, le logiciel HPE Zerto réduit à néant les pertes de données et les temps d’arrêt, permettant ainsi une reprise rapide après ransomware , une catastrophe ou toute autre perturbation..
  • Disaster recovery for virtualized infrastructures and cloud environments, including on-premises, public clouds (AWS, Azure), and hybrid environments. Protect workloads across different environments and cloud providers, creating a comprehensive disaster recovery solution.
  • Workload mobility delivered by simple automation and orchestration of failover, failover tests, and recovery, making it suited for cloud migrations and workload mobility.
  • Cyber des données et de reprise après sinistre, conçue pour protéger les données et les applications dans de multiples environnements sur site et dans le cloud. En assurant une protection continue des données, le logiciel HPE Zerto réduit à néant les pertes de données et les temps d’arrêt, permettant ainsi une reprise rapide après ransomware , une catastrophe ou toute autre perturbation. with a combination of regular data protection, real-time encryption detection, and immutable data recovery data.
  • Scalability and reliability with features like near-synchronous replication that can reduce recovery times significantly.

Pourquoi Commvault et HPE Zerto ?

Each customer has different needs and requirements, and there is no one-size-fits-all solution. Among the factors to consider are the workload types, the size and scale of the environment, the desired recovery point objective and recovery time objective, and the cost of the solution.

Commvault is focused on delivering end-to-end solutions that not only address the operational des données et de reprise après sinistre, conçue pour protéger les données et les applications dans de multiples environnements sur site et dans le cloud. En assurant une protection continue des données, le logiciel HPE Zerto réduit à néant les pertes de données et les temps d’arrêt, permettant ainsi une reprise rapide après ransomware , une catastrophe ou toute autre perturbation. and disaster recovery needs of our customers, but also enable cyber readiness and recovery, governance and compliance, and rapid rebuilding of cloud native applications.

HPE Zerto Software from Commvault is a direct reflection of this commitment. HPE Zerto fits well within Commvault’s Autonomous Recovery offering, providing customers regular replication and operational des données et de reprise après sinistre, conçue pour protéger les données et les applications dans de multiples environnements sur site et dans le cloud. En assurant une protection continue des données, le logiciel HPE Zerto réduit à néant les pertes de données et les temps d’arrêt, permettant ainsi une reprise rapide après ransomware , une catastrophe ou toute autre perturbation. for most critical virtualized workloads that cannot afford any downtime.

Amplifier nos forces

This offering is a testament to the deep, strategic relationship between HPE et Commvault. We amplify each other’s portfolio strengths, creating a synergy that enhances the overall value and effectiveness of our solutions. And what we jointly offer to our customers goes beyond just data protection; it’s the confidence that comes from knowing your operations are set up to be resilient and ready to face the uncertainties of the digital age.

To learn more about early access to HPE Zerto offering from Commvault, please reach out to your account team.

Prêt à commencer ?

The GA launch of HPE Zerto Software from Commvault means now is the time to act – don’t wait. Schedule a demo with your Commvault account team.

More related posts


Thumbnail_Blog_HPE-Zerta-Software-2025

HPE Zerto Software from Commvault: Enhancing Data Resilience and Disaster Recovery

Read more about HPE Zerto Software from Commvault: Enhancing Data Resilience and Disaster Recovery

Points clés à retenir

  • Ransomware le cycle de vie d’un ouragan : les alertes précoces sont souvent ignorées, leur impact est paralysant et une reprise coordonnée est essentielle.
  • Identity systems (Active Directory and Entra ID) are frequent first casualties; without them, data recovery and access stall.
  • The cost of unpreparedness is high – weeks of downtime and seven-figure losses – making identity-centric resilience a business imperative.
  • Preparation should include clean, immutable, and air-gapped backups of AD/Entra ID plus regular full-forest recovery drills.
  • A practical blueprint – assess, protect, isolate, recover, evolve – enables faster, cleaner restoration of data, identity, and trust.

Ransomware has become the digital equivalent of a hurricane – powerful, unpredictable, and capable of wiping out years of progress in a single strike. Like natural disasters, cyber disasters are no longer if events, but when events. The question every organization must answer is not “Can we prevent the storm?” but “Will we survive and recover when it hits?”

This paper explores the parallels between ransomware and hurricanes, with a special focus on résilience des identités – including Active Directory(AD) andMicrosoft Entra ID. These identity systems are often the first casualties of a ransomware event. When identity is compromised, recovery stalls – just as losing your address and keys after a hurricane leaves you locked out of your own home.

1. The Parallel Between Storms and Cyberattacks

Hurricane Lifecycle
Ransomware Lifecycle
Shared Lesson
Formation: Warm waters and unstable air pressure form the perfect storm. Exposure: Unpatched systems, weak credentials, and flat networks create ideal attack conditions. Weak foundations invite disaster.
Warning: Meteorologists issue alerts days in advance. Alerts: Security Information and Event Management, Endpoint Detection and Response, and threat intelligence show early warning signs – often ignored. Detection without action is denial.
Landfall: The hurricane makes impact – power lines fall, flooding begins, and communications fail. Detonation: Malware encrypts systems, disables security tools, and shuts down AD. Both result in complete operational paralysis.
Response: First responders triage, reroute power, and rescue survivors. Response: Incident response teams isolate affected systems, assess backups, and begin recovery procedures . Speed, coordination, and clarity define success.
Recovery: Homes are rebuilt, infrastructure restored, and new defenses added. Recovery: Clean data and identity are restored, enabling business continuity. Recovery must include identity – not just data.

2. The Hidden Cost of Identity Loss

When a hurricane destroys your home, you can’t just rebuild walls – you need new keys, insurance, and documents to reclaim ownership. In a ransomware event, the same is true: Without AD or Entra ID, you can’t re-enter your own network.

Identity is the “address” of your digital home – lose it, and you’re stranded outside your own infrastructure.

3. The Cost of Unpreparedness

When hurricanes strike, unprepared communities face catastrophic loss. When ransomware strikes unprotected environments, the results are equally devastating:

Unprepared organizations struggle not only to restore data but also to rebuild trust chains between systems, domains, and users – often forcing a complete forest rebuild that takes weeks or months.

4. Lessons from the Storm: Building Cyber and Identity Resilience

A. Preparation is Prevention

  • Regularly export and validate AD system state backups and Entra ID configurations.
  • Implement role-based access and privileged identity management to limit blast radius.
  • Store clean, immutable copies of both on-prem AD and Entra ID schemas in a secure, air-gapped vault.
  • Conductforest recovery drillsthat simulate full AD rebuilds.

B. Withstand the Impact

  • Segment identity infrastructure and limit replication paths.
  • Use Conditional Access and Authentication Strength policies in Entra ID to enforce adaptive protection.
  • Employ zero-trust principles to contain lateral movement and privilege escalation.

C. Recover with Confidence

  • Commvault full forest recovery helps automate the end-to-end rebuild of AD forests – restoring DCs, trusts, and configurations from clean, immutable backups.
  • Entra ID Protection integrates with recovery workflows so that cloud identities, multi-factor authentication policies, and Conditional Access settings are restored in sync.
  • Automated validation helps verify there’s no reinfection and no cross-contamination of credentials.

5. The Resilience Blueprint: From Disaster to Continuity

  • Assess: Identify your “digital coastline” – the systems and identities that define business continuity.
  • Protect: Harden your identity and data perimeter through zero trust and ongoing validation.
  • Isolate: Maintain immutable, air-gapped copies of AD, Entra ID, and critical data.
  • Recover: Use orchestrated tools like Commvault’s full forest recovery to restore identity and access rapidly.
  • Evolve: Update and retest your plan with every new patch, policy, or platform integration.

6. Commvault Perspective: Recover Faster. Recover Clean. Recover Identity.

Grâce àfull forest recovery for AD and integrated Entra ID protection, Commvault helps enable organizations to restore on-prem and cloud data and identities with integrity, speed, and confidence after a ransomware incident.

A hurricane tests the strength of your walls. Ransomware tests the strength of your resilience. You cannot stop every storm – natural or digital – but you can decide whether it destroys or defines you.

FAQ

Q: What makes identity loss so disruptive during ransomware recovery?
A: If AD or Entra ID is compromised, organizations can’t authenticate, authorize, or re-establish trust across systems – effectively locking themselves out of their own environment. Attackers often target domain controllers and trust relationships, so recovery must start with clean identity restoration before broader services can come back online.

Q: How big is the downtime and cost risk?
A: The paper cites typical ransomware downtime measured in weeks and total incident costs in the seven-figure range, with identity systems among top targets. These impacts compound when teams lack forest-level recovery capabilities or clean, immutable backups of identity configurations.

Q: What preparation steps most effectively reduce impact?
A: Regularly export and validate AD system-state and Entra ID configurations; apply role-based access and privileged identity management; keep immutable, air-gapped copies of identity schemas; and run full-forest recovery exercises to validate speed and coordination under pressure.

Q: How should recovery be orchestrated after an attack?
A: Start by isolating affected systems and pivot immediately to identity restoration from clean, immutable backups, then rebuild domain controllers, trusts, and policies in sync with cloud identity settings. Automated validation helps confirm a clean state and prevents credential cross-contamination during bring-up.

Q: What does a resilience blueprint look like in practice?
A: Follow five steps: Assess critical “digital coastline,” protect with Zero Trust and continuous validation, isolate with immutable air-gapped copies, recover with orchestrated full-forest workflows, and evolve by testing after every change in patches, policies, or platform integrations.

Jerry Carlson is Field CTO at Commvault.


Blogs connexes

More related posts


Thumbnail_Blog-Ransomware-and-Hurricane-2025

Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

Read more about Ransomware and Hurricanes: The Anatomy of Impact and the Blueprint for Resilience

University of Illinois Chicago (UIC) is home to more than 34,000 studentset13,000 facultyetstaff. Technology Solutions, UIC’s central IT organization, is responsible for ensuring the resilience of research, clinical,etadministrative systems.

We spoke with Dean Dang, Director of Enterprise ApplicationsetServices, about UIC’s data protection journeyethow Commvault helps the university safeguard mission-critical operations.

 

Q: Can you start by introducing yourselfetgiving us a sense of UIC’s missionetwhat drives your IT strategy?

Dean: My name is Dean Dang,etI serve as the Director of Enterprise ApplicationsetServices within Technology Solutions. We support the university’s administrativeetacademic functions, aligning IT with UIC’s mission: to provide the broadest access to the highest levels of educational, research,etclinical excellence. Our commitment to access, vitality, empowerment,etcreativity is our strength.

 

Q: Before onboarding Commvault, what were the biggest data protectionetresilience challenges UIC was up against?

Dean: Our legacy backup system, Spectrum Protect, had accumulated years of technical debt. Recovery was painfully slow — restoring large file servers could take weeks. We also dealt with decentralized IT management across 20+ departments, inconsistent backup policies, inefficient tape storage,etno cloud options. The risks of data lossetdowntime were too high for a university of our size.

 

Q: When it came time to modernize, what stood out about Commvault that made it the right fit for UIC?

Dean: We’d known Commvault for over a decadeettrusted it for Active DirectoryetExchange backups. When we evaluated options, Commvault stood out. The ability to takeVM snapshots without server agents was huge. Even more important was the multi-tenant model. It let us provide departmental autonomy while maintaining centralized governanceetsupport — exactly what higher ed needs.

 

Q: What changes have you seen since implementing Commvault,ethow has it elevated UIC’s cyber resilience?

Dean: With Commvault, we do nightly backups with deduplicationetsynthetic fulls. That reduces storage demandetspeeds up restores. Departments get their own “tenants” to manage backups, but we still enforce policiesetprovide support. All backups are encryptedetcan be stored on-prem or in the cloud.

We also use Air Gap Protect for immutable copiesetCleanroom Recovery for safe recovery testing. This setup means we can recover mission-critical systems in under 8 hours — compared to days or weeks before.

 

Q: If you were talking to other higher-ed IT leaders, what top lessons or best practices would you share about building cyber resilience?

Dean:

  1. Enforce multifactor authentication everywhere, especially admin accounts. Everyone can be phished.
  2. Build a pragmatic, team-driven DR plan. Don’t try to solve everything at once — build consensusetclarity.
  3. Test nightly backups. Make them immutable, air-gapped,etvalidated so you know you can restore when it matters.

 

Q: How do you communicate cyber risks to non-technical leaders?

Dean: We translate risk into business terms. How many hours of downtime? What does that cost in productivity, reputation,etcompliance? We use “what if” scenarios, dashboards,etregular updates on metrics like backup healthetrestore times. When leaders see the financialetmission impact, the case for resilience is clear.

 

Q: Looking ahead, how does Commvault fit into UIC’s long-term strategy?

Dean: UIC is hybrid — on-campus, cloud,etSaaS. Commvault covers all of it, from VMsetdatabases to M365eteven emerging AI workloads. With 95%+ deduplicationettiered storage, we keep costs under control. And with anomaly detection, automation,etcleanroom testing, we’re preparing for a future where downtime is measured in hours, not days.

Read more about the University of Illinois of Chicago’s data protection journey here.

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

The psychologist Abraham Maslow famously said that if the only tool you have is a hammer, you tend to see every problem as a nail. And everywhere you look these days, companies are wielding AI like a hammer, hoping it can solve all their pressing business problems: “How can we use AI? How can we sell AI? How can we make money on AI?”

But here’s the thing – if you’re starting with those questions, you’re starting with a broken assumption. The right question isn’t “How do we use/sell/make a fortune with AI?” The right question is “What problems are we trying to solve?”

Quel problème résolvez-vous ?

Technology should make us more capable of doing uniquely human work, not replace our capacity to think, create, and connect with each other. The approach of starting with the tool instead of the problem is why we’re seeing many AI implementations stall. Companies are throwing technology at problems they haven’t properly defined or understood.
The approach I recommend to any leader considering AI: Start by listing your actual problems. Not theoretical problems, not problems you think you should have, but the real pain points keeping your teams from working fast. Then ask: What tools do I have that can help solve these problems? AI might be one of those tools. It makes sense to explore AI solutions for tedious, repeatable, manual tasks. You likely can identify those opportunities in your organization easily.
But let’s say your employee engagement is suffering, and people have expressed needing better support during difficult times. You want human connection and emotional intelligence here, not algorithmic responses. Starting with the problem helps reveal the appropriate solution.

Devrions-nous éliminer l’élément humain ?

Today, AI excels at automating repetitive tasks – the digital equivalent of assembly line work. If your backup administrators are turning the same widgets over and over, or your data entry teams are focused on purely laborious spreadsheet work, AI absolutely can help. But I believe relationship building, creative problem-solving, and complex decision-making require human judgment, intuition, and contextual understanding that no algorithm today can yet replicate.
At Commvault, we’re committed to the développement et d’un déploiement éthiques de l’IA. We’ve employed it for tasks like turning complex regulatory documents into succinct summaries or helping create targeted versions of content. Saving this time for employees to focus on more value-added activities. None of this work happens without careful human oversight.
The companies I see succeeding understand this distinction. They use AI to eliminate tedious tasks so workers can focus on what humans do best: nuanced decision-making, building trust, navigating complex stakeholder relationships, and thinking through problems that don’t have clear precedents.

Un cadre pour l’adoption intelligente de l’IA

Avant de mettre en œuvre une solution d’IA, les équipes de direction doivent se poser les questions suivantes :

  1. What specific problem are we solving? Be concrete. “We want to be more efficient” isn’t specific enough.Try: “We want to automate X.”
  2. Why is this problem worth solving? What’s the real business impact?
  3. Where do we need human judgment to remain in the loop? Identify the decision points, beyond just high-risk scenarios, that demand wisdom, not just intelligence.
  4. How will we measure success? Not just adoption rates, but actual problem resolution.
  5. Revisit the conversation. Successful AI adoption is not a point-in-time measurement.

Pour en savoir plus, consultezPrincipes directeurs pour une IA responsable.

La voie à suivre

Prenez le temps de mettre en place des procédures relatives au traitement des données, à la protection de la vie privée et à l’autorité décisionnelle.Qui contrôle les informations qui alimentent les systèmes d’IA? What data absolutely cannot be uploaded to external AI platforms? How do you prevent customer data from being used to train models?

When you put information into an AI system, you may be sharing it not only with that vendor, but also with its cloud providers, sub-processors, and others in its data supply chain. A secret known by more than three people isn’t a secret anymore – so be careful before you hand yours to dozens of entities.
Learn more about Commvault’s approach at Principes pour une intelligence artificielle responsable.
Danielle Sheer is Chief Trust Officer at Commvault.

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

We are in the most consequential moment of change in our industry, with the widespread adoption of AI reshaping how enterprises operate, how data flows, and how decisions are made.This introduces new challenges and vulnerabilities for you to manage. Like the explosive growth of data; the evolving governance requirements for human and non-human identities; and new threats to AI-oriented identities, supply chains, and models.To make matters worse, the pressure is on you and your teams to enable your business to embrace AI with data that’s distributed and fragmented across clouds, applications, and endpoints. All of which introduces business risk while increasing the fragility of your AI systems.In anticipation of this evolution, Commvault has been broadening its industry-leading resilience focus to help you to secure data at source; to control identity access; and predictably and cleanly recover following an inevitable cyberattack or disruption.We call it ResOps, or resilience operations. It’s not a product – it’s a new operational approach that enables you to actively manage resilience across increasingly complex emerging AI environments.As you know, Commvault always has been obsessed with solving our customers’ most significant resilience challenges with elegant and innovative solutions. And today, we are taking it even further with the introduction of Commvault Cloud Unity – our next-gen platform to enable ResOps.The platform was built from the ground up to help unify previously disparate data security, identity, and recovery processes across today’s workloads and tomorrow’s emerging AI stacks. It no longer matters where your data lives – if it’s on-prem, cloud-bound, cloud-borne, or an emerging AI workload.In fact, Commvault has the broadest workload support. Across the multi-cloud alone, we cover more than 160 regions and over 200 public cloud services. And we simply manage it all through a single policy engine and a unified pane of glass.None of this would have been possible without our team’s foresight, engineering prowess, and commitment to continuously innovating to solve our customers’ hardest challenges.Want to learn more about ResOps and Commvault Cloud Unity? Cliquez ici pour regarder Commvault’s SHIFT event on demand, and read our whitepaper ResOps : l’avenir de la résilience des entreprises à l’ère de l’IA.


Sanjay Mirchandani is President & Chief Executive Officer of Commvault.

More related posts


Thumbnail_Blog-SHIFT-Sanjay-2025-Linkedin

Re-envisioning Resilience for the Age of AI

Read more about Re-envisioning Resilience for the Age of AI