Skip to content

As we continue our Commvault Cares Month » celebration, we are raising awareness on causes close to our hearts.

This week I had the honor of hosting a Courageous Conversation regarding domestic violence awareness. Our Courageous Conversation platform is our way to have the tough conversation about things that matter – and this one sure did not fail!

During our Courageous Conversation, I was joined by special guests Anna Diaz-White, Caitlin Tamayo, and Randi Zamkotowicz from 180 Turning Lives Around», une organisation locale à but non lucratif de la région du New Jersey qui aide les victimes et les familles touchées par la violence conjugale et les agressions sexuelles à trouver le courage et la force de changer le cours de leur vie. Nous avons également accueilli Bill Appleton, de notre Programme d’aide aux employés (PAE), qui nous a présenté plus en détail les ressources et le soutien dont nous disposons en tant que collaborateurs de Vault. Disponible 24 heures sur 24, 7 jours sur 7, 365 jours par an, notre PAE met les participants en relation avec des conseillers spécialisés dans divers domaines, dont beaucoup concernent la santé mentale.

We broadcasted our Courageous Conversation on domestic violence live from our headquarters so all our Vaulters could join the discussion. During the event, we focused on three ways to drive awareness of domestic violence – how to Recognize, Respond, and Refer – whether it’s for ourselves, our co-workers, friends, or family:

  1. Recognize signs of domestic violence and better understand how common it is. The reality is that anyone can be a victim of domestic violence, regardless of race, age, ethnicity, sexual orientation, or economic status. If you are questioning how you’re treated by your partner, I encourage you to review this checklist from the National Coalition Against Domestic Violence. And when it comes to recognizing signs of domestic violence abuse with a colleague, friend, or family member, it’s important to notice changes in behavior and dress and check in if you think someone may be in an unsafe situation.  
  2. Respond by creating a safety plan to help lower the risk of being hurt by a partner. This is a set of actions to be referenced when experiencing abuse, preparing to leave, or after a victim leaves. Having a safety plan is especially important during moments of crisis when stress makes it very hard to think clearly. An example of one of these actions is to keep a “to-go bag” ready and waiting. This way, in case of an emergency situation, someone who is being abused is able to leave immediately with all the essentials.
  3. Refer to local and/or company resources for safety planning and support. Like many local organizations across the U.S. and throughout the world, 180 Turning Lives Around has hotlines, a safe house, and counselors available to help domestic violence victims. At Commvault, our HR team and our EAP is here to help all our Vaulters through any life challenges.

Et bien que le mois d’octobre soit consacré à la sensibilisation à la violence conjugale aux États-Unis, nous continuons à aborder ce sujet d’une importance capitale tout au long de l’année, en célébrant les journées de sensibilisation à la violence conjugale organisées partout dans le monde.

We believe you need to have the conversation, to change the conversation. And any conversation, whether it’s big or small, can make a difference. I’m so proud of our Vaulter community for continuing to have open discussions as we support our culture of respect, care, and belonging.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

These attacks can be used to block access to—or outright steal—essential business data, which can often include both the backup and restore data contained in places like an Amazon Cloud Backup (AWS Backup). The perpetrators will then encrypt the data and withhold it from the business until they pay a ransom, or threaten to delete it altogether if the company refuses to meet their demands.

Les attaques par ransomware peuvent semer le chaos au sein d’une organisation en raison des perturbations de service, de la perte de données essentielles aux fonctions opérationnelles clés, de la divulgation d’informations confidentielles sur les clients et de la perte de crédibilité auprès du public. Et le problème ne fait que s’aggraver.

According to the U.S. Financial Crimes Enforcement Network (FinCEN), the number of ransomware attacks in 2021 will vastly exceed the number of attacks in 2020. These attacks are growing in terms of cost as well—the average cost of reported ransomware transactions per month in 2021 was $102.3 million.

You may be wondering where des sauvegardes dans le cloud et des instantanés fit into this. After all, can’t you simply restore the stolen data from a backup or snapshot in the event of an attack? Ideally, yes. But ransomware attackers also target an organization’s data backups, which is why it’s crucial to secure those backups to avoid paying outrageous ransoms while ensuring business continuity and a fast recovery.

Vulnérabilités d’Amazon Cloud Backup

​​Although la sauvegarde dans le cloud snapshots are great for operational recoveries, they do not provide complete protection from threats like ransomware. When used directly out of the box, AWS backup vulnerabilities include:

  • No air-gap protection – AWS snapshots are by default created in the same account as the primary data sources. In this scenario, if the primary account is compromised, so are the snapshots. And if the snapshots are compromised, there is no way to recover data deleted or encrypted by outside parties.
  • Backups are not automatically immutable – AWS on its own does not make snapshots immutable, and mutable backups can be altered—or even, in some cases, accidentally deleted.
  • Slow recovery – AWS’s lack of flexible restores impacts recovery speed and can result in disruptions to business continuity in the event of an attack that results in a need for data restore.
  • Possible script errors – Complex, manually-written scripts are required to replicate snapshots across all accounts within AWS. This is obviously time-consuming and prone to human error, which can leave the snapshots exposed during an attack.

Comment protéger les sauvegardes AWS contre les ransomwares

The potential inherent vulnerabilities of sauvegardes AWS can leave your data copies at risk to bad actors. And while AWS does offer some native tools and solutions for securing backups, they can be cumbersome to use while still not providing full protection.

Voici quelques mesures essentielles à prendre pour protéger vos données et vos sauvegardes précieuses contre les ransomwares et autres attaques :

  • Air-gapping – Backups should be air-gapped and stored outside of the customer’s primary account and region. In the event of an attack, this prevents hackers and bad actors from corrupting and deleting the backup copies as well as the working data.
  • Immutable backups – Backup copies of data should be made immutable (unable to be altered or deleted), which preserves the data in a format that prevents it from being altered in any way.
  • Encryption for data at rest and data in transit – Both at rest and in transit, data should be encrypted, ideally with the user’s own encryption keys, and protected at a platform level with top security features in compliance with certifications such as ISO 27001, SOC II Type 1, SOC II Type 2, and PCI DSS.
  • Periodically test your data recovery abilities – In the event of an intrusion or disruption to your data and workloads, it’s essential to know you can recover quickly and ensure business continuity. Organizations should routinely test their ability to recover data from their backups.

(Is your data fully protected from ransomware? Click here to view our comprehensive ransomware checklist.)

Protégez vos sauvegardes AWS contre les ransomwares en quelques minutes seulement grâce à Clumio

Clumio’s innovative, industry-leading platform was designed in the cloud to protect the cloud.

With Clumio, your AWS backups receive instant protection via air-gapping, which places your valuable backup data “off site” and outside of production environments and other accounts.

Data is also encrypted with your encryption key of choice before it leaves any of your cloud accounts. Built-in integrity checking, full immutability for your backup files, and testing data recovery are all only a few clicks away within the intuitive interface.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Importance of Compliance & Data Security

Non seulement les entreprises doivent protéger leurs propres informations sensibles, mais elles doivent également préserver les données personnelles de leurs clients. Le non-respect des réglementations en vigueur peut entraîner des préjudices financiers et nuire à leur réputation, ainsi que des conséquences juridiques potentielles.

Prenons par exemple les récentes fuites de données qui ont touché de nombreuses entreprises de premier plan. Ces incidents ont non seulement entraîné des amendes coûteuses, mais ont également ébranlé la confiance des clients et porté atteinte à la réputation de la marque. En effet, selon une récente enquête menée par Edelman, une agence de communication internationale, 81 % des consommateurs cesseraient d’acheter auprès d’une entreprise s’il s’avérait qu’elle ne gère pas correctement ses données.

Compliance with regulations can help reduce security and privacy risks, align cybersecurity requirements with business processes, maintain effective cybersecurity programs, build customer trust, and improve company reputation. As a result, companies must prioritize both compliance and data security in order to remain competitive in today’s market.

To illustrate the importance of compliance and data security further let’s consider the healthcare industry. Medical providers need to follow various laws and regulations for patient privacy and protection of confidential information such as HIPAA (Health Insurance Portability and Accountability Act), which holds organizations accountable for not protecting medical records correctly. Non-compliance with these laws could lead to customers losing trust or even being sued for neglecting confidentiality obligations at worst case scenarios.

De plus, la mise en place de mesures de conformité adéquates garantit la confidentialité des informations sensibles de l’entreprise auprès des parties prenantes qui en ont besoin au quotidien, tout en empêchant l’accès à ces données par des personnes non autorisées. Cela renforce le sentiment de sécurité chez les employés chargés de traiter des informations confidentielles, ce qui permet de réduire les cas de fuites de données susceptibles d’entraîner de graves préjudices financiers.

However, some people might argue that the cost associated with maintaining such compliance standards might outweigh some of the benefits derived from it. This quite untrue as the benefits of adherence to compliance regulations to data protection surpass the cost in the long-term savings and protection it provides.

  • Selon une étude réalisée en 2020 par Statista, environ 45 % des entreprises à travers le monde ont augmenté leurs dépenses consacrées à la protection des données et à la mise en conformité.
  • Un rapport de recherche publié en 2021 par le Ponemon Institute a révélé que le coût moyen d’une fuite de données aux États-Unis s’élevait à 8,64 millions de dollars, soulignant ainsi l’importance de disposer de solutions de sauvegarde fiables pour garantir la conformité réglementaire.
  • Dans une enquête menée par Spiceworks en 2019, environ 42 % des entreprises ont déclaré utiliser une combinaison d’environnements de cloud public, de cloud privé et de cloud hybride pour la sauvegarde de leurs données, afin d’assurer une meilleure conformité et une meilleure redondance.

Le rôle des sauvegardes dans la conformité réglementaire

When it comes to data security, backups play a crucial role in ensuring regulatory compliance and business continuity. Regulatory compliance can be extremely complex, involving strict guidelines that must be followed to avoid financial penalties, legal consequences, and damage to reputation. Having a reliable backup plan can help companies maintain compliance with regulations such as GDPR (General Data Protection Regulation), which establishes rules for protecting European Union residents’ personal data; PCI (Payment Card Industry) standards for processing and storing payment card information securely; and HIPAA (Health Insurance Portability and Accountability Act) standards for protecting health information.

In addition to satisfying compliance requirements, backups also help companies ensure business continuity. Natural disasters, power outages, cyber attacks, and other unexpected events can cause loss or corruption of data. Without an effective backup plan in place, businesses risk losing important data along with customer trust.

To understand the importance of backups further, let’s consider a company that experiences a ransomware attack. Ransomware is a type of malicious software that threatens to publish sensitive data if payment isn’t made.

If the company doesn’t have a robust backup plan in place, they may have no options but to pay the ransom or lose significant amounts of valuable data. However, if they’ve been backing up their files regularly and properly following best practice recovery protocols when implementing their backup process which involves full and partial backups implemented frequently as possible amongst other features available with top-notch services like Rewind Backup Tool according to SaaS compliance solution then they would be able to recover critical files without paying criminals for release of hijacked files or draining their resources.

Ainsi, le fait de disposer d’une infrastructure robuste, conforme aux exigences en matière de sauvegarde, permet aux entreprises d’atténuer les risques qui, sans cela, pourraient entraîner une perte de données, une interruption de service pour les clients, le paiement d’amendes coûteuses, des poursuites judiciaires de la part des parties lésées, sans compter la perte de confiance entre l’entreprise et ses clients.

Some people might argue that backups are not necessary if the data is already stored securely. However, accidents happen, and when they occur some vendors would not be able to provide data recovery services without backing up their client’s system. It is better to be safe than sorry when dealing with sensitive data which could result in a breach leading to legal consequences.

  • Backups are critical for businesses to maintain regulatory compliance and ensure business continuity. Compliance regulations can be complex, and strict guidelines must be followed to avoid financial penalties, legal consequences, and reputational damage. Reliable backups also help companies protect against the loss or corruption of data due to natural disasters, cyber attacks, or other unexpected events. Investing in a robust backup plan, including full and partial backups implemented frequently as possible amongst other features available with top-notch services like Rewind Backup Tool according to SaaS compliance solution, can help mitigate risks otherwise resulting in data loss, customer downtime, payment of expensive fines, lawsuits from affected parties, and lost trust between company and clients. Ultimately, accidents happen, so it is better to be safe than sorry when dealing with sensitive data that could result in a breach leading to legal consequences.

Conséquences sur la continuité des activités

The impact of compliance and data security on business continuity cannot be overstated. In fact, without a robust backup plan in place, businesses are at a significant risk of irreversible damage to their operations and reputation. With the number of cyber-attacks increasing every year, it’s crucial that companies take proactive measures to protect their data and ensure their systems remain operational in the event of an attack.

For instance, imagine a scenario where a company was hit by a ransomware attack that encrypted all their data and backups. Without a proper backup plan in place, they would lose access to all their critical files and data necessary for business continuity. As a result, they would be forced to restart from scratch, resulting in prolonged downtime, lost revenues from halted operations, and reputational damage.

A backup plan provides the assurance that, should such an attack occur, the company can quickly restore its systems’ functionality without significant disruptions to its operations. This is especially important for companies with compliance obligations or those that deal with sensitive or confidential information.

Backups also help businesses maintain customer trust and build their reputation. Companies that continuously experience service disruptions or data breaches are likely to lose customers who will take their business elsewhere. By having a reliable backup plan in place, businesses can demonstrate their commitment to protecting their customers’ sensitive information while maintaining the continuity of their services.

Certaines entreprises pourraient faire valoir qu’il n’est pas nécessaire de mettre en place un plan de sauvegarde solide, car sa mise en œuvre nécessite trop de temps et de ressources. Elles pourraient y voir un coût supplémentaire sans retour sur investissement immédiat significatif. Cependant, les risques liés à l’absence d’un tel plan l’emportent largement sur les coûts perçus. Le coût de la reprise après une cyberattaque, en l’absence de sauvegardes adéquates, dépasse largement l’investissement requis pour mettre en œuvre un plan de sauvegarde efficace.

Principales réglementations et certifications

Plusieurs réglementations régissent la manière dont les organisations traitent les données sensibles ; il est donc essentiel de comprendre les conséquences d’un manquement à ces réglementations et de savoir quelles certifications sont nécessaires pour atténuer ces risques.

Regulations such as GDPR, PCI, and HIPAA mandate that businesses protect their customers’ sensitive information. Specifically, GDPR applies to European Union (EU) citizens’ personal data, while PCI compliances deal with payment card data handling. Similarly, HIPAA governs the handling of protected health information (PHI). Non-compliance with these regulations can result in significant legal and financial repercussions.

Lorsque les entreprises se conforment à ces réglementations, elles alignent leurs exigences en matière de cybersécurité sur leurs processus métier, mettent en place des programmes de cybersécurité efficaces qui garantissent la sécurité des données clients, réduisent les risques liés à la sécurité et à la confidentialité, et améliorent leur réputation.

Obtaining certifications like ISO 27001 and SOC 2 serve as proof that an organization has implemented thorough audits of its data security compliance. ISO 27001 is an information security management certification that demands a company’s adherence to strict standards of data protection. On the other hand, SOC 2 requires adherence to specific criteria for system security, availability, confidentiality, processing integrity, and privacy. These certifications cater to different aspects of compliance but work together to ensure effective data security practices.

RGPD, PCI et HIPAA

En matière de conformité et de sécurité des données, il existe un certain nombre de réglementations et de certifications que les entreprises doivent connaître afin de s’assurer que leur plan de sauvegarde est à jour et efficace. Parmi celles-ci, trois normes importantes sont le Règlement général sur la protection des données (RGPD), la norme de sécurité des données de l’industrie des cartes de paiement (PCI DSS) et la loi sur la portabilité et la responsabilité en matière d’assurance maladie (HIPAA).

The GDPR, which came into effect in May 2018, is designed to protect personal data belonging to European Union citizens. Any organization that collects or processes EU citizens’ data must comply with these stringent regulations. Failure to do so may result in hefty fines, loss of reputation, or legal action. To comply with the GDPR, businesses need to have a robust data management system including proper backups containing personal data.

La norme PCI DSS s’applique spécifiquement aux entreprises qui traitent des informations relatives aux cartes de paiement. Elle régit la manière dont les entreprises doivent traiter les informations sensibles des clients, telles que les numéros de carte bancaire, afin de prévenir la fraude et le piratage informatique. La norme PCI DSS impose des audits annuels réalisés par un évaluateur de sécurité qualifié (QSA) agréé, ainsi que des revues régulières des politiques de sauvegarde.

HIPAA is another critical regulation for healthcare organizations. It requires strict methods for securing medical records both physically and electronically. The law also enables patients’ access to their own medical records while requiring healthcare providers provide them with proper privacy practices.

Complying with these regulations can be compared to buckling your seatbelt before driving on the road – safety first! Regulations give your business the tools it needs to protect sensitive information and avoid data breaches while keeping your customers’ trust.

ISO 27001 et SOC 2

Outre les exigences réglementaires, il existe des certifications qui attestent d’un engagement en faveur des meilleures pratiques en matière de gestion de la cybersécurité. L’Organisation internationale de normalisation (ISO) propose à la fois des lignes directrices et des certifications relatives à la sécurité de l’information. La norme ISO 27001 porte spécifiquement sur la mise en place d’un système de gestion de la sécurité de l’information (SGSI) au sein de toute organisation.

Implementing ISO 27001 involves assessing risks, devising policies and procedures for securing data at all times, including backup data. This includes specific requirements for data redundancy, disaster recovery planning as well as testing of the policies in places such as offsite backups in particular.

Additionally, the SOC 2 examination report is an independent third-party evaluation that gives assurance about how well you perform your controls. SOC 2 reports concentrate on a company’s non-financial reporting controls as they relate to key compliance and security issues.

Obtaining these sorts of certifications can be compared to receiving your driving license- it takes dedication to learn the rules of the road before being able to safely drive where you need to go. With these certifications, businesses demonstrate their commitment to best practices in cybersecurity management that protect their customers’ sensitive information.

Élaborer un plan de sauvegarde fiable

Lorsqu’il s’agit d’élaborer un plan de sauvegarde solide pour garantir la conformité et la sécurité des données, les entreprises doivent prendre en compte de nombreux facteurs. Un plan de sauvegarde complet doit non seulement assurer la protection des données sensibles, mais aussi permettre de restaurer les informations perdues ou corrompues en cas d’attaque ou de perte de données. Dans cette section, nous aborderons certains des éléments clés à prendre en considération pour élaborer un plan de sauvegarde solide.

First and foremost, your organization needs to decide on the type of backups it will use. This may involve implementing both full and partial backups as often as possible, depending on how critical your data is. Full backups are designed to capture all data on a system while partial backups capture only smaller subsets of data. The frequency of the backups will vary depending on factors such as how rapidly data changes within your organization and the amount of data you’re dealing with.

Une fois que vous avez déterminé le type et la fréquence des sauvegardes que votre entreprise utilisera, vous devez décider où celles-ci seront stockées. Il existe de nombreuses options, notamment les solutions de sauvegarde dans le cloud et les périphériques de stockage physiques tels que les disques durs et les bandes magnétiques. Les sauvegardes stockées à plusieurs endroits sont généralement plus sûres que celles stockées à un seul endroit.

Another important consideration when creating a backup plan is determining how long backups should be retained. While regulatory requirements drive retention policies in some cases, organizations might choose to store their backups even longer than regulations require if business continuity could be threatened without it. In short, retaining more copies does come at a cost – requiring investment in additional storage space and management efforts – but having those extra copies provides an additional layer of risk mitigation.

It’s important to remember that creating a robust backup plan is like creating a safety net for your organization’s sensitive data. If something goes wrong, having a backup plan in place will ensure that your organization can quickly recover and restore lost or corrupt data.

Let’s take a look at some of the key considerations when choosing the right backup tools for your organization.

Choisir les bons outils de sauvegarde

When selecting the correct backup tools, it is essential to find a solution that aligns with your organization’s specific needs. There are several factors to consider before making a final decision, including how often backups need to happen, how they’re being created and operated—whether through an automated mechanism or manual solutions—and what type of encryption algorithms you’d prefer for protecting sensitive information.

La scalabilité et la fiabilité constituent deux facteurs essentiels à prendre en compte lors du choix d’outils de sauvegarde. Les entreprises qui prévoient une croissance future doivent opter pour des solutions capables de s’adapter à l’évolution de leurs besoins. Il convient de privilégier les solutions automatisées telles que Clumio, car elles offrent davantage de flexibilité pour gérer les augmentations imprévues du volume de données sans surcharger le personnel informatique. Grâce à des outils évolutifs, les utilisateurs bénéficient d’une plateforme stable tout en minimisant les interruptions et en garantissant la continuité des activités.

De plus, les outils de sauvegarde doivent être conçus dans une optique de sécurité. Ils doivent être mis à jour régulièrement afin de garantir que toute vulnérabilité connue soit corrigée immédiatement, tout en intégrant des méthodes de chiffrement robustes pour protéger les données sensibles sur l’ensemble des canaux de communication tout au long du cycle de vie de la sauvegarde.

Parmi les autres critères essentiels à prendre en compte lors du choix d’un outil de sauvegarde figurent le rapport qualité-prix et la facilité de gestion. Ces aspects sont particulièrement cruciaux pour les entreprises disposant de budgets serrés et dont les ressources sont parfois limitées. Avant de prendre une décision concernant un outil de sauvegarde, vérifiez s’il offre un bon rapport qualité-prix tout en garantissant une maintenance, un déploiement et une administration faciles, en plus de fournir les fonctions de sécurité adéquates requises par votre entreprise.

Choosing the right backup tool is like finding the perfect pair of shoes. Just as finding a good pair of shoes requires careful evaluation of comfort, style, and price over time – finding an ideal solution requires taking into account key factors, including scalability, security, cost-effectivenesss and management needs, while selecting the right solution for your organization.

Now that we’ve explored some of the essential aspects to consider when creating a backup plan, let’s move on to monitoring and reporting compliance.

Mise en place de sauvegardes complètes et partielles

When it comes to implementing backups for compliance and data security, one size does not fit all. Your organization’s specific needs will determine the type of backup strategy that works best for you. Full backups are ideal if you need complete copies of all your data on a regular basis. However, partial backups may also be necessary to ensure the protection of your most critical data.

For example, let’s say you run an e-commerce website that generates a significant amount of daily sales. In this scenario, you would likely want to implement both full and partial backups. A full backup could be performed once a week or month, while partial backups would occur several times a day, ensuring that critical sales data is always protected.

Les sauvegardes partielles s’avèrent également indispensables dans une entreprise de recherche en biotechnologie menant des expériences complexes. Dans ce contexte, les données en temps réel jouent un rôle crucial dans les expériences ; c’est pourquoi des sauvegardes toutes les heures constituent la meilleure solution pour garantir la restauration de toute information perdue en cas d’incident imprévu.

De plus, la mise en œuvre de plusieurs types de stratégies de sauvegarde peut offrir des niveaux supplémentaires de redondance, ce qui permet de garantir la protection des données en cas de défaillance d’une sauvegarde. Par exemple, le recours à la fois à des sauvegardes incrémentielles et différentielles signifie que seuls les fichiers modifiés depuis la dernière sauvegarde sont enregistrés. Cette approche réduit l’espace de stockage nécessaire et minimise le temps requis pour chaque sauvegarde.

En revanche, les sauvegardes complètes prennent plus de temps, mais permettent une restauration plus rapide, car elles incluent l’ensemble des fichiers système en une seule fois. Bien que le fait de passer d’un type à l’autre puisse accroître la complexité, le recours à ces deux méthodes offre une protection contre les pertes importantes.

L’un des éléments clés lors de la mise en œuvre d’un plan de sauvegarde consiste à envisager des options de stockage hors site, telles que les services dans le cloud ou des sites distants sécurisés. Cette étape permet de garantir la disponibilité des fichiers de sauvegarde en cas d’événement catastrophique survenant sur le site principal.

Suivi et rapports en matière de conformité

Il est essentiel de disposer d’informations de suivi sur chaque stratégie de sauvegarde pour respecter les normes de conformité. Une surveillance régulière des processus et des résultats de sauvegarde permet d’identifier les sauvegardes qui ont échoué et de réduire le risque de perte de données.

To ensure regulatory adherence, it’s crucial to define metrics that measure backup performance over time. From measuring the total storage space used for the backup process to tracking how quickly a full system restore takes, having statistics helps your organization stay on track with its goals while ensuring compliance.

De plus, grâce à des outils logiciels d’automatisation, les responsables peuvent recevoir des rapports quotidiens sur l’état des sauvegardes sans aucune intervention manuelle. Ces outils fournissent des informations en temps réel sur les sauvegardes, notamment pour savoir s’il y a eu un accès non autorisé ou une modification des fichiers. Aujourd’hui, les journaux constituent un moyen simple de consulter ces informations.

Backup performance evaluations are essential for businesses to gauge their adherence to established compliance regulations such as GDPR, HIPAA, and PCI DSS. It is necessary to create policies that specify the types of tests necessary and their frequency—these policies should be reviewed regularly during audits.

While some backup approaches include using external tapes to store data redundantly, these methods aren’t always suitable for larger companies with higher processing demands or those with several locations. This approach can have long restoration times that may damage the continuity of any business.

Thus, implementing a reliable, efficient backup array works wonders here because it reduces operational downtime caused by data corruption or server crash incidents. Therefore, having scheduled “backup retention time” where IT professionals research probable risks acting on timely apparatus replacement is more practical than recurring backups.

It’s just like building a structure strong enough from natural disasters instead of only counting buckets when it floods up to your knees!

Indicateurs de performance des sauvegardes

One of the most critical aspects of backup planning is monitoring and reporting. In today’s compliance-driven world, organizations must be able to prove that they are adhering to regulations and protecting user data. Backup performance metrics play a vital role in ensuring regulatory adherence and avoiding data breaches.

Par exemple, les indicateurs de performance des sauvegardes peuvent fournir des informations sur le temps nécessaire à la création des sauvegardes, leur fréquence ou le nombre de sauvegardes effectuées par jour ou par semaine. En cas de problèmes liés au processus de sauvegarde, ces indicateurs peuvent être utilisés pour les identifier et y remédier avant qu’ils ne deviennent un véritable problème.

Par ailleurs, les indicateurs de performance des sauvegardes peuvent également servir de preuve du respect des exigences réglementaires. Par exemple, des réglementations telles que la loi HIPAA imposent aux organisations de conserver une piste d’audit indiquant qui a accédé aux dossiers des patients et à quel moment. De même, le RGPD exige des organisations qu’elles fournissent une piste d’audit en cas de violation de données. Les indicateurs de performance des sauvegardes peuvent aider les organisations à satisfaire à ces exigences en apportant la preuve que des sauvegardes régulières et des tests de Recovery sont effectués.

However, it’s crucial to note that backup performance metrics alone won’t ensure compliance. Compliance involves implementing a wide range of security procedures, including disaster recovery planning, risk assessments, monitoring security controls, and integrating best practice security procedures into day-to-day workflows. While backup performance metrics are an essential part of compliance monitoring and reporting, they should be used in conjunction with other security measures.

Cela étant dit, comment les organisations peuvent-elles s’assurer que leur plan de secours est conforme ?

Garantir le respect de la réglementation

Pour garantir le respect de la réglementation, les organisations doivent adopter une approche globale de leur plan de sauvegarde. Voici quelques étapes clés à prendre en compte :

Tout d’abord, choisissez des outils de sauvegarde conformes aux normes du secteur. Des outils de sauvegarde de données de pointe, tels que Clumio, peuvent simplifier le processus complexe de mise en conformité et de sécurité des données en automatisant les sauvegardes quotidiennes et en garantissant la possibilité de restaurer les données, tout en respectant les normes de sécurité les plus strictes.

Think of it this way: choosing the right backup tools is like choosing the right lock for your front door. Just as you want a lock that’s tough to break, you want backup tools that are hard to hack. The right tools can help you ensure that your data is safely stored and stored in compliance with industry regulations.

Ensuite, effectuez des sauvegardes complètes et partielles aussi souvent que possible. Les sauvegardes complètes doivent être réalisées régulièrement (par exemple, chaque semaine ou chaque mois) afin de garantir que toutes les données soient sauvegardées. Les sauvegardes partielles doivent être effectuées plus fréquemment (par exemple, chaque jour) afin de garantir que les modifications apportées aux données soient prises en compte.

Par exemple, si vous disposez d’un site de commerce en ligne, vous pouvez effectuer des sauvegardes complètes tous les mois, mais aussi des sauvegardes partielles chaque nuit afin de sauvegarder les nouvelles commandes.

Enfin, testez régulièrement vos sauvegardes afin de vous assurer qu’elles peuvent être restaurées en cas d’attaque ou de perte de données. Ces tests doivent inclure des tests de basculement (c’est-à-dire vérifier si votre système de sauvegarde peut prendre le relais en cas de défaillance de votre système principal) et des tests de retour en production (c’est-à-dire vérifier si votre système principal peut reprendre le contrôle une fois que le système de sauvegarde a été utilisé).

However, it’s important to keep in mind that implementing a compliant backup plan isn’t a one-time thing – it’s an ongoing process. As regulations change and new threats emerge, organizations must continue to evaluate and refine their backup plans to maintain regulatory compliance and protect user data.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

One of the most essential parts of a robust and ultimately effective business continuity plan is the disaster recovery plan. After all, a business may do all it can to protect itself from a disaster event—such as a ransomware attack, a cloud outage, or corrupted data—but it still needs a failsafe plan for how it will restore data and workloads in the event of any disruption that nevertheless occurs.

Qu’est-ce que la reprise après sinistre ?

Although “disaster recovery” is a term often used interchangeably with “business continuity,” it is actually a subset of business continuity management that mainly involves restoring crucial data and operations while minimizing any downtime caused by a disaster event.

Having a disaster recovery plan in place is essential for any enterprise. Without one, the aftermath of a disaster can spiral out of control and leave a business vulnerable to permanent data loss and disruption to operations that eventually affect everything from revenue to customers.

Sauvegarde dans le cloud et optimisation de la reprise après sinistre

An enterprise’s disaster recovery plan should include a way to identify all mission-critical data that should be prioritized during a restore, along with a way to quickly recover and restore lost data from backups — all while still keeping essential operations afloat during recovery. This is in addition to identifying the suitable number of backups needed to meet the recovery point objective (RPO) while avoiding excessive costs from unneeded backups creation and storage.

Tout commence par l’utilisation d’un service de sauvegarde dans le cloud pour répliquer et stocker en continu les données de l’entreprise. Voici trois fonctionnalités de reprise après sinistre à rechercher dans une solution de sauvegarde dans le cloud, qui apporteront des avantages considérables lors de la reprise après sinistre :

Sauvegarde incrémentielle permanente

La sauvegarde incrémentielle permanente est un type de sauvegarde incrémentielle qui utilise une méthode appelée « récupération des blocs modifiés ». Cela simplifie le processus de restauration, évitant ainsi aux équipes informatiques d’avoir à passer en revue les sauvegardes pour déterminer quelles copies doivent être restaurées afin de récupérer les données les plus récentes.

La sauvegarde incrémentielle permanente accélère le processus de restauration en ne restaurant que les dernières versions des blocs appartenant à une sauvegarde restaurée, ce qui permet d’obtenir des restaurations nettement plus rapides.

Récupération de granulés

During disaster recovery, the actual speed of data restoration is at the core of an organization’s RTO. However, during recovery, some data is more important than other data — particularly the mission-critical data and processes that the organization needs to remain operational while full recovery is in progress. Restoring an entire instance can be time-consuming and may put business continuity at risk.

La fonctionnalité de restauration granulaire apporte la solution à ce problème flagrant, car elle permet aux équipes informatiques de lancer une restauration au niveau des fichiers et des enregistrements à partir d’une seule opération de sauvegarde, sans avoir à attendre la restauration complète de l’instance. Cela permet d’identifier et de hiérarchiser certaines données et charges de travail critiques afin de maintenir le bon fonctionnement des processus et opérations essentiels, tout en accélérant considérablement la restauration.

Flexible Recovery

Flexible recovery is another useful feature to integrate into your disaster recovery plan via your cloud backup solution. With flexible recovery, you can restore your data to any account or region that has not been affected by the disaster event, and quickly resume your activities.

Une solution de reprise après sinistre de pointe avec Clumio

Built in the cloud, Clumio supports optimized business continuity management and disaster recovery with capabilities such as granular recovery, incremental forever backup, flexible recovery, and more. Clumio’s industry-leading rapid restore capabilities provide enterprises of all sizes with lightning-quick data restores that can maintain and support business continuity in the face of a disaster event.

Outre des fonctionnalités optimisées de reprise après sinistre, Clumio propose également :

  • Sauvegardes instantanées des données AWS depuis n’importe quelle région, à l’échelle de toute votre entreprise
  • Protection contre les ransomwares et autres attaques malveillantes grâce à des sauvegardes en « air gap »
  • Conformité simplifiée des données aux politiques mondiales
  • Modèle de consommation flexible, basé sur le paiement à l’utilisation
  • Réductions de coûts grâce à une analyse approfondie des dépenses de l’entreprise liées au cloud

Clumio is the industry’s leading innovator for AWS cloud backup.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Cybersecurity Awareness Month is here and, as you can imagine, this topic is always part of our conversations here at Commvault and especially in my role as Chief Information Security Officer.  

Protecting our customers’ data is core to who we are as a company.    

We all know that data has never been more valuable, nor more vulnerable, than it is in today’s digital landscape. Organizations face an increasingly turbulent data environment with cyberattacks increasing year over year. That’s why it’s so important for us to be more proactive than ever – we’ve done this by deploying technologies like Metallic ThreatWise, next-generation cyber deception that immediately engages and surfaces threats the moment they happen, but we also do it by empowering our employees. We discuss data protection, recovery, and ransomware with our partners and customers every day, but it’s crucial that our employees understand that they are the first line of defense in mitigating Security Risks. 

As we look inside Commvault at how we’re talking about this with our Vaulters, creating a culture of continual education and conversation on cybersecurity topics is integral to our security strategy. We recently completed our annual Security Training, which helps us reinforce the security posture of our company and empowers our Vaulters to embrace their role as the first line of defense when it comes to cyber threats. It is our top priority to ensure our teams know how to identify, mitigate, and respond to security risks that could potentially jeopardize Commvault, our data, and impact our stakeholders. Commvault is proud to be a « Champions » du Mois de la sensibilisation à la cybersécurité 2022 and over the next few weeks we’ll be providing our Vaulters with new resources and learning opportunities on this very important topic.   

And outside the walls of Commvault, we certainly remain focused on cybersecurity. We’re continuing the conversation at Connections, our cloud data management experience. Join me as I moderate our session on Ransomware Retrospective: Supporting the Recovery, one of three Fending Off Ransomware solutions tracks that will be offered during our event. Join us to hear real customer recovery stories from our Commvault® Support & Services Team as they share the good, the bad, and the ugly. Learn why some recoveries went well and why others did not. Take advantage of this up close and personal interaction with the Commvault® Support & Services Team, which has helped organizations recover quickly and maintain a state of recovery readiness and steady response. The importance of data protection strategies and cybersecurity awareness will only continue to grow – make sure your business, and employees, are set up for success this month and beyond. 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Qu’est-ce qu’un modèle de plan de Recovery après sinistre ?

Disaster recovery is a subcomponent of a business continuity plan. It focuses on restoring core operations while minimizing or avoiding downtime caused by a disaster event. In today’s data-centric business environment, the IT portion of a disaster recovery plan is typically the heart of a modern business continuity plan. It’s intended to ensure core operations remain online when a disaster event — such as a ransomware attack, natural disaster, or prolonged power outage — threatens the interruption of business continuity.

De nombreuses organisations ont recours à un modèle de plan de reprise après sinistre afin de s’assurer qu’elles prennent en compte le moindre détail lors de l’élaboration de leur plan. Ce document aborde des aspects allant du maintien de l’alimentation électrique aux voies de communication de secours, en passant par la garantie du bon fonctionnement des systèmes informatiques.

Below, we’ll look at perhaps the most important part of a disaster recovery plan template for organizations that have migrated their data and workloads to the cloud:cloud backup.

Comment intégrer la sauvegarde dans le cloud à un modèle de plan de reprise après sinistre

The IT portion of a plan de reprise après sinistre is primarily focused on recovering and restoring the mission-critical data and workloads needed to ensure business continuity. For example, if your business has experienced a ransomware attack and lost access to its primary data, the plan de reprise après sinistre outlines the steps needed to restore that data so core operations can continue.

If your organization has migrated to the cloud, a cloud backup solution is the ideal method to facilitate a restore since it can leverage the scale and elasticity of the cloud. The cloud backup solution allows you to automatically back up data on a customized schedule and then store the data. Should data recovery be required, the solution can restore the data from the most recent backup.

It’s crucial to note that data can only be recovered and restored if there’s a valid backup copy to restore from, making the security of the backup data paramount. If your backup data copy is unsecured and exposed, you are risking your ability to recover the data. Plus, since business continuity is time-sensitive, the disaster recovery plan should be able to restore the most important data and workloads first so your most essential operations and processes can continue unhindered while a full restore completes.

Par conséquent, un modèle de plan de reprise après sinistre efficace pour une entreprise « cloud-native » devrait inclure :

  • Une solution de sauvegarde dans le cloud fiable
  • Un moyen de garantir la sécurité des sauvegardes
  • Une méthode permettant d’identifier et de hiérarchiser les données essentielles à la mission nécessaires pour garantir la continuité des activités

However, not all cloud backup solutions are capable of checking all these boxes. The cloud backup tool you choose will directly affect your organization’s disaster recovery abilities.

Bénéficiez d’une sauvegarde sécurisée dans le cloud et d’une reprise après sinistre rapide grâce à Clumio

Clumio’s secure cloud backup platform optimizes disaster recovery with features designed to streamline data restoration—enabling an organization to meet or exceed its recovery time objective (RTO) during a disaster event.

Clumio safeguards backup copies by storing them in an encrypted, air-gapped backup solutionoutside of the primary account — meaning if your primary data is accessed or compromised, the backup remains safe. When data restoration is needed, Clumio’s granular and flexible recovery capabilities can quickly identify and rapidly restore the specific mission-critical data and applications needed to maintain business continuity while a full recovery completes.

Cloud backup is the key to a successful disaster recovery plan template. Learn why Clumio is the industry’s leading innovator for cloud backup and rapid disaster recovery by programmant une démonstration today.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Our value – We Connect – is a guiding principle for my day-to-day here at Commvault.

Since I joined Commvault seven years ago, I’ve been very fortunate to work with a group of incredibly motivated and hardworking Vaulters.

I first joined Commvault as a Digital Project Manager on the Marketing team, where I assisted the digital marketing team with the planning and execution of multi-channel campaigns. When we incubated Metallic in 2019, I was recruited to join the team. It’s crazy to think that back then, the Metallic team was a small group of agile, scrappy Vaulters in a start-up culture creating and building our new software-as-a-service offering. And now, more than three years later, it’s grown to a $50 million ARR business for Commvault.

Now, as Director of Program Management for Metallic, I’m primarily responsible for managing the overall roadmap, timelines, and cross-functional coordination across the entire Metallic team. With a SaaS business, all team members—from our engineers to our marketers—need to be connected to create a flawless customer experience. My program management team and I drive communication and ensure that all teams have what they need to deliver innovative solutions, campaigns and enhanced customer experiences.

Une grande partie de mon travail consiste à mettre en relation différentes personnes et équipes, et j’ai le privilège de constater directement les avantages de notre collaboration pour obtenir des résultats de manière efficace. Tout récemment,Commvault a racheté TrapXet lancéMetallic® ThreatWise™, a newly-available data security service that provides customers with early threat detection. This is just one example of how we bring together smart people to solve tough problems for our customers—and we have fun doing it!

If you’re looking to learn more about what it’s like to work at Commvault, check out this recent blog from David to hear his perspective!  

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

With today’s announcement around Metallic ThreatWise Cyber Deception Service, Commvault is changing the game when it comes to addressing security threats including ransomware. But our innovations in enhancing data security don’t stop there. We’ve also recently released Commvault Platform Release 2022E, and with that release come additional enhancements to help our customers better protect their data. This new release introduces several new capabilities to simplify data management – in this blog, I’ll focus on the new data security additions in our new release.

Uneune stratégie « zéro perte is designed to help protect you from ransomware attacks and is anchored on the pillars of end-to-end data visibility, broadest workload protection, and faster business response, built on the foundation of Zero Trust principles. End-to-end data visibility ensures that you catch threats before they impact your data – in addition to Metallic ThreatWise for early detection through cyber deception, we have also expanded our file anomaly framework to detect malicious applications that may evade traditional detection methods by posing as safe file types.

Une analyse plus approfondie de l’activité suspecte des fichiers permet une meilleure détection et une réaction plus rapide face aux menaces potentielles pesant sur vos données

 

This feature drives faster business response with immediate alerting of suspicious activity, along with automatic, efficient data recovery using clean versions from unaffected backups. Not just that – we’ve also expanded our data governance capabilities to now profile object storage for Azure, AWS and GCP, eliminating another common area of data leakage.

Another enhancement we’ve added is Changed Block Tracking (CBT) support for Azure Disk encryption. CBT improves backup performance while lowering backup costs, by consuming less storage and bandwidth for incremental backups. Historically, however, the ability to perform encryption while using CBT was limited, forcing a tough customer choice between security or cost savings. Working closely with Microsoft, we are excited to now introduce CBT efficiencies with Azure Disk encryption for managed and unmanaged encrypted disks. No longer do you need to make a choice between security, performance and cost efficiencies!

Enfin, et ce n’est pas le moins important, je suis ravi de vous annoncer que nous avons désormais obtenu la certification Sec17a conforme à la norme WORM pour Commvault Grid. Cette certification vient s’ajouter à notre liste déjà bien fournie de certifications de sécurité, notamment FIPS 140-2, FedRAMP High In Process (en cours d’examen par le PMO) et bien d’autres encore, et vient compléter les capacités du système de fichiers immuable de Commvault Grid.

These are just some of the new Data Security capabilities available in Commvault Platform Release 2022E, a release that’s packed with new features and innovation, reflecting on our continued investment in Intelligent Data Services.

Pour plus d’informations sur cette version, consultez cettepage and stay tuned and we’ll be discussing more of the exciting new updates in Commvault Platform Release 2022E at our virtual event, Connections on Nov 2/3.

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

On September 22, Commvault will be presenting live from San Jose, as part of Cloud Field Day 15. 

For the uninitiated, Cloud Field Day is part of the popular “Field day” series, which also includes Tech Field Day and Security Field Day. 

Hosted by Stephen Foskett, delegates from cutting edge companies, including Commvault, share their latest product news and innovations live with a group of hand-picked influencers.  A lively debate usually results, which also takes place across Social Media.

This Cloud Field Day, we’ll be taking the delegates through the very latest in data security technology including a first deep look at Metallic ThreatWise, a newly available data security service which provides customers with much needed early threat detection.  Highlights from Commvault’s recently released Platform release 2022E will also be included to showcase the breadth of Commvault’s Intelligent Data Services.

We’ll be live streaming the session right here on this blog as well as across Commvault’s LinkedIn Channels.

See you on Thursday, 22nd September at 1:30pm PT. Join in the Social Media conversation by using #CFD15.  You don’t want to miss it.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Microsoft 365 is an essential component of today’s enterprise data environment. Still, many organizations fail to include it in their data protection plan. This is partly due to the misconception that cloud service providers are responsible for both administering the solution and protecting the data created and stored within it. However, this is not the case.

Your data, your responsibility

Microsoft provides a highly resilient platform and goes to great lengths to secure data residing within its application. However, like many cloud service providers, they follow what is known as the shared responsibility model, where they are responsible for maintaining the uptime, availability, and access to the solution, while the customer is responsible for protecting the data created and stored within that solution. And now, more than ever, your Microsoft 365 data must be protected and recoverable in the face of emerging threats.

It’s no secret that cyberattacks are on the rise, and SaaS applications are not immune. And there are other potential risks for the data beyond the risks of ransomware. Accidental deletion of data, network vulnerabilities, and internal breaches are all causes of data loss in SaaS applications.

Protection measures to prevent data loss go beyond understanding the shared responsibility model. They require purpose-built tools to help you safeguard your data from today’s threats.

You need dedicated data protection and recovery

While Microsoft offers native controls for data replication, today’s businesses need long-term retention, data separation, and tools for SLA compliance and recoverability. You need a dedicated third-party backup solution that offers the essential capabilities needed to protect and secure your data.

Here are just a few components where protection from third-party backup extends beyond native capabilities to provide advanced protection from today’s threats:

  • Isolation des Données
  • Conservation prolongée
  • Restauration Flexible
  • Respect des accords de niveau de service

Commvault enhances Microsoft 365 data protection

Que vous soyez déjà client de Commvault ou que vous envisagiez d’utiliser Commvault à l’avenir, nous proposons une solution de protection des données Microsoft 365 via Commvault Complete Data Protection et Metallic SaaS Backup. Vous pouvez ainsi choisir la solution la mieux adaptée aux besoins spécifiques de votre entreprise.

Are you looking for a SaaS-delivered solution with rapid deployments, unlimited storage and retention included, and no additional infrastructure required? Then Metallic for Microsoft 365 is the best fit.

Looking for on-premises data protection or want to leverage your own infrastructure? Do you have specific needs for long-term retention or migration between on-premises Exchange and Microsoft 365?  Then look to on-premises protection through Commvault Complete Data Protection for Microsoft 365.

Pour en savoir plus sur la manière dont Commvault renforce la protection des données Microsoft 365, rendez-vous surcommvault.com/microsoft-365.

Learn more about Microsoft’s Responsabilité partagée.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

https://play.vidyard.com/HSrWMH7cRstsFT42QdpTua.jpg

Vos équipes connaissent-elles leurs rôles et leurs responsabilités en cas de cyberattaque réelle ?

Vos équipes ont-elles le pouvoir de prendre des décisions à la volée, ou doivent-elles organiser des réunions sur Zoom pour obtenir l’autorisation de mettre des serveurs hors service ?

Vos équipes opérationnelles chargées de l’informatique, des réseaux et de la sécurité ont-elles une vision commune des responsabilités de chacune, des moments où elles doivent intervenir et de ceux où elles ne doivent pas le faire ?

According to a recent Gartner report, multidisciplinary teams that blend technology or analytics and business domain expertise and share accountability for business and technology outcomes foster team fusion innovation for digital delivery. Fusion teams consist of business and IT staff: product owners, scrum masters, developers, and domain experts. Fusion teams help to remove friction and address companywide issues and requirements.1

A village

With so many ransomware factors, it is usually within the innocent context that someone simply clicks a link, infecting an organization’s entire network with malware. There are many considerations on how you will defend against this very prevalent threat. Defending against ransomware is a major challenge  – and no individual team can combat it on their own. It takes a well-equipped, prepared, and practiced village to deal with complex threats successfully – one that includes:

People

Il est essentiel de coordonner les actions des équipes internes et externes avant, pendant et après une attaque par rançongiciel afin d’accélérer la Recovery, ce qui leur permet de réagir plus rapidement et de limiter les coûts liés aux temps d’arrêt.

Process

It is important that internal and external teams are aware of and in sync regarding their responsibilities and what processes they need to follow during a ransomware attack. Test, test, and test your process, as speed will be essential, and you don’t want to test out your process during an attack.

Technology

Suivez lecadre de cybersécurité de l’Institut national des normes et des technologies (NIST)pour faciliter votre préparation. L’adoption d’un cadre de sécurité à plusieurs niveaux permet de garantir que vos données sont prêtes à être restaurées et réduit le risque de perte.

Call To Action

La perte de données et l’impossibilité de les récupérer rapidement feront perdre du temps et de l’argent à votre entreprise et mettront en péril votre réputation et votre activité.

  • Identifier les principales parties prenantes : déterminer qui doit être impliqué en cas de cyberattaque.
  • Identifiez les éléments clés : sachez distinguer ce qui est important de ce qui ne l’est pas.
  • Organisez un exercice de simulation : passez en revue vos plans de manière proactive et communiquez-les.
  • Analyse rétrospective et mise en œuvre des changements : identifier les axes d’amélioration et mettre en œuvre ces changements.

Pour en savoir plus, nous vous invitons à consulter notreeBook Understanding Team Roles & Responsibilities in fighting ransomware to learn more.

This content has been derived from Commvault Connections 2021. Watch Dave Martin’s presentation ici.


  1. Gartner, « I&O Forward : à la tête de la prochaine phase de croissance », 2022

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Quelques exemples de l’effet Mandela :

  • Même si la plupart des gens se souviennent que le personnage de leur enfance, Curious George, était représenté avec une queue, il n’en a pas.
  • Many people believe there is a brand of peanut butter called “Jiffy” but there is not. There’s Jif, and there’s Skippy, but no Jiffy.
  • In the iconic scene in “Silence of the Lambs,” Hannibal Lecter does not say “Hello Clarice” as many people remember.  He says “good morning.”

L’effet Mandela dans le cloud

The Mandela effect is not just a pop culture phenomenon, it exists in the world of enterprise technology, too. It’s a common misconception that data stored in the cloud is automatically backed up.  The truth is that cloud providers operate on a shared responsibility model, in which the cloud provider is responsible for the security of the software, hardware and infrastructure, but not customers’ data.

Shared Responsibility Model from AWS

For example, when AWS refers to their highly durable Amazon S3 service, it’s true that the platform is incredibly durable, which means you’re unlikely to experience any trouble with their systems or infrastructure.  However, this has nothing to do with protecting your data from accidental deletions, ransomware attacks or insider threats. According to the shared responsibility model, that’s your job.

Mesures à prendre pour protéger vos données dans le cloud

Les clients apprécient particulièrement de travailler avec Clumio, car cette solution leur offre une protection des données isolée physiquement et immuable, avec un retour sur investissement extrêmement rapide, tandis que la simplicité propre aux solutions SaaS garantit une ingestion, un catalogage, une recherche et une Recovery rapides et faciles, quelle que soit l’échelle. Clumio permet aux clients d’automatiser la protection de leurs données AWS et Microsoft 365, ce qui leur fait gagner du temps et des ressources. Ils peuvent ainsi se concentrer sur des initiatives stratégiques et réduire leur coût total de possession (TCO) par rapport à d’autres solutions.

Don’t let data protection misconceptions leave you vulnerable.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Dans cet article, nous allons aborder les points suivants :

Containerization

What is a conteneur?

  • A Container is a basic software unit that packages up code and all its dependencies so an application can run smoothly in any environment. Each container is made up of a hardware, an operating system, a container engine, libraries, and dependency’s and finally the application. Everything the application needs to run is inside the container which means it can be created and deleted quickly using automation.
    • D’ici 2025, 85 % des entreprises mondiales utiliseront des applications conteneurisées en production¹

Container Orchestration

  • L’orchestration des conteneurs désigne l’automatisation des charges de travail conteneurisées. Elle joue un rôle essentiel dans l’utilisation des conteneurs, car c’est elle qui permet de déployer une même application dans différents environnements sans avoir à la repenser.

Kubernetes

What is Kubernetes (aka K8s)?

  • Kubernetes is an open-source container orchestration software designed for deploying, managing, and scaling containers. So, what does that mean? Essentially it eliminates much of the manual processes that needs to be done during deploying and scaling containerized workloads, even across various types of physical, virtual, and cloud environments.
  • Selon une récente enquête menée par la Cloud Native Computing Foundation, sur les 3 800 personnes interrogées, 96 % des entreprises utilisent ou évaluent actuellement Kubernetes²

Did you know?

  • The name Kubernetes comes Greek word κυβερνήτης (kubernḗtēs) which means pilot or helmsman therefore the Kubernetes logo is a ship’s steering wheel.  Kubernetes is often abbreviated as K8s because there are 8 letters in between ‘K’ and ‘S’
  • Kubernetes a été initialement développé et conçu par des ingénieurs de Google, puis cédé à la CNCF en 2015.

How does it work?

  • Kubernetes is a concept made up of several different components, and, while there are several elements and use-cases in the implementation of Kubernetes, the main concepts to understand are: the Control PlanePods, and Nodes.
    • The Control Plane consists of elements and API processes which coordinate workloads and communications, allowing for the smooth flow of information and resource allocation across the environment.
    • Pods are the base element in Kubernetes. A Pod consists of one or more containers and are co-located on the same node.
    • A Node (also known as a minion, or worker)is a machine on which containers are deployed. Each node must run a container runtime such as Docker, CoreOS rkt, Containerd, etc. Multiple Nodes can be grouped into Clusters.

Your IT environment and Kubernetes

  • En raison de l’évolution des pratiques informatiques modernes, les utilisateurs s’attendent à ce que les applications soient disponibles 24 heures sur 24, 7 jours sur 7, et on attend parfois des développeurs qu’ils soient capables de déployer de nouvelles versions des applications plusieurs fois par jour. De plus, les environnements informatiques sont de plus en plus hybrides et reposent sur des approches multicloud, intégrant des ressources sur site à des clouds publics ou privés provenant de différents fournisseurs. Si les systèmes de conteneurs ont permis aux développeurs de rendre les logiciels plus portables et de regrouper tous les paquets nécessaires à l’exécution d’un service, ils restaient toutefois limités par la charge de travail manuel nécessaire pour provisionner et modifier chaque conteneur au sein d’un environnement.
  • Kubernetes peut aider les entreprises à mieux gérer leurs charges de travail et à réduire les risques. Kubernetes permet d’automatiser les opérations de gestion des conteneurs et d’optimiser l’utilisation des ressources informatiques. Il peut même redémarrer les conteneurs orphelins, arrêter ceux qui ne sont pas utilisés et les recréer. Kubernetes automatise le déploiement des conteneurs sans que les équipes DevOps aient à intervenir manuellement pour chaque étape. Cela permet aux développeurs de déployer plus fréquemment de nouvelles versions d’applications spécifiques et de les mettre en production et de les mettre à jour sans temps d’arrêt, même sur plusieurs environnements (par exemple, Dev, Test, Prod).

Benefits of Kubernetes

  • Les principaux avantages de Kubernetes peuvent se résumer ainsi : réduction des délais de développement et de mise en production des applications, optimisation des coûts informatiques, amélioration de l’évolutivité et de la disponibilité des logiciels, flexibilité dans les environnements multicloud et portabilité vers le cloud.
  • Charges de travail portables
    • Because Kubernetes is an open source your workloads become portable take advantage of on-prem, hybrid, and multiple cloud environment— all while maintaining consistency across each environment.
  • Flexibilité
    • Quel que soit l’endroit où vous utilisez Kubernetes, celui-ci offre une grande flexibilité dans les environnements hybrides et multicloud, ce qui permet d’exploiter sans difficulté n’importe laquelle de nos applications dans n’importe quel environnement, qu’il soit public ou privé.
  • Automatisation
    • Kubernetes permet d’automatiser les environnements conteneurisés en jouant le rôle de système d’exploitation. Pour ce faire, il automatise les opérations requises pour les charges de travail conteneurisées.
  • Évolutivité et disponibilité
    • Kubernetes permet de définir des applications conteneurisées complexes et de les déployer sur des clusters de serveurs. À mesure que Kubernetes adapte la capacité des applications en fonction de l’état souhaité, il surveille et assure automatiquement le bon fonctionnement des conteneurs.

Kubernetes Architecture 

  • Kubernetes control plane: Also known as the master machine, is the container orchestration layer that exposes the API and interfaces to define, deploy, and manage the lifecycle of containers aswell as the nodes that hold the containerized applications. It ensures that every cluster is kept in its desired state.

The components of the Control Plane

  • API Server: The Application Programming Interface also know as API is the front end of Kubernetes. It is where clients make an initial request for an object or a collection and it determines if the request is valid and then it will process it. The API server also is what is used to transmit, create, and configure data within K8 clusters.
  • K8s scheduler: The scheduler is what watches and manages pods that are newly created and assigns them to a node so they can run on it smoothly.
  • Controller manager: Within the Control Plane there are multiple controllers, they are the control loops designed to watch the state of your cluster and make or request changes as they are needed.
  • Etcd: Is a data base where all your container storage is stored. It is a strongly consistent, distributed key-value store that holds and manages the critical information that systems need to run.
  • Cluster
    • NODE: (also known as a minion, or worker)is a machine on which containers are deployed. Each node must run a container runtime such as Docker, CoreOS rkt, Containerd, etc. Multiple Nodes can be grouped into Clusters.
    • Pod: are the base element in Kubernetes. A Pod consists of one or more containers and are co-located on  nodes.
      • C’est ici que sont conservées toutes vos informations importantes

Modernize with Kubernetes

  • Kubernetes permet de simplifier et d’accélérer la migration des applications depuis un environnement sur site vers des clouds publics ou privés, proposés par n’importe quel fournisseur. La migration des applications vers le cloud peut s’effectuer selon différentes méthodologies :
    • la simple transposition de l’application, sans aucune modification du code (Lift & Shift) ;
    • les modifications minimales nécessaires pour permettre à l’application de fonctionner dans de nouveaux environnements (migration vers une nouvelle plateforme) ;
    • la refonte en profondeur de la structure et des fonctionnalités de l’application (refactoring).
  • Modernisez votre environnement plus facilement que jamais grâce à l’adoption de Kubernetes. Plus besoin de vous demander où se trouvent vos données : toutes vos données sont stockées au même endroit. Le stockage Kubernetes repose sur des volumes. Ces volumes peuvent être persistants ou non persistants. Au sein des pods, les conteneurs demandent davantage d’espace de stockage.
    • Kubernetes can be built once and then is able to be deployed anywhere. This means no matter where you build your cluster whether it is on prem or in the cloud you don’t need to rebuild the solution you just have to deploy a different cluster.

Challenge

  • Kubernetes clusters can be prone to ransomware attacks, like any other workload. In some cases, a hacker can gain access to what is inside of your pod –  potentially receiving critical information about your organization. Therefore, backing up and having data protection for your clusters is vital when it comes to moving your workloads around.

Kubernetes Backup

  • Il s’agit du processus de sauvegarde de tous les composants fonctionnant au sein d’une plateforme d’orchestration Kubernetes, qui comprend l’ensemble des applications conteneurisées de l’organisation. Étant donné qu’un cluster Kubernetes comporte un grand nombre de composants (pods, nœuds, plan de contrôle et volumes), chacun d’entre eux nécessite un certain niveau de protection. La protection est essentielle pour un cluster, d’autant plus que les entreprises s’appuient de plus en plus sur Kubernetes. La sauvegarde d’un cluster Kubernetes garantit que les données, les configurations et les fichiers sont protégés contre toute attaque. C’est pourquoi vous avez besoin d’une solution capable de sauvegarder l’intégralité de votre cluster.
  • Les principales étapes de la sauvegarde de Kubernetes sont les suivantes :
    • La découverte
    • Discovery.
    • Backup
      • Selon le rapport 2022 de Red Hat sur l’état de la sécurité de Kubernetes, 93 % des personnes interrogées ont connu au moins un incident de sécurité dans leurs environnements Kubernetes au cours des 12 derniers mois, ce qui a parfois entraîné une perte de chiffre d’affaires ou de clients³

Commvault and Metallic’s Kubernetes Backup

Commvault and Kubernetes Data Protection

  • Commvault has the ability to back up your entire cluster unlike most solutions that can only back up your containers. Commvault provides data protection for persistent storage in your stateful applications. Commvault’s solution automates back up of this data all from a single platform that increases the visibility and management capabilities of your entire environment. Our solution gives you the flexibility to migrate and deploy containers from on-prem to cloud, cloud to cloud and even back on- prem seamlessly with ease. It also offers broad support for VMs, data services and cloud services in a single platform. It is also compatible with all CNCF- certified distributions and integrated with CSI for snapshot-based backups.
  • Commvault has been recognized by the 2022 GigaOm report as a “leader and outperformer” in Kubernetes data protection for our flexible deployment architecture and single interface across multiple deployments. The report also states that our security and ransomware controls are extensive which makes it suitable for larger enterprises.

How Commvault does it

  • Commvault planifie la création d’un groupe de travailleurs temporaires pour effectuer le transfert de données. Les paramètres indiquent un registre de conteneurs privé dans lequel vous stockez une image que Commvault peut télécharger. Cela vous permet de regrouper des clusters, de simplifier la migration entre clusters et d’optimiser la gestion du cycle de vie des clusters.

Challenges before Commvault

  • Avant l’arrivée de Commvault, les entreprises devaient faire face à la prolifération des clusters, gérer leur cycle de vie et les consolider. Commvault vous aide à relever ces défis en vous permettant de migrer facilement vos applications Kubernetes vers n’importe quel cloud.

Metallic and Kubernetes backup

  • Metallic propose une solution de Sauvegarde métallique des VM et Kubernetes. Il s’agit du seul service SaaS de protection des données offrant une couverture complète des charges de travail hybrides, garantissant ainsi la sécurité permanente de vos conteneurs.
  • La solution VM & Kubernetes Backup de Metallic vous permet d’étendre facilement vos environnements aux conteneurs afin de moderniser vos applications en toute confiance, tout en continuant à protéger vos applications traditionnelles. Que vous soyez sur site ou dans le cloud, Metallic prend en charge toutes les distributions Kubernetes certifiées par la Cloud Native Computing Foundation, telles qu’Azure Kubernetes Service (AKS), Amazon EKS, VMware, Rancher et bien d’autres encore.
  • Metallic permet de protéger les bases de données dans le cloud ou sur site, les systèmes de gestion du code source, les registres d’images et le stockage d’objets natif du cloud.
  • Grâce à la flexibilité inégalée, à la sécurité optimale et à la gestion simplifiée de cette solution, toutes vos charges de travail sont prises en charge.

Conclusion

Kubernetes, c’est l’avenir : c’est maintenant qu’il faut vous assurer que toutes vos charges de travail sont protégées et peuvent migrer en toute sécurité vers le cloud. Commvault s’impose comme le choix évident. Nous avons été désignés comme leader et « outperformer » dans le rapport GigaOm 2022 sur la protection des données Kubernetes grâce à notre large prise en charge des charges de travail, à notre compatibilité avec les distributions certifiées CNCF et à nos contrôles approfondis contre les ransomwares. Alors faites vos valises, le navire met le cap sur le cloud dès aujourd’hui.

References

1. Best Practices for Running Containers and Kubernetes in Production – 4 Aug 2020 – Gartner ID G00730344 – 2. CNCF 2021, Annual Survey – 3. Red Hat 2022, State of Kubernetes Security Report

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Enterprises today are inherently heterogeneous, running applications and supporting workloads across on-prem, edge and multiple clouds. As businesses accelerate their IT transformation, this hybrid multi-cloud presence is set to further expand. It is imperative, then, that enterprise data protection and data management solutions excel in all of these areas – across on-prem, edge and multiple clouds.

Gartner Critical Capabilities report assesses these types of solutions on various key aspects such as security, efficiency, scalability and performance, Data Center ecosystem, and reporting and analytics across the key use cases of on-prem, edge and cloud. In my conversations with CIO’s, IT leaders, and architects, these are exactly the key aspects they are concerned with when architecting their data management strategy to protect their crown jewels.

This is why we are thrilled and honored that Commvault Backup & Recovery has scored the highest in all three use cases in the 2022 Gartner Critical Capabilities for Enterprise Backup and Recovery Software Solutions: Data Center Environments (4.23/5), Cloud Environments (4.18/5), and Edge Environments (4.22/5). With the highest scores in all three use cases – for the third time in a row – we believe this is yet another validation of our commitment to be a trusted partner to our customers in protecting their data and workloads – no matter where they reside.

Data Center Environments (4.23/5)
Cloud Environments (4.18/5)
Edge Environments (4.22/5)

Les entreprises ne cessent d’évoluer et de se développer pour répondre à leurs besoins commerciaux. C’est pourquoi un autre facteur clé de la transformation informatique réside dans une solution de gestion des données capable d’évoluer de manière flexible au même rythme que le reste de l’infrastructure informatique.

“Our continuous innovation is designed with ultimate flexibility when it comes to data management – offering not only an enterprise software solution but also the ability to manage and protect enterprise data with Commvault Grid as an integrated solution or via Metallic as a cloud-delivered DMaaS solution.”


Unfortunately, flexibility and breadth are often offered at the cost of simplicity in our industry.  In contrast, Commvault breaks this paradigm with our “infinitely scalable, radically simple” approach. We bring together all management – across our broad set of supported workloads, flexible form factors and array of Intelligent Data Services – through the single experience of Commvault Command Center. This simplicity – with no compromise to flexibility and breadth – empowers customers to fast-track their business transformation aligning their data management to their broader IT strategy. As businesses modernize and transform, transitioning applications and workloads from one form factor or location to another (from on-prem to cloud, for example), we ensure they remain protected no matter where they are in this journey.

As an eleven-time Leader in the Gartner Magic Quadrant and back-to-back years with the highest scores in all three use cases in the Gartner Critical Capabilities report, we are grateful to our customers for partnering with us in this journey of continuous customer-first innovation and to our partners in building a data ecosystem with no boundaries. Our journey to solve the hard data management problems with elegant solutions continues … together with our dear customers and partners!

Gartner, « Magic Quadrant : solutions logicielles de Backup and Recovery pour les entreprises », 28 juillet 2022, Michael Hoeck et al. Gartner, « Capacités essentielles des solutions logicielles de Backup and Recovery pour les entreprises », 22 août 2022, Nik Simpson et al.

Gartner Disclaimer:

**Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.**

**GARTNER et Magic Quadrant sont des marques déposées et des marques de service de Gartner, Inc. et/ou de ses filiales aux États-Unis et à l’international et sont utilisées ici avec autorisation. Tous droits réservés.**

Procurez-vous votre exemplaire du rapport « Gartner Critical Capabilities for Enterprise Backup and Recovery Solutions » 2022

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Commvault’s long time partnership with Microsoft has once again given us the opportunity to offer our customers cutting edge features and functionality.  We are excited to have had the opportunity to develop this feature in lockstep with Microsoft allowing us to release our enhanced capabilities on Commvault Complete and Metallic® DMaaS simultaneously when Azure Restore Points became publicly available on July 19th 2022.

Commvault Protection for Azure Virtual Machines

Figure 1

Commvault has always offered options for protecting Azure Virtual Machines (VM) by using snapshots or even installing software on the VM to provide Application Awareness.   Each disk resource is individually snapped and protected.  The process is serial by nature as each resource request needed to be made in series. 

Dans la figure 1, une demande de sauvegarde devrait protéger le disque du système d’exploitation, puis le disque « Data 1 » et enfin le disque « Data 2 ». Ces trois disques constituent la machine virtuelle et seraient protégés ensemble, mais leurs instantanés pourraient ne pas être finalisés exactement au même moment ; une coordination supplémentaire avec la couche applicative pourrait donc s’avérer nécessaire pour garantir la cohérence au niveau de l’application.

New Restore Point Functionality

Figure 2

With Restore Points, Commvault will now have the ability to create collections of restore points across all volumes on a VM.  When doing so, the restore process is simplified, and the collection points are stored on cost efficient storage.  This is a major architectural change in data protection for Microsoft that Commvault Complete and Metallic enable with a click.

In the example in Figure 2, once a Restore Point Collection is created, the same VM would be protected as a single API call to create a Restore Point.  Every Restore Point is incremental and should complete in seconds.  All disks within the VM are consistent with the restore point automatically.  Every Restore Point will contain a Disk Restore Point for all managed disks.  The Disk Restore Point consists of a snapshot of that disk.  This reduces the restore process in this example from 3 steps to 1.  

How is it simplified? 

Leveraging the Commvault platform to orchestrate VM protection and more importantly, the recovery of VMs at enterprise scale is a critical need.  Getting away from point solutions and homebrew scripting naturally promotes growth and reduces downtime.  Being able to recover dozens or hundreds of instances with a few clicks keeps end user time from being sacrificed.

Improve resiliency while reducing tech waste

Commvault supports creating snapshots in cost audited resource groups already and automatically tags resources as they are created so that cost reporting is accurate.  Adding VM Restore Points to our portfolio now allows us to create the restore points in cost efficient and less redundant storage tiers.  It might be a minor cost difference, but at cloud scale, the billing is in the details and every improvement brings value to the solution.   There’s no tradeoff in taking advantage of Restore Points.  It simplifies and reduces cost while improving resiliency.  Azure Restore Points ensures that the applications and the operating system are consistent when creating these collections at the native instance level. 

A quick recap

Better cost efficiency, better performance, better resiliency, and a simplified design.  A resounding win!  We are excited to have had the opportunity to develop this feature in lockstep with Microsoft and prove yet again our commitment to making the latest enhancements in Azure readily available within the Commvault Intelligent Data Services portfolio of solutions.   

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

L’herbe est vraiment plus verte dans le cloud

Until very recently, many enterprises were limited by on-prem infrastructure, requiring huge data centers that had to be maintained, cooled, and secured. On top of that, the enterprise-owned server utilization rate is a measly 18%, with the majority of data centers operating at energy efficiency levels below 80%. This underutilization made on-prem ripe for disruption when the cloud came about. The cloud’s on-demand scalability provided companies the ability to optimize utilization rates without the hassle of managing, powering or cooling infrastructure. Considering the benefits, it’s not surprising that the average enterprise on-prem to cloud migration led to a 65% energy reduction and 84% carbon reduction (Accenture, The Green Behind the Cloud). Moreover, AWS is set to power all operations with 100% renewable energy by 2025, with a commitment to achieve net-zero carbon emissions by 2040. They use reclaimed or recycled water for cooling and have embodied carbon in the construction of newer data centers across the globe. And as an AWS recommended partner, Clumio is pushing the boundaries of environmentally sustainable computing with its on-demand hyper-scalable architecture.

Les solutions « cloud-native » sont essentielles pour optimiser le développement durable

whether you need help protecticting your data against ransomware, meeting compliance requirements, or recovering from data loss; data backups can take up a significant amount of storage space, and increase your infrastructure footprint if done on-prem. Companies must choose carefully if they are conscious of reducing their carbon footprint from their data. Some best practices include going with a cloud-native / SaaS data protection vendor if possible, implementing incremental backups vs full system snapshots, categorizing and auto-archiving data based on criticality and usage, and most importantly, investing in a platform that is architected to scale on demand. If these concerns sound like yours, Clumio can help.

Comment Clumio peut vous aider

Clumio is a cloud-native backup solution, architected with a container-based stateless data processing pipeline that leverages efficient Lambda functions. This allows adaptability and efficient scaling to optimize usage based on your exact policies. Having this scalable compute and increased utilization rates can ultimately lead to significant carbon reduction from your data estate, in addition to significantly lower TCO (save your wallet while saving the planet).

See for yourself how the industry’s first cloud-native backup and rapid recovery solution can optimize your business’s sustainability metrics. Schedule a demo and learn how your business can be up and running with Clumio in as few as 10 minutes — no need to wait for and install new infrastructure and software.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

In this blog, you’ll learn how Commvault Grid makes implementing an immutable architecture easy as an integrated appliance or reference design for an all-in-one solution. With cyber-attacks increasing it delivers comprehensive data management across workloads to protect your data through 5 security layers. Commvault offers a hybrid of controls that work together to harden data against ransomware, cyber threats, and bad actors. 

What is an Immutable Architecture and how do organization benefit?   

Immutability is defined as the ability of any data to be maintained in a non-fungible state for a specific duration of time. Data immutability can be attained via various methods working in conjunction with each other.  An immutable architecture is a model in which no updates, security patches, or configuration changes happen “in-place” on production systems.  If any change is needed, a new version of the architecture is built and deployed into production.  

Organizations need an immutable architecture to ensure their data is safe and secure and more importantly, ready whenever they need to restore it. Immutability is a proven technique used to reduce cyber-attacks on backup data and ensure that backup copies aren’t changed in any way. 

Commvault Grid for Greater Immutability  

Commvault Grid makes it easier to implement an immutable architecture as an integrated appliance or reference design for an all-in-one solution. It delivers comprehensive data management for all workloads from a single, extensible platform. Commvault employs a multi-layered approach to protect against various threat vectors and ensure data is safe. Commvault’s immutable architecture consists of 5 layers which are:   

  • Storage I/O Controls   
  • Zero Trust AAA Controls   
  • Infrastructure Hardening   
  • Zero trust isolation and air gap  
  • Data Validation  

Commvault Grid leverages the entire Commvault software portfolio providing access to all the features, functions, and industry-leading integrations with applications, databases, public cloud environments, hypervisors, operating systems, containers and NextGen workloads. Wherever your data resides, you have the ability to view it, use it, and confidently protect it. Commvault Grid accelerates hybrid cloud adoption with an integrated solution built on a deeply layered system of controls that work together to harden data against ransomware, cyber threats, and bad actors.   

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Exemples de coûts cachés et variables liés à la sauvegarde dans le cloud

Frais de sortie

The majority of cloud providers will allow their users to place data into the cloud without any fees. However, this does not apply when their data is retrieved from the cloud. Cloud providers typically charge what’s known as egress fees any time data is retrieved.

If your enterprise is constantly pulling its data out of the cloud—such as migrating or recovering data— you can see how the fees can add up quickly and lead to inflated costs that are nearly impossible to predict. Egress fees are considered a hidden fee since they fluctuate based on usage and are tied to a common action (data retrieval).

Licences

There may be a variety of licenses that are required, each with their own fee. These can snowball when cloud backup vendors require licenses for each of the data sources you back up or multiple licenses per user—something you may not realize until the bill comes.

Instantanés et coûts de stockage

It is common for enterprises to create long-term storage for their production data if they need to recover it after an attack—such as ransomware. This could involve creating massive amounts of snapshots for each account in high-tier storage. Furthermore, each time a block or file is changed, a new snapshot is automatically created. These snapshots are replicated across accounts, effectively doubling backup storage costs that continue to pile up over time. Costs are further compounded when considering industry retention requirements that go beyond 35 days.

Adding to all the complexity is the fact that it’s difficult to gauge just how many of the backup snapshots in your AWS accounts are even needed. Sure, your bill can display how much you are spending in a particular region, but it doesn’t show the level of granularity regarding the age of the snapshots or assets they are associated with.

Achieve Predictable Costs and Lower TCO with the Industry’s Leading Cloud-Native Backup Solution

You can avoid excessive cloud spending and gain control over backup costs by choosing a cloud backup solution with a simple, straightforward pricing model that clearly spells out the ongoing charges.

Built natively in AWS, Clumio’s backup solution offers the scalability, performance, data protection, and faster access to innovation made possible by the cloud while avoiding the hidden costs, complexity, and limited flexibility of snapshot-based backup solutions.

Tarification simplifiée

Clumio’s Pay-As-You-Go consumption model with rollover credits provides enterprises with a simplified and clear backup-as-a-service solution that ensures cost predictability while lowering TCO:

  • Transparency – No hidden costs, no license fees, and no egress charges—plus full visibility into data consumption.
  • No Friction – Choose from on-demand or commitment contracts with no setup required.
  • 100% SaaS – No complex cloud infrastructure or software to install or manage.
  • Un outil d’analyse des coûts intégré qui fournit des informations permettant de réduire les dépenses inutiles liées au cloud

Réduction des dépenses liées au stockage

Plutôt que de conserver les instantanés Amazon EBS, Clumio réduit encore davantage les dépenses en stockant les données dans un format compressé et dédupliqué sur Amazon S3, ce qui permet de réduire considérablement le coût de la conservation à long terme des données EBS. Les entreprises peuvent ainsi se conformer aux exigences réglementaires et élaborer des stratégies de conservation fondées sur leurs besoins métier et les exigences réglementaires, plutôt que sur les coûts.

Premiers pas avec Clumio

Clumio ne se limite pas à vous faire réaliser des économies. En moins de 15 minutes, votre entreprise peut :

  • Sauvegardez instantanément les données AWS de l’ensemble de votre entreprise grâce à Clumio
  • Bénéficiez d’une protection des données contre les attaques par ransomware et autres menaces malveillantes grâce au stockage « air-gapped » avec Clumio
  • Répondez à des objectifs variés et complexes en matière de conformité des données grâce aux politiques globales de Clumio
  • Réduisez le RTO (temps de reprise cible) et garantissez la continuité des activités en cas d’indisponibilité grâce à Clumio

Experience firsthand why Clumio is the industry’s leading innovator for AWS cloud backup. Start your free trial, all without any pre-planning or the need to install new infrastructure or software.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era