Skip to content

As Senior Product Marketing Manager at Metallic, I was honored to recently have been awarded a CEO Living Our Values Award by our leadership team for theMetallic Threatwise launch. With ThreatWise, Commvault moved into uncharted territory as the only data protection platform to offer fully-integrated deception technology, capable of surfacing unknown and zero-day cyber threats before they reach your data – and it’s time to recover. Bringing this next-generation service to market was a significant milestone in supporting how our customers combat and respond to cyber threats, and I was fortunate to be a part of the team who helped deliver these capabilities.

Winning this award made me reflect on my time at Commvault and how it has shaped my professional journey. I joined Commvault in 2020 and was part of the first wave of employees who started during the pandemic. Growing up in New Jersey, and having spent the majority of my career in the tech industry, I was very familiar with the Commvault name – not only for it’s reputation as a perennial leader in the data protection spacebut also for its reputation as a great place to work.

In qualità di Product Marketing Manager, mi trovo a muovermi tra mondi molto diversi, guidando e supportando le attività di lancio dei nostriservizi Metallic Commvault’s portfolio of SaaS-delivered data protection solutions. Working in this cross-functional capacity has challenged me but also presented the opportunity to work alongside many different areas of our business. From Product and Engineering to Operations and Customer Success (and everything in between), I partner with various stakeholders daily to achieve one common mission: deliver the best data protection services possible. Working as a collective unit to deliver against this promise is what drives me, and my colleagues, every day. On the customer front, this high level of collaboration has paid significant dividends as we rapidly innovate to bring best-in-class products to market for businesses of all sizes. On the professional front, it has allowed me to build new connections, expand my expertise outside of the Product Marketing domain, and further hone and mature my skillset.

When first arriving to the Metallic team, we were just getting our feet underneath us. Now, just three short years in, the trajectory and the growth have been remarkable. What started as an incubation project within Commvault, Metallic has achieved hyper-growth – more than tripling our portfolio offerings, garnering around 3,000 customers, and introducing new innovations that disrupt and advance the data protection market. I know everyone in Commvault has worked so hard to make this happen – it’s the teamwork, the maniacal focus on helping our customers, and the drive of our employees that have allowed us to reach this massive achievement.

Our values – we connect, we inspire, we care, and we deliver – continue to move our business forward. The past few years have been a wild, exciting ride, and I can’t wait for what the future holds for Commvault and Metallic.   

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

This codification of privacy is transforming how businesses are expected to operate. There is no more question of what happens when a business doesn’t invest in a cyber program and who’s responsible. Let’s take a quick look at what will shape this year.

Normative statunitensi sulla privacy: CCPA, NYDFS e SEC aggiornano i requisiti

CCPA may be amended. Currently the CCPA has an open request for comment on how audits fit with CCPA. In addition, we will start seeing rulings in cases around CCPA showing what we can expect for the reality of losses from not complying. For those who want to keep track with us, Perkins Coie has a great strumento di monitoraggio.

NYDFS will likely be amended. Industry comments are under review. Once DFS makes its recommendations it will move through the legislation process. Notable takes:

    • “The CISO and the highest-ranking officer of the covered entities are both required to sign a certificate of compliance, and notice of compliance must be delivered annually to the NYDFS.” – Morgan Lewis.
    • Non si tratta solo di una legge sulla privacy, ma riguarda anche la resilienza aziendale e la sicurezza delle operazioni

The SEC wants their new rules in place ASAP. This includes provisions for Cyber Security reporting requirements alongside considering rules requiring adoption of standard practices. As with all federal rules, this one may take some time. Other provisions, notably around carbon footprint reporting, seem to be causing friction. We will see if the SEC makes their timeline.

$100 Million penalty for BIPA violations. In 2022, we saw cases relating to the Louisiana BIPA come to a close with significant penalties being doled out. The rubber is meeting the road, and liabilities are a reality. Read more at Data Protection Report.

Perché i dirigenti devono dare priorità alle competenze in materia di sicurezza informatica

Con questa forte spinta legislativa, le responsabilità concrete sono ormai una realtà. I dirigenti non possono più ignorare i consigli dei team di sicurezza. La realtà è che la maggior parte delle aziende non è pronta. Un breve estratto da Forbes lo illustra perfettamente:

“Our analysis showed that only 51% of Fortune 100 companies have a director on their boards with relevant cybersecurity experience. The situation in the Fortune 200 and 500 is more concerning: only 9% have cyber-savvy directors. Worse still are the companies in the Russell 3000 smaller than those in the Fortune 500: only 8% have cyber directors. There is a total shortage of 2,724 directors with cybersecurity expertise across all Russell 3000 companies.” –Forbes

To be successful in filling these positions, security leaders will need to have an opinion on what’s changing from a legal perspective, how that impacts business strategy, and how the business creates opportunity in markets with changing regulations.

In sintesi, i CISO devono partecipare a ogni discussione strategica a livello di consiglio di amministrazione. Un CISO proattivo può infatti rappresentare un vantaggio competitivo. Questi leader proattivi comprenderanno i dati aziendali, sapranno come utilizzarli per ottenere vantaggi di mercato e affronteranno le nuove sfide normative. Le aziende in grado di anticipare l’evoluzione del contesto normativo otterranno un maggiore ritorno sull’investimento. Le aziende che considerano la conformità come una semplice formalità rimarranno indietro.

Adherence to compliance regulations is critical to your business’s operations, but it doesn’t have to consume an outsized portion of your resources. Let Clumio help automate compliance and simplify management while reducing your data protection costs. Contact us for a customized consultation.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

The past year has been amazing – our data protection portfolio has won many accolades of technology leadership from industry analysts like Gartner, Forrester and GigaOm. These wins are no doubt driven by our relentless passion to protect our customers’ data in a difficult world and our fundamental belief that continuous customer collaboration is key to pragmatic innovation.

The next chapter of our 26-year journey of customer-driven innovation is now here – we are excited to announce the General Availability of Commvault Platform Release 2023! Commvault PR 2023 introduces several new features and additions to strengthen our customers’ security posture, deepen our rich integration with all major hyperscalers and introduce more smart savings through operational efficiencies.
Centinaia di clienti hanno già potuto beneficiare di queste nuove funzionalità durante la fase di anteprima tecnologica, iniziata il 15 dicembre 2022.

Harnessing the power of multi-cloud

What differentiates our approach to the ecosystem – and yes, we continue to support the broadest ecosystem when it comes to data protection – is how our integrations are seamlessly built-in and not just clumsily bolted on for a quick mention. Deeper the integrations, greater the synergies enjoyed by our customers.

Commvault PR 2023 introduce nuove integrazioni approfondite per consentire ai nostri clienti di proteggere più facilmente i propri dati su Microsoft Azure, AWS Cloud, Google Cloud Platform e Oracle Cloud Infrastructure.

Take, for instance, our new integration with Microsoft Azure Restore Points. We worked closely with Microsoft to be the first data protection platform to support Azure Restore Points. While Azure has had incremental snapshot capabilities, this new integration allows for application consistency across disks, while reducing costs with the option to use more cost-efficient storage tiers for backups. Commvault PR 2023 also introduces integration with Amazon FSx for NetApp which brings the same on-premises NetApp ONTAP policy-based protection to AWS. The new release also introduces support for Oracle Cloud Infrastructure (OCI) infrequent access & combined storage tiers to help reduce costs for protecting your cloud data.

Enhancing data security

Our trusted approach to data protection is shaped by the fundamental customer direction that data security is an integral and inseparable component of data protection. Building on our robust multi-layered ransomware detection, protection and recovery framework, Commvault PR 2023 introduces new integrations to drive data protection insights into the broader security ecosystem.

An important aspect of data protection is to leverage data awareness to proactively alert IT teams when threats arise. Commvault PR 2023 introduces a new Security Information and Event Management (SIEM) connector that makes it easy to feed alerts, events, and audit data to other platforms through webhooks APIs or even Syslog. Leveraging standard protocols ensures we can work with virtually any SIEM or event management system giving security teams better visibility to anomalies and threats in their data. 

Driving smart savings

With the uncertainty of a global recession looming, customers in every industry are looking to optimize costs in their budgets to make up for the increased spending for security and mission-critical areas. We are continuing to help provide options to lower the cost for data

Le nuove funzionalità che consentono di utilizzare snapshot a regione singola anziché snapshot multiregione per GCP possono far risparmiare il 30% dei costi relativi alle risorse di backup. A volte, ottimizzare i costi è semplice quanto ridurre il tempo necessario per proteggere le applicazioni.

Le nostre ottimizzazioni per Hadoop, che sfruttano snapdiff, consentono di ridurre a pochi minuti le operazioni di scansione dei backup che prima richiedevano ore, grazie ai miglioramenti apportati al metodo di scansione dei blocchi modificati.

These are just a few of the amazing features we have in Platform Release 2023. You can learn about more of the latest features in our What’s New page for Platform Releases. Entra in contatto with our product management team and others in our comunità for all the latest news and release information. 

Join us live on March 8th, 2023 at our Platform Release 2023 customer webinar.  Register here

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

La Giornata internazionale delle donne e delle ragazze nella scienza 2023 si terrà sabato 11 febbraio e rappresenta un’occasione per promuovere il pieno e paritario accesso e la partecipazione delle donne nei settori della scienza, della tecnologia, dell’ingegneria e della matematica (STEM).

Abbiamo incontrato due leader straordinarie e fonte di ispirazione di Commvault, Vidya Shankaran, Field CTO, e Parisa Bazl, Director of User Experience, per conoscere il loro punto di vista su una serie di argomenti, tra cui:

  • Perché solo una minoranza di donne intraprende una carriera nel settore STEM,
  • come l’apporto di prospettive diverse possa rappresentare un enorme vantaggio nel loro ruolo e
  • e quali consigli darebbero alle loro versioni diciottenni.
  • Eroi personali

Why is marking the International Day of Women and Girls in Science important?

Vidya

In qualità di madre di una figlia che frequenta un liceo specializzato in scienze e ingegneria, so quanto sia importante sensibilizzare l’opinione pubblica sulla necessità della parità di genere e promuovere l’emancipazione e l’avanzamento delle donne e delle ragazze nei settori della scienza, della tecnologia, dell’ingegneria e della matematica (STEM).

By celebrating this day, it serves as a constant reminder for all to work towards removing the barriers that prevent women and girls from participating – this helps foster a more inclusive and innovative scientific community and a better future for all.

Questa giornata riconosce l’importante contributo delle donne e delle ragazze in questi settori e incoraggia un numero maggiore di ragazze e donne a intraprendere una carriera nel campo delle discipline STEM.

Parisa

Celebrating this day is a way to remind ourselves of how far we’ve come and the distance we still need to go. While achieving gender equality in the STEM field is an uphill battle, our progress is evidence that it is possible and we will get there. This day is also a reminder of the benefits of having diversity in technology since so many critical, fun, and interesting things — from WiFi to dating apps – had their groundwork laid by women.

Why do you think women earn STEM degrees at half the rate of men – how can we help address this?

Vidya

Despite the fact that women have had a significant role to play in the progress of science and technology, they have not received the same levels of recognition as their male colleagues is an issue that transcends centuries. 

I would not necessarily to ascribe it to lack of female role models in STEM – there are many unsung “heroes” – but rather to the gender stereotypes and societal expectations that science is a “male” field. This manifests in the form of insufficient support for work-life balance that women and girls encounter compared to their male counterparts.

Thankfully, it is not irreparable or beyond redemption yet – there are many things we are already doing today and should continue doing and maybe even accelerate.

Promuovere modelli femminili di riferimento nel campo delle discipline STEM attraverso la copertura mediatica e mettere in luce i successi delle donne nel mondo della scienza è fondamentale, poiché ciò ha il potere di incoraggiare le ragazze ad avvicinarsi alle scienze sin dalla tenera età.

Most importantly, it is imperative that we continue providing supportive environments in education and the workplace, such as mentorship programs and outreach activities. Providing flexible work arrangements ensures that women continue to remain motivated to pursue their careers in STEM. Finally, fostering a culture of diversity and inclusivity in STEM, and promoting equity and equal opportunities in hiring, promotion, and compensation are critical to improving induction and retention of women and girls in STEM careers.

Parisa

Molte donne crescono con la percezione errata che le discipline STEM siano un ambito che favorisce i punti di forza stereotipicamente maschili, e non sempre disponiamo di adeguati sistemi di sostegno sociale per affrontare questi sentimenti di inadeguatezza e mancanza di fiducia in se stesse. La tecnologia viene spesso equiparata al software, ma in realtà riguarda molto di più le persone. Mettendo in risalto gli aspetti umani di questa disciplina, possiamo incoraggiare un maggior numero di donne a comprendere come i loro background, le loro prospettive e le loro competenze uniche possano rappresentare un punto di forza nel perseguimento di studi e carriere nel campo delle discipline STEM.

What can being a woman bring to your roles of field Chief Technology Officer (Vidya) and Director of User Experience (Parisa)

Vidya

In my role, which is technology evangelism with our customers and partners, in order deliver this role successfully, it requires empathy, emotional intelligence, respect for all cultures and obviously, understanding of technology. As a woman it does require a lot more effort and perseverance to get to and keep my “seat at the table”, but it is not without the support of all men and women around me.

Sto inoltre osservando un aumento del numero di uomini che si schierano dalla parte delle donne e che hanno svolto un ruolo fondamentale nel promuovere l’accettazione, l’incoraggiamento e il sostegno alle donne nel settore tecnologico. Questi uomini sono quasi sempre padri o fratelli di donne e ragazze che operano nel campo delle discipline STEM, sono consapevoli delle sfide che le donne e le ragazze devono affrontare e sono lieti di dare il proprio contributo per rimuovere questi ostacoli. Si tratta sicuramente di un cambiamento nella giusta direzione.

Parisa

Working in a field where I’ve historically been at a disadvantage means that I’ve cultivated skills which not only help me navigate the field, but also do my job very well. I have had to pay attention to the smallest details, ask incisive questions, and listen extremely closely in order to best position myself for success. These are skills that make me a better advocate for users, since great UX is built on our ability to pay attention to what their users are saying in order to piece together the optimal solutions. In addition, being an outsider within the field of technology also makes me much more conscientious of inclusivity, and how everything from the way in which my team operates down to the interface that is designed needs to be intentional about creating equitable access and success.

What advice would you give to your 18-year-old self, moving into technology?

Vidya

Direi: tieni duro, perché le cose miglioreranno .

But again, the kind of pressure we put on ourselves to deliver our best day after day, I would only say to take slow down and “smell the roses” – that we are not expected to know everything or have all the answers and it is okay to say, “I don’t know”.  After graduating with a degree in Chemical Engineering when I moved into Information technology, it felt like a personal failure, but I would tell me 18-yo self that it is okay to fail – “Failure” is a verb not a noun.

Parisa

Consiglierei al me stesso diciottenne, che non aveva mai pensato di dedicarsi alla tecnologia, di considerarla al di là della semplice ingegneria. Come ho detto prima, la tecnologia riguarda molto più le persone che il software. Se ci concentriamo sulla nostra capacità di entrare in contatto con le persone e di coltivare la comprensione, diventiamo molto più preziosi e il nostro impatto è molto più positivo.

Personal Heroes – Who do you admire?

Vidya

Nutro grande rispetto per Indra Nooyi, ex amministratore delegato di Pepsico, e cerco ogni occasione per imparare dalle sue esperienze.

Parisa

I’m a big fan of Barack Obama. He is someone who also had to navigate a system that was not predisposed to his success, and he leveraged his unique skillset, background, and point of view to inspire and connect with millions of people.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

It sometimes feels like we are living in the age of the reboot.  If you’re a fan of the hit TV show “That 70’s Show,” you know that it’s all about a group of friends navigating the challenges of adolescence in the 1970s and that it’s been rebooted (and updated to the 90s) on a popular streaming service. 

And it’s not alone.  From the good (Cobra Kai anyone?) to the not so popular (did anyone actually see the Knight Rider remake??) there is always an appetite for an update which reflects the current environment and challenges.

That sentiment can also be applied to your organization’s data management and protection strategy – to ensure it stays current and effective in an ever-changing world of emerging technologies and cyber threats.

Con l’arrivo del nuovo anno e una nuova prospettiva, verifica se uno dei segnali riportati di seguito ti sembra familiare. Se così fosse, potresti trovarti nella posizione ideale per elaborare un piano volto a rinnovare il tuo approccio ai dati nell’era del cloud moderno:

  • Outdated & mismatched technologies: Just like the characters on the show were stuck in the 1970s, your data management and protection strategy may be relying on a “frakenstack” of mismatched and outdated technologies that sprawled organically but are now stuck in time and are no longer effective in today’s modern multi-cloud world. It’s important to regularly review and update your technology strategy to ensure that your approach to data growth and retention is not only purposeful and effective, but also provides you powerful protection and controls from the best tools available.
  • Uncertainty around shared responsibility obligations with Cloud Providers and SaaS Applications: If you don’t have a solid understanding of what your obligations are to protect your data under the shared responsibility model, you could end up losing days, weeks, or even months of valuable insights in the event of a disaster situation. In the show, the characters often found themselves in sticky situations that could have been avoided with proper situational awareness & planning. The same is true for your organization’s off-prem data.
  • Insufficient access controls: Whether resulting from innocent human error, or malicious bad actors, your data management and protection measures can often be wide open to catastrophic incident if users have too large a sandbox to play in. Our crew of misfits in “That 70’s Show” often found themselves in trouble due to a lack of boundaries and rules. The same is true for your organization’s data. With proper access controls in place, your data is more protected, your risk profiler is smaller, and you can rest easy knowing that it’s that much harder to have a major incident due to unauthorized individual actions.
  • Lack of employee & org leader education: Just like the characters on the show needed guidance and direction, your employees and cross-functional partners need to be educated on best practices for data protection. Without proper education, your organization is at risk of data breaches and other cybersecurity threats. Do all of your cross-functional partners (HR, Sales, Operations, Dev Ops, etc.) understand the implications and limitations of native SaaS applications and cloud services? Do they have a trusted partner in the IT function to ensure that their workloads are secure and backed up to cover any gaps in the service provider’s shared responsibility model while simultaneously providing upline leadership a single view of all of their distributed corporate data across all platforms and form-factors?

Se la vostra organizzazione presenta uno qualsiasi di questi segnali, è giunto il momento di pensare a un aggiornamento della vostra strategia di protezione dei dati.

Just like “That 70’s Show” has stood the test of time, a solid data protection strategy can help your organization stay current and protect its sensitive information. Don’t get stuck in the past – take action to ensure your data is safe and secure.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Zero trust architecture is central to an organization’s security posture to mitigate cyberattacks, and the Defense Department recently released its Zero Trust Strategy and Roadmap1 on its plan to get the DOD to a Zero Trust architecture by 2027.2

A zero trust architecture provides the foundations for micro-segmentation of the IT landscape, access limited with the Least Privilege principle, and all communication to and between the micro-segments being authenticated, audited, and verified3. The underlying philosophy for zero trust is never assume trust, but continuously validate trust, so bad actors don’t get in. Companies, organizations and government agencies need to make sure that even users inside a network can’t do serious damage.

Flag Unusual Behavior

I principi dello Zero Trust garantiscono che l’accesso degli utenti sia continuamente convalidato e monitorato in termini di autenticazione e autorizzazione, con un controllo costante. Commvault si avvale di controlli di sicurezza quali l’autenticazione a più fattori per le attività amministrative quotidiane, i blocchi di privacy e la crittografia dei dati. L’accesso degli utenti può essere compartimentato, negando esplicitamente l’accesso a livello di CommCell, mentre si applicano ruoli a gruppi di risorse microsegmentati tramite configurazioni multi-tenant. I controlli Zero Trust contribuiscono a limitare la mobilità laterale interna per prevenire la perdita di dati e l’accesso non autorizzato agli stessi.

Apply Zero Trust Controls

Commvault semplifica l’applicazione dei controlli AAA basati sul modello Zero Trust grazie alladashboard “Security Health Assessment”. La dashboard offre una vista unica che consente di identificare i controlli, evidenziare i potenziali rischi all’interno dell’ambiente di backup e suggerire azioni interattive per applicare tali controlli.

Add Layers of Security

Per contribuire a rafforzare la resilienza della vostra infrastruttura dati, ilCybersecurity Framework del NISTsi concentra su cinque pilastri fondamentali per un programma di sicurezza informatica efficace e olistico. Prestare attenzione a questi pilastri può aiutare la vostra organizzazione a sviluppare una strategia completa di gestione dei rischi. Commvault ha integrato questi pilastri di sicurezza nel proprio software e nelle proprie politiche di protezione dei dati senza comportare un aumento dei costi di gestione. La piattaforma di protezione e gestione dei dati di Commvault comprende cinque livelli di sicurezza:

Identificare 

“Protezione”

Monitorare

Risposta

Ripristino

Il nostro sistema di sicurezza multilivello è costituito da una serie di Features, linee guida e best practice volte a gestire i rischi legati alla sicurezza informatica e a garantire la pronta disponibilità dei dati. Contribuiamo a proteggere e isolare i vostri dati, forniamo monitoraggio proattivo e avvisi e consentiamo ripristini rapidi. Tecnologie avanzate basate sull’intelligenza artificiale e sull’apprendimento automatico, tra cui gli honeypot, consentono di rilevare e segnalare potenziali attacchi nel momento stesso in cui si verificano, permettendovi di reagire rapidamente. Mantenendo i vostri backup al sicuro e garantendo il ripristino entro i tempi previsti dai vostri Accordi sul Livello di Servizio (SLA), potrete ridurre al minimo l’impatto di un attacco ransomware, riprendendo immediatamente la vostra attività (ed evitando di pagare costosi riscatti).

Immutability

Protecting and isolating your backup copies is critical for data integrity and security. Therefore, we have taken an agnostic approach to immutability. With Commvault, you do not need special hardware or cloud storage accounts to lock backup data against ransomware threats. If you happen to have Write-Once, Read Many (WORM)-, object lock- or snapshot-supported hardware (which Commvault fully supports), you can still use Commvault’s built-in locking capabilities to complement and layer on top of existing security controls. Commvault’s ability to support layered defenses for securing data sets against ransomware ensures that your organization benefits from a sound cyber recovery-ready architecture. Here are some elements to include in your immutability architecture:

  •  Access locks to isolate copy store against ransomware
  • Immutabilità con blocchi legati al ciclo di vita per ridurre i rischi, bilanciata con l’impatto sui consumi
  • Rete di isolamento con intercapedine d’aria e sistemi di controllo
  • Governance della configurazione a tutela da modifiche intenzionali o accidentali
  • Concurrent Recovery performance – reduce latency with due importance to speed and cost impact
  • Aggiornamenti automatici per garantire la massima attualità, semplificando la gestione e la manutenzione dell’infrastruttura di protezione dei dati
  • Alignment with the 3-2-1 data protection philosophy  (3 copies of data, 2 different media, 1 vaulted copy)

Learn more about Commvault’s immutable infrastructure architecture qui.

Cyber Deception Technology

Sebbene garantire la continuità operativa sia un elemento fondamentale di qualsiasi strategia multilivello, un solido approccio alla sicurezza comprende anche tecnologie di difesa proattive in grado di individuare e contrastare attivamente minacce sconosciute e di tipo “zero-day”.Metallic® ThreatWiseTMrivoluziona il panorama della protezione dal ransomware, combinando sofisticati sistemi di allerta precoce e intervento tempestivo con una protezione completa dei dati. Consente alle aziende di qualsiasi dimensione di neutralizzare gli attacchi silenziosi prima che causino danni, rilevando e deviando anche gli attacchi zero-day più furtivi, che eludono le tecnologie di rilevamento convenzionali e aggirano i controlli di sicurezza.

A Ransomware Strategy

You need a plan to remain steadfast against ransomware. Beyond simply adhering to zero trust principles and hoping for the best, the ultimate solution can manage and substantially reduce the impact of a ransomware attack. It can reduce costs for your organization by utilizing one centralized management platform, so security teams don’t have multiple product points to log in and out of. It can increase the visibility of your data through a single landscape to minimize complexity for your teams. And finally, it can protect what matters most by providing the broadest workload coverage and rapid recovery capabilities through a unified approach. For all of this to happen, a solution must embrace Zero Loss Strategy.

Become Less Vulnerable

The reality is your organization needs to be prepared and take proactive steps to protect your data and work with a provider who offers ransomware protection and recovery solutions. How prepared are you? Take ourfree risk assessmentto find out. Also, read oureBookon Understanding Team Roles and Responsibilities in Fighting Ransomware.

References
1. Dipartimento della Difesa degli Stati Uniti (DOD), Il Dipartimento della Difesa pubblica la strategia e la roadmap sullo Zero Trust, novembre 2022
2. C. Todd Lopez, DOD News, Il DOD definisce il percorso verso la sicurezza informatica attraverso l’architettura Zero Trust, novembre 2022
3.Commvault, Vidya Shankaran, Ransomware Defense in Depth – Best Practices for Security and Backup Data Immutability, October 2021

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

I’m so proud to announce the inspiring Vaulters who just won our FY’23 Q3 CEO Living Our Values Awards. 

Here at Commvault, our four values – we connect, we inspire, we care, we deliver – are always top of mind! 

This week we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work as they live our values every day. 

I’m so proud to announce our FY’23 Q3 CEO Living Our Values Award winners:

Christina Manning
, Direttrice delle operazioni finanziarie

Mathew Ericson
responsabile senior di prodotto

Jason Gerrard
, Direttore del reparto Ingegneria delle vendite

Parisa Bazl
, Direttrice dello sviluppo UX

Sam Hernandez
, Direttore della gestione delle strutture


Tutti questi vincitori rappresentano un esempio fonte di ispirazione e incarnano il vero significato di essere un Vaulter!

To learn more about what it’s like to work at Commvault, check out our sito dedicato alle carriere.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

La sfida odierna legata ai registri di audit

One major challenge customers face with audit logs is that they’re not aggregated in a central location that is fully immutable. SaaS applications specifically tend to have their audit logs kept within the SaaS application itself, oftentimes with only a 90-day history.

Ciò comporta la creazione di script complessi o l’esportazione periodica dei log da ciascuna applicazione per archiviarli in una posizione centralizzata, al fine di soddisfare gli obiettivi aziendali in materia di conformità e sicurezza.

This is a heavy lift on IT departments, and with hundreds of applications under management in any environment, it’s oftentimes not feasible to accomplish this completely. 

Consolidamento dei registri di audit con AWS CloudTrail Lake

Con il lancio di CloudTrail Lake, AWS ha semplificato la gestione dei log di audit provenienti da fonti disparate. CloudTrail Lake è un data lake gestito dedicato alla sicurezza e all’audit che consente alle organizzazioni di aggregare, archiviare in modo immutabile ed eseguire query sugli eventi registrati da AWS CloudTrail.

This can be done across different regions and accounts – and is backed by a 7-year default retention policy to help you meet compliance requirements.

I clienti possono importare e analizzare gli eventi in uno schema compatibile con AWS CloudTrailda Clumio, nonché da altre fonti di terze parti e non AWS, per ottimizzare le attività di auditing, le indagini di sicurezza e la risoluzione dei problemi operativi.

Sicurezza dei dati semplificata con Clumio e AWS CloudTrail Lake

AWS e Clumio hanno collaborato per realizzare questa integrazione per CloudTrail Lake, che consente di semplificare e ottimizzare il processo di consolidamento dei dati relativi alle attività.

Through the newly launchedPutAuditEvents API for AWS CloudTrail Lake, Clumio has created a simple integration to capture user activity information and events from your Clumio environment alongside the AWS systems you are protecting with Clumio.

Once the integration is enabled, you’ll be able to capture and store audit activity across various categories. This will allow you to easily answer many security and compliance-related questions across various categories such as:

  • Authentication– Was there a high volume of unsuccessful logins to the Clumio console, indicating a brute force entry attempt or an issue with your Single Sign On provider? 
  • User Management– When was a user added to the Development Organization in Clumio, and when were they given the backup Admin role?
  • Backups– When was a backup policy accidentally changed? This will help you quickly determine when a backup policy was changed or created to ensure you’re always meeting both long-term compliance requirements and maintaining any minimum required RPO’s (recovery point objectives).
  • Restores– Is someone browsing the CEO’s email history, or trying to recover Payroll information from a system backup? This activity is tracked even if a restore hasn’t been initiated.
  • S3 Protection Groups– When was a new S3 production bucket added to a protection group? Why was a bucket removed? 

Configurazione e architettura dei log di Clumio su AWS CloudTrail Lake

First, in Clumio, navigate directly to the Audit Report page. You’ll see a link to set up the integration in the upper right corner. You must have the Super Admin role to set up the integration.

Integrazione con AWS CloudTrail

Nella schermata successiva vedrai un ID esterno univoco relativo alla tua integrazione con CloudTrail. Copia questo valore; provvederemo poi a configurare direttamente su AWS la fase successiva dell’integrazione.

After logging into the AWS Console, navigate to CloudTrail, where you will find a new Integrations section under Lake.Click on the Add Integration button to configure the Clumio integration.

You’ll first need to give a name to channel that Clumio will use to send the audit logs data through, and then selectClumioas the source.

Next, we will need a place to deliver the Clumio audit logs and determine how long you would like to get the logs. You can either use an existing event data store or create a new one for this integration.

Next, we’ll configure the resource policy which is what will provide Clumio with a secure way to send the audit log data across the channel. This is where we will paste in the external ID we copied from the Clumio interface.

Lastly, apply any tags you may want to add to the resource and select Add Integration.

The integration is now set up; however, we have one final step. We need to copy the Channel ARN value and bring it back to Clumio, so we can complete the setup.

Once you add the Channel ARN value, click on Connect to CloudTrail

Verrà inviato un evento iniziale all’archivio dati di CloudTrail Lake, consentendoti di verificare la connettività. Da quel momento in poi, gli eventi di audit di Clumio verranno inviati regolarmente all’archivio dati di CloudTrail Lake.

Additionally, you’ll be able to monitor the health of the integration at any time through the Audit Log report.

Di seguito è riportato un elenco di tutte le categorie di eventi di audit che vengono inviate a CloudTrail nell’ambito di questa integrazione:

  • Autenticazione
  • Fonte dei dati
  • Le politiche
  • Protezione S3
  • Ripristino
  • Backup
  • Utenti
  • Unità organizzativa
  • Configurazione KMS
  • SSO/MFA
  • Modello CloudFormation

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

In the handful of months since I became Commvault’s first Chief Partner Officer, I’ve been reading the terrain, talking with our partners, and figuring out how we can better help them in the year to come. I’ve analyzed everything from program incentives to partner enablement and everything in between to plot our course. There is, however, one thing I didn’t consider. The intangible effect of being one of the coolest kids on the block.

For the 7th year in a row, Commvault has been named to CRN’s annual Cloud 100 list! Honoring the 100 Coolest Cloud Companies for 2023 across five key categories: infrastructure, monitoring and management, storage, software, and security, we rated among the Top 20 in the storage category based on CRN’s analysis.

To make the list, which is considered by most in the partner world as the trusted resource for solution providers looking for technology vendors best positioned to support their cloud product and services needs, Commvault had to prove its commitment to channel partners as well as demonstrate our innovation in the development of cloud-based technologies.

This wasn’t difficult for Commvault, as we’re a leader in data management, protecting data wherever it lives – whether on-prem, in the cloud, or in a hybrid cloud environment. We support the broadest range of workloads in the industry and most recently abbiamo esteso la nostra protezione cloud a Kubernetes, posizionandoci come “Outperformer” e “Leader” nelGigaOm’s Radar for Kubernetes Data Protection.

“In today’s remote-facing enterprise environment, cloud services have become the critical component needed to build comprehensive and secure IT solutions,” said Blaine Raddon, CEO, The Channel Company. “The companies selected for this year’s Cloud 100 list have shown time and again that they support partners in the ever-evolving cloud computing business with state-of-the-art products and services. Our team commends those on this year’s list and looks forward to watching them drive positive change in the cloud domain throughout the year.”

CRN’s Cloud 100 list will be featured in the February 2023 issue of CRN magazine and online at www.crn.com/cloud100.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

La Settimana della privacy dei dati è un evento annuale che mira a sensibilizzare l’opinione pubblica sull’importanza della privacy e della sicurezza dei dati. L’obiettivo della Settimana della privacy dei dati è quello di informare i singoli cittadini e le organizzazioni sull’importanza di proteggere i dati personali e di fornire loro gli strumenti e le risorse necessari per farlo in modo efficace.

We’ve brought together three opinion leaders to discuss the key data privacy challenges that face businesses around the world and how to overcome them.

Bill Mew, Data Privacy Champion and CEO of the Crisis Team is joined by Jakub Lewandowski – Global Data Governance Officer, Commvault and Thomas Bryant – Product Marketing Director, Commvault as they discuss;

  • Tendenze e sfide attuali in materia di privacy e sicurezza dei dati
  • Leggi e normative relative alla privacy dei dati, quali il Regolamento generale sulla protezione dei dati (GDPR) nell’Unione Europea e il California Consumer Privacy Act (CCPA) negli Stati Uniti, nonché il DORA e la NIS2
  • Best Practices for protecting data – including a modern (and tested) data protection strategy and conducting regular risk assessments
  • The current state of Data Privacy policy and legislation compliance/ enforcement  

Scopri di più su questi argomenti nella nostra serie di articoli del blog dedicata alla Settimana della privacy dei dati, ora disponibile

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

La Giornata mondiale della privacy, che si celebra ogni anno il 28 gennaio, serve a ricordare l’importanza della protezione dei dati personali nell’era digitale odierna. Con il progresso tecnologico e la crescente diffusione delle informazioni personali online, sia i singoli individui che le organizzazioni devono adottare misure adeguate per salvaguardare i propri dati.

New regulations, such as DORA (Digital Operational Resiliency ACT), mandate that organizations create plans for risk management, incident reporting, and resilience testing. These regulations outline policies for data management, including encryption, data locality, and data lifecycles. Gartner prevede, “by 2023, 65% of the world’s population will have its personal data covered under various privacy regulations, and companies need flexible solutions that can adapt to the multitude of legislation.” Navigating this complex environment can be challenging for both individuals and companies.

Data Privacy is protecting personal information and giving individuals control over how their data is collected, used, and stored.  On the other hand, data protection refers to the technical and organizational measures put in place to protect data (including personal data) from unauthorized access, use, alteration, or destruction. Data protection encompasses Data Privacy and other areas, including backup & recovery, disaster recovery, data security, and a host of other areas.

To help address that complexity, let’s spend some time reviewing the Top 10 topics to consider when managing Data Privacy and Data Protection.


1.Data Protection Strategy
2.Crittografia
3.Multi-Person Authentication
4.Archiviazione Immutabile
5.Sovranità dei dati
6.Data Governance & Discovery
7.Classification of data
8.Conservazione dei dati
9.Resilience plan testing & incident response
10.Risk Assessment

1. Data Protection Strategy

Organizations should start by creating or updating a Data Privacy, Backup & Recovery, and Disaster Recovery plan as part of an overall data protection strategy. There are many facets to a reliable data protection plan and how it specifically relates to protecting the private data your customers have shared with your organization.

2. Encryption

La crittografia è una caratteristica fondamentale della protezione dei dati e della tutela dei dati personali. Consentire la crittografia dei dati sia inattivi che in transito aiuta a prevenire l’accesso non autorizzato alle informazioni personali. Ciò è particolarmente importante per le organizzazioni che gestiscono grandi quantità di dati personali, come gli operatori sanitari e gli istituti finanziari. I dati non risiedono più solo nei nostri data center aziendali, poiché la maggior parte delle organizzazioni dispone di uno o più cloud pubblici in cui sono archiviati carichi di lavoro e dati. Garantire la sicurezza dei dati tramite la crittografia per tutto il loro ciclo di vita contribuisce a mitigare il rischio di potenziali attacchi.

3. Multi-person authentication

Oltre a proteggere i dati tramite la crittografia, le organizzazioni devono salvaguardare i propri sistemi dagli attacchi malevoli. L’utilizzo dell’autenticazione multipla (MPA) nei sistemi di protezione dei dati garantisce che le operazioni critiche richiedano approvazioni multiple da parte di utenti preventivamente autorizzati. Spesso sottovalutato, questo è uno dei modi più semplici per impedire operazioni quali l’esfiltrazione o la cancellazione dei dati.

4. Immutable Storage

L’archiviazione immutabile consente di scrivere dati, privati o di altro tipo, che non possono essere ulteriormente modificati o cancellati. L’impossibilità di manomettere o alterare i dati garantisce il mantenimento dell’integrità degli stessi. I requisiti relativi all’archiviazione immutabile stanno rapidamente diventando una componente standard delle normative sulla governance dei dati, come il GDPR, l’HIPAA e altre. Se abbinata alla MPA, questa soluzione consente di creare livelli di archiviazione dei dati altamente sicuri, ideali per la conservazione di dati riservati e privati.

5. Data Sovereignty

Organizations should consider regulations surrounding private data storage when developing a data protection strategy. This includes the location of data storage and compliance with regulations regarding data sovereignty. For example, a cloud-based workload on GCP in Europe or containing EU citizens’ data must comply with EU regulations. Anywhere that private data may reside, even if temporary, may be required to be in a specific region under regulatory requirements. Commvault helps to address this concern in its latest release, allowing customers to select which specific region they will leverage for snapshot & data protection storage vs. multiple regions that cost more and may have different regulatory requirements.

6. Data Governance & Discovery

In a recent survey, il 57% dei CISO admit they don’t know where some or all their data is or how it is protected! As this amount of private data continues to grow, the sheer number of regulations expands exponentially, and we are confused about what and how we should protect our data.  As a result, organizations need to understand their data, where it is, and what is at risk.  Being able to prioritize data based on your organization’s policies, priorities, and applicable regulations is critical to protecting the data. You cannot protect what you don’t know about!

7. Classification of data

Sapere quali dati esistono e dove si trovano è solo una parte della soluzione. Le organizzazioni devono valutare quali dati siano dati privati dei clienti, critici per l’azienda, ecc., in termini di importanza per la propria attività e per i propri clienti. Proteggere solo i dati on-premise potrebbe significare trascurare alcuni dati critici dei clienti presenti nella vostra soluzione CRM basata su SaaS. A tal proposito, per garantire la protezione dei vostri dati dovete affidarvi a soggetti diversi dal vostro fornitore SaaS o persino dai vostri provider di cloud IaaS. Questi ultimi possono fornire alcuni SLA e un certo livello di ridondanza, ma ciò non sostituisce un solido piano di protezione dei dati. La gestione della classificazione dei dati non è un’operazione da svolgere una tantum, dato che il volume dei dati cresce ogni anno in modo esponenziale.

8. Retention

It is paramount to know what data exists and how important it is, but how long does it stay relevant? This is a hard question to answer for most organizations and one that can be seen every year when buying ever-increasing storage systems to house corporate data. The ability to assign an expected lifespan to data can significantly impact your organization’s bottom line AND protect your customers’ private data. Having systems in place to automatically find, classify, and set retention will reduce the likelihood of data sprawl, reduce the amount of time to recover unused data, and reduce costs. If you are looking for a great place to start efficiently managing your governance, risk, and compliance, read through Commvault’s unique approach to gestione unificata dei dati.

9. Resilience plan testing & incident response

Resilience plan testing often referred to as a runbook, is an often-overlooked area of a data protection strategy. Creating or updating an outdated plan can take time and effort. Partnering with solution providers or strategic data protection companies with experience in creating a plan can significantly reduce the time it takes to get current. While it may be trivial to think runbooks are passe, I’ve found that when an actual DR event or ransomware attack hits, they are the GO-TO asset you want in your arsenal of tools. A regular cadence of updates creates an organizational posture that is ready to face data security threats head-on.

10.  Risk Assessment

As mentioned with runbook, consider working with strategic vendors to perform a risk assessment semi-annually or annually. Scheduled reviews can help build the muscle memory for a solid data protection and data privacy mindset. The benefit of working with well establish data protection & data privacy vendors is they are up to date on the latest security threats and mitigation strategies.

By implementing this list of considerations and routinely refreshing your resilience plan, you can be confident that personal information is secure and compliant with the latest privacy regulations. If you aren’t sure where to start but need help from a company that can answer all these questions.

Commvault è qui per aiutarti! Aggiungiamo continuamente nuove funzionalità, tra cui i nostri ultimi miglioramenti in materia di sovranità dei dati a livello regionale per le istantanee di backup, le certificazioni di settore, le funzionalità di archiviazione immutabile e molto altro ancora.

Head over to our community to Per saperne di più or take a test drive today https://www.commvault.com/request-demo

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Happy 2023 Data Privacy Week!

Just as everyone started to get more or less cozy with the regulatory landscape in data privacy/protection and individuals and businesses learned to navigate the shallow waters of data subject requests, risk management, and impact assessments – BOOM – another tidal wave of regulatory requirements and new challenges rushed in!

2023 is the perfect moment to start internalizing new acronyms (get ready for #NIS2, #DORA, #DPDPB, #CPRA, #CCPA, #CPA, #CDPA, #UCPA, #VCDPA, #ADPPA, #PrivacyPenaltyBill) and legislative acts they stand for.

L’obiettivo alla base delle imminenti modifiche è quello di rafforzare e migliorare la sicurezza informatica delle varie organizzazioni e gestire in modo più efficace i rischi informatici in continua evoluzione.

Ecco una panoramica generale di alcuni sviluppi giuridici in tutto il mondo:

  • EU – Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2)
  • EU – Regulation on digital operational resilience for the financial sector (DORA)
  • US – State & Federal privacy laws
  • India – Digital Personal Data Protection Bill (DPDPB)
  • Australia – Privacy Penalty Bill & overhaul of the Privacy Act 1988

NIS2

According to ENISA, the general spending on cybersecurity is 41 % lower by organisations in the EU than by their US counterparts. With the arrival of NIS2, this ratio is expected to shift to cover this enormous gap at least partially. Conservative estimates are that NIS2 entry in force will translate into a ~22% increase in ICT spending over a 3–4-year period.

La direttiva NIS2 è stata pubblicata poco prima della fine dell’anno e gli Stati membri dell’UE hanno ora 21 mesi di tempo per recepire nella legislazione nazionale i requisiti e i meccanismi in essa descritti. La direttiva NIS del 2016 – nonostante alcune lacune – ha costituito una pietra miliare per il potenziamento delle capacità degli Stati membri in materia di sicurezza informatica. Ora, la NIS2 amplierà l’ambito di applicazione e l’elenco delle organizzazioni interessate. Si prevede che ben 160 000 organizzazioni saranno soggette a questa nuova normativa, tra cui i fornitori di servizi digitali (piattaforme e servizi di data center), i fornitori di reti e servizi di comunicazione elettronica, il settore manifatturiero, quello alimentare e il settore pubblico.


NIS2 aims to strengthen cybersecurity postures by, amongst other: improving cybersecurity governance, addressing the security of supply chains, streamlining reporting obligations (early warnings/shortened notification periods), and introducing more stringent supervisory measures and stricter enforcement requirements.

Cosa puoi fare in questo momento?

  • First, try to understand which obligations will apply to your organization and in which compliance bucket your organization will fall into: “Essential Entity,” “Important Entity,” or maybe “other.”
  • Successivamente, verifica se è possibile creare sinergie e sfruttare le misure tecniche e organizzative già implementate nel corso di precedenti iniziative di conformità (ad esempio, GDPR, NIS1, ecc.)
  • Iniziate a cercare i partner giusti in grado di supportare adeguatamente i vostri sforzi di conformità. Coinvolgete i vostri fornitori nella discussione dell’approccio più adatto alla vostra organizzazione.
  • Infine, ma non meno importante, iniziate a pianificare un aumento della spesa per colmare eventuali lacune residue. La mancata conformità potrebbe comportare sanzioni amministrative fino a 10 milioni di euro o fino al 2% del fatturato annuo globale totale dell’organizzazione.


DORA

DORA aims to achieve “a high common level of digital operational resilience,” mitigating cyber threats and ensuring resilient operations across the EU financial sector. It will become directly applicable from Jan 17th, 2025. It will impact the financial sector (banks, insurance companies, investment firms) and its ICT providers (i.e., cloud platforms) – roughly around 22 000 organizations.

I nuovi requisiti imposti dal DORA si tradurranno, in sostanza, nella revisione e nell’aggiornamento delle pratiche di gestione del rischio. I clienti del settore finanziario dovranno trasferire il maggior numero possibile di rischi normativi ai fornitori di ICT oppure adottare diverse strategie di mitigazione del rischio. In ogni caso, i fornitori di ICT dovranno essere in grado di garantire il rispetto dei requisiti del DORA. L’intero settore dovrà inoltre rivalutare i rapporti contrattuali con i fornitori. Il DORA introdurrà requisiti per i contratti tra le società finanziarie e i loro fornitori di ICT critici, tra cui l’ubicazione in cui vengono trattati i dati, le descrizioni degli accordi sul livello di servizio, gli obblighi di rendicontazione, i diritti di accesso e le circostanze che potrebbero portare alla risoluzione del contratto.

In a separate post – Commvault’s Product Team will perform a more technical deep-dive into DORA’s requirements related to detection (art. 10), response and recovery (art. 11), and backup (art. 12).


US data privacy laws – CPRA/CCPA, CPA, CDPA, UCPA, VCDPA, ADPPA

As of January 1st, 2023, California Privacy Rights Act (CPRA) amendments to the California Consumer Privacy Act 2018 went into effect. Many temporary exemptions in place expire, imposing additional obligations on companies dealing with California residents’ personal information, e.g., regarding employment-related personal data, opt-out from selling personal information.

2023 is also the year when the Colorado Privacy Act (CPA), The Connecticut Data Privacy Act (CDPA), The Utah Consumer Privacy Act (UCPA), and The Virginia Consumer Data Privacy Act (VCDPA) will become effective. Legislative fragmentation risk is imminent and substantial, and this is the kind of risk that caused the European Union to harmonize the regulatory approach. Let us see whether the same will be true in 2023 in the case of the American Data Privacy and Protection Act (‘ADPPA’) – a proposal for a federal and general data privacy law.

India – DPDPB

Indian legislators plan to introduce a very ambitious Digital Personal Data Protection Bill (DPDPB) this year. When enacted, long-awaited legislation will undoubtedly impact all kinds of organizations due to India’s role as a tech powerhouse and a global outsourcing hub.

Australia – Privacy Penalty Bill & overhaul of the Privacy Act

Australian authorities announced yet another complete overhaul of the Privacy Act dated 1988. The current legislation was summarized as “out of date and not fit for purpose in the digital age.”

Nel frattempo, sempre nel 2022, l’Australia ha approvato il “Privacy Penalty Bill”, che ha inasprito le sanzioni in materia di privacy portandole a livelli paragonabili a quelli introdotti dal GDPR (fino a 50 milioni di AUD) e ha ampliato i poteri normativi dell’Ufficio del Commissario australiano per l’informazione (OAIC) e dell’Autorità australiana per le comunicazioni e i media (ACMA).

Summary

Il tempo che scorre inesorabile per la conformità ha appena ricominciato a ticchettare. I team interfunzionali, composti da professionisti dei settori IT, conformità, privacy, legale e da analisti aziendali, dedicheranno molto tempo all’analisi dell’impatto della valanga di novità legislative emerse alla fine dello scorso anno e che si concretizzeranno nel corso del 2023.

Tenete presente che gli sviluppi legislativi qui presentati potrebbero essere più esaustivi. Potete stare certi, tuttavia, che diventeranno argomenti di discussione ricorrenti non solo nel 2023, ma anche negli anni a venire.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Nell’ambito di una serie di tre articoli dedicati alla Giornata della protezione dei dati 2023 (si vedano gli articoli correlati diJakub LewandowskieThomas Bryant ), Bill Mew argues that there is a real enforcement problem – it’s like the ‘Wild West’ out there.

Le politiche, i quadri normativi e le regole sono utili solo se vengono rispettati, proprio come le normative e le leggi non hanno alcun senso se non vengono applicate. Il problema nel campo della protezione dei dati e della sicurezza informatica è che, laddove le regole dovrebbero essere applicate, vengono spesso ignorate, e laddove sono state introdotte delle leggi, occorre garantirne una maggiore applicazione.

I CISO (Chief Information Security Officer) hanno un compito ingrato. Il personale è solitamente riluttante a rispettare le misure di “igiene informatica” che un CISO cerca di far applicare, ma quando la loro mancanza di disciplina porta a una violazione, questi colleghi sono fin troppo pronti ad attribuire la colpa al CISO. Come se non bastasse, mentre ci sono normative costose e complesse da rispettare e regole rigide sulla segnalazione delle violazioni, le autorità, lungi dall’aiutare a gestire eventuali incidenti o a catturare i veri criminali, si limitano a utilizzare le segnalazioni per valutare l’assegnazione delle multe.

Functional, Cultural Mismatch

Se interpellati, la maggior parte dei dipendenti concorderebbe sul fatto che le minacce informatiche rappresentano un problema significativo, ma nel loro lavoro quotidiano si concentrano su indicatori di ROI (ritorno sull’investimento) incentrati sui ricavi o sui profitti. Sono proprio questi gli indicatori in base ai quali vengono valutate le loro prestazioni individuali e di reparto e su cui si basano le politiche di incentivazione a livello aziendale.

The CISO is instead focused on return on risk (ROR). Based on the allocated budget and the organisation’s risk appetite, the CISO focuses on maximising security and minimising risk.

The mismatch between the CISO’s ROR orientation and just about everyone else’s ROI orientation can put the CISO at odds with the rest of the management team. They may not only become isolated (what I term CISOlation) but can also be a scapegoat when things go wrong – even when warnings are ignored.

Perverse regulatory incentives

In an accompanying article, Jakub Lewandowski [LINK] has explored the raft of new privacy and cybersecurity laws expected to add to a considerable regulatory burden. The problem is that regulation without enforcement is not just pointless but counter-productive. After all, only responsible companies will comply with these regulations, and for them, it represents a cost or compliance tax. Meanwhile, irresponsible ones often choose not to abide by the rules. If they believe that there is little or no risk of enforcement, then this is a cost-saving and risk-free source of competitive advantage.

La mancata conformità è un fenomeno diffuso e proviene dai vertici aziendali, come dimostrano i frequenti titoli dei giornali relativi a incidenti relativi ai dati che coinvolgono le Big Tech o alle multe loro inflitte. Tali multe non sembrano avere un effetto deterrente, ma vengono invece considerate un costo aggiuntivo di gestione da parte delle Big Tech e di molte altre aziende che hanno avuto la sfortuna di subire un incidente relativo ai dati.

Again, responsible firms that did their best to take reasonable measures but were unfortunately unable to prevent mistakes or attacks run the risk of being fined once they notify the local regulator. Meanwhile, irresponsible ones who choose not to comply will simply avoid reporting incidents and attempt to cover them up instead to avoid fines. Fines have, therefore, become more of a indicatore in ritardo delle disgrazie subite dalle aziende responsabili rather than of misbehaviour by irresponsible ones.

Record of Regulatory Inaction

Most BigTech firms, attracted by a favourable tax regime, have opted to base their European headquarters in Ireland. The local regulator, DPC Ireland, is therefore responsible for ensuring that they comply with GDPR and other such regulations. Whether down to inadequate funding, reluctance to rock the boat, or simply out-gunned and out-lobbied by the BigTech firms, DPC Ireland has been seen as ineffective in holding them to account.

In one notable case, measures it failed to take against Facebook were eventually resolved in the European High Court under the Schrems I and Schrems II rulings. When it still failed to take action and apply these rulings, DPC Ireland was sanctioned by the European Parliament in a voto di 451 a 1. Quando ulteriori pressioni da parte delle autorità di regolamentazione del resto d’Europa l’hanno costretta, dopo un ritardo di due anni, a intervenire, la sanzione inflitta a Facebook era talmente bassa da dover essere aumentata (di dieci volte) su insistenza delle altre autorità di regolamentazione.

The EU Ombudsman Emily O’Reilly eventually opened an inquiry into the European Commission’s monitoring of how data protection rules are applied in Ireland. Eight months later, the Irish Council of Civil Liberties (ICCL) criticised the EU for its continued failure to properly monitor Ireland’s GDPR enforcement while “the fundamental rights of all Europeans hang in the balance.” There are now moves afoot to strip Ireland of its responsibility for regulating the BigTech firms and centralise such enforcement instead.

Ineffective Global Policing

Meanwhile, the number and sophistication of cyber-attacks are increasing exponentially, as is the cost of remediation. The World Economic Forum (WEF) has recently not only called for more widespread use of cybersecurity ‘fire drills’ to test cybersecurity and incident response capabilities but is also championing the need for global rules to crack down on cybercrime.

Si stima che i danni causati da tutte le forme di criminalità informatica, compresi i costi di Recovery e risanamento, abbiano raggiunto un totale di 3.000 miliardi di dollari nel 2015 e di 6.000 miliardi di dollari nel 2021, e che potrebbero arrivare fino a 10.500 miliardi di dollari all’anno entro il 2025.

Cyber insurance isn’t the answer. Rapidly increasing premiums mean that it is out of reach to most buyers, but even those who can afford it often find it’s not worth it. At the same time, cyber insurance cannot be expected to cover systemic problems, and in any case, it has the perverse effect of potentially making bad problems even worse.

While almost all nations have signed up for United Nations agreements on combatting crime, including quella informatica, some nations turn a blind eye and instead provide safe havens for cybercriminals to operate from. While most quella informatica originates from countries like Russia, Iran, or North Korea, such activities are not confined to these rogue nations and continue closer to home. In addition, countries like China have significant espionage operations, and the United States is responsible for a great deal of global mass surveillance – all of which contravenes GDPR and a host of other laws.

We need to start with mandatory data breaches and cyber theft reporting. This has begun in the US with 2022’s il “Cyber Incident Reporting for Critical Infrastructure Act” and in the EU with 2018’s la Direttiva sulla sicurezza delle reti e dei sistemi informativi. Still, there are also a numerose altre normative that mandate telecom payment services, medical device manufacturers, and critical infrastructure providers to report breaches.

Once we have better data on the problem, we can focus on improving international investigation, prosecution, and adjudication efficiency and effectiveness. The United Nations Office on Drugs and Crime is promoting a Cybercrime Programme which has the following aims:

  • Maggiore efficienza ed efficacia nelle indagini, nel perseguimento penale e nel giudizio dei reati informatici, in particolare lo sfruttamento sessuale e gli abusi sui minori online, nel rispetto di un solido quadro di riferimento in materia di diritti umani.
  • Una risposta efficiente ed efficace a lungo termine da parte dell’intero governo alla criminalità informatica, che comprenda il coordinamento a livello nazionale, la raccolta di dati e quadri giuridici efficaci, al fine di garantire una risposta sostenibile e una maggiore deterrenza.
  • Rafforzamento della comunicazione a livello nazionale e internazionale tra il governo, le forze dell’ordine e il settore privato, con una maggiore consapevolezza da parte del pubblico dei rischi legati alla criminalità informatica.

These are laudable goals. However, we are a long way from victims of crime being able to pick up the phone to police at the local, national, or international level with any expectation of getting either practical assistance or justice. The reality is that when it comes to cybercrime, aside from private sector incident response specialists, you’re on your own.

  • Il personale adotta raramente misure adeguate in materia di sicurezza informatica
  • Le autorità di regolamentazione non agiscono in modo proattivo nell’individuare e contrastare le violazioni
  • I criminali stanno acquisendo sempre più sicurezza, aggressività e sofisticazione
  • La polizia non è in grado di intervenire contro i criminali che operano da luoghi sicuri
  • E i CISO finiscono per essere il capro espiatorio di turno quando le cose vanno male

In this ‘Wild West’ environment, there isn’t any cavalry going to the rescue, so you are expected to be adequately armed and ready to defend yourself. Take hints from Thomas Bryant’s article and learn how to deal with it best. There is no substitute for getting your cybersecurity and incident response right.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

As part of our “Get to know your customers day” series, we’re taking a deeper look at Swinerton Inc, a large national construction company who is pursuing a cloud data management program to drive versatility, sustainability and to free up company resources.

IT Manager, Brandon Marrott gives an insight into Swinerton’s data modernization journey which includes cloud transformation and embracing SaaS flexibility.  He also describes operating a hybrid cloud environment through the need to retain a number of company data assets on prem and how Swinerton manages their entire data estate, including SaaS, with Commvault.

https://play.vidyard.com/U5fZTkcgxdb7v9we3WJghp

What does it mean to go to the cloud?

Selecting the right cloud transformation partner

https://play.vidyard.com/oUYbtkBhyzYRoVibhsaWGm
https://play.vidyard.com/zwLtwiwBcsPG15DN2u5L8L

Superare le sfide e gestire in modo flessibile un patrimonio di dati SaaS in continua crescita


Faced with increased pressures, including an uncertain economic environment, IT teams are constantly finding ways to reduce costs or increase overall efficiency – all while supporting an evolving data environment.

Scopri altri esempi di come i clienti Commvault utilizzano servizi di protezione dei dati moderni e innovativi, tra cui il nostro portafoglio DPaaS Metallic, per raggiungere i propri obiettivi di trasformazione digitalehttps://www.commvault.com/digital-transformation-changes-everything-when-it-comes-to-data.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Dal raggiungimento degli obiettivi di sostenibilità alla ricerca di maggiore efficienza, il tutto sostenendo l’innovazione, i team IT avranno un ruolo fondamentale da svolgere nel 2023.

Dai un’occhiata alla nostra raccolta delle priorità IT dei partner e dei clienti per il 2023 e facci sapere cosa ne pensi sui social media.

Alan Atkinson, Chief Partner Officer – Concentration on highest value projects


2023 will continue to be challenging for companies from an economic perspective, especially those that are neither profitable nor public – leading many organizations to seek opportunities for cost reductions.

Ci saranno inevitabilmente tagli e, in ultima analisi, alcuni fallimenti; inoltre, partner e clienti saranno restii ad adottare soluzioni da fornitori che non abbiano un percorso chiaro da seguire. Questo, unito alle varie pressioni inflazionistiche, richiederà ai partner di concentrarsi sulla realizzazione dei progetti di maggior valore. Il ransomware, la migrazione al cloud e la trasformazione digitale rimarranno priorità che riceveranno finanziamenti, mentre altre aree di attività saranno probabilmente messe in secondo piano. Il consolidamento sarà fondamentale per rispondere a queste esigenze. Partner e clienti non cercheranno un numero maggiore di fornitori, ma piuttosto fornitori in grado di offrire più soluzioni. Punteranno su investimenti più consistenti e mirati, allineandosi con fornitori che offrono una copertura più ampia e un supporto in modelli di erogazione economicamente vantaggiosi.

Darren Yablonski, Sr. Director, Sales Engineering, Canada, U.S. SLED, LATAM – Cyber Security, AI and Regulation


A top, if not the top IT priority for organizations in 2023 will most certainly be cybersecurity. Significant amounts of IT budget spend will be allocated and invested in technologies to prevent, detect and recover from inevitable cyberattacks not if, but when they occur. As cloud adoption in a SaaS (Software as a Service) model continues to proliferate the market, organizations will leverage solutions that provide proven piece of mind knowing their data is safe and recoverable in a timely fashion. Trust will be given to organizations that can clearly articulate cybersecurity best practices that align to a customer specific use case and objectives.

Continuing on the theme of cybersecurity, emerging technologies and trends will be inclusive of both AI (artificial intelligence) and automation. Organizations typically have predictable network and data usage patterns. As data continues to grow exponentially within the realm of the “internet of things” and those patterns deviate within a network or data repository, humans simply cannot keep track of anomalies in real time. As such, Security Information and Event Management (SIEM) solutions that collect, process, analyze and report threats in an expedited and accurate manner will continue to become more ubiquitous. Integration and adoption of such technologies within a zero-trust architecture will be of greater top of mind for CISO’s and security specialists as the years progress.

Come accennato in precedenza, il flusso dei dati continuerà a spostarsi dalle infrastrutture on-premise alle applicazioni cloud che utilizzano un modello SaaS, a seconda del caso d’uso. Le soluzioni ibride, sia on-premise che basate sul cloud, continueranno a esistere per diversi anni, poiché le aziende cercheranno di bilanciare e garantire l’immutabilità dei dati e la velocità di Recovery nel modo più efficiente in termini di costi. Man mano che le nuove normative relative alle pratiche di sicurezza dei dati continueranno a evolversi, si evolveranno anche le soluzioni di gestione dei dati che forniscono una serie completa e esaustiva di strumenti per affrontare tali pratiche. In sintesi, poiché il panorama delle minacce nel settore IT continua a crescere e ad aumentare in complessità, le organizzazioni che cercano di affrontare questa complessità per i propri clienti si concentreranno sullo sviluppo di soluzioni software più diversificate e ampie, in grado di semplificare la recuperabilità e la precisione dei report, indipendentemente da dove risiedano i dati.

Katharine Colucci, Associate Solutions Marketing Manager – Corporate Sustainability


The IT organization will take steps to lower the carbon footprint of its data to support corporate sustainability goals. Adopting more sustainable business practices has become a strategic priority of organizations worldwide as they become increasingly aware of how important sustainability efforts are to the success of the business. In fact, Gartner predicts that by 2025, 50% of CIOs will have performance metrics tied to the sustainability of the IT organization. IT teams will need to take steps to reduce the carbon footprint of their data through responsible data management practices, to support overall corporate sustainability goals. Responsible data management practices make it possible to control the total amount of data produced, thereby reducing the energy needed to create, store, manage and protect it.

Commvault supports our customers wherever they are on their sustainability journey, providing opportunities to mitigate their carbon footprint while reducing costs and maximizing the efficiency and security of their data management practices. To learn more about how Commvault is helping customers take a sustainable approach to intelligently manage data, visit Commvault.com/ corporate-sustainability.

Gartner, stai pensando in modo troppo limitato alla tecnologia sostenibile?, settembre 2022

Jason Gerrard, Director, International Sales Engineering – AI/ML and Automation


Con il progressivo invecchiamento della popolazione, diventa sempre più difficile per le aziende reclutare nuovi talenti nel settore IT. Di conseguenza, il divario di competenze si sta ampliando e le aziende sono costrette a fare meno affidamento sulle persone per promuovere l’innovazione, la crescita e la stabilità, orientandosi verso un mondo più automatizzato, in cui la tecnologia possa colmare tale divario.

Questa trasformazione è già ben avviata e molte organizzazioni stanno sfruttando ambienti, come il cloud pubblico, per automatizzare molti dei processi che storicamente richiedevano l’intervento umano. Le tecnologie di orchestrazione e automazione possono contribuire in modo significativo a questa transizione integrando l’intelligenza artificiale e l’apprendimento automatico nelle loro soluzioni. Queste tecnologie sono state ampiamente adottate nel corso dell’ultimo anno per contribuire a colmare il divario di competenze, ma con i costi destinati a salire a livelli senza precedenti, continueranno a crescere nel 2023 come soluzione per ridurre i costi mantenendo i sistemi operativi.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

As the world enters the post pandemic period of heightened digital transformation, new challenges have emerged which businesses (and their data) will have to navigate.  In the face of increased economic pressure, digital transformation and cloud initiatives are set to focus on creating efficiencies through costs and resources.

To help organizations steer through these (potentially) choppy waters, we’ve gathered thoughts from some Commvault key opinion leaders.  

Param Kumarasamy, VP, Product Management
– Resilience and Cloud Native Technologies

Nel 2023, l’incertezza economica continuerà ad aumentare in un contesto caratterizzato da una crescita massiccia dei dati e da risorse IT sempre più limitate. Ciò porterà le aziende a spostare l’attenzione dalle iniziative di trasformazione verso la resilienza. Prevediamo che i dirigenti adotteranno un approccio difensivo per affrontare le problematiche note e ottenere di più con risorse limitate. Le iniziative di resilienza IT favoriranno una maggiore adozione di tecnologie di IA/ML, quali l’automonitoraggio e la gestione delle risorse IT, nonché l’automazione e l’orchestrazione delle attività IT sia in ambiente on-premise che nel cloud.

Negli ultimi anni abbiamo assistito a una crescita straordinaria delle iniziative di cloud ibrido e multi-cloud nelle aziende. Nel 2023, prevediamo che le organizzazioni puntino ancora di più sulle tecnologie cloud native. Analogamente al passaggio dall’ambiente fisico alla virtualizzazione, vedremo le aziende passare dalle tecnologie di virtualizzazione per adottare sempre più Kubernetes, container e DevOps sia nelle implementazioni on-premise che nel cloud.

Reza Morakabati, Chief Information Officer –
CIOs need a holistic approach to data protection

Con l’avvicinarsi del 2023, i CIO dovranno adottare un approccio olistico e contestualizzato nella valutazione della propria mappa degli obiettivi di archiviazione dei dati. Le aziende potrebbero optare ciecamente per il cloud o per soluzioni on-premise sulla base di raccomandazioni generiche, ma la decisione dovrebbe dipendere in larga misura dall’utilizzo che verrà fatto dei dati.

CIOs need to focus on five main areas – scalability, flexibility, agility, security, and cost. Cloud for instance checks off many of these boxes, but could account for a significant portion of a CIO’s operating budget, whereas data center investments are mostly allocated to capital budgets. It is critical for CIOs to look at the full picture.

Matt Tyrer, Senior Solutions Marketing Manager
and Head of Competitive Intelligence – Data Diversification and Mobility 

The number of applications, clouds, platforms, utilities, tools, and various other data workloads and locations to run them is multiplying. Just to frame this a little let’s just look at one of the bigger providers out there, AWS.  Prior to AWS reInvent in late November 2022, they had over 200 applications and services within their catalog for customers to leverage and build on. They then introduced at their annual event another 50+ including many highly specialized databases and tools.

That’s a lot, and that’s just one vendor. With this growing diversification is my prediction, and one seconded by Gartner at their recent IT Infrastructure, Operations, and Cloud Strategies Conference in Las Vegas just a few weeks ago: 

The applications and workloads you are running today, and where you are running them, will not be the applications and workloads or places where you will be running them in tomorrow. 

The impact here is equally diverse.  

  • Skills Shortages: The constant shifting of data workloads will mean that most organizations will not have the in-house skills to keep up with the changing platforms and services they are depending on to drive their business forward and remain competitive. 
  • Data Protection/Management Challenges: It is already a daunting task ensuring that all of your data sources are not only protected but secured from the growing threats to them. Many businesses are stuck relying on multiple niche or point product solutions in order to tackle this challenge because there simply are not many options out there that can cover it ALL. Now imagine all of those data sources and applications moving and changing on a regular basis, most tools today just can’t keep up and this will lead to overlapping siloes adding complexity, cost, and overall risk to the business. 

To address this, businesses will be turning more and more to partners who provide the broadest possible spectrum of support for data protection and data management to ensure that as their data platforms change, their solutions not only can keep pace, but already provide the needed coverage. This will enable organizations to adapt and transform with significantly less friction as they don’t need to revisit data protection and management with each step. This also supports a number of other initiatives such as sustainability and ESG as it enables the consolidation of tools and reduction of infrastructure and consumption of other resources such as the power and water that fuel that infrastructure. 

Hope D’Amore, Solutions Marketing Manager
– Cloud-Native will become the norm

La trasformazione digitale è necessaria per mantenere un livello di innovazione e competitività sul mercato. Se a ciò si aggiunge un contesto economico turbolento e incerto, le aziende dovranno concentrarsi sulla gestione dei costi del cloud per trovare un equilibrio tra questi due aspetti. Alcuni potrebbero pensare che l’adozione di soluzioni cloud-native passi in secondo piano in questi tempi di incertezza, ma un recente sondaggio di Forrester rivela che il quaranta per cento delle aziende adotterà una strategia “cloud-native-first” nel 2023. Le organizzazioni investiranno maggiormente nelle tecnologie cloud-native, come Kubernetes, per ottenere una maggiore efficienza, anziché continuare a investire nelle infrastrutture legacy.

As the shift to cloud-native environments becomes the norm, security will continue to be top of mind and Commvault is here to help. We provide the most comprehensive and flexible portfolio of solutions for containers. Store, protect, and migrate your Kubernetes applications wherever they live across hybrid multi-cloud environments. To learn more about how Commvault data protection can increase efficiencies within your cloud-native environment, visit Commvault.com/containers.

Forrester, Previsioni 2023: Cloud Computing, 27 ottobre 2022

Cosa ne pensate? Quali sono i piani della vostra azienda in materia di trasformazione digitale e cloud? Avete intenzione di investire di più nella containerizzazione quest’anno?

Fatecelo sapere sui social media.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Mentre il 16 gennaio celebriamo il dottor Martin Luther King, Jr., è fondamentale sottolineare l’importanza della sua vita e della sua eredità come leader dei diritti civili proprio all’inizio del 2023. Nonostante i numerosi risultati raggiunti dai movimenti per la giustizia razziale e sociale, il cammino verso l’uguaglianza per tutti è ancora lungo a livello globale.

This day is a meaningful opportunity to reflect on what it means to drive positive change through the power of connection – whether it’s in our local communities, with family and friends or in our workplaces. For Dr. King, and all those who worked alongside him, their commitment to equality and human rights became another moment in the world in how individuals can empower the collective.

At Commvault, we’re striving for a balance in what it means to connect meaningfully whether it is in person or remotely. The global pandemic helped us navigate how to extend those connections around the world in virtual spaces and do it successfully to have “courageous conversations” around various topics.

In my role, my goal is focused on empowering everyone to be a change agent towards moving the Commvault community forward– especially driving lasting and impactful change for all dimensions of diversity. In various workplaces, there are diversity, equity and inclusion (DE&I) efforts focused on improving the recruitment, retention, advancement and sense of belonging for those from diverse, unique backgrounds and cultures. Within Commvault, we have the Multi-Culture Employee Resource Group (ERG) focused on helping to create connections, education and awareness of our global cultures.

Il gruppo di sostegno multiculturale (ERG) di Commvault si impegna a offrire uno spazio di rifugio, celebrazione e riflessione per i “Vaulters” provenienti da contesti etnici sottorappresentati e per i loro alleati all’interno di Commvault. Ci impegniamo a sensibilizzare l’opinione pubblica sulla bellezza, il valore e il contributo di tutte le origini razziali ed etniche.

As a company, we’re working towards that meaningful change and creating a sustainable foundation to support future efforts where all feel like they belong and can thrive. In honor of Dr. Martin Luther King, Jr., let’s continue to make a commitment to ourselves, others, and our broader global community that we will create space for positive change, more connections, and making our places in the world a more welcoming environment -– we’re in this together!

Clicca qui to learn more about our DE&I efforts at Commvault.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

To be successful in our roles as IT professionals, we frequently need to juggle a variety of responsibilities or “wear a lot of hats” – especially when it comes to the important matter of protecting a company’s great asset, its data. 

Facciamo una pausa per analizzare le caratteristiche di ciascun ruolo e il modo in cui queste si collegano alle responsabilità in materia di protezione dei dati di un professionista IT:

The baseball cap – Readiness

Anticipare e scongiurare potenziali minacce alla sicurezza informatica. In qualità di responsabili IT, è nostra responsabilità proteggere i dati e individuare eventuali punti deboli. Ciò comporta un monitoraggio costante delle potenziali minacce e la loro prevenzione prima che diventino un problema. L’utilizzo di soluzioni come il cyber-deception consente di disporre di un sistema di allerta precoce e fornisce quella protezione necessaria prima di essere colti alla sprovvista da un attacco.

The fedora – Flexibility

Modifying data protection tactics to fit the organization’s evolving needs. As IT executives, we must be ready to modify our approach to data protection to match the shifting requirements of our organization. The digital landscape is always changing. To remain ahead of potential dangers, this can entail putting new security processes into place or modifying current ones. Additionally, an IT leader must consider the latest technologies from cloud to containers and even possibly consider older tech when involved in mergers and acquisitions.  These scenarios all require a robust data protection solution that is scalable and flexible.  

The beret – Creativity

Inventing innovative ways to safeguard data in an increasingly complex digital environment. As IT executives, we must be able to think creatively and develop novel ways to safeguard data in a complicated digital environment. The cybercriminals are often a few steps ahead and might have more resources than your internal IT staff, the only way to combat this is to have elegant solutions to complex problems.  Nothing is more elegant than a beret…

The top hat – Decision Making

Making decisions that secure data and shield the organization from potential dangers while also ensuring that data protection and security are top organizational priorities. As the “top hat” of the company, it is our duty to make sure that data security and protection come first, to make choices that secure data, and to defend the company against any dangers. Our customers, employees, shareholders and even our peace of mind rely on knowing that IT leaders are securing the data and information of our company.  

In conclusione, i responsabili IT hanno molti impegni e devono possedere competenze in diversi ambiti.

In occasione della Giornata Nazionale del Cappello, prendiamoci un momento in più per riconoscere i vari ruoli che ricoprono e il ruolo fondamentale che svolgono nel garantire il funzionamento regolare ed efficace delle nostre aziende.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era