Skip to content

Punti di forza

  • La rapida crescita delle vulnerabilità e l’individuazione basata sull’intelligenza artificiale stanno riducendo il tempo che intercorre tra la divulgazione di una vulnerabilità e il suo sfruttamento attivo.
  • Cicli di applicazione delle patch regolari e disciplinati contribuiscono a ridurre l’esposizione complessiva e a prepararsi alle nuove vulnerabilità (CVE).
  • Il ripristino è fondamentale per la resilienza, ma deve essere accompagnato dall’applicazione tempestiva delle patch per correggere le vulnerabilità.
  • Le organizzazioni dovrebbero avvalersi dell’intelligenza artificiale per accelerare l’individuazione e la risoluzione delle vulnerabilità, anziché lasciare che i problemi si accumulino nei backlog.
  • I fornitori che svolgono un ruolo fondamentale garantiscono ai clienti una comunicazione rapida e trasparente delle vulnerabilità e indicazioni chiare su come risolverle.

L’anno scorso,secondo i dati di settore, il volume annuale dei CVE si attestava a decine di migliaia; in seguito, il NIST ha segnalato una crescita record dei CVE e unaumento del 263% delle segnalazioni between 2020 and 2025.

I hear what that does to a security team in real time, because I am on the calls when it happens. The old questions – what is our exposure, and how fast can we close it? – used to have room to breathe. Now they arrive faster than most teams can staff for them.

Most organizations have vulnerability response processes. Fewer have processes designed for this speed.

For years, the industry organized its response around individual vulnerabilities. A CVE would publish, severity scores would follow, enrichment would catch up, and teams would triage with some margin for judgment. That rhythm assumed a human pace of discovery, but that assumption no longer holds.

That volume is already outrunning the infrastructure built to track it. NIST has said the National Vulnerability Database is moving to a risk-based enrichment model because CVE submissions have grown faster than the program can fully process them.

AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. The window between when a vulnerability is discovered and when it is exploited is closing, and working exploit code can appear before a patch is widely deployed.

That breaks the old model. Structured vulnerability management still matters, but many programs are calibrated for a slower era: gather signal, rank risk, assign owners, then remediate. When discovery accelerates this sharply, even disciplined teams fall behind because the operating model cannot absorb the volume fast enough.

So, the unit of work must change. It no longer matters whether you patched a specific vulnerability but whether your organization can apply, verify, and recover at the speed the threat environment now demands.

Toppe su un orologio

Iniziate dalla cadenza. Le operazioni più resilienti che ho osservato hanno smesso di considerare l’applicazione delle patch come un’interruzione e hanno iniziato a trattarla come una manutenzione di routine: programmata settimanalmente, con responsabilità ben definite e misurata come qualsiasi altro impegno operativo. Una cadenza regolare contribuisce a ridurre il periodo di esposizione in tutto il parco sistemi e ad eliminare il “premio di panico” associato a ogni singola segnalazione. Quando gli aggiornamenti vengono effettuati ogni settimana, le organizzazioni sono preparate ad affrontare le vulnerabilità (CVE).

La cadenza non significa trattare tutto allo stesso modo. Una vulnerabilità oggetto di sfruttamento attivo, del tipo che viene inserita nelCISA’s Known Exploited Vulnerabilities Catalog, richiede comunque una risposta immediata e fuori programma. Il programma settimanale gestisce il flusso di segnalazioni come routine, in modo che le vere emergenze ricevano la giusta attenzione senza dover competere con il rumore di fondo.

Colmare la vulnerabilità, non solo il divario

Ecco la parte che Recovery da solo non può risolvere. Se una vulnerabilità mette a rischio una risorsa, ripristinare quella risorsa senza risolvere la vulnerabilità equivale solo a azzerare il conto alla rovescia. La vulnerabilità è ancora lì, in attesa del prossimo tentativo. Recovery è importante, ma non sostituisce la chiusura della falla che ha permesso all’autore della minaccia di entrare.

Ciò significa che il vero lavoro deve avvenire prima, nel momento in cui le vulnerabilità vengono individuate e risolte. L’intelligenza artificiale sta cambiando questa equazione su entrambi i fronti. Gli stessi modelli che aiutano un autore di minacce a individuare uno sfruttamento possono aiutare un fornitore a individuarlo per primo. Il reparto di ingegneria di Commvault utilizza l’intelligenza artificiale sul nostro codice sorgente per individuare le vulnerabilità prima del rilascio, e applichiamo l’intelligenza artificiale per risolvere i problemi rilevati, anziché inserirli in un elenco di attività in sospeso. Una vulnerabilità che rimane in coda per settimane perché un team ha esaurito le risorse disponibili rimane comunque una vulnerabilità. La rapidità di rilevamento non ha alcun significato senza la rapidità di risoluzione.

Chiedete di più ai vostri fornitori

When the window between discovery and exploit is measured in hours, customers cannot afford to learn about a vulnerability in their vendor’s product from a third party.

They need to hear it from the vendor, early, in plain language, with a direct answer to “Am I affected?” and “What do I do first?” Ask every critical vendor how quickly they disclose, how they notify affected customers, what evidence they provide for remediation, and how customers can validate that the exposure is closed. Vulnerability transparency is part of resilience.

The frontier AI era will not be won by whoever ships the fewest vulnerabilities. Every serious software company will disclose more. The advantage goes to whoever treats patching as a standing discipline and treats recovery as the discipline that makes a missed window survivable.

Domande frequenti

Q: Why is the window between vulnerability discovery and exploitation getting shorter?
A: AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. As a result, exploit code can become available before many organizations have had time to deploy patches.

Q: Why are weekly patching cycles becoming more important?
A: A consistent weekly patching schedule helps reduce the organization’s exposure to known vulnerabilities. It also allows security teams to focus immediate attention on actively exploited threats and prepare new CVEs.

Q: Is disaster recovery enough to protect against cyberattacks?
A: No. Recovery helps organizations restore operations after an incident, but restoring systems without addressing the underlying vulnerability leaves them exposed to future attacks. Effective resilience requires both rapid remediation and reliable recovery.

Q: How can AI help improve vulnerability management?
A: AI can help identify vulnerabilities earlier, prioritize remediation efforts, and accelerate the resolution process. This helps security and engineering teams respond more quickly instead of allowing vulnerabilities to remain unresolved in lengthy backlogs.

Q: What should organizations ask their software vendors about vulnerability management?
A: Organizations should ask how quickly vendors disclose vulnerabilities, how affected customers are notified, what remediation guidance is provided, and how customers can verify that the issue has been fully addressed. Transparent communication is an important part of cyber resilience.


Rajiv Kottomtharayil is Chief Products Officer at Commvault.

 

More related posts


AI Data Resilience

Read more about AI Data Resilience

Cyber Resilience

Read more about Cyber Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Security does not end at the edge of an organization’s own systems. Modern businesses connect a growing web of third-party applications to their core platforms to support sales, service, and collaboration. Each of these connections adds value. Each one also introduces exposure the organization does not fully control.That risk is not hypothetical. In June 2026, a threat actor compromised OAuth tokens tied to Klue, a competitive intelligence platform used to sync sales and marketing data with Salesforce. The attacker used those tokens to reach the Salesforce environments of the many organizations that had authorized the integration, including Commvault’s.As soon as we were notified of potential impact, our Security team activated our incident response process to determine what had occurred, contain the exposure, and assess whether customer information or Commvault services were affected.Our investigation found that the activity was limited to certain business relationship and sales information maintained within our Salesforce environment. The investigation found no indication that any customer backup data, product data, product metadata, operational logs, or Commvault services were impacted.

Acting Quickly When It Matters

Our response followed established security incident response procedures built to contain risk quickly while supporting a thorough investigation. Once we were notified of the incident, we disabled the Klue integration, revoked the associated access, and worked with the appropriate parties to conduct a full assessment of what happened.Throughout the investigation, our teams worked to determine what information had been accessed, validate the integrity of our environment, and confirm the incident stayed within the scope we had already contained.

A Pattern Worth Noting

This incident is one recent example of a pattern security teams have watched grow for several years: attackers targeting third-party applications connected to core business systems rather than attacking those systems directly. A single compromised integration can offer a trusted path into the environments of many downstream organizations at once, often with less resistance than a direct attack on any one of them.This shifts where an organization’s defense actually has to live. Strong internal controls remain necessary, but they are no longer sufficient by themselves. They have to be paired with active oversight of every application an organization connects, and a response capability that is ready before an incident, not built during one.

Building Resilience Beyond Our Own Environment

At Commvault, our security program includes ongoing assessment of the third-party applications connected to our environment. We review connected applications on a regular basis, evaluate the access each one holds, monitor for emerging risk, and reassess those integrations as business needs and the threat landscape change. When circumstances warrant, we act to reduce exposure and strengthen our posture, including disconnecting integrations that no longer meet our standards.

Our Commitment to Transparency

Trust is built through openness and accountability. When an event affects our stakeholders, we believe it is important to communicate what we know, explain how we responded, and share the outcome of our investigation, even when the event originated outside our own systems.We will continue to evaluate our security controls, refine our incident response processes, and strengthen our approach to third-party risk as part of our broader commitment to protecting our customers and partners.For the official details of this incident, including the scope of the investigation and customer guidance, please refer to ourTrust Center Updates.Will Galway is Deputy CISO at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Come progettare una protezione unificata dei dati: un unico ” Platform ” per i carichi di lavoro moderni

Unified data protection consolidates security, recovery, governance, and AI automation into a single platform, enabling consistent protection and reliable recovery across hybrid and multi-cloud environments

Punti di forza

Unified data protection consolidates security, recovery, governance, and AI automation into one platform, helping reduce complexity while strengthening cyber resilience.

  • Unified data protection replaces fragmented tools with a single control plane that spans on-premises, hybrid, and multi-cloud environments for optimized TCO.
  • Siloed protection strategies increase operational complexity, weaken visibility, and reduce confidence in enterprise-wide recoverability.
  • A unified platform connects data security, cyber recovery, and identity resilience to help strengthen overall cyber resilience.
  • A dedicated instance delivers isolated resources, streamlined compliance and data localization, along with SaaS-driven innovation – helping enable secure, compliant operations without infrastructure management overhead.
  • Embedded AI capabilities help support automated discovery, intelligent policy enforcement, and faster, cleaner recovery outcomes.

Most enterprise data protection strategies were designed for a world that no longer exists — before cloud sprawl, AI-generated data growth, and hybrid infrastructure became the norm. Commvault Cloud addresses this architectural gap with a unified platform that connects data security, cyber recovery, identity resilience, and AI-enabled governance across every environment from a single control plane.

Why Do Modern Enterprises Need Unified Data Protection?

According toIBM’s Cost of a Data Breach Report 2025, the average cost of a data breach stands at a staggering $4.4 million globally, with costs rising significantly when recovery is delayed or incomplete.

At the same time,the World Economic Forumnotes that as organizations confront AI threats, geopolitical volatility, and supply chain vulnerabilities, the need for resilience has never been clearer.

Enterprise data protection is rapidly entering a new period of drastic modernization. Data no longer lives in predictable locations, and it certainly does not remain still. Critical workloads exist across on-premises infrastructures, multiple public clouds, SaaS platforms, containers, and emerging AI pipelines. Each environment brings its own operational model, its own tooling, and its own risks.

For security and IT teams, the pressure is intensifying. Many organizations are now confronting three critical structural challenges simultaneously:

  • AI is generating exponential volumes of distributed data, which expands the potential attack surface.
  • Many enterprises still rely on siloed products to secure, protect, manage, and recover data, even though those tools were never designed to operate together.
  • There is no one-size-fits-all approach. Modern enterprises run across on-premises, cloud, and hybrid environments, and require resilience that spans all of them.

This complexity did not emerge overnight. It developed as cloud adoption accelerated and application teams moved faster than protection strategies could evolve, resulting in fragmented visibility, inconsistent operations, and uncertainty around recovery readiness.

In this landscape, unified data protection has emerged as the architectural response – establishing a single control plane that helps protect workloads consistently across environments, reduce complexity, and strengthen confidence in enterprise-wide recoverability.


In che modo la protezione unificata dei dati elimina la frammentazione?

Uno studio recente condotto daIBMe Palo Alto Networks ha evidenziato che un’organizzazione media dispone di 83 diverse soluzioni di sicurezza fornite da 29 diversi fornitori. In questa nuova e poco gradita normalità, il 52% dei dirigenti ritiene che la complessità sia il principale ostacolo alle operazioni di sicurezza.

La frammentazione della protezione causa inefficienze, aumentando al contempo i rischi operativi e di sicurezza. Spesso accade che ogni nuova categoria di carico di lavoro introduca un altro strumento di protezione. I backup cloud-native operano separatamente dalla protezione delle macchine virtuali. I dati SaaS risiedono in un proprio silo. I report di conformità attingono da più sistemi scollegati tra loro. Nel tempo, questa complessità si moltiplica, rendendo la copertura disomogenea e difficile da verificare.

Il carico operativo cresce rapidamente. I team sono costretti a gestire più console, aumentando i costi e le sfide tecniche. Ai responsabili della sicurezza manca una visione unificata dei dati protetti rispetto a quelli esposti. I team di conformità dedicano tempo a riconciliare le prove. I team finanziari faticano a comprendere i costi reali della protezione. E l’ostacolo più grande: la fiducia nel Recovery diventa incostante e l’incertezza regna sovrana.

Infine, i dirigenti si ritrovano a porsi una domanda fondamentale: siamo davvero in grado di recuperare tutti i dati presenti nel nostro intero patrimonio informatico?

Superare l’ostacolo della frammentazione è ormai diventato fondamentale per il successo organizzativo a lungo termine. La protezione unificata dei dati è stata concepita proprio per affrontare questo problema, contribuendo a eliminare i silos e a stabilire un modello operativo coerente in tutti gli ambienti.

Perché le aziende moderne hanno bisogno di un riorientamento architettonico unificato?

La protezione unificata dei dati rappresenta un cambiamento nel modo in cui vengono realizzate e gestite le piattaforme di protezione. Anziché sovrapporre strumenti ai singoli ambienti, le architetture moderne definiscono un unico livello di policy e di intelligence che abbraccia l’intero patrimonio di dati. La protezione unificata consiste nel creare una base ” cyber resilience ” coerente che riunisca la sicurezza dei dati, il ripristino informatico e la resilienza delle identità all’interno di un unico modello operativo.

Un sistema ” platform ” unificato supporta:

  • Protezione costante su tutto lo spettro dell’workload .
  • Visibilità centralizzata sullo stato delle misure di protezione e sui relativi costi.
  • Applicazione unificata delle politiche e dei principi di governance.
  • Modelli di implementazione flessibili che rispettano le esigenze relative alla residenza dei dati.
  • Automazione basata sull’intelligenza artificiale in grado di adattarsi alla crescita dei dati.
  • Un’unica esperienza operativa per il backup, il ripristino e la mobilità.

Il documento “ Cloud ” di Commvault (platform )definisce la protezione unificata come elemento fondamentale dell’ cyber resilience moderna.


In che modo la protezione unificata supporta gli ambienti soggetti a normative e quelli sovrani?

Per i settori fortemente regolamentati e i carichi di lavoro critici, la protezione unificata deve andare oltre la visibilità e l’efficienza. Deve inoltre contribuire a garantire un isolamento dimostrabile, il controllo geografico e la Readiness agli audit. La sovranità digitale richiede un controllo dimostrabile e verificabile su dove risiedono i dati, chi può accedere e gestire l’ambiente e come viene eseguito il Recovery. Ciò non si ottiene semplicemente scegliendo una regione cloud o un provider; dipende da come l’intero sistema è progettato, governato e gestito.

Commvault Geo Shieldcontribuisce a soddisfare tali requisiti, consentendo l’implementazione di controlli configurabili sui dati e adattandosi al contempo alle mutevoli esigenze di sovranità dei clienti nei moderni ambienti di “ cloud ” ibrido. Progettata per rispondere alle normative vigenti, questa soluzione aiuta a mantenere dati, metadati e accessi all’interno della propria regione, limitando l’esposizione extraterritoriale.

Allo stesso modo,l’istanza dedicata “ Cloud ” di Commvaultoffre un ambiente “ SaaS ” completamente isolato, progettato per le organizzazioni soggette a rigidi requisiti di conformità, privacy o residenza dei dati. I clienti dispongono di risorse dedicate di elaborazione, archiviazione e gestione, e questa soluzione è concepita in modo tale che l’infrastruttura non venga mai condivisa con tenant non correlati.

Un’istanza privata dedicata offre numerosi vantaggi alle aziende moderne. Consente di:

  • Semplifica gli audit relativi a standard quali HIPAA, FedRAMP e GDPR.
  • Soddisfare i requisiti relativi alla residenza dei dati attraverso la scelta della distribuzione geografica.
  • Sostenere il ritmo costante dell’innovazione nell’ambito dell’ SaaS , preservando al contempo l’isolamento.
  • Esercitare un maggiore controllo sui tempi degli aggiornamenti e sul lancio delle nuove funzionalità.
  • Ridurre le difficoltà legate al trasferimento dei carichi di lavoro regolamentati su SaaS.

L’istanza privata dedicata opera all’interno della stessa esperienza unificata di platform . Le organizzazioni sono progettate per mantenere la parità delle funzionalità e la velocità di innovazione quando scelgono un modello di implementazione più controllato.


How Does AI Strengthen Unified Cyber Resilience?

AI is reshaping both the threat landscape and the opportunity for smarter protection. However, AI capabilities deliver the most value when they are embedded across the entire data protection lifecycle rather than applied as isolated features.

Within the unified platform, AI-enabled capabilities help support:
Automated data discovery and classification. 

  • Intelligent protection policy recommendations.
  • Continuous monitoring and enforcement.
  • Optimization insights that improve cost and resilience posture.

These capabilities are part of Commvault’s broader data security vision, which was strengthened through the acquisition of Satori Cyber. The acquisition was particularly important in an environment where data growth is outpacing traditional defenses.

Through this acquisition, Commvault Cloud now delivers Commvault Data & AI Security — a cloud-native capability that helps address the needs of modern enterprises adopting AI and managing sensitive data across structured and unstructured environments.

The unified platform also advances cyber recovery through AI-enabled workflows such asSynthetic Recovery, which helps surgically remove compromised data while restoring clean business operations. In parallel, expanding identity resilience capabilities helps organizations detect, audit, and respond to threats targeting identity systems such asActive Directory.

Qual è l’impatto strategico della protezione unificata dei dati?

La protezione unificata dei dati consente alle organizzazioni di ripensare il modo in cui implementano l’cyber resilience. Unendo la sicurezza dei dati, il ripristino informatico e la resilienza delle identità all’interno di un’unica architettura, le organizzazioni ottengono l’accesso a un insieme coordinato di funzionalità che operano in modo coerente in ecosistemi diversi.

Questa base unificata contribuisce a garantire vantaggi aggiuntivi:

  • Protezione unificata per tutti i carichi di lavoro, i cloud e le sedi, progettata per migliorare la disponibilità dei dati affidabili.
  • Una governance unificata che integra le operazioni relative alla sicurezza, all’identità e al ripristino.
  • Intelligenza unificata che mette in correlazione i segnali provenienti da sistemi precedentemente scollegati tra loro.
  • Risultati di ripristino più rapidi e più efficaci in caso di incidenti informatici.
  • Minore complessità operativa su scala aziendale.

Gli osservatori del settore hanno rilevato che, sebbene alcuni elementi di questa convergenza si siano già manifestati in passato, l’unificazione significativa tra queste discipline è stata limitata. Piattaforme come Commvault Cloud promuovono questa visione operativa la resilienza nell’intero patrimonio di dati aziendali.

Per saperne di più, visita lapagina dedicata a Commvault Cloud platform.

Conclusione: in che modo la protezione unificata dei dati definisce la prossima era della resilienza informatica?

Il passaggio verso una protezione unificata dei dati riflette una realtà più ampia. Le aziende non possono più permettersi strategie di resilienza frammentate in un mondo caratterizzato dalla crescita dei dati alimentata dall’intelligenza artificiale, da infrastrutture distribuite e da minacce informatiche sempre più sofisticate.

Oggi, le architetture che uniscono visibilità, governance, analisi e ripristino stanno diventando fondamentali per le operazioni IT e di sicurezza.

Le piattaforme progettate secondo questo principio aiutano le organizzazioni a modernizzare il proprio approccio alla protezione. Coprendo la più ampia gamma di carichi di lavoro, supportando modelli di implementazione flessibili e integrando funzionalità di intelligenza artificiale lungo l’intero ciclo di vita, tali piattaforme consentono alle organizzazioni di aumentare la fiducia nel processo di ripristino senza aggiungere complessità.

Per i responsabili della sicurezza e dell’IT, la strada da seguire sta diventando chiara. La resilienza deve essere unificata, intelligente e adattabile a qualsiasi luogo in cui risiedano i dati.

Domande frequenti

Che cos’è la protezione unificata dei dati e perché è così importante oggi?

La protezione unificata dei dati è un approccio architettonico che utilizza un’unica piattaforma per proteggere tutti i carichi di lavoro in ambienti ibridi e multi-cloud. È importante oggi perché gli strumenti frammentati non sono in grado di gestire la complessità derivante dall’intelligenza artificiale, le infrastrutture distribuite e le sofisticate minacce informatiche su scala aziendale. Commvault Cloud è progettato per garantire tutto questo attraverso un unico piano di controllo che abbraccia la sicurezza dei dati, il Recovery informatico e la resilienza delle identità.

In che modo la frammentazione aumenta il rischio aziendale?

Fragmented protection creates visibility gaps, inconsistent policies, and uneven recovery capabilities — making it difficult to verify coverage or confidently recover at scale. Commvault Cloud is designed to address this by replacing siloed tools with a unified control plane that provides consistent visibility, governance, and recovery confidence across on-premises, hybrid, and multi-cloud environments.

In che modo Commvault Cloud supporta gli ambienti multi-cloud i senza vincoli legati a un unico fornitore?

Commvault Cloud unifica la protezione su AWS, Azure, Google Cloud e negli ambienti on-premise tramite un’unica interfaccia. Questo approccio aiuta le organizzazioni a gestire le politiche, monitorare i rischi e ottimizzare i costi su tutti i cloud senza essere vincolate a un unico fornitore di infrastrutture.

Che ruolo svolge l’istanza dedicata nei settori soggetti a regolamentazione?

L’istanza dedicata offre un ambiente ” SaaS ” completamente isolato, con risorse di elaborazione, archiviazione e gestione dedicate. Consente alle organizzazioni di soddisfare i requisiti di conformità, privacy e sovranità, mantenendo al contempo l’accesso alle stesse funzionalità unificate di ” platform “.

In che modo l’intelligenza artificiale migliora la protezione unificata dei dati?

Commvault Cloud embeds AI-enabled capabilities across the full protection lifecycle — supporting automated data discovery, intelligent classification, policy recommendations, and continuous monitoring. Strengthened through the acquisition of Satori Cyber, these capabilities help reduce exposure windows, optimize protection strategies, and accelerate clean recovery after incidents without adding operational complexity.

In che modo la protezione unificata migliora i risultati del ripristino informatico?

Commvault Cloud integrates data security, cyber recovery workflows, and identity resilience signals within a single platform — helping organizations detect threats earlier and execute faster, more precise recoveries. Capabilities like Synthetic Recovery and anomaly detection work together to help strengthen resilience and reduce operational disruption during incidents.

Esplora le risorse correlate

Commvault’s Complete Cloud Platform

Soluzione

Commvault Cloud Geo Shield

Scopri come Geo Shield aiuta le organizzazioni ad allineare l’ cyber resilience e ai requisiti di sovranità, normativi e operativi in ambienti ibridi e multi-cloud .
Scopri la soluzione suCommvault Cloud Geo Shield
Soluzione

Commvault Cloud , istanza dedicata Unity

Scopri come l’istanza privata dedicata coniuga l’isolamento dell’infrastruttura con operazioni semplificate in stile “ SaaS ” per le organizzazioni soggette a rigorosi requisiti di conformità, privacy o residenza dei dati.
Scopri la soluzione suabout Commvault Cloud , istanza dedicata Unity

The conversation around AI is changing quickly. That’s why I’m so excited to share our podcast series Ready. Or Not. We’ve paired comedian Nathan Macintosh with expert guests to talk about AI agents, cyber resilience, trust, data management, and more.

In our first episode, Nathan sits down with Dr. Reid Blackman, founder and CEO of Virtue Consultants, to tackle one of the biggest topics in AI today: agentic AI. From ethical challenges to security risks, their conversation explores what happens when AI moves beyond making content to making decisions – and taking action.

One thing is clear: Agentic AI isn’t just another technology trend. It’s changing how we think about decision-making and the role AI will play in our organizations. If you’re wondering what agentic AI means for your business, this podcast is a great place to start.

Guarda l’episodio completo su Readiverse.

Blog Key Takeaways

  • Most AI failures are caused by unintended consequences, not malicious intent.
  • Agentic AI can access systems, tools, and data to get work done, making it both incredibly useful and inherently risky.
  • AI agents can create new security challenges, from prompt attacks to expanded attack surfaces.
  • Multi-agent systems can increase efficiency, but they can also amplify mistakes when systems are connected.
  • Organizations need practical frameworks for managing AI risks before they become real-world problems.

First, Do No Harm

One takeaway from the episode is that most AI failures don’t start with bad intentions. Many begin with organizations trying to solve legitimate business problems.

Dr. Blackman uses a failed Amazon AI recruiting tool as an example. The algorithm was trained on past resumes and hiring data to inform future hiring decisions. AI ultimately learned patterns that favored male candidates because those patterns existed in the data.

The result wasn’t what Amazon intended, but that’s exactly the point. AI systems can learn lessons we never meant to teach them.

What happened next was encouraging: Amazon tested the system, identified the issue, tried to correct it, and ultimately discontinued the project when the problem couldn’t be resolved.

We tend to treat AI failures as proof that technology can’t be trusted, but Dr. Blackman makes a different point. Responsible AI isn’t about pretending mistakes won’t happen. It’s about testing, learning, and being willing to stop when something isn’t working the way you intended.

When AI Becomes Your Coworker

The Amazon example also highlights something bigger. AI is capable of delivering value, but it can also produce unintended outcomes when we don’t fully understand how it’s learning or making decisions. Generative AI showed us what AI can create. Agentic AI is showing us what AI can actually do when it’s connected to business systems.

One comparison that stood out to me was that agentic systems are, in some ways, starting to look like employees. To be useful, they need access to the same tools, databases, and software that people use. Give an AI agent access to one system, and it can do one job. Give it access to dozens of systems, and it becomes more powerful.

“More access means more capability, but it also increases risk dramatically.”

– Dr. Reid Blackman

Sneak Peek: Keeping AI in Check

What happens when your AI agent starts interacting with other people’s agents? In this clip, Dr. Blackman explains why monitoring multi-agent systems will become one of our biggest challenges.

A New Kind of Security Challenge

Agentic AI changes more than the way work gets done. It also changes the way we think about security. Instead of following predefined workflows, users interact with AI through natural language. That makes these systems more intuitive – but it also creates new challenges that traditional software doesn’t have.

As Dr. Blackman explained, attackers don’t necessarily have to break into an AI system the way they might traditional software. Instead, they may try to manipulate it through carefully crafted prompts that influence its behavior, bypass safeguards, or expose information it shouldn’t access. It’s a reminder that as AI becomes more capable, security has to evolve right alongside it.

“Do we need AI watching AI?”

– Nathan Macintosh

The Risks of Multi-Agent Systems

If one AI agent can make a mistake, imagine what happens when multiple AI agents start working together. While it may be more efficient for systems to be connected, it also creates more opportunities for failure.

If one agent makes a mistake, it can create a ripple effect. A small issue can become a much larger one if organizations don’t understand how those interactions work. This doesn’t mean multi-agent systems are inherently risky. It simply means they require the same level of planning and oversight that organizations would apply to any complex business process.

“I learned about agentic AI today and I’m already scared. Now you’re telling me AI agents talk to other AI agents?”

– Nathan Macintosh

Do You Know Who Your AI is Talking To?

If managing your own AI agents sounds challenging, consider what happens when they start interacting with someone else’s AI. You may know your own guardrails and policies, but external AI systems may be different. You may not know how they were trained, what they can access, and if they have the same safeguards in place.

Get Ready

Agentic AI is moving quickly, and the technology will keep evolving. The organizations that succeed may not necessarily be the ones that adopt AI first. They’ll be the ones that understand how to govern it, test it, and build trust around it.

One of the goals of Ready. Or Not. is to move beyond the hype and examine what responsible technology adoption actually looks like.

Dr. Blackman’s perspective is a reminder that successful AI adoption isn’t about choosing between innovation and caution. It’s about balancing both. That’s exactly the kind of conversation we’re excited to continue throughout our series.

Guarda l’episodio completo su Readiverse.

Domande frequenti

Q: What is agentic AI?

A: Agentic AI refers to AI systems that can take actions, access tools, interact with applications, and complete multi-step tasks with varying levels of autonomy. Rather than simply generating responses, they can actively perform work across connected systems.

Q: Why does agentic AI introduce new risks?

A: Agentic AI often requires access to multiple systems, applications, and data sources. While that access increases usefulness, it can also expand the potential impact of mistakes, misuse, or security compromises.

Q: What are prompt attacks?

A: Prompt attacks involve using carefully crafted inputs to manipulate an AI system’s behavior, bypass safeguards, or expose information that should remain protected.

Q: Why is monitoring becoming more important?

A: As AI agents become more autonomous and connect to more systems, they are also becoming less predictable. Monitoring helps organizations identify unexpected behavior early and understand how AI systems are interacting with people, data, and other AI agents.

Q: What are multi-agent systems?

A: Multi-agent systems consist of multiple AI agents communicating and collaborating with one another to complete tasks. While they can improve efficiency, they can also introduce additional complexity that organizations must manage carefully.

Q: What’s the biggest takeaway from this episode?

A: AI risk isn’t just about what technology can do. It’s about understanding how systems behave when they interact with people, data, applications, and each other – and putting the right safeguards in place before problems arise.

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Per anni, nell’ambito della sicurezza aziendale si è partendo dal presupposto che un sistema di prevenzione ben consolidato potesse tenere testa alle minacce abbastanza a lungo da consentire ai difensori di reagire. Frontier AI sta mettendo in discussione questa premessa, poiché i modelli più recenti riducono i tempi necessari per individuare e sfruttare le vulnerabilità da giorni o settimane a quasi tempo reale.
Lanciata per valutare i potenziali rischi di sicurezza rappresentati dal proprio modelloMythos model, Anthropic’s Project Glasswingdi Anthropic ha già coinvoltoquasi 200 aziendee ha portato alla luce circa 10.000 vulnerabilità critiche o ad alta gravità. Nel frattempo,OpenAI’s GPT-5.5sta dimostrando capacità simili.
In un recente webinar, Pranay Ahlawat, Chief Technology and AI Officer di Commvault, e Vidya Shankaran, Field CTO, si sono uniti a me per esplorare le nuove tempistiche nella gestione delle vulnerabilità, la crescente importanza della convalida di Recovery e il modo in cui i team dovrebbero concepire la resilienza oggi.Registrati al webinar on-demand.

Punti di forza

  • Man mano che le capacità all’avanguardia dell’IA raddoppiano a un ritmo sempre più accelerato, le funzionalità avanzate che contribuiscono a ridurre il tempo che intercorre tra l’individuazione di una vulnerabilità e il suo sfruttamento saranno a disposizione degli avversari entro sei-nove mesi.
  • Il ripristino di un sistema di IA agentica richiede la sincronizzazione simultanea di fonti di dati, configurazioni degli agenti e identità non umane; il ripristino di un singolo elemento in modo isolato può creare lacune che emergono solo quando si verifica un guasto a valle.
  • Backup and Recovery risolvono problemi diversi: il backup conferma che i dati esistono in un luogo sicuro, mentre Recovery conferma che un’organizzazione possa effettivamente tornare a uno stato pulito e funzionante.
  • ResOps™ (resilience operations) frames recovery as a cross-functional discipline. It brings security, operations, and technology teams together around a shared definition of what clean actually means.
  • A four-step framework – defining a “minimum viable company, isolating and testing crown jewel workloads, evaluating recovery for risk, and running full recovery drills – gives organizations a practical starting point.

L’IA di frontiera rivoluziona la gestione delle vulnerabilità

La potenza dell’IA all’avanguardia raddoppia ora all’incircaogni quattro mesi, molto più rapidamente rispetto a pochi anni fa. Sebbene i modelli di tipo Mythos non siano ancora stati resi pubblici, gli avversari potrebbero presto ottenere accesso open-source a funzionalità simili a quelle di Mythos, tra cui:

  • Una finestra di contesto praticamente illimitata.
  • La capacità di costruire un framework di attacco tramite la decompilazione del codice e la creazione di container per individuare vettori di attacco.
  • Il concatenamento delle vulnerabilità, ovvero il collegamento di debolezze singolarmente minori in un exploit grave.

This has serious implications. Two out of three organizations currently carry more than 100,000 unpatched vulnerabilities, with an average fix life of approximately 240 days. In the past, security teams have dismissed many vulnerabilities as too difficult for an average adversary to chain together, but automation has rendered that viewpoint nearly obsolete.
At the same time, the use of AI for code creation – roughly 41% of new code is now AI-generated, and GitHub saw a 25% year-over-year increase in commits – is expanding the vulnerability surface faster than remediation can address it. The ability to uncover new zero-day vulnerabilities at scale compounds the problem.
When the time from discovery to exploitation approaches zero, the window for defensive action effectively closes.

Anteprima: il futuro in rapida evoluzione dell’IA

Questo video mette in luce una realtà fondamentale: le funzionalità avanzate dell’IA raramente rimangono esclusive a lungo. Man mano che le innovazioni all’avanguardia nel campo dell’IA si diffondono in ecosistemi più ampi, le organizzazioni devono prepararsi a un futuro in cui capacità offensive sempre più sofisticate diventeranno più ampiamente disponibili.

Il nuovo indicatore di resilienza: il tempo medio per la Recovery completa

Backup and recovery solve fundamentally different problems. Backup only confirms that data has been copied somewqui safe, but it says nothing about whether the organization can actually return to a working state. And that’s wqui things can get complicated.
Two challenges often come between a successful backup and a successful recovery.

  1. Il ripristino di un ambiente complesso implica il recupero dell’applicazione, delle macchine virtuali, della configurazione di rete, di Active Directory e dei database transazionali che lo supportano, il tutto nella sequenza corretta.
  2. You have to make sure that the data you’re restoring is free of malwareobackdoors – something seven out of 10 organizations recovering from a cyber incident are currently unable to validate.

A recovery that meets its time target while reintroducing an active threat can be worse than no recovery at all.
To get clearer visibility into their resilience, organizations have begun using the MTCR (Mean Time to Clean Recovery), che combina l’obiettivo di tempo di ripristino (RTO), il tempo necessario per verificare che i dati ripristinati siano effettivamente puliti e una fase finale di verifica manuale prima che i sistemi tornino in produzione. L’obiettivo di Recovery per l’MTCR è la“minimum viable company: the roughly 30% of an environment, sequenced by dependency, that has to come back online for the organization to keep functioning.

La “cleanroom” come strumento di test

Recovery testing, the final human validation step in MTCR, typically means standing up a separate environment from live production systems – a time-consuming task when every minute counts. While cleanrooms are sometimes seen as an element of backup, a cloud-based cleanroom can also play a proactive role in recovery by providing an isolated environment to orchestrate and test complex recoveries before they are restored to production.
The same isolated environment can also help serve as a forensic tool, letting teams stand up two versions of a backup side-by-side to better understand what changed during an incident. And because it’s cloud-native and consumption-based, organizations can avoid standing up dedicated infrastructure just to test recovery.

Quattro passaggi verso la resilienza operativa

Commvault’s four-step framework for building measurable operational resilience builds on these ideas.

  • Step 1: Define the “minimum viable company: A business-oriented view of what has to come back, in what sequence, and with what dependencies, for the organization to function again, rather than a flat inventory of databases and virtual machines.
  • Step 2: Make sure the systems supporting that “minimum viable company sit in an air-gapped, immutable, network-segmented environment that can be spun up and down quickly. For crown jewel workloads, this should be tested on a 45-day cadence.
  • Step 3: Evaluate recovery for risk before declaring it complete, since reintroducing a backdooropiece of malware during recovery defeats the purpose of the exercise and leaves little time for a second attempt.
  • Step 4: Treat recovery as more than a tabletop exercise. Perform recoveries with the same people and processes that would be involved in a real incident, alongside the automation behind them.

Quando l’IA diventa il problema della Recovery

A large share of enterprises are already running AI systems in production, but only about 20% of them have actually tested their recoverability, leaving them vulnerable in the event of an incident. This is especially significant in light of the three ways AI changes resilience architecture.
First, AI expands the surface area that needs protection, from vector databases and model weights to agent configurations and the endpoints, such as Claude CoworkoGoogle Antigravity, wqui employees actually interact with agents.
It also introduces a fan-out problem, wqui a single update from an agent can cascade through a mesh of connected systems in ways that are far less predictable than a traditional three-tier application.
Finally, AI makes recovery itself more complex, since restoring an agentic system means synchronizing memory, state, transactional data, and non-human identities (NHIs) – the credentials and permissions assigned to AI agents rather than people – all at once.
The customers furthest along on agentic deployments have already made these systems part of their “minimum viable company. At every stage of maturity, the emphasis is on restoring data sources, agent configurations, and supporting elements like weights and biases together, rather than as separate efforts, since misalignment between any of those pieces can introduce risk that a single point of recovery wouldn’t catch.

Agire sulla resilienza post-Mythos

As a starting point to reduce risk from frontier AI, map your organization’s crown jewel systems and confirm that they sit in an air-gapped environment. With your “minimum viable company defined, run cleanroom drills to establish a recoverability and MTCR baseline across tier-one workloads. This should be your anchor, board-level metric for resilience, showing clearly how quickly your business can resume essential operations following an incident.
Testing is critical for surfacing gaps in business, technology, and process understanding. Often, some of the biggest problems are organizational. ResOps™ (resilience operations), can address these.
A framework rather than a product, ResOps brings security, operations, and technology teams together around a shared view of what resilient design and recovery validation should look like. ResOps formalizes the growing industry recognition that cyber recovery is a cross-functional problem that requires stakeholders from across the business who each have a stake in the outcome.
In the post-Mythos era, that coordination is critical to both support ongoing readiness and enable a fast, effective response to an incident. Frontier AI makes a tested, well-defined clean recovery process a baseline requirement.

Guarda il webinar completo

Watch the full Resilience Over Panic session on demand to explore our four-step framework in more detail, including the requirements for agentic AI recovery.
Register qui for the webinar.

Domande frequenti

Q: What is MTCR (Mean Time to Clean Recovery)?

A: Mean time to clean recovery (MTCR) measures how long it takes an organization to return to a verified, clean operating state after an incident. It’s a broader measure than simply how long it takes to restore data. It combines the traditional recovery time objective (RTO) with the additional time needed to confirm recovered data is free of malwareobackdoors, plus a final human validation step before systems return to production.

Le organizzazioni considerano sempre più spesso l’MTCR, piuttosto che la sola velocità di Recovery, come la metrica di resilienza a livello dirigenziale, poiché un Recovery rapido che reintroduca una minaccia attiva può causare danni maggiori rispetto a uno più lento, ma verificato.

Q: How is MTCR different from RTO?

A: RTO measures how quickly systems and data can be restored after a disruption. MTCR includes RTO as one component, but adds the time needed to confirm that restored data is clean and the time spent on human validation before systems go back into production. In a cyber incident specifically, a system can meet its RTO and still fall short of true resilience if the restored environment is reinfected shortly afterward.

Q: What is a “minimum viable company, and how is it different from a full disaster recovery plan?

A: A “minimum viable company, sometimes called a minimum viable business, is the smaller, business-prioritized subset of systems, data, and dependencies an organization needs back online to keep functioning after an incident, rather than its entire IT estate.

A full disaster recovery plan typically aims to restore everything, in time; a “minimum viable company definition forces an organization to decide in advance what truly has to come back first, and in what sequence, to avoid an operational shutdown.

Q: What’s the difference between a tabletop exercise and a live recovery drill?

A: A tabletop exercise is a paper-based walkthrough of an incident response plan, typically used to test decision-making and communication among stakeholders without actually executing any technical recovery steps.

A live recovery drill goes further by actually performing a recovery, using the real tools, automation, and people involved, to confirm the process works in practice, beyond what a paper exercise can show. Organizations that rely only on tabletop exercises may have a resilience plan that looks sound on review but hasn’t been tested against the operational details that tend to make real incidents take longer than expected.

Q: What are non-human identities (NHIs), and why do they complicate AI recovery?

A: NHIs are the credentials, permissions, and access rights assigned to software components, such as AI agents, rather than to individual people. As organizations deploy more agentic AI, the number of NHIs in an environment grows, and each one needs to be accounted for during a recovery alongside more familiar elements like databases and transactional systems.

Recovering an agentic AI system typically requires synchronizing NHIs with the rest of the AI stack, since restoring dataoconfigurations without restoring the correct agent permissions can leave gaps that are difficult to detect until something breaks downstream.

Q: How should an organization get started with ResOps™ (resilience operations)?

A: ResOps is a cross-functional framework that brings security, operations, and technology teams together around a shared definition of resilient design, distinct from any single product.

Le organizzazioni possono iniziare identificando un numero limitato di applicazioni fondamentali ed eseguendo un test di Recovery iniziale per stabilire un MTCR di riferimento, anziché cercare di formalizzare l’intera disciplina in una sola volta. Tale punto di riferimento iniziale fornisce ai team di sicurezza, operazioni e governance un punto di riferimento concreto per monitorare i miglioramenti. Contribuisce inoltre a sviluppare nel tempo le abitudini trasversali ai team su cui si basa ResOps.

Michael Thelander is Senior Director of Product Marketing at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

At Commvault, caring is not just something we say. It is something we act on every day.

Over the years, we have been so proud to have partnered with TeenTech, a UK-based educational charity for students aged 11–19. Teams of up to three students design and build tech products that solve real-world problems, then present them to a panel of industry judges.

We recently had the honor of attending the TeenTech Awards in London, where students from across the UK showcased the kind of creativity and problem-solving that gives us real hope for the future.

What made the day so meaningful was watching our people show up for each other. Vaulters from across the UK have supported TeenTech throughout our partnership – from building educational games and reviewing dozens of student projects, to volunteering their time on the big finals day.

This kind of commitment brings together Vaulters from different parts of our business and creates new connections along the way.

The innovation on display at the TeenTech Awards this year was unmatched. Here are a few of the standout ideas from the finalists:

  • A path toward treating Parkinson’s disease. One team proposed an approach for supporting patients earlier in the disease’s progression and explained the science behind it with real clarity.
  • A safer way to get from A to B. Another team rebuilt a navigation app around a “safest route” option, prioritizing personal safety alongside speed and distance.
  • A smart bandage that watches wounds heal. One finalist team designed a bandage that produces a hydrogel to support recovery and pairs with an app to track healing progress.
  • A fencing panel built to cut emissions. A fourth team proposed attaching zeolite panels to farm fencing as a simple way to help reduce agricultural emissions.

TeenTech gives young people a runway into STEM careers they might never have considered. Continuing to invest in the next generation of innovators matters, and we’re honored that Commvault gets to play a part in this journey.

Martha Delehanty is Chief People Officer at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

For years,post-quantum cryptography (PQC) sat comfortably in the category of “important, but not urgent.”

Security leaders knew it was coming. Researchers talked about it. Standards bodies worked on it. Most organizations acknowledged that it would eventually require attention. But I would argue that the time to start preparing is now.
In this episode of STRIVE, I sat down with Sr. Director of Portfolio Marketing Michael Fasulo to discuss why the conversation around PQC is changing so quickly – and why the organizations that wait for certainty may find themselves running out of time.
Watch the episodio.

Punti di forza

  • Harvest Now, Decrypt Later attacks mean sensitive data is already at risk, even if quantum capabilities aren’t stable or commercially viable yet.
  • Most organizations do not have a complete view of their cryptographic inventory, making discovery the first major hurdle.
  • PQC is just as much a technology challenge to solve for and as much as it is about risk prioritization.
  • The organizations that start preparing now will have more options to course correct on prioritizations than those forced to react later.

The Problem Isn’t the Technology

Most discussions about post-quantum cryptography start with technology.

  • How quickly is quantum computing advancing?
  • When will cryptographically-relevant quantum systems become practical?
  • Which algorithms are likely to survive long term?

Those are important questions. But they’re not the questions I would prioritize asking. Michael wrote a blog last year about PQC and we discussed today how several things have changed since then.
Over the past several years, estimates have consistently moved in one direction: what once felt distant now feels increasingly close. At the same time, standards are evolving; regulatory expectations are increasing, and organizations are beginning to recognize how much cryptographic debt they’ve accumulated over the decades.
The exact date of Q-Day may remain uncertain. The direction of travel is not.

The Risk Is Here And Now

One reason this conversation has become more urgent is the growing attention around Harvest Now, Decrypt Later attacks. The concept is straightforward: An adversary gains access to encrypted information today, stores it, and waits for future capabilities to make that information readable.
What’s important here is that the risk doesn’t begin when quantum computing arrives. The risk begins when even encrypted data is exfiltrated and stored.
For organizations protecting intellectual property, healthcare records, government information, or other sensitive long term retention data, that distinction changes everything.
Organizations need to know whether data being retained today will still matter when that future arrives.
For many,esp. the highly regulated industries and critical infrastructure, the answer is yes.

Sneak Peek: Why Crypto Agility Matters

Embed clip here: https://www.youtube.com/watch?v=A3YWU5rlmGA

In this clip, Michael explains why PQC isn’t a one-time fix or switch. The real goal is crypto agility – building the flexibility to adapt cryptographic algorithms as standards, and threats evolve. Because in cybersecurity, the challenge isn’t just preparing for what’s next. It’s being ready for what comes after that.

Discovery Is the Real Project

One misconception about PQC is that it’s primarily an encryption upgrade. In reality, most organizations haven’t reached the stage where replacement is the biggest concern.
They’re still trying to understand the scope of the problem. Cryptography exists everywhere.

  • Applicazioni
  • Certificates
  • Cloud services
  • APIs
  • Code signing
  • Third-party platforms

Many organizations struggle with the creation of the cryptographic inventory or its scope. That makes discovery one of the most important – and often underestimated – parts of the journey.
And for many enterprises, that’s a much larger endeavor than expected.

The Supply Chain Challenge

Another reason PQC has become a priority is that no organization will navigate this transition alone. Modern enterprises depend on vendors, cloud providers, software partners, and countless third parties, all of whom use cryptography.
That means quantum readiness extends beyond internal systems. It becomes a question of ecosystem readiness.

  • Are suppliers preparing?
  • Are critical vendors planning migrations?
  • Are third-party platforms aligned with emerging standards?

These questions will increasingly become part of risk conversations, procurement discussions, and long-term technology planning. Because cryptography doesn’t stop at organizational boundaries. Neither does risk.

Why This Conversation Matters

The most important takeaway from this discussion is that post-quantum cryptography is no longer a future technology challenge.
It’s becoming a present-day resilience conversation.
Organizations don’t need to panic and they don’t need to overhaul every system overnight. But they do need to begin, to make the best use of the time at their disposal for prepartion.
The organizations that navigate this transition successfully won’t necessarily be the ones with the most sophisticated cryptography. They’ll be the ones that started building understanding before certainty arrived.
And that’s often how resilience works.

Watch the Full Episode

There is plenty more that Michael and I explore in the episode that I didn’t capture above. Be sure to Guardalo subitofor insights to:

  • The biggest challenges organizations face when starting their PQC journey.
  • What leaders should prioritize today including some best practices.
  • Understanding MLKEM algorithms and crypto agility.
  • Infrastructure considerations for PQC.
  • How Commvault is preparing for this future.

FAQs

Q: What is post-quantum cryptography (PQC)?
A: PQC refers to cryptographic algorithms designed to help remain secure against attacks from future quantum computers.
Q: What is Harvest Now, Decrypt Later?
A: It’s a strategy where attackers collect encrypted data today with the intention of decrypting it later when more advanced computing capabilities become available.
Q: Why are organizations focusing on PQC now?
A: Because preparation takes years, and sensitive data collected today may still be valuable when quantum threats become practical.
Q: What is the biggest challenge organizations face?
A: Discovery. Most organizations do not have complete visibility into where cryptography is used across their environments.
Q: Do organizations need to replace all cryptography immediately?
A: No. Most experts recommend starting with inventory, discovery, and prioritization before planning broader migrations.
Q: What should leaders do first?
A: Identify long-lived sensitive data, understand cryptographic dependencies, and begin building a roadmap for future transition.
 

Vidya Shankaran is Field CTO at Commvault.

More related posts


Cyber Resilience

Read more about Cyber Resilience

In che modo ResOps guida la prossima evoluzione della resilienza aziendale?

Le operazioni di resilienza (ResOps) sono una disciplina operativa che integra sicurezza, infrastruttura IT e Recovery per consentire alle organizzazioni di dimostrare la propria capacità di ripristino end-to-end.

Punti di forza

ResOps shifts organizations from a reliance on passive tools and assumptions to adoption of a proactive operational discipline that proves recoverability across systems, teams, and processes.

  • ResOps is a practice and discipline that can be adopted, not a product that can be bought. It is a unified operational model that brings together people, process, and technology to address digital fragility and the existential risk facing modern organizations.
  • The rapid adoption of AI has accelerated data growth, increased system interdependencies, and introduced new risks across pipelines, identities, and models. This ecosystem needs an overarching model to achieve resilience.
  • 97% of organizations have had a security incident in the past 12 months, according toMicrosoft’s 2026 Secure Access Report — split fairly evenly between malicious attacks and accidental errors.
  • Traditional metrics such as uptime and recovery time objective (RTO) fail to capture the complexities and risks of cyber recovery, where data integrity and system dependencies play a critical role.
  • Detection and containment alone are not sufficient: organizations must build recovery processes that helps restore clean, trusted, and fully functional data.
  • Increasing regulatory pressure has forced organizations to move beyond policy-based compliance toward demonstrable, evidence-based resilience.

Most enterprises have backup, disaster recovery, and security tools in place — yet few can prove the recoverability of critical services. Especially under real-world, active attack conditions. Commvault enables ResOps by connecting protection, detection, and recovery into a continuous operational model, helping organizations move from assumption-based resilience to evidence-based, measurable, and predictable recoverability.


Why do traditional B&R and disaster recovery solutions fall short?

Disruption is a constant threat in today’s hybrid, multi-cloud world. That’s why most businesses already have backup and disaster recovery in place. Many also invest heavily in cybersecurity tools designed to detect and respond to threats. On paper, it looks like organizations have already built a cyber resilience program.

In pratica, tuttavia, raramente è così.

La sfida non risiede nella mancanza di strumenti, ma nella crescente complessità degli ambienti che questi strumenti dovrebbero proteggere, unita alla virulenza dei nuovi attacchi e alla frammentazione presente nelle moderne architetture di sicurezza.

According to Microsoft’s recent Secure Access report, 97% of organizations have had a security incident in the past 12 months. These attacks are happening in enterprises that now operate across fragmented systems spanning clouds, applications, endpoints, and data platforms. At the same time, AI adoption is accelerating this complexity. With88% of organizationsusing AI in at least one function, data is growing exponentially faster, the threats embedded in that data are stealthily increasing, dependencies have become harder to track, and recovery paths are no longer predictable.

Traditional backup and disaster recovery processes start when something breaks. These tools are also designed for stable, static systems: they confirm that data copies exist and recovery plans are documented, but don’t validate whether entire services, including all dependencies, can be restored under real-world conditions.

Ciò crea una lacuna nella resilienza, che porta a problemi concreti:

  • I dati potrebbero essere recuperabili, ma non utilizzabili o affidabili.
  • I sistemi potrebbero essere ripristinati ma non completamente funzionanti.
  • I piani di Recovery potrebbero esistere, ma fallire in condizioni reali.

La resilienza oggi richiede più che semplici strumenti isolati. Richiede un modello operativo che colleghi continuamente protezione, rilevamento e Recovery.

È qui che ResOps cambia le carte in tavola. Unisce efficacemente protezione dei dati, rilevamento e Recovery in un unico modello operativo continuo e convalidato.


Che cos’è ResOps e perché è importante?

ResOps è una disciplina operativa progettata per garantire che Recovery sia completo e possa essere dimostrato su richiesta, con prove concrete.

Riunisce persone, processi e tecnologia nei settori della sicurezza, dell’IT e delle infrastrutture in un unico modello operativo. Attraverso la pianificazione e l’implementazione collettiva di servizi critici, una progettazione resiliente e una validazione continua, le organizzazioni possono resistere meglio alle interruzioni, riprendersi entro i limiti di tolleranza definiti e dimostrarlo con prove concrete.

The biggest advantage of a high-functioning ResOps practice is that it’s been structured directly to addressing enterprise fragility and existential risk. Some of the model’s key capabilities include:

  • Operationalizing the “safe recovery” process
  • Definizione di indicatori misurabili di resilienza dei servizi (SRI) e di un sistema di valutazione basato su prove concrete
  • Ipotesi (e ottimizzazione) del Recovery in condizioni di stress
  • Ipotesi di interruzione totale e convalida dei percorsi di ricostruzione
  • Identificare continuamente e contribuire a ridurre le lacune di resilienza man mano che i sistemi si evolvono
  • Basarsi su dati provenienti da test realistici
  • Copertura dell’intera organizzazione
  • Gestire il confine tra operazioni normali e operazioni in stato di crisi

La differenza fondamentale sta nell’attenzione. Gli approcci tradizionali danno priorità alle capacità, mentre ResOps dà priorità ai risultati. Ciò offre alle organizzazioni la possibilità di dimostrare che i servizi critici possono essere ripristinati, non solo che gli strumenti sono disponibili.


Perché la resilienza informatica richiede una disciplina operativa?

Adding more tools isn’t the answer for resilience. In fact, il 40% delle organizzazioni dichiara di avere troppi fornitori.

I sistemi moderni sono strettamente integrati e altamente automatizzati. I guasti in un’area possono propagarsi a cascata attraverso i servizi, specialmente in ambienti con infrastrutture condivise e carichi di lavoro interdipendenti.

Without a unifying operational model, teams must coordinate across disconnected tools and workflows during incidents – while the salvos are flying and communication is at its worst. This slows response and increases risk. IT teams and engineers are left figuring out a plethora of tools instead of actually focusing on what matters.

ResOps introduce struttura e responsabilità. Definisce la titolarità dei risultati del Recovery, stabilisce le aspettative relative al livello di servizio e verifica che i processi di Recovery vengano testati regolarmente.


In che modo le organizzazioni dovrebbero misurare oggi la resilienza informatica?

Le metriche tradizionali, come l’uptime e l’RTO, non riflettono la realtà della Recovery informatica. Esse presuppongono che i sistemi possano essere ripristinati in modo rapido e completo, cosa che raramente avviene in ecosistemi complessi e interdipendenti.

Per garantire il vero successo della Recovery informatica è necessaria una nuova metrica:tempo medio per il ripristino completo (MTCR) MTCR addresses this need by precisely measuring how long it takes to restore verified, uncompromised and fully usable data. This metric is based on the belief that cyber recovery can only be complete when data integrity and trustworthiness have been restored. “Time to reastore,” without any context for safety or cleanliness or completeness, is wholly insufficient to provide confidence in addresses this by measuring how long it takes to restore verified, uncompromised data. This metric is based on the belief that cyber recovery must be measured by data integrity and trustworthiness. Only considering the restoration time is insufficient for the complete picture.

Gli SRI rafforzano questa fiducia valutando se i servizi critici siano in grado di operare entro i limiti di tolleranza definiti in caso di interruzione. Nel complesso, questi indicatori aiutano le organizzazioni a passare dalle ipotesi ai dati concreti, a individuare le lacune nelle capacità di Recovery e ad allineare la resilienza ai risultati aziendali.


Cosa trascura l’approccio “zero trust” quando si tratta di Recovery?

Il modello “zero trust” è un paradigma di sicurezza informatica che parte dal presupposto che nessun utente o dispositivo sia intrinsecamente affidabile, che i permessi elevati siano sottoposti a controlli rigorosi e che una violazione si sia già verificata o sia inevitabile.

Il modello “zero trust” ha fatto miracoli nell’aumentare il nostro livello di sicurezza complessivo in tutti i settori industriali.

Il punto debole dello zero trust è il principio n. 3: una violazione effettiva o un fallimento della sicurezza. La maggior parte delle organizzazioni sarà d’accordo su questo, ma non è preparata dal punto di vista operativo per questi scenari.

Le organizzazioni possono rilevare e isolare rapidamente le minacce, ma faticano comunque a ripristinare i sistemi in modo da garantire la continuità operativa e la fiducia. Il rilevamento non garantisce la recuperabilità. Ciò ha creato un evidente divario tra la risposta e il Recovery effettivo.

ResOps fills this gap by serving as the operational layer that extends the zero-trust model all the way through its “assume the breach” mandate and fulfilling its original promise. With ResOps enhancing zero trust through a practice of operational resilience, organizations are better prepared to respond to threats and recover from them effectively.



In che modo le autorità di regolamentazione stanno ridefinendo le aspettative in materia di resilienza?

Le aspettative normative si stanno rapidamente orientando verso una resilienza dimostrabile, soprattutto per quanto riguarda i dati generati dall’IA e scarsamente tracciati. I quadri normativi richiedono ora sempre più spesso una protezione strutturata e una supervisione dei sistemi di IA e dei dati da essa generati. Aspetti quali la trasparenza, la tracciabilità, la supervisione umana, i controlli sulla qualità dei dati e la gestione dei rischi durante l’intero ciclo di vita rivestono un’importanza fondamentale.

Quadri normativi quali la direttiva NIS2 e il Digital Operational Resilience Act (DORA) impongono alle organizzazioni di dimostrare di essere in grado di resistere alle interruzioni e di riprendersi da esse.

Questo include:

  • Definizione di livelli accettabili di interruzione
  • Testare regolarmente i processi di Recovery
  • Fornire prove delle prestazioni di Recovery

Questi quadri normativi e regolamenti sottolineano che la conformità non si basa più esclusivamente sulle politiche, ma richiede risultati misurabili.

Le operazioni di resilienza (ResOps) sostengono questo cambiamento integrando la convalida e la misurazione nelle operazioni interfunzionali e consentendo ai team di dimostrare la propria resilienza attraverso test e report continui.

 

Conclusione: come le aziende colmano il divario di resilienza con ResOps

The gap between perceived resilience and actual, seamless recoverability from disruptions is prominent. It’s visible in how often organizations struggle to restore operations despite having the right tools in place. As environments grow more complex and AI accelerates the pace of change, this gap can only widen. When resilience is treated as a set of disconnected capabilities rather than a cross-functional discipline, the expected “bad days” can be unrecoverable.

ResOps contribuisce a colmare questo divario spostando l’attenzione dalla preparazione alla verifica. Aiuta a integrare protezione, rilevamento e Recovery in un ciclo operativo continuo, in modo che Recovery non sia solo pianificato, ma anche verificato in condizioni reali.

What’s more, approach transforms resilience from a reactive function into a measurable discipline. It helps teams gain clarity on ownership, visibility into dependencies, and confidence that critical services can be restored when it matters most.

Adottando ResOps, le aziende entrano in una nuova era di resilienza basata su prove concrete. Le violazioni e gli attacchi sono inevitabili. Ma un approccio ResOps può aiutare le organizzazioni a riprendersi in modo rapido, sicuro e completo.

 

Domande frequenti

Che cos’è ResOps nella resilienza informatica?

ResOps is an operational discipline that unifies security, IT, and recovery teams to continuously validate and prove recoverability. It focuses on measurable outcomes, not just tools. Commvault Cloud supports the ResOps model by connecting anomaly detection, clean recovery, and Cleanroom validation into a single operational platform — enabling businesses to restore critical services reliably under real-world disruption

Perché i modelli tradizionali di Backup and Recovery falliscono?

Traditional backup and disaster recovery focus on data availability and documented plans, but do not validate whether full services and dependencies can be restored — leaving gaps where data exists but systems are not functional or trusted. Commvault products addresses this with evidence-driven recovery capabilities including anomaly detection, Cleanroom Recovery, and Synthetic Recovery that validate clean restore points before production cutover.

In che modo ResOps migliora la resilienza informatica?

ResOps improves resilience by connecting detection, protection, and recovery into a continuous closed-loop model. Commvault Cloud operationalizes this across five integrated functions: automated discovery and protection, continuous detection, clean recovery, continuous validation and improvement, and continuous compliant business — giving teams a single platform to execute the full ResOps discipline.

Quali metriche misurano efficacemente la resilienza informatica?

Metrics like Mean Time to Clean Recovery (MTCR) and Service Resilience Indicators (SRIs) provide better insight than RTO alone — measuring how quickly organizations can restore trusted, fully functional systems. Commvault introduced MTCR as a cyber recovery metric, shifting the measurement conversation from speed to data integrity and verified service continuity.

In che modo ResOps amplia l’approccio zero trust?

Zero trust focuses on prevention and access control but does not address recovery after a breach. Commvault Cloud fills this gap by connecting threat detection with clean recovery workflows — helping organizations restore trusted systems after compromise and close the gap between detection and operational continuity. In this way, ResOps extends and enables true zero trust by operationalizing restoration.

Perché sta aumentando la pressione normativa in materia di resilienza?

Regulations such as NIS2 and DORA now require organizations to demonstrate resilience through testing, measurement, and evidence — not just documented policies. Commvault supports this shift through ResOps-aligned capabilities including continuous validation, Cleanroom-based recovery testing, and MTCR measurement — providing the audit-ready evidence of recoverability that modern regulatory frameworks require.

Esplora le risorse correlate

Report dell’analista

Rapporto GigaOm sul “Minimum Viable Recovery”

Define exactly what recovery performance your organization must achieve – and benchmark your readiness against industry standards.
Leggi il rapporto sulabout Rapporto GigaOm sul “Minimum Viable Recovery”
Webinar On-Demand

Resilienza basata sull’IA e ResOps: Keynote SHIFT

Watch Commvault’s CEO introduce ResOps and demonstrate how AI-enabled automation transforms enterprise cyber recovery in real time.
Guarda il video on demand suabout Resilienza basata sull’IA e ResOps: Keynote SHIFT

Sono ora disponibili soluzioni di backup e ripristino Cloud per Google Cloud .

Clumio for Google Cloud Storage is now generally available – helping to extend immutable backup and rapid recovery to petabyte-scale object storage in Google Cloud.

Punti di forza

Clumio per Google Cloud Storage è ora disponibile al pubblico e aiuta le organizzazioni a proteggere lo storage a oggetti nel cloud con backup immutabili, Recovery rapido e la semplicità del SaaS. Clumio per Google Cloud Storage consente di:

  • Proteggere i dati di Google Cloud Storage con backup immutabili e isolati fisicamente (air-gapped), progettati per supportare il Recovery a seguito di attacchi ransomware e eventi di cancellazione distruttiva.
  • Recuperare singoli oggetti, prefissi o interi bucket a partire da un momento specifico.
  • Ripristinare set di dati su scala cloud che consentono l’utilizzo di intelligenza artificiale, analisi e applicazioni business-critical.
  • Ridurre la complessità operativa grazie a una piattaforma di Backup and Recovery basata su SaaS completamente gestita.
  • Ridurre le interruzioni dell’attività aziendale grazie a flussi di lavoro di Recovery più rapidi.
  • Supporta le iniziative di conformità e governance con copie di backup isolate e politiche di protezione centralizzate.

Clumio per Google Cloud Storage is a cloud-native backup and recovery solution that helps deliver immutable, air-gapped protection for Google Cloud Storage objects, prefixes, and buckets at petabyte scale. It helps enable rapid, granular recovery following ransomware, accidental deletion, lifecycle policy errors, or data corruption – without requiring organizations to manage backup infrastructure.

Le organizzazioni si affidano sempre più a Google Cloud Storage come base per piattaforme di analisi, iniziative di IA, dati delle applicazioni, archivi e servizi nativi del cloud.

Sebbene Google Cloud offra uno storage altamente durevole, la sola durevolezza non è sufficiente a contrastare attacchi ransomware, cancellazioni accidentali, errori nelle politiche del ciclo di vita, attività malevole o corruzione logica dei dati. Quando lo storage a oggetti nel cloud diventa un sistema di registrazione, le capacità di Recovery assumono la stessa importanza della disponibilità dello storage.

Clumio per Google Cloud Storage is now available, helping extend cloud-native cyber resilience and recovery capabilities to one of the industry’s leading cloud object storage platforms. The solution delivers immutable, air-gapped backups and rapid recovery workflows that help organizations recover data following cyberattacks, operational mistakes, outages, or corruption events.

As organizations continue investing in AI, analytics, and multi-cloud strategies, the ability to recover large-scale datasets becomes a critical business requirement. Clumio per Google Cloud Storage is designed to help organizations support business continuity, reduce operational overhead, and recover with greater confidence at cloud scale.

Perché Google Cloud Storage richiede il servizio dedicato di backup e ripristino

Google Cloud Storage è diventato la base dei dati per le imprese moderne. Le organizzazioni lo utilizzano per archiviare i dati di addestramento per i modelli di intelligenza artificiale, supportare le pipeline di analisi, archiviare i documenti aziendali e alimentare applicazioni cloud-native.

Man mano che i volumi di dati crescono, aumenta anche il potenziale impatto di un’interruzione. Un singolo errore nella politica del ciclo di vita, una cancellazione accidentale, un attacco ransomware o un bug dell’applicazione possono influire contemporaneamente su milioni di oggetti. La durabilità nativa dello storage aiuta a proteggere dai guasti dell’infrastruttura, ma non risolve il problema del danneggiamento logico, delle attività malevole o degli errori umani.

La sfida diventa ancora più ardua per le organizzazioni che gestiscono petabyte di dati. Le operazioni di Recovery richiedono spesso coordinamento manuale, script personalizzati e processi che richiedono molto tempo, ritardando il ripristino dei servizi critici per l’azienda.

Una recente ricerca shows that 84% of cloud leaders intentionally use multiple cloud environments. This helps support AI initiatives, balance risk, and manage large datasets. As multi-cloud adoption expands, organizations need consistent resilience and recovery capabilities across environments.

Come Clumio garantisce una resilienza cloud-native

Clumio per Google Cloud Storage was designed to address these challenges through a cloud-native, SaaS-based approach to protection and recovery. The platform stores backup copies in an immutable, air-gapped environment separate from production data.

Questo isolamento contribuisce a ridurre il rischio che i dati di backup vengano compromessi qualora l’archivio primario fosse colpito da ransomware o da eventi di cancellazione distruttiva. Consente alle organizzazioni di eseguire il ripristino a diversi livelli di granularità, inclusi singoli oggetti, prefissi e interi bucket. Questa flessibilità permette ai team di ripristinare solo i dati di cui hanno bisogno, contribuendo a ridurre i tempi di ripristino e le interruzioni operative.

La soluzione contribuisce inoltre a eliminare la necessità di implementare, applicare patch, scalare o mantenere l’infrastruttura di backup. La gestione centralizzata delle policy e i flussi di lavoro automatizzati di protezione contribuiscono a semplificare le operazioni, consentendo al contempo alle strategie di protezione di scalare di pari passo con la crescita degli ambienti di dati nel cloud.

Risultati aziendali per l’intelligenza artificiale, l’analisi dei dati e le operazioni cloud

For many organizations, downtime is no longer limited to application outages. Disrupted data can halt analytics projects, interrupt AI pipelines, delay customer-facing services, and impact business decision-making. Clumio helps organizations reduce these risks by supporting faster recovery workflows and strengthening cyber resilience. Key business outcomes include:

  • Faster recovery – Rapid point-in-time recovery helps organizations recover data from selected recovery points following ransomware attacks, accidental deletion, corruption events, or lifecycle policy mistakes.
  • Reduced operational overhead – A fully managed SaaS platform that helps remove infrastructure management requirements and reduce reliance on manual recovery processes.
  • Improved cyber resilience – Immutable, air-gapped backups are designed to add an additional layer of resilience against modern cyber threats.
  • Greater confidence in AI and analytics – Organizations can help protect the datasets that enable AI models, business intelligence platforms, and analytics environments.

“With Clumio for Google Cloud, we will be able to restore massive volumes of cloud data with a cloud-native SaaS solution that is easy to use and highly scalable.” – Alex Grach, Responsabile tecnico, Trusted Data Platform presso Atlassian

Garantire una Recovery coerente in ambienti multi-cloud

Molte aziende operano oggi su più ambienti cloud, tra cui AWS e Google Cloud. Sebbene l’adozione del cloud offra flessibilità, può anche introdurre complessità quando i processi di Backup and Recovery differiscono da un ambiente all’altro.

Clumio aiuta ad affrontare questa sfida fornendo un’esperienza di protezione nativa per il cloud coerente su tutte le piattaforme cloud. Le organizzazioni possono applicare politiche unificate, semplificare i flussi di lavoro di Recovery e ridurre gli attriti operativi man mano che gli ambienti cloud crescono.

As businesses continue investing in AI-enabled innovation, cloud resilience must evolve alongside the workloads it protects. With the general availability of Clumio per Google Cloud Storage, organizations gain a purpose-built solution for helping protect and recover cloud object storage data at scale while maintaining the operational simplicity that modern enterprises require.


Domande frequenti

Q: What is Clumio per Google Cloud Storage?

A: Clumio per Google Cloud Storage is a cloud-native backup and recovery solution that helps protect Google Cloud Storage data with immutable, air-gapped backups. It helps enable organizations to recover objects, prefixes, and buckets following ransomware, accidental deletion, corruption, or operational mistakes.

Q: Why isn’t Google Cloud Storage durability enough?

A: Google Cloud Storage durability is designed to help safeguard data against infrastructure failures, but it does not address logical corruption, ransomware, malicious deletion, lifecycle policy mistakes, or human error. Independent backup copies help provide an additional recovery layer.

Q: Can Clumio recover individual objects?

A: Yes. Clumio supports granular recovery workflows that allow organizations to recover individual objects, prefixes, or entire buckets depending on the scope of the incident.

Q: How does Clumio help with ransomware recovery?

A: Clumio stores backup copies in immutable, air-gapped environments separate from production storage. These isolated backup copies help organizations recover data following ransomware attacks or destructive deletion events.

Q: Is Clumio designed for large datasets?

A: Yes. Clumio is designed to support cloud-scale environments and can help organizations protect and recover large object storage datasets that enable analytics, AI, and business-critical applications.

Q: How does Clumio simplify operations?

A: As a fully managed SaaS platform, Clumio helps eliminate the need to deploy and maintain backup infrastructure. Centralized policy management and automated workflows help reduce administrative overhead and operational complexity.

Risorse correlate

PRESS RELEASE 

Clumio Extends Recovery to Google Cloud Storage 

Garantisce protezione e resilienza immutabili, SaaS, per set di dati su scala di petabyte archiviati in Google Cloud , fondamentali per l’era dell’IA agentica

Read the announcement  about Clumio Extends Recovery to Google Cloud Storage 
ANALYST REPORT 

The Total Economic Impact of Clumio 

Explore the business value, efficiency gains, and operational benefits organizations achieve with Clumio.

View the report  about The Total Economic Impact of Clumio 
CUSTOMER STORY 

How LoanBoss Strengthens Cloud Resilience 

Learn how organizations strengthen cloud resilience and simplify data protection with Clumio.

Watch the story  about How LoanBoss Strengthens Cloud Resilience 
ANALYST REPORT 

Building Cyber Resilience in the Cloud 

Discover best practices for helping protect cloud-native workloads against ransomware and operational disruptions.  

Read the Report  about Building Cyber Resilience in the Cloud 

Sei pronto per iniziare?

Operazioni di resilienza

In che modo le operazioni di resilienza (ResOps) favoriscono la capacità di ripristino delle aziende

Enterprise resilience fails not from lack of tools — but because operations, security, and infrastructure teams lack a shared, measurable framework for proving recovery.

It’s 2:47 a.m. and your incident bridge has 40 people on it. The ransomware hit a tier-one workload six hours ago. Containment is done. The forensics team has cleared two recovery points. And now everyone is waiting on the one question nobody prepared for: which services do we restore first, in what order, and how do we know the data is actually clean? Your backup admin pulls up the restore job. Your security lead pulls up the threat report. Your infrastructure lead pulls up the runbook – the one last updated eighteen months ago. Nobody has a shared answer. Nobody has practiced this together. This is the gap that Resilience Operations — ResOps — is designed to close. Not after the incident. Before it.

Resilience Operations (ResOps) is an operational discipline that aligns security, infrastructure, and operations teams around critical services, defined impact tolerances, and continuous validation — so organizations can withstand disruption and demonstrate recoverability with evidence. Commvault Cloud supports ResOps with recovery intelligence, posture visibility, Cleanroom Recovery for isolated restoration, AI-enabled anomaly detection, and automated recovery testing across hybrid, multi-cloud, SaaS, and AI-enabled environments.

Meno del 7%

Fewer than 7% of organizations can recover from a ransomware attack within 24 hours of detection. For enterprises running tightly coupled, automated environments — where one compromised workload can cascade into a full-scale operational shutdown — this statistic defines the gap that ResOps is built to close.


Che cos’è il ResOps e in cosa si differenzia dal backup e dal DR?

Backup and disaster recovery are infrastructure disciplines — they answer whether data exists and whether a datacenter can fail over. ResOps is an enterprise operating discipline: it answers whether critical business services can be recovered end-to-end, under real-world stress, within defined impact tolerances — and produces evidence to prove it.

Where DR treats recovery as an IT-owned procedure, ResOps embeds it into the operating rhythm of the entire enterprise. A ResOps Council gives cross-functional teams — engineering, security, infrastructure, operations, service delivery — shared ownership and decision rights over resilience outcomes. Recovery is then governed by two measurable targets: Service Resilience Indicators (SRIs), which define how well each critical service must perform under disruption, and Mean Time to Clean Recovery (MTCR), which tracks how quickly it actually gets there. The result is a shift from annual DR tests and static runbooks to continuously measured, board-reportable recoverability.

  • Critical Services Mapping: ResOps begins by identifying the Minimum Viable Company (MVC) — the smallest set of critical services required to sustain business operations — and defining acceptable impact tolerances for each. This scope definition informs downstream governance and testing priorities.
  • SRI-Based Performance Targets: Each critical service is assigned a Service Resilience Indicator (SRI) — a specific, testable target for how the service should perform under disruption. SRIs replace vague recovery intentions with more accountable, measurable targets.
  • MTCR Tracking: Mean Time to Clean Recovery (MTCR) measures the elapsed time from incident declaration to verified restoration of a critical service. Unlike recovery time objective (RTO), which measures uptime restoration, MTCR incorporates validation steps to support recovery confidence.
  • Cross-functional Decision Rights: ResOps defines who makes recovery decisions, in what order, and under what conditions — using RACI diagrams, backup authority structures, and preapproved runbooks. This helps reduce coordination gaps that can occur when siloed teams respond during an incident.
  • Continuous Validation Cadence: ResOps replaces annual disaster recovery (DR) tests with an ongoing rhythm of simulations, tabletop exercises, and cleanroom restores — each producing evidence that recovery capabilities remain current and effective.

Il framework ResOps: cinque ambiti integrati per la resilienza aziendale

The ResOps framework is a closed-loop operational model built around five integrated domains — Resilience Governance, Recovery Planning, Recovery Architecture, Resilience Assurance, and Resilience Measurements —that together help organizations maintain critical services within defined impact tolerances during disruption. Once these domains are established, teams can adopt a posture of continuous improvement, transforming resilience from a one-time project into an ongoing, measurable program.

Each domain plays a specific role in the ResOps closed loop. Resilience Governance establishes the charter, defines the Minimum Viable Company (MVC), and creates cross-functional ownership through a ResOps Council. Recovery Planning and Recovery Architecture translate that governance into testable runbooks, recoverability tiers, separation of control and data planes, immutable recovery points, and air-gapped isolation. Resilience Assurance validates these architectures through continuous testing — such as simulations, cleanroom restores, and tabletop exercises — while Resilience Measurements track SRIs, MTCR, and reporting outputs to support visibility and decision-making.

  • Resilience Governance: Establishes a ResOps charter, defines impact tolerances for each critical service, aligns resilience outcomes to organizational funding, and creates a cross-functional ResOps Council for shared accountability and decision-making.
  • Recovery Planning: Defines recoverability tiers by business criticality, including technical runbooks for system restart, RACI diagrams of recovery responsibilities, dependency maps, and testing schedules — so teams have a documented and rehearsed path to recovery.
  • Recovery Architecture: Defines separation between control planes, data planes, and storage tiers; incorporates air-gapping, immutability, and domain isolation; and is designed to reduce blast radius within the recovery environment to support faster, more controlled restoration.
  • Resilience Assurance: Embeds continuous validation into the operating rhythm — including cleanroom restores, simulations, and governed tabletop exercises —designed to validate recovery processes and reduce reinfection risk.
  • Resilience Measurements: Tracks outcome-focused metrics, including impact tolerances, MTCR, SRI attainment, and critical service status, and translates them into quarterly resilience reporting for leadership visibility.

In che modo Commvault Cloud supporta il ResOps negli ambienti aziendali ibridi

Commvault Cloud supporta ResOps in qualità di piattaforma basata sui dati che contribuisce ad estendere la resilienza informatica oltre gli strumenti di protezione, trasformandola in un modello operativo più ampio. Sebbene ResOps sia una disciplina piuttosto che un prodotto, Commvault Cloud offre funzionalità che aiutano le organizzazioni a rendere operativi i suoi cinque ambiti in ambienti ibridi, multi-cloud, SaaS e basati sull’intelligenza artificiale.

Commvault Cloud helps address the ResOps evidence gap by combining recovery intelligence, posture visibility, and recovery workflows within a unified platform. Rather than stitching together point tools for backup, disaster recovery (DR), and security operations, Commvault Cloud provides a unified data protection console across enterprise workloads — on-premises, cloud, and SaaS —while integrating with SecOps tools so detection and recovery can operate in a coordinated manner. This approach enables cross-functional teams to define SRIs, measure MTCR, and continuously validate recovery processes in isolated environments — supporting the evidence needs of stakeholders, including leadership and regulators.

  • Cleanroom Recovery: Commvault’s Cleanroom Recovery capability provisions an isolated, air-gapped environment on demand — separate from the production network— where critical workloads can be restored, analyzed, and scanned prior to returning services to production. (See FAQ Q3 for step-by-step mechanics.)
  • AI-Enabled Anomaly Detection: Commvault Cloud’s AI-enabled detection helps identify unusual data access patterns and backup anomalies early — helping limit incident impact and reduce the scope of recovery.
  • Automated Recovery Testing: Instead of relying solely on periodic DR exercises, Commvault Cloud supports ongoing validation of recoverability by running non-disruptive recovery tests and comparing results against SRI targets, helping surface gaps before an incident.
  • Unified Data Protection Console: A single control plane spans on-premises, cloud, SaaS, and AI-enabled workloads — helping reduce coverage gaps and tool sprawl that can affect recovery confidence in hybrid environments.
  • Posture Visibility and SRI Reporting: Commvault Cloud provides visibility into resilience posture across protected workloads in a unified view — tracking SRI attainment, MTCR trends, and tolerance gaps—and generating reporting artifacts to support internal and external stakeholders.

Sentinella Microsoft (SIEM)

Bidirectional integration allows Commvault Cloud to pass recovery telemetry into Microsoft Sentinel for correlation with threat detections — helping inform recovery decisions with current security context.

CrowdStrike Falcon (piattaforma di sicurezza)

Integration with CrowdStrike provides threat intelligence that helps inform recovery point selection — so restored environments can be assessed against known indicators of compromise before returning to production.

Splunk (SIEM/SOAR)

Commvault Cloud invia i dati relativi agli eventi di Recovery a Splunk per fornire una visibilità unificata sulle operazioni di sicurezza, aiutando i team a correlare le anomalie dei backup con attività di minaccia più ampie.

Microsoft Azure / AWS / Google Cloud (Cloud)

Commvault Cloud’s any-to-any workload portability supports recovery across major hyperscalers — helping organizations maintain resilience as dependencies shift across cloud environments.

ServiceNow (ITSM)

Integration with ServiceNow supports automated incident ticket creation and orchestration of recovery workflows — helping connect security detection with IT operations response.

Come funziona ResOps dall’inizio alla fine: dalla governance al Recuperoy completo


Individua

The unified data protection console helps classify enterprise data and map service dependencies — creating a centralized inventory of what constitutes the Minimum Viable Company (MVC) and which workloads align to specific recoverability tiers.


“Protezione”

Policy-driven protection is applied across workloads based on recoverability tiers defined in Recuperoy Planning. This results in recovery points designed with immutability and air-gap principles, reflecting the Recuperoy Architecture approach — such as separation of control planes, data planes, and storage, and considerations for blast-radius reduction.


Rilevare

AI-enabled anomaly detection monitors backup telemetry and data access patterns. When irregularities are identified, alerts can be routed to integrated SecOps platforms — helping security and recovery teams operate from a shared signal and reduce delays in response.


Recupero

Following incident declaration, orchestrated workflows run against pretested runbooks — reducing the need for ad hoc response. Cleanroom Recuperoy provisions an isolated environment where recovery points can be analyzed and tested before services are returned to production.


Ripristino

Services are promoted to production based on SRI priority. MTCR is captured for each service. The recovery sequence — including timestamps, validation steps, and SRI attainment — can be logged and compiled into reporting artifacts to support internal reviews and stakeholder reporting.

ResOps transforms enterprise resilience from documentation-based planning into a continuously validated, evidence-led operating discipline. Organizations that operationalize ResOps gain a cross-functional framework that unites security, IT, and infrastructure around measurable recoverability — tracked through SRIs, MTCR, and reporting for leadership visibility.

Commvault Cloud supporta questo modello attraverso Cleanroom Recovery, il rilevamento delle anomalie basato sull’intelligenza artificiale, i test di ripristino automatizzati e la protezione unificata dei dati su tutti i carichi di lavoro aziendali.

The result: when disruption occurs — from ransomware, AI-enabled failure, or cascading infrastructure outages — teams are better prepared, recovery processes are validated, and organizations can provide supporting evidence to stakeholders, including regulators.

Domande frequenti

Che cos’è ResOps e in che modo si differenzia dal Backup and Recovery tradizionale?

ResOps addresses a gap backup and DR don’t fully cover: can critical services be recovered end-to-end under real-world conditions within defined impact tolerances — and can we prove it? Backup confirms data copies exist, and DR validates data center failover, but ResOps extends this by accounting for dependencies, clean-state validation, rebuild pathways, and cross-functional execution, with metrics like SRIs and MTCR supported by Commvault Cloud.

In che modo la resilienza operativa differisce dalla pianificazione della continuità operativa (BCP)?

Business continuity planning (BCP) defines how an organization intends to respond to disruption, producing documented procedures that are tested periodically. Operational resilience and ResOps focus on continuously testing and improving an organization’s actual ability to withstand disruption within defined tolerances. Commvault Cloud supports this shift by providing the measurement and validation layer — SRI tracking, MTCR reporting, and Cleanroom-based testing — that enables organisations to demonstrate execution rather than simply document intent.

Come funziona il Cleanroom Recovery di Commvault Cloud nella risposta al ransomware?

When an incident occurs, Commvault Cloud provisions a Cleanroom environment — an isolated network segment designed to limit exposure to compromised systems. Recovery points are scanned for potential threats before validation activities — such as application startup and dependency checks— help confirm readiness, with the process generating logs and artifacts that can support internal review and regulatory reporting.

In che modo ResOps si differenzia da ciò che offrono Rubrik, Cohesity o Veeam?

Rubrik, Cohesity e Veeam forniscono funzionalità di protezione e ripristino dei dati, mentre ResOps introduce un modello operativo che allinea i team di sicurezza, operazioni e infrastruttura attorno a tolleranze di impatto definite e a una recuperabilità basata su prove concrete. Commvault Cloud supporta questo approccio con funzionalità quali un piano di controllo unificato, il Cleanroom Recovery, il rilevamento delle anomalie basato sull’intelligenza artificiale e la misurazione automatizzata di metriche di resilienza come SRI e MTCR.

Quali quadri normativi richiedono prove di resilienza operativa e in che modo ResOps li affronta?

Frameworks such as NIS2, the EU Cyber Resilience Act, DORA, and NIST CSF 2.0 emphasize resilience, testing, and accountability, though specific requirements vary by regulation and jurisdiction. ResOps can help organizations align to these expectations by providing an operating model and measurable outputs — such as SRI metrics and recovery validation records— supported by Commvault Cloud capabilities.

Quando un’azienda dovrebbe adottare ResOps anziché limitarsi a migliorare il proprio programma di DR esistente?

Organizations may improve DR when addressing specific gaps like recovery time objectives, recovery point objectives, or workload coverage. ResOps becomes relevant when challenges are broader — siloed teams, unclear dependencies, or limited visibility into recovery readiness. Commvault Cloud supports the transition from DR to ResOps by providing a unified control plane, Cleanroom Recovery for validated testing, and SRI-based measurement that makes recovery readiness visible and reportable to leadership and regulators.

Dimostra la tua resilienza con Commvault Cloud ResOps

Start with critical services, define impact tolerances, and validate clean recovery with evidence — using SRIs, MTCR, and Commvault Cloud.

Risorse correlate

Esplora

Che cosa sono le operazioni di resilienza (ResOps)?

Understand the ResOps operating model — how it unites data security, identity resilience, and cyber recovery into a continuous discipline for AI-era enterprises.
Leggi l’articolo suabout Che cosa sono le operazioni di resilienza (ResOps)?
Blog

Rivedere la resilienza nell’era dell’IA

Scopri come gestire attivamente la resilienza in ambienti di intelligenza artificiale sempre più complessi grazie a un nuovo approccio operativo interfunzionale basato su Commvault Cloud.
Leggi il post sul blog su “about Rivedere la resilienza nell’era dell’IA

To address mandates governing where their data is stored and used,many organizations think they can buy a sovereign cloud SKU from a hyperscaler and check the box. But this falls far short of what’s actually required – something they might discover only when a regulator asks them to demonstrate that a dataset never left a defined geography,that no foreign-jurisdiction personnel accessed it,and that they can recover it within 24 hours under incident conditions.

In a recent webinar,I joined Commvault GM Alex Zinin,who leads our digital sovereignty task force,along with Jakub Lewandowski,our associate general counsel for EMEA,and Pranay Ahlawat,our chief technology and AI officer,to examine what a complete approach to digital sovereignty needs to include and where most programs fall short.

See the full webinarand get the fullLa sovranità digitale spiegatareadiness report and implementation framework.

Punti di forza

  • The EU Cloud Sovereignty Framework defines eight sovereignty objectives,only one of which concerns data location.
  • Selecting a sovereign cloud region addresses where data lives,but not who can access it,under what legal authority,or whether you can recover it under real conditions.
  • A complete sovereignty posture spans four interdependent pillars: data locality,technological sovereignty,operational sovereignty,and jurisdictional sovereignty.
  • Sovereignty programs that treat recovery architecture separately from primary data governance carry an unexamined risk that can surface during incidents.
  • Rather than a policy of maximum sovereignty at any cost,organizations should design their strategy around minimum viable sovereignty: the right controls,consistently enforced,calibrated to actual obligations.

Digital Sovereignty Becomes an Enterprise Requirement

Over the past decade,the toughest digital and data sovereignty rules have mainly applied to government,defense,and other national‑security workloads. Outside of highly regulated sectors,many enterprises treated sovereignty principles as design guidance rather than a hard architectural constraint.

That’s now changing. GDPRenforcement has matured beyond guidance into substantial fines for operational failures,and newer regimes like“DORA,NIS2,Germany’s KRITIS rules,and the EU Data Act have tightened expectations around jurisdictional control and operational resilience.

Sovereignty questions are now surfacing in RFPs,M&A due diligence,and board‑level risk reviews as well.

The EU Cloud Sovereignty Framework,published in October 2025,clarifies what this scrutiny actually evaluates. Of its eight sovereignty objectives,only one addresses where data resides. The other seven cover access control,operational dependencies,jurisdictional exposure,and recovery.

For enterprises,this structure is now the lens through which vendor capabilities must be evaluated.

Sneak Peek: Rethinking Sovereignty and Resilience

In this moment from the webinar,Jakub discusses how sovereignty is a risk posture,rather than a single product. Organizations need a holistic strategy that combines architecture,operations,governance,auditability,and recovery planning to address it.

Data Residency Does Not Equal Sovereignty

Data residency only answers questions about where. Sovereignty regulations also require being able to explainwho,how,and under what conditions.

In practical terms,a complete sovereignty posture encompasses four interdependent pillars.

1. Data Locality

This pillar covers not just where data is stored,but where it travels. Control-plane artifacts,metadata,and telemetry can cross geographic boundaries even when primary data stays in-region.

2. Technological Sovereignty

This pillar addresses whether the organization controls the mechanisms that protect data:

  • How access is granted.
  • How data is encrypted.
  • Whether encryption key custody is retained under all conditions.

A key concept here (pun intended) is the distinction between Bring Your Own Key (BYOK),where an organization’s own encryption keys are managed within the provider’s platform,and Hold Your Own Key (HYOK),where the organization retains independent custody of keys entirely outside the provider’s environment.

For regulated organizations with strict sovereignty requirements,BYOK may not provide sufficient protection if a foreign legal authority can compel the provider to surrender key access under some circumstances.

3. Operational Sovereignty

This covers who operates the environment and from where,including whether support personnel or third-party vendors are subject to foreign jurisdiction.

4. Jurisdictional Sovereignty

This final pillar establishes the legal framework under which services are delivered and whether there are explicit protections against extraterritorial access,such as the cross-border situations discussed in the U.S. CLOUD Act.

Each of these pillars is essential to maintain compliance. A strong data locality posture with weak operational controls can allow unexamined risk.

Where Digital Sovereignty Programs Break Down

My experiences in the field have revealed a recurring pattern: When sovereignty becomes a technical conversation,it gets too narrow,too quickly. Workshops zoom in on where data lives,teams get to work on that one question,and then they move on,leaving the other three pillars largely unexamined.

Structural problems also come into play. Digital sovereignty needs to be treated as an ongoing program with legal,technical,and operational stakeholders,not as an IT project that gets checked off as complete.

Organizations can also be led astray by a few myths. One,as we’ve discussed,is the impression that sovereignty equals residency.

Then there’s the myth of absolute sovereignty,the idea that you can achieve complete independence from all external jurisdictions and dependencies. In practice,sovereignty always involves tradeoffs between control,cost,technological velocity,and the ability to innovate.

The goal should be to strike the right balance between independence from foreign jurisdictions and the requirements of your business. It’s also important to understand that sovereignty isn’t a product you can buy,but a risk posture built from architecture,operations,contracts,certifications,and continuous auditability.

Resilience Belongs Inside the Sovereignty Boundary

Operational sovereignty is thehardest pillar to audit and the one most commonly underestimated. If your environment needed access for routine maintenance tonight,who would perform it,from which country,and under which legal jurisdiction?

Most organizations,when they work through that question for the first time,find at least one support pathway that crosses a jurisdiction boundary they hadn’t mapped.

This gap becomes most consequential during recovery. Most sovereignty programs govern primary data environments but treat backup infrastructure,restoration sequencing,and recovery point management under a separate – and often weaker – set of controls. When an incident occurs,recovery personnel may not meet jurisdictional requirements,and the sovereign architecture designed to protect data can actively complicate restoration if resilience wasn’t designed in from the start.

Commvault’s resilience operations model,ResOps™,addresses this need directly by framing recovery as an ongoing operational discipline that needs to be designed,tested,and validated inside the same sovereignty boundary as the data it protects.

Minimum Viable Sovereignty: The Right Level of Control,Not the Maximum

An absolutist approach to digital sovereignty can tax resources while unnecessarily restricting a company’s ability to meet its business goals.

A payroll system,a customer transaction database,and an internal HR tool don’t carry the same sovereignty obligations. Taking a binary approach to compliance can lead to either under-investing where it matters or over-investing beyond what’s actually required.

Minimum viable sovereignty sets a more practical target: the right controls,consistently enforced and continuously demonstrated,calibrated to what each workload actually requires across all four pillars.

Organizations have a broad range of options for how sovereign controls are delivered across their environment,each providing different controls.

How Commvault Is Addressing the Digital Sovereignty Issue

Commvault’s Geo Shield framework is designed to help organizations navigate that spectrum. Rather than offering a single sovereign SKU,Geo Shield maps to the full spectrum of deployment models:

  • Regional sovereign cloud services delivered as SaaS
  • Hyperscaler sovereign-launch partnerships
  • Partner-operated national sovereign offerings built with local service providers
  • Fully customer-controlled private sovereign environments qualifying under frameworks likeFedRAMP High.

In this way,organizations can achieve a digital sovereignty posture that holds up in real-world conditions – even when an incident occurs.

Watch the Full Webinar and Get the Readiness Report

In the full webinar,available on demand,you’ll discover:

  • Why digital sovereignty is more than a technology solution.
  • The role of architecture and operations in sovereignty strategy.
  • How governance,contracts,and auditability impact resilience.
  • Why sovereignty must hold up during cyber incidents and outages.
  • The importance of a holistic,risk-based approach to sovereignty.

Guarda il webinar su “and get the fullLa sovranità digitale spiegatareadiness report and companion framework.

Domande frequenti

Q: What is the difference between data residency and digital sovereignty?

A: Data residency addresses where data is physically stored. Digital sovereignty is broader: it addresses who can access data,under what legal authority,through which operational pathways,and whether it can be recovered cleanly under real conditions.

An organization can have data residing in the right country while remaining exposed to foreign jurisdiction through its support personnel,vendor access agreements,or backup infrastructure. Residency is the starting condition; sovereignty is the full posture built on top of it.

Q: What is the EU Cloud Sovereignty Framework,and why does it matter?

A: TheEU Cloud Sovereignty Frameworkis a structured assessment tool developed by the European Commission to evaluate cloud and technology providers against sovereignty criteria during procurement processes.

It defines eight sovereignty objectives,with assurance levels ranging from zero to four for each. Only one of the eight objectives addresses data location; the rest cover operational controls,key custody,jurisdictional exposure,and recovery.

The framework represents the most comprehensive public framework for evaluating sovereignty posture and is increasingly being used as a reference by other regions and procurement bodies beyond the EU.

Q: What is the difference between BYOK and HYOK,and why does it matter for sovereignty?

A: Bring Your Own Key (BYOK) allows an organization to supply its own encryption keys,but those keys are typically managed within the provider’s platform. Hold Your Own Key (HYOK) means the organization retains independent custody of keys entirely outside the provider’s environment,including under crisis conditions or legal compulsion.

For regulated organizations with strict sovereignty requirements,BYOK may not provide sufficient protection if a foreign legal authority can compel the provider to surrender key access. The U.S. CLOUD Act,for example,can reach providers operating under U.S. jurisdiction regardless of where data is physically stored.

HYOK addresses that exposure directly,though it may require a higher platform tier in SaaS deployments.

Q: Why do most sovereignty strategies overlook operational sovereignty?

A: Operational sovereignty,covering who operates the environment and from where,is the hardest pillar to audit because it requires inventorying support contracts,vendor access agreements,and third-party dependencies across the full operational chain.

Most organizations start sovereignty programs focused on data location and encryption,which are more visible. Operational dependencies tend to surface only when explicitly audited or when an incident forces the question.

As a first step to evaluate operational sovereignty,you should identify every access pathway into your sovereign environment and the legal jurisdiction of each party with that access.

Q: How should organizations think about recovery in the context of sovereignty?

A: Recovery architecture needs to meet the same sovereignty requirements as primary data environments,but it often doesn’t. In most organizations,backup infrastructure,restoration sequencing,and recovery point management are frequently governed by a separate set of controls,or none at all.

During an incident,the personnel authorized to execute recovery may not meet jurisdictional requirements,recovery points may not have been validated as clean and uncompromised,and the sovereign architecture designed to protect data can actively complicate recovery if resilience wasn’t built into the original design. A sovereignty review should always include recovery planning.

Q: What does minimum viable sovereignty mean in practice?

A: Minimum viable sovereignty means identifying the right level of control for each workload,calibrated to actual regulatory obligations,risk tolerance,and operational constraints,rather than applying maximum controls uniformly.

Maximum sovereignty comes with real tradeoffs: technological complexity,operational burden,service limitations,and cost. Organizations that define requirements by workload across the four pillars,map those requirements to deployment models,and build evidence of consistent enforcement are in a far stronger position than those pursuing all-or-nothing approaches.

Q: What role do certifications like C5,SecNumCloud,and ISO 27001 play in a sovereignty strategy?

A: Certifications help provide auditable evidence that controls have been independently verified,an important part of any defensible sovereignty posture. C5 in Germany,SecNumCloud in France,and ISO/IEC 27001each establish baseline requirements that providers must demonstrate through independent audits.

The strongest sovereignty postures treat these certifications as a floor,providing necessary evidence that controls exist,but not a substitute for operational testing under realistic conditions.

Darren Thomson is Vice President and Chief Technology Officer,EMEA,at Commvault. Be sure to catch him in the podcast series, STRIVE.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Punti di forza

  • L’utilizzo di più strumenti di backup spesso crea dipendenze operative da un numero ristretto di specialisti, aumentando il rischio organizzativo.
  • La gestione della protezione attraverso console, politiche e sistemi di reportistica separati rende più difficile mantenere la visibilità e rispondere rapidamente ai problemi.
  • Il consolidamento non deve necessariamente comportare un progetto dirompente di sostituzione totale; molte organizzazioni possono modernizzarsi gradualmente, mantenendo al contempo gli investimenti nell’infrastruttura esistente.
  • Un piano di controllo unificato può aiutare a semplificare la gestione delle politiche, il monitoraggio, l’audit e le operazioni di Recovery in ambienti ibridi.
  • Le organizzazioni che semplificano il backup spesso ottengono significativi risparmi sui costi, contribuendo al contempo a migliorare l’efficienza operativa e la resilienza.

You didn’t build a messy environment. You built a functional one.

Each tool in your backup stack solved a real problem when you added it. One handled virtual machines. Another covered cloud workloads. A third came in when the business moved to SaaS. You made smart calls with the budget and the vendors you had. The environment works.

The stack isn’t the problem. It’s the operational model that comes with it.

Today, it’s not uncommon for a data center team managing legacy backup infrastructure to run seven or more separate systems. Seven sets of policies. Seven consoles. Seven renewal cycles.

And, in the background, they also get seven single points of failure: not in the infrastructure, but in the people. Because somewhere in your organization, there are one or two engineers who know how each of these systems behaves. When something breaks at 2 a.m., you know exactly who’s getting the call.

That’s not resilience. That’s dependency masquerading as expertise.

La parete delle dashboard

Here’s a question worth sitting with: How long does it take your team to answer a simple question like “Did last night’s backup run clean across all workloads?”

If the answer involves opening more than one console, you already know the problem. Each tool has its own view of the world. Each one reports on what it protects, in its own format, on its own schedule.

Stitching that picture together – across on-premises systems, cloud workloads, and remote locations – takes time your team doesn’t have and creates gaps that only show up when something goes wrong.

The scripts help. Your team probably wrote them. But scripts that bridge what tools don’t natively share are technical debt with a support contract. They work until they don’t, and when they don’t, the fix requires the person who wrote them.

And if you want to do this across AI-dependent workloads using generated data … let’s just say you increased the degree-of-difficulty factor by 100% or more.

Cosa significa davvero il consolidamento per i team di infrastruttura

The instinct when you hear “consolidate your backup environment” is to picture a rip-and-replace project with new hardware, new procurement, and a migration that takes six months while landing at the worst possible time.

But that’s not what consolidation has to look like.

The right platform works with the storage already in your rack. It doesn’t require you to throw out contracts you negotiated or hardware you haven’t depreciated. You can start where it makes sense – remote offices, a specific cloud workload, a dataset that’s been a problem – and expand as old contracts run out and budget frees up.

What you get in return is a single control plane. One place to set policy, monitor protection, and answer the auditor’s question. One operating model that works across on-premises, cloud, and hybrid workloads without a script to bridge the gap.

The engineers who were keeping seven dashboards cobbled together through scripts and custom executables start doing something more useful instead.

I numeri parlano da soli

Fortune Brands consolidated its backup environment with Commvault® Cloud and ha risparmiato 22,7 milioni di dollari – a 73% reduction in total cost. NTT-Netmagic ha ridotto i costi di 300.000 dollari all’anno and cut storage overhead by 35%.

Those aren’t modernization-project numbers. They’re operational-relief numbers. The kind that come from stopping the compounding cost of complexity – not from buying new things.

Real Resilience Doesn’t Need a War Room

If running a recovery drill requires assembling a team of specialists who each know one piece of the environment, that’s not a drill. That’s a liability.

Real resilience means any qualified engineer on your team can execute recovery. It means one set of policies, one control plane, and a recovery process that doesn’t fall apart when the person who built it is on vacation.

Seven dashboards can protect your data. They can’t protect your team from the operational weight of keeping them running.

That’s the case for consolidation. Not a better product. A better way to run what you’ve built.

Want the full picture? Download “Il costo nascosto di sette strumenti – a field guide for data center teams who built something worth protecting.

Domande frequenti

Q: Why is managing multiple backup platforms a problem if they’re all working?

A: The challenge isn’t usually whether the tools function individually – it’s the operational burden of managing them together. Multiple consoles, policies, and reporting systems can make visibility, troubleshooting, and recovery more complex than they need to be.

Q: What is one of the biggest risks created by a fragmented backup environment?

A: In many organizations, critical knowledge becomes concentrated in a few individuals who understand how specific systems interact. If those team members are unavailable during an incident, recovery efforts can become slower and more difficult.

Q: Does consolidation mean replacing all existing infrastructure?

A: Not necessarily. Many consolidation initiatives are phased approaches that work alongside existing storage, hardware, and contracts. Teams can modernize gradually based on business priorities, budget cycles, and contract renewals.

Q: How can consolidation improve resilience?

A: A unified platform can help provide consistent policies, centralized visibility, and streamlined recovery processes. This helps enable more team members to confidently execute recovery procedures without relying on specialized knowledge tied to individual tools.

Q: What about vendor lock-in when consolidating to a single platform?

A: Vendor lock-in is a valid consideration. The goal of consolidation should be to help reduce operational complexity while maintaining flexibility through open architectures, broad workload support, and the ability to leverage existing infrastructure investments where possible.

Q: How do organizations measure the value of consolidation?

A: Beyond software costs, organizations often evaluate factors such as administrative overhead, recovery efficiency, storage utilization, training requirements, audit readiness, and the reduction of operational risk. The greatest value frequently comes from simplifying day-to-day operations and improving recovery confidence.

Michael Thelander is Senior Director, Product Marketing, at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Dal rilevamento alla Recovery: quali sono i requisiti di una moderna architettura di resilienza informatica?

La moderna resilienza informatica consente alle organizzazioni di ripristinare operazioni affidabili dopo una compromissione, avvalendosi di procedure di Recovery validate, ambienti isolati e una risposta coordinata su un’infrastruttura ibrida.

Punti di forza

La resilienza informatica moderna si concentra su un ripristino affidabile attraverso la convalida dei dati, l’isolamento del ripristino, il coordinamento della risposta e la possibilità di un ripristino flessibile in ambienti ibridi.

  • La resilienza informatica moderna si basa su un processo di Recovery basato su prove concrete che verifica l’integrità dei dati prima del ripristino, non solo la disponibilità dei backup.
  • I modelli tradizionali di disaster recovery falliscono di fronte al ransomware perché gli aggressori prendono di mira i backup, prolungano il tempo di permanenza e compromettono i punti di ripristino.
  • Un modello di operazioni di resilienza (ResOps) allinea i team di sicurezza, IT e dati attorno a una convalida continua, a flussi di lavoro di Recovery puliti e a una Readiness misurabile.
  • Il ripristino informatico deve integrarsi con l’ecosistema di sicurezza più ampio, collegando i sistemi di rilevamento, risposta e ripristino per consentire un’azione coordinata e una visibilità condivisa durante gli incidenti.
  • Recupero in Cleanroom®, Synthetic Recovery™, air-gapped backups, and AI-assisted detection work together to help enable trusted, isolated restoration.
  • La portabilità dei carichi di lavoro e il Recovery minimo necessario aiutano le organizzazioni a ripristinare per prime le funzioni aziendali critiche e a recuperare in ambienti ibridi senza vincoli legati alla piattaforma.

Most organizations can detect cyberattacks. Far fewer can recover cleanly, confidently, and at scale across their entire data estate. Commvault addresses this gap through evidence-driven recovery — combining anomaly detection, Recupero in Cleanroom, Synthetic Recovery, and the ResOps operating model to help organizations validate, isolate, and restore trusted operations even under active adversarial conditions.

Perché i modelli di Recovery tradizionali falliscono di fronte ai moderni attacchi informatici?

241 days. That’s how long the average breach lifecycle is, according to IBM’s Cost of a Data Breach Report 2025“. Il rapporto ha inoltre evidenziato che il 76% delle organizzazioni impiegava ancora più di 100 giorni per riprendersi completamente da una violazione, concedendo agli aggressori tutto il tempo necessario per compromettere i sistemi di backup e i punti di ripristino.

Legacy disaster recovery strategies were designed for outages and hardware failures, not adversarial attacks. They assumed backups could be trusted by default – an assumption that no longer holds.

Gli attacchi informatici non sono più eventi di sicurezza isolati. Si tratta di interruzioni a livello aziendale che mettono in luce la capacità dei team di reagire e riprendersi in un contesto caratterizzato da strumenti, segnali e processi decisionali frammentati.

Gli aggressori agiscono con pazienza e deliberatamente. Quando si verifica la crittografia o la distruzione dei dati, molti punti di ripristino potrebbero essere già compromessi.

Today’s ransomware and cyberattacks follow a playbook that can look like this:

  • Extended dwell time: Adversaries may remain in the environment for weeks or months, during which they modify files, insert dormant malware, steal credentials, and corrupt backup repositories.
  • Backup targeting: Attackers now can actively delete snapshots, disable backup jobs, exfiltrate recovery keys, and alter stored data.

Nel momento in cui avviene la crittografia, diversi punti di ripristino potrebbero essere già compromessi.

La regola di backup 3-2-1IDC MarketScape: Worldwide Cyber-Recovery 2025 Vendor Assessmentsottolinea che la Recovery moderna deve garantire sia la sopravvivenza che l’integrità dei dati, specialmente quando gli aggressori prendono di mira direttamente i livelli di protezione.

Queste condizioni mettono in luce lacune sistemiche. I team di sicurezza e di Recovery operano spesso in modo indipendente, creando ritardi nel processo decisionale. I sistemi di backup non dispongono di meccanismi di convalida integrati, lasciando i team nell’incertezza su cosa sia sicuro ripristinare. Gli ambienti di Recovery potrebbero non essere isolati, aumentando il rischio di reinfezione.

Colmare queste lacune è fondamentale per la moderna resilienza informatica. È essenziale un approccio unificato che riunisca il rilevamento di anomalie e minacce, la protezione dei dati, le analisi assistite dall’intelligenza artificiale e la convalida di Recovery.


Perché il ripristino informatico basato su dati concreti rappresenta la strada da seguire?

Il ripristino basato sulle prove sostituisce il ripristino basato su supposizioni con una verifica continua dello stato di integrità dei dati. Anziché considerare i backup come intrinsecamente sicuri, le organizzazioni valutano i segnali lungo l’intero ciclo di vita dei dati per determinare quali punti di ripristino siano affidabili.

“Can we restore?” is not the right question.

Organizations must ask: “Can we restore clean, validated systems under adversarial conditions?”

Le moderne piattaforme di resilienza comeCommvault Cloudeseguono ispezioni in più fasi. Prima della protezione, l’analisi comportamentale e le informazioni sulle minacce aiutano a identificare attività sospette nei carichi di lavoro di produzione.

Successivamente, durante le operazioni di backup,Il rilevamento delle anomalieanalizza le variazioni di entropia, le modifiche insolite ai file e gli indicatori di minaccia noti per aiutare a identificare potenziali contaminazioni. Infine, dopo l’archiviazione dei dati, la scansione continua aiuta a individuare minacce latenti o ritardate che altrimenti potrebbero passare inosservate.

Le analisi assistite dall’intelligenza artificiale sono essenziali su questa scala. Aiutano a correlare i segnali nel tempo, a individuare i rischi ad alto grado di affidabilità e a ridurre il carico di lavoro associato alle indagini manuali. È importante sottolineare che queste funzionalità devono operare prima del backup, durante il backup e, infine, durante il Recovery.

Questo approccio a più livelli crea una traccia probatoria che aiuta a prendere decisioni di Recovery con una precisione di gran lunga maggiore.


What Is ResOps for Cyber Recovery?

As cyber recovery becomes more complex and security-sensitive, just stocking up on tools is not enough. Organizations need a repeatable operating discipline that aligns security, IT, and data protection teams around a shared outcome.

This is the foundation of“operazioni di resilienza” (ResOps). ResOps treats recovery as a continuous, measurable operational capability rather than a one-time event. It emphasizes shared intelligence, validated recovery paths, and proven readiness. Some of its key capabilities include helping provide:

  • Continuous visibility through anomaly detection across the data lifecycle.
  • AI-assisted threat detection, threat intelligence, and deception-driven early warning.
  • Restoration of clean data.
  • On-demand, air-gapped environments to validate recovery paths.
  • Repeatable testing and improvement.

A critical element of ResOps is integration with the broader security ecosystem. Modern architectures connect with security information and event management (SIEM); security orchestration, automation, and response (SOAR); extended detection and response (XDR); endpoint; and identity platforms to help enable coordinated response.

SOAR-driven orchestration is especially important during active incidents. Automated playbooks help enable consistent execution, reduce manual errors, and accelerate decision-making across teams.

The adoption of the ResOps model highlights a critical shift in cyber resilience, turning a traditionally siloed process into a highly repeatable engineering capability.


In che modo la convalida pulita garantisce una Recovery sicura?

Il ripristino dei backup non è così semplice come sembra. Eseguire i ripristini in modo affrettato può reintrodurre malware negli ambienti di produzione. Ogni punto di ripristino deve essere considerato potenzialmente sospetto fino a prova contraria.

La necessità di garantire la “pulizia” dei dati ripristinati ha portato alla creazione di procedure di validazione qualiRecupero in CleanroomeSynthetic Recovery.

Recupero in Cleanroom helps deliver a fast, on-demand, cloud-based recovery environment for testing, cyber forensics,erecovery staging. This can be practiced by using automated runbooksepre-configured systems to safely validate workloads before returning them to production.

A integrazione di ciò,Protezione del Traferrocontribuisce a fornire backup immutabili archiviati separatamente dall’ambiente di produzione, impedendo agli aggressori di alterare o eliminare dati critici per la Recovery.

AI-assisted Synthetic Recovery extends this validation. It leverages malwareeencryption detection to create a curated, composite recovery point that combines the most recent clean version of files across all backups into a single recovery point. This helps reduce the amount of data roll-back or the discarding of good data when performing a recovery.

Insieme, questi meccanismi contribuiscono a trasformare Recovery da un processo basato sul “miglior sforzo possibile” in una soluzione supportata da prove concrete.

Perché la portabilità del carico di lavoro è fondamentale per i modelli di resilienza informatica?

Gli ambienti aziendali oggi comprendono infrastrutture on-premise, diversi cloud pubblici, piattaforme container e ecosistemi SaaS. Le architetture di cyber-recupero devono riflettere questa realtà. Modelli di recupero rigidi possono creare attriti e ritardi, ostacolando un recupero fluido e la sicurezza dei dati di backup.

Any-to-any portability is essential for cyber resilience. 

Il Recovery “any-to-any” su scala aziendale significa che le imprese hanno la flessibilità di:

  • Ripristinare i carichi di lavoro su infrastrutture eterogenee.
  • Effettuare la migrazione tra fornitori di servizi cloud quando necessario.
  • Supportare scenari di ricostruzione da zero quando gli ambienti sono completamente compromessi.
  • Supportare diverse migrazioni di hypervisor e piattaforme di storage.

La portabilità consente di basare le decisioni di Recovery sulle priorità aziendali piuttosto che sui vincoli della piattaforma. Contribuisce inoltre a ridurre il vincolo di dipendenza dall’infrastruttura durante incidenti su larga scala.


In che modo il concetto di “minimo indispensabile per la Recovery” guida la continuità operativa?

When a major cyber incident occurs, attempting to restore everything at once often creates unnecessary delays and complexity. During such scenarios, beginning with an organization’s sistemi minimi indispensabilidell’organizzazione e procedere gradualmente verso il pieno Recovery dell’attività può rivelarsi una strategia efficace.

Questo approccio assegna la priorità ai sistemi e ai dati necessari per ripristinare innanzitutto le operazioni aziendali fondamentali. La sequenza di Recovery si allinea all’impatto sul business piuttosto che alla topologia dell’infrastruttura. Gli elementi chiave di questa pratica includono un’elevata consapevolezza delle dipendenze, obiettivi di Recovery a più livelli, runbook automatizzati e test e perfezionamenti continui.

Il ripristino minimo essenzialeoffre una miriade di vantaggi:

  • Recovery sicura e affidabile delle parti più critiche dell’azienda.
  • Ritorno molto più rapido alle operazioni aziendali continue.
  • Rapida Recovery dei sistemi di identità, delle applicazioni di comunicazione critiche e dei dati essenziali.

Il ripristino minimo essenziale helps accelerate time to business continuity. It helps enable organizations to regain operational capability quickly, even if full restoration takes longer. This process also aligns directly with the ResOps philosophy of measurable readiness.

Conclusione: integrare ogni aspetto della resilienza informatica

Present-day cyber resilience is not defined by an organization’s capability to create backups. It is defined by how confidently it can restore trusted operations under real adversarial pressure. It demands an architecture that helps continuously connect detection, validation, isolation, and orchestration.

In un’architettura matura, queste funzionalità si rafforzano a vicenda in tempo reale. I segnali di rilevamento contribuiscono a rafforzare la fiducia inCleanpoint™ confidence. Validation workflows continuously test recoverability. Cleanroom environments help provide a controlled proving ground before production cutover. Orchestrated runbooks help align technical recovery with business priorities. When these elements operate together under a ResOps model, they help provide organizations measurable confidence in their ability to recover.

Man mano che le minacce informatiche continuano a evolversi, il vantaggio determinante non sarà la rapidità con cui i sistemi possono essere ripristinati, ma l’affidabilità con cui è possibile ristabilire operazioni pulite e affidabili su larga scala.

Domande frequenti

Perché le strategie di backup tradizionali non sono più sufficienti per garantire la resilienza informatica?

Il disaster recovery tradizionale è stato progettato per interruzioni di servizio e guasti hardware, non per attacchi malevoli. Il ransomware moderno prende di mira gli archivi di backup, corrompe i punti di ripristino e disabilita i sistemi di protezione. Commvault affronta questo problema combinando Air Gap Protect, il rilevamento delle anomalie e Cleanroom Recovery per convalidare e isolare i punti di ripristino prima di riportare i dati in produzione.

Che cos’è la Recovery basata su prove e perché è importante?

Evidence-driven recovery uses anomaly detection, threat intelligence, and validation workflows to confirm restore points are clean before deployment. Commvault Cloud implements this through continuous inspection before, during, and after backup — helping surface contamination early and enabling faster, more confident restoration under adversarial conditions.

Che cos’è ResOps e in che modo migliora il Recovery informatico?

ResOps è un modello operativo che considera il ripristino come una disciplina continua e misurabile piuttosto che come un evento una tantum. Commvault supporta ResOps integrando il rilevamento delle anomalie, i percorsi di ripristino convalidati e i test basati su Cleanroom in un flusso di lavoro condiviso che allinea i team di sicurezza, IT e protezione dei dati attorno a una Readiness misurabile.

In che modo il “Cleanroom Recovery” e il “Synthetic Recovery” supportano un ripristino sicuro?

Il “Cleanroom Recovery” fornisce un ambiente isolato in cui i carichi di lavoro possono essere testati e convalidati prima di tornare in produzione. Il “Synthetic Recovery” utilizza il rilevamento assistito dall’intelligenza artificiale per aiutare a riunire le versioni pulite più recenti dei file in un punto di ripristino verificato. Insieme, aiutano a prevenire la reintroduzione di malware durante il ripristino.

Perché la portabilità dei carichi di lavoro è importante durante un incidente informatico?

In hybrid and multi-cloud environments, organizations need the flexibility to restore workloads across different platforms. Commvault’s any-to-any portability capability allows recovery across heterogeneous infrastructure, cloud migration between providers, and rebuild-from-scratch scenarios — helping ensure recovery decisions are driven by business priorities rather than platform constraints.

Che cos’è il Recovery minimo sostenibile e in che modo supporta la continuità operativa?

Minimum viable recovery prioritizes restoring the most critical systems required to resume core business operations. Commvault supports this through tiered recovery sequencing aligned to business impact — using automated runbooks and continuous testing to help organizations restore identity systems, critical applications, and essential data before completing a full rebuild.

Esplora le risorse correlate

Commvault’s Complete Cloud Platform

Platform

Recupero in Cleanroom

Scopri come l’ambiente di Recovery cloud isolato e on-demand di Commvault consenta di eseguire in sicurezza test sui carichi di lavoro, analisi forensi e convalida della produzione dopo un attacco informatico.
Scopri le funzionalità relative al “about Recupero in Cleanroom
IDC MarketScape

Leader nell’IDC MarketScape per il cyber-Recovery a livello mondiale

Commvault è stata riconosciuta come leader per l’ampiezza della sua offerta di cyber-Recovery, l’integrazione nell’ecosistema e le capacità di formazione dedicate alla resilienza informatica.
Leggi la valutazioneabout Leader nell’IDC MarketScape per il cyber-Recovery a livello mondiale

Punti di forza

  • La pressione normativa, le aspettative del consiglio di amministrazione e i conflitti nel mondo reale stanno accelerando il passaggio da una spesa incentrata sulla prevenzione a risultati in termini di resilienza.
  • L’architettura della resilienza è diventata significativamente più complessa, soprattutto perché i sistemi di intelligenza artificiale introducono nuove sfide relative alla tracciabilità dei dati e a Recovery.
  • La resilienza informatica deve superare il tradizionale concetto di Recovery di emergenza e considerare le interruzioni come una condizione operativa continua piuttosto che come un evento eccezionale.
  • Resilience operations (ResOps™) provides an operating model for making resilience continuous, cross-functional, and demonstrable under actual conditions.
  • La parte più difficile della transizione verso ResOps è di natura organizzativa. La frammentazione delle responsabilità e le priorità disallineate rimangono le cause di fallimento più comuni.

Disruptions have become business as usual. Over the past year alone, we’ve seen:

In un recente webinar, David Nowak, responsabile del Cyber Risk Service di Deloitte; Kent Meyer, amministratore delegato di Deloitte; e Shilpi Handa, vicedirettrice della ricerca di IDC per la sicurezza informatica nella regione META, si sono uniti a me per discutere di ciò che la resilienza operativa richiede effettivamente in termini di strategia, architettura e operazioni quotidiane., David Nowak, principal at Deloitte’s Cyber Risk Service; Kent Meyer, managing director at Deloitte; and Shilpi Handa, IDC’s associate research director for cybersecurity in the METUnregion, joined me to discuss what operational resilience actually demands in strategy, in architecture, and in day-to-day operations.

Sneak Peek: It’s No Longer a Matter of If, but When

In this clip from the webinar, you’ll hear why outages are no longer just IT events – they are business events. Boards and regulators are now shifting focus from if an outage occurs to how quickly organizations can recover.

Why Disaster Recovery Isn’t Enough

Per NIST’s definition, , partendo dal presupposto che le violazioni avverranno e concentrandosi sulla sopravvivenza e sul rapido Recovery, non solo sulla prevenzione. Questo approccio basato sul presupposto della violazione fa parte da anni del modello “zero trust”, ma quante organizzazioni ne stanno effettivamente mettendo in pratica le implicazioni?

Le operazioni di backup si concentrano sul fatto che i dati siano stati copiati, mentre il disaster recovery si concentra sulla possibilità di ripristinare i sistemi, ma la vera resilienza richiede di rispondere a una domanda molto più difficile: questi servizi possono essere ripristinati end-to-end, in condizioni di stress e in modo continuo?

Stiamo assistendo al diffondersi di questa mentalità in tutti i settori, guidata da una combinazione di pressioni normative e aspettative a livello di consiglio di amministrazione. by assuming breaches will happen and focusing on survival and rapid recovery, not just prevention. This assume-breach framing has been part of zero trust for years, but how many organizations are actually putting its implications into practice?

Backup operations focus on whether data has been copied, and disaster recovery on whether systems can be restored, but true resilience demands that you answer a much harder question: Can these services be restored end to end, under stress, and continuously?

We’re seeing this mindset take hold across all sectors, driven by a combination of regulatory pressure and board-level expectations.

  • In Europe, the EU’s Digital Operational Resilience Act (DORA) now mandates specific resilience outcomes and recovery timelines.
  • I requisiti di segnalazione delle violazioni della Securities and Exchange Commission (SEC) hanno posto l’accento non solo sulla divulgazione, ma anche su ciò che le organizzazioni stanno facendo per ripristinare la situazione.
  • I consigli di amministrazione ora considerano qualsiasi interruzione come un evento dannoso per l’azienda, e l’aspettativa si è spostata verso la dimostrazione non solo che il Recovery è possibile, ma che può avvenire rapidamente e con un elevato grado di affidabilità.
    Una ricerca IDC condotta da Handa illustra come le operazioni di Recovery tradizionali possano rivelarsi insufficienti. A seguito dello scoppio della guerra in Medio Oriente, ha riscontrato che i CIO e i CISO hanno dovuto affrontare difficoltà nel garantire la continuità non solo della tecnologia, ma anche delle persone e dei processi, poiché il personale è stato trasferito dall’oggi al domani e gli uffici sono diventati inaccessibili, senza lasciare nessuno in grado di eseguire il failover manuale.

    E questo è solo uno degli innumerevoli scenari imprevedibili di cui le organizzazioni devono tenere conto.

Costruire l’architettura della resilienza

Una strategia di resilienza comprende sia ciò che si protegge sia la capacità di ripristinarlo. Per quanto riguarda il primo aspetto, l’ambito di ciò che deve essere protetto si è ampliato costantemente, includendo sistemi di identità, piattaforme di comunicazione, carichi di lavoro, strumenti di produttività, pipeline CI/CD e dati strutturati e non strutturati.
Il secondo punto – «la capacità di ripristinarli» – crea nuovi requisiti per tale strategia. Non è sufficiente acquisire istantanee puntuali e definire obiettivi di ripristino tradizionali. Poiché gli avversari prendono di mira l’infrastruttura di backup, le organizzazioni devono ora esaminare i dati recuperati e confermare che non siano stati compromessi prima di rimetterli online. Ambienti di ripristino isolati, protezione air-gap per i servizi critici e funzionalità «Cleanroom Recovery» sono diventati componenti essenziali dell’architettura di resilienza.
L’intelligenza artificiale introduce un nuovo livello di difficoltà. Per ripristinare un modello di IA, non è sufficiente un backup del file del modello stesso, ma occorre tutto ciò che è servito per crearlo. Ciò include i set di dati, gli iperparametri, le versioni del framework, l’ingegneria delle caratteristiche e le configurazioni dell’infrastruttura, oltre a una mappa completa delle dipendenze che mostri come tutto si integri.
Meyer definisce le soluzioni di resilienza informatica come un modo per democratizzare il disaster recovery. Mentre il disaster recovery tradizionale era confinato all’interno del reparto IT e accessibile solo agli specialisti, le piattaforme più recenti possono fornire ai team delle operazioni di sicurezza, ai titolari delle aziende e al personale operativo la visibilità di cui hanno bisogno per partecipare attivamente.

Questo è importante per le organizzazioni con risorse limitate e cambia ciò che è possibile fare in termini di passaggio dalle esercitazioni teoriche a ripristini reali e dimostrabili.

Unresilience strategy encompasses both what you protect and whether you can recover it. On the former count, the scope of what needs to be protected has expanded steadily, including identity systems, communication platforms, workloads, productivity tools, CI/CD pipelines, and structured and unstructured data.
The latter point – “whether you can recover it” – creates the new requirements for that strategy. It’s not enough to capture point-in-time snapshots and define traditional recovery objectives. As adversaries target backup infrastructure, organizations must now examine recovered data and confirm that it’s free of compromise before bringing it back online. Isolated recovery environments, air-gap protection for critical services, and cleanroom capabilities have become essential components of resilience architecture.
AI introduces a new layer of difficulty. To recover an AI model, you’ll need not just a backup of the model file itself, but everything that went into creating it. This includes its datasets, hyperparameters, framework versions, feature engineering, and infrastructure configurations, as well as a complete dependency map showing how it all fits together.
Meyer frames cyber resilience solutions as a way to democratize disaster recovery. Whereas traditional disaster recovery was siloed inside IT and accessible only to specialists, newer platforms can give security operations teams, business owners, and operations staff the visibility they need to engage.
That matters for organizations with constrained resources, and it changes what’s possible in terms of moving from tabletop exercises to real, demonstrable restores.

ResOps considera la resilienza come una funzione continua, non solo come qualcosa che avviene in risposta a un incidente.

In termini semplici, si tratta di rendere operativa la resilienza quando le normali ipotesi operative non sono più valide. Invece di dare per scontato che i backup saranno disponibili, integri e ripristinabili quando si verifica un disastro, con ResOps si individua continuamente dove risiedono i dati, li si protegge e li si acquisisce sia in ambienti on-premise che nel cloud, si rilevano le anomalie, si ripristina uno stato affidabile e si ripristinano i carichi di lavoro che sono stati completamente convalidati. In questo modo, si è sempre più preparati ad affrontare un’interruzione e più sicuri di riuscire a superarla con successo.
Nowak propone una frase che coglie l’essenza di ResOps: “resiliente fin dalla progettazione”. È il successore del principio “securo fin dalla progettazione” che ha plasmato l’ultima generazione di architetture di sicurezza. Oltre a realizzare sistemi in grado di resistere alle violazioni, ora stiamo realizzando sistemi che possano continuare a funzionare anche quando si verifica una violazione.

ResOps treats resilience as a continuous function, not just something that happens in response to an incident.
In simple terms, it’s about operationalizing resilience when normal operating assumptions no longer hold. Instead of taking for granted that your backups will be available, clean, and restorable when disaster strikes, with ResOps you’re continually discovering where data lives, protecting and capturing it across on-premises and cloud environments, detecting anomalies, recovering to a trusted state, and restoring workloads that have been fully validated. That way, you’re increasingly ready for a disruption, and more confident that you’ll be able to get through it successfully.
Nowak offers a phrase that captures the essence of ResOps: resilient by design. It’s the successor to the secure-by-design principle that shaped the last generation of security architecture. Beyond building systems that resist compromise, we’re now building systems that can continue functioning when compromise occurs.

L’adozione del ResOps riguarda le persone e i processi almeno tanto quanto la tecnologia. Come osserva Handa, le organizzazioni in genere non falliscono perché mancano degli strumenti giusti; falliscono perché la responsabilità è frammentata tra troppi ruoli, senza un ritmo operativo condiviso e senza chiari poteri decisionali quando le cose vanno male.

Il ResOps costringe le organizzazioni a rispondere a domande che molte non hanno ancora affrontato, come ad esempio:

Adopting ResOps is at least as much about people and process as it is about technology. As Handa notes, organizations don’t typically fail because they lack the right tools; they fail because ownership is fragmented across too many roles, with no shared operating rhythm and no clear decision rights when things go wrong.
ResOps forces organizations to answer questions many haven’t yet worked through, such as:

  • Come dovrebbero essere strutturate le procedure operative per l’esecuzione remota?
  • Come funzionerà il failover interregionale quando non potrà fare affidamento su un’unica sede?
  • How will cross-regional failover work when it can’t depend on a single location?

In that sense, ResOps is less about restoring systems and more about enabling the continuity of decision-making, execution, and accountability under disruption.
To this end, many organizations have created a chief resilience officer title, particularly in state and local government. Whether filled by the CISO, the CIO, or someone new, the emergence of this role reflects broad accountability beyond IT. It requires an owner with the cross-functional authority and communication skills to bring business leaders, security teams, and operations staff into a shared operating rhythm.
The role also includes translating the case for resilience into terms that resonate across stakeholders, including monetary impact for the board, operational continuity for practitioners, and regulatory compliance for GRC teams. The goal is a decision-rights framework that’s been tested in simulations before it’s needed in an incident.

Commvault aiuta le organizzazioni a mettere in pratica il ResOps, dall’individuazione e protezione dei dati negli ambienti on-premise e cloud, al rilevamento delle anomalie, al ripristino a uno stato pulito e al ripristino dei carichi di lavoro convalidati. Per le organizzazioni che stanno cercando di passare dalle esercitazioni teoriche a ripristini dimostrabili, queste sono le funzionalità che contribuiscono a rendere operativa la resilienza in tempi incerti.
Le risorse della sessione, tra cui la ricerca di IDC sulla Readiness dei CIO e i materiali di Deloitte sul Recovery basato su prove concrete, sono disponibili nella

paginaon-demand.

Domande frequenti

Q: What is cyber resilience and how is it different from disaster recovery?

A: Disaster recovery focuses on restoring systems and data after an incident. Cyber resilience is a broader, more active posture: It assumes disruptions will occur and asks whether services can be restored end to end, under stress, on a regular basis. Many organizations have strong disaster recovery plans that nevertheless leave them exposed when a real incident unfolds under unexpected conditions.

Q: What’s driving organizations to prioritize resilience over prevention?

A: Regulatory frameworks like DORUnand evolving NERC standards now mandate specific resilience outcomes, not just security controls. As a result, boards are focusing on recovery timelines as a business metric.

Q: What makes AI systems harder to back up and recover than traditional data?

A: Backing up an AI model means capturing more than the model file itself. Unmodel is the product of a specific training process involving datasets, hyperparameters, framework versions, and infrastructure configurations. Without that full context, recovery may produce something that can’t be trusted or reproduced.

Q: What is ResOps, and how does it differ from a traditional resilience program?

A: ResOps is an operating model that treats resilience as a continuous, cross-functional discipline rather than a contingency plan. Where traditional programs tend to be siloed in IT and activated after an incident, ResOps brings together security, operations, business owners, and leadership around shared playbooks, clear decision rights, and ongoing validation of recovery readiness.

Q: What are the biggest obstacles to adopting ResOps at scale?

A: The challenges are organizational, including fragmented ownership, misaligned priorities, and the absence of a shared operating rhythm. ResOps requires agreement – before an incident occurs – between security operations teams, business owners, and operations staff on what’s critical, who’s responsible, and how recovery will be validated.

Michael Thelander is Senior Director, Product Marketing at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Punti di forza

  • Commvault AirGap è immutabile per definizione e offre funzionalità di blocco WORM per le organizzazioni soggette a ulteriori requisiti normativi e di conformità.
  • Claims that AirGap backups are not truly immutable are inaccurate and do not reflect the platform’s documented capabilities.
  • Lo storage abilitato per WORM comporta un sovraccarico in tutto il settore, ma Commvault contribuisce a ridurre al minimo tale impatto attraverso una gestione efficiente dei dati e un’architettura cloud-native.
  • Il costo dello storage di backup va oltre il consumo di capacità e dovrebbe includere le spese relative all’infrastruttura, alla potenza di calcolo e alle operazioni.
  • Le organizzazioni dovrebbero verificare la resilienza dei backup attraverso test sul campo, anziché affidarsi alle affermazioni di marketing dei fornitori.

Potreste aver recentemente riscontrato affermazioni da parte di un concorrente secondo cuiCommvault AirGap (previously called Commvault Air Gap Protect) contains a critical security gap – that backups are not truly immutable, or that enabling WORM (Write Once, Read Many) lock results in two to three times higher storage costs.
Let us address this directly: These claims are inaccurate.

Supporto dell’immutabilità e del blocco WORM in AirGap

AirGap is immutable by design, meaning that once data is written, it cannot be altered – a foundational capability that has been part of the platform since its initial release.
For organizations with regulatory or compliance requirements, Commvault also supports WORM lock capabilities in addition to immutability. These protections are available across  supported cloud storage targets, including:

  • Amazon S3 Object Lock
  • Microsoft Azure Blob immutability policies

These features are documented, rigorously tested, and actively used by customers in production environments today.
In our latest platform release, we further expanded WORM lock support within AirGap. This enhancement extends protection across both cloud and on-premises storage environments, delivering broader and more comprehensive coverage than many competing solutions.

Efficienza dello storage: comprendere il quadro completo

Across the industry, one fact remains consistent: WORM-enabled storage introduces some degree of overhead. Because WORM-locked data cannot be modified after it is written, systems have limited ability to optimize or reduce stored data over time. This is not unique to Commvault – it applies universally across vendors.
What differentiates Commvault is how efficiently this challenge is managed. Our platform helps support native cloud immutability (including S3 Object Lock and Azure immutability policies) and maintain an efficient storage overhead.
However, total cost of ownership (TCO) extends beyond storage overhead alone. Architectures that rely on always-on virtual appliances can introduce ongoing compute costs and operational complexity that compound over time.
By contrast, modern, cloud-native approaches prioritize:

  • Una gestione efficiente dei dati.
  • Modelli di implementazione flessibili.
  • L’eliminazione delle dipendenze infrastrutturali persistenti.

These design principles can result in more predictable, scalable, and sustainable long-term costs.
Presenting this as a choice between insecure backups and excessive storage costs is misleading. It is a false dichotomy that should prompt careful evaluation of vendors making such claims.

Una tendenza in crescita tra i clienti

Stiamo osservando un chiaro andamento: le organizzazioni stanno passando sempre più spesso a Commvault dopo aver deciso di non rinnovare il contratto con i propri fornitori precedenti. Tra i motivi più comuni figurano:

  • Limitazioni impreviste man mano che gli ambienti si espandono.
  • Limiti prestazionali legati alle architetture basate su Appliance.
  • Aumento dei costi infrastrutturali e operativi.
  • Prezzi di rinnovo significativamente più alti rispetto alle condizioni di acquisto iniziali.

These challenges are not isolated – they reflect a broader trend in the market. Customers are seeking solutions that offer flexibility, transparency, and long-term value, without hidden trade-offs.

Andare oltre le apparenze

In a market often shaped by aggressive claims and unclear comparisons, objective validation can be  critical. That is why we created the Get Real Challenge – a structured, no-cost assessment that enables you to evaluate backup and recovery solutions in a meaningful way.
Through this program, you can:

  • Simulare scenari reali di attacchi informatici.
  • Testare le capacità di Recovery utilizzando i propri dati e il proprio ambiente.
  • Evaluate performance without vendor bias or staged demonstrations.

The result is a clear, evidence-based understanding of your organization’s resilience posture. If you want to determine how your backups would perform under real-world conditions, we would be happy to help you get started. Drop us an email at global-sdr@commvault.com.

Domande frequenti

Q: Is Commvault AirGap truly immutable?

A: AirGap is immutable by design, meaning backup data cannot be altered after it is written. This capability has been a core part of the platform since its initial release.

Q: Does AirGap support WORM lock protection?

A: AirGap helps support WORM lock capabilities across supported cloud storage platforms, including Amazon S3 Object Lock and Microsoft Azure Blob immutability policies. Recent enhancements also have helped expand protection across cloud and on-premises environments.

Q: Does enabling WORM lock significantly increase storage costs?

A: WORM-enabled storage creates some level of overhead regardless of the vendor because protected data cannot be modified after it is written. The more important question is how efficiently a platform manages that overhead and its overall impact on long-term costs.

Q: Why is total cost of ownership more important than storage overhead alone?

A: Storage efficiency is only one part of the equation. Organizations also should consider infrastructure requirements, compute costs, operational complexity, and scalability when evaluating the long-term cost of a backup solution.

Q: Why are some organizations moving away from appliance-based backup architectures?

A: As environments grow, organizations often look for solutions that offer greater flexibility, simpler operations, and more predictable costs. Cloud-native approaches can help eliminate dependencies on always-on infrastructure while enabling organizations to scale more efficiently.

Q: How can organizations validate their cyber resilience strategy?

A: The best way is typically through testing. Running realistic recovery exercises and cyberattack simulations enable organizations to understand how their backups will perform under real-world conditions and help identify gaps before an actual incident occurs.

Kash Ansari is Chief Customer Officer Americas at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Over the past few years, I’ve had more conversations about AI than I can count.
Some are focused on potential. Some are focused on risk. Very few are grounded in how AI actually shows up in day-to-day operations.
That’s why I’m writing about an episode of STRIVE I recorded with Ravit Jain, founder and host of “The Ravit Show.”

We didn’t spend time on hype. We didn’t speculate about the future. We focused on what’s happening right now – and what changes when conversational AI is layered on top of unified resilience.
Watch the episodio.

Key Takeaways: What This Shift Really Means

  • Conversational AI helps lower the barrier to cyber intelligence. Leaders can ask complex questions in plain language and get actionable answers.
  • Unified resilience helps reduce fragmentation. Bringing recovery, security, and governance together can change how quickly organizations respond.
  • Trust is the deciding factor in AI adoption. Without transparency and control, AI doesn’t move beyond experimentation.
  • Clean data matters more than speed alone. Recovery isn’t just about getting systems back – it’s about getting back to a trusted state.
  • AI doesn’t replace expertise. It amplifies it by helping to remove friction and accelerate understanding.

From Dashboards to Dialogue

For years, cybersecurity platforms have relied on dashboards, charts, alerts, and reports. And for technical teams, those tools work. But most leaders don’t think in dashboards. They think in questions:

  • Are we exposed?
  • How long will recovery take?
  • What’s the impact if something happens right now?

Ravit and I talked about how conversational AI changes that dynamic. Instead of navigating layers of tooling, teams can interact directly with their environment using natural language. That fundamentally changes who can engage with cyber resilience – and how quickly decisions can be made.

Sneak Peek: Making Cyber Resilience Conversational

Catch a sneak peek of the episodio where we explore how conversational AI shifts cybersecurity from something you interpret to something with which you can directly interact.

Trust Changes Everything

One theme kept coming up throughout our discussion: trust. It’s easy to build an interface that answers questions. It’s much harder to build one that leaders trust in a real incident.
Trust comes down to a few things:

  • Integrità dei dati
  • Controllo degli accessi
  • Trasparenza
  • Governance
  • Consistency over time

If an executive asks a question about recovery posture, the answer has to be right. It has to be explainable. And it has to be grounded in data that hasn’t been compromised. Without that foundation, conversational AI is interesting, but not operational. With it, it becomes something teams rely on.

Why Unification Matters

Another part of our conversation that stood out was how much complexity still exists in most environments:

  • Different tools for backup.
  • Different systems for security.
  • Different processes for governance.
  • All operating independently.

That fragmentation slows everything down – especially during an incident.
Unified resilience helps change that by bringing those pieces together into a single operational layer. When conversational AI sits on top of that layer, you’re not querying isolated systems anymore. You’re interacting with a connected view of your entire environment. That’s where things can start to move faster and clarity improves. And that’s where recovery decisions become more confident.

This Isn’t About Replacing People

There’s always a question that comes up when AI enters the conversation: What happens to the teams?

Ravit addressed this directly. AI isn’t replacing expertise – it’s extending it. Security teams still define policy. Recovery teams still validate outcomes. And leaders still make decisions.
What changes is how quickly they can get to the information they need – and how clearly they can understand it. Because when you’re in the middle of a cyber event, that clarity matters.

A Shift in How Organizations Operate

There’s also a cultural shift happening when conversational AI becomes part of the workflow:

  • Security discussions can become easier to follow.
  • More stakeholders can participate.
  • Decisions can happen faster.
  • Silos can start to break down.

Instead of cybersecurity being confined to a handful of specialists, it becomes something the broader organization can engage with. To be clear – that doesn’t make it simpler. But it does make it more accessible.

Guarda l’episodio completo

In the full STRIVE episode, you’ll discover:

  • How conversational AI is actually being used in cybersecurity.
  • What it takes to build trust into AI-enabled systems.
  • Why unified platforms help change recovery outcomes.
  • How organizations can start thinking about this shift.

Guardalo subito.
If you’re thinking about how AI fits into your resilience strategy, it’s worth the time.

Domande frequenti

Q: What is conversational AI in cybersecurity?

A: Conversational AI allows users to interact with security and recovery systems using natural language, making it easier to access insights without navigating complex tools.

Q: How does conversational AI help improve resilience?

A: Conversational AI helps reduce friction in understanding data, can speed up decision-making, and allows more stakeholders to engage in recovery and security discussions.

Q: Why is trust so important for AI adoption?

A: If teams don’t trust the data, the controls, or the outputs, they won’t rely on AI during critical moments.

Q: What does unified resilience mean?

A: Unified resilience refers to bringing together data protection, security, governance, and recovery into a single, integrated approach, rather than managing them separately.

Q: Does conversational AI replace security teams?

A: No. Conversational AI can help teams work more efficiently by making information easier to access and understand.

Q: Where should organizations start?

A: Focus on data integrity, governance, and unifying visibility across systems before layering in conversational capabilities.

Darren Thomsonis Vice President and Chief Technology Officer, EMEA, at Commvault

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Punti di forza

  • La resilienza informatica dipende sia dalla tecnologia che dalle competenze dei professionisti incaricati di proteggere e ripristinare i sistemi critici.
  • La formazione continua aiuta i team dei partner a rimanere al passo con l’evoluzione delle minacce, gli ambienti ibridi e le migliori pratiche in materia di resilienza.
  • La Commvault la la Readiverse Academy offre corsi di formazione specifici per ruolo, esercitazioni pratiche e certificazioni pensate per sviluppare cyber resilience concrete in materia di cyber resilience .
  • I clienti apprezzano sempre di più i partner in grado di fornire una consulenza affidabile, accelerare la preparazione al ripristino e massimizzare i risultati in termini di resilienza.
  • Investire nella formazione continua contribuisce a rafforzare le competenze dei partner, a consolidare la fiducia dei clienti e a sostenere la crescita aziendale a lungo termine.

Organizations are facing increasing pressure to defend against sophisticated and ever-changing threats. But they also need to manage complex hybrid environments, enable rapid recovery, and maintain continuous operations. Technology plays a critical role – but it’s not enough on its own.

True resilience depends on the readiness, experience and ongoing development of the professionals designing, implementing and supporting these environments. As resilience operations continues to mature, trusted expertise has become a critical differentiator.

The Growing Importance of Continuous Learning

Cyber resilience environments are constantly evolving – from expanding hybrid infrastructures to increasingly advanced threats and rising recovery expectations.

For partner professionals across sales, consulting, engineering and support, staying current is no longer optional – it’s essential. Continuous learning helps teams:

  • Rafforzare cyber resilience .
  • Acquisire sicurezza nelle conversazioni con i clienti.
  • Rimanete al passo con l’evoluzione delle tecnologie e delle migliori pratiche.
  • Preparati ad assumere nuovi ruoli e a cogliere nuove opportunità.

Whether supporting ransomware readiness, designing recovery strategies or navigating complex data environments, skilled professionals play a critical role in helping maintain resilience and operational continuity.

Building Expertise Across the Partner Ecosystem

At Commvault, we recognize that different partner roles require different skills and learning paths.

That’s why la la Readiverse Academy was created – offering role-based learning and outcome-focused certifications across sales, engineering, consulting, architecture and support. Beyond just certification, our courses provide practical expertise that drives real customer outcomes.

The Commvault la la Readiverse Academyoffre:

  • Percorsi di apprendimento basati sui ruoli.
  • Apprendimento flessibile e personalizzato.
  • Esercitazioni pratiche basate su scenari.
  • Certificazioni che attestano la preparazione al mondo del lavoro.

Today, more than 10,000 active learners across the partner ecosystem are building their expertise through la la Readiverse Academy, reflecting the growing importance of cyber resilience skills across the industry.

Why Expertise Matters to Customers

Customers aren’t just investing in technology – they’re investing in outcomes.

They expect confidence in their ability to protect, manage, and recover systems when disruption occurs. They need trusted experts who can help reduce risk, accelerate recovery, and maximize the value of their investments.

Partners with continuously developing teams are better positioned to help:

  • Accelerare le implementazioni.
  • Adattare le soluzioni alle esigenze in continua evoluzione.
  • Migliorare la prontezza operativa.
  • Rafforzare la preparazione alle operazioni di recupero.
  • Affrontare sfide complesse in materia di resilienza.

As cyber resilience becomes mission-critical, expertise becomes a key differentiator.

Investing in the Future of Cyber Resilience

The cyber resilience landscape will continue to evolve – and so will customer expectations.

For partner professionals, continuous learning helps drive long-term growth, credibility, and readiness. For partners, it helps strengthen delivery and build trust. For customers, it helps enable better outcomes.

Explore the Commvault la la Readiverse Academy, and start building the expertise that sets your team apart – with role-based learning, hands-on training, and certifications designed for real-world impact.

Domande frequenti

Q: Why is technology alone not enough to achieve cyber resilience?
A: Technology provides the tools needed to protect and recover data, but successful cyber resilience also depends on the people using those tools. Skilled professionals are essential for helping design effective strategies, respond to threats, and enable rapid recovery when disruptions occur.

Q: What role does continuous learning play in cyber resilience?
A: Continuous learning helps professionals stay current with evolving cyber threats, changing technologies, and emerging best practices. It also helps build confidence in customer engagements and prepare teams to address increasingly complex resilience challenges.

Q: What is the Commvault la la Readiverse Academy?
A: la la Readiverse Academy is Commvault’s learning platform that offers role-based training, hands-on labs, flexible learning paths, and certifications. Its programs are designed to help sales, engineering, consulting, architecture, and support professionals develop practical cyber resilience expertise.

Q: How do customers benefit from working with highly trained partners?
A: Customers gain access to trusted experts who can help reduce risk, improve operational readiness, accelerate deployments, and strengthen recovery preparedness. This expertise helps organizations achieve better outcomes from their cyber resilience investments.

Q: Why are certifications important in the cyber resilience field?
A: Certifications help validate real-world knowledge and readiness, giving both partners and customers confidence in a professional’s capabilities. They also support career development and demonstrate a commitment to maintaining current expertise.

Q: How can partners prepare for the future of cyber resilience?
A: Partners can prepare by investing in ongoing education, developing role-specific expertise, and staying aligned with evolving resilience requirements. Building a culture of continuous learning helps teams remain effective as customer expectations and threat landscapes continue to evolve.

Thomas Kestner is Global Director Partner Solutions & Services Enablement, WW Education Services, at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Abbiamoannunciato un rafforzamento della partnership strategica tra Commvault e HPE – one grounded in a shared belief that data protection and cyber resilience needed to evolve alongside modern infrastructure.

And if you were in the room for Antonio Neri’s keynote or watched it online, you might remember Commvault being called out on stage.

At the time, it felt like a strong statement of intent.

Today, heading back to Las Vegas, it feels like something more:

Execution. Momentum. And a real opportunity to build modern, resilient IT for customers..

What’s changed in the past year

In the last twelve months, the conversations we’re having with customers have shifted – but so has the environment they’re operating in.

Yes, data is growing. Yes, AI is accelerating. And yes, you absolutely need to have a resilience plan for AI.

But what’s also changed is the nature of the risk.

We’re now entering what many are calling the age of frontier AI – with advanced models like Mythos fundamentally changing how quickly vulnerabilities are discovered and exploited.

You may have seen that in un recente annuncio di Commvault, we highlighted how these models are compressing what used to be weeks-long exploitation cycles into minutes, dramatically shrinking the window organizations have to respond or recover.

Attacks are becoming more automated, more autonomous, and more immediate.

Which means what you thought you knew might not apply anymore:

  • That you’ll have time to patch before something is exploited
  • That recovery can happen “after the fact”
  • Quella copia di sicurezza è sufficiente

That’s what’s really changed.

It’s why the conversations we’re having today – with customers, with partners, and across the industry – are less about if something happens and more about how quickly you can recover when it does.

And it’s also why the joint innovation with partners like HPE – bringing to market differentiated new solutions that solve real customer challenges and strengthen our cyber resilience portfolio – is so incredibly valuable.

Tre ambiti in cui questa collaborazione si è evoluta

If you step back and look at the past year of this partnership, I’d group our progress with HPE into three clear areas.

#1 – Una maggiore integrazione tecnica proprio dove conta di più

We’ve moved well beyond production and protection across storage infrastructure to run-time platforms. So not only do we enable simplified snapshot management and faster recovery across HPE storage technologies like HPE Alletra Storage MP or HPE StoreOnce, we don’t stop at the storage layer. A great example of that is agentless protection for virtual machines (VMs) managed through HPE Morpheus Software.

Virtualization is in a period of real disruption right now. Customers aren’t just evaluating alternatives – they’re actively migrating. And that introduces risk.

What we’ve focused on is helping to make sure protection doesn’t break and can remain consistent during (and after) those transitions.

Agentless protection adds another layer to simplify that – removing dependencies that can slow down or complicate migrations, while helping keep VMs protected across environments.

This level of integration up the stack means customers can accelerate their VM migration strategy confidently and on their own terms, translating to better operational agility, reduced risk, and greater cost-savings.

#2 – Un maggiore allineamento unificato nella strategia di commercializzazione – e una soluzione di resilienza più completa per i clienti

Il secondo cambiamento ha riguardato il modo in cui ci presentiamo sul mercato insieme – e ciò che offriamo ai clienti come suite di soluzioni integrata. Gran parte di ciò è dovuto al ruolo diHPE Zerto Software from Commvault.

By integrating HPE Zerto more deeply into Commvault Cloud, we’ve strengthened our platform with continuous data protection and workload resiliency and mobility that enables customers to modernize platforms and rapidly recover workloads to keep their business running after operational disruptions.

And more recently, we introduced a game-changer with Commvault Flex built on HPE infrastructure, una soluzione full-stack che si fonda su:

  • HPE Alletra Storage MP X10000: soluzione di storage all-flash ad alte prestazioni per il ripristino accelerato di dati oggetto e file
  • Server HPE ProLiant Compute per un’elaborazione sicura e di livello aziendale
  • And an industry-leading cyber resilience platform that’s flexible and scalable enough to take advantage of that performance.

Flex solves customers’ challenges in protecting data-intensive workloads like multi-petabyte data lakes that power AI and analytics applications. With Commvault Flex built on HPE technology, customers get an integrated solution that accelerates recovery, simplifies deployment, scales easily, and can help them meet their resilience objectives and recovery SLAs for the foundational data that powers their business.

One more area that’s really come into focus for us over the past year is GreenLake by HPE. As customers push harder into AI, one thing that becomes clear pretty quickly is how infrastructure is delivered and consumed matters just as much as what’s powering it under the hood. There’s a growing need for environments that can scale, adapt, and evolve alongside these AI workloads without adding more complexity. That’s where GreenLake becomes such an important part of the conversation. It’s not just a platform – it’s how many customers are starting to think about building AI-ready infrastructure and become an agentic enterprise. For us, that means doubling down on how Commvault shows up in that ecosystem, continuing to invest in tighter integration and an optimized experience. It’s an area we’re really excited about, and one where you’ll continue to see both teams pushing forward together.

#3 – Risultati concreti ottenuti dai clienti a conferma della direzione intrapresa

The third area – and probably the most important – is what we’re seeing in customer environments.

We’re starting to see this architecture land in meaningful ways.

For example:

  • A large European bank leveraged the combined Commvault and HPE solution to strengthen cyber resilience across mission-critical banking systems – while also supporting regulatory requirements like DORA compliance. What made the difference here was the combination of Commvault’s architectural advantages and tight integration with the high-performance HPE Alletra Storage MP X10000, enabling the customer to meet recovery objectives that other solutions couldn’t match.
  • Un’importante organizzazione di gaming online in Sudafrica ha intrapreso un percorso leggermente diverso, concentrandosi sulla disponibilità e sul tempo di attività della propria platform. In questo caso, l’integrazione di HPE Zerto nella più ampia offerta di Commvault ha consentito una replica continua e un ripristino più rapido, supportando un ambiente ad alta disponibilità in cui anche brevi interruzioni hanno un impatto sul business. Il cliente ha ottenuto un’offerta di resilienza più completa, fornita end-to-end da Commvault per un processo di approvvigionamento e assistenza più snello.

Different use cases – but a common theme:

Customers aren’t just buying backup anymore. They’re investing in resilience as part of their production architecture.

Perché l’infrastruttura ibrida è più importante che mai

If you zoom out, the pattern is clear.

AI workloads are amplifying everything. There’s more data, cycles are faster, and there’s less tolerance for disruption.

And increasingly, the limiting factor isn’t compute – it’s data: How quickly it can be accessed, how efficiently it can be moved, and how fast it can be recovered when something goes wrong.

That’s why platforms like the HPE Alletra Storage MP X10000 are playing a bigger role in these conversations – high performance, scale-out storage that can scale to meet extreme capacity and throughput demands. And when it’s integrated in a solution like Commvault Flex, it creates something that’s increasingly important – a protection and recovery layer that can actually keep up with AI.

In vista dell’HPE Discover

Heading into this year’s event, there’s a different energy.

A year ago, we were talking about what we could build together.

Now, we’re seeing:

  • Una maggiore integrazione tecnica
  • Un allineamento più chiaro nella strategia di lancio sul mercato
  • E risultati concreti ottenuti dai clienti che confermano la validità di questo approccio

There’s still a lot of work ahead. But it feels like we’re at one of those points where things start to really take off.

Because the reality is simple:

AI doesn’t wait.

And increasingly, neither can your recovery strategy.

If you’re going to be at HPE Discover 2026, I’d encourage you to stop by and take a look.

Have a conversation with our team at our booth.  Take in a demo. Attend our breakout session. Or setup a meeting with our exec teams for a deeper dive.

I can’t wait to see you there – and to see what all this incredible momentum brings in the coming year.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements